- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For example, when using Remote Attestation with DCAP for Quote verification, TCBInfo is obtained from the following URL.
https://api.trustedservices.intel.com/sgx/certification/v3/tcb?fmspc=00906ed50000
The tcbStatus in the response returned by this API has a ConfirmationAndSWHardeningNeeded
status. But why is there no AdvisoryId associated with this Status in the response?
https://api.portal.trustedservices.intel.com/documentation#pcs-tcb-info-v3
The advisoryId is present in this reference.
If there is a vulnerability related to tcbLevel, I would expect the advisoryId to be included in the API response, but is this understanding incorrect?
Also, if the advisoryId is not currently included in the API response, what is the best way for a verifier to know the relationship between a particular TCBLevel and the advisoryId?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Your understanding is correct, and this feature will actually be released soon.
Sincerely,
Sahira
Link Copied
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Additional information.
Attestation Report issued by Intel's IAS when the EPID verification was performed on the same machine.
{"id":"...","timestamp":"2022-07-07T08:29:08.930675","version":4,"advisoryURL":"https://security-center.intel.com","advisoryIDs":["INTEL-SA-00334"],"isvEnclaveQuoteStatus":"SW_HARDENING_NEEDED","isvEnclaveQuoteBody":"..."}
I think AdvisoryId is a common problem independent of either IAS or DCAP.
Then I am wondering why IAS returns AdvisoryId and Intel's PCS does not return AdvisoryId
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Toshi,
Apologies for not responding sooner. I am looking into this and will let you know when I have more information
Sincerely,
Sahira
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Your understanding is correct, and this feature will actually be released soon.
Sincerely,
Sahira
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page