Re: U-Boot FIT Signature Verification

2020-09-16 Thread takahiro.aka...@linaro.org
On Wed, Sep 16, 2020 at 11:40:08AM +, Joakim Tjernlund wrote: > On Wed, 2020-09-16 at 13:14 +0200, Heinrich Schuchardt wrote: > > CAUTION: This email originated from outside of the organization. Do not > > click links or open attachments unless you recognize the sender and know > > the

Re: U-Boot FIT Signature Verification

2020-09-16 Thread takahiro.aka...@linaro.org
On Wed, Sep 16, 2020 at 02:44:45PM +0200, Heinrich Schuchardt wrote: > On 16.09.20 14:05, Joakim Tjernlund wrote: > > On Wed, 2020-09-16 at 13:55 +0200, Heinrich Schuchardt wrote: > >> On 16.09.20 13:40, Joakim Tjernlund wrote: > >>> On Wed, 2020-09-16 at 13:14 +0200, Heinrich Schuchardt wrote: >

Re: U-Boot FIT Signature Verification

2020-09-16 Thread AKASHI Takahiro
On Wed, Sep 16, 2020 at 01:14:56PM +0200, Heinrich Schuchardt wrote: > On 16.09.20 10:13, AKASHI Takahiro wrote: > > On Wed, Sep 16, 2020 at 01:19:03AM +0200, Heinrich Schuchardt wrote: > >> On 9/11/20 7:26 PM, Andrii Voloshyn wrote: > >>> Hi there, > >>> > >>> Does U-boot take into account

Re: U-Boot FIT Signature Verification

2020-09-16 Thread Philippe REYNES
Hi Heinrich, > On 9/11/20 7:26 PM, Andrii Voloshyn wrote: >> Hi there, >> >> Does U-boot take into account certificate expiration date when verifying >> signed >> images in FIT? In other words, is date stored along with the public key in >> DTB >> file? >> >> Cheers, >> Andy >> > > Hello

Re: U-Boot FIT Signature Verification

2020-09-16 Thread Tom Rini
On Wed, Sep 16, 2020 at 02:44:45PM +0200, Heinrich Schuchardt wrote: > On 16.09.20 14:05, Joakim Tjernlund wrote: > > On Wed, 2020-09-16 at 13:55 +0200, Heinrich Schuchardt wrote: > >> On 16.09.20 13:40, Joakim Tjernlund wrote: > >>> On Wed, 2020-09-16 at 13:14 +0200, Heinrich Schuchardt wrote: >

Re: U-Boot FIT Signature Verification

2020-09-16 Thread REITHER Robert - Contractor
Hi there I don't think it would make sense to check for expiration (even in case we would have full certificates like PKCS#7 verifiy) At our point of the boot process we normally do not have access to a trusted time/date, so any check could be simply spoofed or even worse fails, because

Re: U-Boot FIT Signature Verification

2020-09-16 Thread Heinrich Schuchardt
On 16.09.20 14:05, Joakim Tjernlund wrote: > On Wed, 2020-09-16 at 13:55 +0200, Heinrich Schuchardt wrote: >> On 16.09.20 13:40, Joakim Tjernlund wrote: >>> On Wed, 2020-09-16 at 13:14 +0200, Heinrich Schuchardt wrote: CAUTION: This email originated from outside of the organization. Do not

Re: U-Boot FIT Signature Verification

2020-09-16 Thread Joakim Tjernlund
On Wed, 2020-09-16 at 13:55 +0200, Heinrich Schuchardt wrote: > On 16.09.20 13:40, Joakim Tjernlund wrote: > > On Wed, 2020-09-16 at 13:14 +0200, Heinrich Schuchardt wrote: > > > CAUTION: This email originated from outside of the organization. Do not > > > click links or open attachments unless

Re: U-Boot FIT Signature Verification

2020-09-16 Thread Heinrich Schuchardt
On 16.09.20 13:40, Joakim Tjernlund wrote: > On Wed, 2020-09-16 at 13:14 +0200, Heinrich Schuchardt wrote: >> CAUTION: This email originated from outside of the organization. Do not >> click links or open attachments unless you recognize the sender and know the >> content is safe. >> >> >> On

Re: U-Boot FIT Signature Verification

2020-09-16 Thread Joakim Tjernlund
On Wed, 2020-09-16 at 13:14 +0200, Heinrich Schuchardt wrote: > CAUTION: This email originated from outside of the organization. Do not click > links or open attachments unless you recognize the sender and know the > content is safe. > > > On 16.09.20 10:13, AKASHI Takahiro wrote: > > On Wed,

Re: U-Boot FIT Signature Verification

2020-09-16 Thread Heinrich Schuchardt
On 16.09.20 10:13, AKASHI Takahiro wrote: > On Wed, Sep 16, 2020 at 01:19:03AM +0200, Heinrich Schuchardt wrote: >> On 9/11/20 7:26 PM, Andrii Voloshyn wrote: >>> Hi there, >>> >>> Does U-boot take into account certificate expiration date when >>> verifying signed images in FIT? In other

Re: U-Boot FIT Signature Verification

2020-09-16 Thread AKASHI Takahiro
On Wed, Sep 16, 2020 at 01:19:03AM +0200, Heinrich Schuchardt wrote: > On 9/11/20 7:26 PM, Andrii Voloshyn wrote: > > Hi there, > > > > Does U-boot take into account certificate expiration date when > > verifying signed images in FIT? In other words, is date stored along with > > the public

Re: U-Boot FIT Signature Verification

2020-09-15 Thread Heinrich Schuchardt
On 9/11/20 7:26 PM, Andrii Voloshyn wrote: > Hi there, > > Does U-boot take into account certificate expiration date when verifying > signed images in FIT? In other words, is date stored along with the public > key in DTB file? > > Cheers, > Andy > Hello Philippe, looking at

U-Boot FIT Signature Verification

2020-09-11 Thread Andrii Voloshyn
Hi there, Does U-boot take into account certificate expiration date when verifying signed images in FIT? In other words, is date stored along with the public key in DTB file? Cheers, Andy