# Enable secure boot

Secure boot is enabled by blowing a set of hardware fuses that are part of QFPROM. The hash of the root certificate is blown into the hardware fuse, which serves as the primary RoT.

To understand the off-target preparation and the on-device execution, see the workflow.

![../../../../../_images/secure-boot-prep-updated.png](data:image/png;base64,UklGRmQnAABXRUJQVlA4TFcnAAAvvIO3ENfjOpJsVdmnX0L+CRGPw5E9e5AkHDeSpEi1e8z3Ov8NOa+GG6ocN5KkSLXHTP77dk9mvusCto0kKaosLv/MTmfTM1iTAABIK9KL0sQY0MX8EWNAG63R28+4N7BLemlFWZtoOPxxtlUGnQEQAAEwASwAJ4DZQh82NDEfgApg+wNYw9b8AAIgAI5pm5Rxa1uvMB06lktc6oZor/7GoEph0Ht8iCZathHuJ6KlFwYNMWe5xyDR3uOjFTUHuN2IFvaXXirFWgsOb+/xIRqDWjFqzPyCQWF/r/6WXqwL+cGge3kQrRX38iDa+b/WMuuBzawL1PBJykYsUkKYlANd6MCQXFFpuUIZPqUFPsTswexh/V7gfLI9ZrbHDNvK6UfWYdC2kaSm/FlPd547AhExAf6iYkPdci1yEc2H7eJ9xQ3agWdwcGdVsaGe6BbRu9eBGI6qfCgQ9caH8jrTkQHb4EP5kP7Cfz1M2962lW1r1WHm9EOSO+egmXNwadT0nJZ6xs45p59PvC/EkdTk4EyqAZkkwPKDmuYLiaVXZET/ZUGSXLfNXBVsICCzsBY48OHyv2/XtixJkiTrrS7xK4n4pLpr3QJal/9/FN57E4uombuaREQaCFgMIhA98H6gRReAHiL6T0GS5LCNVLhABLGCr2c4AEFiyAdQmK1tbRuVW5WZmcGjLjMzM4MXVPIEreW/73Uz6/Sbz3q+z8mjmOppZEo3smu9USP6DwmSJEdNFh7kjpPH7H5XFTpx+Jx17eCxs62izhwKd23dtNaqtjHdue/CyaLtxb0DsbCtG4UnCnqdmtjZRufvt4bhQGxtnSOteCTW1pbwQbjV3pLwVLjJ4uocD8Xi2kP/MT/PfvAZcH3yQumewG6tenlbyUafPCrA1X/v1VI9FS4JcO1+c1iqhc8eEeh62Hy0xHer8B0Bu4bPlqj5Knq/fo1eLfUnAgFP4+0SjUboebRe6nsF31pF/9F/9N9//Yf+o/8qpn3nF/cAoTP8BJhr92sg3o6j/xMeLrI8/Ueg7XMzQ8pDxOmtwojUFVi6hCzIJ9vDEGADmN0I5phuMo8DvugSQSLedkSkwsuExaBjMhM/oiVrQFC9/Si4FQ+zAgTA30hU9dag6Fa6BSIxDro5yQowMXCz8f37Yma0zQNmZE9/asSONVA/oGTHwNafuiXLzIQwhyebxGD0tjXIwjJmQ2sHrouNR2gyIoPtUyawU02Imea+MBLhNYuEoBOmGtasMLRIwdAFYomIluz8HoiYq/qa+kTjAp6mD4vCATAyU8ftRZYlLyzTJMhEHDwASqybeuJkWSCNhZGB5gEPDPlpiZSezm6xbP38gmzzV0AVUgEP9ETFpELlBKbUP8B0sfFY6fmVQ6JSu6LIHBO1hVisYUsZ1DzMXA+M5sMOEDV0iYrRAGI5g0WhGUYme6bcXnpK1eWj5V4FibYwImzCA0KMoir0msyiZgRGbXFqGFQXmPSBlBGQfJcgpMJoO6MwI3njFDGi/QyLUQM8yQ/ZP0WiyzIeum4REiYdjbBkBgf0RZGEyHbP1BrJ8iWSJTyjBwatMWmLPmuPBqqqRehAhCSDTaEHBK3NXll7rwGtBSrVQJw3wZOC7C6LLSQziK3ZSKLXZB4YiTZqxYjJzqTGIEaATeHMqpcOi+iyjMfGSLQFnGpiviukTMQfzFg1cQrRU6sOSBrIGtERagTVIfbGSqr0Ut2mkOwDBpu9yE7fx5iL2mjtgDHDG6W+KDIAI6vkpzf7eM4AKGUBErICIowygkakN2LIwBIABhuPHTqmCCmczHHKKqsRREoNGjpi0aNVg2XvF5moIcOikBjLW+1FXauaBzYAYLBQQLvkrgxARq6CcR0Fx6I3AjbYeFYWflVRPLvYIGEtLEuBhzEeLwgzOxODKhB9wEabnxrTyqKAnigXHpFabmLYmsmNEtXOOK/O0TwxkxphvJlmnsSwjYfu0oFBPWu2UDxPZGF1s5Bbz53STfhIoKpqBA/0RFSGTeEAZIpt9iLNES0RMi4InhJ5s4XC+XKIz0cLpFWFWtK2p9We2OwBazIYGD0d0Chcae6iAzCtOKxgYveKhdyHBeKWVgnckiM7TMw3NoWCqUuIFnuxjXzk9psRRWI/rICiXaSvZeZjSCQboA1YMDTCPEaOqg9M1Ih+bkEE6C2uHARIM6M3UxjoqlLXfEdgGY9KhvX58gNaNGG3Ndpec6BjixRZMqAfuS6IRVY9X54lYE6eW1oUzgCvku0JmL1sz5e7GohzY5qJ001E2hcAZSBRHfI8PaJMOYUi3YH4hYjCTmCP9ytaugAgdDeaivf3iOk/+o/+o//oP/pv3nLuzbwf6Etzl9XmJFN+sG8sq7ZM3g/+/awyF4K1SmmxD4BUZYmPQK7KfAiqKiyFQGRu+BDw6L/f/kP//fafig2vfvde+cvHS/nrf/h28g8h5/8NaqlBPhlPKElngoj7tG31SRJF6VJAjgf/Zj6JU5R93pD//9VM/xbxuvzVuf/Bc/9N/yqmf7NowpsYuY4QPpC4v4J4Gh/2iN4n2KaAxPQ0z8naTM8y/ftIQ1LB5d94IL0DypkZ4DW8trwO2e8XiUT4XAO4yL4BxEpe2CT5IdTUBigBip3JXCRjkj0eeju5lN7BdUjs2EydTN8ZNgSk1ngDy+VEvhxOcqooEEMxW+dvd/o6KJnMA3XKoS4OigwKK5Ag7Zk9kb1og5KT6SzwFSR2cg6xGGAP0Sq5rPibJP3Q56wRygvbCFwVz1L6lck5pnCT6YhF5uw6kr81vGjJJLkWTB+ITCh1AtOVmsRmCBAMnxi9qmmnD0x+4j5afEm9Jr1gsX1j2IWGCfAEVDYxZJfLAayj4EHdSLyVxAxkJiF69I4kQiTjgRJVjUCy4IXRs7Emj4h+naXnACKmSu8HM1g1JkQuI/50lYHpRbo1ezEDdzog8Y1IF2FuOmL5IcChI/lb85OtNC8ay8bCJAIGiUVwizllVkOAIDKqVYKaHsbacuF/eRiht+bvTPObIa4COegL64Wbt4ERBZsNGOpSmXwA+0FiARrvzYjCJFiOQ1TTgWRRAcsgX9IghSjDoIfIXdpyCA38JMlw613Hn0EBhi/pItTLCFybpZecl5uO8AUhTkfy9+YP+SEYpxl1Dr1AEiQOCE2GAFnlYi74o1p8PWj8PMfl35s/VE+xoE2OVFNFchgYUbAZYajIHZJcISeGeqGxCLpYTluBZB4ccAhuRjkPBKrz+FKRlTgEwdX87Eb8CZS+nqWLMKsVwWGUNwxH3IwCK5K/O/vLsWYsivLgw2S50MVPQ4BoLpNcOnwWOTcGRTnL4vju7C9P3rh556vwvrJNOkXXdKrrbqqY2YoLADqQThO5HwymFxxY8voMYdrXdfyF6MoLy60IPo3hiKjQkfx9ge6vWEo3TuULKjnRdGtXpWTecDXZfLuqvnYO8urmySNqqsleVT9bZWhZtzdJVpUOpC+phq8XVrPGwyQj/n6sKn17usUt84qcaPXdXXuyeXEYe5lRRbNaJm4J/Po2Ndfi+RzM7kDq/NSYUaAJNKtt4y3OrA+BvLQWNhVIZwg1nyNxn20+hV84MOLvBc2nOdOsI/l7060mFZmkED1Z3a4num1eMB6g1jyQGGWaSa5K76yHGqNb/MawC42XB2jMwM0KSeNtddOc6KbmgMQMyRDzTzUC6QTCIBEq+2y3xYQQNxdG7zhFlwFmxV+R5GF1m4Fu10mkI4xudOhI/vakZcpYvEgRYrFKIaU+sb8cu9g0FJQsBCkxRekdmZzz4Opk+v6kZeYI/Ui6XgpkTh0FIbA7PTHJk96l5iaRWmYxAukMyMb+8nNpmRRlmPvLZ1BWXj6s+FvP7S+reD6D6YhF5suNSP6D6VZeOw7ePy9EzM8DwG//of/oP/pvLoMUg0nDKGwCg28JKvMQkBOFZRFQE5XJdQC2jsokygd+Y47axK1qvnf7ul9uhXOVJo7ur5UXv9T9cssEndmDvrWC7exBn/xC+1N/pf/oP/qP/uPnLg+HPx8Ph8O3SyofJcnXPyRJchVVz91D4ldaUlnsFpXgeuTMsLworZVOkRquguFHWlq5WvTjHLIXuQTOy2yXt/79cQ5ZJ0AoszR/6LbAfUWX5fZEra8l2MjkUl/vfRDW/l8WrarNvTml+6vld+0/s2hWbd28H/yLVOYisFZ5Sot9AKQqSzAYLIW5GchKCoHI8g4hif77PSXjIvkfyssZ/+bjFSyy2fwvfp5T95evI3G8lL/OV+DzVR4f/0KWVd9/jN4LSq7jlfg8WC+gsQEh4jl8vJpPfnwR/TW8yuOXl9MOS9zvM3TkF67X8uNdkH8SgB8DWbKagN5+1CxjPQFITm9AYqv0CCB2colRWjmQeMhKJLkH04OLrE3oymRSlEzmDXSSrkcSPamD3emJCbMnsosLJ+Brklkt8fN1yLXMdWVT7OQcmCTdoNRcpKljCB9ePoQmb84aAbRKLnXgV2YEDDWmxSOTy2CSPex5w+ODJCeWWy7FFqbDSU4lV6u5Z64MLvNiFVV7HpgO/I0Ln74e9AFcvrEY5aJVkGtBYntQNxJvYYkYulksZzn0quKQlQTFD1kHvDB6VhzqPR3GRUTX9CG9Ef2SXii9h6rR+xCmjt7lb+tUmpT5TRi8FL6FZK3GtLj3gkSBFLG4Q543Pd47IFiHn5hQfKLULitD7vCJ0RfNGL/ECuBBASJv5Arg8gdNyRpcFre4eM4qdQ01lJO44tbLQA2x1A6krH1QjXGnTO4ZELfwU9MglQhX5C61BMi1SFVovG823IzGagCFSTqvd11BoNUYFiu9Lom8he8Cnj/HEL+YVZq+OASG3MgI7AcDs+WDZMfNJkM9cRxEOaAaP7f1gMtNEoccz0LX4DJvQ2e1KznKBblD0SGkqQM5hm9GmwilZLNJbfDLZvqGGqOFCTVjOTTWzQimZsEss1sWJw6N5THb8+cIPvpLEkvucPmvBsulL8qRolgMiqIpkyRNlquZIECfYti5CVJlbpL+JPEEkRvCzMEkzbKhkNApSkLyUS8TYeUiySBKjckyMWYe5fnn2JZrSYklV5yrNTBZF+maW90sm5UanJKay1dURrmYfsgqXbyBnKEdtBiD1azxVDVrfKpKqjI8f57bMjPZVYJRYl8cmCsfvBXD14MxLHoXA+bAuPM916w52awV9a6bnwK+ArygWV7Than7kO4VJoUJfuEUfiHA2Wbb8081XxWzwsKQu9QZNFi37Mo1HuF+AYkNpU+L+1CT9aTgGZh8UHOom4HVbQa6zbqxfQmG6HYa/dTYJjFi627j0FZsbl6HqWK0Kv/Z3QZ6PTQFUWos1INtq9s4umnPa2oOguVbdFu8EeuDxhum3AuYvYHOJYoy0ecZPhlP0ecLmK4l/nDZAS8lcqsMPb3fpvrDyZ60ggsWiJ3MRQSHFJFqB2Jwf9kgsL9sH1wk7f3l9QRYZM424f1loc0NkJiEqT0KqbdBctYo3TAvHzaWGouRyWVE8SRzRMjz0uMhkMiqTkFOh7rMqeWq/4HU9U567bX0V9J/ei4v37AXIm6252Tl+oUxXmEw8MdRyi3ghQA/Pbnje8XtDeOZc5XzQGP7Mkb9+OaSSG8qLe4KZPSZWWx9GssnS5lKvrOXdGayHeeYZC6GafYC7CL7BoZKtntJXt7O2giXRhQ7wS52cgkGSc7vVdXEovuJYS/vAL6KyQvfWazcvsiE7TOQ0aez2A50mpypbNSMYTxMcRvfiPSEUi3TLOXItWD6QO8Dk/vZvLyQBxKjaB+e9TLSyLqTVe/v7feIP1TOAfq0cvsWB9BSIKPPyGJ7YGwZGMqM5Du1jWGzDgEyFc4wzVJ+H8oL0+ACxtrP5uUFPCBUGQlDm83SfPmvD9/VZnGxFCKCuxuei1aYOASGMiP57mY8SbcfrPoylMvZBnWi1wiznM0OsD1gpCraU4OVdfdux8zti5k1ndjdmOQaghXGSL6Lz2KYtjRL75EdCuZ+Oi/P9oCVqtinxaAo73eM3D4pyLNBIIvtdJUhyv00NZdg5TBKybyfzcsLeMBIVcyBKkllf/T8pB/iiZmsyTrB3QWJzeIiPRk504pureUEz26Y/KDb/vLK0ZxX5P5TZrPhwBjiNvKiGxlVcwgr+c7Xc2jTLOVRCNiIysZn8/ICHtCpirK5sAHaROw/fH7OD/HcvMQzyjCd2SDXgsgE9UB1qeB9OZeXlw+OV+jqHSi8gMh4cnvzTw4rty+xYfQOGyOLzei2aGEk36nUvfPo9EFLOXLdiJ4ghcdn8/ICHjBSFYcL/YdCI+vuD5+f80M8ucoBHaQwsygKm1ph1WwoHd5fTu748RDlVr/9M8bM7UtOzhE4MLLYHujtXhMr+W6R+Tp/oE0zNoz1AlAKr+3pvDzbAzpVUessQO9aVfnD5xUf4tGfyAl+hmaMSfaNRJJ7UJ3RvF/xIZ4u2GuESF6YYJecA8yeBHY+gLT+bKqC3vZPLpXMfsnYTkzsRj6pIcxJTkmsVqDlob7YI3X1iaUfslgZB4GzoHIZfmL0kl8/gvKf4IWIPwsGlznPx6Pd+ERO8DM0vQ9kH/LggfHJnec/xGOstxCi5uAVOrFJkZHpQeStMPIBDOvPpiqgd5if7plMgGTCeJPDEGZd2YQVpU4rm8F9Q+nqU/V6oDMOQmfByGX4s2fUBVxefgTl3zH0rrrxiZzQZ2huNjF4DIzXD1/wIR5czOkEN5u9Xh6k9MEU12GpXWHkAxjWn0hVMPFDfmLBrNAU41FrtYSZy9IslVjZDBfOYWQcBM6Ckcvwp199irXeD6H8+8JLPsQz+wHHqQ/xbJvcceaNYkONDcqqTAdqn+/gYgne47dDW/IoHpFg+TBZB92w/kSqgsXNKPQ0zG4woGxILIYwhaXbyGaAr7P0boe4wshlCB2YqPsRv+BDPBbBz9DETNKmz4PlAQw1AQDEmu1K3VT3Kuyd1pj1pY1JOIFpfcys6RyRG8IxAaQrhCpDmElSukmSzyEmhuBZ0LkMbzBe8SEes1JDSbA5v6waa8sRWGwiZblhlcWxmeRovZSuaWNYr1MVfpQKrqsslT5BNhYd065cdnt/MRsPxGPRuxgfksTy4Fyzwelm68bVZrr9SPNmk1WRuDXaZzbDR/8fbqpwqjnAS5obi5nN8FRzYUssGi0L+w3GbDwQj4H9GRr1IDgf1CwwPrnzgg/xJKYTB8Ov4GcdijANl29sv84yw0c/w00VTpEYhfIAVjdTWON9ottA4lY03iF0xkHoLBi5DO8vZuOBeAyCn6FJzpq4gBjaX37Jh3hiJrlgk3jr4SoYM5SWeZYZPvrbb6pwCr2/HObM/jKQ7f3lBSubwReUrgA64yB4FnRS6duKgNxv/6H/SLMUg0nDKGwCAhmVeQhIRGFZBIyJyqQd/OUclUmUD/5bR23iVjXfu33dL7fCuUoTR/fXyjMf6365dQPP7EFXsJ096JNfaH/2oPTfb/+h/+g/fu78HhLLk5LK1eFwtjwcDg+VVZ6iHLWk8hxIHMpr5WA4vyitlQMhlFd2hkZLKzvDVZntcgUcymyXK3MfpcxysUQos1wscSy5J7oqtyc6nmuxoar/J37+wK35mMoqLroZa76P0nqP3C+u2qo+AEUqc+Lgv1LlM0rrISB1FOZhsFaZm4Gs9CBYq7KWdwhJ9B/9R//RfxUU3t2KyHffdO51eTEf+S8voWRyS5W/auzExPd7K7P/ArEL6U3n9gK3yUt/DbkWpfIXjr1zbiv9DWJ8+S4IeuqTkG6y+n/TjYNfO1xoShYvCsiZalq82YjMy7GZJpkL0B3wmcgaAbRKpjq1aCcvIJIUQadVXmTfsSsx/5UUQTYmmRM3cEi6Di6S6ZeCFJ1zImoOFpmLCq90IEJp1IfLy8s9DLwpjSNB2IW0c4kH3lBqVvgFZAduTmBScXnErl1VFmwY3XuR81CuG0kI8I1YHzQm7MOmeSjh+tWomlowfWByYfQOJEZEv4CbC6V3JHbcJsTBM1j+zwcXgOmKCghNWUz0LtlMQm4L04XKJoJQqatZPYg7qtqlAGlASr8UzXCQBhQmzCqiKsKXCJOC3EW0/Y8E517cSuoJbFGYB+uAw54GIjybJG6p4izxkGHo6Ui8JWL2EME5vf1idAsbujoAdcrmwXQzqrnCl4izBhacc4PQ5nS9DE6TxSHIz7InSXYsbkmkLAlIlf0Xopk6YxBRDFbklrPHkFNFHyJxEfrxN5GwvxWL4bmcqGzDOX8d2MW9c3WEKL9GVRN3FHvzeU43P4chwGpWurdSMv2XoZl+2dA1Ar9GzZ4k5BdlsB92Htkth7s9yZYLwa66+YPEJQO094Jdfx0q9qWpR3gkTF5Wt626SSX3cDh5N4iQC96N1PT9yjmfALGSyUP7y0+itqTFwmKSWdzPtU7mrVJCr/Er8YcGgXMX6emp/eWi96+Hyx0iasYz5cvn+8t/GV+IQIQ3S31iO0+rEchevog+gejX37NeRewbkd7wRPmoYqH9RexJevo773vEv/2H/qP/6L+5DKYg4JqbWaVECLgu5mY+RxKlAGxVJgm4MykTkarme7ev++XmiNok6wX8lpygM3vQlbI/e1B4ov/oP/qP/psP39k9JJYX1SyPUn5U1VYuDWda1XKyzAjVbZcjcKnVLRfnOPli5z30PPVmmX+OpB+v/b+RdKfJB0vY2dZcQu/ZCb077InOaDdwGsNX10L/vMAijww6wNUcSekAes52p2TgBuBYOOg/+o/+o//mFfOmvED5+pf/f4hcH/yvTn+eD+4v429MX0eufx+omrij8/evCNEPPAPPs17P4pDEr6Q/zeJ4i9NLTycZTq4HFr6m/BwD+u8BWJJ6CA64yB6BDybn6I5Fkinz/x7yuppkOpmLFqer6a2SSS7wmTfg8yL7flCyVIqdD0mbJKdRJaZOLlxkjQ9SJecAIAypU7vjwDSr+6GRrElob1naUiZZG5RtPoW4iOmJHUhOT29mtuLZVW/vBRfvB3kA3VUVmYyFARoTRvaixFnkIVYNm1PeArgUOFA8Y+Q65B1B9hI4kPqTGMzZgcSG7RO4OYHJabkDgGGWIDGhZEHdwohR88DkhrDNRNyMXB7RmN7JsL5b8WR2AXUKASaoHZgOQc0Ahl9CnAkLsMX43UBZG94hlUwfUkCuQvIKoPR7FRPSLdcfl8sZBPBpuOPAMOtAarxlBSEj8QYK0xmGduKsb+Y/FJJzseHTNNcTLBb4ZT+Xzn6CIVVuvRDwruYYz0LGJYcwUE7ShYyoLRnwLDHccWCY9UD5YNvaRRlcJ0m8hYzyXmYQv5HeuU5R/ASbqfEGrHE9nwB7ktfW9D4oyxz6oduTjCVUjsEpsdwBQJsliKdomeRpFmXZb2TotCOb8ewQ5QTodVa8qJKGZG6FP6oJWXy+hF7jiSrsp8x9sM8QOZ+r9ls6syuluHV8UpVTNOvhcJ2y+TzZ5UA2mtVCe0MJ8Os5NhcERrN2h8Awy2y2mRw2NdvcTAfl3cyLQjbjo/dP7D7PAGcBAt3O0+Rjt211254HmierW+J+oqr9EMkhu2VOyx0ADLMEiQml2yRh7ANp2/KNXTWY3jCyv5vZxUD/g4vkB06RM4DA/vLpA6mrN8C73l/emazN2F8GRmc/jdA216ElVjL51O4wze7N3l82tUslzbu2bZI9GSA5Ocfb/YWI8SUpFd7xI5TCFxjceL88p/rtzlXxE9JqFIv759yRC0rv+PsGkfXz50PlZ+YnDR6L5DX+zvse8W//of/ov9/+U/lvCgGpY25UERCJuSHVCd378P/rnl5WzIZyt5yPR137Qf/Rf/Qf/cffPBrCb7sQwrerWa7dQ+Jcq1lOKE9Vtc2/Mhy0quVimXG3uj3sOWBf5Z7obHlxRx/3Z0/vffrxmv+xRRmz47of+BtzDA7PB6CcwZH3Eci1vGPhoP/oP/rvt/9UxHvzuyKy9TeBv/HjJdRflhdWCRG9IWq5X0tkUia+3dnI3jn//a/7G6w1AvE1QAbnVjDcqigT3+6ERLrL9obzqvJiPoW3Konx/Q6kp9N0oBveWDv3ptR7MhcAsZPXoWR1RqRKzgEn6XKkjotCKnwmskbzFiBtnEsiIkrwjUjoSUF1zctPWHhwCFma5OQclkuARKqlhlYjUCa+23lRYNGwjRvXS50Re5SaIVXU/KDuQ2PD9mkf9F7QeD3wC8guKZ6d20pvT8Mh7dwgG8LOiEj0UxYi+0Z0RWJCqd1yCXI9ZF0BR73xq0He5KgMzrl9YHv36Wot/8EtJXkWA9Uk8RbaC7zqGUhJdi4FKyq1UdgbmL7spyy8pT5uy4C4huESLWvYjnr3sxeRyKZyLZ5NRg45RG+2B5bQYaAu8Yc874Io8KlumFcUygfK5E7HGQsTt0mS9louSUrQCKixeNcfpOgGofGmhaiUJMkQymy6fMoWZHApkzhMdNNTEueMhSsAWqavYblkcRgTnqXmnf+TFzk8m67Iw7aSXuNXVbxhLzVhn7cQYk1UQ62GS7SAoIj3PS4FDpu43oYa/Vsg5IQwhngJMWu4mSmM+xXNpywMNfu078BRlKzEcqDVvPN5MzbezLjGuX3s3a6JVhKXGMFSSe0DzR/cTMFuBqe62aT0UtsPO2eheoytuDxi5Gq4xOq2uQw173yc34pIetH2NNcKWiezrNSu8GIEJjns/WULe3+ZKbFJiTVL5r4h5/QzFp7bX847sNEs5W8uQ83bkzJVzT/eCxF/J8NHkqHb32tfRewbsre/875H/Nt/6D/6j/4zddw5vDsyhoBUzI1MCoCswSHuzVjzfXaV1nzkumsNhzLX8ahrP+g/+o/+o//4m+PxeO2Q9btbzfK7e0icaTXL3SXh0aq2+Wi41KqWi/OMk+r2sOeAY5V7osP5xR193F88vff5J2v+x7aUMTtu+oG/2DE4PB+AYoMj7yOQa3nHwkH/0X/032//qXj2ySn5i48Q/1IflEzuL2Fxv0T09JeyuU7zN34o/K8mifvryPVdWmUfcuBdCNEPci3AV6FEfy29v4h4sDiCrK+kP03v70Iamxxh9zlV3vGVeMdPAgCLH6a8S4FncVwBfDg9AYnJObojkuTMLOb0cZFMSkCPx2DOZN4HhhqBFC2JStv0VqXsksmp8XnI3bFLoWWStSFRmnhInePBNclc1BRR1Hq8MT6qLYx8kMgarYkrMXVy4VJykrQBOPQlJu0/RXIpq7slTTvrhEN8CnER0xO7OmtvNy4Wdbt6eURjepD1wPGuVsONTTD9E5EL6L3g4i3X+dnLgaEmVAlto9eDPMTiYtQ+kKhhw+jei7Bx1DwwudWFNbGh9P7gEFCzsqQBWTrLPpBOsMnCvnTIkTZsn4eAhJKZLE8BSk3tB5Y0w1lBh5jwgnHW3mvo37Ko9fCsYiCYoHa1sjZGSlLa6pTPlIaLpbShJoAS3XhjsgCbSV6s0TV6cgBqRuINFCZ7bEbGRwXT/guFvR9Cbaow4DaJUHIab7m6uRxSwE3Lf5Z/4hropjTDWYZDzjBgnLW32x+qHfCsB1tiCbNY4Jce/w2AvqzmKocOUAJqzjVHe3hlxxmieRc7uCS3uogWMSqlcjk6m0eWwmZgGRCmK7uVniGN2Q+ym0+1k7qdPzCkGXOC4ZBTmGft3cZiiWzAoiyfYTZTM56jpcqegE5RfJiPryw1YVIladOfo2WSEnOsh2gs+YKnxvJShvTtiBrLU9KaTF9DEE+gHHIS86y91ZADQ6xTkw74MOg1sAxNnMYN7aOyMNQEWUzBaj5F5AxV5yhs3nDlq+Kl9BqFwm1XodJqFewzRM7nqv2my+zq3S8Yw7OcodHTA0PbdDVGilrpqtW8VhPGO4Ik7ieYHCfG5s0WAt0daF7XS5HSF4fRbHkK1jSwzWaTsENqtrDO2vuND/LW99Ej+xngLMYEU/BZJ0bvG7tPq9v0YagJMv1QYzNqPrqdJDFh5INczW5BErNwyK1I3K+oah9oziFsK53J8JTg8oiRZaWkmYQdsnxjV4l11t5vDK/29uopcjY0XiSvoQQka3/5gaUmyJhkTlwGen/5JEhkbYeW7Vxyf/kaJtYfRXYoRmd/ATuTczEa+8uG/yzH5y18rqSZnHDIJHuSWJvTb8gXIoZ/4E+pNN5fKO2JzK43JFfFnw5XLii9v0bau5fI+vnnw1gkr/ESaZb3fsT0H/1H/9F/840ZQ0Aq5kYmBUDW4BA3iTXfP/djzZd01xoOZa6VFdF+9B/9R//Rf/zN8Xi8dsj6nVSz/O4eEmdazXJ3SXi0qm0+Gq6q2y7nwPKkuuUp4Fjlnuhw/u07+mSWPL33+Sf/W/PRNTtu+oG/2DE4rvsAFBsceR+BXMs7Fg76j/6j/377T8U754fkk4xfQ5kk12kS9ylT54/D35je/vxFsl7CX/sJPj0P7N7HCxk/CIMLiO9/nFFQ/YuoQkrx9coK+FH4u8DB9HnQeB18ZrJHbC6hJQLXIUTNACQTkJy8jAVzw1GyYzNNMhfNIWIdxE5eanopXINTGZEA0y5LxPZDYq3FUrUzmTfgUnOcJLmPyvLD9FbJ9GZn+QCQ68eD4hm42JArgFmB3gsu3mZ1ecRn7aFLeuLe9IZSsyL7RvQHjQm7ZiQWoU+Q66HqCthliBBSF29LyM0LyF4MjAPDDwd5HHLf6uTPY+RtpoPpYuxWNN6AX2J8AnVaCJmIbIJlELe67NrPsNaD2uWkUg4lueKBoWoE7LJE5HrzsoTIOWz4OoPph8ki3PJWp4sRuXwc+NSXcV/in7LjQa4a4xrv8wzrgANKu+RmUsv63FGYBEnJHQG7LBHDvZpCtJXlDKYfJsfBerMT5d97MLgkN656HKFTFLdYclbwHD4w6CTT0kTKktBYGsuBFm/ZFRZxMZlCjKdiZ7D88K4HdTbeCFWRtycgq76nqvBPnqpkGZ5yhl0ZdoVFlEc1TCE+JX+PqLC8dwhmVc1A7Sx67Becag7+IYtgs8+DfWjq3mA2J5aAXZaIXrdPQ4hez/uFmp9ofttTxM5ToBuw2AGM3j+x+5TkanULJ4cEQa6qW+JS9+SRPgC7W8AuS0RiO9oNIVa35Ru7MgI+g93e9mD6eGDuL8N4XDwuksmYIbjU/vKJtEyL8P5y62TekE+zFUikp4BdlojtWfygWKp2Vton2dNBIqO9v2zxd94XIn77D/1H/9F/9F9lmjEETIm5kUmDv7RqcIjTjgN+ibvWcIAn+o/+o//oP/qPlHv2VfQ0X4Xe7k8WsLPtg6egJy+/9yhyFoZ1wZ6MPmnWYWv42csP0SfyyKO4JSJ4QzL6rzLKertrk8UVnji4097aGJ4+tm+dtbXr0qqzF0a21tbwZKuVhpZ2MzxwtFXoRLh3q4V9iVFYbxV15kgYdu7a1faHl9LW7T1I+5a1E1HRZVsA)

