Uploaded image for project: 'Openshift sandboxed containers'
  1. Openshift sandboxed containers
  2. KATA-3658

Capture measurements of the pod VM image for remote attestation

XMLWordPrintable

    • Icon: Epic Epic
    • Resolution: Done
    • Icon: Medium Medium
    • OSC 1.10.0
    • None
    • None
    • None
    • Capture measurements of the pod VM image for remote attestation
    • False
    • Hide

      None

      Show
      None
    • False
    • Not Selected
    • To Do
    • 0

      Epic Goal

      • Capture measurements of the pod VM image for remote attestation

      Why is this important?

      • For confidential containers, attestation is critical to verify the trustworthiness of the TEE environment. From pod VM standpoint, a user need to be sure that the kernel, kernel CLI and rootfs disk has not been tampered before releasing a secret into the environment. 

      Scenarios

      1. As a user, I want to ensure that the pod VM has not been tampered.
      2. As a user I want to capture the measurements of my pod VM image and use it in Trustee for remote attestation

      Acceptance Criteria 

      (The Epic is complete when...)

      1. Ability to capture measurements when creating the pod VM image
      2. Ability to verify the measurement as part of remote attestation via Trustee
      3. ..

      Additional context:

              Unassigned Unassigned
              bpradipt Pradipta Banerjee
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: