Support for "Signed firmware" update

Adriana Kobylak anoo at linux.ibm.com
Wed Nov 20 05:01:08 AEDT 2019


On 2019-11-19 01:28, Thaj wrote:
> Is there a plan to support BMC/Host signed firmware update?

Hi Thaj, there's already support for checking signatures during a 
firmware update, it's enabled via the "verify_signature" config option 
in the phosphor-bmc-code-mgmt and openpower-pnor-code-mgmt repos.
The OpenBMC images are signed via the phosphor-image-signing.bb recipe 
in the meta-phosphor layer.
Is this what you were looking for?

> 
> Regards,
> Thaj


More information about the openbmc mailing list