<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re:Does sgx support certificate-based remote authentication? in Intel® Software Guard Extensions (Intel® SGX)</title>
    <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Does-sgx-support-certificate-based-remote-authentication/m-p/1256592#M4322</link>
    <description>&lt;P&gt;&lt;B&gt;This thread has been marked as answered and Intel will no longer monitor this thread. If you want a response from Intel in a follow-up question, please open a new thread.&lt;/B&gt;&lt;/P&gt;&lt;BR /&gt;</description>
    <pubDate>Tue, 16 Feb 2021 23:38:27 GMT</pubDate>
    <dc:creator>JesusG_Intel</dc:creator>
    <dc:date>2021-02-16T23:38:27Z</dc:date>
    <item>
      <title>Does sgx support certificate-based remote authentication?</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Does-sgx-support-certificate-based-remote-authentication/m-p/1253517#M4289</link>
      <description>&lt;P&gt;&amp;nbsp; &amp;nbsp; I &lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b" data-language-for-alternatives="en" data-language-to-translate-into="zh-CN" data-phrase-index="0"&gt;&lt;SPAN&gt;recently started learning SGX technology&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;and if&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b" data-language-for-alternatives="en" data-language-to-translate-into="zh-CN" data-phrase-index="0"&gt;&lt;SPAN&gt;&amp;nbsp;I understand correctly,&amp;nbsp;SGX supports&amp;nbsp;EPID-based remote authentication.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b" data-language-for-alternatives="en" data-language-to-translate-into="zh-CN" data-phrase-index="0"&gt;&lt;SPAN&gt;I wonder whether SGX supports certificate-based authentication, such as the X509 specification of the PKI standard.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b" data-language-for-alternatives="en" data-language-to-translate-into="zh-CN" data-phrase-index="0"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; Because I want SGX to attest ARM TrustZone, if SGX supports certificate-based authentication, then I think it is possible to implement remote authentication between SGX and ARM TrustZone.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 15:02:18 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Does-sgx-support-certificate-based-remote-authentication/m-p/1253517#M4289</guid>
      <dc:creator>Clinale</dc:creator>
      <dc:date>2021-02-05T15:02:18Z</dc:date>
    </item>
    <item>
      <title>Re:Does sgx support certificate-based remote authentication?</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Does-sgx-support-certificate-based-remote-authentication/m-p/1253564#M4293</link>
      <description>&lt;P&gt;Hello Clinale,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The Intel Attestation Service (IAS), or remote attestation service, attests clients that run Intel SGX and cannot be used to attest clients that run ARM TrustZone. The remote attestastion service does not run SGX. Servers and other clients that run SGX use the IAS to prove to service providers that the SGX enclave's:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Its identity&lt;/LI&gt;&lt;LI&gt;That it has not been tampered with&lt;/LI&gt;&lt;LI&gt;That it is running on a genuine platform with Intel SGX enabled&lt;/LI&gt;&lt;LI&gt;That it is running at the latest security level, also referred to as the Trusted Computing Base (TCB) level&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I highly recommend you read the &lt;A href="https://software.intel.com/content/www/us/en/develop/articles/code-sample-intel-software-guard-extensions-remote-attestation-end-to-end-example.html" rel="noopener noreferrer" target="_blank"&gt;Remote Attestation End-to-End Example&lt;/A&gt; for more details.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;Jesus G.&lt;/P&gt;&lt;P&gt;Intel Customer Support&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 05 Feb 2021 18:35:51 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Does-sgx-support-certificate-based-remote-authentication/m-p/1253564#M4293</guid>
      <dc:creator>JesusG_Intel</dc:creator>
      <dc:date>2021-02-05T18:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: Re:Does sgx support certificate-based remote authentication?</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Does-sgx-support-certificate-based-remote-authentication/m-p/1253650#M4297</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;JesusG_Intel,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for your information, and I browsed the web link you posted.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I noticed a sentence mentioning that SGX supports certificate-based attestation.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Clinale_0-1612579668433.png" style="width: 999px;"&gt;&lt;img src="https://community.intel.com/t5/image/serverpage/image-id/15138iCDD5A4931EEB0E0E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999&amp;amp;whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright" role="button" title="Clinale_0-1612579668433.png" alt="Clinale_0-1612579668433.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I wonder what certificate-based authentication means. Does it mean that SGX support authenticate-based authentication, like PKI X509? If it does, will SGX always support certificate-based authentication?&lt;/P&gt;
&lt;P&gt;Thanks for your reply.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Feb 2021 03:05:18 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Does-sgx-support-certificate-based-remote-authentication/m-p/1253650#M4297</guid>
      <dc:creator>Clinale</dc:creator>
      <dc:date>2021-02-06T03:05:18Z</dc:date>
    </item>
    <item>
      <title>Re:Does sgx support certificate-based remote authentication?</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Does-sgx-support-certificate-based-remote-authentication/m-p/1254139#M4302</link>
      <description>&lt;P&gt;Hello Clinale,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Intel &lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;, sans-serif; font-size: 11pt;"&gt;no longer on-boards new customers using the old cert-based authentication.&amp;nbsp;It’s only there for legacy IAS customers and will soon be EOL’d.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The old, cert-based authentication &lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;, sans-serif; font-size: 11pt;"&gt;was simply a mutual TLS authentication mechanism.&amp;nbsp;The customer had to purchase an x.509 client cert from a publicly recognized cert authority (ie. Thawte, DigiCert, etc) just like you would for a secure web site.&amp;nbsp;Intel would use that cert to authenticate them when they connected to IAS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;, sans-serif; font-size: 11pt;"&gt;Sincerely,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;, sans-serif; font-size: 11pt;"&gt;Jesus G.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: &amp;quot;Calibri&amp;quot;, sans-serif; font-size: 11pt;"&gt;Intel Customer Support&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 08 Feb 2021 19:03:00 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Does-sgx-support-certificate-based-remote-authentication/m-p/1254139#M4302</guid>
      <dc:creator>JesusG_Intel</dc:creator>
      <dc:date>2021-02-08T19:03:00Z</dc:date>
    </item>
    <item>
      <title>Re:Does sgx support certificate-based remote authentication?</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Does-sgx-support-certificate-based-remote-authentication/m-p/1256592#M4322</link>
      <description>&lt;P&gt;&lt;B&gt;This thread has been marked as answered and Intel will no longer monitor this thread. If you want a response from Intel in a follow-up question, please open a new thread.&lt;/B&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 16 Feb 2021 23:38:27 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Does-sgx-support-certificate-based-remote-authentication/m-p/1256592#M4322</guid>
      <dc:creator>JesusG_Intel</dc:creator>
      <dc:date>2021-02-16T23:38:27Z</dc:date>
    </item>
  </channel>
</rss>

