Merge branch 'fix/disable_secure_boot_v2_ecdsa' into 'master'

Fix/disable secure boot v2 ecdsa

See merge request espressif/esp-idf!48834
This commit is contained in:
Aditya Patwardhan
2026-06-09 23:46:11 +05:30
22 changed files with 119 additions and 17 deletions
+29
View File
@@ -476,6 +476,18 @@ menu "Security features"
default y default y
depends on SOC_SECURE_BOOT_V2_ECC depends on SOC_SECURE_BOOT_V2_ECC
# ECDSA based Secure Boot V2 is not functional for certain input vectors on these
# SoCs. The scheme stays available but, for hardware Secure Boot, must be explicitly
# turned on via SECURE_BOOT_V2_FORCE_ENABLE_ECDSA under "Allow potentially insecure
# options" (CONFIG_SECURE_BOOT_INSECURE).
#
# TODO: IDF-15721 - drop a SoC from this list once a fixing hardware ECO revision
# ships, gating on the selected minimum chip revision, e.g.:
# default y if IDF_TARGET_ESP32C5 && ESP32C5_REV_MIN_FULL < <fixed_rev>
config SECURE_BOOT_V2_ECDSA_INSECURE
bool
default y if IDF_TARGET_ESP32C5 || IDF_TARGET_ESP32C61 || IDF_TARGET_ESP32H2 || IDF_TARGET_ESP32P4
config SECURE_BOOT_V1_SUPPORTED config SECURE_BOOT_V1_SUPPORTED
bool bool
default y default y
@@ -547,6 +559,10 @@ menu "Security features"
config SECURE_SIGNED_APPS_ECDSA_V2_SCHEME config SECURE_SIGNED_APPS_ECDSA_V2_SCHEME
bool "ECDSA (V2)" bool "ECDSA (V2)"
depends on SECURE_BOOT_V2_ECC_SUPPORTED && (SECURE_SIGNED_APPS_NO_SECURE_BOOT || SECURE_BOOT_V2_ENABLED) depends on SECURE_BOOT_V2_ECC_SUPPORTED && (SECURE_SIGNED_APPS_NO_SECURE_BOOT || SECURE_BOOT_V2_ENABLED)
# On the affected SoCs (SECURE_BOOT_V2_ECDSA_INSECURE), hardware Secure Boot with ECDSA
# is offered only when SECURE_BOOT_V2_FORCE_ENABLE_ECDSA is explicitly set. App signing
# without hardware Secure Boot is not affected by this gate.
depends on !SECURE_BOOT_V2_ENABLED || (!SECURE_BOOT_V2_ECDSA_INSECURE || SECURE_BOOT_V2_FORCE_ENABLE_ECDSA)
help help
For Secure boot V2 (e.g., ESP32-C2 SoC), appends ECDSA based signature block to the application. For Secure boot V2 (e.g., ESP32-C2 SoC), appends ECDSA based signature block to the application.
Refer to documentation before enabling. Refer to documentation before enabling.
@@ -929,6 +945,19 @@ menu "Security features"
# it's possible for the insecure menu to be disabled but the insecure option # it's possible for the insecure menu to be disabled but the insecure option
# to remain on which is very bad.) # to remain on which is very bad.)
config SECURE_BOOT_V2_FORCE_ENABLE_ECDSA
bool "Force enable ECDSA based Secure Boot V2"
depends on SECURE_BOOT_INSECURE && SECURE_BOOT_V2_ECDSA_INSECURE
default n
help
ECDSA based Secure Boot V2 is not functional for certain input vectors on this SoC
and is therefore not offered by default. Refer to the hardware errata document for
details.
Setting this option re-enables the ECDSA based Secure Boot V2 signing scheme despite
the known vulnerability. Only set this option if you fully understand the risk. RSA
based Secure Boot V2 is the recommended scheme on SoCs that support it.
config SECURE_BOOT_ALLOW_ROM_BASIC config SECURE_BOOT_ALLOW_ROM_BASIC
bool "Leave ROM BASIC Interpreter available on reset" bool "Leave ROM BASIC Interpreter available on reset"
depends on (SECURE_BOOT_INSECURE || SECURE_FLASH_ENCRYPTION_MODE_DEVELOPMENT) && IDF_TARGET_ESP32 depends on (SECURE_BOOT_INSECURE || SECURE_FLASH_ENCRYPTION_MODE_DEVELOPMENT) && IDF_TARGET_ESP32
@@ -1,3 +1,6 @@
# NOTE: This sdkconfig is intended solely for CI build purposes - to verify ESP-TEE
# builds across various configurations - and is not intended for production use.
# Reducing TEE IRAM size # Reducing TEE IRAM size
# 29KB # 29KB
CONFIG_SECURE_TEE_IRAM_SIZE=0x7400 CONFIG_SECURE_TEE_IRAM_SIZE=0x7400
@@ -12,6 +15,9 @@ CONFIG_SECURE_TEE_EXT_FLASH_MEMPROT_SPI1=n
# Secure Boot # Secure Boot
CONFIG_PARTITION_TABLE_OFFSET=0xF000 CONFIG_PARTITION_TABLE_OFFSET=0xF000
CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT=y
# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs
CONFIG_SECURE_BOOT_INSECURE=y
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
CONFIG_SECURE_BOOT_BUILD_SIGNED_BINARIES=y CONFIG_SECURE_BOOT_BUILD_SIGNED_BINARIES=y
CONFIG_SECURE_BOOT_SIGNING_KEY="test_keys/secure_boot_signing_key_ecdsa_p256.pem" CONFIG_SECURE_BOOT_SIGNING_KEY="test_keys/secure_boot_signing_key_ecdsa_p256.pem"
@@ -1,3 +1,6 @@
# NOTE: This sdkconfig is intended solely for CI build purposes - to verify ESP-TEE
# builds across various configurations - and is not intended for production use.
# Increasing TEE I/DRAM sizes # Increasing TEE I/DRAM sizes
# 34KB # 34KB
CONFIG_SECURE_TEE_IRAM_SIZE=0x8800 CONFIG_SECURE_TEE_IRAM_SIZE=0x8800
@@ -9,6 +12,9 @@ CONFIG_PARTITION_TABLE_OFFSET=0xf000
# Secure Boot # Secure Boot
CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT=y
# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs
CONFIG_SECURE_BOOT_INSECURE=y
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
CONFIG_SECURE_BOOT_BUILD_SIGNED_BINARIES=y CONFIG_SECURE_BOOT_BUILD_SIGNED_BINARIES=y
CONFIG_SECURE_BOOT_SIGNING_KEY="test_keys/secure_boot_signing_key_ecdsa_p256.pem" CONFIG_SECURE_BOOT_SIGNING_KEY="test_keys/secure_boot_signing_key_ecdsa_p256.pem"
@@ -849,7 +849,7 @@ config SOC_SECURE_BOOT_V2_RSA
config SOC_SECURE_BOOT_V2_ECC config SOC_SECURE_BOOT_V2_ECC
bool bool
default y default n
config SOC_EFUSE_SECURE_BOOT_KEY_DIGESTS config SOC_EFUSE_SECURE_BOOT_KEY_DIGESTS
int int
@@ -386,7 +386,7 @@
/*-------------------------- Secure Boot CAPS----------------------------*/ /*-------------------------- Secure Boot CAPS----------------------------*/
#define SOC_SECURE_BOOT_V2_RSA 1 #define SOC_SECURE_BOOT_V2_RSA 1
#define SOC_SECURE_BOOT_V2_ECC 1 #define SOC_SECURE_BOOT_V2_ECC 0
#define SOC_EFUSE_SECURE_BOOT_KEY_DIGESTS 3 #define SOC_EFUSE_SECURE_BOOT_KEY_DIGESTS 3
#define SOC_EFUSE_REVOKE_BOOT_KEY_DIGESTS 1 #define SOC_EFUSE_REVOKE_BOOT_KEY_DIGESTS 1
#define SOC_SUPPORT_SECURE_BOOT_REVOKE_KEY 1 #define SOC_SUPPORT_SECURE_BOOT_REVOKE_KEY 1
@@ -161,7 +161,7 @@ config SOC_FLASH_ENC_SUPPORTED
config SOC_SECURE_BOOT_SUPPORTED config SOC_SECURE_BOOT_SUPPORTED
bool bool
default y default n
config SOC_BOD_SUPPORTED config SOC_BOD_SUPPORTED
bool bool
@@ -989,7 +989,7 @@ config SOC_SECURE_BOOT_V2_RSA
config SOC_SECURE_BOOT_V2_ECC config SOC_SECURE_BOOT_V2_ECC
bool bool
default y default n
config SOC_EFUSE_SECURE_BOOT_KEY_DIGESTS config SOC_EFUSE_SECURE_BOOT_KEY_DIGESTS
int int
@@ -73,7 +73,7 @@
#define SOC_ECC_SUPPORTED 1 #define SOC_ECC_SUPPORTED 1
#define SOC_ECC_EXTENDED_MODES_SUPPORTED 1 #define SOC_ECC_EXTENDED_MODES_SUPPORTED 1
#define SOC_FLASH_ENC_SUPPORTED 1 #define SOC_FLASH_ENC_SUPPORTED 1
#define SOC_SECURE_BOOT_SUPPORTED 1 #define SOC_SECURE_BOOT_SUPPORTED 0
#define SOC_BOD_SUPPORTED 1 #define SOC_BOD_SUPPORTED 1
// #define SOC_APM_SUPPORTED 1 // TODO: [ESP32H4] IDF-12256 // #define SOC_APM_SUPPORTED 1 // TODO: [ESP32H4] IDF-12256
#define SOC_PMU_SUPPORTED 1 // TODO: [ESP32H4] IDF-12286 #define SOC_PMU_SUPPORTED 1 // TODO: [ESP32H4] IDF-12286
@@ -420,7 +420,7 @@
/*-------------------------- Secure Boot CAPS----------------------------*/ /*-------------------------- Secure Boot CAPS----------------------------*/
#define SOC_SECURE_BOOT_V2_RSA 0 #define SOC_SECURE_BOOT_V2_RSA 0
#define SOC_SECURE_BOOT_V2_ECC 1 #define SOC_SECURE_BOOT_V2_ECC 0
#define SOC_EFUSE_SECURE_BOOT_KEY_DIGESTS 3 #define SOC_EFUSE_SECURE_BOOT_KEY_DIGESTS 3
#define SOC_EFUSE_SECURE_BOOT_P384_WR_DIS 1 #define SOC_EFUSE_SECURE_BOOT_P384_WR_DIS 1
#define SOC_EFUSE_REVOKE_BOOT_KEY_DIGESTS 1 #define SOC_EFUSE_REVOKE_BOOT_KEY_DIGESTS 1
+15 -3
View File
@@ -5,11 +5,11 @@ Secure Boot v2
:link_to_translation:`zh_CN:[中文]` :link_to_translation:`zh_CN:[中文]`
{IDF_TARGET_SBV2_SCHEME:default="RSA-PSS", esp32c2, esp32c61, esp32h4="ECDSA", esp32c6, esp32h2, esp32p4, esp32c5, esp32h21="RSA-PSS or ECDSA"} {IDF_TARGET_SBV2_SCHEME:default="RSA-PSS", esp32c2, esp32c61, esp32h4="ECDSA", esp32c6, esp32h2, esp32p4, esp32c5="RSA-PSS or ECDSA", esp32h21="RSA-PSS"}
{IDF_TARGET_SBV2_KEY:default="RSA-3072", esp32c2, esp32c61="ECDSA-256", esp32c6, esp32h2, esp32p4, esp32h21="RSA-3072, ECDSA-256", esp32h4="ECDSA-384, ECDSA-256", esp32c5="RSA-3072, ECDSA-384, ECDSA-256"} {IDF_TARGET_SBV2_KEY:default="RSA-3072", esp32c2, esp32c61="ECDSA-256", esp32c6, esp32h2, esp32p4="RSA-3072, ECDSA-256", esp32h21="RSA-3072", esp32h4="ECDSA-384, ECDSA-256", esp32c5="RSA-3072, ECDSA-384, ECDSA-256"}
{IDF_TARGET_SECURE_BOOT_OPTION_TEXT:default="", esp32c6, esp32h2, esp32p4, esp32h21="RSA is recommended for faster verification. You can choose either the RSA or ECDSA scheme from the menu.", esp32c5="ECDSA is recommended for faster verification. You can choose either the RSA or ECDSA scheme from the menu."} {IDF_TARGET_SECURE_BOOT_OPTION_TEXT:default="", esp32c6, esp32h2, esp32p4="RSA is recommended for faster verification. You can choose either the RSA or ECDSA scheme from the menu.", esp32c5="ECDSA is recommended for faster verification. You can choose either the RSA or ECDSA scheme from the menu."}
{IDF_TARGET_SBV2_SCHEME_RECOMMENDATION:default="RSA is recommended for use cases where fast boot-up time is required whereas ECDSA is recommended for use cases where shorter key length is required.", esp32c5="ECDSA is recommended for use cases where fast boot-up time and shorter key length is required."} {IDF_TARGET_SBV2_SCHEME_RECOMMENDATION:default="RSA is recommended for use cases where fast boot-up time is required whereas ECDSA is recommended for use cases where shorter key length is required.", esp32c5="ECDSA is recommended for use cases where fast boot-up time and shorter key length is required."}
@@ -52,6 +52,18 @@ Secure Boot v2
In this guide, most used commands are in the form of ``idf.py secure-<command>``, which is a wrapper around corresponding ``espsecure <command>``. The ``idf.py`` based commands provides more user-friendly experience, although may lack some of the advanced functionality of their ``espsecure`` based counterparts. In this guide, most used commands are in the form of ``idf.py secure-<command>``, which is a wrapper around corresponding ``espsecure <command>``. The ``idf.py`` based commands provides more user-friendly experience, although may lack some of the advanced functionality of their ``espsecure`` based counterparts.
.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and SOC_SECURE_BOOT_V2_RSA
.. warning::
On {IDF_TARGET_NAME}, the ECDSA based Secure Boot V2 scheme is not functional for certain input vectors and is therefore **not recommended**. Please use the RSA based Secure Boot V2 scheme instead. To use the ECDSA based scheme regardless of this limitation, enable :ref:`CONFIG_SECURE_BOOT_INSECURE` and :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`. This issue will be fixed in a future hardware ECO revision; refer to the hardware errata document for details.
.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and not SOC_SECURE_BOOT_V2_RSA
.. warning::
On {IDF_TARGET_NAME}, the ECDSA based Secure Boot V2 scheme is vulnerable for certain input vectors and is therefore **not recommended for production**. To use the ECDSA based Secure Boot V2 scheme regardless of this limitation, enable :ref:`CONFIG_SECURE_BOOT_INSECURE` and :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`. This issue will be fixed in a future hardware ECO revision; refer to the hardware errata document for details.
