[PATCH 02/11] Documentation: security: clarify development key insecurity
Ahmad Fatoum
a.fatoum at pengutronix.de
Mon Sep 28 04:26:57 PDT 2026
From: Ahmad Fatoum <a.fatoum at barebox.org>
Should go without saying, but spell it out anyway.
Signed-off-by: Ahmad Fatoum <a.fatoum at barebox.org>
---
Documentation/user/security.rst | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/Documentation/user/security.rst b/Documentation/user/security.rst
index 657bcd690b8e..e650c03a1023 100644
--- a/Documentation/user/security.rst
+++ b/Documentation/user/security.rst
@@ -92,7 +92,8 @@ This can be enforced by setting ``CONFIG_BOOTM_FORCE_SIGNED_IMAGES=y``
and disabling any ways that could be used to override this.
For development convenience ``CONFIG_CRYPTO_BUILTIN_DEVELOPMENT_KEYS``
-can be used to compile well known development keys into the barebox binary.
+can be enabled after enabling ``CONFIG_INSECURE`` to compile well known
+development keys into the barebox binary.
The private keys for these keys can be found
`[here] <https://github.com/pengutronix/ptx-code-signing-dev>`__.
--
2.47.3
More information about the barebox
mailing list