On a Azure Confidential VM running Ubuntu 22.04, what code is measured into each PCR register on the vTPM?

FrancisLam-1752 0 Reputation points
2023-05-09T20:43:02.76+00:00

I have launched and successfully received a valid guest attestation using the Microsoft Azure Attestation service (as documented here: https://learn.microsoft.com/en-us/azure/confidential-computing/guest-attestation-confidential-vms).

My question is what parts of the firmware, VM images, VM configuration are measured into which PCR registers on the vTPM. There does not seem to be any documentation on this even though it looks like on a VM using the Ubuntu 22.04 confidential image, PCRs 0-7, 10, 12 and 14 are used.

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,123 questions
{count} votes