Expand description
Intel TDX and SGX evidence: ECDSA-P256 DCAP quotes (SGX v3, SGX/TDX v4 and v5).
Checks performed:
- the PCK certificate chain embedded in the quote (certification data type 5, PEM or DER) chains to the pinned Intel SGX Root CA and is valid now;
- the Quoting Enclave (QE) report is signed by the PCK key, and is not a debug enclave;
- the QE report’s
REPORT_DATAbinds the attestation key:SHA-256(attestation_key || qe_auth_data)followed by 32 zero bytes; - the quote header and body are signed by the attestation key.
Not evaluated: TCB status and QE identity against Intel PCS collateral (TCB Info, QE Identity, PCK CRLs). A genuine but out-of-date or revoked platform is therefore accepted.
Functions§
- verify
- Verifies the DCAP
quoteproduced bytee(TDX or SGX) at timenow.