From abb086bef6f17640725bc955738791ec171d9ebb Mon Sep 17 00:00:00 2001 From: Ahmad Fatoum Date: Tue, 8 Sep 2026 13:22:43 +0200 Subject: [PATCH] fitimage: strip pkcs11: prefix in FITIMAGE_SIGN_KEYDIR example Following the example in the comment as-is will lead to an error at do_fitimage time: The key ID is not a valid PKCS#11 URI The PKCS#11 URI format is defined by RFC7512 The key ID is not a valid PKCS#11 URI The PKCS#11 URI format is defined by RFC7512 PKCS11_get_private_key returned NULL Failure loading private key from engine: error:40000064:pkcs11 engine::invalid id uboot-mkimage Can't add hashes to FIT blob: -1 Strip the pkcs11: prefix to resolve this and save future users the hassle. Signed-off-by: Ahmad Fatoum Signed-off-by: Fabian Pflug Signed-off-by: Khem Raj --- meta-oe/classes/fitimage.bbclass | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-oe/classes/fitimage.bbclass b/meta-oe/classes/fitimage.bbclass index adcfec0f0e..109b3b421b 100644 --- a/meta-oe/classes/fitimage.bbclass +++ b/meta-oe/classes/fitimage.bbclass @@ -62,7 +62,7 @@ # # FITIMAGE_SIGN = "1" # FITIMAGE_MKIMAGE_EXTRA_ARGS = "--engine pkcs11" -# FITIMAGE_SIGN_KEYDIR = "${PKCS11_URI}" +# FITIMAGE_SIGN_KEYDIR = "${PKCS11_URI#pkcs11:}" LICENSE ?= "MIT"