blob: d40307adb1adb0e32b8f4b30a24f392e1a5c4d9e [file] [log] [blame]
David Brown5153bd62017-01-06 11:16:53 -07001CONFIG_CONSOLE_HANDLER=y
David Brown5153bd62017-01-06 11:16:53 -07002CONFIG_DEBUG=y
Ricardo Salveti8e4d44d2017-02-27 23:00:31 -03003CONFIG_SYSTEM_CLOCK_DISABLE=y
Carles Cufidf4d9a42018-06-15 12:42:26 +02004CONFIG_SYS_POWER_MANAGEMENT=n
David Brown5153bd62017-01-06 11:16:53 -07005
6CONFIG_MAIN_STACK_SIZE=10240
Marti Bolivara4818a52018-04-12 13:02:38 -04007CONFIG_MBEDTLS_CFG_FILE="mcuboot-mbedtls-cfg.h"
David Brown5153bd62017-01-06 11:16:53 -07008
Fabio Utzig5fe874c2018-08-31 07:41:50 -03009CONFIG_BOOT_ENCRYPT_RSA=n
10
Fabio Utzigd0533ed2018-12-19 07:56:33 -020011CONFIG_BOOT_BOOTSTRAP=n
12
Fabio Utzigc690c762018-04-26 10:51:09 -030013### Default to RSA
14CONFIG_BOOT_SIGNATURE_TYPE_RSA=y
Fabio Utzig105b59a2019-05-13 15:08:12 -070015CONFIG_BOOT_SIGNATURE_TYPE_RSA_LEN=2048
Fabio Utzigc690c762018-04-26 10:51:09 -030016CONFIG_BOOT_SIGNATURE_TYPE_ECDSA_P256=n
Fabio Utzig1171df92019-05-10 19:26:38 -030017CONFIG_BOOT_SIGNATURE_TYPE_ED25519=n
Fabio Utzigc690c762018-04-26 10:51:09 -030018
Carles Cufi29af9fe2018-06-11 13:31:41 +020019### The bootloader generates its own signature verification based on a
20### key file which needs to be provided and needs to match the selected signing
21### algorithm (CONFIG_BOOT_SIGNATURE_TYPE_).
Fabio Utzigc690c762018-04-26 10:51:09 -030022### The PEM files below are provided as examples.
Carles Cufi29af9fe2018-06-11 13:31:41 +020023CONFIG_BOOT_SIGNATURE_KEY_FILE="root-rsa-2048.pem"
Fabio Utzig105b59a2019-05-13 15:08:12 -070024#CONFIG_BOOT_SIGNATURE_KEY_FILE="root-rsa-3072.pem"
Fabio Utzigc690c762018-04-26 10:51:09 -030025#CONFIG_BOOT_SIGNATURE_KEY_FILE="root-ec-p256.pem"
Fabio Utzig1171df92019-05-10 19:26:38 -030026#CONFIG_BOOT_SIGNATURE_KEY_FILE="root-ed25519.pem"
Fabio Utzigc690c762018-04-26 10:51:09 -030027
David Brown0bae9652017-10-19 16:45:09 -060028### mbedTLS has its own heap
29# CONFIG_HEAP_MEM_POOL_SIZE is not set
David Brown5153bd62017-01-06 11:16:53 -070030
Marti Bolivara4818a52018-04-12 13:02:38 -040031### We never want Zephyr's copy of tinycrypt. If tinycrypt is needed,
32### MCUboot has its own copy in tree.
33# CONFIG_TINYCRYPT is not set
34# CONFIG_TINYCRYPT_ECC_DSA is not set
35# CONFIG_TINYCRYPT_SHA256 is not set
36
David Brown5153bd62017-01-06 11:16:53 -070037CONFIG_FLASH=y
Ricardo Salveti3dbf2222017-01-18 11:34:47 -020038
Marti Bolivar0e259092018-09-05 14:54:06 -040039### Various Zephyr boards enable features that we don't want.
Marti Bolivarf4d0e1a2017-08-30 18:39:07 -040040# CONFIG_BT is not set
Marti Bolivar0e259092018-09-05 14:54:06 -040041# CONFIG_BT_CTLR is not set
Marti Bolivarf4d0e1a2017-08-30 18:39:07 -040042# CONFIG_I2C is not set
Michael Scottf9be7a92019-02-01 11:19:47 -080043
Piotr Mienkowski15aa6ef2019-04-08 22:48:15 +020044CONFIG_LOG=y
45CONFIG_LOG_IMMEDIATE=y
Michael Scottf9be7a92019-02-01 11:19:47 -080046### Ensure Zephyr logging changes don't use more resources
47CONFIG_LOG_DEFAULT_LEVEL=0