Part Number: AM62L-LINUX-RT-SDK
Other Parts Discussed in Thread: AM62L
Hi Support,
u-boot/tools/binman/btool/openssl.py.TO
This thread has been locked.
If you have a related question, please click the "Ask a related question" button in the top right corner. The newly created question will be automatically linked to this question.
Part Number: AM62L-LINUX-RT-SDK
Other Parts Discussed in Thread: AM62L
Hi Support,
u-boot/tools/binman/btool/openssl.py.Hi TO,
Yes, the two referenced u-boot patches were added in AM62L Linux SDK 12.0.0.7.4, where the u-boot.img is verified using the generic u-boot verified boot framework.
- SDK user guide on secure boot flow
https://software-dl.ti.com/processor-sdk-linux/esd/AM62LX/12_00_00_07_04/exports/docs/linux/Foundational_Components_Secure_Boot.html#secure-boot-flow
- u-boot verified boot
https://docs.u-boot.org/en/latest/usage/fit/verified-boot.html
- u-boot FIT image verification
https://docs.u-boot.org/en/latest/usage/fit/signature.html
where u-boot FIT image signing is using u-boot mkimage utility, and one option on FIT image signing with external HSM server
https://docs.u-boot.org/en/latest/usage/fit/signature.html#hardware-signing-with-pkcs-11-or-with-hsm
Best,
-Hong
Hi Hong,
Thank you for your support. I’ll check the link you shared.
U-Boot signing is automatically handled by Yocto’s bitbake.
I would like to modify the arguments passed to mkimage, and I am trying to determine exactly where this should be changed.
Would the correct approach be to define or override the variables used by mkimage in do_uboot_assemble_fitimage() in oe-core/meta/classes-recipe/uboot-sign.bbclass?
Best Regards,
TO
Hi TO,
Signing the FIT u-boot.img is similar to sign the FIT kernel image. One option to use the key with external HSM server is noted in the link
https://docs.u-boot.org/en/latest/usage/fit/signature.html#hardware-signing-with-pkcs-11-or-with-hsm
Best,
-Hong