Q1: Which statement correctly scopes this EAT?
Multiple ChoiceAn A2A service operator says an EAT for its sandbox process attests the legal identity of the operating company and must contain the same claims in every deployment.
An A2A service operator says an EAT for its sandbox process attests the legal identity of the operating company and must contain the same claims in every deployment.
An attester sends EAT Evidence to a verifier. The verifier checks reference values and emits signed Attestation Results stating that approved software was measured. A relying party controls an A2A resource.
A device EAT reports dbgstat=disabled-fully-and-permanently at the top level. Its TEE appears as a submodule but has no dbgstat. Policy requires debug to be disabled for both device and TEE.
A verifier sends fresh challenge N2. The agent returns a correctly signed EAT containing eat_nonce N1 from yesterday's successful transaction, and every measurement still matches reference values.
An agent sends the same stable UEID to every A2A service, including unauthenticated discovery endpoints. Those services do not need a global device identifier for their authorization rules.
A gateway verifies an EAT and OAuth grant, checks a session-bound proof, then forwards only Attestation-Status: trusted to a backend. The backend owns the resource policy and cannot inspect the original EAT.