diff mbox series

[v4,3/3] uboot-sign: enable signing SPL FIT configuration

Message ID 20261008060935.4225-3-rybczynska@gmail.com
State New
Headers show
Series [v4,1/3] uboot-sign: add the option to sign SPL FIT configurations | expand

Commit Message

Marta Rybczynska Oct. 8, 2026, 6:09 a.m. UTC
This commit enables signing SPL FIT configuration instead of specific
elements. This introduces an incompatibility with the previous behavior,
but is the correct way to do.

Signed-off-by: Marta Rybczynska <rybczynska@gmail.com>
---
 meta/classes-recipe/uboot-sign.bbclass | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)
diff mbox series

Patch

diff --git a/meta/classes-recipe/uboot-sign.bbclass b/meta/classes-recipe/uboot-sign.bbclass
index 42319d15ff..85138bc948 100644
--- a/meta/classes-recipe/uboot-sign.bbclass
+++ b/meta/classes-recipe/uboot-sign.bbclass
@@ -35,13 +35,13 @@  SPL_SIGN_ENABLE ?= "0"
 
 # Sign the FIT configuration in the SPL signing flow. Configuration
 # signatures bind the selected images and boot metadata together.
-SPL_SIGN_CONF ?= "0"
+SPL_SIGN_CONF ?= "1"
 
 # Legacy compatibility knob for per-image signatures in the SPL FIT path.
 # Individual image signatures do not protect the configuration metadata
 # which selects and parameterizes the boot images.
 # INSECURE, use at your own risk
-SPL_SIGN_INDIVIDUAL ?= "1"
+SPL_SIGN_INDIVIDUAL ?= "0"
 
 # Default value for deployment filenames.
 UBOOT_DTB_IMAGE ?= "u-boot-${MACHINE}-${PV}-${PR}.dtb"