mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 18:50:34 +03:00
Merge branch 'fix/disable_secure_boot_v2_ecdsa' into 'master'
Fix/disable secure boot v2 ecdsa See merge request espressif/esp-idf!48834
This commit is contained in:
@@ -1,6 +1,9 @@
|
||||
CONFIG_IDF_TARGET="esp32h2"
|
||||
CONFIG_IDF_TARGET_ESP32H2=y
|
||||
|
||||
# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs
|
||||
CONFIG_SECURE_BOOT_INSECURE=y
|
||||
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
|
||||
CONFIG_SECURE_BOOT_V2_ECDSA_ENABLED=y
|
||||
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
|
||||
CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS=y
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
# ESP32-C61 has no RSA based Secure Boot V2; only the ECDSA scheme exists, and it
|
||||
# is not functional for certain input vectors (see SECURE_BOOT_V2_ECDSA_INSECURE),
|
||||
# so it is gated behind the insecure option. Force-enable it for this build-only test.
|
||||
CONFIG_SECURE_BOOT_INSECURE=y
|
||||
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
|
||||
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
|
||||
@@ -7,6 +7,8 @@ tools/test_apps/security/secure_boot:
|
||||
disable:
|
||||
- if: CONFIG_NAME != "qemu" or IDF_TARGET == "linux"
|
||||
reason: Skipping redundant CI builds for all the targets.
|
||||
- if: IDF_TARGET == "esp32h4"
|
||||
reason: Secure Boot V2 is disabled on ESP32-H4 (ECDSA-only, vulnerable scheme), so the secure boot test app does not apply.
|
||||
|
||||
tools/test_apps/security/signed_app_no_secure_boot:
|
||||
enable:
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
| Supported Targets | ESP32 | ESP32-C2 | ESP32-C3 | ESP32-C5 | ESP32-C6 | ESP32-C61 | ESP32-H2 | ESP32-H21 | ESP32-H4 | ESP32-P4 | ESP32-S2 | ESP32-S3 |
|
||||
| ----------------- | ----- | -------- | -------- | -------- | -------- | --------- | -------- | --------- | -------- | -------- | -------- | -------- |
|
||||
| Supported Targets | ESP32 | ESP32-C2 | ESP32-C3 | ESP32-C5 | ESP32-C6 | ESP32-C61 | ESP32-H2 | ESP32-H21 | ESP32-P4 | ESP32-S2 | ESP32-S3 |
|
||||
| ----------------- | ----- | -------- | -------- | -------- | -------- | --------- | -------- | --------- | -------- | -------- | -------- |
|
||||
|
||||
# Secure Boot
|
||||
|
||||
|
||||
@@ -38,15 +38,15 @@ SECURE_BOOT_RSA_TARGETS = [
|
||||
'esp32c3',
|
||||
'esp32c5',
|
||||
'esp32c6',
|
||||
'esp32c61',
|
||||
'esp32h2',
|
||||
'esp32h21',
|
||||
'esp32s2',
|
||||
'esp32s3',
|
||||
'esp32p4',
|
||||
'esp32h4',
|
||||
]
|
||||
SECURE_BOOT_ECDSA_TARGETS = ['esp32c2', 'esp32c5', 'esp32c6', 'esp32c61', 'esp32h2', 'esp32h21', 'esp32p4', 'esp32h4']
|
||||
# ESP32-H4/H21 are preview targets with ECDSA based Secure Boot V2 marked unsupported,
|
||||
# and ESP32-H4 has Secure Boot disabled entirely, so they are excluded here.
|
||||
SECURE_BOOT_ECDSA_TARGETS = ['esp32c2', 'esp32c5', 'esp32c6', 'esp32c61', 'esp32h2', 'esp32p4']
|
||||
SECURE_BOOT_ECDSA_P384_TARGETS = ['esp32c5']
|
||||
|
||||
CONFIGS_SECURE_BOOT_ECDSA = list(
|
||||
|
||||
@@ -3,6 +3,10 @@ CONFIG_PARTITION_TABLE_OFFSET=0xD000
|
||||
|
||||
CONFIG_SECURE_BOOT=y
|
||||
CONFIG_SECURE_BOOT_V2_ENABLED=y
|
||||
# ECDSA based Secure Boot V2 is not recommended on the affected SoCs (see
|
||||
# SECURE_BOOT_V2_ECDSA_INSECURE) and must be force-enabled to be selected.
|
||||
CONFIG_SECURE_BOOT_INSECURE=y
|
||||
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
|
||||
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
|
||||
CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS=y
|
||||
CONFIG_SECURE_BOOT_SIGNING_KEY="test_ecdsa_p256_key.pem"
|
||||
|
||||
@@ -3,6 +3,10 @@ CONFIG_PARTITION_TABLE_OFFSET=0xD000
|
||||
|
||||
CONFIG_SECURE_BOOT=y
|
||||
CONFIG_SECURE_BOOT_V2_ENABLED=y
|
||||
# ECDSA based Secure Boot V2 is not recommended on the affected SoCs (see
|
||||
# SECURE_BOOT_V2_ECDSA_INSECURE) and must be force-enabled to be selected.
|
||||
CONFIG_SECURE_BOOT_INSECURE=y
|
||||
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
|
||||
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
|
||||
CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS=y
|
||||
CONFIG_SECURE_BOOT_SIGNING_KEY="test_ecdsa_p384_key.pem"
|
||||
|
||||
Reference in New Issue
Block a user