{"resources":{"redfish":{"id":"redfish","name":"redfish","fields":{"account":{"name":"account","type":"\u001bredfish.account","title":"Management controller user account","desc":"Local user account on the management controller. Covers the user name, assigned role, and whether the account is enabled or locked, used to audit who holds administrative access to out-of-band management.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"accounts":{"name":"accounts","type":"\u0019\u001bredfish.account","title":"Local user accounts on the management controller","provider":"go.mondoo.com/mql/providers/redfish"},"certificate":{"name":"certificate","type":"\u001bredfish.certificate","title":"Management controller TLS certificate","desc":"Certificate that a management controller presents on its HTTPS endpoint. Covers the issuer, the subject, the validity window, and the public key size, so an audit can find expired certificates, self-signed certificates, and keys below the required strength.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"certificates":{"name":"certificates","type":"\u0019\u001bredfish.certificate","title":"TLS certificates that the controllers present on their HTTPS endpoint","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"chassis":{"name":"chassis","type":"\u0019\u001bredfish.chassisEnclosure","title":"Physical chassis enclosures","provider":"go.mondoo.com/mql/providers/redfish"},"chassisEnclosure":{"name":"chassisEnclosure","type":"\u001bredfish.chassisEnclosure","title":"Physical chassis","desc":"Physical enclosure that houses a managed system. Covers the chassis type, manufacturer, model, serial number, and current power state used to inventory physical hardware.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"dell":{"name":"dell","type":"\u001bredfish.dell","title":"Dell iDRAC extensions","desc":"Dell-specific management data exposed by Dell Integrated Dell Remote Access Controller (iDRAC) hardware, including the server hardware generation and the BIOS release date. Populated when the connected server is Dell hardware and empty otherwise.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"ethernetInterface":{"name":"ethernetInterface","type":"\u001bredfish.ethernetInterface","title":"Network interface","desc":"Network interface reported by a managed system. Covers the MAC addresses, link speed, duplex, and administrative and link state used to inventory server connectivity.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"firmware":{"name":"firmware","type":"\u0019\u001bredfish.softwareInventory","title":"Firmware and software components tracked by the update service","provider":"go.mondoo.com/mql/providers/redfish"},"hpe":{"name":"hpe","type":"\u001bredfish.hpe","title":"HPE iLO extensions","desc":"HPE-specific management data exposed by HPE Integrated Lights-Out (iLO) controllers, including the installed license edition that governs which management capabilities are available. Populated when the connected server is HPE hardware and empty otherwise.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"manager":{"name":"manager","type":"\u001bredfish.manager","title":"Baseboard management controller","desc":"Out-of-band management controller (the BMC) that operates independently of the host operating system. Covers the controller firmware version, model, power state, and the network services such as SSH, HTTPS, IPMI, SNMP, KVM-IP, and virtual media that it exposes.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"managers":{"name":"managers","type":"\u0019\u001bredfish.manager","title":"Management controllers (BMCs) for this service","provider":"go.mondoo.com/mql/providers/redfish"},"memory":{"name":"memory","type":"\u001bredfish.memory","title":"Memory module","desc":"Single memory module installed in a managed system. Covers the capacity, device type, operating speed, and manufacturer part and serial numbers used to inventory installed memory.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"networkProtocol":{"name":"networkProtocol","type":"\u001bredfish.networkProtocol","title":"Management network protocol settings","desc":"Network protocols that a management controller exposes, with the enabled state and the listening port of each one. Covers the protocols that carry out-of-band access to the server, so an audit can flag cleartext or legacy paths such as telnet, IPMI over LAN, SNMP, and plain HTTP.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"networkProtocols":{"name":"networkProtocols","type":"\u0019\u001bredfish.networkProtocol","title":"Management network protocols exposed by each controller","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"processor":{"name":"processor","type":"\u001bredfish.processor","title":"Processor","desc":"Single processor installed in a managed system. Covers the manufacturer, model, socket, instruction set, and the core and thread counts used to inventory compute capacity.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"serviceRootUnauthenticated":{"name":"serviceRootUnauthenticated","type":"\u0004","title":"Whether the Redfish service root answers without credentials","desc":"The provider sends an unauthenticated GET to `/redfish/v1/` on the same host and port. True means the controller returns the service root to an anonymous caller, which discloses the vendor, firmware version, and the resource layout to anyone who reaches the management network. Null when the probe cannot reach the controller, so an audit does not read a network failure as a closed service root.","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"session":{"name":"session","type":"\u001bredfish.session","title":"Redfish session","desc":"Session that is currently open on the management controller. Covers the account that opened it, the client address, and the timestamps, so an audit can review who holds live out-of-band access.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"sessionService":{"name":"sessionService","type":"\u001bredfish.sessionService","title":"Session service","desc":"Service that issues and tracks Redfish sessions on the management controller. Covers whether the service accepts new sessions and how long an idle or long-lived session stays open, so an audit can require that stale management sessions close. Every field is null when the controller exposes no session service, so an audit can tell an unsupported controller apart from one that reports a disabled service or an unlimited timeout.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"sessions":{"name":"sessions","type":"\u0019\u001bredfish.session","title":"Sessions that are currently open on the management service","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"softwareInventory":{"name":"softwareInventory","type":"\u001bredfish.softwareInventory","title":"Firmware or software inventory item","desc":"Firmware or software component tracked by the update service. Covers the component version, manufacturer, release date, and whether it can be updated, used to audit firmware levels against known-vulnerable releases.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"supermicro":{"name":"supermicro","type":"\u001bredfish.supermicro","title":"Supermicro BMC extensions","desc":"Supermicro-specific management data exposed by the controller, including the activated node-management licenses that unlock Redfish capabilities and whether BMC system lockdown mode is engaged. Populated when the connected server is Supermicro hardware and empty otherwise.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"system":{"name":"system","type":"\u001bredfish.system","title":"Managed computer system","desc":"Compute node managed through the controller. Covers identity such as the UUID, model, and serial number, along with the firmware level, power state, UEFI Secure Boot status, and the installed processors, memory modules, and network interfaces.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"systems":{"name":"systems","type":"\u0019\u001bredfish.system","title":"Compute systems managed through the controller","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Redfish management service","desc":"Management service exposed by a server's baseboard management controller (BMC), such as HPE iLO or Dell iDRAC, over the DMTF Redfish REST API. Provides the managed compute systems, management controllers, physical chassis, BMC user accounts, and firmware inventory for out-of-band audits that run independently of the host operating system.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.account":{"id":"redfish.account","name":"redfish.account","fields":{"accountTypes":{"name":"accountTypes","type":"\u0019\u0007","is_mandatory":true,"title":"Account categories, such as Redfish, SNMP, or OEM","provider":"go.mondoo.com/mql/providers/redfish"},"defaultVendorAccount":{"name":"defaultVendorAccount","type":"\u0004","is_mandatory":true,"title":"Whether the login name is a known vendor default","desc":"True when `userName` matches a name that a controller ships with from the factory, such as root on HPE iLO, root on Dell iDRAC, ADMIN on Supermicro, or USERID on Lenovo XClarity. The match ignores case. A default name keeps half of the credential pair public, so an audit can require that these accounts are renamed or disabled without hardcoding the vendor list.","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the account is enabled","provider":"go.mondoo.com/mql/providers/redfish"},"locked":{"name":"locked","type":"\u0004","is_mandatory":true,"title":"Whether the account is locked out","provider":"go.mondoo.com/mql/providers/redfish"},"roleId":{"name":"roleId","type":"\u0007","is_mandatory":true,"title":"Role assigned to the account, such as Administrator, Operator, or ReadOnly","provider":"go.mondoo.com/mql/providers/redfish"},"userName":{"name":"userName","type":"\u0007","is_mandatory":true,"title":"Login name of the account","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Management controller user account","desc":"Local user account on the management controller. Covers the user name, assigned role, and whether the account is enabled or locked, used to audit who holds administrative access to out-of-band management.","min_provider_version":"13.0.0","defaults":"userName roleId enabled","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.certificate":{"id":"redfish.certificate","name":"redfish.certificate","fields":{"certificateType":{"name":"certificateType","type":"\u0007","is_mandatory":true,"title":"Format of the certificate, such as PEM or PKCS7","provider":"go.mondoo.com/mql/providers/redfish"},"certificateUsageTypes":{"name":"certificateUsageTypes","type":"\u0019\u0007","is_mandatory":true,"title":"Purposes the certificate is used for, such as Web or Device","provider":"go.mondoo.com/mql/providers/redfish"},"fingerprint":{"name":"fingerprint","type":"\u0007","is_mandatory":true,"title":"Fingerprint of the certificate","provider":"go.mondoo.com/mql/providers/redfish"},"fingerprintHashAlgorithm":{"name":"fingerprintHashAlgorithm","type":"\u0007","is_mandatory":true,"title":"Hash algorithm that produced the fingerprint, such as SHA256","provider":"go.mondoo.com/mql/providers/redfish"},"issuerCommonName":{"name":"issuerCommonName","type":"\u0007","is_mandatory":true,"title":"Common name of the issuer","provider":"go.mondoo.com/mql/providers/redfish"},"issuerOrganization":{"name":"issuerOrganization","type":"\u0007","is_mandatory":true,"title":"Organization of the issuer","provider":"go.mondoo.com/mql/providers/redfish"},"keyAlgorithm":{"name":"keyAlgorithm","type":"\u0007","is_mandatory":true,"title":"Public key algorithm, such as RSA, ECDSA, or Ed25519","provider":"go.mondoo.com/mql/providers/redfish"},"keySizeBits":{"name":"keySizeBits","type":"\u0005","is_mandatory":true,"title":"Size of the public key in bits, such as 2048 for RSA or 256 for ECDSA","desc":"Null when the controller does not return the encoded certificate or the provider cannot parse the key, so an audit does not read a missing value as a weak key.","provider":"go.mondoo.com/mql/providers/redfish"},"selfSigned":{"name":"selfSigned","type":"\u0004","is_mandatory":true,"title":"Whether the issuer and the subject are the same entity","desc":"Null when the certificate carries no issuer or subject common name, so an audit does not read missing identity data as a certificate signed by a certificate authority.","provider":"go.mondoo.com/mql/providers/redfish"},"serialNumber":{"name":"serialNumber","type":"\u0007","is_mandatory":true,"title":"Serial number of the certificate","provider":"go.mondoo.com/mql/providers/redfish"},"signatureAlgorithm":{"name":"signatureAlgorithm","type":"\u0007","is_mandatory":true,"title":"Object identifier of the signature algorithm, as defined by RFC 5280","provider":"go.mondoo.com/mql/providers/redfish"},"subjectCommonName":{"name":"subjectCommonName","type":"\u0007","is_mandatory":true,"title":"Common name of the subject","provider":"go.mondoo.com/mql/providers/redfish"},"subjectOrganization":{"name":"subjectOrganization","type":"\u0007","is_mandatory":true,"title":"Organization of the subject","provider":"go.mondoo.com/mql/providers/redfish"},"validNotAfter":{"name":"validNotAfter","type":"\t","is_mandatory":true,"title":"End of the validity period","desc":"Null when the controller reports no expiry date or a date the provider cannot parse, so an audit does not read a missing date as a valid one.","provider":"go.mondoo.com/mql/providers/redfish"},"validNotBefore":{"name":"validNotBefore","type":"\t","is_mandatory":true,"title":"Start of the validity period","desc":"Null when the controller reports no start date or a date the provider cannot parse, so an audit does not read a missing date as a valid one.","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Management controller TLS certificate","desc":"Certificate that a management controller presents on its HTTPS endpoint. Covers the issuer, the subject, the validity window, and the public key size, so an audit can find expired certificates, self-signed certificates, and keys below the required strength.","min_provider_version":"13.0.7","defaults":"subjectCommonName validNotAfter","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.chassisEnclosure":{"id":"redfish.chassisEnclosure","name":"redfish.chassisEnclosure","fields":{"chassisType":{"name":"chassisType","type":"\u0007","is_mandatory":true,"title":"Kind of chassis, such as RackMount, Blade, or Enclosure","provider":"go.mondoo.com/mql/providers/redfish"},"manufacturer":{"name":"manufacturer","type":"\u0007","is_mandatory":true,"title":"Manufacturer of the chassis","provider":"go.mondoo.com/mql/providers/redfish"},"model":{"name":"model","type":"\u0007","is_mandatory":true,"title":"Model name","provider":"go.mondoo.com/mql/providers/redfish"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the chassis","provider":"go.mondoo.com/mql/providers/redfish"},"powerState":{"name":"powerState","type":"\u0007","is_mandatory":true,"title":"Current power state of the chassis","provider":"go.mondoo.com/mql/providers/redfish"},"serialNumber":{"name":"serialNumber","type":"\u0007","is_mandatory":true,"title":"Serial number","provider":"go.mondoo.com/mql/providers/redfish"},"sku":{"name":"sku","type":"\u0007","is_mandatory":true,"title":"Stock keeping unit","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Physical chassis","desc":"Physical enclosure that houses a managed system. Covers the chassis type, manufacturer, model, serial number, and current power state used to inventory physical hardware.","min_provider_version":"13.0.0","defaults":"model chassisType","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.dell":{"id":"redfish.dell","name":"redfish.dell","fields":{"biosReleaseDate":{"name":"biosReleaseDate","type":"\u0007","title":"Release date of the installed BIOS","provider":"go.mondoo.com/mql/providers/redfish"},"generation":{"name":"generation","type":"\u0007","title":"Server hardware generation, such as 15G or 16G","provider":"go.mondoo.com/mql/providers/redfish"},"systemID":{"name":"systemID","type":"\u0005","title":"Dell numeric system model identifier","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Dell iDRAC extensions","desc":"Dell-specific management data exposed by Dell Integrated Dell Remote Access Controller (iDRAC) hardware, including the server hardware generation and the BIOS release date. Populated when the connected server is Dell hardware and empty otherwise.","min_provider_version":"13.0.0","defaults":"generation","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.ethernetInterface":{"id":"redfish.ethernetInterface","name":"redfish.ethernetInterface","fields":{"fullDuplex":{"name":"fullDuplex","type":"\u0004","is_mandatory":true,"title":"Whether the link runs in full duplex","provider":"go.mondoo.com/mql/providers/redfish"},"interfaceEnabled":{"name":"interfaceEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the interface is administratively enabled","provider":"go.mondoo.com/mql/providers/redfish"},"linkStatus":{"name":"linkStatus","type":"\u0007","is_mandatory":true,"title":"Link state","desc":"One of LinkUp (available for communication on the interface), NoLink (no link or connection detected), or LinkDown (connected but no link detected).","provider":"go.mondoo.com/mql/providers/redfish"},"macAddress":{"name":"macAddress","type":"\u0007","is_mandatory":true,"title":"Currently configured MAC address","provider":"go.mondoo.com/mql/providers/redfish"},"permanentMACAddress":{"name":"permanentMACAddress","type":"\u0007","is_mandatory":true,"title":"Factory assigned permanent MAC address","provider":"go.mondoo.com/mql/providers/redfish"},"speedMbps":{"name":"speedMbps","type":"\u0005","is_mandatory":true,"title":"Negotiated link speed in Mbps","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Network interface","desc":"Network interface reported by a managed system. Covers the MAC addresses, link speed, duplex, and administrative and link state used to inventory server connectivity.","min_provider_version":"13.0.0","defaults":"macAddress linkStatus","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.hpe":{"id":"redfish.hpe","name":"redfish.hpe","fields":{"licenseLabel":{"name":"licenseLabel","type":"\u0007","title":"License edition name, such as iLO Advanced or iLO Standard","provider":"go.mondoo.com/mql/providers/redfish"},"licenseType":{"name":"licenseType","type":"\u0007","title":"License term, such as Perpetual or Evaluation","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"HPE iLO extensions","desc":"HPE-specific management data exposed by HPE Integrated Lights-Out (iLO) controllers, including the installed license edition that governs which management capabilities are available. Populated when the connected server is HPE hardware and empty otherwise.","min_provider_version":"13.0.0","defaults":"licenseLabel licenseType","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.manager":{"id":"redfish.manager","name":"redfish.manager","fields":{"dateTime":{"name":"dateTime","type":"\u0007","is_mandatory":true,"title":"Controller date and time in ISO 8601 format","provider":"go.mondoo.com/mql/providers/redfish"},"firmwareVersion":{"name":"firmwareVersion","type":"\u0007","is_mandatory":true,"title":"Installed controller firmware version","provider":"go.mondoo.com/mql/providers/redfish"},"managerType":{"name":"managerType","type":"\u0007","is_mandatory":true,"title":"Kind of controller, such as BMC, EnclosureManager, or Service","provider":"go.mondoo.com/mql/providers/redfish"},"manufacturer":{"name":"manufacturer","type":"\u0007","is_mandatory":true,"title":"Manufacturer of the controller","provider":"go.mondoo.com/mql/providers/redfish"},"model":{"name":"model","type":"\u0007","is_mandatory":true,"title":"Model name","provider":"go.mondoo.com/mql/providers/redfish"},"networkProtocol":{"name":"networkProtocol","type":"\n","title":"Management network services and their enabled state and listening ports","desc":"Deprecated in favor of `redfish.networkProtocols`, which types every field, covers telnet, and reports a protocol the controller does not describe as null rather than as disabled.  The `hostName` and `fqdn` keys carry the controller's network identity. Each of `http`, `https`, `ssh`, `ipmi`, `snmp`, `kvmip`, and `virtualMedia` maps to an object with `enabled` (bool) and `port` (int), letting you audit which out-of-band management protocols are exposed and on which ports (for example flagging cleartext `http`, `snmp`, or `ipmi` that should be disabled).","provider":"go.mondoo.com/mql/providers/redfish","maturity":"deprecated"},"powerState":{"name":"powerState","type":"\u0007","is_mandatory":true,"title":"Current power state of the controller","provider":"go.mondoo.com/mql/providers/redfish"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Stable UUID of the controller","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Baseboard management controller","desc":"Out-of-band management controller (the BMC) that operates independently of the host operating system. Covers the controller firmware version, model, power state, and the network services such as SSH, HTTPS, IPMI, SNMP, KVM-IP, and virtual media that it exposes.","min_provider_version":"13.0.0","defaults":"model firmwareVersion","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.memory":{"id":"redfish.memory","name":"redfish.memory","fields":{"capacityMiB":{"name":"capacityMiB","type":"\u0005","is_mandatory":true,"title":"Capacity in mebibytes","provider":"go.mondoo.com/mql/providers/redfish"},"dataWidthBits":{"name":"dataWidthBits","type":"\u0005","is_mandatory":true,"title":"Data bus width in bits","provider":"go.mondoo.com/mql/providers/redfish"},"manufacturer":{"name":"manufacturer","type":"\u0007","is_mandatory":true,"title":"Manufacturer of the module","provider":"go.mondoo.com/mql/providers/redfish"},"memoryDeviceType":{"name":"memoryDeviceType","type":"\u0007","is_mandatory":true,"title":"Device type, such as DDR4 or DDR5","provider":"go.mondoo.com/mql/providers/redfish"},"operatingSpeedMhz":{"name":"operatingSpeedMhz","type":"\u0005","is_mandatory":true,"title":"Operating speed in MHz","provider":"go.mondoo.com/mql/providers/redfish"},"partNumber":{"name":"partNumber","type":"\u0007","is_mandatory":true,"title":"Manufacturer part number","provider":"go.mondoo.com/mql/providers/redfish"},"rankCount":{"name":"rankCount","type":"\u0005","is_mandatory":true,"title":"Number of ranks","provider":"go.mondoo.com/mql/providers/redfish"},"serialNumber":{"name":"serialNumber","type":"\u0007","is_mandatory":true,"title":"Serial number","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Memory module","desc":"Single memory module installed in a managed system. Covers the capacity, device type, operating speed, and manufacturer part and serial numbers used to inventory installed memory.","min_provider_version":"13.0.0","defaults":"capacityMiB memoryDeviceType","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.networkProtocol":{"id":"redfish.networkProtocol","name":"redfish.networkProtocol","fields":{"fqdn":{"name":"fqdn","type":"\u0007","is_mandatory":true,"title":"Fully qualified domain name of the controller","provider":"go.mondoo.com/mql/providers/redfish"},"hostName":{"name":"hostName","type":"\u0007","is_mandatory":true,"title":"Host name of the controller, without domain information","provider":"go.mondoo.com/mql/providers/redfish"},"httpEnabled":{"name":"httpEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the cleartext HTTP interface is enabled","desc":"Every enabled state in this resource is null when the controller does not report the protocol at all, so an audit can tell a protocol that is switched off apart from one the controller does not describe.","provider":"go.mondoo.com/mql/providers/redfish"},"httpPort":{"name":"httpPort","type":"\u0005","is_mandatory":true,"title":"TCP port of the HTTP interface, usually 80","provider":"go.mondoo.com/mql/providers/redfish"},"httpsEnabled":{"name":"httpsEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the HTTPS interface is