Skip to content
veraisonPublic

About

A feature-rich tool for exploring CCA attestation

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

2 watching

Forks

Latest commit

 

History

5 Commits

Folders and files

ccaguest

This repository contains a Rust-based command-line tool for the following ARM CCA attestation features:

  • Evidence generation
  • Evidence verification in remote and local mode
  • Endorsements fetch
  • Policy fetch and submission (TODO)
  • Evidence, EAR, and endorsements display

Command Tree

Command Tree Detailed explanation for each subcommand is in UserGuide.md

Software Architecture

A summary of software architecture is given below.

Remote verification

Verify Remote

The above diagram is simplified down to the most essential interactions. ccaguest connects to Veraison's remote verification service and establishes a challenge response session using rust-apiclient. Using the nonce received from the remote verifier, it requests the Realm VM for an attestation report using rust-regl and sends it to the verifier.

Once the attestaion evidence has been verified, the received attestation results (EAR) is validated and shown to the relying party. It can also be saved to an output file and displayed later using the ccaguest display subcommand.

Local verification

Verify local

ccaguest uses cover to locally verify an attestation report without connecting to a remote verification service. The endorsements can be queried from a remote CoSERV service using rust-apiclient.

Note

While using the tsm backend for attester, sudo permissions are required for ccaguest. tsm backend uses linux kernel's configfs-tsm-report ABI to fetch the evidence. Hence the process must have sufficient privilege to write to configfs, which can be usually done by escalating the privilege using sudo. It can also be used within a non-realm VM and the attestation evidence can be retrieved from a Realm VM using regl's ratsd backend without sudo permissions.

Note

The CoSERV service used during local verification must support collected result type.

Note

The base url must have empty path segment, e.g. "http://address:port", ""https://veraison.example or "https://veraison.example/" but not "https://veraison.example/foo".

How to Build

This is a Rust-based CLI tool, so user need to install Rust first.

Build the project:

cargo build

The binary executable will be generated at target/debug/ccaguest.

Test the project:

cargo test

Installation

Install the tool from the repository root directory:

cargo install --path . --locked

After installation, the ccaguest binary will be available on your system PATH.

Quick Start

Sample tokens are available in the test/ directory.

Display an example CCA token:

$ ccaguest display evidence -f test/cbor/ccatoken.cbor -p
{
  "cca-platform-token": {
    "cca-platform-profile": "tag:arm.com,2023:cca_platform#1.0.0",
    "cca-platform-challenge": "DSLgiphGkFhIYxgoNIm9s28J2+/rGGTfQz+m5U6i1xE=",
    ...
  },
  "cca-realm-delegated-token": {
    "cca-realm-profile": "tag:arm.com,2023:realm#1.0.0",
    "cca-realm-challenge": "bobW2XzHE7xt1D285JGmtAMRwCeov4WjnaY+nORMEyqKEZ0pb65qaZnpvz5EcbDOASRdiJQkwx6JeTs7HWsVBA==",
    ...
  }
}
[2026-07-22T10:56:08Z INFO  ccaguest] done.

List all available commands:

$ ccaguest --help

About

A feature-rich tool for exploring CCA attestation

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages