All of lore.kernel.org
 help / color / mirror / Atom feed
* BMC threat model docs
@ 2019-07-17 16:26 Joseph Reynolds
  2019-07-17 17:21 ` Chittari Pabba
  0 siblings, 1 reply; 4+ messages in thread
From: Joseph Reynolds @ 2019-07-17 16:26 UTC (permalink / raw)
  To: openbmc

I got a private email asking
 > [where are the] BMC project threat model documents?

The approved network threat model is here:
https://github.com/openbmc/docs/blob/master/security/network-security-considerations.md

The threat model is very basic and does little more than identify 
OpenBMC's network services.  The level of detail was initially 
superficial to get approval for the document.  I hope to add more 
details and add new sections for BMC network connections including LDAP, 
remote logging, remote media, ip-kvm, event subscriptions, etc.  Then 
add a section for Redfish security considerations.

The network threat model is only a subset of the overall BMC threat 
model.  (For example, the BMC faces threats from its environment and its 
host system.)  The OpenBMC project has no overall BMC threat model, and 
mine is in review here:
https://gerrit.openbmc-project.xyz/c/openbmc/docs/+/22404
(You can find other threat model reviews by searching gerrit for 
"threat" or "security").

I am using my review to collect information about BMC threats, which in 
turn depends on how the BMC is used, so I am collecting information 
about BMC use cases too.  Any and all contributions are welcome, and can 
be added as review comments, email to the community, or directly to me.  
I am struggling with the threat model scope, and how to organize the 
document.  Any feedback is welcome.

- Joseph

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2019-07-17 19:36 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-07-17 16:26 BMC threat model docs Joseph Reynolds
2019-07-17 17:21 ` Chittari Pabba
2019-07-17 17:26   ` Chittari Pabba
2019-07-17 19:35     ` Joseph Reynolds

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.