19:18 ` Mark Kettenis 0 siblings, 1 reply 36+ messages in thread Use CONFIG_OF_EMBED which is actually not even allowed in productionĪlso you may need the -r argument to mkimage to mark the key as required. Special way of getting the devicetree into U-Boot. Looking at rpi_4 it uses CONFIG_OF_BOARD which means it has its own The required 'signature' node is present? You can use the 'fdt' Instead one provided by the earlier-stage firmware? Can you check that I wonder if rpi is not using the devicetree compiled with U-Boot, but There is an example of this flow in the sandbox vboot test. > Can you please help me with how to add Control FDT to the U-boot.bin binary or what can be the reason that it isn't checking the signature of the configuration while booting? Any kind of help would be really appreciated. Also, the following has been added in configs/rpi_4_defconfig. > Attached is the FIT source file, rpi_4_defconfig and the control FDT file. > The bytes size of the u-boot.bin and u-boot-nodtb.bin after using both the above commands is the same. Following is the command that I am using to add control FDT to U-boot. > I believe that maybe I am not adding Control FDT in the U-boot binary properly. It should be showing "Verifying Hash Integrity. > but while booting, it doesn't check the signature of the configuration. > We have checked the signature verification via the "fit_check_sign" utility that comes with u-boot and it does verify the configuration of the signature so, I am sure that the image is signed properly and the Control FDT is good as well. I am using the latest master branch from GitHub. I am using Raspi 4B and Compute Model 4 and trying to configure U-boot with Verified boot support, but while booting the signing of the configuration is not being checked. > Hope you are doing well and everything is going good at your end. On Thu, 9 Sept 2021 at 14:21, Moiz Imtiaz wrote: To: Moiz Imtiaz, Tom Rini +Cc: U-Boot Mailing List 18:19 ` Moiz Imtiaz 0 siblings, 1 reply 36+ messages in thread 20:21 Problem with U-boot | Configuration Signature not being checked while booting Moiz 4:37 ` Simon Glass
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |