3 ms·
I think Intel backed away from the documentation that implied all signed enclaves had to go through them. I think people can attest their own SGX enclaves.
by sweis 10y ago
I think Intel backed away from the documentation that implied all signed enclaves had to go through them. I think people can attest their own SGX enclaves.
- anonymousDan 10y agoReally? Where did you hear/see that? Would be really interested to get a link.
- wmf 10y agohttp://lwn.net/Articles/686811/ http://lwn.net/Articles/686811/
- amluto 10y agoUnless the docs changed from last time I read them, those MSRs aren't one shot. Also, the fact that anyone at Intel calls the signing system a "root of trust" makes me think that Intel is deluding itself. It's a root of licensing authority, not a root of trust in the system. You could set those MSRs to a public key for which everyone knows the private key and everything would work just fine.