# [Run an end-to-end attestation flow with Arm CCA and Trustee](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-trustee/)

## In this learning path

- [Introduction](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-trustee/)
- [Architecture overview for Arm CCA Attestation with Trustee](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-trustee/cca-trustee/)
- [Run an end-to-end Attestation with Arm CCA and Trustee](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-trustee/flow/)
- [Next Steps](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-trustee/_next-steps/)

## About this Learning Path

| Skill level: | Advanced              |
|--------------|-----------------------|
| Reading time:| 1 hr                  |
| Last updated:| 03 Jul 2026           |

| Author:    | Anton Antonov |
|------------|---------------|
| Arm IP:    | [Neoverse](https://support.arm.com/?tab=compute-ip&Product%20Type=Infrastructure%20Processors) [Cortex-A](https://support.arm.com/?tab=compute-ip&Product%20Type=Application%20Processors) |
| Tags:      | [Performance and Architecture](https://learn.arm.com/tag/performance-and-architecture) [Linux](https://learn.arm.com/tag/linux) [macOS](https://learn.arm.com/tag/macos) [FVP](https://learn.arm.com/tag/fvp) [RME](https://learn.arm.com/tag/rme) [CCA](https://learn.arm.com/tag/cca) [Docker](https://learn.arm.com/tag/docker) [Veraison](https://learn.arm.com/tag/veraison) [Trustee](https://learn.arm.com/tag/trustee) |

### Who is this for?

This Learning Path is for software developers who want to run an end-to-end attestation flow using Arm Confidential Compute Architecture (CCA) and Trustee services.

### What will you learn?

Upon completion of this Learning Path, you will be able to:

- Describe how you can use attestation with Arm's Confidential Computing Architecture (CCA) and Trustee services
- Deploy a simple workload in a CCA realm on an Armv9-A AEM Base Fixed Virtual Platform (FVP) that has support for RME extensions
- Connect the workload with Trustee services to create an end-to-end example that uses attestation to unlock the confidential processing of data

### Prerequisites

Before starting, you will need the following:

- An AArch64 or x86_64 computer running Linux or macOS; you can use cloud instances - see the [Arm cloud service providers](https://learn.arm.com/learning-paths/servers-and-cloud-computing/csp/)
- Completion of the [Get started with CCA attestation and Veraison](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-veraison/) Learning Path
- Completion of the [Run an end-to-end attestation flow with Arm CCA](https://learn.arm.com/learning-paths/servers-and-cloud-computing/cca-essentials/) Learning Path

### Summary

You’ll complete an end-to-end confidential computing attestation flow on an Arm Fixed Virtual Platform using Arm Confidential Compute Architecture and Trustee services. First, you’ll start the Trustee components, launch a Linux realm on an Armv9-A FVP with Realm Management Extension (RME), and generate attestation evidence from the realm. After intentionally denying the first secret request to see how policy-based gating works, you’ll endorse the realm initial measurement (RIM), repeat attestation, and retrieve the secret after the environment proves its isolation properties. By the end, you’ll exercise and validate the complete path from evidence generation to policy-controlled secret release.

### Frequently asked questions

<details><summary>What result should I expect from the first secret request?</summary>
The initial request is expected to fail. The attestation policy blocks secret release until the realm initial measurement (RIM) is endorsed.
</details>

<details><summary>How do I know the Trustee services are running correctly before launching the realm?</summary>
Check the Docker container status and logs for the Trustee services. They should start without errors and be ready to accept requests.
</details>

<details><summary>When should I endorse the RIM, and how do I confirm it worked?</summary>
Endorse the RIM after the first secret request is denied. After endorsement, re-run attestation and expect the secret request to succeed.
</details>

<details><summary>How can I verify that the realm generated attestation evidence?</summary>
The realm run produces evidence that the Attestation Service (AS) processes. Check the output and logs for evidence generation and a corresponding response from the AS.
</details>

<details><summary>How do I know the FVP realm is ready before requesting a secret?</summary>
The Linux realm should complete boot on the FVP and be able to produce attestation evidence. If evidence generation fails, resolve that before proceeding to secret requests.
</details>
