README.md
1| Supported Targets | ESP32 |
2| ----------------- | ----- |
3
4# Secure Boot
5
6The example checks if the secure boot feature is enabled/disabled and if enabled prints the secure boot version (Version 1 / Version 2) and FLASH_CRYPT_CNT eFuse value.
7
8## How to use example
9
10### Hardware Required
11
12ESP32 (supports Secure Boot V1) or ESP32-ECO3 (supports Secure Boot V2 & Secure Boot V1). It is recommended to use Secure Boot V2 from ESP32-ECO3 onwards.
13
14### Configure the project
15
16```
17idf.py menuconfig
18```
19
20* Set serial port under Serial Flasher Options.
21
22* Enable the `Enable hardware Secure Boot` under Security Features. Default version for ESP32 is Secure Boot V1. The chip revision should be changed to revision 3(ESP32- ECO3) to view the Secure Boot V2 option.
23
24* To change the chip revision, set "Component Config" -> "ESP32- Specific"->"Minimum Supported ESP32 Revision" to Rev 3. Now, set Secure Boot V2 option can now be enabled under "Enable hardware Secure Boot in bootloader" -> "Secure Boot Version".
25
26* Specify the apt secure boot signing key path. If not present generate one using `python $IDF_PATH/components/esptool_py/esptool/espsecure.py generate_signing_key --version {VERSION} secure_boot_signing_key.pem`
27
28* Ensure Bootloader log verbosity is Info under Bootloader config.
29
30* Select Single factory app, no OTA under Partition Table options. Change the partition table offset to 0xb000 from 0x8000 since after enabling secure boot the size of bootloader is increased.
31
32### Build and Flash
33
34- The below steps can be used in any application to enable secure boot.
35
36- Secure Boot is an irreversible operation, please read the Secure Boot section in ESP-IDF Programming Manual.
37
38- Secure boot will be enabled on building the project after enabling hardware secure boot feature in _Security features_ in menuconfig and flashing it to the board FOR THE FIRST TIME.
39
40- The bootloader will not be automatically flashed when secure boot is enabled. Running `idf.py bootloader` will print a command to flash the bootloader on the ESP32. Run this command manually to flash the bootloader.
41
42Run following command to program the partition table and application on the ESP32 and monitor the output:
43```
44idf.py -p PORT flash monitor
45```
46
47(To exit the serial monitor, type ``Ctrl-]``.)
48
49See the Getting Started Guide for full steps to configure and use ESP-IDF to build projects.
50
51- On subsequent boots, the secure boot hardware will verify the software bootloader has not changed and the software bootloader will verify the signed app image (using the validated public key portion of its appended signature block).
52
53## Example Output
54
55## Troubleshooting
56
57