summaryrefslogtreecommitdiff
path: root/meta-ibm/conf
diff options
context:
space:
mode:
authorKlaus Heinrich Kiwi <klaus@linux.vnet.ibm.com>2021-03-10 03:13:15 +0300
committerBrad Bishop <bradleyb@fuzziesquirrel.com>2021-05-19 05:12:21 +0300
commit3a0a8dd8364e1bac95bc6dc50f823bca96b2c5ee (patch)
treed07d6d38268578badac5bd832cf7b3b897299695 /meta-ibm/conf
parent04fa7fa906a548beb1012f3583a194a6b9798244 (diff)
downloadopenbmc-3a0a8dd8364e1bac95bc6dc50f823bca96b2c5ee.tar.xz
meta-ibm: Sign the p10bmc SPL using dev key
Use the 'insecure/imprint' development key to sign the p10bmc SPL. The key can be overriden for a production key if necessary. Signed-off-by: Klaus Heinrich Kiwi <klaus@linux.vnet.ibm.com> Change-Id: I6e4abecb5859fb59c6185a097cf88bdcb958e207
Diffstat (limited to 'meta-ibm/conf')
-rw-r--r--meta-ibm/conf/machine/p10bmc.conf3
1 files changed, 3 insertions, 0 deletions
diff --git a/meta-ibm/conf/machine/p10bmc.conf b/meta-ibm/conf/machine/p10bmc.conf
index 2db74eff2..e71b10ce4 100644
--- a/meta-ibm/conf/machine/p10bmc.conf
+++ b/meta-ibm/conf/machine/p10bmc.conf
@@ -38,6 +38,9 @@ IMAGE_FEATURES_remove = "obmc-ikvm"
UBOOT_SIGN_ENABLE = "1"
SPL_SIGN_ENABLE = "1"
+SOCSEC_SIGN_ENABLE = "1"
+SOCSEC_SIGN_EXTRA_OPTS = "--stack_intersects_verification_region=false"
+SOCSEC_SIGN_KEY ?= "${WORKDIR}/rsa_oem_dss_key.pem"
FIT_HASH_ALG = "sha512"
FIT_SIGN_ALG = "rsa4096"