Enable Linux Kernel signature verification using Thistle on Orange Pi Zero 3 (Allwinner H618)
hardware/orange_pi/zero3_ota_ab_update
.
oem
/ oem
(hostname: orange-os.local
)kernel
. Download kernel-sig
.kernel-sig
to the board’s boot partition:/boot
; place boot.scr
there. Some builds use extlinux.conf
; in that case, adapt your integration to call TVB verification before booting the kernel./boot/tvb-pubkey.pem
) when verifying kernel
against kernel-sig
before booting. If you are using a custom script, keep the key, kernel, and signature paths consistent: