| Message ID | 20261002155105.1184924-2-bst@pengutronix.de |
|---|---|
| State | New |
| Headers | show |
| Series | [meta-oe,v2,1/2] fitimage.bbclass: document provider-based PKCS#11 signing | expand |
diff --git a/meta-oe/classes/fitimage.bbclass b/meta-oe/classes/fitimage.bbclass index 8a59388008..99b74939aa 100644 --- a/meta-oe/classes/fitimage.bbclass +++ b/meta-oe/classes/fitimage.bbclass @@ -519,6 +519,11 @@ do_configure[postfuncs] += "write_manifest" do_fitimage () { if [ "${FITIMAGE_SIGN}" = "1" ]; then + case " ${FITIMAGE_MKIMAGE_EXTRA_ARGS} " in + *" --engine "*|*" --engine="*|*" -N "*) + bbfatal "FITIMAGE_MKIMAGE_EXTRA_ARGS: OpenSSL engines are no longer supported, see updated usage in fitimage.bbclass." + ;; + esac uboot-mkimage ${FITIMAGE_MKIMAGE_EXTRA_ARGS} \ -k "${FITIMAGE_SIGN_KEYDIR}" -r \ -f "${B}/manifest.its" \
Now that oe-core moved to OpenSSL 4.0, the engine API is gone. As a result uboot-mkimage's -N/--engine no longer work: Failed to sign 'signature-1' signature node in 'conf-imx6dl-riotboard.dtb' conf node uboot-mkimage Can't add hashes to FIT blob: -1 Error: Bad parameters for FIT image type Usage: uboot-mkimage [-T type] -l image -l ==> list image header information -T ==> parse image file as 'type' -q ==> quiet A previous patch documented how provider-based PKCS#11 signing works. Now make an engine option in FITIMAGE_MKIMAGE_EXTRA_ARGS a fatal error. It has no effect anymore, so a recipe still setting it has not been migrated; failing with a clear message beats mkimage's generic error messages above. Signed-off-by: Bastian Krause <bst@pengutronix.de> --- Changes since (implicit) v1: - mention FITIMAGE_MKIMAGE_EXTRA_ARGS in bbfatal message, so the user knows where to look for the engine argument --- meta-oe/classes/fitimage.bbclass | 5 +++++ 1 file changed, 5 insertions(+)