[PATCH v3 3/3] doc: verified-boot: add required-mode information
thiruan at linux.microsoft.com
Mon Aug 17 08:01:11 CEST 2020
Add documentation about 'required-mode' property in /signature node
in U-Boot's control FDT.
Signed-off-by: Thirupathaiah Annapureddy <thiruan at linux.microsoft.com>
Reviewed-by: Simon Glass <sjg at chromium.org>
Changes in v3:
- Added commit description to address checkpatch warning.
Changes in v2:
doc/uImage.FIT/signature.txt | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git a/doc/uImage.FIT/signature.txt b/doc/uImage.FIT/signature.txt
index d4afd755e9..a3455889ed 100644
@@ -386,6 +386,20 @@ that might be used by the target needs to be signed with 'required' keys.
This happens automatically as part of a bootm command when FITs are used.
+For Signed Configurations, the default verification behavior can be changed by
+the following optional property in /signature node in U-Boot's control FDT.
+- required-mode: Valid values are "any" to allow verified boot to succeed if
+the selected configuration is signed by any of the 'required' keys, and "all"
+to allow verified boot to succeed if the selected configuration is signed by
+all of the 'required' keys.
+This property can be added to a binary device tree using fdtput as shown in
+ fdtput -t s control.dtb /signature required-mode any
+ fdtput -t s control.dtb /signature required-mode all
Enabling FIT Verification
More information about the U-Boot