# Secure Boot -Generating cwe file

**URL:** https://forum.legato.io/t/secure-boot-generating-cwe-file/5615
**Category:** Uncategorized
**Created:** [February 17, 2021, 10:44am UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615 "2021-02-17T10:44:58Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Pankaj](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/pankaj/32/1317_2.png) [@Pankaj](https://forum.legato.io/u/Pankaj)
#### Post date: [February 17, 2021, 10:44am UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/1 "2021-02-17T10:44:59Z")

</div>

Trying to use Secure Boot with WP7608 and have a few questions going through the Secure Boot Application note from the source.

1. Section 6.2 step 4 mentions about packaging signed images into a CWE image. The script mentions mdm9x28-image-cwe.inc depends on cwetool-native wherein it is not mentioned on how to use it ?

2. Syntax of the script and whether it has to be put in the same folder as the signing server is not mentioned?

3. How to verify the image is signed properly with the key, before loading it into the device?

4. There is no build seen for cwetool-native does this need to be built in the SDK for use?

---

<div class="post-metadata">

### Author: ![Pankaj](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/pankaj/32/1317_2.png) [@Pankaj](https://forum.legato.io/u/Pankaj)
#### Post date: [February 17, 2021, 10:58am UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/2 "2021-02-17T10:58:26Z")

</div>

Further questions:

1. to Generate cwe files do we need to use the linux source and bitbake tool?  
maybe we can provide the task using the command bitbake mdm9x28-image-minimal -c generate\_cwe in this case how to specify the signed image components for cwe generation?

---

<div class="post-metadata">

### Author: ![jyijyi](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/jyijyi/32/822_2.png) [@jyijyi](https://forum.legato.io/u/jyijyi)
#### Post date: [February 17, 2021, 1:15pm UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/3 "2021-02-17T13:15:19Z")

</div>

You can see this document:  
[Example on Secure boot implementation for WP76xx.docx](https://forum.legato.io/uploads/short-url/d5OKBJ89h0XWnq3lKjZQnaFwx15.docx) (173.5 KB)

---

<div class="post-metadata">

### Author: ![jyijyi](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/jyijyi/32/822_2.png) [@jyijyi](https://forum.legato.io/u/jyijyi)
#### Post date: [December 6, 2021, 6:53am UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/4 "2021-12-06T06:53:03Z")

</div>

updated version including bootloader/kernel/rootFS/legatoFS authentication in FW R16:  
[Example on Secure boot implementation for WP76xx (version 7).docx](https://forum.legato.io/uploads/short-url/xnRX0BZEcAtoMaRspewk3BdtCSp.docx) (376.4 KB)

---

<div class="post-metadata">

### Author: ![Pankaj](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/pankaj/32/1317_2.png) [@Pankaj](https://forum.legato.io/u/Pankaj)
#### Post date: [January 3, 2022, 7:15am UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/5 "2022-01-03T07:15:05Z")

</div>

Dear @jyijyi

Thanks for the detailed documentation I will test this and update if any issues faced.

Thanks & Regards,

Pankaj Sant

---

<div class="post-metadata">

### Author: ![Pankaj](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/pankaj/32/1317_2.png) [@Pankaj](https://forum.legato.io/u/Pankaj)
#### Post date: [December 2, 2022, 4:03am UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/6 "2022-12-02T04:03:11Z")

</div>

@jyijyi

The android Signing tool provided in the attached document is pretty old and from 2021 to 2022 there has been new firmware released for WP76 ( from R16 to R16.1.1), can you please confirm if the attached tools in the document can still be used with R16.1.1?

Alternatively for user building WP76 yocto can he copy the tools from his own yocto workspace? This would be helpful as at every future firmware change the signing tool can be updated from the corresponding Yocto workspace?

---

<div class="post-metadata">

### Author: ![jyijyi](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/jyijyi/32/822_2.png) [@jyijyi](https://forum.legato.io/u/jyijyi)
#### Post date: [December 2, 2022, 7:53am UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/7 "2022-12-02T07:53:59Z")

</div>

aren’t the yocto version the same in R16.0.1 and R16.1?

