Skip to content

feat(trust-1): capture Gate 0 baseline evidence receipt and TPM campaign harness - #46

Merged
aien-dev merged 1 commit into
mainfrom
feat/trust-1-gate0-baseline
Sep 24, 2026
Merged

aien-dev merged 1 commit into
mainfrom
feat/trust-1-gate0-baseline

Conversation

@aien-dev

Copy link
Copy Markdown
Owner

Summary

Closes CARD-AIENOS-005A and CARD-AIENOS-006 by recording the empirical TRUST-1 Gate 0 baseline for Machine 1 (DGX Spark):

  • Secure Boot State: Verified enabled. Platform Key (PK) issued by NVIDIA Corporation. KEKs from Microsoft (2011/2023). Signature DB () containing standard UEFI/Windows CA keys.
  • TPM 2.0 Policy: Complete SHA-256 PCR baseline captured. Binary event log measured at 19,328 bytes (SHA-256: 3fe47419e108658d7c5cb1612e2c4dedefb27067639ba9baf59f6e83974f1042).
  • Encrypted Volumes & Vault: Root volume /dev/nvme0n1p2 is ext4 Microsoft basic data. Encrypted storage is atlas-private-storage.service mounting gocryptfs unlocked via systemd-creds LoadCredentialEncrypted bound to PCR 7. atlas-vault shares this backend under mode host+tpm2.
  • Offline Recovery Identification: Located atlas-forge-state-luks-recovery-key.txt.age on ATLAS_RECOV (/dev/sda1). Header targets SSH Ed25519 identity SHA256:+4nykc4onMNyhwHwtg1ZaXzXxxUC8q5xiyhBP66+k3c matching operator shell key. ATLAS_RECOV is certified untouched.
  • Measurement Tooling: Added scripts/tpm_measurement_campaign.sh to capture SHA-1, SHA-256, SHA-384, and raw binary event logs across boot experiments without premature filtering.

Verification

  • JSON validated with jq.
  • Execution strictly on DGX Spark.
  • Zero disk secrets: no plaintext passwords or keys logged.
  • Unslop compliance verified.

…ign harness

- Record Machine 1 Secure Boot configuration (PK, KEK, db, dbx)
- Record TPM 2.0 SHA-256 PCR baseline and binary BIOS measurement digest
- Map encrypted volume layout (gocryptfs via systemd-creds) and atlas-vault host+tpm2 binding (PCR 7)
- Identify offline recovery artifact and operator age identity
- Provide non-destructive TPM measurement campaign tool scripts/tpm_measurement_campaign.sh
- Fully certify Zero Disk Secrets and Unslop standards
@aien-dev
aien-dev merged commit cb97879 into main Sep 24, 2026
1 check passed
@aien-dev
aien-dev deleted the feat/trust-1-gate0-baseline branch September 24, 2026 03:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants