# \#security

**URL:** https://forums.developer.nvidia.com/tag/security/51.md

[Latest](https://forums.developer.nvidia.com/latest.md) · [Categories](https://forums.developer.nvidia.com/categories.md) · [Tags](https://forums.developer.nvidia.com/tags.md)

---

## [L4T 36.5 Orin Nano, Yocto/meta-tegra: odmfuse.sh or R39 fskp\_fuseburn.py, and migrate to R39?](https://forums.developer.nvidia.com/t/l4t-36-5-orin-nano-yocto-meta-tegra-odmfuse-sh-or-r39-fskp-fuseburn-py-and-migrate-to-r39/382005)

<div class="topic-metadata">

**Author:** [@firas.loukil](https://forums.developer.nvidia.com/u/firas.loukil)\
**Replies:** 12\
**Last updated:** [October 8, 2026, 11:15am UTC](https://forums.developer.nvidia.com/t/l4t-36-5-orin-nano-yocto-meta-tegra-odmfuse-sh-or-r39-fskp-fuseburn-py-and-migrate-to-r39/382005 "2026-10-08T11:15:32Z")

</div>

Platform: Jetson Orin Nano 8GB devkit, L4T 36.5.0. Image built with Yocto/meta-tegra; fuse provisioning done in-house from a standard BSP install. The r36.5 Secure Boot page says odmfuse.sh is deprecated in favour of FS…

---

## [Secure OTA Update Support for Jetson Orin with Yocto](https://forums.developer.nvidia.com/t/secure-ota-update-support-for-jetson-orin-with-yocto/385134)

<div class="topic-metadata">

**Author:** [@vikas.patil1](https://forums.developer.nvidia.com/u/vikas.patil1)\
**Replies:** 3\
**Last updated:** [October 8, 2026, 10:49am UTC](https://forums.developer.nvidia.com/t/secure-ota-update-support-for-jetson-orin-with-yocto/385134 "2026-10-08T10:49:11Z")

</div>

Hi, I am currently researching Yocto-based Linux development on NVIDIA Jetson AGX Orin, Orin NX, and Orin Nano platforms, with a focus on implementing a secure OTA update mechanism. The requirements are: Secure Boot …

---

## [Secure boot fuse config with r39.2 can't run on r35.3](https://forums.developer.nvidia.com/t/secure-boot-fuse-config-with-r39-2-cant-run-on-r35-3/385344)

<div class="topic-metadata">

**Author:** [@lingsong.zheng](https://forums.developer.nvidia.com/u/lingsong.zheng)\
**Replies:** 1\
**Last updated:** [October 8, 2026, 6:01am UTC](https://forums.developer.nvidia.com/t/secure-boot-fuse-config-with-r39-2-cant-run-on-r35-3/385344 "2026-10-08T06:01:20Z")

</div>

I am currently working with the R39.2 BSP. My device Orin Nano 8G boots up fine with the following fuse configuration,： \<genericfuse MagicId="0x45535546" version="1.0.0"\> \<fuse name="OdmId" size="8" value="0x1000000…

---

## [CA is blocked by TA with open-tee](https://forums.developer.nvidia.com/t/ca-is-blocked-by-ta-with-open-tee/383328)

<div class="topic-metadata">

**Author:** [@smileandcry2023](https://forums.developer.nvidia.com/u/smileandcry2023)\
**Replies:** 15\
**Last updated:** [October 8, 2026, 3:35am UTC](https://forums.developer.nvidia.com/t/ca-is-blocked-by-ta-with-open-tee/383328 "2026-10-08T03:35:26Z")

</div>

Hi JP: 7.2 super HW: AGX orin 32GB We use CA to call TA, and several hours later, the ca is blocked and get no any message from ta the kernel log error is : 2026-09-15T17:44:16.304347+08:00 localhost kernel: \[TS:2…

---

## [The system fails to boot at the UEFI stage，after Update the db/dbx Keys with a Capsule Update](https://forums.developer.nvidia.com/t/the-system-fails-to-boot-at-the-uefi-stage-after-update-the-db-dbx-keys-with-a-capsule-update/382867)

<div class="topic-metadata">

**Author:** [@zhang.pei.xing](https://forums.developer.nvidia.com/u/zhang.pei.xing)\
**Replies:** 21\
**Last updated:** [October 7, 2026, 3:29am UTC](https://forums.developer.nvidia.com/t/the-system-fails-to-boot-at-the-uefi-stage-after-update-the-db-dbx-keys-with-a-capsule-update/382867 "2026-10-07T03:29:28Z")

</div>

hi nv team： jp version:jp6.2.1 Core Board：orin devkit && orin nano 8g. We attempted to perform a secure boot of UEFI, but encountered an issue while verifying the key update of DBX. My burning command is as follows. …

---

## [Disk Encryption](https://forums.developer.nvidia.com/t/disk-encryption/383476)

<div class="topic-metadata">

**Author:** [@david.r.wyatt](https://forums.developer.nvidia.com/u/david.r.wyatt)\
**Replies:** 5\
**Last updated:** [October 6, 2026, 3:20am UTC](https://forums.developer.nvidia.com/t/disk-encryption/383476 "2026-10-06T03:20:08Z")

</div>

Hello Team I have a need to encrypt the primary and secondary Nvme disks on an Nvidia nano devkit with an NX SOC. Following along in the documentation Nvidia recommends Ubuntu 22.04 on the host. I see in the forums…

---

## [Jetson Orin NX secure boot: confirm BootSecurityInfo fuse value](https://forums.developer.nvidia.com/t/jetson-orin-nx-secure-boot-confirm-bootsecurityinfo-fuse-value/385115)

<div class="topic-metadata">

**Author:** [@eva7](https://forums.developer.nvidia.com/u/eva7)\
**Replies:** 1\
**Last updated:** [October 6, 2026, 2:23am UTC](https://forums.developer.nvidia.com/t/jetson-orin-nx-secure-boot-confirm-bootsecurityinfo-fuse-value/385115 "2026-10-06T02:23:45Z")

</div>

Hi team. We’re currently preparing a production fleet of Orin NX devices for a retail deployment and need secure boot plus disk encryption enabled before shipping. A question came up during the process, could you route…

---

## [FSKP prebuilt blob is not burning any fuses](https://forums.developer.nvidia.com/t/fskp-prebuilt-blob-is-not-burning-any-fuses/384781)

<div class="topic-metadata">

**Author:** [@bcarrick](https://forums.developer.nvidia.com/u/bcarrick)\
**Replies:** 5\
**Last updated:** [October 2, 2026, 8:23pm UTC](https://forums.developer.nvidia.com/t/fskp-prebuilt-blob-is-not-burning-any-fuses/384781 "2026-10-02T20:23:23Z")

</div>

Hi! I’m currently trying to create an FSKP blob to burn the fuses on a Jetson Orin NX board. I created the prebuild package using the following command: ./fskp\_fuseburn.py --board-spec orinnx-board-spec.txt -f fuse.xml …

---

## [Does secure boot work when booting from SD card on the Orin Nano Dev Kit?](https://forums.developer.nvidia.com/t/does-secure-boot-work-when-booting-from-sd-card-on-the-orin-nano-dev-kit/384285)

<div class="topic-metadata">

**Author:** [@menahem](https://forums.developer.nvidia.com/u/menahem)\
**Replies:** 3\
**Last updated:** [September 30, 2026, 7:55am UTC](https://forums.developer.nvidia.com/t/does-secure-boot-work-when-booting-from-sd-card-on-the-orin-nano-dev-kit/384285 "2026-09-30T07:55:07Z")

</div>

Hi, I enabled PKC secure boot (PKC-only, no SBK/OemK1) per the R36.4.3 guide. Fuses burned OK: my .xml: $ cat ../pkc/fuse\_pkc.xml \<genericfuse MagicId="0x45535546" version="1.0.0"\> \<fuse name="PublicKeyHash" size…

---

## [Deterministic Interdiction & Governance for Agentic AI Workflows (Zero Trust Approach)](https://forums.developer.nvidia.com/t/deterministic-interdiction-governance-for-agentic-ai-workflows-zero-trust-approach/384131)

<div class="topic-metadata">

**Author:** [@ArchitectureHPR](https://forums.developer.nvidia.com/u/ArchitectureHPR)\
**Replies:** 0\
**Last updated:** [September 23, 2026, 5:38pm UTC](https://forums.developer.nvidia.com/t/deterministic-interdiction-governance-for-agentic-ai-workflows-zero-trust-approach/384131 "2026-09-23T17:38:48Z")

</div>

​Hi everyone, ​I’m currently researching and developing a Zero Trust Governance Engine designed for autonomous AI agents, with a strong focus on deterministic interdiction, auditability, and edge containment. ​As multi…

---

## [Orin Nano r36.4.4 — exact BootSecurityInfo value when burning OemK1 as the EKB fuse key](https://forums.developer.nvidia.com/t/orin-nano-r36-4-4-exact-bootsecurityinfo-value-when-burning-oemk1-as-the-ekb-fuse-key/383804)

<div class="topic-metadata">

**Author:** [@pavana](https://forums.developer.nvidia.com/u/pavana)\
**Replies:** 2\
**Last updated:** [September 22, 2026, 4:08pm UTC](https://forums.developer.nvidia.com/t/orin-nano-r36-4-4-exact-bootsecurityinfo-value-when-burning-oemk1-as-the-ekb-fuse-key/383804 "2026-09-22T16:08:50Z")

</div>

Hello, We are provisioning a Jetson Orin Nano 8GB devkit (P3768-0000 carrier, P3767-0005 module) on L4T r36.4.4 as a production customer unit, and we have one question we would rather confirm than infer, because the ope…

---

## [The issue of the number of PKC keys for Thor's secure boot](https://forums.developer.nvidia.com/t/the-issue-of-the-number-of-pkc-keys-for-thors-secure-boot/383601)

<div class="topic-metadata">

**Author:** [@zhongwenxin](https://forums.developer.nvidia.com/u/zhongwenxin)\
**Replies:** 6\
**Last updated:** [September 22, 2026, 3:38pm UTC](https://forums.developer.nvidia.com/t/the-issue-of-the-number-of-pkc-keys-for-thors-secure-boot/383601 "2026-09-22T15:38:28Z")

</div>

The official recommendation for the number of PKC keys for Thor’s secure boot is 16. In my actual key list, I only have one key, and I don’t consider that this key might leak information, nor do I need redundancy. Is thi…

---

## [Enable UEFI Secure Boot without Jetson Secure Boot on AGX Orin](https://forums.developer.nvidia.com/t/enable-uefi-secure-boot-without-jetson-secure-boot-on-agx-orin/383383)

<div class="topic-metadata">

**Author:** [@mark.tadourian2](https://forums.developer.nvidia.com/u/mark.tadourian2)\
**Replies:** 7\
**Last updated:** [September 18, 2026, 6:02am UTC](https://forums.developer.nvidia.com/t/enable-uefi-secure-boot-without-jetson-secure-boot-on-agx-orin/383383 "2026-09-18T06:02:36Z")

</div>

Hello, I want to confirm whether it is possible to enable UEFI Secure boot without also enabling/implementing the Jetson Secure Boot. Will there be any consequences for doing so? Thanks!

---

## [Odm\_lock 不能烧录0xFF](https://forums.developer.nvidia.com/t/odm-lock-0xff/381754)

<div class="topic-metadata">

**Author:** [@550399056](https://forums.developer.nvidia.com/u/550399056)\
**Replies:** 34\
**Last updated:** [September 15, 2026, 6:47am UTC](https://forums.developer.nvidia.com/t/odm-lock-0xff/381754 "2026-09-15T06:47:51Z")

</div>

您好， 我们现在使用的是orin nx16G jetpack 5.1.4 我在测试efuse的时候。 reserved\_odm2: 0x32424b4f reserved\_odm3: 0x30313034 reserved\_odm0: 0x53594a57 reserved\_odm1: 0x52503153 reserved\_odm6: 0x3fffffff reserved\_odm7: 0xffffffff res…

---

## [Prevent Thor users from flashing OS](https://forums.developer.nvidia.com/t/prevent-thor-users-from-flashing-os/382991)

