| *** tkelsey has joined #openstack-security | 00:28 | |
| *** tkelsey has quit IRC | 00:32 | |
| *** markvoelker has quit IRC | 00:37 | |
| *** bknudson has joined #openstack-security | 00:51 | |
| *** edmondsw has quit IRC | 01:01 | |
| *** markvoelker has joined #openstack-security | 01:17 | |
| *** markvoelker has quit IRC | 01:22 | |
| *** ukbelch has joined #openstack-security | 01:28 | |
| *** ukbelch has quit IRC | 01:32 | |
| *** bpokorny_ has quit IRC | 01:33 | |
| *** browne has quit IRC | 01:48 | |
| *** markvoelker has joined #openstack-security | 02:18 | |
| *** browne has joined #openstack-security | 02:21 | |
| *** markvoelker has quit IRC | 02:22 | |
| *** jamielennox is now known as jamielennox|lunc | 02:32 | |
| *** jamielennox|lunc is now known as jamielennox|food | 02:32 | |
| *** tmcpeak has quit IRC | 02:36 | |
| *** jamielennox|food is now known as jamielennox | 03:01 | |
| *** subscope_ has joined #openstack-security | 03:05 | |
| *** ukbelch has joined #openstack-security | 03:17 | |
| *** markvoelker has joined #openstack-security | 03:19 | |
| *** ukbelch has quit IRC | 03:21 | |
| *** markvoelker has quit IRC | 03:23 | |
| *** markvoelker has joined #openstack-security | 04:19 | |
| *** markvoelker has quit IRC | 04:24 | |
| *** tkelsey has joined #openstack-security | 04:36 | |
| *** tkelsey has quit IRC | 04:41 | |
| *** dave-mcc_ has joined #openstack-security | 04:57 | |
| *** dave-mccowan has quit IRC | 04:57 | |
| *** ukbelch has joined #openstack-security | 05:06 | |
| *** ukbelch has quit IRC | 05:10 | |
| *** markvoelker has joined #openstack-security | 05:20 | |
| *** markvoelker has quit IRC | 05:25 | |
| *** dave-mcc_ has quit IRC | 05:30 | |
| *** markvoelker has joined #openstack-security | 06:21 | |
| *** markvoelker has quit IRC | 06:26 | |
| *** jamielennox is now known as jamielennox|away | 06:35 | |
| *** subscope_ has quit IRC | 06:42 | |
| *** ukbelch has joined #openstack-security | 06:52 | |
| *** ukbelch has quit IRC | 06:56 | |
| *** browne has quit IRC | 07:03 | |
| *** markvoelker has joined #openstack-security | 07:22 | |
| *** markvoelker has quit IRC | 07:27 | |
| *** openstackgerrit has quit IRC | 08:22 | |
| *** openstackgerrit has joined #openstack-security | 08:22 | |
| *** markvoelker has joined #openstack-security | 08:22 | |
| *** markvoelker has quit IRC | 08:27 | |
| *** ukbelch has joined #openstack-security | 08:41 | |
| *** ukbelch has quit IRC | 08:46 | |
| *** ukbelch has joined #openstack-security | 09:02 | |
| *** jamielennox|away is now known as jamielennox | 09:14 | |
| *** tkelsey has joined #openstack-security | 09:19 | |
| *** markvoelker has joined #openstack-security | 09:23 | |
| *** tkelsey has quit IRC | 09:24 | |
| *** ukbelch has quit IRC | 09:24 | |
| *** tkelsey has joined #openstack-security | 09:24 | |
| *** markvoelker has quit IRC | 09:28 | |
| *** markvoelker has joined #openstack-security | 10:24 | |
| *** markvoelker has quit IRC | 10:29 | |
| *** tkelsey has quit IRC | 10:56 | |
| *** tkelsey has joined #openstack-security | 10:56 | |
| *** ukbelch has joined #openstack-security | 10:58 | |
| *** tmcpeak has joined #openstack-security | 11:01 | |
| *** ukbelch has quit IRC | 11:08 | |
| *** ukbelch has joined #openstack-security | 11:44 | |
| *** ukbelch has quit IRC | 11:51 | |
| *** ukbelch has joined #openstack-security | 11:56 | |
| *** markvoelker has joined #openstack-security | 12:03 | |
| *** ukbelch has quit IRC | 12:16 | |
| *** ukbelch has joined #openstack-security | 12:26 | |
