diff --git a/xml/vm_security.xml b/xml/vm_security.xml index e88daf0a31..4c7e6fc285 100644 --- a/xml/vm_security.xml +++ b/xml/vm_security.xml @@ -76,8 +76,7 @@ The confidential compute module provides replacement packages supporting AMD SEV To install the replacement packages, run the command: - -&prompt.sudo; zypper install --from SLE-Module-Confidential-Computing-15-SP6-Pool --from SLE-Module-Confidential-Computing-15-SP6-Updates qemu libvirt kernel-coco +&prompt.sudo; zypper install --from SLE-Module-Confidential-Computing-15-SP6-Pool --from SLE-Module-Confidential-Computing-15-SP6-Updates qemu libvirt kernel-coco After replacing the packages, you must set up the system with a configuration change to make the AMD SEV-SNP feature ready to use. The IOMMU on the host side must be configured in non-passthrough mode. This is required to prevent peripheral devices from writing to memory that belongs to an encrypted guest and destroying its data integrity. The default IOMMU configuration in &productname; &productnumber; is passthrough mode.