fix(bootloader_support): set SECURE_BOOT_SHA384_EN eFuse on ESP32-P4

Set SECURE_BOOT_SHA384_EN when enabling ECDSA-P384 Secure Boot V2 on
ESP32-P4, as done on C5/H4/S31, so that ROM verifies the bootloader
using the SHA-384 scheme. The eFuse exists only on the rev >= v3.0
eFuse table, so the Kconfig option is gated on rev >= v3.0.
This commit is contained in:
nilesh.kale
2026-07-17 15:15:50 +05:30
parent 3aea82e4b3
commit 7ef8b58873
2 changed files with 7 additions and 1 deletions
+2
View File
@@ -588,6 +588,8 @@ menu "Security features"
config SECURE_BOOT_ECDSA_KEY_LEN_384_BITS
bool "Using ECC curve NISTP384 (Recommended)"
depends on SECURE_SIGNED_APPS_ECDSA_V2_SCHEME && SOC_ECDSA_SUPPORT_CURVE_P384
# ESP32-P4 revisions < v3.0 do not support Secure Boot using ECDSA-P384
depends on !ESP32P4_SELECTS_REV_LESS_V3
endchoice