bmcweb ComponentIntegrity routes for SPDM attestation
Ratan Gupta
ratankgupta31 at gmail.com
Mon Mar 30 15:23:57 AEDT 2026
Hi Gary,
Sorry if I overlooked your patches. If they’re already available, please go
ahead and push them. Otherwise, we’ve been waiting for the SPDM backend
code (MCTP Discovery + SPDM attestation) to be merged first. After that,
NVIDIA can proceed with the bmcweb patches.
I understand that the bmcweb patches are not strictly dependent on the
backend and can be developed in parallel. However, as per the current
guideline, they won’t be merged until the backend is ready.
Thanks
Ratan
On Mon, Mar 30, 2026 at 9:26 AM Manojkiran Eda <manojkiran.eda at gmail.com>
wrote:
> Hi Gary,
>
> Welcome to OpenBMC!
>
> The previous bmcweb patches you referenced have been in review for quite a
> long time now (a couple of years) and haven’t seen any recent activity.
> Based on that, it doesn’t look like there’s active interest or ongoing work
> in that area at the moment.
>
> Given that, it would make sense for you to go ahead and contribute your
> bmcweb implementation either as a fresh patch or revive the old one (it's
> your call). It sounds like your work nicely complements the spdmd D-Bus
> backend/PDI and helps complete the overall attestation stack, so it would
> be a valuable addition upstream.
>
> Looking forward to seeing your patches on Gerrit and collaborating further.
>
>
> Thanks,
>
> Manoj
>
> *From: *Gary Beihl <garybeihl at microsoft.com>
> *Date: *Monday, 30 March 2026 at 2:49 AM
> *To: *openbmc at lists.ozlabs.org <openbmc at lists.ozlabs.org>
> *Cc: *Thirupathaiah Annapureddy <thiruan at microsoft.com>, Sagar Dharia <
> Sagar.Dharia at microsoft.com>, Giri Mudusuru <girimudusuru at microsoft.com>
> *Subject: *bmcweb ComponentIntegrity routes for SPDM attestation
>
> Hello everyone,
>
>
>
> I have been looking at SPDM attestation end-to-end testing using Renode
> and have a working bmcweb implementation of the Redfish ComponentIntegrity
> routes that consumes the D-Bus interfaces already merged in
> phosphor-dbus-interfaces [1]. I noticed that the previous bmcweb WIP for
> ComponentIntegrity was auto-abandoned [2] and there does not appear to be
> an active effort to implement these routes upstream.
>
>
>
> The routes are designed to complement the spdmd D-Bus backend work
> currently in review [3][4], providing the Redfish frontend needed to
> complete the attestation stack described in the design document [5].
>
>
>
> I wanted to check whether anyone is already working on bmcweb routes
> downstream before submitting to Gerrit. If not, I am happy to contribute
> and collaborate on getting this piece upstream.
>
>
>
> References:
>
> 1. *https://github.com/openbmc/phosphor-dbus-interfaces/tree/master/yaml/xyz/openbmc_project/Attestation
> <https://github.com/openbmc/phosphor-dbus-interfaces/tree/master/yaml/xyz/openbmc_project/Attestation>*
>
> 2. *https://gerrit.openbmc.org/c/openbmc/bmcweb/+/61702
> <https://gerrit.openbmc.org/c/openbmc/bmcweb/+/61702>*
>
> 3. *https://gerrit.openbmc.org/c/openbmc/spdm/+/80272
> <https://gerrit.openbmc.org/c/openbmc/spdm/+/80272>*
>
> 4. *https://gerrit.openbmc.org/c/openbmc/spdm/+/80274
> <https://gerrit.openbmc.org/c/openbmc/spdm/+/80274>*
>
> 5. *https://github.com/openbmc/docs/blob/master/designs/redfish-spdm-attestation.md
> <https://github.com/openbmc/docs/blob/master/designs/redfish-spdm-attestation.md>*
>
>
>
> Looking forward to your thoughts,
>
>
>
> Gary Beihl
>
> Firmware Engineering
>
> Microsoft Corporation
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ozlabs.org/pipermail/openbmc/attachments/20260330/9656e373/attachment.htm>
More information about the openbmc
mailing list