AnsweredAssumed Answered

MX6SL and HAB u-boot

Question asked by James Anderson on May 6, 2019
Latest reply on Jun 3, 2019 by James Anderson

Problem booting an IMX6SL board in HAB closed mode.

 

I can succesfully boot via the mfg tool using a signed image.

 

But the installed u-boot signed image just hangs.

 

last attempt at a CSF file looks like:--

 

[Header]
Version = 4.1
Hash Algorithm = sha256
Engine = DCP
Engine Configuration = 0
Certificate Format = X509
Signature Format = CMS

[Install SRK]
File = "../../cst-2.3.3/crts/SRK_1_2_3_4_table.bin"
Source index = 0 # Index of the key location in the SRK table to be installed

[Install CSFK]
# Key used to authenticate the CSF data
File = "../../cst-2.3.3/crts/CSF1_1_sha256_2048_65537_v3_usr_crt.pem"

[Authenticate CSF]

[Install Key]
# Key slot index used to authenticate the key to be installed
Verification index = 0
# Target key slot in HAB key store where key will be installed
Target index = 2
# Key to install
File = "../../cst-2.3.3/crts/IMG1_1_sha256_2048_65537_v3_usr_crt.pem"

[Authenticate Data]
# Key slot index used to authenticate the image data
Verification index = 2
# Address Offset Length Data File Path
Blocks = 0x877ff400 0x00000000 0x00051c00 "boot.bin"

 

The defconfig has the following HAB entries:

CONFIG_ARM=y
CONFIG_ARCH_MX6=y
CONFIG_SYS_TEXT_BASE=0x87800000
CONFIG_TARGET_NAD_MX6SL=y
CONFIG_SYS_CONSOLE_OVERWRITE_ROUTINE=y
CONFIG_BOOTDELAY=0
CONFIG_SECURE_BOOT=y
CONFIG_SYS_FSL_HAS_SEC=y
CONFIG_SYS_FSL_SEC_COMPAT=4

 

and is pretty much identical to the mfg config apart from the MFG=Y

 

I have tried with Engine = Any and Engine = SW but to no avail.

The u-boot works on an Open config machine, and I did not see any hab_status errors before the board was closed.

A similar setup fir a mx6ul board is working without problems.   

Outcomes