- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dear Intel SGX & TDX Services Team,
We are using the Intel PCS's "Get SGX/TDX TCB Info API" (https://api.trustedservices.intel.com/tdx/certification/v4/tcb) and noticed that the TCB signing certificate is about to expire:
Data:
Version: 3 (0x2)
Serial Number:
7e:38:82:d5:fb:55:29:4a:40:49:8e:45:84:03:e9:14:91:bd:f4:55
Signature Algorithm: ecdsa-with-SHA256
Issuer: CN = Intel SGX Root CA, O = Intel Corporation, L = Santa Clara, ST = CA, C = US
Validity
Not Before: May 21 10:50:10 2018 GMT
Not After : May 21 10:50:10 2025 GMT
Subject: CN = Intel SGX TCB Signing, O = Intel Corporation, L = Santa Clara, ST = CA, C = US
Will an updated TCB signing certificate be issued before May 21, 2025? Could you please share any information on the planned update for this certificate?
In our remote attestation system, we strictly manage the validity period of all collateral, so it is important that the latest collateral is always available and valid.
Thank you in advance.
Best regards,
Jun Kimura
Datachain, Inc.
Link Copied
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dear Jun Kimura,
a new certificate was issued today. Could you check and confirm that everything works on your end?
Best regards,
Benny
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dear Benny,
Thank you for the prompt update.
We have confirmed that the new certificate has been successfully issued, and our service continues to function as expected. We appreciate your support.
I’d also like to ask a follow-up question regarding certificate expiration policy. According to the TDX Enabling Guide, DCAP collateral (such as TCBInfo and QE Identity) is expected to have a 30-day validity period from the time of download, and should be refreshed accordingly.
Does this 30-day validity period expectation also apply to certificates (e.g. the TCB signing certificate), or are they managed under a separate policy? In addition, if the expiration date of the TCB signing certificate is earlier than the nextUpdate field of the corresponding TCBInfo, which one should be considered the effective expiration date?
If there is a documented policy or best practice for handling impending certificate expirations, we would greatly appreciate it if you could share it.
Thank you again for your assistance.
Best regards,
Jun Kimura

- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page