1config CHAIN_OF_TRUST 2 depends on !FIT_SIGNATURE && SECURE_BOOT 3 imply CMD_BLOB 4 imply CMD_HASH if ARM 5 select FSL_CAAM 6 select SPL_BOARD_INIT if (ARM && SPL) 7 select SHA_HW_ACCEL 8 select SHA_PROG_HW_ACCEL 9 bool 10 default y 11 12config CMD_ESBC_VALIDATE 13 bool "Enable the 'esbc_validate' and 'esbc_halt' commands" 14 default y if CHAIN_OF_TRUST 15 help 16 This option enables two commands used for secure booting: 17 18 esbc_validate - validate signature using RSA verification 19 esbc_halt - put the core in spin loop (Secure Boot Only) 20