Attested TLS has had some rough patches lately which can be attributed to making big changes to a complex protocol.
It really better to separate the attestation, the check against policy and then the TLS stuff. Solve one problem at a time, sign that progress and move on.