QHx Attestor
Introduction to QHx Attestor
Section titled “Introduction to QHx Attestor”QHx Attestor is a core component of QHx’s admission control infrastructure, and is used to determine whether to issue a cryptographic identity to a node or workload seeking to join a QHx cluster. Nodes generate cryptographic proof of their identity in an attestation process, and the QHx attestation infrastructure verifies this proof before authorizing issuance of node or workload identities.
This process can take advantage of hardware-level remote attestation functionality such as that provided by TPM v2.0-compliant modules, which allows the cluster admission process to confirm the identity not just of the node, but its operating system, firmware, and underlying hardware.
Architecture
Section titled “Architecture”QHx Attestor is integrated into QHx’s PKI infrastructure and runs in two roles:
-
The Agent role runs on each node, and produces attestation evidence to submit to the QHx Attestor Server.
-
The Server role runs as part of the QHx control plane and cryptographically verifies attestation evidence produced by the agent before authorizing issuance of a credential identifying a node or workload.
QHx Attestor supports attestation based on hardware platforms incorporating TPM v2.0-compliant security modules, and can perform remote attestation based on quoted PCR values.
QHx Attestor is an internal and integrated component of QHx and never requires direct installation, configuration or maintenance by users.
Stages
Section titled “Stages”The attestation process runs as follows:
-
The node-local QHx PKI Agent invokes the QHx Attestor in the agent role to produce an attestation.
-
QHx Attestor queries system evidence such as TPM quotes, endorsement keys and other data. A TPM produces a signed attestation of system state.
-
QHx Attestor returns this attestation to the node-local QHx PKI Agent, which passes it on to the QHx PKI Server in the QHx control plane.
-
The QHx PKI server invokes the QHx Attestor in the server role to verify the attestation provided by the node.
-
The QHx Attestor in the server role cryptographically verifies the node’s attestation data against known trusted hardware roots of trust and trusted system configuration values.
-
The QHx PKI server issues a cryptographic identity if, and only if, the QHx Attestor indicates that verification of the attestation data is successful and proved the identity of the node seeking admission.
-
The trusted node identity is then used as the foundation for subsequent attestation of individual workloads on the given node.
Prerequisites
Section titled “Prerequisites”QHx Attestor is integrated into every release of QHx Core. However, if the use
of QHx Attestor’s TPM-based functionality is desired, QHx must be installed
with the tpm.enable Helm value set to true. This value is set to false by
default to facilitate support for non-TPM-enabled platforms.
Enabling QHx Attestor using TPM-based Policy
Section titled “Enabling QHx Attestor using TPM-based Policy”Enabling QHx Attestor using TPM PCR-based attestation is as simple as creating
or modifying your QHxClusterPolicy resource to express authorized hardware
identities.
---apiVersion: qhx.dev/v1kind: QHxClusterPolicymetadata: name: qhx-cluster-policyspec: tpm:
# Enable TPM PCR-based attestation and admission control. enable: true
# Specify approved PCR values. Multiple approved values may be specified # per PCR. Unlisted PCR indices are unconstrained. pcrs: "0": - 67c54cdf7c44d112f8c64f824443c18160c23ab11030341a19c8034b11926238
# Specify approved vendor EK signing certificates. This trust anchor # can be obtained from your TPM or system hardware vendor. trustedEKs: - | -----BEGIN CERTIFICATE----- MIIEFzCCAn+gAwIBAgIBATANBgkqhkiG9w0BAQsFADAfMR0wGwYDVQQDDBRzd3Rw bS1sb2NhbGNhLXJvb3RjYTAgFw0yNTA5MjQyMzE1MTVaGA8yMDU1MDkyMzIzMTUx NVowGDEWMBQGA1UEAwwNc3d0cG0tbG9jYWxjYTCCAaIwDQYJKoZIhvcNAQEBBQAD ggGPADCCAYoCggGBAJphKbxBjoEhx4knbjX+C9LcJzELQeX4VjlRi9jbj15mJLi9 YxME5y2qcJZ/NEOkRS5qtZfy7zLnY6SDuSaA4dmw1yML3tiWPH9DA/eQenW3F7Id lcPIYYyq56F594bCgaGR4LEx1SDsvvzrHfmm8X0LNMjjV9Picl13UP4Ng4/0h614 6o4on8aoFO0dUfdWtH4AIxZdGcaicMJ6DslWo4Q+DzM8bfAZNUqWAw19Gcxc7GzC kBMsB8zLEsFEy6nAvCX5PPKVzSJSLSgDG6iHiSdcZyO4wqIK5bX7MG9sweDwY3/1 niQGvhSf9BWHjvKjxlFsuR0CKjAtX+mK1pB+YGZDPu97CkAN5cbLIXiXfXT15xkV hdGfsNjJzbI9UEmR4eebxirGl+45Xsuu2lwvP3A07gLLgVwoGALd6tOK4RxYxYP9 DvclUIJCqMAeLv13vNZoXfwhZ8DLHjqAPGej6wT9QvtJj7TJloFHYdTKQ+3J58K1 awez990hFdbcDMfvWwIDAQABo2MwYTAdBgNVHQ4EFgQUKIRmdsY4HnnkJoQdwb9p 5duKg4owDwYDVR0TAQH/BAUwAwEB/zAfBgNVHSMEGDAWgBS1G1g222AJ6wCOERyu 5nxSB4zQ1zAOBgNVHQ8BAf8EBAMCAgQwDQYJKoZIhvcNAQELBQADggGBAG+pTpwG daLvj9J3EBfWrWWhbebjPgLw3/6Us7cOykAKAbxmmmTgg5bJ6GDlB8PynOsioWvS 9Iiocey2Q2XGCEIdt5dasM85RpfW5Y37acWQ6rZ/7oosvWPTJ4HpeGlQghBejOWh 1F2xSZP218mFcylJSgQCUiF8tW0CqVPPvM09f8dvCQhnAByvIbURXfX7v1UTLz+3 xZD1lPRcbBSzlYXl2E9bh7GveoX/N8zMHBALbYDy4UmSQErwS/zRE7r+GnCL9//R 3PVMkedFF0wnea2o8lvYeJpO3o9PpOrObpjG8QKwZJzv4BZcu3GxPsGiptBimlx2 Ce5mIdIqmRUqLt08QPofXzkYwECorZfJoRiqOMmmpjA3JpFympr9lAP0pMjZOmk2 inDK6mx18JrOUb0TXd6WxSYF/El2eseqFtCR1V4z7LrrxE9c2unuF3SnYh3jxyvM q/IdBQPA+cxAZL686rfy0rMqmfi3JZW4mqJcdFzT9Eeq/qoly2IEzITcsg== -----END CERTIFICATE-----Setting this policy automatically configures enforcement of hardware-backed identity as a prerequisite to node and workload identity issuance.