<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>mcuboot signature validation</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/86175/mcuboot-signature-validation</link><description>Hi, 
 I am working on DFU-OTA example on BLE. my doubt here is once the controller copied the image into slot1 bootloader will immediately start to validate whether the image is valid or not . if it&amp;#39;s valid then it will go for soft-reset. then control</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Wed, 30 Mar 2022 11:12:27 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/86175/mcuboot-signature-validation" /><item><title>RE: mcuboot signature validation</title><link>https://devzone.nordicsemi.com/thread/360781?ContentTypeID=1</link><pubDate>Wed, 30 Mar 2022 11:12:27 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:40ff9c09-3810-4585-8673-47091c0cff1c</guid><dc:creator>Amanda Hsieh</dc:creator><description>&lt;p&gt;Hi,&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Sorry. I need to correct my answer after confirming with the team.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;There is no pre-validation before the mcuboot gets triggered in NCS.&amp;nbsp;Real validation of the image (integrity check, authentication, decryption) is up to the secure bootloader. We can&amp;#39;t do anything about that right now, only the bootloader has full knowledge and access to private keys. It is up to the application to verify whether the allowed remote actor provides the image and requests the update.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;-Amanda&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: mcuboot signature validation</title><link>https://devzone.nordicsemi.com/thread/360651?ContentTypeID=1</link><pubDate>Wed, 30 Mar 2022 05:32:53 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:77fe6834-8c68-4834-98e1-48460969dcda</guid><dc:creator>Shikamaru</dc:creator><description>&lt;p&gt;thanks amanda,&lt;/p&gt;
&lt;p&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; In 1st validation , it will only check whether the dfu is triggered by the image or not . nothing else , all the security related things are done in booting phase by mcuboot. But how it is checking the &lt;strong&gt;triggering of the dfu in 1st validation part&lt;/strong&gt; , that am not understanding can you please update on this.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: mcuboot signature validation</title><link>https://devzone.nordicsemi.com/thread/359800?ContentTypeID=1</link><pubDate>Thu, 24 Mar 2022 12:32:19 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:105e83a9-bc32-41c2-a16d-a3405c3ceaec</guid><dc:creator>Amanda Hsieh</dc:creator><description>&lt;p&gt;Hi,&amp;nbsp;&lt;/p&gt;
&lt;p&gt;It doesn&amp;#39;t verify&amp;nbsp;security&amp;nbsp;if the image sings with a key. The key will be verified while booting. See&amp;nbsp;&lt;a href="http://developer.nordicsemi.com/nRF_Connect_SDK/doc/latest/nrf/ug_fw_update.html#id5"&gt;Revoking private keys&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Regards,&amp;nbsp;&lt;br /&gt;Amanda&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>