[PATCH 02/11] Documentation: security: clarify development key insecurity

Ahmad Fatoum a.fatoum at pengutronix.de
Mon Sep 28 04:26:57 PDT 2026


From: Ahmad Fatoum <a.fatoum at barebox.org>

Should go without saying, but spell it out anyway.

Signed-off-by: Ahmad Fatoum <a.fatoum at barebox.org>
---
 Documentation/user/security.rst | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/Documentation/user/security.rst b/Documentation/user/security.rst
index 657bcd690b8e..e650c03a1023 100644
--- a/Documentation/user/security.rst
+++ b/Documentation/user/security.rst
@@ -92,7 +92,8 @@ This can be enforced by setting ``CONFIG_BOOTM_FORCE_SIGNED_IMAGES=y``
 and disabling any ways that could be used to override this.
 
 For development convenience ``CONFIG_CRYPTO_BUILTIN_DEVELOPMENT_KEYS``
-can be used to compile well known development keys into the barebox binary.
+can be enabled after enabling ``CONFIG_INSECURE`` to compile well known
+development keys into the barebox binary.
 The private keys for these keys can be found
 `[here] <https://github.com/pengutronix/ptx-code-signing-dev>`__.
 
-- 
2.47.3




More information about the barebox mailing list