mirror of
https://github.com/espressif/esp-idf.git
synced 2026-09-22 13:01:16 +03:00
Merge branch 'fix/disable_secure_boot_v2_ecdsa_v5.4' into 'release/v5.4'
Fix/disable secure boot v2 ecdsa (v5.4) See merge request espressif/esp-idf!49473
This commit is contained in:
@@ -534,6 +534,18 @@ menu "Security features"
|
||||
default y
|
||||
depends on SOC_SECURE_BOOT_V2_ECC
|
||||
|
||||
# ECDSA based Secure Boot V2 is not functional for certain input vectors on these
|
||||
# SoCs. The scheme stays available but, for hardware Secure Boot, must be explicitly
|
||||
# turned on via SECURE_BOOT_V2_FORCE_ENABLE_ECDSA under "Allow potentially insecure
|
||||
# options" (CONFIG_SECURE_BOOT_INSECURE).
|
||||
#
|
||||
# TODO: IDF-15721 - drop a SoC from this list once a fixing hardware ECO revision
|
||||
# ships, gating on the selected minimum chip revision, e.g.:
|
||||
# default y if IDF_TARGET_ESP32C5 && ESP32C5_REV_MIN_FULL < <fixed_rev>
|
||||
config SECURE_BOOT_V2_ECDSA_INSECURE
|
||||
bool
|
||||
default y if IDF_TARGET_ESP32H2 || IDF_TARGET_ESP32P4
|
||||
|
||||
config SECURE_BOOT_V1_SUPPORTED
|
||||
bool
|
||||
default y
|
||||
@@ -604,6 +616,10 @@ menu "Security features"
|
||||
config SECURE_SIGNED_APPS_ECDSA_V2_SCHEME
|
||||
bool "ECDSA (V2)"
|
||||
depends on SECURE_BOOT_V2_ECC_SUPPORTED && (SECURE_SIGNED_APPS_NO_SECURE_BOOT || SECURE_BOOT_V2_ENABLED)
|
||||
# On the affected SoCs (SECURE_BOOT_V2_ECDSA_INSECURE), hardware Secure Boot with ECDSA
|
||||
# is offered only when SECURE_BOOT_V2_FORCE_ENABLE_ECDSA is explicitly set. App signing
|
||||
# without hardware Secure Boot is not affected by this gate.
|
||||
depends on !SECURE_BOOT_V2_ENABLED || (!SECURE_BOOT_V2_ECDSA_INSECURE || SECURE_BOOT_V2_FORCE_ENABLE_ECDSA)
|
||||
help
|
||||
For Secure boot V2 (e.g., ESP32-C2 SoC), appends ECDSA based signature block to the application.
|
||||
Refer to documentation before enabling.
|
||||
@@ -962,6 +978,19 @@ menu "Security features"
|
||||
# it's possible for the insecure menu to be disabled but the insecure option
|
||||
# to remain on which is very bad.)
|
||||
|
||||
config SECURE_BOOT_V2_FORCE_ENABLE_ECDSA
|
||||
bool "Force enable ECDSA based Secure Boot V2"
|
||||
depends on SECURE_BOOT_INSECURE && SECURE_BOOT_V2_ECDSA_INSECURE
|
||||
default n
|
||||
help
|
||||
ECDSA based Secure Boot V2 is not functional for certain input vectors on this SoC
|
||||
and is therefore not offered by default. Refer to the hardware errata document for
|
||||
details.
|
||||
|
||||
Setting this option re-enables the ECDSA based Secure Boot V2 signing scheme despite
|
||||
the known vulnerability. Only set this option if you fully understand the risk. RSA
|
||||
based Secure Boot V2 is the recommended scheme on SoCs that support it.
|
||||
|
||||
config SECURE_BOOT_ALLOW_ROM_BASIC
|
||||
bool "Leave ROM BASIC Interpreter available on reset"
|
||||
depends on (SECURE_BOOT_INSECURE || SECURE_FLASH_ENCRYPTION_MODE_DEVELOPMENT) && IDF_TARGET_ESP32
|
||||
|
||||
@@ -46,6 +46,18 @@ Secure Boot v2
|
||||
|
||||
In this guide, most used commands are in the form of ``idf.py secure-<command>``, which is a wrapper around corresponding ``espsecure.py <command>``. The ``idf.py`` based commands provides more user-friendly experience, although may lack some of the advanced functionality of their ``espsecure.py`` based counterparts.
|
||||
|
||||
.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and SOC_SECURE_BOOT_V2_RSA
|
||||
|
||||
.. warning::
|
||||
|
||||
On {IDF_TARGET_NAME}, the ECDSA based Secure Boot V2 scheme is not functional for certain input vectors and is therefore **not recommended**. Please use the RSA based Secure Boot V2 scheme instead. To use the ECDSA based scheme regardless of this limitation, enable :ref:`CONFIG_SECURE_BOOT_INSECURE` and :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`. This issue will be fixed in a future hardware ECO revision; refer to the hardware errata document for details.
|
||||
|
||||
.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and not SOC_SECURE_BOOT_V2_RSA
|
||||
|
||||
.. warning::
|
||||
|
||||
On {IDF_TARGET_NAME}, the ECDSA based Secure Boot V2 scheme is vulnerable for certain input vectors and is therefore **not recommended for production**. To use the ECDSA based Secure Boot V2 scheme regardless of this limitation, enable :ref:`CONFIG_SECURE_BOOT_INSECURE` and :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`. This issue will be fixed in a future hardware ECO revision; refer to the hardware errata document for details.
|
||||
|
||||
Background
|
||||
----------
|
||||
|
||||
|
||||
@@ -46,6 +46,18 @@
|
||||
|
||||
在本指南中,最常用的命令形式为 ``idf.py secure-<command>``,这是对应 ``espsecure.py <command>`` 的封装。基于 ``idf.py`` 的命令能提供更好的用户体验,但与基于 ``espsecure.py`` 的命令相比,可能会损失一部分高级功能。
|
||||
|
||||
.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and SOC_SECURE_BOOT_V2_RSA
|
||||
|
||||
.. warning::
|
||||
|
||||
在 {IDF_TARGET_NAME} 上,基于 ECDSA 的 Secure Boot V2 方案在某些输入向量下无法正常工作,因此**不推荐使用**。请改用基于 RSA 的 Secure Boot V2 方案。如果仍需使用基于 ECDSA 的方案,请启用 :ref:`CONFIG_SECURE_BOOT_INSECURE` 和 :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`。该问题将在未来的硬件 ECO 版本中修复,详情请参阅硬件勘误文档。
|
||||
|
||||
.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and not SOC_SECURE_BOOT_V2_RSA
|
||||
|
||||
.. warning::
|
||||
|
||||
在 {IDF_TARGET_NAME} 上,基于 ECDSA 的 Secure Boot V2 方案在某些输入向量下存在漏洞,因此**不推荐用于量产**。如果仍需使用基于 ECDSA 的 Secure Boot V2 方案,请启用 :ref:`CONFIG_SECURE_BOOT_INSECURE` 和 :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`。该问题将在未来的硬件 ECO 版本中修复,详情请参阅硬件勘误文档。
|
||||
|
||||
背景
|
||||
----------
|
||||
|
||||
|
||||
@@ -1,6 +1,9 @@
|
||||
CONFIG_IDF_TARGET="esp32h2"
|
||||
CONFIG_IDF_TARGET_ESP32H2=y
|
||||
|
||||
# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs
|
||||
CONFIG_SECURE_BOOT_INSECURE=y
|
||||
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
|
||||
CONFIG_SECURE_BOOT_V2_ECDSA_ENABLED=y
|
||||
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
|
||||
CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS=y
|
||||
|
||||
Reference in New Issue
Block a user