WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] Xen binary distrib's kernel as domU kernel

To: xen-users@xxxxxxxxxxxxxxxxxxx
Subject: Re: [Xen-users] Xen binary distrib's kernel as domU kernel
From: Mark Williamson <mark.williamson@xxxxxxxxxxxx>
Date: Fri, 12 Jan 2007 15:16:36 +0000
Cc: Sipos Ferenc <frank@xxxxxxx>
Delivery-date: Fri, 12 Jan 2007 07:14:43 -0800
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
In-reply-to: <1168457001.4698.6.camel@localhost>
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <1168457001.4698.6.camel@localhost>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: KMail/1.9.5
> just a quicky. Is it a security breach (by any means) if I run the
> official XenSource e.g. vmlinuz-2.6-xen kernel as my domU kernel? I
> mean, this has the 'Privilege domain' option compiled in (as the very
> same one runs under the dom0 itself) as well as the {net,block}-backend
> drivers?

That shouldn't be a security breach.  Security of a domU is enforced by Xen 
and by dom0, not by the particular kernel version running in the domU.

> I'm using it in a potentially malicious environment (VPS hosting) and I
> want to make sure noone can tamper with system from a domU the way that
> is not desirable.

It shouldn't make any difference what kernel you run in the domU.  If users 
have root in their domU they could always (in principle) tamper with the 
kernel anyhow, but the domU kernel isn't a trusted component anyhow.

Basically, you should be fine, the main advantage of a special domU kernel is 
that it can be a bit smaller.

Cheers,
MNark

-- 
Dave: Just a question. What use is a unicyle with no seat?  And no pedals!
Mark: To answer a question with a question: What use is a skateboard?
Dave: Skateboards have wheels.
Mark: My wheel has a wheel!

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users