WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

[Xen-users] How secure is Dom0 from DomU

To: xen-users@xxxxxxxxxxxxxxxxxxx
Subject: [Xen-users] How secure is Dom0 from DomU
From: Thomas King <tking@xxxxxxxxxx>
Date: Wed, 25 Jul 2007 08:35:51 -0400
Delivery-date: Wed, 25 Jul 2007 05:33:44 -0700
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx

Hi,

I would like to understand the security implications between Dom0 and DomU.

Dom0 = openSUSE 10.2
DomU = openSUSE 10.2 (paravirtualization)
DomU = openSUSE 10.2 (full virtualization)
DomU = WindowsXP (full virtualization)

If I must give out the DomU root (administrator) passwords, how secure is the Dom0? Is there a difference in the security between Full and Para virtualization? Can wrapping this in something like AppArmour resolve some of the security issues (if there are any?)

Thanks
Thomas
_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users
<Prev in Thread] Current Thread [Next in Thread>