From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-7.2 required=3.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI, SPF_HELO_NONE,SPF_PASS,USER_AGENT_SANE_1 autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 90190C433EF for ; Mon, 20 Sep 2021 15:33:13 +0000 (UTC) Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id E60BC60F58 for ; Mon, 20 Sep 2021 15:33:12 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.4.1 mail.kernel.org E60BC60F58 Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=konsulko.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=lists.denx.de Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id 85F5680EC5; Mon, 20 Sep 2021 17:33:10 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=none (p=none dis=none) header.from=konsulko.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (1024-bit key; unprotected) header.d=konsulko.com header.i=@konsulko.com header.b="IVHifjx2"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id E698282986; Mon, 20 Sep 2021 17:33:08 +0200 (CEST) Received: from mail-qv1-xf34.google.com (mail-qv1-xf34.google.com [IPv6:2607:f8b0:4864:20::f34]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 9F9E28033E for ; Mon, 20 Sep 2021 17:33:05 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=none (p=none dis=none) header.from=konsulko.com Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=trini@konsulko.com Received: by mail-qv1-xf34.google.com with SMTP id w9so11389315qvs.12 for ; Mon, 20 Sep 2021 08:33:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=lkwVUviWPS1IJ8Im6qpVgf7dOeayXQ/SPUR95c6u7E0=; b=IVHifjx2FtaBwQRBrw2mJWvaEapls4ACz1ugg+8te/1ReeE9tjQIn+fa5YZ3H7H1ef x0GbszqXYaT5xiuxc3lRHE3/iO/iz9c01kx3D6zCAnkZ/J4OowYnZZSdrdKfqZhIfbRs 72d/jPawLCXMAx+GstFN9PBPLh0axwDrmtlRo= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=lkwVUviWPS1IJ8Im6qpVgf7dOeayXQ/SPUR95c6u7E0=; b=3jaYon/8TMc8JH5Frnw12kw3XIsiyY+wyhngYQ2GdrhHyw0e7rTvykYB4NTqRND2r7 EawLr3NYGjD6GIokO0dLl0Y/18VQQLeywINI6U2dSM5lq8v1og+lAEpbtEQIp1b3KJ5G uGEtL3Zf0Pfde04e3uMwbUYj/AM3/NP1rwuiEbCpk02aRxtxKYRxogMMdUxf29wL9Mks iglFH55lHFNR8sWC1opV69WypNKhxb2RjaOArZzU9/ExDZnWnVG5AxFt8kdmt0k6QnFe QlNICdbg9fzCaxZ+iDJ1mwSpkuerNNmzK/L3WfQWHLoQ6gy7mFBlosNSsh4SVutWThax X4Qg== X-Gm-Message-State: AOAM531q55m27DhduZFqO4SHJ+EwMrIrOktZcLPHYc6dLbk6ChXr2SWi PDm0pKlJArw3zVSk13CLV2HsGQ== X-Google-Smtp-Source: ABdhPJzm+UQvq8+1Z/I8ZmFWMdm7nELMeJ+s74WGCOH+kHeWX/bDs51LX/BvHpyOGTLKDyd7qIl9SA== X-Received: by 2002:a0c:dc12:: with SMTP id s18mr25497619qvk.67.1632151984534; Mon, 20 Sep 2021 08:33:04 -0700 (PDT) Received: from bill-the-cat (2603-6081-7b01-cbda-09be-67ba-cce9-f7cd.res6.spectrum.com. [2603:6081:7b01:cbda:9be:67ba:cce9:f7cd]) by smtp.gmail.com with ESMTPSA id d78sm11548973qkg.92.2021.09.20.08.33.03 (version=TLS1_2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305 bits=256/256); Mon, 20 Sep 2021 08:33:03 -0700 (PDT) Date: Mon, 20 Sep 2021 11:33:01 -0400 From: Tom Rini To: =?iso-8859-1?Q?Fran=E7ois?= Ozog Cc: Mark Kettenis , Moiz Imtiaz , jehannazkhan@skyelectric.com, moiz.imtiaz@skyelectric.com, sjg@chromium.org, u-boot@lists.denx.de Subject: Re: Problem with U-boot | Configuration Signature not being checked while booting Message-ID: <20210920153301.GZ8579@bill-the-cat> References: <561452b36639d218@bloch.sibelius.xs4all.nl> <56145f817ba7aedc@bloch.sibelius.xs4all.nl> <20210917172605.GA8971@bill-the-cat> <561469190b08558b@bloch.sibelius.xs4all.nl> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="mdGUb96ZZNqpHCXz" Content-Disposition: inline In-Reply-To: X-Clacks-Overhead: GNU Terry Pratchett User-Agent: Mutt/1.9.4 (2018-02-28) X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.34 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.2 at phobos.denx.de X-Virus-Status: Clean --mdGUb96ZZNqpHCXz Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sat, Sep 18, 2021 at 12:26:00PM +0200, Fran=C3=A7ois Ozog wrote: > Le sam. 18 sept. 2021 =C3=A0 12:10, Mark Kettenis a > =C3=A9crit : >=20 > > > From: Moiz Imtiaz > > > Date: Sat, 18 Sep 2021 14:47:51 +0500 > > > > > > >Nice! If you want to write something up extending the >documentatio= n on > > > >how you made this work for Pi it would be much appreciated. > > > > > > Sure, would love to do a PR. > > > > > > I basically replaced the dtb that pi loads with control Dtb of uboot,= but > > > will do a PR of documentation addition in respect to pi_4, detailing > > > everything shortly :) > > > > Sorry, but I don't think this is safe. The Raspberry Pi firmware > > makes changes to the device tree and it is unclear what requirements > > it has in terms of names of nodes and compatible strings since the > > firmware is closed source. It should be fine to add stuff to the DTB > > that came with the firmware, but replacing it altogether is probably > > going to break things in subtle ways. So I don't think that is > > something we should advocate by documenting it in U-Boot. > > The way I see the chain of trust is: I don=E2=80=99t know how the GPU fir= mware is > checked (or even if it is checked), The GPU firmware does not check or > measure the booted kernel from kernel=3Dxyz that it gets from the unverif= ied > config.txt which have been building a hardware description from unverified > files from the file system. >=20 > Bottom line, trying to create a secure boot flow on RPI4 may lead into > impression of security while it is not supported at hardware level. > Impression of security can be worse than no security at all. In general, there's always the questionable value of enabling some level of "secure" boot on platforms where we don't have a root of trust starting from the hardware, nor hardware assist later on. But there is some value in documenting how to enable the commodity (versus SoC-specific) functionality on very common reference platforms. Sometimes even more so even on platforms you can't otherwise potentially lock yourself out of. --=20 Tom --mdGUb96ZZNqpHCXz Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQGzBAABCgAdFiEEGjx/cOCPqxcHgJu/FHw5/5Y0tywFAmFIqa0ACgkQFHw5/5Y0 tyxHswv/Q8/0kvaWP3QkGy+dOZAPnRm6at5LqtqhENAbKTCr74q6PgKzc2IRNlOD qQchtdu0zCUL0bTbxKv2W/kaQIFZPeJBTFoBiDvctGhVMM4KigUHQ2xXez0hFgqR v8AGc2vNNkpBg8woeALbGioVcb1rwZZSrk/3O6m+d29LBH7iNuZQT9Fw182fI6Y+ 7utXDbLrptgyV27uzWb1uBJIWbfVYLnQbTbcKtkmBPs8MIY1qOectnso1R0xOkDq 76reW+kKvPuQDoiByB9QWg1j3AF3s5B6jhA1TuWX/ZHDbx/KY8L7yDJYmLoOyjnf r4kqmgKJjXuZnc9AW4oFl78oSm0W5upt6XOg/1mDCu4MdCThKWYgzI0ONM27qvxy oH4lKHNHzW1TAkNQ4TwENbBEJgIBkB+Nd6+NggncbAW6mxciQfMO8fiEzwtZfQGN Sl1kPiOAxcJXPZtKyzc3jl7kPJD2tiYx7LI40LhKB3a1qZhtMafYa4Y4fMY+D9R2 q3uvNJSf =MEFs -----END PGP SIGNATURE----- --mdGUb96ZZNqpHCXz--