Skip to content

Conversation

@drgora
Copy link

@drgora drgora commented Jan 26, 2026

This implements the first version of the tee verifier.

This first version implements the offline verification of Intel TDX attestations, following the official documentation.

Concretely, this first version verifies that the given attestation has been signed by a valid Intel TEE, which is deemed secure according to the Intel Trusted Computing Base Recovery.

This verifier does not implement any verification of the actual content of the verification, which is out of scope for the intended usage. Similarly, the verification process does not account for certificate revocation lists, which are out of scope.

@drgora drgora requested a review from 95DDB January 26, 2026 17:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants