> The signing tool supports a single-step signing process, which requires
> the access to the signing key pair on the local build system. However,
> there is a requirement that any white-listed enclave signing key must
> be managed in a hardware security module. Thus, the ISV’s test private
> key stored in the build platform will not be white-listed and enclaves
> signed with this key can only be launched in debug or prerelease mode.
And, indeed, launching an enclave without debug mode set fails with 'SGX_ERROR_SERVICE_INVALID_PRIVILEGE' error.A debuggable SGX enclave enables read-a-word and write-a-word primitives, so loses its confidentiality and integrity.