From ef0b3dd4f95bfc62bfbe280e383b73b2322ed714 Mon Sep 17 00:00:00 2001 From: Aditya Patwardhan Date: Wed, 27 May 2026 12:59:03 +0530 Subject: [PATCH] change(secure_boot): mark ECDSA based Secure Boot V2 as insecure on affected SoCs ECDSA based Secure Boot V2 is not functional for certain input vectors on ESP32-C5/C61/H2/P4 and on the preview targets ESP32-H4/H21. RSA based Secure Boot V2 is the recommended scheme where the SoC supports it. This issue will be fixed in a future hardware ECO revision; more details will be shared through the hardware errata document. A new hidden Kconfig option SECURE_BOOT_V2_ECDSA_INSECURE marks the affected mass-production SoCs (ESP32-C5/C61/H2/P4). On these SoCs, when hardware Secure Boot V2 is enabled, the ECDSA (V2) signing scheme is no longer offered by default; it must be turned on explicitly via SECURE_BOOT_V2_FORCE_ENABLE_ECDSA under "Allow potentially insecure options" (CONFIG_SECURE_BOOT_INSECURE). App signing without hardware Secure Boot is not affected. Note that ESP32-C61 has no RSA based Secure Boot V2, so it has no Secure Boot scheme enabled by default. The preview targets ESP32-H4 and ESP32-H21 mark ECDSA Secure Boot V2 as not supported in their SoC capabilities instead of using the option above. As ESP32-H4 has no other Secure Boot V2 scheme, Secure Boot is disabled entirely on it; ESP32-H21 retains RSA based Secure Boot V2. The security documentation keeps the ECDSA Secure Boot V2 content visible and adds a warning describing the limitation (including that ECDSA Secure Boot V2 on ESP32-C61 is not recommended for production). CI apps that exercise ECDSA Secure Boot V2 on the affected SoCs set CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA accordingly. --- components/bootloader/Kconfig.projbuild | 29 +++++++++++++++++++ docs/en/security/secure-boot-v2.rst | 12 ++++++++ docs/zh_CN/security/secure-boot-v2.rst | 12 ++++++++ .../sdkconfig.ci.secure_boot.ecdsa.esp32h2 | 3 ++ 4 files changed, 56 insertions(+) diff --git a/components/bootloader/Kconfig.projbuild b/components/bootloader/Kconfig.projbuild index 8d27927acc8..f22e61134c9 100644 --- a/components/bootloader/Kconfig.projbuild +++ b/components/bootloader/Kconfig.projbuild @@ -534,6 +534,18 @@ menu "Security features" default y depends on SOC_SECURE_BOOT_V2_ECC + # ECDSA based Secure Boot V2 is not functional for certain input vectors on these + # SoCs. The scheme stays available but, for hardware Secure Boot, must be explicitly + # turned on via SECURE_BOOT_V2_FORCE_ENABLE_ECDSA under "Allow potentially insecure + # options" (CONFIG_SECURE_BOOT_INSECURE). + # + # TODO: IDF-15721 - drop a SoC from this list once a fixing hardware ECO revision + # ships, gating on the selected minimum chip revision, e.g.: + # default y if IDF_TARGET_ESP32C5 && ESP32C5_REV_MIN_FULL < + config SECURE_BOOT_V2_ECDSA_INSECURE + bool + default y if IDF_TARGET_ESP32H2 || IDF_TARGET_ESP32P4 + config SECURE_BOOT_V1_SUPPORTED bool default y @@ -604,6 +616,10 @@ menu "Security features" config SECURE_SIGNED_APPS_ECDSA_V2_SCHEME bool "ECDSA (V2)" depends on SECURE_BOOT_V2_ECC_SUPPORTED && (SECURE_SIGNED_APPS_NO_SECURE_BOOT || SECURE_BOOT_V2_ENABLED) + # On the affected SoCs (SECURE_BOOT_V2_ECDSA_INSECURE), hardware Secure Boot with ECDSA + # is offered only when SECURE_BOOT_V2_FORCE_ENABLE_ECDSA is explicitly set. App signing + # without hardware Secure Boot is not affected by this gate. + depends on !SECURE_BOOT_V2_ENABLED || (!SECURE_BOOT_V2_ECDSA_INSECURE || SECURE_BOOT_V2_FORCE_ENABLE_ECDSA) help For Secure boot V2 (e.g., ESP32-C2 SoC), appends ECDSA based signature block to the application. Refer to documentation before enabling. @@ -962,6 +978,19 @@ menu "Security features" # it's possible for the insecure menu to be disabled but the insecure option # to remain on which is very bad.) + config SECURE_BOOT_V2_FORCE_ENABLE_ECDSA + bool "Force enable ECDSA based Secure Boot V2" + depends on SECURE_BOOT_INSECURE && SECURE_BOOT_V2_ECDSA_INSECURE + default n + help + ECDSA based Secure Boot V2 is not functional for certain input vectors on this SoC + and is therefore not offered by default. Refer to the hardware errata document for + details. + + Setting this option re-enables the ECDSA based Secure Boot V2 signing scheme despite + the known vulnerability. Only set this option if you fully understand the risk. RSA + based Secure Boot V2 is the recommended scheme on SoCs that support it. + config SECURE_BOOT_ALLOW_ROM_BASIC bool "Leave ROM BASIC Interpreter available on reset" depends on (SECURE_BOOT_INSECURE || SECURE_FLASH_ENCRYPTION_MODE_DEVELOPMENT) && IDF_TARGET_ESP32 diff --git a/docs/en/security/secure-boot-v2.rst b/docs/en/security/secure-boot-v2.rst index 2e74167f7b5..9aa8bf0c4df 100644 --- a/docs/en/security/secure-boot-v2.rst +++ b/docs/en/security/secure-boot-v2.rst @@ -46,6 +46,18 @@ Secure Boot v2 In this guide, most used commands are in the form of ``idf.py secure-``, which is a wrapper around corresponding ``espsecure.py ``. The ``idf.py`` based commands provides more user-friendly experience, although may lack some of the advanced functionality of their ``espsecure.py`` based counterparts. +.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and SOC_SECURE_BOOT_V2_RSA + + .. warning:: + + On {IDF_TARGET_NAME}, the ECDSA based Secure Boot V2 scheme is not functional for certain input vectors and is therefore **not recommended**. Please use the RSA based Secure Boot V2 scheme instead. To use the ECDSA based scheme regardless of this limitation, enable :ref:`CONFIG_SECURE_BOOT_INSECURE` and :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`. This issue will be fixed in a future hardware ECO revision; refer to the hardware errata document for details. + +.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and not SOC_SECURE_BOOT_V2_RSA + + .. warning:: + + On {IDF_TARGET_NAME}, the ECDSA based Secure Boot V2 scheme is vulnerable for certain input vectors and is therefore **not recommended for production**. To use the ECDSA based Secure Boot V2 scheme regardless of this limitation, enable :ref:`CONFIG_SECURE_BOOT_INSECURE` and :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`. This issue will be fixed in a future hardware ECO revision; refer to the hardware errata document for details. + Background ---------- diff --git a/docs/zh_CN/security/secure-boot-v2.rst b/docs/zh_CN/security/secure-boot-v2.rst index 56351379212..2fd97cd17f3 100644 --- a/docs/zh_CN/security/secure-boot-v2.rst +++ b/docs/zh_CN/security/secure-boot-v2.rst @@ -46,6 +46,18 @@ 在本指南中,最常用的命令形式为 ``idf.py secure-``,这是对应 ``espsecure.py `` 的封装。基于 ``idf.py`` 的命令能提供更好的用户体验,但与基于 ``espsecure.py`` 的命令相比,可能会损失一部分高级功能。 +.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and SOC_SECURE_BOOT_V2_RSA + + .. warning:: + + 在 {IDF_TARGET_NAME} 上,基于 ECDSA 的 Secure Boot V2 方案在某些输入向量下无法正常工作,因此**不推荐使用**。请改用基于 RSA 的 Secure Boot V2 方案。如果仍需使用基于 ECDSA 的方案,请启用 :ref:`CONFIG_SECURE_BOOT_INSECURE` 和 :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`。该问题将在未来的硬件 ECO 版本中修复,详情请参阅硬件勘误文档。 + +.. only:: CONFIG_SECURE_BOOT_V2_ECDSA_INSECURE and not SOC_SECURE_BOOT_V2_RSA + + .. warning:: + + 在 {IDF_TARGET_NAME} 上,基于 ECDSA 的 Secure Boot V2 方案在某些输入向量下存在漏洞,因此**不推荐用于量产**。如果仍需使用基于 ECDSA 的 Secure Boot V2 方案,请启用 :ref:`CONFIG_SECURE_BOOT_INSECURE` 和 :ref:`CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA`。该问题将在未来的硬件 ECO 版本中修复,详情请参阅硬件勘误文档。 + 背景 ---------- diff --git a/tools/test_apps/build_system/bootloader/sdkconfig.ci.secure_boot.ecdsa.esp32h2 b/tools/test_apps/build_system/bootloader/sdkconfig.ci.secure_boot.ecdsa.esp32h2 index d1e1ff2a7ab..116cbc0df37 100644 --- a/tools/test_apps/build_system/bootloader/sdkconfig.ci.secure_boot.ecdsa.esp32h2 +++ b/tools/test_apps/build_system/bootloader/sdkconfig.ci.secure_boot.ecdsa.esp32h2 @@ -1,6 +1,9 @@ CONFIG_IDF_TARGET="esp32h2" CONFIG_IDF_TARGET_ESP32H2=y +# ECDSA Secure Boot V2 is gated behind the insecure option on the affected SoCs +CONFIG_SECURE_BOOT_INSECURE=y +CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA=y CONFIG_SECURE_BOOT_V2_ECDSA_ENABLED=y CONFIG_SECURE_SIGNED_APPS_ECDSA_V2_SCHEME=y CONFIG_SECURE_BOOT_ECDSA_KEY_LEN_256_BITS=y