Uploaded image for project: 'Release Requirements'
  1. Release Requirements
  2. REQ-231

HTTPS communication vs. HTTP

XMLWordPrintable

    • HTTPS communication vs. HTTP
    • 1

      According to scan executed on 25.10.2019 below HTTP ports are exposed by ONAP:

       It is significantly less than number of open OJSI tickets related to HTTP exposed because some issues has been already fixed but PTL didn't provide any comment in the OJSI ticket which hurts our transparency and traceability.

      This requirement requires two actions:

      1) Review OJSI tickets open and if ticket is already fixed provide a comment with hash-id of commit that removed the HTTP exposure

      2) If port is exposed work towards making it HTTPS instead of HTTP or removing it or providing SECCOM a good explanation why you need to expose HTTP and get a waiver.

       

       

       

       

            kopasiak kopasiak
            Pawel_P Paweł Pawlak
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated: