| tmcpeak | bdpayne: hmm, crazy | 00:10 |
|---|---|---|
| tmcpeak | guess we need some master of IRC to help us sort this out | 00:10 |
| *** fishcried has quit IRC | 00:24 | |
| *** gnef has joined #openstack-security | 00:28 | |
| *** tmcpeak has quit IRC | 00:37 | |
| *** bdpayne has quit IRC | 01:05 | |
| *** amrith has joined #openstack-security | 01:16 | |
| amrith | tmcpeak ... yt? | 01:17 |
| *** MARYLEIN has joined #openstack-security | 01:33 | |
| *** MARYLEIN has quit IRC | 01:35 | |
| *** voodookid has joined #openstack-security | 02:26 | |
| *** voodookid has quit IRC | 02:33 | |
| *** jamielennox|away has quit IRC | 02:37 | |
| *** jamielennox|away has joined #openstack-security | 02:37 | |
| *** jamielennox|away has quit IRC | 02:42 | |
| *** jamielennox|away has joined #openstack-security | 02:42 | |
| *** dmccowan has quit IRC | 02:53 | |
| *** bdpayne has joined #openstack-security | 02:54 | |
| *** jamielennox|away has quit IRC | 02:59 | |
| *** jamielennox|away has joined #openstack-security | 03:00 | |
| *** bdpayne has quit IRC | 03:01 | |
| *** gnef has quit IRC | 03:02 | |
| *** jamielennox|away has quit IRC | 03:38 | |
| *** jamielennox|away has joined #openstack-security | 03:39 | |
| *** bdpayne has joined #openstack-security | 04:03 | |
| *** voodookid has joined #openstack-security | 04:09 | |
| *** voodookid has quit IRC | 04:27 | |
| *** bdpayne has quit IRC | 05:36 | |
| *** bdpayne has joined #openstack-security | 05:48 | |
| *** jamielennox|away has quit IRC | 06:10 | |
| *** jamielennox|away has joined #openstack-security | 06:11 | |
| *** bdpayne has quit IRC | 06:18 | |
| *** jamielennox|away has quit IRC | 07:38 | |
| *** jamielennox|away has joined #openstack-security | 07:39 | |
| *** jamielenz has joined #openstack-security | 09:33 | |
| *** jamielennox|away has quit IRC | 09:36 | |
| *** jamielennox|away has joined #openstack-security | 10:07 | |
| *** jamielenz has quit IRC | 10:09 | |
| *** kr4sh has joined #openstack-security | 10:13 | |
| *** franco has joined #openstack-security | 10:14 | |
| franco | ciao ciao | 10:15 |
| *** franco has left #openstack-security | 10:15 | |
| *** kr4sh has quit IRC | 10:26 | |
| *** dmccowan has joined #openstack-security | 12:00 | |
| *** dmccowan_ has joined #openstack-security | 12:10 | |
| *** dmccowan has quit IRC | 12:11 | |
| *** dmccowan_ is now known as dmccowan | 12:11 | |
| *** nkinder has quit IRC | 13:03 | |
| *** voodookid has joined #openstack-security | 13:05 | |
| *** bknudson has quit IRC | 13:22 | |
| *** bknudson has joined #openstack-security | 13:41 | |
| *** voodookid has quit IRC | 13:41 | |
| *** nkinder has joined #openstack-security | 13:53 | |
| *** dmccowan has quit IRC | 14:00 | |
| *** dmccowan has joined #openstack-security | 14:13 | |
| *** voodookid has joined #openstack-security | 14:40 | |
| *** openstackgerrit has joined #openstack-security | 14:54 | |
| *** nkinder has quit IRC | 15:22 | |
| *** gmurphy has quit IRC | 15:22 | |
| *** nkinder has joined #openstack-security | 15:22 | |
| *** gmurphy has joined #openstack-security | 15:22 | |
| *** paulmo has joined #openstack-security | 15:27 | |
| *** paulmo1 has quit IRC | 15:29 | |
| *** paulmo has quit IRC | 15:32 | |
| *** fungi has quit IRC | 15:34 | |
| *** openstack has joined #openstack-security | 16:19 | |
| *** bdpayne has joined #openstack-security | 16:21 | |
| *** bknudson has quit IRC | 16:26 | |
| *** nkinder has quit IRC | 16:37 | |
| *** nkinder has joined #openstack-security | 16:39 | |
| *** bdpayne has quit IRC | 16:46 | |
| *** voodookid has quit IRC | 16:59 | |
| *** voodookid has joined #openstack-security | 17:00 | |
| tmcpeak | nkinder: if you get a chance will you take a look at this patch? https://review.openstack.org/#/c/117174/1 | 17:02 |
| tmcpeak | actually for that matter any of you | 17:03 |
| tmcpeak | if you've got a minute | 17:03 |
| *** bdpayne has joined #openstack-security | 17:11 | |
| tmcpeak | bdpayne: you got time to throw a second pair of eyes on this: https://review.openstack.org/#/c/117174/ | 17:17 |
| *** ptd has joined #openstack-security | 17:23 | |
| bdpayne | sure, I'll take a look now tmcpeak | 17:26 |
| tmcpeak | bdpayne: awesome, thank you sir | 17:26 |
| tmcpeak | bdpayne: FYI we've decided to address insecure temp files separately | 17:26 |
| bdpayne | ok | 17:26 |
| bdpayne | but still before the release? | 17:27 |
| tmcpeak | the commitment is to do as much as we can | 17:27 |
| tmcpeak | amrith is the author of the patch btw | 17:27 |
| tmcpeak | amrith: you around? | 17:27 |
| amrith | tmcpeak, yes | 17:34 |
| amrith | how's u? | 17:34 |
| tmcpeak | amrith: good, I've got bdpayne taking a look as well | 17:34 |
| tmcpeak | amrith: your changes are good, I'm just trying to decide if there is a good way to clean up that other part I mentioned on the review | 17:34 |
| amrith | thanks travis | 17:34 |
| amrith | much appreciate | 17:34 |
| amrith | I have some ideas | 17:35 |
| tmcpeak | amrith: I'm glad you're taking this on | 17:35 |
| amrith | and some prototypes for that | 17:35 |
| tmcpeak | oh cool | 17:35 |
| amrith | no worries, happy to help | 17:35 |
| bdpayne | so I've made some comments on that CR | 17:35 |
| amrith | you'll be paying for it right ;) | 17:35 |
| amrith | where do I send the bill? | 17:35 |
| tmcpeak | bdpayne: oh cool | 17:35 |
| bdpayne | amrith it looks like your CR, so feel free to ping me if you have questions | 17:35 |
| amrith | bdpayne, just reading your comments | 17:36 |
| amrith | one second | 17:36 |
| amrith | so tmcpeak ... maybe best to forward bdpayne the email thread so he understands the context? | 17:36 |
| tmcpeak | amrith: yeah, agree | 17:37 |
| amrith | ok, will do that | 17:37 |
| tmcpeak | bdpayne: I've also brought up the rootwrap thing, the issue is how much we are comfortable changing before code freeze | 17:37 |
| tmcpeak | bdpayne: I'm not very familiar with how the whole process works | 17:38 |
| bdpayne | sure | 17:38 |
| amrith | bdpayne, this is just one step in (hopefully) the right direction | 17:38 |
| bdpayne | yeah, I think that makes sense | 17:38 |
| tmcpeak | bdpayne: there are things I'd really like to have fixed before release, but I don't know how prioritization works | 17:38 |
| amrith | I think this fix has uncovered some other areas for improvement | 17:38 |
| bdpayne | I'm just providing some comments... largely from an outsider perspective | 17:38 |
| tmcpeak | bdpayne: awesome | 17:38 |
| tmcpeak | bdpayne: I appreciate the second look | 17:38 |
| bdpayne | np | 17:39 |
| tmcpeak | amrith: maybe we could synch up with Nikhil and set priorities on this stuff | 17:39 |
| amrith | tmcpeak, I notice you sent the review to a couple of others | 17:39 |
| amrith | thanks for doing that | 17:39 |
