etminan
Blog

Engineering & design, in depth.

Longer-form writing from the team building Etminan — the trust model, the decisions behind it, and the honest limits. For per-release “what shipped” notes, see News instead.

📡  Subscribe via RSS
Attestation 2026-07-25 ~9 min read

Offline-verifiable TPM attestation for Linux — no cloud, no third-party registrar

On-box integrity checkers let a compromised host suppress its own alarm. Etminan splits the job across two trust domains — a TPM on the host, an offline verifier that makes every decision — and the verifier needs no TPM of its own. How the quote-and-replay loop works, why the verifier is a TPM-less static binary, and the threat model stated plainly.

Read the post →

More to come — the tpm_wire.rs story, attestation that works air-gapped, and NIS2-grade tamper-evident host integrity. Subscribe via RSS above to get them as they land.