Hi Vikrant,
This makes sense to me.
Today cert_create effectively treats the registered key set as global: even if only a subset of certificates is requested, it still walks the full key list for load/create/save,
and -k can fail on filenames for keys that are not actually needed by the requested outputs.
Your proposed approach seems like the right direction. At a high level, the tool should first derive the required key set from the certificates that were actually requested, then use that set consistently for validation, key load/create, and key save. That
would make requesting only a subset of certificates work the way users would expect, without needing to provide or generate unrelated keys.
One thing I would suggest is to make sure the filtering is applied consistently across all three places:
-
command-line validation
-
key load/create
-
key save
If that is what your change does, then the approach looks good to me. Please upload it to Gerrit and it can go through the usual review process and CI validation.
Thanks,
Manish Badarkhe
From: Vikrant Yadav <vikrantyadav4802@gmail.com>
Sent: 29 September 2026 07:14
To: tf-a@lists.trustedfirmware.org <tf-a@lists.trustedfirmware.org>
Cc: Sandrine Bailleux <Sandrine.Afsa@arm.com>; Manish Badarkhe <Manish.Badarkhe@arm.com>
Subject: [RFC] cert_create: only generate/save keys needed by requested certs
Hi all,
I'd like to propose a small change to cert_create (tools/cert_create) and get your feedback before uploading to Gerrit.
What it does today:
When generating certificates, cert_create unconditionally generates all keys in the Chain of Trust (CoT), and with the -k option it requires filenames for every key - even when only a subset of certificates is requested.
Why this is a problem:
Keys that no requested certificate needs are still generated, and -k errors out on missing filenames for keys that are never used. Requesting a single certificate shouldn't require dealing with keys it doesn't depend on.
Proposed fix:
Add a "bool required" field to the key struct. For each requested certificate, mark as required the keys it depends on:
- the certificate's own key
- its issuer's signing key
- keys referenced by its extensions
The key generation and save loops then act only on keys marked required.
Does this approach make sense? If so, I'll upload the change to Gerrit.
Thanks,
Vikrant