Our BMCs are not great at keeping accurate time
utcc.utoronto.ca
utcc.utoronto.ca
If you weren't previously using NTP with your BMC, then that might suggest you haven't put enough time and attention in to your configurations.
If you're not already keeping your BMCs from talking to the Internet, then you really, really should, as soon as you can.
> not all vendors include NTP as a free feature on all of their BMCs. Charging licensing costs for some features is a good way to insure that we don't use them, unless the licensing cost is trivial (which, spoiler, it hasn't been when we asked
If you assume something will get remote execution on your BMC, it's likely going to get full access to the BMC, because no updates. Then, what does your BMC have access to? DMA to the host, ability to monitor and trigger lots of exciting things, etc. It's pretty scary if you think about it, but IPMI replaces serial concentrators and remote access PDUs with zero rack space and not much security, so yay?
Most vendors are indeed running Linux. For example, HPE iLO 5 is capable of starting smart storage administrator from bios, and when doing so it just launches some flavor of centos, launches SSA server then starts an antediluvian build of Firefox pointing to it.
I wouldn't be surprised to learn that the chip serving iLO was Linux too.
The industry has really build around 2 vendors for chips, and two vendors for software solutions for those chips, AMI and Insyde. These systems are generally pretty locked dow , but there are was to get to the Linux core(sometimes serial headers).
All we ever use in practice would be covered by dropbox/opensshd on a minimal rootfs with a shell where we can (presumably) toggle GPIOs through sysfs to power on/off/reset and interact with the serial console over a tty. This is almost certainly what the horrible manufacturer interfaces already build on top of.
But as far as I know, the damn things only accept signed images and aren't easily stripped down and replaced like this?
Also companies like Raptor Computing, Facebook and others are creating open BMCs people can use.
A more than a decade old BMCs based on Aspeed 20xx had the NTP baked in. Because you know, it's already running Linux there.
I don't remember on hw/os ancient iLOs/iDRACs were running on, but they had NTP client too.
I'd say everything newer than 2010 should already have NTP client.
While this is a true statement, I don't remember NTP client being on this list.
SuperMicro only wants a license for a online BIOS update, HP/HPE wants money for iKVM to a running OS[0] and some features making sense only in enterprise environments, like AD integrations and Dell's iDRAC... well I haven't used iDRAC without aN Ent. license for a decade, so I can't bet my $5 on the feature set.
Overall, most BMC implementations does have NTP client free of charge.
[0] You can have any time you need to install OS. You have a one or two minute limit in already running OS. Enough to for the troubleshooting.
See table here: https://www.dell.com/support/manuals/en-us/idrac8-lifecycle-...
Who else provides licenses for features?
Every enterprise grade hardware provider as far as I am aware.
I'm not aware of anyone charging for it, either.