Skip to content

6.0.0

@puiterwijk puiterwijk tagged this 24 Feb 14:16
This ensures we verify the EK and AIK we get from the agent before
trusting signatures by it.

Advisory: https://github.com/keylime/keylime/security/advisories/GHSA-78f8-6c68-375m
For details, see https://patrick.uiterwijk.org/blog/tpm2-attestation-keylime-vulnerability
Signed-off-by: Patrick Uiterwijk <[email protected]>
Signed-off-by: Michael Peters <[email protected]>
Assets 2
Loading