感谢您发送咨询!我们的团队成员将很快与您联系。
感谢您发送预订!我们的团队成员将很快与您联系。
课程大纲
- BMC Threat Model
- Attack surface of server BMCs
- Common vulnerabilities in legacy BMC firmware
- OpenBMC security architecture overview
- Compliance requirements (NIST, PCI-DSS)
Secure Boot
- U-Boot verified boot chain
- Image signing with RSA and ECDSA
- Key hierarchy and revocation
- Measurement and attestation basics
Firmware Update Security
- Image signature verification flow
- Rollback protection and version policies
- Dual-bank update strategies
- Code update via Redfish and IPMI
Certificate Management
- Phosphor-certificate-manager architecture
- Installing and replacing HTTPS certificates
- Certificate Authority (CA) trust stores
- LDAPS and client certificate authentication
Authentication and Authorization
- Local user management and password policies
- LDAP and Active Directory integration
- PAM stack configuration
- Redfish RBAC and privilege mapping
Network Security
- Firewall rules and nftables
- TLS 1.3 configuration in bmcweb
- SSH hardening and key-based auth
- Network segmentation for BMC interfaces
Audit and Response
- Remote syslog configuration
- Security event logging
- SEL and audit trail management
- Incident response for compromised BMCs
Security Testing
- Static analysis with CodeQL and Bandit
- Fuzzing D-Bus interfaces
- Penetration testing REST and Redfish APIs
- CVE tracking and patch management
要求
- Understanding of PKI and TLS fundamentals
- Basic Linux security concepts
- Familiarity with embedded firmware update mechanisms
Audience
- Security engineers
- Firmware developers
- System administrators managing BMC infrastructure
14 小时
客户评论 (3)
培训师非常乐于助人。
Attila - Lifial
课程 - Compliance and the Management of Compliance Risk
机器翻译
培训师的演讲技巧和沟通方式。
Gianpiero Arico - Urmet Spa
课程 - Embedded Linux Systems Architecture
机器翻译
学习巴塞尔协议
Daksha Vallabh - Standard Bank of SA Ltd
课程 - Basel III – Certified Basel Professional
机器翻译