-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathsev.go
87 lines (71 loc) · 1.93 KB
/
sev.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
package attestation
import (
_ "embed"
"encoding/base64"
"encoding/hex"
"fmt"
"net/url"
"strings"
"github.com/google/go-sev-guest/abi"
"github.com/google/go-sev-guest/proto/sevsnp"
"github.com/google/go-sev-guest/verify"
"github.com/google/go-sev-guest/verify/trust"
"google.golang.org/protobuf/types/known/wrapperspb"
"github.com/tinfoilsh/verifier/util"
)
// https://kdsintf.amd.com/vcek/v1/Genoa/cert_chain
//
//go:embed genoa_cert_chain.pem
var vcekGenoaCertChain []byte
type getter struct{}
func (_ *getter) Get(targetURL string) ([]byte, error) {
u, err := url.Parse(targetURL)
if err != nil {
return nil, fmt.Errorf("failed to parse URL: %v", err)
}
if strings.HasSuffix(u.Path, "/cert_chain") {
if u.Path == "/vcek/v1/Genoa/cert_chain" {
return vcekGenoaCertChain, nil
} else {
return nil, fmt.Errorf("cert_chain is not supported")
}
}
u.Host = "kds-proxy.tinfoil.sh"
return util.Get(u.String())
}
var (
_ trust.HTTPSGetter = &getter{}
)
func verifySevAttestation(attestationDoc string) (*Verification, error) {
attDocBytes, err := base64.StdEncoding.DecodeString(attestationDoc)
if err != nil {
return nil, err
}
opts := verify.DefaultOptions()
opts.Getter = &getter{}
opts.Product = &sevsnp.SevProduct{
Name: sevsnp.SevProduct_SEV_PRODUCT_GENOA,
MachineStepping: &wrapperspb.UInt32Value{Value: uint32(0)},
}
parsedReport, err := abi.ReportToProto(attDocBytes)
if err != nil {
return nil, fmt.Errorf("failed to parse report: %v", err)
}
if err := verify.SnpReport(parsedReport, opts); err != nil {
return nil, err
}
cfp, err := hex.DecodeString(string(parsedReport.ReportData))
if err != nil {
return nil, fmt.Errorf("failed to decode certificate fingerprint: %v", err)
}
measurement := &Measurement{
Type: SevGuestV1,
Registers: []string{
hex.EncodeToString(parsedReport.Measurement),
},
}
return &Verification{
Measurement: measurement,
CertFP: cfp,
}, nil
}