testEcAttestationChain&testRsaAttestationChain Failed

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

testEcAttestationChain&testRsaAttestationChain Failed

1,183 Views
wenbo_he
Contributor I

Dear NXP's expert,

    I am running though the Android GTS test packages and  getting a number of failures. 

testEcAttestationChain&testRsaAttestationChain Failed.

I have got the googlekey file attest_keyboxes.xxx-nxp.output.

My question is how to make it work on the device?

Could you please give me some guidance documents. 

Thanks in advanced !

B.R.

0 Kudos
7 Replies

989 Views
nxf45548
NXP Employee
NXP Employee

To assist you properly, can you please let us know the part number that you are using.

0 Kudos

989 Views
wenbo_he
Contributor I

Hardware : Freescale i.MX6 Quad/DualLite (Device Tree)

0 Kudos

989 Views
joanxie
NXP TechSupport
NXP TechSupport

I found this link, maybe customer can check google key first,

https://www.itread01.com/content/1541408407.html 

0 Kudos

989 Views
wenbo_he
Contributor I

Dear Joan,

I've got the attestation "keybox" from Google.
I want to know how to flash the attestation keys to device i.MX6.

Thanks.

0 Kudos

989 Views
joanxie
NXP TechSupport
NXP TechSupport

it seems that you need refer to the security user guide  which is under NDA, so you need to get NDA first

0 Kudos

989 Views
wenbo_he
Contributor I

Dear Joan, 

I found some program attestation key commands from Android_User's_Guide.pdf,
which is downloaded from https://community.nxp.com/servlet/JiveServlet/download/1267028-1-465427/Android_User%27s_Guide.pdf
content as following,
8.11 Key attestation
Fastboot commands are provided to provision the attestation keys and certificates. Make sure the secure storage is properlyinitialized for Trusty OS:
• Set RSA private key:
fastboot stage <path-to-rsa-private-key>
fastboot oem set-rsa-atte-key

Unfortunately, the above command is not supported on imx6.
Could you tell me if the method in the security user guide is the same as the above?
If not, how can I apply for the NDA?


Thanks.

0 Kudos

989 Views
joanxie
NXP TechSupport
NXP TechSupport

for NDA, you need to contact local representative or create a case in salesforce:
Distributor Network | NXP 

https://community.nxp.com/docs/DOC-329745 

0 Kudos