WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

[Xen-users] Understanding HVM DomU Isolation

To: xen-users@xxxxxxxxxxxxxxxxxxx
Subject: [Xen-users] Understanding HVM DomU Isolation
From: Scott Kuehn <skuehn@xxxxxxxxxxxxxxxxxxx>
Date: Thu, 04 Feb 2010 14:41:49 -0800
Delivery-date: Thu, 04 Feb 2010 14:42:23 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Thunderbird 2.0.0.23 (X11/20090817)
Hello All,

I'm trying to build my understanding of the isolation provided to an HVM DomU. A base Xen 3.4 install on a fancy vPro system works well. It's fast enough for my needs and I'm pleased with the features. That said, I'd like to better understand the extent of separation between Dom0 and an HVM DomU. Would it be possible now, or with a feature on the current Xen roadmap, to fully decouple an HVM DomU from Dom0? To put it another way, I'm concerned that an error in my Dom0 kernel could impact the security of a mission-critical app running in an HVM DomU. What Xen tools or features can I utilize to improve or verify the isolation?

Any comments or suggested reading?

Sincerely,

Scott Kuehn

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users

<Prev in Thread] Current Thread [Next in Thread>
  • [Xen-users] Understanding HVM DomU Isolation, Scott Kuehn <=