You can verify the firmware with Flashrom and a Bus Pirate.
I have a CH341A device which is supported by the flashrom Linux program but I could not yet find instructions which parts of the memory are relevant for calculating the checksums and
also want to avoid removing the flash chips from the socket just to read them (perhaps this it not required since the flash update is possible from within OpenBMC but if OpenBMC is
compromised it could manipulate the reported checksum too).