From 1f79e711067d85ff2155bb0bf8a71273ad71a7ea Mon Sep 17 00:00:00 2001 From: Noah Stride Date: Tue, 18 Apr 2023 15:02:05 +0100 Subject: [PATCH] Rename device attestation types (#24724) --- .../go/teleport/devicetrust/v1/device.pb.go | 61 +++++++++++-------- .../teleport/devicetrust/v1/device.proto | 10 ++- api/types/device.go | 12 ++-- api/types/device_test.go | 5 +- 4 files changed, 54 insertions(+), 34 deletions(-) diff --git a/api/gen/proto/go/teleport/devicetrust/v1/device.pb.go b/api/gen/proto/go/teleport/devicetrust/v1/device.pb.go index 0716a6baa42..ccb5333f7ff 100644 --- a/api/gen/proto/go/teleport/devicetrust/v1/device.pb.go +++ b/api/gen/proto/go/teleport/devicetrust/v1/device.pb.go @@ -44,23 +44,29 @@ const ( // Used on macOS. DeviceAttestationType_DEVICE_ATTESTATION_TYPE_UNSPECIFIED DeviceAttestationType = 0 // Credential was verified through a TPM EK->AK->App key chain on enrollment. - DeviceAttestationType_DEVICE_ATTESTATION_TYPE_TPM DeviceAttestationType = 1 - // Credential was verified through a TPM EK->AK->App key chain on enrollment - // and an EKCert was present and signed by a configured approved CA. + DeviceAttestationType_DEVICE_ATTESTATION_TYPE_TPM_EKPUB DeviceAttestationType = 1 + // Credential was verified through a TPM EKCert->AK->App key chain on + // enrollment, but no allow-listed CAs were configured to validate this EKCert + // against. DeviceAttestationType_DEVICE_ATTESTATION_TYPE_TPM_EKCERT DeviceAttestationType = 2 + // Credential was verified through a TPM EKCert->AK->App key chain on + // enrollment, and the EKCert was signed by a configured allow-listed CA. + DeviceAttestationType_DEVICE_ATTESTATION_TYPE_TPM_EKCERT_TRUSTED DeviceAttestationType = 3 ) // Enum value maps for DeviceAttestationType. var ( DeviceAttestationType_name = map[int32]string{ 0: "DEVICE_ATTESTATION_TYPE_UNSPECIFIED", - 1: "DEVICE_ATTESTATION_TYPE_TPM", + 1: "DEVICE_ATTESTATION_TYPE_TPM_EKPUB", 2: "DEVICE_ATTESTATION_TYPE_TPM_EKCERT", + 3: "DEVICE_ATTESTATION_TYPE_TPM_EKCERT_TRUSTED", } DeviceAttestationType_value = map[string]int32{ - "DEVICE_ATTESTATION_TYPE_UNSPECIFIED": 0, - "DEVICE_ATTESTATION_TYPE_TPM": 1, - "DEVICE_ATTESTATION_TYPE_TPM_EKCERT": 2, + "DEVICE_ATTESTATION_TYPE_UNSPECIFIED": 0, + "DEVICE_ATTESTATION_TYPE_TPM_EKPUB": 1, + "DEVICE_ATTESTATION_TYPE_TPM_EKCERT": 2, + "DEVICE_ATTESTATION_TYPE_TPM_EKCERT_TRUSTED": 3, } ) @@ -491,30 +497,33 @@ var file_teleport_devicetrust_v1_device_proto_rawDesc = []byte{ 0x70, 0x6d, 0x5f, 0x61, 0x74, 0x74, 0x65, 0x73, 0x74, 0x61, 0x74, 0x69, 0x6f, 0x6e, 0x5f, 0x6b, 0x65, 0x79, 0x5f, 0x64, 0x65, 0x72, 0x18, 0x05, 0x20, 0x01, 0x28, 0x0c, 0x52, 0x14, 0x74, 0x70, 0x6d, 0x41, 0x74, 0x74, 0x65, 0x73, 0x74, 0x61, 0x74, 0x69, 0x6f, 0x6e, 0x4b, 0x65, 0x79, 0x44, - 0x65, 0x72, 0x2a, 0x89, 0x01, 0x0a, 0x15, 0x44, 0x65, 0x76, 0x69, 0x63, 0x65, 0x41, 0x74, 0x74, + 0x65, 0x72, 0x2a, 0xbf, 0x01, 0x0a, 0x15, 0x44, 0x65, 0x76, 0x69, 0x63, 0x65, 0x41, 0x74, 0x74, 0x65, 0x73, 0x74, 0x61, 0x74, 0x69, 0x6f, 0x6e, 0x54, 0x79, 0x70, 0x65, 0x12, 0x27, 0x0a, 0x23, 0x44, 0x45, 0x56, 0x49, 0x43, 0x45, 0x5f, 0x41, 0x54, 0x54, 0x45, 0x53, 0x54, 0x41, 0x54, 0x49, 0x4f, 0x4e, 0x5f, 0x54, 0x59, 0x50, 0x45, 0x5f, 0x55, 0x4e, 0x53, 0x50, 0x45, 0x43, 0x49, 0x46, - 0x49, 0x45, 0x44, 0x10, 0x00, 0x12, 0x1f, 0x0a, 0x1b, 0x44, 0x45, 0x56, 0x49, 0x43, 0x45, 0x5f, + 0x49, 0x45, 0x44, 0x10, 0x00, 0x12, 0x25, 0x0a, 0x21, 0x44, 0x45, 0x56, 0x49, 0x43, 0x45, 0x5f, 0x41, 0x54, 0x54, 0x45, 0x53, 0x54, 0x41, 0x54, 0x49, 0x4f, 0x4e, 0x5f, 0x54, 0x59, 0x50, 0x45, - 0x5f, 0x54, 0x50, 0x4d, 0x10, 0x01, 0x12, 0x26, 0x0a, 0x22, 0x44, 0x45, 0x56, 0x49, 0x43, 0x45, - 0x5f, 0x41, 0x54, 0x54, 0x45, 0x53, 0x54, 0x41, 0x54, 0x49, 0x4f, 0x4e, 0x5f, 0x54, 0x59, 0x50, - 0x45, 0x5f, 0x54, 0x50, 0x4d, 0x5f, 0x45, 0x4b, 0x43, 0x45, 0x52, 0x54, 0x10, 0x02, 0x2a, 0x84, - 0x01, 0x0a, 0x12, 0x44, 0x65, 0x76, 0x69, 0x63, 0x65, 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x53, - 0x74, 0x61, 0x74, 0x75, 0x73, 0x12, 0x24, 0x0a, 0x20, 0x44, 0x45, 0x56, 0x49, 0x43, 0x45, 0x5f, - 0x45, 0x4e, 0x52, 0x4f, 0x4c, 0x4c, 0x5f, 0x53, 0x54, 0x41, 0x54, 0x55, 0x53, 0x5f, 0x55, 0x4e, - 0x53, 0x50, 0x45, 0x43, 0x49, 0x46, 0x49, 0x45, 0x44, 0x10, 0x00, 0x12, 0x25, 0x0a, 0x21, 0x44, + 0x5f, 0x54, 0x50, 0x4d, 0x5f, 0x45, 0x4b, 0x50, 0x55, 0x42, 0x10, 0x01, 0x12, 0x26, 0x0a, 0x22, + 0x44, 0x45, 0x56, 0x49, 0x43, 0x45, 0x5f, 0x41, 0x54, 0x54, 0x45, 0x53, 0x54, 0x41, 0x54, 0x49, + 0x4f, 0x4e, 0x5f, 0x54, 0x59, 0x50, 0x45, 0x5f, 0x54, 0x50, 0x4d, 0x5f, 0x45, 0x4b, 0x43, 0x45, + 0x52, 0x54, 0x10, 0x02, 0x12, 0x2e, 0x0a, 0x2a, 0x44, 0x45, 0x56, 0x49, 0x43, 0x45, 0x5f, 0x41, + 0x54, 0x54, 0x45, 0x53, 0x54, 0x41, 0x54, 0x49, 0x4f, 0x4e, 0x5f, 0x54, 0x59, 0x50, 0x45, 0x5f, + 0x54, 0x50, 0x4d, 0x5f, 0x45, 0x4b, 0x43, 0x45, 0x52, 0x54, 0x5f, 0x54, 0x52, 0x55, 0x53, 0x54, + 0x45, 0x44, 0x10, 0x03, 0x2a, 0x84, 0x01, 0x0a, 0x12, 0x44, 0x65, 0x76, 0x69, 0x63, 0x65, 0x45, + 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x53, 0x74, 0x61, 0x74, 0x75, 0x73, 0x12, 0x24, 0x0a, 0x20, 0x44, 0x45, 0x56, 0x49, 0x43, 0x45, 0x5f, 0x45, 0x4e, 0x52, 0x4f, 0x4c, 0x4c, 0x5f, 0x53, 0x54, 0x41, - 0x54, 0x55, 0x53, 0x5f, 0x4e, 0x4f, 0x54, 0x5f, 0x45, 0x4e, 0x52, 0x4f, 0x4c, 0x4c, 0x45, 0x44, - 0x10, 0x01, 0x12, 0x21, 0x0a, 0x1d, 0x44, 0x45, 0x56, 0x49, 0x43, 0x45, 0x5f, 0x45, 0x4e, 0x52, - 0x4f, 0x4c, 0x4c, 0x5f, 0x53, 0x54, 0x41, 0x54, 0x55, 0x53, 0x5f, 0x45, 0x4e, 0x52, 0x4f, 0x4c, - 0x4c, 0x45, 0x44, 0x10, 0x02, 0x42, 0x5a, 0x5a, 0x58, 0x67, 0x69, 0x74, 0x68, 0x75, 0x62, 0x2e, - 0x63, 0x6f, 0x6d, 0x2f, 0x67, 0x72, 0x61, 0x76, 0x69, 0x74, 0x61, 0x74, 0x69, 0x6f, 0x6e, 0x61, - 0x6c, 0x2f, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2f, 0x61, 0x70, 0x69, 0x2f, 0x67, - 0x65, 0x6e, 0x2f, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x2f, 0x67, 0x6f, 0x2f, 0x74, 0x65, 0x6c, 0x65, - 0x70, 0x6f, 0x72, 0x74, 0x2f, 0x64, 0x65, 0x76, 0x69, 0x63, 0x65, 0x74, 0x72, 0x75, 0x73, 0x74, - 0x2f, 0x76, 0x31, 0x3b, 0x64, 0x65, 0x76, 0x69, 0x63, 0x65, 0x74, 0x72, 0x75, 0x73, 0x74, 0x76, - 0x31, 0x62, 0x06, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x33, + 0x54, 0x55, 0x53, 0x5f, 0x55, 0x4e, 0x53, 0x50, 0x45, 0x43, 0x49, 0x46, 0x49, 0x45, 0x44, 0x10, + 0x00, 0x12, 0x25, 0x0a, 0x21, 0x44, 0x45, 0x56, 0x49, 0x43, 0x45, 0x5f, 0x45, 0x4e, 0x52, 0x4f, + 0x4c, 0x4c, 0x5f, 0x53, 0x54, 0x41, 0x54, 0x55, 0x53, 0x5f, 0x4e, 0x4f, 0x54, 0x5f, 0x45, 0x4e, + 0x52, 0x4f, 0x4c, 0x4c, 0x45, 0x44, 0x10, 0x01, 0x12, 0x21, 0x0a, 0x1d, 0x44, 0x45, 0x56, 0x49, + 0x43, 0x45, 0x5f, 0x45, 0x4e, 0x52, 0x4f, 0x4c, 0x4c, 0x5f, 0x53, 0x54, 0x41, 0x54, 0x55, 0x53, + 0x5f, 0x45, 0x4e, 0x52, 0x4f, 0x4c, 0x4c, 0x45, 0x44, 0x10, 0x02, 0x42, 0x5a, 0x5a, 0x58, 0x67, + 0x69, 0x74, 0x68, 0x75, 0x62, 0x2e, 0x63, 0x6f, 0x6d, 0x2f, 0x67, 0x72, 0x61, 0x76, 0x69, 0x74, + 0x61, 0x74, 0x69, 0x6f, 0x6e, 0x61, 0x6c, 0x2f, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, + 0x2f, 0x61, 0x70, 0x69, 0x2f, 0x67, 0x65, 0x6e, 0x2f, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x2f, 0x67, + 0x6f, 0x2f, 0x74, 0x65, 0x6c, 0x65, 0x70, 0x6f, 0x72, 0x74, 0x2f, 0x64, 0x65, 0x76, 0x69, 0x63, + 0x65, 0x74, 0x72, 0x75, 0x73, 0x74, 0x2f, 0x76, 0x31, 0x3b, 0x64, 0x65, 0x76, 0x69, 0x63, 0x65, + 0x74, 0x72, 0x75, 0x73, 0x74, 0x76, 0x31, 0x62, 0x06, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x33, } var ( diff --git a/api/proto/teleport/devicetrust/v1/device.proto b/api/proto/teleport/devicetrust/v1/device.proto index e667e9f627a..2f3cd678d23 100644 --- a/api/proto/teleport/devicetrust/v1/device.proto +++ b/api/proto/teleport/devicetrust/v1/device.proto @@ -115,10 +115,14 @@ enum DeviceAttestationType { // Used on macOS. DEVICE_ATTESTATION_TYPE_UNSPECIFIED = 0; // Credential was verified through a TPM EK->AK->App key chain on enrollment. - DEVICE_ATTESTATION_TYPE_TPM = 1; - // Credential was verified through a TPM EK->AK->App