- Intel® Software Guard Extensions for Linux* OS
Intel® Software Guard Extensions (Intel® SGX) is an Intel technology for application developers seeking to protect select code and data from disclosure or modification.
The Linux* Intel® SGX software stack is comprised of the Intel® SGX driver see note, the Intel® SGX SDK and the Intel® SGX Platform Software (PSW).
Note
Starting with release 2.30, the SDK (including samples) as well as the SGX enclave runtime libraries are maintained in
confidential-computing.sgx.sdk and vendored here as the sdk submodule.1
- The
sdk-extraction-2.30tag captures the same source state ( 🏷️ SGX ↔ 🏷️ SGX SDK) at split.
Note
The Linux* kernel includes the SGX driver since mainline release 5.11 — no separate driver installation is needed on modern kernels. Device nodes are at /dev/{sgx_enclave, sgx_provision}. The platform must support and have Flexible Launch Control configured.
Related Projects
The intel-device-plugins-for-kubernetes project enables users to run container applications running Intel® SGX enclaves in Kubernetes clusters. It also gives instructions how to set up ECDSA based attestation in a cluster.
The intel-sgx-ssl project provides a full-strength general purpose cryptography library for Intel® SGX enclave applications. It is based on the underlying OpenSSL* Open Source project.
- Intel® SGX SDK provides a build combination to build out a SGXSSL-based SDK.
- Users can also use this cryptography library in SGX enclave applications separately.
The Intel® SGX Data Center Attestation Primitives (DCAP) project provides libraries and tools for ECDSA-based remote attestation targeted for data centers, cloud service providers, and enterprises, including the Quoting Library, PCK Certificate Caching Service (PCCS), Quote Verification Library, and more.
See License.txt for details.
See CONTRIBUTING.md for details.
For questions and general discussion, the Intel® SGX community forum is a good place to start.
- Intel® SGX for Linux* OS project home page on Intel Developer Zone
- Intel® Confidential Computing Enabling documentation
- Intel® SGX for Linux* OS — release documents
- Developer Guide — enclave design patterns, sealing, attestation concepts
- Developer Reference — SDK/EDL API reference (edger8r, trts/urts)
- Intel® SGX Programming Reference2
- SDM Vol 3D: System Programming Guide, Part 4 — SGX architecture, data structures, ENCLS/ENCLU leaf function reference
- SDM Vol 2: Instruction Set Reference — ENCLS/ENCLU instruction opcode encoding
Pre-built packages for Linux are published on 01.org:
- Intel® SGX PSW and SDK — distro packages and the SDK installer binary
- Intel® SGX DCAP — quoting and verification libraries
Packages can be installed directly, or via a live repository (Intel-hosted) or a local repository assembled from the packages above. Both approaches and the full installation procedure are covered in the Intel® SGX Software Installation Guide for Linux*.
Note: Packages and repository metadata published by Intel are signed with the GPG package signing key (fingerprint: 1504 34D1 488B F803 08B6 9398 E5C7 F0FA 1C6C 6C3C, "Intel(R) Software Development Products").
Note
Windows*: The Intel® SGX SDK, DCAP, and Platform Software for Windows* are distributed via the Intel® License & Registration Center (login required; the product suite covers the SDK, DCAP, and PSW). See the Getting Started with Intel® SGX SDK for Windows* guide for setup instructions. Individual packages (SDK, headers, enclave common API, DCAP components) are also available on NuGet.
Clone this repository, then use Docker and Docker Compose to get up and running quickly. Two modes are available — pick the one that fits your goal.
-
Build from source — compiles the Intel® SGX PSW and SDK inside Docker, then runs a sample enclave. See docker/build/README.md for details.
# 'make preparation': apply patches and download prebuilt dependencies make preparation \ && cd docker/build && ./build_compose_run.sh
-
Use pre-built packages — downloads the Intel® SGX PSW and SDK from 01.org (no local build required) and deploys a sample SGX application. See linux/installer/docker/README.md for details.
cd linux/installer/docker && ./build_compose_run.sh
The following Linux* distributions are supported for both building and installing the Intel® SGX software stack:
- Ubuntu* Server (64-bit): 22.04, 24.04, 26.04 LTS
- Red Hat Enterprise Linux* Server (64-bit): 9.6, 9.8, 10.0, 10.2
- CentOS* Stream (64-bit): 9, 10
- SUSE Linux Enterprise Server* (64-bit): 15 SP7, 16
- Anolis* OS (64-bit): 8.10
- Azure* Linux (64-bit): 3.0
- Debian* (64-bit): 10, 12, 13
-
Ensure that you have one of the supported operating systems.
-
To build the Intel® SGX SDK, install its build toolchain (gcc 7.3+ and glibc 2.27+ are required). On Ubuntu, for example:
sudo apt-get install build-essential ocaml ocamlbuild automake autoconf \ libtool wget python-is-python3 libssl-dev git cmake perlThe full per-distribution list is in the SDK repository.
-
Install the additional tools required to build the Intel® SGX PSW:
-
System libraries and build tools — install the packages for your distribution:
- On Debian 10, Debian 12, Debian 13, Ubuntu 22.04, Ubuntu 24.04, and Ubuntu 26.04:
sudo apt-get install libssl-dev libcurl4-openssl-dev protobuf-compiler \ libprotobuf-dev debhelper cmake reprepro unzip pkgconf libboost-dev \ libboost-system-dev libboost-thread-dev lsb-release libsystemd0 - On Red Hat Enterprise Linux 9.6, 9.8, 10.0, and 10.2:
sudo yum install openssl-devel libcurl-devel protobuf-devel cmake \ rpm-build createrepo yum-utils pkgconf boost-devel \ protobuf-lite-devel systemd-libs - On CentOS Stream 9 and 10:
sudo dnf install openssl-devel libcurl-devel protobuf-devel cmake \ rpm-build createrepo yum-utils pkgconf boost-devel \ protobuf-lite-devel systemd-libs - On Anolis 8.10:
sudo dnf --enablerepo=PowerTools install openssl-devel libcurl-devel \ protobuf-devel cmake rpm-build createrepo yum-utils pkgconf \ boost-devel protobuf-lite-devel systemd-libs - On Azure Linux 3.0:
sudo dnf --enablerepo=powertools install openssl-devel libcurl-devel \ protobuf-devel cmake rpm-build createrepo yum-utils pkgconf \ boost-devel protobuf-lite-devel systemd-libs - On SUSE Linux Enterprise Server 15 SP7 and 16:
sudo zypper install libopenssl-devel libcurl-devel protobuf-devel cmake \ rpm-build createrepo_c libsystemd0 libboost_system1_66_0-devel \ libboost_thread1_66_0-devel
- On Debian 10, Debian 12, Debian 13, Ubuntu 22.04, Ubuntu 24.04, and Ubuntu 26.04:
-
The Intel® SGX SDK installer — required before building the PSW. Either:
- Build it from this repo:
make sdk_install_pkg(see Build the Intel® SGX SDK below), or - Download a pre-built release from 01.org:
wget -r -l1 -np -nd --accept 'sgx_linux_x64_sdk_*.bin' \ https://download.01.org/intel-sgx/latest/linux-latest/distro/<distro>/
Then install it — same for both methods (the installer will prompt you to accept the license; adjust
--prefixto your preferred location):./sgx_linux_x64_sdk_*.bin --prefix=$(pwd) source $(pwd)/sgxsdk/environment
- Build it from this repo:
-
-
If you haven't already cloned this repository, do so now and prepare the submodules and prebuilt binaries:
git clone --recurse-submodules \ https://github.com/intel/confidential-computing.sgx.git sgx-source cd sgx-source && make preparationmake preparationinitialises git submodules, applies patches, and runsdownload_prebuilt.shto fetch prebuilt binaries. If you prefer to initialise submodules manually (e.g. to control depth or mirror URLs), do so before runningmake preparation:git submodule update --init --recursive
💡 Tip: Both
git submodule updateanddownload_prebuilt.sh(wget) fetch over the network. If you are behind a proxy, set the relevant proxy variables first, e.g.:export https_proxy=http://proxy:port export no_proxy=localhost,127.0.0.1
ℹ️ Note: When pulling a new release, run
make distcleanfirst if patched submodules changed — this avoids patch conflicts (error: Your local changes to the following files would be overwritten by checkout). Caution: this deletes all submodule working trees; commit any local changes first.make distclean
-
(Debian 10 only) The system
binutilson Debian 10 lacks mitigation options support. Copy the patched tools downloaded bymake preparationto/usr/local/bin:sudo cp external/toolset/debian10/* /usr/local/binRepeat after any update to ensure the latest versions are used.
