On Tue, Jul 28 2026, "Sergio Prado" <[email protected]> wrote:

> Motivation
> ----------
>
> TI K3 secure boot requires X509 certificates to be signed with a private
> key at build time. For production use, that key should never exist
> unprotected on a build machine - it belongs inside a Hardware Security
> Module (HSM) which enforces access control and keeps the key material
> unexportable.

Hi Sergio

I was completely unaware of this work when I sent
https://lore.kernel.org/u-boot/[email protected]/
(and v1 of that); I assume your v5 must have been sent some time before
my v1.

We clearly have very similar goals, but somewhat different approaches. I
will look through your patches tomorrow and see if they would work for
us.

Rasmus

Reply via email to