For Confidential Containers on ACI, what key is AMD SEV/SNP attestation ID_KEY_DIGEST the SHA384 of?

Gram 0 Reputation points
2023-08-03T22:02:54.6966667+00:00

When a container is run via ACI's confidential VMs, a key is used as part of SNP_LAUNCH_FINISH to sign the measurement and policy. A digest of that key is put into ID_KEY_DIGEST and is accessible by requesting a SNP attestation report via /dev/sev-guest from within the confidential VM. At last look, this key digest is

ebeeeabce075eeaba3d9ea24d8495137a2877c0d20ac6ea73fc6d2f8aeb50de132150e0a0752664919bcebbf2e8c5807

Is this key accessible to clients, and is there a certificate chain from this key up to a long-lived Microsoft-controlled root key?

Azure Container Instances
Azure Container Instances
An Azure service that provides customers with a serverless container experience.
750 questions
Azure
Azure
A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.
1,243 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.