The Intel® SGX SDK is maintained in the confidential-computing.sgx.sdk repository and vendored here as the sdk submodule. If you prefer to build everything in one place, it can be built from this repository:
make sdk # LOAD + CF + no-mitigation passes (sdk_install_pkg runs this automatically)
make sdk_install_pkg # bundles all three variants into one .bin installerFor build flavors (USE_OPT_LIBS, DEBUG, make sdk_install_pkg_no_mitigation), see the SDK repository README.
The Intel® SGX Platform Software (PSW) covers the following components built from this repository:
-
SGX Runtime System (RTS, enclave runtime) (
libsgx-urts,libsgx-enclave-common) — the SGX loader and enclave-common API. Sourced from the confidential-computing.sgx.sdk repository (sdk/enclave_runtime/) via thesdksubmodule. -
Architectural Enclave Service Manager (AESM) — the
aesmdbackground daemon hosting the attestation enclaves (PCE, QE3, IDE), pluslibsgx-quote-ex, the untrusted client library applications use to request quotes from the daemon, andlibsgx-uae-service, a binary-compatibility shim over it for applications linked against the legacy Untrusted AE (UAE) API.ℹ️ Note: The DCAP quoting library (
libsgx-dcap-ql) fromexternal/dcap_source/can operate either in-process (loading QE3 directly into the app, no daemon required) or out-of-process (delegating to AESM vialibsgx-quote-ex). In both modes, QPL (libdcap_quoteprov) is loaded at runtime to fetch PCK certificate collateral from PCCS/Intel PCS.
make psw builds both the enclave runtime (via sdk_urts from the SDK submodule) and the AESM service together.
-
To build the Intel® SGX PSW (both the runtime libraries as well as the AESM) with default configuration:
make psw
Tools and libraries are generated in the
build/linuxdirectory.💡 Tip: To build each part standalone:
- Enclave runtime only:
make sdk_urtsfrom the root (ormake urtsdirectly insdk/). - AESM side only:
makedirectly inpsw/— provided the enclave runtime has already been built.
- Enclave runtime only:
-
To build with debug information:
make psw DEBUG=1
-
To clean files generated by a previous
make psw:make clean
-
To build the Intel® SGX PSW installer packages (
DEB/RPM):ℹ️ Note: The packaging bundles prebuilt Intel® Architecture Enclaves (PCE3, QE3, IDE), signed by Intel, downloaded by
make preparation. To build any of these yourself (unsigned), e.g. PCE:cd psw/ae/pce && make
To verify or reproduce them, see Reproducibility.
For packaging, run the command matching your package format:
-
DEB-based systems (Ubuntu 22.04/24.04/26.04, Debian 10/12):
make deb_psw_pkg
Packages are generated under
linux/installer/deb/and cover the three components required to run SGX workloads and generate SGX ECDSA quotes:- Enclave runtime —
libsgx-urts,libsgx-enclave-common - AESM daemon and client libraries —
sgx-aesm-service(with PCE/ECDSA/quote-ex plugins),libsgx-quote-ex,libsgx-uae-service - SGX DCAP quoting stack —
libsgx-dcap-ql,libsgx-pce-logic,libsgx-qe3-logic, QPL (libsgx-dcap-default-qpl), and the signed enclaves they drive (libsgx-ae-pce,libsgx-ae-qe3,libsgx-ae-id-enclave)
Use
make deb_local_repoto assemble a complete local repository that additionally includes TDX quoting, quote verification, appraisal, PCCS, and platform registration tools. The repository is generated underlinux/installer/deb/sgx_debian_local_reporelative to the repo root. Register it and refresh apt — adjust the path if you moved or copied the repo elsewhere:echo "deb [trusted=yes arch=amd64] file:$PWD/linux/installer/deb/sgx_debian_local_repo $(. /etc/os-release && echo $VERSION_CODENAME) main" \ | sudo tee /etc/apt/sources.list.d/sgx-local.list sudo apt update
💡 Tip: To ensure locally built packages take precedence over any same-named packages from official repositories, pin the local repo to a higher priority:
printf 'Package: *\nPin: origin ""\nPin-Priority: 1001\n' \ | sudo tee /etc/apt/preferences.d/sgx-local
ℹ️ Note: A
*-dbgsym_*.ddebpackage is always produced alongside each.debbydh_strip.In a default (release) build it contains only minimal symbol information; use
DEBUG=1to rebuild with-O0 -ggdband get fully populated symbol packages:make deb_psw_pkg DEBUG=1
Debian 10 only: the default
PATHmay not include/sbin— add it before building:export PATH=$PATH:/sbin
- Enclave runtime —
-
RPM-based systems (RHEL 9.6/9.8/10.0/10.2, CentOS Stream 9/10, Anolis OS 8.10, SLES 15 SP7/16):
make rpm_psw_pkg
Use
make rpm_local_repoto assemble a complete local repository that additionally includes TDX quoting, quote verification, appraisal, PCCS, and platform registration tools. The repository is generated underlinux/installer/rpm/sgx_rpm_local_reporelative to the repo root. Register it with highest priority so locally built packages take precedence — adjust the path if you moved or copied the repo elsewhere:- On RHEL/CentOS Stream/Anolis:
sudo dnf config-manager --add-repo file://$PWD/linux/installer/rpm/sgx_rpm_local_repo sudo dnf config-manager --save --setopt="*sgx_rpm_local_repo*.priority=1" \ --setopt="*sgx_rpm_local_repo*.gpgcheck=0"
- On SLES 15 SP7/16:
sudo zypper addrepo --priority 1 --no-gpgcheck \ $PWD/linux/installer/rpm/sgx_rpm_local_repo sgx-local
ℹ️ Note: To build with debug information:
make rpm_psw_pkg DEBUG=1
- On RHEL/CentOS Stream/Anolis:
-
The make sdk_install_pkg build above produces the installer at linux/installer/bin/sgx_linux_x64_sdk_${version}.bin. A typical install is:
cd linux/installer/bin
# omit --prefix to choose the install path interactively:
sudo ./sgx_linux_x64_sdk_${version}.bin --prefix /opt/intel
source /opt/intel/sgxsdk/environment # set up the build environmentThat covers the common case. The full installation manual — non-interactive options, custom prefixes, environment setup and the code samples — is maintained in the SDK repository. To run the samples in hardware mode you also need the Intel® SGX PSW installed (see Install the Intel® SGX PSW below).
The Intel® SGX SDK sample enclaves and host applications live in the SDK source tree under SampleCode/; they are also packaged by the SDK installer, so the same samples are available after installation. See the SDK README for simulation-mode and hardware-mode walkthroughs.
For remote attestation and quoting flows, start with the DCAP samples, especially QuoteGenerationSample and QuoteVerificationSample in the repository's SampleCode/ directory.
Before installing, ensure that:
- Your system runs one of the supported operating systems.
- Your hardware supports Intel® SGX with Flexible Launch Control (FLC). This includes select Intel® Xeon® Scalable, Xeon® D, Xeon® E, Core™, and Atom® processors — see Which Platforms Support Intel® SGX DCAP? for the full list.
- Intel SGX hardware mode is enabled in the firmware and a Linux* kernel with SGX driver support is running4.
Starting with release 2.8, the PSW is split into smaller packages — install only the features you need. Use the local repo method where possible: the package manager resolves dependencies automatically.
Note
Removed in release 2.28. All legacy EPID-based functionality has been removed, including EPID provisioning and attestation (QE/PVE) and platform services (PSE). Whitelist-based launch control and support for the deprecated [ref1], [ref2] out-of-tree Linux kernel drivers have also been removed.
For a full step-by-step walkthrough — including how to set up the Intel SGX package repository, alternative installation methods, and platform-specific notes — see the Intel® SGX Software Installation Guide for Linux.
Install the top-level package for your use case — the package manager resolves all dependencies automatically:
| Package | Purpose | Depends | Recommends |
|---|---|---|---|
libsgx-urts |
SGX enclave loader and runtime | libsgx-enclave-common |
— |
libsgx-dcap-ql |
DCAP ECDSA quoting — in-process by default; set SGX_AESM_ADDR to delegate to AESM |
• quoting orchestration (host-side, untrusted wrappers): libsgx-qe3-logic, libsgx-pce-logic• architectural enclaves (signed, runs in SGX): libsgx-ae-qe3, libsgx-ae-id-enclave, libsgx-ae-pce• enclave loader: libsgx-urts |
• libsgx-dcap-quote-verify• libsgx-quote-ex (for AESM-delegated mode) |
libsgx-quote-ex |
Algorithm-agnostic quote client (sgx_get_quote_ex API, delegates to AESM via Unix socket);Note: A separate package: libsgx-uae-service is a compat shim over it for apps linked against the older API |
(shlibs only) | • libsgx-aesm-quote-ex-plugin |
libsgx-dcap-default-qpl |
Quote collateral provider — fetches collateral (PCK certificates for quote generation, and/or reference values for quote verification) from PCCS (self-hosted cache) or directly from Intel PCS | libcurl4 |
— |
| Notable supporting packages | |||
libsgx-aesm-quote-ex-plugin |
AESM plugin: algorithm-agnostic quoting via QE3 | • sgx-aesm-service• libsgx-aesm-ecdsa-plugin (pulls the same logic/AE/loader deps as libsgx-dcap-ql, routed via libsgx-aesm-pce-plugin) |
— |
libsgx-dcap-quote-verify |
Quote verification (QVL) and appraisal (QAL) — both APIs exported from the same .so; for each, the caller selects either the hardware-attested mode (running inside QVE/QAE respectively - both in-process) or software-only mode |
(shlibs only) | • libsgx-ae-qve (QVE enclave image)• libsgx-urts (required to load QVE or QAE)• Note: libsgx-ae-qae |
Important
libsgx-dcap-default-qpl is not pulled in automatically by any package — it is loaded at runtime via dlopen("libdcap_quoteprov.so.1") by libsgx-qe3-logic (in-process quoting), libsgx-dcap-quote-verify (in-process verification), and AESM (delegated path).
Install it explicitly when live collateral fetching is needed.
Note
sgx-aesm-service arrives automatically on a default installation via the Recommends chain (libsgx-aesm-quote-ex-plugin → sgx-aesm-service).
libsgx-quote-ex always requires a running AESM daemon at runtime — it connects to the AESM Unix socket unconditionally; the Recommends rather than Depends is a packaging flexibility that allows the daemon to be provided externally (e.g. a host socket bind-mounted into a container). To suppress it — for example when using only libsgx-dcap-ql in in-process mode — pass --no-install-recommends (see Configure the installation).
Tip
The package manager command depends on the distribution:
sudo apt-get install(Ubuntu, Debian),sudo dnf install/sudo yum install(RHEL, CentOS Stream, Anolis OS, Azure Linux)sudo zypper install(SLES).
Note
Optionally install *-dbgsym (DEB) / *-debuginfo (RPM) packages for debug symbols, or *-dev (DEB) / *-devel (RPM) packages for development headers and static link libraries.
When upgrading from a legacy installation to a newer release where packages were reorganised (files moved between packages, or a single package split into smaller ones), or when mixing release packages with locally built ones, the package manager may report a file conflict:
# DEB: dpkg: error processing archive ... (--unpack): trying to overwrite ...
# RPM: file ... from install of ... conflicts with file from package ...
To resolve this, choose one of:
- Clean upgrade (DEB and RPM) — uninstall the legacy packages first, then install the new ones. This is the recommended path for RPM-based systems.
