Get in Touch

Course Outline

  • BMC Threat Model.
  • Attack surface analysis of server BMCs.
  • Common vulnerabilities in legacy BMC firmware.
  • Overview of OpenBMC security architecture.
  • Compliance requirements (NIST, PCI-DSS).

Secure Boot

  • U-Boot verified boot chain.
  • Image signing using RSA and ECDSA.
  • Key hierarchy and revocation processes.
  • Introduction to measurement and attestation.

Firmware Update Security

  • Flow of image signature verification.
  • Rollback protection and version policies.
  • Dual-bank update strategies.
  • Code updates via Redfish and IPMI.

Certificate Management

  • Architecture of Phosphor-certificate-manager.
  • Installing and replacing HTTPS certificates.
  • Certificate Authority (CA) trust stores.
  • LDAPS and client certificate authentication.

Authentication and Authorization

  • Local user management and password policies.
  • Integration with LDAP and Active Directory.
  • PAM stack configuration.
  • Redfish RBAC and privilege mapping.

Network Security

  • Firewall rules and nftables.
  • TLS 1.3 configuration in bmcweb.
  • SSH hardening and key-based authentication.
  • Network segmentation for BMC interfaces.

Audit and Response

  • Remote syslog configuration.
  • Security event logging.
  • SEL and audit trail management.
  • Incident response procedures for compromised BMCs.

Security Testing

  • Static analysis using CodeQL and Bandit.
  • Fuzzing D-Bus interfaces.
  • Penetration testing of REST and Redfish APIs.
  • CVE tracking and patch management.

Requirements

  • Familiarity with PKI and TLS fundamentals.
  • Basic understanding of Linux security concepts.
  • Knowledge of embedded firmware update mechanisms.

Audience

  • Security engineers.
  • Firmware developers.
  • System administrators managing BMC infrastructure.
 14 Hours

Number of participants


Price per participant

Testimonials (4)

Upcoming Courses

Related Categories