<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intel SGX TCB Signing Certificate Expiry on May 21, 2025 – When Will It Be Updated? in Intel® Software Guard Extensions (Intel® SGX)</title>
    <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-TCB-Signing-Certificate-Expiry-on-May-21-2025-When/m-p/1687874#M6366</link>
    <description>&lt;P&gt;Dear&amp;nbsp;&lt;SPAN&gt;Jun Kimura,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;a new certificate was issued today. Could you check and confirm that everything works on your end?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;BR /&gt;Benny&lt;/P&gt;</description>
    <pubDate>Tue, 06 May 2025 15:49:26 GMT</pubDate>
    <dc:creator>Benny_Intel</dc:creator>
    <dc:date>2025-05-06T15:49:26Z</dc:date>
    <item>
      <title>Intel SGX TCB Signing Certificate Expiry on May 21, 2025 – When Will It Be Updated?</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-TCB-Signing-Certificate-Expiry-on-May-21-2025-When/m-p/1687273#M6365</link>
      <description>&lt;P&gt;Dear Intel SGX &amp;amp; TDX Services Team,&lt;/P&gt;&lt;P&gt;We are using the Intel PCS's&amp;nbsp; "Get SGX/TDX TCB Info API" (&lt;A href="https://api.trustedservices.intel.com/tdx/certification/v4/tcb" target="_blank"&gt;https://api.trustedservices.intel.com/tdx/certification/v4/tcb&lt;/A&gt;) and noticed that the TCB signing certificate is about to expire:&lt;/P&gt;&lt;LI-CODE lang="none"&gt;    Data:
        Version: 3 (0x2)
        Serial Number:
            7e:38:82:d5:fb:55:29:4a:40:49:8e:45:84:03:e9:14:91:bd:f4:55
        Signature Algorithm: ecdsa-with-SHA256
        Issuer: CN = Intel SGX Root CA, O = Intel Corporation, L = Santa Clara, ST = CA, C = US
        Validity
            Not Before: May 21 10:50:10 2018 GMT
            Not After : May 21 10:50:10 2025 GMT
        Subject: CN = Intel SGX TCB Signing, O = Intel Corporation, L = Santa Clara, ST = CA, C = US&lt;/LI-CODE&gt;&lt;P&gt;Will an updated TCB signing certificate be issued before May 21, 2025? Could you please share any information on the planned update for this certificate?&lt;/P&gt;&lt;P&gt;In our remote attestation system, we strictly manage the validity period of all collateral, so it is important that the latest collateral is always available and valid.&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;Best regards,&lt;BR /&gt;Jun Kimura&lt;/P&gt;&lt;P&gt;Datachain, Inc.&lt;/P&gt;</description>
      <pubDate>Sun, 04 May 2025 03:30:35 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-TCB-Signing-Certificate-Expiry-on-May-21-2025-When/m-p/1687273#M6365</guid>
      <dc:creator>jun_kimura_dc</dc:creator>
      <dc:date>2025-05-04T03:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Intel SGX TCB Signing Certificate Expiry on May 21, 2025 – When Will It Be Updated?</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-TCB-Signing-Certificate-Expiry-on-May-21-2025-When/m-p/1687874#M6366</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;SPAN&gt;Jun Kimura,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;a new certificate was issued today. Could you check and confirm that everything works on your end?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;BR /&gt;Benny&lt;/P&gt;</description>
      <pubDate>Tue, 06 May 2025 15:49:26 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-TCB-Signing-Certificate-Expiry-on-May-21-2025-When/m-p/1687874#M6366</guid>
      <dc:creator>Benny_Intel</dc:creator>
      <dc:date>2025-05-06T15:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: Intel SGX TCB Signing Certificate Expiry on May 21, 2025 – When Will It Be Updated?</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-TCB-Signing-Certificate-Expiry-on-May-21-2025-When/m-p/1688029#M6368</link>
      <description>&lt;P class=""&gt;Dear Benny,&lt;/P&gt;&lt;P class=""&gt;Thank you for the prompt update.&lt;/P&gt;&lt;P class=""&gt;We have confirmed that the new certificate has been successfully issued, and our service continues to function as expected. We appreciate your support.&lt;/P&gt;&lt;P class=""&gt;I’d also like to ask a follow-up question regarding certificate expiration policy. According to&amp;nbsp;&lt;SPAN&gt;the&amp;nbsp;&lt;A href="https://cc-enabling.trustedservices.intel.com/intel-tdx-enabling-guide/02/infrastructure_setup/#collateral-caching-service" target="_blank" rel="noopener"&gt;TDX Enabling Guide&lt;/A&gt;&lt;/SPAN&gt;, DCAP collateral (such as TCBInfo and QE Identity) is expected to have a 30-day validity period from the time of download, and should be refreshed accordingly.&lt;/P&gt;&lt;P class=""&gt;Does this 30-day validity period expectation also apply to certificates (e.g. the TCB signing certificate), or are they managed under a separate policy?&amp;nbsp; In addition, if the expiration date of the TCB signing certificate is earlier than the nextUpdate field of the corresponding TCBInfo, which one should be considered the effective expiration date?&lt;/P&gt;&lt;P class=""&gt;If there is a documented policy or best practice for handling impending certificate expirations, we would greatly appreciate it if you could share it.&lt;/P&gt;&lt;P class=""&gt;Thank you again for your assistance.&lt;/P&gt;&lt;P class=""&gt;Best regards,&lt;BR /&gt;Jun Kimura&lt;/P&gt;</description>
      <pubDate>Wed, 07 May 2025 04:33:22 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Intel-SGX-TCB-Signing-Certificate-Expiry-on-May-21-2025-When/m-p/1688029#M6368</guid>
      <dc:creator>jun_kimura_dc</dc:creator>
      <dc:date>2025-05-07T04:33:22Z</dc:date>
    </item>
  </channel>
</rss>

