Skip to content

Check the binding of the server certificate with the sgx quote#679

Merged
henrysun007 merged 1 commit intoapache:masterfrom
henrysun007:fix-python-sdk
Mar 23, 2023
Merged

Check the binding of the server certificate with the sgx quote#679
henrysun007 merged 1 commit intoapache:masterfrom
henrysun007:fix-python-sdk

Conversation

@henrysun007
Copy link
Contributor

The fix is reported from https://github.com/mithril-security/poison-tea.

Description

Fix an attestation bypass attack reported from https://github.com/mithril-security/poison-tea.

Fixes # (issue)

Type of change (select or add applied and delete the others)

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • API change with a documentation update
  • Additional test coverage
  • Code cleanup or just sync with upstream third-party crates

How has this been tested?

Checklist

  • Fork the repo and create your branch from master.
  • If you've added code that should be tested, add tests.
  • If you've changed APIs, update the documentation.
  • Ensure the tests pass (see CI results).
  • Make sure your code lints/format.

@henrysun007 henrysun007 requested a review from mssun March 23, 2023 03:12
Copy link
Contributor

@AI-Memory AI-Memory left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks.

@henrysun007 henrysun007 merged commit 1c42f6c into apache:master Mar 23, 2023
@henrysun007 henrysun007 deleted the fix-python-sdk branch March 23, 2023 05:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants