Skip to content

Feature Request: TDX RTMR Extension for Workload Measurement #2604

@frieder-ritual

Description

@frieder-ritual

Summary

Add support for extending TDX RTMR3 with initdata digest when running on TDX-enabled platforms, similar to the current TPM PCR8 extension.

Current Behavior

  • Workload measurement via tpm2_pcrextend 8:sha256=$(head -c64 /run/peerpod/initdata.digest)
  • Works with TPM/vTPM but fails silently on TDX-only environments
  • No workload reflection in TDX attestation when TPM is unavailable

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions