Skip to content

[Design]: Device Atestation Posture Check #2898

@teon

Description

@teon
  • Add new posture to Location for: Windows/Mac/Linux - Allow only Attested Devices with TPM 2.0 (admin help: During enrollment or first use of the Desktop Client after enabling this posture user will require to activate Device TPM and device ID will be stored only this device will be able to connect.)
  • Attested device is when user during enrollment or first Desktop Client Launch after enabling this feature will use TPM (Windows/Mac - system based entering: pin/touch ID/password or in case of linux we will need to inform that we will enable TPM for the user, TPM will be erased and user needs to define a PIN) and we will save the device ID in Defguard
  • In device list (admin/user) we should add information about that this device is attested and it's attestation ID: eg. %WQ4etkml23dl
  • Activity log needs to have info that User X posture Device Attestation failed, expected ID: XYZ received: MNZ
  • In desktop client: Posture Check failed due to device attestation

Metadata

Metadata

Assignees

Labels

designFirst we should do UI/UX, then development

Type

No type
No fields configured for issues without a type.

Projects

Status

New

Relationships

None yet

Development

No branches or pull requests

Issue actions