Get in Touch

Course Outline

  • BMC threat modeling analysis
  • Exposure assessment of server BMC attack surfaces
  • Pervasive vulnerabilities associated with legacy BMC firmware
  • Architectural overview of OpenBMC security framework
  • Regulatory compliance standards (NIST, PCI-DSS) for government infrastructure

Secure Boot Implementation

  • Verification of the U-Boot secure boot chain
  • Cryptographic image signing utilizing RSA and ECDSA
  • Management of key hierarchies and certificate revocation
  • Foundational measurement and attestation protocols

Firmware Update Integrity

  • Verification workflows for image signatures
  • Protection against rollback attacks and version control policies
  • Dual-bank update strategies for operational continuity
  • Deployment mechanisms via Redfish and IPMI protocols

Certificate Lifecycle Management

  • Architectural design of Phosphor-certificate-manager
  • Procedures for installing and rotating HTTPS certificates
  • Administration of Certificate Authority (CA) trust stores
  • Implementation of LDAPS and client certificate-based authentication

Access Control and Authentication

  • Local user administration and password complexity policies
  • Integration with LDAP and Active Directory directories
  • Configuration of the PAM authentication stack
  • Role-based access control (RBAC) and privilege mapping in Redfish

Network Defense Posture

  • Implementation of firewall rules and nftables policies
  • Configuration of TLS 1.3 within the bmcweb service
  • Hardening of SSH services and enforcement of key-based authentication
  • Network segmentation strategies for BMC interface protection

Logging and Incident Response

  • Configuration of remote syslog forwarding
  • Centralized security event logging
  • Management of System Event Logs (SEL) and audit trails
  • Response protocols for compromised BMC instances for government use

Security Verification Testing

  • Static code analysis using CodeQL and Bandit
  • Fuzzing of D-Bus interface endpoints
  • Penetration testing of REST and Redfish API surfaces
  • Tracking of CVEs and management of security patches

Requirements

  • Proficiency in Public Key Infrastructure (PKI) and TLS fundamentals
  • Foundational knowledge of Linux security concepts
  • Understanding of embedded firmware update mechanisms

Target Audience

  • Security engineers
  • Firmware developers
  • System administrators responsible for BMC infrastructure
 14 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories