Allow dynamic overriding of ROTPK verification
A production ROM with TBB enabled must have the ability to boot test software
before a real ROTPK is deployed (e.g. manufacturing mode). Previously the
function plat_get_rotpk_info() must return a valid ROTPK for TBB to succeed.
This patch adds an additional bit `ROTPK_NOT_DEPLOYED` in the output `flags`
parameter from plat_get_rotpk_info(). If this bit is set, then the ROTPK
in certificate is used without verifying against the platform value.

Fixes ARM-software/tf-issues#381

Change-Id: Icbbffab6bff8ed76b72431ee21337f550d8fdbbb
1 parent a7e5303 commit 04943d33cf379868a1dfa3971c2c2250526f0670
@Soby Mathew Soby Mathew authored on 24 May 2016
Showing 3 changed files
View
docs/porting-guide.md
View
drivers/auth/auth_mod.c
View
include/plat/common/platform.h