Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

In Frankfurt Authorization and Authentication are implemented. Accounting is not considered.

Related to: 

Jira
serverONAP JIRA
serverId425b2b0a-557c-3c0c-b515-579789cceedb
keySDNC-880

Jira
serverONAP JIRA
serverId425b2b0a-557c-3c0c-b515-579789cceedb
keySDNC-897

Components referring Refering to disaggregated Frankurt SDNR architecture

  • Affected containers are:SDNC/OAM/SDNR
  • SDNRDB
  • SDNRWEBArchitecture

Authentication of SDNC/OAM/SDNR client with

  • SDNR → DMaaP/DCAE
  • SDNR → SDNRDB

Authorization between containers

  • password only or
  • certificated base for client side authentication 

Questions are

  • How to provide password/certs?
  • Using: Kubernetes Secrets?
  • How to handle passwords inside container
    1. Hand over Kubernetes into container 
    2. Hand over inside containter container to karaf/odl  
  • File or environment variable?


Server/Componentsupported auth methodcomments
SDNC(Opendaylight)

basic auth (username,password)
token based auth
ssl client cert?


SDNC-Web (nginx)basic auth
ssl client cert

SDNC-database (elasticsearch+nginx)basic auth
ssl client cert

DMaaP Message Router

basic auth (HTTP)

auth key (HTTP_AUTHKEY)


AAI

DCAE
not important for us, only for devices