A key slot that is revoked it can no longer be pushed.
A key slot can be revoked when it is in the PROVISIONED state or when its revocation policy is not LOCKED.
To revoke a key slot, perform the following steps:
- Configure the key slot ID in the KEYSLOT register.
- Enable RRAM write operation in Normal write mode. For details, see RRAMC — Resistive random access memory controller.
- Trigger the REVOKE task.
KMU erases the asset from SICR. If revoking the key slot is successful, KMU generates the REVOKED event. If unsuccessful, or the key slot is already in the REVOKED state, KMU generates the ERROR event.
- Disable RRAM write operation. For details, see RRAMC — Resistive random access memory controller.