Conversation

We've run into a few users on Pixel 3 phones where using key attestation with StrongBox creates a certificate with an invalid signature. This only happens with StrongBox. TEE keystore certificate chains still pass verification for these users. Is this a known issue?
1
Replying to
We're unsure if it fails due to a bug in signing or if it corrupts the main public key certificate. This happens with both the stock OS and with GrapheneOS. At least one of the users installed Android 11 developer preview and then downgraded. Maybe that broke it?
1