Tuesday, 2014-07-22

*** ved_lad has joined #openstack-security00:07
*** malini1 has quit IRC00:41
*** ved_lad has quit IRC00:57
*** gmurphy has quit IRC01:08
*** gmurphy has joined #openstack-security01:09
*** sicarie has joined #openstack-security01:56
*** sicarie has quit IRC01:57
*** tmcpeak has joined #openstack-security03:06
tmcpeakgmurphy: great catch on that change.  I didn't think to check the rest of the source for other places the command was being dumped without being sanitized, just checked the new stuff :)03:12
gmurphythanks.03:13
*** paulmo has quit IRC03:15
tmcpeakgmurphy: where are you from?03:18
tmcpeakon kind of late, aren't you?03:18
gmurphynope. i'm in australia03:19
tmcpeakgmurphy: ahh nice, you aren't one of hyakuhei's guys, are you?03:19
gmurphyno. i'm with red hat product security.03:20
gmurphytmcpeak - how about you? late there?03:21
tmcpeakgmurphy: oh cool, are you nkinder's guy?03:21
tmcpeakgmurphy: I know he said he had a guy in Australia03:21
gmurphydifferent team same company.03:21
tmcpeakgmurphy: oh cool, you guys are doing some good stuff03:22
tmcpeakgmurphy: I'm in SF, just popped on to check some stuff out03:22
tmcpeakgmurphy: where in Australia are you?03:22
gmurphythink that would be umm.. jamie lennox03:23
gmurphyi'm in brisbane.03:24
gmurphywe have a few security guys here.03:24
tmcpeakgmurphy: oh cool, Jamie Lennox sounds right03:24
tmcpeakgmurphy: I'm Symantec btw… to answer your original question03:24
tmcpeakgmurphy: so are you focused on OpenStack or across all RedHat projects?03:25
gmurphytmcpeak - oh right. geeze must be pretty late there atm.03:25
gmurphytmcpeak - i do a bunch of different things at red hat03:25
gmurphytmcpeak - i help out on the openstack vmt in my spare time03:25
tmcpeakgmurphy: it's 8:25 PM, not so late03:26
tmcpeakgmurphy: oh you're VMT?03:26
gmurphytmcpeak - ah ok that's more reasonable.03:26
gmurphytmcpeak - yep.03:26
tmcpeakgmurphy: badass, that always sounded like a cool gig03:26
tmcpeakgmurphy: how many are on VMT?03:26
gmurphytmcpeak - it has its moments :-)03:27
gmurphytmcpeak - 403:27
gmurphyhttps://launchpad.net/~openstack-vuln-mgmt/+members#active03:27
tmcpeakgmurphy: awesome, how's the workload? you guys have enough resources to chew through everything?03:27
tmcpeakgmurphy: oh yeah, there you are :)03:28
tmcpeakgmurphy: did you reach out to them or them to you?03:28
gmurphytmcpeak - think we are keeping on top of it.03:28
gmurphytmcpeak - i volunteered to help03:29
tmcpeakgmurphy: do you guys handle incident response too?03:29
gmurphytmcpeak - this is our process etc https://wiki.openstack.org/wiki/VulnerabilityManagement03:30
gmurphytmcpeak - so we get people reporting things related to openstack infrastructure sometimes too if thats what you mean?03:31
tmcpeakgmurphy: yeah, that's part of what I was wondering, also about the notifying downstream stakeholders03:31
tmcpeakgmurphy: the embargo process is fascinating too03:33
tmcpeakgmurphy: I'd like to get somebody from Symantec on that stakeholder list, probably the Dir in charge of security stuff, can I just explain that we are running a large private OpenStack deployment?03:35
gmurphytmcpeak - one thing i would like to get the ossg to help out with is doing audits for projects we are considering adding to our security supported project list03:35
gmurphy(https://wiki.openstack.org/wiki/Security_supported_projects)03:35
tmcpeakgmurphy: oh yeah, that sounds like a great project for us to take a stab at03:36
tmcpeakgmurphy: what do you have in mind for the audits?03:37
gmurphytmcpeak - what you should do is send through a request via email to everybody in the VMT. we will review and approve etc.03:37
tmcpeakgmurphy: ok cool, I'll help him with it03:39
tmcpeakgmurphy: in terms of the audit, nkinder was working on getting some baseline review of projects03:39
tmcpeakgmurphy: crypto inventory, stored secrets, etc..03:39
gmurphytmcpeak - yeah.  i think that is a great idea.03:39
tmcpeakgmurphy: he's leading that effort03:40
tmcpeakgmurphy: Keystone has done one, and I'm working on one for Glance (although I'll admit I'm lagging a bit)03:40
tmcpeakgmurphy: I think others may be working on other projects03:40
tmcpeakgmurphy: do you have any reference audits so we could compare what you're looking at versus the ones we're already working on?03:40
tmcpeakgmurphy: these are the ones that nkinder is leading the push for03:41
tmcpeakhttps://wiki.openstack.org/wiki/Security/Icehouse/Keystone03:41
gmurphytmcpeak - ok great. i'll check them out.03:41
tmcpeakgmurphy: sounds good03:42
tmcpeakgmurphy: going to run, I'll catch you later03:42
gmurphytmcpeak - not really. i'll try to put something together about it and send it through to ossg list for feedback.03:42
tmcpeakgmurphy: ok cool03:43
gmurphytmcpeak k. thanks for the chat.03:43
tmcpeakgmurphy: sounds good03:43
tmcpeakgmurphy: nice talking to you03:43
*** tmcpeak has quit IRC03:44
openstackgerritNathaniel Dillon proposed a change to openstack/security-doc: Removing references of out-of-date versions of OpenStack  https://review.openstack.org/10856903:58
openstackgerritMike Lange proposed a change to openstack/security-doc: Added sections 1.2 and 1.3  https://review.openstack.org/10857004:02
openstackgerritA change was merged to openstack/security-doc: Removed some duplicate spaces  https://review.openstack.org/10823904:29
*** voodookid has joined #openstack-security04:47
openstackgerritMike Lange proposed a change to openstack/security-doc: Added sections 1.2 and 1.3  https://review.openstack.org/10857004:51
*** voodookid has quit IRC05:50
openstackgerritOpenStack Proposal Bot proposed a change to openstack/security-doc: Imported Translations from Transifex  https://review.openstack.org/10858506:05
*** elo has quit IRC06:26
openstackgerritA change was merged to openstack/security-doc: Imported Translations from Transifex  https://review.openstack.org/10858506:36
*** malini has joined #openstack-security07:36
*** elo has joined #openstack-security07:51
*** malini has quit IRC08:42
*** elo has quit IRC08:43
*** elo has joined #openstack-security08:47
*** openstackgerrit has quit IRC09:31
*** openstackgerrit has joined #openstack-security09:32
*** hyakuhei has quit IRC09:54
*** viraptor1 has quit IRC09:54
*** hyakuhei has joined #openstack-security09:55
*** viraptor1 has joined #openstack-security09:55
openstackgerritKATO Tomoyuki proposed a change to openstack/security-doc: Use the right name and add reference to.  https://review.openstack.org/10864511:11
openstackgerritDan Sneddon proposed a change to openstack/security-doc: Changes wording from "spin it up" to "create an instance"  https://review.openstack.org/10866312:02
*** bknudson has quit IRC13:10
*** nkinder has quit IRC13:18
*** bknudson has joined #openstack-security13:29
openstackgerritA change was merged to openstack/security-doc: Changes wording from "spin it up" to "create an instance"  https://review.openstack.org/10866314:01
*** paulmo has joined #openstack-security14:02
*** nkinder has joined #openstack-security14:04
*** voodookid has joined #openstack-security14:15
*** elo has quit IRC14:28
*** elo has joined #openstack-security14:30
*** gabriela has joined #openstack-security14:43
gabrielaHELLO14:43
gabriela BXLG14:43
gabrielahola volvi14:56
*** sicarie has joined #openstack-security15:10
gabriela: *15:13
gabrielađ€ßðđłsf15:13
*** gabriela has left #openstack-security15:17
*** sicarie_ has joined #openstack-security15:28
*** sicarie has quit IRC15:29
*** sicarie_ is now known as sicarie15:29
*** viraptor1 has quit IRC15:49
*** elo has quit IRC16:13
*** tmcpeak has joined #openstack-security16:36
tmcpeakwoohoo, glance change made it upstream16:39
tmcpeakgood learning experience to tackle it end to end16:39
tmcpeaknow time to fix all the things :P16:39
paulmoWow, congrats!  Pushing upstream is not always easy. :)16:48
tmcpeakpaulmo: thanks!16:49
tmcpeakpaulmo: this was actually a tiny change but great to get my feet wet16:49
paulmoIt is all downhill now16:49
paulmo(well, on a bumpy road maybe hah)16:50
*** ved_lad has joined #openstack-security17:02
tmcpeakpaulmo: LOL17:05
tmcpeakI have an idea for new content for the book17:06
tmcpeakI spoke to gmurphy last night about VMT a little bit17:07
tmcpeakwhat about a section on workflow for applying security patches in a timely manner17:07
tmcpeakplus I think we should call out the ability to get early access to new vulnerability patches if you are a stakeholder17:07
tmcpeakwhich I think is important information to make available and isn't the kind of thing people would think of by themselves17:08
tmcpeaknkinder: this is a good point about affected versions17:11
tmcpeakare we going back and adding new versions to old notes?17:11
nkindertmcpeak: we haven't, but that's a good idea17:13
tmcpeaknkinder: yeah, otherwise people may assume that newer versions aren't affected, which in some cases they may not be, but in some they almost certainly are17:14
tmcpeaknkinder: there's a fair amount of work to be done to sort them out, but it's probably worth it17:14
tmcpeaknkinder: otherwise the notes get kind of stale17:14
nkindertmcpeak: a good portion of the notes have been written since Icehouse, so we're good there17:14
tmcpeaknkinder: I'm mostly concerned with what happens when Juno is released17:15
nkindertmcpeak: we should audit through them when juno release candidates start landing17:15
tmcpeaknkinder: yep, for sure17:15
tmcpeaknkinder: you see the bit above about the new section for the book?17:16
openstackgerritNathaniel Dillon proposed a change to openstack/security-doc: Removing references of out-of-date versions of OpenStack  https://review.openstack.org/10878017:17
nkindertmcpeak: yeah, it's good to mention (but there are vast differences in how updates should be applied depending on the distribution)17:17
tmcpeaknkinder: yeah for sure, I just mean some rough discussion about what sample workflows might look like17:18
nkindertmcpeak: open a doc bug so we don't lose track of it17:18
tmcpeaknkinder: cool, will do17:18
tmcpeaknkinder: that's here, right? https://bugs.launchpad.net/openstack-manuals17:19
nkindertmcpeak: yeah, but you need to add the sec-guide tag - https://bugs.launchpad.net/openstack-manuals/+bugs?field.tag=sec-guide17:20
tmcpeaknkinder: ahh cool, thank you17:21
openstackgerritNathaniel Dillon proposed a change to openstack/security-doc: Removing references of out-of-date versions of OpenStack  https://review.openstack.org/10856917:25
tmcpeakhttps://bugs.launchpad.net/openstack-manuals/+bug/134705717:27
*** sicarie_ has joined #openstack-security18:00
*** sicarie has quit IRC18:03
*** sicarie_ is now known as sicarie18:06
*** elo has joined #openstack-security18:10
*** sicarie has quit IRC18:12
*** ved_lad_ has joined #openstack-security18:14
*** ved_lad has quit IRC18:15
*** ved_lad_ has quit IRC18:21
*** nkinder has quit IRC18:32
*** nkinder has joined #openstack-security18:44
*** ved_lad has joined #openstack-security18:46
*** elo has quit IRC19:21
*** ved_lad has quit IRC19:46
*** ved_lad has joined #openstack-security20:08
*** ved_lad has quit IRC20:45
*** tmcpeak1 has joined #openstack-security21:34
*** tmcpeak has quit IRC21:37
openstackgerritDan Sneddon proposed a change to openstack/security-doc: Add link to management security domain to security guide  https://review.openstack.org/10885121:39
openstackgerritDan Sneddon proposed a change to openstack/security-doc: Add link to management security domain to security guide  https://review.openstack.org/10885121:42
openstackgerritDan Sneddon proposed a change to openstack/security-doc: Add link to management security domain to security guide  https://review.openstack.org/10885121:43
openstackgerritDan Sneddon proposed a change to openstack/security-doc: Add link to management security domain to security guide  https://review.openstack.org/10885121:49
openstackgerritDan Sneddon proposed a change to openstack/security-doc: Cleaning up grammer and wording, avoiding 2nd person  https://review.openstack.org/10885522:12
openstackgerritDan Sneddon proposed a change to openstack/security-doc: Cleaning up grammer and wording, avoiding 2nd person  https://review.openstack.org/10885522:14
*** paulmo has quit IRC22:21
openstackgerritA change was merged to openstack/security-doc: Removing references of out-of-date versions of OpenStack  https://review.openstack.org/10856922:35
*** tmcpeak1 has quit IRC22:50
*** tmcpeak has joined #openstack-security22:56
*** bknudson has quit IRC22:57
*** nkinder has quit IRC22:59
*** tmcpeak has quit IRC23:01
*** voodookid has quit IRC23:10

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!