diff --git a/components/bootloader/Kconfig.projbuild b/components/bootloader/Kconfig.projbuild index 5ad8faf1390..7b1ba1588a4 100644 --- a/components/bootloader/Kconfig.projbuild +++ b/components/bootloader/Kconfig.projbuild @@ -530,6 +530,18 @@ menu "Security features" default y depends on SOC_SECURE_BOOT_V2_ECC + # ECDSA based Secure Boot V2 is not functional for certain input vectors on these + # SoCs. The scheme stays available but, for hardware Secure Boot, must be explicitly + # turned on via SECURE_BOOT_V2_FORCE_ENABLE_ECDSA under "Allow potentially insecure + # options" (CONFIG_SECURE_BOOT_INSECURE). + # + # TODO: IDF-15721 - drop a SoC from this list once a fixing hardware ECO revision + # ships, gating on the selected minimum chip revision, e.g.: + # default y if IDF_TARGET_ESP32C5 && ESP32C5_REV_MIN_FULL < + config SECURE_BOOT_V2_ECDSA_INSECURE + bool + default y if IDF_TARGET_ESP32H2 + config SECURE_BOOT_V1_SUPPORTED bool default y @@ -600,6 +612,10 @@ menu "Security features" config SECURE_SIGNED_APPS_ECDSA_V2_SCHEME bool "ECDSA (V2)" depends on SECURE_BOOT_V2_ECC_SUPPORTED && (SECURE_SIGNED_APPS_NO_SECURE_BOOT || SECURE_BOOT_V2_ENABLED) + # On the affected SoCs (SECURE_BOOT_V2_ECDSA_INSECURE), hardware Secure Boot with ECDSA + # is offered only when SECURE_BOOT_V2_FORCE_ENABLE_ECDSA is explicitly set. App signing + # without hardware Secure Boot is not affected by this gate. + depends on !SECURE_BOOT_V2_ENABLED || (!SECURE_BOOT_V2_ECDSA_INSECURE || SECURE_BOOT_V2_FORCE_ENABLE_ECDSA) help For Secure boot V2 (e.g., ESP32-C2 SoC), appends ECDSA based signature block to the application. Refer to documentation before enabling. @@ -958,6 +974,19 @@ menu "Security features" # it's possible for the insecure menu to be disabled but the insecure option # to remain on which is very bad.) + config SECURE_BOOT_V2_FORCE_ENABLE_ECDSA + bool "Force enable ECDSA based Secure Boot V2" + depends on SECURE_BOOT_INSECURE && SECURE_BOOT_V2_ECDSA_INSECURE + default n + help + ECDSA based Secure Boot V2 is not functional for certain input vectors on this SoC + and is therefore not offered by default. Refer to the hardware errata document for + details. + + Setting this option re-enables the ECDSA based Secure Boot V2 signing scheme despite + the known vulnerability. Only set this option if you fully understand the risk. RSA + based Secure Boot V2 is the recommended scheme on SoCs that support it. + config SECURE_BOOT_ALLOW_ROM_BASIC bool "Leave ROM BASIC Interpreter available on reset" depends on (SECURE_BOOT_INSECURE || SECURE_FLASH_ENCRYPTION_MODE_DEVELOPMENT) && IDF_TARGET_ESP32 diff --git a/docs/en/security/secure-boot-v2.rst b/docs/en/security/secure-boot-v2.rst index b73d0e01cc8..952ceeaf7c0 100644 --- a/docs/en/security/secure-boot-v2.rst +++ b/docs/en/security/secure-boot-v2.rst @@ -39,6 +39,18 @@ Secure Boot V2 ``Secure Boot V2`` is available for ESP32-C3 from ECO3 onwards. To use these options in menuconfig, set :ref:`CONFIG_ESP32C3_REV_MIN` greater than or equal to `Rev 3`. +.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and SOC_SECURE_BOOT_V2_RSA + + .. warning:: + + On {IDF_TARGET_NAME}, the ECDSA based Secure Boot V2 scheme is not functional for certain input vectors and is therefore **not recommended**. Please use the RSA based Secure Boot V2 scheme instead. To use the ECDSA based scheme regardless of this limitation, enable :ref:`CONFIG_SECURE_BOOT_INSECURE` and :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`. This issue will be fixed in a future hardware ECO revision; refer to the hardware errata document for details. + +.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and not SOC_SECURE_BOOT_V2_RSA + + .. warning:: + + On {IDF_TARGET_NAME}, the ECDSA based Secure Boot V2 scheme is vulnerable for certain input vectors and is therefore **not recommended for production**. To use the ECDSA based Secure Boot V2 scheme regardless of this limitation, enable :ref:`CONFIG_SECURE_BOOT_INSECURE` and :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`. This issue will be fixed in a future hardware ECO revision; refer to the hardware errata document for details. + Background ----------