The Host Integrity at Runtime and Start-up Attestation Certificate Authority is a Proof of Concept - Prototype intended to spur interest and adoption of the Trusted Platform Module (TPM). It's intended for testing and development purposes only and is not intended for production. The ACA's functionality supports the provisioning of TPM 2.0 with an Attestation Certificate. The ACA can be configured to enforce the Validation of Endorsement Certificates, Platform Certificates, and Refernce Intregrity Manifests (RIMs) to illustrate a supply chain validation capability known as an "Acceptance Test".
Notice: Github Discussions have been enabled for this repo. Please refer to the Discussion entitled "HIRS development changes" for development and support notifications.
The HIRS ACA is a web based server which processes Attestation Identity Requests. The ACA provides a “provisioner” application to be installed on all devices which will be requesting Attestation Certificates.
NOTEL The HIRS ACA, tcg_rim_tool, and tcg_eventLog_tool require Java 17 jre be installed before attempting to install these packages. For detailed instructions, see Installation notes.
Packages used for installation can be found on the release page.
There are several options for installing the HIRS ACA
An ACA Docker image is automatically created for each release. To run the ACA container using docker
docker run --name=aca -p 8443:8443 ghcr.io/nsacyber/hirs/aca:latest
To install the ACA on a Redhat or Rocky Linux download the latest rpm from the release page then run the command
sudo dnf install HIRS_AttestationCA*.rpm.
To install the ACA on a Ubuntu Linux download the latest rpm from the release page then run the command
sudo apt-get install ./HIRS_AttestationCA*.deb.
To install the HIRS_Provisioner.NET on a Redhat or Rocky Linux download the latest rpm package from the release page then open a terminal and run the command
sudo dnf install HIRS_Provisioner.NET.*.rpm
To install the HIRS_Provisioner.NET on Ubuntu Linux download the latest deb package from the release page then open a terminal and run the command
sudo apt-get install ./HIRS_Provisioner.NET.*.deb
To install the HIRS_Provisioner.NET on Windows download the latest msi package from the release page then open a powershell windows as an administrator then run the command
msiexec /package HIRS_Provisioner.NET.*.msi /quiet
Then follow the instructions for setting up the HIRS_provisioner.NET in the HIRS_Provisioner.NET Readme.
On Linux: To kick off a provision on the client, open a terminal and run the command
sudo tpm_aca_provision
On Windows: Open a powershell terminal as an administrator and enter the command
tpm_aca_provision
To see the results and interact with the ACA, using a browser go to the ACA Portal usng the URL:
https://localhost:8443/
For more information see the Getting Started Guide
Version 1.1 added support for the Platform Certificate v1.1 Specification. This allows entities that are part of the supply chain (System integrators and Value Added Resellers) the ability to create Delta Platform Certificate to compliment the Base Platform Certificate created by the Platform Manufacturer. See the Article on Base and Delta Platform Certificates for details.
Version 2.0 added support for the PC Client Reference Integrity Manifest (RIM) Specification to provide firmware validation capability to the HIRS ACA. This requires that the manufacturer of a device provide a digitally signed RIM "Bundle" for each device. The HIRS ACA has a new page for uploading and viewing RIM Bundles and a policy setting for requiring Firmware validation.
Version 3.0 was completely refactored to build and run on multiple platforms. The Base OS used for development of the ACA was migrated to Rocky Linux with updates to current dependencies (e.g. Java, Tomcat, Mariadb, etc.) and development tools (e.g. Gradle). New features introduced in Version 3.0 include support for the PC Client RIM 1.1 specification including composite RIMs, time-stamps, and counter signatures and detailed linkages between TCG Event Logs, OEM issuer certificates, and Reference Integrity Manifests (RIMs) have been added to provide greater granularity of information. Support for TPM 1.2 (HIRS_Provisioner) and the Cplus version of the TPM provsioner (HIRS_ProvisionerTPM2) was dropped from Version 3.0 and replaced with the HIRS_Provisioner.NET.
To support the TCG RIM concept a new tools folder has been added to the HIRS project which contains a tcg_rim_tool command line application. The tcg_rim_tool can be used to create NISTIR 8060 compatible SWID tags that adhere to the TCG PC Client RIM specification. It also supports the ability to digitally sign the Base RIM file as the HIRS ACA will require a valid signature in order to upload any RIM file. See the tgc_rim_tool READ.md for more details.
Background
HIRS Documentation
HIRS Notes
Tools