diff options
author | Klaus Heinrich Kiwi <klaus@linux.vnet.ibm.com> | 2021-03-10 03:13:15 +0300 |
---|---|---|
committer | Brad Bishop <bradleyb@fuzziesquirrel.com> | 2021-05-19 05:12:21 +0300 |
commit | 3a0a8dd8364e1bac95bc6dc50f823bca96b2c5ee (patch) | |
tree | d07d6d38268578badac5bd832cf7b3b897299695 | |
parent | 04fa7fa906a548beb1012f3583a194a6b9798244 (diff) | |
download | openbmc-3a0a8dd8364e1bac95bc6dc50f823bca96b2c5ee.tar.xz |
meta-ibm: Sign the p10bmc SPL using dev key
Use the 'insecure/imprint' development key to sign the p10bmc SPL. The
key can be overriden for a production key if necessary.
Signed-off-by: Klaus Heinrich Kiwi <klaus@linux.vnet.ibm.com>
Change-Id: I6e4abecb5859fb59c6185a097cf88bdcb958e207
-rw-r--r-- | meta-ibm/conf/machine/p10bmc.conf | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/meta-ibm/conf/machine/p10bmc.conf b/meta-ibm/conf/machine/p10bmc.conf index 2db74eff2..e71b10ce4 100644 --- a/meta-ibm/conf/machine/p10bmc.conf +++ b/meta-ibm/conf/machine/p10bmc.conf @@ -38,6 +38,9 @@ IMAGE_FEATURES_remove = "obmc-ikvm" UBOOT_SIGN_ENABLE = "1" SPL_SIGN_ENABLE = "1" +SOCSEC_SIGN_ENABLE = "1" +SOCSEC_SIGN_EXTRA_OPTS = "--stack_intersects_verification_region=false" +SOCSEC_SIGN_KEY ?= "${WORKDIR}/rsa_oem_dss_key.pem" FIT_HASH_ALG = "sha512" FIT_SIGN_ALG = "rsa4096" |