The crate dependencies were a bit to slack. Due to the rust dependency resolver's strategy of always selecting the latest version this never lead to any issues. This has no impact on the workspaces Cargo.lock Reviewed-by: Marc Hartmayer <marc@linux.ibm.com> Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
pvsecret
Description
Use pvsecret to manage secrets for IBM Secure Execution guests. pvsecret can create add-secret requests on any architecture. On s390x systems, use pvsecret to add the secrets to the ultravisor secret store, list all secrets in the secret store, or lock the secret store to prevent any modifications in the future.
The ultravisor secret store stores secrets for the IBM Secure Execution guest. The secret store is cleared on guest reboot.
Create requests only on trusted systems that are not the IBM Secure Execution guest where you want to inject the secrets. This approach prevents the secrets from being in cleartext on the guest. For extra safety, do an attestation with pvattest of your guest beforehand, and include the configuration UID in the secret request using --cuid. Refer to pvsecret-add(1) for more information. For all certificates, revocation lists, and host-key documents, both the PEM and DER input formats are supported.
Synopsis
pvsecret [OPTIONS] <COMMAND>
Commands Overview
- create Create a new add-secret request
- add Repeat an add-secret request (s390x only)
- lock Lock the secret-store (s390x only)
- list List all ultravisor secrets (s390x only)
Options
-v, --verbose
-
Provide more detailed output
--version
-
Print version information and exit
pvsecret create
Description
Create add-secret requests for IBM Secure Execution guests. Only create these requests in a trusted environment, such as your workstation. The pvattest create command creates a randomly generated key to protect the request. The generated requests can then be added on an IBM Secure Execution guest using pvsecret add. The guest can then use the secrets with the use case depending on the secret type.
Such a request is bound to a specific IBM Secure Execution image specified with --hdr. Optionally, the request can be bound to a specific instance when bound to the Configuration Unique ID from pvattest using --cuid
Synopsis
pvsecret create [OPTIONS] --host-key-document <FILE> --hdr <FILE> --output <FILE> <--no-verify|--cert <FILE>> <COMMAND>
Commands Overview
- meta Use a meta secret to carry flags to the ultravisor without having to provide an actual secret value. Meta secrets do not appear in the list of secrets
- association
Use an association secret to connect a trusted I/O device to a guest. The
pvapconfigtool provides more information about association secrets
Options
-k, --host-key-document <FILE>
-
Use FILE as a host-key document. Can be specified multiple times and must be
used at least once.
--no-verify
-
Disable the host-key document verification. Does not require the host-key
documents to be valid. Do not use for a production request unless you
verified the host-key document beforehand.
-C, --cert <FILE>
-
Use FILE as a certificate to verify the host key or keys. The certificates
are used to establish a chain of trust for the verification of the host-key
documents. Specify this option twice to specify the IBM Z signing key and
the intermediate CA certificate (signed by the root CA).
--crl <FILE>
-
Use FILE as a certificate revocation list. The list is used to check whether
a certificate of the chain of trust is revoked. Specify this option multiple
times to use multiple CRLs.
--offline
-
Make no attempt to download CRLs
--root-ca <ROOT_CA>
-
Use FILE as the root-CA certificate for the verification. If omitted, the
system-wide root CAs installed on the system are used. Use this only if you
trust the specified certificate.
--hdr <FILE>
-
Specifies the header of the guest image. Can be an IBM Secure Execution
image created by genprotimg or an extracted IBM Secure Execution header. The
header must start at a page boundary.
-f, --force
-
Force the generation of add-secret requests on IBM Secure Execution guests.
If the program detects that it is running on an IBM Secure Execution guest,
it denies the generation of add-secret requests. The force flag overwrites
this behavior.
-o, --output <FILE>
-
Write the generated request to FILE
--extension-secret <FILE>
-
Use the content of FILE as an extension secret. The file must be exactly 32
bytes long. If this request is the first, all subsequent requests must have
the same extension secret. Only makes sense if bit 1 of the secret control
flags of the IBM Secure Execution header is 0. Otherwise the ultravisor
rejects the request.
--cck <FILE>
-
Use the content of FILE as the customer-communication key (CCK) to derive
the extension secret. The file must contain exactly 32 bytes of data. If the
target guest was started with bit 1 of the secret control flag set, the
ultravisor also derives the secret from the CCK. Otherwise, the ultravisor
interprets the extension secret as a normal one. This still works if you
use the same CCK for all requests.
--cuid-hex <HEXSTRING>
-
Use HEXSTRING as the Configuration Unique ID. Must be a hex 128-bit unsigned
big endian number string. Leading zeros must be provided. If specified, the
value must match with the Config-UID from the attestation result of that
guest. If not specified, the CUID will be ignored by the ultravisor during
the verification of the request.
--cuid <FILE>
-
Use the content of FILE as the Configuration Unique ID. The file must
contain exactly 128 bit of data, a hex string, or a yaml with a `cuid`
entry. If specified, the value must match the Config-UID from the
attestation result of that guest. If not specified, the CUID will be ignored
by the Ultravisor during the verification of the request.
--flags <FLAGS>
-
Flags for the add-secret request.
Possible values:
- disable-dump: Disables host-initiated dumping for the target guest
instance
pvsecret create meta
Description
Use a meta secret to carry flags to the ultravisor without having to provide an actual secret value. Meta secrets do not appear in the list of secrets.
Synopsis
pvsecret create meta
pvsecret create association
Description
Use an association secret to connect a trusted I/O device to a guest. The
pvapconfig tool provides more information about association secrets.
Synopsis
pvsecret create association [OPTIONS] <NAME>
Arguments
<NAME>
-
String to identify the new secret. The actual secret is set with
--input-secret. The name is saved in `NAME.yaml` with white-spaces
mapped to `_`.
Options
--stdout
-
Print the hashed name to stdout. The hashed name will not be written to
`NAME.yaml`
--input-secret <FILE>
-
Path from which to read the plaintext secret. Uses a random secret if not
specified.
--output-secret <FILE>
-
Save the generated secret as plaintext in FILE. The generated secret can be
used to generate add-secret requests for a different guest with the same
secret using --input-secret. Destroy the secret when it is not used
anymore.
pvsecret add
Description
Perform an add-secret request using a previously generated add-secret request. Only available on s390x.
Synopsis
pvsecret add <FILE>
Arguments
<FILE>
-
Specify the request to be sent
pvsecret lock
Description
Lock the secret store (s390x only). After this command executed successfully, all add-secret requests will fail. Only available on s390x.
Synopsis
pvsecret lock
pvsecret list
Description
Lists the IDs of all non-null secrets currently stored in the ultravisor for the currently running IBM Secure Execution guest. Only available on s390x.
Synopsis
pvsecret list [OPTIONS] [FILE]
Arguments
<FILE>
-
Store the result in FILE. Default value: '-'
Options
--format <FORMAT>
Define the output format of the list. Default value: 'human'
Possible values:
- human: Human-focused, non-parsable output format
- yaml: Use yaml format
- bin: Use the format the ultravisor uses to pass the list