Re: [libvirt PATCH v2 09/12] tools: support generating SEV secret injection tables

2022-10-26 Thread Dov Murik
On 26/10/2022 15:51, Daniel P. Berrangé wrote: > On Wed, Oct 26, 2022 at 03:34:00PM +0300, Dov Murik wrote: >> >> >> On 26/10/2022 12:59, Daniel P. Berrangé wrote: >>> On Tue, Oct 25, 2022 at 07:38:43PM -0400, Cole Robinson wrote: >>>> On

Re: [libvirt PATCH v2 09/12] tools: support generating SEV secret injection tables

2022-10-26 Thread Dov Murik
On 19/10/2022 13:17, berrange at redhat.com (Daniel P. Berrangé) wrote: > It is possible to build OVMF for SEV with an embedded Grub that can > fetch LUKS disk secrets. This adds support for injecting secrets in > the required format. > > Signed-off-by: Daniel P. Berrang? > --- > docs/manpage

Re: [libvirt PATCH v2 09/12] tools: support generating SEV secret injection tables

2022-10-26 Thread Dov Murik
On 26/10/2022 12:59, Daniel P. Berrangé wrote: > On Tue, Oct 25, 2022 at 07:38:43PM -0400, Cole Robinson wrote: >> On 10/19/22 6:17 AM, Daniel P. Berrangé wrote: >>> It is possible to build OVMF for SEV with an embedded Grub that can >>> fetch LUKS disk secrets. This adds support for injecting s

Re: [libvirt PATCH v2 04/12] tools: support validating SEV direct kernel boot measurements

2022-10-26 Thread Dov Murik
(sorry in advance for missing CCs, I tried to download the mbox from https://listman.redhat.com/archives/libvir-list/ but it doesn't include the To and Cc lines of the messages.) On 19/10/2022 13:17, berrange at redhat.com (Daniel P. Berrangé) wrote: > When doing direct kernel boot we need to inc

Re: REST service for libvirt to simplify SEV(ES) launch measurement

2022-02-24 Thread Dov Murik
+cc Tobin, James On 23/02/2022 19:28, Daniel P. Berrangé wrote: > Extending management apps using libvirt to support measured launch of > QEMU guests with SEV/SEV-ES is unreasonably complicated today, both for > the guest owner and for the cloud management apps. We have APIs for > exposing info ab