| amrith | the more eyes on it, the better | 17:39 |
| tmcpeak | amrith: sure, those guys are similar to Bryan, not familiar with this issue but very experienced security guys | 17:40 |
| amrith | I think it will produce more ideas and suggestions for improvement. again some that we can do right away, others that may take a little more time. | 17:40 |
| amrith | given the juno freeze. | 17:40 |
| tmcpeak | when is the Juno freeze btw | 17:40 |
| amrith | I think it is two weeks. | 17:40 |
| tmcpeak | hmm | 17:40 |
| amrith | there's a lot of stuff in flight in trove | 17:42 |
| amrith | and that's the reason for the concern at this stage. | 17:43 |
| tmcpeak | I see | 17:43 |
| amrith | but yes, we should sync with Nikhil and the other core team members. | 17:43 |
| tmcpeak | amrith: my only concern is if some of this stuff would generate an advisory | 17:43 |
| amrith | that is a good point and I noticed that there was a decision not to? | 17:44 |
| tmcpeak | I believe the original issue found would have if it had been released | 17:44 |
| tmcpeak | yeah, so if it got released in Juno, and then I found the same issue it would have generated an advisroy | 17:44 |
| tmcpeak | advisory | 17:44 |
| tmcpeak | amrith: what's your involvement in Trove btw, do you know anybody who could answer if any security reviews have been done on it? | 17:45 |
| amrith | I'm one of the contributors to trove. There is a Trove team meeting (IRC, #openstack-meeting-alt) in 24 minutes. I'm sure someone there could answer. Or Nikhil can, he's the PTL. | 17:46 |
| tmcpeak | oh ok cool | 17:47 |
| tmcpeak | I'll sit in on that | 17:47 |
| tmcpeak | I believe I met Nikhil once in Seattle, cool guy | 17:47 |
| amrith | may be better to ping nikhil directly. | 17:47 |
| amrith | SlickNik on IRC | 17:48 |
| tmcpeak | cool | 17:48 |
| tmcpeak | pinging now | 17:48 |
| *** SlickNik has joined #openstack-security | 17:49 | |
| amrith | ok | 17:49 |
| *** ptd has quit IRC | 17:58 | |
| *** chair6_ is now known as chair6 | 17:59 | |
| *** bknudson has joined #openstack-security | 18:21 | |
| bknudson | I've got a question for the team here... maybe someone is familiar with openssl cms. | 18:23 |
| bknudson | we use cms in keystone for the token sig. | 18:24 |
| bknudson | according to the docs for openssl cms, the digest algorithm defaults to sha1 | 18:24 |
| bknudson | https://www.openssl.org/docs/apps/cms.html (see the -md option) | 18:24 |
| bknudson | why I try running the command myself it shows algorithm is sha1 | 18:25 |
| bknudson | digestAlgorithms: algorithm: sha1 (1.3.14.3.2.26) | 18:25 |
| bknudson | so I think that this is inadequate based on NIST 800-131A. | 18:25 |
| *** tmcpeak has quit IRC | 18:32 | |
| *** nkinder has quit IRC | 20:28 | |
| *** nkinder has joined #openstack-security | 20:45 | |
| *** tmcpeak has joined #openstack-security | 20:56 | |
| *** tmcpeak has quit IRC | 21:13 | |
| *** dmccowan has quit IRC | 21:14 | |
| *** tmcpeak has joined #openstack-security | 21:15 | |
| *** paulmo has quit IRC | 21:33 | |
| *** nkinder has quit IRC | 21:39 | |
| *** tmcpeak has quit IRC | 22:19 | |
| *** tmcpeak has joined #openstack-security | 22:21 | |
| *** dmccowan has joined #openstack-security | 23:07 | |
| *** jamielennox|away is now known as jamielennox | 23:10 | |
| *** voodookid has quit IRC | 23:20 | |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!