Under the HAB technology the SRK fuses contain the hash of the SRK public key and the fuses
can be read. This restriction may be overcome if BSP uses GUI, does not support terminal program,
JTAG is disabled.
As for encryption boot under i.MX6 : in order to generate a Data Encryption Key (DEK) blob for
encrypted boot, the OTPMK must be used, so blobs must be generated on the i.MX6.
Next, this requires the device be in the Closed configuration, so the Mfg Tool U-boot and OS Kernel
images must be signed - in order to use the OTP Master Key. Today we do not have recommendations
and tools for customers how to perform it, sorry.
Have a great day,
Yuri
-----------------------------------------------------------------------------------------------------------------------
Note: If this post answers your question, please click the Correct Answer button. Thank you!
-----------------------------------------------------------------------------------------------------------------------