Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SPDM OIDs not present in DICE certs #1885

Open
bluegate010 opened this issue Jan 9, 2025 · 1 comment
Open

SPDM OIDs not present in DICE certs #1885

bluegate010 opened this issue Jan 9, 2025 · 1 comment

Comments

@bluegate010
Copy link
Contributor

bluegate010 commented Jan 9, 2025

Version 2.6 of the OCP NVMe data center specification states:

  • CERT-5: "The AliasCert chain shall contain an immutable hardware identity certificate and hardware identity OID (refer to the SPDM Specification) shall be used to indicate hardware identity certificate(s)."
  • CERT-6: "A Mutable certificate OID (refer to the SPDM Specification) shall be used to indicate mutable certificates."

SPDM version 1.2 defines these OIDs:

  • "The id-DMTF-hardware-identity OID is defined to help identify the hardware identity certificate in a chain regardless of the certificate chain model used ( DeviceCert or AliasCert ). If the AliasCert model is used, this OID shall not be present in any alias certificates in the chain."
  • "Mutable certificates may include the id-DMTF-mutable-certificate OID to identify them as mutable. If used, this OID shall be present in all mutable certificates in the chain."
@varuns-nvidia
Copy link

Dupe of chipsalliance/Caliptra#32 ?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants