[Skiboot] [PATCH v2 00/20] libstb: add support for secure and trusted boot in P9

Stewart Smith stewart at linux.vnet.ibm.com
Thu Dec 14 14:08:29 AEDT 2017


Claudio Carvalho <cclaudio at linux.vnet.ibm.com> writes:
> The log=0xffffffffffffff8160 message means that hardware key hash check 
> failed. In other words, the hw-key-hash in the container doesn't match 
> with the hw-key-hash that skiboot provided to the CVC (Container 
> Verification Code).

/sys/firmware/devicetree/base/ibm,secureboot # lsprop 
compatible       "ibm,secureboot-v2"
hw-key-hash-size 00000040 (64)
hw-key-hash      00000000 00000000 00000000 00000000
                 00000000 00000000 00000000 00000000
                 00000000 00000000 00000000 00000000
                 00000000 00000000 00000000 00000000
phandle          00000058 (88)
name             "ibm,secureboot"


yep, that'll explain it. Hrm... not getting anything from Hostboot. Time
to dig in there

-- 
Stewart Smith
OPAL Architect, IBM.



More information about the Skiboot mailing list