Recommendation Scope:

The scope of this recommendation is to cover how ONAP achieves secure communication to the network functions.  The network functions could be VNFs, PNFs.  This includes:

Recommendation Status:

Recommended security enhancements for Dublin, presented at PTL meeting Jan 14, 2019.


Recommended security enhancements for Dublin to improve secure communications between NFs and ONAP.

Assumptions:

May 17, 2018 Agreed to the following Assumptions:

Recommendations:

May 17, 2018 Agreed to the following Recommendations:

May 21, 2018 Agreed to the following Recommendation:

May 24, 2018 Agreed to the following Recommendations:

May 31, 2018 Agreed to the following Recommendations:

Oct 5: VNF Activation with updates to remove roles/permissions and perform cert enroll after instantiation - version 20


Aug 29: VNF Activation with updates to instantiation scenario - version 18


Aug 23:  PNF Registration Scenario with Security Enhancements added


Aug 23:  Final VNF Activation presentation - version 16  

Aug 16:  Update to show SO calling OpenStack directly, no M-VIM - version 14

Aug 9:  Update which data is sent during instantiation vs configuration - version 13

Aug 6: Update CA signing chain to CA root certificate - version 12

Aug 2: Update to last slide for CADI - version 11


July 28: Updated use case document - version 10

 

July 24: Updated use case document - version 8

July 18: Use case document - version 6




Security Enhancements Roadmap

Aug 23, 2018

Aug 16, 2018


Aug 9, 2018


Aug 2, 2018

Meeting Minutes:

Aug 23, 2018


Aug 16, 2018


Aug 9, 2018


Aug 2, 2018


July 26, 2018


July 19, 2018


July 12, 2018



June 28, 2018


VNF Initial Certificate Enrollment v2


June 14, 2018


VNF Initial Certificate Enrollment v1


Jun 7, 2018


May 31, 2018

May 24, 2018


May 21, 2018


May 17, 2018


Security Requirements for HTTPS Authentication Enhancements:

Aug 6 2019 v4

v4 of the xNF and DCAE security requirements for HTTPS authentication are below.  There were no significant changes from v3.  These requirements are ready for formal review and have been entered into JIRA.  The excel spreadsheet below contains the requirement wording and a link to the JIRA ticket.  Please review the JIRA tickets and provide comments or a +1 if you approve.  These requirements are targeted for El Alto, so please review by Sep 3, 2019.  Thank you!

El Alto Security Requirements for HTTPS.xlsx


July 29 2019 v3

v3 of xNF and ONAP security requirements for HTTPS authentication.  Modified based on decisions from the July 29 review meeting.

  1. Add requirement for one-way TLS authentication when using Basic Authentication.
  2. Add reference to RFC 5280 to specify how to validate a certificate.
  3. Eliminate certOnly and basicAuthOnly and noAuth options and support only certBasicAuth in DCAE.


Security VNFRQTS updates for HTTPS Authentication v3.docx


July 23 2019 v2

Updated version of the xNF and ONAP security requirements for HTTPS authentication enhancements from the July 23 review meeting.


Security VNFRQTS updates for HTTPS Authentication v2.docx


July 16 2019 v1

This is the latest version of the xNF and ONAP security requirements for the HTTPS authentication enhancements to support certificate authentication for HTTPS.

At the last review meeting on July 16, SECCOM decided that only HTTP/TLS is supported.  HTTP would not be supported.

Security VNFRQTS updates for HTTPS Authentication.docx