AM6421: signed/verified elf boot via u-boot

Part Number: AM6421

Tool/software:

I am looking into secure booting a simple ELF file, i.e. not using Linux.
The ELF file boots just fine using "bootelf" in u-boot.
But: As far as my understanding goes so far, I need:
* a FIT image
* use "bootm"
to get u-boot to verify a signature successfully.
But I cannot get u-boot to start my ELF file using a FIT image because it always wants a "kernel" entry in the FIT which I do not have.

So my questions are:

1) is it correct, that there is no other way to have a signature verification before booting other than FIT+bootm?

1a) if there is another way, please point me to it

2) How can I get u-boot to load, verify and boot my ELF file using a simple but correct FIT?