Public Access
OTA design: glossary, ADR 0003 (own signature check), plan
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
@@ -0,0 +1,11 @@
|
||||
# Signed Update Files checked by the firmware, not ESP32 Secure Boot
|
||||
|
||||
Firmware Updates are accepted only when their Update File carries a valid ECDSA P-256 signature over the image's SHA-256. The firmware itself checks it, against a public key compiled into it, before switching the boot partition. The private key lives outside the repository, in `~/.config/roro9stack/ota-key.pem`.
|
||||
|
||||
We chose this over the ESP32's hardware Secure Boot. Secure Boot is enforced by the chip, but it burns eFuses one-way: a mistake bricks the device, and the device can never run unsigned firmware again, which makes recovery over USB harder. On a single development device, a software check that refuses unsigned pushes is enough, and it stays reversible: a new firmware can carry a new public key.
|
||||
|
||||
## Consequences
|
||||
|
||||
- Someone with physical USB access can still flash anything. Only Wi-Fi and SD card updates are guarded.
|
||||
- **Losing the private key** means the next update has to go over USB, carrying a new public key.
|
||||
- P-256 rather than Ed25519, because the firmware's TLS library (mbedTLS) already verifies it, so it costs no extra code.
|
||||
Reference in New Issue
Block a user