Skip to content

attested-mTLS v0.2.0 — seal-sync HPKE v3

Latest

Choose a tag to compare

@weijiguo weijiguo released this 30 Aug 14:19
· 5 commits to main since this release

Security

Closes the protocol implementation portion of TeeChat RB-54:

  • replaces plaintext key export with RFC 9180 HPKE (X25519/HKDF-SHA256/ChaCha20-Poly1305)
  • binds nonce, recipient key, TLS channel SPKI, and both identities into mutual TEE evidence
  • adds production SEV-SNP VCEK/ARK/ASK verification and strict measurement allowlists
  • makes production servers v3-only and rejects legacy plaintext endpoints
  • makes pre-export audit emission fail closed and zeroizes plaintext containers

Production deployment and replacement key ceremonies are tracked separately in TeeChat.