{
"Resources": [
{
"Uri": "/cli/v1/securityenhance",
"Interfaces": [
{
"Type": "Patch",
"Description": "Operate security enhance"
}
]
},
{
"Uri": "/cli/v1/securityenhance/inactivetimelimit",
"Interfaces": [
{
"Type": "Patch",
"Description": "Set inactive user timelimit(day)",
"Usage": "ipmcset -t securityenhance -d inactivetimelimit -v <time>",
"Example": [
"ipmcset -t securityenhance -d inactivetimelimit -v 0",
"ipmcset -t securityenhance -d inactivetimelimit -v 30"
],
"Confirm": {
"Condition": "${Statements/ConfirmExp()}",
"Description": "WARNING: This operation could lead to {{SoftwareName}} users be disabled when users' inactive time is overdue.\nDo you want to continue?[Y/N]:"
},
"ReqBody": {
"Type": "object",
"Required": true,
"Properties": {
"time": {
"Required": true,
"Type": "integer",
"Validator": [
{
"Type": "Script",
"Formula": "if not (Input == 0 or (Input >= 30 and Input <= 365)) then error(base_messages.PropertyValueNotInList(Input, PropertyName)) end"
}
],
"Description": "\n 0 Never disable inactive user\n30~365 Days of inactivity before disable user"
}
}
},
"Statements": {
"ConfirmExp": {
"Input": "${ReqBody/time}",
"Steps": [
{
"Type": "Switch",
"Formula": [
{
"Case": 0,
"To": false
},
{
"To": true
}
]
}
]
}
},
"ProcessingFlow": [
{
"Type": "Property",
"Path": "/bmc/kepler/AccountService",
"Interface": "bmc.kepler.AccountService",
"Source": {
"InactiveDaysThreshold": "${ReqBody/time}"
}
}
],
"Echoes": [
"ipmcset/securityenhance_inactivetimelimit",
""
]
}
]
},
{
"Uri": "/cli/v1/securityenhance/masterkeyupdateinterval",
"Interfaces": [
{
"Type": "Patch",
"Description": "Set master key automatic update interval(day)",
"Usage": "ipmcset -t securityenhance -d masterkeyupdateinterval -v <interval>",
"Confirm": {
"Condition": "${Statements/ConfirmExp()}",
"Description": "WARNING: This operation enables the BMC to automatically update the master key when the update interval is reached.\nDo you want to continue?[Y/N]:"
},
"ReqBody": {
"Type": "object",
"Required": true,
"Properties": {
"interval": {
"Required": true,
"Type": "integer",
"Validator": [
{
"Type": "Range",
"Formula": [
0,
365
]
}
],
"Description": "\n 0 Never enabled to update master key automatically\n1~365 Days of master key automatic update interval"
}
}
},
"Statements": {
"ConfirmExp": {
"Input": "${ReqBody/interval}",
"Steps": [
{
"Type": "Switch",
"Formula": [
{
"Case": 0,
"To": false
},
{
"To": true
}
]
}
]
}
},
"ProcessingFlow": [
{
"Type": "Property",
"Path": "/bmc/kepler/KeyService",
"Interface": "bmc.kepler.KeyService",
"Source": {
"UpdateInterval": "${ReqBody/interval}"
}
}
],
"Echoes": [
"ipmcset/securityenhance_masterkeyupdateinterval",
""
]
}
]
},
{
"Uri": "/cli/v1/securityenhance/updatemasterkey",
"Interfaces": [
{
"Type": "Patch",
"LockdownAllow": false,
"Usage": "ipmcset -t securityenhance -d updatemasterkey",
"Description": "Update master key",
"Confirm": {
"Condition": true,
"Description": "WARNING: You are about to update the following master key:\n IPMI password master key\n SNMP community master key\n SNMP privacy password master key\n Trap community master key\n SMTP password master key\n Redfish master key\n VNC password master key\n Upgrade file master key\n SSH host key master key\n SSL master key\n LDAP bind password master key\n NTP GroupKey file master key\n BIOS password master key\nDo you want to continue?[Y/N]:"
},
"RspBody": {},
"ProcessingFlow": [
{
"Type": "Task",
"Path": "/bmc/kepler/KeyService",
"Interface": "bmc.kepler.KeyService",
"Name": "UpdateKey",
"Destination": {
"TaskId": "TaskId"
}
}
],
"Echoes": [
"ipmcset/securityenhance_updatemasterkey",
""
]
}
]
}
]
}