> On 7 Sep 2026, at 2:26 PM, Abhisek Panda <[email protected]> wrote:
> 
> QEMU provides the capability to encrypt the migration data stream using
> two transport layer security (TLS) authentication schemes: X.509
> certificates and pre-shared keys (PSK). Currently, Libvirt only
> supports the X.509-based TLS authentication scheme. In TLS X.509
> certificates, a set of live migrations utilize a fixed
> set of static certificates for encrypted migration. In this
> authentication scheme, users require to deploy a certificate authority
> and monitor the certificate expiration window. In case certificates
> are compromised all the future live migrations are vulnerable.
> 
> To resolve this, this patch series introduce the support for pre-shared
> key-based authentication scheme. This mechanism relies on symmetric
> pre-shared keys (a secret key that is known to both sender and receiver
> prior to secure communication) for providing secure transfer of data.
> Libvirt solely manages the lifecycle of the ephemeral pre-shared keys,
> including, generation, persistent storage, and cleanup. Libvirt
> generates the key on the source machine, then transfers it to the
> destination machine using the migration cookie. To allow users to
> configure the size of the key, Libvirt provides the
> migrate_tls_psk_length configuration parameter in qemu.conf.
> 
> We enable the PSK-based TLS authentication scheme if both source and
> destination supports the tls-creds-psk object regardless of the value
> of VIR_MIGRATE_TLS flag. Else, we use the X.509-based TLS
> authentication scheme if the VIR_MIGRATE_TLS flag is set.
> 
> v4:
>  1. Enable TLS-PSK if source and destination supports it regardless of
>     the VIR_MIGRATE_TLS flag.
>  2. If either source or destination does not support TLS-PSK and the
>     VIR_MIGRATE_TLS flag is set then fallback to TLS X509
> 
> v3:
>  1. Destination host decides which TLS authentication scheme to use.
>  2. The directory of the key file is set to
>     <tls_psk_state_dir>/$ID-$VMNAME.
>  3. Use the same alias for both tls-creds-x509 and tls-creds-psk
>     objects.
>  4. Validate the length of the pre-shared key.
>  5. Unit test to validate the pre-shared key in the migration cookie.
> 
> v2:
>  1. Libvirt manages the lifecycle of pre-shared keys.
>  2. Transfer of keys to the destination via the migration cookie
>  3. Remove the VIR_MIGRATE_TLS_PSK flag instead rely on
>     VIR_MIGRATE_TLS and availability of ca-cert.pem on source.
>  4. Drop VIR_MIGRATE_PARAM_TLS_PSK_DIRECTORY, Libvirt solely manages
>     the pre-shared keys.
> 
> Abhisek Panda (7):
>  conf: Add a configuration param for TLS-PSK
>  qemu: Manage a pre-shared key's lifecycle
>  qemu: Add support to build the tls-creds-psk object
>  qemu: rename tls-creds-x509 obj related functions
>  qemu: Manage tls-creds-psk object lifecycle
>  qemu: Set up the migrate TLS-PSK objects
>  tests: Add testing of pre-shared key lifecycle
> 
> include/libvirt/libvirt-domain.h              |  10 +-
> src/qemu/libvirtd_qemu.aug                    |   1 +
> src/qemu/qemu.conf.in                         |   8 +
> src/qemu/qemu_capabilities.c                  |   2 +
> src/qemu/qemu_capabilities.h                  |   1 +
> src/qemu/qemu_command.c                       |  26 +++
> src/qemu/qemu_command.h                       |   7 +
> src/qemu/qemu_conf.c                          |  22 +++
> src/qemu/qemu_conf.h                          |   2 +
> src/qemu/qemu_domain.c                        |   1 +
> src/qemu/qemu_domain.h                        |   1 +
> src/qemu/qemu_driver.c                        |   6 +
> src/qemu/qemu_hotplug.c                       |  40 ++---
> src/qemu/qemu_hotplug.h                       |  24 +--
> src/qemu/qemu_migration.c                     | 170 +++++++++++++++---
> src/qemu/qemu_migration.h                     |   3 +
> src/qemu/qemu_migration_cookie.c              |  79 +++++++-
> src/qemu/qemu_migration_cookie.h              |   5 +
> src/qemu/qemu_migration_params.c              |  98 ++++++++--
> src/qemu/qemu_migration_params.h              |  22 ++-
> src/qemu/qemu_process.c                       |   3 +
> src/qemu/test_libvirtd_qemu.aug.in            |   1 +
> .../caps_10.0.0_aarch64.xml                   |   1 +
> .../caps_10.0.0_ppc64.xml                     |   1 +
> .../caps_10.0.0_s390x.xml                     |   1 +
> .../caps_10.0.0_x86_64+amdsev.xml             |   1 +
> .../caps_10.0.0_x86_64.xml                    |   1 +
> .../caps_10.1.0_s390x.xml                     |   1 +
> .../caps_10.1.0_x86_64+inteltdx.xml           |   1 +
> .../caps_10.1.0_x86_64.xml                    |   1 +
> .../caps_10.2.0_aarch64.xml                   |   1 +
> .../caps_10.2.0_x86_64+mshv.xml               |   1 +
> .../caps_10.2.0_x86_64.xml                    |   1 +
> .../caps_11.0.0_aarch64.xml                   |   1 +
> .../caps_11.0.0_s390x.xml                     |   1 +
> .../caps_11.0.0_x86_64+sgx.xml                |   1 +
> .../caps_11.0.0_x86_64.xml                    |   1 +
> .../caps_11.1.0_aarch64.xml                   |   1 +
> .../caps_11.1.0_s390x.xml                     |   1 +
> .../caps_11.1.0_x86_64.xml                    |   1 +
> tests/qemucapabilitiesdata/caps_7.2.0_ppc.xml |   1 +
> .../caps_7.2.0_x86_64+hvf.xml                 |   1 +
> .../caps_7.2.0_x86_64.xml                     |   1 +
> .../caps_8.0.0_x86_64.xml                     |   1 +
> .../qemucapabilitiesdata/caps_8.1.0_s390x.xml |   1 +
> .../caps_8.1.0_x86_64.xml                     |   1 +
> .../caps_8.2.0_aarch64.xml                    |   1 +
> .../caps_8.2.0_armv7l.xml                     |   1 +
> .../caps_8.2.0_loongarch64.xml                |   1 +
> .../qemucapabilitiesdata/caps_8.2.0_s390x.xml |   1 +
> .../caps_8.2.0_x86_64.xml                     |   1 +
> .../qemucapabilitiesdata/caps_9.0.0_sparc.xml |   1 +
> .../caps_9.0.0_x86_64.xml                     |   1 +
> .../caps_9.1.0_riscv64.xml                    |   1 +
> .../qemucapabilitiesdata/caps_9.1.0_s390x.xml |   1 +
> .../caps_9.1.0_x86_64.xml                     |   1 +
> .../caps_9.2.0_aarch64+hvf.xml                |   1 +
> .../qemucapabilitiesdata/caps_9.2.0_s390x.xml |   1 +
> .../caps_9.2.0_x86_64+amdsev.xml              |   1 +
> .../caps_9.2.0_x86_64.xml                     |   1 +
> tests/qemumigrationcookiexmltest.c            | 135 +++++++++++++-
> tests/testutilsqemu.c                         |  12 ++
> 62 files changed, 632 insertions(+), 85 deletions(-)
> 
> -- 
> 2.43.7
> 

Ping for the series.

Checking in to see if anyone has feedback on this patch set.

Thanks and warm regards
Dr. Abhisek Panda
 

Reply via email to