- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to cancel the root keys in intel agilex series?
If root keys got compromised, how to cancel the rot keys ID from HPS linux userspace mailboxes or via FPGA mailbox client?
Link Copied
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi rajasekarselva,
Sorry for the late respond.
Referring to this document at Canceling Root Keys section:
Does this answer your questions?
Thanks.
Regards,
Aik Eu
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for your reply, Aik Eu.
Unfortunately, I can't able to open the link. Replied with 'Access Denied'
Do I need any additional login authentication to view this document?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As a reference, are you pointing the below document in the previous link?
Intel® Agilex™ Device Security User Guide
4.4. Canceling Root Keys
If you are pointing the above then there is no detailed explanation/brief on, How to do that from the FPGA mailbox IP or HPS mailbox IP client? Could you point that document, if possible?
Thanks
Raj
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi rajasekarselva,
Yes, I am pointing to that document.
I will get back to you on more info regarding cancellation of root keys from HPS Linux userspace or FPGA mailbox client.
Thanks.
Regards,
Aik Eu
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi rajasekarselva,
I get the info from the software security team as below:
Firstly you would need to create the certificate to cancel the root key hash. This is detailed in section 4.5 “Canceling Root Keys” of the Agilex Device Security UG.
To create the certificate, you would send the Certificate Command (0x0B) through the mailbox (HPS/FPGA)
This command is not currently documented, but will be soon in the Security Methodology UG.
The Security Methodology UG will be out in at least one month time.
Do let me know if you have further questions or concern from the info above.
Thanks.
Regards,
Aik Eu
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi rajasekarselva,
Any follow up with the previous comment?
Thanks.
Regards,
Aik Eu
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi rajasekarselva,
I will close this thread if no further question.
Thanks.
Regards,
Aik Eu
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page