-
Story
-
Resolution: Unresolved
-
Undefined
-
None
-
None
-
None
-
False
-
-
False
-
-
Story (Required)
Authenticate application components that communicate through a network before exchanging any kind of information.
- This includes mobile applications that communicate with a cloud-based web service, or embedded devices that communicates with a controller.
- Implicit and inherent trust of other components leads to external cyberattack avenues.
- For example, if your web server uses a database located on a separate machine and communicates with it through the network, it should authenticate the database before using it.
- As another example, your mobile application should authenticate your cloud service before uploading user information.
More information: https://redhat.sdelements.com/bunits/psse-secure-development/group-2-extended-functionality-offerings/openshift-gitops/tasks/phase/requirements/125-T558/
Background (Required)
Refer to the Epic description.
Out of scope
Any previous counter measures.
Approach (Required)
- Discuss this issue in the bug triage or cabal.
Dependencies
NA
Acceptance Criteria (Mandatory)
- Bring this issue to the bug triage call and take a decision on the counter measure.
- If further discussion is needed, bring this issue to the cabal.
INVEST Checklist
Dependencies identified
Blockers noted and expected delivery timelines set
Design is implementable
Acceptance criteria agreed upon
Story estimated
Legend
Unknown
Verified
Unsatisfied
Done Checklist
- Code is completed, reviewed, documented and checked in
- Unit and integration test automation have been delivered and running cleanly in continuous integration/staging/canary environment
- Continuous Delivery pipeline(s) is able to proceed with new code included
- Customer facing documentation, API docs etc. are produced/updated, reviewed and published
- Acceptance criteria are met
- is cloned by
-
GITOPS-3670 T69: Strong password requirements for server-to-server system accounts
-
- New
-
-
GITOPS-3674 T1919: Use JSON Web Token (JWT) securely
-
- New
-
-
GITOPS-3679 T1951: Do not use static token files for authentication (OpenShift)
-
- New
-