Elektrine lite

← Feed

@andersonc0d3@infosec.exchange

2026-06-29 19:12 UTC

Red Hat is working on a capability for virtual machine guests (tenants) to provide their own firmware (UEFI). This is interesting for measured boot (attestation), implementing per-guest features/configurations, and various other use cases. It's known as Bring Your Own Firmware (BYOF). Introducing FUKI, guest firmware in a UKI for confidential cloud deployments (2025) https://archive.fosdem.org/2025/schedule/event/fosdem-2025-4661-introducing-fuki-guest-firmware-in-a-uki-for-confidential-cloud-deployments/ Empowering confidential VMs in the cloud to use their own firmware upon instantiation. (2024) https://people.redhat.com/~anisinha/BYOF-KVMForum2024.pdf Additionally, there is a technical challenge regarding resetting certain confidential guests. Because their CPU register states and memory regions are encrypted and inaccessible to the host, the hypervisor cannot execute a standard, hardware-assisted reset, which previously caused these confidential guests to terminate upon a reboot attempt. The author explains the problem and the two approaches to address it in the blog post below: Confidential guest reset on QEMU hypervisor: Design choices and approach https://www.redhat.com/en/blog/confidential-guest-reset-qemu-hypervisor-design-choices-and-approach

Replies (0)

No replies.