LS1021A: Loading encrypted linux image

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

LS1021A: Loading encrypted linux image

590 Views
z_v
Contributor I

Hello,

How can u-boot created with Yocto load an encrypted  linux kernel (+ file system) ?

I found the attached article but according to it, this concept is not supported by Yocto (fitImage) yet.

Is there an alternative ?

Thank you,

Z.V

0 Kudos
2 Replies

400 Views
bpe
NXP Employee
NXP Employee

Please visit the link below for online description of secure boot with confidentiality:


https://freescale.sdlproducts.com/LiveContent/content/en-US/QorIQ_SDK/GUID-6D2EDD0D-F752-4080-96CF-A...

Notes:

1. Blob commands used for encrypting boot images make no difference
   between FIT and non-FIT images.
   
2. Default SDK 2.0 deployment type for LS1021ATWR is non-FIT.


Have a great day,
Platon

-----------------------------------------------------------------------------------------------------------------------
Note: If this post answers your question, please click the Correct Answer button. Thank you!
-----------------------------------------------------------------------------------------------------------------------

0 Kudos

400 Views
z_v
Contributor I

Hi Platon,

Can you please explain what are "blob commands" ?

Is it possible to encrypt fsl.rootfs.ext2.gz loaded by u-boot and opened to RAM in LS1021A ?

How can the PC that runs TFTP server gets the public key upon "tftpboot" command initiated by LS1021A ?

Thank you,

Z.V

0 Kudos