Thanks Jerry,
I did see Topic 284400 and I already regenerated the EKS image/partition. I have verified that the new EKS image is present after flashing because I have patched OPTEE (nv-optee) to print the FV and EKB CMAC values and they match what I expect; I can see the CMAC in the EKB image via hexdump -C
and it matches the CMAC OPTEE prints as ekb->ekb_cmac
.