feature request clock offset adjustment random value from KVM upstream

Information

ID: 439
PHID: PHID-TASK-a64vscppvmc7uuqjy3x5
Author: Patrick
Status at Migration Time: resolved
Priority at Migration Time: Normal

Description

To stop clock correlation attacks it would be good, if we could automate the advice from advanced security guide, Spoof the Initial Virtual Hardware Clock Offset. Currently the offset can only be set to a fixed value, that’s why we cannot deploy this setting by default.

TODO:
post a feature request upstream that allows setting a random value with a configurable minimum, maximum value

Comments


HulaHoop

2015-11-25 23:29:43 UTC


Patrick

2015-11-26 01:26:13 UTC


HulaHoop

2015-11-26 01:48:58 UTC


Patrick

2015-11-26 17:18:23 UTC


HulaHoop

2016-03-01 20:15:02 UTC


HulaHoop

2016-03-02 17:06:07 UTC


HulaHoop

2016-09-05 14:08:44 UTC


Patrick

2016-09-05 14:15:48 UTC