wolfBoot/tools/keytools
Daniele Lacamera 9a25fae89d F-6127: fix custom-TLV 8-byte value saturation in arg2num
arg2num() parsed --custom-tlv values with signed strtoll(), which
saturates to LLONG_MAX (0x7FFFFFFFFFFFFFFF) on positive overflow. For
LEN==8 no masking is applied afterwards (unlike LEN 1/2/4), so any
value >= 2^63 silently encoded as 0x7FFFFFFFFFFFFFFF instead of the
value the user supplied, breaking the TLV encode/decode roundtrip.

Switch to strtoull() and reject (exit 16) when it reports ERANGE for
an 8-byte value, mirroring the existing fw_version range check.
2026-07-02 15:28:09 +02:00
..
otp F-6408: zeroize UDS from OTP keystore generator's heap and stack buffers 2026-07-02 14:56:48 +02:00
Makefile
README.md
keygen.c F-4419: zeroize LmsKey on all error paths in keygen_lms 2026-06-10 21:01:17 +02:00
keygen.py
sign.c F-6127: fix custom-TLV 8-byte value saturation in arg2num 2026-07-02 15:28:09 +02:00
sign.py F-5352: emit 4-byte delta size TLVs from Python signer 2026-06-09 15:50:48 +02:00
user_settings.h Continue the ML-DSA renaming 2026-05-19 11:21:20 -07:00
wolfBootKeyTools.sln
wolfBootKeygenTool.vcxproj
wolfBootSignTool.vcxproj

README.md

Key Tools for signing and key generation

Sign

See code file ./tools/keytools/sign.c and documentation in docs/Signing.md.

KeyGen and KeyStore

See code file ./tools/keytools/keygen.c and documentation docs/keystore.md.

Flash OTP Keystore Generation, Primer, Startup

See documentation docs/flash-OTP.md.

Keystore Generation

Pack public keys into a single binary (otp.bin) formatted the way wolfBoot expects for provisioning the devices OTP/NVM keystore. No signing, no encryption—just a correctly laid-out image with a header plus fixed-size "slots" for each key.

See code file ./tools/keytools/otp/otp-keystore-gen.c

Flash OTP Primer

See code file ./tools/keytools/otp/otp-keystore-primer.c

Flash OTP Startup

See code file ./tools/keytools/otp/startup.c

Quick Start (Linux)

make wolfboot_signing_private_key.der SIGN=ED25519

# or

./tools/keytools/keygen --ed25519 -g wolfboot_signing_private_key.der

Note the above example is a basic case where a single key is generated. The tool supports multiple keys both with [-g privkey] and [-i pubkey] parameters.

See the local docs docs/keystore.md and the wolfBoot Keystore section of the manual for additional details.

Debugging and Development

DEBUG_SIGNTOOL

Enables additional diagnostic messages that may be useful during development and initial bring-up.

WOLFBOOT_SHOW_INCLUDE

Enables compile-time verbosity to indicate which user_settings.h file is being used.