Skip to content

HLD for Redfish Certificate Provisioning Integration - #2461

Open
shreyansh-nexthop wants to merge 4 commits into
sonic-net:masterfrom
nexthop-ai:shreyansh.redfish_acms_integration
Open

shreyansh-nexthop wants to merge 4 commits into
sonic-net:masterfrom
nexthop-ai:shreyansh.redfish_acms_integration

Conversation

@shreyansh-nexthop

Copy link
Copy Markdown

No description provided.

@mssonicbld

Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines

Copy link
Copy Markdown
No pipelines are associated with this pull request.

@shreyansh-nexthop
shreyansh-nexthop marked this pull request as ready for review July 13, 2026 11:42
@mssonicbld

Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines

Copy link
Copy Markdown
No pipelines are associated with this pull request.

@shreyansh-nexthop
shreyansh-nexthop force-pushed the shreyansh.redfish_acms_integration branch from ba9b34e to 42192c3 Compare July 14, 2026 07:08
@mssonicbld

Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines

Copy link
Copy Markdown
No pipelines are associated with this pull request.

@shreyansh-nexthop shreyansh-nexthop changed the title HLD for Redfish ACMS Integration HLD for Redfish Certificate Provisioning Integration Jul 14, 2026
Comment thread doc/sonic-redfish/Redfish_Certificate_Provisioning_HLD.md Outdated
@mssonicbld

Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines

Copy link
Copy Markdown
No pipelines are associated with this pull request.

High-level design for staging externally provisioned certificates into the
redfish (bmcweb) container and enforcing mTLS, without modifying bmcweb.

Signed-off-by: shreyansh-nexthop <shreyansh@nexthop.ai>
Address review comment: keep the secure-mode policy out of DEVICE_METADATA
and store it in REDFISH|AUTHENTICATION_MODE:secure_mode instead.

Signed-off-by: shreyansh-nexthop <shreyansh@nexthop.ai>
@shreyansh-nexthop
shreyansh-nexthop force-pushed the shreyansh.redfish_acms_integration branch from 84d18b2 to 8b2b38c Compare July 16, 2026 19:33
@mssonicbld

Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines

Copy link
Copy Markdown
No pipelines are associated with this pull request.

nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Aug 23, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 8b2b38c [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Aug 24, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 8b2b38c [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Aug 25, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 8b2b38c [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Aug 25, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 8b2b38c [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Aug 26, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 8b2b38c [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Aug 27, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 8b2b38c [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Aug 27, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 8b2b38c [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Aug 28, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 8b2b38c [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Aug 29, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 8b2b38c [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Sep 5, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 8b2b38c [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Sep 5, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 8b2b38c [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Sep 7, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 8b2b38c [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Sep 7, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 8b2b38c [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Sep 9, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 8b2b38c [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Sep 9, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 8b2b38c [case: upstream:open]
Comment thread doc/sonic-redfish/Redfish_Certificate_Provisioning_HLD.md Outdated
Comment thread doc/sonic-redfish/Redfish_Certificate_Provisioning_HLD.md Outdated
Comment thread doc/sonic-redfish/Redfish_Certificate_Provisioning_HLD.md Outdated
Comment thread doc/sonic-redfish/Redfish_Certificate_Provisioning_HLD.md
Comment thread doc/sonic-redfish/Redfish_Certificate_Provisioning_HLD.md Outdated
@judyjoseph

Copy link
Copy Markdown
Contributor

@qiluo-msft @yxieca for review

Signed-off-by: Shreyansh Jain <shreyansh@nexthop.ai>
@mssonicbld

Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines

Copy link
Copy Markdown
No pipelines are associated with this pull request.

nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Sep 11, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 62cb184 [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Sep 11, 2026
rebuild-source: sonic-net/pull/2461 @ nexthop-ai/SONiC 62cb184 [case: upstream:open]
Comment thread doc/sonic-redfish/Redfish_Certificate_Provisioning_HLD.md
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Sep 13, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 62cb184 [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Sep 13, 2026
rebuild-source: sonic-net/pull/2461 @ nexthop-ai/SONiC 62cb184 [case: upstream:open]
@judyjoseph

judyjoseph commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

@shreyansh-nexthop you could refer to this config https://github.com/sonic-net/sonic-mgmt/tree/master/ansible/roles/testbed/nut/templates/config_patch/common .. we could have redfish config similar to how it is done for other services like gnmi/restapi/telemetry

Sample config as below, so with this we can use the attributes server_crt/server_key/ca_crt etc and the other configs to set the port as configurable, client_auth = cert, where CN validation is enforced OR none.

  // Similar to restapi/telemetry certs
 "REDFISH": {
    "config": {
      "client_auth": "cert|none",
      "port": "443"
    },
    "certs": {
      "server_crt": "/etc/sonic/redfish/redfishserver.cer",
      "server_key": "/etc/sonic/redfish/redfishserver.key",
      "ca_crt": "/etc/sonic/credentials/ROOT_CERTIFICATE.pem"
    }
 }

nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Sep 15, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 62cb184 [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Sep 15, 2026
rebuild-source: sonic-net/pull/2461 @ nexthop-ai/SONiC 62cb184 [case: upstream:open]
@shreyansh-nexthop

Copy link
Copy Markdown
Author

@shreyansh-nexthop you could refer to this config https://github.com/sonic-net/sonic-mgmt/tree/master/ansible/roles/testbed/nut/templates/config_patch/common .. we could have redfish config similar to how it is done for other services like gnmi/restapi/telemetry

Sample config as below, so with this we can use the attributes server_crt/server_key/ca_crt etc and the other configs to set the port as configurable, client_auth = cert, where CN validation is enforced OR none.

  // Similar to restapi/telemetry certs
 "REDFISH": {
    "config": {
      "client_auth": "cert|none",
      "port": "443"
    },
    "certs": {
      "server_crt": "/etc/sonic/redfish/redfishserver.cer",
      "server_key": "/etc/sonic/redfish/redfishserver.key",
      "ca_crt": "/etc/sonic/credentials/ROOT_CERTIFICATE.pem"
    }
 }

Sure, this can be done, will update the HLD

nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Sep 17, 2026
rebuild-source: sonic-net#2461 @ nexthop-ai/SONiC 62cb184 [case: upstream:open]
nh-grecs Bot pushed a commit to nexthop-ai/SONiC that referenced this pull request Sep 17, 2026
rebuild-source: sonic-net/pull/2461 @ nexthop-ai/SONiC 62cb184 [case: upstream:open]
Signed-off-by: Shreyansh Jain <shreyansh@nexthop.ai>
@mssonicbld

Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines

Copy link
Copy Markdown
No pipelines are associated with this pull request.

- **Fail closed after first provisioning (secure mode).** A dedicated marker file, `/var/lib/bmcweb/provisioned`, is written on the first successful staging. Once it exists, every bmcweb start is gated: with no valid staged certificate, bmcweb does not start at all, instead of falling back to a self-signed cert. No CONFIG_DB attribute is involved, and the marker survives reboot and container recreation. Recovery is automatic when valid certs reappear.
- **Deletion behavior.** Deleting the source certificates does not tear down the running service (bmcweb keeps serving the last staged certificate), and it is not a way to revoke access: the running bmcweb keeps serving the already-loaded certificate and keeps trusting the same CA. To actually revoke, rotate the CA (clients whose certs were issued by the old CA then fail the mTLS handshake).
- **Observability.** The watcher publishes sync status to STATE_DB (`REDFISH_CERT_STATUS|global`: `in_sync`, `last_error`, fingerprints, served serial, plus `mtls_enforced` for the enforcement state) every cycle, and every decision is logged to syslog. A rotation that fails to land is visible, not silent; monitoring must watch `in_sync`.
- **Boot resilience preserved.** Before certificates are ever provisioned, the BMC still boots with bmcweb's self-signed certificate and the API is reachable.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So assuming the following is true

By default when BMC boots up for first time, the certificate bmcweb serves is not CA-signed. 
It is a self-signed certificate that bmcweb generates itself at first startup -- There is no CA, no truststore, and mTLS is off. In that default state /redfish/v1 works. 
Because no client certificate is required, you can reach it with curl -k https:///redfish/v1                                                                                                                                                                                                                                                                        

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants