Base Attestation #1
Owner
- Client initiates TLS session, proxied from TCP/IP to vsock, with bootproofd
- Ensure TLS session is bound properly by performing TLS Channel Binding with EKM as userdata in attestation document, helps with MITM
- Client should request data from a service it wants to connect to, such as a HTTPS certfp, or Keyfork signing key
- Client can access third-party endpoint or long-lived key to validate attestation
* Client initiates TLS session, proxied from TCP/IP to vsock, with bootproofd
* Ensure TLS session is bound properly by performing TLS Channel Binding with EKM as userdata in attestation document, helps with MITM
* Client should request data from a service it wants to connect to, such as a HTTPS certfp, or Keyfork signing key
* Client can access third-party endpoint or long-lived key to validate attestation
Loading…
Reference in New Issue
No description provided.
Delete Branch "%!s(<nil>)"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?