From 9778490a30b274544662a9916e0a9fd04d0acdfb Mon Sep 17 00:00:00 2001 From: Arturo Buzarra Date: Fri, 2 Feb 2024 13:40:35 +0100 Subject: [PATCH] u-boot-dey: ccmp1: disable CMD_BOOTZ when secure boot with FIT image is enabled Command 'bootz' allows boot unsigned Linux zImages, so disable it when secure boot is enabled using FIT images. https://onedigi.atlassian.net/browse/DEL-8769 Signed-off-by: Arturo Buzarra --- .../recipes-bsp/u-boot/u-boot-dey/ccmp1/fit_signature.cfg | 1 + 1 file changed, 1 insertion(+) diff --git a/meta-digi-arm/recipes-bsp/u-boot/u-boot-dey/ccmp1/fit_signature.cfg b/meta-digi-arm/recipes-bsp/u-boot/u-boot-dey/ccmp1/fit_signature.cfg index eb5d7d683..362903338 100644 --- a/meta-digi-arm/recipes-bsp/u-boot/u-boot-dey/ccmp1/fit_signature.cfg +++ b/meta-digi-arm/recipes-bsp/u-boot/u-boot-dey/ccmp1/fit_signature.cfg @@ -2,3 +2,4 @@ CONFIG_FIT_SIGNATURE=y CONFIG_RSA=y CONFIG_ECDSA=y CONFIG_ECDSA_VERIFY=y +# CONFIG_CMD_BOOTZ is not set