All of lore.kernel.org
 help / color / mirror / Atom feed
* BMC threat model docs
@ 2019-07-17 16:26 Joseph Reynolds
  2019-07-17 17:21 ` Chittari Pabba
  0 siblings, 1 reply; 4+ messages in thread
From: Joseph Reynolds @ 2019-07-17 16:26 UTC (permalink / raw)
  To: openbmc

I got a private email asking
 > [where are the] BMC project threat model documents?

The approved network threat model is here:
https://github.com/openbmc/docs/blob/master/security/network-security-considerations.md

The threat model is very basic and does little more than identify 
OpenBMC's network services.  The level of detail was initially 
superficial to get approval for the document.  I hope to add more 
details and add new sections for BMC network connections including LDAP, 
remote logging, remote media, ip-kvm, event subscriptions, etc.  Then 
add a section for Redfish security considerations.

The network threat model is only a subset of the overall BMC threat 
model.  (For example, the BMC faces threats from its environment and its 
host system.)  The OpenBMC project has no overall BMC threat model, and 
mine is in review here:
https://gerrit.openbmc-project.xyz/c/openbmc/docs/+/22404
(You can find other threat model reviews by searching gerrit for 
"threat" or "security").

I am using my review to collect information about BMC threats, which in 
turn depends on how the BMC is used, so I am collecting information 
about BMC use cases too.  Any and all contributions are welcome, and can 
be added as review comments, email to the community, or directly to me.  
I am struggling with the threat model scope, and how to organize the 
document.  Any feedback is welcome.

- Joseph

^ permalink raw reply	[flat|nested] 4+ messages in thread

* RE: BMC threat model docs
  2019-07-17 16:26 BMC threat model docs Joseph Reynolds
@ 2019-07-17 17:21 ` Chittari Pabba
  2019-07-17 17:26   ` Chittari Pabba
  0 siblings, 1 reply; 4+ messages in thread
From: Chittari Pabba @ 2019-07-17 17:21 UTC (permalink / raw)
  To: Joseph Reynolds, openbmc

Thank you, Joseph, for quick response !!! I will review the Open BMC threat model document and will provide my feedback. 

-----Original Message-----
From: openbmc <openbmc-bounces+chittarip=ami.com@lists.ozlabs.org> On Behalf Of Joseph Reynolds
Sent: Wednesday, July 17, 2019 12:27 PM
To: openbmc <openbmc@lists.ozlabs.org>
Subject: BMC threat model docs

I got a private email asking
 > [where are the] BMC project threat model documents?

The approved network threat model is here:
https://github.com/openbmc/docs/blob/master/security/network-security-considerations.md

The threat model is very basic and does little more than identify OpenBMC's network services.  The level of detail was initially superficial to get approval for the document.  I hope to add more details and add new sections for BMC network connections including LDAP, remote logging, remote media, ip-kvm, event subscriptions, etc.  Then add a section for Redfish security considerations.

The network threat model is only a subset of the overall BMC threat model.  (For example, the BMC faces threats from its environment and its host system.)  The OpenBMC project has no overall BMC threat model, and mine is in review here:
https://gerrit.openbmc-project.xyz/c/openbmc/docs/+/22404
(You can find other threat model reviews by searching gerrit for "threat" or "security").

I am using my review to collect information about BMC threats, which in turn depends on how the BMC is used, so I am collecting information about BMC use cases too.  Any and all contributions are welcome, and can be added as review comments, email to the community, or directly to me. I am struggling with the threat model scope, and how to organize the document.  Any feedback is welcome.

- Joseph


Please consider the environment before printing this email.

The information contained in this message may be confidential and proprietary to American Megatrends, Inc.  This communication is intended to be read only by the individual or entity to whom it is addressed or by their designee. If the reader of this message is not the intended recipient, you are on notice that any distribution of this message, in any form, is strictly prohibited.  Please promptly notify the sender by reply e-mail or by telephone at 770-246-8600, and then delete or destroy all copies of the transmission.

^ permalink raw reply	[flat|nested] 4+ messages in thread

* RE: BMC threat model docs
  2019-07-17 17:21 ` Chittari Pabba
@ 2019-07-17 17:26   ` Chittari Pabba
  2019-07-17 19:35     ` Joseph Reynolds
  0 siblings, 1 reply; 4+ messages in thread
From: Chittari Pabba @ 2019-07-17 17:26 UTC (permalink / raw)
  To: Joseph Reynolds, openbmc

Joseph,

I am new to this group; hence I don't know communication protocol, my apology for that. Next time onwards I will use open BMC email list to send for any of our questions or our feedback or suggestions on Open BMC security.  

Thanks,
Chittari

-----Original Message-----
From: Chittari Pabba 
Sent: Wednesday, July 17, 2019 1:21 PM
To: 'Joseph Reynolds' <jrey@linux.ibm.com>; openbmc <openbmc@lists.ozlabs.org>
Subject: RE: BMC threat model docs

Thank you, Joseph, for quick response !!! I will review the Open BMC threat model document and will provide my feedback. 

-----Original Message-----
From: openbmc <openbmc-bounces+chittarip=ami.com@lists.ozlabs.org> On Behalf Of Joseph Reynolds
Sent: Wednesday, July 17, 2019 12:27 PM
To: openbmc <openbmc@lists.ozlabs.org>
Subject: BMC threat model docs

I got a private email asking
 > [where are the] BMC project threat model documents?

The approved network threat model is here:
https://github.com/openbmc/docs/blob/master/security/network-security-considerations.md

The threat model is very basic and does little more than identify OpenBMC's network services.  The level of detail was initially superficial to get approval for the document.  I hope to add more details and add new sections for BMC network connections including LDAP, remote logging, remote media, ip-kvm, event subscriptions, etc.  Then add a section for Redfish security considerations.

The network threat model is only a subset of the overall BMC threat model.  (For example, the BMC faces threats from its environment and its host system.)  The OpenBMC project has no overall BMC threat model, and mine is in review here:
https://gerrit.openbmc-project.xyz/c/openbmc/docs/+/22404
(You can find other threat model reviews by searching gerrit for "threat" or "security").

I am using my review to collect information about BMC threats, which in turn depends on how the BMC is used, so I am collecting information about BMC use cases too.  Any and all contributions are welcome, and can be added as review comments, email to the community, or directly to me. I am struggling with the threat model scope, and how to organize the document.  Any feedback is welcome.

- Joseph


Please consider the environment before printing this email.

The information contained in this message may be confidential and proprietary to American Megatrends, Inc.  This communication is intended to be read only by the individual or entity to whom it is addressed or by their designee. If the reader of this message is not the intended recipient, you are on notice that any distribution of this message, in any form, is strictly prohibited.  Please promptly notify the sender by reply e-mail or by telephone at 770-246-8600, and then delete or destroy all copies of the transmission.

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: BMC threat model docs
  2019-07-17 17:26   ` Chittari Pabba
@ 2019-07-17 19:35     ` Joseph Reynolds
  0 siblings, 0 replies; 4+ messages in thread
From: Joseph Reynolds @ 2019-07-17 19:35 UTC (permalink / raw)
  To: Chittari Pabba, openbmc


On 7/17/19 12:26 PM, Chittari Pabba wrote:
> Joseph,
>
> I am new to this group; hence I don't know communication protocol, my apology for that. Next time onwards I will use open BMC email list to send for any of our questions or our feedback or suggestions on Open BMC security.

Welcome to the group.  I am looking forward to working with you.  It 
took me a while to get up to speed working the open source way.  The 
guidelines for OpenBMC are here: 
https://github.com/openbmc/docs/blob/master/CONTRIBUTING.md

- Joseph

> Thanks,
> Chittari
>
> -----Original Message-----
> From: Chittari Pabba
> Sent: Wednesday, July 17, 2019 1:21 PM
> To: 'Joseph Reynolds' <jrey@linux.ibm.com>; openbmc <openbmc@lists.ozlabs.org>
> Subject: RE: BMC threat model docs
>
> Thank you, Joseph, for quick response !!! I will review the Open BMC threat model document and will provide my feedback.
>
> -----Original Message-----
> From: openbmc <openbmc-bounces+chittarip=ami.com@lists.ozlabs.org> On Behalf Of Joseph Reynolds
> Sent: Wednesday, July 17, 2019 12:27 PM
> To: openbmc <openbmc@lists.ozlabs.org>
> Subject: BMC threat model docs
>
> I got a private email asking
>   > [where are the] BMC project threat model documents?
>
> The approved network threat model is here:
> https://github.com/openbmc/docs/blob/master/security/network-security-considerations.md
>
> The threat model is very basic and does little more than identify OpenBMC's network services.  The level of detail was initially superficial to get approval for the document.  I hope to add more details and add new sections for BMC network connections including LDAP, remote logging, remote media, ip-kvm, event subscriptions, etc.  Then add a section for Redfish security considerations.
>
> The network threat model is only a subset of the overall BMC threat model.  (For example, the BMC faces threats from its environment and its host system.)  The OpenBMC project has no overall BMC threat model, and mine is in review here:
> https://gerrit.openbmc-project.xyz/c/openbmc/docs/+/22404
> (You can find other threat model reviews by searching gerrit for "threat" or "security").
>
> I am using my review to collect information about BMC threats, which in turn depends on how the BMC is used, so I am collecting information about BMC use cases too.  Any and all contributions are welcome, and can be added as review comments, email to the community, or directly to me. I am struggling with the threat model scope, and how to organize the document.  Any feedback is welcome.
>
> - Joseph
>
>
> Please consider the environment before printing this email.
>
> The information contained in this message may be confidential and proprietary to American Megatrends, Inc.  This communication is intended to be read only by the individual or entity to whom it is addressed or by their designee. If the reader of this message is not the intended recipient, you are on notice that any distribution of this message, in any form, is strictly prohibited.  Please promptly notify the sender by reply e-mail or by telephone at 770-246-8600, and then delete or destroy all copies of the transmission.

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2019-07-17 19:36 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-07-17 16:26 BMC threat model docs Joseph Reynolds
2019-07-17 17:21 ` Chittari Pabba
2019-07-17 17:26   ` Chittari Pabba
2019-07-17 19:35     ` Joseph Reynolds

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.