<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>NCS encrypted MCUboot images supported?</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/73162/ncs-encrypted-mcuboot-images-supported</link><description>Is there support in NCS for MCUboot images encrypted with a different encryption key (not the same key as the signing key)? How is that configured (via prj.conf, etc)?</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Thu, 25 Mar 2021 08:47:08 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/73162/ncs-encrypted-mcuboot-images-supported" /><item><title>RE: NCS encrypted MCUboot images supported?</title><link>https://devzone.nordicsemi.com/thread/301819?ContentTypeID=1</link><pubDate>Thu, 25 Mar 2021 08:47:08 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:ebf0f666-5d3c-4a18-a7f8-2215ea9a3260</guid><dc:creator>Hung Bui</dc:creator><description>&lt;p&gt;Hi Denis,&amp;nbsp;&lt;br /&gt;I see. I thought you were asking for using your own signing key.&amp;nbsp;&lt;br /&gt;Regarding image encryption, you can find the documentation &lt;a href="https://developer.nordicsemi.com/nRF_Connect_SDK/doc/latest/mcuboot/encrypted_images.html"&gt;here&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I&amp;#39;m not too familiar with the topic but could you try follow this instruction from Simon in &lt;a href="https://devzone.nordicsemi.com/f/nordic-q-a/62488/mcuboot-ecies-encryption"&gt;this case &lt;/a&gt;?&amp;nbsp;&lt;br /&gt;I will try to get Simon to look into the case if you have any problem following his guide.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: NCS encrypted MCUboot images supported?</title><link>https://devzone.nordicsemi.com/thread/301789?ContentTypeID=1</link><pubDate>Thu, 25 Mar 2021 02:45:45 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:bf9f361f-14e7-456c-8065-64407f9978d8</guid><dc:creator>denis</dc:creator><description>&lt;p&gt;I&amp;rsquo;m aware of the signing. &amp;nbsp;I&amp;rsquo;d also like to encrypt the image. &amp;nbsp;Using a separate key.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: NCS encrypted MCUboot images supported?</title><link>https://devzone.nordicsemi.com/thread/301701?ContentTypeID=1</link><pubDate>Wed, 24 Mar 2021 13:55:55 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:5fe83f49-9eee-4457-b1c4-335c7a64d32c</guid><dc:creator>Hung Bui</dc:creator><description>&lt;p&gt;Hi Denis,&amp;nbsp;&lt;/p&gt;
&lt;p&gt;There is a clarification here. Image signing is not encrypting image. What it does is to hash the image and then use the signature to sign the hash. You can read about that &lt;a href="https://developer.nordicsemi.com/nRF_Connect_SDK/doc/latest/mcuboot/signed_images.html"&gt;here.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;You can also use imgtool to generate&amp;nbsp;your own key file,&amp;nbsp;documentation &lt;a href="https://developer.nordicsemi.com/nRF_Connect_SDK/doc/latest/mcuboot/imgtool.html"&gt;here.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;There are a few of related Devzone case that can be useful :&amp;nbsp;&lt;br /&gt;&lt;a href="https://devzone.nordicsemi.com/f/nordic-q-a/72365/best-process-for-signing-firmware-images-when-using-mcuboot"&gt;https://devzone.nordicsemi.com/f/nordic-q-a/72365/best-process-for-signing-firmware-images-when-using-mcuboot&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://devzone.nordicsemi.com/f/nordic-q-a/61048/signing-zephyr-images---west-sign"&gt;devzone.nordicsemi.com/.../signing-zephyr-images---west-sign&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>