[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [win-pv-devel] Signing PV drivers



Citrix currently sign the XenServer builds of the Xen Project PV drivers (which 
are often less up-to-date than the xenbits repos, and may contain one or two 
patches that are not upstreamed.  At the moment there are a few issues known to 
exist in the 8.0 driver set, so for stability's sake it's still 7.2 drivers - 
which predate the drivers being part of the Xen Project, and for which sources 
can be found on github - that are being packaged.  I'm hoping to get 8.0 
drivers in place there soon). 

You can get them from the development snapshots at 
http://xenserver.org/open-source-virtualization-download/2-uncategorised/115-development-snapshots.html

(Download the Base ISO from the snapshot list, then mount it and look inside, 
specifically at  
packages.main\tools-iso.tar.bz2\tools-iso.tar\.\opt\xensource\packages\iso\xs-tools-*.iso

You'll find 2 drivers msi  files (one 64 bit, one 32 bit) - you can open these 
with msiexec or 7zip, and extract the signed drivers from within.)

 Citrix also currently arrange for Microsoft WHQL signing of XenServer PV 
driver releases

However - none of this addresses Xen Project nightly builds which, I believe, 
Citrix can't  vouch for (as it doesn't have control of who gets to be a project 
committer).

Of course, if you - or anyone else - has a trusted-chain code signing 
certificate, there is nothing to stop you from signing the xen project driver 
builds yourself. 

Ben

> -----Original Message-----
> From: win-pv-devel-bounces@xxxxxxxxxxxxxxxxxxxx [mailto:win-pv-devel-
> bounces@xxxxxxxxxxxxxxxxxxxx] On Behalf Of Martin Cerveny
> Sent: 14 April 2015 9:43 PM
> To: win-pv-devel@xxxxxxxxxxxxxxxxxxxx
> Subject: [win-pv-devel] Signing PV drivers
> 
> Hello.
> 
> The "Bcdedit.exe -set TESTSIGNING ON" is not very comfortable.
> Will the PV drivers be signed by trusted-chain authority
> (http://xenproject.org/downloads/windows-pv-drivers.html) ?
> - ReactOS (https://reactos.org/wiki/Driver_Signing)
> - maybe univention.de
> - maybe cirix
> 
> Thanks, Martin Cerveny
> 
> _______________________________________________
> win-pv-devel mailing list
> win-pv-devel@xxxxxxxxxxxxxxxxxxxx
> http://lists.xenproject.org/cgi-bin/mailman/listinfo/win-pv-devel

_______________________________________________
win-pv-devel mailing list
win-pv-devel@xxxxxxxxxxxxxxxxxxxx
http://lists.xenproject.org/cgi-bin/mailman/listinfo/win-pv-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.