**Figure : Secure boot workflow**

Secure boot is guaranteed only after blowing a QFPROM, which is an eFuse. The eFuse configuration required to enable platform secure boot includes:

- Enabling image authentication and anti-rollback protection.
- Disabling debug and JTAG access.
- Blowing *disable read/write permission* fuses for the QFPROM regions.

## Enable secure boot by blowing the QFPROM fuse

1. Obtain the unique OEM ID from Qualcomm.

    The ID is required when using the code authorization signing services (CASS) or Qualcomm WES services. Or, you can use 0 as the value for the OEM ID.
2. Generate and configure signing assets such as keys and certificates.
3. Generate a signed ELF (sec.elf) for blowing fuses.
4. Sign firmware images.
5. Flash sec.elf and signed images to the device.

Images that aren’t based on Linux are signed using SecTools v2 and a local signer. This process requires signing certificates and keys to be present on the local machine where the signing takes place. However, these keys aren’t secure and can be exposed during and after the signing process on the machine running SecTools.

Note

Qualcomm doesn’t provide guidance on how to secure these keys. It’s recommended to follow standard security protocols, obtain keys/certificates from a trusted certification authority (CA), and protect these keys using a hardware security module (HSM).

Keys and certificates that are self-generated using the OpenSSL tool don’t have a link to any certificate authority.

## Enable secure boot using SecTools

1. Set up the environment variable for SecTools v2. For more information, see [Security tools](https://docs.qualcomm.com/doc/80-70022-11/topic/tools.html#tools).

    The following code snippets are provided as references. Replace `<chipset>` and `<chipset>.LE.X.x` according to the build in use.
For example, `<QCM6490.LE.1.0>`.

Note

The terms metabuild, meta, and meta paths are used interchangeably to indicate the path from the Qualcomm ChipCode™ Portal. The metabuild denotes the complete Qualcomm ChipCode release for a build.

    For Linux:

> 
> 
> setenv SECTOOLS=/<chipset>.LE.X.x/common/sectoolsv2/ext/linux/sectools
>         Copy to clipboard
> 
> 
> export SECTOOLS=/<chipset>.LE.X.x/common/sectoolsv2/ext/linux/sectools
>         Copy to clipboard
2. Use SecTools v2 from the following path:

> 
> 
> `<chipset>.LE.X.x/common/sectoolsv2/ext/<platform>`
> 
>     - The `<chipset>_security_profile.xml` file is located in the meta at `<chipset>.LE.X.x/common/sectoolsv2`
>     - The minimum SecTools version required is 1.17 or later.

4. It’s recommended to use a hardware security module (HSM). However, if a LOCAL (insecure) signer is used, see the LOCAL signing option with -signing-help in [SecTools V2: Secure Image User Guide](https://docs.qualcomm.com/bundle/80-NM248-12/resource/80-NM248-12_REV_AB_SecTools_V2__Secure_Image_User_Guide.pdf).
5. All the keys and certificate generation commands are run using OpenSSL 1.1.1g (21 Apr 2020). It’s a prerequisite to install OpenSSL.
6. Ensure that you enable secure boot on a device that’s not RPMB provisioned. See [Check RPMB provision status](https://docs.qualcomm.com/doc/80-70022-11/topic/bring-up.html#section-bringup-check-rpmb-provision-status-label).

    RPMB will be automatically provisioned with production keys after secure boot fuses are blown.

Note

The *SecTools* guides are available to licensed users with authorized access.

## Next steps

- To enable secure boot, QFPROM fuses must be blown. This is a one-time, irreversible process that permanently sets these values. For more information see [Set the QFPROM fuses](https://docs.qualcomm.com/doc/80-70022-11/topic/appendix-fuse-configurations.html#appendix-fuse-configurations).
- To ensure the that the cryptographic keys and certificates are generated and managed in a secure and trusted environment, see [Generate keys and certificates](https://docs.qualcomm.com/doc/80-70022-11/topic/generate-keys-and-certificates.html#generate-key-and-certificate).

Last Published: Apr 14, 2026

[Previous Topic
Enable device configuration (Devcfg) from Qualcomm TEE](https://docs.qualcomm.com/bundle/publicresource/80-70022-11/topics/enable-device-devcfg-from-qtee.md) [Next Topic
Set the QFPROM fuses](https://docs.qualcomm.com/bundle/publicresource/80-70022-11/topics/appendix-fuse-configurations.md)