blob: 09125a899b4066875e754ca32422de8197e9fea9 [file] [log] [blame]
Sai Gandhamd67a9de2018-05-25 15:48:11 +00001.. This work is licensed under a Creative Commons Attribution 4.0 International License.
2.. http://creativecommons.org/licenses/by/4.0
Instrumental7a1817b2018-11-05 11:11:15 -06003.. Copyright © 2017 AT&T Intellectual Property. All rights reserved.
Sai Gandhamd67a9de2018-05-25 15:48:11 +00004
Sai Gandhamd67a9de2018-05-25 15:48:11 +00005Release Notes
6=============
7
Instrumental1a101ab2019-09-19 09:23:53 -05008Version: 2.1.15 (El Alto, 5.0.1)
Instrumental6f4db932019-08-22 07:54:17 -05009---------------------------------------------
10
11:Release Date: 2019-08-12
12
13**New Features**
14El Alto is a consolidation release. New Features are not Added.
15However, for El Alto, ONAP is propagating the AAF Auto-Configuration and Certificate Generation feature from Dublin, see below
16
17An important change, however, is that the AAF Locator requires internal K8s Apps to use
18 internal-to-K8s Service URL tags as (example) "onap.org.osaaf.aaf.service:2.1"
19 external-to-K8s Service URL tags as (example) "org.osaaf.aaf.service.2.1"
20
Instrumental4872ec02019-09-10 06:52:52 -050021 IF you are using previous configurations, you may need to clear the existing directory
22
23 - Login to your Init Container
24 - cd /opt/app/osaaf/local
25 - CAREFULLY rm *.*, and have it regenerate
26
Instrumental6f4db932019-08-22 07:54:17 -050027**Bug Fixes**
28 - `AAF-859 <https://jira.onap.org/browse/AAF-859>`_ Images hardcoded in AAF helm deployment yamls
29
Instrumental130eb662019-10-14 14:55:37 -050030**Known Issues - solve in Frankfurt**
31 - `AAF-962 <https://jira.onap.org/browse/AAF-962>`_ AAF Certs could not generate...
32
Instrumentale84b4312019-06-24 08:14:51 -050033Version: 2.1.13 (Dublin, 4.0.0-ONAP)
Gathman, Jonathan (jg1555)ff3dc8e2019-05-02 09:28:35 -050034---------------------------------------
Sai Gandhamd67a9de2018-05-25 15:48:11 +000035
Gathman, Jonathan (jg1555)ff3dc8e2019-05-02 09:28:35 -050036:Release Date: 2019-06-06
37
38**New Features**
39
40Note: In general, Infrastructure must be accomplished in the release PRIOR to general usage. This is the case for most of the features included here.
41
42 - AAF has built the required features to automatically generate all Certificates and Configurations real-time. This will be utilized by ONAP MSs in El Alto
43 - AAF has the ability to publish both Public and Internal Private K8s Service information (Locator)
44 - Greatly Reduced size of Docker Images
45 - Greatly enhanced startup procedures in K8s, to more cleanly start, with Certificate, Property Generation every time
46 - Ability to run internally as non-root (fully setup K8s in El Alto)
47 - Removal of unused classes in Batch
48 - Large improvement in Batch and methodology, to be used in El Alto
49
50**Bug Fixes**
51 - `AAF-797 <https://jira.onap.org/browse/AAF-797>`_ Update IP address for aaf-onap-test.osaaf.org
52 - `AAF-794 <https://jira.onap.org/browse/AAF-794>`_ Misleading error message in agent.sh
53 - `AAF-773 <https://jira.onap.org/browse/AAF-773>`_ aaf-cass timing issues
54 - `AAF-769 <https://jira.onap.org/browse/AAF-769>`_ AAF CSIT not working
55 - `AAF-727 <https://jira.onap.org/browse/AAF-727>`_ Cert Subject Check confused by Email
56 - `AAF-722 <https://jira.onap.org/browse/AAF-722>`_ aaf continues to be available to aai-resources even though aaf database appears to be down
57 - `AAF-720 <https://jira.onap.org/browse/AAF-720>`_ Docker Images not passing Signal -1
58 - `AAF-645 <https://jira.onap.org/browse/AAF-645>`_ Fix "Null" string for fetching path inside CADI API enforcement filter
59 - `AAF-522 <https://jira.onap.org/browse/AAF-522>`_ rsa 4096 signing fails with TPM
60 - `AAF-813 <https://jira.onap.org/browse/AAF-813>`_ Missing Role for dmaap-bc Identity
61 - `AAF-514 <https://jira.onap.org/browse/AAF-514>`_ TPM Plugin: Remove global structure used for storing session data
62 - `AAF-785 <https://jira.onap.org/browse/AAF-785>`_ non STAGING version on master
63 - `AAF-822 <https://jira.onap.org/browse/AAF-822>`_ Startup issues with K8S, Certs
Sai Gandhamd67a9de2018-05-25 15:48:11 +000064
Gathman, Jonathan (jg1555)3677e0a2019-06-20 11:00:28 -050065**Usage Notes**
66 - AAF Core and SMS elements have consistently started from scratch. The one case where this didn't happen for SMS,
67 it was found that incompatible data was left in volume. Removal of old data for SMS (See SMS notes) should resolve
68 - On the same instance, one AAF Core component had a similar scenario. A simple bounce of aaf-locator resolved.
69 - Existing Cassandra
70 - For each release, AAF maintains the authz/auth/auth-cass/cass_init/init.cql which is used to setup Keyspaces from scratch
71 - Any changes are also done in small CQL files, you MIGHT need authz/auth/auth-cass/cass_init/init2_10.cql for Dublin
72
73
Instrumental3505a522019-01-31 14:49:24 -060074Version: 2.1.8 (Casablanca, 3.0.0-ONAP, Casablanca Maintenance Release)
Gathman, Jonathan (jg1555)ff3dc8e2019-05-02 09:28:35 -050075--------------------------------------------------------------------------
Sai Gandhamd67a9de2018-05-25 15:48:11 +000076
Instrumental3505a522019-01-31 14:49:24 -060077Note: AAF did not create new artifacts for Casablanca Maintenance Release.
78
Sai Gandhamd67a9de2018-05-25 15:48:11 +000079
Gildas Lanilis60868262018-11-21 16:42:19 -080080:Release Date: 2018-11-30
Sai Gandhamd67a9de2018-05-25 15:48:11 +000081
82**New Features**
83
Instrumental1923c882018-11-15 10:01:18 -060084 - AAF created a local CA and CA Strategy to be utilized for ONAP Test Environments that can instantiated daily, yet have continuity over time and environments. (REAL ONAP instantiations should use their *own* CAs outside of initial tests.)
85 - AAF has auto-creation of configurations and certificates. This is expected to be done inside an "agent" container, and used by Apps.
86 - AAF stores and creates "Bootstrap Data" for all users of AAF in ONAP. This simplifies the efforts of ONAP components to organize their Authorizations, and so that various Test Environments can start with correct data every time.
87 - Refactored all of AAF instantiations to use the above, and have consistency between the 5 ways to start AAF.
88 - Ability for CADI Clients to map previous User/Password combinations to current credentials for migration purposes. This is applied to Shiro Plugin as well
89 - CADI Coarse Grain Enforcement Point (Authorize API access).
90 - Created Backward compatibility features, both for DB (Cassandra) and for API access.
91
Sai Gandhamd67a9de2018-05-25 15:48:11 +000092
93**Bug Fixes**
Instrumental1923c882018-11-15 10:01:18 -060094 - AAF in OOM was not stable coming out of Beijing. AAF OOM was refactored using above Container based Configurations.
95 - `AAF-617 <https://jira.onap.org/browse/AAF-617>`_ LOCATE Proxy DELETE not working
96 - `AAF-605 <https://jira.onap.org/browse/AAF-605>`_ DB Stoppage not causing Reset of Connection
97 - `AAF-601 <https://jira.onap.org/browse/AAF-601>`_ Agent "showpass" errors on optional "chal" file, when not exists
98 - `AAF-600 <https://jira.onap.org/browse/AAF-600>`_ Bad Data for APPC in AAF Test Evironment
99 - `AAF-598 <https://jira.onap.org/browse/AAF-598>`_ Inconsistent Startup with truly persistent Cass Data
100 - `AAF-597 <https://jira.onap.org/browse/AAF-597>`_ Please change default appc@appc.onap.org permission
101 - `AAF-592 <https://jira.onap.org/browse/AAF-592>`_ SDNC not able to authenticate with BAth username/password
102 - `AAF-530 <https://jira.onap.org/browse/AAF-530>`_ AAF inside Kubernetes inaccessible for clients from outside
103
Sai Gandhamd67a9de2018-05-25 15:48:11 +0000104**Known Issues**
Instrumental1923c882018-11-15 10:01:18 -0600105 N/A
106
107**Other**
108 - REAL ONAP versus ONAP Test Environment
109 - CA used in ONAP Test Environment should (of course) NOT be used by individual companies in REAL deployments.
110 - Cassandra Instance in Kubernetes ONAP Test environment is a single instance. REAL deployments should follow global, multi-datacenter deployment strategies per Cassandra recommendations.
111 - AAF team organized all the Identities, all the Credentials, etc, on behalf of ONAP Apps.
Sai Gandhamd67a9de2018-05-25 15:48:11 +0000112
Gildas Lanilisd9cfae52018-05-29 17:25:01 -0700113**Security Notes**
Instrumental1923c882018-11-15 10:01:18 -0600114 - AAF has achieved clean scans for everything in authz.git repo
115 - In the cadi.git (used for Adaptors), there is a Shiro adapter. Shiro itself has security flags, *NOT* the adapter, so understand the security issues of Shiro before use.
Sai Gandhamd67a9de2018-05-25 15:48:11 +0000116
Gildas Lanilis60868262018-11-21 16:42:19 -0800117 - AAF code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and determined to be false positive. The AAF open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=43386201>`_.
Gildas Lanilisd9cfae52018-05-29 17:25:01 -0700118
Sai Gandhamd67a9de2018-05-25 15:48:11 +0000119
120**Upgrade Notes**
121 NA
122
123**Deprecation Notes**
124
Gildas Lanilis60868262018-11-21 16:42:19 -0800125Version: 2.1.1 (Beijing, 2.0.0-ONAP)
Instrumental1923c882018-11-15 10:01:18 -0600126--------------------------------------
Sai Gandhamd67a9de2018-05-25 15:48:11 +0000127
Instrumental1923c882018-11-15 10:01:18 -0600128:Release Date: 2017-06-05
Sai Gandhamd67a9de2018-05-25 15:48:11 +0000129
130
Instrumental1923c882018-11-15 10:01:18 -0600131**New Features:**
Sai Gandhamd67a9de2018-05-25 15:48:11 +0000132
133 - Service (primary) – All the Authorization information (more on that in a bit)
134 - Locate – how to find ANY OR ALL AAF instances across any geographic distribution
135 - OAuth 2.0 – new component providing Tokens and Introspection (no time to discuss here)
136 - GUI – Tool to view and manage Authorization Information, and create Credentials
137 - Certman – Certificate Manger, create and renew X509 with Fine-Grained Identity
138 - FS – File Server to provide access to distributable elements (like well known certs)
139 - Hello - Test your client access (certs, OAuth 2.0, etc)
140
Instrumental1923c882018-11-15 10:01:18 -0600141**Bug Fixes**
142 - `AAF-290 <https://jira.onap.org/browse/AAF-290>`_ Fix aaf truststore
Sai Gandhamd67a9de2018-05-25 15:48:11 +0000143 - `AAF-270 <https://jira.onap.org/browse/AAF-270>`_ AAF fails health check on HEAT deployment
144 - `AAF-286 <https://jira.onap.org/browse/AAF-286>`_ SMS fails health check on OOM deployment
145 - `AAF-273 <https://jira.onap.org/browse/AAF-273>`_ Cassandra pod running over 8G heap - or 10% of ONAP ram (for 135 other pods on 256G 4 node cluster)
146
147
Instrumental1923c882018-11-15 10:01:18 -0600148**Known Issues**
149 N/A
Sai Gandhamd67a9de2018-05-25 15:48:11 +0000150
Instrumental1923c882018-11-15 10:01:18 -0600151**Other**
152 - REAL ONAP versus ONAP Test Environment
153 - Cassandra Instance in Kubernetes ONAP Test environment is a single instance. REAL deployments should follow global, multi-datacenter deployment strategies per Cassandra recommendations.
154
155
Instrumental6f4db932019-08-22 07:54:17 -0500156================
157Quick Links
158================
Instrumental1923c882018-11-15 10:01:18 -0600159 - `AAF project page <https://wiki.onap.org/display/DW/Application+Authorization+Framework+Project>`_
Instrumental6f4db932019-08-22 07:54:17 -0500160 - `CII Best Practices Silver Badge information for AAF <https://bestpractices.coreinfrastructure.org/en/projects/2303?criteria_level=1>`_
Instrumental1923c882018-11-15 10:01:18 -0600161 - `CII Best Practices Passing Badge information for AAF <https://bestpractices.coreinfrastructure.org/en/projects/2303?criteria_level=0>`_
Instrumental6f4db932019-08-22 07:54:17 -0500162 - `Project Vulnerability Review Table for AAF <https://wiki.onap.org/pages/viewpage.action?pageId=43386201>`_
Sai Gandhamd67a9de2018-05-25 15:48:11 +0000163
Gathman, Jonathan (jg1555)3677e0a2019-06-20 11:00:28 -0500164
165