[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Xen-users] Re: Disable QEMU monitor in HVM domains


  • To: xen-users@xxxxxxxxxxxxxxxxxxx
  • From: "Rik v. A" <rikratva@xxxxxxxxx>
  • Date: Thu, 15 Jan 2009 22:03:42 +0100
  • Delivery-date: Thu, 15 Jan 2009 13:04:30 -0800
  • Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:to:subject:in-reply-to:mime-version :content-type:content-transfer-encoding:content-disposition :references; b=em/ZSbUle5cfCv43Wdxey2IT8DpkbEnb22S55cjvSrF14WRLLbyLXiySkX0eHm4DOM iMDoR/OX1dNVxAt46hDf2TIkgYPHYrNMR3rWrqldoeYJEz2Xcqg/5prlFi0M5yaVZyoo UKiH0ULWHnw93ACFVIbFXzg1kxpThed5i/cxU=
  • List-id: Xen user discussion <xen-users.lists.xensource.com>

I'm replying to my own E-mail of 2 weeks ago. I have still found no
way to disable the Qemu monitor in HVM DomUs. I'd really like to
disable it for security reasons, but I can't seem to find anything in
the docs or on Google. Please help (pretty please?)

Rik

2008/12/30 Rik v. A <rikratva@xxxxxxxxx>:
> Hi,
>
> I use Xen 3.3, installed from sources. I run a few HVM domains for
> clients. QEMU is also from the Xen 3.3 source package.
>
> It seems that the QEMU Monitor is *by default* accessible via the VNC
> interface (CTRL+ALT+2) on these domains. I did some research on
> Google, and it seems that most people say that it has been disabled by
> default since an earlier Xen/QEMU branch.
>
> I am using more or less the default out-of-the box configuration, with
> few options changed.
> This is of course a big security risk. The monitor should be disabled
> by default, and it clearly isn't.
>
> I can't seem to disable it either. I tried options "monitor=0" and
> such in the domain configurations, but there's no difference.
>
> I would really, really, really like to change this behavior!
>
> Kind regards,
> Rik
>

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.