Skip to content

Switch proxy to use nested attested TLS protocol#152

Open
ameba23 wants to merge 9 commits intopeg/use-attestation-crate-from-new-repofrom
peg/use-nested-attested-tls
Open

Switch proxy to use nested attested TLS protocol#152
ameba23 wants to merge 9 commits intopeg/use-attestation-crate-from-new-repofrom
peg/use-nested-attested-tls

Conversation

@ameba23
Copy link
Collaborator

@ameba23 ameba23 commented Mar 17, 2026

This switches the HTTP proxy to use the new nested attested TLS protocol.

Currently this means we no longer include measurements in HTTP headers, as the verifier does not expose them. We may be able to come up with a workaround for this later.

TODO:

  • Test with a deployment
  • ALPN - change the protocol name to indicate nested TLS? Maybe this should be an issue for the attested-tls repo.

TODO in followups:

  • Make configurable nested tls or inner session only.
  • Also offer both (nested and non-nested) on different ports

@ameba23 ameba23 marked this pull request as draft March 17, 2026 10:49
@ameba23 ameba23 marked this pull request as ready for review March 18, 2026 08:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant