WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-devel

Re: [Xen-devel] Enabling domU to create other domUs

Cihula, Joseph writes ("RE: [Xen-devel] Enabling domU to create other domUs"):
> If you're up for doing some work, I'd recommend that approach as it will
> not only solve your problem but also bring the community a step closer
> to a de-privileged dom0.

I agree with this (although the original enquirer may find that this
is not necessarily the most expedient path to solving their problem).

Hayawardh V writes ("Re: [Xen-devel] Enabling domU to create other domUs"):
> On Tue, Jul 8, 2008 at 12:25 PM, Derek Murray <Derek.Murray@xxxxxxxxxxxx>
> wrote:
> >  [...]  you could probably conjure up a Xen Security Module that
> > enforced hierarchical privilege, but you would probably still have
> > to modify the tools.

I would not recommend using the Xen Security Modules arrangements.
There are quite a few bugs in this code, including some very serious
security bugs (which sadly we aren't allowed to give more information
about as the reports were embargoed).

Unfortunately turning on the XSM support is likely to result in a
substantially less secure system.

Ian.

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel