[yocto-security] Design for initial expired default password

Joseph Reynolds jrey at linux.ibm.com
Wed Jul 24 16:06:42 PDT 2019


I pushed an OpenBMC design to [Gerrit review][] for the OpenBMC project 
for a new distro or image feature (disabled by default) which causes the 
initial password to be disabled by default, so the password has to be 
changed before using the BMC.

This design is intended to make it easier to comply with the new CA law 
[SB-327][] which becomes effective on 2020-01-01 (in 5 months).

- Joseph

[Gerrit review]: https://gerrit.openbmc-project.xyz/c/openbmc/docs/+/23849
[SB-327]: 
https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=201720180SB327


More information about the yocto-security mailing list