github Azure/azure-sdk-for-java com.azure+azure-security-attestation_1.2.0

2 hours ago

1.2.0 (2026-10-07)

Features Added

  • Added attestTpm(BinaryData) and attestTpmWithResponse(BinaryData, ...) overloads to AttestationClient and
    AttestationAsyncClient. They treat the TPM attestation request and response as opaque binary data, consistent with
    attestOpenEnclave, attestSgxEnclave, and the other Azure Attestation SDKs.
  • Added TpmAttestationResult, the result type returned by the new BinaryData-based TPM attestation overloads.

Bugs Fixed

  • Fixed a signature verification bypass (CWE-347) in attestation token validation. Previously, a signed token
    whose signature could not be verified by any of the trusted signers was silently accepted. Such tokens are now
    rejected with a validation error, matching the behavior of the other Azure Attestation SDKs.
  • Hardened attestation token validation so that a signed token can no longer vouch for its own signature via its
    embedded certificate chain when no trusted signers are supplied. Validation now fails closed in that case,
    matching the behavior of the other Azure Attestation SDKs.

Other Changes

  • Deprecated the String-based attestTpm(String) and attestTpmWithResponse(String, ...) overloads on
    AttestationClient and AttestationAsyncClient; use the BinaryData-based overloads instead. The String
    overloads are retained for compatibility with earlier versions and will be removed in a future major release. They
    do not work with binary TPM payloads: converting binary data to a String using UTF-8 changes the bytes, and the
    attestation request fails.

Don't miss a new azure-sdk-for-java release

NewReleases is sending notifications on new releases.