Friday, 2015-07-24

openstackgerritStanislaw Pitucha proposed openstack/security-specs: Add Anchor spec for parsing backend change  https://review.openstack.org/20532800:05
DavieyJust when i am about to go to bed viraptor submits something i want to read.00:07
*** elo1 has joined #openstack-security00:22
*** elo1 has joined #openstack-security00:22
*** elo has quit IRC00:26
*** tmcpeak has quit IRC00:29
*** sigmavirus24_awa is now known as sigmavirus2400:47
*** browne has joined #openstack-security00:55
*** tmcpeak has joined #openstack-security00:55
openstackgerritMerged openstack/security-doc: Updating Messaging section files to RST  https://review.openstack.org/20488000:57
*** bpokorny has quit IRC01:18
openstackgerritMerged openstack/security-doc: Updating Management section files to RST  https://review.openstack.org/20522701:19
openstackgerritMerged openstack/security-doc: Convert tenant-data/case-studies to RST  https://review.openstack.org/20530301:19
openstackgerritMerged openstack/security-doc: Convert tenant-data/data-encryption to RST  https://review.openstack.org/20529801:19
openstackgerritMerged openstack/security-doc: Convert tenant-data/data-privacy-concerns to RST  https://review.openstack.org/20529701:19
*** markvoelker has joined #openstack-security01:25
*** bknudson has quit IRC01:58
*** sigmavirus24 is now known as sigmavirus24_awa02:05
*** sweston has quit IRC02:07
*** sweston has joined #openstack-security02:08
*** y_sawai has joined #openstack-security02:16
*** y_sawai has quit IRC02:19
*** salv-orlando has joined #openstack-security02:23
*** salv-orlando has quit IRC02:27
*** bpokorny has joined #openstack-security02:52
*** dave-mcc_ has joined #openstack-security02:58
*** dave-mccowan has quit IRC03:01
*** tmcpeak has quit IRC03:14
*** sdake has quit IRC03:28
*** sdake has joined #openstack-security03:30
*** markvoelker has quit IRC03:38
viraptorDaviey: it's a good bedtime story :)03:42
*** sdake has quit IRC03:46
openstackgerritMerged openstack/security-doc: conversion of dashboard https section to rst  https://review.openstack.org/20524603:48
openstackgerritMerged openstack/security-doc: Uploading networking ch file  https://review.openstack.org/20434103:48
*** salv-orlando has joined #openstack-security03:49
openstackgerritMerged openstack/security-doc: Conversion of Object Storage chapter to rst  https://review.openstack.org/20396503:55
*** salv-orlando has quit IRC03:55
openstackgerritMerged openstack/security-doc: Convert tenant-data/key-management to RST  https://review.openstack.org/20530004:03
*** markvoelker has joined #openstack-security04:03
*** bpokorny has quit IRC04:06
*** dave-mcc_ has quit IRC04:07
*** markvoelker has quit IRC04:08
*** y_sawai has joined #openstack-security04:46
*** y_sawai_ has joined #openstack-security05:04
*** markvoelker has joined #openstack-security05:04
*** y_sawai has quit IRC05:06
*** y_sawai_ has quit IRC05:06
*** markvoelker has quit IRC05:09
*** pdesai has joined #openstack-security05:09
openstackgerritMerged openstack/security-doc: Updating Identity section files to RST  https://review.openstack.org/20443505:10
*** pdesai has quit IRC05:22
*** salv-orlando has joined #openstack-security05:48
*** salv-orlando has quit IRC05:55
*** y_sawai has joined #openstack-security06:34
*** y_sawai has quit IRC06:45
*** salv-orlando has joined #openstack-security06:53
*** salv-orlando has quit IRC06:57
*** markvoelker has joined #openstack-security07:05
*** pcaruana has joined #openstack-security07:10
*** markvoelker has quit IRC07:10
*** pcaruana is now known as centos07:13
*** centos is now known as Guest5973007:13
*** Guest59730 is now known as pcaruana07:13
*** browne has quit IRC07:18
openstackgerritStanislaw Pitucha proposed openstack/security-specs: Add Anchor spec for parsing backend change  https://review.openstack.org/20532807:39
*** salv-orlando has joined #openstack-security08:20
*** salv-orlando has quit IRC08:25
*** y_sawai has joined #openstack-security08:43
*** y_sawai has quit IRC08:50
*** markvoelker has joined #openstack-security08:51
*** y_sawai has joined #openstack-security08:52
*** markvoelker has quit IRC08:56
openstackgerritDave Walker proposed openstack/security-doc: Convert security-boundaries-and-threats to RST  https://review.openstack.org/20477409:05
*** salv-orlando has joined #openstack-security09:22
*** y_sawai has quit IRC09:26
*** tkelsey has joined #openstack-security09:34
*** shohel has joined #openstack-security09:42
*** airen has quit IRC09:57
*** airen has joined #openstack-security09:57
*** y_sawai has joined #openstack-security09:58
*** y_sawai has quit IRC09:59
*** y_sawai has joined #openstack-security10:04
Davieyviraptor: around?10:07
*** y_sawai has quit IRC10:13
*** y_sawai has joined #openstack-security10:34
*** alex_klimov has joined #openstack-security10:49
*** alex_klimov has quit IRC10:49
*** alex_klimov has joined #openstack-security10:49
*** markvoelker has joined #openstack-security10:52
*** y_sawai has quit IRC10:53
*** markvoelker has quit IRC10:57
*** y_sawai has joined #openstack-security11:00
*** openstackgerrit has quit IRC11:01
*** openstackgerrit has joined #openstack-security11:01
*** woodrow has quit IRC11:26
*** woodrow has joined #openstack-security11:26
openstackgerritDoug Chivers proposed openstack/security-doc: Update Compliance section to RST  https://review.openstack.org/20509911:39
openstackgerritDoug Chivers proposed openstack/security-doc: Migrated monitoring and logging section.  https://review.openstack.org/20523311:47
*** dave-mccowan has joined #openstack-security11:49
openstackgerritTim Kelsey proposed openstack/bandit: Adding documentation  https://review.openstack.org/20549911:53
openstackgerritTim Kelsey proposed openstack/bandit: Adding documentation for configuration  https://review.openstack.org/20550112:05
openstackgerritTim Kelsey proposed openstack/bandit: Adding test plugin docs  https://review.openstack.org/20550512:18
*** y_sawai_ has joined #openstack-security12:18
openstackgerritTim Kelsey proposed openstack/bandit: Adding documentation framework  https://review.openstack.org/20549912:19
openstackgerritTim Kelsey proposed openstack/bandit: Adding documentation for configuration  https://review.openstack.org/20550112:19
openstackgerritTim Kelsey proposed openstack/bandit: Adding test plugin docs  https://review.openstack.org/20550512:19
openstackgerritTim Kelsey proposed openstack/bandit: Adding documentation for test plugins  https://review.openstack.org/20550512:21
*** y_sawai has quit IRC12:21
openstackgerritTim Kelsey proposed openstack/bandit: Adding documentation for test plugins  https://review.openstack.org/20550512:22
*** markvoelker has joined #openstack-security12:25
*** bknudson has joined #openstack-security12:48
*** browne has joined #openstack-security13:12
*** salv-orlando has quit IRC13:16
openstackgerritTim Kelsey proposed openstack/bandit: Revised XML tests  https://review.openstack.org/20552713:27
*** sdake has joined #openstack-security13:28
openstackgerritTim Kelsey proposed openstack/bandit: Revised XML tests  https://review.openstack.org/20552713:28
*** sdake_ has joined #openstack-security13:29
*** tristanC has quit IRC13:31
*** tristanC has joined #openstack-security13:32
*** sdake has quit IRC13:32
*** tmcpeak has joined #openstack-security13:39
*** sdake_ is now known as sdake13:47
*** dg_ has joined #openstack-security13:48
*** lexholden has joined #openstack-security13:55
*** edmondsw has joined #openstack-security13:56
*** browne has quit IRC14:05
openstackgerritMichael McCune proposed openstack/security-doc: Updating Compute chapter to RST  https://review.openstack.org/20391614:14
*** sigmavirus24_awa is now known as sigmavirus2414:23
*** browne has joined #openstack-security14:27
*** tkelsey has quit IRC14:32
*** voodookid has joined #openstack-security14:32
*** tkelsey has joined #openstack-security14:32
*** voodookid has quit IRC14:36
*** voodookid has joined #openstack-security14:51
openstackgerritTim Kelsey proposed openstack/bandit: Revised XML tests  https://review.openstack.org/20552714:58
*** dave-mccowan has quit IRC14:59
*** shohel has quit IRC15:01
openstackgerritDoug Chivers proposed openstack/security-doc: Update Compliance section to RST  https://review.openstack.org/20509915:01
*** shohel has joined #openstack-security15:01
*** tmcpeak has quit IRC15:03
*** tmcpeak has joined #openstack-security15:05
*** dwyde has joined #openstack-security15:09
*** sicarie_ has joined #openstack-security15:12
*** dave-mccowan has joined #openstack-security15:12
*** timkennedy has joined #openstack-security15:14
tmcpeakcan I bum some votes? :P   http://email.openstack.org/wf/click?upn=KDXUwHsqj2QOekTYbWDSGOQec3b75Fovt3HVvm3PiyFsTeh9f03Hig50WTaMW6Vh9UXoSwNRuH08K4E0EcoOIkw4vHH2-2B8q1HiFESJ3lLmm-2BEuahFdFy-2FSYdBXlYcZZ2_V2BEvbXc0o40l556bQTVbAlCmltWg-2BJY2MWR67Oeg-2FTKvxZmZg9UHGe5Iis91f3NpbdsLrdXxcbI-2B5RAOcW4e6kXYsS7jDHDvBUystRco0Kz-2FJgbDlBXdKkkc4OjX-2FPnCPIIai03YgUYxfl9l4JaGmnQwNted8LWjT7b8Z6Agcf193EazU5k7XHmwveljNBrp474rggfIhcMmmuj15:20
Davieytmcpeak: Hmm, it doesn't let you vote down?15:21
tmcpeakwow, that was a nasty URL, not malware, not rick-roll I promise :)15:21
tmcpeakDaviey: haha, actually 0 is the same as -1 we found out15:21
Davieytmcpeak: Ah perfect, thanks15:21
Davieytmcpeak: Although, that URL is 404'ing15:22
tmcpeakhah, dammit15:22
tmcpeaklet me get a better one15:22
tmcpeakhttps://www.openstack.org/summit/tokyo-2015/vote-for-speakers/Presentation/388615:22
tmcpeakwithout all the BS15:22
tmcpeak^15:22
elmikolol15:22
elmikonice looking talk15:23
tmcpeakthanks elmiko :)15:23
Davieyelmiko: Regarding the ^^^ header .. dg_ wants sicarie_ and I to arm wrestle over it. :)15:23
elmikoLOL15:23
elmikothe thing is, it really doesn't matter15:23
sicarie_Daviey: you were absolutely right about it - shoudl have been -'s15:23
elmikorst processing the headers in order, so it just looks for a different type of header then makes that the next one on the list15:24
sicarie_ha, nice15:24
elmikoso, even putting ^^^^ there doesn't make h4, it still makes h315:24
Davieysicarie_: Oh, well.. i wrote that without reading the history - so i assumed i missed something.15:24
openstackgerritDoug Chivers proposed openstack/security-doc: Update Compliance section to RST  https://review.openstack.org/20509915:24
elmikoi still want to see the arm wrestling =)15:24
sigmavirus24https://www.openstack.org/summit/tokyo-2015/vote-for-speakers/presentation/5027 looks intriguing too15:24
openstackgerritMichael McCune proposed openstack/security-doc: Updating Compute chapter to RST  https://review.openstack.org/20391615:25
elmikosigmavirus24: whaa...15:25
*** y_sawai_ has quit IRC15:25
*** y_sawai has joined #openstack-security15:25
sigmavirus24elmiko: yeah. I'm curious15:25
*** y_sawai has quit IRC15:25
elmikodid you get a 400 off that page?15:25
elmikooh, nvm. it reloaded15:26
Davieytmcpeak: Here have a +3.15:26
elmikoif you guys are curious about something not specifically security related, https://www.openstack.org/summit/tokyo-2015/vote-for-speakers/presentation/5333 =)15:27
