| openstackgerrit | Deepti Navale proposed a change to openstack/security-doc: Include glossterm tags for Federated Identity topic https://review.openstack.org/128792 | 00:19 |
|---|---|---|
| *** bdpayne has quit IRC | 00:50 | |
| *** tmcpeak has joined #openstack-security | 01:12 | |
| *** bpokorny has quit IRC | 01:28 | |
| *** salv-orlando has quit IRC | 02:05 | |
| *** tmcpeak has quit IRC | 02:13 | |
| *** vdreamarkitex has quit IRC | 03:37 | |
| *** vdreamarkitex has joined #openstack-security | 06:10 | |
| *** vdreamarkitex has quit IRC | 06:32 | |
| *** salv-orlando has joined #openstack-security | 08:23 | |
| openstackgerrit | Tim Kelsey proposed a change to openstack/security-doc: Adding OSSN-0038: Suds local cache poisoning. https://review.openstack.org/128636 | 09:11 |
| openstackgerrit | Tim Kelsey proposed a change to openstack/security-doc: Adding OSSN-0038: Suds local cache poisoning. https://review.openstack.org/128636 | 09:17 |
| *** openstackgerrit has quit IRC | 10:19 | |
| *** openstackgerrit has joined #openstack-security | 10:19 | |
| *** salv-orlando has quit IRC | 10:48 | |
| *** vdreamarkitex has joined #openstack-security | 11:07 | |
| *** amrith is now known as _amrith_ | 11:11 | |
| *** dave-mccowan has joined #openstack-security | 12:25 | |
| *** bknudson has joined #openstack-security | 12:47 | |
| *** tmcpeak has joined #openstack-security | 12:49 | |
| *** tmcpeak has quit IRC | 13:19 | |
| *** dave-mccowan has quit IRC | 13:53 | |
| *** elo1 has quit IRC | 13:59 | |
| *** dave-mccowan has joined #openstack-security | 14:06 | |
| *** tmcpeak has joined #openstack-security | 14:28 | |
| *** voodookid has joined #openstack-security | 14:30 | |
| *** openstackgerrit has quit IRC | 14:48 | |
| *** openstackgerrit has joined #openstack-security | 14:49 | |
| *** _amrith_ is now known as amrith | 14:53 | |
| *** elo1 has joined #openstack-security | 15:53 | |
| *** vdreamarkitex has quit IRC | 16:06 | |
| *** sicarie has joined #openstack-security | 16:11 | |
| *** bdpayne has joined #openstack-security | 16:23 | |
| *** rlpple has joined #openstack-security | 16:57 | |
| *** shohel02 has joined #openstack-security | 17:00 | |
| *** dipak has joined #openstack-security | 17:40 | |
| openstackgerrit | A change was merged to openstack/security-doc: Update SSL/TTL section in the security guide https://review.openstack.org/127419 | 17:40 |
| *** rlpple has quit IRC | 17:57 | |
| nkinder | bdpayne: so I just saw that firefox is going to disable SSLv3 in the 31esr release - https://bugzilla.mozilla.org/show_bug.cgi?id=1076983#c73 | 17:57 |
| bdpayne | yeah, Chrome is disabling it too | 17:57 |
| bdpayne | hopefully this is the final nail in the coffin on v3 | 17:58 |
| nkinder | update is still about a month out though AFAIK | 17:58 |
| nkinder | yeah, would be nice for it to die | 17:58 |
| bdpayne | now if only people would implement TLS 1.2 | 17:58 |
| nkinder | the main mod_nss developer (rcrit) is disabling v3 and adding TLS 1.2 | 17:59 |
| nkinder | mod_ssl has 1.2 | 17:59 |
| nkinder | so we're good on the httpd side of things at least | 17:59 |
| *** tmcpeak1 has joined #openstack-security | 18:01 | |
| *** tmcpeak has quit IRC | 18:01 | |
| shohel02 | bdpayne, did you already sent me email regarding the election | 18:05 |
| shohel02 | i did not get one yet | 18:05 |
| bdpayne | yeah | 18:05 |
| bdpayne | hrm | 18:05 |
| bdpayne | can you PM me your preferred email address? | 18:05 |
| shohel02 | okey... i check other mail in yahoo.. got it now | 18:06 |
| shohel02 | thanks | 18:06 |
| bdpayne | ah great | 18:06 |
| bdpayne | shohel02 btw, I have a script that will figure out how many meetings someone has attended... so perhaps I can fill in that col on the spreadsheet once you have added any new names to check | 18:08 |
| bdpayne | shohel02 actually, let me back up | 18:08 |
| bdpayne | step 1 is probably to look at the launchpad group and figure out who has joined since last election | 18:09 |
| bdpayne | step 2 is to add those names to the spreadsheet at the bottom | 18:09 |
| bdpayne | step 3 is to then fill out the cols for each new person to see if they are eligible | 18:09 |
| bdpayne | and I have a tool that can help with one of those cols, so let me know when it is time and I can run that and put the data into the spreadsheet | 18:10 |
| shohel02 | okey | 18:10 |
| shohel02 | i take step 1, step 2 | 18:10 |
| shohel02 | then step three is the filling against criteria | 18:10 |
| shohel02 | here are multiple criterias.. | 18:11 |
| shohel02 | you are going to take all that part ? | 18:11 |
| bdpayne | perhaps we can have multiple people help with that | 18:12 |
| bdpayne | we can each take a col | 18:12 |
| *** dipak has quit IRC | 18:12 | |
| bdpayne | but I can certainly do the col for meeting attendance | 18:12 |
| shohel02 | that sounds good.. | 18:12 |
| shohel02 | okey let me first fill the new names... and see how many are there | 18:13 |
| bdpayne | great, thanks for the help! | 18:13 |
| shohel02 | no problem | 18:13 |
| *** salv-orlando has joined #openstack-security | 18:15 | |
| *** tmcpeak1 has quit IRC | 18:26 | |
| *** tmcpeak has joined #openstack-security | 18:27 | |
| *** tmcpeak has quit IRC | 18:52 | |
| openstackgerrit | Nathaniel Dillon proposed a change to openstack/security-doc: Re-submitting OSSN 25 concerning Swift/Glance public images https://review.openstack.org/117928 | 18:53 |
| *** xen_roger has joined #openstack-security | 19:35 | |
| *** xen_roger has left #openstack-security | 19:36 | |
| *** dipak has joined #openstack-security | 20:03 | |
| *** bknudson has quit IRC | 20:14 | |
| *** dipak has quit IRC | 20:19 | |
| *** gabriela has joined #openstack-security | 20:26 | |
| *** gabriela has left #openstack-security | 20:26 | |
| *** amrith is now known as _amrith_ | 20:31 | |
| *** tmcpeak has joined #openstack-security | 20:35 | |
| *** dave-mccowan has quit IRC | 20:49 | |
| *** shohel02 has quit IRC | 20:50 | |
| *** bdpayne has quit IRC | 20:51 | |
| *** bdpayne has joined #openstack-security | 20:51 | |
| tmcpeak | hey | 20:53 |
| tmcpeak | so that link that Mr. Payne put in the meeting | 20:53 |
| tmcpeak | mentions that downgrades are a product of browser behavior | 20:54 |
| tmcpeak | do we have any reason to think that Python libraries are vulnerable to the same behavior? | 20:54 |
| *** bdpayne has quit IRC | 20:56 | |
| *** bdpayne has joined #openstack-security | 20:56 | |
| *** bdpayne has quit IRC | 21:01 | |
| *** dave-mccowan has joined #openstack-security | 21:03 | |
| tmcpeak | nkinder: ^ thoughts? | 21:03 |
| nkinder | tmcpeak: they may not be (at least for the downgrade portion of this) | 21:05 |
| nkinder | tmcpeak: I would think that the downgrade part is browser specific, but I haven't looked into it | 21:05 |
| tmcpeak | nkinder: if a downgrade isn't possible, then it really shouldn't be much of an issue for OpenStack, surely client and server will agree on something better than SSL3, yeah? | 21:10 |
| nkinder | tmcpeak: still would want to disable v3 | 21:11 |
| nkinder | something better might be agreed upon, but the recommendation should be to disable v3 | 21:11 |
| tmcpeak | nkinder: sure, might as well disable it, but… I don't see any urgency without the downgrade dance possibility | 21:12 |
| nkinder | tmcpeak: though there's always horizon to worry about | 21:12 |
| tmcpeak | nkinder: yeah, that's true | 21:16 |
| *** bdpayne has joined #openstack-security | 21:41 | |
| *** dave-mccowan_ has joined #openstack-security | 21:48 | |
| *** dave-mccowan has quit IRC | 21:49 | |
| *** dave-mccowan_ is now known as dave-mccowan | 21:49 | |
| bdpayne | nkinder I'd like to start working on the ossn for poodle | 22:24 |
| bdpayne | nkinder I don't see a bug filed for that yet... should I file a bug? | 22:24 |
| *** tmcpeak has quit IRC | 22:30 | |
| *** _amrith_ is now known as amrith | 22:40 | |
| *** voodookid has quit IRC | 23:03 | |
| *** bdpayne has quit IRC | 23:16 | |
| nkinder | darn, missed bdpayne... | 23:27 |
| *** sicarie has quit IRC | 23:41 | |
| *** tmcpeak has joined #openstack-security | 23:59 | |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!