Skip to content

PKCS11 Key Support Issues #153

@kenanjasim

Description

@kenanjasim

Hello team,

While trying to provision a CM4 with with PKCS11 keys, I encountered two issues:

Issue 1: Hardcoded PEM References

Between the integration of PKCS11 code and the merging of the keywriter/provisioner scripts, the derivePublicKey and update_eeprom functions still contain hardcoded references to customer PEM files rather than properly switching between PKCS11 and PEM options.

I've submitted a pull request with a partial fix for this issue. #152

Issue 2: CM5 Bootcode Signing

CM5s require signed bootcode images, which are currently processed by the rpi-sign-bootcode tool. This tool only accepts PEM files by default.

Question: Is PKCS11 support continuing to be supported for this tool? If not, would you be open to contributions implementing this functionality?

Thank you for your attention to these issues.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions