• Michael Roth's avatar
    crypto: ccp: Add the SNP_VLEK_LOAD command · 332d2c1d
    Michael Roth authored
    When requesting an attestation report a guest is able to specify whether
    it wants SNP firmware to sign the report using either a Versioned Chip
    Endorsement Key (VCEK), which is derived from chip-unique secrets, or a
    Versioned Loaded Endorsement Key (VLEK) which is obtained from an AMD
    Key Derivation Service (KDS) and derived from seeds allocated to
    enrolled cloud service providers (CSPs).
    
    For VLEK keys, an SNP_VLEK_LOAD SNP firmware command is used to load
    them into the system after obtaining them from the KDS. Add a
    corresponding userspace interface so to allow the loading of VLEK keys
    into the system.
    
    See SEV-SNP Firmware ABI 1.54, SNP_VLEK_LOAD for more details.
    Reviewed-by: default avatarTom Lendacky <thomas.lendacky@amd.com>
    Signed-off-by: default avatarMichael Roth <michael.roth@amd.com>
    Message-ID: <20240501085210.2213060-21-michael.roth@amd.com>
    Signed-off-by: default avatarPaolo Bonzini <pbonzini@redhat.com>
    332d2c1d
sev-guest.rst 8.73 KB