Part Number: AM6442
Hi TI Support,
We are using TI Processor SDK Linux RT for AM64xx (09.02.01.10) and need clarification on secure boot and image signing support.
We would like to know the supported procedure and tools for signing the following boot components:
-
Bootloader image signing
-
Is signing supported for:
-
tiboot3.bin -
tispl.bin -
u-boot.img
-
-
What are the supported signing tools and commands?
-
Does the SDK provide scripts/tools for generating:
-
Public keys
-
Private keys
-
Certificates
-
Hashes/signatures?
-
-
-
Secure Boot flow
-
Does AM64xx Processor SDK support HS-SE (High Security Secure) boot?
-
What is the recommended flow for:
-
Key generation
-
Key provisioning
-
Image signing
-
Image verification during boot?
-
-
Which keys are stored in eFuses/OTP and which remain in the filesystem?
-
-
Kernel image signing
-
Is Linux kernel image signing supported?
-
Can the following images be signed:
-
Image -
fitImage -
Device Tree blobs (DTB)
-
Root filesystem images
-
-
Does U-Boot verify kernel signatures before boot?
-
-
FIT image support
-
Does TI recommend using FIT image signing (
mkimagewith RSA keys) for:-
Kernel
-
DTB
-
initramfs
-
-
Are examples available in the Processor SDK?
-
-
Filesystem / SFFS signing
-
Is SFFS (Secure File System) supported on AM64xx Linux?
-
Are there tools available for:
-
Filesystem encryption
-
Filesystem signing
-
Integrity verification?
-
-
Which filesystem types are supported (ext4, squashfs, UBIFS, etc.)?
-
-
Yocto integration
-
Which Yocto recipes/classes are required to enable:
-
OpenSSL
-
Image signing
-
Secure boot
-
FIT image generation
-
Key generation during build
-
-
Are these features enabled by default in TI Processor SDK images or must they be added manually?
-
-
OpenSSL dependency
-
Which signing operations depend on OpenSSL?
-
Is the OpenSSL package included in the SDK build environment?
-
Which OpenSSL utilities/libraries are required for:
-
RSA key generation
-
Signing
-
Verification
-
Certificate generation?
-
-
Please provide the recommended secure boot/signing flow and supported features for AM64xx Processor SDK 09.02.01.10.
Thanks.
Ganesh D