key chain on enrollment - // and an EKCert was present and signed by a configured approved CA. + DEVICE_ATTESTATION_TYPE_TPM_EKPUB = 1; + // Credential was verified through a TPM EKCert->AK->App key chain on + // enrollment, but no allow-listed CAs were configured to validate this EKCert + // against. DEVICE_ATTESTATION_TYPE_TPM_EKCERT = 2; + // Credential was verified through a TPM EKCert->AK->App key chain on + // enrollment, and the EKCert was signed by a configured allow-listed CA. + DEVICE_ATTESTATION_TYPE_TPM_EKCERT_TRUSTED = 3; } // DeviceEnrollStatus represents the enrollment status of a device. diff --git a/api/types/device.go b/api/types/device.go index 40b1a72eafc..e1f1ad4db4b 100644 --- a/api/types/device.go +++ b/api/types/device.go @@ -287,10 +287,12 @@ func ResourceDeviceAttestationTypeToString( switch attestationType { case devicepb.DeviceAttestationType_DEVICE_ATTESTATION_TYPE_UNSPECIFIED: return "unspecified" - case devicepb.DeviceAttestationType_DEVICE_ATTESTATION_TYPE_TPM: - return "tpm" + case devicepb.DeviceAttestationType_DEVICE_ATTESTATION_TYPE_TPM_EKPUB: + return "tpm_ekpub" case devicepb.DeviceAttestationType_DEVICE_ATTESTATION_TYPE_TPM_EKCERT: return "tpm_ekcert" + case devicepb.DeviceAttestationType_DEVICE_ATTESTATION_TYPE_TPM_EKCERT_TRUSTED: + return "tpm_ekcert_trusted" default: return attestationType.String() } @@ -302,10 +304,12 @@ func ResourceDeviceAttestationTypeFromString( switch attestationType { case "unspecified", "": return devicepb.DeviceAttestationType_DEVICE_ATTESTATION_TYPE_UNSPECIFIED, nil - case "tpm": - return devicepb.DeviceAttestationType_DEVICE_ATTESTATION_TYPE_TPM, nil + case "tpm_ekpub": + return devicepb.DeviceAttestationType_DEVICE_ATTESTATION_TYPE_TPM_EKPUB, nil case "tpm_ekcert": return devicepb.DeviceAttestationType_DEVICE_ATTESTATION_TYPE_TPM_EKCERT, nil + case "tpm_ekcert_trusted": + return devicepb.DeviceAttestationType_DEVICE_ATTESTATION_TYPE_TPM_EKCERT_TRUSTED, nil default: return devicepb.DeviceAttestationType_DEVICE_ATTESTATION_TYPE_UNSPECIFIED, trace.BadParameter("unknown attestation type %q", attestationType) } diff --git a/api/types/device_test.go b/api/types/device_test.go index 7b0ec4c58fe..1a1810c9f60 100644 --- a/api/types/device_test.go +++ b/api/types/device_test.go @@ -162,11 +162,14 @@ func TestResourceAttestationType_toAndFrom(t *testing.T) { attestationType: "unspecified", }, { - attestationType: "tpm", + attestationType: "tpm_ekpub", }, { attestationType: "tpm_ekcert", }, + { + attestationType: "tpm_ekcert_trusted", + }, { attestationType: "quantum_entanglement", errorContains: "unknown attestation type",