-
Notifications
You must be signed in to change notification settings - Fork 1.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
doc: nsib: remove FEM mention and move some docs #12398
Conversation
You can find the documentation preview for this PR at this link. It will be updated about 10 minutes after the documentation build succeeds. Note: This comment is automatically posted by the Documentation Publishing GitHub Action. |
This public key is checked against the provisioned hashes of public keys to determine if the image is valid. | ||
|
||
All public key hashes at lower indices than the matching hash are permanently invalidated at this point. | ||
You can use this mechanism to decommission broken keys. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I wonder if broken is the right word here. Maybe stolen/cracked keys?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
"compromised keys"?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes i like the suggestion above
|
||
All peripherals that have been used are reset and the next stage is booted. | ||
|
||
Except for providing your own keys, there is no need to modify the immutable bootloader in any way before you program it. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
there is no need to modify the immutable bootloader in any way before you program it.
Something seems off with this statement.
I agree that you do not have to do this.
However, in several situations, it is beneficial to configure the immutable bootloader. To mention one: If you want MCUboot as an immutable bootloader with Serial Recovery enabled, you must configure it.
For an general overview over my comments: |
af955af
to
cffeb59
Compare
@sigvartmh , @hellesvik-nordic , @einarthorsrud , kindly please have another look. |
cffeb59
to
3f50b85
Compare
Removed mention of FEM from the NSIB readme. Moved generic information about RoT establishment to bootloader docs. Part of NCSIDB-1053. Signed-off-by: Grzegorz Ferenc <[email protected]>
Removed mention of FEM from the NSIB readme.
Moved generic information about RoT establishment to bootloader docs. Part of NCSIDB-1053.