Hi everyone,
I'm working on secure boot for the IMX8MP platform. I've successfully managed to get it working on my board. Now, I'm wondering if it's possible to build and generate the unsigned flash.bin on one computer, and then, in a second phase, sign the binary on another secure computer that has exclusive access to the private keys and signing tools.
I've read that it is possible to run binman outside the U-Boot source tree, but I'm having trouble understanding if this approach is currently feasible for the IMX8MP signing procedure. Do any of you have any insights or suggestions?
Thanks a lot!
Meeting time now, and the announce email yesterday has dial in numbers too
