Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

As a Security Specialist I want to study what open source tools could be used for automating X-Road security testing so that I know which tools are best suited for X-Road #1356

Open
2 tasks
raits opened this issue Sep 22, 2022 · 0 comments
Labels
help wanted Extra attention is needed

Comments

@raits
Copy link
Contributor

raits commented Sep 22, 2022

An open-source security testing tool could be used for automating Security Server penetration testing. The Security Server has multiple interfaces: UI (port 4000), message transport (ports 5500, 5577) and a SOAP/REST interface for information systems (ports 80 / 443 and 8080 / 8443). Central Server and Configuration Proxy use different ports. It should be studied how different alternatives can be used for testing all the interfaces of different X-Road components. More information about different X-Road components and their interfaces is available here.

The JIRA ticket this issue was created from can be found here: https://nordic-institute.atlassian.net/browse/XRDDEV-129

Acceptance criteria:

  • Different open source alternatives for implementing automated security tests for Security Server, Central Server and Configuration Proxy are evaluated, and results are documented
  • Interfaces of different components that can be tested using different tools are documented in the results
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
help wanted Extra attention is needed
Projects
Status: Todo
Development

No branches or pull requests

1 participant