-
Notifications
You must be signed in to change notification settings - Fork 95
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
GCP TDX attests failed in RHEL VM #670
Comments
Haven't seen this error before. Would you be able to share the Trustee server logs too? |
Hi @mythi ,
|
@yuxisun1217 thanks. Are you using the docker-compose setup or the kubernetes deployment for Trustee? I'd be helpful if you could run KBS (and AS if they are separate) using |
Hi @mythi , |
@yuxisun1217 thanks! The reason seems obvious: TDX Evidence is bigger than what the KBS server default max payload size is (according to Actix web docs: 256KiB) we might need either confidential-containers/guest-components#575 (or similar) or some Trustee adjustments on the payload size. |
hmm yeah we probably want to adjust that from the Trustee side, especially given that we will soon be passing the init-data claims to Trustee as well. |
Describe the bug
Attest GCP TDX VM failed in RHEL-9.6:
Not see such issue in GCP SNP VM.
How to reproduce
Create a RHEL-9.6 TDX VM in GCP:
And compile install all-attesters from source code. Then try to attest it:
CoCo version information
trustee main branch
RHEL-9.6
What TEE are you seeing the problem on
Tdx
Failing command and relevant log output
The text was updated successfully, but these errors were encountered: