Automatic creation method and system for BMC user of server and storage medium

By parsing configuration files and using multi-threading technology to batch execute BMC user creation tasks, the problems of inefficiency of traditional configuration methods and lack of automatic retry mechanisms are solved, efficient and automated BMC user configuration is achieved, and the security and stability of the server system are improved.

CN119960855AInactive Publication Date: 2025-05-09POWERLEADER COMPUTER SYST CO LTD

Patent Information

Application Number
CN202510442945.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-10
Publication Date
2025-05-09
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The traditional BMC user configuration method is inefficient and prone to human errors, resulting in inconsistent configuration and error in permission allocation, affecting the security and stability of the server system. Especially when facing large-scale servers, the lack of automatic retry mechanism leads to failure of configuration operations.

Method used

By reading configuration files, parsing and extracting server information, BMC login credential information, configuration information, etc., using multi-threading technology or multi-process technology to batch execute BMC user creation tasks and permission configuration operations, and log error logs when failure and generate retry instructions to achieve an automatic retry mechanism.

Benefits of technology

It improves the automation and efficiency of BMC user creation, reduces human configuration errors, enhances configuration accuracy and consistency, ensures the security and stability of the server system, and is suitable for server configuration requirements in large-scale data centers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119960855A_ABST
    Figure CN119960855A_ABST
Patent Text Reader

Abstract

The invention relates to an automatic creating method and system for a BMC user of a server and a storage medium. The method comprises the steps that a configuration file is read; performing content analysis processing on the configuration file to obtain BMC information of each server, a to-be-created BMC user list, permission configuration information and retry mechanism configuration information; establishing a log file to record an automatic creation process of a BMC user of the server; in response to an ipmitool command, executing BMC user creation tasks and permission configuration operations in batches through a multi-thread technology or a multi-process technology; if the execution of the ipmitool command fails, recording an error log in the log file and generating an ipmitool command retry instruction; and in response to the ipmitool command retry instruction, entering a retry mechanism, re-executing the ipmitool command, and when the execution failure times of the ipmitool command reach the preset retry times, ending the current BMC user creation task, and executing the next BMC user creation task. According to the invention, the automation degree and the creation efficiency of the BMC user creation of the server are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of BMC of a server, and in particular to a method, system and storage medium for automatically creating a BMC user of a server. Background Art

[0002] With the rapid development of information technology and the popularization of cloud computing, big data, artificial intelligence and other technologies, data centers have become the core infrastructure of modern enterprises and various organizations. The construction and management of data centers require a large amount of computing and storage resources, usually consisting of hundreds or even thousands of servers.

[0003] BMC is an independent hardware used to remotely manage server hardware and monitor the health status of server systems. It interacts with the server host through an independent control channel, allowing administrators to perform tasks such as power control, hardware monitoring, and operating system installation without directly accessing the server itself. With the continuous expansion of the scale of data centers, the number of BMC users has increased dramatically. How to efficiently and batch-manage these BMC users has become an important issue facing operation and maintenance personnel. In the related art, the traditional BMC user configuration method is mostly done by operation and maintenance personnel through IPMI tools or proprietary BMC management software, connecting to each server one by one, and manually performing operations such as user creation, password setting, and permission configuration. This method is not only inefficient, but also easily affected by human errors, resulting in inconsistent configurations, incorrect permission allocation, and other problems, thereby reducing the accuracy of BMC configuration. In addition, when facing hundreds or thousands of servers, tasks such as batch creation, modification, deletion, and permission setting of a large number of BMC users may encounter command execution failures, network problems, etc. during the configuration process. The traditional manual configuration method does not have an effective automatic retry mechanism, resulting in configuration operation failures, thereby affecting the security and stability of the server system. Therefore, the traditional manual operation method can no longer meet the needs of large-scale BMC user configuration operations. Summary of the invention

[0004] The present invention provides a method, system and storage medium for automatically creating a BMC user of a server, aiming to solve at least one of the technical problems existing in the prior art.

[0005] The technical solution of the present invention is a method, system and storage medium for automatically creating a BMC user of a server, which includes: S100: Read a configuration file, where the configuration file includes server information, BMC login credential information, and configuration information; S200: performing content parsing processing on the configuration file to obtain BMC information of each server, a list of BMC users to be created, permission configuration information, and retry mechanism configuration information; S300: creating a log file and initializing the log file to record the automated creation process of the BMC user of the server; S400: In response to the ipmitool command, executing BMC user creation tasks and permission configuration operations in batches according to the list of BMC users to be created and the permission configuration information through multi-threading technology or multi-process technology; S500: Check the execution result of the ipmitool command. If the execution of the ipmitool command fails, record an error log in the log file and generate an ipmitool command retry instruction; S600: Entering a retry mechanism in response to the ipmitool command retry instruction, re-executing the ipmitool command, and when the number of failed executions of the ipmitool command reaches a preset number of retries, ending the current BMC user creation task and executing the next BMC user creation task.

[0006] According to some embodiments of the present invention, the ipmitool command includes an ipmitool user set name command, an ipmitool user set password command, and an ipmitool user priv command, and the step S400 includes: S410: Determine BMC user information to be created for each server according to the BMC user list to be created, wherein the BMC user information includes a BMC user name, a BMC password, and an authority level; S420: Create a BMC user through the ipmitool user set name command; S430: Setting a password for the BMC user by using the ipmitool user set password command; S440: Setting the permission level of the BMC user through the ipmitool user priv command.

[0007] According to some embodiments of the present invention, step S500 includes: S510: Check the execution result of the ipmitool command; S520: If the ipmitool command fails to be executed, the timestamp, log level, and operation failure type of the current BMC user's failure to create the task are recorded in the log file; S530: If the ipmitool command is executed successfully, the successful execution of the current BMC user creation task is recorded in the log file, and the next BMC user creation task is executed.

[0008] According to some embodiments of the present invention, the retry mechanism configuration information includes a preset retry time, and the step S600 includes: S610: After entering the retry mechanism, the ipmitool command is automatically executed according to the preset number of retries; S620: When the ipmitool command execution fails, wait for a preset retry time before executing the next ipmitool command, until the number of automatic executions of the ipmitool command reaches the preset retry number or until the ipmitool command is successfully executed, end the current BMC user creation task, and execute the next BMC user creation task.

[0009] According to some embodiments of the present invention, the method further comprises: S401: Implementing multi-thread technology or multi-process technology to batch execute the BMC user creation task of each server through ThreadPoolExecutor or ProcessPoolExecutor; S402: Setting the maximum concurrent number of the multi-threading technology and the multi-process technology to control the load.

[0010] According to some embodiments of the present invention, the method further comprises: S210: Determine whether the configuration file includes the IP address information of each server, the BMC user name, the BMC password, the BMC user list to be created, the permission configuration information and the retry mechanism configuration information, so as to determine the validity of the configuration file; S220: If the configuration file is valid, generate a BMC user creation task instruction; S230: If the configuration file is invalid, output an error warning and terminate the BMC user creation task.

[0011] According to some embodiments of the present invention, the method further comprises: S700: deploying a firewall security anti-tampering mechanism on the log file; S710: Setting an access control list through the firewall security anti-tampering mechanism to allow only a specific IP range or subnet to access the BMC interface of the server; S720: Configure a whitelist policy to allow only authenticated trusted IP segments to access the server's BMC interface; S730: Start the deep packet inspection function of the firewall security anti-tampering mechanism to detect the traffic passing through the BMC interface of the server and identify and filter out abnormal traffic; S740: Upload the abnormal traffic events and abnormal access events to the log file, and issue an error alarm prompt.

[0012] According to some embodiments of the present invention, the method further comprises: S750: deploying an intrusion detection mechanism and an intrusion prevention mechanism in the log file; S760: Monitor and analyze access from the external network through the intrusion detection mechanism, record potential malicious traffic and send it to the intrusion prevention mechanism; S770: When the intrusion prevention mechanism detects malicious traffic, malicious behavior is determined based on the malicious traffic, and the attack source of the malicious behavior is blocked.

[0013] The technical solution of the present invention also relates to an automatic creation system of a BMC user of a server, which is applied to the method described in the above embodiment and comprises: A reading module is used to read a configuration file, wherein the configuration file includes server information, BMC login credential information, and configuration information; A parsing module, used for parsing the configuration file to obtain BMC information of each server, a list of BMC users to be created, permission configuration information and retry mechanism configuration information; A log module, used to create a log file and initialize the log file to record the automated creation process of the BMC user of the server; A task processing module, for responding to an ipmitool command, and executing BMC user creation tasks and permission configuration operations in batches according to the BMC user list to be created and the permission configuration information through multi-threading technology or multi-process technology; A proofreading module, used to check the execution result of the ipmitool command, and if the ipmitool command fails to execute, record an error log in the log file and generate an ipmitool command retry instruction; The task retry module is used to enter the retry mechanism in response to the ipmitool command retry instruction, re-execute the ipmitool command, and when the number of ipmitool command execution failures reaches a preset number of retries, end the current BMC user creation task and execute the next BMC user creation task.

[0014] The technical solution of the present invention also relates to a computer device, comprising a memory and a processor, wherein the processor implements the above method when executing a computer program stored in the memory.

[0015] The technical solution of the present invention also relates to a computer-readable storage medium on which computer program instructions are stored, and the computer program instructions implement the above method when executed by a processor.

[0016] The method, system and storage medium for automatically creating a BMC user of a server provided by an embodiment of the present invention have at least one of the following advantages or beneficial effects: reading a configuration file, the configuration file includes server information, BMC login credential information, and configuration information, realizing automatic extraction of key configuration information, parsing and structuring the configuration file to obtain the BMC information of each server, the list of BMC users to be created, the permission configuration information and the retry mechanism configuration information, providing a clear data basis for the subsequent automatic creation of BMC users, and performing preliminary verification of the content of the configuration file during the parsing process, timely discovering errors or incomplete information in the configuration file, avoiding subsequent operation failures or abnormalities due to configuration errors, thereby improving the accuracy of the automatic creation of BMC users. A log file is established and initialized, and the automatic creation process of the BMC user of the server is recorded through the log file, which facilitates auditing and backtracking of the operation process, speeds up troubleshooting and repair, and improves the maintainability of the server system. In response to the ipmitool command, the creation tasks and permission configuration operations of multiple BMC users are processed in parallel through multi-threading technology or multi-process technology, which greatly improves the efficiency of creating BMC users and meets the configuration requirements of BMC users of servers in large-scale data centers. It is determined whether the ipmitool command is executed successfully to improve the reliability of the automatic creation of BMC users. If the ipmitool command execution fails, the error information is recorded in the log file, providing detailed error records for the operation and maintenance personnel, and generating an ipmitool command retry instruction. The retry mechanism is entered through the retry instruction to automatically re-execute the ipmitool command without manual intervention, thereby improving the automation of BMC user creation. The retry is automatically performed according to the preset retry mechanism configuration information to improve the success rate of BMC user creation. When the number of ipmitool command execution failures reaches the preset number of retries, the current BMC user creation task is terminated and the next BMC user creation task is executed, thereby avoiding infinite retries when an unsolvable error is encountered during the BMC user creation task and falling into an invalid loop operation that causes resource waste. When the number of retries reaches the preset number of retries, the current BMC user creation task is terminated. Even if the current task fails, the next BMC user creation task will continue to be executed, thereby ensuring the continuity of the entire batch BMC user creation task and permission configuration operation, ensuring that other tasks are not affected by the failure of the current task, and improving the overall work efficiency of the automatic creation of BMC users of the server.

[0017] In addition, additional aspects and advantages of the present invention will be given in part in the following description, and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 It is an overall flow chart of a method for automatically creating a BMC user of a server provided by an embodiment of the present invention; Figure 2 is a detailed flow chart of step S400 in the method for automatically creating a BMC user of a server provided in an embodiment of the present invention; Figure 3 is a detailed flow chart of step S500 in the method for automatically creating a BMC user of a server provided in an embodiment of the present invention; Figure 4 is a detailed flow chart of step S600 in the method for automatically creating a BMC user of a server provided in an embodiment of the present invention; Figure 5 It is a detailed flow chart of the method for automatically creating a BMC user of a first server provided by an embodiment of the present invention; Figure 6 is a detailed flow chart of the method for automatically creating a BMC user of a second server provided by an embodiment of the present invention; Figure 7 is a detailed flow chart of the method for automatically creating a BMC user of a third server provided by an embodiment of the present invention; Figure 8 It is a structural diagram of an automatic creation system of a BMC user of a server provided by an embodiment of the present invention; Fig. 9 It is a structural schematic diagram of a computer device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0019] The concept, specific structure and technical effects of the present invention will be clearly and completely described below in combination with the embodiments and drawings to fully understand the purpose, scheme and effect of the present invention.

[0020] It should be noted that, unless otherwise specified, when a feature is referred to as being "fixed" or "connected" to another feature, it may be directly fixed or connected to another feature, or it may be indirectly fixed or connected to another feature. The singular forms "a", "said" and "the" used herein are also intended to include the plural forms, unless the context clearly indicates otherwise. In addition, unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art. The terms used in this specification are intended only to describe specific embodiments and are not intended to limit the invention. The term "and / or" used herein includes any combination of one or more of the related listed items.

[0021] It should be understood that, although the term first, second, third etc. may be adopted to describe various elements in the present disclosure, these elements should not be limited to these terms. These terms are only used to distinguish the same type of elements from each other. For example, without departing from the scope of the present disclosure, the first element may also be referred to as the second element, and similarly, the second element may also be referred to as the first element. The use of any and all examples or exemplary language ("for example", "such as" etc.) provided herein is only intended to better illustrate embodiments of the present invention, and unless otherwise required, will not impose limitations on the scope of the present invention.

[0022] BMC is an independent hardware used to remotely manage server hardware and monitor the health status of server systems. It interacts with the server host through an independent control channel, allowing administrators to perform tasks such as power control, hardware monitoring, and operating system installation without directly accessing the server itself. With the continuous expansion of the scale of data centers, the number of BMC users has increased dramatically. How to efficiently and batch-manage these BMC users has become an important issue facing operation and maintenance personnel. In the related art, the traditional BMC user configuration method is mostly done by operation and maintenance personnel through IPMI tools or proprietary BMC management software, connecting to each server one by one, and manually performing operations such as user creation, password setting, and permission configuration. This method is not only inefficient, but also easily affected by human errors, resulting in inconsistent configurations, incorrect permission allocation, and other problems, thereby reducing the accuracy of BMC configuration. In addition, when facing hundreds or thousands of servers, tasks such as batch creation, modification, deletion, and permission setting of a large number of BMC users may encounter command execution failures, network problems, etc. during the configuration process. The traditional manual configuration method does not have an effective automatic retry mechanism, resulting in configuration operation failures, thereby affecting the security and stability of the server system. Therefore, the traditional manual operation method can no longer meet the needs of large-scale BMC user configuration operations.

[0023] Based on this, the embodiments of the present invention provide a method, system and storage medium for automatically creating BMC users of a server, which are conducive to improving the automation level and creation efficiency of BMC user creation of the server, eliminating the need for manual configuration, reducing human configuration errors and thus improving the accuracy of BMC configuration. In addition, by batch executing BMC user creation tasks and permission configuration operations through multi-threading technology or multi-process technology, the creation efficiency of BMC users of the server is further improved, and the method is suitable for configuration operations of BMC users of servers in large-scale data centers.

[0024] Please refer to the following Figures 1 to 9 The method, system and storage medium for automatically creating a BMC user of a server provided in an embodiment of the present invention are further described.

[0025] Reference Figure 1As shown, Figure 1 1 is a general flow chart of a method for automatically creating a BMC user of a server provided by an embodiment of the present invention. The method for automatically creating a BMC user of a server includes but is not limited to steps S100 to S600. Specifically, S100: Read a configuration file, which includes server information, BMC login credential information, and configuration information; S200: parsing the configuration file to obtain BMC information of each server, a list of BMC users to be created, permission configuration information, and retry mechanism configuration information; S300: creating a log file and initializing the log file to record the automatic creation process of the BMC user of the server; S400: In response to the ipmitool command, batch execute BMC user creation tasks and permission configuration operations according to the list of BMC users to be created and permission configuration information through multi-threading technology or multi-process technology; S500: Check the execution result of the ipmitool command. If the execution of the ipmitool command fails, record the error log in the log file and generate an ipmitool command retry instruction; S600: Entering a retry mechanism in response to the ipmitool command retry instruction, re-executing the ipmitool command, and when the number of failed executions of the ipmitool command reaches a preset number of retries, ending the current BMC user creation task and executing the next BMC user creation task.

[0026] In some embodiments of the present invention, a method for automatically creating a BMC user of a server includes: first, reading a configuration file, the configuration file including server information, BMC login credential information, and configuration information, so as to realize unified management of the server information, BMC login credential information, and configuration information. Operation and maintenance personnel only need to maintain one configuration file to uniformly manage BMC users of all servers, thereby greatly simplifying the management process; performing content parsing and structured processing on the configuration file to obtain BMC information of each server, a list of BMC users to be created, permission configuration information, and retry mechanism configuration information, thereby providing a clear data basis for the subsequent automatic creation of BMC users. During the parsing process, the content of the configuration file can be preliminarily verified to promptly discover errors or incomplete information in the configuration file, thereby avoiding subsequent operation failures or exceptions due to configuration errors, thereby improving the accuracy of the automatic creation of BMC users.

[0027] Then, a log file is created and initialized. The log file records the automated creation process of the BMC user of the server. The operation and maintenance personnel can understand the execution status of each step of the operation in the BMC user creation process through the log file, which is convenient for auditing and backtracking the operation process. When an operation fails or other problems occur, the log file provides detailed error information and context to help the operation and maintenance personnel quickly locate the cause of the problem, speed up the troubleshooting and repair, and improve the maintainability of the server system. In response to the ipmitool command, the BMC user creation tasks and permission configuration operations are executed in batches according to the BMC user list to be created and the permission configuration information through multi-threading technology or multi-process technology; the multi-threading technology or multi-process technology can simultaneously and parallelly process the creation tasks and permission configuration operations of multiple BMC users, greatly improving the creation efficiency of BMC users, shortening the execution time of BMC user creation tasks, meeting the configuration requirements of BMC users of servers in large-scale data centers, and improving the applicability of the automated creation method of BMC users of servers.

[0028] Afterwards, it is determined whether the ipmitool command is executed successfully to improve the reliability of the automatic creation of BMC users. If it is detected that the ipmitool command fails to execute, the error information is recorded in the log file, which provides detailed error records for operation and maintenance personnel, facilitates error analysis and statistics, and generates an ipmitool command retry instruction. The retry mechanism is entered through the retry instruction to automatically re-execute the ipmitool command without manual intervention, thereby improving the automation level of BMC user creation, and automatically retrying according to the preset retry mechanism configuration information to improve the success rate of BMC user creation; when the number of ipmitool command execution failures reaches the preset retry number, the current BMC user creation task is terminated and the next BMC user creation task is executed; a preset retry number limit is set to avoid the problem of infinite retries when an unsolvable error is encountered during the BMC user creation task, which leads to invalid cycle operations and waste of resources and degradation of system performance. When the number of retries reaches the preset number of retries, the current BMC user creation task is terminated. Even if the current task fails, the next BMC user creation task will continue to be executed, ensuring the continuity of the entire batch BMC user creation task and permission configuration operation, ensuring that other tasks are not affected by the failure of the current task, and improving the overall work efficiency of the automatic creation of BMC users on the server.

[0029] It should be noted that the servers are equipped with independent BMC interfaces, support the IPMI protocol, and implement BMC user creation tasks, permission setting operations, etc. through the BMC interface.

[0030] It can be understood that ipmitool is a command line tool for managing and controlling hardware devices (such as servers) that support the IPMI protocol. The ipmitool commands include but are not limited to the ipmitool user set name command, the ipmitool user set password command, the ipmitool user priv command, the ipmitool chassis powerstatus command, and the ipmitool user list command. Among them, the ipmitool user set name command is used to create a BMC user; the ipmitool user set password command is used to set a password for a BMC user; the ipmitool user priv command is used to set the permission level of a BMC user; the ipmitool chassis power status command is used to view the power status of the server; and the ipmitool user list command is used to list the account information of all BMC users, including the user name, user password, and user permission level.

[0031] It should be noted that those skilled in the art can select corresponding ipmitool commands to perform configuration and operation according to the actual tasks to be tested of the server, and the embodiment of the present invention does not limit the types of ipmitool commands.

[0032] In some embodiments of the present invention, the configuration file is in YAML format or JSON format, thereby standardizing the format of the configuration file and facilitating the administrator to centrally manage multiple servers and BMC users. The configuration file in YAML format or JSON format is not only concise and clear, but also easy to maintain and update, which improves the flexibility and scalability of management.

[0033] In one embodiment, the configuration content of the configuration file includes: The IP address, BMC username, and BMC password of each server; A list of BMC users that need to be created on each server. Each BMC user includes the BMC user name, BMC password, and permission level; Preset retry times, log level and other configuration information.

[0034] The configuration file can flexibly define the BMC information of multiple servers, the list of BMC users to be created, the permission configuration information and the retry mechanism configuration information, and configure permissions for each BMC user to facilitate batch operations.

[0035] In some embodiments of the present invention, the configuration content of the configuration file also includes the login information and target password of the BMC. By parsing the configuration file (such as YAML or JSON format), the BMC login information, old password and new password of each server are obtained. In this way, the administrator only needs to define the server information in the configuration file, without hard coding in the code, which is convenient for later maintenance and expansion.

[0036] Based on the execution password change command of the ipmitool tool, the password change task of BMC users is automatically executed in batches, and the password change operation of replacing the old passwords with new passwords of multiple servers is processed in parallel. It is implemented through the following code: import subprocess def change_bmc_password(ip, username, old_password, new_password,retry_limit): attempt = 0 while attempt < retry_limit: try: cmd = [ "ipmitool", "-I", "lanplus", "-H", ip, "-U",username, "-P", old_password, "user", "set", "password", "1", new_password ] result = subprocess.run(cmd, capture_output=True, text=True) if result.returncode == 0: return True else: attempt += 1 except Exception as e: attempt += 1 return False Use ThreadPoolExecutor or multiprocessing modules to implement multi-threaded or multi-process batch processing and parallelize BMC user password modification operations, which can significantly shorten batch execution time and improve work efficiency, especially in large-scale data centers.

[0037] Reference Figure 2 As shown, Figure 2 is a detailed flow chart of step S400 in the method for automatically creating a BMC user of a server provided in an embodiment of the present invention. Step S400 includes but is not limited to step S410 to step S440. Specifically, S410: Determine BMC user information to be created for each server according to the BMC user list to be created, where the BMC user information includes a BMC user name, a BMC password, and an authority level; S420: Create a BMC user through the ipmitool user set name command; S430: Set a password for the BMC user through the ipmitool user set password command; S440: Use the ipmitool user priv command to set the BMC user's permission level.

[0038] In some embodiments of the present invention, the BMC information of each server and the list of BMC users to be created are parsed from the configuration file. The BMC user information to be created on each server can be confirmed through the list of BMC users to be created, wherein the BMC user information includes the BMC user name, BMC password and permission level, which will be used as input parameters for the subsequent creation of BMC users. By extracting detailed user information (BMC user name, BMC password and permission level) from the configuration file, a BMC user with specific permissions can be created for each server to meet the needs of different servers and application scenarios. This avoids possible errors that may occur when manually entering user information, such as spelling errors or permission allocation errors, thereby improving the accuracy and consistency of the configuration.

[0039] In response to the ipmitool command, according to the parsed BMC user information to be created on each server, the creation tasks and permission configuration operations of multiple BMC users are processed in parallel through multi-threading technology or multi-process technology. Specifically, through the user set name command of the ipmitool tool, a new BMC user is created on the target server according to the parsed BMC user name information; through the user set password command of the ipmitool tool, a password is set for the newly created BMC user to ensure that the user can log in safely, thereby enhancing the security of the server system and preventing unauthorized access; through the user priv command of the ipmitool tool, corresponding permissions are allocated to the BMC user according to the permission level specified in the configuration file to ensure that the user can perform authorized operations.

[0040] The ipmitool command can be used to automatically batch execute BMC user creation, BMC password setting, and permission allocation operations, without the need to manually log in to each server for configuration. This greatly improves the efficiency of BMC user creation and management. The automated script reduces the repetitive work of operation and maintenance personnel, ensuring that BMC user configurations for all servers are performed in accordance with unified standards, avoiding inconsistencies and confusion that may occur during manual configuration, reducing operational errors caused by human negligence, and improving the reliability of the server system.

[0041] Reference Figure 3 As shown, Figure 3 is a detailed flow chart of step S500 in the method for automatically creating a BMC user of a server provided by an embodiment of the present invention. Step S500 includes but is not limited to step S510 to step S530. Specifically, S510: Check the execution result of the ipmitool command; S520: If the ipmitool command fails to be executed, the timestamp, log level, and operation failure type of the failure of the current BMC user to create the task are recorded in the log file; S530: If the ipmitool command is executed successfully, the success of the current BMC user creation task is recorded in the log file, and the next BMC user creation task is executed.

[0042] In some embodiments of the present invention, after executing the ipmitool command, the automatic creation method of the BMC user of the server also includes detecting the execution result of the ipmitool command to ensure the reliability of the automatic creation of the BMC user. Detecting the execution result of the ipmitool command includes: checking the return status code or output information of the ipmitool command to determine whether the ipmitool command is successfully executed. If the ipmitool command execution fails, the timestamp, log level and operation failure type of the failure of the current BMC user creation task are recorded in the log file. The timestamp records the specific time when the ipmitool command failure occurs, which is convenient for subsequent troubleshooting and auditing. The log level is usually ERROR or WARNING, indicating that there is an error problem. The operation failure type is a detailed description of the cause of the failure, such as network problems, insufficient permissions, command syntax errors, etc. If the ipmitool command is detected to be executed successfully, the timestamp of the successful operation of the current BMC user creation task is recorded. The log level is usually INFO, indicating that the current BMC creation task is completed normally, and the information of the successful user creation is recorded. After completing the current BMC creation task, it automatically enters the next BMC user creation task and continues to perform batch operations, ensuring the continuity of the automated process and improving the efficiency of BMC user management.

[0043] By detecting the execution results of the ipmitool command and recording the success or failure information of each BMC user creation task, a complete operation record is provided to facilitate subsequent auditing and troubleshooting. Operation and maintenance personnel can clearly understand the execution status of each BMC user creation task through the log file, including detailed information on success and failure, which improves the transparency of the server system and the efficiency, reliability and security of BMC user management, and facilitates operation and maintenance personnel to monitor, audit and optimize the BMC user creation and configuration process in large-scale data centers.

