- Issued:
- 2023-11-07
- Updated:
- 2023-11-07
RHBA-2023:6765 - Bug Fix Advisory
Synopsis
Updated FIDO Device Onboarding container images
Type/Severity
Bug Fix Advisory
Topic
Updated FIDO Device Onboarding Server container images are now available in the Red Hat container registry.
Description
The FIDO Device Onboarding (FDO) process automatically authenticates and provisions Edge devices, providing secure, zero touch onboarding and configuration at scale.
The FDO protocol is based on four servers:
FDO Manufacturing Server: The server side implementation of the "Device Initialize" protocol, the FDO Manufacturing Server is responsible for signing a device and creating a voucher used for device ownership.
FDO Owner Onboarding Server: The FDO Owner Onboarding server creates a secure channel for communication with an Edge device and sends the required configuration, files and keys needed for onboarding.
FDO Rendezvous Server: The FDO Rendezvous server is the first point of contact for a newly powered on Edge device during Onboarding. The FDO Rendezvous server receives an Owner Voucher from the Manufacturing server which is used for device authentication and points to the Owner Onboarding server for onboarding automation.
FDO Serviceinfo API Server: The FDO Serviceinfo API server is used with the Owner Onboarding server and provides Edge device configuration details.
The following new container images are now available in the Red Hat container registry:
fdo-manufacturing-server
fdo-owner-onboarding-server
fdo-rendezvous-server
fdo-serviceinfo-api-server
To pull a container image, run the following command:
podman pull registry.redhat.io/rhel9/<image_name>
Solution
The container image provided by this update can be downloaded from the Red Hat container registry at registry.access.redhat.com using the "podman pull" command.
Affected Products
- Red Hat Enterprise Linux for x86_64 9 x86_64
- Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64
- Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
- Red Hat Enterprise Linux Server - AUS 9.6 x86_64
- Red Hat Enterprise Linux Server - AUS 9.4 x86_64
- Red Hat Enterprise Linux for IBM z Systems 9 s390x
- Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x
- Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x
- Red Hat Enterprise Linux for Power, little endian 9 ppc64le
- Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le
- Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le
- Red Hat Enterprise Linux for ARM 64 9 aarch64
- Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64
- Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
- Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le
- Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
- Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64
- Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
- Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64
- Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
- Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x
- Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x
Fixes
- BZ - 2232019 - rebuild of fdo-manufacturing-server-container 9.3
- BZ - 2232020 - rebuild of fdo-owner-onboarding-server-container 9.3
- BZ - 2232021 - rebuild of fdo-rendezvous-server-container 9.3
- BZ - 2232022 - rebuild of fdo-serviceinfo-api-server-container 9.3
CVEs
(none)
aarch64
| rhel9/fdo-manufacturing-server@sha256:a5e6d8b102f9a39e13f6901c8729d0d21a51f8597e146c5be58b4f2d1ee836ff |
| rhel9/fdo-owner-onboarding-server@sha256:959a0081f0695d2d09aaec7b80becdfec6de77b79053c434d76383e116aa36f5 |
| rhel9/fdo-rendezvous-server@sha256:e2091b66ab9b4895769becc54edc206e3fa9d848952965d7f15195df00fa62a2 |
| rhel9/fdo-serviceinfo-api-server@sha256:2e83994f27b37c67e1a4e6a3a86e9eda6c2595ebce70f91feace9cc91eb0df0e |
x86_64
| rhel9/fdo-manufacturing-server@sha256:4e991f4340776e51bf6908b79d7f6af5c874e54108ef98cf1cf4548793e186a0 |
| rhel9/fdo-owner-onboarding-server@sha256:8a6131fd11e87d84d1cb08df4ac0f612f71247acec1a35d54c47e46e84d70f73 |
| rhel9/fdo-rendezvous-server@sha256:9075a53395d08cd8934d15904fc330f57af9c468087b347a0a3db259bfd62b7d |
| rhel9/fdo-serviceinfo-api-server@sha256:ddb1498515f510ab1611ed2abd6e50c6eb57c6caed1bf91f8cf54aabe32c4564 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.