Body:
Currently, the Caliptra ROM engine attests to both Owner and Vendor controlled fuse measurements into a single digest, which is reported as TCBInfo extension to the FMC_Alias certificate. This approach makes it challenging for vendors to provide an accurate reference measurement in CoRIM, since the Owner-specific settings are unknown to them.
Request:
We propose that the measurement of Owner and Vendor controlled fuses be separated into two distinct claims. This change will enable vendors to generate accurate reference measurements without requiring knowledge of owner-specific fuse settings.