2021-03-23 Security Subcommittee Meeting Notes

Please find below the Minutes of Meetings and recording for the SECCOM meeting that was held on 23rd of March 2021.

Jira No

Summary

Description

Status

Solution

Jira No

Summary

Description

Status

Solution

 

Last TSC update

CNF Task Force meeting moved to 31st of March, US governement support may help increasing open source „apps 5G”. 

https://zoom.us/j/219945081?pwd=ZEN3U3daem9oMGJuZ3BXZExCdldkUT09

ogoing

SECCOM representatives will join this session with US military on open source secure software development for 5G.

 

Last TSC meeting

  • RC0 merged with RC1 on March 25th

  • Hardcoded certificate in AAI just expired, HELM limitations

  • Istanbul release – kick-off date (M0) April 1st. Full planning redefinition to be determined

  • Our proposal to replace maintained by unmaintained was approved by TSC

  • Chaker integrated security programming best practices

  • We are to book a slot at on e of next TSCs (25th of March) to present our proposal for moving TSC best practices to global requirements by M1 for:

    • CII Badging

    • Upgrading packages

  • Internship – we have to act fast…but we need time to be an active mentor

ongoing

Slot to be booked for the next TSC meeting for moving best practices to global requirements

 

How to create secure applications

https://lf-onap.atlassian.net/wiki/display/DW/Secure+Programming+Practices

Already linked by Chaker, presented to TSC and presented to PTLs.

ongoing

PTLs will provide their feedback by March 29th

 

SonarCloud findings to fix in Istanbul release

  • Focus on fixing crypto vulnerabilities

  • How to tag unmaintained projects

  • Automation introduction for projects not fixing the vulnerability within 60 days

ongoing

Tony to contact David Wheeler to check if automation could be introduced

 

NEXUS-IQ container scanning 

New feature under checking with LFN, but no update from Jess

ongoing

Amy to contact Jess for an update

 

Logs management

Follow up by Amy – container logging requirements review:

ongoing

Requirements to be reviewed next week at the SECCOM meeting.

 

OUR NEXT SECCOM MEETING CALL WILL BE HELD ON 30th OF MARCH'21. 

 

 

 

 

Recording:

 

SECCOM presentation: