<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Receiving ISV Enclave Trust Status as Enclave NOT TRUSTED. CONFIGURATION_AND_SW_HARDENING_NEEDED in Intel® Software Guard Extensions (Intel® SGX)</title>
    <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Receiving-ISV-Enclave-Trust-Status-as-Enclave-NOT-TRUSTED/m-p/1193544#M3832</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;I am trying out this remote attestation example&amp;nbsp;&lt;A href="https://github.com/intel/sgx-ra-sample" target="_self"&gt;https://github.com/intel/sgx-ra-sample&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I'm using SGX SDK version 2.9.1 and openSSL version 1.1.1c. I'm running it on a dell laptop with BIOS 1.15.1 and latest microcode 0xd6 on ubuntu 18.04, Intel i7 8th gen. When executing the remote attestation example, in the final verification step, i receive ISV Enclave Trust Status as:&amp;nbsp;&lt;STRONG&gt;Enclave NOT TRUSTED - Reason: CONFIGURATION_AND_SW_HARDENING_NEEDED.&amp;nbsp;&lt;/STRONG&gt;The mitigation tools were properly added with sdk 2.9.1. Still i receive the same status. Can anyone make a suggestion on how to rectify this?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Bala&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jul 2020 07:19:34 GMT</pubDate>
    <dc:creator>k__balaganapathy</dc:creator>
    <dc:date>2020-07-20T07:19:34Z</dc:date>
    <item>
      <title>Receiving ISV Enclave Trust Status as Enclave NOT TRUSTED. CONFIGURATION_AND_SW_HARDENING_NEEDED</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Receiving-ISV-Enclave-Trust-Status-as-Enclave-NOT-TRUSTED/m-p/1193544#M3832</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;I am trying out this remote attestation example&amp;nbsp;&lt;A href="https://github.com/intel/sgx-ra-sample" target="_self"&gt;https://github.com/intel/sgx-ra-sample&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I'm using SGX SDK version 2.9.1 and openSSL version 1.1.1c. I'm running it on a dell laptop with BIOS 1.15.1 and latest microcode 0xd6 on ubuntu 18.04, Intel i7 8th gen. When executing the remote attestation example, in the final verification step, i receive ISV Enclave Trust Status as:&amp;nbsp;&lt;STRONG&gt;Enclave NOT TRUSTED - Reason: CONFIGURATION_AND_SW_HARDENING_NEEDED.&amp;nbsp;&lt;/STRONG&gt;The mitigation tools were properly added with sdk 2.9.1. Still i receive the same status. Can anyone make a suggestion on how to rectify this?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Bala&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 07:19:34 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Receiving-ISV-Enclave-Trust-Status-as-Enclave-NOT-TRUSTED/m-p/1193544#M3832</guid>
      <dc:creator>k__balaganapathy</dc:creator>
      <dc:date>2020-07-20T07:19:34Z</dc:date>
    </item>
    <item>
      <title>Re:Receiving ISV Enclave Trust Status as Enclave N...</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Receiving-ISV-Enclave-Trust-Status-as-Enclave-NOT-TRUSTED/m-p/1193690#M3835</link>
      <description>&lt;P&gt;Hello Bala,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Your platform needs further configuration and mitigation actions. Please read this advisory, &lt;A href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00320.html" rel="noopener noreferrer" target="_blank"&gt;https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00320.html&lt;/A&gt;, and download the Intel SGX Attestation Technical Details linked to in the following sentence:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px; font-family: intel-clear, tahoma, Helvetica, helvetica, Arial, sans-serif;"&gt;"To address this issue, an SGX TCB recovery will be required in Q3 2020. Refer to&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://cdrdv2.intel.com/v1/dl/getContent/627144" rel="noopener noreferrer" target="_blank" style="font-size: 12px; font-family: intel-clear, tahoma, Helvetica, helvetica, Arial, sans-serif;"&gt;Intel® SGX Attestation Technical Details&lt;/A&gt;&lt;SPAN style="font-size: 12px; font-family: intel-clear, tahoma, Helvetica, helvetica, Arial, sans-serif;"&gt;&amp;nbsp;for more information on the SGX TCB recovery process."&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 20 Jul 2020 17:11:24 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Receiving-ISV-Enclave-Trust-Status-as-Enclave-NOT-TRUSTED/m-p/1193690#M3835</guid>
      <dc:creator>JesusG_Intel</dc:creator>
      <dc:date>2020-07-20T17:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Receiving ISV Enclave Trust Status as Enclave N...</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Receiving-ISV-Enclave-Trust-Status-as-Enclave-NOT-TRUSTED/m-p/1194041#M3842</link>
      <description>&lt;P&gt;Hello JesusG,&lt;/P&gt;
&lt;P&gt;Thank you for replying. I went through the links that you provided and followed accordingly. Still i'm not able to rectify this status&amp;nbsp;&lt;STRONG&gt;Enclave NOT TRUSTED - Reason: CONFIGURATION_AND_SW_HARDENING_NEEDED.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I tried installing the latest SGX SDK v2.10 on my Ubuntu 18.04.4 LTS,&amp;nbsp;Intel® Core™ i7-8650U.&lt;/P&gt;
&lt;P&gt;Here is the server output i'm receiving after running the sample&amp;nbsp;&lt;A href="https://github.com/intel/sgx-ra-sample" target="_blank" rel="noopener"&gt;https://github.com/intel/sgx-ra-sample&lt;/A&gt;&amp;nbsp;:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;---- IAS Report - JSON - Optional Fields -----------------------------------
platformInfoBlob  = 1502006500000800000F0F02040101070000000000000000000B00000B000000020000000000000BCB2411F1D4E37D6B5CDF21B4613E469239F1C06588B7BE7C7CA81BFD312E355224084EE08C6DE3C0F4E161110917A447C999F63DEF657AF59768A4E15F74F912CB
revocationReason  = 
pseManifestStatus = 
pseManifestHash   = 
nonce             = 
epidPseudonym     = 
advisoryURL       = https://security-center.intel.com
advisoryIDs       = INTEL-SA-00334,INTEL-SA-00161,INTEL-SA-00219,INTEL-SA-00289
----------------------------------------------------------------------------
+++ Verifying report version against API version

---- ISV Enclave Trust Status ----------------------------------------------
Enclave NOT TRUSTED - Reason: CONFIGURATION_AND_SW_HARDENING_NEEDED
A Platform Info Blob (PIB) was provided by the IAS

&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The platform info blob returned by IAS:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;---- Enclave Trust Status from Service Provider ----------------------------
Enclave NOT TRUSTED
+++ PIB: 00000800000f0f02040101070000000000000000000b00000b000000020000000000000bcb2411f1d4e37d6b5cdf21b4613e469239f1c06588b7be7c7ca81bfd312e355224084ee08c6de3c0f4e161110917a447c999f63def657af59768a4e15f74f912cb
+++ sgx_report_attestation_status ret = 0x0000
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;advisoryIDs listed are INTEL-SA-00334,INTEL-SA-00161,INTEL-SA-00219,INTEL-SA-00289&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;As per INTEL-SA-00161 (&amp;nbsp;&lt;A href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00161.html" target="_self"&gt;https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00161.html&lt;/A&gt; ), it was recommended to "update to the latest microcode". But i'm already using the latest microcode yet this is not resolved:&lt;LI-CODE lang="markup"&gt; Name              Version        Architecture   Description
intel-microcode    3.20200609.0ub  amd64         Processor microcode firmware 
                                                 for Intel CPUs​&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;$ dmesg | grep microcode
[    1.855393] microcode: sig=0x806ea, pf=0x80, revision=0xd6
[    1.855580] microcode: Microcode Update Driver: v2.2.​&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;LI&gt;As per&amp;nbsp;INTEL-SA-00219(&amp;nbsp;&lt;A href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00219.html" target="_self"&gt;https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00219.html&lt;/A&gt; ), to avoid this vulnerability "&lt;SPAN&gt;Ensure the latest BIOS from your system provider and Intel SGX platform software (PSW) is installed&lt;/SPAN&gt;". I'm already using the latest BIOS:&amp;nbsp;&lt;LI-CODE lang="markup"&gt;$ sudo dmidecode -s bios-version
1.15.1​&lt;/LI-CODE&gt;The SGX PSW is also installed as per SGX SDK 2.10. Also there is another recommendation "&lt;SPAN&gt;Disable integrated processor graphics where they are not used (usually server).&lt;/SPAN&gt;" I'm not sure about this since i was not able to find any option to disable integrated graphics in bios. Kindly clarify if this is necessary.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;As per&amp;nbsp;INTEL-SA-00289 (&amp;nbsp;&lt;A href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00289.html" target="_blank" rel="noopener"&gt;https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00289.html&lt;/A&gt;&amp;nbsp;), the recommendation was to "&lt;SPAN&gt;update to the latest BIOS version provided by the system manufacturer&lt;/SPAN&gt;" which i've already done.&lt;/LI&gt;
&lt;LI&gt;As per&amp;nbsp;INTEL-SA-00334 (&amp;nbsp;&lt;A href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00334.html" target="_blank" rel="noopener"&gt;https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00334.html&lt;/A&gt;&amp;nbsp;), it was recommended to "&lt;SPAN&gt;Ensure the latest Intel SGX PSW&amp;nbsp;2.9.100.2 or above for Linux is installed&lt;/SPAN&gt;". I've installed the latest SGX PSW as per SGX SDK 2.10.&lt;/LI&gt;
&lt;LI&gt;I've also disabled hyperthreading (HT) as mentioned in one of your docs&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Can you kindly help me troubleshoot the problem?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Bala&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 09:32:20 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Receiving-ISV-Enclave-Trust-Status-as-Enclave-NOT-TRUSTED/m-p/1194041#M3842</guid>
      <dc:creator>k__balaganapathy</dc:creator>
      <dc:date>2020-07-22T09:32:20Z</dc:date>
    </item>
    <item>
      <title>Re:Receiving ISV Enclave Trust Status as Enclave N...</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Receiving-ISV-Enclave-Trust-Status-as-Enclave-NOT-TRUSTED/m-p/1194116#M3843</link>
      <description>&lt;P&gt;Hello Bala,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thanks for the information. We will look into this further and I will update this thread when we have a response from our engineers.&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 22 Jul 2020 16:45:34 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Receiving-ISV-Enclave-Trust-Status-as-Enclave-NOT-TRUSTED/m-p/1194116#M3843</guid>
      <dc:creator>JesusG_Intel</dc:creator>
      <dc:date>2020-07-22T16:45:34Z</dc:date>
    </item>
    <item>
      <title>Re:Receiving ISV Enclave Trust Status as Enclave N...</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Receiving-ISV-Enclave-Trust-Status-as-Enclave-NOT-TRUSTED/m-p/1194130#M3844</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Intel will no longer monitor this thread since this issue has been resolved.&amp;nbsp; If you need any additional information from Intel, please submit a new question.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Hello Bala,&lt;/P&gt;
&lt;P&gt;There are a few things going on here.&lt;/P&gt;
&lt;P&gt;Intel-SA-00334 (Load Value Injection): &lt;A href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00334.html" target="_blank" rel="noopener noreferrer"&gt;https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00334.html&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Please follow these links within the page above:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://cdrdv2.intel.com/v1/dl/getContent/619320" target="_blank" rel="noopener"&gt;https://cdrdv2.intel.com/v1/dl/getContent/619320&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;An attestation response may report “SW_HARDENING_NEEDED” for attestation requests originating from Intel® SGX-enabled platforms that have applied the microcode and SGX platform software update and are properly configured but are affected by INTEL-SA-00334. In this case a Remote Attestation Verifier should evaluate the potential risk of an attack on these platforms and whether the attesting enclave employs adequate software hardening to mitigate the risk.&lt;/P&gt;
&lt;P&gt;• An attestation response may report “CONFIGURATION_NEEDED” or “CONFIGURATION_AND_SW_HARDENING_NEEDED” for attestation requests originating from Intel® SGX-enabled platforms affected by INTEL-SA-00289 that have applied the microcode update, but where the BIOS did not disable the interface the privileged software can cause undervoltage to the processor. The “CONFIGURATION_NEEDED” response implies the platform is not affected by INTEL-SA-00334, while “CONFIGURATION_AND_SW_HARDENING_NEEDED” indicates the platform is affected by INTEL-SA-00334.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://software.intel.com/security-software-guidance/insights/deep-dive-load-value-injection" target="_blank" rel="noopener noreferrer"&gt;https://software.intel.com/security-software-guidance/insights/deep-dive-load-value-injection&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In short, &lt;STRONG&gt;any processor that is affected by LVI will always receive the "SW_HARDENING_REPLY"&lt;/STRONG&gt; even if you build the enclave with the mitigations place. It is up to the service provider/relying party to determine a policy whether to accept the enclave or not if it believes the mitigations have been put in place. In other words, IAS provides this information and the relying party determines what to do with the information.&lt;/P&gt;
&lt;P&gt;The “CONFIGURATION_AND_SW_HARDENING_NEEDED” may come from a combination of SA-00334 and SA-00289 as described above, or from the fact that you can't disable internal Gfx from your BIOS so you will always get "CONFIGURATION_NEEDED."&lt;/P&gt;
&lt;P&gt;Again, this is just info from IAS on what they found. Your policy at the service provider determines whether to trust the enclave or not knowing the above limitations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 17:18:50 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Receiving-ISV-Enclave-Trust-Status-as-Enclave-NOT-TRUSTED/m-p/1194130#M3844</guid>
      <dc:creator>JesusG_Intel</dc:creator>
      <dc:date>2020-07-27T17:18:50Z</dc:date>
    </item>
  </channel>
</rss>

