[PATCH] binman: add fast authentication method for i.MX8M signing

Tom Rini trini at konsulko.com
Fri Sep 27 22:40:46 CEST 2024


On Fri, Sep 27, 2024 at 10:50:29AM -0600, Simon Glass wrote:
> Hi,
> 
> On Fri, 27 Sept 2024 at 06:42, Brian Ruley <brian.ruley at gehealthcare.com> wrote:
> >
> > Using the PKI tree with SRKs as intermediate CA isn't necessary or even
> > desirable in some situations (boot time, for example). Add the possbility
> > to use the "fast authentication" method where the image and CSF are both
> > signed using the SRK [1, p.63].
> >
> > [1] https://community.nxp.com/pwmxy87654/attachments/pwmxy87654/imx-processors/202591/1/CST_UG.pdf
> >
> > Signed-off-by: Brian Ruley <brian.ruley at gehealthcare.com>
> > Cc: Marek Vasut <marex at denx.de>
> >
> >  tools/binman/etype/nxp_imx8mcst.py | 23 +++++++++++++++++++----
> >  1 file changed, 19 insertions(+), 4 deletions(-)
> >
> 
> Please can you coordinate with Marek as we need to sort out the test
> coverage for this etype, before adding more functionality. I did a
> starting point, now in -next, which should help.

Well, when someone has both time and understanding of the tools and the
frameworks, we can expand the automatic tests while still having
functional testing as people use the feature.

-- 
Tom
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 659 bytes
Desc: not available
URL: <https://lists.denx.de/pipermail/u-boot/attachments/20240927/36616d91/attachment.sig>


More information about the U-Boot mailing list