Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

What is the plan to support to verify SEV(-ES) attestation report using PEK? #1

Closed
tylerfanelli opened this issue Apr 19, 2022 · 0 comments

Comments

@tylerfanelli
Copy link
Member

enarx-archive/sev#100

From @haosanzi - "User can get sev attestation report signed by PEK by QMP interface "query-sev-attestation-report" in the host.
It is reasonable to add a report verification process."

Hi, we've moved the enarx/sev repository over to this domain and are currently working upstream. I've been investigating query-sev-attestation-report in QEMU, and haven't found much use of querying an attestation report over simply using LAUNCH_MEASURE, what are the advantages of getting a PEK in regards of SEV-ES?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant