Mulțumim pentru trimiterea solicitării! Un membru al echipei noastre vă va contacta în curând.
Mulțumim pentru trimiterea rezervării! Un membru al echipei noastre vă va contacta în curând.
Schița de curs
- BMC Threat Model
- Attack surface of server BMCs
- Common vulnerabilities in legacy BMC firmware
- OpenBMC security architecture overview
- Compliance requirements (NIST, PCI-DSS)
Secure Boot
- U-Boot verified boot chain
- Image signing with RSA and ECDSA
- Key hierarchy and revocation
- Measurement and attestation basics
Firmware Update Security
- Image signature verification flow
- Rollback protection and version policies
- Dual-bank update strategies
- Code update via Redfish and IPMI
Certificate Management
- Phosphor-certificate-manager architecture
- Installing and replacing HTTPS certificates
- Certificate Authority (CA) trust stores
- LDAPS and client certificate authentication
Authentication and Authorization
- Local user management and password policies
- LDAP and Active Directory integration
- PAM stack configuration
- Redfish RBAC and privilege mapping
Network Security
- Firewall rules and nftables
- TLS 1.3 configuration in bmcweb
- SSH hardening and key-based auth
- Network segmentation for BMC interfaces
Audit and Response
- Remote syslog configuration
- Security event logging
- SEL and audit trail management
- Incident response for compromised BMCs
Security Testing
- Static analysis with CodeQL and Bandit
- Fuzzing D-Bus interfaces
- Penetration testing REST and Redfish APIs
- CVE tracking and patch management
Cerințe
- Understanding of PKI and TLS fundamentals
- Basic Linux security concepts
- Familiarity with embedded firmware update mechanisms
Audience
- Security engineers
- Firmware developers
- System administrators managing BMC infrastructure
14 Ore
Mărturii (4)
învățând despre Basel
Daksha Vallabh - Standard Bank of SA Ltd
Curs - Basel III – Certified Basel Professional
Tradus de catre o masina
Viteza de răspuns și comunicare
Bader Bin rubayan - Lean Business Services
Curs - ISO/IEC 27001 Lead Implementer
Tradus de catre o masina
Optimizarea riscului este mai clară decât celelalte subiecte
Munirah Alsahli - GOSI
Curs - CGEIT – Certified in the Governance of Enterprise IT
Tradus de catre o masina
Înțeleptul instruiector se adaptează nevoilor noastre
Eduardo Fontecha - ORMAZABAL PROTECTION & AUTOMATION S.L.U.
Curs - The Yocto Project - An Overview - hands-on
Tradus de catre o masina