[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Qemu-devel] [PATCH] mark nic as trusted
From: |
Gleb Natapov |
Subject: |
Re: [Qemu-devel] [PATCH] mark nic as trusted |
Date: |
Wed, 7 Jan 2009 20:41:03 +0200 |
On Wed, Jan 07, 2009 at 11:54:29AM -0600, Anthony Liguori wrote:
> Anthony Liguori wrote:
>>> That is for secure guest<->host communication over network. Guest has to
>>> know somehow which link host uses for communication. If guest has no way
>>> to know this, another computer on untrusted network can pretend it is
>>> real
>>> host and "own" a guest.
>>
>> So this is for vmchannel? How do you differentiate a real device with
>> that bit set compared to the vmchannel device?
>
> Like if you were doing PCI passthrough of an e1000...
>
It's not just one bit. It is 14 byte string. We can put something unique there.
--
Gleb.
- [Qemu-devel] [PATCH] mark nic as trusted, Gleb Natapov, 2009/01/07
- Re: [Qemu-devel] [PATCH] mark nic as trusted, Anthony Liguori, 2009/01/07
- Re: [Qemu-devel] [PATCH] mark nic as trusted, Gleb Natapov, 2009/01/07
- Re: [Qemu-devel] [PATCH] mark nic as trusted, Anthony Liguori, 2009/01/07
- Re: [Qemu-devel] [PATCH] mark nic as trusted, Anthony Liguori, 2009/01/07
- Re: [Qemu-devel] [PATCH] mark nic as trusted,
Gleb Natapov <=
- Re: [Qemu-devel] [PATCH] mark nic as trusted, Anthony Liguori, 2009/01/07
- Re: [Qemu-devel] [PATCH] mark nic as trusted, Gleb Natapov, 2009/01/07
- Re: [Qemu-devel] [PATCH] mark nic as trusted, Anthony Liguori, 2009/01/08
- Re: [Qemu-devel] [PATCH] mark nic as trusted, Gleb Natapov, 2009/01/08
- Re: [Qemu-devel] [PATCH] mark nic as trusted, Anthony Liguori, 2009/01/08
- Re: [Qemu-devel] [PATCH] mark nic as trusted, Jamie Lokier, 2009/01/08
- Re: [Qemu-devel] [PATCH] mark nic as trusted, Dor Laor, 2009/01/08
- Re: [Qemu-devel] [PATCH] mark nic as trusted, Daniel P. Berrange, 2009/01/09
- Re: [Qemu-devel] [PATCH] mark nic as trusted, Jamie Lokier, 2009/01/09
- Re: [Qemu-devel] [PATCH] mark nic as trusted, Anthony Liguori, 2009/01/10