Intel® Software Guard Extensions (Intel® SGX)
Discussion board focused on hardware-based isolation and memory encryption to provide extended code protection in solutions.

Test Intel Attestation Service has incorrect certificate

Rosłaniec__Piotr
912 Views

Hello.

I just noticed that the certificate on https://test-as.sgx.trustedservices.intel.com domain is incorrect. It's issued for CN "dev-as.sgx.trustedservices.intel.com". The latter is also inaccessible.

Regards,
Piotr

0 Kudos
3 Replies
Elephant
Beginner
912 Views

I noticed this too!

Please fix this ASAP.  Thanks!

* Server certificate:
* 	 subject: C=US; postalCode=95054-1537; ST=California; L=Santa Clara; street=FM1-110; street=2200 Mission College Blvd; O=Intel Corporation; OU=Hosted by Intel Corporation; OU=Multi-Domain SSL; CN=dev-as.sgx.trustedservices.intel.com
* 	 start date: Jun  7 00:00:00 2019 GMT
* 	 expire date: Jun  6 23:59:59 2021 GMT
* 	 subjectAltName does not match test-as.sgx.trustedservices.intel.com

 

0 Kudos
shi__webb
Beginner
912 Views

I'm calling the `get_sigrl_from_intel`  and it return the following error:

get_sigrl_from_intel tls.read_to_end: Custom { kind: InvalidData, error: WebPKIError(CertNotValidForName) }

0 Kudos
Rosłaniec__Piotr
912 Views

Turns out that the V2 attestation service has reached its end of life. You can learn about the new IAS below:

https://api.portal.trustedservices.intel.com/

https://api.trustedservices.intel.com/documents/sgx-attestation-api-spec.pdf

Update:

I'm not sure about the EOL, but the test IAS seems to have correct certificate now.

0 Kudos
Reply