mail archive of the barebox mailing list
 help / color / mirror / Atom feed
From: Sascha Hauer <sha@pengutronix.de>
To: "Barbier, Renaud" <renaud.barbier@abaco.com>
Cc: "barebox@lists.infradead.org" <barebox@lists.infradead.org>
Subject: Re: Layerscape secure boot
Date: Mon, 1 Feb 2021 10:46:02 +0100	[thread overview]
Message-ID: <20210201094602.GP19583@pengutronix.de> (raw)
In-Reply-To: <MN2PR16MB31357A9BB6E7D4B2B31274A591B99@MN2PR16MB3135.namprd16.prod.outlook.com>

Hi Renaud,

On Fri, Jan 29, 2021 at 05:59:02PM +0000, Barbier, Renaud wrote:
> Is secure boot supported or planned to be supported on Layerscape
> (LS1046A)?  This will be our first board supporting secure boot.

We have no plans adding that.

> 
> If not supported yet we intend to support it (pending having the
> documentation/SDK...) and would like to do in a way that could be
> accepted upstream.

Nice :)

> 
> Are other boards like the IMX6/8 in barebox supporting secure boot a
> reference to do secure boot for other boards?  I guess it quite
> hardware specific.

It seems that NXP reused parts of the secure boot concept from i.MX. The
overall concept on i.MX is known as "High Assurance Boot" (HAB), I
haven't found that on Layerscape. However, just like the i.MX the
Layerscape also has "Command Sequence Files" (CSF), the Code signing
Tool (CST) also works on Layerscape, and on Layerscape there are also
"Super Root Key hashes". I suspect the overall process is quite similar
to i.MX, so the HAB code could probably be used as a stone quarry.

Sascha

-- 
Pengutronix e.K.                           |                             |
Steuerwalder Str. 21                       | http://www.pengutronix.de/  |
31137 Hildesheim, Germany                  | Phone: +49-5121-206917-0    |
Amtsgericht Hildesheim, HRA 2686           | Fax:   +49-5121-206917-5555 |

_______________________________________________
barebox mailing list
barebox@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/barebox

      reply	other threads:[~2021-02-01  9:48 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-01-29 17:59 Barbier, Renaud
2021-02-01  9:46 ` Sascha Hauer [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20210201094602.GP19583@pengutronix.de \
    --to=sha@pengutronix.de \
    --cc=barebox@lists.infradead.org \
    --cc=renaud.barbier@abaco.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox