Security Working Group meeting - Wednesday February 16 - results

Joseph Reynolds jrey at linux.ibm.com
Thu Feb 17 06:31:25 AEDT 2022


On 2/16/22 7:21 AM, Joseph Reynolds wrote:
> This is a reminder of the OpenBMC Security Working Group meeting 
> scheduled for this Wednesday February 16 at 10:00am PDT.
>
> We'll discuss the following items on the agenda 
> <https://docs.google.com/document/d/1b7x9BaxsfcukQDqbvZsU2ehMq4xoJRQvLxxsDUWmAOI>, 
> and anything else that comes up:

Attended: Joseph, Daniil, Dhananjay, Dick, James, Jiang


> 1.Do we need to discuss the concept and need for NoAccess users and 
> how they would be different from disabled BMC user accounts?  See 
> discussion in 
> https://gerrit.openbmc-project.xyz/c/openbmc/bmcweb/+/49295 
> <https://gerrit.openbmc-project.xyz/c/openbmc/bmcweb/+/49295>

DISCUSSION:

Does the project have any NoAccess (priv-noaccess) users?

Is noaccess needed to implement IPMI Callback users?

Note that we prefer to disable ipmi users, not change their role.

Can ipmitool be used to create a callback user?  If so, what role does 
phosphor-user-manager use for that user?

Is the IPMI callback role deprecated?  Can we remove it from OpenBMC?

Is callback needed to implement trusted system interfaces and 
sessionless interfaces IPMB?



BONUS TOPICS:

2 Update on OpenBMC becoming a CNA.

James got CNA admin credentials, and is able to create test CVEs.

James is working on documentation for OpenBMC security responders who 
work to create CVEs .  James is working to document the process for the 
OpenBMC CNA to work with Mitre’s CVEs.  (For example, how OpenBMC will 
reserve CVEs and ensure they are published in a timely manner.)

Next steps: (1) Document process steps in openbmc/docs.  (2) Reserve 
CVEs for existing privately reported vulnerabilities.


3 Question: How does BMC respond to too many failed login attempts?

DISCUSSION: It uses (the deprecated module) pam_tally2 (and should move 
to pam_faillock).

See 
https://gerrit.openbmc-project.xyz/c/openbmc/phosphor-user-manager/+/39853 
<https://gerrit.openbmc-project.xyz/c/openbmc/phosphor-user-manager/+/39853>  
questions:

Background: 
https://github.com/openbmc/docs/blob/master/architecture/user-management.md 
<https://github.com/openbmc/docs/blob/master/architecture/user-management.md>

Note: The default is to not lock out users due to excessive password 
attempts.


Joseph

>
> Access, agenda and notes are in the wiki:
> https://github.com/openbmc/openbmc/wiki/Security-working-group 
> <https://github.com/openbmc/openbmc/wiki/Security-working-group>
>
> - Joseph



More information about the openbmc mailing list