*** Please note that this reply is generated by LLM automatically ***
A question about secure boot on the Jetson AGX Orin!
According to the NVIDIA Jetson Linux Developer Guide, burning the fuse with “Factory Secure Key and Expansion Key Provisioning” enables secure boot on the Jetson AGX Orin board. This means that the board will only boot with authorized firmware and software, which enhances the security of the system.
Once the fuse is burned, the board will enter secure boot mode permanently. This is a one-way process, and there is no way to revert back to non-secure boot mode without reflashing the entire board.
However, you can verify the secure boot feature without entering secure boot mode permanently by using the following methods:
Check the boot logs: During the boot process, the board will display boot logs that indicate whether secure boot is enabled or not. You can check these logs to verify that secure boot is working correctly.
Use the tegrasign tool: The tegrasign tool is a part of the NVIDIA Jetson Linux Developer Guide. It allows you to sign and verify the boot images, which can help you verify that secure boot is working correctly.
Verify the fuse status: You can use the tegradevfuse tool to verify the status of the fuse. This tool can help you check whether the fuse has been burned correctly and whether secure boot is enabled.
To verify secure boot in normal development mode, you can use the following steps:
Boot the board in normal development mode.
Use the tegrasign tool to sign a test boot image.
Use the tegradevfuse tool to verify that the fuse has been burned correctly.
Boot the board with the signed test boot image.
Check the boot logs to verify that secure boot is working correctly.
By following these steps, you can verify the secure boot feature on the Jetson AGX Orin board without entering secure boot mode permanently.
In comparison to other Jetson boards, the secure boot process on the Jetson AGX Orin is similar to that on the Jetson Xavier NX and Jetson Orin NX. However, the specific steps and tools may vary depending on the board and the version of the NVIDIA Jetson Linux Developer Guide.
I hope this helps! Let me know if you have any further questions.
*** Please give the thumbs up if you get answers you like. Or provide feedback to help us improve the answer. ***
If I don’t burn fuse, How does the Orin AGX board start secure boot process?
In other words, what flag can trigger Orin AGX board to start secure boot process to verify the first image of bootloader, and then verify continuously?
the question should be.. what/how is your verification steps?
there’re bootloader secureboot and UEFI secureboot. you’ll need to burn fuse to enable bootloader secureboot, you may have UEFI secure boot enabled independently.
note, Secure boot establishes a root of trust, when you enable bootloader secure boot (to burn those fuse variables), the root-of-trust can start from the BootROM.
BTW,
once you’ve fused a target, you’ll need to provide the exactly same keys for running flash command-line. otherwise, it’ll abort the flashing process.
there’s Boot Rom communication in the early stage.
for instance,
it’ll report the errors like below and abort the process if you did not given keys to the fused target. Error: Either RSA key file is not provided or SBK key file is provided for PKC protected target board.
But I don’t know why it appears in section Factory Secure Key and Expansion Key Provisioning.
Where the Self-Signed X.509 Certificate will be used? And why the CER file is sent to the NVIDIA key custodian? What will NVIDIA key custodian do after receiving the CER file?