bmcweb ComponentIntegrity routes for SPDM attestation

Gary Beihl <[email protected]>
Newsgroups org.ozlabs.lists.openbmc
Message-ID <LV2PR21MB6760A3F8E6E54A1BFC53709FA655A@LV2PR21MB6760.namprd21.prod.outlook.com>
Hello everyone,

I have been looking at SPDM attestation end-to-end testing using Renode and have a working bmcweb implementation of the Redfish ComponentIntegrity routes that consumes the D-Bus interfaces already merged in phosphor-dbus-interfaces [1]. I noticed that the previous bmcweb WIP for ComponentIntegrity was auto-abandoned [2] and there does not appear to be an active effort to implement these routes upstream.

The routes are designed to complement the spdmd D-Bus backend work currently in review [3][4], providing the Redfish frontend needed to complete the attestation stack described in the design document [5].

I wanted to check whether anyone is already working on bmcweb routes downstream before submitting to Gerrit. If not, I am happy to contribute and collaborate on getting this piece upstream.

References:
1. https://github.com/openbmc/phosphor-dbus-interfaces/tree/master/yaml/xyz/openbmc_project/Attestation
2. https://gerrit.openbmc.org/c/openbmc/bmcweb/+/61702
3. https://gerrit.openbmc.org/c/openbmc/spdm/+/80272
4. https://gerrit.openbmc.org/c/openbmc/spdm/+/80274
5. https://github.com/openbmc/docs/blob/master/designs/redfish-spdm-attestation.md

Looking forward to your thoughts,

Gary Beihl
Firmware Engineering
Microsoft Corporation
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.