*** markvoelker has quit IRC | 00:07 | |
*** tmcpeak has quit IRC | 00:51 | |
*** markvoelker has joined #openstack-security | 00:52 | |
*** tmcpeak has joined #openstack-security | 00:56 | |
*** tmcpeak has quit IRC | 00:58 | |
*** markvoelker has quit IRC | 01:00 | |
*** jursey has quit IRC | 01:12 | |
*** mohitsharma has joined #openstack-security | 01:12 | |
*** jursey has joined #openstack-security | 01:19 | |
*** markvoelker has joined #openstack-security | 01:19 | |
*** jamielennox is now known as jamielennox|away | 01:33 | |
*** amrith is now known as _amrith_ | 01:34 | |
*** coasterz has joined #openstack-security | 01:36 | |
*** tmcpeak has joined #openstack-security | 01:39 | |
*** bpokorny has quit IRC | 02:06 | |
*** tmcpeak has quit IRC | 02:11 | |
*** jursey has quit IRC | 02:27 | |
*** salv-orlando has quit IRC | 02:29 | |
*** jursey has joined #openstack-security | 02:54 | |
*** bdpayne has quit IRC | 03:25 | |
*** mitz_ has quit IRC | 03:56 | |
*** mitz has joined #openstack-security | 03:56 | |
*** tmcpeak has joined #openstack-security | 04:02 | |
*** tmcpeak has quit IRC | 04:03 | |
*** markvoelker has quit IRC | 06:08 | |
*** markvoelker has joined #openstack-security | 06:39 | |
*** markvoelker has quit IRC | 06:43 | |
*** markvoelker has joined #openstack-security | 07:39 | |
*** markvoelker has quit IRC | 07:44 | |
*** nkinder has joined #openstack-security | 08:08 | |
*** markvoelker has joined #openstack-security | 08:40 | |
*** markvoelker has quit IRC | 08:45 | |
*** salv-orlando has joined #openstack-security | 09:37 | |
*** markvoelker has joined #openstack-security | 09:41 | |
*** markvoelker has quit IRC | 09:47 | |
*** jursey has quit IRC | 10:26 | |
*** jursey has joined #openstack-security | 10:39 | |
*** markvoelker has joined #openstack-security | 10:43 | |
*** markvoelker has quit IRC | 10:48 | |
*** De has joined #openstack-security | 10:52 | |
*** De has quit IRC | 10:59 | |
*** tkelsey has joined #openstack-security | 11:04 | |
*** markvoelker has joined #openstack-security | 11:44 | |
*** markvoelker has quit IRC | 11:49 | |
*** tkelsey_ has joined #openstack-security | 12:12 | |
*** tkelsey has quit IRC | 12:20 | |
*** coasterz has quit IRC | 12:20 | |
*** mohitsha_ has joined #openstack-security | 12:23 | |
*** mohitsh__ has joined #openstack-security | 12:24 | |
*** mohitsharma has quit IRC | 12:25 | |
*** coasterz has joined #openstack-security | 12:27 | |
*** mohitsha_ has quit IRC | 12:27 | |
*** markvoelker has joined #openstack-security | 12:45 | |
*** markvoelker has quit IRC | 12:49 | |
*** mohitsh__ has quit IRC | 13:06 | |
*** mohitsharma has joined #openstack-security | 13:07 | |
*** mohitsharma has quit IRC | 13:08 | |
*** nkinder has quit IRC | 13:10 | |
*** bknudson has joined #openstack-security | 13:11 | |
*** markvoelker has joined #openstack-security | 13:20 | |
*** elo has joined #openstack-security | 13:28 | |
*** _amrith_ is now known as amrith | 13:54 | |
*** mohitsharma has joined #openstack-security | 14:01 | |
*** mvangund has joined #openstack-security | 14:16 | |
*** mvangund is now known as singlethink | 14:16 | |
*** elo has quit IRC | 14:28 | |
*** nkinder has joined #openstack-security | 14:31 | |
*** nkinder has quit IRC | 15:04 | |
*** nkinder has joined #openstack-security | 15:06 | |
*** tmcpeak has joined #openstack-security | 15:22 | |
*** elo has joined #openstack-security | 15:24 | |
*** jursey has quit IRC | 15:28 | |
*** voodookid has joined #openstack-security | 15:35 | |
*** huerte has joined #openstack-security | 15:36 | |
openstackgerrit | Doug Chivers proposed openstack/security-doc: OSSN for gethostbyname glibc vuln. https://review.openstack.org/152519 | 15:57 |
---|---|---|
*** nkinder has quit IRC | 16:02 | |
*** mohitsha_ has joined #openstack-security | 16:02 | |
*** mohitsharma has quit IRC | 16:05 | |
*** nkinder has joined #openstack-security | 16:06 | |
openstackgerrit | Doug Chivers proposed openstack/security-doc: OSSN for gethostbyname glibc vuln. https://review.openstack.org/152519 | 16:11 |
*** bpokorny has joined #openstack-security | 16:13 | |
*** tmcpeak has quit IRC | 16:27 | |
*** mohitsha_ has quit IRC | 16:32 | |
*** amrith is now known as _amrith_ | 16:48 | |
*** nkinder has quit IRC | 16:57 | |
*** tmcpeak has joined #openstack-security | 17:06 | |
*** nkinder has joined #openstack-security | 17:07 | |
*** elo has quit IRC | 17:17 | |
*** elo has joined #openstack-security | 17:17 | |
*** _amrith_ is now known as amrith | 17:23 | |
*** nkinder has quit IRC | 17:30 | |
openstackgerrit | Doug Chivers proposed openstack/security-doc: OSSN for gethostbyname glibc vuln. https://review.openstack.org/152519 | 17:40 |
*** sicarie has joined #openstack-security | 18:12 | |
*** bdpayne has joined #openstack-security | 18:34 | |
*** sicarie has quit IRC | 18:37 | |
*** elo has quit IRC | 18:39 | |
*** sicarie has joined #openstack-security | 18:45 | |
*** vozcelik has joined #openstack-security | 18:52 | |
*** vozcelik has quit IRC | 18:52 | |
openstackgerrit | Merged openstack/security-doc: Clarified timeline in Vulnerability Management Triage section https://review.openstack.org/152407 | 18:57 |
openstackgerrit | Merged openstack/security-doc: Change link reference from icehouse to juno https://review.openstack.org/152663 | 18:58 |
openstackgerrit | Merged openstack/security-doc: OSSN for gethostbyname glibc vuln. https://review.openstack.org/152519 | 19:00 |
*** amrith is now known as _amrith_ | 19:52 | |
*** tkelsey_ has quit IRC | 20:01 | |
*** _amrith_ is now known as amrith | 20:18 | |
*** sicarie has quit IRC | 20:20 | |
*** tmcpeak has quit IRC | 20:30 | |
*** tmcpeak has joined #openstack-security | 20:33 | |
openstackgerrit | Hareesh Puthalath proposed openstack/security-doc: Add intro and reference to the Alice and Bob case study https://review.openstack.org/152581 | 20:47 |
openstackgerrit | Merged openstack/security-doc: Rephrase intro to Hypervisor Selection section https://review.openstack.org/151479 | 20:52 |
openstackgerrit | Merged openstack/security-doc: Fix sentence fragment https://review.openstack.org/151625 | 20:55 |
*** elmiko has joined #openstack-security | 20:59 | |
elmiko | yo | 20:59 |
elmiko | dang these spammers... | 20:59 |
tmcpeak | elmiko: who now? | 21:00 |
elmiko | huerte | 21:01 |
tmcpeak | bdpayne: ^ | 21:01 |
tmcpeak | oh yeah, I got him | 21:01 |
elmiko | like, as soon as i joined i got a private msg | 21:01 |
tmcpeak | yeah, I also got one for typing in the channel | 21:01 |
elmiko | heh lol | 21:01 |
elmiko | bdpayne: we doing a meeting today? | 21:02 |
tmcpeak | same MO as jursey, I wonder if it's the same IP | 21:02 |
bdpayne | heyyo | 21:02 |
tmcpeak | bpdyane: time to dust off your beating stick | 21:02 |
elmiko | i checked out that link they keep sending, but didn't see anything too weird | 21:02 |
* bdpayne gets on that | 21:02 | |
tmcpeak | elmiko: you clicked it? gutsy | 21:03 |
*** ChanServ sets mode: +o bdpayne | 21:03 | |
elmiko | tmcpeak: nah, wget | 21:03 |
bdpayne | well, elmiko is owned | 21:03 |
tmcpeak | ;) | 21:03 |
elmiko | i did load it on a vm, it was some weirdo fish tank video | 21:03 |
*** huerte was kicked by bdpayne (for spamming via PM) | 21:04 | |
*** huerte has joined #openstack-security | 21:04 | |
tmcpeak | aren't they always? | 21:04 |
bdpayne | weee, this is fun | 21:04 |
elmiko | lol | 21:04 |
tmcpeak | oh, it's a different IP too | 21:04 |
tmcpeak | still got "jursey" in his name | 21:04 |
bdpayne | classic | 21:05 |
*** bdpayne sets mode: +b *!*@213.143.60.224 | 21:05 | |
*** huerte was kicked by bdpayne (for spamming via PM) | 21:05 | |
tmcpeak | buhbye | 21:06 |
* elmiko waves | 21:06 | |
*** sicarie has joined #openstack-security | 21:06 | |
bdpayne | alrighty then | 21:06 |
bdpayne | hey there elmiko and sicarie | 21:06 |
elmiko | hey | 21:06 |
sicarie | hello | 21:06 |
bdpayne | let me pull up our bugs webpage, one sec | 21:06 |
bdpayne | here we go https://bugs.launchpad.net/openstack-manuals/+bugs?field.tag=sec-guide | 21:07 |
bdpayne | one more sec while I get organized | 21:07 |
elmiko | no prob | 21:07 |
bdpayne | ok, I think this is the next one https://bugs.launchpad.net/openstack-manuals/+bug/1344291 | 21:09 |
bdpayne | on a side note, lots of contribution activity over the past week, which is great | 21:09 |
elmiko | nice | 21:09 |
elmiko | chap43? this must be old | 21:10 |
sicarie | Yep, it's the old location, but the content itself just seemed more 'user-guide' material to me | 21:10 |
sicarie | I should probably let this go for the moment, I haven't done anything on it in 2 weeks | 21:10 |
* elmiko looking at the content | 21:10 | |
elmiko | that does seem a little out of scope for the security stuff | 21:11 |
sicarie | And it's only a small subset of filters too | 21:11 |
bdpayne | yeah, agreed | 21:11 |
bdpayne | I think this ticket is good where it sits | 21:12 |
bdpayne | any discussion? | 21:12 |
elmiko | well, i could see this being incomplete given the recommendations | 21:13 |
elmiko | we're basically asking for more from the nova folks | 21:13 |
elmiko | i dunno, i guess the bug itself isn't incomplete.. tough call | 21:13 |
bdpayne | I think I'd look for something between (1) and (2) here | 21:14 |
bdpayne | list the filters that have a security impact | 21:14 |
bdpayne | and provide some discussion around best practices / recommendations for those | 21:14 |
elmiko | that makes sense | 21:15 |
sicarie | The reason I didn't want to do #1 is if the list of filters grows | 21:15 |
sicarie | but it does make sense | 21:15 |
sicarie | and I suppose that's work you really only have to do once | 21:15 |
bdpayne | ok, I'll comment on this ticket | 21:15 |
bdpayne | https://bugs.launchpad.net/openstack-manuals/+bug/1346986 | 21:16 |
sicarie | I really like this one, but I wonder if it might encourage more effort if each # was a ticket? | 21:17 |
sicarie | s/ticket/bug | 21:17 |
bdpayne | if anything, perhaps this should be broken out into separate bugs | 21:17 |
elmiko | yea, seems like a big bug | 21:17 |
bdpayne | heh, yeah | 21:17 |
bdpayne | could one of you take an action item to break this up after this meeting? | 21:18 |
sicarie | Sure! | 21:18 |
bdpayne | thanks sicarie | 21:18 |
sicarie | np | 21:18 |
bdpayne | https://bugs.launchpad.net/openstack-manuals/+bug/1349540 | 21:19 |
elmiko | +1 for this one | 21:19 |
sicarie | I think you created this one last week? | 21:19 |
bdpayne | hrm, I feel like there was another bug related to this | 21:19 |
bdpayne | b/c this was filed last summer | 21:20 |
sicarie | I think it may have been this https://bugs.launchpad.net/openstack-manuals/+bug/1413001 | 21:20 |
bdpayne | ahh | 21:21 |
bdpayne | so let's close that one as a dup of the first? | 21:21 |
sicarie | +1 | 21:21 |
elmiko | +1 | 21:21 |
bdpayne | I don't see a dup option, made a comment and chose won't fix | 21:22 |
bdpayne | https://bugs.launchpad.net/openstack-manuals/+bug/1349555 | 21:22 |
bdpayne | I think this one looks good as it | 21:23 |
bdpayne | *as is | 21:23 |
elmiko | mark as duplicate is on the right hand side near the top | 21:23 |
sicarie | +1, I have seen a few chapters without | 21:24 |
bdpayne | ah cool, dup properly marked now | 21:25 |
bdpayne | ok, moving forward | 21:25 |
bdpayne | https://bugs.launchpad.net/openstack-manuals/+bug/1415218 | 21:25 |
bdpayne | actually, we did this one last week | 21:25 |
bdpayne | https://bugs.launchpad.net/openstack-manuals/+bug/1342369 | 21:26 |
elmiko | yea, i'm making good progress. should have a first review up soon(TM). | 21:26 |
bdpayne | I'm actually not sure about this one | 21:27 |
elmiko | yea, the intro para isn't that bad imo | 21:27 |
bdpayne | the ask feels pretty similar to what is there today | 21:27 |
bdpayne | thoughts? | 21:27 |
elmiko | agreed | 21:27 |
bdpayne | ok, so I'll comment and close | 21:28 |
bdpayne | https://bugs.launchpad.net/openstack-manuals/+bug/1360095 | 21:29 |
bdpayne | ahh, at first I was reading this thinking that it looked like a code change | 21:30 |
bdpayne | and it is | 21:30 |
bdpayne | docimpact | 21:30 |
bdpayne | so this makes sense | 21:30 |
sicarie | Yeah, it looks like a good thing ot have and an even better feature to have documented | 21:30 |
bdpayne | perhaps a higher priority would be useful? | 21:30 |
bdpayne | medium? | 21:30 |
elmiko | not sure i understand this one, are they talking about audit_ids in the links of the guide? | 21:31 |
bdpayne | this is a new keystone feature | 21:31 |
elmiko | ahh ok | 21:31 |
sicarie | elmiko: my interpretation was the documentation of a new feature | 21:31 |
bdpayne | that they want documented | 21:31 |
elmiko | cool, yea i'd go medium or even high | 21:32 |
sicarie | +1 to medium for m | 21:32 |
sicarie | e | 21:32 |
elmiko | i'm good with that | 21:32 |
bdpayne | ok, bumped to medium | 21:32 |
bdpayne | ok that's all for today... we will pick up with https://bugs.launchpad.net/openstack-manuals/+bug/1261735 next week | 21:33 |
elmiko | sounds good, thanks =) | 21:33 |
bdpayne | thanks guys! | 21:33 |
sicarie | Sounds good - thanks! | 21:34 |
*** sicarie has quit IRC | 21:43 | |
elmiko | would it be more appropriate to refer to the policy.json files as RBAC or ACL? | 22:32 |
elmiko | (i'm thinking RBAC makes more sense) | 22:33 |
*** bpokorny has quit IRC | 22:33 | |
*** tmcpeak has quit IRC | 22:43 | |
*** tmcpeak has joined #openstack-security | 22:44 | |
*** amrith is now known as _amrith_ | 22:57 | |
bdpayne | elmiko yes, I'd agree that RBAC makes more sense | 23:19 |
elmiko | bdpayne: thanks | 23:21 |
*** singlethink has quit IRC | 23:50 | |
*** markvoelker has quit IRC | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!