diff --git a/arch/arm/imx-common/Kconfig b/arch/arm/imx-common/Kconfig
index 5eb3ba014160e2ed0acacf8d41735eabfb19adf7..25cbd12c899e8b732349fdc57affad3a86886c03 100644
--- a/arch/arm/imx-common/Kconfig
+++ b/arch/arm/imx-common/Kconfig
@@ -29,6 +29,7 @@ config SECURE_BOOT
 	bool "Support i.MX HAB features"
 	depends on ARCH_MX7 || ARCH_MX6 || ARCH_MX5
 	select FSL_CAAM
+	imply CMD_DEKBLOB
 	help
 	  This option enables the support for secure boot (HAB).
 	  See doc/README.mxc_hab for more details.
@@ -46,3 +47,11 @@ config CMD_BMODE
 	  on U-Boot.  Using the reset button or running bmode normal
 	  will set it back to normal.  This command currently
 	  supports i.MX53 and i.MX6.
+
+config CMD_DEKBLOB
+	bool "Support the 'dek_blob' command"
+	help
+	  This enables the 'dek_blob' command which is used with the
+	  Freescale secure boot mechanism. This command encapsulates and
+	  creates a blob of data. See also CMD_BLOB and doc/README.mxc_hab for
+	  more information.
diff --git a/include/configs/mx6_common.h b/include/configs/mx6_common.h
index c841ca9115854ed25f040b6885f1afb91b40994f..21ac3fc357a3fb1591d4f5dc104d58a38fb38afd 100644
--- a/include/configs/mx6_common.h
+++ b/include/configs/mx6_common.h
@@ -84,7 +84,6 @@
 /* Secure boot (HAB) support */
 #ifdef CONFIG_SECURE_BOOT
 #define CONFIG_CSF_SIZE			0x2000
-#define CONFIG_CMD_DEKBLOB
 #ifdef CONFIG_SPL_BUILD
 #define CONFIG_SPL_DRIVERS_MISC_SUPPORT
 #endif
diff --git a/include/configs/mx7_common.h b/include/configs/mx7_common.h
index e2b05caa945fae3239126c39c85555a1b3694ea5..9a20c7732dd8648b04f219fd5043d860d823f5d2 100644
--- a/include/configs/mx7_common.h
+++ b/include/configs/mx7_common.h
@@ -67,7 +67,6 @@
 /* Secure boot (HAB) support */
 #ifdef CONFIG_SECURE_BOOT
 #define CONFIG_CSF_SIZE			0x2000
-#define CONFIG_CMD_DEKBLOB
 #endif
 
 #endif
diff --git a/scripts/config_whitelist.txt b/scripts/config_whitelist.txt
index bbb0a1dec091bb0e0a73bbfa3132d6c5a91a30cc..3c1feed25399c6a20419e724fd8cff6a9ba68ae7 100644
--- a/scripts/config_whitelist.txt
+++ b/scripts/config_whitelist.txt
@@ -394,7 +394,6 @@ CONFIG_CMDLINE_EDITING
 CONFIG_CMDLINE_PS_SUPPORT
 CONFIG_CMDLINE_TAG
 CONFIG_CMD_DATE
-CONFIG_CMD_DEKBLOB
 CONFIG_CMD_DFL
 CONFIG_CMD_DIAG
 CONFIG_CMD_DISPLAY