XEN and KERNEXEC
Posted: Wed Sep 28, 2011 7:05 am
Purpose: to use a hardened 3.x kernel for dom0 in Xen with KERNEXEC (otherwise you would have to trust the whole kernel that there's no exploitable bugs)
In light of the fact that XEN (and/or KVM) is at the moment incompatible with KERNEXEC how secure is it to have XEN enabled and KERNEXEC disabled in dom0?
Seems with KERNEXEC enabled dom0 options that are necessary are grayed out.
Isn't this a big security risk? Seems there's no pint to linux 3.x with hardened support if you want to use Xen.
I've never actually used Xen which is what I'm interested in more than KVM. Am I wrong that you need those options? I need backend drivers for various devices which I can't select.
Do you think a fix will available soon? (Unlikely from what I've read)
In light of the fact that XEN (and/or KVM) is at the moment incompatible with KERNEXEC how secure is it to have XEN enabled and KERNEXEC disabled in dom0?
Seems with KERNEXEC enabled dom0 options that are necessary are grayed out.
Isn't this a big security risk? Seems there's no pint to linux 3.x with hardened support if you want to use Xen.
I've never actually used Xen which is what I'm interested in more than KVM. Am I wrong that you need those options? I need backend drivers for various devices which I can't select.
Do you think a fix will available soon? (Unlikely from what I've read)