Skip to content

Verify the VBS enclave key binding on the async attestation path - #4798

Open
virzak wants to merge 1 commit into
dotnet:mainfrom
virzak:dev/automation/vbs-async-key-binding
Open

virzak wants to merge 1 commit into
dotnet:mainfrom
virzak:dev/automation/vbs-async-key-binding

Conversation

@virzak

@virzak virzak commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

CreateEnclaveSessionCoreAsync derives the session secret without calling VerifyEnclavePublicKeyBinding. The check was added to the sync path in #4532, and the async path added in #4541 doesn't call it. Nothing calls the async path yet, so no release is affected. @cheenamalhotra for context, as this is your async enclave work.

The check now runs inside GetSharedSecret, so neither path can derive a secret from a key the signed report doesn't commit to.

Testing

  • New GetSharedSecret_UnboundKey_Throws: rejects an unbound key before using the Diffie-Hellman inputs. Fails without the fix.
  • Enclave unit tests pass on net8.0 and net462.
  • Not added: an end-to-end async test, which needs a signed HGS health report and enclave report fixture.

@virzak
virzak requested a review from a team as a code owner October 7, 2026 03:33
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: To triage

Development

Successfully merging this pull request may close these issues.

1 participant