1config CHAIN_OF_TRUST 2 depends on !FIT_SIGNATURE && SECURE_BOOT 3 imply CMD_BLOB 4 imply CMD_HASH if ARM 5 select FSL_CAAM 6 select SPL_BOARD_INIT if (ARM && SPL) 7 select SHA_HW_ACCEL 8 select SHA_PROG_HW_ACCEL 9 select ENV_IS_NOWHERE 10 select CMD_EXT4 if ARM 11 select CMD_EXT4_WRITE if ARM 12 bool 13 default y 14 15config CMD_ESBC_VALIDATE 16 bool "Enable the 'esbc_validate' and 'esbc_halt' commands" 17 default y if CHAIN_OF_TRUST 18 help 19 This option enables two commands used for secure booting: 20 21 esbc_validate - validate signature using RSA verification 22 esbc_halt - put the core in spin loop (Secure Boot Only) 23