[0044] Reference Figure 4 As shown, Figure 4 is a detailed flow chart of step S600 in the method for automatically creating a BMC user of a server provided in an embodiment of the present invention. Step S600 includes but is not limited to step S610 to step S620. Specifically, S610: After entering the retry mechanism, the ipmitool command is automatically executed according to the preset number of retries; S620: When the ipmitool command execution fails, wait for a preset retry time before executing the next ipmitool command, until the number of automatic executions of the ipmitool command reaches the preset retry number or until the ipmitool command is successfully executed, end the current BMC user creation task, and execute the next BMC user creation task.

[0045] In some embodiments of the present invention, the execution result of the ipmitool command is checked. If the ipmitool command fails to execute, an error log is recorded in a log file and an ipmitool command retry instruction is generated. In response to the ipmitool command retry instruction, a retry mechanism is entered. After entering the retry mechanism, the ipmitool command is automatically re-executed according to a preset number of retries. A preset number of retries is set to avoid infinite retries when an unsolvable error is encountered, thereby saving server system resources and avoiding wasting time and computing power. After each ipmitool command retry fails, the next ipmitool command is executed after waiting for a preset retry time interval. By setting a preset retry time interval, frequent command sending in a short time is avoided, thereby preventing overload of server or network resources. When the number of automatic re-executions of the ipmitool command reaches the preset number of retries, the current BMC user creation task is terminated and the next BMC user creation task is executed. Even if the current BMC user creation task fails, the current BMC user creation task is automatically terminated after reaching the preset number of retries, and the next BMC user creation task is continued to be executed to ensure the continuity of the entire batch operation. Alternatively, during the process of automatically re-executing the ipmitool command, if the ipmitool command is executed successfully, the retry mechanism is directly exited, and the next BMC user creation task is executed, thereby improving the automation degree and creation efficiency of the BMC user creation task.

[0046] By introducing a retry mechanism, some temporary or accidental errors, such as network fluctuations and temporary server unavailability, can be automatically handled, thereby improving the success rate of BMC user creation tasks. In addition, by automatically re-executing the ipmitool command in the retry mechanism, the intervention of operation and maintenance personnel in failed tasks can be reduced. The server system can automatically try to solve the problem, which improves the automation level of the server's BMC user creation method. In addition, by setting a reasonable preset number of retries and preset retry time, it is possible to balance resource utilization and task execution efficiency, ensuring that the server system can still operate stably in a high-concurrency environment.

[0047] It should be noted that, in some embodiments of the present invention, the preset number of retries is 5 times, and the preset retry time is 3S. Those skilled in the art can set the preset number of retries and the preset retry time according to the BMC user list to be created and the number of servers. The embodiments of the present invention do not limit the preset number of retries and the preset retry time.

[0048] In response to the ipmitool command, the BMC user creation tasks and permission configuration operations are executed in batches according to the BMC user list to be created and the permission configuration information through multi-threading technology or multi-process technology, and after the creation task and permission configuration operations are completed, a task completion instruction is sent to notify the operation and maintenance personnel that the batch creation task and permission configuration operations are completed.

[0049] In one embodiment, after entering the retry mechanism, the ipmitool command is automatically executed according to the preset number of retries and the preset retry time, and the error log is recorded in the log file, which is implemented by the following code: import logging import time def setup_logging(): logging.basicConfig( filename='bmc_user_creation.log', level=logging.DEBUG, format='%(asctime)s - %(levelname)s - %(message)s' ) def create_bmc_user_with_retries(ip, username, password, new_username, new_password, privilege, retry_limit): attempt = 0 while attempt < retry_limit: try: # Create a BMC user, set a BMC password, and set the permission level result = subprocess.run([...]) if result.returncode == 0: logging.info(f"Successfully created BMC user for {new_username}.") return True else: logging.error(f"Failed to create BMC user {new_username}.") attempt += 1 time.sleep(2) # Wait 2 seconds and try again except Exception as e: logging.error(f"Error: {str(e)}") attempt += 1 time.sleep(2) # Wait 2 seconds and try again return False In some embodiments of the present invention, the method for automatically creating a BMC user of a server also includes but is not limited to steps S401 to S402. Specifically, S401: Implementing multi-thread technology or multi-process technology to batch execute the BMC user creation task of each server through ThreadPoolExecutor or ProcessPoolExecutor; S402: Set the maximum number of concurrent operations of multi-threading technology and multi-process technology to control the load.

[0050] In some embodiments of the present invention, the concurrency number, that is, the maximum number of threads or processes running simultaneously, is controlled by setting the max_workers parameter in ThreadPoolExecutor or ProcessPoolExecutor, so as to control the maximum number of creation tasks for creating BMC users by parallel execution of multi-threading technology and multi-process technology. By properly configuring max_workers, the server system can be prevented from being overloaded due to too many tasks, thereby ensuring the rational use of system resources.

[0051] It should be noted that ThreadPoolExecutor is suitable for I / O intensive tasks, such as network requests, and ProcessPoolExecutor is suitable for CPU intensive tasks, such as complex calculations. Choose the appropriate tool based on the actual situation to implement multi-threading technology or multi-process technology to batch execute the BMC user creation task for each server.

[0052] Reference Figure 5 As shown, Figure 5 is a detailed flow chart of the first method for automatically creating a BMC user of a server provided by an embodiment of the present invention, including but not limited to steps S210 to S230. Specifically, S210: Determine whether the configuration file includes the IP address information of each server, the BMC user name, the BMC password, the BMC user list to be created, the permission configuration information, and the retry mechanism configuration information, so as to determine the validity of the configuration file; S220: If the configuration file is valid, generate a BMC user creation task instruction; S230: If the configuration file is invalid, an error warning is output and the BMC user creation task is terminated.

[0053] In some embodiments of the present invention, the method for automatically creating a BMC user of a server further includes detecting the validity of a configuration file to ensure the accuracy and reliability of the configuration file, thereby ensuring the reliability of the automatic creation of the BMC user of the server. Detecting the validity of the configuration file includes: determining whether the configuration file contains necessary information, such as the IP address information of each server, the BMC user name, the BMC password, the list of BMC users to be created, the permission configuration information, and the retry mechanism configuration information (such as the preset number of retries and the preset retry time). If any of the above key information is missing in the configuration file, the configuration file is determined to be an invalid file. If the configuration file is missing all of the above key information, the configuration file is determined to be a valid file.

[0054] When the configuration file is a valid file, a BMC user creation task instruction is generated based on the valid information in the configuration file, and the subsequent BMC user creation task is prepared to be executed. When the configuration file is an invalid file, an error warning is output. The error warning includes the missing key information or the wrong part of the key information in the configuration file, which helps the operation and maintenance personnel to quickly understand the problem of the configuration file and reduce the time for troubleshooting and repairing the problem. In addition, the invalid BMC user creation task is terminated to avoid the failure of the subsequent BMC user creation task operation or the configuration inconsistency caused by the configuration file error, thereby saving resources and preventing potential security risks, and improving the accuracy and reliability of the BMC user creation task.

