19.3.1 Configuring Secure Boot Mode
The recommended procedure to configure the Secure Boot mode, using the
SAM-BA tool (available on www.microchip.com), is the following:
- Write the Boot Configuration Packet, with the required boot settings and boot memory interface.
- Set the Secure Boot mode.
- Send the customer key.
- Send the Root Certificate Hash (in case RSA signature is used).
- Configure the boot memory interface.
- Program the ciphered bootstrap.
- Program the other application files.
- Disable the monitor to avoid any further access to the Secure monitor.
- Lock the Boot Configuration Packet.
Note: Keeping the Secure Monitor enabled in order to update the bootstrap on the field or
in-house is not recommended.
Warning: The Boot Configuration Packet must be written as
the very first packet in OTP.