 ![image](https://us1.discourse-cdn.com/flex019/uploads/legato1/original/2X/d/d6570982269bbd513cfd3a8b2da225300a12eb66.png)  
 ![image](https://us1.discourse-cdn.com/flex019/uploads/legato1/original/2X/a/a72951b6271670165953dc73a8c0e8c0a862c098.png)

BTW, here is an updated version of document for applying secure boot to new memory  
[Example on Secure boot implementation for WP76xx (version 6).docx](https://forum.legato.io/uploads/short-url/ivtnrIvFXOPqGiOC6WY6mtrtyEK.docx) (371.9 KB)

Of course you can take the one in your own workspace and diff to the one in document and see if there is any difference.

---

<div class="post-metadata">

### Author: ![pankaj1](https://avatars.discourse-cdn.com/v4/letter/p/8baadc/32.png) [@pankaj1](https://forum.legato.io/u/pankaj1)
#### Post date: [December 2, 2022, 12:30pm UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/8 "2022-12-02T12:30:58Z")

</div>

Following the steps on Ubuntu 18.04 when running the step to sign the image android\_signature\_add\_R16.sh getting the following error:

./android\_signature\_add\_R16.sh /boot boot-yocto-mdm9x28.4k.unsigned.img boot-yocto-mdm9x28.4k.img verity  
Password for the private key file:  
Exception in thread “main” java.security.NoSuchAlgorithmException: 1.2.840.113549.1.5.13 SecretKeyFactory not available  
at java.base/javax.crypto.SecretKeyFactory.(SecretKeyFactory.java:122)  
at java.base/javax.crypto.SecretKeyFactory.getInstance(SecretKeyFactory.java:168)  
at com.android.verity.Utils.decryptPrivateKey(Utils.java:150)  
at com.android.verity.Utils.loadDERPrivateKey(Utils.java:166)  
at com.android.verity.Utils.loadDERPrivateKeyFromFile(Utils.java:189)  
at com.android.verity.BootSignature.doSignature(BootSignature.java:264)  
at com.android.verity.BootSignature.main(BootSignature.java:324)  
Looking here [Java 256-bit AES Password-Based Encryption - Stack Overflow](https://stackoverflow.com/questions/992019/java-256-bit-aes-password-based-encryption/992413#992413) seems to be Java bug

> <https://stackoverflow.com/questions/8397047/what-secretkeyfactory-not-available-does-mean>

Is there any solution to this issue in ubuntu 18.04? Which Ubuntu version is recommended for signing the ubuntu image?

---

<div class="post-metadata">

### Author: ![pankaj1](https://avatars.discourse-cdn.com/v4/letter/p/8baadc/32.png) [@pankaj1](https://forum.legato.io/u/pankaj1)
#### Post date: [December 2, 2022, 12:33pm UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/9 "2022-12-02T12:33:28Z")

</div>

Actual bug info here :

[https://bugs.openjdk.org/browse/JDK-8226824](https://bugs.openjdk.org/browse/JDK-8226824)

Java Version used in Ubuntu 18.04:

java --version  
openjdk 11.0.17 2022-10-18  
OpenJDK Runtime Environment (build 11.0.17+8-post-Ubuntu-1ubuntu218.04)  
OpenJDK 64-Bit Server VM (build 11.0.17+8-post-Ubuntu-1ubuntu218.04, mixed mode, sharing)

---

<div class="post-metadata">

### Author: ![jyijyi](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/jyijyi/32/822_2.png) [@jyijyi](https://forum.legato.io/u/jyijyi)
#### Post date: [December 2, 2022, 2:24pm UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/10 "2022-12-02T14:24:42Z")

</div>

I used java8 in ubuntu

```auto
owner@CNHKG-EX-001367:~/QMI/MBPL/R23/USB$ java -version

openjdk version "1.8.0_292"

OpenJDK Runtime Environment (build 1.8.0_292-8u292-b10-0ubuntu1~16.04.1-b10)

OpenJDK 64-Bit Server VM (build 25.292-b10, mixed mode)

```

---

<div class="post-metadata">

### Author: ![pankaj1](https://avatars.discourse-cdn.com/v4/letter/p/8baadc/32.png) [@pankaj1](https://forum.legato.io/u/pankaj1)
#### Post date: [December 3, 2022, 4:19am UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/11 "2022-12-03T04:19:43Z")

</div>

Have used java8 on ubuntu 18.04 as below:

 ![image](https://us1.discourse-cdn.com/flex019/uploads/legato1/original/2X/e/e439e0255032e37e4b5634ad087efe0011688cda.png)

Still facing the same error? I see that if there is no password provided in step 2 generate keystore cwe image then the error is not faced.

Can you kindly confirm if providing password in step 2 is mandatory or we can use without password.

---

<div class="post-metadata">

### Author: ![jyijyi](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/jyijyi/32/822_2.png) [@jyijyi](https://forum.legato.io/u/jyijyi)
#### Post date: [December 3, 2022, 4:50am UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/12 "2022-12-03T04:50:49Z")

</div>

Using incorrect password should show the followings:

```auto

owner@CNHKG-EX-001367:~/Yocto/tools/signing_dir$ ./android_signature_add.sh /boot boot-yocto-mdm9x28.4k.unsigned.img boot-yocto-mdm9x28.4k.img
Password for the private key file: 
Password may be bad.
Exception in thread "main" java.security.spec.InvalidKeySpecException: Cannot retrieve the PKCS8EncodedKeySpec
	at javax.crypto.EncryptedPrivateKeyInfo.getKeySpec(EncryptedPrivateKeyInfo.java:255)
	at com.android.verity.Utils.decryptPrivateKey(Utils.java:158)
	at com.android.verity.Utils.loadDERPrivateKey(Utils.java:166)
	at com.android.verity.Utils.loadDERPrivateKeyFromFile(Utils.java:189)
	at com.android.verity.BootSignature.doSignature(BootSignature.java:264)
	at com.android.verity.BootSignature.main(BootSignature.java:324)
Caused by: javax.crypto.BadPaddingException: Given final block not properly padded. Such issues can arise if a bad key is used during decryption.
	at com.sun.crypto.provider.CipherCore.unpad(CipherCore.java:975)
	at com.sun.crypto.provider.CipherCore.fillOutputBuffer(CipherCore.java:1056)
	at com.sun.crypto.provider.CipherCore.doFinal(CipherCore.java:853)
	at com.sun.crypto.provider.PBES1Core.doFinal(PBES1Core.java:432)
	at com.sun.crypto.provider.PBEWithMD5AndDESCipher.engineDoFinal(PBEWithMD5AndDESCipher.java:316)
	at javax.crypto.Cipher.doFinal(Cipher.java:2168)
	at javax.crypto.EncryptedPrivateKeyInfo.getKeySpec(EncryptedPrivateKeyInfo.java:250)
	... 5 more

```

Using correct password should show the followings:

```auto

owner@CNHKG-EX-001367:~/Yocto/tools/signing_dir$ ./android_signature_add.sh /boot boot-yocto-mdm9x28.4k.unsigned.img boot-yocto-mdm9x28.4k.img
Password for the private key file: 
owner@CNHKG-EX-001367:

```

You can try the same openjdk version “1.8.0\_292” as mine

---

<div class="post-metadata">

### Author: ![Pankaj](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/pankaj/32/1317_2.png) [@Pankaj](https://forum.legato.io/u/Pankaj)
#### Post date: [December 3, 2022, 9:21am UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/13 "2022-12-03T09:21:29Z")

</div>

What if we do not use the password at all? No password we just press enter during creating of keystore.

---

<div class="post-metadata">

### Author: ![jyijyi](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/jyijyi/32/822_2.png) [@jyijyi](https://forum.legato.io/u/jyijyi)
#### Post date: [December 3, 2022, 12:00pm UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/14 "2022-12-03T12:00:57Z")

</div>

have you created a test key that required password?  
you can then test the password with your environment

---

<div class="post-metadata">

### Author: ![Pankaj](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/pankaj/32/1317_2.png) [@Pankaj](https://forum.legato.io/u/Pankaj)
#### Post date: [December 4, 2022, 4:11am UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/15 "2022-12-04T04:11:03Z")

</div>

Yes the key is created without password and used for signing the image and the module is working correctly with the signed image.

For the legato image signing the yocto code does not contain the legato-af can you let us know how we can use the files from legato-af from VScode?

---

<div class="post-metadata">

### Author: ![jyijyi](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/jyijyi/32/822_2.png) [@jyijyi](https://forum.legato.io/u/jyijyi)
#### Post date: [December 4, 2022, 4:29am UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/16 "2022-12-04T04:29:42Z")

</div>

then do you mean your java was working fine for signing the image?  
What version did you use at that time?

For your second question, do you mean the following in step 4?

 ![image](https://us1.discourse-cdn.com/flex019/uploads/legato1/original/2X/9/9945e1babcdb6dd1a275749a9d45033d253317ca.png)

I think you can use this one:  
./build\_bin/tmp/sysroots-components/x86\_64/cwetool-native/usr/bin/hdrcnv

For ubinize.cfg , you can use mine as it is just a configuration file:  
[ubinize.cfg](https://forum.legato.io/uploads/short-url/7JYtG8iXoOst5uLvEgHP1B31IHr.cfg) (514 Bytes)

---

<div class="post-metadata">

### Author: ![Pankaj](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/pankaj/32/1317_2.png) [@Pankaj](https://forum.legato.io/u/Pankaj)
#### Post date: [December 4, 2022, 6:38am UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/17 "2022-12-04T06:38:08Z")

</div>

Thanks I will try these files but for the rhash.bin I am not able to find it in my legato app setup using Vscode:

here is the reference from document:

 ![image](https://us1.discourse-cdn.com/flex019/uploads/legato1/original/2X/6/636454e35ea213c8c7b3e6008acf8c10ab6746f2.png)

Here is the image of my vscode setup where rhash.bin is missing in leaf-data folder:

 ![image](https://us1.discourse-cdn.com/flex019/uploads/legato1/original/2X/2/290dd3095a3f3d293f0ca63c1fcb2eb4a383965c.png)

Also not available in current folder as seen here:

 ![image](https://us1.discourse-cdn.com/flex019/uploads/legato1/original/2X/0/03fcc90cb548b4f9810469fe9bb4dedcd81a0875.png)

Regarding the java issue I skipped entering password here in step 6 :

 ![image](https://us1.discourse-cdn.com/flex019/uploads/legato1/original/2X/2/2ee5369c5e05a35eeaca5124ced1bb0af21b3c28.png)

Just press enter without any password and then when signing the image here:

 ![image](https://us1.discourse-cdn.com/flex019/uploads/legato1/original/2X/9/900b5740aac2f93a40d744d4e16e513a28de9d15.png)

it does not ask you for password. It seems the password step is not mandatory and it is just for protection of the keystore.

btw for the java issue when I get some time I will try to make a docker container with Ubuntu 16 and try to sign the image in the container.

Will share that details later for now can you please let me know how to get the rhash.bin in vscode setup?

Thanks in advance.

---

<div class="post-metadata">

### Author: ![jyijyi](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/jyijyi/32/822_2.png) [@jyijyi](https://forum.legato.io/u/jyijyi)
#### Post date: [December 4, 2022, 6:44am UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/18 "2022-12-04T06:44:01Z")

</div>

you need to make the legato image by “make wp76xx” in leaf shell , after that you will see it here:

```auto
(lsh:WP76_stable) owner@CNHKG-EX-001367:~/LEAF/WP76/leaf-data/WP76_stable/wp76-legato$ ls ./build/wp76xx/rhash.bin 
./build/wp76xx/rhash.bin

```

---

<div class="post-metadata">

### Author: ![Pankaj](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/pankaj/32/1317_2.png) [@Pankaj](https://forum.legato.io/u/Pankaj)
#### Post date: [December 4, 2022, 7:36am UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/19 "2022-12-04T07:36:24Z")

</div>

will make\_wp76xx generate the rhash.bin for the default legato AF inside the leaf-data folder? In our case we have applications outside the leaf-data folder and we convert the .update file to .cwe.

Therefore do we have to move our applications into default .sdef so our applications are built with make\_wp76xx and are included in rhash.bin?

---

<div class="post-metadata">

### Author: ![jyijyi](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.legato.io/jyijyi/32/822_2.png) [@jyijyi](https://forum.legato.io/u/jyijyi)
#### Post date: [December 4, 2022, 7:43am UTC](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615/20 "2022-12-04T07:43:32Z")

</div>

Yes. i did it inside the leaf-data folder  
I suggest you try on default one with “make wp76xx” first, this can make sure the signing procedure is working fine first.  
After that you can add your application to your legato image.

e.g.

> [@Flash size wp7607](https://forum.legato.io/t/flash-size-wp7607/3805/35):
>
> you can go to legato-19.02.0/modules/WiFi/wifi.sdef, under “apps:” section, add e.g. $LEGATO\_ROOT/apps/sample/helloWorld/helloWorld.adef [image] Now the new app will be included in legato.cwe. Please also note that the max size for legato partition is 8MB.

[Next page](https://forum.legato.io/t/secure-boot-generating-cwe-file/5615.md?page=2)
