From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E840BC433EF for ; Mon, 18 Apr 2022 16:56:42 +0000 (UTC) Subject: signing an initramfs kernel To: meta-freescale@lists.yoctoproject.org From: toyonembedded@gmail.com X-Originating-Location: Santa Barbara, California, US (209.203.101.124) X-Originating-Platform: Linux Firefox 99 User-Agent: GROUPS.IO Web Poster MIME-Version: 1.0 Date: Mon, 18 Apr 2022 09:10:22 -0700 Message-ID: Content-Type: multipart/alternative; boundary="6OV3S1vOgfckxKhnJvHu" List-Id: X-Webhook-Received: from li982-79.members.linode.com [45.33.32.79] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Mon, 18 Apr 2022 16:56:42 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/meta-freescale/message/24834 --6OV3S1vOgfckxKhnJvHu Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable On my i.mx8mp board I have secure boot enabled. I can boot a signed kernel = fine. I'd like to now sign the kernel used with the initramfs image. I don'= t understand if that kernel is the same as the regular kernel and if I can = just replace the signed kernel with it? when I build my initramfs image recipe I get a few new files including a ro= otfs.cpio.gz file and a Image-initramfs file. I'm unclear what the differen= ces are between these files. If I unpack the cpio.gz file I see an Image file in /boot/Image. I don't se= em to be able to boot this cpio.gz image though. --6OV3S1vOgfckxKhnJvHu Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: quoted-printable On my i.mx8mp board I have secure boot enabled. I can boot a signed kernel = fine. I'd like to now sign the kernel used with the initramfs image. I don'= t understand if that kernel is the same as the regular kernel and if I can = just replace the signed kernel with it?

when I build my initramf= s image recipe I get a few new files including a rootfs.cpio.gz file and a = Image-initramfs file. I'm unclear what the differences are between these fi= les.

If I unpack the cpio.gz file I see an Image file in /boot/= Image. I don't seem to be able to boot this cpio.gz image though. --6OV3S1vOgfckxKhnJvHu--