sicarie_elmiko: +3!15:28
Davieysigmavirus24: That talk has a clickbaity title.. Might aswell say "Got Root?  Industry secret, Security Teams tried to supress this talk!"15:28
elmikosigmavirus24: i wonder if that "got root" talk has something to do with the horizon token vuln that was in the bug tracker15:28
elmikosicarie_: tnx!15:28
sigmavirus24elmiko: Daviey yeah, like I said, curious but it sounds very ... oversold15:29
sicarie_So I’m curious has anyone here seen a plugmgrid talk that wasn’t a sales pitch? Every talk from them that I see is pitching their product, and I see a few registered talks, but I’m hesitant to vote on them because I think it’ll just be a demo…15:29
elmikolol15:29
sigmavirus24sicarie_: I haven't watched one of their talks15:29
elmikoi have not15:29
sigmavirus24But they're pretty friendly15:29
Davieyelmiko: I'd hope not.. I thought we established that the token issue was mostly irrelevant to Horizon?15:29
* sigmavirus24 worked the Rackspace booth which was next to their booth in Vancouver15:29
elmikoDaviey: ok, cool, it looked like that from the comments but i didn't know15:29
Davieyelmiko: I assumed that talk was about getting deeper access to API's that aren't network exposed.15:30
sicarie_sigmavirus24: definitely nice guys, but every talk is based on openstack, but plumgrid specific (and therefore not quite as useful)15:30
sicarie_guess I’ll just skip voting on them for now15:30
Davieysicarie_: I had a meeting with them 18 months ago, expecting technical detail but was the wrong people..15:31
DavieyThey bought me lunch, so I'm not complaining.15:31
tmcpeakDaviey: thank you sir :)15:31
*** shohel has quit IRC15:31
Davieytmcpeak: I think the address you want to share is, https://www.openstack.org/summit/tokyo-2015/vote-for-speakers/SaveRating/?id=5027&rating=3 (note the last parameter)..   Not fully convinced it is a well designed system!15:32
sigmavirus24Daviey: lol15:33
Davieyoh dammit, that is for the clickbait talk.15:33
tmcpeakhaha15:33
tmcpeaksketchy ;)15:33
sigmavirus24good job Daviey15:33
elmikolol, awesome15:34
dg_lol15:34
dg_my next talk is going to have 'you wont guess what happened next' in the title15:34
tmcpeakdg_ : ++15:34
Davieydg_: YES!15:34
tkelseyDaviey: lol15:34
sicarie_Cloud Vendors Hate Him!15:35
tmcpeak"The government doesn't want you to know these five things about securing OpenStack"15:35
dg_someone really needs to write a clickbait blocker15:35
sicarie_I have to stop myself from reflexively downvoting any “X is dead, long live X!”15:36
Davieyusing simple tools such as /sbin/halt, we can show you how to make your deployment ultra secure.15:36
sicarie_haha15:36
dg_or at least a translator, to tell you what it really is, you know in case you REALLY need to know what happens next15:36
elmikoDaviey: LOL15:36
dg_Daviey +115:36
tmcpeakDaviey: lol15:37
openstackgerritMerged openstack/security-doc: Convert security-boundaries-and-threats to RST  https://review.openstack.org/20477415:38
sicarie_Ouch: https://www.openstack.org/summit/tokyo-2015/vote-for-speakers/presentation/618915:38
sicarie_(looking at the title & the 3rd speaker there)15:39
DavieyThings could be worse for OpenStack TBH, CloudStack recently made a change to their metadata service which cloud-init interprets to make every login password "HTTP/1.0 200 OK"... I am guessing that might cause some people to have a fun day.15:39
sicarie_wow15:39
elmikodg_: minor nit on https://review.openstack.org/#/c/205233/15:39
tmcpeakDaviey: wut15:40
elmikoyea, wtf...15:40
*** y_sawai has joined #openstack-security15:42
elmikosicarie_: we are so close on the doc conversion, nicely done =)15:43
sicarie_elmiko: I’ll be happier when I don’t own most of the -1’s in my own queue :\15:43
elmikolol, i hear ya15:44
Davieysicarie_: Oh, i noticed there is a roadmap.xml attached to you I almost hijacked to get completion... but i wondered if you left it as it probably doesn't belong in tree?15:44
sicarie_Daviey dg_ elmiko: I’ll be in and out all day today, please feel free to hijack one of my patches15:44
DavieyIt is an unreferenced TODO list, which makes more sense on a wiki IMO15:45
elmikosicarie_: ack15:45
sicarie_Daviey: yes, I was going to hold off on that for the end, though if you wanted to take it and note that we’re planning a new leaf version by the next summit, you could15:45
Davieysicarie_: You want it kept intree?15:46
sicarie_ehhh15:46
sicarie_undecided15:46
sicarie_I’d say add it, we can pull it later15:47
*** y_sawai has quit IRC15:47
sicarie_let’s aim for the ‘convert everything as-is” bar15:47
dg_elmiko good spot!15:48
Davieysicarie_: I assumed unreferenced rst files exploded the build.  Do i need to add a line to index.rst for it?15:49
dg_sicarie_ thanks, but I'm going to finish up for the day fairly soon15:49
sicarie_+1 dg_ thanks for the help!15:49
sicarie_Daviey: in that case, let’s hold off on it - I’ll ping AJeager and see how critical it is15:50
*** alex_klimov has quit IRC15:52
openstackgerritNathaniel Dillon proposed openstack/security-doc: Migrating Networking case studies  https://review.openstack.org/20530515:54
*** bpokorny has joined #openstack-security15:56
openstackgerritNathaniel Dillon proposed openstack/security-doc: Converting API endpoints section to RST  https://review.openstack.org/20389415:56
Davieysicarie_: Am i right in saying all content is now inflight, just blocking on niggles on review?15:56
sicarie_Daviey: I hope so :) I was going to address my -1’s and then validate the etherpad15:56
Daviey\o/15:56
*** bitblt has joined #openstack-security15:57
elmikosicarie_: i'll make a pass at the etherpad at the end of my day too. just for cleanup15:57
sicarie_elmiko: thanks!15:57
Davieysicarie_: So, you need to use h4 here? https://review.openstack.org/#/c/203894/7/security-guide-rst/source/api-endpoints/api-endpoint-configuration-recommendations.rst -----> ^^^^^^^ <---15:58
Daviey?15:58
sicarie_line 54?15:59
sicarie_(and 67)15:59
Davieyyeah16:00
DavieyUnrelated, here is the CloudStack password issue - now Public - https://launchpad.net/bugs/1464253  (surprised nobody raised a CVE TBH)16:01
openstackLaunchpad bug 1464253 in cloud-init (Ubuntu Vivid) "[SRU] CloudStack data source will always set password to "HTTP/1.0 200 OK" on CloudStack 4.5.1 and later" [Undecided,Fix committed] - Assigned to Dan Watkins (daniel-thewatkins)16:01
sicarie_Daviey: that was a comment by pdesai, I did not validate, but will make sure to check16:02
openstackgerritNathaniel Dillon proposed openstack/security-doc: Migrating Networking Architecture page  https://review.openstack.org/20532116:04
*** sdake has quit IRC16:06
elmikoDaviey: ooph on that bug16:06
openstackgerritNathaniel Dillon proposed openstack/security-doc: Updating Documentation section from DocBook to RST  https://review.openstack.org/20393316:07
sicarie_elmiko: considering rst will convert it anyway, do we want to just merge and open a bug? https://review.openstack.org/#/c/205233/216:08
elmikoyea, i don't mind. we can just merge and make another patch16:09
Davieyelmiko: I'm guessing it is unfixed in RHEL and friends, don't think it has been coordinated. :/16:09
elmikoDaviey: i was asking around some rh folks, sounds very inconvenient ;)16:10
elmikosicarie_: once that merges, i'll make a patch16:10
sicarie_+116:10
sicarie_elmiko: review? https://review.openstack.org/#/c/203916/16:11
elmikoi just don't want us to get sloppy because it's friday ;)16:11
Davieyelmiko: Good, i've done my good netcitzen by telling you and washing my hands of concern.16:11
elmikoDaviey: lol, +116:11
Davieysicarie_: Review inbound16:12
elmikosicarie_: i feel a little slimy about +A on that one since i uploaded to last patch...16:12
sicarie_Daviey: thanks!16:12
elmikooops, i workflowed that one16:12
sicarie_elmiko: cool, then I’ll do it16:12
sicarie_haha16:12
sicarie_nvm16:12
sicarie_I +2’d it just to show I’d looked at it as well16:13
elmikocool16:13
openstackgerritDoug Chivers proposed openstack/security-doc: Migrated monitoring and logging section.  https://review.openstack.org/20523316:13
sicarie_Oh +1 dg_ thought you were done for the day :)16:13
elmikooh nice, dg_ snuck a new patch in ;)16:14
elmikocheers!16:14
DavieyFlooding in commits Friday afternoon.16:14
elmikosicarie_: i'm gonna +A on that patch16:14
sicarie_elmiko: let’s start letting Jenkins verify before we +A16:15
sicarie_That got me in trouble yesterday :(16:15
elmikosicarie_: yea, that's probably for the best16:15
dg_sicarie_ really want to get those two merged! Probably not going to pick up anything new, one of the anchor users pointed out there wasnt any example code or documentation on how to use Anchor with Keystone for auth. Quick straw poll showed that no-one has actually tried using anchor with keystone auth...16:15
elmikogonna grab some lunch, i'll check the reviews when i get back16:15
dg_thanks elmiko16:16
DavieyIf Jenkins doesn't Verify, it won't merge anyway.  So it isn't that bad.16:16
elmikoDaviey: +116:16
Davieydg_: anchor users?  Projects become less fun with users.16:16
dg_yeah turns out all our marketing has worked.16:17
openstackgerritMerged openstack/security-doc: Update Compliance section to RST  https://review.openstack.org/20509916:17
Davieydg_: I'm thinking over the idea of a devstack plugin for Anchor, that would default to Keystone integration.  What do you think?16:19
openstackgerritMerged openstack/security-doc: Updating Compute chapter to RST  https://review.openstack.org/20391616:21
dg_Daviey that would be awesome16:23
*** bpokorny has quit IRC16:23
dg_would be very interesting to talk that over16:23
*** bpokorny has joined #openstack-security16:23
dg_im planning on spinning up devstack on monday and integrating cathead and anchor, but we'll see how that goes, because Im deep in contract review for something else16:24
*** lamisma has joined #openstack-security16:25
lamisma;-)16:26
lamisma;-):-[16:26
lamisma:16:26
tmcpeakdammit16:27
lamismaque lindo nombre16:27
*** ChanServ sets mode: +o tmcpeak16:28
*** lamisma was kicked by tmcpeak (lamisma)16:28
Davieydg_: Oh, if it is already on your road map - carry on. :).. But if you want to bounce an idea, let me know.16:28
elmikolol16:28
*** ChanServ sets mode: -o tmcpeak16:28
elmikotmcpeak: so, now we're getting smiley bombed?16:28
tmcpeakapparently, it's the new thing16:29
elmikostay classy anonymous spanish spammers ;)16:29
tmcpeaklol16:29
dg_Daviey it'd be cool to talk over it, because I have never attempted to integrate something into devstack! I'll just be hacking something together to check it actually works, and probably patching cathead in the process16:29
dg_lets talk on monday, RL is calling16:29
Davieyo/, have a good one16:30
sigmavirus24I had an IRCop in here the other day who klined a bunch of those spammers16:30
sigmavirus24Including the ones who PM you spam links16:30
dg_Daviey thanks, you too16:31
*** dg_ has quit IRC16:31
tmcpeaklamisma is spamming me emojis16:31
*** evandown has quit IRC16:32
*** evandown has joined #openstack-security16:32
sigmavirus24tmcpeak: in pms?16:33
tmcpeakyeah16:33
tmcpeakor was16:33
sigmavirus24tmcpeak: /ignore lamisma@*!*16:33
tmcpeaksigmavirus24: hmm, my client doesn't seem to understand that16:34
tmcpeakbut yeah, good point16:34
tmcpeakignore should work :)16:34
sigmavirus24don't you start spamming *me* emoji now tmcpeak =P16:36
tmcpeakhaha16:36
tmcpeakyou guys remember the command to fetch a review into a named local branch?16:36
*** browne has quit IRC16:37
tmcpeaknevermind, got it16:37
*** dwyde has quit IRC16:38
sigmavirus24tmcpeak: which command were you looking for?16:38
sigmavirus24review -d?16:39
*** dwyde has joined #openstack-security16:39
openstackgerritNathaniel Dillon proposed openstack/security-doc: Updating Documentation section from DocBook to RST  https://review.openstack.org/20393316:43
*** dwyde has quit IRC16:46
*** nkinder has joined #openstack-security16:48
tmcpeakI ended up just doing the git fetch in the review and then using git checkout -b to get it into a named branch16:49
openstackgerritNathaniel Dillon proposed openstack/security-doc: Migrating Networking Architecture page  https://review.openstack.org/20532116:51
*** voodookid has quit IRC16:55
sicarie_Daviey: I was mistaken, I have not done 3 of the networking sections16:56
sicarie_elmiko Daviey: care for one more conversion?16:56
*** tkelsey has quit IRC17:02
tmcpeakDaviey: I do get your point about config, I guess the idea behind config should be: unless somebody would want to change it, it doesn't belong in config17:05
tmcpeakand you're right - which XML libraries are unsafe shouldn't change17:05
tmcpeakI'm curious about the performance aspect of it17:05
Davieytmcpeak: I hadn't even thought of that part.17:06
openstackgerritNathaniel Dillon proposed openstack/security-doc: WIP Updating Network services section  https://review.openstack.org/20562417:06
*** sicarie_ has left #openstack-security17:06
Davieysicarie_: I'm not leaping off my chair to do it.. but if it isn't done by later, i may well do.17:06
*** voodookid has joined #openstack-security17:10
openstackgerritMerged openstack/security-doc: Migrated monitoring and logging section.  https://review.openstack.org/20523317:14
openstackgerritMerged openstack/security-doc: Converting API endpoints section to RST  https://review.openstack.org/20389417:16
tmcpeakDaviey: I think that was tkelsey's initial concern17:18
tmcpeakpresumably his change improved performance17:18
openstackgerritMerged openstack/security-doc: Migrating Networking case studies  https://review.openstack.org/20530517:19
Davieytmcpeak: Right, but i think it would be good to move the config hunks into the py file.17:19
openstackgerritPriti Desai proposed openstack/security-doc: Migrating Networking section to RST  https://review.openstack.org/20562817:20
*** dwyde has joined #openstack-security17:20
tmcpeakDaviey: yeah, I think what you're saying makes sense, and I'm glad you brought it up, we don't want bandit.yaml to balloon17:23
Davieycool17:25
elmikosigmavirus24: what did you have in mind?17:29
elmikooops, meant that for sicarie17:30
*** browne has joined #openstack-security17:30
*** tkelsey has joined #openstack-security17:31
openstackgerritPriti Desai proposed openstack/security-doc: Updating Documentation section from DocBook to RST  https://review.openstack.org/20393317:33
*** tkelsey has quit IRC17:36
openstackgerritMerged openstack/security-doc: Migrating Networking section to RST  https://review.openstack.org/20562817:44
tmcpeakoh, this is cool (looks like most of you were added anyway) https://review.openstack.org/#/c/205629/1/specs/no-global-admin.rst17:45
elmikointeresting...17:47
Davieysicarie: How come you are working with XML on https://review.openstack.org/#/c/205624/1 ?17:50
