Skip to content

Add checking of TCB version when checking a SNP attestation #6812

@cjen1-msft

Description

@cjen1-msft

SNP attestation reports are checked by verify_snp_attestation_report but only validates that the TCB in the attestation report matches that in the endorsed_tcb field in the quote.

The 'correct' fix will probably be to add a new set of 'good' tcbs.
This can then get populated with the current TCB on network creation and then updated via a governance action.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions