From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-7.5 required=3.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI, NICE_REPLY_A,SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED,USER_AGENT_SANE_1 autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4DC6FC07E95 for ; Sat, 10 Jul 2021 09:14:28 +0000 (UTC) Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id F01056054E for ; Sat, 10 Jul 2021 09:14:26 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org F01056054E Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=denx.de Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id 665AE83277; Sat, 10 Jul 2021 11:14:24 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=none (p=none dis=none) header.from=denx.de Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=denx.de; s=phobos-20191101; t=1625908464; bh=oRv6iXCPfA0jKuR1DkrBnmavkS5ZXh1ckapRHATdjeQ=; h=Subject:To:References:From:Date:In-Reply-To:List-Id: List-Unsubscribe:List-Archive:List-Post:List-Help:List-Subscribe: From; b=tO9uM017hioxu/DDVmOTdCS9NVlJdBx7biuJ2790CX1V6dq2Er1erL0RmPwX052OO eFZnkfUmnMBsb7K7kCj7mkThGm9Km6TsB/hRYg3CdJxQncZC4AEae4ZmEKMNNXnchE nrh4HFGtEQtBRJoCyvWHQCrn7lFz6qCsuhlvCAUZZRfT2ERIikVMWY0T1ko+Xe0V8R e9QDmCnDbf71vrq7bPh76UZ98zikTX51BKq5eGtgFCnp98W95sCXq5IOG0JfdGuqNb 1E6qasXnMY3Bh/rSTZ5KxSeE9pF8o+silLz8nihYHYheguN+wFpTniSo1euACZJIdK RXhQKS3MAPVtw== Received: from [IPv6:2001:a61:601f:ce01:6d10:5831:472c:a40f] (unknown [IPv6:2001:a61:601f:ce01:6d10:5831:472c:a40f]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) (Authenticated sender: sbabic@denx.de) by phobos.denx.de (Postfix) with ESMTPSA id 20F4F83249; Sat, 10 Jul 2021 11:14:22 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=denx.de; s=phobos-20191101; t=1625908462; bh=oRv6iXCPfA0jKuR1DkrBnmavkS5ZXh1ckapRHATdjeQ=; h=Subject:To:References:From:Date:In-Reply-To:From; b=MM04YMuOY0bCPXIL4Ti8s3FP3Zt+WrpniRCzl4f/EBZe0aXoge0uuyuCUlWnD7GoG AVzfoCb+scZmuCRnoTiaACV7h5QtR7DnqcI/J3/OM4Vm8l1q89Pgpzm8pQogdEo7F0 SVzYENCTQHlOl4Zz15Mg/w/X4UOIRAIyisacK7YS46s+oHf5IJ41uPEK2ZKTaxvBX9 LjjmK0x5eID3Z8EPu7OFji3GLzzDBUzxHhFZep0qn37FF9W53rR3Z2NmsA386sDGAe MqbI/ZdsVTyOFeZortsvUXJnHSjD7tUjWIRJDc+duBJKuFo53BJVenn03WuOaWmMfP JQQ6YxTaKxTdQ== Subject: Re: IMX8M Mini HAB secure boot - working? To: Tim Harvey , Fabio Estevam , sbabic@denx.de, u-boot@lists.denx.de, uboot-imx@nxp.com, Peng Fan , Heiko Schocher References: From: Stefano Babic Message-ID: <6742d326-2daf-0480-cfb6-04e43a147b94@denx.de> Date: Sat, 10 Jul 2021 11:14:21 +0200 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.11.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: de-DE Content-Transfer-Encoding: 7bit X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.34 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.2 at phobos.denx.de X-Virus-Status: Clean Hi Tim, On 10.07.21 02:05, Tim Harvey wrote: > Greetings, > > Has anyone successfully used secure boot with IMX8M Mini or other > IMX8M? Peng's recent series got merged with the exception of what > looks like the addition of couple of 'caam' commands to blob/deblob > DEK's. > > There are no guides yet however I'm following the guides for the > downstream NXP U-Boot and thus far have been able to get the SPL to > boot with no HAB events but when it tries to authenticate the FIT > image it validate_ivt fails with 'Error: Invalid IVT structure'. Heiko tested this and found it, if I am not wrong he found the cause. Added him in CC. I have also planned to test this, it is on my TODO list... > I'm > not entirely clear if my CSF is wrong, or in the wrong place or if > there is something missing. > Best regards, Stefano -- ===================================================================== DENX Software Engineering GmbH, Managing Director: Wolfgang Denk HRB 165235 Munich, Office: Kirchenstr.5, D-82194 Groebenzell, Germany Phone: +49-8142-66989-53 Fax: +49-8142-66989-80 Email: sbabic@denx.de =====================================================================