Prerequisites
Compile devcfg image from TrustZone
- Select the configuration options that TrustZone offers through the built in
devcfg.mbn/devcfg_iot.mbnXML files. For example:trustzone_images/ssg/securemsm/trustzone/qsee/mink/oem/config/<chipset>/oem_config.xml. - Use the command to compile the devcfg image from TZ.XF.5.29.1.
This steps generates the
devcfg.mbn/devcfg_iot.mbnimages attrustzone_images/build/ms/bin/<build_flavor>. Use the following build flavors and commands.
- QCS5430/QCS6490
- IQ-9075/IQ-9100
- IQ-8275/IQ-8300
- IQ-615
- QCS5430/QCS6490
- IQ-9075/IQ-9100
- IQ-8275/IQ-8300
- IQ-615
Use the following devcfg files:<devcfg> is
devcfgfor QCS6490devcfg_iotfor IQ-9100, IQ-8300, IQ-615
Customize device using configuration parameters
Use the configuration parameters listed in the following table to customize the device as needed.Enable RPMB-based SFS anti-rollback protection
To enable or disable the RPMB-based SFS anti-rollback protection, use the following configuration parameter and the XML file.Configuration parameter
cmnlib_gppo_rpmb_enablement, can be set to Enabled or Disabled, where the default value is Enabled and must be changed only when required.
XML file location
trustzone_images/ssg/securemsm/trustzone/qsee/mink/oem/config/common/cmnlib_oem_config.xml
Next steps
- To enable secure boot and to ensure only trusted applications runs on the device, see Enable secure boot.
- To enable secure boot, QFPROM fuses must be blown. This is a one-time, irreversible process that permanently sets these values. For more information, see Set the QFPROM fuses.