Background Background
---------- ----------
+15 -3
View File
@@ -5,11 +5,11 @@
:link_to_translation:`en:[English]` :link_to_translation:`en:[English]`
{IDF_TARGET_SBV2_SCHEME:default="RSA-PSS", esp32c2, esp32c61, esp32h4="ECDSA", esp32c6, esp32h2, esp32p4, esp32c5, esp32h21="RSA-PSS 或 ECDSA"} {IDF_TARGET_SBV2_SCHEME:default="RSA-PSS", esp32c2, esp32c61, esp32h4="ECDSA", esp32c6, esp32h2, esp32p4, esp32c5="RSA-PSS 或 ECDSA", esp32h21="RSA-PSS"}
{IDF_TARGET_SBV2_KEY:default="RSA-3072", esp32c2, esp32c61="ECDSA-256", esp32c6, esp32h2, esp32p4, esp32h21="RSA-3072、ECDSA-256", esp32h4="ECDSA-384、ECDSA-256", esp32c5="RSA-3072、ECDSA-384、ECDSA-256"} {IDF_TARGET_SBV2_KEY:default="RSA-3072", esp32c2, esp32c61="ECDSA-256", esp32c6, esp32h2, esp32p4="RSA-3072、ECDSA-256", esp32h21="RSA-3072", esp32h4="ECDSA-384、ECDSA-256", esp32c5="RSA-3072、ECDSA-384、ECDSA-256"}
{IDF_TARGET_SECURE_BOOT_OPTION_TEXT:default="", esp32c6, esp32h2, esp32p4, esp32h21="推荐使用 RSA,其验证时间更短。可以在菜单中选择 RSA 或 ECDSA 方案。", esp32c5="推荐使用 ECDSA,其验证时间更短。可以在菜单中选择 RSA 或 ECDSA 方案。"} {IDF_TARGET_SECURE_BOOT_OPTION_TEXT:default="", esp32c6, esp32h2, esp32p4="推荐使用 RSA,其验证时间更短。可以在菜单中选择 RSA 或 ECDSA 方案。", esp32c5="推荐使用 ECDSA,其验证时间更短。可以在菜单中选择 RSA 或 ECDSA 方案。"}
{IDF_TARGET_SBV2_SCHEME_RECOMMENDATION:default="如果需要快速启动,推荐使用 RSA;如果需要较短的密钥长度,建议使用 ECDSA。", esp32c5="如果需要快速启动且需要较短的密钥长度,建议使用 ECDSA。"} {IDF_TARGET_SBV2_SCHEME_RECOMMENDATION:default="如果需要快速启动,推荐使用 RSA;如果需要较短的密钥长度,建议使用 ECDSA。", esp32c5="如果需要快速启动且需要较短的密钥长度,建议使用 ECDSA。"}
@@ -52,6 +52,18 @@
在本指南中,最常用的命令形式为 ``idf.py secure-<command>``,这是对应 ``espsecure <command>`` 的封装。基于 ``idf.py`` 的命令能提供更好的用户体验,但与基于 ``espsecure`` 的命令相比,可能会损失一部分高级功能。 在本指南中,最常用的命令形式为 ``idf.py secure-<command>``,这是对应 ``espsecure <command>`` 的封装。基于 ``idf.py`` 的命令能提供更好的用户体验,但与基于 ``espsecure`` 的命令相比,可能会损失一部分高级功能。
.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and SOC_SECURE_BOOT_V2_RSA
.. warning::
在 {IDF_TARGET_NAME} 上,基于 ECDSA 的 Secure Boot V2 方案在某些输入向量下无法正常工作,因此**不推荐使用**。请改用基于 RSA 的 Secure Boot V2 方案。如果仍需使用基于 ECDSA 的方案,请启用 :ref:`CONFIG_SECURE_BOOT_INSECURE` 和 :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`。该问题将在未来的硬件 ECO 版本中修复,详情请参阅硬件勘误文档。
.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and not SOC_SECURE_BOOT_V2_RSA
.. warning::
在 {IDF_TARGET_NAME} 上,基于 ECDSA 的 Secure Boot V2 方案在某些输入向量下存在漏洞,因此**不推荐用于量产**。如果仍需使用基于 ECDSA 的 Secure Boot V2 方案,请启用 :ref:`CONFIG_SECURE_BOOT_INSECURE` 和 :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`。该问题将在未来的硬件 ECO 版本中修复,详情请参阅硬件勘误文档。
背景 背景
---- ----
@@ -8,6 +8,9 @@ CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="test/partitions_efuse_emul.csv"
CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT=y
CONFIG_SECURE_BOOT_V2_ENABLED=y CONFIG_SECURE_BOOT_V2_ENABLED=y
# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs
CONFIG_SECURE_BOOT_INSECURE=y
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp256.pem" CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp256.pem"
CONFIG_SECURE_ENABLE_SECURE_ROM_DL_MODE=y CONFIG_SECURE_ENABLE_SECURE_ROM_DL_MODE=y
@@ -8,6 +8,9 @@ CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="test/partitions_efuse_emul.csv"
CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT=y
CONFIG_SECURE_BOOT_V2_ENABLED=y CONFIG_SECURE_BOOT_V2_ENABLED=y
# ECDSA based Secure Boot V2 is not recommended on ESP32-C61 and must be force-enabled.
CONFIG_SECURE_BOOT_INSECURE=y
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp256.pem" CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp256.pem"
CONFIG_SECURE_ENABLE_SECURE_ROM_DL_MODE=y CONFIG_SECURE_ENABLE_SECURE_ROM_DL_MODE=y
@@ -8,6 +8,9 @@ CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="test/partitions_efuse_emul.csv"
CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT=y
CONFIG_SECURE_BOOT_V2_ENABLED=y CONFIG_SECURE_BOOT_V2_ENABLED=y
# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs
CONFIG_SECURE_BOOT_INSECURE=y
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS=y CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS=y
CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp384.pem" CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp384.pem"
@@ -8,6 +8,9 @@ CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="test/partitions_efuse_emul.csv"
CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT=y
CONFIG_SECURE_BOOT_V2_ENABLED=y CONFIG_SECURE_BOOT_V2_ENABLED=y
# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs
CONFIG_SECURE_BOOT_INSECURE=y
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp256.pem" CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp256.pem"
CONFIG_SECURE_INSECURE_ALLOW_DL_MODE=y CONFIG_SECURE_INSECURE_ALLOW_DL_MODE=y
@@ -8,6 +8,9 @@ CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="test/partitions_efuse_emul.csv"
CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT=y
CONFIG_SECURE_BOOT_V2_ENABLED=y CONFIG_SECURE_BOOT_V2_ENABLED=y
# ECDSA based Secure Boot V2 is not recommended on ESP32-C61 and must be force-enabled.
CONFIG_SECURE_BOOT_INSECURE=y
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp256.pem" CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp256.pem"
CONFIG_SECURE_INSECURE_ALLOW_DL_MODE=y CONFIG_SECURE_INSECURE_ALLOW_DL_MODE=y
@@ -8,6 +8,9 @@ CONFIG_PARTITION_TABLE_CUSTOM_FILENAME="test/partitions_efuse_emul.csv"
CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT=y
CONFIG_SECURE_BOOT_V2_ENABLED=y CONFIG_SECURE_BOOT_V2_ENABLED=y
# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs
CONFIG_SECURE_BOOT_INSECURE=y
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS=y CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS=y
CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp384.pem" CONFIG_SECURE_BOOT_SIGNING_KEY="test/secure_boot_signing_key_ecdsa_nistp384.pem"
@@ -1,6 +1,9 @@
CONFIG_IDF_TARGET="esp32h2" CONFIG_IDF_TARGET="esp32h2"
CONFIG_IDF_TARGET_ESP32H2=y CONFIG_IDF_TARGET_ESP32H2=y
# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs
CONFIG_SECURE_BOOT_INSECURE=y
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
CONFIG_SECURE_BOOT_V2_ECDSA_ENABLED=y CONFIG_SECURE_BOOT_V2_ECDSA_ENABLED=y
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS=y CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS=y
@@ -0,0 +1,6 @@
# ESP32-C61 has no RSA based Secure Boot V2; only the ECDSA scheme exists, and it
# is not functional for certain input vectors (see SECURE_BOOT_V2_ECDSA_INSECURE),
# so it is gated behind the insecure option. Force-enable it for this build-only test.
CONFIG_SECURE_BOOT_INSECURE=y
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
@@ -7,6 +7,8 @@ tools/test_apps/security/secure_boot:
disable: disable:
- if: CONFIG_NAME != "qemu" or IDF_TARGET == "linux" - if: CONFIG_NAME != "qemu" or IDF_TARGET == "linux"
reason: Skipping redundant CI builds for all the targets. reason: Skipping redundant CI builds for all the targets.
