Obtaining the attestation policy fields

You must obtain the IBM Secure Execution (SE) header and other attestation policy fields.

  1. Follow the step "Obtain the attestation policy fields" in Configuring the IBM Secure Execution Certificates and Keys to obtain the following files:
    • ibmse-policy.rego
    • hdr.bin
      Note: You will be shown a link to continue to the third-party screen. Click the link to proceed.
  2. Create a directory hdr for the hdr.bin file by running the following command:
    $ mkdir -p kbs/data/hdr
  3. Copy the hdr.bin file to the hdr directory by running the following command:
    $ cp hdr.bin kbs/data/hdr/hdr.bin
  4. Create a directory attestation-service for the attestation service repository by running the following command:
    $ mkdir -p kbs/data/attestation-service
  5. Create a directory opa for the ibmse-policy.rego by running the following command:
    $ mkdir -p kbs/data/attestation-service/opa
  6. Copy the ibmse-policy.rego to the opa directory by running the following command:
    $ cp ibmse-policy.rego kbs/data/attestation-service/opa/default.rego