Re: [RFC] Allowing SEV attestation

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 5/6/21 6:51 AM, Daniel P. Berrangé wrote:
>> It looks like QEMU will expose commands needed for attestation via QMP [3].
> 
> As mentioned in my reply to that thread, I believe we can already do
> pretty much all of that via a combination of libvirt APIs & guest XML.

This is not a good user experience. The entire attestation process
should be made ephemeral, taking place 100% over a socket. Enabling a
fully socket-based attestation workflow will decouple it from the domain
XML and the host file system and make it easier for guest-owner tooling
to facilitate attestation.

Connor




[Index of Archives]     [Virt Tools]     [Libvirt Users]     [Lib OS Info]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite News]     [KDE Users]     [Fedora Tools]

  Powered by Linux