From 80f5acee8fd41d0e94090f4d936ebb5998b64ac6 Mon Sep 17 00:00:00 2001 From: Sebastiano Barezzi Date: Tue, 4 Oct 2022 23:51:44 +0200 Subject: [PATCH] sm6250-common: Use RSA4096 keys for recovery and vbmeta_system * Per https://android.googlesource.com/platform/external/avb/+/master/README.md#build-system-integration, SHA256_RSA4096 is used if BOARD_AVB_ALGORITHM isn't defined * We can assume bootloader is able to understand RSA4096 keys for recovery and vbmeta_system as well Change-Id: I7325387ed4bf04407629c48bbc2e7126c151c192 --- BoardConfigCommon.mk | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/BoardConfigCommon.mk b/BoardConfigCommon.mk index 7d2e910..60f5d51 100644 --- a/BoardConfigCommon.mk +++ b/BoardConfigCommon.mk @@ -178,13 +178,13 @@ BOARD_SEPOLICY_DIRS += $(COMMON_PATH)/sepolicy/vendor # Verified Boot BOARD_AVB_ENABLE := true BOARD_AVB_MAKE_VBMETA_IMAGE_ARGS += --flags 3 -BOARD_AVB_RECOVERY_KEY_PATH := external/avb/test/data/testkey_rsa2048.pem -BOARD_AVB_RECOVERY_ALGORITHM := SHA256_RSA2048 +BOARD_AVB_RECOVERY_KEY_PATH := external/avb/test/data/testkey_rsa4096.pem +BOARD_AVB_RECOVERY_ALGORITHM := SHA256_RSA4096 BOARD_AVB_RECOVERY_ROLLBACK_INDEX := $(PLATFORM_SECURITY_PATCH_TIMESTAMP) BOARD_AVB_RECOVERY_ROLLBACK_INDEX_LOCATION := 1 BOARD_AVB_VBMETA_SYSTEM := system system_ext product -BOARD_AVB_VBMETA_SYSTEM_KEY_PATH := external/avb/test/data/testkey_rsa2048.pem -BOARD_AVB_VBMETA_SYSTEM_ALGORITHM := SHA256_RSA2048 +BOARD_AVB_VBMETA_SYSTEM_KEY_PATH := external/avb/test/data/testkey_rsa4096.pem +BOARD_AVB_VBMETA_SYSTEM_ALGORITHM := SHA256_RSA4096 BOARD_AVB_VBMETA_SYSTEM_ROLLBACK_INDEX := $(PLATFORM_SECURITY_PATCH_TIMESTAMP) BOARD_AVB_VBMETA_SYSTEM_ROLLBACK_INDEX_LOCATION := 1