tmcpeak | bdpayne: hmm, crazy | 00:10 |
---|---|---|
tmcpeak | guess we need some master of IRC to help us sort this out | 00:10 |
*** fishcried has quit IRC | 00:24 | |
*** gnef has joined #openstack-security | 00:28 | |
*** tmcpeak has quit IRC | 00:37 | |
*** bdpayne has quit IRC | 01:05 | |
*** amrith has joined #openstack-security | 01:16 | |
amrith | tmcpeak ... yt? | 01:17 |
*** MARYLEIN has joined #openstack-security | 01:33 | |
*** MARYLEIN has quit IRC | 01:35 | |
*** voodookid has joined #openstack-security | 02:26 | |
*** voodookid has quit IRC | 02:33 | |
*** jamielennox|away has quit IRC | 02:37 | |
*** jamielennox|away has joined #openstack-security | 02:37 | |
*** jamielennox|away has quit IRC | 02:42 | |
*** jamielennox|away has joined #openstack-security | 02:42 | |
*** dmccowan has quit IRC | 02:53 | |
*** bdpayne has joined #openstack-security | 02:54 | |
*** jamielennox|away has quit IRC | 02:59 | |
*** jamielennox|away has joined #openstack-security | 03:00 | |
*** bdpayne has quit IRC | 03:01 | |
*** gnef has quit IRC | 03:02 | |
*** jamielennox|away has quit IRC | 03:38 | |
*** jamielennox|away has joined #openstack-security | 03:39 | |
*** bdpayne has joined #openstack-security | 04:03 | |
*** voodookid has joined #openstack-security | 04:09 | |
*** voodookid has quit IRC | 04:27 | |
*** bdpayne has quit IRC | 05:36 | |
*** bdpayne has joined #openstack-security | 05:48 | |
*** jamielennox|away has quit IRC | 06:10 | |
*** jamielennox|away has joined #openstack-security | 06:11 | |
*** bdpayne has quit IRC | 06:18 | |
*** jamielennox|away has quit IRC | 07:38 | |
*** jamielennox|away has joined #openstack-security | 07:39 | |
*** jamielenz has joined #openstack-security | 09:33 | |
*** jamielennox|away has quit IRC | 09:36 | |
*** jamielennox|away has joined #openstack-security | 10:07 | |
*** jamielenz has quit IRC | 10:09 | |
*** kr4sh has joined #openstack-security | 10:13 | |
*** franco has joined #openstack-security | 10:14 | |
franco | ciao ciao | 10:15 |
*** franco has left #openstack-security | 10:15 | |
*** kr4sh has quit IRC | 10:26 | |
*** dmccowan has joined #openstack-security | 12:00 | |
*** dmccowan_ has joined #openstack-security | 12:10 | |
*** dmccowan has quit IRC | 12:11 | |
*** dmccowan_ is now known as dmccowan | 12:11 | |
*** nkinder has quit IRC | 13:03 | |
*** voodookid has joined #openstack-security | 13:05 | |
*** bknudson has quit IRC | 13:22 | |
*** bknudson has joined #openstack-security | 13:41 | |
*** voodookid has quit IRC | 13:41 | |
*** nkinder has joined #openstack-security | 13:53 | |
*** dmccowan has quit IRC | 14:00 | |
*** dmccowan has joined #openstack-security | 14:13 | |
*** voodookid has joined #openstack-security | 14:40 | |
*** openstackgerrit has joined #openstack-security | 14:54 | |
*** nkinder has quit IRC | 15:22 | |
*** gmurphy has quit IRC | 15:22 | |
*** nkinder has joined #openstack-security | 15:22 | |
*** gmurphy has joined #openstack-security | 15:22 | |
*** paulmo has joined #openstack-security | 15:27 | |
*** paulmo1 has quit IRC | 15:29 | |
*** paulmo has quit IRC | 15:32 | |
*** fungi has quit IRC | 15:34 | |
*** openstack has joined #openstack-security | 16:19 | |
*** bdpayne has joined #openstack-security | 16:21 | |
*** bknudson has quit IRC | 16:26 | |
*** nkinder has quit IRC | 16:37 | |
*** nkinder has joined #openstack-security | 16:39 | |
*** bdpayne has quit IRC | 16:46 | |
*** voodookid has quit IRC | 16:59 | |
*** voodookid has joined #openstack-security | 17:00 | |
tmcpeak | nkinder: if you get a chance will you take a look at this patch? https://review.openstack.org/#/c/117174/1 | 17:02 |
tmcpeak | actually for that matter any of you | 17:03 |
tmcpeak | if you've got a minute | 17:03 |
*** bdpayne has joined #openstack-security | 17:11 | |
tmcpeak | bdpayne: you got time to throw a second pair of eyes on this: https://review.openstack.org/#/c/117174/ | 17:17 |
*** ptd has joined #openstack-security | 17:23 | |
bdpayne | sure, I'll take a look now tmcpeak | 17:26 |
tmcpeak | bdpayne: awesome, thank you sir | 17:26 |
tmcpeak | bdpayne: FYI we've decided to address insecure temp files separately | 17:26 |
bdpayne | ok | 17:26 |
bdpayne | but still before the release? | 17:27 |
tmcpeak | the commitment is to do as much as we can | 17:27 |
tmcpeak | amrith is the author of the patch btw | 17:27 |
tmcpeak | amrith: you around? | 17:27 |
amrith | tmcpeak, yes | 17:34 |
amrith | how's u? | 17:34 |
tmcpeak | amrith: good, I've got bdpayne taking a look as well | 17:34 |
tmcpeak | amrith: your changes are good, I'm just trying to decide if there is a good way to clean up that other part I mentioned on the review | 17:34 |
amrith | thanks travis | 17:34 |
amrith | much appreciate | 17:34 |
amrith | I have some ideas | 17:35 |
tmcpeak | amrith: I'm glad you're taking this on | 17:35 |
amrith | and some prototypes for that | 17:35 |
tmcpeak | oh cool | 17:35 |
