英特尔SGX开发人员许可和开源软件 [英] Intel SGX developer licensing and open-source software

查看:124
本文介绍了英特尔SGX开发人员许可和开源软件的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

是否有可能获得许可的开发人员证书,以在生产模式下对经过安全审查的,社区开发的开源SGX软件二进制文件进行签名,并将其发布到apt或rpm等开源存储库中?

Is it possible to obtaining a licensed developer certificate for signing security-reviewed, community-developed open source SGX software binary in production mode, and publish it on open source repository like apt or rpm?

我刚刚问过英特尔SGX团队,他们说只有经过验证的供应商才能获得证书并以生产模式运行.就像Apple的App Store一样,不允许开放源代码,对吧?

I just asked Intel SGX team, they said only verified vendors are able to obtain a certificate and run in production mode. It just like Apple’s App Store, no open source code allowed, right?

推荐答案

可以,但是这是一个非常复杂的任务,

Well, it's possible, but it's a quite complicated task,

您需要将您自己或您的组织注册为Intel的ISV,这不是一件容易的事,例如,远程证明的必要条件之一是Mutual TLS,因此,要使其正常工作,您需要一个证书该地址必须在您控制的URL上公开可用,这样才能在Intel和您的服务器之间建立信任.

You will need to register yourself or your organization as an ISV with Intel, which is not an easy task, i.e. one of the requisites for the Remote Attestation is Mutual TLS, therefore and in order to get it working you need a Certificate which must be publicly available on an URL you control, so trust can be established between Intel and your server.

这篇关于英特尔SGX开发人员许可和开源软件的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!

查看全文
登录 关闭
扫码关注1秒登录
发送“验证码”获取 | 15天全站免登陆