Skip to main content

Module attestation

Module attestation 

Source
Expand description

Hardware-agnostic attestation providers.

Each supported TEE (AWS Nitro, AMD SEV-SNP, Intel TDX, …) implements AttestationProvider. detect probes the machine at runtime and returns the provider matching the hardware we are running on; by_name selects one explicitly.

Backends are gated by additive Cargo features (nitro, sev-snp, tdx, mock), so a single binary can support several of them.

Re-exports§

pub use nitro::NsmSession;
pub use mock::MockSession;

Modules§

eat
RFC 9711 Entity Attestation Token (EAT) data model.
mock
Mock provider for local development and CI where no TEE hardware exists.
nitro
AWS Nitro Security Module (NSM) provider.
nitro_doc
Nitro attestation-document helpers shared by the real (nitro) and mock providers: COSE_Sign1 payload extraction, parsing, mock document creation and EAT wrapping.

Enums§

AttestationError
Errors produced by any attestation provider.

Constants§

PROVIDER_ENV
Environment variable that forces a specific provider (see by_name).

Traits§

AttestationProvider
A source of attestation evidence backed by a specific TEE.

Functions§

by_name
Opens the provider called name.
detect
Picks the provider matching the current hardware.