Re: About Xen: maybe a reiterative question but ..

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: adam.getchell
Date: Tuesday, October 23, 2007 - 5:57 pm

Virtualization seems to have a lot of security benefits. Rootkits can lie to DomU but not Dom0, and of course snapshotting, migration etc is *really* nice. 

Dom0 in OpenBSD in a current Xen implementation (with HVM) would be a dream. I'd switch wholesale, and buy a CD for every server (as I do now). But doubtless there are a whole host of issues, kernel, SMP, bootloaders (I found OpenBSDs bootloader to be superior to grub in Ubuntu 7.10, it detects media bay HDs, and the installer is fast, efficient, and doesn't crap out on certain video cards/monitors), an LVM, iSCSI support -- and I have no code to contribute, so I will merely remain hopeful without expectation. 

I tried NetBSD Xen, but it seemed the worst of both worlds. Pf circa 3.7, hacks for grub, old version of Xen (2.x series IIRC) without support for the most interesting features, not the same level of security focus, etc. 

So I just picked the best tool for the job. 

I'm happier our webservers are now on OpenBSD with CARP failover.

--
"Invincibility is in oneself, vulnerability in the opponent." -- Sun Tzu

-----Original Message-----
From: Luca Corti <luca@leenoox.net>

Date: Tue, 23 Oct 2007 10:03:42 
To:ropers <ropers@gmail.com>
Cc:Jeff Quast <af.dingo@gmail.com>, OpenBSD-Misc <misc@openbsd.org>,       Nick Guenther <kousue@gmail.com>
Subject: Re: About Xen: maybe a reiterative question but ..


On Tue, 2007-10-23 at 01:11 +0200, ropers wrote:

A proper Dom0 port of XEN to OpenBSD would solve this by removing the
linux dependency. However this would probably require a significant
effort on OpenBSD side and a XEN Hypervisor code audit.

Also from earlier discussion on the list it seems this kind of
virtualization may impact on security, which is in direct contrast with
OpenBSD goals. Can someone elaborate more on this?

ciao

Luca
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
About Xen: maybe a reiterative question but .., carlopmart, (Mon Oct 22, 1:05 am)
Re: About Xen: maybe a reiterative question but .., Nick Guenther, (Mon Oct 22, 12:11 pm)
Re: About Xen: maybe a reiterative question but .., Jeff Quast, (Mon Oct 22, 3:07 pm)
Re: About Xen: maybe a reiterative question but .., carlopmart, (Tue Oct 23, 12:07 am)
Re: About Xen: maybe a reiterative question but .., Luca Corti, (Tue Oct 23, 1:03 am)
Re: About Xen: maybe a reiterative question but .., Per-Erik Persson, (Tue Oct 23, 2:00 am)
Re: About Xen: maybe a reiterative question but .., Lars Noodén, (Tue Oct 23, 3:45 am)
Re: About Xen: maybe a reiterative question but .., Lars Hansson, (Tue Oct 23, 3:56 am)
Re: About Xen: maybe a reiterative question but .., Henning Brauer, (Tue Oct 23, 5:19 am)
Re: About Xen: maybe a reiterative question but .., Ted Unangst, (Tue Oct 23, 9:39 am)
Re: About Xen: maybe a reiterative question but .., adam.getchell, (Tue Oct 23, 5:57 pm)
Re: About Xen: maybe a reiterative question but .. , Theo de Raadt, (Tue Oct 23, 6:14 pm)
Re: About Xen: maybe a reiterative question but .. , Damien Miller, (Tue Oct 23, 6:25 pm)
Re: About Xen: maybe a reiterative question but .., Ben Goren, (Tue Oct 23, 8:35 pm)
Re: About Xen: maybe a reiterative question but .., Adam Getchell, (Tue Oct 23, 10:41 pm)
Re: About Xen: maybe a reiterative question but .., carlopmart, (Wed Oct 24, 6:38 am)
Re: About Xen: maybe a reiterative question but .., Douglas A. Tutty, (Wed Oct 24, 6:58 am)
Re: About Xen: maybe a reiterative question but .., Chris Kuethe, (Wed Oct 24, 7:14 am)
Re: About Xen: maybe a reiterative question but .., carlopmart, (Wed Oct 24, 7:20 am)
Re: About Xen: maybe a reiterative question but .., Christoph Egger, (Wed Oct 24, 8:09 am)
Re: About Xen: maybe a reiterative question but .., Christoph Egger, (Wed Oct 24, 8:10 am)
Re: About Xen: maybe a reiterative question but .., Artur Grabowski, (Wed Oct 24, 8:25 am)
Re: About Xen: maybe a reiterative question but .., Christoph Egger, (Wed Oct 24, 8:33 am)
Re: About Xen: maybe a reiterative question but .., carlopmart, (Wed Oct 24, 8:45 am)
Re: About Xen: maybe a reiterative question but .., Ted Unangst, (Wed Oct 24, 11:09 am)
Re: Non-x86, Lars Noodén, (Fri Oct 26, 12:54 am)
Re: About Xen: maybe a reiterative question but .. , Carlo Gebhardt, (Fri Oct 26, 3:58 am)
Re: Non-x86, Martin Schröder, (Fri Oct 26, 4:39 am)
Re: Non-x86, mickey, (Fri Oct 26, 4:49 am)
Re: Non-x86, Ted Unangst, (Fri Oct 26, 8:28 am)
Re: Non-x86, Lars Noodén, (Fri Oct 26, 9:17 am)
Re: Non-x86, Martin Schröder, (Fri Oct 26, 9:23 am)
Re: Non-x86, Matthew Szudzik, (Fri Oct 26, 2:03 pm)
Re: Non-x86, Jeff Quast, (Sun Oct 28, 6:59 am)
Re: Non-x86, Douglas A. Tutty, (Sun Oct 28, 8:27 am)
Re: Non-x86, Lars Noodén, (Mon Oct 29, 9:53 am)
Re: Non-x86, Douglas A. Tutty, (Mon Oct 29, 2:47 pm)
Re: Non-x86, Matthew Szudzik, (Tue Oct 30, 11:26 am)