[U-Boot] [U-Boot, v2] verified-boot: Minimal support for booting U-Boot proper from SPL

Tom Rini trini at konsulko.com
Sun Jun 19 16:08:13 CEST 2016


On Thu, Jun 09, 2016 at 07:18:44PM -0700, Teddy Reed wrote:

> This allows a board to configure verified boot within the SPL using
> a FIT or FIT with external data. It also allows the SPL to perform
> signature verification without needing relocation.
> 
> The board configuration will need to add the following feature defines:
> CONFIG_SPL_CRYPTO_SUPPORT
> CONFIG_SPL_HASH_SUPPORT
> CONFIG_SPL_SHA256
> 
> In this example, SHA256 is the only selected hashing algorithm.
> 
> And the following booleans:
> CONFIG_SPL=y
> CONFIG_SPL_DM=y
> CONFIG_SPL_LOAD_FIT=y
> CONFIG_SPL_FIT=y
> CONFIG_SPL_OF_CONTROL=y
> CONFIG_SPL_OF_LIBFDT=y
> CONFIG_SPL_FIT_SIGNATURE=y
> 
> Signed-off-by: Teddy Reed <teddy.reed at gmail.com>
> Acked-by: Simon Glass <sjg at chromium.org>
> Acked-by: Andreas Dannenberg <dannenberg at ti.com>
> Acked-by: Sumit Garg <sumit.garg at nxp.com>

Applied to u-boot/master, thanks!

-- 
Tom
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: Digital signature
URL: <http://lists.denx.de/pipermail/u-boot/attachments/20160619/a2f52533/attachment.sig>


More information about the U-Boot mailing list