*** dwyde has quit IRC17:58
tmcpeakelmiko: oh yeah, good with the spelling errors - I didn't even look at those - I mean I saw them but I was too focused on "what is he saying" :)18:03
elmikotmcpeak: haha, yea i had to read it twice18:04
elmikoi just did some tweaking of the sahara policy stuff earlier in this cycle, so i was a little familiar with what adam is talking about.18:04
elmikobut it's still a bigger idea to understand18:05
tmcpeakyeah, I'm jumping feet first in (probs early next week) for that note I'm writing18:06
elmikonice18:06
elmikosicarie: i see i'm listed for case-studies-identity-management.xml (TODO), not sure what that refers to18:10
openstackgerritMerged openstack/security-doc: Updating Documentation section from DocBook to RST  https://review.openstack.org/20393318:12
openstackgerritMerged openstack/security-doc: Migrating Networking Architecture page  https://review.openstack.org/20532118:20
openstackgerritPriti Desai proposed openstack/security-doc: Migrating Networking section to RST  https://review.openstack.org/20564218:21
openstackgerritMichael McCune proposed openstack/security-doc: fixing todo in compute chapter  https://review.openstack.org/20564418:21
openstackgerritMichael McCune proposed openstack/security-doc: fixing todo in instance management chapter  https://review.openstack.org/20564518:28
openstackgerritPriti Desai proposed openstack/security-doc: Updating Network services section  https://review.openstack.org/20562418:44
openstackgerritMichael McCune proposed openstack/security-doc: fixing todo in data processing chapter  https://review.openstack.org/20566918:45
openstackgerritPriti Desai proposed openstack/security-doc: Updating Network services section  https://review.openstack.org/20562418:46
elmikosicarie: if you get a moment, could use a review on https://review.openstack.org/#/c/20564218:54
*** dwyde has joined #openstack-security19:00
sicarieelmiko: reviewed - I'll take a look at the idm case study thing19:00
sicarieDaviey: pdesai took it, I just attached you to the review19:01
elmikosicarie: thanks, i can clear up a few TODOs once that networking one merges19:02
elmikoso... close....19:03
openstackgerritMerged openstack/security-doc: fixing todo in compute chapter  https://review.openstack.org/20564419:08
openstackgerritMerged openstack/security-doc: Migrating Networking section to RST  https://review.openstack.org/20564219:08
*** KriSstaL has joined #openstack-security19:13
openstackgerritMichael McCune proposed openstack/security-doc: fixing todos in data processing config section  https://review.openstack.org/20568019:13
*** tjt263 has joined #openstack-security19:14
openstackgerritMichael McCune proposed openstack/security-doc: fixing todos in security services section  https://review.openstack.org/20568519:19
*** KriSstaL has left #openstack-security19:20
*** bitblt has quit IRC19:22
*** tkelsey has joined #openstack-security19:32
*** tkelsey has quit IRC19:37
*** lexholden has quit IRC20:04
*** KriSstaL has joined #openstack-security20:12
*** KriSstaL has left #openstack-security20:15
*** dwyde has quit IRC20:27
*** timkennedy has quit IRC20:51
*** salv-orlando has joined #openstack-security20:53
*** salv-orlando has quit IRC20:58
*** edmondsw has quit IRC21:06
*** sicarie_ has joined #openstack-security21:32
*** tkelsey has joined #openstack-security21:34
*** tkelsey has quit IRC21:38
*** dave-mccowan has quit IRC22:29
*** dave-mccowan has joined #openstack-security22:46
*** voodookid has quit IRC23:01
*** bpokorny_ has joined #openstack-security23:04
*** bpokorny has quit IRC23:07
*** tjt263_ has joined #openstack-security23:14
*** markvoelker has quit IRC23:15
*** tmcpeak has quit IRC23:23
viraptorDaviey: am now23:26

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!