tbbr_oid.h 5.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182
  1. /*
  2. * Copyright (c) 2015-2024, Arm Limited and Contributors. All rights reserved.
  3. *
  4. * SPDX-License-Identifier: BSD-3-Clause
  5. */
  6. #ifndef TBBR_OID_H
  7. #define TBBR_OID_H
  8. #include "zero_oid.h"
  9. #define MAX_OID_NAME_LEN 30
  10. /*
  11. * The following is a list of OID values defined and reserved by ARM, which
  12. * are used to define the extension fields of the certificate structure, as
  13. * defined in the Trusted Board Boot Requirements (TBBR) specification,
  14. * ARM DEN0006C-1.
  15. */
  16. /* TrustedFirmwareNVCounter - Non-volatile counter extension */
  17. #define TRUSTED_FW_NVCOUNTER_OID "1.3.6.1.4.1.4128.2100.1"
  18. /* NonTrustedFirmwareNVCounter - Non-volatile counter extension */
  19. #define NON_TRUSTED_FW_NVCOUNTER_OID "1.3.6.1.4.1.4128.2100.2"
  20. /*
  21. * Non-Trusted Firmware Updater Certificate
  22. */
  23. /* APFirmwareUpdaterConfigHash - BL2U */
  24. #define AP_FWU_CFG_HASH_OID "1.3.6.1.4.1.4128.2100.101"
  25. /* SCPFirmwareUpdaterConfigHash - SCP_BL2U */
  26. #define SCP_FWU_CFG_HASH_OID "1.3.6.1.4.1.4128.2100.102"
  27. /* FirmwareUpdaterHash - NS_BL2U */
  28. #define FWU_HASH_OID "1.3.6.1.4.1.4128.2100.103"
  29. /* TrustedWatchdogRefreshTime */
  30. #define TRUSTED_WATCHDOG_TIME_OID "1.3.6.1.4.1.4128.2100.104"
  31. /*
  32. * Trusted Boot Firmware Certificate
  33. */
  34. /* TrustedBootFirmwareHash - BL2 */
  35. #define TRUSTED_BOOT_FW_HASH_OID "1.3.6.1.4.1.4128.2100.201"
  36. #define TRUSTED_BOOT_FW_CONFIG_HASH_OID "1.3.6.1.4.1.4128.2100.202"
  37. #define HW_CONFIG_HASH_OID "1.3.6.1.4.1.4128.2100.203"
  38. #define FW_CONFIG_HASH_OID "1.3.6.1.4.1.4128.2100.204"
  39. /*
  40. * Trusted Key Certificate
  41. */
  42. /* PrimaryDebugCertificatePK */
  43. #define PRIMARY_DEBUG_PK_OID "1.3.6.1.4.1.4128.2100.301"
  44. /* TrustedWorldPK */
  45. #define TRUSTED_WORLD_PK_OID "1.3.6.1.4.1.4128.2100.302"
  46. /* NonTrustedWorldPK */
  47. #define NON_TRUSTED_WORLD_PK_OID "1.3.6.1.4.1.4128.2100.303"
  48. /*
  49. * Trusted Debug Certificate
  50. */
  51. /* DebugScenario */
  52. #define TRUSTED_DEBUG_SCENARIO_OID "1.3.6.1.4.1.4128.2100.401"
  53. /* SoC Specific */
  54. #define TRUSTED_DEBUG_SOC_SPEC_OID "1.3.6.1.4.1.4128.2100.402"
  55. /* SecondaryDebugCertPK */
  56. #define SECONDARY_DEBUG_PK_OID "1.3.6.1.4.1.4128.2100.403"
  57. /*
  58. * SoC Firmware Key Certificate
  59. */
  60. /* SoCFirmwareContentCertPK */
  61. #define SOC_FW_CONTENT_CERT_PK_OID "1.3.6.1.4.1.4128.2100.501"
  62. /*
  63. * SoC Firmware Content Certificate
  64. */
  65. /* APRomPatchHash - BL1_PATCH */
  66. #define APROM_PATCH_HASH_OID "1.3.6.1.4.1.4128.2100.601"
  67. /* SoCConfigHash */
  68. #define SOC_CONFIG_HASH_OID "1.3.6.1.4.1.4128.2100.602"
  69. /* SoCAPFirmwareHash - BL31 */
  70. #define SOC_AP_FW_HASH_OID "1.3.6.1.4.1.4128.2100.603"
  71. /* SoCFirmwareConfigHash = SOC_FW_CONFIG */
  72. #define SOC_FW_CONFIG_HASH_OID "1.3.6.1.4.1.4128.2100.604"
