mail archive of the barebox mailing list
 help / color / mirror / Atom feed
* [PATCH 0/6] implement i.MX93 AHAB secure boot
@ 2024-02-13 15:17 Sascha Hauer
  2024-02-13 15:17 ` [PATCH 1/6] hab: drop incomplete i.MX28 support Sascha Hauer
                   ` (7 more replies)
  0 siblings, 8 replies; 13+ messages in thread
From: Sascha Hauer @ 2024-02-13 15:17 UTC (permalink / raw)
  To: Barebox List

This adds support for AHAB based secure boot on i.MX93. The user
interface is integrated into the existing hab command used for ealier
i.MX variants. On i.MX93 the hab command can:

- read/write the SRK hash
- lock the device
- show lock status of the device

Like done with HAB the AHAB events will be shown during boot so that
possible failure events are seen should there be any issues like no
or wrong SRK hash fused or an unsigned image is attempted to be started.

Unlike with HAB it is currently not possible to sign the barebox images
directly within the barebox build system. Instead, the images need to be
signed afterwards with the NXP CST tool. I am currently unsure if it's
worth the hassle, as it turned out to be quite straight forward to
integrate the signing process into YOCTO (likely also ptxdist, but I
haven't tried yet). In the end it might be easier than adding another
indirection with tunneling the necessary keys through the barebox build
process. I might be convinced otherwise though.

Sascha

Sascha Hauer (6):
  hab: drop incomplete i.MX28 support
  hab: drop i.MX35
  hab: cleanup hab status printing during boot
  hab: pass flags to lockdown_device()
  ARM: i.MX: ele: implement more ELE operations
  hab: implement i.MX9 support

 arch/arm/mach-imx/Kconfig |   5 +
 arch/arm/mach-imx/ele.c   | 345 +++++++++++++++++++++++++++++++++++++-
 drivers/hab/hab.c         | 137 ++++++++++++++-
 drivers/hab/hab.h         |  10 ++
 drivers/hab/habv3.c       |   6 +-
 drivers/hab/habv4.c       |  62 +------
 include/hab.h             |  20 +--
 include/mach/imx/ele.h    |  18 ++
 8 files changed, 516 insertions(+), 87 deletions(-)
 create mode 100644 drivers/hab/hab.h

-- 
2.39.2




^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2024-02-16 11:58 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-02-13 15:17 [PATCH 0/6] implement i.MX93 AHAB secure boot Sascha Hauer
2024-02-13 15:17 ` [PATCH 1/6] hab: drop incomplete i.MX28 support Sascha Hauer
2024-02-13 15:17 ` [PATCH 2/6] hab: drop i.MX35 Sascha Hauer
2024-02-13 15:17 ` [PATCH 3/6] hab: cleanup hab status printing during boot Sascha Hauer
2024-02-13 15:17 ` [PATCH 4/6] hab: pass flags to lockdown_device() Sascha Hauer
2024-02-13 15:17 ` [PATCH 5/6] ARM: i.MX: ele: implement more ELE operations Sascha Hauer
2024-02-13 15:17 ` [PATCH 6/6] hab: implement i.MX9 support Sascha Hauer
2024-02-14 18:09 ` [PATCH 0/6] implement i.MX93 AHAB secure boot Ahmad Fatoum
2024-02-15  8:17   ` Sascha Hauer
2024-02-15  8:29     ` Ahmad Fatoum
2024-02-15  8:36       ` Sascha Hauer
2024-02-15 10:12     ` Marco Felsch
2024-02-16 11:58 ` Sascha Hauer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox