diff --git a/components/bootloader/Kconfig.projbuild b/components/bootloader/Kconfig.projbuild index c7d37c71422..fd269ec3338 100644 --- a/components/bootloader/Kconfig.projbuild +++ b/components/bootloader/Kconfig.projbuild @@ -471,6 +471,18 @@ menu "Security features" default y depends on SOC_SECURE_BOOT_V2_ECC + # ECDSA based Secure Boot V2 is not functional for certain input vectors on these + # SoCs. The scheme stays available but, for hardware Secure Boot, must be explicitly + # turned on via SECURE_BOOT_V2_FORCE_ENABLE_ECDSA under "Allow potentially insecure + # options" (CONFIG_SECURE_BOOT_INSECURE). + # + # TODO: IDF-15721 - drop a SoC from this list once a fixing hardware ECO revision + # ships, gating on the selected minimum chip revision, e.g.: + # default y if IDF_TARGET_ESP32C5 && ESP32C5_REV_MIN_FULL < + config SECURE_BOOT_V2_ECDSA_INSECURE + bool + default y if IDF_TARGET_ESP32C5 || IDF_TARGET_ESP32C61 || IDF_TARGET_ESP32H2 || IDF_TARGET_ESP32P4 + config SECURE_BOOT_V1_SUPPORTED bool default y @@ -542,6 +554,10 @@ menu "Security features" config SECURE_SIGNED_APPS_ECDSA_V2_SCHEME bool "ECDSA (V2)" depends on SECURE_BOOT_V2_ECC_SUPPORTED && (SECURE_SIGNED_APPS_NO_SECURE_BOOT || SECURE_BOOT_V2_ENABLED) + # On the affected SoCs (SECURE_BOOT_V2_ECDSA_INSECURE), hardware Secure Boot with ECDSA + # is offered only when SECURE_BOOT_V2_FORCE_ENABLE_ECDSA is explicitly set. App signing + # without hardware Secure Boot is not affected by this gate. + depends on !SECURE_BOOT_V2_ENABLED || (!SECURE_BOOT_V2_ECDSA_INSECURE || SECURE_BOOT_V2_FORCE_ENABLE_ECDSA) help For Secure boot V2 (e.g., ESP32-C2 SoC), appends ECDSA based signature block to the application. Refer to documentation before enabling. @@ -906,6 +922,19 @@ menu "Security features" # it's possible for the insecure menu to be disabled but the insecure option # to remain on which is very bad.) + config SECURE_BOOT_V2_FORCE_ENABLE_ECDSA + bool "Force enable ECDSA based Secure Boot V2" + depends on SECURE_BOOT_INSECURE && SECURE_BOOT_V2_ECDSA_INSECURE + default n + help + ECDSA based Secure Boot V2 is not functional for certain input vectors on this SoC + and is therefore not offered by default. Refer to the hardware errata document for + details. + + Setting this option re-enables the ECDSA based Secure Boot V2 signing scheme despite + the known vulnerability. Only set this option if you fully understand the risk. RSA + based Secure Boot V2 is the recommended scheme on SoCs that support it. + config SECURE_BOOT_ALLOW_ROM_BASIC bool "Leave ROM BASIC Interpreter available on reset" depends on (SECURE_BOOT_INSECURE || SECURE_FLASH_ENCRYPTION_MODE_DEVELOPMENT) && IDF_TARGET_ESP32 diff --git a/components/esp_tee/test_apps/tee_cli_app/sdkconfig.ci.release.esp32c61 b/components/esp_tee/test_apps/tee_cli_app/sdkconfig.ci.release.esp32c61 new file mode 100644 index 00000000000..698ff4cbf5c --- /dev/null +++ b/components/esp_tee/test_apps/tee_cli_app/sdkconfig.ci.release.esp32c61 @@ -0,0 +1,6 @@ +# ESP32-C61 has no RSA based Secure Boot V2; the ECDSA scheme is gated behind the insecure +# option (see SECURE_BOOT_V2_ECDSA_INSECURE), so force-enable it and use an ECDSA key. +CONFIG_SECURE_BOOT_INSECURE=y +CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y +CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y +CONFIG_SECURE_BOOT_SIGNING_KEY="test_keys/secure_boot_signing_key_ecdsa_p256.pem" diff --git a/components/esp_tee/test_apps/tee_cli_app/sdkconfig.ci.sb_fe.esp32c61 b/components/esp_tee/test_apps/tee_cli_app/sdkconfig.ci.sb_fe.esp32c61 new file mode 100644 index 00000000000..698ff4cbf5c --- /dev/null +++ b/components/esp_tee/test_apps/tee_cli_app/sdkconfig.ci.sb_fe.esp32c61 @@ -0,0 +1,6 @@ +# ESP32-C61 has no RSA based Secure Boot V2; the ECDSA scheme is gated behind the insecure +# option (see SECURE_BOOT_V2_ECDSA_INSECURE), so force-enable it and use an ECDSA key. +CONFIG_SECURE_BOOT_INSECURE=y +CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y +CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y +CONFIG_SECURE_BOOT_SIGNING_KEY="test_keys/secure_boot_signing_key_ecdsa_p256.pem" diff --git a/components/esp_tee/test_apps/tee_cli_app/test_keys/secure_boot_signing_key_ecdsa_p256.pem b/components/esp_tee/test_apps/tee_cli_app/test_keys/secure_boot_signing_key_ecdsa_p256.pem new file mode 100644 index 00000000000..e9dd5863254 --- /dev/null +++ b/components/esp_tee/test_apps/tee_cli_app/test_keys/secure_boot_signing_key_ecdsa_p256.pem @@ -0,0 +1,5 @@ +-----BEGIN EC PRIVATE KEY----- +MHcCAQEEIFFwmnckyThKZQMV40ceAQm8OxwP1aI0dvWt3P9/4VAgoAoGCCqGSM49 +AwEHoUQDQgAEwMObAE6S2QjA4vYnifYGDO/Jd9Pr9p2CWKxQVTsziuqz2pJxzjcQ +zJT6Aj30auml+oIGvNwBnhoZ3v5SCyzqOw== +-----END EC PRIVATE KEY----- diff --git a/components/soc/esp32h21/include/soc/Kconfig.soc_caps.in b/components/soc/esp32h21/include/soc/Kconfig.soc_caps.in index 8887b0d1f59..5fe819c3be6 100644 --- a/components/soc/esp32h21/include/soc/Kconfig.soc_caps.in +++ b/components/soc/esp32h21/include/soc/Kconfig.soc_caps.in @@ -693,7 +693,7 @@ config SOC_SECURE_BOOT_V2_RSA config SOC_SECURE_BOOT_V2_ECC bool - default y + default n config SOC_EFUSE_SECURE_BOOT_KEY_DIGESTS int diff --git a/components/soc/esp32h21/include/soc/soc_caps.h b/components/soc/esp32h21/include/soc/soc_caps.h index ec43995222b..2850ea80474 100644 --- a/components/soc/esp32h21/include/soc/soc_caps.h +++ b/components/soc/esp32h21/include/soc/soc_caps.h @@ -470,7 +470,7 @@ /*-------------------------- Secure Boot CAPS----------------------------*/ #define SOC_SECURE_BOOT_V2_RSA 1 -#define SOC_SECURE_BOOT_V2_ECC 1 +#define SOC_SECURE_BOOT_V2_ECC 0 #define SOC_EFUSE_SECURE_BOOT_KEY_DIGESTS 3 #define SOC_EFUSE_REVOKE_BOOT_KEY_DIGESTS 1 #define SOC_SUPPORT_SECURE_BOOT_REVOKE_KEY 1 diff --git a/docs/en/security/secure-boot-v2.rst b/docs/en/security/secure-boot-v2.rst index f076b6413ff..127eac6283e 100644 --- a/docs/en/security/secure-boot-v2.rst +++ b/docs/en/security/secure-boot-v2.rst @@ -5,11 +5,11 @@ Secure Boot v2 :link_to_translation:`zh_CN:[中文]` -{IDF_TARGET_SBV2_SCHEME:default="RSA-PSS", esp32c2, esp32c61="ECDSA", esp32c6, esp32h2, esp32p4, esp32c5, esp32h21="RSA-PSS or ECDSA"} +{IDF_TARGET_SBV2_SCHEME:default="RSA-PSS", esp32c2, esp32c61="ECDSA", esp32c6, esp32h2, esp32p4, esp32c5="RSA-PSS or ECDSA", esp32h21="RSA-PSS"} -{IDF_TARGET_SBV2_KEY:default="RSA-3072", esp32c2, esp32c61="ECDSA-256 or ECDSA-192", esp32c6, esp32h2, esp32p4, esp32h21="RSA-3072, ECDSA-256, or