On May 19, 2025, at 9:43 AM, Sergii Dmytruk <sergii.dmyt...@3mdeb.com> wrote:
> 
> On Sun, May 18, 2025 at 07:31:49PM -0400, Rich Persaud wrote:
>> If there's no stable URL for the TXT spec, can we mirror the relevant
>> doc(s) somewhere in the Xen docs tree? A trusted archive of the spec
>> for trusted execution.
>> 
>> Rich
> 
> By "unversioned link to Software Development Guide" I meant
> https://www.intel.com/content/www/us/en/content-details/315168/
> which always provides the latest version.

By "trusted archive of the spec" I meant a server under control of Intel or the 
Xen community, hosting the specific version(s) of the spec that have been 
implemented in the Xen tree.  

Unless Intel reference PDFs are digitally signed by an Intel certificate, we 
should not be linking to non-Intel mirrors of Intel PDFs, which could be 
targeted by attackers to relay malware onto the workstations of developers of 
trusted execution software. If Intel reference PDFs are signed, we should 
include instructions for verifying their authenticity, if we are linking to 
non-Intel sources.

Rich

Reply via email to