This document provides an overview of improvements, bug fixes, and known issues in the Fortanix Confidential Computing Manager (CCM) 3.23 release.
Prerequisites
A container registry account to push the converted application container Image(s).
A subscription account on Azure Portal to create Compute Node/s.
Improvements
Enclave OS:
Nitro Converter API
push_converted_imageparameter can be set to false to avoid pushing the converted image to the output registry.Updated the log messages of expected unset
ENCLAVEOS_APPCONFIG_IDandCCM_BACKENDenvironment variable.
Bug Fixes
CCM SaaS:
Fixed a visual bug on the image detail page where an unnecessary inner panel was displayed for Docker and Enclave details.
Enclave OS:
Fixed the race condition-based inconsistencies related to internal filesystems.
Fixed an issue that now makes
/proc/<pid>/fd/<fdnum>and/proc/self/fd/<fdnum>type symlinks work together within a single process.Fixed the unnecessary printing of debug level logs on the terminal and erroneous log statements coming to stdout.
Fixed the
arch_prctl syscallfunction as it now returns the EINVAL for unsupported and invalid sub function codes.Nitro Conversion now returns an error during conversion when the output image credentials are wrong.
Known Issues
CCM SaaS Issues:
Node enrollment with EPID attestation is failing with
GroupOutOfDateerror on node with older BIOS.
Limitations
Fortanix has a fair usage policy in this Early Customer Access Program. Hence, Fortanix has limited the resources one can create per account. Therefore, it is expected to observe a resource creation failure message once you have reached the max limit.
To report an issue/bug, visit https://support.fortanix.com/hc/en-us/requests/new.
Node Agent Download
Download link for SGX Platform: https://support.fortanix.com/hc/en-us/articles/360043407012-Fortanix-Node-Agent-Software-Intel-SGX-Platform
Download link for AWS Nitro Platform: https://support.fortanix.com/hc/en-us/articles/4412575587732-Fortanix-Node-Agent-Software-AWS-Nitro-Platform
NOTE
The current version of the node agent on Azure Marketplace will not create certificates.