summaryrefslogtreecommitdiff
path: root/static/articles/attestation-compatibility-guide.html
diff options
context:
space:
mode:
authorDaniel Micay <danielmicay@gmail.com>2023-02-16 09:36:56 -0500
committerDaniel Micay <danielmicay@gmail.com>2023-02-16 09:36:56 -0500
commit94995232685b33e5906e12420ea7630eabbf2ee6 (patch)
treeaca0cb5fc62ad7c8ed8098a234c5ff435242d37b /static/articles/attestation-compatibility-guide.html
parent7ad211f93b34905f905f3f683b1cf5ccf200e85c (diff)
Auditor as example to use for hardware attestation
Diffstat (limited to 'static/articles/attestation-compatibility-guide.html')
-rw-r--r--static/articles/attestation-compatibility-guide.html9
1 files changed, 9 insertions, 0 deletions
diff --git a/static/articles/attestation-compatibility-guide.html b/static/articles/attestation-compatibility-guide.html
index 3284ae0f..05150de8 100644
--- a/static/articles/attestation-compatibility-guide.html
+++ b/static/articles/attestation-compatibility-guide.html
@@ -74,6 +74,15 @@
with hardware attestation and fall back to the Play Integrity API or do both and
accept either passing as success.</p>
+ <p>Our <a href="https://github.com/GrapheneOS/Auditor">MIT / Apache 2 licensed Auditor
+ app</a> can be used a reference implementation for verifying hardware-based
+ attestations. There are some subtleties in the verification process such as making
+ sure only the 2nd certificate in the chain (the one signing the certificate for the
+ key generated by your app) has an attestation extension to prevent making a fake
+ attestation by extending the chain. You can reuse our code and simply omit support for
+ an app generated attestation signing key (attest key) and the other pinning
+ support.</p>
+
<p>After verifying the signature of the attestation certificate chain and extracting
the attestation metadata, you can enforce that <code>verifiedBootState</code> is
either <code>Verified</code> or <code>SelfSigned</code>. For the