diff options
author | Ulises Cardenas <Ulises.Cardenas@freescale.com> | 2015-04-20 13:47:58 -0500 |
---|---|---|
committer | Stefano Babic <sbabic@denx.de> | 2015-05-15 19:20:46 +0200 |
commit | 8148b824492e7696a9e72bb5b715720db8fd889e (patch) | |
tree | 232bc8a50c3e23440a0b93124ef243fea92df309 | |
parent | 8a2bd215a26baf73f06ad64f0ac276f8172cd3d8 (diff) | |
download | u-boot-imx-8148b824492e7696a9e72bb5b715720db8fd889e.zip u-boot-imx-8148b824492e7696a9e72bb5b715720db8fd889e.tar.gz u-boot-imx-8148b824492e7696a9e72bb5b715720db8fd889e.tar.bz2 |
Fix mxc_hab documenation
It is necessary to modify the configuration file for the target
board. It wasn't well documented that to enable any of the secure
boot modes, it is required to add CONFIG_SECURE_BOOT to the board
configuration file.
Also, fixed a typo in the encrypted boot section.
Signed-off-by: Ulises Cardenas <Ulises.Cardenas@freescale.com>
-rw-r--r-- | doc/README.mxc_hab | 12 |
1 files changed, 9 insertions, 3 deletions
diff --git a/doc/README.mxc_hab b/doc/README.mxc_hab index a1b1d34..b688580 100644 --- a/doc/README.mxc_hab +++ b/doc/README.mxc_hab @@ -1,7 +1,13 @@ High Assurance Boot (HAB) for i.MX6 CPUs -To authenticate U-Boot only by the CPU there is no code required in -U-Boot itself. However, the U-Boot image to be programmed into the +To enable the authenticated or encrypted boot mode of U-Boot, it is +required to set the proper configuration for the target board. This +is done by adding the following configuration in in the proper config +file (e.g. include/configs/mx6qarm2.h) + +#define CONFIG_SECURE_BOOT + +In addition, the U-Boot image to be programmed into the boot media needs to be properly constructed, i.e. it must contain a proper Command Sequence File (CSF). @@ -69,7 +75,7 @@ CONFIG_SECURE_BOOT CONFIG_SYS_FSL_SEC_COMPAT 4 /* HAB version */ CONFIG_FSL_CAAM CONFIG_CMD_DEKBLOB -CONFIG_SYS_FSL_LE +CONFIG_SYS_FSL_SEC_LE Note: The encrypted boot feature is only supported by HABv4 or greater. |