Boot a signed Zephyr image with U-Boot on Arm Cortex-A
Introduction
Understand where U-Boot verifies Zephyr in the Cortex-A boot chain
Set up the host tools for your target
Build a Zephyr image that U-Boot can start
Create signing keys and sign the Zephyr image into a FIT
Build U-Boot with the public key and a boot command that fails closed
Boot the signed Zephyr FIT with U-Boot on QEMU or the TI AM62L EVM
(Optional) Test that U-Boot refuses a wrong key and a tampered image
Review the Zephyr FIT verification boundary and production needs
Next Steps
Boot a signed Zephyr image with U-Boot on Arm Cortex-A
Introduction
Understand where U-Boot verifies Zephyr in the Cortex-A boot chain
Set up the host tools for your target
Build a Zephyr image that U-Boot can start
Create signing keys and sign the Zephyr image into a FIT
Build U-Boot with the public key and a boot command that fails closed
Boot the signed Zephyr FIT with U-Boot on QEMU or the TI AM62L EVM
(Optional) Test that U-Boot refuses a wrong key and a tampered image
Review the Zephyr FIT verification boundary and production needs
Next Steps
Who is this for?
This is an advanced topic for embedded developers who boot Zephyr from U-Boot on an Arm Cortex-A processor and want U-Boot to verify the Zephyr image before starting it.
What will you learn?
Upon completion of this Learning Path, you will be able to:
- Identify where U-Boot verifies Zephyr in the Arm Cortex-A boot chain.
- Build and sign a Flattened Image Tree (FIT) containing Zephyr, and embed the public key in U-Boot without changing its source.
- Configure U-Boot to verify Zephyr before booting, and optionally test rejection of wrong-key and tampered images.
- Identify the verification boundary in QEMU and on a development board, and how fusing your key extends trust in production.
Prerequisites
Before starting, you will need the following:
- One of two targets - QEMU, which needs no hardware, or a Texas Instruments (TI) AM62L EVM with accessories to power it, write an SD card, and attach a serial console
- A Linux host running Ubuntu 22.04 or 24.04, with about 20 GB of free disk space; QEMU runs on x86_64 or arm64, while the AM62L EVM needs x86_64 for the TI SDK
- Visual Studio Code with the Workbench for Zephyr extension installed
- Basic knowledge of U-Boot and the Linux command line
Summary
This summary was drafted with an approved AI-assisted workflow and reviewed by Arm contributors before publication. Human technical review remains part of the process so the final page reflects engineering rigor, accuracy, and Arm editorial standards.
Frequently asked questions
These FAQs were drafted with an approved AI-assisted workflow and reviewed by Arm contributors before publication. Human technical review remains part of the process so the final page reflects engineering rigor, accuracy, and Arm editorial standards.
signature.dtsi and include it when you build U-Boot. For the AM62L EVM, use CONFIG_DEVICE_TREE_INCLUDES. For QEMU, add the node to the control device tree supplied with EXT_DTB. You don’t need to change the U-Boot source files.fit_check_sign tool with your signed FIT and built u-boot.dtb. This checks the FIT against the public key in the control device tree before you prepare the boot media.sha256,rsa2048:key-a+ OK in the U-Boot output, followed by the Zephyr image A banner. You can also run the optional wrong-key and tampered-image tests to check that U-Boot refuses to start either image.