mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
Merge branch 'fix/disable_secure_boot_v2_ecdsa_v6.0' into 'release/v6.0'
Fix/disable secure boot v2 ecdsa (v6.0) See merge request espressif/esp-idf!49470
This commit is contained in:
@@ -478,6 +478,18 @@ menu "Security features"
|
||||
default y
|
||||
depends on SOC_SECURE_BOOT_V2_ECC
|
||||
|
||||
# ECDSA based Secure Boot V2 is not functional for certain input vectors on these
|
||||
# SoCs. The scheme stays available but, for hardware Secure Boot, must be explicitly
|
||||
# turned on via SECURE_BOOT_V2_FORCE_ENABLE_ECDSA under "Allow potentially insecure
|
||||
# options" (CONFIG_SECURE_BOOT_INSECURE).
|
||||
#
|
||||
# TODO: IDF-15721 - drop a SoC from this list once a fixing hardware ECO revision
|
||||
# ships, gating on the selected minimum chip revision, e.g.:
|
||||
# default y if IDF_TARGET_ESP32C5 && ESP32C5_REV_MIN_FULL < <fixed_rev>
|
||||
config SECURE_BOOT_V2_ECDSA_INSECURE
|
||||
bool
|
||||
default y if IDF_TARGET_ESP32C5 || IDF_TARGET_ESP32C61 || IDF_TARGET_ESP32H2 || IDF_TARGET_ESP32P4
|
||||
|
||||
config SECURE_BOOT_V1_SUPPORTED
|
||||
bool
|
||||
default y
|
||||
@@ -549,6 +561,10 @@ menu "Security features"
|
||||
config SECURE_SIGNED_APPS_ECDSA_V2_SCHEME
|
||||
bool "ECDSA (V2)"
|
||||
depends on SECURE_BOOT_V2_ECC_SUPPORTED && (SECURE_SIGNED_APPS_NO_SECURE_BOOT || SECURE_BOOT_V2_ENABLED)
|
||||
# On the affected SoCs (SECURE_BOOT_V2_ECDSA_INSECURE), hardware Secure Boot with ECDSA
|
||||
# is offered only when SECURE_BOOT_V2_FORCE_ENABLE_ECDSA is explicitly set. App signing
|
||||
# without hardware Secure Boot is not affected by this gate.
|
||||
depends on !SECURE_BOOT_V2_ENABLED || (!SECURE_BOOT_V2_ECDSA_INSECURE || SECURE_BOOT_V2_FORCE_ENABLE_ECDSA)
|
||||
help
|
||||
For Secure boot V2 (e.g., ESP32-C2 SoC), appends ECDSA based signature block to the application.
|
||||
Refer to documentation before enabling.
|
||||
@@ -931,6 +947,19 @@ menu "Security features"
|
||||
# it's possible for the insecure menu to be disabled but the insecure option
|
||||
# to remain on which is very bad.)
|
||||
|
||||
config SECURE_BOOT_V2_FORCE_ENABLE_ECDSA
|
||||
bool "Force enable ECDSA based Secure Boot V2"
|
||||
depends on SECURE_BOOT_INSECURE && SECURE_BOOT_V2_ECDSA_INSECURE
|
||||
default n
|
||||
help
|
||||
ECDSA based Secure Boot V2 is not functional for certain input vectors on this SoC
|
||||
and is therefore not offered by default. Refer to the hardware errata document for
|
||||
details.
|
||||
|
||||
Setting this option re-enables the ECDSA based Secure Boot V2 signing scheme despite
|
||||
the known vulnerability. Only set this option if you fully understand the risk. RSA
|
||||
based Secure Boot V2 is the recommended scheme on SoCs that support it.
|
||||
|
||||
config SECURE_BOOT_ALLOW_ROM_BASIC
|
||||
bool "Leave ROM BASIC Interpreter available on reset"
|
||||
depends on (SECURE_BOOT_INSECURE || SECURE_FLASH_ENCRYPTION_MODE_DEVELOPMENT) && IDF_TARGET_ESP32
|
||||
|
||||
@@ -1,6 +1,9 @@
|
||||
# NOTE: This sdkconfig is intended solely for CI build purposes - to verify ESP-TEE
|
||||
# builds across various configurations - and is not intended for production use.
|
||||
|
||||
# Reducing TEE IRAM size
|
||||
# 30KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x7800
|
||||
# 29KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x7400
|
||||
|
||||
# TEE Secure Storage: Release mode
|
||||
CONFIG_SECURE_TEE_SEC_STG_MODE_RELEASE=y
|
||||
@@ -10,7 +13,11 @@ CONFIG_SECURE_TEE_SEC_STG_EFUSE_HMAC_KEY_ID=5
|
||||
CONFIG_SECURE_TEE_EXT_FLASH_MEMPROT_SPI1=n
|
||||
|
||||
# Secure Boot
|
||||
CONFIG_PARTITION_TABLE_OFFSET=0xf000
|
||||
CONFIG_PARTITION_TABLE_OFFSET=0xF000
|
||||
CONFIG_SECURE_BOOT=y
|
||||
# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs
|
||||
CONFIG_SECURE_BOOT_INSECURE=y
|
||||
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
|
||||
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
|
||||
CONFIG_SECURE_BOOT_BUILD_SIGNED_BINARIES=y
|
||||
CONFIG_SECURE_BOOT_SIGNING_KEY="test_keys/secure_boot_signing_key.pem"
|
||||
CONFIG_SECURE_BOOT_SIGNING_KEY="test_keys/secure_boot_signing_key_ecdsa_p256.pem"
|
||||
|
||||
@@ -1,3 +1,6 @@
|
||||
# NOTE: This sdkconfig is intended solely for CI build purposes - to verify ESP-TEE
|
||||
# builds across various configurations - and is not intended for production use.
|
||||
|
||||
# Increasing TEE I/DRAM sizes
|
||||
# 34KB
|
||||
CONFIG_SECURE_TEE_IRAM_SIZE=0x8800
|
||||
@@ -9,8 +12,12 @@ CONFIG_PARTITION_TABLE_OFFSET=0xf000
|
||||
|
||||
# Secure Boot
|
||||
CONFIG_SECURE_BOOT=y
|
||||
# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs
|
||||
CONFIG_SECURE_BOOT_INSECURE=y
|
||||
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
|
||||
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
|
||||
CONFIG_SECURE_BOOT_BUILD_SIGNED_BINARIES=y
|
||||
CONFIG_SECURE_BOOT_SIGNING_KEY="test_keys/secure_boot_signing_key.pem"
|
||||
CONFIG_SECURE_BOOT_SIGNING_KEY="test_keys/secure_boot_signing_key_ecdsa_p256.pem"
|
||||
|
||||
# Flash Encryption
|
||||
CONFIG_SECURE_FLASH_ENC_ENABLED=y
|
||||
|
||||
+5
@@ -0,0 +1,5 @@
|
||||
-----BEGIN EC PRIVATE KEY-----
|
||||
MHcCAQEEIFFwmnckyThKZQMV40ceAQm8OxwP1aI0dvWt3P9/4VAgoAoGCCqGSM49
|
||||
AwEHoUQDQgAEwMObAE6S2QjA4vYnifYGDO/Jd9Pr9p2CWKxQVTsziuqz2pJxzjcQ
|
||||
zJT6Aj30auml+oIGvNwBnhoZ3v5SCyzqOw==
|
||||
-----END EC PRIVATE KEY-----
|
||||
@@ -753,7 +753,7 @@ config SOC_SECURE_BOOT_V2_RSA
|
||||
|
||||
config SOC_SECURE_BOOT_V2_ECC
|
||||
bool
|
||||
default y
|
||||
default n
|
||||
|
||||
config SOC_EFUSE_SECURE_BOOT_KEY_DIGESTS
|
||||
int
|
||||
|
||||
@@ -430,7 +430,7 @@
|
||||
|
||||
/*-------------------------- Secure Boot CAPS----------------------------*/
|
||||
#define SOC_SECURE_BOOT_V2_RSA 1
|
||||
#define SOC_SECURE_BOOT_V2_ECC 1
|
||||
#define SOC_SECURE_BOOT_V2_ECC 0
|
||||
#define SOC_EFUSE_SECURE_BOOT_KEY_DIGESTS 3
|
||||
#define SOC_EFUSE_REVOKE_BOOT_KEY_DIGESTS 1
|
||||
#define SOC_SUPPORT_SECURE_BOOT_REVOKE_KEY 1
|
||||
|
||||
Reference in New Issue
Block a user