Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature: Add QEMU option to include ARK, ASK and VCEK certificates to the guest VM #193

Open
danko-miladinovic opened this issue Aug 7, 2024 · 8 comments
Assignees
Labels
enhancement New feature or request

Comments

@danko-miladinovic
Copy link
Contributor

Is your feature request related to a problem? Please describe.

This feature is designed to increase the speed of the verification process.

Describe the feature you are requesting, as well as the possible use case(s) for it.

This feature will enable the Manager to run SVMs with added ARK, AS and VCEK to guest memory. This will enable the Agent to send the certificates ARK, ASK and VCEK alongside the attestation report. The CLI will then only have to fetch the CRL from AMD and not ARK, ASK and VCEK.

Indicate the importance of this feature to you.

Must-have

Anything else?

No response

@danko-miladinovic danko-miladinovic added the enhancement New feature or request label Aug 7, 2024
@danko-miladinovic danko-miladinovic self-assigned this Aug 7, 2024
@dborovcanin
Copy link
Contributor

@danko-miladinovic What's the status with this one?

@dborovcanin
Copy link
Contributor

@danko-miladinovic What's the status of this ticket?

@danko-miladinovic
Copy link
Contributor Author

This was not able to be done before because of QEMU. Now with the new version of QEMU installed, this can be done. I will work on it.

@dborovcanin
Copy link
Contributor

@danko-miladinovic What's the status here?

@danko-miladinovic
Copy link
Contributor Author

I will start on this one as soon as I finish with aTLS bug.

@dborovcanin
Copy link
Contributor

@danko-miladinovic Any progress on this one?

@dborovcanin
Copy link
Contributor

@danko-miladinovic Any updates?

@danko-miladinovic
Copy link
Contributor Author

It seems that the parameter for certs-path is still not implemented in QEMU, it is implemented in AMDSEV repo QEMU. This feature will still be delayed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants