[Openstack-security] [security] [QA] Do we have security tests suite for OpenStack components?

Timur Nurlygayanov tnurlygayanov at mirantis.com
Mon Jun 15 17:20:31 UTC 2015


Hi team,

Looks like we are using Bandit framework [1] for static analysis of code of
different OpenStack components, but I can't find some integration security
tests for OpenStack components. Do we have some additional open-source test
framework / tests suite for security testing of OpenStack components?

I found the blueprint in Tempest about fuzzy testing [2], so, we can start
to develop some security tests in Tempest and use them to perform security
testing on the integration level and also to validate some security bug
fixes.
Do we have some list with scenarios, which we can cover with fuzzing tests
in Tempest? We can start from some tests which will validate fixed security
issues, it will be really helpful if you can share some ideas about tests,
which we have to create.

Thank you!

[1] https://github.com/stackforge/bandit
[2] https://blueprints.launchpad.net/tempest/+spec/fuzzy-test

-- 

Timur,
Senior QA Engineer
OpenStack Projects
Mirantis Inc
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack-security/attachments/20150615/0082444e/attachment.html>


More information about the Openstack-security mailing list