Building flashless servers with Open Source Firmware for higher security and better flexibility
- Track: Open Source Firmware, BMC and Bootloader
- Room: UB4.136
- Day: Saturday
- Start: 11:50
- End: 12:10
- Video only: ub4136
- Chat: Join the conversation!
We will cover into that talk a new proposal to design and distribute open source firmware in the datacenter world by relying on secure boot from a single component (the BMC) and extensive attestation from the remaining part of a server. The BMC will starts from a network boot and load all required firmware (from PCIe end points, to microcontroller) from a trusted source before starting target. This approach is currently implemented on HPE Gen11 servers which supports Open Source Firmware. Our goal is to enhance security by decoupling the firmware and hardware supply chain, and allowing easier update process.
Speakers
Jean-Marie Verdun |
Links
- CoreDHCP Discover plugin support for Automatic OpenBMC network distribution on BananaPI machines
- Automatic testing of systems running Open Source Firmware configuration through OpenBMC network boot device
- BananaPI R4 reference firmware with integrated coredhcp startup for automatic firmware distribution management