feat(policy): add CoRIM mappings and optional servTD identity - #1037
haitaohuang wants to merge 15 commits into
Conversation
0b153d3 to
d86b127
Compare
There was a problem hiding this comment.
🟡 Changes recommended
One or more issues must be addressed before approval.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Adds feature-gated CoRIM TCB mappings, optional servTD identity, signer-anchor enrollment, CRL handling, and peer endorsement transport.
Changes:
- Adds COSE/x5chain CoRIM verification and RTMR1 binding.
- Updates policy and collateral generators for optional identity, CRLs, and CoRIM-only policies.
- Extends measurement, migration transport, and cumulative mapping tooling.
File summaries
| File | Description |
|---|---|
| xtask/src/build.rs | Updated as part of this pull request. |
| tools/servtd-collateral-generator/src/main.rs | Updated as part of this pull request. |
| tools/servtd-collateral-generator/src/build.rs | Updated as part of this pull request. |
| tools/servtd-collateral-generator/readme.md | Updated as part of this pull request. |
| tools/migtd-policy-generator/src/policy_v2.rs | Updated as part of this pull request. |
| tools/migtd-policy-generator/src/main.rs | Updated as part of this pull request. |
| tools/migtd-hash/src/main.rs | Updated as part of this pull request. |
| tools/migtd-hash/src/lib.rs | Updated as part of this pull request. |
| tools/migtd-hash/Cargo.toml | Updated as part of this pull request. |
| src/policy/test/policy_v2/tcb_mapping.json | Updated as part of this pull request. |
| src/policy/test/policy_v2/servtd_collateral.json | Updated as part of this pull request. |
| src/policy/test/policy_v2/cert_chain/policy_issuer_chain.pem | Updated as part of this pull request. |
| src/policy/src/v2/servtd_corim.rs | Updated as part of this pull request. |
| src/policy/src/v2/servtd_collateral.rs | Updated as part of this pull request. |
| src/policy/src/v2/mod.rs | Updated as part of this pull request. |
| src/policy/src/v2/measurement.rs | Updated as part of this pull request. |
| src/policy/src/lib.rs | Updated as part of this pull request. |
| src/policy/Cargo.toml | Updated as part of this pull request. |
| src/migtd/src/spdm/spdm_rsp.rs | Updated as part of this pull request. |
| src/migtd/src/ratls/server_client.rs | Updated as part of this pull request. |
| src/migtd/src/migration/session.rs | Updated as part of this pull request. |
| src/migtd/src/migration/rebinding.rs | Updated as part of this pull request. |
| src/migtd/src/migration/pre_session_data.rs | Updated as part of this pull request. |
| src/migtd/src/migration/mod.rs | Updated as part of this pull request. |
| src/migtd/src/lib.rs | Updated as part of this pull request. |
| src/migtd/src/event_log.rs | Updated as part of this pull request. |
| src/migtd/src/config.rs | Updated as part of this pull request. |
| src/migtd/src/bin/migtd/main.rs | Updated as part of this pull request. |
| src/migtd/Cargo.toml | Updated as part of this pull request. |
| src/crypto/src/lib.rs | Updated as part of this pull request. |
| src/crypto/src/crl.rs | Updated as part of this pull request. |
| sh_script/build_policy_v2.sh | Updated as part of this pull request. |
| sh_script/build_AzCVMEmu_policy_and_test.sh | Updated as part of this pull request. |
| sh_script/Azure/build_azure_mock_test.sh | Updated as part of this pull request. |
| deps/td-shim-AzCVMEmu/tdx-tdcall/src/tdx_emu.rs | Updated as part of this pull request. |
| config/templates/td_identity.json | Updated as part of this pull request. |
| config/templates/td_identity_signed.json | Updated as part of this pull request. |
| config/templates/tcb_mapping.json | Updated as part of this pull request. |
| config/templates/tcb_mapping_signed.json | Updated as part of this pull request. |
| config/templates/servtd_collateral.json | Updated as part of this pull request. |
| config/templates/policy_issuer_chain.pem | Updated as part of this pull request. |
| config/AzCVMEmu/tcb_mapping.json | Updated as part of this pull request. |
| Cargo.lock | Updated as part of this pull request. |
Review details
Suppressed comments (8)
sh_script/build_policy_v2.sh:25
- This new command invocation now requires a second positional input, but the existing documented command
bash sh_script/build_policy_v2.sh [preprod/prod]supplies only the environment (doc/policy_v2.md:126), so it exits before generating a policy. Either preserve a default cumulative mapping path or update the documented/release invocation in the same change.
if [[ -z "$tcb_mapping_file" ]]; then
echo "Usage: $0 <pre-production|production> <cumulative-tcb-mapping.json>" >&2
exit 1
src/migtd/src/config.rs:126
- The new anchor/CoRIM accessors read GUIDs that the AzCVMEmu firmware-volume implementation does not recognize: its
get_file_from_fvonly handles policy, root-CA, and legacy policy-issuer-chain GUIDs, and its file-based initialization has no anchor or CoRIM loaders. Consequently aservtd_corim/direct-anchor build cannot initialize under the existing emulation feature even thoughconfignow selects these paths. Add emulation support for these enrolled files or reject this configuration explicitly.
/// Read the signed ServTD TCB-mapping CoRIM (`COSE_Sign1`) from the CFV, if
/// enrolled. Returns `None` when no CoRIM was enrolled (the policy then falls
/// back to the JSON `servtdCollateral` mapping). This file is deliberately not
/// measured; see [`MIGTD_SERVTD_CORIM_FFS_GUID`].
#[cfg(feature = "servtd_corim")]
pub fn get_servtd_corim() -> Option<&'static [u8]> {
let cfv = get_config_volume();
fv::get_file_from_fv(cfv, pi::fv::FV_FILETYPE_RAW, MIGTD_SERVTD_CORIM_FFS_GUID)
src/migtd/src/mig_policy.rs:483
- Because TD Identity is optional, a peer that only needs SVN evaluation may legitimately omit
servtdIdentityeven when the local policy includes it. This one-sided-chain branch rejects that valid SVN-only pairing before policy evaluation; date/status rules already fail closed later when peer identity data is absent. Only cross-check the identity signer chains when both artifacts are present.
match (
local_policy.servtd_identity_issuer_chain.as_deref(),
verified_policy.servtd_identity_issuer_chain.as_deref(),
) {
(Some(local_identity_chain), Some(peer_identity_chain)) => {
crypto::validate_peer_cert_chain(
src/policy/src/v2/policy.rs:399
- When
servtdTcbMappingIssuerChainis omitted, the new collateral-generator CLI documents that the identity chain is the compatibility fallback, and the collateral type likewise describes older policies using the identity chain for both artifacts. This branch instead parses the CFV issuer input; a mapping signed by the identity chain fails whenever those chains differ. Preferservtd_identity_issuer_chainbefore falling back to the outer CFV chain.
src/policy/src/v2/servtd_corim.rs:264 - This only accepts the untagged
Bytesinstance, but the CoRIM contract documented above is#6.560("migration-td"). A standard producer encoding the required tagged instance will be rejected here, so its signed mapping can never be used. Match the corim crate's representation of tag 560 (and make the test fixture emit that wire form) instead of accepting only a raw bstr.
tools/migtd-hash/src/lib.rs:266 Measurementsexplicitly accepts both the canonicaltdinfo_hashand legacytdinfoHashspellings, but this release-tool updater only readstdinfo_hash. Running the new cumulative-update flow on a legacy camelCase mapping—which the runtime still supports—fails with a missing-field error instead of preserving/updating the history. Read the alias here as well.
xtask/src/build.rs:226- This relaxed validation permits
--signer-anchorwithout--policy-issuer-chainor--servtd-corim, but the enrollment branch then passes the raw 48-byte anchor toRawPolicyData::verify. A JSON policy whose mapping has no explicitservtdTcbMappingIssuerChainfalls back to that raw anchor as PEM and fails during startup, so the CLI can produce an unusable image. Reject this combination or retain a PEM source for JSON collateral verification.
xtask/src/build.rs:230 --signer-anchoris silently accepted in legacy mode, butenrollonly consumes it inside theself.policy_v2branch. A caller who supplies the new option without--policy-v2therefore gets a legacy image with no enrolled anchor and no diagnostic. Reject this option alongside--servtd-corimwhen policy v2 is disabled.
- Files reviewed: 44/49 changed files
- Comments generated: 5
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
🟡 Changes recommended
Unresolved critical and moderate findings must be addressed before approval.
Get a fresh assessment by requesting another Copilot review.
Review details
Suppressed comments (14)
sh_script/build_policy_v2.sh:25
- This new guard makes the existing documented invocation
bash sh_script/build_policy_v2.sh [preprod/prod]fail whenever the second argument is omitted, whiledoc/policy_v2.mdstill instructs that command. Either preserve a default mapping source or update the documented command and all callers to pass the required cumulative mapping.
if [[ -z "$tcb_mapping_file" ]]; then
echo "Usage: $0 <pre-production|production> <cumulative-tcb-mapping.json>" >&2
exit 1
src/migtd/src/mig_policy.rs:463
- This one-sided check rejects JSON↔CoRIM peers before the peer CoRIM is attached: a JSON policy has a mapping issuer chain, while a CoRIM-only policy necessarily has none. The signer-anchor comparison above already binds both policies to the same measured root/subject, so this prevents the advertised interchangeable formats from migrating together; compare JSON chains only when both peers use that format.
// Cross-check the JSON mapping issuer chains when both sides ship one
// (defense-in-depth; the signer_anchor equality above already binds the
// signer). Absent on both sides (CoRIM-only) is fine; one-sided fails.
match (
local_policy.servtd_tcb_mapping_issuer_chain.as_deref(),
src/policy/src/v2/policy.rs:399
- When
--signer-anchoris used with JSONservtdCollateralthat omitsservtdTcbMappingIssuerChain,RawPolicyData::verifyreceives the raw 48-byte anchor asissuer_chainand the fallback at line 397 failsfrom_utf8before the mapping can be verified. The image build succeeds but policy initialization fails; reject this combination or require/propagate an explicit mapping PEM for direct-anchor builds.
src/policy/src/v2/servtd_corim.rs:264 - The accepted environment does not match the wire form documented above (
instance = #6.560("migration-td")): this branch accepts onlyInstanceIdChoice::Bytes. A CoRIM carrying the tagged text instance from the proposal will therefore decode successfully but every CES lookup will be ignored, causing anUnqualifiedMigTdInfofailure. Handle the text choice (or use the exact producer encoding) and add a fixture test with encoded CoRIM bytes.
src/policy/src/v2/servtd_corim.rs:155 svn_for_hashreturns the first matching CES record, so a signed CoRIM containing duplicate entries for oneSERVTD_INFO_HASHwith different SVNs is accepted and the result depends on CBOR/order. The mapping contract is one hash to one SVN (and the JSON updater already rejects conflicting duplicates); reject conflicting matches during decode/lookup instead of silently selecting one.
src/policy/src/v2/servtd_corim.rs:155- The required
reference-tripleis never consulted: lookup walks onlyconditional_endorsement_series, so a signed CoRIM containing a CES for a hash but no corresponding reference digest is accepted even though the documented mapping consists of both triples. Validate the reference/CES relationship (or reject missing reference triples) during CoRIM decoding so malformed mapping documents cannot be treated as valid endorsements.
tools/migtd-hash/src/lib.rs:264 - This updater only reads
tdinfo_hash, although the runtimeMeasurementstype explicitly acceptstdinfoHashas a legacy alias. Updating an older v2 mapping that still uses the camelCase spelling therefore fails instead of preserving its history; accept both spellings here (or deserialize through the shared type).
tools/migtd-hash/src/lib.rs:299 - This current-entry insertion silently overwrites an existing mapping for the same
tdinfo_hashwhen the new SVN differs. That can rewrite a historical release's SVN in the cumulative authority file and undermine the intended immutable hash-to-SVN history; reject a conflicting current entry instead of replacing it.
tools/migtd-hash/src/main.rs:201 tdinfo_hash_v2isNoneunless--policy-v2is set, butmainunconditionally reaches theexpectbelow when this flag is used in v1 mode, so an invalid CLI combination panics instead of producing a controlled argument error. Addrequires = "policy_v2"to this option (or validate it before the calculation).
tools/migtd-policy-generator/src/policy_v2.rs:35- The documented CoRIM-only mode says omitting
--servtd-collateralproduces noservtdCollateral, but this branch leaves any pre-existing field from the base policy untouched. A reused/template policy can therefore retain stale JSON mapping/identity data, changing the measured schema and potentially causing initialization or peer-format failures. Remove the field explicitly in theelsebranch.
tools/servtd-collateral-generator/readme.md:22 - Removing
--mapping-chainchanges the generated collateral from explicitly carrying the chain that verifies the mapping to relying on the later CFV policy issuer chain. With the example's separateidentity_issuer_chain.pem(or any independently signed mapping), the resulting policy will fail mapping verification. Keep the explicit mapping-chain argument here, or update the example to show that the mapping must be signed by the CFV policy issuer.
tools/servtd-collateral-generator/src/build.rs:39 - When
--mapping-chainis omitted, the CLI help and the updated README say the identity chain is reused, but this expression only reads the explicitly supplied mapping chain. With the documented command,servtdTcbMappingIssuerChainis omitted and runtime falls back to the CFV policy issuer chain; if the mapping was signed by the identity chain (or another explicit mapping signer), the generated collateral cannot be verified. Fall back toidentity_chain_pathhere, or require--mapping-chainwhen no identity chain is available.
tools/servtd-collateral-generator/src/main.rs:34 - This option description says the identity chain is used when
--mapping-chainis omitted, but the implementation leavesservtdTcbMappingIssuerChainabsent; runtime then falls back to the CFV policy issuer chain, notidentity_chain_path. A caller that signs the mapping with the identity chain will therefore produce collateral that fails verification unless the chains happen to match. Describe the actual policy-chain fallback (or implement the documented identity-chain fallback).
xtask/src/build.rs:230 --signer-anchoris silently ignored when--policy-v2is not set: the non-v2 build path never enrolls this file, whilecheck_argumentsrejects only--servtd-corim. This makes a successful build differ from the requested CFV contents; reject the anchor option in the same branch as the CoRIM option.
- Files reviewed: 44/49 changed files
- Comments generated: 1
- Review effort level: Lite
7ca8908 to
a9846da
Compare
|
Comment from Claude:
|
|
Comment from Claude:
|
a9846da to
ca7ba83
Compare
Require --mapping-chain even when an identity chain is supplied, and always embed servtdTcbMappingIssuerChain in generated collateral. This avoids the ambiguous omission that selected the CFV policy chain at runtime rather than the independently supplied identity chain. Pass the actual mapping signer's chain from each policy-generation caller, including independent signer-rotation variants, and document the explicit input contract. Keep identity optional with its separate chain and preserve existing runtime verification, enrollment modes, and legacy policy compatibility. Link: intel#1037 (comment) Signed-off-by: Haitao Huang <haitaohuang@microsoft.com> Assisted-by: GitHub Copilot CLI:gpt-6-astra
|
cargo deny was new dep vul. |
Yes. Will look into that. Please focus on review feedback first. BTW: I still did not see anyone from MSFT to review and approve... |
008ff16 to
48e8c9e
Compare
Use SHA-384 over the complete unmasked TDINFO as the Policy v2 mapping key. Canonicalize policyData once with only the circular mapping removed so runtime verification and offline tooling extend identical RTMR2 bytes. Verify the signed mapping with the RTMR1-bound policy issuer chain, remove the separate mapping chain and obsolete mapping identity fields, and ignore the legacy outer policy signature as required by the proposal. Resolve the initial SVN through the source's authenticated JSON mapping and take its current SVN from the authenticated quote or TDREPORT evaluation. This allows an older destination to accept a newer source release without predicting its hash. Fail closed on missing authenticated SVN evidence and prevent the SERVTD_EXT current hash from overriding it. Signed-off-by: Haitao Huang <haitaohuang@microsoft.com> Assisted-by: GitHub Copilot CLI:GPT-5.6 Sol Assisted-by: GitHub Copilot CLI:gpt-6-astra
Carry authenticated SERVTD_EXT continuity evidence through migration and rebinding. Bind the peer policy issuer chain to attested RTMR1, reject lookup misses or SVN rollback, and fail closed when SERVTD_ATTR masking makes the endorsed unmasked hashes inapplicable. Match policy-v2 migration and rebinding request headers to their four encoded elements while retaining the five-element policy-v1 migration format. Signed-off-by: Haitao Huang <haitaohuang@microsoft.com> Assisted-by: GitHub Copilot CLI:GPT-5.6 Sol Assisted-by: GitHub Copilot CLI:gpt-6-astra
Retain authority-maintained hash history when adding a release, allow multiple hashes at one SVN, and reject conflicting duplicate assignments. Emit deterministic mapping bytes and validate signed mappings before use. Update the policy-v2 guide and mapping-update example for the cumulative workflow, including the required --mapping-isvsvn argument. Document mapping signer authority, trust assumptions, and the distinction between release-SVN continuity and independent policy-SVN ordering. Signed-off-by: Haitao Huang <haitaohuang@microsoft.com> Assisted-by: GitHub Copilot CLI:GPT-5.6 Sol Assisted-by: GitHub Copilot CLI:gpt-6-astra
Consume the signed identity used to build the measured release instead of re-signing it after recording tdinfo_hash. Reject any non-mapping policy change before replacing the final policy outputs, including identity, issuer-chain, and platform collateral changes. Document preparation before measurement, immutable release inputs, and a final image hash comparison against the recorded endorsement. Assisted-by: GitHub Copilot CLI:gpt-6-astra Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Remove check_engine_not_older and its dedicated test because runtime continuity uses the MigTD helper instead. Preserve the equal-SVN assertion in the live continuity tests alongside the existing upgrade, downgrade, and lookup-failure coverage. Signed-off-by: Haitao Huang <haitaohuang@microsoft.com> Assisted-by: GitHub Copilot CLI:gpt-6-astra
Measure the policy signer as a stable root-certificate plus leaf-subject anchor in both runtime and offline hashing. Require authenticated, numbered servTD CRLs so omission cannot bypass signer-chain enforcement at initialization or peer validation, and support a monotonic servtd CRL policy floor.\n\nPort only the proposal-specific implementation from ms/integration while retaining tcbmapping's existing JSON mapping and identity model. Assisted-by: GitHub Copilot CLI:GPT-5.6 Sol Signed-off-by: Haitao Huang <haitaohuang@microsoft.com> Assisted-by: GitHub Copilot CLI:gpt-6-astra
Exercise signed empty CRLs, revoked leaf and intermediate certificates, issuer mismatches, invalid signatures, and CA constraints. Cover policy rejection and peer checks against verifier-owned revocation state, including a rotated local policy signer. Use public fixtures without retaining private keys. Extract the existing peer revocation block without changing its ordering or logging so tests can use independently verified policies without global state. Add serde_json only as a dev dependency for test policy construction. Signed-off-by: Haitao Huang <haitaohuang@microsoft.com> Assisted-by: GitHub Copilot CLI:gpt-6-astra
Accept only complete, direct, issuer-wide CRLs signed by the signing leaf\x27s immediate non-root CA with explicit cRLSign permission. Scope serial lookups to the signing leaf, authenticate peer CRL metadata under the same issuer as the local authoritative CRL, and keep peer revocation entries out of local decisions. Reject delta, partitioned, indirect, reason-scoped, malformed and unsupported critical inputs while retaining non-critical Microsoft metadata. Leave Intel platform CRL parsing unrestricted. Cover signed negative fixtures and update mock issuers and the supported-profile documentation. Assisted-by: GitHub Copilot CLI:gpt-6-astra Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Add feature-gated signed CoRIM TCB mappings, authenticated peer transport, and direct signer-anchor enrollment. Keep JSON mappings as the default, support optional simplified servTD identity, and fail closed for date or status rules when identity data is unavailable. Co-authored-by: Haitao Huang <haitaohuang@microsoft.com> Signed-off-by: Haitao Huang <haitaohuang@microsoft.com> Assisted-by: GitHub Copilot CLI:GPT-5.6 Sol Assisted-by: GitHub Copilot CLI:gpt-6-astra
Check the actual policy before building an anchor-only configuration. Require an embedded mapping chain for retained JSON collateral, or a CoRIM artifact when JSON collateral is absent, and retain the mandatory signer CRL. Reject invalid anchor sizes and missing or empty CoRIM files early. Document anchor precedence without imposing a CoRIM requirement on valid JSON-only configurations. Signed-off-by: Haitao Huang <haitaohuang@microsoft.com> Assisted-by: GitHub Copilot CLI:gpt-6-astra
Expose signer anchors and signed CoRIM under their firmware GUIDs in AzCVMEmu. Load direct anchors as a PEM alternative and route shared or per-peer artifacts through the launcher while preserving JSON mode and rejecting unsupported or invalid inputs explicitly. Add public signed fixtures and regressions for artifact routing, signer binding, local revocation, and TLS/SPDM CoRIM emulation with optional JSON identity. Exercise startup errors before VMM logging is available. Signed-off-by: Haitao Huang <haitaohuang@microsoft.com> Assisted-by: GitHub Copilot CLI:gpt-6-astra
