diff options
author | Stephen Cprek <smcprek@us.ibm.com> | 2017-03-29 16:43:32 -0500 |
---|---|---|
committer | William G. Hoffa <wghoffa@us.ibm.com> | 2017-04-19 09:16:17 -0400 |
commit | 909542d1ff7e5de27b6b671c5ffbb215dda834ab (patch) | |
tree | 3df115102d38a196582553b8907c4891404890cd /src/build/buildpnor/genPnorImages.pl | |
parent | 5334b1e8d4f2ff7463defcf39c8c9c9c6b6012f7 (diff) | |
download | talos-hostboot-909542d1ff7e5de27b6b671c5ffbb215dda834ab.tar.gz talos-hostboot-909542d1ff7e5de27b6b671c5ffbb215dda834ab.zip |
Sign and securely load SBE partition
Change-Id: I92d1b9544168cfa8780d5be1a666fb3e748bf942
Reviewed-on: http://ralgit01.raleigh.ibm.com/gerrit1/38627
Reviewed-by: Martin Gloff <mgloff@us.ibm.com>
Reviewed-by: Nicholas E. Bofferding <bofferdn@us.ibm.com>
Tested-by: Jenkins Server <pfd-jenkins+hostboot@us.ibm.com>
Tested-by: Jenkins OP Build CI <op-jenkins+hostboot@us.ibm.com>
Tested-by: FSP CI Jenkins <fsp-CI-jenkins+hostboot@us.ibm.com>
Reviewed-by: William G. Hoffa <wghoffa@us.ibm.com>
Diffstat (limited to 'src/build/buildpnor/genPnorImages.pl')
-rwxr-xr-x | src/build/buildpnor/genPnorImages.pl | 8 |
1 files changed, 2 insertions, 6 deletions
diff --git a/src/build/buildpnor/genPnorImages.pl b/src/build/buildpnor/genPnorImages.pl index 8ad102eab..b23f01a0a 100755 --- a/src/build/buildpnor/genPnorImages.pl +++ b/src/build/buildpnor/genPnorImages.pl @@ -500,9 +500,8 @@ sub manipulateImages # Sections that have secureboot support. Secureboot still must be # enabled for secureboot actions on these partitions to occur. # @TODO securebootp9 re-enable with SBE/SBEC/PAYLOAD secureboot ports - my $isNormalSecure = 0; + my $isNormalSecure = ($eyeCatch eq "SBE"); #|| ($eyeCatch eq "HBRT"); - #|| ($eyeCatch eq "SBE") #|| ($eyeCatch eq "SBEC") #|| ($eyeCatch eq "PAYLOAD") #|| ($eyeCatch eq "OCC") @@ -698,10 +697,7 @@ sub manipulateImages run_command("cat $bin_file >> $tempImages{HDR_PHASE}"); } } - # @TODO securebootp9 re-enable with SBE/SBEC secureboot ports - elsif(0) #$secureboot - #&& ( ($sectionHash{$layoutKey}{sha512perEC} eq "yes") - # || ($isNormalSecure))) + elsif ($secureboot && $isNormalSecure) { $callerHwHdrFields{configure} = 1; if($openSigningTool) |