Skip to content

Verify TLS/attestation binding.#77

Merged
NullHypothesis merged 1 commit into
masterfrom
verify-tls-binding
May 31, 2026
Merged

Verify TLS/attestation binding.#77
NullHypothesis merged 1 commit into
masterfrom
verify-tls-binding

Conversation

@NullHypothesis

Copy link
Copy Markdown
Contributor

So far, veil-verify failed to check the binding between the peer's TLS certificate and the enclave's attestation hashes. That's important because if we don't check that, a malicious reverse proxy could interfere with the attestation process. Thanks to GPT-5.5 for noticing this oversight.

So far, veil-verify failed to check the binding between the peer's TLS
certificate and the enclave's attestation hashes. That's important
because if we don't check that, a malicious reverse proxy could
interfere with the attestation process. Thanks to GPT-5.5 for noticing
this oversight.
@NullHypothesis NullHypothesis merged commit 90b780d into master May 31, 2026
5 checks passed
@NullHypothesis NullHypothesis deleted the verify-tls-binding branch May 31, 2026 19:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant