-
Notifications
You must be signed in to change notification settings - Fork 565
Description
Description:
Authentication and authorization are the most important security considerations in the cloud-native ecosystem, as evidenced by their high ranking in the OWASP Top 10 and OWASP Top 10 API Security Risks.
On the other hand, authentication and authorization frameworks have a wide range of related specifications, including OAuth and OpenID Connect, and it can be difficult for implementers to implement the frameworks, so it would be beneficial to publish best practices for identity and access management.
Fortunately, Keycloak, a powerful IAM OSS, has joined the CNCF ecosystem as a CNCF incubating project, so it may be time to consider what IAM should be like in the cloud-native world.
Impact:
As seen in the high rankings in the OWASP Top 10 and OWASP Top 10 API Security Risks, security risks related to authentication and authorization remain of great concern to customers. Once IAM best practices are published, they can mitigate these concerns and realize a more secure cloud-native ecosystem.
Scope:
not yet determined.
Authentication and authorization are broad terms, and some of them are related to other areas like zero trust currently the WP being promoted, so it is very important to decide what the scope should be.
Intent to lead:
- I volunteer to be a project lead on this proposal if the community is
interested in pursing this work. This statement of intent does not preclude
others from co-leading or becoming lead in my stead.
Proposal to Project:
- Added to the planned meeting template for mm dd
- Raised in a Security TAG meeting to determine interest - mm dd
- Collaborators comment on issue for determine interest and nominate project
lead - Scope determined via meeting mm dd and/or shared document add link
with call for participation in #tag-security slack channel thread add link
and mailing list email add link - Scope presented to Security TAG leadership and Sponsor is assigned
TO DO
- Security TAG Leadership Representative: @eddie-knight
- Project leader(s): @y-tabata
- Issue is assigned to project leaders and Security TAG Leadership
Representative - Share this whitepaper collaboration opportunity at each of the TAG community meetings
- Project Members:
- Fill in addition TODO items here so the project team and community can
see progress! - Scope
- Deliverable(s)
- Project Schedule
- Slack Channel (as needed)
- Meeting Time & Day:
- Meeting Notes (link)
- Meeting Details (zoom or hangouts link)
- Retrospective