summaryrefslogtreecommitdiffstats
path: root/src/build/buildpnor/genPnorImages.pl
diff options
context:
space:
mode:
authorStephen Cprek <smcprek@us.ibm.com>2017-03-29 16:43:32 -0500
committerWilliam G. Hoffa <wghoffa@us.ibm.com>2017-04-19 09:16:17 -0400
commit909542d1ff7e5de27b6b671c5ffbb215dda834ab (patch)
tree3df115102d38a196582553b8907c4891404890cd /src/build/buildpnor/genPnorImages.pl
parent5334b1e8d4f2ff7463defcf39c8c9c9c6b6012f7 (diff)
downloadtalos-hostboot-909542d1ff7e5de27b6b671c5ffbb215dda834ab.tar.gz
talos-hostboot-909542d1ff7e5de27b6b671c5ffbb215dda834ab.zip
Sign and securely load SBE partition
Change-Id: I92d1b9544168cfa8780d5be1a666fb3e748bf942 Reviewed-on: http://ralgit01.raleigh.ibm.com/gerrit1/38627 Reviewed-by: Martin Gloff <mgloff@us.ibm.com> Reviewed-by: Nicholas E. Bofferding <bofferdn@us.ibm.com> Tested-by: Jenkins Server <pfd-jenkins+hostboot@us.ibm.com> Tested-by: Jenkins OP Build CI <op-jenkins+hostboot@us.ibm.com> Tested-by: FSP CI Jenkins <fsp-CI-jenkins+hostboot@us.ibm.com> Reviewed-by: William G. Hoffa <wghoffa@us.ibm.com>
Diffstat (limited to 'src/build/buildpnor/genPnorImages.pl')
-rwxr-xr-xsrc/build/buildpnor/genPnorImages.pl8
1 files changed, 2 insertions, 6 deletions
diff --git a/src/build/buildpnor/genPnorImages.pl b/src/build/buildpnor/genPnorImages.pl
index 8ad102eab..b23f01a0a 100755
--- a/src/build/buildpnor/genPnorImages.pl
+++ b/src/build/buildpnor/genPnorImages.pl
@@ -500,9 +500,8 @@ sub manipulateImages
# Sections that have secureboot support. Secureboot still must be
# enabled for secureboot actions on these partitions to occur.
# @TODO securebootp9 re-enable with SBE/SBEC/PAYLOAD secureboot ports
- my $isNormalSecure = 0;
+ my $isNormalSecure = ($eyeCatch eq "SBE");
#|| ($eyeCatch eq "HBRT");
- #|| ($eyeCatch eq "SBE")
#|| ($eyeCatch eq "SBEC")
#|| ($eyeCatch eq "PAYLOAD")
#|| ($eyeCatch eq "OCC")
@@ -698,10 +697,7 @@ sub manipulateImages
run_command("cat $bin_file >> $tempImages{HDR_PHASE}");
}
}
- # @TODO securebootp9 re-enable with SBE/SBEC secureboot ports
- elsif(0) #$secureboot
- #&& ( ($sectionHash{$layoutKey}{sha512perEC} eq "yes")
- # || ($isNormalSecure)))
+ elsif ($secureboot && $isNormalSecure)
{
$callerHwHdrFields{configure} = 1;
if($openSigningTool)
OpenPOWER on IntegriCloud