diff mbox

[U-Boot] Fix mxc_hab documenation

Message ID 1429555678-27537-1-git-send-email-Ulises.Cardenas@freescale.com
State Awaiting Upstream
Delegated to: Stefano Babic
Headers show

Commit Message

Ulises.Cardenas@freescale.com April 20, 2015, 6:47 p.m. UTC
From: Ulises Cardenas <Ulises.Cardenas@freescale.com>

It is necessary to modify the configuration file for the target
board. It wasn't well documented that to enable any of the secure
boot modes, it is required to add CONFIG_SECURE_BOOT to the board
configuration file.

Also, fixed a typo in the encrypted boot section.

Signed-off-by: Ulises Cardenas <Ulises.Cardenas@freescale.com>
---

 doc/README.mxc_hab | 12 +++++++++---
 1 file changed, 9 insertions(+), 3 deletions(-)

Comments

Stefano Babic May 2, 2015, 9:11 a.m. UTC | #1
On 20/04/2015 20:47, Ulises.Cardenas@freescale.com wrote:
> From: Ulises Cardenas <Ulises.Cardenas@freescale.com>
> 
> It is necessary to modify the configuration file for the target
> board. It wasn't well documented that to enable any of the secure
> boot modes, it is required to add CONFIG_SECURE_BOOT to the board
> configuration file.
> 
> Also, fixed a typo in the encrypted boot section.
> 
> Signed-off-by: Ulises Cardenas <Ulises.Cardenas@freescale.com>
> ---
> 

Applied to u-boot-imx, thanks !

Best regards,
Stefano Babic
diff mbox

Patch

diff --git a/doc/README.mxc_hab b/doc/README.mxc_hab
index a1b1d34..b688580 100644
--- a/doc/README.mxc_hab
+++ b/doc/README.mxc_hab
@@ -1,7 +1,13 @@ 
 High Assurance Boot (HAB) for i.MX6 CPUs
 
-To authenticate U-Boot only by the CPU there is no code required in
-U-Boot itself. However, the U-Boot image to be programmed into the
+To enable the authenticated or encrypted boot mode of U-Boot, it is
+required to set the proper configuration for the target board. This
+is done by adding the following configuration in in the proper config
+file (e.g. include/configs/mx6qarm2.h)
+
+#define CONFIG_SECURE_BOOT
+
+In addition, the U-Boot image to be programmed into the
 boot media needs to be properly constructed, i.e. it must contain a
 proper Command Sequence File (CSF).
 
@@ -69,7 +75,7 @@  CONFIG_SECURE_BOOT
 CONFIG_SYS_FSL_SEC_COMPAT    4 /* HAB version */
 CONFIG_FSL_CAAM
 CONFIG_CMD_DEKBLOB
-CONFIG_SYS_FSL_LE
+CONFIG_SYS_FSL_SEC_LE
 
 Note: The encrypted boot feature is only supported by HABv4 or
 greater.