eRoT (External Root of Trust)
All eRoTs are provisioned with certificates that are rooted in an NVIDIA root certificate. Alternative, non-NVIDIA provided attestation certificates are not supported.
The diagram below illustrates the structure of the certificate chain returned by the eRoTs via the GET_CERTIFICATE SPDM command. The eRoT certificate chains comply with TCG DICE standards. This certificate chain can be accessed through both the Redfish and NVUE APIs.
