---
title: "SGX prerequisites"
description: "Confirm Intel SGX with FLC and DCAP on Ubuntu 22.04 or 24.04 before you start secretd."
---

> Documentation Index
> Fetch the complete documentation index at: https://docs-redux.pages.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# SGX prerequisites

:::caution
Do not treat `Platform Okay!` as success. `check-hw` does not put the machine on the allowlist. An Azure attestation JWT does not authorize registration.
:::

Confirm all four before you register:

1. `/proc/cpuinfo` flags include `sgx` and `sgx_lc`.
2. `/dev/sgx_enclave` and `/dev/sgx_provision` exist, and your user can open both.
3. `aesmd` is running and the quote provider can fetch collateral.
4. `check-hw`, loaded with the v1.27.2 mainnet enclave, prints `DCAP attestation obtained and verified ok` and `Platform verification successful! You are able to run a mainnet Secret node`, then `Your machine ID:`.

## Pick the machine

Use Intel SGX with FLC on Ubuntu 22.04 or 24.04, the in-kernel driver, and a route to a PCCS.

- CPU families: Xeon E-23xxG, Xeon D-1700, D-2700, D-1800, D-2800, Xeon Max, Xeon Scalable 3rd, 4th, and 5th gen.
- Motherboards: Supermicro X11SCM-F, X11SCW-F, X11SCZ-F, X11SSL-F; Dell R240 (BIOS 2.14.1) and R350 (BIOS 1.7.3); HP DL20 G10 (BIOS 1.80, 2023-07-20); ASUS RS100-E10-PI2 (BIOS 5601); ASRock E3C246D4U2-2T; GIGABYTE MX33-BS1 (BIOS F06).
- On Azure, use DCsv3 or DCdsv3 (Ice Lake, EPC large enough for the 512 MiB heap). 1.27.2 does not configure the quote path.
  - Ubuntu 22.04 on those sizes: Azure DCAP client, collateral from THIM. Do not use Intel IAS.
  - Ubuntu 24.04 on those sizes: Intel QPL, pointed at THIM. Do not install the Azure DCAP client.
- Do not use DCsv2. It is Xeon E-2288G. The largest published EPC is 168 MiB, below the heap.
- Do not use DCasv5, DCadsv5, ECasv5, or ECadsv5 (AMD SEV-SNP), or DCesv5, DCesv6, and EC TDX sizes. They do not load this enclave.
- On another provider, use the same device nodes and `check-hw`. You still need the allowlist.
- Do not use a Client Core CPU after the 11th generation, an EPID-only platform, AMD, or ME-only SGX.
- The enclave heap is `0x20000000` (512 MiB) plus an 8 MiB stack. A smaller EPC cannot start it.
- Give the host 32 GB RAM, 20 GB or more of swap, and a 512 GB SSD. 64 GB and 1 TB NVMe is the larger size.

## Steps

1. On a physical machine, install the latest BIOS, enable SGX (not software-controlled), disable Secure Boot, and disable hyperthreading. On 3rd Gen Xeon Scalable and newer, FLC is already on and is not a BIOS switch. On Azure DCsv3 or DCdsv3, skip the BIOS menu and pick a Gen2 image.

2. Confirm OS and CPU flags:

```bash
. /etc/os-release
# VERSION_ID must be 22.04 or 24.04
uname -r
grep -m1 '^flags' /proc/cpuinfo | tr ' ' '\n' | grep -E '^(sgx|sgx_lc)$'
```

3. Confirm the in-kernel nodes. Do not install the out-of-tree `.bin` driver on a kernel that already has in-kernel SGX.

```bash
ls -l /dev/sgx_enclave /dev/sgx_provision
dmesg | grep -i sgx
```

If the nodes are missing on 22.04 or 24.04, turn SGX on in firmware, use a CPU with FLC, or use an SGX VM. Intel’s kernel floor is 5.11. Ubuntu 22.04 GA is 5.15 and 24.04 GA is 6.8.

4. Install the DCAP runtime from Intel’s apt repo:

```bash
curl -fsSL https://download.01.org/intel-sgx/sgx_repo/ubuntu/intel-sgx-deb.key | sudo apt-key add -
. /etc/os-release
sudo add-apt-repository "deb https://download.01.org/intel-sgx/sgx_repo/ubuntu ${VERSION_CODENAME} main"
sudo apt-get update
sudo apt-get install -y \
  libsgx-aesm-launch-plugin libsgx-enclave-common libsgx-epid libsgx-launch \
  libsgx-quote-ex libsgx-uae-service libsgx-qe3-logic libsgx-pce-logic \
  libsgx-aesm-pce-plugin libsgx-dcap-ql libsgx-dcap-quote-verify libsgx-urts \
  sgx-aesm-service libsgx-aesm-ecdsa-plugin libsgx-aesm-quote-ex-plugin \
  libsgx-ae-qve libsgx-dcap-default-qpl
```

The build pin is PSW `2.25.100.3` and DCAP `1.22.100.3` for `jammy1` or `noble1`. Intel apt may publish newer packages.

`libsgx-enclave-common` creates the `sgx` group on systemd 248 and newer. `/dev/sgx_enclave` is then group-restricted.

5. Add your user to `sgx` and `sgx_prv`. Log in again and confirm both names are in `groups`. The deb `postinst` does not do this.

6. Point the quote provider at a PCCS. On Ubuntu 22.04 DCsv3 or DCdsv3, use the Azure DCAP client and take collateral from THIM. Do not use Intel IAS. On Ubuntu 24.04 on those sizes, use Intel QPL pointed at THIM. Do not install the Azure DCAP client. 1.27.2 does not configure either path.

7. On a multi-socket Xeon Scalable, configure `sgx-ra-service` and read `/var/log/mpa_registration.log`.

8. Install the mainnet deb so the signed enclave is on disk. Stop before `init-enclave` and before `tx register`. Do not start `secret-node`. Follow [Install secretd](/operators/install).

9. `check-hw` from a directory that contains `check_hw_enclave.so`. The kit binary is at `kits/v1.27.2/mainnet/check-hw/check-hw`. Copy the signed enclave out of the deb:

```bash
mkdir -p "$HOME/check-hw" && cd "$HOME/check-hw"
curl -fsSL https://docs-redux.pages.dev/check-hw -o check-hw
chmod +x check-hw
dpkg-deb -x /tmp/secretnetwork_1.27.2_MAINNET_goleveldb_amd64_ubuntu-${VERSION_ID}.deb /tmp/sn127
cp /tmp/sn127/usr/lib/librust_cosmwasm_enclave.signed.so ./check_hw_enclave.so
./check-hw
```

Success text:

```text
Creating enclave instance..
DCAP attestation obtained and verified ok
DCAP attestation: Enclave quote is valid
Platform verification successful! You are able to run a mainnet Secret node
Your machine ID: <40 hex chars>
```

`check-hw` verifies the quote with the allowlist check off. It accepts `SGX_QL_QV_RESULT_OK` and `SGX_QL_QV_RESULT_SW_HARDENING_NEEDED`. If the result is not `OK`, it prints a warning and still treats the quote as verified. The allowlist check happens later, on chain.

Save the machine id. It is the first 20 bytes of SHA-256 over the platform PPID (40 hex characters). It changes if you toggle SGX, reset it in BIOS, replace the board or CPU, or install some firmware updates.

- If `check-hw` succeeds and `tx register auth` fails the allowlist, continue at [Allowlist and machine replacement](/operators/allowlist).
- Do not run `embed_azure_attestation.sh`.
- The deb depends only on `libsnappy1v5`. `dpkg -i` can succeed and `secretd` can still fail looking for `libsgx_urts.so.2`, `libsgx_dcap_ql.so.1`, or `libsgx_dcap_quoteverify.so.1`.
- Do not set `SGX_MODE=SW`.
- Check `check-hw` against sha256 `5f1fb76fb611e91bd8bb1ec3f12bb21216d66a0782b6bf21968309897c2c122d` in `kits/v1.27.2/SHA256SUMS`.

Run every step on a new machine. If this hardware already quoted and you only changed the OS, repeat the OS, device, and DCAP steps, then follow [Upgrade a seeded node](/operators/upgrade). Skip `check-hw` on a machine that is already signing. Run it before a new registration.

Source: https://docs-redux.pages.dev/operators/sgx/index.mdx
