From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8E51EC433EF for ; Wed, 20 Oct 2021 14:43:16 +0000 (UTC) Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 63E01610CB for ; Wed, 20 Oct 2021 14:43:15 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.4.1 mail.kernel.org 63E01610CB Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=denx.de Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=lists.denx.de Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id B64E083246; Wed, 20 Oct 2021 16:43:12 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=none (p=none dis=none) header.from=denx.de Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=denx.de; s=phobos-20191101; t=1634740993; bh=0M7WGt3r7lEhDhxrTeXWPG7lUafqwptTXyXkWDXL1kA=; h=From:To:Subject:In-reply-to:Date:List-Id:List-Unsubscribe: List-Archive:List-Post:List-Help:List-Subscribe:From; b=HgIWaQ1f3MVwGj9bbh1PJ4ydSKkYY7S4OGeoNljDbF/zdqT19t81qyXnH8qTIWhap 1AwhGw71tLMZFJk2YgmWkCgXht7TjVvZHyNoglWiBT1Q9zD7Jv/j/TcKej0bCPbe7D /9y9ygy7zVyt9oEdiNIR2MLEhzpgvJBlWFG2FnFTl+LHJS3SMWuI4TlCgZ4tChtyLm E6NCfjUSkAe74s9JtpC1RkIx+ry85KMF1ZcbIkZnyxb8KS79jKrS7ZRQu7TEge6coC I/K5qx8KxbxXnGw2IpDUA3p7OBLjdeOb7GSn592rAqjYlI3lRzIs0iWl5D3duGDmYA YE6uq+wjXr+Pw== Received: by phobos.denx.de (Postfix, from userid 109) id 224A98203C; Wed, 20 Oct 2021 16:43:11 +0200 (CEST) Received: from mail-out.m-online.net (mail-out.m-online.net [IPv6:2001:a60:0:28:0:1:25:1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 1A95980516 for ; Wed, 20 Oct 2021 16:43:08 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=none (p=none dis=none) header.from=denx.de Authentication-Results: phobos.denx.de; spf=fail smtp.mailfrom=sbabic@denx.de Received: from frontend01.mail.m-online.net (unknown [192.168.8.182]) by mail-out.m-online.net (Postfix) with ESMTP id 4HZCyg52GHz1sFFX; Wed, 20 Oct 2021 16:43:07 +0200 (CEST) Received: from localhost (dynscan1.mnet-online.de [192.168.6.70]) by mail.m-online.net (Postfix) with ESMTP id 4HZCyg410qz1qqkB; Wed, 20 Oct 2021 16:43:07 +0200 (CEST) X-Amavis-Alert: BAD HEADER SECTION, Missing required header field: "Date" Received: from mail.mnet-online.de ([192.168.8.182]) by localhost (dynscan1.mail.m-online.net [192.168.6.70]) (amavisd-new, port 10024) with ESMTP id HKLmH_t9kWXg; Wed, 20 Oct 2021 16:43:06 +0200 (CEST) Received: from papero (host-88-217-136-221.customer.m-online.net [88.217.136.221]) by mail.mnet-online.de (Postfix) with ESMTP; Wed, 20 Oct 2021 16:43:06 +0200 (CEST) From: sbabic@denx.de X-Patchwork-Submitter: Marcel Ziswiler X-Patchwork-Id: 1538869 X-Patchwork-Delegate: sbabic@denx.de To: Marcel Ziswiler ,u-boot@lists.denx.de Subject: [PATCH v6 03/11] ARM: dts: imx8mm-verdin: prepare for dek blob encapsulation In-reply-to: <20211009204113.1208641-4-marcel@ziswiler.com> Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit MIME-Version: 1.0 Message-Id: <20211020144311.224A98203C@phobos.denx.de> Date: Wed, 20 Oct 2021 16:43:08 +0200 (CEST) X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.34 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.2 at phobos.denx.de X-Virus-Status: Clean > From: Marcel Ziswiler > Prepare for DEK blob encapsulation support through "dek_blob" command. > On ARMv8, u-boot runs in non-secure, thus cannot encapsulate a DEK blob > for encrypted boot. > The DEK blob is encapsulated by OP-TEE through a trusted application > call. U-boot sends and receives the DEK and the DEK blob binaries > through OP-TEE dynamic shared memory. > To enable the DEK blob encapsulation, add to the defconfig: > CONFIG_SECURE_BOOT=y > CONFIG_FAT_WRITE=y > CONFIG_CMD_DEKBLOB=y > Taken from NXP's commit 56d2050f4028 ("imx8m: Add DEK blob encapsulation > for imx8m"). > Signed-off-by: Marcel Ziswiler > Reviewed-by: Fabio Estevam Applied to u-boot-imx, master, thanks ! Best regards, Stefano Babic -- ===================================================================== DENX Software Engineering GmbH, Managing Director: Wolfgang Denk HRB 165235 Munich, Office: Kirchenstr.5, D-82194 Groebenzell, Germany Phone: +49-8142-66989-53 Fax: +49-8142-66989-80 Email: sbabic@denx.de =====================================================================