Tuesday, 2015-03-24

*** markvoelker has joined #openstack-security00:02
*** JAHoagie has quit IRC00:11
*** tmcpeak has joined #openstack-security00:24
*** bpokorny has joined #openstack-security00:33
*** bpokorn__ has quit IRC00:36
*** salv-orlando has quit IRC01:04
*** bpokorny has quit IRC01:11
*** browne1 has quit IRC01:48
*** salv-orlando has joined #openstack-security02:05
*** bpokorny has joined #openstack-security02:08
*** browne has joined #openstack-security02:21
*** tmcpeak has quit IRC02:28
*** salv-orlando has quit IRC02:38
*** salv-orlando has joined #openstack-security02:39
*** bpokorny has quit IRC02:54
*** salv-orlando has quit IRC03:05
*** salv-orlando has joined #openstack-security03:37
*** salv-orlando has quit IRC04:09
*** dave-mccowan has quit IRC04:22
*** JAHoagie has joined #openstack-security04:58
*** salv-orlando has joined #openstack-security05:08
*** salv-orlando has quit IRC05:47
openstackgerritOpenStack Proposal Bot proposed openstack/security-doc: Imported Translations from Transifex  https://review.openstack.org/16658006:01
openstackgerritRajesh Asanabada proposed openstack/security-doc: Reframed the sentence in Authentication methods  https://review.openstack.org/16582306:02
*** JAHoagie has quit IRC06:03
*** pcaruana has quit IRC06:41
*** browne has quit IRC07:07
*** salv-orlando has joined #openstack-security07:16
*** browne has joined #openstack-security07:45
*** hyakuhei has joined #openstack-security07:57
*** browne has quit IRC08:01
*** salv-orlando has quit IRC08:03
*** tkelsey has joined #openstack-security08:08
*** hyakuhei has quit IRC08:38
*** salv-orlando has joined #openstack-security08:52
*** salv-orlando has quit IRC09:35
*** hyakuhei has joined #openstack-security09:39
*** markvoelker has quit IRC10:26
*** salv-orlando has joined #openstack-security10:31
*** tmcpeak has joined #openstack-security10:34
*** hyakuhei has quit IRC10:47
*** markvoelker has joined #openstack-security11:26
*** markvoelker has quit IRC11:31
*** jamielennox is now known as jamielennox|away11:45
*** salv-orlando has quit IRC11:46
*** markvoelker has joined #openstack-security11:58
*** salv-orlando has joined #openstack-security12:24
*** dave-mccowan has joined #openstack-security12:34
*** bknudson has quit IRC12:51
*** salv-orlando has quit IRC13:04
*** salv-orlando has joined #openstack-security13:09
*** bknudson has joined #openstack-security13:15
*** salv-orl_ has joined #openstack-security13:24
*** singlethink has joined #openstack-security13:26
*** salv-orlando has quit IRC13:27
*** salv-orlando has joined #openstack-security13:28
*** salv-orl_ has quit IRC13:32
*** localloop127 has joined #openstack-security14:20
*** browne has joined #openstack-security14:30
*** voodookid has joined #openstack-security14:43
*** dwyde has joined #openstack-security14:44
*** browne has quit IRC14:49
*** bpokorny has joined #openstack-security14:55
*** bpokorny has quit IRC14:59
*** bpokorny has joined #openstack-security15:08
tmcpeakbknudson: you around?15:12
bknudsontmcpeak: y15:12
tmcpeakbknudson: want to use the config file I made for keystone instead?15:13
tmcpeakI'll throw that up on pastebin15:13
bknudsontmcpeak: yes, I need to update the config file.15:13
bknudsonit's actually reporting a lot of failures as is.15:13
bknudsonjust using the default config + changed to skip tests15:14
tmcpeakbknudson: http://pastebin.com/FrCXBrYW15:14
tmcpeakthis defines keystone_conservative and keystone_verbose15:14
tmcpeakat least keystone_conservative has no results15:14
bknudson[tester]        ERROR   Bandit internal error running: execute_with_run_as_root_equals_true on file keystone/trust/routers.py at line 51: 'NoneType' object has no attribute '__getitem__'15:16
bknudsonI get a lot of those.15:16
tmcpeakreally..?15:16
tmcpeakbknudson: can you file a bug?15:17
tmcpeakare you using latest?15:17
tmcpeakthat's bad…15:17
tmcpeakI'm wondering how we haven't seen that15:17
bknudsontmcpeak: using tox -e bandit with https://review.openstack.org/#/c/157930/ and the config in http://pastebin.com/FrCXBrYW15:17
bknudsonI didn't see this with the default config ... maybe it's the execute_with_run_as_root_equals_true: were removed?15:18
bknudsonI'll try it15:18
tmcpeakbknudson: oh… maybe that test was renamed15:18
tmcpeakbknudson: I'm not getting that error when running locally15:21
*** browne has joined #openstack-security15:21
bknudsonhmmm... maybe it's not running right in this tox env.15:21
tmcpeakbknudson: yeah, makes sense15:22
bknudsontmcpeak: reposted https://review.openstack.org/#/c/157930/ with the updated bandit.yaml15:23
bknudsonhttps://review.openstack.org/#/c/157930/2..3/bandit.yaml15:23
bknudsonare the changes from the default15:23
bknudsonI still get a lot of hits, e.g., https://review.openstack.org/#/c/157930/2..3/bandit.yaml15:24
bknudsonoops15:24
bknudson>> Use of random is not suitable for security/cryptographic purposes.15:24
bknudson>> oslo config option not marked secret=True identified, security issue.15:24
bknudsonthat's a new one since last time.15:24
bknudsonI don't think I was using the right profile.15:27
tmcpeakbknudson bandit -c keystone.yaml -p keystone_conservative15:30
tmcpeakshould do it15:30
bknudsonI updated https://review.openstack.org/#/c/157930/ with -p15:31
bknudsonit runs cleanly now.15:31
tmcpeakbknudson: awesome15:31
*** browne has quit IRC15:39
openstackgerritNathaniel Dillon proposed openstack/security-doc: Adding new introudctions for chapters missing one  https://review.openstack.org/16488315:40
bknudsonwas somebody working on the -infra change for an experimental job already?15:43
tmcpeakbknudson: not that I know of15:43
bknudsonI'll take a stab at it...15:44
tmcpeakbknudson: awesome, thank you15:44
openstackgerritNathaniel Dillon proposed openstack/security-doc: Moving Data processing intro up to chapter file, and touching up intro section  https://review.openstack.org/16728215:54
*** singlethink has quit IRC15:58
*** singlethink has joined #openstack-security16:00
*** salv-orlando has quit IRC16:00
bknudsontmcpeak: https://review.openstack.org/#/c/157595/2/jenkins/jobs/projects.yaml -- we'll see what the pros say.16:01
tmcpeakbknudson: awesome, thanks for setting it up!16:04
bknudsonI don't know what order things go in... whether it's the jenkins job or keystone change is first16:05
bknudsonprobably the jenkins job would be best then I could run it.16:05
tmcpeakbknudson: yeah, those openstack-infra folks are pretty good, they'll probably help push it along :)16:06
*** salv-orlando has joined #openstack-security16:07
*** browne has joined #openstack-security16:26
brownetmcpeak: by missing config file, you mean the bandit.yaml, right?  If so, guess Bandit is still ok since most projects would include their own16:29
tmcpeakbrowne: yeah… missing bandit.yaml.  Will be ok for projects, but people that just "pip install bandit" might get annoyed by it, so I'd like to have a version that includes that, although we can probably pin where it is16:31
*** dwyde has quit IRC16:45
openstackgerritNathaniel Dillon proposed openstack/security-doc: Moving Data processing intro up to chapter file, and touching up section  https://review.openstack.org/16728216:51
*** hyakuhei has joined #openstack-security16:52
tmcpeakbrowne: you good with setuptools?17:05
tmcpeakbknudson: ^?17:05
bknudsontmcpeak: no, I've never had to look at it.17:06
tmcpeakbknudson: you're fortunate17:06
brownenot sure i would say good, but i've used it17:06
tmcpeakbrowne: I'm trying to figure out how to make binary setup builds include bandit.yaml in the same directory as bandit.py17:08
tmcpeaktkelsey has also tried…17:08
brownehmm, not sure you can do that since bandit.py is in the source and bandit.yaml is a config like file.  why not install bandit.yaml to /etc/bandit ?17:09
tmcpeakbrowne: that will break Windows17:09
bknudsonhe he17:09
tmcpeaklol17:09
bknudsonis there any other kind?17:09
browneha, well, pretty sure bandit doesn't claim support for windows17:09
browneOperating System :: POSIX :: Linux17:10
browneOperating System :: MacOS :: MacOS X17:10
browneaccording to your setup.cfg17:10
tmcpeakhmm, good point17:10
tmcpeakis it fair game for Python packages to install things into etc?17:10
brownedefinitely normal for openstack projects17:11
tmcpeakbrowne: good point… I think tkelsey did have installation into /etc working… although the way Bandit currently works it will still be broken17:11
tmcpeakcurrently config has to be in the same directory you're running in or specified with -c17:12
brownecan't the code be changed to look to load bandit.yaml from current directory or /etc/bandit/ or etc17:13
tkelseyim fixing that, lets go with /etc, any comments?17:13
brownegiving priority to current directory17:13
tkelseyyeah17:14
tmcpeakso order of ops 1) -c override, 2) cwd bandit.yaml, 3) /etc/bandit/bandit.yaml17:15
tmcpeakgmurphy suggested adding $HOME/.bandit.yaml17:16
tmcpeakso 1) -c override, 2) cwd bandit.yaml, 3) $HOME/.bandit.yaml, 4) /etc/bandit/bandit.yaml17:17
openstackgerritDoug Chivers proposed stackforge/anchor: Added validation for CA configuration  https://review.openstack.org/16468917:17
brownesounds good17:17
tmcpeakcool17:19
*** salv-orlando has quit IRC17:26
*** hyakuhei has quit IRC17:27
*** salv-orlando has joined #openstack-security17:28
*** dwyde has joined #openstack-security17:30
openstackgerritDoug Chivers proposed stackforge/anchor: Added validation for CA configuration  https://review.openstack.org/16468917:40
*** bpokorny has quit IRC18:01
*** localloop127 has quit IRC18:03
*** bpokorny has joined #openstack-security18:03
openstackgerritDoug Chivers proposed stackforge/anchor: Added validation for CA configuration  https://review.openstack.org/16468918:04
*** jamielennox|away is now known as jamielennox18:04
*** bpokorny_ has joined #openstack-security18:16
openstackgerritTim Kelsey proposed stackforge/bandit: fixing bandits config settings  https://review.openstack.org/16734918:18
*** bpokorny has quit IRC18:19
*** localloop127 has joined #openstack-security18:23
openstackgerritTim Kelsey proposed stackforge/bandit: fixing bandits config settings  https://review.openstack.org/16734918:29
*** dwyde_ has joined #openstack-security18:42
*** dwyde has quit IRC18:45
*** dwyde_ is now known as dwyde18:46
*** hyakuhei has joined #openstack-security18:48
openstackgerritShellee Arnold proposed openstack/security-doc: Fixes for formatting and grammatical errors  https://review.openstack.org/16391118:56
openstackgerritTim Kelsey proposed stackforge/bandit: fixing bandits config settings  https://review.openstack.org/16734918:57
*** edmondsw has joined #openstack-security19:10
*** Shail has joined #openstack-security19:19
*** tkelsey has quit IRC19:23
openstackgerritMerged openstack/security-doc: Reframed the sentence in Authentication methods  https://review.openstack.org/16582319:38
*** tkelsey has joined #openstack-security19:50
*** dwyde has quit IRC19:53
*** tkelsey has quit IRC19:55
*** bpokorny has joined #openstack-security20:00
*** bpokorny_ has quit IRC20:03
*** dwyde has joined #openstack-security20:35
*** localloo1 has joined #openstack-security20:42
*** localloop127 has quit IRC20:44
*** dwyde_ has joined #openstack-security20:55
*** dwyde_ has quit IRC20:55
*** dwyde_ has joined #openstack-security20:56
*** dwyde has quit IRC20:57
*** dwyde_ is now known as dwyde20:57
*** openstackgerrit has quit IRC21:07
*** openstackgerrit has joined #openstack-security21:07
*** bpokorny_ has joined #openstack-security21:27
openstackgerritMerged stackforge/bandit: fixing bandits config settings  https://review.openstack.org/16734921:27
*** bpokorny has quit IRC21:30
*** edmondsw has quit IRC21:39
*** dwyde has quit IRC21:40
*** redrobot has quit IRC21:42
*** redrobot has joined #openstack-security21:47
*** redrobot is now known as Guest938521:47
*** tristanC has quit IRC21:48
openstackgerritShellee Arnold proposed openstack/security-doc: Identity in OpenStack Security Guide  - Style nits  https://review.openstack.org/16740921:49
*** tristanC has joined #openstack-security21:49
*** localloo1 has quit IRC21:57
*** dwyde has joined #openstack-security21:58
*** Guest9385 is now known as redrobot22:00
*** bknudson has quit IRC22:04
openstackgerritShellee Arnold proposed openstack/security-doc: Sentence revision  https://review.openstack.org/15835422:04
*** dwyde has quit IRC22:28
*** singlethink has quit IRC22:40
*** salv-orl_ has joined #openstack-security22:58
*** salv-orlando has quit IRC23:02
*** voodookid has quit IRC23:05
*** markvoelker has quit IRC23:06
*** markvoelker has joined #openstack-security23:47
*** tkelsey has joined #openstack-security23:52
*** markvoelker has quit IRC23:52
*** tkelsey has quit IRC23:56
*** tmcpeak has quit IRC23:58

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!