  73. /*
  74. * SCP Firmware Key Certificate
  75. */
  76. /* SCPFirmwareContentCertPK */
  77. #define SCP_FW_CONTENT_CERT_PK_OID "1.3.6.1.4.1.4128.2100.701"
  78. /*
  79. * SCP Firmware Content Certificate
  80. */
  81. /* SCPFirmwareHash - SCP_BL2 */
  82. #define SCP_FW_HASH_OID "1.3.6.1.4.1.4128.2100.801"
  83. /* SCPRomPatchHash - SCP_BL1_PATCH */
  84. #define SCP_ROM_PATCH_HASH_OID "1.3.6.1.4.1.4128.2100.802"
  85. /*
  86. * Trusted OS Firmware Key Certificate
  87. */
  88. /* TrustedOSFirmwareContentCertPK */
  89. #define TRUSTED_OS_FW_CONTENT_CERT_PK_OID "1.3.6.1.4.1.4128.2100.901"
  90. /*
  91. * Trusted OS Firmware Content Certificate
  92. */
  93. /* TrustedOSFirmwareHash - BL32 */
  94. #define TRUSTED_OS_FW_HASH_OID "1.3.6.1.4.1.4128.2100.1001"
  95. /* TrustedOSExtra1FirmwareHash - BL32 Extra1 */
  96. #define TRUSTED_OS_FW_EXTRA1_HASH_OID "1.3.6.1.4.1.4128.2100.1002"
  97. /* TrustedOSExtra2FirmwareHash - BL32 Extra2 */
  98. #define TRUSTED_OS_FW_EXTRA2_HASH_OID "1.3.6.1.4.1.4128.2100.1003"
  99. /* TrustedOSFirmwareConfigHash - TOS_FW_CONFIG */
  100. #define TRUSTED_OS_FW_CONFIG_HASH_OID "1.3.6.1.4.1.4128.2100.1004"
  101. /*
  102. * Non-Trusted Firmware Key Certificate
  103. */
  104. /* NonTrustedFirmwareContentCertPK */
  105. #define NON_TRUSTED_FW_CONTENT_CERT_PK_OID "1.3.6.1.4.1.4128.2100.1101"
  106. /*
  107. * Non-Trusted Firmware Content Certificate
  108. */
  109. /* NonTrustedWorldBootloaderHash - BL33 */
  110. #define NON_TRUSTED_WORLD_BOOTLOADER_HASH_OID "1.3.6.1.4.1.4128.2100.1201"
  111. /* NonTrustedFirmwareConfigHash - NT_FW_CONFIG */
  112. #define NON_TRUSTED_FW_CONFIG_HASH_OID "1.3.6.1.4.1.4128.2100.1202"
  113. /*
  114. * Secure Partitions Content Certificate
  115. */
  116. #define SP_PKG1_HASH_OID "1.3.6.1.4.1.4128.2100.1301"
  117. #define SP_PKG2_HASH_OID "1.3.6.1.4.1.4128.2100.1302"
  118. #define SP_PKG3_HASH_OID "1.3.6.1.4.1.4128.2100.1303"
  119. #define SP_PKG4_HASH_OID "1.3.6.1.4.1.4128.2100.1304"
  120. #define SP_PKG5_HASH_OID "1.3.6.1.4.1.4128.2100.1305"
  121. #define SP_PKG6_HASH_OID "1.3.6.1.4.1.4128.2100.1306"
  122. #define SP_PKG7_HASH_OID "1.3.6.1.4.1.4128.2100.1307"
  123. #define SP_PKG8_HASH_OID "1.3.6.1.4.1.4128.2100.1308"
  124. /*
  125. * Public Keys present in SOC FW content certificates authenticate BL31 and
  126. * its configuration.
  127. */
  128. #define BL31_IMAGE_KEY_OID SOC_FW_CONTENT_CERT_PK_OID
  129. #define SOC_FW_CONFIG_KEY_OID SOC_FW_CONTENT_CERT_PK_OID
  130. #define HW_CONFIG_KEY_OID ZERO_OID
  131. #define SCP_BL2_IMAGE_KEY_OID SCP_FW_CONTENT_CERT_PK_OID
  132. #define BL32_IMAGE_KEY_OID TRUSTED_OS_FW_CONTENT_CERT_PK_OID
  133. #define TOS_FW_CONFIG_KEY_OID TRUSTED_OS_FW_CONTENT_CERT_PK_OID
  134. #define BL33_IMAGE_KEY_OID NON_TRUSTED_FW_CONTENT_CERT_PK_OID
  135. #define NT_FW_CONFIG_KEY_OID NON_TRUSTED_FW_CONTENT_CERT_PK_OID
  136. #ifdef PLAT_DEF_OID
  137. #include <platform_oid.h>
  138. #endif
  139. #endif /* TBBR_OID_H */