Get in Touch

Course Outline

  • BMC Threat Model
  • Attack surface analysis of server BMCs
  • Common vulnerabilities in legacy BMC firmware
  • Overview of OpenBMC security architecture
  • Compliance requirements (NIST, PCI-DSS)

Secure Boot

  • U-Boot verified boot chain
  • Image signing using RSA and ECDSA
  • Key hierarchy and revocation processes
  • Fundamentals of measurement and attestation

Firmware Update Security

  • Flow for image signature verification
  • Rollback protection and version policies
  • Dual-bank update strategies
  • Code updates via Redfish and IPMI protocols

Certificate Management

  • Architecture of Phosphor-certificate-manager
  • Installing and replacing HTTPS certificates
  • Trusted Certificate Authority (CA) stores
  • LDAPS and client certificate authentication

Authentication and Authorization

  • Local user management and password policies
  • Integration with LDAP and Active Directory
  • PAM stack configuration
  • Redfish RBAC and privilege mapping

Network Security

  • Firewall rules and nftables implementation
  • TLS 1.3 configuration in bmcweb
  • SSH hardening and key-based authentication
  • Network segmentation for BMC interfaces

Audit and Response

  • Configuration of remote syslog
  • Logging of security events
  • Management of SEL and audit trails
  • Incident response procedures for compromised BMCs

Security Testing

  • Static analysis using CodeQL and Bandit
  • Fuzzing D-Bus interfaces
  • Penetration testing of REST and Redfish APIs
  • CVE tracking and patch management

Requirements

  • Familiarity with Public Key Infrastructure (PKI) and TLS fundamentals
  • Basic understanding of Linux security concepts
  • Knowledge of embedded firmware update mechanisms

Audience

  • Security engineers
  • Firmware developers
  • System administrators managing BMC infrastructure
 14 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories