Which virtualization solution when security matters ?
Linux - SecurityThis forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
There is an argument from Green Hills http://www.ghs.com/products/rtos/integritypc.html that their hypervisor solution is architecturally better from the point of view of security. My opinion is that this argument may be true but, in the abscence of a developed infrastructure of hypervisor exploits it is impossible to say how significant this architectural detail is (compared, let's say, to implementation details).
In any case, you probably need to look at it, if security is your overriding concern.
It is about "security context". (..) Seems security is their point.
If you say it like that the phrase caveat emptor comes to mind. As you defined "advertised" as having "more segregation" and being "more robust" (just trying only to create enough doubt necessary for discussion) just because it says so on the package, what guarantees do you have that it "works as advertised"?.. (any CVE/NVD/OSVDB entries?)
You are right, I don't know about the quality of the implementation of Vserver.
But when you talk about the design itself, it seems Vserver takes the security (I mainly mean segregation of applications and network) well into account.
It is purely subjective, I agree.
But I am not able to find any contest between Vserver and OpenVZ (both are containers)clearly pointing the advantage and drawback of each other.
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.