> they're not going to be satisfied because they're trusting their own, and not yours.This cuts in both directions. Unlike signing certificates, attestation is not a zero-sum fight over a single monolithic measurement attribute that can only be A or B, it can support a goal of having A and B, e.g. as disaggregated VMs. If a cloud wants subset B, then the user/owner/enterprise local attestation can insist that the client must also have subset A, otherwise it can reject subset-B-without-A. Also applies to multiple clouds with conflicting requirements.
Enterprise clients connected to centralized clouds are not the same as consumption-oriented DRM, where the decision is grant/deny. Enterprise client devices generate business data that is sent to the cloud, and they consume data/compute/apps from the cloud. If businesses stop sending data to the cloud, the hybrid workflow breaks down. It's not as one-sided as Netflix DRM.
> We already had "owner control" until they started trying to take that away from us.
With the exception of IBM POWER / Talos servers that have open firmware including the BMC, most servers depend on many blobs, so there has been little transparency for owners, never mind control. One has to start somewhere, and Caliptra starts at the beginning, with an open silicon+firmware RoT that can potentially evaluate some of the myriad blobs and processors and devices needed to bring a server online.
E.g. DMTF SPDM can be used for local PCI (or virtualized I/O like NVMe-over-TCP) device attestation of firmware integrity to the server, before the device is authorized for use in the server, https://www.dmtf.org/standards/SPDM & https://www.platformsecuritysummit.com/2019/speaker/plank