Merge branch 'fix/disable_secure_boot_v2_ecdsa_v6.1' into 'release/v6.1'

Fix/disable secure boot v2 ecdsa (v6.1)

See merge request espressif/esp-idf!49469
This commit is contained in:
Mahavir Jain
2026-06-10 14:39:06 +05:30
24 changed files with 131 additions and 17 deletions
@@ -1,3 +1,6 @@
# NOTE: This sdkconfig is intended solely for CI build purposes - to verify ESP-TEE
# builds across various configurations - and is not intended for production use.
# Reducing TEE IRAM size
# 29KB
CONFIG_SECURE_TEE_IRAM_SIZE=0x7400
@@ -12,6 +15,9 @@ CONFIG_SECURE_TEE_EXT_FLASH_MEMPROT_SPI1=n
# Secure Boot
CONFIG_PARTITION_TABLE_OFFSET=0xF000
CONFIG_SECURE_BOOT=y
# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs
CONFIG_SECURE_BOOT_INSECURE=y
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
CONFIG_SECURE_BOOT_BUILD_SIGNED_BINARIES=y
CONFIG_SECURE_BOOT_SIGNING_KEY="test_keys/secure_boot_signing_key_ecdsa_p256.pem"
@@ -1,3 +1,6 @@
# NOTE: This sdkconfig is intended solely for CI build purposes - to verify ESP-TEE
# builds across various configurations - and is not intended for production use.
# Increasing TEE I/DRAM sizes
# 34KB
CONFIG_SECURE_TEE_IRAM_SIZE=0x8800
@@ -9,6 +12,9 @@ CONFIG_PARTITION_TABLE_OFFSET=0xf000
# Secure Boot
CONFIG_SECURE_BOOT=y
# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs
CONFIG_SECURE_BOOT_INSECURE=y
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
CONFIG_SECURE_BOOT_BUILD_SIGNED_BINARIES=y
CONFIG_SECURE_BOOT_SIGNING_KEY="test_keys/secure_boot_signing_key_ecdsa_p256.pem"