- Generate the capsule. For scripts and instructions, see: https://github.com/qualcomm/cbsp-boot-utilities/tree/main/uefi_capsule_generation.
- Obtain the git clone link
cbsp-boot-utilities/uefi_capsule_generation/directory at https://github.com/qualcomm/cbsp-boot-utilities.git.
Sign the capsule
To sign capsule-based system firmware updates using the instructions from the Capsule Generation, follow these steps:- Generate signing keys:
- Use OpenSSL command line utilities to create a new self-signed X.509 certificate chain. This involves generating a private key and a corresponding public certificate.
- The system uses the private key to sign the firmware update capsules, and the UEFI firmware uses the public certificate to verify the signature.
- Sign the firmware update capsule:
- Use the signing keys to sign the firmware update capsule. This process authenticates the capsule and ensures it hasn’t been tampered with.
- The signing process involves creating a hash of the firmware update payload and then encrypting this hash with the private key to create a digital signature.
- Place these certificates in a folder named `Certificates’. Sample files available in this folder might include
QcFMPCert.pem,QcFMPRoot.pub.pem, andQcFMPSub.pub.pem.
- Verify the capsule:
- The UEFI firmware uses the public certificate to verify the digital signature on the capsule. If the signature is valid and matches the trusted certificate, the firmware update process will proceed.
- The boot devicetree (DT) provides the root certificate—either
QcFMPRoot.cerorNewRoot.cerat the following node:/sw/uefi/uefiplat/QcCapsuleRootCert. - This boot DT node is a UEFI DT node, so its binary location depends on the platform. On platforms where
xbl_config.elfcontains both XBL and UEFI DT nodes, it’s part ofxbl_config.elf. On platforms where the UEFI DT nodes are split out, it’s part ofuefi_dtbs.elf(or its compressed/KVM variants) instead. For the full platform breakdown, see Boot interfaces overview. Either file can be updated using the QDTE tool. - Capsule update can only be performed if the root certificate is already present on the device, specifically within this boot DT node.
- Ensure the certificate is correctly embedded in the applicable binary and available on the device before initiating any capsule update process.

