*** salv-orlando has quit IRC | 00:04 | |
*** elo1 has joined #openstack-security | 00:09 | |
*** browne has joined #openstack-security | 00:45 | |
*** salv-orlando has joined #openstack-security | 01:05 | |
*** salv-orlando has quit IRC | 01:11 | |
*** salv-orlando has joined #openstack-security | 01:32 | |
*** salv-orlando has quit IRC | 01:35 | |
*** salv-orlando has joined #openstack-security | 01:41 | |
*** salv-orlando has quit IRC | 01:51 | |
*** elo1 has quit IRC | 02:27 | |
*** bpokorny has joined #openstack-security | 02:40 | |
*** jamielennox is now known as jamielennox|away | 02:58 | |
*** tmcpeak has quit IRC | 02:59 | |
*** jamielennox|away is now known as jamielennox | 03:03 | |
*** elo1 has joined #openstack-security | 03:41 | |
*** salv-orlando has joined #openstack-security | 03:45 | |
*** salv-orlando has quit IRC | 03:51 | |
*** dave-mccowan has quit IRC | 04:16 | |
*** subscope has joined #openstack-security | 04:25 | |
*** Kennan2 has joined #openstack-security | 04:26 | |
*** Kennan has quit IRC | 04:26 | |
*** aswadr has joined #openstack-security | 04:32 | |
*** subscope has quit IRC | 04:47 | |
*** bpokorny has quit IRC | 04:50 | |
*** elo1 has quit IRC | 05:38 | |
*** elo1 has joined #openstack-security | 05:44 | |
*** salv-orlando has joined #openstack-security | 05:57 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Imported Translations from Transifex https://review.openstack.org/175108 | 06:01 |
---|---|---|
*** salv-orlando has quit IRC | 06:06 | |
*** Guest85711 has quit IRC | 06:30 | |
*** smu_ has joined #openstack-security | 06:33 | |
*** smu_ is now known as Guest17708 | 06:33 | |
*** jamielennox is now known as jamielennox|away | 06:52 | |
*** browne has quit IRC | 06:52 | |
*** browne has joined #openstack-security | 07:05 | |
*** tkelsey has joined #openstack-security | 07:09 | |
*** browne has quit IRC | 07:21 | |
*** tkelsey has quit IRC | 07:23 | |
*** tkelsey has joined #openstack-security | 07:27 | |
*** tkelsey has quit IRC | 07:39 | |
*** tkelsey has joined #openstack-security | 08:00 | |
*** salv-orlando has joined #openstack-security | 08:07 | |
*** salv-orlando has quit IRC | 08:11 | |
*** salv-orlando has joined #openstack-security | 08:17 | |
*** tkelsey has quit IRC | 08:20 | |
*** salv-orlando has quit IRC | 08:21 | |
*** salv-orlando has joined #openstack-security | 08:23 | |
*** salv-orlando has quit IRC | 08:28 | |
*** salv-orlando has joined #openstack-security | 08:51 | |
*** tkelsey has joined #openstack-security | 09:05 | |
*** pcaruana has quit IRC | 09:27 | |
*** pcaruana has joined #openstack-security | 09:30 | |
*** elo1 has quit IRC | 09:36 | |
*** tmcpeak has joined #openstack-security | 10:02 | |
*** dave-mccowan has joined #openstack-security | 12:14 | |
*** bknudson has quit IRC | 12:26 | |
*** salv-orlando has quit IRC | 12:28 | |
*** jamielennox|away is now known as jamielennox | 12:31 | |
*** jamielennox is now known as jamielennox|away | 12:32 | |
*** bknudson has joined #openstack-security | 12:55 | |
*** salv-orlando has joined #openstack-security | 12:56 | |
*** elo1 has joined #openstack-security | 14:34 | |
*** browne has joined #openstack-security | 14:39 | |
*** elo1 has quit IRC | 14:42 | |
*** dwyde has joined #openstack-security | 14:57 | |
*** voodookid has joined #openstack-security | 14:58 | |
*** browne has quit IRC | 15:08 | |
*** bpokorny has joined #openstack-security | 15:11 | |
*** elo1 has joined #openstack-security | 16:21 | |
*** browne has joined #openstack-security | 16:21 | |
*** voodookid has quit IRC | 16:24 | |
*** dwyde has quit IRC | 16:27 | |
*** Kennan2 has quit IRC | 16:29 | |
*** Kennan has joined #openstack-security | 16:29 | |
*** nkinder has quit IRC | 16:38 | |
*** voodookid has joined #openstack-security | 16:42 | |
*** shelleea007 has joined #openstack-security | 16:56 | |
*** sicarie has joined #openstack-security | 17:00 | |
* sicarie waves | 17:00 | |
*** pdesai has joined #openstack-security | 17:00 | |
* elmiko waves | 17:00 | |
shelleea007 | hi | 17:00 |
pdesai | Hi | 17:00 |
sicarie | Greetings! | 17:00 |
pdesai | Good Morning | 17:01 |
sicarie | So we have one new bug for triage: https://bugs.launchpad.net/openstack-manuals/+bug/1444657 | 17:01 |
openstack | Launchpad bug 1444657 in openstack-manuals "Adding a chapter on Barbican - OpenStack Security Guide" [Undecided,Confirmed] - Assigned to Jason Fritcher (jason-fritcher) | 17:01 |
elmiko | ooh, nice! | 17:01 |
sicarie | pdesai: would you like to give a quick overview? | 17:01 |
shelleea007 | cool | 17:02 |
pdesai | sure, i have a team mate who has deployed barbican in our dev test env., and would like to contribute secure way of deployment to our guide | 17:02 |
pdesai | i have promised him, help from my side on composing his content into doc book | 17:03 |
sicarie | awesome | 17:03 |
elmiko | awesome | 17:03 |
elmiko | hehe | 17:03 |
pdesai | he he | 17:03 |
sicarie | So what level do you think this should be? | 17:03 |
elmiko | med/high imo | 17:04 |
pdesai | i think med | 17:04 |
pdesai | yeah dont mind high | 17:04 |
sicarie | I would lean towards medium, but wouldn’t be averse to a high | 17:04 |
*** bpokorny_ has joined #openstack-security | 17:04 | |
pdesai | lets go with Med | 17:04 |
elmiko | sounds like med. might be the prudent choice | 17:04 |
pdesai | +1 | 17:05 |
sicarie | Great, that’s updated | 17:05 |
pdesai | awesome thanks | 17:05 |
sicarie | Looking through the bugs there’s not much else that’s new: https://bugs.launchpad.net/openstack-manuals/+bugs?field.tag=sec-guide | 17:05 |
sicarie | Looking through the project in gerrit there is mostly OSSN stuff | 17:06 |
elmiko | sicarie: i have a question about the case studies pad | 17:07 |
sicarie | there are two new contributor reviews | 17:07 |
sicarie | elmiko: sure | 17:07 |
sicarie | https://etherpad.openstack.org/p/sec-guide-case-studies | 17:07 |
sicarie | Just a quick note, I moved the Alice section up to the top and labeled the sections I thought were ready for review | 17:07 |
elmiko | looking at the notes for the data processing section, should i go ahead and recraft the studies there for data p. based on the notes? | 17:07 |
sicarie | Yeah, that’d be awesome | 17:07 |
elmiko | ok, cool. didn't want to start mucking around till we talked =) | 17:08 |
*** bpokorny has quit IRC | 17:08 | |
sicarie | Oh yeah, that’s why I posed it on the etherpad - feel free everyone to make any updates | 17:08 |
elmiko | ack, will do | 17:08 |
sicarie | I was going to draft it on the etherpad for a rough draft and then submit to Gerrit for wider OSSG review once I was sure there weren’t crazy gaps | 17:08 |
shelleea007 | i will look at it too | 17:08 |
sicarie | I did mark the Management section as ready to review, but there is a piece I have not had time to fit into it | 17:09 |
pdesai | are we tracking all of the case studies, i mean case studies from all the ch? | 17:09 |
sicarie | SO if you have input on that (or just want to edit the existing), please feel free | 17:09 |
shelleea007 | i am still working on the two chapters and will file some bugs on that | 17:09 |
sicarie | Yes, the headings (System Documetnation, Management, etc…) reference the case study for that chapter | 17:09 |
pdesai | i see, | 17:09 |
sicarie | Right now i have only done Alice's | 17:09 |
sicarie | I figured hers would be more stringent because she would be heavily governed by regulation, and then Bob’s could be much more free-flowing to contrast to Alice's | 17:10 |
elmiko | i think it might be best to stage out the updates into gerrit review, to keep from having a huge CR. (if that wasn't already the plan) | 17:10 |
sicarie | +1 elmiko | 17:10 |
pdesai | +1 | 17:10 |
sicarie | As there hasn’t been much response on these, I was going to take lead, but if you write a section and you feel comfortable with it, please feel free to submit it into Gerrit | 17:11 |
elmiko | nice, that works | 17:11 |
sicarie | bug is https://bugs.launchpad.net/openstack-manuals/+bug/1349540 | 17:11 |
openstack | Launchpad bug 1349540 in openstack-manuals "Ensure one case study per chapter in security guide" [Medium,In progress] - Assigned to N Dillon (sicarie) | 17:11 |
elmiko | and we're going with case study at the end of each chapter? | 17:11 |
pdesai | awesome, i can help you with identity and secure communication ch | 17:12 |
sicarie | elmiko: yes, I believe the previous tmeplate was a case study for each alice and bob at the end of each chapter showing how that chapter was implemented into their deployments | 17:12 |
sicarie | pdesai: that would be great! | 17:12 |
elmiko | sicarie: cool, just wanted to double check | 17:12 |
sicarie | pdesai: Please feel free to rewrite the Secure Communication section as you see fit - I have not drafted Identity yet, so I will assign that to you? | 17:13 |
pdesai | sure | 17:13 |
pdesai | elmiko, do you have any recommendation on restructring case studies? | 17:13 |
sicarie | awesome | 17:13 |
sicarie | shelleea007: did you want to take a case study, or are you good with your 2 chapters and doing some review on them overall? | 17:14 |
elmiko | pdesai: none that haven't been mentioned. i'll take another pass at the data processing stuff, but in general everything sounds good to me. | 17:14 |
shelleea007 | i can do both | 17:14 |
pdesai | cool | 17:14 |
sicarie | Oh, and please feel free to give input on or start drafting “Bob’s” case studies as well if you think of a good contrast or alternate configuration | 17:15 |
sicarie | (all) | 17:15 |
shelleea007 | OK, I can do that too | 17:15 |
sicarie | shelleea007: thanks! | 17:15 |
sicarie | So there were two new (or relatively new) contributors | 17:16 |
*** Guest36304 is now known as mgagne | 17:16 | |
*** mgagne has joined #openstack-security | 17:16 | |
sicarie | https://review.openstack.org/#/c/173734/ | 17:16 |
sicarie | and | 17:16 |
sicarie | https://review.openstack.org/#/c/174727/ | 17:16 |
elmiko | very nice | 17:16 |
sicarie | So thanks all for submitting bugs on the chapters - we do get good new contributors on the low-hanging-fruit stuff! | 17:17 |
pdesai | +1 | 17:17 |
elmiko | +1, i gotta remember to add that to the grammar bugs | 17:18 |
sicarie | So I can’t remember with how many meetings I’ve been in, did I mention the sec-guide move to RST format? | 17:18 |
pdesai | yeah in few months (around 7) | 17:19 |
sicarie | okay, cool | 17:19 |
sicarie | Nothing to think about yet, but know it’s coming down | 17:19 |
pdesai | but we havent discussed the process on migration | 17:19 |
pdesai | cool | 17:19 |