[0055] By judging the validity of the configuration file before executing the BMC user creation task in batches, it can ensure that the subsequent BMC user creation tasks are based on complete and correct configurations, avoiding task failures caused by missing or incorrect configurations. Only when the configuration file is valid will the BMC user creation task instruction be generated and the BMC user creation task be executed, ensuring the integrity and accuracy of the BMC user automated creation process and avoiding interruptions or failures caused by configuration errors.

[0056] Reference Figure 6 As shown, Figure 6 is a detailed flow chart of the method for automatically creating a BMC user of a second server provided by an embodiment of the present invention, including but not limited to steps S700 to S740. Specifically, S700: Deploy firewall security anti-tampering mechanism in log files; S710: Set up access control lists through firewall security anti-tampering mechanisms to allow only specific IP ranges or subnets to access the server's BMC interface; S720: Configure a whitelist policy to allow only authenticated trusted IP segments to access the server's BMC interface; S730: Start the deep packet inspection function of the firewall security anti-tampering mechanism to detect the traffic passing through the BMC interface of the server and identify and filter out abnormal traffic; S740: Upload abnormal traffic events and abnormal access events to the log file and issue an error alarm prompt.

[0057] In some embodiments of the present invention, the method for automatically creating a BMC user of a server also includes deploying a firewall security anti-tampering mechanism in a log file. The firewall security anti-tampering mechanism is an important barrier to network security and improves the security of the BMC user creation task process. An access control list is set in the firewall security anti-tampering mechanism to limit access to the server BMC interface, allowing only a specific IP range or subnet to access the server's BMC interface. The management server can only access the server through the intranet or VPN to prevent direct access from the public network, thereby improving security. Reasonable configuration of the rules and access control lists of the firewall security anti-tampering mechanism can achieve load balancing of traffic and avoid overloading of a single server or interface. Configure a whitelist policy to only allow authenticated trusted IP segments to access the server's BMC interface to ensure that only authorized users can access the BMC interface and prevent unauthorized access.

[0058] Start the deep packet inspection function of the firewall security anti-tampering mechanism to analyze the traffic passing through the server's BMC interface in real time. The firewall security anti-tampering mechanism can identify abnormal traffic, such as brute force attacks, SQL injections, etc., and automatically intercept malicious traffic based on the detection results. Configure specific port filtering rules to ensure that the BMC interface management traffic is only accessed through authorized ports (such as IPMI ports) to avoid unnecessary port exposure. When abnormal traffic is identified and filtered out, the abnormal traffic events and abnormal access events are uploaded to the log file for subsequent auditing and analysis. At the same time, an error alarm prompt is issued to notify the administrator of abnormal events so that they can respond and handle them in a timely manner. Through deep packet inspection and traffic filtering, abnormal traffic can be identified and blocked, reducing the impact on normal business traffic and optimizing the use of network resources.

[0059] The firewall security anti-tampering mechanism is configured with a log audit mechanism to record all access attempts, traffic filtering events and erroneous behaviors. All operations should be recorded in detail in the log audit mechanism and retained for a period of time for audit and backtracking. The firewall security anti-tampering mechanism is also configured with a real-time monitoring and alarm mechanism. When abnormal access or attack behavior is detected, an alarm is automatically triggered, and the administrator can respond in time to improve the security and reliability of the server system.

[0060] Reference Figure 7 As shown, Figure 7 is a detailed flow chart of the method for automatically creating a BMC user of a third server provided by an embodiment of the present invention, including but not limited to steps S750 to S770. Specifically, S750: Deploy intrusion detection and intrusion prevention mechanisms in log files; S760: Monitors and analyzes access from external networks through intrusion detection mechanisms, records potential malicious traffic and sends it to intrusion prevention mechanisms; S770: When the intrusion prevention mechanism detects malicious traffic, it determines malicious behavior based on the malicious traffic and blocks the attack source of the malicious behavior.

[0061] In some embodiments of the present invention, the firewall security anti-tampering mechanism is used in conjunction with the intrusion detection mechanism and the intrusion prevention mechanism to monitor and analyze access from external networks in real time and promptly discover potential security threats. The intrusion detection mechanism and the intrusion prevention mechanism are deployed in the log file. The intrusion detection mechanism will identify suspicious network activities and potential malicious traffic, such as port scanning, abnormal login attempts, etc., and record the timestamp, source IP address, target IP address, port number, protocol type and description of suspicious behavior of any potential malicious traffic, and send it to the intrusion prevention mechanism. When the intrusion prevention mechanism finds malicious traffic and determines the malicious behavior (such as brute force attack, DoS attack, etc.) based on the malicious traffic, the intrusion prevention mechanism can automatically block the attack source of the malicious behavior. The blocking measures may include blocking access to specific IP addresses, blocking infected systems or resetting connections, thereby preventing further damage.

[0062] By deploying intrusion detection and intrusion prevention mechanisms in log files, network traffic can be monitored and analyzed in real time, and potential malicious attacks can be discovered and blocked in a timely manner. This mechanism is of great significance for protecting the security of servers and networks, especially in the face of complex network environments and potential attacks. Through detailed log records and rapid response measures, the security and stability of the system can be significantly improved.

[0063] By deploying a firewall security anti-tampering mechanism in the log file, access to the BMC interface can be strictly controlled to improve security. At the same time, through deep packet inspection and abnormal event recording, potential security threats can be discovered and handled in a timely manner, and traceability and response speed can be enhanced. This mechanism is of great significance for protecting the security of servers and storage devices, especially in the face of complex network environments and potential attacks. Recording abnormal events and abnormal access events in log files provides detailed records for subsequent security audits and problem tracking. Through log files, operation and maintenance personnel can understand the occurrence time, source IP, access behavior and other information of abnormal events, which is convenient for event tracking and analysis.

[0064] In some embodiments of the present invention, the automatic creation method of the BMC user of the server also includes an anti-misoperation and anti-tampering mechanism. The fundamental method to prevent misoperation is to ensure that all operations follow the principle of least privilege. Through the principle of least privilege, each administrator can only perform operations related to his position. For example, the BMC user management script should limit different operation permissions according to the role. In addition, when performing important operations (such as modifying firewall rules, creating BMC users, etc.), the server system requires multiple authentication, such as entering a password and OTP (one-time password) for two-factor authentication to ensure the identity of the operator. In the anti-tampering mechanism, strict access control is configured for the firewall security anti-tampering mechanism to prevent unauthorized modifications. Any changes to the firewall rules need to go through the approval process, and the changes will be automatically recorded in the detailed log file. In addition, the rule version control and rollback function are supported to ensure that once an erroneous operation or attack occurs, it can be quickly restored to a safe state. After that, firewall policy audits and vulnerability scans are performed regularly to ensure that there are no loopholes in the firewall rules and that the configuration is up to date. Audits check whether there are unauthorized access, rule changes, and potential security issues.

[0065] Reference Figure 8 As shown, Figure 8The invention is a structural diagram of a system for automatically creating a BMC user of a server provided by an embodiment of the present invention. The system for automatically creating a BMC user of a server includes a reading module, a parsing module, a log module, a task processing module and a task retry module, wherein the reading module is used to read a configuration file, the configuration file includes server information, BMC login credential information, and configuration information; the parsing module is used to parse the configuration file to obtain the BMC information of each server, the list of BMC users to be created, the permission configuration information and the retry mechanism configuration information; the log module is used to create a log file and initialize the log file to record the automatic creation process of the BMC user of the server; the task processing module is used to respond to The invention relates to an ipmitool command, and a multi-thread technology or a multi-process technology is used to batch execute BMC user creation tasks and permission configuration operations according to a list of BMC users to be created and permission configuration information; the proofreading module is used to check the execution result of the ipmitool command, and if the ipmitool command execution fails, an error log is recorded in a log file and an ipmitool command retry instruction is generated; the task retry module is used to enter a retry mechanism in response to the ipmitool command retry instruction, and re-execute the ipmitool command; when the number of ipmitool command execution failures reaches a preset number of retries, the current BMC user creation task is terminated, and the next BMC user creation task is executed.

[0066] In some embodiments of the present invention, in the automatic creation system of the BMC user of the server, the reading module is responsible for reading the configuration file, the configuration file includes server information, BMC login credential information, and configuration information, so as to realize the automatic reading of data, and the configuration file is parsed by the parsing module to obtain the BMC information of each server, the list of BMC users to be created, the permission configuration information, and the retry mechanism configuration information, so as to extract the necessary key information, and provide a clear data basis for the subsequent automatic creation of BMC users. In the parsing process, the content of the configuration file can be preliminarily verified, and the errors or incomplete information in the configuration file can be found in time to avoid the subsequent operation failure or abnormality caused by configuration errors, thereby improving the accuracy of the automatic creation of BMC users. Through the various steps and results of the automatic creation process of the BMC user of the server of the log module, the operation process is audited and traced back. When an operation fails or other problems occur, the log file provides detailed error information and context, which helps the operation and maintenance personnel to quickly locate the cause of the problem, speed up the troubleshooting and repair, and improve the maintainability of the server system. The task processing module executes BMC user creation tasks and permission configuration operations through multi-threading technology or multi-process technology. Threading technology or multi-process technology can process multiple BMC user creation tasks and permission configuration operations in parallel, greatly improving the efficiency of BMC user creation, shortening the execution time of BMC user creation tasks, meeting the configuration requirements of BMC users of servers in large-scale data centers, and improving the applicability of the automated creation method of BMC users of servers. The proofreading module checks the execution results of the ipmitool command, records the error log of the failed execution of the ipmitool command, and generates the ipmitool command retry instruction, providing detailed error records for operation and maintenance personnel, facilitating error analysis and statistics. The task retry module enters the retry mechanism through the retry instruction and automatically re-executes the ipmitool command without manual intervention, which improves the automation level of BMC user creation. It automatically retries according to the preset retry mechanism configuration information to improve the success rate of BMC user creation. When the number of failed ipmitool command executions reaches the preset number of retries, the current BMC user creation task is terminated, avoiding infinite retries and invalid loop operations that waste resources when an unresolvable error is encountered during the BMC user creation task, and executing the next BMC user creation task, ensuring the continuity of the entire batch BMC user creation task and permission configuration operation, ensuring that other tasks are not affected by the failure of the current task, and improving the overall work efficiency of the automatic creation of BMC users on the server.

[0067] The automated creation system of the server's BMC users realizes batch execution of BMC user creation tasks and permission configuration operations through the collaborative work of various modules, thereby improving the efficiency and reliability of the automated creation method of the server's BMC users and ensuring the traceability of operations.

[0068] In some embodiments of the present invention, the automatic creation system of the BMC user of the server also includes a network device module, which includes a switch, a router and a firewall. The switch is used to connect various management servers, BMC management devices and target servers, and supports gigabit or 10G speeds. The router is used to provide network connection, IP routing and data packet forwarding functions, and supports traffic forwarding between different subnets. The firewall is used to provide security isolation between the internal network and the external network to prevent external attacks and illegal access.

[0069] In some embodiments of the present invention, a computer device 1000 is further provided, referring to Fig. 9 As shown, Fig. 9It is a structural diagram of a computer device 1000 provided in an embodiment of the present invention, including a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor executes the program to implement the method described in the above embodiment. Specifically, the electronic device includes a processor 1001, which can be implemented in the form of a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (Application Specific Integrated Circuit, ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the method provided in the embodiment of the present invention; the memory 1002 can be implemented in the form of a read-only memory 1002 (Read Only Memory, ROM), a static storage device, a dynamic storage device, or a random access memory 1002 (Random Access Memory, RAM). The memory 1002 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program codes are stored in the memory 1002 and are called by the processor 1001 to execute the embodiments of the present invention; the input / output interface 1003 is used to implement information input and output; the communication interface 1004 is used to implement communication interaction between the device and other devices, and communication can be achieved through wired methods (such as USB, network cables, etc.) or wireless methods (such as mobile networks, WIFI, Bluetooth, etc.); a bus transmits information between various components of the device (such as the processor 1001, the memory 1002, the input / output interface 1003 and the communication interface 1004); wherein the processor 1001, the memory 1002, the input / output interface 1003 and the communication interface 1004 are connected to each other within the device through the bus.

[0070] It should be appreciated that the method steps in the embodiments of the present invention can be implemented or implemented by computer hardware, a combination of hardware and software, or by computer instructions stored in a non-transitory computer readable memory. The method can use standard programming techniques. Each program can be implemented in a high-level process or object-oriented programming language to communicate with a computer system. However, if necessary, the program can be implemented in an assembly or machine language. In any case, the language can be a compiled or interpreted language. In addition, the program can be run on a programmed ASIC for this purpose.

[0071] In addition, the operations of the processes described herein may be performed in any suitable order unless otherwise indicated herein or otherwise clearly contradicted by context. The processes described herein (or variations and / or combinations thereof) may be performed under the control of one or more computer systems configured with executable instructions, and may be implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) that is executed collectively on one or more processors, by hardware, or a combination thereof. The computer program includes a plurality of instructions that may be executed by one or more processors.

[0072] Further, the method can be implemented in any type of computing platform that is operably connected to a suitable computer, including but not limited to a personal computer, a minicomputer, a mainframe, a workstation, a network or distributed computing environment, a separate or integrated computer platform, or in communication with a charged particle tool or other imaging device, etc. Various aspects of the present invention can be implemented in machine-readable code stored on a non-transitory storage medium or device, whether removable or integrated into a computing platform, such as a hard disk, an optical read and / or write storage medium, a RAM, a ROM, etc., so that it can be read by a programmable computer, and when the storage medium or device is read by the computer, it can be used to configure and operate the computer to perform the process described herein. In addition, the machine-readable code, or portions thereof, can be transmitted via a wired or wireless network. When such media includes instructions or programs that implement the steps described above in conjunction with a microprocessor or other data processor, the invention described herein includes these and other different types of non-transitory computer-readable storage media. When programmed according to the methods and techniques of the present invention, the present invention can also include the computer itself.

