VirtualBox

Changeset 56609 in vbox for trunk/doc/manual


Ignore:
Timestamp:
Jun 23, 2015 5:35:00 PM (9 years ago)
Author:
vboxsync
Message:

doc/manual: document clearly that disk encryption can lead to data loss when the VM config is lost, and minor wording changes elsewhere

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/doc/manual/en_US/user_AdvancedTopics.xml

    r56451 r56609  
    37613761      hard disk images transparently for the guest. It does not depend on a specific
    37623762      image format to be used. Images which have the data encrypted are not portable
    3763       between VirtualBox and other virtualization software though.
     3763      between VirtualBox and other virtualization software.
    37643764    </para>
    37653765
     
    37713771    </para>
    37723772
     3773    <para>
     3774      Since the DEK is stored as part of the VM configuration file, it is
     3775      important that it is kept safe. Losing the DEK means that the data stored
     3776      in the disk images is lost irrecoverably. Having complete and up to
     3777      date backups of all data related to the VM is the responsibility of the
     3778      user.
     3779    </para>
     3780
    37733781    <sect2 id="diskencryption-limitations">
    37743782      <title>Limitations</title>
     
    37823790
    37833791        <listitem>
    3784           <para>This feature is currently closed source and requires the VirtualBox extension
    3785             pack to be installed to work.</para>
     3792          <para>This feature is part of the Oracle VM VirtualBox Extension
     3793            Pack, which needs to be installed. Otherwise disk encryption
     3794            is unavailable.</para>
    37863795        </listitem>
    37873796
     
    37893798          <para>Since encryption works only on the stored user data,
    37903799            it is currently not possible to check for metadata integrity of the disk image.
    3791             Attackers might take advantage of this to remove or insert blocks of data
    3792             into the image or change certain metadata items such as the disk size.</para>
     3800            Attackers might destroy data by removing or changing blocks of data
     3801            in the image or change metadata items such as the disk size.
     3802          </para>
    37933803        </listitem>
    37943804
     
    38033813            decrypt data read and encrypt data written by the guest. While this should
    38043814            be obvious the user needs to be aware of this because an attacker might be able
    3805             to extract the key on a compromised host and get access to the data later.</para>
     3815            to extract the key on a compromised host and decrypt the data.</para>
    38063816        </listitem>
    38073817
    38083818        <listitem>
    3809           <para>When encrypting or decrypting the images, the password is passed unencrypted
    3810             via the Main API from the frontend to VBoxSVC. This needs to be kept in mind,
    3811             especially when using third party frontends which make use of the webservice
    3812             where the password might be transmitted unencrypted over the network.</para>
     3819          <para>When encrypting or decrypting the images, the password is
     3820            passed in clear text via the VirtualBox API. This needs to be kept
     3821            in mind, especially when using third party API clients which make
     3822            use of the webservice where the password might be transmitted
     3823            over the network. The use of HTTPS is mandatory in such a case.
     3824          </para>
    38133825        </listitem>
    38143826
    38153827        <listitem>
    3816           <para>Encrypting images with differencing images is only possible if there
    3817             are no branches. This limitation may be addressed in a future
    3818             VirtualBox version.</para>
     3828          <para>Encrypting images with differencing images is only possible if
     3829            there are no snapshots or a linear chain of snapshots. This
     3830            limitation may be addressed in a future VirtualBox version.</para>
    38193831        </listitem>
    38203832
Note: See TracChangeset for help on using the changeset viewer.

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette