On Sat, Sep 25, 2021 at 07:43:29PM -0600, Simon Glass wrote:

> At present EFI_SECURE BOOT selects RSA but does not necessarily enable
> FIT_SIGNATURE. Mostly this is fine, but a few boards do not enable it,
> so U-Boot tries to do RSA verification when loading FIT images, but it
> is not enabled.
> 
> This worked because the condition for checking the RSA signature is
> wrong in the fit_image_verify_with_data() function. In order to fix it
> we need to fix this dependency. Make sure that FIT_SIGNATURE is enabled
> so that RSA can be used.
> 
> It might be better to avoid using 'select' in this situation.
> 
> Signed-off-by: Simon Glass <s...@chromium.org>

Applied to u-boot/master, thanks!

-- 
Tom

Attachment: signature.asc
Description: PGP signature

Reply via email to