bmcweb ComponentIntegrity routes for SPDM attestation

Manojkiran Eda manojkiran.eda at gmail.com
Mon Mar 30 14:56:24 AEDT 2026


Hi Gary,

Welcome to OpenBMC!

The previous bmcweb patches you referenced have been in review for quite a long time now (a couple of years) and haven’t seen any recent activity. Based on that, it doesn’t look like there’s active interest or ongoing work in that area at the moment.

Given that, it would make sense for you to go ahead and contribute your bmcweb implementation either as a fresh patch or revive the old one (it's your call). It sounds like your work nicely complements the spdmd D-Bus backend/PDI and helps complete the overall attestation stack, so it would be a valuable addition upstream.

Looking forward to seeing your patches on Gerrit and collaborating further.


Thanks,

Manoj

From: Gary Beihl <garybeihl at microsoft.com>
Date: Monday, 30 March 2026 at 2:49 AM
To: openbmc at lists.ozlabs.org <openbmc at lists.ozlabs.org>
Cc: Thirupathaiah Annapureddy <thiruan at microsoft.com>, Sagar Dharia <Sagar.Dharia at microsoft.com>, Giri Mudusuru <girimudusuru at microsoft.com>
Subject: bmcweb ComponentIntegrity routes for SPDM attestation

Hello everyone,

I have been looking at SPDM attestation end-to-end testing using Renode and have a working bmcweb implementation of the Redfish ComponentIntegrity routes that consumes the D-Bus interfaces already merged in phosphor-dbus-interfaces [1]. I noticed that the previous bmcweb WIP for ComponentIntegrity was auto-abandoned [2] and there does not appear to be an active effort to implement these routes upstream.

The routes are designed to complement the spdmd D-Bus backend work currently in review [3][4], providing the Redfish frontend needed to complete the attestation stack described in the design document [5].

I wanted to check whether anyone is already working on bmcweb routes downstream before submitting to Gerrit. If not, I am happy to contribute and collaborate on getting this piece upstream.

References:
1. https://github.com/openbmc/phosphor-dbus-interfaces/tree/master/yaml/xyz/openbmc_project/Attestation
2. https://gerrit.openbmc.org/c/openbmc/bmcweb/+/61702
3. https://gerrit.openbmc.org/c/openbmc/spdm/+/80272
4. https://gerrit.openbmc.org/c/openbmc/spdm/+/80274
5. https://github.com/openbmc/docs/blob/master/designs/redfish-spdm-attestation.md

Looking forward to your thoughts,

Gary Beihl
Firmware Engineering
Microsoft Corporation









-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ozlabs.org/pipermail/openbmc/attachments/20260330/5761ba5d/attachment.htm>


More information about the openbmc mailing list