[Openstack-security] Virtualization of TPM in QEMU

Daniel P. Berrange berrange at redhat.com
Tue Dec 9 09:49:28 UTC 2014


On Tue, Dec 09, 2014 at 09:17:57AM +0500, Muhammad Faraz Hyder wrote:
> Is there anyone who has virtualized the TPM using KVM/QEMU Hypervisor.
> 
> I am trying to use IBM software TPM and trying to virtualize it to the VMs
> , but unable to do so.

QEMU has TPM device emulation, but the backend for the emulation must be a
real TPM in the host. As such only a single guest can have a virtual TPM
on each host. This basically it essentially useless as a feature for the
cloud. There was work to allow the virtual TPM to be backed by a custom
data store, so that all guests on a host could have this functionality,
but it was never merged upstream in QEMU

Regards,
Daniel
-- 
|: http://berrange.com      -o-    http://www.flickr.com/photos/dberrange/ :|
|: http://libvirt.org              -o-             http://virt-manager.org :|
|: http://autobuild.org       -o-         http://search.cpan.org/~danberr/ :|
|: http://entangle-photo.org       -o-       http://live.gnome.org/gtk-vnc :|




More information about the Openstack-security mailing list