[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] Enabling domU to create other domUs



Cihula, Joseph writes ("RE: [Xen-devel] Enabling domU to create other domUs"):
> If you're up for doing some work, I'd recommend that approach as it will
> not only solve your problem but also bring the community a step closer
> to a de-privileged dom0.

I agree with this (although the original enquirer may find that this
is not necessarily the most expedient path to solving their problem).

Hayawardh V writes ("Re: [Xen-devel] Enabling domU to create other domUs"):
> On Tue, Jul 8, 2008 at 12:25 PM, Derek Murray <Derek.Murray@xxxxxxxxxxxx>
> wrote:
> >  [...]  you could probably conjure up a Xen Security Module that
> > enforced hierarchical privilege, but you would probably still have
> > to modify the tools.

I would not recommend using the Xen Security Modules arrangements.
There are quite a few bugs in this code, including some very serious
security bugs (which sadly we aren't allowed to give more information
about as the reports were embargoed).

Unfortunately turning on the XSM support is likely to result in a
substantially less secure system.

Ian.

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.