From: Vernon Mauery <vernon.mauery@linux.intel.com>
To: Brad Bishop <bradleyb@fuzziesquirrel.com>
Cc: OpenBMC Development <openbmc@lists.ozlabs.org>,
Emily Shaffer <emilyshaffer@google.com>,
MARRI DEVENDER RAO <devenrao@in.ibm.com>,
Tom Joseph <tomjoseph@in.ibm.com>
Subject: Re: Supporting insecure protocols in RMCP+
Date: Tue, 24 Apr 2018 08:34:56 -0700 [thread overview]
Message-ID: <20180424153456.GC130821@mauery> (raw)
In-Reply-To: <EA662B0F-9F97-49FA-9D9B-8545CBFD3E3B@fuzziesquirrel.com>
On 24-Apr-2018 09:17 AM, Brad Bishop wrote:
>
>> On Apr 23, 2018, at 3:30 PM, Vernon Mauery <vernon.mauery@linux.intel.com> wrote:
>>
>> On 23-Apr-2018 11:47 AM, Vernon Mauery wrote:
>>>> Patch Set 4:
>>>>
>>>>> Given that RMCP+ is already insecure, unless it is a requirement to support 1, 2, 15, and 16, you may just want to support 3 and 17.
>>>>
>>>> 1,2,3 are marked as mandatory in the specification. It should be a community decision to revoke support for 1,2. If the community is ok, it will need additional code changes.
>>>
>>> tl;dr IPMI is old; let's drop the most insecure parts
>>
>> While I am at it, can we agree
>
>I agree with all your points. But why is consensus necessary?
Consensus is best when we are intentionally going against the IPMI
standard. With IPMI, there may be several of these things where we might
want to break the standard in order to provide better security. But I
don't think we can do that unilaterally.
--Vernon
>> that anonymous and nameless accounts are dangerous. I know that the IPMI spec says that having an account with no name is mandatory, I think this is another case of security trumps the standard.
>>
>> I would at least like a way to disable this at build time so we CANNOT have this exploited.
>
>That sounds like a reasonable way to make the code do what you need.
>
>>
>> --Vernon
next prev parent reply other threads:[~2018-04-24 15:35 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-04-23 18:47 Supporting insecure protocols in RMCP+ Vernon Mauery
2018-04-23 19:30 ` Vernon Mauery
2018-04-24 13:17 ` Brad Bishop
2018-04-24 15:34 ` Vernon Mauery [this message]
2018-04-24 17:52 ` Brad Bishop
2018-04-24 13:39 ` Brad Bishop
2018-04-24 15:37 ` Vernon Mauery
2018-04-24 17:41 ` Brad Bishop
2018-04-24 18:26 ` Vernon Mauery
2018-04-24 20:25 ` Brad Bishop
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20180424153456.GC130821@mauery \
--to=vernon.mauery@linux.intel.com \
--cc=bradleyb@fuzziesquirrel.com \
--cc=devenrao@in.ibm.com \
--cc=emilyshaffer@google.com \
--cc=openbmc@lists.ozlabs.org \
--cc=tomjoseph@in.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.