Is priv-noaccess needed?
Joseph Reynolds
jrey at linux.ibm.com
Thu Feb 17 07:32:05 AEDT 2022
User manager and IPMI maintainers (and please forward to additional
interested parties):
We are trying to understand how the NoAccess (priv-noaccess) role is
used in OpenBMC. See the discussion below, the gerrit review, and the
IPMI questions.
What are the use cases? What is this role used for? If we need this
role, let's understand why. Otherwise, can we deprecate this role and
remove it?
Joseph
-------- Forwarded Message --------
Subject: Re: Security Working Group meeting - Wednesday February 16 -
results
Date: Wed, 16 Feb 2022 13:31:25 -0600
From: Joseph Reynolds <jrey at linux.ibm.com>
To: openbmc <openbmc at lists.ozlabs.org>
On 2/16/22 7:21 AM, Joseph Reynolds wrote:
> This is a reminder of the OpenBMC Security Working Group meeting
> scheduled for this Wednesday February 16 at 10:00am PDT.
>
> We'll discuss the following items on the agenda
> <https://docs.google.com/document/d/1b7x9BaxsfcukQDqbvZsU2ehMq4xoJRQvLxxsDUWmAOI>,
> and anything else that comes up:
Attended: Joseph, Daniil, Dhananjay, Dick, James, Jiang
> 1.Do we need to discuss the concept and need for NoAccess users and
> how they would be different from disabled BMC user accounts? See
> discussion in
> https://gerrit.openbmc-project.xyz/c/openbmc/bmcweb/+/49295
> <https://gerrit.openbmc-project.xyz/c/openbmc/bmcweb/+/49295>
DISCUSSION:
Does the project have any NoAccess (priv-noaccess) users?
Is noaccess needed to implement IPMI Callback users?
Note that we prefer to disable ipmi users, not change their role.
Can ipmitool be used to create a callback user? If so, what role does
phosphor-user-manager use for that user?
Is the IPMI callback role deprecated? Can we remove it from OpenBMC?
Is callback needed to implement trusted system interfaces and
sessionless interfaces IPMB?
...snip...
Joseph
>
> Access, agenda and notes are in the wiki:
> https://github.com/openbmc/openbmc/wiki/Security-working-group
> <https://github.com/openbmc/openbmc/wiki/Security-working-group>
>
> - Joseph
More information about the openbmc
mailing list