<div class="topic-metadata">

**Author:** [@tandrew](https://forums.developer.nvidia.com/u/tandrew)\
**Replies:** 5\
**Last updated:** [September 15, 2026, 1:44am UTC](https://forums.developer.nvidia.com/t/prevent-thor-users-from-flashing-os/382991 "2026-09-15T01:44:05Z")

</div>

My group has a Jetson Thor that might be testing unsafe/insecure code. I want to prevent end users from being able to reinstall the operating system for security reasons. I have not been able to find any documentation on…

---

## [Orin Rootfs A/B issue caused by unexpected power loss,](https://forums.developer.nvidia.com/t/orin-rootfs-a-b-issue-caused-by-unexpected-power-loss/382841)

<div class="topic-metadata">

**Author:** [@rico.deng](https://forums.developer.nvidia.com/u/rico.deng)\
**Replies:** 11\
**Last updated:** [September 14, 2026, 12:20am UTC](https://forums.developer.nvidia.com/t/orin-rootfs-a-b-issue-caused-by-unexpected-power-loss/382841 "2026-09-14T00:20:33Z")

</div>

Hi： After enabling RootFS A/B on Orin, we have recently encountered multiple product issues caused by unexpected power loss, such as: The active rootfs slot switching unexpectedly. The system entering recovery mode an…

---

## [Request for official R35.6.0 UEFI fix for AGX Xavier A/B slot switching failure](https://forums.developer.nvidia.com/t/request-for-official-r35-6-0-uefi-fix-for-agx-xavier-a-b-slot-switching-failure/382138)

<div class="topic-metadata">

**Author:** [@shuang.cao](https://forums.developer.nvidia.com/u/shuang.cao)\
**Replies:** 5\
**Last updated:** [September 4, 2026, 1:59am UTC](https://forums.developer.nvidia.com/t/request-for-official-r35-6-0-uefi-fix-for-agx-xavier-a-b-slot-switching-failure/382138 "2026-09-04T01:59:20Z")

</div>

Hi NVIDIA Team, We have multiple Jetson AGX Xavier production devices running Jetson Linux R35.6.0 with ROOTFS A/B enabled. Affected devices show: bios\_version : 6.0-37391689 bios\_date : 08/28/2024 VarErrorFlag : 0…

---

## [Configuration of General Security Carveouts](https://forums.developer.nvidia.com/t/configuration-of-general-security-carveouts/381314)

<div class="topic-metadata">

**Author:** [@abrandao](https://forums.developer.nvidia.com/u/abrandao)\
**Replies:** 5\
**Last updated:** [September 2, 2026, 5:26am UTC](https://forums.developer.nvidia.com/t/configuration-of-general-security-carveouts/381314 "2026-09-02T05:26:27Z")

</div>

We have a Jetson AGX Orin devkit on Jetson Linux R38.4. We are trying to use the MC’s Generalized Security Carveouts to restrict which memory clients can reach a particular DRAM region, specifically restricting the iGPU …

---

## [THOR Secure Boot Issues](https://forums.developer.nvidia.com/t/thor-secure-boot-issues/381971)

<div class="topic-metadata">

**Author:** [@zhongwenxin](https://forums.developer.nvidia.com/u/zhongwenxin)\
**Replies:** 7\
**Last updated:** [September 1, 2026, 8:21am UTC](https://forums.developer.nvidia.com/t/thor-secure-boot-issues/381971 "2026-09-01T08:21:09Z")

</div>

Could you please advise? Currently, I’m testing secure boot on my local Thor board. When I started programming the eFuses, I didn’t set the security mode to 1, but all other settings were programmed normally. Under this …

---

## [THOR Secure Boot Issues](https://forums.developer.nvidia.com/t/thor-secure-boot-issues/381979)

<div class="topic-metadata">

**Author:** [@zhongwenxin](https://forums.developer.nvidia.com/u/zhongwenxin)\
**Replies:** 1\
**Last updated:** [September 1, 2026, 6:37am UTC](https://forums.developer.nvidia.com/t/thor-secure-boot-issues/381979 "2026-09-01T06:37:33Z")

</div>

Could you please advise? Currently, I’m testing secure boot on my local Thor T4000 board. When I started programming the eFuses, I didn’t set the security mode to 1, but all other settings were programmed normally. The v…

---

## [The warning sign was in the logs. Nobody looked for three weeks](https://forums.developer.nvidia.com/t/the-warning-sign-was-in-the-logs-nobody-looked-for-three-weeks/381800)

<div class="topic-metadata">

**Author:** [@SIPA-OS](https://forums.developer.nvidia.com/u/SIPA-OS)\
**Replies:** 0\
**Last updated:** [August 29, 2026, 2:32pm UTC](https://forums.developer.nvidia.com/t/the-warning-sign-was-in-the-logs-nobody-looked-for-three-weeks/381800 "2026-08-29T14:32:35Z")

</div>

The warning sign was in the logs. Nobody looked for three weeks. OpenAI’s own report on the Hugging Face incident names root cause as reward hacking: agents being evaluated on cybersecurity tasks found they could chain …

---

## [DGX Spark Security](https://forums.developer.nvidia.com/t/dgx-spark-security/359773)

<div class="topic-metadata">

**Author:** [@tsasse](https://forums.developer.nvidia.com/u/tsasse)\
**Replies:** 9\
**Last updated:** [August 27, 2026, 4:56pm UTC](https://forums.developer.nvidia.com/t/dgx-spark-security/359773 "2026-08-27T16:56:27Z")

</div>

Hello, My company has just purchased the DGX Spark, but after receiving the device our IS department has concerns about a network breach. More importantly whats stopping a bad apple from putting malware into the Live VL…

---

## [Hololink IP](https://forums.developer.nvidia.com/t/hololink-ip/381405)

<div class="topic-metadata">

**Author:** [@mohassan](https://forums.developer.nvidia.com/u/mohassan)\
**Replies:** 3\
**Last updated:** [August 27, 2026, 3:02pm UTC](https://forums.developer.nvidia.com/t/hololink-ip/381405 "2026-08-27T15:02:52Z")

</div>

Hi, Looking into implementing Hololink on an AMD FPGA development board. I downloaded the RTL files but they are encrypted. Could you tell me the process for obtaining the key? I want to get the decryption key for …

---

## [Rootfs A/B After flashing default to Slot B](https://forums.developer.nvidia.com/t/rootfs-a-b-after-flashing-default-to-slot-b/381305)

<div class="topic-metadata">

**Author:** [@meishujie](https://forums.developer.nvidia.com/u/meishujie)\
**Replies:** 2\
**Last updated:** [August 27, 2026, 7:11am UTC](https://forums.developer.nvidia.com/t/rootfs-a-b-after-flashing-default-to-slot-b/381305 "2026-08-27T07:11:13Z")

</div>

Hello Nvidia team, I have a question about Rootfs A/B. Enable Root File System Redundancy during the flashing process. After flashing, enter the system, the default is to enter slot A . nvidia@tegra-ubuntu:~$ lsblk N…

---

## [Orin Nano/NX startup issue after Secure Boot+RootFS+Disk Encryption](https://forums.developer.nvidia.com/t/orin-nano-nx-startup-issue-after-secure-boot-rootfs-disk-encryption/379517)

<div class="topic-metadata">

**Author:** [@chris\_luo](https://forums.developer.nvidia.com/u/chris_luo)\
**Replies:** 21\
**Last updated:** [August 26, 2026, 2:12am UTC](https://forums.developer.nvidia.com/t/orin-nano-nx-startup-issue-after-secure-boot-rootfs-disk-encryption/379517 "2026-08-26T02:12:47Z")

</div>

We are experiencing a high boot failure rate during the process of enabling Secure Boot, RootFS, and disk encryption on Orin Nano and NX modules. We strongly believe the primary cause is that the SOM is being used after…

---

## [T264 R39.2: BootSecurityInfo, PscOemKdk1 Dependencies, and PKC Key Revocation](https://forums.developer.nvidia.com/t/t264-r39-2-bootsecurityinfo-pscoemkdk1-dependencies-and-pkc-key-revocation/381113)

