--- $> libvirtd --version libvirtd (libvirt) 5.5.0 --- $> rpm -ql edk2-ovmf-20190308stable-1.fc29.noarch | grep -i secboot /usr/share/OVMF/OVMF_CODE.secboot.fd /usr/share/OVMF/OVMF_VARS.secboot.fd /usr/share/edk2/ovmf/OVMF_CODE.secboot.fd /usr/share/edk2/ovmf/OVMF_VARS.secboot.fd --- $> virsh domcapabilities --machine q35 --arch x86_64 /usr/bin/qemu-system-x86_64 kvm pc-q35-4.0 x86_64 /usr/share/edk2/ovmf/OVMF_CODE.fd /usr/share/edk2/aarch64/QEMU_EFI-pflash.raw rom pflash yes no no Skylake-Client-IBRS Intel qemu64 qemu32 phenom pentium3 pentium2 pentium n270 kvm64 kvm32 coreduo core2duo athlon Westmere-IBRS Westmere Skylake-Server-IBRS Skylake-Server Skylake-Client-IBRS Skylake-Client SandyBridge-IBRS SandyBridge Penryn Opteron_G5 Opteron_G4 Opteron_G3 Opteron_G2 Opteron_G1 Nehalem-IBRS Nehalem IvyBridge-IBRS IvyBridge Icelake-Server Icelake-Client Haswell-noTSX-IBRS Haswell-noTSX Haswell-IBRS Haswell EPYC-IBPB EPYC Conroe Cascadelake-Server Broadwell-noTSX-IBRS Broadwell-noTSX Broadwell-IBRS Broadwell 486 disk cdrom floppy lun fdc scsi virtio usb sata virtio virtio-transitional virtio-non-transitional sdl vnc spice subsystem default mandatory requisite optional usb pci scsi ---