4.1.1.2.1 Single Fixed Code Signing Key
For some systems, a single fixed code signing key is sufficient to meet the system security goals. In a system with a single fixed code signing key, a single code signing key is used to sign all firmware updates. If that key is compromised, the device needs to be replaced. In the case of a single fixed code signing key, the immutability of that key protects both the integrity and authenticity of the code signing key.
