constellation/bootstrapper/internal
Otto Bittner 7c5556864b AB#2333: Add AMD SNP-based attestation
Currently only available on Azure CVMs.

* Get the public attestation key from the TPM.
* Get the snp report from the TPM.
* Get the VCEK and ASK certificate from the metadata api.
* Verify VCEK using hardcoded root key (ARK)
* Verify SNP report using VCEK
* Verify HCLAkPub using SNP report by comparing
AK with runtimeData
* Extend unittest

Co-authored-by: Thomas Tendyck <51411342+thomasten@users.noreply.github.com>
Co-authored-by: Daniel Weiße <dw@edgeless.systems>
2022-08-29 16:29:33 +02:00
..
clean Simplify node lock and various small changes 2022-07-14 17:25:18 +02:00
diskencryption Rename coordinator to bootstrapper and rename roles 2022-07-14 17:25:18 +02:00
initserver move nodestate and role 2022-08-29 16:07:55 +02:00
joinclient move nodestate and role 2022-08-29 16:07:55 +02:00
kubelet Use Certificate Requests to issue Kubelet Certificates and set CA (#261) 2022-07-15 09:33:11 +02:00
kubernetes AB#2333: Add AMD SNP-based attestation 2022-08-29 16:29:33 +02:00
logging Rename coordinator to bootstrapper and rename roles 2022-07-14 17:25:18 +02:00
nodelock AB#2200 Merge Owner and Cluster ID (#282) 2022-07-26 10:58:39 +02:00