-
Notifications
You must be signed in to change notification settings - Fork 46
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
New bare metal machine not producing attestations #314
Comments
Thank you for reporting your feedback to us! The internal ticket has been created: https://warthogs.atlassian.net/browse/PEK-1603.
|
I had this same issue, I did set SGX Factory Reset, but was able to enable |
@fwoodruff-ab Could you please run |
Hi, I was wrong about the machine not having |
@fwoodruff-ab did you run the |
@fwoodruff-ab, @hector-cao I think this becomes a very similar problem to the one I am having |
@hector-cao I ran |
Ýes, that would be great |
@hector-cao , I've sent you an email. I hope that's ok |
@fwoodruff-ab the qgsd output indicates to me that the certificate used to communicate with PCCS service is not good, the only thing i would think of is to make sure to run |
That solved it, thank you! |
Great ! Closing |
Describe the support request
Having previously got guests and attestations working, I am now on a new machine on a new bare metal provider. I am able to launch a TD guest but I can't generate an attestation report (it's empty).
I ran the attestation setup instructions and I noticed that
cat /var/log/mpa_registration.log
was giving bad logs.I tried setting
SGX Factory Reset
andSGX Auto MP Registration
to 'enable'. This has resolved the registration logs but I am still not able to generate attestations from guests.How do I debug this and get attestations working on this machine?
System report
Git ref
Operating system details
Kernel version
TDX kernel logs
TDX CPU instruction support
Model specific registers (MSRs)
CPU details
QEMU package details
Libvirt package details
OVMF package details
sgx-dcap-pccs package details
tdx-qgs package details
sgx-ra-service package details
sgx-pck-id-retrieval-tool package details
QGSD service status
PCCS service status
MPA registration logs (last 30 lines)
The text was updated successfully, but these errors were encountered: