Uploaded image for project: 'Network Controller'
  1. Network Controller
  2. SDNC-970

Password removal from OOM Helm charts

XMLWordPrintable

    • Icon: Epic Epic
    • Resolution: Done
    • Icon: High High
    • Frankfurt Release
    • None
    • None
    • None
    • Password removal
    • To Do

      As discovered in ONAP Casablanca pentest (and confirmed in latest version) OOM contains a lot of different passwords. There are 3 issues related to this:

      1) Some of passwords are stored in resource files rather than in secrets

      2) The same passwords are reused for almost all deployments

      3) It's is not possible to use already existing secrets for ONAP deployment

      To fix those issues we plan:

      1) Ensure that all passwords are stored in kubernetes secrets

      2) Make all passwords randomly generated per deployment unless a passwords override has been provided for the deployment

      3) Add ability to use external secrets instead of providing passwords override.

            djtimoney Dan Timoney
            djtimoney Dan Timoney
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: