Skip to content
Discussion options

You must be logged in to vote

Okay.
This is an automated process done by the service (like KMS).

  1. The attestation document from the enclave comes with a digital signature from the Nitro Hypervisor.

  2. KMS has a copy of AWS's public certificate (like a public master key that everyone can trust).

  3. KMS uses this public certificate to mathematically verify that the signature on the document is genuine. This proves two things:

  • The document was created by a real AWS Nitro Hypervisor.

  • The document was not tampered with after it was signed.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by UniWASMTech
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants