Sai Gandham | d67a9de | 2018-05-25 15:48:11 +0000 | [diff] [blame] | 1 | .. This work is licensed under a Creative Commons Attribution 4.0 International License. |
| 2 | .. http://creativecommons.org/licenses/by/4.0 |
Instrumental | 7a1817b | 2018-11-05 11:11:15 -0600 | [diff] [blame] | 3 | .. Copyright © 2017 AT&T Intellectual Property. All rights reserved. |
Sai Gandham | d67a9de | 2018-05-25 15:48:11 +0000 | [diff] [blame] | 4 | |
| 5 | |
| 6 | Release Notes |
| 7 | ============= |
| 8 | |
| 9 | |
| 10 | |
Instrumental | 3505a52 | 2019-01-31 14:49:24 -0600 | [diff] [blame] | 11 | Version: 2.1.8 (Casablanca, 3.0.0-ONAP, Casablanca Maintenance Release) |
Instrumental | 1923c88 | 2018-11-15 10:01:18 -0600 | [diff] [blame] | 12 | ---------------------------------------- |
Sai Gandham | d67a9de | 2018-05-25 15:48:11 +0000 | [diff] [blame] | 13 | |
Instrumental | 3505a52 | 2019-01-31 14:49:24 -0600 | [diff] [blame] | 14 | Note: AAF did not create new artifacts for Casablanca Maintenance Release. |
| 15 | |
Sai Gandham | d67a9de | 2018-05-25 15:48:11 +0000 | [diff] [blame] | 16 | |
Gildas Lanilis | 6086826 | 2018-11-21 16:42:19 -0800 | [diff] [blame] | 17 | :Release Date: 2018-11-30 |
Sai Gandham | d67a9de | 2018-05-25 15:48:11 +0000 | [diff] [blame] | 18 | |
| 19 | **New Features** |
| 20 | |
Instrumental | 1923c88 | 2018-11-15 10:01:18 -0600 | [diff] [blame] | 21 | - AAF created a local CA and CA Strategy to be utilized for ONAP Test Environments that can instantiated daily, yet have continuity over time and environments. (REAL ONAP instantiations should use their *own* CAs outside of initial tests.) |
| 22 | - AAF has auto-creation of configurations and certificates. This is expected to be done inside an "agent" container, and used by Apps. |
| 23 | - AAF stores and creates "Bootstrap Data" for all users of AAF in ONAP. This simplifies the efforts of ONAP components to organize their Authorizations, and so that various Test Environments can start with correct data every time. |
| 24 | - Refactored all of AAF instantiations to use the above, and have consistency between the 5 ways to start AAF. |
| 25 | - Ability for CADI Clients to map previous User/Password combinations to current credentials for migration purposes. This is applied to Shiro Plugin as well |
| 26 | - CADI Coarse Grain Enforcement Point (Authorize API access). |
| 27 | - Created Backward compatibility features, both for DB (Cassandra) and for API access. |
| 28 | |
Sai Gandham | d67a9de | 2018-05-25 15:48:11 +0000 | [diff] [blame] | 29 | |
| 30 | **Bug Fixes** |
Instrumental | 1923c88 | 2018-11-15 10:01:18 -0600 | [diff] [blame] | 31 | - AAF in OOM was not stable coming out of Beijing. AAF OOM was refactored using above Container based Configurations. |
| 32 | - `AAF-617 <https://jira.onap.org/browse/AAF-617>`_ LOCATE Proxy DELETE not working |
| 33 | - `AAF-605 <https://jira.onap.org/browse/AAF-605>`_ DB Stoppage not causing Reset of Connection |
| 34 | - `AAF-601 <https://jira.onap.org/browse/AAF-601>`_ Agent "showpass" errors on optional "chal" file, when not exists |
