Intel® Software Guard Extensions (Intel® SGX)
Discussion board focused on hardware-based isolation and memory encryption to provide extended code protection in solutions.

fTPM Endorsement Key invalid certificate

gerasiovM
Beginner
249 Views

pyca/cryptography can't parse the distributed EK certificate because it contains an encrypted default value for "critical" field in one of its extensions. This makes the certificate invalid and pyca/cryptography doesn't support parsing of invalid certificates.

 

Here's the github issue with relevant information:

https://github.com/pyca/cryptography/issues/12665

 

Attached is the PEM encoded EK certificate

0 Kudos
1 Reply
Benny_Intel
Moderator
129 Views

Could you please elaborate what the relation of this request and Intel SGX is? 
The Github Issue you linked to (https://github.com/pyca/cryptography/issues/12665) seems to be the proper place for the request and you already received an answer there.

Best regards,
Benny

0 Kudos
Reply