[0073] The computer program can be applied to input data to perform the functions described herein, thereby converting the input data to generate output data stored in a non-volatile memory. The output information can also be applied to one or more output devices such as a display. In a preferred embodiment of the present invention, the converted data represents physical and tangible objects, including specific visual depictions of physical and tangible objects produced on the display.

[0074] The above is only a preferred embodiment of the present invention. The present invention is not limited to the above implementation. As long as the technical effect of the present invention is achieved by the same means, any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the scope of protection of the present invention. Within the scope of protection of the present invention, its technical scheme and / or implementation method may have various modifications and changes.

Claims

1. A method for automatically creating a BMC user of a server, characterized in that: The method comprises the following steps: S100: Read a configuration file, where the configuration file includes server information, BMC login credential information, and configuration information; S200: performing content parsing processing on the configuration file to obtain BMC information of each server, a list of BMC users to be created, permission configuration information, and retry mechanism configuration information; S300: creating a log file and initializing the log file to record the automated creation process of the BMC user of the server; S400: In response to the ipmitool command, executing BMC user creation tasks and permission configuration operations in batches according to the list of BMC users to be created and the permission configuration information through multi-threading technology or multi-process technology; S500: Check the execution result of the ipmitool command. If the execution of the ipmitool command fails, record an error log in the log file and generate an ipmitool command retry instruction; S600: Entering a retry mechanism in response to the ipmitool command retry instruction, re-executing the ipmitool command, and when the number of failed executions of the ipmitool command reaches a preset number of retries, ending the current BMC user creation task and executing the next BMC user creation task.

2. The method for automatically creating a BMC user of a server according to claim 1, characterized in that: The ipmitool command includes an ipmitool user set name command, an ipmitool user set password command, and an ipmitool user priv command, and the step S400 includes: S410: Determine BMC user information to be created for each server according to the BMC user list to be created, wherein the BMC user information includes a BMC user name, a BMC password, and an authority level; S420: Create a BMC user through the ipmitool user set name command; S430: Setting a password for the BMC user through the ipmitool user set password command; S440: Setting the permission level of the BMC user through the ipmitool user priv command.

3. The method for automatically creating a BMC user of a server according to claim 1, characterized in that: The step S500 includes: S510: Check the execution result of the ipmitool command; S520: If the ipmitool command fails to be executed, the timestamp, log level and operation failure type of the failure of the current BMC user to create the task are recorded in the log file; S530: If the ipmitool command is executed successfully, the successful execution of the current BMC user creation task is recorded in the log file, and the next BMC user creation task is executed.

4. The method for automatically creating a BMC user of a server according to claim 1, characterized in that: The retry mechanism configuration information includes a preset retry time, and the step S600 includes: S610: After entering the retry mechanism, the ipmitool command is automatically executed according to the preset number of retries; S620: When the ipmitool command execution fails, wait for a preset retry time before executing the next ipmitool command, until the number of automatic executions of the ipmitool command reaches the preset retry number or until the ipmitool command is successfully executed, end the current BMC user creation task, and execute the next BMC user creation task.

5. The method for automatically creating a BMC user of a server according to claim 1, characterized in that: The method further comprises: S401: Implementing multi-thread technology or multi-process technology to batch execute the BMC user creation task of each server through ThreadPoolExecutor or ProcessPoolExecutor; S402: Setting the maximum concurrent number of the multi-threading technology and the multi-process technology to control the load.

6. The method for automatically creating a BMC user of a server according to claim 1, characterized in that: The method further comprises: S210: Determine whether the configuration file includes the IP address information of each server, the BMC user name, the BMC password, the BMC user list to be created, the permission configuration information and the retry mechanism configuration information, so as to determine the validity of the configuration file; S220: If the configuration file is valid, generate a BMC user creation task instruction; S230: If the configuration file is invalid, output an error warning and terminate the BMC user creation task.

7. The method for automatically creating a BMC user of a server according to claim 1, characterized in that: The method further comprises: S700: deploying a firewall security anti-tampering mechanism on the log file; S710: Setting an access control list through the firewall security anti-tampering mechanism to allow only a specific IP range or subnet to access the BMC interface of the server; S720: Configure a whitelist policy to allow only authenticated trusted IP segments to access the server's BMC interface; S730: Start the deep packet inspection function of the firewall security anti-tampering mechanism to detect the traffic passing through the BMC interface of the server and identify and filter out abnormal traffic; S740: Upload the abnormal traffic events and abnormal access events to the log file, and issue an error alarm prompt.

8. The method for automatically creating a BMC user of a server according to claim 7, characterized in that: The method further comprises: S750: deploying an intrusion detection mechanism and an intrusion prevention mechanism in the log file; S760: Monitor and analyze access from the external network through the intrusion detection mechanism, record potential malicious traffic and send it to the intrusion prevention mechanism; S770: When the intrusion prevention mechanism detects malicious traffic, malicious behavior is determined based on the malicious traffic, and the attack source of the malicious behavior is blocked.

9. A system for automatically creating a BMC user of a server, applied to the method according to any one of claims 1 to 8, characterized in that: include: A reading module is used to read a configuration file, wherein the configuration file includes server information, BMC login credential information, and configuration information; A parsing module, used for parsing the configuration file to obtain BMC information of each server, a list of BMC users to be created, permission configuration information and retry mechanism configuration information; A log module, used to create a log file and initialize the log file to record the automated creation process of the BMC user of the server; A task processing module, for responding to an ipmitool command, and executing BMC user creation tasks and permission configuration operations in batches according to the list of BMC users to be created and the permission configuration information through multi-threading technology or multi-process technology; A proofreading module, used to check the execution result of the ipmitool command, and if the ipmitool command fails to execute, record an error log in the log file and generate an ipmitool command retry instruction; The task retry module is used to enter the retry mechanism in response to the ipmitool command retry instruction, re-execute the ipmitool command, and when the number of ipmitool command execution failures reaches a preset number of retries, end the current BMC user creation task and execute the next BMC user creation task.

10. A computer-readable storage medium having program instructions stored thereon, characterized in that: When the program instructions are executed by a processor, the method according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Method and system for on-batch setup of BMC (Baseboard Management Controller) user names and passwords

    CN107895107A

  • BMC system new user creation function test method, device and related assembly

    CN110399266A

  • Intelligent server fault pushing method, device and equipment and storage medium

    CN113238913A

Cited By

  • Password management method, computer equipment, readable storage medium and program product

    CN120387159A

  • Password management method, computer device, readable storage medium and program product

    CN120387159B

  • Weak network environment batch user migration management method and device and storage medium

    CN122457614A

  • Batch user migration management method and device in weak network environment and storage medium

    CN122457614B