ECDSA-192", esp32c5="RSA-3072, ECDSA-384, ECDSA-256, or ECDSA-192"} +{IDF_TARGET_SBV2_KEY:default="RSA-3072", esp32c2, esp32c61="ECDSA-256 or ECDSA-192", esp32c6, esp32h2, esp32p4="RSA-3072, ECDSA-256, or ECDSA-192", esp32h21="RSA-3072", esp32c5="RSA-3072, ECDSA-384, ECDSA-256, or ECDSA-192"} -{IDF_TARGET_SECURE_BOOT_OPTION_TEXT:default="", esp32c6, esp32h2, esp32p4, esp32h21="RSA is recommended for faster verification. You can choose either the RSA or ECDSA scheme from the menu.", esp32c5="ECDSA is recommended for faster verification. You can choose either the RSA or ECDSA scheme from the menu."} +{IDF_TARGET_SECURE_BOOT_OPTION_TEXT:default="", esp32c6, esp32h2, esp32p4="RSA is recommended for faster verification. You can choose either the RSA or ECDSA scheme from the menu.", esp32c5="ECDSA is recommended for faster verification. You can choose either the RSA or ECDSA scheme from the menu."} {IDF_TARGET_SBV2_SCHEME_RECOMMENDATION:default="RSA is recommended for use cases where fast boot-up time is required whereas ECDSA is recommended for use cases where shorter key length is required.", esp32c5="ECDSA is recommended for use cases where fast boot-up time and shorter key length is required."} @@ -52,6 +52,18 @@ Secure Boot v2 In this guide, most used commands are in the form of ``idf.py secure-``, which is a wrapper around corresponding ``espsecure.py ``. The ``idf.py`` based commands provides more user-friendly experience, although may lack some of the advanced functionality of their ``espsecure.py`` based counterparts. +.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and SOC_SECURE_BOOT_V2_RSA + + .. warning:: + + On {IDF_TARGET_NAME}, the ECDSA based Secure Boot V2 scheme is not functional for certain input vectors and is therefore **not recommended**. Please use the RSA based Secure Boot V2 scheme instead. To use the ECDSA based scheme regardless of this limitation, enable :ref:`CONFIG_SECURE_BOOT_INSECURE` and :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`. This issue will be fixed in a future hardware ECO revision; refer to the hardware errata document for details. + +.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and not SOC_SECURE_BOOT_V2_RSA + + .. warning:: + + On {IDF_TARGET_NAME}, the ECDSA based Secure Boot V2 scheme is vulnerable for certain input vectors and is therefore **not recommended for production**. To use the ECDSA based Secure Boot V2 scheme regardless of this limitation, enable :ref:`CONFIG_SECURE_BOOT_INSECURE` and :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`. This issue will be fixed in a future hardware ECO revision; refer to the hardware errata document for details. + Background ---------- diff --git a/docs/zh_CN/security/secure-boot-v2.rst b/docs/zh_CN/security/secure-boot-v2.rst index bf5fb86412a..ccbee4fc87b 100644 --- a/docs/zh_CN/security/secure-boot-v2.rst +++ b/docs/zh_CN/security/secure-boot-v2.rst @@ -5,11 +5,11 @@ :link_to_translation:`en:[English]` -{IDF_TARGET_SBV2_SCHEME:default="RSA-PSS", esp32c2, esp32c61="ECDSA", esp32c6, esp32h2, esp32p4, esp32c5, esp32h21="RSA-PSS 或 ECDSA"} +{IDF_TARGET_SBV2_SCHEME:default="RSA-PSS", esp32c2, esp32c61="ECDSA", esp32c6, esp32h2, esp32p4, esp32c5="RSA-PSS 或 ECDSA", esp32h21="RSA-PSS"} -{IDF_TARGET_SBV2_KEY:default="RSA-3072", esp32c2, esp32c61="ECDSA-256 或 ECDSA-192", esp32c6, esp32h2, esp32p4, esp32h21="RSA-3072、ECDSA-256 或 ECDSA-192", esp32c5="RSA-3072、ECDSA-384、ECDSA-256 或 ECDSA-192"} +{IDF_TARGET_SBV2_KEY:default="RSA-3072", esp32c2, esp32c61="ECDSA-256 或 ECDSA-192", esp32c6, esp32h2, esp32p4="RSA-3072、ECDSA-256 或 ECDSA-192", esp32h21="RSA-3072", esp32c5="RSA-3072、ECDSA-384、ECDSA-256 或 ECDSA-192"} -{IDF_TARGET_SECURE_BOOT_OPTION_TEXT:default="", esp32c6, esp32h2, esp32p4, esp32h21="推荐使用 RSA,其验证时间更短。可以在菜单中选择 RSA 或 ECDSA 方案。", esp32c5="推荐使用 ECDSA,其验证时间更短。可以在菜单中选择 RSA 或 ECDSA 方案。"} +{IDF_TARGET_SECURE_BOOT_OPTION_TEXT:default="", esp32c6, esp32h2, esp32p4="推荐使用 RSA,其验证时间更短。可以在菜单中选择 RSA 或 ECDSA 方案。", esp32c5="推荐使用 ECDSA,其验证时间更短。可以在菜单中选择 RSA 或 ECDSA 方案。"} {IDF_TARGET_SBV2_SCHEME_RECOMMENDATION:default="如果需要快速启动,推荐使用 RSA;如果需要较短的密钥长度,建议使用 ECDSA。", esp32c5="如果需要快速启动且需要较短的密钥长度,建议使用 ECDSA。"} @@ -52,6 +52,18 @@ 在本指南中,最常用的命令形式为 ``idf.py secure-``,这是对应 ``espsecure.py `` 的封装。基于 ``idf.py`` 的命令能提供更好的用户体验,但与基于 ``espsecure.py`` 的命令相比,可能会损失一部分高级功能。 +.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and SOC_SECURE_BOOT_V2_RSA + + .. warning:: + + 在 {IDF_TARGET_NAME} 上,基于 ECDSA 的 Secure Boot V2 方案在某些输入向量下无法正常工作,因此**不推荐使用**。请改用基于 RSA 的 Secure Boot V2 方案。如果仍需使用基于 ECDSA 的方案,请启用 :ref:`CONFIG_SECURE_BOOT_INSECURE` 和 :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`。该问题将在未来的硬件 ECO 版本中修复,详情请参阅硬件勘误文档。 + +.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and not SOC_SECURE_BOOT_V2_RSA + + .. warning:: + + 在 {IDF_TARGET_NAME} 上,基于 ECDSA 的 Secure Boot V2 方案在某些输入向量下存在漏洞,因此**不推荐用于量产**。如果仍需使用基于 ECDSA 的 Secure Boot V2 方案,请启用 :ref:`CONFIG_SECURE_BOOT_INSECURE` 和 :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`。该问题将在未来的硬件 ECO 版本中修复,详情请参阅硬件勘误文档。 + 背景 ---- diff --git a/examples/system/efuse/sdkconfig.ci.virt_sb_v2_and_fe.esp32c5 b/examples/system/efuse/sdkconfig.ci.virt_sb_v2_and_fe.esp32c5 index 08c00f84374..22226e8fdb6 100644 --- a/examples/system/efuse/sdkconfig.ci.virt_sb_v2_and_fe.esp32c5 +++ b/examples/system/efuse/sdkconfig.ci.virt_sb_v2_and_fe.esp32c5 @@ -8,6 +8,10 @@ CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="test/partitions_efuse_emul.csv" CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT_V2_ENABLED=y +# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs +CONFIG_SECURE_BOOT_INSECURE=y +CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y +CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp256.pem" CONFIG_SECURE_ENABLE_SECURE_ROM_DL_MODE=y diff --git a/examples/system/efuse/sdkconfig.ci.virt_sb_v2_and_fe.esp32c61 b/examples/system/efuse/sdkconfig.ci.virt_sb_v2_and_fe.esp32c61 index 3f64d4614e2..468c9477ada 100644 --- a/examples/system/efuse/sdkconfig.ci.virt_sb_v2_and_fe.esp32c61 +++ b/examples/system/efuse/sdkconfig.ci.virt_sb_v2_and_fe.esp32c61 @@ -8,6 +8,10 @@ CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="test/partitions_efuse_emul.csv" CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT_V2_ENABLED=y +# ECDSA based Secure Boot V2 is not recommended on ESP32-C61 and must be force-enabled. +CONFIG_SECURE_BOOT_INSECURE=y +CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y +CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp256.pem" CONFIG_SECURE_ENABLE_SECURE_ROM_DL_MODE=y diff --git a/examples/system/efuse/sdkconfig.ci.virt_sb_v2_ecdsa_p384_and_fe.esp32c5 b/examples/system/efuse/sdkconfig.ci.virt_sb_v2_ecdsa_p384_and_fe.esp32c5 index 4152d2e9c8b..71d9d0c0fc7 100644 --- a/examples/system/efuse/sdkconfig.ci.virt_sb_v2_ecdsa_p384_and_fe.esp32c5 +++ b/examples/system/efuse/sdkconfig.ci.virt_sb_v2_ecdsa_p384_and_fe.esp32c5 @@ -8,6 +8,9 @@ CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="test/partitions_efuse_emul.csv" CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT_V2_ENABLED=y +# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs +CONFIG_SECURE_BOOT_INSECURE=y +CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS=y CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp384.pem" diff --git a/examples/system/efuse/sdkconfig.ci.virt_secure_boot_v2.esp32c5 b/examples/system/efuse/sdkconfig.ci.virt_secure_boot_v2.esp32c5 index 08ebca9f6ba..687b15f1e82 100644 --- a/examples/system/efuse/sdkconfig.ci.virt_secure_boot_v2.esp32c5 +++ b/examples/system/efuse/sdkconfig.ci.virt_secure_boot_v2.esp32c5 @@ -8,6 +8,10 @@ CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="test/partitions_efuse_emul.csv" CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT_V2_ENABLED=y +# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs +CONFIG_SECURE_BOOT_INSECURE=y +CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y +CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp256.pem" CONFIG_SECURE_INSECURE_ALLOW_DL_MODE=y diff --git a/examples/system/efuse/sdkconfig.ci.virt_secure_boot_v2.esp32c61 b/examples/system/efuse/sdkconfig.ci.virt_secure_boot_v2.esp32c61 index adeb362d9ee..f0ada0868be 100644 --- a/examples/system/efuse/sdkconfig.ci.virt_secure_boot_v2.esp32c61 +++ b/examples/system/efuse/sdkconfig.ci.virt_secure_boot_v2.esp32c61 @@ -8,6 +8,10 @@ CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="test/partitions_efuse_emul.csv" CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT_V2_ENABLED=y +# ECDSA based Secure Boot V2 is not recommended on ESP32-C61 and must be force-enabled. +CONFIG_SECURE_BOOT_INSECURE=y +CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y +CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp256.pem" CONFIG_SECURE_INSECURE_ALLOW_DL_MODE=y diff --git a/examples/system/efuse/sdkconfig.ci.virt_secure_boot_v2_ecdsa_p384.esp32c5 b/examples/system/efuse/sdkconfig.ci.virt_secure_boot_v2_ecdsa_p384.esp32c5 index 9264a22b99e..7096272a85d 100644 --- a/examples/system/efuse/sdkconfig.ci.virt_secure_boot_v2_ecdsa_p384.esp32c5 +++ b/examples/system/efuse/sdkconfig.ci.virt_secure_boot_v2_ecdsa_p384.esp32c5 @@ -8,6 +8,9 @@ CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="test/partitions_efuse_emul.csv" CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT_V2_ENABLED=y +# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs +CONFIG_SECURE_BOOT_INSECURE=y +CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS=y CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp384.pem" diff --git a/examples/system/ota/partitions_ota/sdkconfig.ci.virt_sb_v2_and_fe.esp32c61 b/examples/system/ota/partitions_ota/sdkconfig.ci.virt_sb_v2_and_fe.esp32c61 new file mode 100644 index 00000000000..dd383a0e946 --- /dev/null +++ b/examples/system/ota/partitions_ota/sdkconfig.ci.virt_sb_v2_and_fe.esp32c61 @@ -0,0 +1,6 @@ +# ESP32-C61 has no RSA based Secure Boot V2; the ECDSA scheme is gated behind the +# insecure option (see SECURE_BOOT_V2_ECDSA_INSECURE), so force-enable it and use an ECDSA key. +CONFIG_SECURE_BOOT_INSECURE=y +CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y +CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y +CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa.pem" diff --git a/examples/system/ota/partitions_ota/sdkconfig.ci.virt_sb_v2_and_fe_2.esp32c61 b/examples/system/ota/partitions_ota/sdkconfig.ci.virt_sb_v2_and_fe_2.esp32c61 new file mode 100644 index 00000000000..dd383a0e946 --- /dev/null +++ b/examples/system/ota/partitions_ota/sdkconfig.ci.virt_sb_v2_and_fe_2.esp32c61 @@ -0,0 +1,6 @@ +# ESP32-C61 has no RSA based Secure Boot V2; the ECDSA scheme is gated behind the +# insecure option (see SECURE_BOOT_V2_ECDSA_INSECURE), so force-enable it and use an ECDSA key. +CONFIG_SECURE_BOOT_INSECURE=y +CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y +CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y +CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa.pem" diff --git a/tools/test_apps/build_system/bootloader/sdkconfig.ci.secure_boot.ecdsa.esp32h2 b/tools/test_apps/build_system/bootloader/sdkconfig.ci.secure_boot.ecdsa.esp32h2 index d1e1ff2a7ab..116cbc0df37 100644 --- a/tools/test_apps/build_system/bootloader/sdkconfig.ci.secure_boot.ecdsa.esp32h2 +++ b/tools/test_apps/build_system/bootloader/sdkconfig.ci.secure_boot.ecdsa.esp32h2 @@ -1,6 +1,9 @@ CONFIG_IDF_TARGET="esp32h2" CONFIG_IDF_TARGET_ESP32H2=y +# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs +CONFIG_SECURE_BOOT_INSECURE=y +CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y CONFIG_SECURE_BOOT_V2_ECDSA_ENABLED=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS=y diff --git a/tools/test_apps/build_system/bootloader/sdkconfig.defaults.esp32c61 b/tools/test_apps/build_system/bootloader/sdkconfig.defaults.esp32c61 new file mode 100644 index 00000000000..d3845b46592 --- /dev/null +++ b/tools/test_apps/build_system/bootloader/sdkconfig.defaults.esp32c61 @@ -0,0 +1,6 @@ +# ESP32-C61 has no RSA based Secure Boot V2; only the ECDSA scheme exists, and it +# is not functional for certain input vectors (see SECURE_BOOT_V2_ECDSA_INSECURE), +# so it is gated behind the insecure option. Force-enable it for this build-only test. +CONFIG_SECURE_BOOT_INSECURE=y +CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y +CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y diff --git a/tools/test_apps/security/.build-test-rules.yml b/tools/test_apps/security/.build-test-rules.yml index cb02072ea3c..2aadd7e564c 100644 --- a/tools/test_apps/security/.build-test-rules.yml +++ b/tools/test_apps/security/.build-test-rules.yml @@ -7,6 +7,8 @@ tools/test_apps/security/secure_boot: disable: - if: CONFIG_NAME != "qemu" or IDF_TARGET == "linux" reason: Skipping redundant CI builds for all the targets. + - if: IDF_TARGET == "esp32h4" + reason: Secure Boot V2 is disabled on ESP32-H4 (ECDSA-only, vulnerable scheme), so the secure boot test app does not apply. tools/test_apps/security/signed_app_no_secure_boot: enable: diff --git a/tools/test_apps/security/secure_boot/README.md b/tools/test_apps/security/secure_boot/README.md index 1c251de5bca..5c744e51ccc 100644 --- a/tools/test_apps/security/secure_boot/README.md +++ b/tools/test_apps/security/secure_boot/README.md @@ -1,5 +1,5 @@ -| Supported Targets | ESP32 | ESP32-C2 | ESP32-C3 | ESP32-C5 | ESP32-C6 | ESP32-C61 | ESP32-H2 | ESP32-H21 | ESP32-H4 | ESP32-P4 | ESP32-S2 | ESP32-S3 | -| ----------------- | ----- | -------- | -------- | -------- | -------- | --------- | -------- | --------- | -------- | -------- | -------- | -------- | +| Supported Targets | ESP32 | ESP32-C2 | ESP32-C3 | ESP32-C5 | ESP32-C6 | ESP32-C61 | ESP32-H2 | ESP32-H21 | ESP32-P4 | ESP32-S2 | ESP32-S3 | +| ----------------- | ----- | -------- | -------- | -------- | -------- | --------- | -------- | --------- | -------- | -------- | -------- | # Secure Boot diff --git a/tools/test_apps/security/secure_boot/pytest_secure_boot.py b/tools/test_apps/security/secure_boot/pytest_secure_boot.py index 4e23e724a87..e767ee71171 100644 --- a/tools/test_apps/security/secure_boot/pytest_secure_boot.py +++ b/tools/test_apps/security/secure_boot/pytest_secure_boot.py @@ -40,14 +40,15 @@ SECURE_BOOT_RSA_TARGETS = [ 'esp32c3', 'esp32c5', 'esp32c6', - 'esp32c61', 'esp32h2', 'esp32h21', 'esp32s2', 'esp32s3', 'esp32p4', ] -SECURE_BOOT_ECDSA_TARGETS = ['esp32c2', 'esp32c5', 'esp32c6', 'esp32c61', 'esp32h2', 'esp32h21', 'esp32p4'] +# ESP32-H21 is a preview target with ECDSA based Secure Boot V2 marked unsupported, +# so it is excluded here. +SECURE_BOOT_ECDSA_TARGETS = ['esp32c2', 'esp32c5', 'esp32c6', 'esp32c61', 'esp32h2', 'esp32p4'] SECURE_BOOT_ECDSA_P384_TARGETS = ['esp32c5'] CONFIGS_SECURE_BOOT_ECDSA = list( diff --git a/tools/test_apps/security/secure_boot/sdkconfig.ci.ecdsa_p256 b/tools/test_apps/security/secure_boot/sdkconfig.ci.ecdsa_p256 index b70b07cdf18..8f285355d77 100644 --- a/tools/test_apps/security/secure_boot/sdkconfig.ci.ecdsa_p256 +++ b/tools/test_apps/security/secure_boot/sdkconfig.ci.ecdsa_p256 @@ -3,6 +3,10 @@ CONFIG_PARTITION_TABLE_OFFSET=0xD000 CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT_V2_ENABLED=y +# ECDSA based Secure Boot V2 is not recommended on the affected SoCs (see +# SECURE_BOOT_V2_ECDSA_INSECURE) and must be force-enabled to be selected. +CONFIG_SECURE_BOOT_INSECURE=y +CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS=y CONFIG_SECURE_BOOT_SIGNING_KEY="test_ecdsa_p256_key.pem" diff --git a/tools/test_apps/security/secure_boot/sdkconfig.ci.ecdsa_p384 b/tools/test_apps/security/secure_boot/sdkconfig.ci.ecdsa_p384 index d46c56ea0a4..6addb07b9b4 100644 --- a/tools/test_apps/security/secure_boot/sdkconfig.ci.ecdsa_p384 +++ b/tools/test_apps/security/secure_boot/sdkconfig.ci.ecdsa_p384 @@ -3,6 +3,10 @@ CONFIG_PARTITION_TABLE_OFFSET=0xD000 CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT_V2_ENABLED=y +# ECDSA based Secure Boot V2 is not recommended on the affected SoCs (see +# SECURE_BOOT_V2_ECDSA_INSECURE) and must be force-enabled to be selected. +CONFIG_SECURE_BOOT_INSECURE=y +CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS=y CONFIG_SECURE_BOOT_SIGNING_KEY="test_ecdsa_p384_key.pem"