{"resources":{"redfish":{"id":"redfish","name":"redfish","fields":{"account":{"name":"account","type":"\u001bredfish.account","title":"Management controller user account","desc":"Local user account on the management controller. Covers the user name, assigned role, and whether the account is enabled or locked, used to audit who holds administrative access to out-of-band management.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"accountService":{"name":"accountService","type":"\u001bredfish.accountService","title":"Management controller account service","desc":"Service that governs the local accounts on the management controller. Covers the password and lockout policy applied to them, whether HTTP Basic authentication is accepted, and the external directories the controller federates authentication to. These are the settings that decide how much a guessed or stolen out-of-band credential is worth, and the accounts themselves do not report any of them. Every field is null when the controller exposes no account service or omits the property, so an audit can tell an unreported setting apart from one the controller reports as zero or as disabled.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"accounts":{"name":"accounts","type":"\u0019\u001bredfish.account","title":"Local user accounts on the management controller","provider":"go.mondoo.com/mql/providers/redfish"},"asset":{"name":"asset","type":"\u001basset","title":"Asset this root belongs to","desc":"Platform, version, identity and labels of the asset this root describes.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"certificate":{"name":"certificate","type":"\u001bredfish.certificate","title":"Management controller TLS certificate","desc":"Certificate that a management controller presents on its HTTPS endpoint. Covers the issuer, the subject, the validity window, and the public key size, so an audit can find expired certificates, self-signed certificates, and keys below the required strength.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"certificates":{"name":"certificates","type":"\u0019\u001bredfish.certificate","title":"TLS certificates that the controllers present on their HTTPS endpoint","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"chassis":{"name":"chassis","type":"\u0019\u001bredfish.chassisEnclosure","title":"Physical chassis enclosures","provider":"go.mondoo.com/mql/providers/redfish"},"chassisEnclosure":{"name":"chassisEnclosure","type":"\u001bredfish.chassisEnclosure","title":"Physical chassis","desc":"Physical enclosure that houses a managed system. Covers the chassis type, manufacturer, model, serial number, and current power state used to inventory physical hardware.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"dell":{"name":"dell","type":"\u001bredfish.dell","title":"Dell iDRAC extensions","desc":"Dell-specific management data exposed by Dell Integrated Dell Remote Access Controller (iDRAC) hardware, including the server hardware generation and the BIOS release date. Populated when the connected server is Dell hardware and empty otherwise.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"ethernetInterface":{"name":"ethernetInterface","type":"\u001bredfish.ethernetInterface","title":"Network interface","desc":"Network interface reported by a managed system. Covers the MAC addresses, link speed, duplex, and administrative and link state used to inventory server connectivity.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"firmware":{"name":"firmware","type":"\u0019\u001bredfish.softwareInventory","title":"Firmware and software components tracked by the update service","provider":"go.mondoo.com/mql/providers/redfish"},"hpe":{"name":"hpe","type":"\u001bredfish.hpe","title":"HPE iLO extensions","desc":"HPE-specific management data exposed by HPE Integrated Lights-Out (iLO) controllers, including the installed license edition that governs which management capabilities are available. Populated when the connected server is HPE hardware and empty otherwise.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"manager":{"name":"manager","type":"\u001bredfish.manager","title":"Baseboard management controller","desc":"Out-of-band management controller (the BMC) that operates independently of the host operating system. Covers the controller firmware version, model, power state, and the network services such as SSH, HTTPS, IPMI, SNMP, KVM-IP, and virtual media that it exposes.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"managers":{"name":"managers","type":"\u0019\u001bredfish.manager","title":"Management controllers (BMCs) for this service","provider":"go.mondoo.com/mql/providers/redfish"},"memory":{"name":"memory","type":"\u001bredfish.memory","title":"Memory module","desc":"Single memory module installed in a managed system. Covers the capacity, device type, operating speed, and manufacturer part and serial numbers used to inventory installed memory.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"networkProtocol":{"name":"networkProtocol","type":"\u001bredfish.networkProtocol","title":"Management network protocol settings","desc":"Network protocols that a management controller exposes, with the enabled state and the listening port of each one. Covers the protocols that carry out-of-band access to the server, so an audit can flag cleartext or legacy paths such as telnet, IPMI over LAN, SNMP, and plain HTTP.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"networkProtocols":{"name":"networkProtocols","type":"\u0019\u001bredfish.networkProtocol","title":"Management network protocols exposed by each controller","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"processor":{"name":"processor","type":"\u001bredfish.processor","title":"Processor","desc":"Single processor installed in a managed system. Covers the manufacturer, model, socket, instruction set, and the core and thread counts used to inventory compute capacity.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"serviceRootUnauthenticated":{"name":"serviceRootUnauthenticated","type":"\u0004","title":"Whether the Redfish service root answers without credentials","desc":"The provider sends an unauthenticated GET to `/redfish/v1/` on the same host and port. True means the controller returns the service root to an anonymous caller, which discloses the vendor, firmware version, and the resource layout to anyone who reaches the management network. Null when the probe cannot reach the controller, so an audit does not read a network failure as a closed service root.","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"session":{"name":"session","type":"\u001bredfish.session","title":"Redfish session","desc":"Session that is currently open on the management controller. Covers the account that opened it, the client address, and the timestamps, so an audit can review who holds live out-of-band access.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"sessionService":{"name":"sessionService","type":"\u001bredfish.sessionService","title":"Session service","desc":"Service that issues and tracks Redfish sessions on the management controller. Covers whether the service accepts new sessions and how long an idle or long-lived session stays open, so an audit can require that stale management sessions close. Every field is null when the controller exposes no session service, so an audit can tell an unsupported controller apart from one that reports a disabled service or an unlimited timeout.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"sessions":{"name":"sessions","type":"\u0019\u001bredfish.session","title":"Sessions that are currently open on the management service","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"softwareInventory":{"name":"softwareInventory","type":"\u001bredfish.softwareInventory","title":"Firmware or software inventory item","desc":"Firmware or software component tracked by the update service. Covers the component version, manufacturer, release date, and whether it can be updated, used to audit firmware levels against known-vulnerable releases.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"supermicro":{"name":"supermicro","type":"\u001bredfish.supermicro","title":"Supermicro BMC extensions","desc":"Supermicro-specific management data exposed by the controller. Covers the activated node-management licenses that unlock Redfish capabilities, system lockdown mode, and the hardening settings that Supermicro keeps outside the standard Redfish resources: the IPMI RAKP key exchange, the host side KCS interface, source address filtering, and the RADIUS, NTP, and syslog servers the controller talks to. Populated when the connected server is Supermicro hardware and empty otherwise. The RAKP, KCS, access control, RADIUS, NTP and syslog fields are null when the controller exposes no setting of that kind, so an audit can tell a setting that is switched off apart from one the controller never reports. In that same case `licenses` reports an empty list and `systemLockdownEnabled` reports false.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"system":{"name":"system","type":"\u001bredfish.system","title":"Managed computer system","desc":"Compute node managed through the controller. Covers identity such as the UUID, model, and serial number, along with the firmware level, power state, UEFI Secure Boot status, and the installed processors, memory modules, and network interfaces.","provider":"go.mondoo.com/mql/providers/redfish","is_implicit_resource":true},"systems":{"name":"systems","type":"\u0019\u001bredfish.system","title":"Compute systems managed through the controller","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Redfish management service","desc":"Management service exposed by a server's baseboard management controller (BMC), such as HPE iLO or Dell iDRAC, over the DMTF Redfish REST API. Provides the managed compute systems, management controllers, physical chassis, BMC user accounts, and firmware inventory for out-of-band audits that run independently of the host operating system.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/redfish","root":true},"redfish.account":{"id":"redfish.account","name":"redfish.account","fields":{"accountExpiration":{"name":"accountExpiration","type":"\t","is_mandatory":true,"title":"Time the account itself expires","desc":"Null when the account does not expire or the controller reports a date the provider cannot parse.","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"accountTypes":{"name":"accountTypes","type":"\u0019\u0007","is_mandatory":true,"title":"Account categories, such as Redfish, SNMP, or OEM","provider":"go.mondoo.com/mql/providers/redfish"},"defaultVendorAccount":{"name":"defaultVendorAccount","type":"\u0004","is_mandatory":true,"title":"Whether the login name is a known vendor default","desc":"True when `userName` matches a name that a controller ships with from the factory, such as root on HPE iLO, root on Dell iDRAC, ADMIN on Supermicro, or USERID on Lenovo XClarity. The match ignores case. A default name keeps half of the credential pair public, so an audit can require that these accounts are renamed or disabled without hardcoding the vendor list.","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the account is enabled","provider":"go.mondoo.com/mql/providers/redfish"},"locked":{"name":"locked","type":"\u0004","is_mandatory":true,"title":"Whether the account is locked out","provider":"go.mondoo.com/mql/providers/redfish"},"passwordChangeRequired":{"name":"passwordChangeRequired","type":"\u0004","is_mandatory":true,"title":"Whether the account must change its password at the next login","desc":"True on an account that still holds a password somebody else set for it, which is the state a factory or handover credential stays in until its owner logs in. Null when the controller does not report the property.","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"passwordExpiration":{"name":"passwordExpiration","type":"\t","is_mandatory":true,"title":"Time the password of the account expires","desc":"Null when the password does not expire or the controller reports a date the provider cannot parse, so an audit does not read a missing date as an expired password.","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"roleId":{"name":"roleId","type":"\u0007","is_mandatory":true,"title":"Role assigned to the account, such as Administrator, Operator, or ReadOnly","provider":"go.mondoo.com/mql/providers/redfish"},"strictAccountTypes":{"name":"strictAccountTypes","type":"\u0004","is_mandatory":true,"title":"Whether the account is restricted to the categories it declares","desc":"False lets the controller reach the account through categories beyond the ones in `accountTypes`, so that list understates what the account can do. Null when the controller does not report the property.","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"userName":{"name":"userName","type":"\u0007","is_mandatory":true,"title":"Login name of the account","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Management controller user account","desc":"Local user account on the management controller. Covers the user name, assigned role, and whether the account is enabled or locked, used to audit who holds administrative access to out-of-band management.","min_provider_version":"13.0.0","defaults":"userName roleId enabled","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.accountService":{"id":"redfish.accountService","name":"redfish.accountService","fields":{"accountLockoutCounterResetAfter":{"name":"accountLockoutCounterResetAfter","type":"\u0005","title":"Seconds after which the failed login counter returns to zero","provider":"go.mondoo.com/mql/providers/redfish"},"accountLockoutCounterResetEnabled":{"name":"accountLockoutCounterResetEnabled","type":"\u0004","title":"Whether the failed login counter resets on its own","desc":"False keeps the counter until an administrator clears it, so waiting out the lockout duration does not restore the account.","provider":"go.mondoo.com/mql/providers/redfish"},"accountLockoutDuration":{"name":"accountLockoutDuration","type":"\u0005","title":"Seconds an account stays locked out once the threshold is reached","provider":"go.mondoo.com/mql/providers/redfish"},"accountLockoutThreshold":{"name":"accountLockoutThreshold","type":"\u0005","title":"Failed login attempts that lock an account out","desc":"Zero means the controller never locks an account out, which leaves every local account open to unlimited password guessing from the management network.","provider":"go.mondoo.com/mql/providers/redfish"},"activeDirectoryAuthenticationType":{"name":"activeDirectoryAuthenticationType","type":"\u0007","title":"How the controller authenticates itself to the Active Directory server","desc":"One of Token, KerberosKeytab, UsernameAndPassword, or OEM. The provider reads the method only, never the credential.","provider":"go.mondoo.com/mql/providers/redfish"},"activeDirectoryEnabled":{"name":"activeDirectoryEnabled","type":"\u0004","title":"Whether the controller authenticates users against Active Directory","provider":"go.mondoo.com/mql/providers/redfish"},"activeDirectoryServiceAddresses":{"name":"activeDirectoryServiceAddresses","type":"\u0019\u0007","title":"Active Directory servers the controller authenticates against","provider":"go.mondoo.com/mql/providers/redfish"},"authFailureLoggingThreshold":{"name":"authFailureLoggingThreshold","type":"\u0005","title":"Failed login attempts after which the controller logs the failure","provider":"go.mondoo.com/mql/providers/redfish"},"enforcePasswordHistoryCount":{"name":"enforcePasswordHistoryCount","type":"\u0005","title":"Number of previous passwords the controller refuses to accept again","provider":"go.mondoo.com/mql/providers/redfish"},"httpBasicAuth":{"name":"httpBasicAuth","type":"\u0007","title":"Whether HTTP Basic authentication is accepted","desc":"One of Enabled, Unadvertised, or Disabled. Basic authentication sends the credential on every single request instead of exchanging it once for a session token, so it is the path that leaks a password into request logs and proxies. Unadvertised means the controller still accepts it but does not offer it in its authentication challenge.","provider":"go.mondoo.com/mql/providers/redfish"},"ldapAuthenticationType":{"name":"ldapAuthenticationType","type":"\u0007","title":"How the controller authenticates itself to the LDAP server","desc":"One of Token, KerberosKeytab, UsernameAndPassword, or OEM. The provider reads the method only, never the credential.","provider":"go.mondoo.com/mql/providers/redfish"},"ldapEnabled":{"name":"ldapEnabled","type":"\u0004","title":"Whether the controller authenticates users against LDAP","provider":"go.mondoo.com/mql/providers/redfish"},"ldapServiceAddresses":{"name":"ldapServiceAddresses","type":"\u0019\u0007","title":"LDAP servers the controller authenticates against","provider":"go.mondoo.com/mql/providers/redfish"},"localAccountAuth":{"name":"localAccountAuth","type":"\u0007","title":"How local accounts are treated once an external directory is configured","desc":"One of Enabled, Disabled, Fallback, or LocalFirst. Enabled keeps local accounts usable at all times, so a local credential still opens the controller after the directory has revoked the operator's access.","provider":"go.mondoo.com/mql/providers/redfish"},"maxPasswordLength":{"name":"maxPasswordLength","type":"\u0005","title":"Longest password the controller accepts","provider":"go.mondoo.com/mql/providers/redfish"},"minPasswordLength":{"name":"minPasswordLength","type":"\u0005","title":"Shortest password the controller accepts","provider":"go.mondoo.com/mql/providers/redfish"},"passwordExpirationDays":{"name":"passwordExpirationDays","type":"\u0005","title":"Days after which a password expires","provider":"go.mondoo.com/mql/providers/redfish"},"requireChangePasswordAction":{"name":"requireChangePasswordAction","type":"\u0004","title":"Whether the controller forces a password change on first login","provider":"go.mondoo.com/mql/providers/redfish"},"serviceEnabled":{"name":"serviceEnabled","type":"\u0004","title":"Whether the account service is enabled","provider":"go.mondoo.com/mql/providers/redfish"},"tacacsPlusAuthenticationType":{"name":"tacacsPlusAuthenticationType","type":"\u0007","title":"How the controller authenticates itself to the TACACS+ server","desc":"One of Token, KerberosKeytab, UsernameAndPassword, or OEM. The provider reads the method only, never the shared secret.","provider":"go.mondoo.com/mql/providers/redfish"},"tacacsPlusEnabled":{"name":"tacacsPlusEnabled","type":"\u0004","title":"Whether the controller authenticates users against TACACS+","provider":"go.mondoo.com/mql/providers/redfish"},"tacacsPlusServiceAddresses":{"name":"tacacsPlusServiceAddresses","type":"\u0019\u0007","title":"TACACS+ servers the controller authenticates against","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Management controller account service","desc":"Service that governs the local accounts on the management controller. Covers the password and lockout policy applied to them, whether HTTP Basic authentication is accepted, and the external directories the controller federates authentication to. These are the settings that decide how much a guessed or stolen out-of-band credential is worth, and the accounts themselves do not report any of them. Every field is null when the controller exposes no account service or omits the property, so an audit can tell an unreported setting apart from one the controller reports as zero or as disabled.","min_provider_version":"13.1.1","defaults":"minPasswordLength accountLockoutThreshold httpBasicAuth","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.certificate":{"id":"redfish.certificate","name":"redfish.certificate","fields":{"certificateType":{"name":"certificateType","type":"\u0007","is_mandatory":true,"title":"Format of the certificate, such as PEM or PKCS7","provider":"go.mondoo.com/mql/providers/redfish"},"certificateUsageTypes":{"name":"certificateUsageTypes","type":"\u0019\u0007","is_mandatory":true,"title":"Purposes the certificate is used for, such as Web or Device","provider":"go.mondoo.com/mql/providers/redfish"},"fingerprint":{"name":"fingerprint","type":"\u0007","is_mandatory":true,"title":"Fingerprint of the certificate","provider":"go.mondoo.com/mql/providers/redfish"},"fingerprintHashAlgorithm":{"name":"fingerprintHashAlgorithm","type":"\u0007","is_mandatory":true,"title":"Hash algorithm that produced the fingerprint, such as SHA256","provider":"go.mondoo.com/mql/providers/redfish"},"issuerCommonName":{"name":"issuerCommonName","type":"\u0007","is_mandatory":true,"title":"Common name of the issuer","provider":"go.mondoo.com/mql/providers/redfish"},"issuerOrganization":{"name":"issuerOrganization","type":"\u0007","is_mandatory":true,"title":"Organization of the issuer","provider":"go.mondoo.com/mql/providers/redfish"},"keyAlgorithm":{"name":"keyAlgorithm","type":"\u0007","is_mandatory":true,"title":"Public key algorithm, such as RSA, ECDSA, or