All of lore.kernel.org
 help / color / mirror / Atom feed
* Security Working Group - Wednesday July 22
@ 2020-07-20 13:57 Joseph Reynolds
  2020-07-23 14:11 ` Security Working Group - Wednesday July 22 - results Joseph Reynolds
  0 siblings, 1 reply; 8+ messages in thread
From: Joseph Reynolds @ 2020-07-20 13:57 UTC (permalink / raw)
  To: openbmc

This is a reminder of the OpenBMC Security Working Group meeting 
scheduled for this Wednesday July 22 at 10:00am PDT.

We'll discuss current development items, and anything else that comes up.

1. The OpenBMC interface overview is merged into the docs repository 
here: 
https://github.com/openbmc/docs/blob/master/architecture/interface-overview.md.  
Is there interest in building a threat model on top of this?

2. A gerrit review merged. It is a rework of BMCWeb authorization flow: 
https://gerrit.openbmc-project.xyz/c/openbmc/bmcweb/+/30994

and tweaks some security settings.  Is there interest in reviewing the 
code or changed settings?  (Please note: This changed was introduced 
Months ago and it went unnoticed in the security workgroup.  Better late 
than never.)

3.Gerrit review: Firmware minimum ship level (can help with host 
firmware anti-rollback protection) 
https://gerrit.openbmc-project.xyz/c/openbmc/phosphor-bmc-code-mgmt/+/29914
Access, agenda, and notes are in the wiki:
https://github.com/openbmc/openbmc/wiki/Security-working-group

- Joseph

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2020-08-04  9:36 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2020-07-20 13:57 Security Working Group - Wednesday July 22 Joseph Reynolds
2020-07-23 14:11 ` Security Working Group - Wednesday July 22 - results Joseph Reynolds
2020-07-23 15:13   ` Ed Tanous
2020-07-23 16:04     ` Joseph Reynolds
2020-07-23 19:05     ` Michael Richardson
2020-07-23 20:09       ` Ed Tanous
2020-07-23 21:34         ` Michael Richardson
2020-08-04  9:36     ` Jayanth Othayoth

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.