You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Discussion started in oxidecomputer/hubris#2026. Generating the FWID in the hubris xtask is useful for debugging but it's not something that we can use to make security decisions like using them to construct a corpus of measurements for appraising attestations. Instead we need tooling that allows us to generate this value from a hubris archive. Bonus points for providing a mechanism to check the signature over the image as a means to establish trust in the FWID value (this should probably be another issue).
The text was updated successfully, but these errors were encountered:
Discussion started in oxidecomputer/hubris#2026. Generating the FWID in the hubris
xtask
is useful for debugging but it's not something that we can use to make security decisions like using them to construct a corpus of measurements for appraising attestations. Instead we need tooling that allows us to generate this value from a hubris archive. Bonus points for providing a mechanism to check the signature over the image as a means to establish trust in the FWID value (this should probably be another issue).The text was updated successfully, but these errors were encountered: