Define acceptance before verification
At minimum, specify:- acceptable Intel TDX verification status and advisory policy
- rejection of quotes with TDX debug mode enabled (bit 0 of
TD_ATTRIBUTESin the verified quote) - required signer algorithm and identity matching rules
- whether GPU evidence is required and the accepted verdict
- accepted workload measurements and configuration rules
- trusted image repositories, build identities, workflows, refs, and source revisions
- maximum acceptable evidence age
- whether TLS endpoint binding and response signatures are required
Treat required checks as fail-closed
When a required check is missing, unavailable, malformed, mismatched, or fails verification, the result is unverified. Do not replace it with a report for a different signer, certificate, request, or model instance.Load balancing and rotations
The same hostname can be served by more than one attested instance. A report is not evidence for a later request merely because it came from the same hostname.- For TLS, obtain the peer certificate and report on the same connection.
- For a
provider_teeresponse signature, verify and retain every returned model-attestation candidate before the completion. Accept the signature only when its signer identity and algorithm match exactly one verified candidate. A report fetched after the completion cannot replace that preflight check. - Refresh preflight evidence before a later request after a signer, certificate, configuration, deployment, or policy-age change.