wolfBoot/tools/keytools
Daniele Lacamera 776378ca78 Preparing release v2.8.0 + update copyright 2026-04-16 13:11:56 +02:00
..
otp Preparing release v2.8.0 + update copyright 2026-04-16 13:11:56 +02:00
Makefile Adjust BIGINT limits for new wolfSSL ECC+SMALLSTACK 2026-04-07 14:14:44 +02:00
README.md Minor docs update, code review changes, script modifications. 2025-11-24 13:04:06 -08:00
keygen.c Preparing release v2.8.0 + update copyright 2026-04-16 13:11:56 +02:00
keygen.py Preparing release v2.8.0 + update copyright 2026-04-16 13:11:56 +02:00
sign.c Preparing release v2.8.0 + update copyright 2026-04-16 13:11:56 +02:00
sign.py Preparing release v2.8.0 + update copyright 2026-04-16 13:11:56 +02:00
user_settings.h Preparing release v2.8.0 + update copyright 2026-04-16 13:11:56 +02:00
wolfBootKeyTools.sln Added keygen C tool + vcproj for windows 2020-03-30 14:12:39 +02:00
wolfBootKeygenTool.vcxproj Progress getting the Windows tools to build. 2024-12-05 08:36:02 -08:00
wolfBootSignTool.vcxproj Update project file line endings for Windows CRLF 2025-10-28 11:37:49 -07:00

README.md

Key Tools for signing and key generation

Sign

See code file ./tools/keytools/sign.c and documentation in docs/Signing.md.

KeyGen and KeyStore

See code file ./tools/keytools/keygen.c and documentation docs/keystore.md.

Flash OTP Keystore Generation, Primer, Startup

See documentation docs/flash-OTP.md.

Keystore Generation

Pack public keys into a single binary (otp.bin) formatted the way wolfBoot expects for provisioning the devices OTP/NVM keystore. No signing, no encryption—just a correctly laid-out image with a header plus fixed-size "slots" for each key.

See code file ./tools/keytools/otp/otp-keystore-gen.c

Flash OTP Primer

See code file ./tools/keytools/otp/otp-keystore-primer.c

Flash OTP Startup

See code file ./tools/keytools/otp/startup.c

Quick Start (Linux)

make wolfboot_signing_private_key.der SIGN=ED25519

# or

./tools/keytools/keygen --ed25519 -g wolfboot_signing_private_key.der

Note the above example is a basic case where a single key is generated. The tool supports multiple keys both with [-g privkey] and [-i pubkey] parameters.

See the local docs docs/keystore.md and the wolfBoot Keystore section of the manual for additional details.

Debugging and Development

DEBUG_SIGNTOOL

Enables additional diagnostic messages that may be useful during development and initial bring-up.

WOLFBOOT_SHOW_INCLUDE

Enables compile-time verbosity to indicate which user_settings.h file is being used.