Skip to content

ACA Portal: Policy Page

The Policy page is used to provide configuration settings for attestation provisioning for the system.

Default Policy

The default for the ACA is to not check any credentials or attributes for TPM provisioning. This initial setting is intended to:

  1. Test the proper installation of HIRS, with no validation of supply chain credentials performed.
  2. Support TPM provisioning of systems that might not be delivered with supply chain credentials.

HIRS Policy Page

The recommended policy setting for Trusted Computing-based supply chain validation will require these policy settings to be set to enabled:

  • Endorsement Certificate Validation: Enabled
  • Platform Certificate Validation: Enabled
  • Platform Certificate Attribute Validation: Enabled
  • Firmware Validation: Enabled

Endorsement Validation

If Endorsement Certificate Validation is selected, the ACA will validate the Endorsement Certificate prior to issuing an Attestation Certificate. The default is ‘Disabled’.

Platform Validation

If Platform Certificate Validation is selected, the ACA will validate the Platform Certificate prior to issuing an Attestation Certificate. This option only validates the Certificate itself, not the attributes within the Platform Certificate. Endorsement Certificate Validation is required to be enabled prior to enabling this policy option. The default is ‘Disabled’.

Platform Attribute Validation

If Platform Attribute Certificate Validation is selected, the ACA will validate the Platform Certificate Attributes prior to issuing an Attestation Certificate. This option only validates the Certificate Attributes, not the Platform Certificate. Platform Certificate Validation is required to be enabled prior to enabling this policy option. The default is ‘Disabled’.

Ignore Component Revision

If Ignore Component Revision Attribute is selected, the ACA will ignore the revision field within a component identifier in a Platform Certificate.

Ignore PCIe VPD

If Ignore PCIE VPD Attribute is selected, the ACA will ignore VPD (Vital Product Data) data when validating Platform Certificate component identifiers that reference the PCIe-based Component Class Registry.

Firmware Validation

If Firmware Validation is selected, the ACA will validate firmware prior to issuing an Attestation Credential. The TCG-defined artifacts necessary for this validation are:

  • RIM
  • Event Log (log file produced by UEFI)
  • TPM Quote and PCR list
  • Platform Certificate issued by the OEM, System Integrator or Value-Added Reseller
  • Endorsement Credential linked to Platform Certificate
  • Certificate chain of the organization that produced the Endorsement Certificate
  • Certificate chain of the organization that produced the Platform Certificate
  • Certificate chain of the organization that produced the RIM

Firmware Validation is required to be enabled prior to enabling the following sub-category policy options:

Ignore IMA PCR

The IMA policy option refers to the IMA (Integrity Measurement Architecture) subsystem which is a Linux feature that utilizes PCR10. The Linux IMA mechanism captures a hash of individual files right before the Linux kernel processes them via system calls like execve() or mmap(), recording the software payloads currently driving user-space and kernel runtime environments.

If Ignore IMA PCR Entry is selected, this option will cause the ACA to ignore the IMA PCR Entry (skip evaluation of PCR10) prior to issuing an Attestation Certificate.

Ignore TBOOT PCRs

The TBOOT policy option refers to the TBOOT which is a Linux feature that utilizes PCR17+. If Ignore TBOOT PCRs Entry is selected, this option will cause the ACA to ignore the TBOOT PCRs Entry (skip evaluation of PCR17+) prior to issuing an Attestation Certificate.

Ignore GPT PCRs

If Ignore GPT PCRs Entry is selected, the ACA will ignore the GPT PCRs Entry (events of type EV_EFI_GPT_EVENT) prior to issuing an Attestation Certificate.

Ignore OS Events

If Ignore OS Events is selected, the ACA will ignore PCRs > 7 as well as PCR4 events that occur after the PCR4 event separator.

Ignore OS Events PXE Boot

If Ignore OS Events for PXE Boot is selected, the ACA will ignore events that are altered specifically during PXE Boot.

Generate Attestation Certificate

If selected, the ACA will conditionally generate an Attestation Certificate after a successful TPM provisioning.

Attestation Certificate Validity

If Attestation Certificate Validity period is selected, the ACA will have an Attestation Certificate Validity period of the input number of days. Generate Attestation Certificate is required to be enabled prior to enabling this option. Attestation Certificate Validity period being enabled automatically causes Attestation Certificate Renewal period to become enabled. If Attestation Certificate Renewal period is disabled, this will also disable Attestation Certificate Validity period.

Attestation Certificate Renewal

If Attestation Certificate Renewal period is selected, the ACA will renew the input n number of days before the Attestation Certificate’s ‘Not After’ validity date which has a default of 365 days. Generate Attestation Certificate is required to be enabled prior to enabling this option. Attestation Certificate Validity period being enabled automatically causes Attestation Certificate Renewal period to become enabled. If Attestation Certificate Validity period is disabled, this will also disable Attestation Certificate Renewal period.

Generate LDevID Certificate

If selected, the ACA will conditionally generate a Local Device ID (LDevID) certificate after a successful TPM provisioning.

Save Protobuf to ACA Log

If selected, the ACA will save protobuf data to its log.