- In-place upgrade (DEB only) — use
dist-upgradeinstead ofupgrade, and pass--force-overwritethrough to dpkg:For locally builtapt-get dist-upgrade -o Dpkg::Options::="--force-overwrite".rpmpackages,rpm -Uvh --replacefilesachieves the equivalent.
Some packages list optional Recommends that are not required for all use cases — for example, the AESM daemon is not needed for fully in-process deployments or container workloads where the daemon runs on the host and its Unix socket is bind-mounted in. Recommends are installed by default; to suppress them, pass the appropriate flag to the install command:
| Distribution | Flag |
|---|---|
| Ubuntu, Debian | apt-get install --no-install-recommends <package> |
| RHEL, CentOS Stream, Anolis OS, Azure Linux | dnf install --setopt=install_weak_deps=False <package> |
| SLES | zypper install --no-recommends <package> |
In addition to the prerequisites and the packages in the table above:
-
Hardware — requires FLC-capable hardware (8th Gen Intel® Core™ or newer, or Intel® Atom® with FLC). See Which Platforms Support Intel® SGX DCAP?.
-
QPL — install
libsgx-dcap-default-qpl(see the[!IMPORTANT]callout in the package table) or provide a customlibdcap_quoteprov.so.1. -
<recommended> PCCS — deploy a Provisioning Certificate Caching Service and configure
/etc/sgx_default_qcnl.conf(JSON; overridable per-process viaQCNL_CONF_PATH).
For all available keys and their semantics, see the annotated default config.Example (on-premises PCCS):
{ "pccs_url": "https://your_pccs_server:8081/sgx/certification/v4/" }💡 Tip: For local testing or single-machine deployments, PCCS caching layer can be skipped — point the QPL directly at the Intel PCS by setting
pccs_urlin the config file:{ "pccs_url": "https://api.trustedservices.intel.com/sgx/certification/v4/" }For production scale deployments a local PCCS is strongly recommended: it caches collateral, reduces round-trip latency on every quote operation, and removes a dependency on a persistent internet connection.
ℹ️ Note: A PCS subscription key (
Ocp-Apim-Subscription-Key) is optional for most PCS APIs, but still recommended for production: without one, rate limits are shared across all anonymous callers; with one, your account receives a dedicated quota. When using PCCS, configure the key in PCCS itself — see the PCCS documentation. When pointing QCNL directly at Intel PCS, pass it as a custom request header:{ "pccs_url": "https://api.trustedservices.intel.com/sgx/certification/v4/", "custom_request_options": { "get_cert": { "headers": { "Ocp-Apim-Subscription-Key": "<your-subscription-key>" } } } }
The PSW installer registers aesmd as a systemd service running under the aesmd account:
sudo systemctl start aesmd
sudo systemctl stop aesmd
sudo systemctl restart aesmdNote
If using AESM-based out-of-process quoting, the QPL runs inside aesmd and makes outbound HTTP requests to PCCS or Intel PCS. If a proxy is required, configure it in /etc/aesmd.conf and restart the service. The same file also controls the QPL log level.
Intel® SGX ships several prebuilt binaries. All are produced inside a reproducible SGX Docker container to allow independent verification. To reproduce the build environment and verify the binaries, follow the reproducibility README.
Most binaries can be compared against a locally rebuilt output using the standard diff command. Architectural Enclaves (AEs) are an exception — their verification requires the dedicated AE reproducibility verifier. AE reproducibility also depends on a reproducibly built Intel® SGX SDK; the SDK's own reproducible build process is documented in the SDK repository.
Footnotes
-
This is a source-layout change only: the consolidated build is unchanged (
maketargets from this repository continue to build all the components), and the released packages, installers and download locations are not affected. ↩ -
The original standalone doc (329298) has been absorbed into the Intel® Software Developer's Manual (SDM); the two SDM volumes above are the current authoritative references. ↩
-
PCE is also copied into the PSW build output (
build/linux) duringmake psw. ↩ -
The Linux* kernel contains the necessary driver since the mainline kernel release
5.11. ↩