| 35 | - `AAF-600 <https://jira.onap.org/browse/AAF-600>`_ Bad Data for APPC in AAF Test Evironment |
| 36 | - `AAF-598 <https://jira.onap.org/browse/AAF-598>`_ Inconsistent Startup with truly persistent Cass Data |
| 37 | - `AAF-597 <https://jira.onap.org/browse/AAF-597>`_ Please change default appc@appc.onap.org permission |
| 38 | - `AAF-592 <https://jira.onap.org/browse/AAF-592>`_ SDNC not able to authenticate with BAth username/password |
| 39 | - `AAF-530 <https://jira.onap.org/browse/AAF-530>`_ AAF inside Kubernetes inaccessible for clients from outside |
| 40 | |
Sai Gandham | d67a9de | 2018-05-25 15:48:11 +0000 | [diff] [blame] | 41 | **Known Issues** |
Instrumental | 1923c88 | 2018-11-15 10:01:18 -0600 | [diff] [blame] | 42 | N/A |
| 43 | |
| 44 | **Other** |
| 45 | - REAL ONAP versus ONAP Test Environment |
| 46 | - CA used in ONAP Test Environment should (of course) NOT be used by individual companies in REAL deployments. |
| 47 | - Cassandra Instance in Kubernetes ONAP Test environment is a single instance. REAL deployments should follow global, multi-datacenter deployment strategies per Cassandra recommendations. |
| 48 | - AAF team organized all the Identities, all the Credentials, etc, on behalf of ONAP Apps. |
Sai Gandham | d67a9de | 2018-05-25 15:48:11 +0000 | [diff] [blame] | 49 | |
Gildas Lanilis | d9cfae5 | 2018-05-29 17:25:01 -0700 | [diff] [blame] | 50 | **Security Notes** |
Instrumental | 1923c88 | 2018-11-15 10:01:18 -0600 | [diff] [blame] | 51 | - AAF has achieved clean scans for everything in authz.git repo |
| 52 | - In the cadi.git (used for Adaptors), there is a Shiro adapter. Shiro itself has security flags, *NOT* the adapter, so understand the security issues of Shiro before use. |
Sai Gandham | d67a9de | 2018-05-25 15:48:11 +0000 | [diff] [blame] | 53 | |
Gildas Lanilis | 6086826 | 2018-11-21 16:42:19 -0800 | [diff] [blame] | 54 | - AAF code has been formally scanned during build time using NexusIQ and all Critical vulnerabilities have been addressed, items that remain open have been assessed for risk and determined to be false positive. The AAF open Critical security vulnerabilities and their risk assessment have been documented as part of the `project <https://wiki.onap.org/pages/viewpage.action?pageId=43386201>`_. |
Gildas Lanilis | d9cfae5 | 2018-05-29 17:25:01 -0700 | [diff] [blame] | 55 | |
Instrumental | 1923c88 | 2018-11-15 10:01:18 -0600 | [diff] [blame] | 56 | **Quick Links:** |
Gildas Lanilis | d9cfae5 | 2018-05-29 17:25:01 -0700 | [diff] [blame] | 57 | - `AAF project page <https://wiki.onap.org/display/DW/Application+Authorization+Framework+Project>`_ |
Instrumental | 1923c88 | 2018-11-15 10:01:18 -0600 | [diff] [blame] | 58 | - `CII Best Practices Silver Badge information for AAF <https://bestpractices.coreinfrastructure.org/en/projects/2303?criteria_level=1>`_ |
| 59 | - `CII Best Practices Passing Badge information for AAF <https://bestpractices.coreinfrastructure.org/en/projects/2303?criteria_level=0>`_ |
Gildas Lanilis | 6086826 | 2018-11-21 16:42:19 -0800 | [diff] [blame] | 60 | - `Project Vulnerability Review Table for AAF <https://wiki.onap.org/pages/viewpage.action?pageId=43386201>`_ |
