From 15954136227df23fe90a99d2e97665508e22417d Mon Sep 17 00:00:00 2001 From: Cameron Auser Date: Fri, 1 Nov 2024 13:02:06 -0600 Subject: [PATCH 1/3] Add clarification that rpi-otp-private-key only works with certain devices. --- .../asciidoc/computers/raspberry-pi/raspberry-pi-industrial.adoc | 1 + 1 file changed, 1 insertion(+) diff --git a/documentation/asciidoc/computers/raspberry-pi/raspberry-pi-industrial.adoc b/documentation/asciidoc/computers/raspberry-pi/raspberry-pi-industrial.adoc index 92c23593d..b70785a87 100644 --- a/documentation/asciidoc/computers/raspberry-pi/raspberry-pi-industrial.adoc +++ b/documentation/asciidoc/computers/raspberry-pi/raspberry-pi-industrial.adoc @@ -172,6 +172,7 @@ secure-boot / file-system encryption is not required, then the device private ke See https://gitlab.com/cryptsetup/cryptsetup[Cryptsetup] for more information about open-source disk encryption. ==== Program a key into OTP with `rpi-otp-private-key` +NOTE: The `rpi-otp-private-key` script can only be used on devices with the Broadcom BCM2711 or BCM2712 processor. The https://github.com/raspberrypi/rpi-eeprom/blob/master/tools/rpi-otp-private-key[`rpi-otp-private-key`] script wraps the device private key `vcmailbox` APIs to make it easier to read and write a key in the OpenSSL format. From 769f4b0ab2a11fc3efcebe3f3b01295f8ff713f2 Mon Sep 17 00:00:00 2001 From: nate contino Date: Thu, 7 Nov 2024 14:23:21 +0000 Subject: [PATCH 2/3] Add link to processor detail pages --- .../computers/raspberry-pi/raspberry-pi-industrial.adoc | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/documentation/asciidoc/computers/raspberry-pi/raspberry-pi-industrial.adoc b/documentation/asciidoc/computers/raspberry-pi/raspberry-pi-industrial.adoc index b70785a87..c9562df14 100644 --- a/documentation/asciidoc/computers/raspberry-pi/raspberry-pi-industrial.adoc +++ b/documentation/asciidoc/computers/raspberry-pi/raspberry-pi-industrial.adoc @@ -172,7 +172,8 @@ secure-boot / file-system encryption is not required, then the device private ke See https://gitlab.com/cryptsetup/cryptsetup[Cryptsetup] for more information about open-source disk encryption. ==== Program a key into OTP with `rpi-otp-private-key` -NOTE: The `rpi-otp-private-key` script can only be used on devices with the Broadcom BCM2711 or BCM2712 processor. + +NOTE: The `rpi-otp-private-key` script only works on devices that use the Broadcom xref:processors.adoc#bcm2711[BCM2711] or xref:processors.adoc#bcm2712[BCM2712]) processors. The https://github.com/raspberrypi/rpi-eeprom/blob/master/tools/rpi-otp-private-key[`rpi-otp-private-key`] script wraps the device private key `vcmailbox` APIs to make it easier to read and write a key in the OpenSSL format. From 72b5bc1ee91636490cd88a864d7d2d834da9664e Mon Sep 17 00:00:00 2001 From: nate contino Date: Thu, 7 Nov 2024 14:23:52 +0000 Subject: [PATCH 3/3] Fix hanging paren --- .../computers/raspberry-pi/raspberry-pi-industrial.adoc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/documentation/asciidoc/computers/raspberry-pi/raspberry-pi-industrial.adoc b/documentation/asciidoc/computers/raspberry-pi/raspberry-pi-industrial.adoc index c9562df14..faf0f06f0 100644 --- a/documentation/asciidoc/computers/raspberry-pi/raspberry-pi-industrial.adoc +++ b/documentation/asciidoc/computers/raspberry-pi/raspberry-pi-industrial.adoc @@ -173,7 +173,7 @@ See https://gitlab.com/cryptsetup/cryptsetup[Cryptsetup] for more information ab ==== Program a key into OTP with `rpi-otp-private-key` -NOTE: The `rpi-otp-private-key` script only works on devices that use the Broadcom xref:processors.adoc#bcm2711[BCM2711] or xref:processors.adoc#bcm2712[BCM2712]) processors. +NOTE: The `rpi-otp-private-key` script only works on devices that use the Broadcom xref:processors.adoc#bcm2711[BCM2711] or xref:processors.adoc#bcm2712[BCM2712] processors. The https://github.com/raspberrypi/rpi-eeprom/blob/master/tools/rpi-otp-private-key[`rpi-otp-private-key`] script wraps the device private key `vcmailbox` APIs to make it easier to read and write a key in the OpenSSL format.