This tutorial will discuss and demonstrate remote verification of a platform’s hardware, firmware and runtime (IMA) events using open source components with industry standard protocols. It will show client utilities to send verifiers a collection of firmware and runtime measurement all in the TCG defined Canonical Event Log format. It will show a utility that suppliers can use to send verifiers a collection of expected firmware and runtime golden measurements in TCG defined signed structures as extensions to SWID Tags. It will show how to use an open source verifier to confirm that the platform booted with the expected firmware and is running the expected software. It will show how these components, along with TPM and Platform Certificates can be part of a complete Trusted Supply Chain solution by integration with the HIRS project (https://github.com/nsacyber/HIRS).