Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add ACA policy to ignore component revision within the Platform Cerificate #707

Open
iadgovuser26 opened this issue Feb 8, 2024 · 1 comment
Assignees
Labels
enhancement New feature or request server

Comments

@iadgovuser26
Copy link
Contributor

Within the ComponentIdentifier of the Platform Certificates is a componentRevision field. While an exact match should be required for most Supply Chain scenarios there are use cases in which the Platform Certificate may be used for system monitoring use cases which must accommodate for component firmware updates. Component revisions (e.g. System BIOS revision) get systematically updated and a verification of the component will currently fail.

Proposed ACA Policy addition:

  • Platform Credential Validation:
    * Ignore component revisions: Disabled

Default should be set to Disabled

@cyrus-dev cyrus-dev self-assigned this Mar 7, 2024
@cyrus-dev
Copy link
Contributor

This is also reference in #705

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request server
Projects
None yet
Development

No branches or pull requests

2 participants