public inbox for u-boot@lists.denx.de
 help / color / mirror / Atom feed
* [U-Boot] booting signed Images
@ 2014-05-05  7:35 Heiko Schocher
  2014-05-05 17:25 ` Simon Glass
  0 siblings, 1 reply; 7+ messages in thread
From: Heiko Schocher @ 2014-05-05  7:35 UTC (permalink / raw)
  To: u-boot

Hello Simon,

just talked with Wolfgang about the booting process from signed images,
as it is described in:

doc/uImage.FIT/verified-boot.txt
doc/uImage.FIT/signature.txt

If we see it correct, then it is still possible to boot an uImage
or a FIT image without signature with "bootm" when CONFIG_FIT_SIGNATURE
is defined.

The question raised, if this is a good behaviour.

Should we not prevent booting uImages or not signed FIT Images when
CONFIG_FIT_SIGNATURE is defined?
Or at least prevent booting such unsigned images through an U-Boot
env variable.

What Do you think?

Thanks in advance

bye,
Heiko
-- 
DENX Software Engineering GmbH,     MD: Wolfgang Denk & Detlev Zundel
HRB 165235 Munich, Office: Kirchenstr.5, D-82194 Groebenzell, Germany

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2014-05-07 22:51 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-05-05  7:35 [U-Boot] booting signed Images Heiko Schocher
2014-05-05 17:25 ` Simon Glass
2014-05-05 17:55   ` Wolfgang Denk
2014-05-05 18:31     ` Simon Glass
2014-05-05 19:19       ` Wolfgang Denk
2014-05-07  7:06       ` Heiko Schocher
2014-05-07 22:51         ` Simon Glass

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox