From: Tom Rini <trini@konsulko.com>
To: Quentin Schulz <quentin.schulz@cherry.de>
Cc: Simon Glass <sjg@chromium.org>,
Quentin Schulz <foss+uboot@0leil.net>,
U-Boot Mailing List <u-boot@lists.denx.de>,
Aristo Chen <jj251510319013@gmail.com>,
Rasmus Villemoes <ravi@prevas.dk>,
Marek Vasut <marek.vasut+renesas@mailbox.org>,
Paul HENRYS <paul.henrys_ext@softathome.com>,
Heinrich Schuchardt <xypron.glpk@gmx.de>,
Shiji Yang <yangshiji66@outlook.com>,
Anton Moryakov <ant.v.moryakov@gmail.com>,
Alper Nebi Yasak <alpernebiyasak@gmail.com>,
Alice Guo <alice.guo@nxp.com>, Bryan Brattlof <bb@ti.com>
Subject: Re: [PATCH 2/3] tools: binman: mkimage: add support for passing the engine
Date: Mon, 3 Nov 2025 08:17:33 -0600 [thread overview]
Message-ID: <20251103141733.GK6688@bill-the-cat> (raw)
In-Reply-To: <77d2b661-3416-41ae-9f73-68977a26aa30@cherry.de>
[-- Attachment #1: Type: text/plain, Size: 2169 bytes --]
On Mon, Nov 03, 2025 at 01:13:04PM +0100, Quentin Schulz wrote:
> Hi Simon,
>
> On 11/2/25 8:53 PM, Simon Glass wrote:
> > Hi Quentin,
> >
> > On Fri, 31 Oct 2025 at 16:23, Quentin Schulz <foss+uboot@0leil.net> wrote:
> > >
> > > From: Quentin Schulz <quentin.schulz@cherry.de>
> > >
> > > mkimage has support for OpenSSL engines but binman currently doesn't for
> > > direct callers of mkimage (e.g. the fit etype). This prepares for adding
> > > support for OpenSSL engines for signing elements of a FIT image, which
> > > will done in the next commit.
> > >
> > > Signed-off-by: Quentin Schulz <quentin.schulz@cherry.de>
> > > ---
> > > tools/binman/btool/mkimage.py | 5 ++++-
> > > 1 file changed, 4 insertions(+), 1 deletion(-)
> >
> > Please make sure this is tested.
> >
>
> That was the anticipated and feared answer. I'll need to figure out how to
> create a dummy OpenSSL engine which doesn't require any hardware so it can
> be part of the CI. I have no experience with OpenSSL, so this will take a
> while.
>
> Just to be sure I'm not sinking time into things U-Boot has no interest in,
> would supporting OpenSSL engines for signing be mergeable? OpenSSL has
> deprecated engines with their 3.0 release in favor of providers (see a
> recent series on the U-Boot ML for their support in U-Boot and
> https://github.com/openssl/openssl/blob/master/README-ENGINES.md for the
> official stance of OpenSSL on this). Porting my employer's engine to
> provider isn't planned (yet?) but I would like to know if U-Boot has no
> interest supporting that use-case, in which case I will "happily" keep this
> downstream only.
This is another case I think where the utility of adding a test is
important too. For the question of supporting SSL and engines, the
answer is that LibreSSL isn't doing what OpenSSL is doing and we will
continue supporting LibreSSL using hosts. And I would rather see this
code in the project, so that the real life needs can be accounted for in
future changes to the code than it be kept out because introducing a
dummy test wasn't easy and so didn't end up happening.
--
Tom
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]
next prev parent reply other threads:[~2025-11-03 14:17 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-10-31 15:22 [PATCH 0/3] fit: allow signing with only an engine_id Quentin Schulz
2025-10-31 15:22 ` [PATCH 1/3] fit: support " Quentin Schulz
2025-11-02 19:53 ` Simon Glass
2025-11-11 10:10 ` Wolfgang Wallner
2025-10-31 15:22 ` [PATCH 2/3] tools: binman: mkimage: add support for passing the engine Quentin Schulz
2025-11-02 19:53 ` Simon Glass
2025-11-03 12:13 ` Quentin Schulz
2025-11-03 14:17 ` Tom Rini [this message]
2025-11-03 14:21 ` Quentin Schulz
2025-11-03 14:52 ` Simon Glass
2025-11-11 10:11 ` Wolfgang Wallner
2025-10-31 15:23 ` [PATCH 3/3] tools: binman: fit: add support for OpenSSL engines Quentin Schulz
2025-11-02 19:53 ` Simon Glass
2025-11-03 16:21 ` Peter Robinson
2025-11-03 16:47 ` Quentin Schulz
2025-11-11 10:14 ` Wolfgang Wallner
2025-11-17 15:18 ` Peter Robinson
2025-11-17 15:38 ` Tom Rini
2025-11-17 16:09 ` Quentin Schulz
2025-11-11 10:12 ` Wolfgang Wallner
2025-11-11 10:10 ` [PATCH 0/3] fit: allow signing with only an engine_id Wolfgang Wallner
2025-11-11 11:22 ` Quentin Schulz
2025-11-11 14:49 ` Wolfgang Wallner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20251103141733.GK6688@bill-the-cat \
--to=trini@konsulko.com \
--cc=alice.guo@nxp.com \
--cc=alpernebiyasak@gmail.com \
--cc=ant.v.moryakov@gmail.com \
--cc=bb@ti.com \
--cc=foss+uboot@0leil.net \
--cc=jj251510319013@gmail.com \
--cc=marek.vasut+renesas@mailbox.org \
--cc=paul.henrys_ext@softathome.com \
--cc=quentin.schulz@cherry.de \
--cc=ravi@prevas.dk \
--cc=sjg@chromium.org \
--cc=u-boot@lists.denx.de \
--cc=xypron.glpk@gmx.de \
--cc=yangshiji66@outlook.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox