From: Daniel Schultz <d.schultz@phytec.de>
To: Andrew Davis <afd@ti.com>,
w.egorov@phytec.de, trini@konsulko.com, ggiordano@phytec.com,
u-boot@lists.denx.de
Cc: nm@ti.com, n-francis@ti.com, nmorrisson@phytec.com,
d-gole@ti.com, m.otto@phytec.de, bb@ti.com,
upstream@lists.phytec.de
Subject: Re: [PATCH 1/4] board: phytec: common: k3: Introduce Configs to Sign Images
Date: Mon, 10 Feb 2025 08:40:48 +0100 [thread overview]
Message-ID: <eca48319-dfb6-4118-9639-ff8286ada2ef@phytec.de> (raw)
In-Reply-To: <b97fa179-8293-480e-8757-f8cc15c39828@ti.com>
On 07.02.25 18:07, Andrew Davis wrote:
> On 2/7/25 12:51 AM, Daniel Schultz wrote:
>> Private keys to sign bootloader images shouldn't be commit or part
>> of this repository. Add config entries to use keys located outside
>> of U-Boot to sign images.
>>
>
> The custMpk.pem was always a placeholder, we fill it with the TI Dummy
> key as an example. The idea was you replace it with your key using
> something like a symlink. So custMpk.pem is replaced with a pointing
> to your real key when building on the production HSM. Why do you
> need to have a Kconfig to point to your real key?
Thanks for pointing that out! We were not aware of that process and
added these Kconfigs. I just sent new patches to add the missing keyfile
entries in our binman to use symlinks.
- Daniel
>
> If you really want a full path to be settable from Kconfig for some
> reason that I am not seeing, then others will want to too. So you
> should make this option generic for all K3, nothing specific to this
> one board family.
>
> Andrew
>
>> Signed-off-by: Maik Otto <m.otto@phytec.de>
>> Signed-off-by: Nathan Morrisson <nmorrisson@phytec.com>
>> Signed-off-by: Daniel Schultz <d.schultz@phytec.de>
>> ---
>> board/phytec/common/k3/Kconfig | 34 ++++++++++++++++++++++++++++++++++
>> 1 file changed, 34 insertions(+)
>>
>> diff --git a/board/phytec/common/k3/Kconfig
>> b/board/phytec/common/k3/Kconfig
>> index 282f4b79742..19fe927b22e 100644
>> --- a/board/phytec/common/k3/Kconfig
>> +++ b/board/phytec/common/k3/Kconfig
>> @@ -3,3 +3,37 @@ config PHYTEC_K3_DDR_PATCH
>> help
>> Allow to override default DDR timings prior to
>> DDRSS driver probing.
>> +
>> +config PHYTEC_K3_KEY_BLOB_COPY
>> + bool "Copy the MPK key and the degenerate TI key to the build path"
>> + default y
>> + help
>> + Select how to manage the MPK and degenerate TI keys.
>> + If PHYTEC_K3_KEY_BLOB_COPY is enabled, the keys will be
>> copied into
>> + the U-Boot directory for compatibility with the TI dummy keys
>> + stored there.
>> + If PHYTEC_K3_KEY_BLOB_COPY is disabled, the build will use the
>> + original key directly. It is recommended to use the original
>> key to
>> + avoid unnecessary duplication.
>> +
>> +config PHYTEC_K3_MPK_KEY
>> + string "Path to customer specific MPK key"
>> + default "custMpk.pem" if PHYTEC_K3_KEY_BLOB_COPY
>> + default "arch/arm/mach-k3/keys/custMpk.pem" if
>> !PHYTEC_K3_KEY_BLOB_COPY
>> + help
>> + Specifies the path to the MPK signing key:
>> + If PHYTEC_K3_KEY_BLOB_COPY is enabled, provide the path to
>> the blob
>> + copy of the original key.
>> + If PHYTEC_K3_KEY_BLOB_COPY is disabled, provide the path to the
>> + original key.
>> +
>> +config PHYTEC_K3_DEGENERATE_KEY
>> + string "Path to the degenerate TI key"
>> + default "ti-degenerate-key.pem" if PHYTEC_K3_KEY_BLOB_COPY
>> + default "arch/arm/mach-k3/keys/ti-degenerate-key.pem" if
>> !PHYTEC_K3_KEY_BLOB_COPY
>> + help
>> + Specifies the path to the degenerate key:
>> + If PHYTEC_K3_KEY_BLOB_COPY is enabled, provide the path to
>> the blob
>> + copy of the original key.
>> + If PHYTEC_K3_KEY_BLOB_COPY is disabled, provide the path to the
>> + original key.
next prev parent reply other threads:[~2025-02-10 7:41 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-02-07 6:51 [PATCH 0/4] phyCORE-AM62x/AM64x: Sign Images with External Keys Daniel Schultz
2025-02-07 6:51 ` [PATCH 1/4] board: phytec: common: k3: Introduce Configs to Sign Images Daniel Schultz
2025-02-07 17:07 ` Andrew Davis
2025-02-10 7:40 ` Daniel Schultz [this message]
2025-02-07 6:51 ` [PATCH 2/4] board: Phytec: phycore_am6*: Add k3 Kconfig to A53 Daniel Schultz
2025-02-07 6:51 ` [PATCH 3/4] arch: arm: dts: k3-am625-phycore-som-binman: Add custMpk and ti-degenerate keys with CONFIG entries Daniel Schultz
2025-02-07 6:51 ` [PATCH 4/4] arch: arm: dts: k3-am642-phycore-som-binman: " Daniel Schultz
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=eca48319-dfb6-4118-9639-ff8286ada2ef@phytec.de \
--to=d.schultz@phytec.de \
--cc=afd@ti.com \
--cc=bb@ti.com \
--cc=d-gole@ti.com \
--cc=ggiordano@phytec.com \
--cc=m.otto@phytec.de \
--cc=n-francis@ti.com \
--cc=nm@ti.com \
--cc=nmorrisson@phytec.com \
--cc=trini@konsulko.com \
--cc=u-boot@lists.denx.de \
--cc=upstream@lists.phytec.de \
--cc=w.egorov@phytec.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox