Skip To Main Content
Support Knowledge Base

Is There a Mechanism to Provision Secrets to an Enclave after Quote has been Verified using Intel® Software Guard Extensions (Intel® SGX) Datacenter Attestation Primitives (DCAP)?

Content Type: Product Information & Documentation   |   Article ID: 000087699   |   Last Reviewed: 09/25/2021

Description

Unable to determine how to provision secrets from the service provider to the enclave after the quote has been verified.

Resolution

For Intel SGX DCAP*, Intel provides the QuoteGeneration* and QuoteVerification* components and leaves it up to the solution developer to choose their own mechanism for exchanging secrets. Most developers use  Transport Layer Security (TLS) terminating inside the enclave, but there are other ways it could be done.

Related Products

This article applies to 1 products.