Skip to content

can a guest-owner verify svsm? #15

@aep

Description

@aep

there's a fundamental thing i still don't understand about SNP, and i was assuming SVSM solves that, but i cant figure out how.

in a cloud environment, a guest owner can typically not supply their own firmware (OVMF, vTPM)
and the common solution appears to be that the identityblock is signed by the CSP,
and the guest owner verifies that that signature came from a known good CSP key.

i was assuming with the svsm stack, it's actually svsm that gets attested, but it looks like its still the entire firmware.
even tho svsm has higher privilege than the next firmware, the guest owner can't really verify that a specific expected version of svsm was loaded.

did i fundamentally misunderstand what problem svsm actually solves?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions