Hi All,
I have a problem about the encription and key management about the external
system register information.
For the ESR scenario, users will input the auth infomation of external system,
including the password to ESR portal and the information will be stored to
A&AI. And then the external system data consumer (Multi-VIM/VF-C/SDNC, etc.)
call the API of A&AI to query the informations. The structure shows bellow:
Since there are multi-consumer of ESR data. We considered to use symmetric
encryption. ESR can encript the auth info, especially the password, with the
key difined with the consumers. Then the consumers decript the data with the
key after they queried the external system information. But another problem
comes, how to manage the encription key?
Just like what Oliver said maybe AAF and other projects have similar questions.
Is there an available approach or suggistion to deal this problem?
BR,
LiZi
原始邮件
发件人: <[email protected]>
收件人: <[email protected]>
抄送人: <[email protected]> <[email protected]>李滋00164331
日 期 :2017年07月28日 20:23
主 题 :Re: [Onap-seccom] Ask for password saving problem
I would think AAF and other projects have similar questions. We should probably
try to solve this cross project as otherwise we will end up with an
unmanageable number of credential stores leaking information all over the
place… .
Oliver
On Jul 28, 2017, at 1:10 AM, Stephen Terrill <[email protected]>
wrote:
Resending due to email bounce.
From: [email protected]
[mailto:[email protected]] On Behalf Of Stephen Terrill Sent:
28 July 2017 07:06 To: [email protected] Cc: [email protected] Xinhui
Li Subject: [Onap-seccom] FW: Ask for password saving problem
Hi Security Experts,
Xinhui and Zili are requesting best practice information for this- It would be
good to reference the CII badging program input where possible in the reponse.
https://github.com/coreinfrastructure/best-practices-badge/blob/master/doc/criteria.md
https://github.com/coreinfrastructure/best-practices-badge/blob/master/doc/other.md
Best Regards,
Steve
From: Xinhui Li [mailto:[email protected]] Sent: 28 July 2017 06:18 To:
Stephen Terrill <[email protected]> Cc: [email protected] Subject:
Ask for password saving problem
Stephen,
We are discussing about multi vim/cloud registry scenario with AAI/ESR team,
Zli is on the copy list. When registry a vim, we need to save authentication
information into AAI. Zili and Multi VIM team is discussing about encryption
for this. I am wondering if you would like to share some security rules for
ONAP community for this.
Thanks.
Xinhui
_______________________________________________ Onap-seccom mailing list
[email protected]
https://urldefense.proofpoint.com/v2/url?u=https-3A__lists.onap.org_mailman_listinfo_onap-2Dseccom&d=DwICAg&c=LFYZ-o9_HUMeMTSQicvjIg&r=9iyuArzgyekj47PZSPfIijI2cSHsUJtAlcTA0X_udNI&m=4jGPP66576XkluzDzYL0mMh48a8IjfqmtLSZfqi-95M&s=tVUfztYxzlFcV8xFO1y99n92erCLfrYb651mDgIoPcE&e=
_______________________________________________
onap-discuss mailing list
[email protected]
https://lists.onap.org/mailman/listinfo/onap-discuss