Sai Gandham | d67a9de | 2018-05-25 15:48:11 +0000 | [diff] [blame] | 61 | |
| 62 | **Upgrade Notes** |
| 63 | NA |
| 64 | |
| 65 | **Deprecation Notes** |
| 66 | |
Gildas Lanilis | 6086826 | 2018-11-21 16:42:19 -0800 | [diff] [blame] | 67 | Version: 2.1.1 (Beijing, 2.0.0-ONAP) |
Instrumental | 1923c88 | 2018-11-15 10:01:18 -0600 | [diff] [blame] | 68 | -------------------------------------- |
Sai Gandham | d67a9de | 2018-05-25 15:48:11 +0000 | [diff] [blame] | 69 | |
Instrumental | 1923c88 | 2018-11-15 10:01:18 -0600 | [diff] [blame] | 70 | :Release Date: 2017-06-05 |
Sai Gandham | d67a9de | 2018-05-25 15:48:11 +0000 | [diff] [blame] | 71 | |
| 72 | |
Instrumental | 1923c88 | 2018-11-15 10:01:18 -0600 | [diff] [blame] | 73 | **New Features:** |
Sai Gandham | d67a9de | 2018-05-25 15:48:11 +0000 | [diff] [blame] | 74 | |
| 75 | - Service (primary) – All the Authorization information (more on that in a bit) |
| 76 | - Locate – how to find ANY OR ALL AAF instances across any geographic distribution |
| 77 | - OAuth 2.0 – new component providing Tokens and Introspection (no time to discuss here) |
| 78 | - GUI – Tool to view and manage Authorization Information, and create Credentials |
| 79 | - Certman – Certificate Manger, create and renew X509 with Fine-Grained Identity |
| 80 | - FS – File Server to provide access to distributable elements (like well known certs) |
| 81 | - Hello - Test your client access (certs, OAuth 2.0, etc) |
| 82 | |
Instrumental | 1923c88 | 2018-11-15 10:01:18 -0600 | [diff] [blame] | 83 | **Bug Fixes** |
| 84 | - `AAF-290 <https://jira.onap.org/browse/AAF-290>`_ Fix aaf truststore |
Sai Gandham | d67a9de | 2018-05-25 15:48:11 +0000 | [diff] [blame] | 85 | - `AAF-270 <https://jira.onap.org/browse/AAF-270>`_ AAF fails health check on HEAT deployment |
| 86 | - `AAF-286 <https://jira.onap.org/browse/AAF-286>`_ SMS fails health check on OOM deployment |
| 87 | - `AAF-273 <https://jira.onap.org/browse/AAF-273>`_ Cassandra pod running over 8G heap - or 10% of ONAP ram (for 135 other pods on 256G 4 node cluster) |
| 88 | |
| 89 | |
Instrumental | 1923c88 | 2018-11-15 10:01:18 -0600 | [diff] [blame] | 90 | **Known Issues** |
| 91 | N/A |
Sai Gandham | d67a9de | 2018-05-25 15:48:11 +0000 | [diff] [blame] | 92 | |
Instrumental | 1923c88 | 2018-11-15 10:01:18 -0600 | [diff] [blame] | 93 | **Other** |
| 94 | - REAL ONAP versus ONAP Test Environment |
| 95 | - Cassandra Instance in Kubernetes ONAP Test environment is a single instance. REAL deployments should follow global, multi-datacenter deployment strategies per Cassandra recommendations. |
| 96 | |
| 97 | |
| 98 | **Quick Links:** |
| 99 | - `AAF project page <https://wiki.onap.org/display/DW/Application+Authorization+Framework+Project>`_ |
| 100 | - `CII Best Practices Passing Badge information for AAF <https://bestpractices.coreinfrastructure.org/en/projects/2303?criteria_level=0>`_ |
| 101 | - `Project Vulnerability Review Table for AAF <https://wiki.onap.org/pages/viewpage.action?pageId=43385140>`_ |
Sai Gandham | d67a9de | 2018-05-25 15:48:11 +0000 | [diff] [blame] | 102 | |