This article provides an overview of improvements and bug fixes in the Fortanix Confidential Computing Manager (CCM) 3.29 release.
Prerequisites
A container registry account to push the converted application container Image(s).
A subscription account on Azure Portal to create Compute Node/s.
Improvements
CCM SaaS:
Minor changes made to Group API response objects.
Enclave OS:
Fixed an internal unchecked pointer overflows error to enhance security and prevent data leaks.
Bug Fixes
Enclave OS:
Fixed the crash that occurred when the child process made a system call operating on a file descriptor for a particular file, which was unlinked by the parent process.
Fixed two security vulnerabilities. For details, see the Fortanix Security Advisory portal. (Fortanix would like to thank Jo van Bulck, Fritz Alder, Lesly-Ann Daniel, Frank Piessens, and David Oswald for reporting these issues and their cooperation in getting them fixed.)
Limitations
Fortanix has a fair usage policy in this Early Customer Access Program. Hence, Fortanix has limited the resources one can create per account. Therefore, it is expected to observe a resource creation failure message once you have reached the max limit.
To report an issue/bug, visit https://support.fortanix.com/hc/en-us/requests/new.
Node Agent Download
Download link for SGX Platform: https://support.fortanix.com/hc/en-us/articles/360043407012-Fortanix-Node-Agent-Software-Intel-SGX-Platform
Download link for AWS Nitro Platform: https://support.fortanix.com/hc/en-us/articles/4412575587732-Fortanix-Node-Agent-Software-AWS-Nitro-Platform
NOTE
The current version of the node agent on Azure Marketplace will not create certificates.