On Thu, Sep 03, 2026 at 10:16:50AM +0200, Philippe Reynes wrote: > This series adds the support of ecdsa with software > using mbedtls. So boards without ecdsa hardware may > also use signature with ecdsa. > > To achieve this goal, several changes are done: > - fix the support of secp521r1 > - enable support of ecdsa in mbedtls > - add software ecdsa signature check using mbedtls > - add support of ecdsa for internal fit signature > - add test for ecdsa for internal fit signature in vboot > - add support of ecdsa for pre-load signature > - add test for ecdsa for pre-load signature in vboot > - enable software ecdsa signature check in sandbox
OK, so it's enabled on sandbox.
>
> To test this new feature, just follow those steps:
>
> 0) build u-boot using sandbox_defconfig and adding those options:
>
> CONFIG_ECDSA_MBEDTLS=y
> CONFIG_ECDSA_VERIFY_MBEDTLS=y
> CONFIG_ECDSA=y
> CONFIG_ECDSA_VERIFY=y
>
> 1) add a signature node to an its file
> signature-256 {
> algo = "sha256,ecdsa256";
> key-name-hint = "private-key-256";
> };
>
> 2) generate an ecdsa key
> openssl ecparam -name prime256v1 -genkey -noout -out private-key-256.pem
>
> 3) create the itb file
> ./tools/mkimage -f <file.its> -k . -K arch/sandbox/dts/test.dtb <file.itb>
>
> 4) launch sandbox u-boot
>
> ./u-boot -d arch/sandbox/dts/test.dtb
>
> 5) on sandbox u-boot prompt, load the itb and launch bootm on it
>
> => host load hostfs - 1000000 uboot-ecdsa.itb
> 4628674 bytes read in 1 ms (4.3 GiB/s)
> => bootm 1000000
> ...
> ...
> Verifying Hash Integrity ... sha256,ecdsa256:private-key-256+ OK
Does this mean the new tests aren't run automatically?
--
Tom
signature.asc
Description: PGP signature
