All of lore.kernel.org
 help / color / mirror / Atom feed
* Proposal add PerformService privilege
@ 2020-12-04 20:11 Joseph Reynolds
  2020-12-09 18:25 ` Ed Tanous
  0 siblings, 1 reply; 4+ messages in thread
From: Joseph Reynolds @ 2020-12-04 20:11 UTC (permalink / raw)
  To: openbmc

This is a proposal to add an OemOpenBMCPerformService privilege to BMCWeb.

See https://redfishforum.com/thread/397/redfish-direction-update-eeproms
As mentioned in the Redfish forum thread, the use case is that some 
OpenBMC use cases require isolating manufacturing and service functions 
away from the customer/admin (including updating FRU serial numbers, and 
updating a permanent MAC address), and this is a Redfish compatible way 
to do it.

The work items would be like:
- Add this OEM privilege to the base BMCWeb implementation.
- Identify URIs that we need to be able to isolate away from 
customer/admins.  Then modify the privilege mapping to require this 
privilege to PUT to those URIs.
- Add this privilege to the Administrator role (but not Operator or 
ReadOnly).
- Document how to isolate these operations.  Specifically, remove this 
privilege from Administrator, and create a custom OEM role that has this 
privilege

What do you think?
- Joseph


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2020-12-17 17:50 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-12-04 20:11 Proposal add PerformService privilege Joseph Reynolds
2020-12-09 18:25 ` Ed Tanous
2020-12-17 17:31   ` Joseph Reynolds
2020-12-17 17:48     ` Ed Tanous

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.