Skip to content

Add checking of TCB version when checking a SNP attestation #6812

@cjen1-msft

Description

@cjen1-msft

SNP attestation reports are checked by verify_snp_attestation_report but only validates that the TCB in the attestation report matches that in the endorsed_tcb field in the quote.

The 'correct' fix will probably be to add a new set of 'good' tcbs.
This can then get populated with the current TCB on network creation and then updated via a governance action.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions