diff --git a/components/esp_security/src/init.c b/components/esp_security/src/init.c index 51adb01edf6..207706b0064 100644 --- a/components/esp_security/src/init.c +++ b/components/esp_security/src/init.c @@ -13,6 +13,9 @@ #include "esp_security_priv.h" #include "esp_err.h" #include "hal/efuse_hal.h" +#if SOC_ECDSA_P192_CURVE_DEFAULT_DISABLED +#include "hal/ecdsa_ll.h" +#endif #if SOC_KEY_MANAGER_ECDSA_KEY_DEPLOY || SOC_KEY_MANAGER_FE_KEY_DEPLOY #include "hal/key_mgr_ll.h" @@ -68,6 +71,17 @@ ESP_SYSTEM_INIT_FN(esp_security_init, SECONDARY, BIT(0), 103) } #endif +#if CONFIG_SECURE_BOOT_V2_ENABLED && SOC_ECDSA_P192_CURVE_DEFAULT_DISABLED + // Also write protect the ECDSA_CURVE_MODE efuse bit. + if (ecdsa_ll_is_configurable_curve_supported()) { + err = esp_efuse_write_field_bit(ESP_EFUSE_WR_DIS_ECDSA_CURVE_MODE); + if (err != ESP_OK) { + ESP_LOGE(TAG, "Failed to write protect the ECDSA_CURVE_MODE efuse bit."); + return err; + } + } +#endif + err = ESP_OK; return err; } diff --git a/docs/en/security/security-features-enablement-workflows.rst b/docs/en/security/security-features-enablement-workflows.rst index 9ff9f717896..e021022320a 100644 --- a/docs/en/security/security-features-enablement-workflows.rst +++ b/docs/en/security/security-features-enablement-workflows.rst @@ -485,6 +485,7 @@ In this workflow we shall use ``espsecure`` tool to generate signing keys and us :SOC_EFUSE_DIS_USB_JTAG: - ``DIS_USB_JTAG``: Disable USB switch to JTAG. :SOC_EFUSE_DIS_PAD_JTAG: - ``DIS_PAD_JTAG``: Disable JTAG permanently. :SOC_EFUSE_REVOKE_BOOT_KEY_DIGESTS: - ``SECURE_BOOT_AGGRESSIVE_REVOKE``: Aggressive revocation of key digests, see :ref:`secure-boot-v2-aggressive-key-revocation` for more details. + :SOC_ECDSA_P192_CURVE_DEFAULT_DISABLED: - ``WR_DIS_ECDSA_CURVE_MODE``: Disable writing to the ECDSA curve mode eFuse bit (As this write protection bit is shared with ECC_FORCE_CONST_TIME, it is recommended to write protect this bit only after configuring the ECC_FORCE_CONST_TIME efuse). The respective eFuses can be burned by running: