*** jamesmcarthur has quit IRC | 00:04 | |
*** jamesmcarthur has joined #openstack-infra | 00:05 | |
*** jamesmcarthur has quit IRC | 00:09 | |
*** Goneri has quit IRC | 00:10 | |
*** jamesmcarthur has joined #openstack-infra | 00:27 | |
*** gyee has quit IRC | 00:54 | |
*** jamesmcarthur has quit IRC | 01:05 | |
*** Tengu_ has joined #openstack-infra | 01:16 | |
*** Tengu has quit IRC | 01:19 | |
*** Tengu has joined #openstack-infra | 01:21 | |
*** Tengu_ has quit IRC | 01:22 | |
*** jamesmcarthur has joined #openstack-infra | 01:32 | |
*** larsks has joined #openstack-infra | 01:48 | |
*** jamesmcarthur has quit IRC | 01:49 | |
*** jamesmcarthur has joined #openstack-infra | 01:49 | |
*** jamesmcarthur has quit IRC | 01:54 | |
*** jamesmcarthur has joined #openstack-infra | 02:24 | |
*** kenkenen0 has quit IRC | 02:28 | |
*** jamesmcarthur has quit IRC | 02:34 | |
*** dviroel has quit IRC | 02:44 | |
*** jamesmcarthur has joined #openstack-infra | 03:08 | |
*** jamesmcarthur has quit IRC | 03:11 | |
*** jamesmcarthur has joined #openstack-infra | 03:11 | |
*** ysandeep|away is now known as ysandeep | 03:13 | |
*** ramishra has quit IRC | 03:20 | |
*** jamesmcarthur has quit IRC | 03:20 | |
*** psachin has joined #openstack-infra | 03:23 | |
*** zxiiro has joined #openstack-infra | 03:23 | |
*** ysandeep is now known as ysandeep|afk | 03:47 | |
*** ramishra has joined #openstack-infra | 03:48 | |
*** tonyb has quit IRC | 04:10 | |
*** jamesmcarthur has joined #openstack-infra | 04:25 | |
*** jamesmcarthur has quit IRC | 04:29 | |
*** evrardjp has quit IRC | 04:33 | |
*** evrardjp has joined #openstack-infra | 04:33 | |
*** ykarel|away has joined #openstack-infra | 04:34 | |
*** ykarel|away is now known as ykarel | 04:44 | |
*** hongbin has quit IRC | 04:59 | |
*** ykarel_ has joined #openstack-infra | 05:03 | |
*** ykarel has quit IRC | 05:04 | |
*** matt_kosut has joined #openstack-infra | 05:13 | |
*** tkajinam has quit IRC | 05:21 | |
*** tkajinam has joined #openstack-infra | 05:22 | |
*** ykarel_ is now known as ykarel | 05:22 | |
*** chenil has joined #openstack-infra | 05:31 | |
*** zxiiro has quit IRC | 05:34 | |
*** vishalmanchanda has joined #openstack-infra | 05:35 | |
*** sboyron has joined #openstack-infra | 05:36 | |
*** ysandeep|afk is now known as ysandeep | 05:43 | |
*** bdodd has quit IRC | 05:55 | |
*** bdodd has joined #openstack-infra | 05:57 | |
*** ricolin has quit IRC | 06:00 | |
*** psachin has quit IRC | 06:20 | |
*** elod_pto is now known as elod | 06:38 | |
*** eolivare has joined #openstack-infra | 06:40 | |
*** dklyle has quit IRC | 06:43 | |
*** hashar has joined #openstack-infra | 06:52 | |
*** slaweq has joined #openstack-infra | 06:57 | |
*** jtomasek has joined #openstack-infra | 07:01 | |
*** ralonsoh has joined #openstack-infra | 07:02 | |
*** psachin has joined #openstack-infra | 07:04 | |
*** andrewbonney has joined #openstack-infra | 07:08 | |
*** jcapitao has joined #openstack-infra | 07:17 | |
*** tosky has joined #openstack-infra | 07:26 | |
*** rpittau|afk is now known as rpittau | 07:27 | |
*** SpamapS has quit IRC | 07:35 | |
*** gfidente has joined #openstack-infra | 07:36 | |
*** chenil has quit IRC | 07:42 | |
*** SpamapS has joined #openstack-infra | 07:52 | |
*** rcernin has quit IRC | 07:52 | |
*** jpena|off is now known as jpena | 07:57 | |
*** lucasagomes has joined #openstack-infra | 08:05 | |
*** ricolin has joined #openstack-infra | 08:06 | |
*** lbragstad has quit IRC | 08:08 | |
*** piotrowskim has joined #openstack-infra | 08:19 | |
*** tetsuro has joined #openstack-infra | 08:22 | |
*** pmannidi has quit IRC | 08:24 | |
*** pmannidi has joined #openstack-infra | 08:24 | |
*** tetsuro has quit IRC | 08:27 | |
*** priteau has joined #openstack-infra | 08:33 | |
*** ociuhandu has joined #openstack-infra | 08:34 | |
*** ociuhandu has quit IRC | 08:35 | |
*** ociuhandu has joined #openstack-infra | 08:35 | |
*** rcernin has joined #openstack-infra | 08:44 | |
*** derekh has joined #openstack-infra | 08:44 | |
*** jtomasek has quit IRC | 08:52 | |
*** jtomasek has joined #openstack-infra | 08:55 | |
*** ramishra has quit IRC | 08:56 | |
*** ramishra has joined #openstack-infra | 08:57 | |
*** lbragstad has joined #openstack-infra | 09:04 | |
*** dtantsur|afk is now known as dtantsur | 09:06 | |
openstackgerrit | Moisés Guimarães proposed openstack/pbr master: Adding pre-commit https://review.opendev.org/742160 | 09:16 |
---|---|---|
*** hashar has quit IRC | 09:17 | |
*** psachin has quit IRC | 09:20 | |
*** psachin has joined #openstack-infra | 09:22 | |
*** rcernin has quit IRC | 09:33 | |
*** rcernin has joined #openstack-infra | 09:34 | |
*** jtomasek has quit IRC | 09:36 | |
*** jamesmcarthur has joined #openstack-infra | 09:38 | |
*** jamesmcarthur has quit IRC | 09:42 | |
*** vishalmanchanda has quit IRC | 09:44 | |
*** rcernin has quit IRC | 09:58 | |
*** rcernin has joined #openstack-infra | 09:59 | |
*** rcernin has quit IRC | 10:14 | |
*** rcernin has joined #openstack-infra | 10:25 | |
*** vishalmanchanda has joined #openstack-infra | 10:25 | |
*** priteau has quit IRC | 10:30 | |
*** jcapitao is now known as jcapitao_lunch | 10:33 | |
*** dchen has quit IRC | 10:58 | |
*** psachin has quit IRC | 11:00 | |
*** dviroel has joined #openstack-infra | 11:26 | |
*** jpena is now known as jpena|lunch | 11:31 | |
*** lpetrut has joined #openstack-infra | 11:37 | |
*** eolivare has quit IRC | 11:41 | |
*** eolivare has joined #openstack-infra | 11:42 | |
*** zxiiro has joined #openstack-infra | 11:56 | |
*** ysandeep is now known as ysandeep|brb | 11:56 | |
weshay | proxy error on gerrit | 11:58 |
weshay | fyi | 11:58 |
*** rlandy has joined #openstack-infra | 11:58 | |
*** rlandy is now known as rlandy|rover | 11:58 | |
sboyron | weshay +1 | 11:59 |
*** witek_ has joined #openstack-infra | 12:02 | |
*** jcapitao_lunch is now known as jcapitao | 12:04 | |
*** ysandeep|brb is now known as ysandeep | 12:08 | |
*** hongbin has joined #openstack-infra | 12:09 | |
*** rfolco has joined #openstack-infra | 12:10 | |
*** rcernin has quit IRC | 12:11 | |
ttx | +1 | 12:18 |
fungi | discussion in #opendev but it should be responding again now | 12:22 |
sboyron | fungi ok, thx, yes it's working now | 12:24 |
*** jpena|lunch is now known as jpena | 12:31 | |
*** Goneri has joined #openstack-infra | 12:54 | |
*** openstackgerrit has quit IRC | 13:17 | |
*** dwalt has joined #openstack-infra | 13:42 | |
*** mihalis68_ has joined #openstack-infra | 13:44 | |
*** hongbin has quit IRC | 13:52 | |
*** larsks has quit IRC | 13:56 | |
*** jamesmcarthur has joined #openstack-infra | 13:56 | |
*** larsks has joined #openstack-infra | 13:58 | |
*** dklyle has joined #openstack-infra | 14:12 | |
*** artom has joined #openstack-infra | 14:18 | |
*** redrobot has quit IRC | 14:22 | |
*** ysandeep is now known as ysandeep|away | 14:25 | |
*** jamesdenton has quit IRC | 14:31 | |
*** jamesmcarthur has quit IRC | 14:38 | |
*** jamesmcarthur has joined #openstack-infra | 14:40 | |
*** jamesdenton has joined #openstack-infra | 14:42 | |
*** hongbin has joined #openstack-infra | 14:46 | |
*** ociuhandu_ has joined #openstack-infra | 14:50 | |
*** jamesmcarthur has quit IRC | 14:51 | |
*** lpetrut has quit IRC | 14:51 | |
*** ociuhandu has quit IRC | 14:54 | |
*** jamesmcarthur has joined #openstack-infra | 14:58 | |
*** SpamapS has quit IRC | 15:10 | |
*** SpamapS has joined #openstack-infra | 15:10 | |
*** smcginnis has quit IRC | 15:17 | |
*** ykarel is now known as ykarel|away | 15:18 | |
*** smcginnis has joined #openstack-infra | 15:30 | |
*** jamesmcarthur has quit IRC | 15:33 | |
*** otherwiseguy_ is now known as otherwiseguy | 15:41 | |
*** dtantsur is now known as dtantsur|afk | 15:42 | |
*** ociuhandu_ has quit IRC | 15:46 | |
*** ociuhandu has joined #openstack-infra | 15:47 | |
*** jamesmcarthur has joined #openstack-infra | 15:49 | |
*** ykarel|away has quit IRC | 15:50 | |
*** gyee has joined #openstack-infra | 15:54 | |
*** lucasagomes has quit IRC | 16:03 | |
*** witek_ has quit IRC | 16:07 | |
*** rpittau is now known as rpittau|afk | 16:21 | |
*** SotK has quit IRC | 16:27 | |
*** jcapitao has quit IRC | 16:28 | |
*** SotK has joined #openstack-infra | 16:29 | |
EmilienM | fungi, clarkb : FYI I'm debugging ssh issues against review.opendev.org | 16:31 |
*** rpittau|afk has quit IRC | 16:31 | |
EmilienM | and it seems related to the new version of openssh shipped in fedora 33 beta | 16:31 |
EmilienM | which has stronger requirements and our version of Gerrit seems too old | 16:31 |
EmilienM | http://paste.openstack.org/show/hG6lhK3Aw2d8rqDoYNRE/ | 16:32 |
EmilienM | i'll let you know what I find | 16:32 |
fungi | EmilienM: thanks, curious to find out what you discover | 16:32 |
EmilienM | it's the /etc/crypto-policies/back-ends/openssh.config that is shipped in f33 | 16:33 |
EmilienM | https://www.diffchecker.com/hAA6vbTQ | 16:33 |
EmilienM | the one on the left works fine against our gerrit | 16:34 |
EmilienM | the one on the right doesn't | 16:34 |
fungi | EmilienM: we also have an upgraded gerrit at review-test.opendev.org you might want to compare against (it's got a snapshot of our production data from the beginning of the month) | 16:34 |
EmilienM | I reverted the changes done in /etc/crypto-policies/back-ends/openssh.config | 16:34 |
EmilienM | to put the f32 content | 16:34 |
*** rpittau|afk has joined #openstack-infra | 16:34 | |
clarkb | I'm on tumbleweed and it works fine | 16:34 |
fungi | same here on debian unstable, fwiw | 16:34 |
clarkb | ya I expect its a config/policy issye not the software istelf | 16:34 |
fungi | sounds like fedora got more restictive with allowed cipher suites | 16:35 |
EmilienM | yeah | 16:35 |
EmilienM | I'll dig after lunch, and let you know what I find | 16:35 |
fungi | they dropped aes256-cbc from ciphers | 16:36 |
clarkb | also dont forget to set up your btrfs defrag schedule :P | 16:36 |
* clarkb just ran into that after running out of disk while supposedly having plenty | 16:36 | |
fungi | and dropped ssh-rsa,ssh-rsa-cert-v01@openssh.com from pubkeyacceptedkeytypes | 16:39 |
fungi | i expect it's the loss of ssh-rsa which did it | 16:39 |
*** priteau has joined #openstack-infra | 16:39 | |
fungi | EmilienM: https://marcin.juszkiewicz.com.pl/2020/09/30/upgraded-to-fedora-33/ | 16:40 |
clarkb | why would they drop ssh-rsa? | 16:41 |
fungi | interestingly debian's openssh 8.3p1 doesn't drop it | 16:41 |
clarkb | ya because rsa is still good aiui | 16:41 |
fungi | concern over chosen-prefix attacks | 16:43 |
fungi | the deprecation notice in 8.3 recommends using rsa-sha2-256/512, ssh-ed25519, or ecdsa-sha2-nistp256/384/521 | 16:43 |
*** hamalq has joined #openstack-infra | 16:44 | |
clarkb | fungi: PubkeyAcceptedKeyTypes +rsa-sha2-256,rsa-sha2-512 <- is the workaround from marcin | 16:44 |
clarkb | so fedora is dropping the recommended rsa's too? | 16:44 |
fungi | apparently it's 8.4 which removes it by default, and i guess f33 updated to that but tumbleweed and sid have not yet | 16:45 |
clarkb | gotcha | 16:46 |
fungi | ahh, no, 8.4 doesn't say that it's dropped from defaults either: https://www.openssh.com/releasenotes.html | 16:46 |
clarkb | ya I expect fedora has done a more restrictive configuration | 16:47 |
clarkb | one that goes beyond openssh's recommendations | 16:47 |
clarkb | but need to check if gerrit 2.13 will do a sha2 256 rsa hostkey? | 16:48 |
clarkb | ya ok so gerrit won't do the sha256 | 16:49 |
clarkb | review-test will | 16:49 |
clarkb | as a side note https can be used instead if people prefer | 16:50 |
clarkb | and its the use of sha1 to verify host key signatures not rsa itself that is the problem. I'm not completely crazy in remember rsa is fine | 16:52 |
fungi | right, which is why the rsa-sha2-* types are still acceptable | 16:53 |
*** ociuhandu_ has joined #openstack-infra | 16:54 | |
clarkb | and openssh itself has warned a future release will remove ssh-rsa but the current release has not yet done so | 16:54 |
fungi | granted i'm struggling to think of how an attacker could leverage that in the case of our gerrit deployment. they couldn't really use it to fully hijack the session because they don't have the user's private key | 16:55 |
clarkb | they could replace the data pushed to gerrit? | 16:56 |
fungi | they could impersonate our gerrit and cause people to think they were issuing commands/pushing to us when they weren't | 16:56 |
*** ociuhandu has quit IRC | 16:57 | |
fungi | they couldn't push something to us though, because they can't authenticate to our gerrit on behalf of the user without also compromising the user's private key, at which point there's no need to hijack anything anyway | 16:57 |
clarkb | ah | 16:57 |
fungi | they might be able to serve backdoored versions of changes to users over ssh, e.g. git fetch | 16:57 |
*** ociuhandu_ has quit IRC | 16:58 | |
clarkb | new gerrit doesn't show you host keys in the web ui? | 16:58 |
clarkb | that is a disappointing regression | 16:58 |
fungi | it's not like impersonating your shell account where you might then log into what you think is your shell and sudo something and enter your password at a sudo password prompt and then because you're not too bright and have allowed ssh password auth for your shell server the attacker then has your account login and can take over your real account | 16:59 |
clarkb | ya I expect we can continue to live with this until we upgrade in a month or two | 16:59 |
clarkb | since openssh hasn't even removed it by default | 16:59 |
*** derekh has quit IRC | 17:00 | |
*** bdodd has quit IRC | 17:00 | |
*** ykarel|away has joined #openstack-infra | 17:01 | |
fungi | it's also not like we're encouraging unsafe configuration, we can recommend users temporarily stick a Host review.opendev.org override in their ~/.ssh/config with PubkeyAcceptedKeyTypes +ssh-rsa | 17:02 |
fungi | EmilienM: ^ curious if that solves if for you, btw | 17:02 |
*** jpena is now known as jpena|off | 17:05 | |
*** ykarel|away has quit IRC | 17:14 | |
*** gfidente is now known as gfidente|afk | 17:21 | |
*** Guest75569 has joined #openstack-infra | 17:21 | |
*** Guest75569 is now known as redrobot | 17:23 | |
*** jamesmcarthur has quit IRC | 17:25 | |
*** vesper11 has joined #openstack-infra | 17:25 | |
*** ociuhandu has joined #openstack-infra | 17:27 | |
*** andrewbonney has quit IRC | 17:28 | |
*** eolivare has quit IRC | 17:30 | |
*** ociuhandu has quit IRC | 17:32 | |
*** jamesmcarthur has joined #openstack-infra | 17:41 | |
EmilienM | fungi: thanks for the link, I didn't see it before | 17:42 |
*** bdodd has joined #openstack-infra | 17:42 | |
EmilienM | fungi: yes the workaround works for me | 17:46 |
fungi | awesome, thanks for confirming | 17:47 |
EmilienM | for the record I hate installing f33 on my work laptop but I'm having strange issues with the new work laptop and thought using latest would help | 17:47 |
clarkb | EmilienM: I run tumbleweed to try and be canary for things like this but I guess their security stance is less strict than fedora's | 17:48 |
EmilienM | clarkb: thx for the defrag tip, I'll take it | 17:48 |
clarkb | EmilienM: I think the command is call rebalance or something | 17:48 |
clarkb | EmilienM: it is functionally similar to a defrag | 17:48 |
*** harlowja has joined #openstack-infra | 17:51 | |
*** priteau has quit IRC | 17:53 | |
*** priteau has joined #openstack-infra | 17:54 | |
*** ralonsoh has quit IRC | 18:00 | |
*** priteau has quit IRC | 18:01 | |
*** piotrowskim has quit IRC | 18:05 | |
*** rlandy|rover is now known as rlandy|rover|brb | 18:14 | |
*** sshnaidm is now known as sshnaidm|afk | 18:24 | |
*** sboyron has quit IRC | 18:44 | |
*** rlandy|rover|brb is now known as rlandy|rover | 18:55 | |
*** hashar has joined #openstack-infra | 18:57 | |
*** dwalt has quit IRC | 19:22 | |
*** matt_kosut has quit IRC | 20:13 | |
*** gfidente|afk has quit IRC | 20:26 | |
*** zxiiro has quit IRC | 20:28 | |
*** hashar has quit IRC | 20:30 | |
*** iurygregory has quit IRC | 20:50 | |
*** iurygregory has joined #openstack-infra | 20:50 | |
*** jamesmcarthur has quit IRC | 20:51 | |
*** ociuhandu has joined #openstack-infra | 20:55 | |
*** jamesmcarthur has joined #openstack-infra | 20:56 | |
*** rfolco has quit IRC | 21:12 | |
*** rfolco has joined #openstack-infra | 21:14 | |
*** jamesmcarthur has quit IRC | 21:19 | |
*** jamesmcarthur has joined #openstack-infra | 21:26 | |
*** ociuhandu has quit IRC | 21:43 | |
*** artom has quit IRC | 21:49 | |
*** artom has joined #openstack-infra | 21:50 | |
*** rfolco has quit IRC | 22:10 | |
*** rcernin has joined #openstack-infra | 22:16 | |
*** vishalmanchanda has quit IRC | 22:34 | |
*** ociuhandu has joined #openstack-infra | 22:38 | |
*** ociuhandu has quit IRC | 22:42 | |
*** rcernin has quit IRC | 22:45 | |
*** rcernin has joined #openstack-infra | 22:50 | |
*** rcernin has quit IRC | 22:51 | |
*** rcernin has joined #openstack-infra | 22:51 | |
*** rfolco has joined #openstack-infra | 22:53 | |
*** artom has quit IRC | 23:01 | |
*** artom has joined #openstack-infra | 23:03 | |
*** artom has quit IRC | 23:04 | |
*** artom has joined #openstack-infra | 23:04 | |
*** slaweq has quit IRC | 23:08 | |
*** rfolco has quit IRC | 23:13 | |
*** jamesdenton has quit IRC | 23:20 | |
*** jamesdenton has joined #openstack-infra | 23:20 | |
*** samP has quit IRC | 23:21 | |
*** matbu has quit IRC | 23:22 | |
*** bnemec has quit IRC | 23:22 | |
*** matbu has joined #openstack-infra | 23:23 | |
*** zigo has quit IRC | 23:23 | |
*** bnemec has joined #openstack-infra | 23:24 | |
*** samP has joined #openstack-infra | 23:26 | |
*** harlowja has quit IRC | 23:29 | |
*** pmannidi has quit IRC | 23:33 | |
*** pmannidi has joined #openstack-infra | 23:33 | |
*** tosky has quit IRC | 23:40 | |
*** rfolco has joined #openstack-infra | 23:41 | |
*** dchen has joined #openstack-infra | 23:47 | |
*** Goneri has quit IRC | 23:48 | |
*** artom has quit IRC | 23:52 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!