Confirm all four before you register:
/proc/cpuinfoflags includesgxandsgx_lc./dev/sgx_enclaveand/dev/sgx_provisionexist, and your user can open both.aesmdis running and the quote provider can fetch collateral.check-hw, loaded with the v1.27.2 mainnet enclave, printsDCAP attestation obtained and verified okandPlatform verification successful! You are able to run a mainnet Secret node, thenYour machine ID:.
Pick the machine
Use Intel SGX with FLC on Ubuntu 22.04 or 24.04, the in-kernel driver, and /etc/sgx_default_qcnl.conf for DCAP collateral.
- CPU families: Xeon E-23xxG, Xeon D-1700, D-2700, D-1800, D-2800, Xeon Max, Xeon Scalable 3rd, 4th, and 5th gen.
- Motherboards: Supermicro X11SCM-F, X11SCW-F, X11SCZ-F, X11SSL-F; Dell R240 (BIOS 2.14.1) and R350 (BIOS 1.7.3); HP DL20 G10 (BIOS 1.80, 2023-07-20); ASUS RS100-E10-PI2 (BIOS 5601); ASRock E3C246D4U2-2T; GIGABYTE MX33-BS1 (BIOS F06).
- On Azure, use DCsv3 or DCdsv3 (Ice Lake, EPC large enough for the 2 GiB heap). Ubuntu 22.04 and 24.04 both use Intel’s quote provider and the DCAP 1.22 Azure file below. Do not install
az-dcap-client. - Do not use DCsv2. It is Xeon E-2288G. The largest published EPC is 168 MiB, below the heap.
- Do not use DCasv5, DCadsv5, ECasv5, or ECadsv5 (AMD SEV-SNP), or DCesv5, DCesv6, and EC TDX sizes. They do not load this enclave.
- On another provider, use the same device nodes and
check-hw. You still need the allowlist. - Do not use a Client Core CPU after the 11th generation, an EPID-only platform, AMD, or ME-only SGX.
- The signed mainnet enclave heap is
0x80000000(2 GiB) plus an 8 MiB stack. A smaller EPC cannot start it. - Give the host 32 GB RAM, 20 GB or more of swap, and a 512 GB SSD. 64 GB and 1 TB NVMe is the larger size.
Steps
-
On a physical machine, install the latest BIOS, enable SGX (not software-controlled), disable Secure Boot, and disable hyperthreading. On 3rd Gen Xeon Scalable and newer, FLC is already on and is not a BIOS switch. On Azure DCsv3 or DCdsv3, skip the BIOS menu and pick a Gen2 image.
-
Confirm OS and CPU flags:
. /etc/os-release
# VERSION_ID must be 22.04 or 24.04
uname -r
grep -m1 '^flags' /proc/cpuinfo | tr ' ' '\n' | grep -E '^(sgx|sgx_lc)$'- Confirm the in-kernel nodes. Do not install the out-of-tree
.bindriver on a kernel that already has in-kernel SGX.
ls -l /dev/sgx_enclave /dev/sgx_provision
dmesg | grep -i sgxIf the nodes are missing on 22.04 or 24.04, turn SGX on in firmware, use a CPU with FLC, or use an SGX VM. Intel’s kernel floor is 5.11. Ubuntu 22.04 GA is 5.15 and 24.04 GA is 6.8.
- Install the DCAP runtime from Intel’s apt repo (keyring and
${VERSION_CODENAME}from/etc/os-release). The build pin is PSW2.25.100.3and DCAP1.22.100.3forjammy1ornoble1. Intel apt may publish newer packages.
On a physical host and on Azure DCsv3 or DCdsv3, Ubuntu 22.04 or 24.04, install the Intel quote provider:
. /etc/os-release
curl -fsSL https://download.01.org/intel-sgx/sgx_repo/ubuntu/intel-sgx-deb.key \
| gpg --dearmor | sudo tee /usr/share/keyrings/intel-sgx-archive-keyring.gpg > /dev/null
echo "deb [signed-by=/usr/share/keyrings/intel-sgx-archive-keyring.gpg] https://download.01.org/intel-sgx/sgx_repo/ubuntu ${VERSION_CODENAME} main" \
| sudo tee /etc/apt/sources.list.d/intel-sgx.list
sudo apt-get update
sudo apt-get install -y \
libsgx-aesm-launch-plugin libsgx-enclave-common libsgx-epid libsgx-launch \
libsgx-quote-ex libsgx-uae-service libsgx-qe3-logic libsgx-pce-logic \
libsgx-aesm-pce-plugin libsgx-dcap-ql libsgx-dcap-quote-verify libsgx-urts \
sgx-aesm-service libsgx-aesm-ecdsa-plugin libsgx-aesm-quote-ex-plugin \
libsgx-ae-qve libsgx-dcap-default-qpl- Write
/etc/sgx_default_qcnl.confbefore you enable and restartaesmd.
On other hosts, point the quote provider at Intel PCS:
sudo tee /etc/sgx_default_qcnl.conf <<'EOF'
{"pccs_url":"https://api.trustedservices.intel.com/sgx/certification/v4/","use_secure_cert":true,"retry_times":6,"retry_delay":10,"pck_cache_expire_hours":168,"verify_collateral_cache_expire_hours":168,"local_cache_only":false}
EOFOn Azure DCsv3 or DCdsv3, Ubuntu 22.04 or 24.04:
sudo tee /etc/sgx_default_qcnl.conf <<'EOF'
{"pccs_url":"https://global.acccache.azure.net/sgx/certification/v4/","use_secure_cert":true,"collateral_service":"https://api.trustedservices.intel.com/sgx/certification/v4/","pccs_api_version":"3.1","retry_times":6,"retry_delay":5,"local_pck_url":"http://169.254.169.254/metadata/THIM/sgx/certification/v4/","pck_cache_expire_hours":48,"verify_collateral_cache_expire_hours":48,"custom_request_options":{"get_cert":{"headers":{"metadata":"true"},"params":{"api-version":"2021-07-22-preview"}}}}
EOF- Enable and restart the AESM service:
sudo systemctl enable --now aesmd
sudo systemctl restart aesmd
systemctl is-active aesmd- Add your user to
sgxandsgx_prv, install udev rules, and fix device permissions.usermoddoes not affect your current shell; runinit-enclavethroughsgso the groups apply without logging out.
NODE_USER="${USER}"
sudo groupadd sgx 2>/dev/null || true
sudo groupadd sgx_prv 2>/dev/null || true
sudo usermod -aG sgx,sgx_prv "$NODE_USER"
sudo tee /etc/udev/rules.d/99-sgx-permissions.rules <<'EOF'
SUBSYSTEM=="misc", KERNEL=="sgx_enclave", MODE="0660", GROUP="sgx"
SUBSYSTEM=="misc", KERNEL=="sgx_provision", MODE="0660", GROUP="sgx_prv"
EOF
sudo udevadm control --reload-rules
sudo udevadm trigger
sudo chgrp sgx /dev/sgx_enclave
sudo chmod 0660 /dev/sgx_enclave
sudo chgrp sgx_prv /dev/sgx_provision
sudo chmod 0660 /dev/sgx_provision-
On a multi-socket Xeon Scalable, configure
sgx-ra-serviceand read/var/log/mpa_registration.log. -
Install the mainnet deb so the signed enclave is on disk. Stop before
init-enclaveand beforetx register. Do not startsecret-node. Follow Install secretd. -
check-hwfrom a directory that containscheck_hw_enclave.so. The kit binary is atkits/v1.27.2/mainnet/check-hw/check-hw. Copy the signed enclave out of the deb:
. /etc/os-release
mkdir -p "$HOME/check-hw" && cd "$HOME/check-hw"
curl -fsSL https://docs.scrt.network/check-hw -o check-hw
chmod +x check-hw
dpkg-deb -x /tmp/secretnetwork_1.27.2_MAINNET_goleveldb_amd64_ubuntu-${VERSION_ID}.deb /tmp/sn127
cp /tmp/sn127/usr/lib/librust_cosmwasm_enclave.signed.so ./check_hw_enclave.so
sg sgx -c "sg sgx_prv -c './check-hw'"Success text:
Creating enclave instance..
DCAP attestation obtained and verified ok
DCAP attestation: Enclave quote is valid
Platform verification successful! You are able to run a mainnet Secret node
Your machine ID: <40 hex chars>check-hw verifies the quote with the allowlist check off. It accepts SGX_QL_QV_RESULT_OK and SGX_QL_QV_RESULT_SW_HARDENING_NEEDED. If the result is not OK, it prints a warning and still treats the quote as verified. The allowlist check happens later, on chain.
Save the machine id. It is the first 20 bytes of SHA-256 over the platform PPID (40 hex characters). It changes if you toggle SGX, reset it in BIOS, replace the board or CPU, or install some firmware updates.
- If
check-hwsucceeds andtx register authfails the allowlist, continue at Allowlist and machine replacement. - Do not run
embed_azure_attestation.sh. - The deb depends only on
libsnappy1v5.dpkg -ican succeed andsecretdcan still fail looking forlibsgx_urts.so.2,libsgx_dcap_ql.so.1, orlibsgx_dcap_quoteverify.so.1. - Do not set
SGX_MODE=SW. - Check
check-hwagainst sha2565f1fb76fb611e91bd8bb1ec3f12bb21216d66a0782b6bf21968309897c2c122dinkits/v1.27.2/SHA256SUMS.
Run every step on a new machine. If this hardware already quoted and you only changed the OS, repeat the OS, device, and DCAP steps, then follow Upgrade a seeded node. Skip check-hw on a machine that is already signing. Run it before a new registration.