<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Intel SGX Exception AttestationError { message: &amp;quot;(endorsements -&amp;gt; CrlPckCert) [WRONG_TAG] [NESTED_AS in Intel® Software Guard Extensions (Intel® SGX)</title>
    <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Exception-AttestationError-message-quot-endorsements/m-p/1652813#M6288</link>
    <description>&lt;P&gt;I am seeing the following error in my program:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;failure to attest remote SGX enclave code: AttestationError { message: "(endorsements -&amp;gt; CrlPckCert) [WRONG_TAG] [NESTED_ASN1_ERROR]" }&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at java.base/java.util.concurrent.CompletableFuture.encodeThrowable(CompletableFuture.java:315)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at java.base/java.util.concurrent.CompletableFuture.completeThrowable(CompletableFuture.java:320)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at java.base/java.util.concurrent.CompletableFuture$AsyncRun.run(CompletableFuture.java:1807)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at io.micrometer.core.instrument.composite.CompositeTimer.record(CompositeTimer.java:141)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at io.micrometer.core.instrument.Timer.lambda$wrap$0(Timer.java:196)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1144)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at java.base/java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:642)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at java.base/java.lang.Thread.run(Thread.java:1583)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Caused by: org.signal.libsignal.cds2.DcapException: failure to attest remote SGX enclave code: AttestationError { message: "(endorsements -&amp;gt; CrlPckCert) [WRONG_TAG] [NESTED_ASN1_ERROR]" }&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at org.signal.libsignal.internal.Native.Cds2Metrics_extract(Native Method)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at org.signal.libsignal.cds2.Cds2Metrics.extract(Cds2Metrics.java:31)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at org.signal.cdsi.enclave.Enclave.publishAttestationMetrics(Enclave.java:216)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at org.signal.cdsi.enclave.Enclave.lambda$renewAttestation$3(Enclave.java:192)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at io.micrometer.core.instrument.composite.CompositeTimer.record(CompositeTimer.java:141)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at org.signal.cdsi.enclave.Enclave.lambda$runAsync$18(Enclave.java:440)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at java.base/java.util.concurrent.CompletableFuture$AsyncRun.run(CompletableFuture.java:1804)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;... 5 common frames omitted&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;In syslog for aesmd, I am seeing the following:&lt;BR /&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Dec 28 12:34:21 accvm aesm_service[1921]: [QCNL] JSON config file /etc/sgx_default_qcnl.conf is loaded successfully.&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Dec 28 12:34:21 accvm aesm_service[1921]: [QCNL] Getting pck certificate and chain.&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Dec 28 12:34:21 accvm aesm_service[1921]: [QCNL] Request URL &lt;A href="http://169.254.169.254/metadata/THIM/sgx/certification/v4/pckcert?qeid=6AAC784AB26930F2EC6337359CB0A28D&amp;amp;encrypted_ppid=00000000000000000" target="_blank" rel="noopener"&gt;http://169.254.169.254/metadata/THIM/sgx/certification/v4/pckcert?qeid=6AAC784AB26930F2EC6337359CB0A28D&amp;amp;encrypted_ppid=00000000000000000&lt;/A&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;I&gt;&amp;gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Dec 28 12:34:21 accvm aesm_service[1921]: [QCNL] HTTP status code: 200&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Dec 28 12:34:21 accvm aesm_service[1921]: [QCNL] Successfully fetched certificate from primary URL: '&lt;A href="http://169.254.169.254/metadata/THIM/sgx/certification/v4/" target="_blank" rel="noopener"&gt;http://169.254.169.254/metadata/THIM/sgx/certification/v4/&lt;/A&gt;'.&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Dec 28 12:34:21 accvm aesm_service[1921]: [QCNL] Header 'sgx-tcbm' not found.&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Dec 28 12:34:21 accvm aesm_service[1921]: [QCNL] Header 'sgx-pck-certificate-issuer-chain' not found.&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Dec 28 12:34:21 accvm aesm_service[1921]: [QCNL] sgx-Tcbm: 0e0e0303ffff010000000000000000000D00&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;What are the header not found issues?&amp;nbsp; Any assistance is greatly appreciated.&amp;nbsp; Thanks!&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 28 Dec 2024 12:38:26 GMT</pubDate>
    <dc:creator>jgnoonan</dc:creator>
    <dc:date>2024-12-28T12:38:26Z</dc:date>
    <item>
      <title>Intel SGX Exception AttestationError { message: "(endorsements -&gt; CrlPckCert) [WRONG_TAG] [NESTED_AS</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Exception-AttestationError-message-quot-endorsements/m-p/1652813#M6288</link>
