meta-ibm: Sign the p10bmc SPL using dev key

Use the 'insecure/imprint' development key to sign the p10bmc SPL. The
key can be overriden for a production key if necessary.

Signed-off-by: Klaus Heinrich Kiwi <klaus@linux.vnet.ibm.com>
Change-Id: I6e4abecb5859fb59c6185a097cf88bdcb958e207
diff --git a/meta-ibm/conf/machine/p10bmc.conf b/meta-ibm/conf/machine/p10bmc.conf
index 2db74ef..e71b10c 100644
--- a/meta-ibm/conf/machine/p10bmc.conf
+++ b/meta-ibm/conf/machine/p10bmc.conf
@@ -38,6 +38,9 @@
 
 UBOOT_SIGN_ENABLE = "1"
 SPL_SIGN_ENABLE = "1"
+SOCSEC_SIGN_ENABLE = "1"
+SOCSEC_SIGN_EXTRA_OPTS = "--stack_intersects_verification_region=false"
+SOCSEC_SIGN_KEY ?= "${WORKDIR}/rsa_oem_dss_key.pem"
 
 FIT_HASH_ALG = "sha512"
 FIT_SIGN_ALG = "rsa4096"