On Sat, Nov 24, 2018 at 02:13:18PM -0600, Dr. Greg wrote: > This isn't about an enclave being able to tell that it is really an > enclave. As I noted in my previous reply, access to the provisioning > bit allows an enclave author to create a perpetual hardware identifier > for a platform based on a signing key of their choosing, along with a > few other incidentals, all of which are completely under the control > of the enclave author. I think I'm now in the same page with the issue now. Thanks for the patience explaining this. /Jarkko