| *** bknudson has quit IRC | 12:29 | |
| *** edmondsw has joined #openstack-security | 12:39 | |
| *** singlethink has joined #openstack-security | 12:52 | |
| *** bknudson has joined #openstack-security | 12:54 | |
| *** jamielennox is now known as jamielennox|away | 13:36 | |
| *** ljfisher has joined #openstack-security | 13:38 | |
| *** tkelsey has quit IRC | 13:51 | |
| *** raginbajin has joined #openstack-security | 13:55 | |
| *** ukbelch has quit IRC | 13:56 | |
| *** sicarie has joined #openstack-security | 14:09 | |
| openstackgerrit | Nathaniel Dillon proposed openstack/security-doc: Adding new introudctions for chapters missing one https://review.openstack.org/164883 | 14:23 |
|---|---|---|
| *** singlethink has quit IRC | 14:36 | |
| *** dave-mccowan has joined #openstack-security | 14:41 | |
| *** singlethink has joined #openstack-security | 14:41 | |
| *** voodookid has joined #openstack-security | 14:43 | |
| *** voodookid has quit IRC | 14:47 | |
| *** browne has joined #openstack-security | 14:50 | |
| *** elo has joined #openstack-security | 14:57 | |
| *** voodookid has joined #openstack-security | 15:02 | |
| *** dwyde has joined #openstack-security | 15:02 | |
| *** bpokorny has joined #openstack-security | 15:18 | |
| *** openstackgerrit has quit IRC | 15:21 | |
| *** openstackgerrit has joined #openstack-security | 15:22 | |
| *** ukbelch has joined #openstack-security | 15:22 | |
| *** singlethink has quit IRC | 15:30 | |
| sicarie | Does anyone here know of decent SELinux/AppArmor profiles for OpenStack? | 15:43 |
| sicarie | I found https://github.com/openstack/tripleo-image-elements/tree/master/elements/selinux | 15:43 |
| sicarie | But was curious if anyone knew if more was out there | 15:43 |
| nkinder | sicarie: there is quite a bit of openstack stuff in the base selinux-policy on RHEL/CentOS/Fedora | 15:44 |
| sicarie | awesome, thanks nkinder | 15:45 |
| nkinder | Also, there is an openstack-selinux package that has additional policy that layers on-top | 15:45 |
| sicarie | Interesting, I was not aware of that | 15:45 |
| nkinder | I don't really see people writing additional policy on a per-deployment basis (maybe labelling some custom paths or things like that) | 15:45 |
| sicarie | Yeah, I'm trying to put together some stuff for the secgude on the compute section | 15:46 |
| sicarie | The Philly notes were really interesting | 15:46 |
| *** browne has quit IRC | 15:46 | |
| nkinder | the ops meeting? | 15:46 |
| sicarie | yeah | 15:46 |
| *** dwyde has quit IRC | 15:47 | |
| sicarie | I don't remember if it was in there, or in a bug linked from there, but they were talking about pushing the responsibility for the selinux/apparmor profiles to the individual operators | 15:47 |
| nkinder | yeah, some interesting stuff | 15:47 |
| *** elo has quit IRC | 15:47 | |
| nkinder | wow, that seems like a lot to ask of an operator | 15:47 |
| nkinder | writing policy can be pretty tough | 15:47 |
| *** dwyde has joined #openstack-security | 15:47 | |
| sicarie | I was surprised by that statement as well | 15:47 |
| *** singlethink has joined #openstack-security | 16:15 | |
| openstackgerrit | Dave Belcher proposed stackforge/bandit: Fixed -n flag processing https://review.openstack.org/166301 | 16:19 |
| *** ukbelch has quit IRC | 16:26 | |
| sicarie | Comments/critiques welcome on my current outline for Compute chapter: https://bugs.launchpad.net/openstack-manuals/+bug/1412975 | 16:31 |
