nsacyber / HIRS

Trusted Computing based services supporting TPM provisioning and supply chain validation concepts. #nsacyber
Other
181 stars 58 forks source link

Add ACA policy to ignore component revision within the Platform Cerificate #707

Open iadgovuser26 opened 9 months ago

iadgovuser26 commented 9 months ago

Within the ComponentIdentifier of the Platform Certificates is a componentRevision field. While an exact match should be required for most Supply Chain scenarios there are use cases in which the Platform Certificate may be used for system monitoring use cases which must accommodate for component firmware updates. Component revisions (e.g. System BIOS revision) get systematically updated and a verification of the component will currently fail.

Proposed ACA Policy addition:

Default should be set to Disabled

cyrus-dev commented 8 months ago

This is also reference in #705