From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:47921) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1T75d3-0003SI-GO for qemu-devel@nongnu.org; Thu, 30 Aug 2012 10:21:59 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1T75cv-000083-B4 for qemu-devel@nongnu.org; Thu, 30 Aug 2012 10:21:53 -0400 Received: from mail3.scytl.com ([217.111.179.100]:47689) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1T75cv-00007N-0X for qemu-devel@nongnu.org; Thu, 30 Aug 2012 10:21:45 -0400 Message-ID: <503F76F6.2030801@scytl.com> Date: Thu, 30 Aug 2012 16:21:42 +0200 From: Jordi Cucurull Juan MIME-Version: 1.0 References: <50336381.8040009@scytl.com> <50368D0B.7060402@linux.vnet.ibm.com> <503E11AA.2010709@linux.vnet.ibm.com> In-Reply-To: <503E11AA.2010709@linux.vnet.ibm.com> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 8bit Subject: Re: [Qemu-devel] Is is possible to virtualise or share the TPM? List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Stefan Berger Cc: yoder1@us.ibm.com, Corey Bryant , qemu-devel Dear Stefan, What does it mean that the patches with the VTPM functionality exist but they are behind the regular ones? Does it mean that they are not currently updated? That they have less priority? Best regards, Jordi. On 08/29/2012 02:57 PM, Stefan Berger wrote: > On 08/23/2012 04:05 PM, Corey Bryant wrote: >> >> >> On 08/21/2012 06:31 AM, Jordi Cucurull Juan wrote: >>> Dear all, >>> >>> After applying the TPM patches to QEMU, I was wondering if it is >>> possible to simultaneously use the TPM in more than one virtual >>> machine, >>> i.e. virtualisation of the TPM. >>> >>> According to the paper "Stefan Berger, Ramón Cáceres, Kenneth A. >>> Goldman, Ronald Perez, Reiner Sailer, Leendert van Doorn. vTPM: >>> Virtualizing the Trusted Platform Module" this seems to be possible in >>> Xen. Is not possible in QEMU? >>> >>> Thanks! >>> Jordi. >>> >>> >> >> I don't think the pass-through driver supports use by multiple VMs. >> Stefan Berger should be able to answer better so I'm adding him to >> the thread. >> > > The pass-through driver cannot provide access for multiple VMs to the > single hardware TPM on the host. The usage model and the statefulness > of the TPM (SRK password, owner password, keys) basically > prevent/complicate this. The implementation for Xen was indep. of the > Qemu code base today and there we used a software implementation of > the TPM that provided a private TPm instance to each VM. I have > patches for this for Qemu but due to an IRC chat in Sept. 2011 they > are 'behind' the pass-through driver patches. > > Stefan > -- Jordi Cucurull Juan Researcher Scytl Secure Electronic Voting Plaça Gal·la Placidia, 1-3, 1st floor · 08006 Barcelona Phone: + 34 934 230 324 Fax + 34 933 251 028 jordi.cucurull@scytl.com http://www.scytl.com NOTICE: The information in this e-mail and in any of its attachments is confidential and intended solely for the attention and use of the named addressee(s). If you are not the intended recipient, any disclosure, copying, distribution or retaining of this message or any part of it, without the prior written consent of Scytl Secure Electronic Voting, SA is prohibited and may be unlawful. If you have received this in error, please contact the sender and delete the material from any computer. Your data are in a file owned by Scytl Secure Electronic Voting, S.A. You can exercice your rights of access, rectification, cancellation and opposition by contacting Scytl Secure Electronic Voting, S.A. at the following address: Gal·la Placídia, 1-3. 1st, 08006 Barcelona (Spain), according to the Organic Law 15/1999, of 13th December of Protection of Personal Data.