[PATCH v6 5/5] binman: Add BINMAN_X509_KEYFILE to override the signing key

Sergio Prado <[email protected]>
Newsgroups gmane.comp.boot-loaders.u-boot
Message-ID <[email protected]>
The key used to sign an x509 certificate entry comes from the image
description, either as a 'keyfile' property or as a 'keyfile' entry
argument. Neither is convenient for a build which must not carry the key,
such as one signing with an HSM.

Add a BINMAN_X509_KEYFILE make variable which, when set, passes
'-a keyfile=<value>' to binman and so overrides the image description for
every x509 certificate entry in the build::

    URI="pkcs11:token=mytoken;object=mykey;type=private"
    make BINMAN_X509_KEYFILE="$URI" OPENSSL_CONF=/path/to/openssl.cnf

The variable is a plain keyfile override, so it takes a path to a PEM key
file just as happily as a PKCS#11 URI; signing with an HSM is simply the
case which needs it most.

Signed-off-by: Sergio Prado <[email protected]>
---
 Makefile                |  1 +
 tools/binman/binman.rst | 12 ++++++++++++
 2 files changed, 13 insertions(+)

diff --git a/Makefile b/Makefile
index 7f5d83658d75..c418fda1981f 100644
--- a/Makefile
+++ b/Makefile
@@ -1704,6 +1704,7 @@ cmd_binman = $(srctree)/tools/binman/binman $(if $(BINMAN_DEBUG),-D) \
 		-a vpl-dtb=$(CONFIG_VPL_OF_REAL) \
 		-a pre-load-key-path=${PRE_LOAD_KEY_PATH} \
 		-a of-spl-remove-props=$(CONFIG_OF_SPL_REMOVE_PROPS) \
+		$(if $(BINMAN_X509_KEYFILE),-a keyfile="$(BINMAN_X509_KEYFILE)") \
 		$(BINMAN_$(@F))
 
 OBJCOPYFLAGS_u-boot.ldr.hex := -I binary -O ihex
diff --git a/tools/binman/binman.rst b/tools/binman/binman.rst
index 106c34efb76c..ff61baf6d5fe 100644
--- a/tools/binman/binman.rst
+++ b/tools/binman/binman.rst
@@ -2232,6 +2232,18 @@ BINMAN_VERBOSE
     Sets the logging verbosity of binman by adding a `-v` argument. See
     :ref:`BinmanLogging`.
 
+BINMAN_X509_KEYFILE
+    Sets the key used to sign x509 certificate entries by adding an
+    `-a keyfile=<value>` argument, overriding whatever the image description
+    says. The value is either the filename of a PEM key file on disk or a
+    PKCS#11 URI naming a key held in an HSM, so this is the way to keep the
+    signing key out of the source tree::
+
+        URI="pkcs11:token=mytoken;object=mykey;type=private"
+        make BINMAN_X509_KEYFILE="$URI" OPENSSL_CONF=/path/to/openssl.cnf
+
+    See :ref:`SigningX509Hsm` for the URI forms which are accepted and the
+    OpenSSL configuration they need.
 
 Error messages
 --------------
-- 
2.34.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.