Part Number: CC3230SF
Other Parts Discussed in Thread: CC3235SF, SYSCONFIG
Hi TI Support Team,
We are currently working with the CC3230SF in Production Mode and are utilizing the Secure Filesystem for OTA updates.
During our recent testing, we noticed that our custom Vendor/Code Signing Certificate (which is used to sign the ota.cmd manifest and generate te ota.sign file) has expired. However, to our surprise, the CC3230SF still successfully verifies the signature and installs the OTA update without throwing any security alerts.
We found a few older forum posts suggesting that the NWP might ignore the expiration date for code signing purposes to prevent devices from bricking in the field.
Could you please clarify the following points regarding the NWP behavior during OTA and Secure Filesystem operations:
-
Code Signing Certificate: Does the CC3235SF network processor intentionally ignore the expiration date ("Not After" field) of the Code Signing Certificate when verifying the ota.sign file?
-
Root CA in Catalog: Does the same logic apply to the Root CA stored inside the Certificate Catalog? If the Root CA expires, will the device still accept signatures derived from it?
-
Future Behavior: Is it safe to assume we can continue updating our devices in the field with an expired code signing certificate, or are there any plans to enforce expiration dates in future Service Packs / ROM updates?
Having a definitive answer on this will greatly help us in planning our long-term OTA migration strategy.
Thanks in advance for your support!
Regards
Thomas