Secure Boot: Can the fuses be written multiple times?

Question asked by Tanjeff Moos on May 9, 2019
I'm implementing Secure Boot on the QorIQ T1023 SoC. I have to write  the hash of the pubkey into the fuse box.


Is it possible to prototype secure boot with a "temporary" pubkey and to change the pubkey hash later on? I.e. can I write the pubkey hash to the fuse box multiple times?


There is a "Write Protect" bit (SFP_OSPR.WP) which suggest that it might be possible.