You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

启用SGX的VM中PCCS请求rootcacrl报错No cache data for this platform

SGX PCCS 请求返回"No cache data for this platform"问题分析

问题场景

在已启用SGX的Azure虚拟机中安装PCCS服务,执行sudo systemctl start pccs启动服务后,运行命令:

curl -k -G "https://localhost:8081/sgx/certification/v4/rootcacrl"

收到错误提示:No cache data for this platform

内核版本信息

cat /proc/version
Linux version 5.15.0-1029-azure (buildd@lcy02-amd64-076) (gcc (Ubuntu 9.4.0-1ubuntu1~20.04.1) 9.4.0, GNU ld (GNU Binutils for Ubuntu) 2.34) #36~20.04.1-Ubuntu SMP Tue Dec 6 17:00:26 UTC 2022

PCCS日志内容

2022-12-27 16:25:22.885 [info]: HTTPS Server is running on: https://localhost:8081
2022-12-27 16:26:17.206 [info]: Client Request-ID : 19de7dcf832143418bd560e236a3e745
2022-12-27 16:26:17.210 [error]: Error: No cache data for this platform.
    at ReqCachingMode.getRootCACrlFromPCS (file:///opt/intel/sgx-dcap-pccs/services/caching_modes/cachingMode.js:84:11)
    at CachingModeManager.getRootCACrlFromPCS (file:///opt/intel/sgx-dcap-pccs/services/caching_modes/cachingModeManager.js:73:23)
    at Module.getRootCaCrl (file:///opt/intel/sgx-dcap-pccs/services/rootcacrlService.js:47:36)
    at async getRootCaCrl (file:///opt/intel/sgx-dcap-pccs/controllers/rootcacrlController.js:38:21)
2022-12-27 16:26:17.217 [info]: 127.0.0.1 - - [27/Dec/2022:16:26:17 +0000] "GET /sgx/certification/v4/rootcacrl HTTP/1.1" 404 32 "-" "curl/7.68.0"

问题原因

本质原因

该错误说明PCCS服务未能从Intel Provisioning Certification Service (PCS) 获取到对应平台的根CA CRL缓存数据,导致无法响应当地请求。

具体触发逻辑

PCCS默认采用请求缓存模式(ReqCachingMode),只有收到客户端请求时才会触发从Intel PCS拉取对应数据的操作。如果拉取失败,就会返回该错误。从日志调用栈可以看出,错误发生在ReqCachingMode.getRootCACrlFromPCS方法,说明PCCS在尝试从PCS获取根CA CRL时未拿到有效数据。

可能的具体诱因

  • 网络连通性问题:虚拟机无法访问Intel PCS的公网端点(默认是https://api.trustedservices.intel.com),比如Azure安全组/NSG限制了出站HTTPS流量,或者网络存在代理但PCCS未配置代理参数。
  • PCCS配置错误:检查/opt/intel/sgx-dcap-pccs/config/default.json中的pcs_api_url是否正确,是否匹配环境(生产/测试);若使用需要API密钥的端点,确认api_key是否有效。
  • 平台SGX配置问题:虽然虚拟机启用了SGX,但可能SGX DCAP驱动未正确加载,或者平台型号/版本不被当前PCCS版本支持,甚至平台未在Intel PCS注册。
  • 版本兼容性问题:当前PCCS版本与内核版本(5.15.0-1029-azure)存在兼容性冲突,导致无法正确处理平台数据或与PCS交互。

内容的提问来源于stack exchange,提问作者sama

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 15:10:24