cert_create: add SiP owned secure partitions support
Add support to generate certificate "sip-sp-cert" for Secure
Partitions(SP) owned by Silicon provider(SiP).
To avoid deviation from TBBR specification the support is only added for
dualroot CoT and not for TBBR CoT.

A single certificate file is generated containing hash of individual
packages. Maximum 8 secure partitions are supported.

Following new options added to cert_tool:
 --sip-sp-cert --> SiP owned Secure Partition Content Certificate
 --sp-pkg1 --> Secure Partition Package1 file
 --sp-pkg2
 .....
 --sp-pkg8

Trusted world key pair is used for signing.

Going forward, this feature can be extended for Platfrom owned
Partitions, if required.

Signed-off-by: Manish Pandey <manish.pandey2@arm.com>
Change-Id: Ia6dfbc1447cfb41b1fcbd12cf2bf7b88f409bd8d
1 parent 967a6d1 commit 0792dd7d64d1056fae05eab8cebe91ffc993923e
@Manish Pandey Manish Pandey authored on 22 May 2020
Showing 8 changed files
View
include/tools_share/dualroot_oid.h
View
include/tools_share/firmware_image_package.h
View
lib/debugfs/devfip.c
View
make_helpers/tbbr/tbbr_tools.mk
View
tools/cert_create/include/cert.h
View
tools/cert_create/include/dualroot/cot.h
View
tools/cert_create/src/dualroot/cot.c
View
tools/fiptool/tbbr_config.c