towards a separate ipmi domain
Download
Skip this Video
Download Presentation
Towards a separate IPMI Domain

Loading in 2 Seconds...

play fullscreen
1 / 3

Towards a separate IPMI Domain - PowerPoint PPT Presentation


  • 153 Views
  • Uploaded on

Towards a separate IPMI Domain. Stefan L üders CERN Computer Security Officer AI 2014/1/23. About IPMI No-Security. IPMI/BMC is the most direct way to access physical hosts BMCs are full fledged computers themselves today IPMI/BMC interfaces insufficiently protected:

loader
I am the owner, or an agent authorized to act on behalf of the owner, of the copyrighted work described.
capcha
Download Presentation

PowerPoint Slideshow about ' Towards a separate IPMI Domain' - audra


An Image/Link below is provided (as is) to download presentation

Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author.While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server.


- - - - - - - - - - - - - - - - - - - - - - - - - - E N D - - - - - - - - - - - - - - - - - - - - - - - - - -
Presentation Transcript
towards a separate ipmi domain

Towards a separate IPMI Domain

Stefan LüdersCERN Computer Security Officer

AI 2014/1/23

about ipmi no security
About IPMI No-Security
  • IPMI/BMC is the most direct way to access physical hosts
  • BMCs are full fledged computers themselves today
  • IPMI/BMC interfaces insufficiently protected:
    • New firmware only irregularly provided
    • Old BMC are difficult to upgrade
    • Prompt patching, in any case, difficult
  • 2013: Fixing severe IPMI/BMC vulnerabilities took 5 months
a cc mgmt domain
A CC MGMT Domain
  • We have already a dedicated network domain for IPMI,PDUS, KVM connections, …
  • …in the barn and at Wigner
  • …to come to CC machine room
  • …transparent to GPN/LCG
  • Proposal:
  • Restrict access on Feb 5th
  • Any objections?
  • What misses to be “trusted”?(e.g. IPMI no_contact)

“Trusted” Bypass List:

IT CC AGILE IPMI

IT CC CONSOLE SERVICE

IT CC LXADM WITH SSH

IT DRUPAL IPMI

IT LINUXSOFT IPMI

HTTPS

ad