CCI-MOC / esi

Elastic Secure Infrastructure project
6 stars 12 forks source link

Add password to BIOS setup to prevent tenant users from making BIOS changes #499

Closed tzumainn closed 1 month ago

tzumainn commented 6 months ago

Giving tenant users BIOS access has a lot of risks; it's better to just protect it from them.

We may want to do the following:

tzumainn commented 1 month ago

I manually set a BIOS password, and verified that deploying/cleaning still worked. I think setting a BIOS password should be fine.

hakasapl commented 1 month ago

Okay, I will plan to implement this post-shutdown before we open up ESI to users

hakasapl commented 1 month ago

BIOS password has been added to all ESI fx2 nodes