Uploaded image for project: 'Openshift sandboxed containers'
  1. Openshift sandboxed containers
  2. KATA-3977

Provide reference TEE measurements for the initrd to do remote attestation

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: High High
    • OSC 1.12
    • None
    • None
    • None
    • OSC 1.12 Ready for sprint, OSC Sprint #2026/1
    • 0

      Goal and why this matters

      TEE measurements are critical to enforce fool proof confidentiality through the hardware root-of-trust mechanism. This requires remote attestation of the TEE (TDX and SNP) measurements by comparing the hash values with reference values available with Trustee. Currently, our build pipeline doesn't compute and publish the reference hash value for initrd to Trustee/RVPS. 

      Therefore, creating launch measurements for the initrd at build pipeline and providing it to Trustee is a must have.

       

      Acceptance Criteria

      Availability of the reference value in Trustee for remote attestation.

      i.e., Generate reference hash values for both TDX and SNP during the build and publish to Trustee/RVPS. 

       

       

       

       

              bpradipt Pradipta Banerjee
              jfreiman Jens Freimann
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: