> On 6 Aug 2026, at 9:30 PM, Abhisek Panda <[email protected]> wrote:
> 
> 
>> On 29 Jul 2026, at 2:28 PM, Abhisek Panda <[email protected]> wrote:
>> 
>> QEMU provides the capability to encrypt the migration data stream using
>> two transport layer security (TLS) authentication schemes: X.509
>> certificates and pre-shared keys (PSK). Currently, Libvirt only
>> supports the X.509-based TLS authentication scheme. In TLS X.509
>> certificates, a set of live migrations utilize a fixed
>> set of static certificates for encrypted migration. In this
>> authentication scheme, users require to deploy a certificate authority
>> and monitor the certificate expiration window. In case certificates
>> are compromised all the future live migrations are vulnerable.
>> 
>> To resolve this, this patch series introduce the support for pre-shared
>> key-based authentication scheme. This mechanism relies on symmetric
>> pre-shared keys (a secret key that is known to both sender and receiver
>> prior to secure communication) for providing secure transfer of data.
>> Libvirt solely manages the lifecycle of the ephemeral pre-shared keys,
>> including, generation, persistent storage, and cleanup. Libvirt
>> generates the key on the source machine, then transfers it to the
>> destination machine using the migration cookie. To allow users to
>> configure the size of the key, Libvirt provides the
>> migrate_tls_psk_length configuration parameter in qemu.conf.
>> 
>> To avoid introduction of an additional VIR_MIGRATE_* flag, we rely on
>> existing the VIR_MIGRATE_TLS flag. If the VIR_MIGRATE_TLS flag
>> is set but the necessary X.509 credential files are missing on the
>> destination, then we fallback to using PSK-based authentication scheme
>> during migration.
>> 
>> v3:
>> 1. Destination host decides which TLS authentication scheme to use.
>> 2. The directory of the key file is set to
>>    <tls_psk_state_dir>/$ID-$VMNAME.
>> 3. Use the same alias for both tls-creds-x509 and tls-creds-psk
>>    objects.
>> 4. Validate the length of the pre-shared key.
>> 5. Unit test to validate the pre-shared key in the migration cookie.
>> 
>> v2:
>> 1. Libvirt manages the lifecycle of pre-shared keys.
>> 2. Transfer of keys to the destination via the migration cookie
>> 3. Remove the VIR_MIGRATE_TLS_PSK flag instead rely on
>>    VIR_MIGRATE_TLS and availability of ca-cert.pem on source.
>> 4. Drop VIR_MIGRATE_PARAM_TLS_PSK_DIRECTORY, Libvirt solely manages
>>    the pre-shared keys.
>> 
>> Abhisek Panda (7):
>> conf: Add a configuration param for TLS-PSK
>> qemu: Manage a pre-shared key's lifecycle
>> qemu: Add support to build the tls-creds-psk object
>> qemu: rename tls-creds-x509 obj related functions
>> qemu: Manage tls-creds-psk object lifecycle
>> qemu: Set up the migrate TLS-PSK objects
>> tests: Add testing of pre-shared key lifecycle
>> 
>> include/libvirt/libvirt-domain.h   |  11 +-
>> src/qemu/libvirtd_qemu.aug         |   1 +
>> src/qemu/qemu.conf.in              |   8 ++
>> src/qemu/qemu_command.c            |  26 ++++
>> src/qemu/qemu_command.h            |   7 +
>> src/qemu/qemu_conf.c               |  22 ++++
>> src/qemu/qemu_conf.h               |   2 +
>> src/qemu/qemu_domain.c             |   1 +
>> src/qemu/qemu_domain.h             |   1 +
>> src/qemu/qemu_driver.c             |   6 +
>> src/qemu/qemu_hotplug.c            |  40 +++---
>> src/qemu/qemu_hotplug.h            |  24 ++--
>> src/qemu/qemu_migration.c          | 202 +++++++++++++++++++++++++----
>> src/qemu/qemu_migration_cookie.c   |  94 +++++++++++++-
>> src/qemu/qemu_migration_cookie.h   |   5 +
>> src/qemu/qemu_migration_params.c   |  98 +++++++++++---
>> src/qemu/qemu_migration_params.h   |  22 +++-
>> src/qemu/test_libvirtd_qemu.aug.in |   1 +
>> tests/qemumigrationcookiexmltest.c | 141 +++++++++++++++++++-
>> tests/testutilsqemu.c              |  12 ++
>> 20 files changed, 631 insertions(+), 93 deletions(-)
>> 
>> -- 
>> 2.43.7
>> 
> 
> Ping for the series.
> 
> Checking in to see if anyone has feedback on this patch set.
> 
> Thanks and warm regards
> Dr. Abhisek Panda

Ping for the series.

Checking in to see if anyone has feedback on this patch set.

Thanks and warm regards
Dr. Abhisek Panda


Reply via email to