2021-04-20 Security Subcommittee Meeting Notes

Please find below the Minutes of Meetings and recording for the SECCOM meeting that was held on 20th of April 2021.

Jira No

Summary

Description

Status

Solution

Jira No

Summary

Description

Status

Solution

 

Java and python upgrades in Istanbul release

We do not plan on creating tickets for unmaintained projects, instead we should add those repos to Morgan’s exception list.

Looking for info on which projects are responsible for the following repos:(responses from PTLs in parentheses)

  • ejbca-ejbca (testing)

  • esr-gui (unmaintained - exclude)

  • esr-server (unmaintained - exclude)

  • message-router, message-router-kafkamessage-router-zookeeper (DMAAP)

  • framework-artifactbroker (MULTICLOUD)

  • awx-celery, awx-rabbit,awx-web (testing)

  • robot (testing & integration)

ongoing

Additional jiras to be created excluding the ones related to testing that will go to whitelist.

Awx to be checked in what context it is used for testing - Morgan to be asked.

 

 

Security and critical vulns per project

Orange developer strated with DMaap: 421 issues down to 53 - at the last PTLs meeting DMaaP PTL promissed to review the proposed changes and merge it.

Next step will be to analyze SO.

ongoing

 

 

NSA contribution proposal for ONAP security

Vijay reached-out Maggie, establishing contact with relevant ONAP community members.

ongoing

Next meeting to be booked.

 

CNF Task Force enterprise business workgroup 

Meeting on April 14th at 2:00 UTC - 

Work with O-RAN to use ONAP for service management and orchestration, how to handle Magma - no decision yet on how to treat access control gw? ONAP Architecture Subcommittee to be involved.

ongoing

Feedback collection on Magma

 

[WAIVERS] Set Honolulu security waivers

Merge done

done

 

 

Meeting with Jess and SECCOM on Jenkins/Gerrit and SonarCloud

Meeting done on April 15th - integration between Wikimedia and Sonar:

https://phabricator.wikimedia.org/phame/post/view/160/introducing_the_codehealth_pipeline_beta/

ongoing

Fabian will come back to us with an update.

 

Slide deck for new Global Requirements

No slot again at the last TSC, although booked. - e-mail request was sent to TSC distribution list

ongoing

Waiting for TAC approval

 

Training for SonarCloud

Please refer to slides in the slide deck below for a complete list of the questions.

Additional question identified on possibility to integrate SonarCloud with Gerrit – scan before merge.

ongoing

Updated list of questions to be shared by Jess with SonarCloud team.

 

CII Badging – automation support for Tony

Dave Wheeler was able to create a base library that could be used to do an update. Tony created a Python script that would allow updates to big number of projects based on configuration file.

ongoing

Next step is to get additional people and try it out - especially David McBride. Code is available in Tony's GitHub private area.

 

Container logging requirements

Container application logging ok but for container not.

Logging is stored in stdout, how it gets out of the container?. 

Kubernetes can capture both stdout and stderr. Additional component is needed like FluentD to push those logs to an external system.

How does container know from which container logs come from?

It is important to know what security information in the logging has

ongoing

General link to requirements to be added.

 

OUR NEXT SECCOM MEETING CALL WILL BE HELD ON 27th OF APRIL'21. 

 

 

 

 

Recording:

 

SECCOM presentation: