Course Outline
- Baseboard Management Controller (BMC) threat modeling framework
- Identification of the server BMC attack surface
- Prevalent vulnerabilities within legacy BMC firmware ecosystems
- Overview of the OpenBMC security architectural design
- Regulatory compliance mandates (NIST, PCI-DSS)
Secure Boot Protocols
- U-Boot verified boot chain implementation
- Image signing utilizing RSA and ECDSA algorithms
- Cryptographic key hierarchy and revocation procedures
- Fundamentals of measurement and attestation processes
Firmware Update Security Controls
- Workflow for image signature verification
- Rollback prevention mechanisms and version governance policies
- Dual-bank update strategies for system resilience
- Secure code delivery via Redfish and IPMI interfaces
Certificate Lifecycle Management
- Architecture of the Phosphor-certificate-manager service
- Procedures for installing and replacing HTTPS certificates
- Configuration of Certificate Authority (CA) trust stores
- Implementation of LDAPS and client certificate authentication
Authentication and Authorization Frameworks
- Local user administration and password governance policies
- Integration with LDAP and Active Directory directories
- PAM stack configuration standards
- Redfish Role-Based Access Control (RBAC) and privilege mapping protocols
Network Security Measures
- Firewall rule management using nftables
- TLS 1.3 configuration within the bmcweb service
- SSH hardening practices and key-based authentication methods
- Network segmentation strategies for BMC interface isolation
Audit Logging and Incident Response
- Configuration of remote syslog aggregation
- Security event logging standards
- Syslog Event Language (SEL) and audit trail management
- Incident response protocols for compromised BMCs
Security Testing and Validation
- Static code analysis using CodeQL and Bandit tools
- Fuzz testing of D-Bus interfaces
- Penetration testing of REST and Redfish APIs
- Vulnerability tracking and patch management procedures for government systems
Requirements
- Knowledge of Public Key Infrastructure (PKI) and Transport Layer Security (TLS) principles
- Fundamental understanding of Linux security frameworks
- Awareness of embedded firmware update procedures
Intended Audience
- Security engineering personnel
- Firmware development specialists
- System administrators responsible for Baseboard Management Controller (BMC) infrastructure
Testimonials (3)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
I understood the process of the operating system and how do we link all factors together information of network as well so now I have an obvious and full picture about what is going on these computers how they communicate with each others ultimately gained knowledge about the most important operating system which is Linux and how do we implement our own embedded Linux
Rawda Alnaqbi - beamtrail
Course - Introduction to Embedded Linux (Hands-on training)
Speed of response and communication