Layr-Labs / Layr-Labs/d-inference

Provider enrollment: support SecurityInfo attestation without bootstrap-token escrow

Open
#884 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
522
Forks
113
Avg merge
17h 26m
Merged PRs (30d)
111

Description

Could maintainers clarify whether bootstrap-token escrow is required for provider hardware attestation and paid routing?

The enrollment profile reviewed requests AccessRights 1041 (configuration-profile inspection, device-information queries, security queries), but also advertises com.apple.mdm.bootstraptoken in ServerCapabilities. Apple documents that capability as enabling bootstrap-token escrow. The referenced MicroMDM v1.13.1 implementation supports storing and returning those tokens.

This is a least-privilege/support question, not a claim that the profile grants remote erase: the erase access-right bit is absent.

Questions:
1. Is the bootstrap capability actually necessary for SecurityInfo-based hardware trust or paid-routing eligibility?
2. Can you provide/support an enrollment profile omitting com.apple.mdm.bootstraptoken while retaining AccessRights 1041, SCEP identity and per-user connections?
3. If token escrow is required, what uses, retention/deletion behavior and storage protections apply?
4. Is automatic login a strict routing requirement, or only an uptime recommendation for recovering after reboot? Can a provider retain FileVault and manual login?

A documented no-bootstrap enrollment option would make the read-only attestation scope clearer. No enrollment has been performed as part of this review.

Contributor guide

Open the contributing guide

Research direction

Review the referenced enrollment profile, AccessRights 1041, ServerCapabilities, SCEP identity, and the MicroMDM v1.13.1 token handling. Confirm whether bootstrap-token escrow and automatic login are required, then document a supported no-bootstrap profile and the uses, retention, deletion, and protections for any stored tokens.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.