| openstack | Launchpad bug 1412975 in openstack-manuals "Security Guide - Compute Section" [Low,Confirmed] - Assigned to N Dillon (sicarie) | 16:31 |
| sicarie | nkinder: I didn't include rdo/rhel selinux policies in there as I couldn't see them in a public repo, digging into rdo's is on my todo list | 16:31 |
| sicarie | This is just my cursory pass, I have more to do on each section | 16:32 |
| *** browne has joined #openstack-security | 16:35 | |
| *** ljfisher has quit IRC | 16:37 | |
| nkinder | sicarie: it's all public | 16:41 |
| sicarie | nkinder: what I saw on the rdo site (and again, this is with ~10seconds of Googl'ing) linked to an empty git repo | 16:42 |
| nkinder | sicarie: SRPM is the best way to get at it | 16:42 |
| tmcpeak | if it doesn't exist in 10 seconds of googling, it doesn't exist ;) | 16:42 |
| sicarie | So what I found right away was: https://github.com/redhat-openstack/openstack-selinux | 16:43 |
| nkinder | sicarie: ftp://ftp.redhat.com/redhat/linux/enterprise/7Server/en/RHOS/SRPMS/ | 16:44 |
| sicarie | integrated into rdo definitely deserves a mention, but I want to be able to call out what does and doesn't hav epolicies | 16:44 |
| sicarie | Awesome | 16:44 |
| nkinder | that will have the openstack-selinux SRPMS for RHEL OSP | 16:44 |
| nkinder | sicarie: RHEL SRPMS are now hosted via centos | 16:45 |
| nkinder | https://git.centos.org/project/rpms | 16:45 |
| sicarie | nkinder: thanks, did not know about this yet! | 16:46 |
| *** openstackgerrit has quit IRC | 17:21 | |
| *** openstackgerrit has joined #openstack-security | 17:21 | |
| *** ljfisher has joined #openstack-security | 17:27 | |
| openstackgerrit | Dave Belcher proposed stackforge/bandit: Fixed -n flag processing https://review.openstack.org/166301 | 17:28 |
| *** ukbelch has joined #openstack-security | 17:33 | |
| openstackgerrit | Dave Belcher proposed stackforge/bandit: Fixed -n flag processing https://review.openstack.org/166301 | 17:34 |
| *** ukbelch has quit IRC | 17:39 | |
| *** rkgudboy has joined #openstack-security | 17:43 | |
| openstackgerrit | Nathaniel Dillon proposed openstack/security-doc: Moving introduction sections 'up' from section_* files to ch_* files https://review.openstack.org/164526 | 17:45 |
| *** rkgudboy has quit IRC | 17:50 | |
| *** dwyde has quit IRC | 17:53 | |
| *** bpokorny_ has joined #openstack-security | 17:56 | |
| *** bpokorn__ has joined #openstack-security | 17:58 | |
| *** bpokorny has quit IRC | 17:59 | |
| *** bpokorny has joined #openstack-security | 18:00 | |
| *** bpokorny_ has quit IRC | 18:02 | |
| *** JAHoagie has joined #openstack-security | 18:02 | |
| *** bpokorn__ has quit IRC | 18:04 | |
| tmcpeak | nkinder: you around? | 18:04 |
| nkinder | tmcpeak: yep | 18:06 |
| tmcpeak | no judgies: http://pastebin.com/bAGv7RBU | 18:06 |
| tmcpeak | super hack city | 18:06 |
| tmcpeak | but it works | 18:06 |
| tmcpeak | open question - how to handle newlines | 18:06 |
| nkinder | tmcpeak: well, we're going to need a program to do the inverse conversion (YAML -> e-mail format) | 18:07 |
| tmcpeak | That should be easy | 18:07 |
| nkinder | I think that's where we will have logic to put newlines at the correct wrapping width | 18:08 |
| tmcpeak | sure, yeah that's no problem | 18:08 |
| nkinder | So in YAML, I'm not too picky about where the newlines would be | 18:08 |
| tmcpeak | the difficult part with this is, sometimes we obviously want to preserve newlines, like around code segments | 18:08 |
| nkinder | Yes, so maybe we have no newlines except those that we want to preserve | 18:08 |
| nkinder | ...in YAML | 18:08 |
| nkinder | then we wrap long lines in the YAML->OSSN automagically | 18:09 |
| tmcpeak | yeah, but how do you programatically determine which newlines you want to preserve? | 18:09 |
| nkinder | well that's the rub :) | 18:09 |
| tmcpeak | yeah, prob not possible | 18:09 |
| nkinder | I don't think we can | 18:09 |
| tmcpeak | yeah, so I think this is as close to magic we can do for this | 18:09 |
| tmcpeak | has dropped text into yaml format sensibly | 18:09 |
| tmcpeak | now we just need to clean up | 18:09 |
| tmcpeak | shouldn't be too much labor | 18:09 |
| nkinder | yeah, just a bit of mindless manual work :) | 18:10 |
| tmcpeak | yep yep | 18:11 |
| tmcpeak | so.. my weekend tribute to you nkinder is that hacky script :P | 18:11 |
| nkinder | thanks! | 18:11 |
| tmcpeak | sure thing | 18:11 |
| tmcpeak | nkinder: when we're ready for other way around I can bang something up that will wrap lines back | 18:12 |
| *** dwyde has joined #openstack-security | 18:14 | |
| *** dwyde has quit IRC | 18:15 | |
| openstackgerrit | Dave Belcher proposed stackforge/bandit: Fixed -n flag processing https://review.openstack.org/166301 | 18:21 |
| *** ukbelch has joined #openstack-security | 18:21 | |
| *** tkelsey has joined #openstack-security | 18:21 | |
| *** ukbelch has quit IRC | 18:35 | |
| *** sweston has quit IRC | 18:38 | |
| *** erw has quit IRC | 18:39 | |
| *** dwyde has joined #openstack-security | 18:49 | |
| *** ukbelch has joined #openstack-security | 19:02 | |
| *** tkelsey has quit IRC | 19:03 | |
| *** dwyde has quit IRC | 19:07 | |
| *** ukbelch has quit IRC | 19:26 | |
| *** jeanmanuel has joined #openstack-security | 19:54 | |
| *** singlethink has quit IRC | 19:55 | |
| jeanmanuel | hola | 19:55 |
| jeanmanuel | quien habla espaƱol | 19:55 |
| *** jeanmanuel has left #openstack-security | 19:55 | |
| *** jeanmanuel has joined #openstack-security | 19:56 | |
| *** jeanmanuel has left #openstack-security | 19:56 | |
| *** singlethink has joined #openstack-security | 20:05 | |
| *** erw has joined #openstack-security | 20:15 | |
| *** sweston has joined #openstack-security | 20:16 | |
| openstackgerrit | Shellee Arnold proposed openstack/security-doc: Fix for restatement of duplicated work https://review.openstack.org/163946 | 20:35 |
| *** hyakuhei has joined #openstack-security | 20:46 | |
| *** ljfisher has quit IRC | 20:57 | |
| *** tkelsey has joined #openstack-security | 21:00 | |
| *** tkelsey has quit IRC | 21:04 | |
| *** bpokorny_ has joined #openstack-security | 21:09 | |
| *** sicarie has quit IRC | 21:12 | |
| *** bpokorny has quit IRC | 21:13 | |
| *** hyakuhei has quit IRC | 21:24 | |
| *** singlethink has quit IRC | 21:36 | |
| *** jamielennox|away is now known as jamielennox | 21:49 | |
| *** singlethink has joined #openstack-security | 21:52 | |
| *** edmondsw has quit IRC | 21:53 | |
| *** JAHoagie has quit IRC | 22:03 | |
| *** jamielennox is now known as jamielennox|away | 22:05 | |
| *** JAHoagie has joined #openstack-security | 22:31 | |
| *** singlethink has quit IRC | 22:34 | |
| *** bknudson has quit IRC | 22:36 | |
| *** JAHoagie has quit IRC | 22:47 | |
| *** voodookid has quit IRC | 22:49 | |
| *** dave-mccowan has quit IRC | 23:20 | |
| *** tkelsey has joined #openstack-security | 23:31 | |
| *** tkelsey has quit IRC | 23:35 | |
| *** dave-mccowan has joined #openstack-security | 23:38 | |
| *** markvoelker has quit IRC | 23:42 | |
| *** JAHoagie has joined #openstack-security | 23:50 | |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!