[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Qemu-devel] [PATCH v6 09/18] qcow: convert QCow to use QCryptoBlock
From: |
Eric Blake |
Subject: |
Re: [Qemu-devel] [PATCH v6 09/18] qcow: convert QCow to use QCryptoBlock for encryption |
Date: |
Wed, 26 Apr 2017 10:12:10 -0500 |
User-agent: |
Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.0 |
On 04/25/2017 10:38 AM, Daniel P. Berrange wrote:
> This converts the qcow driver to make use of the QCryptoBlock
> APIs for encrypting image content. This is only wired up to
> permit use of the legacy QCow encryption format. Users who wish
> to have the strong LUKS format should switch to qcow2 instead.
>
> With this change it is now required to use the QCryptoSecret
> object for providing passwords, instead of the current block
> password APIs / interactive prompting.
>
> $QEMU \
> -object secret,id=sec0,filename=/home/berrange/encrypted.pw \
> -drive file=/home/berrange/encrypted.qcow,encrypt.format=qcow,\
> encrypt.key-secret=sec0
>
> Likewise when creating such images
>
> qemu-img create -f qcow \
> -object secret,id=sec0,filename=/home/berrange/encrypted.pw \
> -o encrypt.format=qcow,encrypt.key-secret=sec0 \
> /home/berrange/encrypted.qcow
>
> Signed-off-by: Daniel P. Berrange <address@hidden>
> ---
> block/crypto.c | 10 +++
> block/crypto.h | 20 ++++--
> block/qcow.c | 196
> +++++++++++++++++++++++++--------------------------
> qapi/block-core.json | 37 +++++++++-
> 4 files changed, 156 insertions(+), 107 deletions(-)
>
> +++ b/qapi/block-core.json
> @@ -2277,6 +2277,41 @@
> 'mode': 'Qcow2OverlapCheckMode' } }
>
> ##
> +# @BlockdevQcowEncryptionFormat:
> +# @qcow: AES-CBC with plain64 initialization venctors
s/venctors/vectors/
With that fixed,
Reviewed-by: Eric Blake <address@hidden>
and it turned out much nicer than v5 !
--
Eric Blake, Principal Software Engineer
Red Hat, Inc. +1-919-301-3266
Virtualization: qemu.org | libvirt.org
signature.asc
Description: OpenPGP digital signature
- Re: [Qemu-devel] [PATCH v6 02/18] block: add ability to set a prefix for opt names, (continued)
[Qemu-devel] [PATCH v6 03/18] qcow: document another weakness of qcow AES encryption, Daniel P. Berrange, 2017/04/25
[Qemu-devel] [PATCH v6 01/18] block: expose crypto option names / defs to other drivers, Daniel P. Berrange, 2017/04/25
[Qemu-devel] [PATCH v6 04/18] qcow: require image size to be > 1 for new images, Daniel P. Berrange, 2017/04/25
[Qemu-devel] [PATCH v6 06/18] iotests: skip 048 with qcow which doesn't support resize, Daniel P. Berrange, 2017/04/25
[Qemu-devel] [PATCH v6 05/18] iotests: skip 042 with qcow which dosn't support zero sized images, Daniel P. Berrange, 2017/04/25
[Qemu-devel] [PATCH v6 08/18] qcow: make encrypt_sectors encrypt in place, Daniel P. Berrange, 2017/04/25
[Qemu-devel] [PATCH v6 09/18] qcow: convert QCow to use QCryptoBlock for encryption, Daniel P. Berrange, 2017/04/25
- Re: [Qemu-devel] [PATCH v6 09/18] qcow: convert QCow to use QCryptoBlock for encryption,
Eric Blake <=
[Qemu-devel] [PATCH v6 07/18] block: deprecate "encryption=on" in favour of "encrypt.format=aes", Daniel P. Berrange, 2017/04/25
[Qemu-devel] [PATCH v6 12/18] qcow2: extend specification to cover LUKS encryption, Daniel P. Berrange, 2017/04/25
[Qemu-devel] [PATCH v6 10/18] qcow2: make qcow2_encrypt_sectors encrypt in place, Daniel P. Berrange, 2017/04/25
[Qemu-devel] [PATCH v6 11/18] qcow2: convert QCow2 to use QCryptoBlock for encryption, Daniel P. Berrange, 2017/04/25
[Qemu-devel] [PATCH v6 14/18] qcow2: add iotests to cover LUKS encryption support, Daniel P. Berrange, 2017/04/25
[Qemu-devel] [PATCH v6 13/18] qcow2: add support for LUKS encryption format, Daniel P. Berrange, 2017/04/25
[Qemu-devel] [PATCH v6 15/18] iotests: enable tests 134 and 158 to work with qcow (v1), Daniel P. Berrange, 2017/04/25