      <description>&lt;P&gt;I am seeing the following error in my program:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;failure to attest remote SGX enclave code: AttestationError { message: "(endorsements -&amp;gt; CrlPckCert) [WRONG_TAG] [NESTED_ASN1_ERROR]" }&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at java.base/java.util.concurrent.CompletableFuture.encodeThrowable(CompletableFuture.java:315)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at java.base/java.util.concurrent.CompletableFuture.completeThrowable(CompletableFuture.java:320)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at java.base/java.util.concurrent.CompletableFuture$AsyncRun.run(CompletableFuture.java:1807)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at io.micrometer.core.instrument.composite.CompositeTimer.record(CompositeTimer.java:141)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at io.micrometer.core.instrument.Timer.lambda$wrap$0(Timer.java:196)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1144)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at java.base/java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:642)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at java.base/java.lang.Thread.run(Thread.java:1583)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Caused by: org.signal.libsignal.cds2.DcapException: failure to attest remote SGX enclave code: AttestationError { message: "(endorsements -&amp;gt; CrlPckCert) [WRONG_TAG] [NESTED_ASN1_ERROR]" }&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at org.signal.libsignal.internal.Native.Cds2Metrics_extract(Native Method)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at org.signal.libsignal.cds2.Cds2Metrics.extract(Cds2Metrics.java:31)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at org.signal.cdsi.enclave.Enclave.publishAttestationMetrics(Enclave.java:216)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at org.signal.cdsi.enclave.Enclave.lambda$renewAttestation$3(Enclave.java:192)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at io.micrometer.core.instrument.composite.CompositeTimer.record(CompositeTimer.java:141)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at org.signal.cdsi.enclave.Enclave.lambda$runAsync$18(Enclave.java:440)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;at java.base/java.util.concurrent.CompletableFuture$AsyncRun.run(CompletableFuture.java:1804)&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;... 5 common frames omitted&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;In syslog for aesmd, I am seeing the following:&lt;BR /&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Dec 28 12:34:21 accvm aesm_service[1921]: [QCNL] JSON config file /etc/sgx_default_qcnl.conf is loaded successfully.&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Dec 28 12:34:21 accvm aesm_service[1921]: [QCNL] Getting pck certificate and chain.&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Dec 28 12:34:21 accvm aesm_service[1921]: [QCNL] Request URL &lt;A href="http://169.254.169.254/metadata/THIM/sgx/certification/v4/pckcert?qeid=6AAC784AB26930F2EC6337359CB0A28D&amp;amp;encrypted_ppid=00000000000000000" target="_blank" rel="noopener"&gt;http://169.254.169.254/metadata/THIM/sgx/certification/v4/pckcert?qeid=6AAC784AB26930F2EC6337359CB0A28D&amp;amp;encrypted_ppid=00000000000000000&lt;/A&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;I&gt;&amp;gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Dec 28 12:34:21 accvm aesm_service[1921]: [QCNL] HTTP status code: 200&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Dec 28 12:34:21 accvm aesm_service[1921]: [QCNL] Successfully fetched certificate from primary URL: '&lt;A href="http://169.254.169.254/metadata/THIM/sgx/certification/v4/" target="_blank" rel="noopener"&gt;http://169.254.169.254/metadata/THIM/sgx/certification/v4/&lt;/A&gt;'.&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Dec 28 12:34:21 accvm aesm_service[1921]: [QCNL] Header 'sgx-tcbm' not found.&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Dec 28 12:34:21 accvm aesm_service[1921]: [QCNL] Header 'sgx-pck-certificate-issuer-chain' not found.&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;Dec 28 12:34:21 accvm aesm_service[1921]: [QCNL] sgx-Tcbm: 0e0e0303ffff010000000000000000000D00&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;What are the header not found issues?&amp;nbsp; Any assistance is greatly appreciated.&amp;nbsp; Thanks!&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;I&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Dec 2024 12:38:26 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Exception-AttestationError-message-quot-endorsements/m-p/1652813#M6288</guid>
      <dc:creator>jgnoonan</dc:creator>
      <dc:date>2024-12-28T12:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: Intel SGX Exception AttestationError { message: "(endorsements -&gt; CrlPckCert) [WRONG_TAG</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Exception-AttestationError-message-quot-endorsements/m-p/1653098#M6289</link>
      <description>&lt;P&gt;it's looks like you are using az-dcap-client instead of&amp;nbsp;&lt;SPAN class=""&gt;libsgx-dcap-default-qpl&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I have similar problem with it, so I'm using&amp;nbsp;libsgx-dcap-default-qpl, but having different error&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2024 09:02:14 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Exception-AttestationError-message-quot-endorsements/m-p/1653098#M6289</guid>
      <dc:creator>Roman888</dc:creator>
      <dc:date>2024-12-30T09:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: Intel SGX Exception AttestationError { message: "(endorsements -&gt; CrlPckCert) [WRONG_TAG</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Exception-AttestationError-message-quot-endorsements/m-p/1653109#M6290</link>
      <description>&lt;P&gt;So I removed the az-dcap library and reinstalled the intel sqx qpl.&amp;nbsp; I got an error because it couldn't find the library so I created a symbolic link to the library and everything works fine now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2024 11:48:58 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-Exception-AttestationError-message-quot-endorsements/m-p/1653109#M6290</guid>
      <dc:creator>jgnoonan</dc:creator>
      <dc:date>2024-12-30T11:48:58Z</dc:date>
    </item>
  </channel>
</rss>

