On Tue, Jul 28 2026, "Sergio Prado" <[email protected]> wrote:
> Motivation > ---------- > > TI K3 secure boot requires X509 certificates to be signed with a private > key at build time. For production use, that key should never exist > unprotected on a build machine - it belongs inside a Hardware Security > Module (HSM) which enforces access control and keeps the key material > unexportable. Hi Sergio I was completely unaware of this work when I sent https://lore.kernel.org/u-boot/[email protected]/ (and v1 of that); I assume your v5 must have been sent some time before my v1. We clearly have very similar goals, but somewhat different approaches. I will look through your patches tomorrow and see if they would work for us. Rasmus
