Merge "Remove recommentation of non-normal mode" am: a0f28846c4 am: fbc43248ed
Original change: https://android-review.googlesource.com/c/platform/hardware/interfaces/+/2586968
Change-Id: If5bfee34edb70eb5ad601cbabe16ee4086d9b60a
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
diff --git a/security/rkp/README.md b/security/rkp/README.md
index 7477f80..ab767d6 100644
--- a/security/rkp/README.md
+++ b/security/rkp/README.md
@@ -303,9 +303,10 @@
* debug ports, fuses or other debug facilities are disabled
* device booted software from the normal primary source e.g. internal flash
-If any of these conditions are not met then it is recommended to explicitly
-acknowledge this fact by using the `debug` mode. The mode should never be `not
-configured`.
+The mode should never be `not configured`.
+
+Every certificate in the DICE chain will need to be have the `normal` mode in
+order to be provisioned with production certificates by RKP.
#### Configuration descriptor