@@ -14,66 +14,43 @@ data:
1414 default hardware := 97
1515 default configuration := 36
1616
17- ## miminimal but reliable attestation policy
18- ## hardware and firmware changes. This is not in our control. It's up to the user to update acceptable measurements
19- ## In conjuction with verification with the service provider.
20- ## currently setup for azure vTPM
21-
17+ trust_claims := {
18+ "executables": executables,
19+ "hardware": hardware,
20+ "configuration": configuration,
21+ }
2222
2323 ##### Azure vTPM SNP
2424 executables := 3 if {
25- # input.azsnpvtpm.measurement in data.reference.measurement
26- input.azsnpvtpm.tpm.pcr03 in data.reference.snp_pcr03
27- input.azsnpvtpm.tpm.pcr08 in data.reference.snp_pcr08
28- input.azsnpvtpm.tpm.pcr09 in data.reference.snp_pcr09
29- input.azsnpvtpm.tpm.pcr11 in data.reference.snp_pcr11
30- input.azsnpvtpm.tpm.pcr12 in data.reference.snp_pcr12
25+ input["az-snp-vtpm"].tpm.pcr03 in query_reference_value("snp_pcr03")
26+ input["az-snp-vtpm"].tpm.pcr08 in query_reference_value("snp_pcr08")
27+ input["az-snp-vtpm"].tpm.pcr09 in query_reference_value("snp_pcr09")
28+ input["az-snp-vtpm"].tpm.pcr11 in query_reference_value("snp_pcr11")
29+ input["az-snp-vtpm"].tpm.pcr12 in query_reference_value("snp_pcr12")
3130 }
3231
3332 hardware := 2 if {
34- # Check the reported TCB to validate the ASP FW
35- # input.azsnpvtpm.reported_tcb_bootloader in data.reference.tcb_bootloader
36- # input.azsnpvtpm.reported_tcb_microcode in data.reference.tcb_microcode
37- # input.azsnpvtpm.reported_tcb_snp in data.reference.tcb_snp
38- # input.azsnpvtpm.reported_tcb_tee in data.reference.tcb_tee
39- input.azsnpvtpm
33+ input["az-snp-vtpm"]
4034 }
4135
42- # For the 'configuration' trust claim 2 stands for
43- # "The configuration is a known and approved config."
44- #
45- # For this, we compare all the configuration fields.
4636 configuration := 2 if {
47- # input.azsnpvtpm.platform_smt_enabled in data.reference.smt_enabled
48- # input.azsnpvtpm.platform_tsme_enabled in data.reference.tsme_enabled
49- # input.azsnpvtpm.policy_abi_major in data.reference.abi_major
50- # input.azsnpvtpm.policy_abi_minor in data.reference.abi_minor
51- # input.azsnpvtpm.policy_single_socket in data.reference.single_socket
52- # input.azsnpvtpm.policy_smt_allowed in data.reference.smt_allowed
53- input.azsnpvtpm
37+ input["az-snp-vtpm"]
5438 }
5539
5640 ##### Azure vTPM TDX
5741 executables := 3 if {
58- input.aztdxvtpm. tpm.pcr03 in data.reference. tdx_pcr03
59- input.aztdxvtpm. tpm.pcr08 in data.reference. tdx_pcr08
60- input.aztdxvtpm. tpm.pcr09 in data.reference. tdx_pcr09
61- input.aztdxvtpm. tpm.pcr11 in data.reference. tdx_pcr11
62- input.aztdxvtpm. tpm.pcr12 in data.reference. tdx_pcr12
42+ input["az-tdx-vtpm"]. tpm.pcr03 in query_reference_value(" tdx_pcr03")
43+ input["az-tdx-vtpm"]. tpm.pcr08 in query_reference_value(" tdx_pcr08")
44+ input["az-tdx-vtpm"]. tpm.pcr09 in query_reference_value(" tdx_pcr09")
45+ input["az-tdx-vtpm"]. tpm.pcr11 in query_reference_value(" tdx_pcr11")
46+ input["az-tdx-vtpm"]. tpm.pcr12 in query_reference_value(" tdx_pcr12")
6347 }
6448
6549 hardware := 2 if {
66- # Check the quote is a TDX quote signed by Intel SGX Quoting Enclave
67- input.aztdxvtpm.quote.header.tee_type == "81000000"
68- input.aztdxvtpm.quote.header.vendor_id == "939a7233f79c4ca9940a0db3957f0607"
69-
70- # Check TDX Module version and its hash. Also check OVMF code hash.
71- # input.aztdxvtpm.quote.body.mr_seam in data.reference.mr_seam
72- # input.aztdxvtpm.quote.body.tcb_svn in data.reference.tcb_svn
73- # input.aztdxvtpm.quote.body.mr_td in data.reference.mr_td
50+ input["az-tdx-vtpm"].quote.header.tee_type == "81000000"
51+ input["az-tdx-vtpm"].quote.header.vendor_id == "939a7233f79c4ca9940a0db3957f0607"
7452 }
7553
7654 configuration := 2 if {
77- # input.aztdxvtpm.quote.body.xfam in data.reference.xfam
78- input.aztdxvtpm
55+ input["az-tdx-vtpm"]
7956 }
0 commit comments