Ed25519","provider":"go.mondoo.com/mql/providers/redfish"},"keySizeBits":{"name":"keySizeBits","type":"\u0005","is_mandatory":true,"title":"Size of the public key in bits, such as 2048 for RSA or 256 for ECDSA","desc":"Null when the controller does not return the encoded certificate or the provider cannot parse the key, so an audit does not read a missing value as a weak key.","provider":"go.mondoo.com/mql/providers/redfish"},"selfSigned":{"name":"selfSigned","type":"\u0004","is_mandatory":true,"title":"Whether the issuer and the subject are the same entity","desc":"Null when the certificate carries no issuer or subject common name, so an audit does not read missing identity data as a certificate signed by a certificate authority.","provider":"go.mondoo.com/mql/providers/redfish"},"serialNumber":{"name":"serialNumber","type":"\u0007","is_mandatory":true,"title":"Serial number of the certificate","provider":"go.mondoo.com/mql/providers/redfish"},"signatureAlgorithm":{"name":"signatureAlgorithm","type":"\u0007","is_mandatory":true,"title":"Object identifier of the signature algorithm, as defined by RFC 5280","provider":"go.mondoo.com/mql/providers/redfish"},"subjectCommonName":{"name":"subjectCommonName","type":"\u0007","is_mandatory":true,"title":"Common name of the subject","provider":"go.mondoo.com/mql/providers/redfish"},"subjectOrganization":{"name":"subjectOrganization","type":"\u0007","is_mandatory":true,"title":"Organization of the subject","provider":"go.mondoo.com/mql/providers/redfish"},"validNotAfter":{"name":"validNotAfter","type":"\t","is_mandatory":true,"title":"End of the validity period","desc":"Null when the controller reports no expiry date or a date the provider cannot parse, so an audit does not read a missing date as a valid one.","provider":"go.mondoo.com/mql/providers/redfish"},"validNotBefore":{"name":"validNotBefore","type":"\t","is_mandatory":true,"title":"Start of the validity period","desc":"Null when the controller reports no start date or a date the provider cannot parse, so an audit does not read a missing date as a valid one.","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Management controller TLS certificate","desc":"Certificate that a management controller presents on its HTTPS endpoint. Covers the issuer, the subject, the validity window, and the public key size, so an audit can find expired certificates, self-signed certificates, and keys below the required strength.","min_provider_version":"13.0.7","defaults":"subjectCommonName validNotAfter","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.chassisEnclosure":{"id":"redfish.chassisEnclosure","name":"redfish.chassisEnclosure","fields":{"chassisType":{"name":"chassisType","type":"\u0007","is_mandatory":true,"title":"Kind of chassis, such as RackMount, Blade, or Enclosure","provider":"go.mondoo.com/mql/providers/redfish"},"manufacturer":{"name":"manufacturer","type":"\u0007","is_mandatory":true,"title":"Manufacturer of the chassis","provider":"go.mondoo.com/mql/providers/redfish"},"model":{"name":"model","type":"\u0007","is_mandatory":true,"title":"Model name","provider":"go.mondoo.com/mql/providers/redfish"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the chassis","provider":"go.mondoo.com/mql/providers/redfish"},"powerState":{"name":"powerState","type":"\u0007","is_mandatory":true,"title":"Current power state of the chassis","provider":"go.mondoo.com/mql/providers/redfish"},"serialNumber":{"name":"serialNumber","type":"\u0007","is_mandatory":true,"title":"Serial number","provider":"go.mondoo.com/mql/providers/redfish"},"sku":{"name":"sku","type":"\u0007","is_mandatory":true,"title":"Stock keeping unit","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Physical chassis","desc":"Physical enclosure that houses a managed system. Covers the chassis type, manufacturer, model, serial number, and current power state used to inventory physical hardware.","min_provider_version":"13.0.0","defaults":"model chassisType","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.dell":{"id":"redfish.dell","name":"redfish.dell","fields":{"biosReleaseDate":{"name":"biosReleaseDate","type":"\u0007","title":"Release date of the installed BIOS","provider":"go.mondoo.com/mql/providers/redfish"},"generation":{"name":"generation","type":"\u0007","title":"Server hardware generation, such as 15G or 16G","provider":"go.mondoo.com/mql/providers/redfish"},"systemID":{"name":"systemID","type":"\u0005","title":"Dell numeric system model identifier","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Dell iDRAC extensions","desc":"Dell-specific management data exposed by Dell Integrated Dell Remote Access Controller (iDRAC) hardware, including the server hardware generation and the BIOS release date. Populated when the connected server is Dell hardware and empty otherwise.","min_provider_version":"13.0.0","defaults":"generation","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.ethernetInterface":{"id":"redfish.ethernetInterface","name":"redfish.ethernetInterface","fields":{"fullDuplex":{"name":"fullDuplex","type":"\u0004","is_mandatory":true,"title":"Whether the link runs in full duplex","provider":"go.mondoo.com/mql/providers/redfish"},"interfaceEnabled":{"name":"interfaceEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the interface is administratively enabled","provider":"go.mondoo.com/mql/providers/redfish"},"linkStatus":{"name":"linkStatus","type":"\u0007","is_mandatory":true,"title":"Link state","desc":"One of LinkUp (available for communication on the interface), NoLink (no link or connection detected), or LinkDown (connected but no link detected).","provider":"go.mondoo.com/mql/providers/redfish"},"macAddress":{"name":"macAddress","type":"\u0007","is_mandatory":true,"title":"Currently configured MAC address","provider":"go.mondoo.com/mql/providers/redfish"},"permanentMACAddress":{"name":"permanentMACAddress","type":"\u0007","is_mandatory":true,"title":"Factory assigned permanent MAC address","provider":"go.mondoo.com/mql/providers/redfish"},"speedMbps":{"name":"speedMbps","type":"\u0005","is_mandatory":true,"title":"Negotiated link speed in Mbps","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Network interface","desc":"Network interface reported by a managed system. Covers the MAC addresses, link speed, duplex, and administrative and link state used to inventory server connectivity.","min_provider_version":"13.0.0","defaults":"macAddress linkStatus","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.hpe":{"id":"redfish.hpe","name":"redfish.hpe","fields":{"licenseLabel":{"name":"licenseLabel","type":"\u0007","title":"License edition name, such as iLO Advanced or iLO Standard","provider":"go.mondoo.com/mql/providers/redfish"},"licenseType":{"name":"licenseType","type":"\u0007","title":"License term, such as Perpetual or Evaluation","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"HPE iLO extensions","desc":"HPE-specific management data exposed by HPE Integrated Lights-Out (iLO) controllers, including the installed license edition that governs which management capabilities are available. Populated when the connected server is HPE hardware and empty otherwise.","min_provider_version":"13.0.0","defaults":"licenseLabel licenseType","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.manager":{"id":"redfish.manager","name":"redfish.manager","fields":{"commandShellConnectTypes":{"name":"commandShellConnectTypes","type":"\u0019\u0007","is_mandatory":true,"title":"Transports the command shell accepts, such as SSH, Telnet, or IPMI","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"commandShellEnabled":{"name":"commandShellEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the command shell service is enabled","desc":"The command shell gives an operator a text console on the controller itself. Every console field in this resource is null when the controller does not describe the service, so an audit can tell a console that is switched off apart from one the controller never reports.","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"commandShellMaxConcurrentSessions":{"name":"commandShellMaxConcurrentSessions","type":"\u0005","is_mandatory":true,"title":"Concurrent command shell sessions the controller supports","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"dateTime":{"name":"dateTime","type":"\u0007","is_mandatory":true,"title":"Controller date and time in ISO 8601 format","provider":"go.mondoo.com/mql/providers/redfish"},"firmwareVersion":{"name":"firmwareVersion","type":"\u0007","is_mandatory":true,"title":"Installed controller firmware version","provider":"go.mondoo.com/mql/providers/redfish"},"graphicalConsoleConnectTypes":{"name":"graphicalConsoleConnectTypes","type":"\u0019\u0007","is_mandatory":true,"title":"Transports the graphical console accepts, such as KVMIP or RDP","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"graphicalConsoleEnabled":{"name":"graphicalConsoleEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the graphical console service is enabled","desc":"The graphical console carries keyboard, video, and mouse for the host, which is enough to read the screen of a running operating system or to reinstall it.","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"graphicalConsoleMaxConcurrentSessions":{"name":"graphicalConsoleMaxConcurrentSessions","type":"\u0005","is_mandatory":true,"title":"Concurrent graphical console sessions the controller supports","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"managerType":{"name":"managerType","type":"\u0007","is_mandatory":true,"title":"Kind of controller, such as BMC, EnclosureManager, or Service","provider":"go.mondoo.com/mql/providers/redfish"},"manufacturer":{"name":"manufacturer","type":"\u0007","is_mandatory":true,"title":"Manufacturer of the controller","provider":"go.mondoo.com/mql/providers/redfish"},"model":{"name":"model","type":"\u0007","is_mandatory":true,"title":"Model name","provider":"go.mondoo.com/mql/providers/redfish"},"networkProtocol":{"name":"networkProtocol","type":"\n","title":"Management network services and their enabled state and listening ports","desc":"Deprecated in favor of `redfish.networkProtocols`, which types every field, covers telnet, and reports a protocol the controller does not describe as null rather than as disabled.  The `hostName` and `fqdn` keys carry the controller's network identity. Each of `http`, `https`, `ssh`, `ipmi`, `snmp`, `kvmip`, and `virtualMedia` maps to an object with `enabled` (bool) and `port` (int), letting you audit which out-of-band management protocols are exposed and on which ports (for example flagging cleartext `http`, `snmp`, or `ipmi` that should be disabled).","provider":"go.mondoo.com/mql/providers/redfish","maturity":"deprecated"},"powerState":{"name":"powerState","type":"\u0007","is_mandatory":true,"title":"Current power state of the controller","provider":"go.mondoo.com/mql/providers/redfish"},"serialConsoleConnectTypes":{"name":"serialConsoleConnectTypes","type":"\u0019\u0007","is_mandatory":true,"title":"Transports the serial console accepts, such as SSH, Telnet, or IPMI","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"serialConsoleEnabled":{"name":"serialConsoleEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the serial console service is enabled","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"serialConsoleMaxConcurrentSessions":{"name":"serialConsoleMaxConcurrentSessions","type":"\u0005","is_mandatory":true,"title":"Concurrent serial console sessions the controller supports","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Stable UUID of the controller","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Baseboard management controller","desc":"Out-of-band management controller (the BMC) that operates independently of the host operating system. Covers the controller firmware version, model, power state, and the network services such as SSH, HTTPS, IPMI, SNMP, KVM-IP, and virtual media that it exposes.","min_provider_version":"13.0.0","defaults":"model firmwareVersion","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.memory":{"id":"redfish.memory","name":"redfish.memory","fields":{"capacityMiB":{"name":"capacityMiB","type":"\u0005","is_mandatory":true,"title":"Capacity in mebibytes","provider":"go.mondoo.com/mql/providers/redfish"},"dataWidthBits":{"name":"dataWidthBits","type":"\u0005","is_mandatory":true,"title":"Data bus width in bits","provider":"go.mondoo.com/mql/providers/redfish"},"manufacturer":{"name":"manufacturer","type":"\u0007","is_mandatory":true,"title":"Manufacturer of the module","provider":"go.mondoo.com/mql/providers/redfish"},"memoryDeviceType":{"name":"memoryDeviceType","type":"\u0007","is_mandatory":true,"title":"Device type, such as DDR4 or DDR5","provider":"go.mondoo.com/mql/providers/redfish"},"operatingSpeedMhz":{"name":"operatingSpeedMhz","type":"\u0005","is_mandatory":true,"title":"Operating speed in MHz","provider":"go.mondoo.com/mql/providers/redfish"},"partNumber":{"name":"partNumber","type":"\u0007","is_mandatory":true,"title":"Manufacturer part number","provider":"go.mondoo.com/mql/providers/redfish"},"rankCount":{"name":"rankCount","type":"\u0005","is_mandatory":true,"title":"Number of ranks","provider":"go.mondoo.com/mql/providers/redfish"},"serialNumber":{"name":"serialNumber","type":"\u0007","is_mandatory":true,"title":"Serial number","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Memory module","desc":"Single memory module installed in a managed system. Covers the capacity, device type, operating speed, and manufacturer part and serial numbers used to inventory installed memory.","min_provider_version":"13.0.0","defaults":"capacityMiB memoryDeviceType","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.networkProtocol":{"id":"redfish.networkProtocol","name":"redfish.networkProtocol","fields":{"fqdn":{"name":"fqdn","type":"\u0007","is_mandatory":true,"title":"Fully qualified domain name of the controller","provider":"go.mondoo.com/mql/providers/redfish"},"hostName":{"name":"hostName","type":"\u0007","is_mandatory":true,"title":"Host