Sponsor: VoiceMeUp - Corporate & Wholesale VoIP Services

VoIP Mailing List Archives
Mailing list archives for the VoIP community
 SearchSearch 

[asterisk-users] Security Architecture or Security Evaluations Docs?


 
Post new topic   Reply to topic    VoIP Mailing List Archives Forum Index -> Asterisk Users
View previous topic :: View next topic  
Author Message
noloader at gmail.com
Guest





PostPosted: Sat Jul 26, 2014 7:24 am    Post subject: [asterisk-users] Security Architecture or Security Evaluatio Reply with quote

Does anyone know of Security Architecture or Security Evaluations
documents that I could read?

Searching is turning up no hits. For example,
http://www.google.com/#q=security+evaluation+site:asterisk.org and
http://www.google.com/#q=security+architecture+site:asterisk.org.

--
_____________________________________________________________________
-- Bandwidth and Colocation Provided by http://www.api-digital.com --
New to Asterisk? Join us for a live introductory webinar every Thurs:
http://www.asterisk.org/hello

asterisk-users mailing list
To UNSUBSCRIBE or update options visit:
http://lists.digium.com/mailman/listinfo/asterisk-users
Back to top
patrick at laimbock.com
Guest





PostPosted: Sat Jul 26, 2014 8:18 am    Post subject: [asterisk-users] Security Architecture or Security Evaluatio Reply with quote

On 26-07-14 14:23, Jeffrey Walton wrote:
Quote:
Does anyone know of Security Architecture or Security Evaluations
documents that I could read?

Searching is turning up no hits. For example,
http://www.google.com/#q=security+evaluation+site:asterisk.org and
http://www.google.com/#q=security+architecture+site:asterisk.org.

Assuming "security+evaluation" refers to Common Criteria, I'm not aware
of any Common Criteria initiatives in relation to Asterisk (nor
FreeSWITCH, OpenSIPS, Kamailio, Yate or any other Open Source VoIP
project I'm aware of). Asterisk is a toolbox with many flexible building
blocks and not a product like Cisco CallManager with pre-defined
features set in stone. As such it doesn't really make sense to get
Asterisk certified, if possible at all. It would be like trying to
certify C or Python. If EALx certification is your requirement then have
a look at the CallManager as iirc it's EAL1 certified.

Re "asterisk+architecture", Asterisk Security related best practices are
described here:
http://svn.asterisk.org/svn/asterisk/trunk/README-SERIOUSLY.bestpractices.txt

HTH,
Patrick

--
_____________________________________________________________________
-- Bandwidth and Colocation Provided by http://www.api-digital.com --
New to Asterisk? Join us for a live introductory webinar every Thurs:
http://www.asterisk.org/hello

asterisk-users mailing list
To UNSUBSCRIBE or update options visit:
http://lists.digium.com/mailman/listinfo/asterisk-users
Back to top
noloader at gmail.com
Guest





PostPosted: Mon Jul 28, 2014 5:28 am    Post subject: [asterisk-users] Security Architecture or Security Evaluatio Reply with quote

Thanks Patrick,

Quote:
Assuming "security+evaluation" refers to Common Criteria,
Common Criteria is one, but not necessarily the only type of security
evaluation. Often times organizations with resources will perform an
evaluation against its own standards before adopting or accepting a
system. I was hoping the project had an evaluation from past reviews
it could share.

Quote:
Re "asterisk+architecture", Asterisk Security related best practices are
described here:
http://svn.asterisk.org/svn/asterisk/trunk/README-SERIOUSLY.bestpractices.txt
Ah, OK thanks.

Is there anything that includes the development process? I'm
interested in the secure development items and testing.

Jeff

On Sat, Jul 26, 2014 at 9:18 AM, Patrick Laimbock <patrick@laimbock.com> wrote:
Quote:
On 26-07-14 14:23, Jeffrey Walton wrote:
Quote:

Does anyone know of Security Architecture or Security Evaluations
documents that I could read?

Searching is turning up no hits. For example,
http://www.google.com/#q=security+evaluation+site:asterisk.org and
http://www.google.com/#q=security+architecture+site:asterisk.org.


Assuming "security+evaluation" refers to Common Criteria, I'm not aware of
any Common Criteria initiatives in relation to Asterisk (nor FreeSWITCH,
OpenSIPS, Kamailio, Yate or any other Open Source VoIP project I'm aware
of). Asterisk is a toolbox with many flexible building blocks and not a
product like Cisco CallManager with pre-defined features set in stone. As
such it doesn't really make sense to get Asterisk certified, if possible at
all. It would be like trying to certify C or Python. If EALx certification
is your requirement then have a look at the CallManager as iirc it's EAL1
certified.

Re "asterisk+architecture", Asterisk Security related best practices are
described here:
http://svn.asterisk.org/svn/asterisk/trunk/README-SERIOUSLY.bestpractices.txt


--
_____________________________________________________________________
-- Bandwidth and Colocation Provided by http://www.api-digital.com --
New to Asterisk? Join us for a live introductory webinar every Thurs:
http://www.asterisk.org/hello

asterisk-users mailing list
To UNSUBSCRIBE or update options visit:
http://lists.digium.com/mailman/listinfo/asterisk-users
Back to top
patrick at laimbock.com
Guest





PostPosted: Mon Jul 28, 2014 8:22 am    Post subject: [asterisk-users] Security Architecture or Security Evaluatio Reply with quote

On 28-07-14 12:28, Jeffrey Walton wrote:
[snip]
Quote:

Is there anything that includes the development process? I'm
interested in the secure development items and testing.

Info about the development of Asterisk can be found here:
http://asterisk.org/community/developers
https://wiki.asterisk.org/wiki/display/AST/Development

Development related questions can best be asked on the asterisk-dev
mailing list or on irc.freenode.net in #asterisk-dev.

HTH,
Patrick




--
_____________________________________________________________________
-- Bandwidth and Colocation Provided by http://www.api-digital.com --
New to Asterisk? Join us for a live introductory webinar every Thurs:
http://www.asterisk.org/hello

asterisk-users mailing list
To UNSUBSCRIBE or update options visit:
http://lists.digium.com/mailman/listinfo/asterisk-users
Back to top
Display posts from previous:   
Post new topic   Reply to topic    VoIP Mailing List Archives Forum Index -> Asterisk Users All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group

VoiceMeUp - Corporate & Wholesale VoIP Services