Re: [qubes-users] Running a single appVM off another volume

2018-11-03 Thread 'awokd' via qubes-users

Achim Patzner:

Hi!

Is there an easier way of storing a single VM on an external device
(assume it to be an USB conneted medium) without doing elaborate dances
around it or having to backup and restore? One of our customers got the
bright idea to store a VM containing their CA on an USB flash and
connecting it to "an appropriate machine" (Yes! "Appropriate! Imagine
the fun I'm having *now*) for key signing ("Guys, have you ever heard
of a device called HSM?" "No, and please don't tell us.").

$appropriate was considered to be VMware without a virtual network
interface, running the machine off a USB flash. Securely stored on a
hook besides the door, "because if it is physically disconected it is
safe".

Ok, may not be TAILS (because that's used by criminals) but using Qubes
is an option. Getting off the VM-on-external-media-only trip not. Is it
possible to get these guys on Qubes without "changing the documented
process"?


There's https://www.qubes-os.org/doc/secondary-storage/ but not sure how 
well either approach works with drives appearing and disappearing. Think 
there's been some earlier discussion in this mailing list too.


--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/c331108f-fdb0-e6c8-d35a-cd0436f7bd18%40danwin1210.me.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Running a single appVM off another volume

2018-11-02 Thread Achim Patzner
Hi!

Is there an easier way of storing a single VM on an external device
(assume it to be an USB conneted medium) without doing elaborate dances
around it or having to backup and restore? One of our customers got the
bright idea to store a VM containing their CA on an USB flash and
connecting it to "an appropriate machine" (Yes! "Appropriate! Imagine
the fun I'm having *now*) for key signing ("Guys, have you ever heard
of a device called HSM?" "No, and please don't tell us.").

$appropriate was considered to be VMware without a virtual network
interface, running the machine off a USB flash. Securely stored on a
hook besides the door, "because if it is physically disconected it is
safe".

Ok, may not be TAILS (because that's used by criminals) but using Qubes
is an option. Getting off the VM-on-external-media-only trip not. Is it
possible to get these guys on Qubes without "changing the documented
process"?


Achim


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/30149d2008d3ee42cd7ebfc798a3a1772c071d35.camel%40noses.com.
For more options, visit https://groups.google.com/d/optout.