Get in Touch

Course Outline

  • BMC Threat Modeling
  • Assessing the attack surface of server BMCs
  • Identifying common vulnerabilities in legacy BMC firmware
  • Overview of the OpenBMC security architecture
  • Compliance standards (NIST, PCI-DSS)

Secure Boot

  • U-Boot verified boot chain implementation
  • Image signing using RSA and ECDSA
  • Key hierarchy management and revocation procedures
  • Foundations of measurement and attestation

Firmware Update Security

  • Image signature verification workflows
  • Rollback protection and versioning policies
  • Dual-bank update strategies
  • Code updates via Redfish and IPMI

Certificate Management

  • Architecture of Phosphor-certificate-manager
  • Installation and replacement of HTTPS certificates
  • Managing Certificate Authority (CA) trust stores
  • LDAPS and client certificate authentication

Authentication and Authorization

  • Local user administration and password policies
  • Integration with LDAP and Active Directory
  • Configuring the PAM stack
  • Redfish RBAC and privilege mapping

Network Security

  • Firewall rules and nftables configuration
  • TLS 1.3 setup within bmcweb
  • SSH hardening and key-based authentication
  • Network segmentation for BMC interfaces

Audit and Response

  • Configuring remote syslog
  • Logging security events
  • Managing SEL and audit trails
  • Incident response strategies for compromised BMCs

Security Testing

  • Static analysis using CodeQL and Bandit
  • Fuzzing D-Bus interfaces
  • Penetration testing of REST and Redfish APIs
  • CVE tracking and patch management

Requirements

  • Proficiency in PKI and TLS fundamentals
  • Knowledge of basic Linux security principles
  • Familiarity with embedded firmware update processes

Target Audience

  • Security engineers
  • Firmware developers
  • System administrators responsible for BMC infrastructure
 14 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories