---
title: "Allowlist and machine replacement"
description: "Put the machine id on the enclave allowlist, including on Azure."
---

> Documentation Index
> Fetch the complete documentation index at: https://docs-redux.pages.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Allowlist and machine replacement

Use this when `check-hw` succeeded and `tx register auth` failed the allowlist, or when you are moving a machine id that is already bound to your consensus key.

Take the machine id from `check-hw` (40 hex characters). To replace a machine, the old id must already be on the list and bound to the consensus key that the new quote will carry. Hardware is on [SGX prerequisites](/operators/sgx).

Every platform, including Azure, needs the machine id on the enclave allowlist.

## Add a new id

Do this before the first successful `tx register auth`. `check-hw` does not add the id. The enclave boots with a compiled-in allowlist. Governance can add ids after that.

Pass a proposal whose message is `/secret.compute.v1beta1.MsgUpdateMachineWhitelistProposal`, field `machine_id`, a comma-separated list of hex machine ids. Authority is the governance module account.

After status `PROPOSAL_STATUS_PASSED`, send a second transaction. Pass two arguments. `machine_ids` must equal the proposal string exactly.

```bash
secretd tx compute update-machine-whitelist <proposal-id> <machine_ids>
```

The transaction fails if the proposal is not passed, does not contain exactly one message, or has the wrong type URL. On success the id is added.

Do not use `--replace-machine-id` for an id that has never been on the list.

## Replace a listed machine

Stop the old process first. See [Validator](/operators/validator). Copy `config/priv_validator_key.json` from the old home to the new home before `init-enclave`, so the new quote’s owner field is that same key. Then run `init-enclave`, then:

```bash
secretd tx register auth /opt/secret/.sgx_secrets/attestation_combined.bin \
  --replace-machine-id <40 hex chars of the old machine id> \
  --from KEY --chain-id secret-4 \
  --node https://rpc.secret.mainnet.secret3.dev
```

Pass 40 hex characters. Anything else is treated as no replacement. The swap succeeds only when the old id is on the list, its stored owner equals this quote’s validator key, and the new id is not already present. Failures log `Failed to replace MachineID - machine … not owned by validator key …`, `unknown machine`, or `machine … already exists`, and the transaction is `InvalidCert`. The allowlist key is the quote’s PPID hash. `--replace-machine-id` is only the id you are removing. After a successful replace the old machine logs `Self machine included: false`.

## Id already listed on this machine

Register with no `--replace-machine-id` to bind this machine to your validator key. An unknown machine fails with `unknown machine`. Produce the quote and seed on [Register the node](/operators/register).

## Upgrade

Replacing the deb on a machine that is already registered does not add or remove an id. A hardware change that changes the PPID does. Follow the replace steps above.

Source: https://docs-redux.pages.dev/operators/allowlist/index.mdx
