IPMI 通道安全套件相关表项详情
更新时间:2025/06/26
在Gitcode上查看源码

修订记录

openUBMC版本号修订日期修订人修订内容
25.062025/06/26pengqiang-gs初稿,新增

Cipher Suite Record Format

sizeTag bits [7:6]Tag bits[5:0]
2 or 5--This field starts off with either a C0h or C1h "Start of Record" byte, depending on whether the Cipher Suite is a standard Cipher Suite ID or an OEM Cipher Suite, respectively

Byte 1:
[7:0] = 1100_0000b. Start of Record, Standard Cipher Suite Data following C0h (1100_0000b) start of record byte:
 Byte 2 - Cipher Suite ID
 This value is used a numeric way of identifying the Cipher Suite on the platform. It’s used in commands and configuration parameters that enable and disable Cipher Suites. See Cipher Suite IDs.

[5:0] = 1100_0001b. Start or Record, OEM Cipher Suite
 Data following C1h (1100_0001) start of record byte:
 Byte 2 - OEM Cipher Suite ID. See Cipher Suite IDs.

 Byte 3:5 - OEM IANA
 Least significant byte first. 3-byte IANA for the OEM or body that defined the Cipher Suite.
100b[5:0] = Authentication Algorithm Number.
A Cipher Suite is only allowed to utilize one Authentication algorithm. See Authentication Algorithm Numbers
var01b[5:0] = Integrity Algorithm Number(s). See Integrity Algorithm Numbers
var10b[5:0] = Confidentiality Algorithm Number(s). See Confidentiality Algorithm Numbers

Cipher Suite IDs

IDcharacteristicsCipher SuiteAuthentication AlgorithmIntegrity Algorithm(s)Confidentiality Algorithm(s)
0"no password"00h, 00h, 00hRAKP-noneNoneNone
1S01h, 00h, 00hRAKP-HMAC-SHA1NoneNone
2S, A01h, 01h, 00hRAKP-HMAC-SHA1HMAC-SHA1-96None
3S, A, E01h, 01h, 01hRAKP-HMAC-SHA1HMAC-SHA1-96AES-CBC-128
4S, A, E01h, 01h, 02hRAKP-HMAC-SHA1HMAC-SHA1-96xRC4-128
5S, A, E01h, 01h, 03hRAKP-HMAC-SHA1HMAC-SHA1-96xRC4-40
6S02h, 00h, 00hRAKP-HMAC-MD5NoneNone
7S, A02h, 02h, 00hRAKP-HMAC-MD5HMAC-MD5-128None
8S, A, E02h, 02h, 01hRAKP-HMAC-MD5HMAC-MD5-128AES-CBC-128
9S, A, E02h, 02h, 02hRAKP-HMAC-MD5HMAC-MD5-128xRC4-128
10S, A, E02h, 02h, 03hRAKP-HMAC-MD5HMAC-MD5-128xRC4-40
11S, A02h, 03h, 00hRAKP-HMAC-MD5MD5-128None
12S, A, E02h, 03h, 01hRAKP-HMAC-MD5MD5-128AES-CBC-128
13S, A, E02h, 03h, 02hRAKP-HMAC-MD5MD5-128xRC4-128
14S, A, E02h, 03h, 03hRAKP-HMAC-MD5MD5-128xRC4-40
15S03h, 00h, 00hRAKP-HMAC-SHA256NoneNone
16S, A03h, 04h, 00hRAKP-HMAC-SHA256HMAC-SHA256-128None
17S, A, E03h, 04h, 01hRAKP-HMAC-SHA256HMAC-SHA256-128AES-CBC-128
18S, A, E03h, 04h, 02hRAKP-HMAC-SHA256HMAC-SHA256-128xRC4-128
19S, A, E03h, 04h, 03hRAKP-HMAC-SHA256HMAC-SHA256-128xRC4-40
80h - BFhOEM specifiedOEM specifiedOEM specifiedOEM specifiedOEM specified
C0h - FFhreserved--------

Authentication Algorithm Numbers

numbertypeMandatory /Optional
00hRAKP-noneM
01hRAKP-HMAC-SHA1M
02hRAKP-HMAC-MD5O
03hRAKP-HMAC-SHA256O
C0h - FFhOEMO
all otherreserved--

Integrity Algorithm Numbers

numbertypeMandatory /Optional
00hnoneM
01hHMAC-SHA1-96M
02hHMAC-MD5-128O
03hMD5-128O
04hHMAC-SHA256-128O
C0h - FFhOEMO
all otherreserved--

Confidentiality Algorithm Numbers

numbertypeMandatory /Optional
00hnoneM
01hAES-CBC-128M
02hxRC4-128O
03hxRC4-40O
30h - 3FhOEMO
all otherreserved--