blob: 4d1d79498c2d8738a2cb5886c5f0cd7435873419 [file] [log] [blame]
Jan Kiszka033ab462023-02-28 19:19:17 +01001#!/bin/sh
2
3if [ -z "$1" ]; then
4 echo "Usage: $0 KEY"
5 exit 1
6fi
7
8TEMP_X509=$(mktemp XXXXXXXX.temp)
9
10REVISION=${2:-0}
11SHA_VAL=$(openssl dgst -sha512 -hex tispl.bin | sed -e "s/^.*= //g")
12BIN_SIZE=$(stat -c %s tispl.bin)
13
14cat <<EOF >$TEMP_X509
15[ req ]
16distinguished_name = req_distinguished_name
17x509_extensions = v3_ca
18prompt = no
19dirstring_type = nobmp
20
21[ req_distinguished_name ]
22CN = IOT2050 Firmware Signature
23
24[ v3_ca ]
25basicConstraints = CA:true
261.3.6.1.4.1.294.1.3 = ASN1:SEQUENCE:swrv
271.3.6.1.4.1.294.1.34 = ASN1:SEQUENCE:sysfw_image_integrity
28
29[ swrv ]
30swrv = INTEGER:$REVISION
31
32[ sysfw_image_integrity ]
33shaType = OID:2.16.840.1.101.3.4.2.3
34shaValue = FORMAT:HEX,OCT:$SHA_VAL
35imageSize = INTEGER:$BIN_SIZE
36EOF
37
38CERT_X509=$(mktemp XXXXXXXX.crt)
39
40openssl req -new -x509 -key $1 -nodes -outform DER -out $CERT_X509 -config $TEMP_X509 -sha512
41cat $CERT_X509 tispl.bin > tispl.bin_signed
42# currently broken in upstream
43#source/tools/binman/binman replace -i flash.bin -f tispl.bin_signed blob@0x180000
44dd if=tispl.bin_signed of=flash.bin bs=$((0x1000)) seek=$((0x180000/0x1000)) conv=notrunc
45
46rm $TEMP_X509 $CERT_X509
47
48tools/mkimage -G $1 -r -o sha256,rsa4096 -F fit@0x380000.fit
49# currently broken in upstream
50#source/tools/binman/binman replace -i flash.bin -f fit@0x380000.fit fit@0x380000
51dd if=fit@0x380000.fit of=flash.bin bs=$((0x1000)) seek=$((0x380000/0x1000)) conv=notrunc