User Tools

Site Tools


meetings:security:03062015

Security Group 03/06/2015

Attendees:

  • Luke Hinds (Nokia) - Chaired
  • Juan Antonio Osorio Robles (Ericsson)
  • Ari Pietikäinen (Ericsson)
  • Mike Bursell (Intel)
  • Mike Camel (Intel)
  • Luigi (Huawei)
  • Kapil Sood (intel)
  • Ashutosh (AT&T)

Agenda

  • ETSI Mapping
  • Inspector Discussion

agenda bashing (LukeHinds, 14:02:23)

  https://etherpad.opnfv.org/p/opnfv-sec-meetings (LukeHinds, 14:02:38)
  LukeHinds: did anyone want to add to the agenda? (LukeHinds, 14:03:36)
  AGREED: agenda (LukeHinds, 14:04:35)

OSVM (LukeHinds, 14:04:48)

  quick one here, I am back in touch with Aric to finalise this (they were busy with the release) and hope to present the whole process to the TSC (LukeHinds, 14:05:21)

Inspector Update

      Inspector has finally been approved as an official OPNFV project (jaosorior, 14:11:17)
      As I mentioned in the mail, I have already asked for a repository and a bug-tracker (jaosorior, 14:11:45)
      the guys would like to use the security group to align / discuss inspector activties, which was agreed to be a good idea. (LukeHinds, 14:11:52)
      jaosorior: We should look into making the material that has been already created by ETSI and CSA into a concrete maping towards the components we use in OPNFV (LukeHinds, 14:14:15)
      aripie: provisioning list should be sanity checked (LukeHinds, 14:14:35)
      inspector can be used for SEC008, a work item on security monitoring and management in ETSI NFV which may well be very relevant. (LukeHinds, 14:16:11)
      ACTION: Kapil to attend next SEC group to discuss SEC008 and inspector (LukeHinds, 14:17:00)
      ACTION: Luke to contact Ashutosh to perform the same. (LukeHinds, 14:17:19)
      ACTION: Luke to contact ONF about inspector project (LukeHinds, 14:20:14)
      https://etherpad.opnfv.org/p/inspector_preliminary (aripie, 14:22:11)
      three main activities: (LukeHinds, 14:23:31)
      Proactively monitor the components (such as OpenStack) to see that the relevant events in the system (such as requests taken in the services) are properly emitted (logged) (LukeHinds, 14:23:42)
      Align with relevant institutions (such as ETSI) in order to have their requirements and use-cases be mapped in a concrete way with the actual services we are using in OPNFV (LukeHinds, 14:23:56)
      Respond to bug-reports (and properly implement them in the components upstream), which will be filed when we figure out there is something missing or when our shareholders report they need more information for a certain use-case (LukeHinds, 14:24:03)
      all covered in the following #link https://etherpad.opnfv.org/p/inspector_preliminary (LukeHinds, 14:24:19)
      https://wiki.opnfv.org/requirements_projects/inspector (jaosorior, 14:44:14)
      ACTION: juan/ari to start listing specific components / work items for commiters / contributers (LukeHinds, 14:48:17)

Other items

  I had an action to contact the ODL. Next week David Jorm and Colin Dixon of ODL will join us to discuss Inspector and how that would work in a collaborative effort with opendaylight (LukeHinds, 14:06:52)
  David Jorm started the security group there (LukeHinds, 14:07:05)
  Colin Dixon is the TSC chair on opendaylight (LukeHinds, 14:07:56)
  ari and juan had to call off listing work items for inspector this week, as juan is on leave/ (LukeHinds, 14:08:56)
  here is a good little overview of inspector that ari / juan just did https://etherpad.opnfv.org/p/inspector_preliminary (LukeHinds, 14:21:47)
  https://wiki.openstack.org/wiki/Ceilometer/blueprints/support-standard-audit-formats (LukeHinds, 14:31:38)
  http://docs.openstack.org/developer/keystone/event_notifications.html (LukeHinds, 14:34:08)

Full Meetbot Log http://ircbot.wl.linuxfoundation.org/meetings/opnfv-sec/2015/opnfv-sec.2015-06-03-13.59.html

meetings/security/03062015.txt · Last modified: 2015/06/10 13:57 by Luke Hinds