Thursday, 2014-11-20

*** bpokorny has joined #openstack-security00:19
*** bpokorny_ has quit IRC00:22
*** jimhoagland has quit IRC00:25
*** sicarie has left #openstack-security00:31
openstackgerritDarren Chan proposed openstack/security-doc: Updated sVirt diagram in the Security Guide  https://review.openstack.org/13411400:34
*** ved_lad has joined #openstack-security00:36
*** shohel02 has joined #openstack-security00:50
*** jimhoagland has joined #openstack-security00:51
*** shohel02 has quit IRC00:55
*** tmcpeak has quit IRC00:59
*** jimhoagland has quit IRC01:09
*** shohel02 has joined #openstack-security01:50
*** bpokorny has quit IRC01:54
*** shohel02 has quit IRC01:55
*** ved_lad has quit IRC01:58
*** tmcpeak has joined #openstack-security02:16
*** tmcpeak has quit IRC02:19
*** shohel02 has joined #openstack-security02:50
*** shohel02 has quit IRC02:54
*** dave-mccowan has quit IRC03:18
*** shohel02 has joined #openstack-security03:50
*** shohel02 has quit IRC03:54
*** shohel02 has joined #openstack-security04:50
openstackgerritTom Fifield proposed openstack/security-doc: Fix recommendations post-POODLE  https://review.openstack.org/13584404:53
*** shohel02 has quit IRC04:55
openstackgerritTom Fifield proposed openstack/security-doc: Fix recommendations post-POODLE  https://review.openstack.org/13584405:19
LinStatSDRThank you openstackgerrit05:33
*** g5 has joined #openstack-security05:35
g5hi05:36
*** g5 has quit IRC05:37
*** shohel02 has joined #openstack-security05:50
*** shohel02 has quit IRC05:55
*** LinStatSDR has quit IRC06:15
*** jimhoagland has joined #openstack-security06:42
openstackgerritOpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals  https://review.openstack.org/13554606:44
*** shohel02 has joined #openstack-security06:50
*** shohel02 has quit IRC06:55
*** shohel02 has joined #openstack-security07:44
*** salv-orlando_ has joined #openstack-security10:18
*** salv-orlando has quit IRC10:19
*** salv-orlando_ is now known as salv-orlando10:19
openstackgerritMerged openstack/security-doc: Updated from openstack-manuals  https://review.openstack.org/13554611:49
openstackgerritMerged openstack/security-doc: Updated sVirt diagram in the Security Guide  https://review.openstack.org/13411411:55
*** dave-mccowan has joined #openstack-security12:44
*** dave-mccowan_ has joined #openstack-security13:02
*** dave-mccowan has quit IRC13:04
*** dave-mccowan_ is now known as dave-mccowan13:04
*** salv-orlando has quit IRC13:47
*** amrith is now known as _amrith_14:00
*** elo has quit IRC14:01
*** paulmo has joined #openstack-security14:14
*** jimhoagland has quit IRC14:17
*** paulmo1 has joined #openstack-security14:20
*** nkinder has quit IRC14:21
*** paulmo has quit IRC14:22
*** paulmo has joined #openstack-security14:25
*** paulmo1 has quit IRC14:26
*** _amrith_ is now known as amrith14:51
*** salv-orlando has joined #openstack-security14:57
*** nkinder has joined #openstack-security15:10
*** voodookid has joined #openstack-security15:19
*** sicarie has joined #openstack-security16:04
*** amrith is now known as _amrith_16:07
*** _amrith_ is now known as amrith16:21
*** bpokorny has joined #openstack-security16:24
*** tmcpeak has joined #openstack-security16:34
openstackgerritNathaniel Dillon proposed openstack/security-doc: Adding paragraph on updates to security instances section  https://review.openstack.org/13505116:43
*** shohel02 has quit IRC16:54
*** amrith is now known as _amrith_16:54
*** bdpayne has joined #openstack-security17:00
*** LinStatSDR has joined #openstack-security17:12
openstackgerritNathaniel Dillon proposed openstack/security-doc: Adding paragraph on updates to security instances section  https://review.openstack.org/13505117:16
openstackgerritRamaraja proposed openstack/security-doc: Bugid: 1368406 : Link has been provided for 'Attack type'. closes-bug:#1368406  https://review.openstack.org/12482417:22
*** Viswanath has joined #openstack-security17:24
*** shohel02 has joined #openstack-security17:25
*** LinStatSDR has quit IRC17:26
*** LinStatSDR has joined #openstack-security17:26
*** Viswanath has quit IRC17:27
*** shohel02 has quit IRC17:29
*** hyakuhei has joined #openstack-security17:59
*** dg__ has joined #openstack-security18:00
*** tkelsey has joined #openstack-security18:01
tkelseyo/18:01
*** mvangund has joined #openstack-security18:01
hyakuheio/18:01
tmcpeak\o18:01
hyakuheiSeems people still want to talk SSL18:01
nkinderpesky time change... :)18:01
hyakuheilol, oh hai nkinder18:01
hyakuheinice to see you18:02
tkelseyheh yeah, outlook exploded and i missed last weeks OSSG :(18:02
nkinderWhat'd I miss in the meeting?18:02
tmcpeaknkinder: synching up about mid-cycle18:03
tkelseyok folks, I have to dash, good meeting though.18:03
nkindertkelsey: later18:03
tmcpeaklooks like we're going to try for SF in late Feb18:03
tmcpeakwith back to back OSSG/Barbican18:03
nkinderOk, still SF.  Cool.18:03
nkinderSo Barbican is in SF still?  (Keystone switched to San Antonio)18:04
tmcpeakthey're going to try to synch with us18:04
tmcpeakwe'll see how they vote, but most of OSSG voted for SF18:04
nkinderSounds good.  That would be nice18:04
nkinderI like late Feb too since I'm traveling already in the beginning of Feb18:04
tmcpeakyeah late Feb is good18:05
nkinderSo what's up around SSL that hyakuhei mentioned above?18:06
tmcpeaksicarie is going on a witch hunt18:06
*** tkelsey has quit IRC18:07
tmcpeakhe volunteered to make a list of projects which support better SSL and aren't using it (I think)18:07
nkindertmcpeak: you mean the versions?18:07
tmcpeaknkinder: yep18:08
nkinderwe're *really* close to being able to run tempest with TLS enabled for everything with a full pass rate18:09
*** anyibethRRR has joined #openstack-security18:09
nkinderthere are some issues around boto IIRC, but it's a very small number of tests that fail now (15/2000+ I think)18:09
tmcpeaknkinder: that would be cool18:10
nkinderThe gate tests are only a subset of that, so I think the ability to test with TLS enabled in the gate is just about there18:10
anyibethRRRHola18:10
tmcpeakwe have some Bandit test which will search for support for bad versions of SSL18:11
tmcpeakwe were going to run that too18:11
*** ChanServ sets mode: +o bdpayne18:12
*** ChanServ sets mode: +o bdpayne18:14
anyibethRRRHola,no hablan espaƱo18:14
*** anyibethRRR has left #openstack-security18:15
bdpaynethat was fun, you guys can buy me a beer later ;-)18:16
*** shohel02 has joined #openstack-security18:20
sicarienkinder I was poking around Neutron a few days ago and didn't see anything in lp around SSL and was wondering how that would be approached by the community as a whole18:24
*** shohel02 has quit IRC18:25
nkindersicarie: you mean configuring Neutron to use TLS for it's API, or something else?18:26
sicarieI was just noticing there was still widespread use of SSL18:26
sicarieI was wondering what the approach was, if we were going to keep it as default or move to TLS as default, but allow downgrading to SSL, etc...18:27
sicarieAnd how that would be implemented across projects18:27
sicarienkinder: ps I sent a redhat ceph programmer your way18:28
sicarieHe did an interesting presentation  around pentesting neutron (hence my digging into Neutron afterwards) - https://www.usenix.org/conference/lisa14/conference-program/presentation/lambright18:30
*** bpokorny_ has joined #openstack-security18:31
nkindersicarie: I honestly feel that all projects should just run via mod_wsgi and then we just use mod_ssl for the server side of TLS...18:32
nkindersicarie: but that's just me...18:32
sicarieYeah, and I know tkelsey did a bandit test for bad versions of ssl, but I was curious if anything was hardcoded, etc...18:33
*** bpokorny has quit IRC18:33
dg__probably18:34
*** _amrith_ is now known as amrith18:39
*** bdpayne has quit IRC18:44
*** Viswanath has joined #openstack-security19:00
*** ved_lad has joined #openstack-security19:01
*** bpokorny has joined #openstack-security19:01
*** bdpayne has joined #openstack-security19:02
*** dg__ has quit IRC19:02
*** bpokorny_ has quit IRC19:04
*** Viswanath has quit IRC19:07
*** salv-orlando has quit IRC19:12
*** shohel02 has joined #openstack-security19:20
*** dave-mccowan_ has joined #openstack-security19:23
*** shohel02 has quit IRC19:25
*** dave-mccowan has quit IRC19:26
*** dave-mccowan_ is now known as dave-mccowan19:26
*** bpokorny_ has joined #openstack-security19:27
*** bpokorny has quit IRC19:30
*** ved_lad has quit IRC19:47
openstackgerritNathaniel Dillon proposed openstack/security-doc: Adding paragraph on updates to security instances section  https://review.openstack.org/13505119:49
*** shohel02 has joined #openstack-security19:54
*** shohel02 has quit IRC19:59
*** nkinder has quit IRC20:02
*** bpokorny has joined #openstack-security20:05
*** bpokorny_ has quit IRC20:08
*** shohel02 has joined #openstack-security20:21
*** dave-mccowan_ has joined #openstack-security20:39
*** dave-mccowan has quit IRC20:41
*** dave-mccowan_ is now known as dave-mccowan20:41
*** MasterPiece has joined #openstack-security20:43
*** salv-orlando has joined #openstack-security20:44
*** MasterPiece has quit IRC20:49
*** MasterPiece has joined #openstack-security20:50
*** edmondsw has joined #openstack-security21:06
*** bpokorny_ has joined #openstack-security21:14
*** bpokorny has quit IRC21:16
*** nkinder has joined #openstack-security21:46
*** bpokorny has joined #openstack-security21:47
*** bpokorny_ has quit IRC21:50
*** amrith is now known as _amrith_21:50
*** paulmo has quit IRC21:51
*** edmondsw has quit IRC21:54
*** shohel02 has quit IRC22:29
*** MasterPiece has quit IRC22:37
*** mvangund has quit IRC22:45
*** shohel02 has joined #openstack-security23:02
*** shohel02 has quit IRC23:07
*** Harry51S has joined #openstack-security23:34
*** bpokorny_ has joined #openstack-security23:35
*** bpokorny has quit IRC23:39
*** bpokorny has joined #openstack-security23:47
*** bpokorny_ has quit IRC23:50
*** shohel02 has joined #openstack-security23:50
*** shohel02 has quit IRC23:54
*** voodookid has quit IRC23:58

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!