- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How is the root secret key and PCK secret key generated in DCAP remote authentication,and How are root certificates and PCK certificates generated in DCAP remote authentication?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello enclave_research,
The Introduction and Terminology sections of this paper, Remote Attestation for Multipackage Platforms using Intel SGX DCAP, will shed more light on your questions. This is all the information we have at this moment.
Sincerely,
Jesus G.
Intel Customer Support
Link Copied
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello enclave_Research,
The DCAP Orientation Guide and the Intel SGX PCK Certificate CRL Spec contain all of the information you need.
The basic steps to receive the PCK certs from the Intel Attestation Service are:
- Subscribe at the ECDSA Attestation Service to be able to receive and cache the PCK certs.
- Setup Intel SGX DCAP environment.
- Build and install the Provisioning Certificate Caching Service (PCCS)
- Generate pckid_retrieval.csv
- Run PCKIDRetrievalTool to download and cache the certs into your PCCS.
The QuoteGeneration Sample shows how to get the cert data from the quote.
Sincerely,
Jesus G.
Intel Customer Support
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello!I know how to retrieve the PCK certificate. I want to know where, when and how the Intel root certificate and PCK certificate are generated? Thanks for your answer.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello enclave_research,
This DCAP paper has more technical details on the certs. I am checking with my resources if we can provide more specific information, but that information may not be publicly disclosable.
Sincerely,
Jesus G.
Intel Customer Support
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello enclave_research,
The Introduction and Terminology sections of this paper, Remote Attestation for Multipackage Platforms using Intel SGX DCAP, will shed more light on your questions. This is all the information we have at this moment.
Sincerely,
Jesus G.
Intel Customer Support
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello enclave_research,
Do you still need help with this issue?
Sincerely,
Jesus G.
Intel Customer Support
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page