- if: IDF_TARGET == "esp32h4"
reason: Secure Boot V2 is disabled on ESP32-H4 (ECDSA-only, vulnerable scheme), so the secure boot test app does not apply.
tools/test_apps/security/signed_app_no_secure_boot: tools/test_apps/security/signed_app_no_secure_boot:
enable: enable:
@@ -1,5 +1,5 @@
| Supported Targets | ESP32 | ESP32-C2 | ESP32-C3 | ESP32-C5 | ESP32-C6 | ESP32-C61 | ESP32-H2 | ESP32-H21 | ESP32-H4 | ESP32-P4 | ESP32-S2 | ESP32-S3 | | Supported Targets | ESP32 | ESP32-C2 | ESP32-C3 | ESP32-C5 | ESP32-C6 | ESP32-C61 | ESP32-H2 | ESP32-H21 | ESP32-P4 | ESP32-S2 | ESP32-S3 |
| ----------------- | ----- | -------- | -------- | -------- | -------- | --------- | -------- | --------- | -------- | -------- | -------- | -------- | | ----------------- | ----- | -------- | -------- | -------- | -------- | --------- | -------- | --------- | -------- | -------- | -------- |
# Secure Boot # Secure Boot
@@ -38,15 +38,15 @@ SECURE_BOOT_RSA_TARGETS = [
'esp32c3', 'esp32c3',
'esp32c5', 'esp32c5',
'esp32c6', 'esp32c6',
'esp32c61',
'esp32h2', 'esp32h2',
'esp32h21', 'esp32h21',
'esp32s2', 'esp32s2',
'esp32s3', 'esp32s3',
'esp32p4', 'esp32p4',
'esp32h4',
] ]
SECURE_BOOT_ECDSA_TARGETS = ['esp32c2', 'esp32c5', 'esp32c6', 'esp32c61', 'esp32h2', 'esp32h21', 'esp32p4', 'esp32h4'] # ESP32-H4/H21 are preview targets with ECDSA based Secure Boot V2 marked unsupported,
# and ESP32-H4 has Secure Boot disabled entirely, so they are excluded here.
SECURE_BOOT_ECDSA_TARGETS = ['esp32c2', 'esp32c5', 'esp32c6', 'esp32c61', 'esp32h2', 'esp32p4']
SECURE_BOOT_ECDSA_P384_TARGETS = ['esp32c5'] SECURE_BOOT_ECDSA_P384_TARGETS = ['esp32c5']
CONFIGS_SECURE_BOOT_ECDSA = list( CONFIGS_SECURE_BOOT_ECDSA = list(
@@ -3,6 +3,10 @@ CONFIG_PARTITION_TABLE_OFFSET=0xD000
CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT=y
CONFIG_SECURE_BOOT_V2_ENABLED=y CONFIG_SECURE_BOOT_V2_ENABLED=y
# ECDSA based Secure Boot V2 is not recommended on the affected SoCs (see
# SECURE_BOOT_V2_ECDSA_INSECURE) and must be force-enabled to be selected.
CONFIG_SECURE_BOOT_INSECURE=y
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS=y CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS=y
CONFIG_SECURE_BOOT_SIGNING_KEY="test_ecdsa_p256_key.pem" CONFIG_SECURE_BOOT_SIGNING_KEY="test_ecdsa_p256_key.pem"
@@ -3,6 +3,10 @@ CONFIG_PARTITION_TABLE_OFFSET=0xD000
CONFIG_SECURE_BOOT=y CONFIG_SECURE_BOOT=y
CONFIG_SECURE_BOOT_V2_ENABLED=y CONFIG_SECURE_BOOT_V2_ENABLED=y
# ECDSA based Secure Boot V2 is not recommended on the affected SoCs (see
# SECURE_BOOT_V2_ECDSA_INSECURE) and must be force-enabled to be selected.
CONFIG_SECURE_BOOT_INSECURE=y
CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y
CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y
CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS=y CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_384_BITS=y
CONFIG_SECURE_BOOT_SIGNING_KEY="test_ecdsa_p384_key.pem" CONFIG_SECURE_BOOT_SIGNING_KEY="test_ecdsa_p384_key.pem"