This article provides an overview of improvements in the Fortanix Confidential Computing Manager (CCM) 3.41 release.
1. Prerequisites
A container registry account to push the converted application container Image(s).
2. Improvements
CCM SaaS:
Administrators of deactivated accounts can now access account contents in a read-only mode. They are restricted from making modifications, except for account deletion.
Users requesting a password reset must now complete a reCAPTCHA verification, similar to the signup process, to prevent automated requests. If reCAPTCHA is disabled in the system configuration, this requirement is bypassed.
The Azure Container Instances (ACI) node agent now verifies the workflow AppConfig ID and hash before applying configurations to ensure that only authorized configurations are used.
The Nitro agent now performs hash verification on configurations retrieved from CCM before accepting them to prevent unauthorized modifications.
The Zircon agent now validates the hash of the retrieved workflow AppConfig at runtime to ensure integrity.
skip_server_verifyandccm_backend_urlparameters have been disabled in the runtime configuration handler to mitigate security risks.
3. Limitations
Fortanix has a fair usage policy in this Early Customer Access Program. Hence, Fortanix has limited the resources one can create per account. Therefore, it is expected to observe a resource creation failure message once you have reached the maximum limit.
To report an issue or bug, visit New Requests.
4. Node Agent Download
Download link for SGX Platform: Fortanix Node Agent Software Intel SGX Platform
Download link for AWS Nitro Platform: Fortanix Node Agent Software AWS Nitro Platform