<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SGX EGETKEY clarification? in Intel Confidential Computing</title>
    <link>https://community.intel.com/t5/Intel-Confidential-Computing/SGX-EGETKEY-clarification/m-p/1731057#M6475</link>
    <description>&lt;P&gt;great info!&lt;/P&gt;</description>
    <pubDate>Mon, 22 Dec 2025 09:26:45 GMT</pubDate>
    <dc:creator>lilii98</dc:creator>
    <dc:date>2025-12-22T09:26:45Z</dc:date>
    <item>
      <title>SGX EGETKEY clarification?</title>
      <link>https://community.intel.com/t5/Intel-Confidential-Computing/SGX-EGETKEY-clarification/m-p/1035752#M14</link>
      <description>&lt;P&gt;&lt;SPAN style="color: rgb(33, 33, 33); font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13.1999998092651px; line-height: 19.7999992370605px;"&gt;I've been looking at a variety of things with&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="lG" style="color: rgb(33, 33, 33); font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13.1999998092651px; line-height: 19.7999992370605px; background-color: rgba(251, 246, 167, 0.498039);"&gt;SGX&lt;/SPAN&gt;&lt;SPAN style="color: rgb(33, 33, 33); font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13.1999998092651px; line-height: 19.7999992370605px;"&gt;, and while looking into the EGETKEY description, I think I've found an inconsistency in the October 2014 spec. Specifically:&lt;/SPAN&gt;&lt;/P&gt;

&lt;OL&gt;
	&lt;LI style="color: rgb(33, 33, 33); font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13.1999998092651px; line-height: 19.7999992370605px;"&gt;&lt;SPAN style="font-size: 13.1999998092651px; line-height: 19.7999992370605px;"&gt;Table 5-43 says that the Provisioning Key and the Provisioning Seal Key both derive from the owner epoch; however, the algorithmic description of both says that the owner epoch is 0 for derivation purposes.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-size: 13.1999998092651px; line-height: 19.7999992370605px;"&gt;White papers on provisioning make it sound like the owner epoch can be changed to make provisioned secrets inaccessible, so I expected the owner epoch to be used, at least for the provisioning seal key (which is sealed to the fuses in the machine). I could see it not being used for the provisioning key, however, since that's not dependent on the machine itself. Is there an errata for the document that clarifies this?&lt;/SPAN&gt;&lt;/LI&gt;
	&lt;LI style="color: rgb(33, 33, 33); font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13.1999998092651px; line-height: 19.7999992370605px;"&gt;&lt;SPAN style="font-size: 13.1999998092651px; line-height: 19.7999992370605px;"&gt;&lt;SPAN style="font-size: 13.1999998092651px; line-height: 19.7999992370605px;"&gt;For clarify, it might help to add to table 5-43 that the provisioning key isn't derived from the fuses but the provisioning seal key is, since this seems to be the main difference between them.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;DIV style="color: rgb(33, 33, 33); font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 13.1999998092651px; line-height: 19.7999992370605px;"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 11 Jun 2015 16:52:09 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Confidential-Computing/SGX-EGETKEY-clarification/m-p/1035752#M14</guid>
      <dc:creator>Patrick_B_2</dc:creator>
      <dc:date>2015-06-11T16:52:09Z</dc:date>
    </item>
    <item>
      <title>Thank you for your diligence.</title>
      <link>https://community.intel.com/t5/Intel-Confidential-Computing/SGX-EGETKEY-clarification/m-p/1035753#M15</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 1em; line-height: 1.5;"&gt;Thank you for your diligence. You are correct this is an inconsistency in the document. The instruction algorithm is correct and table is incorrect wrt to the treatment of the ownerepoch field in the derivation of the Provisioning Key. We will look to correct this in a future publication.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2015 18:12:02 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Confidential-Computing/SGX-EGETKEY-clarification/m-p/1035753#M15</guid>
      <dc:creator>Simon_J_Intel</dc:creator>
      <dc:date>2015-08-17T18:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: SGX EGETKEY clarification?</title>
      <link>https://community.intel.com/t5/Intel-Confidential-Computing/SGX-EGETKEY-clarification/m-p/1731057#M6475</link>
      <description>&lt;P&gt;great info!&lt;/P&gt;</description>
      <pubDate>Mon, 22 Dec 2025 09:26:45 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Confidential-Computing/SGX-EGETKEY-clarification/m-p/1731057#M6475</guid>
      <dc:creator>lilii98</dc:creator>
      <dc:date>2025-12-22T09:26:45Z</dc:date>
    </item>
  </channel>
</rss>

