2022-03-22 16:03:15 +01:00
|
|
|
package azure
|
|
|
|
|
|
|
|
import (
|
|
|
|
"io"
|
|
|
|
|
2022-06-01 15:08:42 +02:00
|
|
|
"github.com/edgelesssys/constellation/internal/attestation/vtpm"
|
|
|
|
"github.com/edgelesssys/constellation/internal/oid"
|
2022-03-22 16:03:15 +01:00
|
|
|
tpmclient "github.com/google/go-tpm-tools/client"
|
|
|
|
)
|
|
|
|
|
|
|
|
// Issuer for Azure TPM attestation.
|
|
|
|
type Issuer struct {
|
|
|
|
oid.Azure
|
|
|
|
*vtpm.Issuer
|
|
|
|
}
|
|
|
|
|
|
|
|
// NewIssuer initializes a new Azure Issuer.
|
|
|
|
func NewIssuer() *Issuer {
|
|
|
|
return &Issuer{
|
|
|
|
Issuer: vtpm.NewIssuer(
|
|
|
|
vtpm.OpenVTPM,
|
|
|
|
tpmclient.AttestationKeyRSA,
|
|
|
|
getSNPAttestation,
|
|
|
|
),
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// getSNPAttestation loads and returns the SEV-SNP attestation statement.
|
|
|
|
//
|
|
|
|
// As long as we are using regular VMs on Azure this is a stub, returning nil.
|
|
|
|
func getSNPAttestation(tpm io.ReadWriteCloser) ([]byte, error) {
|
|
|
|
// TODO: implement this for CVMs
|
|
|
|
return nil, nil
|
|
|
|
}
|