From 0a2bee68aed1228d81e5134966578de3c1ca63ae Mon Sep 17 00:00:00 2001 From: Mike Engel Date: Thu, 17 Dec 2020 16:45:59 +0100 Subject: [PATCH] imx-boot: add u-boot image encryption. This commit adds u-boot image encryption. Signed-off-by: Mike Engel --- meta-digi-arm/recipes-bsp/imx-mkimage/imx-boot_1.0.bbappend | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/meta-digi-arm/recipes-bsp/imx-mkimage/imx-boot_1.0.bbappend b/meta-digi-arm/recipes-bsp/imx-mkimage/imx-boot_1.0.bbappend index dab1947bd..92ac322b1 100644 --- a/meta-digi-arm/recipes-bsp/imx-mkimage/imx-boot_1.0.bbappend +++ b/meta-digi-arm/recipes-bsp/imx-mkimage/imx-boot_1.0.bbappend @@ -220,6 +220,12 @@ do_deploy_append () { # Link to current "target" mkimage log ln -sf mkimage-${target}.log mkimage.log trustfence-sign-uboot.sh ${DEPLOYDIR}/${UBOOT_PREFIX}-${MACHINE}.bin-${target} ${DEPLOYDIR}/${UBOOT_PREFIX}-signed-${MACHINE}.bin-${target} + + if [ "${TRUSTFENCE_DEK_PATH}" != "0" ]; then + export ENABLE_ENCRYPTION=y + trustfence-sign-uboot.sh ${DEPLOYDIR}/${UBOOT_PREFIX}-${MACHINE}.bin-${target} ${DEPLOYDIR}/${UBOOT_PREFIX}-encrypted-${MACHINE}.bin-${target} + unset ENABLE_ENCRYPTION + fi done else for ramc in ${UBOOT_RAM_COMBINATIONS}; do