- Partially reverts ed8405d0fd which included
`sgx_dcap_qal.h` in `libsgx-headers` and transferred ownership of its contents
to this repository.
- The QAL API definitions are now transferred back to DCAP, where the QAL implementation
lives.
- The common structure definitions ( `tee_policy_bundle_t`, `tee_policy_auth_result_t`) which
are shared between SGX (TVL) and DCAP repositories are extracted to a new header
`sgx_dcap_qal_types.h` and kept as part of the SGX repository, with the intent
to also be included by DCAP's 'sgx_dcap_qal.h`.
Additional changes:
--------------------
- SGX SDK installer package and `libsgx-headers` DEB/RPM package's BOM changes:
1) *REMOVE* an SGX-side copy of `sgx_dcap_qal.h` (QAL APIs)
This header is still available via `libsgx-dcap-quote-verify-dev` DEB/RPM package,
matching the exported API of the corresponding `libsgx_dcap_quoteverify.so` library.
2) *ADD* `sgx_dcap_qal_types.h` (QAL types, shared with TVL)
---------
Signed-off-by: Krzysztof1 Wisniewski <krzysztof1.wisniewski@intel.com>
SGX SDK–related attestation headers and the TVL sources originating from DCAP
tag: 'DCAP_1.25' are now relocated:
FROM: the intermediate staging area: './external/from_dcap'
(created by the '[from DCAP][move 1/2]...') commit 5b0b8e9)
INTO: their target SGX SDK repository layout.
This is a follow-on commit that places relocated files in its final locations
and updates the build system accordingly.
Additional changes:
--------------------
- `libsgx-headers` DEB/RPM package now also contains the following 2 headers:
1) sgx_qve_header.h
2) sgx_dcap_qal.h
Leveling w/ SDK - both files were part of the SDK already.
- SDK installer package now also contains the `sgx_dcap_constant_val.h` header
(from TVL), including common QvE and QAE identity verification constants.
---------
Signed-off-by: Krzysztof1 Wisniewski <krzysztof1.wisniewski@intel.com>
Upgraded to OpenSSL 3.0.13.
Upgraded to Intel(R) Integrated Performance Primitives (IPP) Cryptography library
version 2021.11.
Upgraded to Protobuf 3.23.2.
Upgraded MbedTLS to 3.5.2.
Upgraded Intel DCAP Ring3 Abstraction Layer (R3AAL) library to support ConfigFS-TSM
as communication channel between host and guest for TDX remote attestation.
Upgraded Intel DCAP Quote Verification Enclave to integrate OpenSSL/SgxSSL 3.0.13.
Upgraded new TDX attestation result “TD_RELAUNCH_ADVISED” in Intel DCAP Quote
Verification Library (QVL) and Appraisal Engine.
Fixed bugs.
Signed-off-by: Li, Xun <xun.li@intel.com>
Supported the Key Separation and Sharing (KSS) feature in Simulation mode.
Upgraded to OpenSSL 1.1.1t.
Upgraded Intel(R) SGX Quote Verification Enclave to integrate SgxSSL/OpenSSL
version 1.1.1t.
Added new API in quote verification library to extract FMSPC
(Family-Model-SteppingPlatform-CustomSKU) value from ECDSA quote.
Added Rust support for SGX ECDSA quote generation.
Added Linux kernel 5.19 support in TDX R3AAL (Ring 3 Attestation Abstraction Layer).
Removed Protobuf in TDX QGS (Quote Generation Service) and R3AAL (Ring 3
Attestation Abstraction Layer).
Fixed bugs.
Signed-off-by: Li, Xun <xun.li@intel.com>
Added Ubuntu 20.04 and CentOS 8.2 support.
Added Intel(R) Provisioning Certification Service V3 API support for ECDSA attestation.
Fixed bugs.
Signed-off-by: Li, Xun <xun.li@intel.com>