sicarie | pdesai: thanks for the great lead-in! | 17:19 |
sicarie | Summit Planning: | 17:19 |
elmiko | should be too bad, are they working on tools for auto-migration of xml->rst? | 17:20 |
pdesai | sure | 17:20 |
elmiko | *shouldn't | 17:20 |
sicarie | I’d like to sit down with a group and discuss 1) published book standards and 2) migration process | 17:20 |
pdesai | nice | 17:20 |
sicarie | elmiko: Good question, I will take that to the doc team | 17:20 |
sicarie | I know there is manual work, but I don’t know how much | 17:20 |
elmiko | sicarie: thanks | 17:21 |
sicarie | elmiko: i’ve added it to the meeting invite | 17:21 |
*** dwyde has joined #openstack-security | 17:21 | |
sicarie | Unfortunately this is the meeting that is in the afternoon, which is right during my commute time | 17:21 |
sicarie | So there’s a good chance I’ll miss it | 17:22 |
elmiko | doh! | 17:22 |
sicarie | It may be pushed to next week | 17:22 |
sicarie | So the process for publishing a new lulu version of the book is apparnetly spinning up a pdf and submitting it | 17:22 |
sicarie | very straightforward | 17:22 |
elmiko | nice and simple ;) | 17:23 |
sicarie | So I’d like to decide on a few milestones to complete before we get there | 17:23 |
sicarie | Personally, the identity chapter refactoring was big on my list, I’d like to do that with Dashboard as well | 17:23 |
pdesai | nice | 17:23 |
sicarie | so pdesai thanks for doing that! | 17:23 |
pdesai | sure you are welcome | 17:23 |
sicarie | And I would like to 1) finish the case studies, 2) finish the Compute chapter, and 3) do a thorough reivew of Identity (in-progress), Dashboard, and Networking | 17:24 |
sicarie | Those are just my personal list, I’d like to decide on the criteria at the Summit, and then push the new lulu version and have it available by the Liberty release | 17:25 |
sicarie | Sound good? | 17:25 |
pdesai | +1 | 17:25 |
elmiko | +1 | 17:26 |
sicarie | And then at the summit I’d also like to discuss the migration to RST, as soon as we have an idea of how much manual work will be needed | 17:26 |
sicarie | The admin guide and user guides have already been converted, so we have a good set of experience we can ping the docs team on | 17:26 |
sicarie | And that’s ll I had | 17:27 |
sicarie | Did anyone else have anything they’d like to discuss, or anything I missed? | 17:27 |
elmiko | nothing from me | 17:27 |
pdesai | nothing from me | 17:27 |
sicarie | Great, well thanks for all your help, and see you next week! | 17:28 |
pdesai | thanks, see ya | 17:28 |
elmiko | thanks! | 17:28 |
shelleea007 | nothing from me either | 17:28 |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/175196 | 17:30 |
*** pdesai has quit IRC | 17:30 | |
*** shelleea007 has quit IRC | 17:32 | |
*** aswadr has quit IRC | 17:32 | |
*** sicarie has quit IRC | 17:32 | |
*** edmondsw has joined #openstack-security | 17:39 | |
*** tkelsey has quit IRC | 18:01 | |
*** elo1 has quit IRC | 18:05 | |
*** dwyde has quit IRC | 18:08 | |
*** bpokorny has joined #openstack-security | 18:09 | |
*** elo1 has joined #openstack-security | 18:11 | |
*** bpokorny_ has quit IRC | 18:12 | |
*** bpokorny_ has joined #openstack-security | 18:18 | |
*** singlethink has joined #openstack-security | 18:20 | |
*** bpokorny has quit IRC | 18:21 | |
*** dwyde has joined #openstack-security | 18:28 | |
*** tkelsey has joined #openstack-security | 18:30 | |
*** tkelsey has quit IRC | 18:34 | |
*** elo2 has joined #openstack-security | 18:35 | |
*** elo1 has quit IRC | 18:35 | |
*** elo1 has joined #openstack-security | 18:44 | |
*** elo2 has quit IRC | 18:45 | |
*** elo2 has joined #openstack-security | 18:48 | |
*** elo1 has quit IRC | 18:48 | |
*** elo1 has joined #openstack-security | 18:49 | |
*** elo2 has quit IRC | 18:49 | |
*** elo1 has quit IRC | 18:54 | |
*** elo1 has joined #openstack-security | 18:54 | |
*** elo2 has joined #openstack-security | 19:01 | |
*** elo1 has quit IRC | 19:02 | |
*** tkelsey has joined #openstack-security | 19:28 | |
*** tkelsey has quit IRC | 19:32 | |
*** tkelsey has joined #openstack-security | 20:04 | |
*** tkelsey has quit IRC | 20:13 | |
*** tkelsey has joined #openstack-security | 20:15 | |
*** dwyde has quit IRC | 20:45 | |
*** dstanek has joined #openstack-security | 20:45 | |
dstanek | wow, cool! i just guessed that this channel existed and y'all are here! | 20:46 |
*** edmondsw has quit IRC | 20:47 | |
*** dwyde has joined #openstack-security | 20:49 | |
* elmiko waves | 20:49 | |
tmcpeak | hey, what's up dstanek | 21:01 |
*** bpokorny has joined #openstack-security | 21:02 | |
dstanek | hey tmcpeak, is there a way to document possible attack vectors? something that doesn't exist now, but could in the future | 21:02 |
*** tkelsey has quit IRC | 21:04 | |
tmcpeak | dstanek: sure, what do you have in mind? | 21:04 |
*** bpokorny_ has quit IRC | 21:05 | |
tmcpeak | I guess what kind of attack vectors?… generic security threats or OpenStack specific? | 21:05 |
*** elo2 has quit IRC | 21:13 | |
dstanek | tmcpeak: sorry wasn't paying attention | 21:15 |
dstanek | tmcpeak: https://bugs.launchpad.net/keystone/+bug/1440958 | 21:15 |
openstack | Launchpad bug 1440958 in Keystone "loosen validation on matching trusted dashboard" [Medium,Fix committed] - Assigned to Lin Hua Cheng (lin-hua-cheng) | 21:15 |
dstanek | i notice in this particular bug that if there was a flaw in the dashboard (horizon or other) then this federation feature may be exploitable | 21:16 |
dstanek | what i don't like is that the security of a feature in keystone relies on the security of another system and we have to way to check/verify the provided data | 21:17 |
*** elo2 has joined #openstack-security | 21:17 | |
*** elo3 has joined #openstack-security | 21:24 | |
*** elo2 has quit IRC | 21:24 | |
*** elo3 has quit IRC | 21:37 | |
*** voodookid has quit IRC | 21:46 | |
*** elo2 has joined #openstack-security | 21:58 | |
*** voodookid has joined #openstack-security | 22:01 | |
*** elo2 has quit IRC | 22:07 | |
*** elo1 has joined #openstack-security | 22:07 | |
*** elo2 has joined #openstack-security | 22:16 | |
*** elo1 has quit IRC | 22:16 | |
*** elo2 has quit IRC | 22:17 | |
*** elo1 has joined #openstack-security | 22:17 | |
*** elo1 has quit IRC | 22:21 | |
*** elo1 has joined #openstack-security | 22:21 | |
*** dwyde has left #openstack-security | 22:22 | |
*** bknudson has quit IRC | 22:26 | |
*** elo1 has quit IRC | 22:31 | |
*** elo1 has joined #openstack-security | 22:32 | |
*** singlethink has quit IRC | 22:50 | |
*** bpokorny_ has joined #openstack-security | 22:55 | |
*** bpokorny has quit IRC | 22:58 | |
*** voodookid has quit IRC | 22:58 | |
openstackgerrit | Jamie Finnigan proposed stackforge/bandit: Shift in result types & ranking scales https://review.openstack.org/175612 | 23:37 |
*** jamielennox|away is now known as jamielennox | 23:45 | |
*** openstackgerrit has quit IRC | 23:58 | |
*** openstackgerrit has joined #openstack-security | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!