[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [Xen-API] Xenserver/XCP encrypted disk
Thanks George,
  I've pondered both of these. For the first solution - my thoughts were that the DomU's are logged into and used by various people and they're also maintained by various other people. My idea behind encrypting the Dom0's SR is that the DomU's would be encrypted and the Dom0 wouldn't boot without having the appropriate key. This way we're limiting the chances that one of the DomU's would have been configured improperly and sensitive data would be accessible.
Getting block encryption support in the Dom0 has become such a pain that encrypting the DomU's may be the best option. Your Âsecond solution I'd thought about but discounted it as a hack. Yes, it would work but I'm not sure it's a great idea. A similar solution to this is to have an NFS or iSCSI SR accessible through the VPN back in the data center so all sensitive data would be stored off the device. If the device can't connect to the VPN without the external key then the data would be reasonably secure etc..
Still pondering. I'd be interested to hear from anyone who may have gotten Dom0 block encryption to work.Â
_______________________________________________ Xen-api mailing list Xen-api@xxxxxxxxxxxxx http://lists.xen.org/cgi-bin/mailman/listinfo/xen-api
|
Lists.xenproject.org is hosted with RackSpace, monitoring our |