Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Intel SGX developer licensing and open-source software

Is it possible to obtaining a licensed developer certificate for signing security-reviewed, community-developed open source SGX software binary in production mode, and publish it on open source repository like apt or rpm?

I just asked Intel SGX team, they said only verified vendors are able to obtain a certificate and run in production mode. It just like Apple’s App Store, no open source code allowed, right?

like image 594
Heting Wang Avatar asked Feb 14 '26 21:02

Heting Wang


1 Answers

Well, it's possible, but it's a quite complicated task,

You will need to register yourself or your organization as an ISV with Intel, which is not an easy task, i.e. one of the requisites for the Remote Attestation is Mutual TLS, therefore and in order to get it working you need a Certificate which must be publicly available on an URL you control, so trust can be established between Intel and your server.

like image 178
ruizpauker Avatar answered Feb 17 '26 10:02

ruizpauker