generate_keys - generate_keys - 2026.1 English - UG1283

Bootgen User Guide (UG1283)

Document ID
UG1283
Release Date
2026-06-23
Version
2026.1 English

Syntax

bootgen -image test.bif -generate_keys <rsa|pem|obfuscatedkey|lms-shake256>

Description

This option generates keys for authentication and obfuscated key used for encryption.

Note: For more information on generating encryption keys, see Key Generation.
Important: Keys generated by Bootgen are intended for development use only. For fielded systems, AMD recommends that you generate your own keys for fielded systems using a high-quality entropy source and then provide those keys to the development tools. See AR76171 for more information.

Authentication Key Generation Example

Authentication key generation example. This example generates the authentication keys in the paths specified in the BIF file.

bootgen -image test.bif -generate_keys rsa

Examples

image:
{  
	[ppkfile] <path/ppkgenfile.txt>
	[pskfile] <path/pskgenfile.txt>
	[spkfile] <path/spkgenfile.txt>
	[sskfile] <path/sskgenfile.txt>
}

LMS

{                                                              
     lms_key_params                                            
     {                                                          
         primary {lms_shake256_h5_w2}                          
         secondary {lms_shake256_h5_w2}                        
     }                                                          
     [ppkfile] <path/ppkgenfile.txt>                            
     [pskfile] <path/pskgenfile.txt>                            
     [spkfile] <path/spkgenfile.txt>                            
     [sskfile] <path/sskgenfile.txt>                            
 }                    

HSS

 image:                                                        
 {                                                              
     lms_key_params                                            
     {                                                          
         primary {lms_shake256_h15_w2, lms_shake256_h15_w2}    
         secondary {lms_shake256_h15_w2, lms_shake256_h15_w2}  
     }                                                          
     [ppkfile] <path/ppkgenfile.txt>                            
     [pskfile] <path/pskgenfile.txt>                            
     [spkfile] <path/spkgenfile.txt>                            
     [sskfile] <path/sskgenfile.txt>                            
 }
Note: Here h and w are parameters that you need to specify in the BIF. Even for hss, use the -generate_keys lms flag while generating keys.

The system generates the key files in the paths mentioned above. You can use them for LMS and HSS.

Obfuscated Key Generation Example

This example generates the obfuscated in the same path as that of the familykey.txt.

Command:

bootgen -image test.bif -generate_keys obfuscatedkey

The following example shows the Sample BIF file:

image:
{
	[aeskeyfile] aes.nky
	[bh_key_iv] bhkeyiv.txt
	[familykey] familykey.txt
}

Arguments

  • rsa
  • pem
  • obfuscated
  • lms-shake256