enabled","provider":"go.mondoo.com/mql/providers/redfish"},"httpsPort":{"name":"httpsPort","type":"\u0005","is_mandatory":true,"title":"TCP port of the HTTPS interface, usually 443","provider":"go.mondoo.com/mql/providers/redfish"},"ipmiEnabled":{"name":"ipmiEnabled","type":"\u0004","is_mandatory":true,"title":"Whether IPMI over LAN is enabled","desc":"IPMI over LAN keeps password hashes retrievable before authentication in the RAKP handshake of IPMI 2.0. An enabled IPMI interface therefore bypasses the account controls that apply to the Redfish interface.","provider":"go.mondoo.com/mql/providers/redfish"},"ipmiPort":{"name":"ipmiPort","type":"\u0005","is_mandatory":true,"title":"UDP port of the IPMI over LAN interface, usually 623","provider":"go.mondoo.com/mql/providers/redfish"},"kvmipEnabled":{"name":"kvmipEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the KVM over IP console is enabled","provider":"go.mondoo.com/mql/providers/redfish"},"kvmipPort":{"name":"kvmipPort","type":"\u0005","is_mandatory":true,"title":"TCP port of the KVM over IP console","provider":"go.mondoo.com/mql/providers/redfish"},"snmpEnabled":{"name":"snmpEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the SNMP agent is enabled","provider":"go.mondoo.com/mql/providers/redfish"},"snmpPort":{"name":"snmpPort","type":"\u0005","is_mandatory":true,"title":"UDP port of the SNMP agent, usually 161","provider":"go.mondoo.com/mql/providers/redfish"},"sshEnabled":{"name":"sshEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the SSH interface is enabled","provider":"go.mondoo.com/mql/providers/redfish"},"sshPort":{"name":"sshPort","type":"\u0005","is_mandatory":true,"title":"TCP port of the SSH interface, usually 22","provider":"go.mondoo.com/mql/providers/redfish"},"telnetEnabled":{"name":"telnetEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the telnet interface is enabled","desc":"Telnet carries credentials in cleartext and has no host authentication. An enabled telnet interface bypasses the controls that guard the Redfish and SSH paths.","provider":"go.mondoo.com/mql/providers/redfish"},"telnetPort":{"name":"telnetPort","type":"\u0005","is_mandatory":true,"title":"TCP port of the telnet interface, usually 23","provider":"go.mondoo.com/mql/providers/redfish"},"virtualMediaEnabled":{"name":"virtualMediaEnabled","type":"\u0004","is_mandatory":true,"title":"Whether virtual media is enabled","desc":"Virtual media lets the controller attach a remote image as a local drive, which supplies a boot source that the host operating system cannot see.","provider":"go.mondoo.com/mql/providers/redfish"},"virtualMediaPort":{"name":"virtualMediaPort","type":"\u0005","is_mandatory":true,"title":"TCP port of the virtual media service","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Management network protocol settings","desc":"Network protocols that a management controller exposes, with the enabled state and the listening port of each one. Covers the protocols that carry out-of-band access to the server, so an audit can flag cleartext or legacy paths such as telnet, IPMI over LAN, SNMP, and plain HTTP.","min_provider_version":"13.0.7","defaults":"hostName ipmiEnabled telnetEnabled","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.processor":{"id":"redfish.processor","name":"redfish.processor","fields":{"instructionSet":{"name":"instructionSet","type":"\u0007","is_mandatory":true,"title":"Instruction set, such as x86-64 or ARM-A64","provider":"go.mondoo.com/mql/providers/redfish"},"manufacturer":{"name":"manufacturer","type":"\u0007","is_mandatory":true,"title":"Manufacturer of the processor","provider":"go.mondoo.com/mql/providers/redfish"},"maxSpeedMHz":{"name":"maxSpeedMHz","type":"\u0005","is_mandatory":true,"title":"Maximum clock speed in MHz","provider":"go.mondoo.com/mql/providers/redfish"},"model":{"name":"model","type":"\u0007","is_mandatory":true,"title":"Model name","provider":"go.mondoo.com/mql/providers/redfish"},"processorType":{"name":"processorType","type":"\u0007","is_mandatory":true,"title":"Kind of processor, such as CPU, GPU, or FPGA","provider":"go.mondoo.com/mql/providers/redfish"},"socket":{"name":"socket","type":"\u0007","is_mandatory":true,"title":"Socket the processor occupies","provider":"go.mondoo.com/mql/providers/redfish"},"totalCores":{"name":"totalCores","type":"\u0005","is_mandatory":true,"title":"Number of physical cores","provider":"go.mondoo.com/mql/providers/redfish"},"totalThreads":{"name":"totalThreads","type":"\u0005","is_mandatory":true,"title":"Number of hardware threads","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Processor","desc":"Single processor installed in a managed system. Covers the manufacturer, model, socket, instruction set, and the core and thread counts used to inventory compute capacity.","min_provider_version":"13.0.0","defaults":"model totalCores","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.session":{"id":"redfish.session","name":"redfish.session","fields":{"clientOriginIPAddress":{"name":"clientOriginIPAddress","type":"\u0007","is_mandatory":true,"title":"IP address of the client that opened the session","provider":"go.mondoo.com/mql/providers/redfish"},"createdTime":{"name":"createdTime","type":"\t","is_mandatory":true,"title":"Time the session was created","provider":"go.mondoo.com/mql/providers/redfish"},"expirationTime":{"name":"expirationTime","type":"\t","is_mandatory":true,"title":"Time the session expires regardless of activity","desc":"Null when the session does not expire on an absolute time.","provider":"go.mondoo.com/mql/providers/redfish"},"roles":{"name":"roles","type":"\u0019\u0007","is_mandatory":true,"title":"Redfish roles that carry the privileges of the session","provider":"go.mondoo.com/mql/providers/redfish"},"sessionType":{"name":"sessionType","type":"\u0007","is_mandatory":true,"title":"Kind of session, such as Redfish, HostConsole, or IPMI","provider":"go.mondoo.com/mql/providers/redfish"},"userName":{"name":"userName","type":"\u0007","is_mandatory":true,"title":"Account that opened the session","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Redfish session","desc":"Session that is currently open on the management controller. Covers the account that opened it, the client address, and the timestamps, so an audit can review who holds live out-of-band access.","min_provider_version":"13.0.7","defaults":"userName clientOriginIPAddress","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.sessionService":{"id":"redfish.sessionService","name":"redfish.sessionService","fields":{"absoluteSessionTimeout":{"name":"absoluteSessionTimeout","type":"\u0005","title":"Maximum lifetime in seconds of a session, regardless of activity","provider":"go.mondoo.com/mql/providers/redfish"},"absoluteSessionTimeoutEnabled":{"name":"absoluteSessionTimeoutEnabled","type":"\u0004","title":"Whether the service applies the absolute session lifetime","provider":"go.mondoo.com/mql/providers/redfish"},"serviceEnabled":{"name":"serviceEnabled","type":"\u0004","title":"Whether the session service accepts new sessions","provider":"go.mondoo.com/mql/providers/redfish"},"sessionTimeout":{"name":"sessionTimeout","type":"\u0005","title":"Idle time in seconds after which the service closes a session","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Session service","desc":"Service that issues and tracks Redfish sessions on the management controller. Covers whether the service accepts new sessions and how long an idle or long-lived session stays open, so an audit can require that stale management sessions close. Every field is null when the controller exposes no session service, so an audit can tell an unsupported controller apart from one that reports a disabled service or an unlimited timeout.","min_provider_version":"13.0.7","defaults":"serviceEnabled sessionTimeout","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.softwareInventory":{"id":"redfish.softwareInventory","name":"redfish.softwareInventory","fields":{"lowestSupportedVersion":{"name":"lowestSupportedVersion","type":"\u0007","is_mandatory":true,"title":"Lowest version the component can be downgraded to","provider":"go.mondoo.com/mql/providers/redfish"},"manufacturer":{"name":"manufacturer","type":"\u0007","is_mandatory":true,"title":"Manufacturer of the component","provider":"go.mondoo.com/mql/providers/redfish"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the component","provider":"go.mondoo.com/mql/providers/redfish"},"releaseDate":{"name":"releaseDate","type":"\u0007","is_mandatory":true,"title":"Release date of the installed version","provider":"go.mondoo.com/mql/providers/redfish"},"softwareId":{"name":"softwareId","type":"\u0007","is_mandatory":true,"title":"Vendor assigned software identifier","provider":"go.mondoo.com/mql/providers/redfish"},"updateable":{"name":"updateable","type":"\u0004","is_mandatory":true,"title":"Whether the component can be updated through the service","provider":"go.mondoo.com/mql/providers/redfish"},"version":{"name":"version","type":"\u0007","is_mandatory":true,"title":"Installed version","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Firmware or software inventory item","desc":"Firmware or software component tracked by the update service. Covers the component version, manufacturer, release date, and whether it can be updated, used to audit firmware levels against known-vulnerable releases.","min_provider_version":"13.0.0","defaults":"name version","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.supermicro":{"id":"redfish.supermicro","name":"redfish.supermicro","fields":{"licenses":{"name":"licenses","type":"\u0019\u0007","title":"Activated license keys, such as