2022-09-06 Security Subcommittee Meeting Notes

Please find below the Minutes of Meetings and recording for the SECCOM meeting that was held on 6th of September 2022.

Jira No

Summary

Description

Status

Solution

Jira No

Summary

Description

Status

Solution

 

5G Super Blueprint - Martial

The major goal is to build a self contained setup that can start and test a 'reference' implementation.

Sabres might not follow entirely 3GPP.

ongoing

 

 

TSC meeting update - September 1st

M3 and M4 moved by 1 week

New PTL for CLI and VNFSDK

TAC is looking for security expert – Amy in touch with Ranny

Project Lifecycle was approved

ongoing

 

 

Ticket created by Thomas Kulik 

New request from Thomas: https://jira.linuxfoundation.org/plugins/servlet/theme/portal/2/IT-24491 

started

 

 

Vulnerabilities management

Single source of truth for recommended versions for ONAP components.

started

Update expected next week.

 

Recommended protocols vs. deprecated/retired

List of cryptographic protocols used in ONAP.

started

To be elaborated next week. Examination activity to be considered.

 

Please register if plan to participate:

ONE Summit NARegistration Open – Amy and Pawel submission accepted!

  • Nov. 15 & 16 2022 Seattle, WA, USA, In Person

  • Pawel and Amy submitted proposal: ONAP’s Recipe for Managing CVEs and Securing Open Source Software

  • Byung will present service descriptor and potentially new ONAP security architecture with service mesh.

LFN Developer & Testing Forum NARegistration Open

  • Nov. 17 & 18 2022 Seattle, WA, USA, In Person

  • Productization of Assured Opensource Software

  • SBOM implementation and challenges in ONAP

 

 

 

Security cloud detailed record concept

Could be presented by Muddasar's colleague from Mitre. It is planned to be presented at the upcoming DTF.

 

 

 

SABRES, OPS-5G Task order, correct?  Dr. Kline (USC) work on Super Blueprint.

Muddasar to share the links

started

https://www.darpa.mil/program/open-programmable-secure-5g

https://www.darpa.mil/news-events/2020-02-05

OUSD(R&E) Mini TEM MOJITO and Linux Foundation 5G ...

https://wiki.onap.org › download › attachments

Contract Announcement Task Details

HR001120S0026-Amendment-02.pdf - GovTribe

https://govtribe.com › file › government-file

 

SECCOM MEETING CALL WILL BE HELD ON 13th OF September'22. 

Architecture review template to be reviewed.

 

 

 

 

Recordings: 

SECCOM presentation: