Security Working Group meeting - Wednesday August 3

Joseph Reynolds jrey at linux.ibm.com
Wed Aug 3 22:21:21 AEST 2022


This is a reminder of the OpenBMC Security Working Group meeting 
scheduled for this Wednesday August 3 at 10:00am PDT.

We'll discuss the following items on the agenda 
<https://docs.google.com/document/d/1b7x9BaxsfcukQDqbvZsU2ehMq4xoJRQvLxxsDUWmAOI>, 
and anything else that comes up:

1. Continue discussing CVE response, SELinux, and Measured Boot

2. Recommend http header values per email dated 2022-07-22 with subject: 
BMCWeb support new HTTP headers Referrer-Policy and Feature-Policy 
renamed to Permissions-Policy

3. Consider increasing the TLS DH keysize from 1024 to 2048 bits per 
best practice (reference needed).

4. Consider migrating this meeting access to Discord > Voice channels >  
Security.



Access, agenda and notes are in the wiki:
https://github.com/openbmc/openbmc/wiki/Security-working-group 
<https://github.com/openbmc/openbmc/wiki/Security-working-group>

- Joseph


More information about the openbmc mailing list