...
Jira No | Summary | Description | Status | Solution | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Description and examples of the CLAMP script Feedback from the PTLs\ meeting was to not run the script because the Jira tickets would create addtional work. They would prefer to track progress using gerrit reviews. SECCOM:
Actions: put ideas on onap-discuss and set up a separate meeting if there is enough interest | On Hold | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Automated K8S tests enabled for Frankfurt | Feedback from PTLs Propose enabling | Present to TSC | Docker and Kubernetes Security | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Secrets encryption | Krzysztof has a draft wiki page documenting the approach for ONAP secrets management and would like feedback Questions for Krzysztof:
| In Progress | ONAP secret management | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
SECCOM chair and vice chair elections | Confirm that the correct voting member for your company is on the Security Sub-committee Members list | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Java and the new model of licensing for Oracle JDK versus Open JDK – Natacha | Oracle JDK which is commercial - benefits updates Open JDK - like open source so free of charge but support for java 11 but not earlier versions. 2/11 update Docker images for both the Debian and Alpine releases of the Java 11 JDK will be available for all projects | Docker images for both the Debian and Alpine releases of the Java 11 JDK will be available for all projects | TSC wants to know which distribution of the OpenJDK is used – Integration team/OOM to be contacted - discussion planned for next status meeting on Wednesday. SECCOM cares Java 11 and not particular distribution - we appreciate common image from governance perspective and harmonization - coordination on release manager side. Next steps: E-mail to be sent to Morgan with Pawel B. in copy to confirm if image is already created. 2/11: Confirm documentation and location of Debian and Alpine images | Secrets management | Agreement achieved last week (Krzysztof and Samuli) | Written description is needed on the Wiki. | Once we have a written recommendation, it would be reviewed at the next SECCOM meeting and further presented at the TSC for an prroval - once gained it would become best practice. | Script for automatic jira ticket generation of direct dependencies to be upgraded was successfully tested with CLAMP by Julien and Pierre. | 2 scripts were created in Python
| Scripts were reviewed as well as CLAMP. No specific feedback from SECCOM received from demo till today. | Nexts steps:
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
New xtesting security docker has been integrated end of last week. | Meeting on Wednesday with OOM and Integration. | Update next week. | Frankfurt M2/M3 scorecard SECCOM requirements update | Items reviewed:
|
Status | ||||
---|---|---|---|---|
|
Status colour Red title RED
Status colour Red title RED
Status colour Green title GREEN
Status colour Red title RED
OJSI status update - projects to be reasked - if no feedback - slot to be assigned on the next PTL call
CII Badging - Jira tickets to be isued with script usage. Some answers from hardening questions.
ONES NA CFP
SECCOM presentations submitted:
- ODL and ONAP (Pawel & Luis)
- Password generation with ONAP (Krzysztof)
- Cloudnative deployment of ONAP with ingress controller (Krzysztof)
- Kubernetes and security aspects (Samuli & Amy)
To be further discussed the scope of SECCOM F2F in LA:
ONAP security requirements and allignment with VNF security requirements
VNF security requirements
CMPv2 update
Buiding containers in an unified way for ONAP
Decide which meeting(s) SECCOM wants to focus on
Start collecting topics for the meeting(s)
View file | ||||
---|---|---|---|---|
|
View file | ||||
---|---|---|---|---|
|