amrith | no worries, happy to help | 17:35 |
bdpayne | so I've made some comments on that CR | 17:35 |
amrith | you'll be paying for it right ;) | 17:35 |
amrith | where do I send the bill? | 17:35 |
tmcpeak | bdpayne: oh cool | 17:35 |
bdpayne | amrith it looks like your CR, so feel free to ping me if you have questions | 17:35 |
amrith | bdpayne, just reading your comments | 17:36 |
amrith | one second | 17:36 |
amrith | so tmcpeak ... maybe best to forward bdpayne the email thread so he understands the context? | 17:36 |
tmcpeak | amrith: yeah, agree | 17:37 |
amrith | ok, will do that | 17:37 |
tmcpeak | bdpayne: I've also brought up the rootwrap thing, the issue is how much we are comfortable changing before code freeze | 17:37 |
tmcpeak | bdpayne: I'm not very familiar with how the whole process works | 17:38 |
bdpayne | sure | 17:38 |
amrith | bdpayne, this is just one step in (hopefully) the right direction | 17:38 |
bdpayne | yeah, I think that makes sense | 17:38 |
tmcpeak | bdpayne: there are things I'd really like to have fixed before release, but I don't know how prioritization works | 17:38 |
amrith | I think this fix has uncovered some other areas for improvement | 17:38 |
bdpayne | I'm just providing some comments... largely from an outsider perspective | 17:38 |
tmcpeak | bdpayne: awesome | 17:38 |
tmcpeak | bdpayne: I appreciate the second look | 17:38 |
bdpayne | np | 17:39 |
tmcpeak | amrith: maybe we could synch up with Nikhil and set priorities on this stuff | 17:39 |
amrith | tmcpeak, I notice you sent the review to a couple of others | 17:39 |
amrith | thanks for doing that | 17:39 |
amrith | the more eyes on it, the better | 17:39 |
tmcpeak | amrith: sure, those guys are similar to Bryan, not familiar with this issue but very experienced security guys | 17:40 |
amrith | I think it will produce more ideas and suggestions for improvement. again some that we can do right away, others that may take a little more time. | 17:40 |
amrith | given the juno freeze. | 17:40 |
tmcpeak | when is the Juno freeze btw | 17:40 |
amrith | I think it is two weeks. | 17:40 |
tmcpeak | hmm | 17:40 |
amrith | there's a lot of stuff in flight in trove | 17:42 |
amrith | and that's the reason for the concern at this stage. | 17:43 |
tmcpeak | I see | 17:43 |
amrith | but yes, we should sync with Nikhil and the other core team members. | 17:43 |
tmcpeak | amrith: my only concern is if some of this stuff would generate an advisory | 17:43 |
amrith | that is a good point and I noticed that there was a decision not to? | 17:44 |
tmcpeak | I believe the original issue found would have if it had been released | 17:44 |
tmcpeak | yeah, so if it got released in Juno, and then I found the same issue it would have generated an advisroy | 17:44 |
tmcpeak | advisory | 17:44 |
tmcpeak | amrith: what's your involvement in Trove btw, do you know anybody who could answer if any security reviews have been done on it? | 17:45 |
amrith | I'm one of the contributors to trove. There is a Trove team meeting (IRC, #openstack-meeting-alt) in 24 minutes. I'm sure someone there could answer. Or Nikhil can, he's the PTL. | 17:46 |
tmcpeak | oh ok cool | 17:47 |
tmcpeak | I'll sit in on that | 17:47 |
tmcpeak | I believe I met Nikhil once in Seattle, cool guy | 17:47 |
amrith | may be better to ping nikhil directly. | 17:47 |
amrith | SlickNik on IRC | 17:48 |
tmcpeak | cool | 17:48 |
tmcpeak | pinging now | 17:48 |
*** SlickNik has joined #openstack-security | 17:49 | |
amrith | ok | 17:49 |
*** ptd has quit IRC | 17:58 | |
*** chair6_ is now known as chair6 | 17:59 | |
*** bknudson has joined #openstack-security | 18:21 | |
bknudson | I've got a question for the team here... maybe someone is familiar with openssl cms. | 18:23 |
bknudson | we use cms in keystone for the token sig. | 18:24 |
bknudson | according to the docs for openssl cms, the digest algorithm defaults to sha1 | 18:24 |
bknudson | https://www.openssl.org/docs/apps/cms.html (see the -md option) | 18:24 |
bknudson | why I try running the command myself it shows algorithm is sha1 | 18:25 |
bknudson | digestAlgorithms: algorithm: sha1 (1.3.14.3.2.26) | 18:25 |
bknudson | so I think that this is inadequate based on NIST 800-131A. | 18:25 |
*** tmcpeak has quit IRC | 18:32 | |
*** nkinder has quit IRC | 20:28 | |
*** nkinder has joined #openstack-security | 20:45 | |
*** tmcpeak has joined #openstack-security | 20:56 | |
*** tmcpeak has quit IRC | 21:13 | |
*** dmccowan has quit IRC | 21:14 | |
*** tmcpeak has joined #openstack-security | 21:15 | |
*** paulmo has quit IRC | 21:33 | |
*** nkinder has quit IRC | 21:39 | |
*** tmcpeak has quit IRC | 22:19 | |
*** tmcpeak has joined #openstack-security | 22:21 | |
*** dmccowan has joined #openstack-security | 23:07 | |
*** jamielennox|away is now known as jamielennox | 23:10 | |
*** voodookid has quit IRC | 23:20 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!