1.2.0 (2026-10-07)
Features Added
- Added
attestTpm(BinaryData)andattestTpmWithResponse(BinaryData, ...)overloads toAttestationClientand
AttestationAsyncClient. They treat the TPM attestation request and response as opaque binary data, consistent with
attestOpenEnclave,attestSgxEnclave, and the other Azure Attestation SDKs. - Added
TpmAttestationResult, the result type returned by the newBinaryData-based TPM attestation overloads.
Bugs Fixed
- Fixed a signature verification bypass (CWE-347) in attestation token validation. Previously, a signed token
whose signature could not be verified by any of the trusted signers was silently accepted. Such tokens are now
rejected with a validation error, matching the behavior of the other Azure Attestation SDKs. - Hardened attestation token validation so that a signed token can no longer vouch for its own signature via its
embedded certificate chain when no trusted signers are supplied. Validation now fails closed in that case,
matching the behavior of the other Azure Attestation SDKs.
Other Changes
- Deprecated the
String-basedattestTpm(String)andattestTpmWithResponse(String, ...)overloads on
AttestationClientandAttestationAsyncClient; use theBinaryData-based overloads instead. TheString
overloads are retained for compatibility with earlier versions and will be removed in a future major release. They
do not work with binary TPM payloads: converting binary data to aStringusing UTF-8 changes the bytes, and the
attestation request fails.