{"id":2224479,"url":"http://patchwork.ozlabs.org/api/patches/2224479/?format=json","web_url":"http://patchwork.ozlabs.org/project/uboot/patch/20260417130204.49896-9-philippe.reynes@softathome.com/","project":{"id":18,"url":"http://patchwork.ozlabs.org/api/projects/18/?format=json","name":"U-Boot","link_name":"uboot","list_id":"u-boot.lists.denx.de","list_email":"u-boot@lists.denx.de","web_url":null,"scm_url":null,"webscm_url":null,"list_archive_url":"","list_archive_url_format":"","commit_url_format":""},"msgid":"<20260417130204.49896-9-philippe.reynes@softathome.com>","list_archive_url":null,"date":"2026-04-17T13:01:58","name":"[v4,08/14] test: vboot: add test for ecdsa","commit_ref":null,"pull_url":null,"state":"superseded","archived":false,"hash":"5454ff298b038b0cb0684f2a72e248b1e822c61c","submitter":{"id":74351,"url":"http://patchwork.ozlabs.org/api/people/74351/?format=json","name":"Philippe Reynes","email":"philippe.reynes@softathome.com"},"delegate":{"id":161313,"url":"http://patchwork.ozlabs.org/api/users/161313/?format=json","username":"raymo200915","first_name":"Raymond","last_name":"Mao","email":"raymondmaoca@gmail.com"},"mbox":"http://patchwork.ozlabs.org/project/uboot/patch/20260417130204.49896-9-philippe.reynes@softathome.com/mbox/","series":[{"id":500332,"url":"http://patchwork.ozlabs.org/api/series/500332/?format=json","web_url":"http://patchwork.ozlabs.org/project/uboot/list/?series=500332","date":"2026-04-17T13:02:04","name":"add software ecdsa support","version":4,"mbox":"http://patchwork.ozlabs.org/series/500332/mbox/"}],"comments":"http://patchwork.ozlabs.org/api/patches/2224479/comments/","check":"pending","checks":"http://patchwork.ozlabs.org/api/patches/2224479/checks/","tags":{},"related":[],"headers":{"Return-Path":"<u-boot-bounces@lists.denx.de>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@legolas.ozlabs.org","Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=softathome1.onmicrosoft.com header.i=@softathome1.onmicrosoft.com\n header.a=rsa-sha256 header.s=selector1-softathome1-onmicrosoft-com\n header.b=FAAE22Yx;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=lists.denx.de\n (client-ip=2a01:238:438b:c500:173d:9f52:ddab:ee01; helo=phobos.denx.de;\n envelope-from=u-boot-bounces@lists.denx.de; receiver=patchwork.ozlabs.org)","phobos.denx.de;\n dmarc=none (p=none dis=none) header.from=softathome.com","phobos.denx.de;\n spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de","phobos.denx.de;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=softathome1.onmicrosoft.com header.i=@softathome1.onmicrosoft.com\n header.b=\"FAAE22Yx\";\n\tdkim-atps=neutral","phobos.denx.de; dmarc=none (p=none dis=none)\n header.from=softathome.com","phobos.denx.de;\n spf=pass smtp.mailfrom=philippe.reynes@softathome.com"],"Received":["from phobos.denx.de (phobos.denx.de\n [IPv6:2a01:238:438b:c500:173d:9f52:ddab:ee01])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4fxw6C1Wmvz1yCv\n\tfor <incoming@patchwork.ozlabs.org>; Fri, 17 Apr 2026 23:02:59 +1000 (AEST)","from h2850616.stratoserver.net (localhost [IPv6:::1])\n\tby phobos.denx.de (Postfix) with ESMTP id 9742484337;\n\tFri, 17 Apr 2026 15:02:18 +0200 (CEST)","by phobos.denx.de (Postfix, from userid 109)\n id 4523284297; Fri, 17 Apr 2026 15:02:17 +0200 (CEST)","from PAUP264CU001.outbound.protection.outlook.com\n (mail-francecentralazlp170110002.outbound.protection.outlook.com\n [IPv6:2a01:111:f403:c20a::2])\n (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits))\n (No client certificate requested)\n by phobos.denx.de (Postfix) with ESMTPS id B5D11842B7\n for <u-boot@lists.denx.de>; Fri, 17 Apr 2026 15:02:13 +0200 (CEST)","from MR1P264CA0093.FRAP264.PROD.OUTLOOK.COM (2603:10a6:501:3f::21)\n by MR1P264MB3233.FRAP264.PROD.OUTLOOK.COM (2603:10a6:501:3a::17) with\n Microsoft SMTP Server (version=TLS1_2,\n cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9818.25; Fri, 17 Apr\n 2026 13:02:10 +0000","from MR1PEPF00000D5A.FRAP264.PROD.OUTLOOK.COM\n (2603:10a6:501:3f:cafe::c) by MR1P264CA0093.outlook.office365.com\n (2603:10a6:501:3f::21) with Microsoft SMTP Server (version=TLS1_3,\n cipher=TLS_AES_256_GCM_SHA384) id 15.20.9769.52 via Frontend Transport; Fri,\n 17 Apr 2026 13:02:10 +0000","from proxy.softathome.com (149.6.166.170) by\n MR1PEPF00000D5A.mail.protection.outlook.com (10.167.241.7) with Microsoft\n SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.20.9769.17\n via Frontend Transport; Fri, 17 Apr 2026 13:02:10 +0000","from sah1lpt726.home (unknown [192.168.72.39])\n by proxy.softathome.com (Postfix) with ESMTPSA id 37E0520EDA;\n Fri, 17 Apr 2026 15:02:10 +0200 (CEST)"],"X-Spam-Checker-Version":"SpamAssassin 3.4.2 (2018-09-13) on phobos.denx.de","X-Spam-Level":"","X-Spam-Status":"No, score=-1.9 required=5.0 tests=BAYES_00,DKIM_SIGNED,\n DKIM_VALID,RCVD_IN_DNSWL_BLOCKED,SPF_HELO_PASS,SPF_PASS autolearn=ham\n autolearn_force=no version=3.4.2","ARC-Seal":"i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none;\n b=j/z1vCumQxGQfX7Sx0DDQkBHrXCaVncnhVXG3jvGrR/l9xWt2POgJaLiOOxXI5jRxITN1bzwhngg/FykfpkCc11TYHpPDQIyU+cwTHY8q0gSTurzAKSL1hcCXp85VgwaJ2Zpe3ZF13lFYV6zcWSa8K0FxgnhH0qRKGUn3RJEoIF8GtwIoWW/kMqBckNZYY2Ir6mMyzFXYmmhLKup7buWNoKH9yUM/UZNMTc1JXtSx+l6Inq/9j9RJiKLCN0sdnje++8Og2MTyqhrT1Z9zypJp0DYnYNFEb4U9sV8GvhvGdRqDjcImCvwIh7xTNovBAmdC7sIEyvxP4WKnBSQVZaylQ==","ARC-Message-Signature":"i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;\n s=arcselector10001;\n h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;\n bh=qSBmwgjRiqto6KMz7xblDuWCUq142qI+PcXefjSh4i4=;\n b=jPZCGEisDvMzq8E6OTUPnWbwzc/6rKKCZtR8SxMBjVNnft1Xurr9pBPJVhg8XwfGlS8rKdKA2lW4I0+YxA5YmXjkEvKusmk4gX4OankM6gXr4i5XZEyB+3TIn/AYbs8DVfmGSkEGUOXDkja/Ov2KryFsMtexsZylH6J8mCt/vA/Vzf9QMTNoD88Z/e8nMB5lJoKVjq3Db3acuOfTtSrEsHc0Wm/F97bN/Uc7u9xOvpIi7ps6N2PrijxLmlqFCBVnKMRtyA3d2sL0wNcEW9RhCPQ2XfGN4kPDyQ50MLKya/G19iWUKGJueU1BKMRFu9dsli/Z2jOhU2lrJYi9pQuxZA==","ARC-Authentication-Results":"i=1; mx.microsoft.com 