diff mbox series

[meta-oe,v2,1/2] fitimage.bbclass: document provider-based PKCS#11 signing

Message ID 20261002155105.1184924-1-bst@pengutronix.de
State New
Headers show
Series [meta-oe,v2,1/2] fitimage.bbclass: document provider-based PKCS#11 signing | expand

Commit Message

Bastian Krause Oct. 2, 2026, 3:49 p.m. UTC
Now that oe-core moved to OpenSSL 4.0, the engine API is gone.
As a result uboot-mkimage's -N/--engine no longer work:

  Failed to sign 'signature-1' signature node in 'conf-imx6dl-riotboard.dtb' conf node
  uboot-mkimage Can't add hashes to FIT blob: -1
  Error: Bad parameters for FIT image type
  Usage: uboot-mkimage [-T type] -l image
            -l ==> list image header information
            -T ==> parse image file as 'type'
            -q ==> quiet

Document the provider-based setup instead: signing_create_uri_pem() wraps
the role's PKCS#11 URI in a PEM file that OpenSSL loads like a key file and
resolves through the PKCS#11 provider configured by signing_prepare().

mkimage looks for a key in
${FITIMAGE_SIGN_KEYDIR}/${FITIMAGE_SIGN_KEYNAME}.key, so store it there.
This way the existing mkimage invocations do not need to be touched.

Signed-off-by: Bastian Krause <bst@pengutronix.de>
---
Changes since (implicit) v1:
- drop no longer supported pkcs#11 URI from FITIMAGE_SIGN_KEYDIR[doc]
---
 meta-oe/classes/fitimage.bbclass | 8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)
diff mbox series

Patch

diff --git a/meta-oe/classes/fitimage.bbclass b/meta-oe/classes/fitimage.bbclass
index 109b3b421b..8a59388008 100644
--- a/meta-oe/classes/fitimage.bbclass
+++ b/meta-oe/classes/fitimage.bbclass
@@ -58,11 +58,13 @@ 
 #    do_fitimage:prepend() {
 #        signing_prepare
 #        signing_use_role "${FITIMAGE_SIGNING_KEY_ROLE}"
+#        mkdir -p "${FITIMAGE_SIGN_KEYDIR}"
+#        signing_create_uri_pem "${FITIMAGE_SIGNING_KEY_ROLE}" "${FITIMAGE_SIGN_KEYDIR}/${FITIMAGE_SIGN_KEYNAME}.key"
 #    }
 #
 #    FITIMAGE_SIGN = "1"
-#    FITIMAGE_MKIMAGE_EXTRA_ARGS = "--engine pkcs11"
-#    FITIMAGE_SIGN_KEYDIR = "${PKCS11_URI#pkcs11:}"
+#    FITIMAGE_SIGN_KEYDIR = "${B}/keys"
+#    FITIMAGE_SIGN_KEYNAME = "fit"
 
 
 LICENSE ?= "MIT"
@@ -81,7 +83,7 @@  DEPENDS = "u-boot-mkimage-native dtc-native"
 FITIMAGE_SIGN ?= "0"
 FITIMAGE_SIGN[doc] = "Enable FIT image signing"
 FITIMAGE_SIGN_KEYDIR ?= ""
-FITIMAGE_SIGN_KEYDIR[doc] = "Key directory or pkcs#11 URI to use for signing configuration"
+FITIMAGE_SIGN_KEYDIR[doc] = "Key directory to use for signing configuration"
 FITIMAGE_MKIMAGE_EXTRA_ARGS[doc] = "Extra arguemnts to pass to uboot-mkimage call"
 FITIMAGE_HASH_ALGO ?= "sha256"
 FITIMAGE_HASH_ALGO[doc] = "Hash algorithm to use"