name of the controller, without domain information","provider":"go.mondoo.com/mql/providers/redfish"},"httpEnabled":{"name":"httpEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the cleartext HTTP interface is enabled","desc":"Every enabled state in this resource is null when the controller does not report the protocol at all, so an audit can tell a protocol that is switched off apart from one the controller does not describe.","provider":"go.mondoo.com/mql/providers/redfish"},"httpPort":{"name":"httpPort","type":"\u0005","is_mandatory":true,"title":"TCP port of the HTTP interface, usually 80","provider":"go.mondoo.com/mql/providers/redfish"},"httpsEnabled":{"name":"httpsEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the HTTPS interface is enabled","provider":"go.mondoo.com/mql/providers/redfish"},"httpsPort":{"name":"httpsPort","type":"\u0005","is_mandatory":true,"title":"TCP port of the HTTPS interface, usually 443","provider":"go.mondoo.com/mql/providers/redfish"},"ipmiEnabled":{"name":"ipmiEnabled","type":"\u0004","is_mandatory":true,"title":"Whether IPMI over LAN is enabled","desc":"IPMI over LAN keeps password hashes retrievable before authentication in the RAKP handshake of IPMI 2.0. An enabled IPMI interface therefore bypasses the account controls that apply to the Redfish interface.","provider":"go.mondoo.com/mql/providers/redfish"},"ipmiPort":{"name":"ipmiPort","type":"\u0005","is_mandatory":true,"title":"UDP port of the IPMI over LAN interface, usually 623","provider":"go.mondoo.com/mql/providers/redfish"},"kvmipEnabled":{"name":"kvmipEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the KVM over IP console is enabled","provider":"go.mondoo.com/mql/providers/redfish"},"kvmipPort":{"name":"kvmipPort","type":"\u0005","is_mandatory":true,"title":"TCP port of the KVM over IP console","provider":"go.mondoo.com/mql/providers/redfish"},"snmpEnabled":{"name":"snmpEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the SNMP agent is enabled","provider":"go.mondoo.com/mql/providers/redfish"},"snmpPort":{"name":"snmpPort","type":"\u0005","is_mandatory":true,"title":"UDP port of the SNMP agent, usually 161","provider":"go.mondoo.com/mql/providers/redfish"},"sshEnabled":{"name":"sshEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the SSH interface is enabled","provider":"go.mondoo.com/mql/providers/redfish"},"sshPort":{"name":"sshPort","type":"\u0005","is_mandatory":true,"title":"TCP port of the SSH interface, usually 22","provider":"go.mondoo.com/mql/providers/redfish"},"telnetEnabled":{"name":"telnetEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the telnet interface is enabled","desc":"Telnet carries credentials in cleartext and has no host authentication. An enabled telnet interface bypasses the controls that guard the Redfish and SSH paths.","provider":"go.mondoo.com/mql/providers/redfish"},"telnetPort":{"name":"telnetPort","type":"\u0005","is_mandatory":true,"title":"TCP port of the telnet interface, usually 23","provider":"go.mondoo.com/mql/providers/redfish"},"virtualMediaEnabled":{"name":"virtualMediaEnabled","type":"\u0004","is_mandatory":true,"title":"Whether virtual media is enabled","desc":"Virtual media lets the controller attach a remote image as a local drive, which supplies a boot source that the host operating system cannot see.","provider":"go.mondoo.com/mql/providers/redfish"},"virtualMediaPort":{"name":"virtualMediaPort","type":"\u0005","is_mandatory":true,"title":"TCP port of the virtual media service","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Management network protocol settings","desc":"Network protocols that a management controller exposes, with the enabled state and the listening port of each one. Covers the protocols that carry out-of-band access to the server, so an audit can flag cleartext or legacy paths such as telnet, IPMI over LAN, SNMP, and plain HTTP.","min_provider_version":"13.0.7","defaults":"hostName ipmiEnabled telnetEnabled","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.processor":{"id":"redfish.processor","name":"redfish.processor","fields":{"instructionSet":{"name":"instructionSet","type":"\u0007","is_mandatory":true,"title":"Instruction set, such as x86-64 or ARM-A64","provider":"go.mondoo.com/mql/providers/redfish"},"manufacturer":{"name":"manufacturer","type":"\u0007","is_mandatory":true,"title":"Manufacturer of the processor","provider":"go.mondoo.com/mql/providers/redfish"},"maxSpeedMHz":{"name":"maxSpeedMHz","type":"\u0005","is_mandatory":true,"title":"Maximum clock speed in MHz","provider":"go.mondoo.com/mql/providers/redfish"},"model":{"name":"model","type":"\u0007","is_mandatory":true,"title":"Model name","provider":"go.mondoo.com/mql/providers/redfish"},"processorType":{"name":"processorType","type":"\u0007","is_mandatory":true,"title":"Kind of processor, such as CPU, GPU, or FPGA","provider":"go.mondoo.com/mql/providers/redfish"},"socket":{"name":"socket","type":"\u0007","is_mandatory":true,"title":"Socket the processor occupies","provider":"go.mondoo.com/mql/providers/redfish"},"totalCores":{"name":"totalCores","type":"\u0005","is_mandatory":true,"title":"Number of physical cores","provider":"go.mondoo.com/mql/providers/redfish"},"totalThreads":{"name":"totalThreads","type":"\u0005","is_mandatory":true,"title":"Number of hardware threads","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Processor","desc":"Single processor installed in a managed system. Covers the manufacturer, model, socket, instruction set, and the core and thread counts used to inventory compute capacity.","min_provider_version":"13.0.0","defaults":"model totalCores","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.session":{"id":"redfish.session","name":"redfish.session","fields":{"clientOriginIPAddress":{"name":"clientOriginIPAddress","type":"\u0007","is_mandatory":true,"title":"IP address of the client that opened the session","provider":"go.mondoo.com/mql/providers/redfish"},"createdTime":{"name":"createdTime","type":"\t","is_mandatory":true,"title":"Time the session was created","provider":"go.mondoo.com/mql/providers/redfish"},"expirationTime":{"name":"expirationTime","type":"\t","is_mandatory":true,"title":"Time the session expires regardless of activity","desc":"Null when the session does not expire on an absolute time.","provider":"go.mondoo.com/mql/providers/redfish"},"roles":{"name":"roles","type":"\u0019\u0007","is_mandatory":true,"title":"Redfish roles that carry the privileges of the session","provider":"go.mondoo.com/mql/providers/redfish"},"sessionType":{"name":"sessionType","type":"\u0007","is_mandatory":true,"title":"Kind of session, such as Redfish, HostConsole, or IPMI","provider":"go.mondoo.com/mql/providers/redfish"},"userName":{"name":"userName","type":"\u0007","is_mandatory":true,"title":"Account that opened the session","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Redfish session","desc":"Session that is currently open on the management controller. Covers the account that opened it, the client address, and the timestamps, so an audit can review who holds live out-of-band access.","min_provider_version":"13.0.7","defaults":"userName clientOriginIPAddress","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.sessionService":{"id":"redfish.sessionService","name":"redfish.sessionService","fields":{"absoluteSessionTimeout":{"name":"absoluteSessionTimeout","type":"\u0005","title":"Maximum lifetime in seconds of a session, regardless of activity","provider":"go.mondoo.com/mql/providers/redfish"},"absoluteSessionTimeoutEnabled":{"name":"absoluteSessionTimeoutEnabled","type":"\u0004","title":"Whether the service applies the absolute session lifetime","provider":"go.mondoo.com/mql/providers/redfish"},"serviceEnabled":{"name":"serviceEnabled","type":"\u0004","title":"Whether the session service accepts new sessions","provider":"go.mondoo.com/mql/providers/redfish"},"sessionTimeout":{"name":"sessionTimeout","type":"\u0005","title":"Idle time in seconds after which the service closes a session","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Session service","desc":"Service that issues and tracks Redfish sessions on the management controller. Covers whether the service accepts new sessions and how long an idle or long-lived session stays open, so an audit can require that stale management sessions close. Every field is null when the controller exposes no session service, so an audit can tell an unsupported controller apart from one that reports a disabled service or an unlimited timeout.","min_provider_version":"13.0.7","defaults":"serviceEnabled sessionTimeout","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.softwareInventory":{"id":"redfish.softwareInventory","name":"redfish.softwareInventory","fields":{"lowestSupportedVersion":{"name":"lowestSupportedVersion","type":"\u0007","is_mandatory":true,"title":"Lowest version the component can be downgraded to","provider":"go.mondoo.com/mql/providers/redfish"},"manufacturer":{"name":"manufacturer","type":"\u0007","is_mandatory":true,"title":"Manufacturer of the component","provider":"go.mondoo.com/mql/providers/redfish"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the component","provider":"go.mondoo.com/mql/providers/redfish"},"releaseDate":{"name":"releaseDate","type":"\u0007","is_mandatory":true,"title":"Release date of the installed version","provider":"go.mondoo.com/mql/providers/redfish"},"softwareId":{"name":"softwareId","type":"\u0007","is_mandatory":true,"title":"Vendor assigned software identifier","provider":"go.mondoo.com/mql/providers/redfish"},"updateable":{"name":"updateable","type":"\u0004","is_mandatory":true,"title":"Whether the component can be updated through the service","provider":"go.mondoo.com/mql/providers/redfish"},"version":{"name":"version","type":"\u0007","is_mandatory":true,"title":"Installed version","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Firmware or software inventory item","desc":"Firmware or software component tracked by the update service. Covers the component version, manufacturer, release date, and whether it can be updated, used to audit firmware levels against known-vulnerable releases.","min_provider_version":"13.0.0","defaults":"name version","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.supermicro":{"id":"redfish.supermicro","name":"redfish.supermicro","fields":{"ipAccessControlEnabled":{"name":"ipAccessControlEnabled","type":"\u0004","title":"Whether the controller filters management access by source address","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"ipAccessControlRules":{"name":"ipAccessControlRules","type":"\u0019\n","title":"Source address filter rules","desc":"One entry per rule, with the keys `address`, `prefixLength`, and `policy` (Allow or Deny). Empty when the controller reports no rule, which leaves the management interface reachable from every source that can route to it.","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"kcsPrivilege":{"name":"kcsPrivilege","type":"\u0007","title":"Privilege level granted over the host side KCS interface","desc":"One of Administrator, Operator, User, or Callback. The KCS interface is reachable from the host operating system with no credential at all, so Administrator there lets any process running as root on the host create controller accounts and reach the out-of-band network.","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"licenses":{"name":"licenses","type":"\u0019\u0007","title":"Activated license keys, such as SFT-DCMS-Single","provider":"go.mondoo.com/mql/providers/redfish"},"ntpEnabled":{"name":"ntpEnabled","type":"\u0004","title":"Whether the controller synchronizes its clock over NTP","desc":"A controller with no time source stamps its event log from a clock that drifts, which breaks the ordering that an incident review depends on.","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"ntpPrimaryServer":{"name":"ntpPrimaryServer","type":"\u0007","title":"Primary NTP server the controller synchronizes with","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"ntpSecondaryServer":{"name":"ntpSecondaryServer","type":"\u0007","title":"Secondary NTP server the controller synchronizes with","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"radiusEnabled":{"name":"radiusEnabled","type":"\u0004","title":"Whether the controller authenticates users against a RADIUS server","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"radiusPort":{"name":"radiusPort","type":"\u0005","title":"Port of the RADIUS server","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"radiusServer":{"name":"radiusServer","type":"\u0007","title":"Address of the RADIUS server","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"rakpEnabled":{"name":"rakpEnabled","type":"\u0004","title":"Whether the controller answers the IPMI RAKP key exchange","desc":"RAKP is the authentication handshake of IPMI 2.0, and it returns a salted password hash for any valid user name before the caller has proven anything. Supermicro exposes a switch for it that is separate from the IPMI interface itself, so a controller can leave IPMI enabled with the handshake closed.","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"syslogEnabled":{"name":"syslogEnabled","type":"\u0004","title":"Whether the controller forwards its event log to a syslog server","desc":"A controller with no syslog destination keeps its security event log in local storage only, so the record of who opened a console or reset the host does not survive the next reboot.","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"syslogServers":{"name":"syslogServers","type":"\u0019\n","title":"Syslog destinations the controller forwards to","desc":"One entry per configured destination, with the keys `host` and `port`. Firmware older than Gen 13 1.10 and Gen 14 1.08 reports a single destination, which appears here as a list of one. Empty when the controller reports no destination.","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"systemLockdownEnabled":{"name":"systemLockdownEnabled","type":"\u0004","title":"Whether BMC system lockdown mode is enabled","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Supermicro BMC extensions","desc":"Supermicro-specific management data exposed by the controller. Covers the activated node-management licenses that unlock Redfish capabilities, system lockdown mode, and the hardening settings that Supermicro keeps outside the standard Redfish resources: the IPMI RAKP key exchange, the host side KCS interface, source address filtering, and the RADIUS, NTP, and syslog servers the controller talks to. Populated when the connected server is Supermicro hardware and empty otherwise. The RAKP, KCS, access control, RADIUS, NTP and syslog fields are null when the controller exposes no setting of that kind, so an audit can tell a setting that is switched off apart from one the controller never reports. In that same case `licenses` reports an empty list and `systemLockdownEnabled` reports false.","min_provider_version":"13.0.0","defaults":"systemLockdownEnabled rakpEnabled","provider":"go.mondoo.com/mql/providers/redfish"},"redfish.system":{"id":"redfish.system","name":"redfish.system","fields":{"biosVersion":{"name":"biosVersion","type":"\u0007","is_mandatory":true,"title":"Installed BIOS or UEFI firmware version","provider":"go.mondoo.com/mql/providers/redfish"},"bootSourceOverrideEnabled":{"name":"bootSourceOverrideEnabled","type":"\u0007","is_mandatory":true,"title":"Boot source override state, one of Disabled, Once, or Continuous","desc":"Continuous is the value that matters for an audit. It keeps the system on the overridden boot source across every reset, so a network or removable boot source stays active until an operator clears it.","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"bootSourceOverrideMode":{"name":"bootSourceOverrideMode","type":"\u0007","is_mandatory":true,"title":"Firmware mode the override boots in, either Legacy or UEFI","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"bootSourceOverrideTarget":{"name":"bootSourceOverrideTarget","type":"\u0007","is_mandatory":true,"title":"Boot source that the override selects, such as Pxe, Usb, Hdd, or None","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"ethernetInterfaces":{"name":"ethernetInterfaces","type":"\u0019\u001bredfish.ethernetInterface","title":"Network interfaces attached to the system","provider":"go.mondoo.com/mql/providers/redfish"},"hostName":{"name":"hostName","type":"\u0007","is_mandatory":true,"title":"Configured host name","provider":"go.mondoo.com/mql/providers/redfish"},"manufacturer":{"name":"manufacturer","type":"\u0007","is_mandatory":true,"title":"Hardware manufacturer","provider":"go.mondoo.com/mql/providers/redfish"},"memory":{"name":"memory","type":"\u0019\u001bredfish.memory","title":"Installed memory modules","provider":"go.mondoo.com/mql/providers/redfish"},"model":{"name":"model","type":"\u0007","is_mandatory":true,"title":"Model name","provider":"go.mondoo.com/mql/providers/redfish"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the system","provider":"go.mondoo.com/mql/providers/redfish"},"persistentBootOverride":{"name":"persistentBootOverride","type":"\u0004","is_mandatory":true,"title":"Whether a boot source override is set to persist across resets","desc":"True when the override state is Continuous and the target is a real boot source rather than None. A persistent override to Pxe or Usb lets anyone who controls the network or the virtual media device supply the operating system on every boot.","min_provider_version":"13.0.7","provider":"go.mondoo.com/mql/providers/redfish"},"powerState":{"name":"powerState","type":"\u0007","is_mandatory":true,"title":"Current power state, such as On, Off, or PoweringOn","provider":"go.mondoo.com/mql/providers/redfish"},"processors":{"name":"processors","type":"\u0019\u001bredfish.processor","title":"Installed processors","provider":"go.mondoo.com/mql/providers/redfish"},"secureBootCurrentBoot":{"name":"secureBootCurrentBoot","type":"\u0007","title":"Secure Boot state of the boot cycle that is running","desc":"One of Enabled or Disabled. This is what the firmware actually enforced on the current boot, which differs from the configured state when the setting changed since the last reset. Null when the system exposes no Secure Boot resource or the controller does not report the value.","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"secureBootEnabled":{"name":"secureBootEnabled","type":"\u0004","title":"Whether UEFI Secure Boot is enabled","desc":"Null when the system does not expose a Secure Boot resource or the controller cannot report its state, so an audit can tell an unsupported or unreachable system apart from one where Secure Boot is switched off.","provider":"go.mondoo.com/mql/providers/redfish"},"secureBootMode":{"name":"secureBootMode","type":"\u0007","title":"Secure Boot key management mode","desc":"One of SetupMode, UserMode, AuditMode, or DeployedMode. SetupMode is the value that matters for an audit. The firmware enrolls any key presented to it while in Setup Mode, so a system that reports Secure Boot as enabled still accepts an attacker supplied platform key. Null when the system exposes no Secure Boot resource or the controller does not report the mode.","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"serialNumber":{"name":"serialNumber","type":"\u0007","is_mandatory":true,"title":"Serial number","provider":"go.mondoo.com/mql/providers/redfish"},"sku":{"name":"sku","type":"\u0007","is_mandatory":true,"title":"Stock keeping unit","provider":"go.mondoo.com/mql/providers/redfish"},"systemType":{"name":"systemType","type":"\u0007","is_mandatory":true,"title":"Kind of system, such as Physical, Virtual, OS, or PhysicallyPartitioned","provider":"go.mondoo.com/mql/providers/redfish"},"trustedModules":{"name":"trustedModules","type":"\u0019\n","is_mandatory":true,"title":"Trusted Platform Modules installed in the system","desc":"One entry per installed module, with the keys `interfaceType` (TPM1_2, TPM2_0, or TCM1_0), `interfaceTypeSelection`, `firmwareVersion`, `firmwareVersion2`, `health`, and `state`. An empty list means the system reports no trusted module, so an audit can require that a TPM 2.0 is present and healthy before trusting measured boot or a disk encryption key sealed to it.","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/redfish"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Stable UUID of the system","provider":"go.mondoo.com/mql/providers/redfish"}},"title":"Managed computer system","desc":"Compute node managed through the controller. Covers identity such as the UUID, model, and serial number, along with the firmware level, power state, UEFI Secure Boot status, and the installed processors, memory modules, and network interfaces.","min_provider_version":"13.0.0","defaults":"model powerState","provider":"go.mondoo.com/mql/providers/redfish"}},"dependencies":{"core":{"id":"go.mondoo.com/mql/providers/core","name":"core"}},"provider_roots":{"go.mondoo.com/mql/providers/redfish":"redfish"}}