# Secure boot fuse programming

**URL:** <https://community.solid-run.com/t/secure-boot-fuse-programming/785>\
**Category:** NXP LX2160\
**Tags:** NXP-LX2160\
**Created:** [December 14, 2023, 1:19am UTC](https://community.solid-run.com/t/secure-boot-fuse-programming/785 "2023-12-14T01:19:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kairovini](https://dub1.discourse-cdn.com/flex005/user_avatar/community.solid-run.com/kairovini/32/252_2.png) [@kairovini](https://community.solid-run.com/u/kairovini)\
**Post date:** [December 14, 2023, 1:19am UTC](https://community.solid-run.com/t/secure-boot-fuse-programming/785/1 "2023-12-14T01:19:51Z")

</div>

I’m trying to setup secure boot on ClearFog CX LX2 (lx2160a-cex7). Following [NXP instructions for secure boot](https://docs.nxp.com/bundle/GUID-3FFCCD77-5220-414D-8664-09E6FB1B02C6/page/GUID-27FC40AD-3321-4A82-B29E-7BB49EE94F23.html), I need to enable POVDD for fuse provisioning. In [cex7 schematics](https://solidrun.atlassian.net/wiki/download/attachments/197493994/lx2160a-cex7-2.1-simplified-schematics.pdf?version=1&modificationDate=1687260510852&cacheVersion=1&api=v2), I can see that EN\_SFP\_PROG exists, but how can I enable it?

I already tried to blow OTPMK and SRKH writing SFP\_INGR register with `mw 0x01e80020 0x2` but the board reset and when I check the memory, OTPMK and SRKH are empty. Following the same instructions with NXP LX2160ARDB, I can enable POVDD when I put J9 to enable PROG\_SFP, then I write the OTPMK and SRKH in the registers and I write SFP\_INGR register, the NXP board doesn’t reset and when I check the memory after a manual reset, the OTPMK and SRKH were written correctly. Due that, I supose that the only different step is the POVDD enabled, so returning to the first question, how to do it (enable POVDD) in ClearFog CX LX2 (lx2160a-cex7) board?

---

<div class="post-metadata">

**Author:** ![jnettlet](https://dub1.discourse-cdn.com/flex005/user_avatar/community.solid-run.com/jnettlet/32/62_2.png) [@jnettlet](https://community.solid-run.com/u/jnettlet)\
**Post date:** [December 14, 2023, 12:23pm UTC](https://community.solid-run.com/t/secure-boot-fuse-programming/785/2 "2023-12-14T12:23:06Z")

</div>

If you have a Rev 2.1 of the LX2160a CEX7 module then enabling the PROG\_SFP power circuit is done through GPIO1\_DAT12, if the board is assembled with the proper assembly options. I am currently waiting to hear back from production if we are assembling this circuit by default or not. If it is a previous revision CEX7 module then the programming needs to be done through the GPIO exported to the carrier, but would also need hardware changes to enable this feature.

---

<div class="post-metadata">

**Author:** ![phillipplavor](https://dub1.discourse-cdn.com/flex005/user_avatar/community.solid-run.com/phillipplavor/32/253_2.png) [@phillipplavor](https://community.solid-run.com/u/phillipplavor)\
**Post date:** [December 18, 2023, 6:18pm UTC](https://community.solid-run.com/t/secure-boot-fuse-programming/785/3 "2023-12-18T18:18:02Z")

</div>

The simplified schematics for the LX2160A CEX7 2.1 only display the EN\_SFP\_PROG signal and its 1.8V/3.3V level shifter. Could you please provide information about the circuit that connects to the TA\_PROG\_SFP signal (pin G13 on LS1046A)? Also, for the PROG\_SFP power circuit, could you share the part numbers or designators of the DNP components if this circuit is not assembled by default or if you cannot disclose the circuit itself?

---

<div class="post-metadata">

**Author:** ![jnettlet](https://dub1.discourse-cdn.com/flex005/user_avatar/community.solid-run.com/jnettlet/32/62_2.png) [@jnettlet](https://community.solid-run.com/u/jnettlet)\
**Post date:** [December 21, 2023, 10:17am UTC](https://community.solid-run.com/t/secure-boot-fuse-programming/785/4 "2023-12-21T10:17:01Z")

</div>

I will update you once I have the answers from the hardware and production teams.

---

<div class="post-metadata">

**Author:** ![phillipplavor](https://dub1.discourse-cdn.com/flex005/user_avatar/community.solid-run.com/phillipplavor/32/253_2.png) [@phillipplavor](https://community.solid-run.com/u/phillipplavor)\
**Post date:** [March 11, 2024, 3:32pm UTC](https://community.solid-run.com/t/secure-boot-fuse-programming/785/5 "2024-03-11T15:32:19Z")

</div>

Hi. Are there any updates from them?
