SVSM draft specification

Tom Lendacky <[email protected]> Mon, 30 Jun 2025 11:36:18 -0500
Newsgroups dev.linux.lists.coconut-svsm
Message-ID <[email protected]>
Attached is a draft specification with the following changes:

  - New single service extended attestation request
  - vTPM service update for single service extended attestation request
  - UEFI Management Mode service
    - Needs references to the request/response formats
  - Placeholder for the APIC emulation service

I just noticed that Dionna is now looking instead at adding a new
manifest version that would return a list of the various forms of the
storage and signing keys. This would eliminate any kernel changes as the
caller would now just request the new manifest version in the attest
single service request.

I would prefer this as it would eliminate the need for the single
service extended attestation request and support for that within each
service. For now, this draft specification has the original changes
requested. Please review at least for the UEFI MM service, if the
direction is to move to a new vTPM manifest version.

Thanks,
Tom
SVSM-Draft-v1.01.pdf (application/pdf, 739.3 KB) - not displayed