Merge branch 'fix/disable_secure_boot_v2_ecdsa_v5.5' into 'release/v5.5'

Fix/disable secure boot v2 ecdsa (v5.5)

See merge request espressif/esp-idf!49472
This commit is contained in:
Jiang Jiang Jian
2026-06-17 12:00:48 +08:00
23 changed files with 136 additions and 12 deletions
@@ -0,0 +1,6 @@
# ESP32-C61 has no RSA based Secure Boot V2; the ECDSA scheme is gated behind the insecure
# option (see SECURE_BOOT_V2_ECDSA_INSECURE), so force-enable it and use an ECDSA key.
CONFIG_SECURE_BOOT_INSECURE=y
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
CONFIG_SECURE_BOOT_SIGNING_KEY="test_keys/secure_boot_signing_key_ecdsa_p256.pem"
@@ -0,0 +1,6 @@
# ESP32-C61 has no RSA based Secure Boot V2; the ECDSA scheme is gated behind the insecure
# option (see SECURE_BOOT_V2_ECDSA_INSECURE), so force-enable it and use an ECDSA key.
CONFIG_SECURE_BOOT_INSECURE=y
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
CONFIG_SECURE_BOOT_SIGNING_KEY="test_keys/secure_boot_signing_key_ecdsa_p256.pem"
@@ -0,0 +1,5 @@
-----BEGIN EC PRIVATE KEY-----
MHcCAQEEIFFwmnckyThKZQMV40ceAQm8OxwP1aI0dvWt3P9/4VAgoAoGCCqGSM49
AwEHoUQDQgAEwMObAE6S2QjA4vYnifYGDO/Jd9Pr9p2CWKxQVTsziuqz2pJxzjcQ
zJT6Aj30auml+oIGvNwBnhoZ3v5SCyzqOw==
-----END EC PRIVATE KEY-----