fix(secure_boot): marks 192 bit support curve legacy

This commit is contained in:
Ashish Sharma
2026-03-20 19:07:55 +05:30
committed by Mahavir Jain
parent 9c6ca38ab3
commit f40f9ac497
4 changed files with 21 additions and 2 deletions
+4 -2
View File
@@ -562,7 +562,7 @@ menu "Security features"
help
Select the ECDSA key size. Three key sizes are supported depending upon on the target:
- 192 bit key using NISTP192 curve
- 192 bit key using NISTP192 curve (Legacy, not recommended)
- 256 bit key using NISTP256 curve (Recommended)
- 384 bit key using NISTP384 curve (Recommended)
@@ -571,8 +571,10 @@ menu "Security features"
At present, both key sizes are practically implausible to bruteforce.
config SECURE_BOOT_ECDSA_KEY_LEN_192_BITS
bool "Using ECC curve NISTP192"
bool "Using ECC curve NISTP192 (Legacy, not recommended)"
depends on SECURE_SIGNED_APPS_ECDSA_V2_SCHEME
help
This legacy option is not recommended for new designs. Prefer NISTP256 or NISTP384.
config SECURE_BOOT_ECDSA_KEY_LEN_256_BITS
bool "Using ECC curve NISTP256 (Recommended)"