The full, unmasked tdinfo_hash includes MROWNER and MROWNERCONFIG. Authentication requires a matching hash in an authenticated JSON or CoRIM TCB mapping whose signer is bound to the RTMR1-measured trust anchor. That endorsement already authorizes the exact owner-field values together with the rest of TDINFO. Under this endorsement model, rechecking MROWNER against the policy signer's leaf-key hash and MROWNERCONFIG against an encoding of policySvn adds no further authorization. It only imposes legacy encodings on already-endorsed fields. Changing either field changes the hash that must be endorsed; no owner-field coverage is lost. Document this rationale for retiring verify_own_tdinfo, rather than treating RTMR measurements as an assertion of the old equalities. Explain that RTMR1 binds signer identity, RTMR2 measures canonical policy data including policySvn, and the authenticated mapping supplies the distinct release isvsvn. Apply the model to PEM and direct-anchor enrollment without forcing leaf-key rotation into TD-creation fields. Remove get_policy_signer_key_hash, which has no remaining callers. Retain the public-key extraction used by certificate and signature verification. Signed-off-by: Haitao Huang <haitaohuang@microsoft.com> Assisted-by: GitHub Copilot CLI:gpt-6-astra
RawServtdTcbMapping::verify_signature stopped validating the deserialized mapping, so a valid signature could authenticate malformed TDINFO hashes or conflicting SVNs for the same hash. Signature authenticity does not establish that the endorsed mapping is structurally valid or unambiguous. Restore TdTcbMapping::validate and call it after signature verification and deserialization. Reject invalid hex, hashes other than 48 bytes, and case-insensitive duplicate hashes with different SVNs. Preserve the previous acceptance of identical hash/SVN duplicates. Cover malformed encodings and lengths, conflicting and identical duplicates, and a correctly signed conflicting mapping whose signature is independently verified by the regression. Retain only the public fixture chain and signed payload; its temporary signing keys are not included. Document the restored JSON mapping requirements. Signed-off-by: Haitao Huang <haitaohuang@microsoft.com> Assisted-by: GitHub Copilot CLI:gpt-6-astra
Require --mapping-chain even when an identity chain is supplied, and always embed servtdTcbMappingIssuerChain in generated collateral. This avoids the ambiguous omission that selected the CFV policy chain at runtime rather than the independently supplied identity chain. Pass the actual mapping signer's chain from each policy-generation caller, including independent signer-rotation variants, and document the explicit input contract. Keep identity optional with its separate chain and preserve existing runtime verification, enrollment modes, and legacy policy compatibility. Link: intel#1037 (comment) Signed-off-by: Haitao Huang <haitaohuang@microsoft.com> Assisted-by: GitHub Copilot CLI:gpt-6-astra
Regenerate signed CoRIM and optional JSON fixtures with a leaf/intermediate/root chain and intermediate-issued complete CRLs. Preserve the endorsed TDINFO hash and SVN and verify peer CRL metadata only after the authenticated COSE signer chain is attached. Keep local revocations authoritative even when a delivered peer CRL revokes its own signer, reject unauthenticated peer CRL metadata, and document the mapping-chain measurement exclusion used by finalization. Assisted-by: GitHub Copilot CLI:gpt-6-astra Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
48e8c9e to
2a52dc2
Compare
Summary
This is a stacked continuation of #1035 and #1032. The new commit in this PR implements the CoRIM TCB-mapping and optional servTD Identity proposals tracked in #929 and #930.
COSE_Sign1ES384/ESP384 signatures and RFC 9360x5chain, reject unsupported time claims, and bind the signer to the RTMR1 root-certificate plus leaf-subject anchor from feat(policy): add stable RTMR1 signer anchor and revocation #1035;No documentation, test-fixture, workflow, or integration-script changes are included.
Validation
servtd_corimenabled;Follow-up
The remaining future work is the release-tooling and coverage work described in #1032: independent policy/mapping/identity signer-rotation coverage and stronger two-phase measurement-generation/hash-stability checks.