From: Zhuoying Cai <zycai@linux.ibm.com>
To: qemu-s390x@nongnu.org, qemu-devel@nongnu.org
Cc: jrossi@linux.ibm.com, cohuck@redhat.com, berrange@redhat.com,
richard.henderson@linaro.org, david@kernel.org,
walling@linux.ibm.com, jjherne@linux.ibm.com,
pasic@linux.ibm.com, borntraeger@linux.ibm.com,
farman@linux.ibm.com, mjrosato@linux.ibm.com, iii@linux.ibm.com,
eblake@redhat.com, armbru@redhat.com, zycai@linux.ibm.com,
alifm@linux.ibm.com, brueckner@linux.ibm.com,
pierrick.bouvier@oss.qualcomm.com, jdaley@linux.ibm.com
Subject: [PATCH v17 33/34] docs/system/s390x: Add secure IPL documentation
Date: Thu, 30 Jul 2026 17:46:22 -0400 [thread overview]
Message-ID: <20260730214624.2328883-34-zycai@linux.ibm.com> (raw)
In-Reply-To: <20260730214624.2328883-1-zycai@linux.ibm.com>
Add documentation for secure IPL
Signed-off-by: Collin Walling <walling@linux.ibm.com>
Signed-off-by: Zhuoying Cai <zycai@linux.ibm.com>
Reviewed-by: Joshua Daley <jdaley@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
---
docs/system/s390x/secure-ipl.rst | 103 +++++++++++++++++++++++++++++++
1 file changed, 103 insertions(+)
diff --git a/docs/system/s390x/secure-ipl.rst b/docs/system/s390x/secure-ipl.rst
index c8fb887ac0..67de20f47a 100644
--- a/docs/system/s390x/secure-ipl.rst
+++ b/docs/system/s390x/secure-ipl.rst
@@ -1,5 +1,22 @@
.. SPDX-License-Identifier: GPL-2.0-or-later
+s390 Secure IPL
+===============
+
+Secure IPL, also known as secure boot, enables s390-ccw virtual machines to
+verify the integrity of guest kernels.
+
+For technical details of this feature, see the
+:doc:`specs document </specs/s390x-secure-ipl>`.
+
+This document explains how to use secure IPL with s390x in QEMU. It covers
+the command line options for providing certificates and enabling secure IPL,
+the different IPL modes (Normal, Audit, and Secure), and system requirements.
+
+A quickstart guide is provided to demonstrate how to generate certificates,
+sign images, and start a guest in Secure Mode.
+
+
Secure IPL Command Line Options
-------------------------------
@@ -79,3 +96,89 @@ Configuration:
.. code-block:: shell
qemu-system-s390x -machine s390-ccw-virtio,secure-boot=on,boot-certs.0.path=/.../qemu/certs,boot-certs.1.path=/another/path/cert.pem ...
+
+
+Constraints
+-----------
+
+The following constraints apply when attempting to boot an s390x guest in secure
+mode:
+
+- z16 or "qemu" CPU model
+- certificates must be in X.509 PEM format
+- only support for SCSI scheme of virtio-blk/virtio-scsi devices
+- a boot device must be specified
+- any unsupported devices (e.g., ECKD and VFIO) or non-eligible devices (e.g.,
+ network) will cause the entire boot process to terminate early, with an error
+ logged to the console.
+
+
+Secure IPL Quickstart
+---------------------
+
+Build QEMU with gnutls enabled
+^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
+
+.. code-block:: shell
+
+ ./configure … --enable-gnutls
+
+Generate certificate (e.g. via certtool)
+^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
+
+A private key is required before generating a certificate. This key must be kept
+secure and confidential.
+
+Use an RSA private key for signing.
+
+.. code-block:: shell
+
+ certtool --generate-privkey > key.pem
+
+A self-signed certificate requires the organization name. Use the ``cert.info``
+template to pre-fill values and avoid interactive prompts from certtool.
+
+.. code-block:: shell
+
+ cat > cert.info <<EOF
+ cn = "My Name"
+ expiration_days = 365
+ cert_signing_key
+ EOF
+
+ certtool --generate-self-signed \
+ --load-privkey key.pem \
+ --template cert.info \
+ --hash=SHA256 \
+ --outfile cert.pem
+
+Sign Images (e.g. via sign-file)
+^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
+
+- signing must be performed on a guest filesystem
+- sign-file script used in the example below is located within the kernel source
+ repo
+
+.. code-block:: shell
+
+ ./sign-file sha256 key.pem cert.pem /boot/vmlinuz-…
+ ./sign-file sha256 key.pem cert.pem /usr/lib/s390-tools/stage3.bin
+
+Note: re-signing a component will not verify correctly; the existing signature
+must be stripped before a new one is applied.
+
+Run zipl with secure boot enabled
+^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
+
+- zipl must be performed on a guest filesystem
+
+.. code-block:: shell
+
+ zipl --secure 1 -V
+
+Command line options for starting the guest
+^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
+
+.. code-block:: shell
+
+ qemu-system-s390x -machine s390-ccw-virtio,secure-boot=on,boot-certs.0.path=cert.pem ...
