What does this option mean? I didn’t find explanation of it.
-S ------------ 128bit Secure Boot Key file in HEX format.
What is format of this file ?
This?
0x12345678 0x9abcdef0 0xfedcba98 0x76543210
Or this?
0x123456789abcdef0fedcba9876543210
The -p option is to loock the PKC and SBK key. Without it, if the bits of PKC and SBK are 0, they can still be programmed to 1. However, there is an issue of programming PKC + SBK without -p, so please always set the option on Xavier and Xavier NX.