Thursday, 2015-07-02

*** dave-mccowan has quit IRC01:21
*** sigmavirus24 is now known as sigmavirus24_awa01:40
*** dave-mccowan has joined #openstack-security02:51
*** sdake has joined #openstack-security04:30
*** dave-mccowan has quit IRC04:44
*** amit213 has joined #openstack-security05:00
*** tmcpeak has quit IRC05:00
*** browne has quit IRC06:36
openstackgerritOpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals  https://review.openstack.org/19786307:23
*** VivCheri has joined #openstack-security07:27
openstackgerritMerged openstack/security-doc: Updated from openstack-manuals  https://review.openstack.org/19786307:36
*** airen has joined #openstack-security07:45
openstackgerritStanislaw Pitucha proposed stackforge/anchor: Implement saving certificate in memory  https://review.openstack.org/19743308:17
*** jamielennox is now known as jamielennox|away08:20
*** jamielennox|away is now known as jamielennox08:41
*** openstackgerrit has quit IRC09:19
*** openstackgerrit has joined #openstack-security09:20
*** shohel has joined #openstack-security10:13
*** VivCheri has quit IRC10:13
*** dave-mccowan has joined #openstack-security12:30
*** edmondsw has joined #openstack-security12:42
*** singlethink has joined #openstack-security13:32
*** tmcpeak has joined #openstack-security13:42
*** jian5397 has joined #openstack-security13:45
*** VivCheri has joined #openstack-security13:50
*** singleth_ has joined #openstack-security13:54
VivCheriGood evening.13:54
elmikogood morning =)13:55
jian5397goo morning13:55
jian5397good morning13:55
*** jian5397 is now known as michaelxin13:55
michaelxinvivcheri: where are you?13:56
*** sigmavirus24_awa is now known as sigmavirus2413:56
VivCherimichaelxin: why do you ask ? :)13:56
VivCheriVivCheri: I am in India.13:57
michaelxingot it. Thanks.13:57
*** singlethink has quit IRC13:57
michaelxinjust curious13:57
VivCheriok :)13:58
*** localloop127 has joined #openstack-security14:02
openstackgerritTim Kelsey proposed stackforge/bandit: Adding a test for partial paths in exec functions  https://review.openstack.org/19718014:02
*** browne has joined #openstack-security14:11
*** voodookid has joined #openstack-security14:36
*** VivCheri has quit IRC14:42
*** timkennedy has joined #openstack-security14:43
*** shohel has quit IRC14:45
*** VivCheri has joined #openstack-security14:54
openstackgerritTim Kelsey proposed stackforge/bandit: Adding a test for partial paths in exec functions  https://review.openstack.org/19718014:58
openstackgerritTim Kelsey proposed stackforge/bandit: Adding a test for partial paths in exec functions  https://review.openstack.org/19718015:01
*** shohel has joined #openstack-security15:07
*** dwyde has joined #openstack-security15:13
*** michaelxin has quit IRC15:16
sigmavirus24I think bkudson mentioned this already, but someone wants us to use oslo.rootwrap in Glance: https://review.openstack.org/#/c/186201/ I added a bunch of you for reviews =P15:28
tmcpeaksigmavirus24: I'm not as up on rootwrap and the evils of it as I should be, is the idea that basically people suck at using filters?15:32
sigmavirus24I'm not entirely sure15:32
sigmavirus24I think it's meant to be the lesser of two evils15:33
tmcpeakI mean, it's fairly prevalent, and I think in theory it could be used securely.  I'd rather at least have the option for filters than people just "sudo this" and "sudo that"'ing all over the place15:33
sigmavirus24yeah15:34
tmcpeaknext midcycle I"m going to spend some time with bknudson and browne and the other rootwrap experts and finally understand what's up15:34
tmcpeakI'd like a day to just poke at it15:34
*** singleth_ has quit IRC15:37
browneas i recall rootwrap really sucks when they use the blank CommandFilter. basically it permits that command to run with any argument.  RegExpFilter should be preferred15:38
elmikotmcpeak: yea, my experience was that filters usually messed our users up15:39
tmcpeakahh ok cool15:40
tmcpeakhmm, yeah that's what we ended up with here.  https://security.openstack.org/guidelines/dg_use-oslo-rootwrap-securely.html15:41
tmcpeakat some point it would be interesting to dig in, and find some examples of suck and some examples of not-suck15:41
*** tkelsey has joined #openstack-security15:45
tmcpeakelmiko: https://bugs.launchpad.net/python-swiftclient/+bug/147074015:46
openstackLaunchpad bug 1470740 in python-swiftclient "swiftclient disclose token in debug logs" [Undecided,New]15:46
tmcpeaksee comment here :)15:46
sigmavirus24thanks for the link tmcpeak15:47
tmcpeak;)15:47
elmikointeresting...15:47
tmcpeaklooks like we need to just say "DEBUG may log all the things"15:47
tmcpeakadd all affected projects and versions15:47
elmikook, so one more re-write on 0049 then?15:48
elmikotristanC: thanks! ;)15:48
tmcpeakelmiko: yeah :( sorry man, this one is turning out epic15:48
elmikohaha totes15:48
tmcpeakthat's cool though man, if you're going to write a note it might as well be an epic one15:49
elmikosure, why not. then at least we don't have to write one like this again15:49
elmikohopefully....15:49
tristanCelmiko: you're welcome ;)15:50
tmcpeakthe fun part is going to be listing out all of the projects15:50
tmcpeaktristanC: would you recommend listing all of the projects, since this could be in any of them?15:50
elmikooh man...15:50
tmcpeakalso what projects do we list? I'm not up on the big tent manifesto as much as I should be15:51
* Daviey regrets looking at the backscroll, and decides to put the kettle on instead.15:51
elmikothere should be a way for use to have an ossn that applies to all services15:51
elmikoDaviey: lol!15:52
tristanCa starting list could be: https://bugs.launchpad.net/ossa/?field.searchtext=debug&search=Search&field.status%3Alist=WONTFIX&field.assignee=&field.bug_reporter=&field.omit_dupes=on&field.has_patch=&field.has_no_package=15:52
tmcpeakyeah, maybe just "all" ? or something, nkinder: ^15:52
tmcpeaktristanC: but just because it doesn't exist in a project now doesn't mean it wouldn't in the future if it's not a security bug, it doesn't seem like we necessarily have a firm stance on this one way or the other15:53
elmikothis seems like a good candidate for an "all", although if need be i'll hit the list that tristanC is suggesting15:53
tristanC"all" seems fine, but then operators will yell that they need debug mode in prod so...15:53
DavieyIf operators *need* to use Debug in prod, then openstack logging is busted.15:54
tmcpeaktristanC: at which point we yell that they're going to get popped and then the cycle goes around again15:54
elmikocan we just say, "if you use debug mode then the security group says https://www.youtube.com/watch?v=5c2etjMl3WM" ?15:55
tmcpeak^ if this is a rick-roll I'm going to be upset15:55
elmikolol15:55
DavieyIs there a Tempest job to look for strings that shouldn't be logged?15:55
nkindertmcpeak: just escaped from a meeting.  Let me read the backscroll...15:57
tmcpeakokies15:58
nkinderelmiko, tmcpeak: we have an example of "all services" in the heartbleed or poodle OSSN IIRC15:58
nkinderelmiko, tmcpeak: https://wiki.openstack.org/wiki/OSSN/OSSN-003915:59
elmikonkinder: awesome, thanks16:00
* elmiko heads off back to the re-write dungeon16:00
tmcpeakoh yeah, cool, that's right16:00
tmcpeaknkinder: I even wrote one of them ;) https://wiki.openstack.org/wiki/OSSN/OSSN-0045  — I have the memory of a sparrow apparently16:01
sigmavirus24I have it on my todo list to write one for glance16:01
nkindertmcpeak: lol.  I know how you feel.16:02
tmcpeakyeah, I should pick another up soon too16:02
*** singlethink has joined #openstack-security16:11
*** dwyde has quit IRC16:11
*** dwyde has joined #openstack-security16:11
*** dwyde has quit IRC16:16
*** dwyde has joined #openstack-security16:16
*** singleth_ has joined #openstack-security16:31
*** singlethink has quit IRC16:35
*** deepika has joined #openstack-security16:45
*** deepika has quit IRC16:46
*** mvaldes has joined #openstack-security16:46
*** deepika has joined #openstack-security16:47
*** jian5397 has joined #openstack-security16:52
*** gmurphy_ is now known as gmurphy16:57
*** jian5397 is now known as michaelxin17:01
*** mvaldes has left #openstack-security17:02
*** singlethink has joined #openstack-security17:05
*** singleth_ has quit IRC17:08
*** dwyde has quit IRC17:27
*** dwyde has joined #openstack-security17:58
*** michaelxin has quit IRC17:59
*** VivCheri has quit IRC18:19
*** elo1 has joined #openstack-security18:19
*** browne has quit IRC18:20
openstackgerritTim Kelsey proposed stackforge/bandit: Adding a test for partial paths in exec functions  https://review.openstack.org/19718018:20
*** elo has quit IRC18:23
*** sdake_ has joined #openstack-security18:58
*** sdake has quit IRC19:00
*** sdake has joined #openstack-security19:01
*** sdake_ has quit IRC19:04
*** rbrooker has joined #openstack-security19:25
*** deepika has quit IRC19:45
*** tkelsey has quit IRC19:51
*** jian5397 has joined #openstack-security20:09
*** edmondsw has quit IRC20:14
*** browne has joined #openstack-security20:16
*** localloop127 has quit IRC20:19
*** singleth_ has joined #openstack-security20:25
*** timkennedy has quit IRC20:25
*** jian5397 is now known as michaelxin20:28
*** singlethink has quit IRC20:29
*** dwyde has quit IRC20:43
*** michaelxin has quit IRC21:44
*** tkelsey has joined #openstack-security21:48
*** tkelsey has quit IRC21:53
openstackgerritMerged stackforge/bandit: Adding a test for partial paths in exec functions  https://review.openstack.org/19718021:56
*** singlethink has joined #openstack-security22:09
*** singleth_ has quit IRC22:12
*** sdake has quit IRC22:22
*** sdake has joined #openstack-security22:22
*** elo1 has quit IRC22:41
*** shohel has quit IRC22:42
*** amit213 has quit IRC22:42
*** woodrow has quit IRC22:42
*** shohel has joined #openstack-security22:43
*** sdake has quit IRC22:43
*** sdake has joined #openstack-security22:44
*** woodrow has joined #openstack-security22:45
*** sdake has quit IRC22:46
*** sdake has joined #openstack-security22:50
*** sdake has quit IRC22:51
*** voodookid has quit IRC22:53
*** singlethink has quit IRC22:56
*** shohel has quit IRC22:59
*** security-admin has joined #openstack-security23:17
*** elo has joined #openstack-security23:23
*** sdake has joined #openstack-security23:37
*** Ripon has joined #openstack-security23:42
*** tmcpeak has quit IRC23:51
*** browne has quit IRC23:51

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!