[PATCH 5/5] configs: am62a: use kernel fitImage when using secure bootflow

Tom Rini trini at konsulko.com
Wed Jan 11 03:17:15 CET 2023


On Fri, Dec 23, 2022 at 07:15:25PM -0600, Bryan Brattlof wrote:

> In order to maintain the chain of trust, each stage of the boot process
> will first authenticate each binary it loads before continuing. To
> extend this to the kernal and its dtbs we can package the kernal and
> its dtbs into another fitImage for Uboot to authenticate and extend the
> chain of trust all the way to the kernel.
> 
> When 'boot_fit' is set, indicating we're using the secure bootflow, look
> for and authenticate the kernel's fitImage.
> 
> Signed-off-by: Judith Mendez <jm at ti.com>
> Signed-off-by: Bryan Brattlof <bb at ti.com>

Applied to u-boot/master, thanks!

-- 
Tom
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 659 bytes
Desc: not available
URL: <https://lists.denx.de/pipermail/u-boot/attachments/20230110/435af5f6/attachment.sig>


More information about the U-Boot mailing list