Thursday, 2015-09-24

openstackgerritStanislaw Pitucha proposed openstack/anchor: Remove useless tests  https://review.openstack.org/22343600:12
openstackgerritStanislaw Pitucha proposed openstack/anchor: Add EKU extension validator  https://review.openstack.org/22340300:14
openstackgerritStanislaw Pitucha proposed openstack/anchor: Add EKU extension validator  https://review.openstack.org/22340300:24
*** d0ugal has quit IRC00:35
*** d0ugal has joined #openstack-security00:40
*** d0ugal is now known as Guest6585300:40
*** edmondsw has quit IRC00:46
*** sdake has joined #openstack-security01:03
*** tjt263 has quit IRC01:45
*** bpokorny has quit IRC01:57
*** sdake has quit IRC02:06
*** Canaimera-georg1 has joined #openstack-security02:20
Canaimera-georg1;-)02:21
Canaimera-georg1:'(02:23
Canaimera-georg1=-O02:27
*** Canaimera-georg1 has left #openstack-security02:27
*** tjt263 has joined #openstack-security02:36
*** salv-orl_ has joined #openstack-security02:59
*** salv-orlando has quit IRC03:02
*** tkelsey has joined #openstack-security04:09
*** tkelsey has quit IRC04:15
*** firebait has joined #openstack-security04:26
*** thehoffau has joined #openstack-security04:27
*** firebait has quit IRC04:27
openstackgerritStanislaw Pitucha proposed openstack/anchor: Add audit  https://review.openstack.org/22710804:43
openstackgerritStanislaw Pitucha proposed openstack/anchor: Add audit  https://review.openstack.org/22710804:49
*** sdake has joined #openstack-security04:54
*** dave-mccowan has quit IRC05:00
*** thehoffau has quit IRC05:00
openstackgerritStanislaw Pitucha proposed openstack/anchor: Add audit  https://review.openstack.org/22710805:00
*** airen has quit IRC05:24
*** airen has joined #openstack-security05:25
*** sdake has quit IRC05:40
*** tmcpeak has joined #openstack-security06:08
*** markvoelker has quit IRC06:27
*** Guest65863 has joined #openstack-security06:45
Guest65863freeBid is a online auction and ecommerce solution for both private and business sellers a great alternative with zero listing fees. http://www.theluxbay.com sell online free06:45
*** Guest65863 is now known as luxbay06:48
*** salv-orl_ has quit IRC06:55
*** salv-orlando has joined #openstack-security06:56
*** browne has quit IRC07:07
*** luxbay has quit IRC07:10
*** alex_klimov has joined #openstack-security07:22
*** markvoelker has joined #openstack-security07:28
*** markvoelker has quit IRC07:33
*** jamielennox is now known as jamielennox|away07:53
*** Guest65853 is now known as d0ugal08:08
*** d0ugal has quit IRC08:08
*** d0ugal has joined #openstack-security08:08
*** tkelsey has joined #openstack-security08:12
*** jkf has quit IRC08:14
*** jkf_ has joined #openstack-security08:15
*** jkf_ is now known as jkf08:15
*** tmcpeak1 has joined #openstack-security08:40
*** tmcpeak has quit IRC08:40
*** Trident has quit IRC08:57
*** alex_klimov has quit IRC09:02
openstackgerritMerged openstack/bandit: Fixing bug introduced by manager refactor  https://review.openstack.org/22683209:24
*** markvoelker has joined #openstack-security09:29
openstackgerritMerged openstack/bandit: Increasing coverage of try-except-pass to 100%  https://review.openstack.org/22074209:31
openstackgerritMerged openstack/bandit: Increasing coverage of try-except-pass to 100%  https://review.openstack.org/22074209:31
*** markvoelker has quit IRC09:34
*** alex_klimov has joined #openstack-security09:40
*** salv-orlando has quit IRC10:40
*** salv-orlando has joined #openstack-security10:40
*** dave-mccowan has joined #openstack-security10:57
openstackgerritTim Kelsey proposed openstack/bandit: Adding docs for blacklist_imports test  https://review.openstack.org/22723311:11
*** tmcpeak1 has quit IRC11:19
*** markvoelker has joined #openstack-security11:30
*** markvoelker has quit IRC11:34
tkelseythanks elmiko11:36
openstackgerritTim Kelsey proposed openstack/bandit: Adding docs for blacklist_imports test  https://review.openstack.org/22723311:38
elmikonp tkelsey, just a small one ;)11:38
tkelseyyup :) good spot11:38
tkelseyupdated11:38
*** Emo_Girl has joined #openstack-security12:05
Emo_Girlla12:06
Emo_Girlhola*12:07
*** Emo_Girl has left #openstack-security12:07
*** Emo_Girl has joined #openstack-security12:08
Emo_Girlhola12:08
*** Emo_Girl has left #openstack-security12:09
*** alex_klimov has quit IRC12:24
*** markvoelker has joined #openstack-security12:31
*** edmondsw has joined #openstack-security12:32
*** jamielennox|away is now known as jamielennox12:37
*** alex_klimov has joined #openstack-security12:53
*** alejandrito has joined #openstack-security13:14
*** jhfeng has joined #openstack-security14:06
*** dave-mccowan has quit IRC14:15
*** jamielennox is now known as jamielennox|away14:26
openstackgerritMichael Xin proposed openstack/security-doc: Adding an OSSN for bug 1456228 - Trusted VM powered on untrusted host  https://review.openstack.org/22026314:35
openstackbug 1456228 in OpenStack Security Notes "Trusted vm can be powered on untrusted host" [Medium,Confirmed] https://launchpad.net/bugs/1456228 - Assigned to Michael Xin (michael-xin)14:35
*** dave-mccowan has joined #openstack-security14:36
*** tjt263 has quit IRC14:39
*** salv-orlando has quit IRC14:41
*** salv-orlando has joined #openstack-security14:41
openstackgerritMerged openstack/anchor: Remove useless tests  https://review.openstack.org/22343614:52
openstackgerritMerged openstack/anchor: Fix all the doc build paths  https://review.openstack.org/22088114:54
*** jhfeng has quit IRC14:55
*** browne1 has joined #openstack-security14:59
*** jhfeng has joined #openstack-security15:03
*** voodookid has joined #openstack-security15:04
*** ccneill has joined #openstack-security15:07
*** dwyde has joined #openstack-security15:08
*** Windir has quit IRC15:08
openstackgerritMichael Xin proposed openstack/security-doc: Adding an OSSN for bug 1456228 - Trusted VM powered on untrusted host  https://review.openstack.org/22026315:08
openstackbug 1456228 in OpenStack Security Notes "Trusted vm can be powered on untrusted host" [Medium,Confirmed] https://launchpad.net/bugs/1456228 - Assigned to Michael Xin (michael-xin)15:08
*** yaya has joined #openstack-security15:22
*** bpokorny has joined #openstack-security15:26
*** salv-orlando has quit IRC15:28
ccneillhey folks, quick question for you: would anyone consider this bug worthy of CVE? https://bugs.launchpad.net/designate/+bug/149703115:40
openstackLaunchpad bug 1497031 in Designate "Authenticated Denial of Service in Blacklists" [High,Fix released] - Assigned to Kiall Mac Innes (kiall)15:40
elmikogmurphy, tristanC ^^15:41
openstackgerritDoug Chivers proposed openstack/security-specs: Added spec for seperating Anchor validation  https://review.openstack.org/22738415:41
elmikoccneill: not really sure what qualifies for a CVE, but that seems like you would need to control the server first to create the blacklist. is that accurate?15:42
ccneillyep, gotta be an admin15:42
ccneilland you have to create a dumb blacklist regex too15:42
elmikoright15:42
elmikohonestly, i'm not sure about the CVE. it sounds like maybe no, but i don't know the VMT process well enough15:43
elmikohopefully one of them will respond15:43
elmiko =)15:44
*** yaya_ has joined #openstack-security15:44
gmurphydesignate isn't currently one of the projects that are vulnerability managed (http://governance.openstack.org/reference/tags/vulnerability_managed.html)15:44
gmurphyso the vmt process doesn't handle it15:44
gmurphybut anyway…15:44
ccneillah, so I should email oss-sec with a cc to mitre maybe?15:45
gmurphyis the default configuration vulnerable?15:45
gmurphyor do you have to shoot yourself in the foot..15:45
ccneillwell.. vulnerable in the sense that someone could go in and add a bad blacklist15:45
ccneillnot vulnerable in the sense that there is a default blacklist that will crash the server15:45
gmurphyhmm.. i probably would classify it as C1 under this https://security.openstack.org/vmt-process.html#incident-report-taxonomy15:46
gmurphyNot considered a practical vulnerability (but some people might assign a CVE for it)15:46
*** yaya has quit IRC15:47
*** yaya_ is now known as yaya15:47
ccneillyeah, I'd agree15:47
gmurphyso i think definitely a security note..15:47
gmurphymaybe not for the cve.. you could ask mitre if you like15:48
*** jhfeng has quit IRC15:52
*** gabriela has joined #openstack-security15:53
ccneillI'll email oss-sec and cc mitre. what's the process for proposing a new OSSN?15:53
gmurphycan add a ossn task to the lp bug.15:54
gmurphythen this - https://wiki.openstack.org/wiki/Security/Security_Note_Process15:54
gabrielahol<a15:54
*** jhfeng has joined #openstack-security15:54
ccneillgmurphy: how does one add the OSSN task? "Also affects project"?15:57
gmurphyyep15:57
gmurphythen search for ossn15:57
gmurphyor security note15:57
gmurphysomething like that15:57
tristanCccneill: last time I tried, blacklist update needs admin access right ?16:01
ccneillyep16:01
tristanCthen yes, I agree with gmurphy, this qualify as a C1 type of bug16:05
ccneillcool, I just added the "also-affects OSSN"16:05
ccneillnot sure what has to happen for it to take effect16:05
*** yaya has quit IRC16:11
gmurphyccneill: https://bugs.launchpad.net/ossn <- it shows up in this list now16:11
ccneillaha16:11
ccneillnice16:11
gmurphyso then people from security group can pick it up and start working on it16:11
gmurphyetc.16:11
ccneillcool cool16:13
*** yaya has joined #openstack-security16:15
*** markvoelker_ has joined #openstack-security16:21
*** markvoelker has quit IRC16:24
*** mihero_ has quit IRC16:24
*** mihero has joined #openstack-security16:25
*** yaya has quit IRC16:26
*** gabriela has quit IRC16:26
*** yaya has joined #openstack-security16:36
*** yaya has quit IRC16:39
*** alex_klimov has quit IRC16:47
*** browne1 has quit IRC16:49
*** singlethink has joined #openstack-security16:54
*** bpokorny_ has joined #openstack-security17:25
*** bpokorny has quit IRC17:25
*** salv-orlando has joined #openstack-security17:29
*** sassymaribel has joined #openstack-security17:34
*** sassymaribel has left #openstack-security17:35
*** browne has joined #openstack-security17:40
*** bpokorny_ has quit IRC17:55
*** bpokorny has joined #openstack-security17:55
*** ccneill has quit IRC17:57
*** tkelsey has quit IRC18:00
*** dwyde has quit IRC18:02
*** ccneill has joined #openstack-security18:03
*** bpokorny has quit IRC18:10
*** bpokorny has joined #openstack-security18:10
*** salv-orlando has quit IRC18:15
*** Mn3m0n1k has joined #openstack-security18:40
*** gabriela2 has joined #openstack-security18:41
*** gabriela2 has left #openstack-security18:42
openstackgerritPriti Desai proposed openstack/security-doc: Adding Security Checklist  https://review.openstack.org/22529118:46
*** austin987 has quit IRC18:51
*** gabriela2 has joined #openstack-security18:52
*** gabriela2 has left #openstack-security18:54
*** yaya has joined #openstack-security19:08
*** tjt263 has joined #openstack-security19:32
*** jhfeng has quit IRC19:32
*** jhfeng has joined #openstack-security19:33
*** yaya has quit IRC19:36
*** Mn3m0n1k has quit IRC19:45
*** alejandrito has quit IRC19:53
*** yaya has joined #openstack-security20:05
*** alex_klimov has joined #openstack-security20:09
*** salv-orlando has joined #openstack-security20:19
*** salv-orlando has quit IRC20:22
*** jhfeng has quit IRC20:24
*** su_zhang has joined #openstack-security20:24
*** jhfeng has joined #openstack-security20:31
*** salv-orlando has joined #openstack-security20:35
*** salv-orlando has quit IRC20:35
*** yaya_ has joined #openstack-security20:36
*** salv-orlando has joined #openstack-security20:36
*** yaya has quit IRC20:37
*** yaya_ is now known as yaya20:37
*** yaya has quit IRC20:46
*** yaya has joined #openstack-security20:48
*** timkennedy has quit IRC20:48
*** dave-mccowan has quit IRC20:58
*** edmondsw has quit IRC21:02
*** gabriela has joined #openstack-security21:33
*** gabriela has left #openstack-security21:33
*** alejandrito has joined #openstack-security21:41
*** gabriela has joined #openstack-security21:46
*** gabriela has left #openstack-security21:46
*** yaya has quit IRC21:56
*** jhfeng has quit IRC22:03
*** austin987 has joined #openstack-security22:24
*** tjt263 has quit IRC22:31
*** su_zhang has quit IRC22:37
*** dave-mccowan has joined #openstack-security22:47
*** singlethink has quit IRC22:53
*** voodookid has quit IRC23:02
*** alejandrito has quit IRC23:03
*** alex_klimov has quit IRC23:04
*** markvoelker_ has quit IRC23:04
openstackgerritStanislaw Pitucha proposed openstack/anchor: Don't accept unknown extensions  https://review.openstack.org/22297023:07
*** ccneill has quit IRC23:34
*** agireud has quit IRC23:42
*** evandown has quit IRC23:55
*** evandown has joined #openstack-security23:55
*** jamielennox|away is now known as jamielennox23:56

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!