All of lore.kernel.org
 help / color / mirror / Atom feed
From: Neeraj Ladkani <neladk@microsoft.com>
To: Zhenfei Tai <ztai@google.com>,
	OpenBMC Maillist <openbmc@lists.ozlabs.org>
Subject: RE: [EXTERNAL] bmcweb TLS certificates installation and management
Date: Fri, 24 Jul 2020 01:11:35 +0000	[thread overview]
Message-ID: <MN2PR21MB1519C9958D6126B9ECC815C8C8770@MN2PR21MB1519.namprd21.prod.outlook.com> (raw)
In-Reply-To: <CAMXw96PkBaj2+AEPJdRURmdCr9kyQ1Q8F8U9rUjeN+pck+fS2w@mail.gmail.com>

[-- Attachment #1: Type: text/plain, Size: 1248 bytes --]

+1 as I had the same concerns. We can not use untrusted connection to provision certs.   It would be good to create a separate workflow to provision these certs.

Regards
N

From: openbmc <openbmc-bounces+neladk=microsoft.com@lists.ozlabs.org> On Behalf Of Zhenfei Tai
Sent: Thursday, July 23, 2020 5:46 PM
To: OpenBMC Maillist <openbmc@lists.ozlabs.org>
Subject: [EXTERNAL] bmcweb TLS certificates installation and management

Hi,

I'm recently looking into certificates installation and management for bmcweb and hope to understand the best practice in this regard.

According to the TLS doc<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fopenbmc%2Fdocs%2Fblob%2Fmaster%2Fsecurity%2FTLS-configuration.md&data=02%7C01%7Cneladk%40microsoft.com%7C846fee89707c417d83a208d82f6b216c%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637311484449788358&sdata=RIIF0B3muux2NEFx%2B401u7NQCFZ%2Fi4UdENIEwsVtGDI%3D&reserved=0>, bmcweb has APIs that allows root CA installation and https server certificate replacement.

My questions are:

  *   Should there be a separate workflow to manage certifications of BMCs?
  *   Should the bmcweb APIs be used for the installation and management?

Thanks,
Zhenfei


[-- Attachment #2: Type: text/html, Size: 6134 bytes --]

      reply	other threads:[~2020-07-24  1:18 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-07-24  0:46 bmcweb TLS certificates installation and management Zhenfei Tai
2020-07-24  1:11 ` Neeraj Ladkani [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=MN2PR21MB1519C9958D6126B9ECC815C8C8770@MN2PR21MB1519.namprd21.prod.outlook.com \
    --to=neladk@microsoft.com \
    --cc=openbmc@lists.ozlabs.org \
    --cc=ztai@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.