<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IPMI touch - ipmitool for your iPhone &#187; security</title>
	<atom:link href="http://www.yellowkompressor.com/ipmi-touch/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.yellowkompressor.com/ipmi-touch</link>
	<description>unKompressed Perspective</description>
	<lastBuildDate>Tue, 24 Jan 2012 03:38:43 +0000</lastBuildDate>
	<language>en-US</language>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=4.0</generator>
	<item>
		<title>Security sensor groups</title>
		<link>http://www.yellowkompressor.com/ipmi-touch/2010/04/security-sdr-groups/</link>
		<comments>http://www.yellowkompressor.com/ipmi-touch/2010/04/security-sdr-groups/#comments</comments>
		<pubDate>Mon, 19 Apr 2010 00:53:54 +0000</pubDate>
		<dc:creator><![CDATA[yellowKompressor]]></dc:creator>
				<category><![CDATA[Development updates]]></category>
		<category><![CDATA[screenshots]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[V1.2]]></category>

		<guid isPermaLink="false">http://www.yellowkompressor.com/ipmi-touch/?p=292</guid>
		<description><![CDATA[Two new sensor groups will be making appearance in the next revision of the IPMI apps &#8211; &#8216;Platform Security&#8216; and &#8216;Physical Security&#8216;. Deciding which groups to include is a balancing act. Too many and the app slows down too much (i.e. forget running on Edge). Too few and the usefulness is hard to justify. An option to. . . (<a href="http://www.yellowkompressor.com/ipmi-touch/2010/04/security-sdr-groups/">Read more</a>)]]></description>
				<content:encoded><![CDATA[<p>Two new sensor groups will be making appearance in the next revision of the IPMI apps &#8211; &#8216;<em>Platform Security</em>&#8216; and &#8216;<em>Physical Security</em>&#8216;.</p>
<p>Deciding which groups to include is a balancing act. Too many and the app slows down too much (i.e. forget running on Edge). Too few and the usefulness is hard to justify. An option to control the list of sensor groups for every server is probably ideal but will require major rethinking of how the application manages and stores its state. Definitely not something we want to deal with for 1.X versions.</p>
<p>Security groups seem to be a needed addition though. On most hardware the groups only include a handful of sensors so the extra overhead is really low. More importantly, it will provide essential clarification for security-related alarms. Chassis status cell already shows an aggregated  security indicator (lock icon) that lights up <strong><span style="color: #ff0000;">red</span></strong> if security is compromised. However by design it does not provide any explanation of what happened. </p>
<p>With new groups the apps will potentially recognize (depending on server&#8217;s BMC) and report the following list of events:</p>
<table width="100%">
<tbody>
<tr>
<td width="45%" valign="top">
<h3>Physical Security</h3>
<ul>
<li style="text-align: left;">Chassis intrusion</li>
<li style="text-align: left;">Drive Bay intrusion</li>
<li style="text-align: left;">I/O Card area intrusion</li>
<li style="text-align: left;">Processor area intrusion</li>
<li style="text-align: left;">System unplugged from LAN</li>
<li style="text-align: left;">Unauthorized dock</li>
<li style="text-align: left;">FAN area intrusion</li>
</ul>
</td>
<td width="55%" valign="top">
<h3>Platform Security</h3>
<ul>
<li style="text-align: left;">Front Panel Lockout violation attempted</li>
<li style="text-align: left;">Pre-boot user password violation</li>
<li style="text-align: left;">Pre-boot setup password violation</li>
<li style="text-align: left;">Pre-boot network boot password violation</li>
<li style="text-align: left;">Other pre-boot password violation</li>
<li style="text-align: left;">Out-of-band access password violation</li>
</ul>
</td>
</tr>
</tbody>
</table>
<p style="text-align: center;">
<p style="text-align: left;">Screenshots below show output from a server running with cover off.</p>
<p style="text-align: center;"><img class="alignnone size-medium wp-image-291" style="margin: 20px;" title="IPMI Security SDR group - Summary view" src="http://www.yellowkompressor.com/ipmi-touch/wp-content/uploads/IPMI-touch-security-SDR-summary-208x300.png" alt="" width="208" height="300" /><img class="alignnone size-medium wp-image-289" style="margin: 20px;" title="IPMI Security SDR group - Detailed sensor view" src="http://www.yellowkompressor.com/ipmi-touch/wp-content/uploads/IPMI-touch-security-SDR-details-208x300.png" alt="" width="208" height="300" /></p>
<table>
<tbody></tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.yellowkompressor.com/ipmi-touch/2010/04/security-sdr-groups/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
