<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Platform Manifest being rejected by api server in Intel® Software Guard Extensions (Intel® SGX)</title>
    <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Platform-Manifest-being-rejected-by-api-server/m-p/1735120#M6476</link>
    <description>&lt;PRE&gt;I'm currently trying to get a basic TDX attestation to work. To that
effect I'm following the guide at &lt;A class="" href="https://cc" target="_blank" rel="noopener"&gt;https://cc&lt;/A&gt;-
enabling.trustedservices.intel.com/intel-tdx-enabling-guide/02/
infrastructure_setup/#platform-registration

What I've gathered up until now is that in order to get the QGS working
I'd need to get collateral from Intel. So essentially I'm trying to
obtain the PCK. It should be as simple as running PCKIDRetrievalTool and
then making the respective API call as per https://
api.portal.trustedservices.intel.com/content/documentation.html#pcs-
certificate-v4

Unfortunately as I'm doing this I'm receiving the following error from
Intel's API service:

&amp;nbsp;&amp;lt; HTTP/1.1 400 Bad Request
&amp;lt; Content-Length: 0
&amp;lt; Request-ID: 041fa7d2fbb54d48aad51702d2f5000a
&amp;lt; Error-Code: PackageNotFound
&amp;lt; Error-Message: The request was rejected by the server as at least one
of the processor packages could not be recognized by the server.
&amp;lt; Date: Wed, 28 Jan 2026 18:31:10 GMT


I've tried the request with platform manifest generated on 2 separate
machines:

processor&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0
vendor_id&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : GenuineIntel
cpu family&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 6
model&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 207
model name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : INTEL(R) XEON(R) PLATINUM 8592+
stepping&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 2


and

processor&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0
vendor_id&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : GenuineIntel
cpu family&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 6
model&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 173
model name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Intel(R) Xeon(R) 6972P
stepping&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1


and I get the same error. The call I'm doing is a POST to https://
api.trustedservices.intel.com/sgx/certification/v4/pckcert

As per the API docs it should be possible to obtain a PCK with a
platform manifest and&amp;nbsp; SVNs i.e without first registering the platform
manifest via the Register Platform API&lt;/PRE&gt;</description>
    <pubDate>Wed, 28 Jan 2026 21:10:25 GMT</pubDate>
    <dc:creator>doskias</dc:creator>
    <dc:date>2026-01-28T21:10:25Z</dc:date>
    <item>
      <title>Platform Manifest being rejected by api server</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Platform-Manifest-being-rejected-by-api-server/m-p/1735120#M6476</link>
      <description>&lt;PRE&gt;I'm currently trying to get a basic TDX attestation to work. To that
effect I'm following the guide at &lt;A class="" href="https://cc" target="_blank" rel="noopener"&gt;https://cc&lt;/A&gt;-
enabling.trustedservices.intel.com/intel-tdx-enabling-guide/02/
infrastructure_setup/#platform-registration

What I've gathered up until now is that in order to get the QGS working
I'd need to get collateral from Intel. So essentially I'm trying to
obtain the PCK. It should be as simple as running PCKIDRetrievalTool and
then making the respective API call as per https://
api.portal.trustedservices.intel.com/content/documentation.html#pcs-
certificate-v4

Unfortunately as I'm doing this I'm receiving the following error from
Intel's API service:

&amp;nbsp;&amp;lt; HTTP/1.1 400 Bad Request
&amp;lt; Content-Length: 0
&amp;lt; Request-ID: 041fa7d2fbb54d48aad51702d2f5000a
&amp;lt; Error-Code: PackageNotFound
&amp;lt; Error-Message: The request was rejected by the server as at least one
of the processor packages could not be recognized by the server.
&amp;lt; Date: Wed, 28 Jan 2026 18:31:10 GMT


I've tried the request with platform manifest generated on 2 separate
machines:

processor&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0
vendor_id&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : GenuineIntel
cpu family&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 6
model&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 207
model name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : INTEL(R) XEON(R) PLATINUM 8592+
stepping&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 2


and

processor&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0
vendor_id&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : GenuineIntel
cpu family&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 6
model&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 173
model name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Intel(R) Xeon(R) 6972P
stepping&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1


and I get the same error. The call I'm doing is a POST to https://
api.trustedservices.intel.com/sgx/certification/v4/pckcert

As per the API docs it should be possible to obtain a PCK with a
platform manifest and&amp;nbsp; SVNs i.e without first registering the platform
manifest via the Register Platform API&lt;/PRE&gt;</description>
      <pubDate>Wed, 28 Jan 2026 21:10:25 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Platform-Manifest-being-rejected-by-api-server/m-p/1735120#M6476</guid>
      <dc:creator>doskias</dc:creator>
      <dc:date>2026-01-28T21:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: Platform Manifest being rejected by api server</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Platform-Manifest-being-rejected-by-api-server/m-p/1735135#M6477</link>
      <description>&lt;P&gt;Hello doskias.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please run through the Troubleshooting steps in the TDX Enabling Guide and provide the results?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://cc-enabling.trustedservices.intel.com/intel-tdx-enabling-guide/02/infrastructure_setup/#troubleshooting" target="_blank"&gt;https://cc-enabling.trustedservices.intel.com/intel-tdx-enabling-guide/02/infrastructure_setup/#troubleshooting&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Scott&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jan 2026 22:29:47 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Platform-Manifest-being-rejected-by-api-server/m-p/1735135#M6477</guid>
      <dc:creator>Scott_R_Intel</dc:creator>
      <dc:date>2026-01-28T22:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: Platform Manifest being rejected by api server</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Platform-Manifest-being-rejected-by-api-server/m-p/1735196#M6478</link>
      <description>&lt;P&gt;So the issue was that I had a pre-production CPU. Using the sbx.api endpoint I'm now getting :&lt;/P&gt;&lt;P&gt;{ "statusCode": 401, "message": "Access denied due to invalid subscription key. Make sure to provide a valid key for an active subscription." }&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Despite sending the subscription key for "&lt;SPAN&gt;Product Intel® Software Guard Extensions Provisioning Certification Service subscription" in the&amp;nbsp;&lt;/SPAN&gt;Ocp-Apim-Subscription-Key header:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Connected to sbx.api.trustedservices.intel.com (4.255.73.206) port 443&lt;BR /&gt;* using HTTP/1.x&lt;BR /&gt;&amp;gt; POST /sgx/certification/v4/pckcert HTTP/1.1&lt;BR /&gt;&amp;gt; Host: sbx.api.trustedservices.intel.com&lt;BR /&gt;&amp;gt; User-Agent: curl/8.14.1&lt;BR /&gt;&amp;gt; Accept: */*&lt;BR /&gt;&amp;gt; Content-Type: application/json&lt;BR /&gt;&amp;gt; Ocp-Apim-Subscription-Key: 1bc*******************&lt;BR /&gt;&amp;gt; Content-Length: 35998&lt;BR /&gt;&amp;gt;&lt;BR /&gt;* upload completely sent off: 35998 bytes&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):&lt;BR /&gt;&amp;lt; HTTP/1.1 401 Access Denied&lt;BR /&gt;&amp;lt; Content-Length: 143&lt;BR /&gt;&amp;lt; Content-Type: application/json&lt;BR /&gt;&amp;lt; WWW-Authenticate: AzureApiManagementKey realm="&lt;A href="https://sbx.api.trustedservices.intel.com/sgx/certification/v4/pckcert" target="_blank"&gt;https://sbx.api.trustedservices.intel.com/sgx/certification/v4/pckcert&lt;/A&gt;",name="Ocp-Apim-Subscription-Key",type="header"&lt;BR /&gt;&amp;lt; Date: Thu, 29 Jan 2026 07:02:38 GMT&lt;BR /&gt;&amp;lt;&lt;BR /&gt;* Connection #0 to host sbx.api.trustedservices.intel.com left intact&lt;BR /&gt;{ "statusCode": 401, "message": "Access denied due to invalid subscription key. Make sure to provide a valid key for an active subscription." }&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried both the primary and secondary key and even without a key but I get the same error? On a different note, I believe there is an error in the API documentation for the&amp;nbsp;&lt;A href="https://api.trustedservices.intel.com/sgx/certification/v4/pckcert" target="_blank"&gt;https://api.trustedservices.intel.com/sgx/certification/v4/pckcert&lt;/A&gt;&amp;nbsp;since the Ocp-Apim_subscription-Key header is documented as not being required/mandatory, isn't it always required when using this API?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 07:10:33 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Platform-Manifest-being-rejected-by-api-server/m-p/1735196#M6478</guid>
      <dc:creator>doskias</dc:creator>
      <dc:date>2026-01-29T07:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: Platform Manifest being rejected by api server</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Platform-Manifest-being-rejected-by-api-server/m-p/1736156#M6481</link>
      <description>&lt;P&gt;FWIW I think this is a problem with the &lt;STRONG&gt;sbx.api&lt;/STRONG&gt; endpoint, because I'm able to get a certificate from &lt;STRONG&gt;api&lt;/STRONG&gt;&amp;nbsp;when using a production CPU, even without providing an API key.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 12:36:32 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/Platform-Manifest-being-rejected-by-api-server/m-p/1736156#M6481</guid>
      <dc:creator>doskias</dc:creator>
      <dc:date>2026-02-06T12:36:32Z</dc:date>
    </item>
  </channel>
</rss>

