Forum Discussion
How to test Secure Boot in Arria10 without programming any FUSE
The documents mention "unsecured root key" that doesn't need to be stored in the device and is supposed to be present in the boot header.
But I can't find any procedure to achieve this.
8 Replies
- EBERLAZARE_I_Intel
Regular Contributor
Hi,
Is this the document you are referring to?:
- AbhishekH
New Contributor
Yes
- EBERLAZARE_I_Intel
Regular Contributor
Hi,
Please read the SoC Security Section of the Arria 10 SoC HPS TRM:
https://www.intel.com/content/www/us/en/docs/programmable/683711/21-2/soc-security.html
- EBERLAZARE_I_Intel
Regular Contributor
Hi,
Do you have any follow-up questions?
- EBERLAZARE_I_Intel
Regular Contributor
Hi,
Did you try to reply? I see some changes made from you on this case but no latest reply is visible in the forum.
- AbhishekH
New Contributor
Hi,
Sorry for the delay. But I couldn't find the procedure to place KAK in boot header in that document. I also noticed that It's mentioned we need to get NDA to get complete document. By any chance that document has the procedure I need or are you referring to the publicly available document ? - EBERLAZARE_I_Intel
Regular Contributor
In the AN759. You need python and the secure boot tools (https://github.com/altera-opensource/alt-secure-boot)
python -B -E secure_boot_tools/alt-secure-boot/bin/\
alt_authtool.py sign -t user -k root_key.pem -i\
u-boot_w_dtb-single-mkimage.bin -o u-boot_w_dtb-signed.abin
The User is the Unsecure key.
- EBERLAZARE_I_Intel
Regular Contributor
Hi,
Do you have any further questions?