Post

Replies

Boosts

Views

Activity

Is the macOS 27 App Attest SIP check a csr_check() wrapper, or is SIP state actually attested?
On macOS 27, App Attest attestations include a key access control property (the aclBlob, OID 1.2.840.113635.100.8.6) that Apple says reflects SIP and Full Security mode being enabled. Is this just a wrapper around the CSR check (csr_check / what csrutil status reads) at attestation time, or is the SIP state actually enforced by the Secure Enclave and bound to the attested key?
0
0
208
9h
Is the macOS 27 App Attest SIP check a csr_check() wrapper, or is SIP state actually attested?
On macOS 27, App Attest attestations include a key access control property (the aclBlob, OID 1.2.840.113635.100.8.6) that Apple says reflects SIP and Full Security mode being enabled. Is this just a wrapper around the CSR check (csr_check / what csrutil status reads) at attestation time, or is the SIP state actually enforced by the Secure Enclave and bound to the attested key?
Replies
0
Boosts
0
Views
208
Activity
9h