Document navigation

VM Trusted Security

VM trusted security is used to enhance the security of the VM operating system runtime environment. By configuring key providers, vTPM, UEFI boot, and Secure Boot, VMs can obtain trusted platform module capabilities and stronger boot chain protection.

Before you configure vTPM for a VM, make sure an available key provider is configured on the platform and that the VM runtime environment and operating system meet the requirements for TPM 2.0, UEFI, and related features.

Secure VMs with vTPM

When you create a new virtual machine or add a virtual Trusted Platform Module (vTPM) to an existing virtual machine, you provide enhanced security for the virtual machine operating system.

Before you begin

  • The platform has an available key provider. If you use the native key provider, back it up first.
  • The host on which the VM runs must meet the vTPM support requirements for kernel, QEMU, and libvirt versions. The following table lists the required component versions for each architecture and host operating system version:
    Architecture Host OS version Kernel version QEMU version libvirt version
    x86 H84r 4.18.0-553.69.1.13.gc220c6303994.el8.x86_64 qemu-kvm-6.2.0-235.g51749aa16b.el8 libvirt-8.0.0-90.g4f8dd1cb01.el8.x86_64
    KY10 SP3 4.19.90-52.48.v2207.ky10.x86_64 qemu-kvm-6.2.0-235.g51749aa16b.ky10 libvirt-8.0.0-90.g4f8dd1cb01.ky10.x86_64
    KY10 SP3.2403 4.19.90-89.25.v2401.ky10.x86_64 qemu-kvm-6.2.0-232.g09252161d1.ky10 libvirt-8.0.0-90.g4f8dd1cb01.ky10.x86_64
    ARM KY10 SP3 4.19.90-52.48.v2207.ky10.aarch64 qemu-6.2.0-906.g271454a05e.ky10 libvirt-6.2.0-415.gf2c25be909.ky10.aarch64
    KY10 SP3.2403 4.19.90-89.25.v2401.ky10.aarch64 qemu-6.2.0-1042.g7eecd245dd.ky10 libvirt-6.2.0-463.g2ee090fe60.ky10.aarch64
    H22e 5.10.0-136.12.0.86.oe2203sp1.aarch64 qemu-6.2.0-906.g271454a05e libvirt-6.2.0-415.gf2c25be909.aarch64
  • The virtual machine boot mode must be set to UEFI.
  • The virtual machine operating system must support the TPM 2.0 specification. Operating systems that do not support TPM 2.0 (including but not limited to Windows Server 2012 and earlier, CentOS 6 / RHEL 6, Ubuntu 14.04 and earlier) are not supported.
  • Before you add a TPM to an existing virtual machine, power off the virtual machine.

Procedure

  1. In the navigation pane, select Inventory > VM and Host.
  2. In the resource tree, right-click the target cluster, host, or image, and then click New Virtual Machine.
  3. In the Select VM Creation Method dialog, select New VM, and then click Next.
  4. In the New Virtual Machine dialog, complete the relevant basic configuration. For more information about virtual machine parameters, see Create a Virtual Machine.
  5. In the Advanced Settings section, click Boot Options and select UEFI as the virtual machine BIOS mode.
  6. In the Hardware Info section, click Add Hardware > TPM.
    After the TPM is added successfully, click TPM in the hardware list. You can view the TPM status and specification in the hardware configurations pane on the right.
  7. After you confirm the configuration details are correct, click OK.
User Guide | ZStack ZSphere · ZVF | ZStack Resource Center