BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//talks.osfc.io//osfc-2026//speaker//GZMHPB
BEGIN:VTIMEZONE
TZID:Europe/Berlin
BEGIN:DAYLIGHT
DTSTART:20250915T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Automated Bare-Metal Remediation: Closing the Zero-Trust Loop with
  Staged Firmware Sanitization - Nnamdi Ajah\, Giovanni Zantedeschi
DTSTART;TZID=Europe/Berlin:20260915T163500
DTEND;TZID=Europe/Berlin:20260915T170500
DTSTAMP:20260817T081557Z
UID:pretalx-osfc-2026-LE99ND@talks.osfc.io
DESCRIPTION:At hyperscale\, detecting a firmware compromise is a solved pr
 oblem\; recovering from it is not. While Static Root-of-Trust Measurement 
 (SRTM) provides reliable platform measurement\, responding to a Secure Boo
 t compliance breach typically results in a dead node awaiting manual inter
 vention. Standard OS-level tools are blocked by System Management Mode\, S
 MM\,  runtime locks\, and proprietary out-of-band BMC APIs are too fragmen
 ted across heterogeneous fleets to provide a unified\, automated recovery 
 pipeline.\nWe introduce a self-healing firmware state machine designed to 
 bridge the gap between attestation and active remediation without distribu
 ting a powerful\, portable signed key-clearing payload across the fleet. B
 y delivering a custom EFI application via iPXE during the Boot Device Sele
 ction (BDS) phase\, infrastructure control planes can evaluate a node's ha
 rdware compliance strictly in-band. Upon detecting unauthorized state drif
 t\, the application stages a vendor-agnostic\, BDS-staged UEFI variable\, 
 `StageOptimzedDefaults`.\nThis architecture circumvents runtime firmware c
 onstraints without violating the platform's security boundary. Together wi
 th our OEM hardware partners\, we are currently adapting this mechanism\, 
 and are bringing this approach to OSFC for feedback.
LOCATION:Main
URL:https://talks.osfc.io/osfc-2026/talk/LE99ND/
END:VEVENT
END:VCALENDAR
