Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Jira No
SummaryDescriptionStatusSolutionDavid Wheeler presnetation on SBOM and digital signatures

Operationalization of OpenSSF recommendations is not an easy topic...

David's slides: https://docs.google.com/presentation/d/1BptlMG8kV14FutTMx3s9u4EnIL1Yzxt6-NID5H5XfAE/edit#slide=id.g13d496f372e_0_110

https://openssf.org/oss-security-mobilization-plan/

  • Identifies 3 goals, 10 streams to address those goals

SBOM recommended to be part of build process.

Package managers are good first step. SPDX in SECCOM uses package manager.

Dan Lorenc wrote an interesting papaer on what is inside the container.


Update on the Security Logging Fields and Global Requirement  

DRAFT slides: https://wiki.onap.org/display/DW/Security+Logging+Fields+-+Global+Requirement

Bob presented the deck and collected feedback.

Implementatiojn does not require highly qualified resources to modify XML files. To be further investigated the project complexity and resources needed to implement.

ongoing

Other than CPS project shall be involved for resource estimation for requirement implementation.

Test proposal - can it be taken from CPS on how do you know it works?


SBOM creation 

Good news: It worked on DCAE VES repo.

-https://logs.onap.org/production/vex-yul-ecomp-jenkins-1/dcaegen2-collectors-ves-maven-stage-master/1142/sbom-dcaegen2-collectors-ves-maven-stage-master

- SBOM file is generated successfully without any further manipulation after the SBOM SW upgrade

LF IT will be introducing an another parameter in the Jenkins job that will allow to define the target path for the repo.

ongoingWaiting for the feedbck on introducing and testing 

Superblueprint

They preparing some demo for ONES NA. Security aspects would be good to cover, it would require to contribute and attend their meetings (on Tuesdays and Wednesdays).

-Currently project team is seeking suggestion on Use cases:  https://wiki.lfnetworking.org/pages/viewpage.action?pageId=68792322

- Advisory group: https://wiki.lfnetworking.org/display/LN/Advisory+Group+Meeting+Minutes

- Please feel free to add what you think will add value.

- SBP FAQs: https://wiki.lfnetworking.org/display/LN/5G+Super+Blueprint+FAQ

Security slicing definition to be explored. Is it related only to confidentiality? 

It can be securing entire Ci/CD pipeline

ongoingAmy to share meeting invitation to SECCOM distribution list. 

Service Mesh for Kohn release

follow-up of the Andreas presentation - service mesh used for communication as default.

AuN and AuZ as next steps by E/// team. Connection to Keyclock is needed for user management with token. For London to be applied.

AAF removal not ready for Kohn as providing full RBAC and certificates. Target to London.

ISTIO GW configuration.We ave only one ONAP namespace.


Andreas will talk to Seshu.

Byung will have internal meeting at E/// to keep resources to support service Mesh.


PTL meeting – July 25th

Kohn M3 scheduled for Sept 1




TSC meeting – July 21st

Approved Kohn M2 under the condition that GR / Best Practice are color coded by all projects by M3.




Pawel and Amy submitted proposal, 

Byung will present service descriptor and potentially new ONAP security architecture with service mesh.


Proposal to be submitted - CFP deadline is July 29thNext LFN events

ONE Summit NARegistration Open

  • CFP - Deadline: July 8th; 2022
  • Nov. 15 & 16 2022 Seattle, WA, USA
  • In Person

LFN Developer & Testing Forum NARegistration Open

  • Nov. 17 & 18 2022 Seattle, WA, USA
  • In Person
  • Securiung software supply chain by LFN - new topic to be proposed
Proposals to be submitted.

SECCOM MEETING CALL WILL BE HELD ON 26th 2nd OF JulyAugust'22. logging implementation discussion continuation.






Recording: 

View file
name2022-07-26_SECCOM_week.mp4
height150


SECCOM presentation:

View file
name2022-07-26 ONAP Security Meeting - AgendaAndMinutes.pptx
height150