[Seat] Re: Threat model and properties for attested TLS
Songbo Bu <bluedognull@gmail.com> Mon, 17 August 2026 09:10 UTC
Return-Path: <bluedognull@gmail.com>
X-Original-To: seat@mail2.ietf.org
Delivered-To: seat@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 0D3EA12AE2D64 for <seat@mail2.ietf.org>; Mon, 17 Aug 2026 02:10:36 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786957836; bh=x7LwZAoj10GuOKQCIh9GjxRQuSpwY6jAeo/dIxUcPeA=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=TBP9YbnZJlWtd4W5OF6+YPDMJegt9nZUqtaNX1Z3BOWUVEEIVL145OVYUMfZQjucQ P2MmQ923Khub1PBg9aaPbBbdt3sKCwpZvF/3QvrxCQDeuM2CGuDBqNCwrXhtsBcl2o io62vRkdy5mnGvMJ+pYsck0MJ0fQNrbxtZ8O6F2A=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.088
X-Spam-Level:
X-Spam-Status: No, score=-2.088 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uwNW_kJtijaJ for <seat@mail2.ietf.org>; Mon, 17 Aug 2026 02:10:35 -0700 (PDT)
Received: from mail-qv1-xf34.google.com (mail-qv1-xf34.google.com [IPv6:2607:f8b0:4864:20::f34]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 4846B12AE2D5D for <seat@ietf.org>; Mon, 17 Aug 2026 02:10:35 -0700 (PDT)
Received: by mail-qv1-xf34.google.com with SMTP id 6a1803df08f44-9088fa81abbso13862546d6.3 for <seat@ietf.org>; Mon, 17 Aug 2026 02:10:35 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1786957829; cv=none; d=google.com; s=arc-20260327; b=p4ArDYQb3r3SVezR1ZxwYd1xmrKSQJ9YQ1YSxDTJJoXcozbEDJ2Xj/co0XPDFz83O2 cHHzMctHaYYR7STQDmUX8bK//qCq8KGkGOO5WpPVn3kv032G3U4edNrYnKkR4WdQuEjS 04xKYO7BT62fr9BboBeqfiY6LgnhQ0oFgnqte+aPBRNIcSxmumxKQuh99D0agaZLOUxE DOhYlP0CltRqz61rCfCr5YMn2qd5h7+/N+gBNrycXpJwOAJ4XRlKpoTMP90jIpiatlFk feEhKkO30Yjv6IzaaA8Ff8hEtV2epIaHAnVU6qrarQIO8k57lGV6eBtct9iC0hj1tzcM OAUw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=x7LwZAoj10GuOKQCIh9GjxRQuSpwY6jAeo/dIxUcPeA=; fh=ltGa5jPjDpTRY45qynPpVCXWZ99Iai7+xFly1WGX3Y0=; b=b4XB0VLIzuFrKF9Apt0ARxPlCRveK4VLy+eZbAvmD+y8q+2mxlZGTR4Fg/JhpAVEmm 65AYsiC9XjWd0ArG6OKFUAIMsRJUnZvHN1ZVubM3cN+axWsKbNfySt8JnMZoeENJBRQ6 IOwz3583taZULC/DKOJmjLRsDp19v6x5ZYOIkw/fA0Pm5qF2ljvMs2kWbo6mBPH8ihRE H8K5wt5z0EobQJEgjJzNOWPOxjCZIz8PmcygISgNVzMNE4/zcPl3II2BJGvn6irogQgS 17KN/fTxT2tOIS8rD1l9kHbi3b02e4E4ceGmNeg19aw5fVhtvu/dHWBlUD3M6WH2VEet kEvA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786957829; x=1787562629; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=x7LwZAoj10GuOKQCIh9GjxRQuSpwY6jAeo/dIxUcPeA=; b=rNovvjCAuczDnWayyfAQlrmwRpvdDBvf4LIEAj3nbcqYvlXATqZNfB4y4VTRZOkQ5W /KzgRRuK/z0shFb/dMfqVjVMQdVW7C96EMm8TkMrYqflJC2YFyUUKt7uCHVG6B3tYnmC o7J0yRIlr4ZyIu76o+NnlBS1O/4qKU0oSqSKZXCpYn4aYjlEiXIt8JrVNtjotk32l/gM U9280xY8m4M7/1gcFCv+90CjmI9kEszwaLG+sq5DhN6jD2gp5dciHLgexQsa7VT7BvMk MGKjxZn/YFxw4YkOoHBGjEZiexRS/6k854jkW0tyq9NsCcm/ARV901Mzmc/fkrgziVNU 8+1g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786957829; x=1787562629; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=x7LwZAoj10GuOKQCIh9GjxRQuSpwY6jAeo/dIxUcPeA=; b=o2nQRyzh6Sm0UQkQGT0AaZQcW2NC/RK5XYIvaNj78hBscwRiZs/hvWzP0eYL+MuqRc 0s6XzAcqf/Iz0iJDM1mSN2Xwkufm6jO4kx8CxB9NBjh8kdfOV2E5Sswj8V/EcJU+q8Y8 eitOEJzBibuoi3EjgF9Qz6727DyzBt17tUgZ4N0ITqxzBjd/LcYlJDyDoIYYMOWXxFqC cQBiXaRpKz3rWPLqYAUV5jw5MWoOMTE/v7DGqN5awS6U59CjYltg9vTzPFjQYUc20rXE QO160UbBTPG8Oz4GdPxQPgq8KeoKRzm4SmfV4AUXBJWG/chZDhEqA22WYsrwA6ruc952 I9kQ==
X-Gm-Message-State: AOJu0YwZPPcIbJgpHtHTa10WPy/RVGfGYoNCDQI4OzEJ/JD+02MwMt3l 4O35vEzLUsXqktfAnYNvtpeux5T97Ilo1KZY8wMpNSAnm8EcEfGUE0dwQJwifjurAYVB42DrGRW iU3s3HLumuEV94bk2GwZdy8v7GHNBWpvFFexEN0I=
X-Gm-Gg: AR+sD13oiZ14S9F5ep0sXL6uGLyoQkFjALMCyS3BjEw5O+fDFEvnFOFT9t59aqtOTPN Sk9HZ1K8liRvscQzk12/6AAF0RNo4NssVHsfNZUJLf8AIxiAPpzJIubP5FKn0SatdyaZrOYbkQn pq15KDLWcQsijA1Gntpz5gDyz83Bms01BHsn6O/ZVTkKrfARk0dFnlBXzaPCs7hjdDXnsT2oXrX JLKbdoxTd211u0VwzKYNifsenzey6dmZu17eruo8NKQBYhkA/MnjyR1O8XGfkmmSSU5KvPLspZe dunFHowsvJj0CfrRrY8HNyct+D20eX3R5EqL1kP0FkOsw2bzvv7Fa157+/eVciyIVQCl3aob5+r npUaq7Hfp7fY=
X-Received: by 2002:a05:6214:21ca:b0:8f2:4100:8613 with SMTP id 6a1803df08f44-90a91a36788mr235218686d6.0.1786957828649; Mon, 17 Aug 2026 02:10:28 -0700 (PDT)
MIME-Version: 1.0
References: <fcec2ef9-4881-48a8-ba45-83e2b9110f3c@tu-dresden.de> <CAHxYnaMimQXVxaNLw89fnyUHUYfArcFeAjkEKnXp8h3w2+JoOg@mail.gmail.com> <CAEEbLAZ3zdgL_9i-h6Hxf_Mth6mNY188TN4QW9s2MceXax_0Tg@mail.gmail.com> <CAHxYnaM5gs_389oN0xOtbcwnL5nsRb0Op6hb3dCadi=sY_kdWg@mail.gmail.com> <CAK08nYZgvmjKv74ChRPoM-MbiR-GhuUhZr1aCPJFCKWtN1cF=w@mail.gmail.com> <CAHxYnaMDYhkZGvnSOgZfSvtUtfUfLAS3sydQok4R0c9fmF-VQw@mail.gmail.com> <CAEEbLAa21eKKemkT7KN_yWkLH0NeCDHP2Uz8aHPZiyMckQcYAQ@mail.gmail.com> <CAGL5yWbpMhO+iVF4z8SP7Xq+LDmrG9HkMEPtb1tZPOTM2ehnGQ@mail.gmail.com> <CAK08nYb2tok7-ecr63vQsUYKsBJV+cNxR7VQhyreKg0OwRrEOQ@mail.gmail.com> <CAGL5yWboduKz4LoOs2RxxxVdWGEoMBNNRgSXGrWcgKRvY1Wi8w@mail.gmail.com> <CAP3D6h+Uo2COqP=XFxtbLCKtATqQgSYXSR4KwQxyb1jB96ZL5A@mail.gmail.com> <CAHxYnaOkRL5fTGyYcvaavCa39pQLz=p2QazTNVVim7iAhZdJSQ@mail.gmail.com> <CAP3D6hLvgTQyv_z2ZeO8SZYTwHJtXOxtGSJZuir+CzeOBBmN_A@mail.gmail.com> <CAHxYnaPwcZMN8s60xG7HTAOzHxAMWt0z=a3GSG0BtwkT8FRTcQ@mail.gmail.com>
In-Reply-To: <CAHxYnaPwcZMN8s60xG7HTAOzHxAMWt0z=a3GSG0BtwkT8FRTcQ@mail.gmail.com>
From: Songbo Bu <bluedognull@gmail.com>
Date: Mon, 17 Aug 2026 17:10:17 +0800
X-Gm-Features: AcwNN1WAUmazxv-SB7edVoKoIR5OnyYMNIGaN540DeUvsH3vn5C8N1VLMfMWNBc
Message-ID: <CAK08nYa8YqQxtk2ohFcDqJ6KqitkLtBmtifbJp7AzxWcCZ-Npg@mail.gmail.com>
To: Nathanael Ritz <nathanritz@gmail.com>
Content-Type: multipart/alternative; boundary="0000000000009af61e06593a8a89"
Message-ID-Hash: ZTYCI57KLMAJTTWY7XPFIGD544QVQMGG
X-Message-ID-Hash: ZTYCI57KLMAJTTWY7XPFIGD544QVQMGG
X-MailFrom: bluedognull@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: seat@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Seat] Re: Threat model and properties for attested TLS
List-Id: "Secure Evidence and Attestation Transport (SEAT) WG" <seat.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/seat/7SYSuB83Kmr9qCb1V1F94n9W33U>
List-Archive: <https://mailarchive.ietf.org/arch/browse/seat>
List-Help: <mailto:seat-request@ietf.org?subject=help>
List-Owner: <mailto:seat-owner@ietf.org>
List-Post: <mailto:seat@ietf.org>
List-Subscribe: <mailto:seat-join@ietf.org>
List-Unsubscribe: <mailto:seat-leave@ietf.org>
Nathanael, Thank you. I have a narrow clarifying question. I use Intel TDX in a public cloud provider infrastructure. Where can I get values of PIIDs of the cloud provider machines to put in that field that Edgeless has defined? To my knowledge they are not available, and hence Chengxin is right. Best, Songbo Nathanael Ritz <nathanritz@gmail.com> 于2026年8月14日周五 18:01写道: > On Fri, 14 Aug 2026 at 02:52, Chengxin Huang <aurestarnull@gmail.com> > wrote: > >> Dear Nathanael, >> >> I don't think I am misinformed. I clarified to Paul that some identity >> exists and this is not a barrier to his solution. Do you disagree? <SNIP> >> >> Please clarify what is misinformed in my reading of the security advisory >> above. >> >> Best regards, >> >> Chengxin Huang >> > > The statement was "My understanding [...] is [...] there is no way to > check at the verifier side." If this were true, then Edgeless would not > offer extensive documentation at explaining in great detail to configure > their verifier/rp client to appraise an attester's Evidence in such a way > to achieve exactly [that check]. > > For more information, see the RATS Architecture RFC9334 Sec. 8 on > Appraisal Policies for how this applies to threat model for far more > diverse than just this one very specific example [1]. > > Cheers, > Nathanael > > [0] > https://docs.edgeless.systems/contrast/1.16/architecture/components/manifest#referencevaluessnpallowedchipids > > [1] https://www.rfc-editor.org/rfc/rfc9334.html#name-appraisal-policies > > >> [Edgeless] >> https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h >> >> On Fri, Aug 14, 2026 at 11:39 AM Nathanael Ritz <nathanritz@gmail.com> >> wrote: >> >>> On Thu, 13 Aug 2026 at 21:14, Chengxin Huang <aurestarnull@gmail.com> >>> wrote: >>> >>>> My understanding from the security advisory [Edgeless] is that while >>>> some TEEs (Intel, AMD) have some form of identity (PIID, CHIP_ID), there is >>>> no way to check at the verifier side. >>>> >>>> From a formal analysis standpoint, this means that a genuine machine in >>>> the genuine datacenter and the compromised one in someone's basement are >>>> indistinguishable, unless datacenter releases a list of all the machines >>>> that it owns. In my understanding, cloud providers are probably not willing >>>> to release that list. >>>> >>> >>> This is misinformed. From [Edgeless]: >>> >>> "On TDX, users can set an explicit list of PIIDs in the manifest, *which >>> will prevent reports from other TEEs to pass validation. *On SEV-SNP, >>> we try to mirror that approach with an explicit list of HWIDs (chip_id), >>> assuming that they are a suitable identifier for this purpose.* We >>> highly recommend setting these fields to avoid relay attacks*, until >>> more scalable solutions are available in practice." >>> >>> Emphasis mine. >>> >>> Cheers, >>> Nathanael >>> >>> On Thu, 13 Aug 2026 at 21:14, Chengxin Huang <aurestarnull@gmail.com> >>> wrote: >>> >>>> Dear Paul, >>>> >>>> My understanding from the security advisory [Edgeless] is that while >>>> some TEEs (Intel, AMD) have some form of identity (PIID, CHIP_ID), there is >>>> no way to check at the verifier side. >>>> >>>> From a formal analysis standpoint, this means that a genuine machine in >>>> the genuine datacenter and the compromised one in someone's basement are >>>> indistinguishable, unless datacenter releases a list of all the machines >>>> that it owns. In my understanding, cloud providers are probably not willing >>>> to release that list. >>>> >>>> Does this help you in your solution? If you can precisely state the >>>> value of `rdata`, I will happily do the formal analysis for you. >>>> >>>> Best regards, >>>> >>>> Chengxin Huang >>>> >>>> [Edgeless] >>>> https://github.com/edgelesssys/contrast/security/advisories/GHSA-hjgc-jc5v-fw7h >>>> >>> _______________________________________________ >>> Seat mailing list -- seat@ietf.org >>> To unsubscribe send an email to seat-leave@ietf.org >>> >> _______________________________________________ > Seat mailing list -- seat@ietf.org > To unsubscribe send an email to seat-leave@ietf.org >
- [Seat] Threat model and properties for attested T… Muhammad Usama Sardar
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Sophie Schmieg
- [Seat] Re: Threat model and properties for attest… Muhammad Usama Sardar
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Sophie Schmieg
- [Seat] Re: Threat model and properties for attest… Muhammad Usama Sardar
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Song Haowen
- [Seat] Re: Threat model and properties for attest… Steve
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Muhammad Usama Sardar
- [Seat] Re: Threat model and properties for attest… Iman Schrock
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Chengxin Huang
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Chengxin Huang
- [Seat] Re: Threat model and properties for attest… tirumal reddy
- [Seat] Re: Threat model and properties for attest… Thomas Fossati
- [Seat] Re: Threat model and properties for attest… Ionut Mihalcea
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Thomas Fossati
- [Seat] Re: Threat model and properties for attest… Muhammad Usama Sardar
- [Seat] Re: Threat model and properties for attest… Thomas Fossati
- [Seat] Re: Threat model and properties for attest… Muhammad Usama Sardar
- [Seat] Regarding the charter-mandated restriction… Nathanael Ritz
- [Seat] Re: Regarding the charter-mandated restric… Ionut Mihalcea
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Muhammad Usama Sardar
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Iman Schrock
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Iman Schrock
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Chengxin Huang
- [Seat] Rhetoric on the SEAT mailing list Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… tirumal reddy
- [Seat] Re: Threat model and properties for attest… Song Haowen
- [Seat] Re: Threat model and properties for attest… Iman Schrock
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Song Haowen
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… tirumal reddy
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Chengxin Huang
- [Seat] Re: Threat model and properties for attest… Steve
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Song Haowen
- [Seat] Re: Threat model and properties for attest… Paul Wouters
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Paul Wouters
- [Seat] Re: Threat model and properties for attest… Chengxin Huang
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Chengxin Huang
- [Seat] Re: Threat model and properties for attest… Nathanael Ritz
- [Seat] Re: Threat model and properties for attest… Songbo Bu
- [Seat] Re: Threat model and properties for attest… Ionut Mihalcea