Re: bmcweb ComponentIntegrity routes for SPDM attestation

Manojkiran Eda <[email protected]>
Newsgroups org.ozlabs.lists.openbmc
Message-ID <PU4P216MB1072C37E5470E90705DE7839FB52A@PU4P216MB1072.KORP216.PROD.OUTLOOK.COM>
Hi Gary,

Welcome to OpenBMC!

The previous bmcweb patches you referenced have been in review for quite a long time now (a couple of years) and haven’t seen any recent activity. Based on that, it doesn’t look like there’s active interest or ongoing work in that area at the moment.

Given that, it would make sense for you to go ahead and contribute your bmcweb implementation either as a fresh patch or revive the old one (it's your call). It sounds like your work nicely complements the spdmd D-Bus backend/PDI and helps complete the overall attestation stack, so it would be a valuable addition upstream.

Looking forward to seeing your patches on Gerrit and collaborating further.


Thanks,

Manoj

From: Gary Beihl <[email protected]>
Date: Monday, 30 March 2026 at 2:49 AM
To: [email protected] <[email protected]>
Cc: Thirupathaiah Annapureddy <[email protected]>, Sagar Dharia <[email protected]>, Giri Mudusuru <[email protected]>
Subject: bmcweb ComponentIntegrity routes for SPDM attestation

Hello everyone,

I have been looking at SPDM attestation end-to-end testing using Renode and have a working bmcweb implementation of the Redfish ComponentIntegrity routes that consumes the D-Bus interfaces already merged in phosphor-dbus-interfaces [1]. I noticed that the previous bmcweb WIP for ComponentIntegrity was auto-abandoned [2] and there does not appear to be an active effort to implement these routes upstream.

The routes are designed to complement the spdmd D-Bus backend work currently in review [3][4], providing the Redfish frontend needed to complete the attestation stack described in the design document [5].

I wanted to check whether anyone is already working on bmcweb routes downstream before submitting to Gerrit. If not, I am happy to contribute and collaborate on getting this piece upstream.

References:
1. https://github.com/openbmc/phosphor-dbus-interfaces/tree/master/yaml/xyz/openbmc_project/Attestation
2. https://gerrit.openbmc.org/c/openbmc/bmcweb/+/61702
3. https://gerrit.openbmc.org/c/openbmc/spdm/+/80272
4. https://gerrit.openbmc.org/c/openbmc/spdm/+/80274
5. https://github.com/openbmc/docs/blob/master/designs/redfish-spdm-attestation.md

Looking forward to your thoughts,

Gary Beihl
Firmware Engineering
Microsoft Corporation
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.