Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Amy presented process for all possible use cases with execution and planning phases. Slide deck with modifications included

Jira No
SummaryDescriptionStatusSolution

Vulnerable package reportion automation 

Presentation provided by Brianna and Bert. Great job (150 hours → 2 hours)! Safes a lot of manual work for us.

Enhancements for the future:

  • flag for failing CLM scanning jenkins job (older than 1 week)
  • CVE list with threat levels ratio
  • remove _xD000_ for CVE's names
  • log4j-core recommended version to be updated into 2.17.1 
  • usage of Wiki reference with recommended versions as single source of true as dynamic
  • configure other jobs option - non master that would be usefull for Maintenance Release analysis
  • additional tab with unstructured data
ongoing

import excel into confluence:

https://community.atlassian.com/t5/Confluence-articles/How-to-import-an-excel-file-into-Confluence-using-Elements/ba-p/1672151


LFN Developer & Testing Forum

Event June 13th-16th Porto, Portugal

Please register: https://events.linuxfoundation.org/lfn-developer-testing-forum/

started


  • SECCOM topics proposal:

    • SECCOM retrospectives:
      • Log4j fix implementation in Istanbul Maintenance Release
      • Jakarta security status update
    • Kohnsecuritygoals:
      • Global Requirements and Best Practices
      • Security PoCs:
      • logging req
      • code quality quality
      • service mesh
    • SBOM enablement and maintenance, and packaging
    • Waiver policy update
    • Unmaintained projects joint meeting with Amy, Thomas and Andreas, Chaker and Byung.
    • On the road to gold badge - Tony and Toine
    others?
    • Operator perspective on ONAP security
    -
    • Amy
    ?
    • , Andreas?
    ,
    • Brian? Fabian?
    • Security principles in the implementation – Tony, Maggie
started

Topic Remaining topic proposals to be submitted.

Brian to share what kind of security due diligence is performed by BellCanada. ONAP is used for 5G slicing orchestration.

Bug in SBOM software - ticket was opened to LFN IT by Vijay.

ONAP unmaintained and deprecated functions startedModifications to be provided by Amy based on the discussion held - doneLogging update

Majority of the fields implemented in CPS. 2 topics to be addressed:

  • ordering if the fields
  • format of how would be outputed
ongoingSynch with Byung on architecture.Synch with OOM

Fabian to check if could contribute on how qualify software to be deployed, what duediligence was performed. 



OSA documentation update per release Thomas asked for a branch to be created for JakartastartedPawel to 

Last PTLs meeting – 25th of April

1.SDC-3954 - open

2.SDNC-1692 -

closed

done

3.OOM-2957

-

open reassigned to Fiachra

    • fix root_pods in Jakarta release:

1.OOM-2958 – open -

open

reassigned to Fiachra

2.INT-2104

- open
ongoing

Michał to run additional run to get status update.

As none of the tickets were progressed - issue to be escalated at the TSC.

in progress




logging PoC reportAjay (Ericsson) is working on the connection between FluntBit and ElasticSearch. He is leaving Ericsson end of this week, so some of our OOM team members have key learning sessions with him. I told Ajay to check in his code. We plan to report our log PoC progress/demo to SECCOM sometime soon. That is the plan.ongoing

SBOM: patch to add the path for VES 

-Jess is trying to validate the procedure

ongoingMuddasar to share e-mail that Vijay shared with Jess.

CPS gold badge 

Dedicated meeting to be scheduled – 2 tickets created at LFN IT:

  • IT-23828 2FA (2 Factor Authentication) needed for merging to Gerrit in ONAP
  • IT-23829 Hardening LFN hosted ONAP project web sites – goodprogress
    • Gerrit has now been updated to receive and A grade on securityheaders.com (thanks to this change we will be getting this on all of the Gerrit we operate as the systems pick up their updates).
    • We are still working on getting the headers fixed for the nexus systems (getting a C) as well as the wiki and jira systems (getting an A but could be stronger).

Next focus on Nexus to get A grade.

LFN white paper 5G E2E security

https://lfnetworking.org/wp-content/uploads/sites/7/2022/04/LFN-Security-Whitepaper-v4.pdf?utm_campaign=LFN%20Newsletter&utm_medium=email&_hsmi=210819121&_hsenc=p2ANqtz-8l0-nc3Y9V0NGaQ63h3EBkuxAT5KxkeHGJJ_bM7pbtql_aQEOQvjeTpEsJrDmEQCzJ2c2Ar7yeIU45g9PD0JX30oKCkQ&utm_content=210819121&utm_source=hs_email




5Y review tp be presented on May 9th to PTLs.
slot to be booked for Tony at the PTLs meeting by Pawel.

OpenSSF intro by David Wheeler

Link to recording and slide deck: 

https://wiki.lfnetworking.org/display/LN/LFN+Security+Forum

review for the near future – are our pipeline or processes optimal?

to be done

NIST 5G Cybersecurity draft documenthttps://csrc.nist.gov/publications/detail/sp/1800-33/draftstartedto be addressed at the next SECCOM

Kohn SECCOM Global Requirements

-[REQ-437 -> REQ-800] -> REQ-1067 -> REQ-1208 COMPLETION OF PYTHON LANGUAGE UPDATE (v2.7 → v3.8)

-[REQ-438 -> REQ-801] -> REQ-1068 -> REQ-1209 COMPLETION OF JAVA LANGUAGE UPDATE (v8 → v11)

-[REQ-439 -> REQ-863] -> REQ-1066  -> REQ-1211 CONTINUATION OF PACKAGES UPGRADES IN DIRECT DEPENDENCIES

-[REQ-443] -> REQ-1069 -> REQ-1210 CONTINUATION OF CII BADGING SCORE IMPROVEMENTS FOR SILVER LEVEL

startedLogging requirment - target full PoC for Kohn and then Global Requirement for London release.5Y asessmentDedicated teams in projects for security. We have security tests at the Integration level but usually no delegated security expert.ongoingHardening validation process might not exist at all for some ONAP projects.

SECCOM MEETING CALL WILL BE HELD ON 3rd OF MAY'22. 






...

View file
name2022-04-26_SECCOM_week.mp4
height150



SECCOM presentation:

View file
name2022-04-26 ONAP Security Meeting - AgendaAndMinutes.pptx
height150