...
- Assumptions on cert management
- Communication between the network function and DCAE
- Communication between the network function and the controllers
- SSH
- Requirements on projects
Recommendation Status:
DraftRecommended security enhancements for Dublin, presented at PTL meeting Jan 14, 2019.
View file | ||||
---|---|---|---|---|
|
Recommended security enhancements for Dublin to improve secure communications between NFs and ONAP.
View file | ||||
---|---|---|---|---|
|
Assumptions:
May 17, 2018 Agreed to the following Assumptions:
...
- Initial VNF Certificate Enrollment
- Follows ETSI standards: SOL002, SOL003, SOL005, IFA006, IFA007.
- Two options are supported.
Option 1: PKCS#12 container can be installed on the VNF at instantiation time.
Out-of-band pre-provisioning with the CA is necessary to generate the PKCS#12 bundle before the VNF is instantiated.
- Option 2: VNF can perform certificate enrollment with a One Time Password (OTP).
The OTP, which is a Pre-Shared Key (PSK), is generated by the CA, along with a Reference Number (REFNUM) and provisioned on the VNF at instantiation.
- After instantiation, VNF performs certificate enrollment via CMPv2; VNF includes the REFNUM in the Certificate Signing Request (CSR); PSK is used to sign the CSR. See RFC4210 Appendix D.4
- Out-of-band pre-provisioning with the CA is necessary to generate the PSK and REFNUM before the VNF is instantiated. This is just one part of the larger network planning exercise that must be completed before a gNB is deployed.
Oct 5: VNF Activation with updates to remove roles/permissions and perform cert enroll after instantiation - version 20
View file | ||||
---|---|---|---|---|
|
Aug 29: VNF Activation with updates to instantiation scenario - version 18
...
Expand | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Aug 16, 2018
Aug 9, 2018
Aug 2, 2018
July 26, 2018
July 19, 2018
July 12, 2018
June 28, 2018
VNF Initial Certificate Enrollment v2 June 14, 2018
VNF Initial Certificate Enrollment v1 Jun 7, 2018
May 31, 2018
May 24, 2018
May 21, 2018
May 17, 2018
|
Security Requirements for HTTPS Authentication Enhancements:
Aug 6 2019 v4
v4 of the xNF and DCAE security requirements for HTTPS authentication are below. There were no significant changes from v3. These requirements are ready for formal review and have been entered into JIRA. The excel spreadsheet below contains the requirement wording and a link to the JIRA ticket. Please review the JIRA tickets and provide comments or a +1 if you approve. These requirements are targeted for El Alto, so please review by Sep 3, 2019. Thank you!
El Alto Security Requirements for HTTPS.xlsx
July 29 2019 v3
v3 of xNF and ONAP security requirements for HTTPS authentication. Modified based on decisions from the July 29 review meeting.
- Add requirement for one-way TLS authentication when using Basic Authentication.
- Add reference to RFC 5280 to specify how to validate a certificate.
- Eliminate certOnly and basicAuthOnly and noAuth options and support only certBasicAuth in DCAE.
Security VNFRQTS updates for HTTPS Authentication v3.docx
July 23 2019 v2
Updated version of the xNF and ONAP security requirements for HTTPS authentication enhancements from the July 23 review meeting.
Security VNFRQTS updates for HTTPS Authentication v2.docx
July 16 2019 v1
This is the latest version of the xNF and ONAP security requirements for the HTTPS authentication enhancements to support certificate authentication for HTTPS.
At the last review meeting on July 16, SECCOM decided that only HTTP/TLS is supported. HTTP would not be supported.
Security VNFRQTS updates for HTTPS Authentication.docx