[PATCH v17 33/34] docs/system/s390x: Add secure IPL documentation
Zhuoying Cai <[email protected]>
| Newsgroups | gmane.comp.emulators.qemu |
|---|---|
| Message-ID | <[email protected]> |
Add documentation for secure IPL Signed-off-by: Collin Walling <[email protected]> Signed-off-by: Zhuoying Cai <[email protected]> Reviewed-by: Joshua Daley <[email protected]> Reviewed-by: Matthew Rosato <[email protected]> --- docs/system/s390x/secure-ipl.rst | 103 +++++++++++++++++++++++++++++++ 1 file changed, 103 insertions(+) diff --git a/docs/system/s390x/secure-ipl.rst b/docs/system/s390x/secure-ipl.rst index c8fb887ac0..67de20f47a 100644 --- a/docs/system/s390x/secure-ipl.rst +++ b/docs/system/s390x/secure-ipl.rst @@ -1,5 +1,22 @@ .. SPDX-License-Identifier: GPL-2.0-or-later +s390 Secure IPL +=============== + +Secure IPL, also known as secure boot, enables s390-ccw virtual machines to +verify the integrity of guest kernels. + +For technical details of this feature, see the +:doc:`specs document </specs/s390x-secure-ipl>`. + +This document explains how to use secure IPL with s390x in QEMU. It covers +the command line options for providing certificates and enabling secure IPL, +the different IPL modes (Normal, Audit, and Secure), and system requirements. + +A quickstart guide is provided to demonstrate how to generate certificates, +sign images, and start a guest in Secure Mode. + + Secure IPL Command Line Options ------------------------------- @@ -79,3 +96,89 @@ Configuration: .. code-block:: shell qemu-system-s390x -machine s390-ccw-virtio,secure-boot=on,boot-certs.0.path=/.../qemu/certs,boot-certs.1.path=/another/path/cert.pem ... + + +Constraints +----------- + +The following constraints apply when attempting to boot an s390x guest in secure +mode: + +- z16 or "qemu" CPU model +- certificates must be in X.509 PEM format +- only support for SCSI scheme of virtio-blk/virtio-scsi devices +- a boot device must be specified +- any unsupported devices (e.g., ECKD and VFIO) or non-eligible devices (e.g., + network) will cause the entire boot process to terminate early, with an error + logged to the console. + + +Secure IPL Quickstart +--------------------- + +Build QEMU with gnutls enabled +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +.. code-block:: shell + + ./configure … --enable-gnutls + +Generate certificate (e.g. via certtool) +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +A private key is required before generating a certificate. This key must be kept +secure and confidential. + +Use an RSA private key for signing. + +.. code-block:: shell + + certtool --generate-privkey > key.pem + +A self-signed certificate requires the organization name. Use the ``cert.info`` +template to pre-fill values and avoid interactive prompts from certtool. + +.. code-block:: shell + + cat > cert.info <<EOF + cn = "My Name" + expiration_days = 365 + cert_signing_key + EOF + + certtool --generate-self-signed \ + --load-privkey key.pem \ + --template cert.info \ + --hash=SHA256 \ + --outfile cert.pem + +Sign Images (e.g. via sign-file) +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +- signing must be performed on a guest filesystem +- sign-file script used in the example below is located within the kernel source + repo + +.. code-block:: shell + + ./sign-file sha256 key.pem cert.pem /boot/vmlinuz-… + ./sign-file sha256 key.pem cert.pem /usr/lib/s390-tools/stage3.bin + +Note: re-signing a component will not verify correctly; the existing signature +must be stripped before a new one is applied. + +Run zipl with secure boot enabled +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +- zipl must be performed on a guest filesystem + +.. code-block:: shell + + zipl --secure 1 -V + +Command line options for starting the guest +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +.. code-block:: shell + + qemu-system-s390x -machine s390-ccw-virtio,secure-boot=on,boot-certs.0.path=cert.pem ... -- 2.55.0