On macOS 27, App Attest attestations include a key access control property (the aclBlob, OID 1.2.840.113635.100.8.6) that Apple says reflects SIP and Full Security mode being enabled. Is this just a wrapper around the CSR check (csr_check / what csrutil status reads) at attestation time, or is the SIP state actually enforced by the Secure Enclave and bound to the attested key?
Topic:
Privacy & Security
SubTopic:
App Attest & DeviceCheck
0
0
210