2013.04.02 CAS AppSec Working Group Call

2013-04-02 CAS AppSec Working Group Call

Meeting Details

Participants 

 Agenda

  • Introductions
  • Review/Approve Meeting Minutes
     
  • Review Action Items
  • JIRA for issue tracking?
  • Apereo Conference in June
  • Input Validation/Filtering
  • Open Discussion
  • Meeting Schedule
  • Share sample security artifacts
  • Next Steps

Meeting Notes

Decide to pursue JIRA project for tracking WG AIs.

Briefly discussed DFD.  Will continue to progress on that via mailing list.  Looking to create additional level diagrams.  Discussed how DFD helps to identify areas that may need additional security controls or consideration.

Aaron shared a new static code scan of CAS 3.5.2.  No major issues, will triage others and share on cas-appsec-private.

Discussed the use of ZapProxy for dynamic scans and the need for test instance.

Will pursue renaming cas-appsec to cas-appsec-public to help avoid inadvertent disclosure.

Action Items

Post Meeting Notes (catch-all, Alibi's)