Skip to content

Support one hash endorsement in MigTD #123

@haitaohuang

Description

@haitaohuang

Assume MS will always own MigTD code and policy. we will have one MS signed endorsement for migtd td-info hash, which gives tcb_date
Root Signing key for endorsement will be in MrOwner.
Need investigate:

  1. can we measure policy in MRTD? This is to get rid of circular dependency for build pipeline. policy currently measured in RTMR and we need it to build the hash.
  • the endorsement will not be measured. Only trust the signing key, which is measured in MrOwner.
  1. support CORIM format for the endorsement

  2. If we still need policy signing (related to 1), tcb-mapping, identy signing for ServTD collateral

  3. verify we do not use collateral for init tdinfo hash evaluation

  4. MrOwnerConfig (SVN) still needed? nice to have it for audit? Keep implementation for now.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions