From 3a0a8dd8364e1bac95bc6dc50f823bca96b2c5ee Mon Sep 17 00:00:00 2001 From: Klaus Heinrich Kiwi Date: Tue, 9 Mar 2021 21:13:15 -0300 Subject: meta-ibm: Sign the p10bmc SPL using dev key Use the 'insecure/imprint' development key to sign the p10bmc SPL. The key can be overriden for a production key if necessary. Signed-off-by: Klaus Heinrich Kiwi Change-Id: I6e4abecb5859fb59c6185a097cf88bdcb958e207 --- meta-ibm/conf/machine/p10bmc.conf | 3 +++ 1 file changed, 3 insertions(+) (limited to 'meta-ibm') diff --git a/meta-ibm/conf/machine/p10bmc.conf b/meta-ibm/conf/machine/p10bmc.conf index 2db74eff2..e71b10ce4 100644 --- a/meta-ibm/conf/machine/p10bmc.conf +++ b/meta-ibm/conf/machine/p10bmc.conf @@ -38,6 +38,9 @@ IMAGE_FEATURES_remove = "obmc-ikvm" UBOOT_SIGN_ENABLE = "1" SPL_SIGN_ENABLE = "1" +SOCSEC_SIGN_ENABLE = "1" +SOCSEC_SIGN_EXTRA_OPTS = "--stack_intersects_verification_region=false" +SOCSEC_SIGN_KEY ?= "${WORKDIR}/rsa_oem_dss_key.pem" FIT_HASH_ALG = "sha512" FIT_SIGN_ALG = "rsa4096" -- cgit v1.2.3