|
ONAP weekly security committee meeting.
Update – correcting the time Update: The agenda can be found at: https://wiki.onap.org/display/DW/ONAP+Security+coordination -- Hi All, Here is a regular call for the ONAP security committee team meet
Update – correcting the time Update: The agenda can be found at: https://wiki.onap.org/display/DW/ONAP+Security+coordination -- Hi All, Here is a regular call for the ONAP security committee team meet
|
By
Amy Zwarico
· #55
·
|
|
FW: [onap-tsc] [onap-discuss] Importance of common auth service in this release
Please add the common authentication/authorization service to the agenda for the 10/11 Security subteam meeting.
Please add the common authentication/authorization service to the agenda for the 10/11 Security subteam meeting.
|
By
Amy Zwarico
· #70
·
|
|
ONAP R2
I suggest putting this on the agenda for the 10/11 meeting
I suggest putting this on the agenda for the 10/11 meeting
|
By
Amy Zwarico
· #71
·
|
|
Carrier Grade addition for comments (security)
I’ve added a list of passing (bronze) requirement that non-projects have to satisfy. I’m pretty adamant about getting crypto right the first time and documentation. I will take a stab at silver and go
I’ve added a list of passing (bronze) requirement that non-projects have to satisfy. I’m pretty adamant about getting crypto right the first time and documentation. I will take a stab at silver and go
|
By
Amy Zwarico
· #76
·
|
|
Meeting November 1
I plan on attending
By
Amy Zwarico
· #92
·
|
|
Proposed topic for Wednesday meeting
Review the TSC decision on bug fixes and security patching for the Amsterdam release. Amy Zwarico, LMTS Chief Security Office / Enterprise Security Support / Cloud Security Services AT&T Services
Review the TSC decision on bug fixes and security patching for the Amsterdam release. Amy Zwarico, LMTS Chief Security Office / Enterprise Security Support / Cloud Security Services AT&T Services
|
By
Amy Zwarico
· #102
·
|
|
CLAMP and CII Badging
Martial Ngueko, project technical lead for CLAMP, said that the CLAMP team has not done any further work on CII badging. -Amy
Martial Ngueko, project technical lead for CLAMP, said that the CLAMP team has not done any further work on CII badging. -Amy
|
By
Amy Zwarico
· #114
·
|
|
OAuth Access Token Revocation IETF RFC
https://tools.ietf.org/html/rfc7009
https://tools.ietf.org/html/rfc7009
|
By
Amy Zwarico
· #188
·
|
|
ONAP Security Agenda for 2/28/2018
I will be hosting tomorrow’s seccom call while Steve is on vacation. Attached is the agenda. -Amy
I will be hosting tomorrow’s seccom call while Steve is on vacation. Attached is the agenda. -Amy
|
By
Amy Zwarico
· #208
·
|
|
ONAP Security Subcommittee breakout at ONS
Several of us from the ONAP sub-committee who are attending ONS are going to meet on Wednesday morning at 8am on the tables on the 6th floor of the Intercontinental hotel. If you are at ONS, please gr
Several of us from the ONAP sub-committee who are attending ONS are going to meet on Wednesday morning at 8am on the tables on the 6th floor of the Intercontinental hotel. If you are at ONS, please gr
|
By
Amy Zwarico
· #261
·
|
|
[onap-tsc] Known vulnerability analysis of CLI
Hi Kanagaraj, I was reviewing the CLI known vulnerability analysis – thank-you for providing that (https://wiki.onap.org/pages/viewpage.action?pageId=28377287) 1. You stated that the use of the common
Hi Kanagaraj, I was reviewing the CLI known vulnerability analysis – thank-you for providing that (https://wiki.onap.org/pages/viewpage.action?pageId=28377287) 1. You stated that the use of the common
|
By
Amy Zwarico
· #274
·
|
|
ONAP Vulnerability Report - SO
Hi Seshu, I was reviewing the SO known vulnerability analysis – thank-you for providing that (https://wiki.onap.org/pages/viewpage.action?pageId=28377799) 1. Is the vulnerability in camunda-webapp-jbo
Hi Seshu, I was reviewing the SO known vulnerability analysis – thank-you for providing that (https://wiki.onap.org/pages/viewpage.action?pageId=28377799) 1. Is the vulnerability in camunda-webapp-jbo
|
By
Amy Zwarico
· #275
·
|
|
ONAP Vulnerability Report -
Hi Tao, I was reviewing the Usecase-UI known vulnerability analysis – thank-you for providing that (https://wiki.onap.org/pages/viewpage.action?pageId= 28379767) 1. Please clarify what you mean by the
Hi Tao, I was reviewing the Usecase-UI known vulnerability analysis – thank-you for providing that (https://wiki.onap.org/pages/viewpage.action?pageId= 28379767) 1. Please clarify what you mean by the
|
By
Amy Zwarico
· #276
·
|
|
ONAP Vulnerability Report - VF-C
Hi Yan, I was reviewing the Usecase-UI known vulnerability analysis – thank-you for providing that (https://wiki.onap.org/pages/viewpage.action?pageId=25437810) 1. Is VF-C using the vulnerable compone
Hi Yan, I was reviewing the Usecase-UI known vulnerability analysis – thank-you for providing that (https://wiki.onap.org/pages/viewpage.action?pageId=25437810) 1. Is VF-C using the vulnerable compone
|
By
Amy Zwarico
· #277
·
|
|
Notes from ad hoc meeting on 3/28/2018 at ONS
A few of us who were at ONS had an ad hoc meeting on Wednesday morning to create a proposed prioritization of the seccom deliverables for Casablanca. Attached are the notes and prioritization. This wi
A few of us who were at ONS had an ad hoc meeting on Wednesday morning to create a proposed prioritization of the seccom deliverables for Casablanca. Attached are the notes and prioritization. This wi
|
By
Amy Zwarico
· #278
·
|
|
[onap-tsc] Known vulnerability analysis of CLI
Thank you for the update. Please update the vulnerability analysis for CLI at (https://wiki.onap.org/pages/viewpage.action?pageId=28377287) with this information.
Thank you for the update. Please update the vulnerability analysis for CLI at (https://wiki.onap.org/pages/viewpage.action?pageId=28377287) with this information.
|
By
Amy Zwarico
· #313
·
|
|
ONAP Vulnerability Report - VF-C
Thank you for the information. Please update the vulnerability analysis in the wiki (https://wiki.onap.org/pages/viewpage.action?pageId=25437810) with this information. Thank you, Amy
Thank you for the information. Please update the vulnerability analysis in the wiki (https://wiki.onap.org/pages/viewpage.action?pageId=25437810) with this information. Thank you, Amy
|
By
Amy Zwarico
· #314
·
|
|
CMPv2 support in AAF
I agree. Good catch.
By
Amy Zwarico
· #350
·
|
|
SECCOM meeting time extention?
Either option works for me
Either option works for me
|
By
Amy Zwarico
· #361
·
|
|
Documenting Security Issue in Release Notes
In my opinion, it is the CLAMP note is good and can be followed by each of the projects. I suggest modifying the second sentence to read “CLAMP code is formally scanned at build time using NexusIQ,…”
In my opinion, it is the CLAMP note is good and can be followed by each of the projects. I suggest modifying the second sentence to read “CLAMP code is formally scanned at build time using NexusIQ,…”
|
By
Amy Zwarico
· #379
·
|