[Rats] Coordination between SEAT and RATS for attested TLS for confidential computing

Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de> Thu, 14 May 2026 13:24 UTC

Return-Path: <muhammad_usama.sardar@tu-dresden.de>
X-Original-To: rats@mail2.ietf.org
Delivered-To: rats@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 975A4EE4EFC8 for <rats@mail2.ietf.org>; Thu, 14 May 2026 06:24:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1778765062; bh=6yGO5w34O1vPX3ZCTEyFGZ5uvq34ImbBOt+49wDKOM8=; h=Date:From:Subject:To; b=YEXOq4+ykWc1a9JTwcHZqJRcE6rPhMdX0L/fV2292sTRKPmQ2FVOTTNcfyom+0FNB V+kQTCVrdXsLBK0sw8teEtjahWL45pTeFYWn1JqnTKavBzYDKK3kEVH8pFHEuojfPm iue/mXXT7XsfbbZTlsDCObYGGk5W7980WVmswX54=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.397
X-Spam-Level:
X-Spam-Status: No, score=-4.397 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=tu-dresden.de
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id v2y43GxEIM7G for <rats@mail2.ietf.org>; Thu, 14 May 2026 06:24:21 -0700 (PDT)
Received: from mailout3.zih.tu-dresden.de (mailout3.zih.tu-dresden.de [141.30.67.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id F15A9EE4EF9D for <rats@ietf.org>; Thu, 14 May 2026 06:24:19 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=tu-dresden.de; s=dkim2022; h=Content-Type:To:Subject:From:MIME-Version:Date :Message-ID:Sender:Reply-To:Cc:Content-Transfer-Encoding:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=SkHGYeypUkc57HokrVgABU1P12s9C3mjbE5REGOceJw=; b=VPxn77ik+kV5SlBGor6haayVz+ 6qHombAeQwq82BiNppWLHiFoVt3Pl0kyisraIxq7paJrvKhXxaAwbsfNmJrBMdaDOsQfcn05csU+l 5p11ec06yJvPibSpIGA44dAO5Ihr9n2pSO00aU2XZLlfK+S4NQs57WxXdYWZqckgbF4qCSB/8JTbh a2UtYi0oyvwVY12VpDZ+uXxJGh/pNGHv7+yq+V0sCNgXIrAzDwePBoLGVk3YXsGtEMKzkKqzUgeoN ZImymDQccg1Ab1Chh1VnxKLeFYiTO0lbS9iy5S6deZOtwGztSniiuz+k5fO9k29BnnPHOO2f67UOK Jpu6bgfw==;
Received: from msx-t422.msx.ad.zih.tu-dresden.de ([172.26.35.139] helo=msx.tu-dresden.de) by mailout3.zih.tu-dresden.de with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from <muhammad_usama.sardar@tu-dresden.de>) id 1wNW2z-002mxQ-1z for rats@ietf.org; Thu, 14 May 2026 15:24:18 +0200
Received: from [10.12.5.228] (141.76.13.149) by msx-t422.msx.ad.zih.tu-dresden.de (172.26.35.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.37; Thu, 14 May 2026 15:24:17 +0200
Message-ID: <6163b628-e185-4106-af55-5b9b3fd112cd@tu-dresden.de>
Date: Thu, 14 May 2026 15:24:15 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Content-Language: en-US
From: Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de>
To: "rats@ietf.org" <rats@ietf.org>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-512"; boundary="------------ms000307010105020808030701"
X-ClientProxiedBy: MSX-T416.msx.ad.zih.tu-dresden.de (172.26.35.136) To msx-t422.msx.ad.zih.tu-dresden.de (172.26.35.139)
X-TUD-Virus-Scanned: mailout3.zih.tu-dresden.de
Message-ID-Hash: 5BZTFNJAK323WU5GQS5UEQLPJ6V7UWM6
X-Message-ID-Hash: 5BZTFNJAK323WU5GQS5UEQLPJ6V7UWM6
X-MailFrom: muhammad_usama.sardar@tu-dresden.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-rats.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Rats] Coordination between SEAT and RATS for attested TLS for confidential computing
List-Id: Remote ATtestation procedureS <rats.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/rats/Fb6MDD4JwccNEy5kfaDgIs1mdi8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rats>
List-Help: <mailto:rats-request@ietf.org?subject=help>
List-Owner: <mailto:rats-owner@ietf.org>
List-Post: <mailto:rats@ietf.org>
List-Subscribe: <mailto:rats-join@ietf.org>
List-Unsubscribe: <mailto:rats-leave@ietf.org>

Hi RATS,

As some of you know, SEAT [0] is working on attested TLS. The boundary 
of SEAT with TLS seems to be precisely defined, but I believe the 
boundary between SEAT and RATS would benefit from more explicit definitions.

Some questions came up in SEAT about what belongs in RATS and what 
belongs in SEAT. In particular:

 1. What should be the minimum requirements for the user-defined Claims
    (like REPORTDATA field in Intel TDX) in Evidence?
 2. How should these Claims be verified?

I am particularly interested in Confidential Computing.

After some brainstorming, I have the following idea:

 1. One document describing the above two points in general
 2. One document per vendor describing the profile
      * Intel TDX
      * AMD SEV-SNP
      * Arm CCA

I would appreciate feedback on the following questions:

 1. Do chairs view that within scope of RATS charter?
 2. If yes, then:
     1. Is there already some document on these lines?
     2. Is there already a plan to move some document towards this
        direction?
     3. is there interest in RATS to work on this?

Thank you.

Best regards,

-Usama


[0] https://datatracker.ietf.org/wg/seat/about/