--
2.55.0
next prev parent reply other threads:[~2026-07-30 21:49 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-30 21:45 [PATCH v17 00/34] Secure IPL Support for SCSI Scheme of virtio-blk/virtio-scsi Devices Zhuoying Cai
2026-07-30 21:45 ` [PATCH v17 01/34] Add boot-certs to s390-ccw-virtio machine type option Zhuoying Cai
2026-07-30 21:45 ` [PATCH v17 02/34] crypto/x509-utils: Refactor with GNUTLS fallback Zhuoying Cai
2026-07-30 21:45 ` [PATCH v17 03/34] crypto/x509-utils: Add helper functions for certificate store Zhuoying Cai
2026-07-30 21:45 ` [PATCH v17 04/34] hw/s390x/ipl: Create " Zhuoying Cai
2026-07-30 21:45 ` [PATCH v17 05/34] s390x/diag: Introduce DIAG 320 for Certificate Store Facility Zhuoying Cai
2026-07-30 21:45 ` [PATCH v17 06/34] s390x/diag: Refactor address validation check from diag308_parm_check Zhuoying Cai
2026-07-30 21:45 ` [PATCH v17 07/34] s390x/diag: Implement DIAG 320 subcode 1 Zhuoying Cai
2026-07-30 21:45 ` [PATCH v17 08/34] crypto/x509-utils: Add helper functions for DIAG 320 subcode 2 Zhuoying Cai
2026-07-30 21:45 ` [PATCH v17 09/34] s390x/diag: Implement " Zhuoying Cai
2026-07-30 21:45 ` [PATCH v17 10/34] hw/s390x: Define finite size for single entry VCEntry Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 11/34] s390x/diag: Introduce DIAG 508 for secure IPL operations Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 12/34] crypto/x509-utils: Add helper functions for DIAG 508 subcode 1 Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 13/34] s390x/diag: Generalize s390_ipl_read/write to accept void * Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 14/34] s390x/diag: Implement DIAG 508 subcode 1 for signature verification Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 15/34] s390x/ipl: Introduce IPL Information Report Block (IIRB) Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 16/34] pc-bios/s390-ccw: Define memory for IPLB and convert IPLB to pointers Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 17/34] hw/s390x/ipl: Add IPIB flags to IPL Parameter Block Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 18/34] hw/s390x/ipl: Rework s390_ipl_map_iplb_chain for certificate storage Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 19/34] s390x: Guest support for Secure-IPL Facility Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 20/34] pc-bios/s390-ccw: Refactor zipl_run() Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 21/34] pc-bios/s390-ccw: Rework zipl_load_segment function Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 22/34] pc-bios/s390-ccw: Introduce ZiplBootMode enum for IPL mode selection Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 23/34] pc-bios/s390-ccw: Add signature verification for secure IPL in audit mode Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 24/34] pc-bios/s390-ccw: Add signed component address overlap checks Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 25/34] s390x: Guest support for Secure-IPL Code Loading Attributes Facility (SCLAF) Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 26/34] pc-bios/s390-ccw: Add additional security checks for secure boot Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 27/34] Add secure-boot to s390-ccw-virtio machine type option Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 28/34] hw/s390x/ipl: Set IPIB flags for secure IPL Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 29/34] pc-bios/s390-ccw: Handle true secure IPL mode Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 30/34] hw/s390x/ipl: Handle secure boot with multiple boot devices Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 31/34] tests/functional/s390x: Add secure IPL functional test Zhuoying Cai
2026-07-30 21:46 ` [PATCH v17 32/34] docs/specs: Add secure IPL documentation Zhuoying Cai
2026-07-30 21:46 ` Zhuoying Cai [this message]
2026-07-30 21:46 ` [PATCH v17 34/34] MAINTAINERS: Add secure IPL files to S390-ccw boot group Zhuoying Cai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260730214624.2328883-34-zycai@linux.ibm.com \
--to=zycai@linux.ibm.com \
--cc=alifm@linux.ibm.com \
--cc=armbru@redhat.com \
--cc=berrange@redhat.com \
--cc=borntraeger@linux.ibm.com \
--cc=brueckner@linux.ibm.com \
--cc=cohuck@redhat.com \
--cc=david@kernel.org \
--cc=eblake@redhat.com \
--cc=farman@linux.ibm.com \
--cc=iii@linux.ibm.com \
--cc=jdaley@linux.ibm.com \
--cc=jjherne@linux.ibm.com \
--cc=jrossi@linux.ibm.com \
--cc=mjrosato@linux.ibm.com \
--cc=pasic@linux.ibm.com \
--cc=pierrick.bouvier@oss.qualcomm.com \
--cc=qemu-devel@nongnu.org \
--cc=qemu-s390x@nongnu.org \
--cc=richard.henderson@linaro.org \
--cc=walling@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.