SFT-DCMS-Single","provider":"go.mondoo.com/mql/providers/redfish"},"systemLockdownEnabled":{"name":"systemLockdownEnabled","type":"\u0004","title":"Whether BMC system lockdown mode is enabled","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Supermicro BMC extensions","desc":"Supermicro-specific management data exposed by the controller, including the activated node-management licenses that unlock Redfish capabilities and whether BMC system lockdown mode is engaged. Populated when the connected server is Supermicro hardware and empty otherwise.","min_provider_version":"13.0.0","defaults":"systemLockdownEnabled","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.system":{"id":"redfish.system","name":"redfish.system","fields":{"biosVersion":{"name":"biosVersion","type":"\u0007","is_mandatory":true,"title":"Installed BIOS or UEFI firmware version","provider":"go.mondoo.com/mql/providers/redfish"},"bootSourceOverrideEnabled":{"name":"bootSourceOverrideEnabled","type":"\u0007","is_mandatory":true,"title":"Boot source override state, one of Disabled, Once, or Continuous","desc":"Continuous is the value that matters for an audit. It keeps the system on the overridden boot source across every reset, so a network or removable boot source stays active until an operator clears it.","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"bootSourceOverrideMode":{"name":"bootSourceOverrideMode","type":"\u0007","is_mandatory":true,"title":"Firmware mode the override boots in, either Legacy or UEFI","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"bootSourceOverrideTarget":{"name":"bootSourceOverrideTarget","type":"\u0007","is_mandatory":true,"title":"Boot source that the override selects, such as Pxe, Usb, Hdd, or None","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"ethernetInterfaces":{"name":"ethernetInterfaces","type":"\u0019\u001bredfish.ethernetInterface","title":"Network interfaces attached to the system","provider":"go.mondoo.com/mql/providers/redfish"},"hostName":{"name":"hostName","type":"\u0007","is_mandatory":true,"title":"Configured host name","provider":"go.mondoo.com/mql/providers/redfish"},"manufacturer":{"name":"manufacturer","type":"\u0007","is_mandatory":true,"title":"Hardware manufacturer","provider":"go.mondoo.com/mql/providers/redfish"},"memory":{"name":"memory","type":"\u0019\u001bredfish.memory","title":"Installed memory modules","provider":"go.mondoo.com/mql/providers/redfish"},"model":{"name":"model","type":"\u0007","is_mandatory":true,"title":"Model name","provider":"go.mondoo.com/mql/providers/redfish"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the system","provider":"go.mondoo.com/mql/providers/redfish"},"persistentBootOverride":{"name":"persistentBootOverride","type":"\u0004","is_mandatory":true,"title":"Whether a boot source override is set to persist across resets","desc":"True when the override state is Continuous and the target is a real boot source rather than None. A persistent override to Pxe or Usb lets anyone who controls the network or the virtual media device supply the operating system on every boot.","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"powerState":{"name":"powerState","type":"\u0007","is_mandatory":true,"title":"Current power state, such as On, Off, or PoweringOn","provider":"go.mondoo.com/mql/providers/redfish"},"processors":{"name":"processors","type":"\u0019\u001bredfish.processor","title":"Installed processors","provider":"go.mondoo.com/mql/providers/redfish"},"secureBootEnabled":{"name":"secureBootEnabled","type":"\u0004","title":"Whether UEFI Secure Boot is enabled","desc":"Null when the system does not expose a Secure Boot resource or the controller cannot report its state, so an audit can tell an unsupported or unreachable system apart from one where Secure Boot is switched off.","provider":"go.mondoo.com/mql/providers/redfish"},"serialNumber":{"name":"serialNumber","type":"\u0007","is_mandatory":true,"title":"Serial number","provider":"go.mondoo.com/mql/providers/redfish"},"sku":{"name":"sku","type":"\u0007","is_mandatory":true,"title":"Stock keeping unit","provider":"go.mondoo.com/mql/providers/redfish"},"systemType":{"name":"systemType","type":"\u0007","is_mandatory":true,"title":"Kind of system, such as Physical, Virtual, OS, or PhysicallyPartitioned","provider":"go.mondoo.com/mql/providers/redfish"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Stable UUID of the system","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Managed computer system","desc":"Compute node managed through the controller. Covers identity such as the UUID, model, and serial number, along with the firmware level, power state, UEFI Secure Boot status, and the installed processors, memory modules, and network interfaces.","min_provider_version":"13.0.0","defaults":"model powerState","provider":"go.mondoo.com/mql/providers/redfish"}}}