| Message ID | 20261002154148.1181457-1-bst@pengutronix.de |
|---|---|
| State | New |
| Headers | show |
| Series | [meta-oe,1/2] fitimage.bbclass: document provider-based PKCS#11 signing | expand |
diff --git a/meta-oe/classes/fitimage.bbclass b/meta-oe/classes/fitimage.bbclass index 109b3b421b..69e1c5c7b2 100644 --- a/meta-oe/classes/fitimage.bbclass +++ b/meta-oe/classes/fitimage.bbclass @@ -58,11 +58,13 @@ # do_fitimage:prepend() { # signing_prepare # signing_use_role "${FITIMAGE_SIGNING_KEY_ROLE}" +# mkdir -p "${FITIMAGE_SIGN_KEYDIR}" +# signing_create_uri_pem "${FITIMAGE_SIGNING_KEY_ROLE}" "${FITIMAGE_SIGN_KEYDIR}/${FITIMAGE_SIGN_KEYNAME}.key" # } # # FITIMAGE_SIGN = "1" -# FITIMAGE_MKIMAGE_EXTRA_ARGS = "--engine pkcs11" -# FITIMAGE_SIGN_KEYDIR = "${PKCS11_URI#pkcs11:}" +# FITIMAGE_SIGN_KEYDIR = "${B}/keys" +# FITIMAGE_SIGN_KEYNAME = "fit" LICENSE ?= "MIT"
Now that oe-core moved to OpenSSL 4.0, the engine API is gone. As a result uboot-mkimage's -N/--engine no longer work: Failed to sign 'signature-1' signature node in 'conf-imx6dl-riotboard.dtb' conf node uboot-mkimage Can't add hashes to FIT blob: -1 Error: Bad parameters for FIT image type Usage: uboot-mkimage [-T type] -l image -l ==> list image header information -T ==> parse image file as 'type' -q ==> quiet Document the provider-based setup instead: signing_create_uri_pem() wraps the role's PKCS#11 URI in a PEM file that OpenSSL loads like a key file and resolves through the PKCS#11 provider configured by signing_prepare(). mkimage looks for a key in ${FITIMAGE_SIGN_KEYDIR}/${FITIMAGE_SIGN_KEYNAME}.key, so store it there. This way the existing mkimage invocations do not need to be touched. Signed-off-by: Bastian Krause <bst@pengutronix.de> --- meta-oe/classes/fitimage.bbclass | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-)