[U-Boot] mkimage unable to assign sign value to fitimage

deepak kumar Pradhan hydipu at gmail.com
Thu Jul 25 06:17:16 UTC 2019


Hi,
I saw another thread with same issue but unfortunately commented any
solution on that too.
[U-Boot] Unable to boot the new FIT image
https://lists.denx.de/pipermail/u-boot/2014-May/180688.html
Basically there are 2 issues that I am facing .
1. Compile u-boot 2018.3 with FIT_SIGNATURE and CONFIG_FIT along with
signature algorithm (sha1,rs2048) for marvell armada 388 clearfog pro
device.
2. Sign value add inside generated fitimage shows   "*Sign value:
unavailable*". and u-boot not validating the signature which fitimage load.

I am have no clue what to do next. So please help me out and point me
what's I am missing or doing wrong?
Lots of thanks in advance.







On Tue, Jul 23, 2019 at 9:41 AM deepak kumar Pradhan <hydipu at gmail.com>
wrote:

> HI ,
>
> I am using marvell armada 388 clearfog pro device.
> I am using fitimage to upgrade my device. To make the device bootup secure
> I want to sign the fitimage and verify the same in u-boot.
> 1. However I am observing that the mkimage is unable to assign sign value
> to my fit image.
> 2. One more issue I am facing that is when I am enabling the CONFIG_FIT
> and FIT_SIGNATURE, the mkimage is throughing error like below
>
>
>
> *"mkimage -f fitimage-temp.its -k keys
> fitimage-kernel-rfs-dtb.itbUnsupported signature algorithm (sha1,rs2048)
> for 'signature at 1' signature node in 'kernel at 1' image nodemkimage Can't add
> hashes to FIT blob"*
>
> Can someone help me out and uide me what I am doing wrong?
>
> Below are the outputs
> *mkimage -F -k keys bkp-fitimage-initramfs-script.bin *
> FIT description: U-Boot fitImage for Aprisa
> NEXT/4.14.54+gitAUTOINC+7c0df4bf46/clearfog
> Created:         Tue Jul 16 12:25:27 2019
>  Image 0 (kernel at 1)
>   Description:  Linux kernel
>   Created:      Tue Jul 16 12:25:27 2019
>   Type:         Kernel Image
>   Compression:  uncompressed
>   Data Size:    4906704 Bytes = 4791.70 KiB = 4.68 MiB
>   Architecture: ARM
>   OS:           Linux
>   Load Address: 0x01314c40
>   Entry Point:  0x01314c40
>   Hash algo:    crc32
>   Hash value:   8aeccf3a
>   Hash algo:    sha1
>   Hash value:   b8fafa028a78428a90304ab913877d2d0adbfd88
>
> *  Sign algo:    sha1,rs2048:my_key  Sign value:   unavailable*
>   Timestamp:    unavailable
>  Image 1 (fdt at armada-388-clearfog.dtb)
>   Description:  Flattened Device Tree blob
>   Created:      Tue Jul 16 12:25:27 2019
>   Type:         Flat Device Tree
>   Compression:  uncompressed
>   Data Size:    18373 Bytes = 17.94 KiB = 0.02 MiB
>   Architecture: ARM
>   Hash algo:    crc32
>   Hash value:   dbe5de9d
>   Hash algo:    sha1
>   Hash value:   c1b29ef3c908ecf4c9e800f573a7c33184954b4f
> *  Sign algo:    sha1,rs2048:my_key*
> *  Sign value:   unavailable*
>   Timestamp:    unavailable
>
> --
> Deepak Kumar Pradhan
>


-- 
Deepak Kumar Pradhan


More information about the U-Boot mailing list