Boot Time Security - 2025.2 English - UG1137

Zynq UltraScale+ MPSoC Software Developer Guide (UG1137)

Document ID
UG1137
Release Date
2025-12-03
Version
2025.2 English

This section details the various boot image formats for authentication and encryption.

Important: For Zynq MPSoC, when RSA_EN eFUSE is not programmed and BOOT.BIN does not have BH_AUTH enabled, FSBL can load bin as non-secure even if the partitions are authenticated. It is disabled by default, so to enable it, set FSBL_UNPROVISIONED_AUTH_SIGN_EXCLUDE_VAL to 0 in xfsbl_config.h.