Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

No.Project NameTSC Subgroup Release StatusIs this your first release Going for Maturity Review? 

CD Logs URL to be used for review

(Column filled in by PTLs)

Link to executive one pager

(editable doc format)

(Column filled in by PTLs)

API Info Reporting Info Review

(Column filled in by API Subcommittee)

(note for PTLs – go here for steps to fill in project API info template)

BluVal

Certification

Security

Certification

Provide link to Vuls, Lynis, and Kube-Hunter logs below.

Pass/Fail Criteria:  Steps To Implement Security Scan Requirements

Exception requests should be filed at:

https://wiki.akraino.org/display/AK/Akraino+CVE+Vulnerability+Exception+Request

Upstream Review (Column filled by Upstream Subcommittee and PTLs)


(note PTL can go to Release Upstream Compliance to find details)

Date ready for TSC review

(Column filled in by PTLs)

 TSC Review Date

(Column filled in by TSC)

1scheduled at 

TSC 2020-12-01 (Tues) 7 am Pacific

NY

https://nexus.akraino.org/content/sites/logs/parserlabs/r4/jobs/cvb/


https://nexus.akraino.org/content/sites/logs/parserlabs/r4/jobs/cvb/

 

Vuls:  Accepted with exceptions show at:

Release 4 Vuls Exception Request

 

Lynis:  Failed - errors sent to BP owner

Kube-Hunter:  Exception granted:  K8s not used by this BP.

Yes12/01
2scheduled at 

TSC 2020-12-01 (Tues) 7 am Pacific

NY

https://nexus.akraino.org/content/sites/logs/parserlabs/r4/jobs/iec-type4/


https://nexus.akraino.org/content/sites/logs/parserlabs/r4/jobs/iec-type4/

 

Vuls:  Failed - errors sent to BP owner

 

Lynis:  Failed - errors sent to BP owner

Kube-Hunter:  Exception granted:  K8s not used by this BP.

Yes12/01
3Scheduled at Release 4 Review 2020-12-01 (Tues) 7 am PacificNMature

https://nexus.akraino.org/content/sites/logs/att/job/Install_REC_on_OpenEdge1/

https://logs.akraino.org/production/vex-yul-akraino-jenkins-prod-1/rec-aarch64_baremetal-install-rec-weekly-master/

Received.

Accepted

https://nexus.akraino.org/content/sites/logs/att/job/Bluval_Logs/results-11-27-2020.tar

https://nexus.akraino.org/content/sites/logs/att/job/Bluval_Logs/results-11-27-2020.tar

 

Vuls:  Accepted with exceptions show at:

Release 4 Vuls Exception Request

 

Lynis:   - errors sent to BP owner

Kube-Hunter: Does not appear to have run correctly - question sent to BP owner




4Scheduled at 

Release 4 Review 2020-12-16 (Wed) 7 am Pacific

NN

ICN Master Baremetal Deployment Verifier

ICN Master Virtual Deployment Verifier

ICN SDEWAN Master End2End Testing

Received

Accepted

https://nexus.akraino.org/content/sites/logs/intel/bluval_results/icn/master/20201210-010310/.

https://nexus.akraino.org/content/sites/logs/intel/bluval_results/icn/master/20201210-010310/

ICN R4 Test Document#BluValTesting

Vuls:  Accepted with exceptions show at:

Release 4 Vuls Exception

os/lynis:

  • USB-2000: ICN contributor whitelisted HID keyboard and mouse.  Without this, we lose keyboard and mouse access through the BMC console, and the means to access the node without physically visiting the lab.
  • SSH-7408, MaxSessions and Port: ICN contributor left these at 10 and 2222 respectively to allow Lynis to run.

  • Lynis:  Accepted with exceptions show at:

    Release 4 Lynis Exceptions

    KRNL-6000, net.ipv4.conf.all.forwarding: ICN contributor left this enabled following other discussions on security list email about the requirement by Kubernetes.


    k8s/conformance:

    k8s/kube-Hunter:

    • The logs show the run with the aquasec/kube-hunter:edge image to fix the CAP_NET_RAW inside a pod issue


    Yes12/1012/16
    5scheduled at 

    TSC 2020-12-15 (Tues) 7 am Pacific

    NN

    https://nexus.akraino.org/content/sites/logs/huawei/blueprints/iotgateway/job/eliot-iotgateway-deploy-k8s-virtual-daily-master/649/





    https://nexus.akraino.org/content/sites/logs/huawei/blueprints/iotgateway/job/eliot-iotgateway-bluval-virtual-daily-master/11/results/

    vuls exceptions Akraino CVE Vulnerability Exception Request

    Akraino BluVal Exception Request

     

    Vuls:  Accepted with exceptions show at:

    Release 4 Vuls Exception

    Lynis: Failed -

    For the following test for installed compilers, this issue MUST be fixed:

    1. Performing test ID HRDN-7220 (Check if one or more compilers are installed)

    Release 4 Lynis Exceptions

    Kube-Hunter:  Accepted with exceptions show at:

    Release 4 Kube-Hunter Exceptions


    12/08
    6scheduled at 

    TSC 2020-12-15 (Tues) 7 am Pacific

    NNhttps://nexus.akraino.org/content/sites/logs/huawei/blueprints/uCPE/job/eliot-uCPE-deploy-k8s-centos-virtual-daily-master/534/

    https://nexus.akraino.org/content/sites/logs/huawei/blueprints/uCPE/job/eliot-uCPE-deploy-k8s-centos-virtual-daily-master/535/results/

    vuls exceptions Akraino CVE Vulnerability Exception Request

    Akraino BluVal Exception Request

     

    Vuls:  Accepted with exceptions show at:

    Release 4 Vuls Exception

    Lynis: Failed

    ISSUES that MUST be fixed or a more specific exception reason needs to be provided:

    1. sysctl key kernel.dmesg_restrict contains equal expected and current value (1)  ## Restrict unprivileged access to kernel syslog

    For the following test for installed compilers, this issue MUST be fixed:

    1. Performing test ID HRDN-7220 (Check if one or more compilers are installed)

    Release 4 Lynis Exceptions

    Kube-Hunter:  Accepted with exceptions show at:

    Release 4 Kube-Hunter Exceptions

    Yes12/08
    7

    Scheduled at

    Release 4 Review 2020-12-09 (Wed) 7:30am


    NNot Applicable

    https://nexus.akraino.org/content/sites/logs/juniper/job/NC-Tungsten_Fabric/40/



    NetworkCloud-TF blueprint Datasheet.docx

    UploadedY

     

    Vuls:  Need to provide vuls.log

     

    Lynis:  ISSUES that MUST be fixed or a more specific exception reason needs to be provided:

    1. Performing test ID BOOT-5122 (Check for GRUB boot password)
    2. Test: Checking PASS_MAX_DAYS option in /etc/login.defs
    3. Performing test ID AUTH-9328 (Default umask values)
    4. Performing test ID SSH-7440 (Check OpenSSH option: AllowUsers and AllowGroups)
    5. sysctl key fs.suid_dumpable contains equal expected and current value (0)
    6. sysctl key kernel.dmesg_restrict contains equal expected and current value (1)
    7. Test: Check if one or more compilers can be found on the system

    Following compilers found:

    • Found known binary: as (compiler) - /usr/bin/as
    • Found known binary: cc (compiler) - /usr/bin/cc
    • Found known binary: gcc (compiler) - /usr/bin/gcc

     

    Kube-Hunter:  In review

    Sukhdev Kapur has requested that the Release 3 exceptions be provided for Release 4

    Y12/0912/09
    8Scheduled at 

    TSC 2020-12-17 (Thurs) 7 am Pacific

    NN

    AWS footprint:
    https://logs.akraino.org/production/vex-yul-akraino-jenkins-prod-1/kni-blueprint-pae-verify-deploy-aws/81/

    GCP footprint:

    https://logs.akraino.org/production/vex-yul-akraino-jenkins-prod-1/kni-blueprint-pae-verify-deploy-gcp/51/


    Received

    Accepted

    N [ Not passing as blueprint is based on OKD, not Kubernetes. So we run our own validation suite - https://logs.akraino.org/redhat-kni/bluval_results/blueprint-pae/20200505-104443/out.log ]



    12/0912/09
    9Scheduled at 

    TSC 2020-12-17 (Thurs) 7 am Pacific

    YN

    Mgmt Hub logs:

    https://logs.akraino.org/production/vex-yul-akraino-jenkins-prod-1/kni-blueprint-management-hub-verify-deploy-gcp/9/

    IE logs:

    https://logs.akraino.org/production/vex-yul-akraino-jenkins-prod-1/kni-blueprint-ie-verify-deploy-gcp/2/


    Received

    Accepted






    10

    Micro-MEC


    YNhttps://nexus.akraino.org/content/sites/logs/micromecAkraino R3 MicroMEC blueprint datasheet.docxReceivedN/A





    11

    Scheduled at TSC 2020-11-24 (Tues) 7 am Pacific

    NY

    https://nexus.akraino.org/content/sites/logs/baidu/job/aiedge-otestack-master-deploy/

    https://nexus.akraino.org/content/sites/logs/baidu/job/aiedge-otestack-master-validation/


    N/A



    06/02
    12

    The AI Edge: Intelligent Vehicle-Infrastructure Cooperation System(I-VICS) Hechun Zhang


    YN







    13

    5G MEC/Slice System to Support Cloud Gaming, HD Video and Live Broadcasting Blueprint

    Feng Yang


    YN

    https://nexus.akraino.org/content/sites/logs/tencent/job/5g-mec-cloud-gaming-CD/15/

    https://logs.akraino.org/production/vex-yul-akraino-jenkins-prod-1/5g-mec-cloud-gaming-master-verify/

    5G MEC Rel 3 DatasheetReceivedN/A



    06/03
    14

    Scheduled at

    TSC 2021-1-14 (Thurs) 7 am Pacific

    NNhttps://nexus.akraino.org/content/sites/logs/ampere/job/akraino_arm_anbox_test/6/




    01/15
    15Scheduled at 

    TSC 2020-12-10 (Thurs) 7 am Pacific

    NN

    https://nexus.akraino.org/content/sites/logs/bytedance/job/run-install-bluefield-fs/

    https://nexus.akraino.org/content/sites/logs/bytedance/job/run-install-ovs-dpdk/


    NA (First Release)


    Release document is still for R306/04
    16scheduled at 

    TSC 2020-12-10(Thurs) 7 am Pacific

    NN
    https://nexus.akraino.org/content/sites/logs/huawei/blueprints/ealt-edge/
    job/ealt-edge-deploy-virtual-daily-master/397

    Received;

    Accepted

    https://nexus.akraino.org/content/sites/logs/huawei/blueprints/ealt-edge/job/ealt-edge-bluval-daily-master/237/results/

    updated results link - 09-dec

    Vuls Exception Akraino CVE Vulnerability Exception Request

    Akraino BluVal Exception Request

    https://nexus.akraino.org/content/sites/logs/huawei/blueprints/ealt-edge/job/ealt-edge-bluval-daily-master/237/results/

    Akraino CVE Vulnerability Exception Request

     

    Vuls:  Accepted with exceptions show at:

    Release 4 Vuls Exception Request

    Lynis: Failed

    For the following issue MUST be fixed for Incubation:

    1. Performing test ID BOOT-5122 (Check for GRUB boot password)

    The following issues SHOULD be fixed for incubation, and MUST be fixed for MATURITY, if not fixed exceptions must be requested:

    1. Performing test ID AUTH-9229 (Check password hashing methods)
    2. Performing test ID USB-2000 (Check USB authorizations)
    3. Test: Checking MaxSessions
    4. Test: Checking Port
    5. sysctl key kernel.core_uses_pid contains equal expected and current value (1)
    6. sysctl key kernel.kptr_restrict has a different value than expected in scan profile. Expected=2, Real=0
    7. sysctl key kernel.sysrq has a different value than expected in scan profile. Expected=0, Real=16
    8. sysctl key net.ipv4.conf.all.forwarding has a different value than expected in scan profile. Expected=0, Real=1
    9. sysctl key net.ipv4.conf.all.log_martians contains equal expected and current value (1)
    10. sysctl key net.ipv4.conf.all.send_redirects contains equal expected and current value (0)
    11. sysctl key net.ipv4.conf.default.accept_redirects contains equal expected and current value (0)
    12. sysctl key net.ipv4.conf.default.log_martians contains equal expected and current value (1)
    13. sysctl key net.ipv6.conf.all.accept_redirects has a different value than expected in scan profile. Expected=0, Real=1
    14. sysctl key net.ipv6.conf.default.accept_redirects has a different value than expected in scan profile. Expected=0, Real=1

    Kube-Hunter:  Accepted with exceptions show at:

    Release 4 Kube-Hunter Exceptions

    updated results link - 09-dec

    Yes12/10
    17
    Y
    https://nexus.akraino.org/content/sites/logs/cmti/job/pcei-daily/PCEI Release 3 Datasheet
    N/A



    11/19
    18Scheduled at 

    TSC 2020-12-08 (Tues) 7 am Pacific

    YNhttps://nexus.akraino.org/content/sites/logs/webank/job/Federated ML application at edge R4 Datasheet

    Received

    Accepted

    N/A

    https://nexus.akraino.org/content/sites/logs/webank/job/FL_SCAN/results/

    https://nexus.akraino.org/content/sites/logs/webank/job/FL_SCAN/lynis_fixed/

     

    Vuls:  Accepted with exceptions show at:

    Release 4 Vuls Exception Request


     

    Lynis:  Failed - errors sent to BP owner

    1. Compilers must be removed.
      Found known binary: g++ (compiler) - /usr/bin/g++

    Kube-Hunter:  Exception granted:  K8s not used by this BP.

    Yes12/08
    19Scheduled at Release 4 Review 2020-11-17 (Tue) 7 am PacificYNhttps://nexus.akraino.org/content/sites/logs/futurewei/kubeedgees/

    Received;

    Accepted.

    Yes

    https://nexus.akraino.org/content/sites/logs/futurewei/kubeedgees/58/results/

    Akraino BluVal Exception Request

     

    Vuls:  Accepted with exceptions show at:

    Release 4 Vuls Exception Request

     

    Lynis:  Accepted

    Kube-Hunter: Exception granted:  KubeEdge node is not on same subnet as the cloud node.  Communication occurs through the websocket endpoint, so kube-hunter can't be used.

    Yes11/17
    20
    Y








    21Scheduled at Release 4 Review 2020-12-09 YN
    Received


    12/09


    ...