Page MenuHomeFreeBSD

bhyve.8: add details on using TPM with UEFI
AcceptedPublic

Authored by novel on Wed, Sep 30, 6:05 PM.
Tags
None
Referenced Files
F174160642: D60181.id188234.diff
Thu, Oct 1, 12:58 AM
F174160641: D60181.id188233.diff
Thu, Oct 1, 12:58 AM
F174160585: D60181.diff
Thu, Oct 1, 12:57 AM
F174158910: D60181.id188234.diff
Thu, Oct 1, 12:37 AM
F174158789: D60181.id188233.diff
Thu, Oct 1, 12:35 AM
F174154505: D60181.diff
Wed, Sep 30, 11:47 PM
F174151413: D60181.id188234.diff
Wed, Sep 30, 11:13 PM
F174150532: D60181.id188233.diff
Wed, Sep 30, 11:06 PM

Details

Reviewers
ziaee
michaelo
Group Reviewers
bhyve
Summary

Add a note that UEFI VMs using TPM devices should be configured
to use a varfile. Some UEFI boot loaders, such as shim, update
persistent boot variables and then reset the system when a TPM is
present. Without a writable varfile, the VM may be reset repeatedly.

Add a TPM device example to the examples list.

While here, add a missing "\" to the "uefivm" example, and add ".Pp"
before the vCPU pinning examples for consistency with other examples.

PR: 287326
MFC after: 3 days

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 77534
Build 74417: arc lint + arc unit

Event Timeline

novel requested review of this revision.Wed, Sep 30, 6:05 PM
michaelo added a subscriber: michaelo.
michaelo added inline comments.
usr.sbin/bhyve/bhyve.8
1445

This implies that swtpm is installed, but this isn't metioned. There is also TPM passthrough.

1446

Where is documented that "/usr/local/share/uefi-firmware/BHYVE_UEFI_VARS.fd" should be copied to tpmvm_VARS.fd first? The vars file isn't TPM specific, no?

This revision now requires changes to proceed.Wed, Sep 30, 6:21 PM
  • Mention the sysutils/swtpm port.
  • Refer to the UEFI examples on VARS file creation.

I am fine with that. Others should have a look as well. Do you plan to MFC it to 15?

This revision is now accepted and ready to land.Wed, Sep 30, 6:41 PM
novel added inline comments.
usr.sbin/bhyve/bhyve.8
1445

I have added swtpm reference to the main TPM section where it is first mentioned.

1446

It is documented few lines above in the UEFI command example. I've added a reference there for people getting there through searching rather then reading from top to bottom.

novel marked an inline comment as done.

I am fine with that. Others should have a look as well. Do you plan to MFC it to 15?

Great. Yes, added the MFC tag to summary.