All of lore.kernel.org
 help / color / mirror / Atom feed
From: Tom Rini <trini@konsulko.com>
To: Philippe Reynes <philippe.reynes@softathome.com>
Cc: marko.makela@iki.fi, jonny.green@keytechinc.com,
	raymondmaoca@gmail.com, simon.glass@canonical.com,
	u-boot@lists.u-boot-project.org
Subject: Re: [PATCH v9 00/15] add software ecdsa support
Date: Fri, 4 Sep 2026 08:32:52 -0600	[thread overview]
Message-ID: <20260904143252.GP1764417@bill-the-cat> (raw)
In-Reply-To: <9c0d700d-04f3-4ad0-9453-bae0dbe6e471@softathome.com>

[-- Attachment #1: Type: text/plain, Size: 2328 bytes --]

On Fri, Sep 04, 2026 at 10:10:24AM +0200, Philippe Reynes wrote:
> Hi Tom,
> 
> Le 03/09/2026 à 20:35, Tom Rini a écrit :
> > On Thu, Sep 03, 2026 at 10:16:50AM +0200, Philippe Reynes wrote:
> > 
> > > This series adds the support of ecdsa with software
> > > using mbedtls. So boards without ecdsa hardware may
> > > also use signature with ecdsa.
> > > 
> > > To achieve this goal, several changes are done:
> > > - fix the support of secp521r1
> > > - enable support of ecdsa in mbedtls
> > > - add software ecdsa signature check using mbedtls
> > > - add support of ecdsa for internal fit signature
> > > - add test for ecdsa for internal fit signature in vboot
> > > - add support of ecdsa for pre-load signature
> > > - add test for ecdsa for pre-load signature in vboot
> > > - enable software ecdsa signature check in sandbox
> > OK, so it's enabled on sandbox.
> > 
> > > To test this new feature, just follow those steps:
> > > 
> > > 0) build u-boot using sandbox_defconfig and adding those options:
> > > 
> > > CONFIG_ECDSA_MBEDTLS=y
> > > CONFIG_ECDSA_VERIFY_MBEDTLS=y
> > > CONFIG_ECDSA=y
> > > CONFIG_ECDSA_VERIFY=y
> > > 
> > > 1) add a signature node to an its file
> > > 	signature-256 {
> > > 		algo = "sha256,ecdsa256";
> > > 		key-name-hint = "private-key-256";
> > > 	};
> > > 
> > > 2) generate an ecdsa key
> > > openssl ecparam -name prime256v1 -genkey -noout -out private-key-256.pem
> > > 
> > > 3) create the itb file
> > > ./tools/mkimage -f <file.its> -k . -K arch/sandbox/dts/test.dtb <file.itb>
> > > 
> > > 4) launch sandbox u-boot
> > > 
> > > ./u-boot -d arch/sandbox/dts/test.dtb
> > > 
> > > 5) on sandbox u-boot prompt, load the itb and launch bootm on it
> > > 
> > > => host load hostfs - 1000000 uboot-ecdsa.itb
> > > 4628674 bytes read in 1 ms (4.3 GiB/s)
> > > => bootm 1000000
> > > ...
> > > ...
> > >     Verifying Hash Integrity ... sha256,ecdsa256:private-key-256+ OK
> > Does this mean the new tests aren't run automatically?
> The tests for software ecdsa are added in vboot, so they are run
> automatically.
> Ecdsa signature in fit and ecdsa signature in pre-load header are tested.
> This last paragraph was for human being, to explain how to use it. Sorry if
> this adds confusion.

Ah, OK, thanks.

-- 
Tom

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

      reply	other threads:[~2026-09-04 14:33 UTC|newest]

Thread overview: 36+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03  8:16 [PATCH v9 00/15] add software ecdsa support Philippe Reynes
2026-09-03  8:16 ` [PATCH v9 01/15] ecdsa: fix support of secp521r1 Philippe Reynes
2026-09-03 14:30   ` Raymond Mao
2026-09-03  8:16 ` [PATCH v9 02/15] mbedtls: enable support of ecc Philippe Reynes
2026-09-03 14:31   ` Raymond Mao
2026-09-03  8:16 ` [PATCH v9 03/15] ecdsa: initial support of ecdsa using mbedtls Philippe Reynes
2026-09-03 14:31   ` Raymond Mao
2026-09-03  8:16 ` [PATCH v9 04/15] test: lib: ecdsa: add initial test Philippe Reynes
2026-09-03 14:32   ` Raymond Mao
2026-09-03  8:16 ` [PATCH v9 05/15] drivers: crypto: add software ecdsa support Philippe Reynes
2026-09-03 14:32   ` Raymond Mao
2026-09-03 15:33     ` Raymond Mao
2026-09-03 18:33       ` Tom Rini
2026-09-03  8:16 ` [PATCH v9 06/15] test: dm: ecdsa.c: clean this test as software ecdsa is now implemented Philippe Reynes
2026-09-03 14:33   ` Raymond Mao
2026-09-03  8:16 ` [PATCH v9 07/15] test: py: vboot: prepare integration test for ecdsa Philippe Reynes
2026-09-03 15:42   ` Raymond Mao
2026-09-03  8:16 ` [PATCH v9 08/15] test: vboot: add " Philippe Reynes
2026-09-03 15:43   ` Raymond Mao
2026-09-03  8:16 ` [PATCH v9 09/15] tools: fit_image_setup_sig: set required_keynode to -1 Philippe Reynes
2026-09-03 14:34   ` Raymond Mao
2026-09-03  8:17 ` [PATCH v9 10/15] tools: mkimage: pre-load: add support of ecdsa Philippe Reynes
2026-09-03 14:36   ` Raymond Mao
2026-09-03  8:17 ` [PATCH v9 11/15] tools: binman: " Philippe Reynes
2026-09-03 14:37   ` Raymond Mao
2026-09-03  8:17 ` [PATCH v9 12/15] boot: " Philippe Reynes
2026-09-03 14:38   ` Raymond Mao
2026-09-03  8:17 ` [PATCH v9 13/15] tools: preload_check_sign: " Philippe Reynes
2026-09-03 14:39   ` Raymond Mao
2026-09-03  8:17 ` [PATCH v9 14/15] test: py: vboot: prepare test for global signature with ecdsa Philippe Reynes
2026-09-03 14:40   ` Raymond Mao
2026-09-03  8:17 ` [PATCH v9 15/15] test: py: vboot: add " Philippe Reynes
2026-09-03 14:41   ` Raymond Mao
2026-09-03 18:35 ` [PATCH v9 00/15] add software ecdsa support Tom Rini
2026-09-04  8:10   ` Philippe Reynes
2026-09-04 14:32     ` Tom Rini [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260904143252.GP1764417@bill-the-cat \
    --to=trini@konsulko.com \
    --cc=jonny.green@keytechinc.com \
    --cc=marko.makela@iki.fi \
    --cc=philippe.reynes@softathome.com \
    --cc=raymondmaoca@gmail.com \
    --cc=simon.glass@canonical.com \
    --cc=u-boot@lists.u-boot-project.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.