Re: [PATCH v6 0/5] binman: add PKCS#11/HSM signing support for X509 certificates

Rasmus Villemoes via U-Boot <[email protected]>
Newsgroups gmane.comp.boot-loaders.u-boot
Message-ID <[email protected]>
On Tue, Jul 28 2026, "Sergio Prado" <[email protected]> wrote:

> Motivation
> ----------
>
> TI K3 secure boot requires X509 certificates to be signed with a private
> key at build time. For production use, that key should never exist
> unprotected on a build machine - it belongs inside a Hardware Security
> Module (HSM) which enforces access control and keeps the key material
> unexportable.

Hi Sergio

I was completely unaware of this work when I sent
https://lore.kernel.org/u-boot/[email protected]/
(and v1 of that); I assume your v5 must have been sent some time before
my v1.

We clearly have very similar goals, but somewhat different approaches. I
will look through your patches tomorrow and see if they would work for
us.

Rasmus
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.