@@ -58,11 +58,13 @@
# do_fitimage:prepend() {
# signing_prepare
# signing_use_role "${FITIMAGE_SIGNING_KEY_ROLE}"
+# mkdir -p "${FITIMAGE_SIGN_KEYDIR}"
+# signing_create_uri_pem "${FITIMAGE_SIGNING_KEY_ROLE}" "${FITIMAGE_SIGN_KEYDIR}/${FITIMAGE_SIGN_KEYNAME}.key"
# }
#
# FITIMAGE_SIGN = "1"
-# FITIMAGE_MKIMAGE_EXTRA_ARGS = "--engine pkcs11"
-# FITIMAGE_SIGN_KEYDIR = "${PKCS11_URI#pkcs11:}"
+# FITIMAGE_SIGN_KEYDIR = "${B}/keys"
+# FITIMAGE_SIGN_KEYNAME = "fit"
LICENSE ?= "MIT"
@@ -81,7 +83,7 @@ DEPENDS = "u-boot-mkimage-native dtc-native"
FITIMAGE_SIGN ?= "0"
FITIMAGE_SIGN[doc] = "Enable FIT image signing"
FITIMAGE_SIGN_KEYDIR ?= ""
-FITIMAGE_SIGN_KEYDIR[doc] = "Key directory or pkcs#11 URI to use for signing configuration"
+FITIMAGE_SIGN_KEYDIR[doc] = "Key directory to use for signing configuration"
FITIMAGE_MKIMAGE_EXTRA_ARGS[doc] = "Extra arguemnts to pass to uboot-mkimage call"
FITIMAGE_HASH_ALGO ?= "sha256"
FITIMAGE_HASH_ALGO[doc] = "Hash algorithm to use"
Now that oe-core moved to OpenSSL 4.0, the engine API is gone. As a result uboot-mkimage's -N/--engine no longer work: Failed to sign 'signature-1' signature node in 'conf-imx6dl-riotboard.dtb' conf node uboot-mkimage Can't add hashes to FIT blob: -1 Error: Bad parameters for FIT image type Usage: uboot-mkimage [-T type] -l image -l ==> list image header information -T ==> parse image file as 'type' -q ==> quiet Document the provider-based setup instead: signing_create_uri_pem() wraps the role's PKCS#11 URI in a PEM file that OpenSSL loads like a key file and resolves through the PKCS#11 provider configured by signing_prepare(). mkimage looks for a key in ${FITIMAGE_SIGN_KEYDIR}/${FITIMAGE_SIGN_KEYNAME}.key, so store it there. This way the existing mkimage invocations do not need to be touched. Signed-off-by: Bastian Krause <bst@pengutronix.de> --- Changes since (implicit) v1: - drop no longer supported pkcs#11 URI from FITIMAGE_SIGN_KEYDIR[doc] --- meta-oe/classes/fitimage.bbclass | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-)