1; spf=pass (sender ip is\n 149.6.166.170) smtp.rcpttodomain=canonical.com smtp.mailfrom=softathome.com;\n dmarc=bestguesspass action=none header.from=softathome.com; dkim=none\n (message not signed); arc=none (0)","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=softathome1.onmicrosoft.com; s=selector1-softathome1-onmicrosoft-com;\n h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;\n bh=qSBmwgjRiqto6KMz7xblDuWCUq142qI+PcXefjSh4i4=;\n b=FAAE22YxwtLQe4MhCccwMb7bjcXiOheP3q3e3pShsNRYqu9RK/A00HbxINDVO2KRUU90k/Tgwi4xUSLmryIJjEYWixNjio0r0FQHYjb/7WBa54XFmcXGiiomY2nrI6DkICP5YubWaT4pjj8hC1iazd0aAG/qkPAPh78nKXFmXlyLF2uKLp9M+WcQ0e+F+wg0aTsScu56PBgIGex5g70avjjnFuTDesEAweYe7lvnscgtcSsypAZFMIX3YRIrSho+xv0BFNXlyq7bgLIIzCft01oHGWSoNMrwE7GChFRyuXkESu0YT5MY9keJfcfpdnHCvRqvGdn/yQFp/8XKgzhvuw==","X-MS-Exchange-Authentication-Results":"spf=pass (sender IP is 149.6.166.170)\n smtp.mailfrom=softathome.com; dkim=none (message not signed)\n header.d=none;dmarc=bestguesspass action=none header.from=softathome.com;","Received-SPF":"Pass (protection.outlook.com: domain of softathome.com\n designates 149.6.166.170 as permitted sender)\n receiver=protection.outlook.com; client-ip=149.6.166.170;\n helo=proxy.softathome.com; pr=C","From":"Philippe Reynes <philippe.reynes@softathome.com>","To":"marko.makela@iki.fi, jonny.green@keytechinc.com, raymondmaoca@gmail.com,\n trini@konsulko.com, simon.glass@canonical.com","Cc":"u-boot@lists.denx.de, Philippe Reynes <philippe.reynes@softathome.com>,\n Simon Glass <sjg@chromium.org>","Subject":"[PATCH v4 08/14] test: vboot: add test for ecdsa","Date":"Fri, 17 Apr 2026 15:01:58 +0200","Message-ID":"<20260417130204.49896-9-philippe.reynes@softathome.com>","X-Mailer":"git-send-email 2.43.0","In-Reply-To":"<20260417130204.49896-1-philippe.reynes@softathome.com>","References":"<20260417130204.49896-1-philippe.reynes@softathome.com>","MIME-Version":"1.0","Content-Transfer-Encoding":"8bit","X-EOPAttributedMessage":"0","X-MS-PublicTrafficType":"Email","X-MS-TrafficTypeDiagnostic":"MR1PEPF00000D5A:EE_|MR1P264MB3233:EE_","Content-Type":"text/plain","X-MS-Office365-Filtering-Correlation-Id":"4c28117b-ee08-4cda-5352-08de9c818990","X-MS-Exchange-SenderADCheck":"1","X-MS-Exchange-AntiSpam-Relay":"0","X-Microsoft-Antispam":"BCL:0;\n ARA:13230040|82310400026|376014|36860700016|1800799024|56012099003|18002099003|22082099003;","X-Microsoft-Antispam-Message-Info":"\n fGqY5BW5a5ZarbJpuZ7B5UreDj0B+kw4DOtJ+t9ziF8sMHT2LLM1RDHQ8UfD0evzQ93XZylV5uGFelpwrla7tjrW6Dh72wKXjb0aZqB9cRCDZzyCf8mOjCNvgrzY51jtJYlHlP7oIlVp08r4XX9shYxnSjNPi0lTI5Uw3+vuHeR0jU3Rhe4Z8Lb7a/xLHCl0Q7Z24iyAJSxGeSs8vFer5lssMlJvSRWD0wP7P4zqhXqoCLuQO12uKT1VCNa52Byr0aj3FsKCUnzx2472jRydKVpP3n9gPA47UUUT+Szi22F3YTngpSGS/bt1yome4cJVDj+Jbo7RfwAyDBHqW+nVioVJnWmXXkN8yGt8NWiQp9jpT0y1iyJOEaRpu/nkoujN1gv6gjbKpd+o5JfCL+qQ2VXKIWjLsbjPSNBt0NrWzf+sGJS3B13TiBxDVP9qlnkEMGfOmoW4DbjP3Di4h8fkwM+p9kik7efZ2+hdxRIoQpcJX0J2Al8gouidpqQDwvowSC0Gdx+qDdV7JSOFgsZlKRRE7c7jhMlMwr9kSPMHZ8vFrfNWEuHQdDRWefBUj/cMiY8D5KorIj579JRTsgVtTZ5UJy/rhjOkmkE6zWuOtHh+UShSceon1un6bklc6it7vz4fRKzMQsRcfboOxdg5X/+Zj6p8y16DKwv+8CPC2Sq8ftb5cdiezdv0JpZcuPnBw9wvbHi/JuyVQ7ivhH5zmZIw7f33tQ9ff9mixuhNK6hVUpPsyuqOFQibRIC6yTUJ5/nmofe6gczH+/X2YGy5Vg==","X-Forefront-Antispam-Report":"CIP:149.6.166.170; CTRY:FR; LANG:en; SCL:1; SRV:;\n IPV:CAL; SFV:NSPM; H:proxy.softathome.com; PTR:InfoDomainNonexistent;\n CAT:NONE;\n SFS:(13230040)(82310400026)(376014)(36860700016)(1800799024)(56012099003)(18002099003)(22082099003);\n DIR:OUT; SFP:1101;","X-MS-Exchange-AntiSpam-MessageData-ChunkCount":"1","X-MS-Exchange-AntiSpam-MessageData-0":"\n FFyTDZ4XWdzhJnxazxDCw8r9StE8lyIKrRYxjesOeMCmD33IEphwEcbYXxLgsXdvKNRwCx+rtUC84zPeYAerAdZQmHC4C/AlW9Cyv/+HVHw41AlNnteqax+yt/yGvGsdZ/clGBKOuArMexgTxEQzemfj/wVTE4flC52iuU2cUkZQ1s6YR0Uiuza3sTOSQoIXIK95ChTK16765tbyLk5FaPybt3KbbmOsxjPeZpcJW+TnAER+sq2DlqcxyHrJiS4ZL8/vIHsxNJYtwwgDq7Xr8hf5IIV3hbQIBGdsZa2WDXoUyf+DQXGLSgJ2M2pe4N+DT/4KBcHk4MLBHdtt9FDDhfuRIw1yKS3M0zylEZRAxECz4cOcxW7PpU6vzKY3f9hgSY1+laRN4oEH0SvA6s7wVeuchEywDallNTgaqyOpZQccvDKuNFfvTsV+1qPcI45t","X-OriginatorOrg":"softathome.com","X-MS-Exchange-CrossTenant-OriginalArrivalTime":"17 Apr 2026 13:02:10.5115 (UTC)","X-MS-Exchange-CrossTenant-Network-Message-Id":"\n 4c28117b-ee08-4cda-5352-08de9c818990","X-MS-Exchange-CrossTenant-Id":"aa10e044-e405-4c10-8353-36b4d0cce511","X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp":"\n TenantId=aa10e044-e405-4c10-8353-36b4d0cce511; Ip=[149.6.166.170];\n Helo=[proxy.softathome.com]","X-MS-Exchange-CrossTenant-AuthSource":"MR1PEPF00000D5A.FRAP264.PROD.OUTLOOK.COM","X-MS-Exchange-CrossTenant-AuthAs":"Anonymous","X-MS-Exchange-CrossTenant-FromEntityHeader":"HybridOnPrem","X-MS-Exchange-Transport-CrossTenantHeadersStamped":"MR1P264MB3233","X-BeenThere":"u-boot@lists.denx.de","X-Mailman-Version":"2.1.39","Precedence":"list","List-Id":"U-Boot discussion <u-boot.lists.denx.de>","List-Unsubscribe":"<https://lists.denx.de/options/u-boot>,\n <mailto:u-boot-request@lists.denx.de?subject=unsubscribe>","List-Archive":"<https://lists.denx.de/pipermail/u-boot/>","List-Post":"<mailto:u-boot@lists.denx.de>","List-Help":"<mailto:u-boot-request@lists.denx.de?subject=help>","List-Subscribe":"<https://lists.denx.de/listinfo/u-boot>,\n <mailto:u-boot-request@lists.denx.de?subject=subscribe>","Errors-To":"u-boot-bounces@lists.denx.de","Sender":"\"U-Boot\" <u-boot-bounces@lists.denx.de>","X-Virus-Scanned":"clamav-milter 0.103.8 at phobos.denx.de","X-Virus-Status":"Clean"},"content":"This commit adds test case for ecdsa on fit, but not (yet) for\nthe global image signature (preload).\n\nReviewed-by: Simon Glass <simon.glass@canonical.com>\nReviewed-by: Simon Glass <sjg@chromium.org>\nSigned-off-by: Philippe Reynes <philippe.reynes@softathome.com>\n---\nv2:\n- initial version\nv3:\n- no change\nv4:\n- no change\n\n test/py/tests/test_vboot.py                   | 29 ++++++++++++\n .../vboot/sign-configs-sha256-ecdsa256.its    | 45 +++++++++++++++++++\n .../vboot/sign-configs-sha256-ecdsa384.its    | 45 +++++++++++++++++++\n .../vboot/sign-configs-sha256-ecdsa521.its    | 45 +++++++++++++++++++\n .../vboot/sign-images-sha256-ecdsa256.its     | 42 +++++++++++++++++\n .../vboot/sign-images-sha256-ecdsa384.its     | 42 +++++++++++++++++\n .../vboot/sign-images-sha256-ecdsa521.its     | 42 +++++++++++++++++\n 7 files changed, 290 insertions(+)\n create mode 100644 test/py/tests/vboot/sign-configs-sha256-ecdsa256.its\n create mode 100644 test/py/tests/vboot/sign-configs-sha256-ecdsa384.its\n create mode 100644 test/py/tests/vboot/sign-configs-sha256-ecdsa521.its\n create mode 100644 test/py/tests/vboot/sign-images-sha256-ecdsa256.its\n create mode 100644 test/py/tests/vboot/sign-images-sha256-ecdsa384.its\n create mode 100644 test/py/tests/vboot/sign-images-sha256-ecdsa521.its","diff":"diff --git a/test/py/tests/test_vboot.py b/test/py/tests/test_vboot.py\nindex 496d314c649..4e4d9529031 100644\n--- a/test/py/tests/test_vboot.py\n+++ b/test/py/tests/test_vboot.py\n@@ -94,6 +94,9 @@ TESTDATA_IN = [\n     ['sha256-pss-pad', 'sha256', '-rsa2048', '-pss', '-E -p 0x10000', False, False, False, False],\n     ['sha256-pss-required', 'sha256', '-rsa2048', '-pss', None, True, False, False, False],\n     ['sha256-pss-pad-required', 'sha256', '-rsa2048', '-pss', '-E -p 0x10000', True, True, False, False],\n+    ['sha256-basic-ecdsa256', 'sha256', '-ecdsa256', '', None, False, False, False, False],\n+    ['sha256-basic-ecdsa384', 'sha256', '-ecdsa384', '', None, False, False, False, False],\n+    ['sha256-basic-ecdsa521', 'sha256', '-ecdsa521', '', None, False, False, False, False],\n     ['sha384-basic', 'sha384', '-rsa3072', '', None, False, False, False, False],\n     ['sha384-pad', 'sha384', '-rsa3072', '', '-E -p 0x10000', False, False, False, False],\n     ['algo-arg', 'algo-arg', '', '', '-o sha256,rsa2048', False, False, True, False],\n@@ -287,6 +290,29 @@ def test_vboot(ubman, name, sha_algo, sig_algo, padding, sign_options, required,\n         utils.run_and_log(ubman, 'openssl req -batch -new -x509 -key %s%s.key '\n                           '-out %s%s.crt' % (tmpdir, name, tmpdir, name))\n \n+    def create_ecdsa_pair(name):\n+        \"\"\"Generate a new ECDSA key pair\n+\n+        Args:\n+            name: Name of the key (e.g. 'dev')\n+        \"\"\"\n+\n+        if sig_algo == \"-ecdsa256\":\n+            curve_name = \"secp256r1\"\n+        elif sig_algo == \"-ecdsa384\":\n+            curve_name = \"secp384r1\"\n+        elif sig_algo == \"-ecdsa521\":\n+            curve_name = \"secp521r1\"\n+        else:\n+            curve_name = \"unknownCurve\"\n+\n+        utils.run_and_log(ubman, 'openssl ecparam -name %s -genkey -noout -out %s%s.pem' %\n+                     (curve_name, tmpdir, name))\n+\n+        # Create a certificate containing the public key\n+        utils.run_and_log(ubman, 'openssl req -batch -new -x509 -key %s%s.pem '\n+                          '-out %s%s.crt' % (tmpdir, name, tmpdir, name))\n+\n     def test_with_algo(sha_algo, sig_algo, padding, sign_options):\n         \"\"\"Test verified boot with the given hash algorithm.\n \n@@ -537,6 +563,9 @@ def test_vboot(ubman, name, sha_algo, sig_algo, padding, sign_options, required,\n     if sig_algo == \"-rsa2048\" or sig_algo == \"-rsa3072\" or sig_algo == \"\":\n         create_rsa_pair('dev')\n         create_rsa_pair('prod')\n+    elif sig_algo == \"-ecdsa256\" or sig_algo == \"-ecdsa384\" or sig_algo == \"-ecdsa521\":\n+        create_ecdsa_pair('dev')\n+        create_ecdsa_pair('prod')\n \n     # Create a number kernel image with zeroes\n     with open('%stest-kernel.bin' % tmpdir, 'wb') as fd:\ndiff --git a/test/py/tests/vboot/sign-configs-sha256-ecdsa256.its b/test/py/tests/vboot/sign-configs-sha256-ecdsa256.its\nnew file mode 100644\nindex 00000000000..4d0ef903a78\n--- /dev/null\n+++ b/test/py/tests/vboot/sign-configs-sha256-ecdsa256.its\n@@ -0,0 +1,45 @@\n+/dts-v1/;\n+\n+/ {\n+\tdescription = \"Chrome OS kernel image with one or more FDT blobs\";\n+\t#address-cells = <1>;\n+\n+\timages {\n+\t\tkernel {\n+\t\t\tdata = /incbin/(\"test-kernel.bin\");\n+\t\t\ttype = \"kernel_noload\";\n+\t\t\tarch = \"sandbox\";\n+\t\t\tos = \"linux\";\n+\t\t\tcompression = \"none\";\n+\t\t\tload = <0x4>;\n+\t\t\tentry = <0x8>;\n+\t\t\tkernel-version = <1>;\n+\t\t\thash-1 {\n+\t\t\t\talgo = \"sha256\";\n+\t\t\t};\n+\t\t};\n+\t\tfdt-1 {\n+\t\t\tdescription = \"snow\";\n+\t\t\tdata = /incbin/(\"sandbox-kernel.dtb\");\n+\t\t\ttype = \"flat_dt\";\n+\t\t\tarch = \"sandbox\";\n+\t\t\tcompression = \"none\";\n+\t\t\tfdt-version = <1>;\n+\t\t\thash-1 {\n+\t\t\t\talgo = \"sha256\";\n+\t\t\t};\n+\t\t};\n+\t};\n+\tconfigurations {\n+\t\tdefault = \"conf-1\";\n+\t\tconf-1 {\n+\t\t\tkernel = \"kernel\";\n+\t\t\tfdt = \"fdt-1\";\n+\t\t\tsignature {\n+\t\t\t\talgo = \"sha256,ecdsa256\";\n+\t\t\t\tkey-name-hint = \"dev\";\n+\t\t\t\tsign-images = \"fdt\", \"kernel\";\n+\t\t\t};\n+\t\t};\n+\t};\n+};\ndiff --git a/test/py/tests/vboot/sign-configs-sha256-ecdsa384.its b/test/py/tests/vboot/sign-configs-sha256-ecdsa384.its\nnew file mode 100644\nindex 00000000000..10427b43659\n--- /dev/null\n+++ b/test/py/tests/vboot/sign-configs-sha256-ecdsa384.its\n@@ -0,0 +1,45 @@\n+/dts-v1/;\n+\n+/ {\n+\tdescription = \"Chrome OS kernel image with one or more FDT blobs\";\n+\t#address-cells = <1>;\n+\n+\timages {\n+\t\tkernel {\n+\t\t\tdata = /incbin/(\"test-kernel.bin\");\n+\t\t\ttype = \"kernel_noload\";\n+\t\t\tarch = \"sandbox\";\n+\t\t\tos = \"linux\";\n+\t\t\tcompression = \"none\";\n+\t\t\tload = <0x4>;\n+\t\t\tentry = <0x8>;\n+\t\t\tkernel-version = <1>;\n+\t\t\thash-1 {\n+\t\t\t\talgo = \"sha256\";\n+\t\t\t};\n+\t\t};\n+\t\tfdt-1 {\n+\t\t\tdescription = \"snow\";\n+\t\t\tdata = /incbin/(\"sandbox-kernel.dtb\");\n+\t\t\ttype = \"flat_dt\";\n+\t\t\tarch = \"sandbox\";\n+\t\t\tcompression = \"none\";\n+\t\t\tfdt-version = <1>;\n+\t\t\thash-1 {\n+\t\t\t\talgo = \"sha256\";\n+\t\t\t};\n+\t\t};\n+\t};\n+\tconfigurations {\n+\t\tdefault = \"conf-1\";\n+\t\tconf-1 {\n+\t\t\tkernel = \"kernel\";\n+\t\t\tfdt = \"fdt-1\";\n+\t\t\tsignature {\n+\t\t\t\talgo = \"sha256,ecdsa384\";\n+\t\t\t\tkey-name-hint = \"dev\";\n+\t\t\t\tsign-images = \"fdt\", \"kernel\";\n+\t\t\t};\n+\t\t};\n+\t};\n+};\ndiff --git a/test/py/tests/vboot/sign-configs-sha256-ecdsa521.its b/test/py/tests/vboot/sign-configs-sha256-ecdsa521.its\nnew file mode 100644\nindex 00000000000..a65593ec64b\n--- /dev/null\n+++ b/test/py/tests/vboot/sign-configs-sha256-ecdsa521.its\n@@ -0,0 +1,45 @@\n+/dts-v1/;\n+\n+/ {\n+\tdescription = \"Chrome OS kernel image with one or more FDT blobs\";\n+\t#address-cells = <1>;\n+\n+\timages {\n+\t\tkernel {\n+\t\t\tdata = /incbin/(\"test-kernel.bin\");\n+\t\t\ttype = \"kernel_noload\";\n+\t\t\tarch = \"sandbox\";\n+\t\t\tos = \"linux\";\n+\t\t\tcompression = \"none\";\n+\t\t\tload = <0x4>;\n+\t\t\tentry = <0x8>;\n+\t\t\tkernel-version = <1>;\n+\t\t\thash-1 {\n+\t\t\t\talgo = \"sha256\";\n+\t\t\t};\n+\t\t};\n+\t\tfdt-1 {\n+\t\t\tdescription = \"snow\";\n+\t\t\tdata = /incbin/(\"sandbox-kernel.dtb\");\n+\t\t\ttype = \"flat_dt\";\n+\t\t\tarch = \"sandbox\";\n+\t\t\tcompression = \"none\";\n+\t\t\tfdt-version = <1>;\n+\t\t\thash-1 {\n+\t\t\t\talgo = \"sha256\";\n+\t\t\t};\n+\t\t};\n+\t};\n+\tconfigurations {\n+\t\tdefault = \"conf-1\";\n+\t\tconf-1 {\n+\t\t\tkernel = \"kernel\";\n+\t\t\tfdt = \"fdt-1\";\n+\t\t\tsignature {\n+\t\t\t\talgo = \"sha256,ecdsa521\";\n+\t\t\t\tkey-name-hint = \"dev\";\n+\t\t\t\tsign-images = \"fdt\", \"kernel\";\n+\t\t\t};\n+\t\t};\n+\t};\n+};\ndiff --git a/test/py/tests/vboot/sign-images-sha256-ecdsa256.its b/test/py/tests/vboot/sign-images-sha256-ecdsa256.its\nnew file mode 100644\nindex 00000000000..009003bb601\n--- /dev/null\n+++ b/test/py/tests/vboot/sign-images-sha256-ecdsa256.its\n@@ -0,0 +1,42 @@\n+/dts-v1/;\n+\n+/ {\n+\tdescription = \"Chrome OS kernel image with one or more FDT blobs\";\n+\t#address-cells = <1>;\n+\n+\timages {\n+\t\tkernel {\n+\t\t\tdata = /incbin/(\"test-kernel.bin\");\n+\t\t\ttype = \"kernel_noload\";\n+\t\t\tarch = \"sandbox\";\n+\t\t\tos = \"linux\";\n+\t\t\tcompression = \"none\";\n+\t\t\tload = <0x4>;\n+\t\t\tentry = <0x8>;\n+\t\t\tkernel-version = <1>;\n+\t\t\tsignature {\n+\t\t\t\talgo = \"sha256,ecdsa256\";\n+\t\t\t\tkey-name-hint = \"dev\";\n+\t\t\t};\n+\t\t};\n+\t\tfdt-1 {\n+\t\t\tdescription = \"snow\";\n+\t\t\tdata = /incbin/(\"sandbox-kernel.dtb\");\n+\t\t\ttype = \"flat_dt\";\n+\t\t\tarch = \"sandbox\";\n+\t\t\tcompression = \"none\";\n+\t\t\tfdt-version = <1>;\n+\t\t\tsignature {\n+\t\t\t\talgo = \"sha256,ecdsa256\";\n+\t\t\t\tkey-name-hint = \"dev\";\n+\t\t\t};\n+\t\t};\n+\t};\n+\tconfigurations {\n+\t\tdefault = \"conf-1\";\n+\t\tconf-1 {\n+\t\t\tkernel = \"kernel\";\n+\t\t\tfdt = \"fdt-1\";\n+\t\t};\n+\t};\n+};\ndiff --git a/test/py/tests/vboot/sign-images-sha256-ecdsa384.its b/test/py/tests/vboot/sign-images-sha256-ecdsa384.its\nnew file mode 100644\nindex 00000000000..567de687a06\n--- /dev/null\n+++ b/test/py/tests/vboot/sign-images-sha256-ecdsa384.its\n@@ -0,0 +1,42 @@\n+/dts-v1/;\n+\n+/ {\n+\tdescription = \"Chrome OS kernel image with one or more FDT blobs\";\n+\t#address-cells = <1>;\n+\n+\timages {\n+\t\tkernel {\n+\t\t\tdata = /incbin/(\"test-kernel.bin\");\n+\t\t\ttype = \"kernel_noload\";\n+\t\t\tarch = \"sandbox\";\n+\t\t\tos = \"linux\";\n+\t\t\tcompression = \"none\";\n+\t\t\tload = <0x4>;\n+\t\t\tentry = <0x8>;\n+\t\t\tkernel-version = <1>;\n+\t\t\tsignature {\n+\t\t\t\talgo = \"sha256,ecdsa384\";\n+\t\t\t\tkey-name-hint = \"dev\";\n+\t\t\t};\n+\t\t};\n+\t\tfdt-1 {\n+\t\t\tdescription = \"snow\";\n+\t\t\tdata = /incbin/(\"sandbox-kernel.dtb\");\n+\t\t\ttype = \"flat_dt\";\n+\t\t\tarch = \"sandbox\";\n+\t\t\tcompression = \"none\";\n+\t\t\tfdt-version = <1>;\n+\t\t\tsignature {\n+\t\t\t\talgo = \"sha256,ecdsa384\";\n+\t\t\t\tkey-name-hint = \"dev\";\n+\t\t\t};\n+\t\t};\n+\t};\n+\tconfigurations {\n+\t\tdefault = \"conf-1\";\n+\t\tconf-1 {\n+\t\t\tkernel = \"kernel\";\n+\t\t\tfdt = \"fdt-1\";\n+\t\t};\n+\t};\n+};\ndiff --git a/test/py/tests/vboot/sign-images-sha256-ecdsa521.its b/test/py/tests/vboot/sign-images-sha256-ecdsa521.its\nnew file mode 100644\nindex 00000000000..74ed45b21b8\n--- /dev/null\n+++ b/test/py/tests/vboot/sign-images-sha256-ecdsa521.its\n@@ -0,0 +1,42 @@\n+/dts-v1/;\n+\n+/ {\n+\tdescription = \"Chrome OS kernel image with one or more FDT blobs\";\n+\t#address-cells = <1>;\n+\n+\timages {\n+\t\tkernel {\n+\t\t\tdata = /incbin/(\"test-kernel.bin\");\n+\t\t\ttype = \"kernel_noload\";\n+\t\t\tarch = \"sandbox\";\n+\t\t\tos = \"linux\";\n+\t\t\tcompression = \"none\";\n+\t\t\tload = <0x4>;\n+\t\t\tentry = <0x8>;\n+\t\t\tkernel-version = <1>;\n+\t\t\tsignature {\n+\t\t\t\talgo = \"sha256,ecdsa521\";\n+\t\t\t\tkey-name-hint = \"dev\";\n+\t\t\t};\n+\t\t};\n+\t\tfdt-1 {\n+\t\t\tdescription = \"snow\";\n+\t\t\tdata = /incbin/(\"sandbox-kernel.dtb\");\n+\t\t\ttype = \"flat_dt\";\n+\t\t\tarch = \"sandbox\";\n+\t\t\tcompression = \"none\";\n+\t\t\tfdt-version = <1>;\n+\t\t\tsignature {\n+\t\t\t\talgo = \"sha256,ecdsa521\";\n+\t\t\t\tkey-name-hint = \"dev\";\n+\t\t\t};\n+\t\t};\n+\t};\n+\tconfigurations {\n+\t\tdefault = \"conf-1\";\n+\t\tconf-1 {\n+\t\t\tkernel = \"kernel\";\n+\t\t\tfdt = \"fdt-1\";\n+\t\t};\n+\t};\n+};\n","prefixes":["v4","08/14"]}