<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PCS v4 pckcert/pckcerts HTTP 404 — cannot fill PCK cache (TDX attestation blocked) in Intel® Software Guard Extensions (Intel® SGX)</title>
    <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/PCS-v4-pckcert-pckcerts-HTTP-404-cannot-fill-PCK-cache-TDX/m-p/1754534#M6501</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Need help with Intel PCS for TDX attestation.&lt;/P&gt;&lt;P&gt;Host: virtlab2652-grr&lt;BR /&gt;OS: RHEL 9.9&lt;BR /&gt;Local PCCS + QGS are running. PCKIDRetrievalTool can collect platform IDs (no platform manifest / not multi-package).&lt;/P&gt;&lt;P&gt;Works:&lt;BR /&gt;- GET /sgx/certification/v4/pckcrl?ca=processor → HTTP 200&lt;/P&gt;&lt;P&gt;Fails:&lt;BR /&gt;- GET /sgx/certification/v4/pckcert → HTTP 404&lt;BR /&gt;- GET /sgx/certification/v4/pckcerts → HTTP 404&lt;BR /&gt;(empty body; local pckcache stays empty; attestation quote verify blocked)&lt;/P&gt;&lt;P&gt;Request-IDs:&lt;BR /&gt;- pckcert: 0110b3f6130a47a6b7f7f6cd85f55cc0&lt;BR /&gt;- pckcerts: c6a8732a17c7497ab363a850b285f68f&lt;/P&gt;&lt;P&gt;Platform:&lt;BR /&gt;- qeid: 5cea3354ba5b36b4b1ba36ba19f807f9&lt;BR /&gt;- pceid: 0000&lt;BR /&gt;- cpusvn: 07070a0a05ff00020000000000000000&lt;BR /&gt;- pcesvn: 1000&lt;/P&gt;&lt;P&gt;Why is PCK unavailable for this PPID/PCE-ID, and how can we enable pckcerts to return 200?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jul 2026 05:57:46 GMT</pubDate>
    <dc:creator>rahul-kr</dc:creator>
    <dc:date>2026-07-22T05:57:46Z</dc:date>
    <item>
      <title>PCS v4 pckcert/pckcerts HTTP 404 — cannot fill PCK cache (TDX attestation blocked)</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/PCS-v4-pckcert-pckcerts-HTTP-404-cannot-fill-PCK-cache-TDX/m-p/1754534#M6501</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Need help with Intel PCS for TDX attestation.&lt;/P&gt;&lt;P&gt;Host: virtlab2652-grr&lt;BR /&gt;OS: RHEL 9.9&lt;BR /&gt;Local PCCS + QGS are running. PCKIDRetrievalTool can collect platform IDs (no platform manifest / not multi-package).&lt;/P&gt;&lt;P&gt;Works:&lt;BR /&gt;- GET /sgx/certification/v4/pckcrl?ca=processor → HTTP 200&lt;/P&gt;&lt;P&gt;Fails:&lt;BR /&gt;- GET /sgx/certification/v4/pckcert → HTTP 404&lt;BR /&gt;- GET /sgx/certification/v4/pckcerts → HTTP 404&lt;BR /&gt;(empty body; local pckcache stays empty; attestation quote verify blocked)&lt;/P&gt;&lt;P&gt;Request-IDs:&lt;BR /&gt;- pckcert: 0110b3f6130a47a6b7f7f6cd85f55cc0&lt;BR /&gt;- pckcerts: c6a8732a17c7497ab363a850b285f68f&lt;/P&gt;&lt;P&gt;Platform:&lt;BR /&gt;- qeid: 5cea3354ba5b36b4b1ba36ba19f807f9&lt;BR /&gt;- pceid: 0000&lt;BR /&gt;- cpusvn: 07070a0a05ff00020000000000000000&lt;BR /&gt;- pcesvn: 1000&lt;/P&gt;&lt;P&gt;Why is PCK unavailable for this PPID/PCE-ID, and how can we enable pckcerts to return 200?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2026 05:57:46 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/PCS-v4-pckcert-pckcerts-HTTP-404-cannot-fill-PCK-cache-TDX/m-p/1754534#M6501</guid>
      <dc:creator>rahul-kr</dc:creator>
      <dc:date>2026-07-22T05:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: PCS v4 pckcert/pckcerts HTTP 404 — cannot fill PCK cache (TDX attestation blocked)</title>
      <link>https://community.intel.com/t5/Intel-Software-Guard-Extensions/PCS-v4-pckcert-pckcerts-HTTP-404-cannot-fill-PCK-cache-TDX/m-p/1754751#M6502</link>
      <description>&lt;P&gt;What CPU model are you running?&amp;nbsp; If you're trying to use TDX, it has to be a Xeon Scalable, and all Xeon Scalables have to be registered with our Intel Registration Service, even if you're only running a single CPU.&amp;nbsp; So, you will need to get the platform manifest.&amp;nbsp; To get the platform to generate new platform keys and a new platform manifest, you'll need to do an "SGX Factory Reset" in the BIOS and then again use the &lt;SPAN&gt;PCKIDRetrievalTool to get the platform manifest and use it to register the platform.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;More info on platform registration can be found in our TDX Enabling Guide &lt;A href="https://cc-enabling.trustedservices.intel.com/intel-tdx-enabling-guide/02/infrastructure_setup/#platform-registration" target="_self"&gt;here&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 00:06:11 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-Software-Guard-Extensions/PCS-v4-pckcert-pckcerts-HTTP-404-cannot-fill-PCK-cache-TDX/m-p/1754751#M6502</guid>
      <dc:creator>Scott_R_Intel</dc:creator>
      <dc:date>2026-07-24T00:06:11Z</dc:date>
    </item>
  </channel>
</rss>

