mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
98f7a0569c
Introduces the ability to `pvsecret` to add a signature (ecdsa or rsa) to the program-reserved space (user-data) of an add-secret request during the request creation. Additionally, some arbitrary data may be inserted. The new command `verify` checks if add-secret requests are sane (e.g. start with the correct magic value). If the request contains a user-signature `verify` will also verify this signature. Acked-by: Marc Hartmayer <mhartmay@linux.ibm.com> Signed-off-by: Steffen Eiden <seiden@linux.ibm.com> Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
56 lines
1.3 KiB
Groff
56 lines
1.3 KiB
Groff
.\" Copyright 2023 IBM Corp.
|
|
.\" s390-tools is free software; you can redistribute it and/or modify
|
|
.\" it under the terms of the MIT license. See LICENSE for details.
|
|
.\"
|
|
|
|
.TH pvsecret-create-association 1 "2024-01-30" "s390-tools" "UV-Secret Manual"
|
|
.nh
|
|
.ad l
|
|
.SH NAME
|
|
\fBpvsecret create association\fP - Create an association secret
|
|
\fB
|
|
.SH SYNOPSIS
|
|
.nf
|
|
.fam C
|
|
pvsecret create association [OPTIONS] <NAME>
|
|
.fam C
|
|
.fi
|
|
.SH DESCRIPTION
|
|
Use an association secret to connect a trusted I/O device to a guest. The
|
|
`pvapconfig` tool provides more information about association secrets.
|
|
.SH OPTIONS
|
|
.PP
|
|
<NAME>
|
|
.RS 4
|
|
String to identify the new secret. The actual secret is set with
|
|
\fB--input-secret\fR. The name is saved in `NAME.yaml` with white-spaces mapped
|
|
to `_`.
|
|
.RE
|
|
.RE
|
|
|
|
.PP
|
|
\-\-stdout
|
|
.RS 4
|
|
Print the hashed name to stdout. The hashed name is not written to `NAME.yaml`
|
|
.RE
|
|
.RE
|
|
.PP
|
|
\-\-input-secret <FILE>
|
|
.RS 4
|
|
Path from which to read the plaintext secret. Uses a random secret if not
|
|
specified.
|
|
.RE
|
|
.RE
|
|
.PP
|
|
\-\-output-secret <FILE>
|
|
.RS 4
|
|
Save the generated secret as plaintext in FILE. The generated secret can be used
|
|
to generate add-secret requests for a different guest with the same secret using
|
|
\fB--input-secret\fR. Destroy the secret when it is not used anymore.
|
|
.RE
|
|
.RE
|
|
|
|
.SH "SEE ALSO"
|
|
.sp
|
|
\fBpvsecret\fR(1) \fBpvsecret-create\fR(1)
|