This article provides an overview of new features, improvements, bug fixes, and known issues in the Fortanix Confidential Computing Manager (CCM) 3.22 release.
Prerequisites
A container registry account to push the converted application container Image(s).
A subscription account on Azure Portal to create Compute Node/s.
New Features
CCM SaaS:
Added file system support for AWS Nitro Enclaves.
Improvements
CCM SaaS:
Added support for scenarios where there is no EPC size to display in the UI, for example for AWS Nitro Enclaves.
Enclave OS:
The AWS Nitro converter now runs with privileged access to accommodate file system support
The AWS Nitro converted applications now run with a modified enclave kernel which includes NBD, DM_CRYPT, and dependent kernel modules built into it.
Added file system support to use the luks2 encryption format for encrypting data written into the file system by the application.
The AWS Nitro converted applications can now pass environment variables to the enclave at runtime. This can be done with the help of docker's
-eoption.This release allows command line arguments from the docker run command that is used to run the AWS Nitro converted application to be propagated to the enclave program.
Bug Fixes
CCM SaaS:
Fixed an issue where the Get all ApprovalRequest API did not return the requests when the user was a viewer or reviewer.
Fixed an issue where the task details were not shown if the corresponding application was deleted.
Fixed an issue where, when delisting a compute node, the list of nodes would not get automatically refreshed.
Fixed an issue where, when delisting a compute node, the list of nodes would not get automatically refreshed.
EnclaveOS:
Fixed an issue where the NodeJS app fails on SGX.
Fixed an issue that resulted in AWS Nitro parent base crashing when enclave exits first. The parent is now expected to exit without a console read error.
Fixed an issue that now catches unexpected exits from background tasks that run alongside the enclave application.
Known Issues
CCM SaaS issues:
The
get PCK certAPI does not require authentication currently.Node agents are presenting an invalid certificate chain length.
The converter should throw an error if the certificate key is not in an encrypted folder.
Curl request fails for deployed Docker Hub stock Tensorflow app image inside the AWS Nitro enclave.
Error starting Docker Hub stock Elasticsearch app inside the AWS Nitro enclave as default enclave user is root.
Limitations
Fortanix has a fair usage policy in this Early Customer Access Program. Hence, Fortanix has limited the resources one can create per account. Therefore, it is expected to observe a resource creation failure message once you have reached the max limit.
To report an issue/bug, visit https://support.fortanix.com/hc/en-us/requests/new.
Node Agent Download
Download link for SGX Platform: https://support.fortanix.com/hc/en-us/articles/360043407012-Fortanix-Node-Agent-Software-Intel-SGX-Platform
Download link for AWS Nitro Platform: https://support.fortanix.com/hc/en-us/articles/4412575587732-Fortanix-Node-Agent-Software-AWS-Nitro-Platform
NOTE
The current version of the node agent on Azure Marketplace will not create certificates.