Gentoo Archives: gentoo-hardened

From: Matthew Thode <prometheanfire@g.o>
To: gentoo-hardened@l.g.o
Cc: Matthias-Christian Ott <ott@×××××.org>
Subject: Re: [gentoo-hardened] virtualization
Date: Wed, 07 Aug 2013 15:00:05
Message-Id: 52026101.30807@gentoo.org
In Reply to: Re: [gentoo-hardened] virtualization by Matthias-Christian Ott
1 On 08/06/2013 05:09 PM, Matthias-Christian Ott wrote:
2 > On 08/06/13 13:04, Alex Efros wrote:
3 >> On Tue, Aug 06, 2013 at 12:58:12PM +0800, Pavel Labushev wrote:
4 >>> I wouldn't call such news good. KERNEXEC, especially on x86_64, plays a
5 >>> big role in protecting the kernel from both local and remote attacks.
6 >>> KVM doesn't require such arguable compromises (no pun intended).
7 >>
8 >> True. But KVM unable to run Mac OS X, that's main reason to use VirtualBox.
9 >> Less important things: KVM don't support 3D acceleration; don't have
10 >> signed drivers for guest Windows (and thus require switching Windows to
11 >> "Testing mode" to install drivers); sometimes it need awful tricks like
12 >> building custom BIOS from patches sources; I can't give my KVM virtual
13 >> machines to friends which use Windows as host OS; etc.
14 >
15 > I have no Windows license to test this, but as far as I found these
16 > drivers should be signed:
17 >
18 > https://alt.fedoraproject.org/pub/alt/virtio-win/latest/
19 >
20 > - Matthias-Christian
21 >
22 I've used fedora's virtio drivers with a windows8 before (windows 8.1
23 actually).
24
25 --
26 -- Matthew Thode (prometheanfire)

Attachments

File name MIME type
signature.asc application/pgp-signature