Get in Touch

Course Outline

  • Baseboard Management Controller (BMC) threat modeling framework
  • Identification of the server BMC attack surface
  • Prevalent vulnerabilities within legacy BMC firmware ecosystems
  • Overview of the OpenBMC security architectural design
  • Regulatory compliance mandates (NIST, PCI-DSS)

Secure Boot Protocols

  • U-Boot verified boot chain implementation
  • Image signing utilizing RSA and ECDSA algorithms
  • Cryptographic key hierarchy and revocation procedures
  • Fundamentals of measurement and attestation processes

Firmware Update Security Controls

  • Workflow for image signature verification
  • Rollback prevention mechanisms and version governance policies
  • Dual-bank update strategies for system resilience
  • Secure code delivery via Redfish and IPMI interfaces

Certificate Lifecycle Management

  • Architecture of the Phosphor-certificate-manager service
  • Procedures for installing and replacing HTTPS certificates
  • Configuration of Certificate Authority (CA) trust stores
  • Implementation of LDAPS and client certificate authentication

Authentication and Authorization Frameworks

  • Local user administration and password governance policies
  • Integration with LDAP and Active Directory directories
  • PAM stack configuration standards
  • Redfish Role-Based Access Control (RBAC) and privilege mapping protocols

Network Security Measures

  • Firewall rule management using nftables
  • TLS 1.3 configuration within the bmcweb service
  • SSH hardening practices and key-based authentication methods
  • Network segmentation strategies for BMC interface isolation

Audit Logging and Incident Response

  • Configuration of remote syslog aggregation
  • Security event logging standards
  • Syslog Event Language (SEL) and audit trail management
  • Incident response protocols for compromised BMCs

Security Testing and Validation

  • Static code analysis using CodeQL and Bandit tools
  • Fuzz testing of D-Bus interfaces
  • Penetration testing of REST and Redfish APIs
  • Vulnerability tracking and patch management procedures for government systems

Requirements

  • Knowledge of Public Key Infrastructure (PKI) and Transport Layer Security (TLS) principles
  • Fundamental understanding of Linux security frameworks
  • Awareness of embedded firmware update procedures

Intended Audience

  • Security engineering personnel
  • Firmware development specialists
  • System administrators responsible for Baseboard Management Controller (BMC) infrastructure
This educational material is designed specifically for government professionals seeking to enhance their technical proficiency in secure system management and firmware integrity.
 14 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories