Debug Lock Settings#
CPMS provides four debug lock settings for this required field:
Standard Debug Lock
Secure Debug Lock
Permanent Lock
Unlocked
If you select Secure Debug Lock, you must provide a public command key. CPMS provisions the public command key to the device, if required, and applies the selected debug lock setting.
For more information about each debug lock setting, see Series 2 and Series 3 Secure Debug.
The following table summarizes the available settings in the CPMS portal:
CPMS Setting | Behavior | How Unlock Works |
|---|---|---|
Unlocked | Debug access remains fully enabled. | Unlock is not required. |
Standard Debug Lock | Debug access is locked at boot. | Can be unlocked only by performing a device erase (flash memory is erased). |
Secure Debug Lock | Debug access is locked at boot and protected by a challenge-response mechanism. | Can be temporarily unlocked using Secure Debug Unlock with a provisioned public command key. |
Permanent Lock | Debug access is permanently disabled. Device erase and Secure Debug are blocked. | The device cannot be unlocked. |
Note: Enabling Secure Debug Lock in the CPMS portal permanently disables device erase.
To configure the required debug lock setting, select one of the available options in the CPMS portal, as shown in the following figure.

