On Wed, Jun 04, 2025 at 05:56:56PM -0400, Zhuoying Cai wrote: > Add documentation for secure IPL > > Signed-off-by: Collin Walling <wall...@linux.ibm.com> > Signed-off-by: Zhuoying Cai <zy...@linux.ibm.com> > --- > docs/specs/s390x-secure-ipl.rst | 145 +++++++++++++++++++++++++++++++ > docs/system/s390x/secure-ipl.rst | 129 +++++++++++++++++++++++++++ > 2 files changed, 274 insertions(+) > create mode 100644 docs/specs/s390x-secure-ipl.rst > create mode 100644 docs/system/s390x/secure-ipl.rst >
> +Secure IPL Quickstart > +===================== > + > +Build QEMU with gnutls enabled: > + > +.. code-block:: shell > + > + ./configure … --enable-gnutls > + > +Generate certificate (e.g. via openssl): > + > +.. code-block:: shell > + > + openssl req -new -x509 -newkey rsa:2048 -keyout mykey.priv \ > + -outform DER -out mycert.der -days 36500 \ > + -subj "/CN=My Name/" -nodes Please illustrate with gnutls 'certtool' for consistency with other cert creation docs we have at: https://www.qemu.org/docs/master/system/tls.html With regards, Daniel -- |: https://berrange.com -o- https://www.flickr.com/photos/dberrange :| |: https://libvirt.org -o- https://fstop138.berrange.com :| |: https://entangle-photo.org -o- https://www.instagram.com/dberrange :|