AMDEPYC / AMDEPYC/sev-certify

Include ID block when launching guests

Open
#246 1 comment 0 reactions 1 assignee Claimed by @markg-github View on GitHub
enhancement
Dominant language
Python
Stars
3
Forks
7
Avg merge
1d 21h
Merged PRs (30d)
8

Description

An SEV-SNP "ID block" allows additional properties to be associated with/bound to an SEV-SNP CVM, for example, a "guest policy", a guest SVN and a Family ID. More guest tests are possible when SNP CVMs have these properties.

ID blocks need to be signed, but self-signing is allowed as the verifier checks the signature and the public key, which is included in the "ID authentication information structure". Both the ID block and the authentication information structure must be provided, for example, on the QEMU command line.

Note that ID blocks were introduced with SEV-SNP.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.