<div class="topic-metadata">

**Author:** [@Lucpos](https://forums.developer.nvidia.com/u/Lucpos)\
**Replies:** 7\
**Last updated:** [August 26, 2026, 2:12am UTC](https://forums.developer.nvidia.com/t/t264-r39-2-bootsecurityinfo-pscoemkdk1-dependencies-and-pkc-key-revocation/381113 "2026-08-26T02:12:09Z")

</div>

Hello NVIDIA team, We are planning the following Jetson Thor T264 / JP7.2 / R39.2 configuration: Configuration: RSA-3K PKC-only secure boot Full 16-entry PKC keylist, key\_id 0..15, each entry containing a distinct pu…

---

## [Can the Jetson bootloader and the rootfs A/B partitions be switched independently?](https://forums.developer.nvidia.com/t/can-the-jetson-bootloader-and-the-rootfs-a-b-partitions-be-switched-independently/380564)

<div class="topic-metadata">

**Author:** [@jackp](https://forums.developer.nvidia.com/u/jackp)\
**Replies:** 4\
**Last updated:** [August 21, 2026, 3:50am UTC](https://forums.developer.nvidia.com/t/can-the-jetson-bootloader-and-the-rootfs-a-b-partitions-be-switched-independently/380564 "2026-08-21T03:50:43Z")

</div>

On Jetson systems, both the bootloader and rootfs have their own A/B partitions. In practice, I’ve found that setting the bootloader/rootfs slot separately using the following command also changes the other slot, for ex…

---

## [Question about TEE Secure Storage and Firmware Update on Jetson Orin NX](https://forums.developer.nvidia.com/t/question-about-tee-secure-storage-and-firmware-update-on-jetson-orin-nx/379990)

<div class="topic-metadata">

**Author:** [@Jerry-W](https://forums.developer.nvidia.com/u/Jerry-W)\
**Replies:** 6\
**Last updated:** [August 18, 2026, 8:23am UTC](https://forums.developer.nvidia.com/t/question-about-tee-secure-storage-and-firmware-update-on-jetson-orin-nx/379990 "2026-08-18T08:23:31Z")

</div>

Hi NVIDIA Team, I am working with Jetson Orin NX using Jetson Linux 36.4.4 and have some questions regarding TEE secure storage. I noticed that the TEE data is currently stored in the REE filesystem. From my understand…

---

## [NVIDIA Sync bundles an outdated Tailscale version (v1.92.5) in 0.100.19-18](https://forums.developer.nvidia.com/t/nvidia-sync-bundles-an-outdated-tailscale-version-v1-92-5-in-0-100-19-18/379413)

<div class="topic-metadata">

**Author:** [@pducharme](https://forums.developer.nvidia.com/u/pducharme)\
**Replies:** 5\
**Last updated:** [August 13, 2026, 6:17pm UTC](https://forums.developer.nvidia.com/t/nvidia-sync-bundles-an-outdated-tailscale-version-v1-92-5-in-0-100-19-18/379413 "2026-08-13T18:17:54Z")

</div>

NVIDIA Sync bundles an outdated Tailscale version (v1.92.5) in 0.100.19-18 Hi NVIDIA team, While troubleshooting NVIDIA Sync’s Tailscale integration on macOS (Apple Silicon), I inspected the bundled nvsync-arm64 binary …

---

## [Application encryption or other security mechanism](https://forums.developer.nvidia.com/t/application-encryption-or-other-security-mechanism/377470)

<div class="topic-metadata">

**Author:** [@adrian\_erofei](https://forums.developer.nvidia.com/u/adrian_erofei)\
**Replies:** 3\
**Last updated:** [August 13, 2026, 4:32pm UTC](https://forums.developer.nvidia.com/t/application-encryption-or-other-security-mechanism/377470 "2026-08-13T16:32:43Z")

</div>

I am using an Jetson AGX Orin Developer Kit 64GB with JetPack (6.2.1) R36.4.7 For this kit and Processor/OS combination are there any security features that we can enable to protect proprietary application SW code? I …

[Next page](https://forums.developer.nvidia.com/tag/security/51.md?match_all_tags=true&page=1&tags%5B%5D=security)
