From: Wolfgang Denk <wd@denx.de>
To: u-boot@lists.denx.de
Subject: [U-Boot] booting signed Images
Date: Mon, 05 May 2014 19:55:04 +0200 [thread overview]
Message-ID: <20140505175504.9FE723809DA@gemini.denx.de> (raw)
In-Reply-To: <CAPnjgZ2-qC8YK8t2DvmzXWKy3Wd+=7VY1Ti=Jm98LF96PLfu-g@mail.gmail.com>
Dear Simon,
In message <CAPnjgZ2-qC8YK8t2DvmzXWKy3Wd+=7VY1Ti=Jm98LF96PLfu-g@mail.gmail.com> you wrote:
>
> > Should we not prevent booting uImages or not signed FIT Images when
> > CONFIG_FIT_SIGNATURE is defined?
> > Or at least prevent booting such unsigned images through an U-Boot
> > env variable.
> >
> > What Do you think?
>
> There is a 'required' property in the public keys which is intended to
> support this. If you mark a key as 'required then it will need to be
> verified by any image that is loaded. There is a test for this case,
> but it may not be comprehensive.
But what about legacy uImage files? It appears nothing would stop
booting one of those?
Best regards,
Wolfgang Denk
--
DENX Software Engineering GmbH, MD: Wolfgang Denk & Detlev Zundel
HRB 165235 Munich, Office: Kirchenstr.5, D-82194 Groebenzell, Germany
Phone: (+49)-8142-66989-10 Fax: (+49)-8142-66989-80 Email: wd at denx.de
Accident: A condition in which presence of mind is good, but absence
of body is better.
next prev parent reply other threads:[~2014-05-05 17:55 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-05-05 7:35 [U-Boot] booting signed Images Heiko Schocher
2014-05-05 17:25 ` Simon Glass
2014-05-05 17:55 ` Wolfgang Denk [this message]
2014-05-05 18:31 ` Simon Glass
2014-05-05 19:19 ` Wolfgang Denk
2014-05-07 7:06 ` Heiko Schocher
2014-05-07 22:51 ` Simon Glass
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20140505175504.9FE723809DA@gemini.denx.de \
--to=wd@denx.de \
--cc=u-boot@lists.denx.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.