feat: use real RA-TLS for everything

* add `tee-ratls-preexec` for creating the vault certificate
* remove the old attestation API

Signed-off-by: Harald Hoyer <harald@matterlabs.dev>
This commit is contained in:
Harald Hoyer 2024-02-27 12:07:15 +01:00
parent 020159b9d7
commit 0b60abc030
Signed by: harald
GPG key ID: F519A1143B3FBE32
21 changed files with 837 additions and 834 deletions

View file

@ -1,4 +1,5 @@
// SPDX-License-Identifier: Apache-2.0
// Copyright (c) 2024 Matter Labs
mod sgx {
use anyhow::Result;
@ -23,7 +24,7 @@ mod sgx {
tcb_level_date_tag,
} = verify_quote_with_collateral(quote, Some(collateral), current_time).unwrap();
if collateral_expired || !matches!(result, sgx_ql_qv_result_t::SGX_QL_QV_RESULT_OK) {
if collateral_expired || result != sgx_ql_qv_result_t::SGX_QL_QV_RESULT_OK {
print!("Attestation failed: ");
if collateral_expired {