*** tmcpeak has quit IRC | 00:02 | |
*** bdpayne has joined #openstack-security | 00:36 | |
*** rcernin has quit IRC | 00:50 | |
*** bpokorny has quit IRC | 01:04 | |
*** bpokorny has joined #openstack-security | 01:05 | |
*** prometheanfire has joined #openstack-security | 01:07 | |
prometheanfire | bandit had a release (tag) but it's not in pypi yet | 01:08 |
---|---|---|
chair6 | i noticed that too, prometheanfire.. probably something that tmcpeak will need to check on | 01:21 |
*** tjt263 has joined #openstack-security | 01:22 | |
prometheanfire | ya, was l looking for him here | 01:22 |
prometheanfire | I had a user that wanted it two hours after it came out (packaged that is) | 01:23 |
prometheanfire | https://bugs.gentoo.org/show_bug.cgi?id=568484 | 01:23 |
openstack | bugs.gentoo.org bug 568484 in Applications "=dev-python/bandit-0.17.0 version bump" [Normal,Confirmed] - Assigned to prometheanfire | 01:23 |
chair6 | crikey.. demanding users :) | 01:25 |
prometheanfire | :D | 01:26 |
*** bdpayne has quit IRC | 01:43 | |
*** bpokorny_ has joined #openstack-security | 02:12 | |
*** browne has quit IRC | 02:12 | |
*** bpokorny has quit IRC | 02:16 | |
*** bpokorny_ has quit IRC | 02:16 | |
*** tmcpeak has joined #openstack-security | 02:25 | |
*** elo has quit IRC | 03:01 | |
*** browne has joined #openstack-security | 03:13 | |
*** evand_ has joined #openstack-security | 03:20 | |
*** evand has quit IRC | 03:20 | |
*** evand_ is now known as evand | 03:20 | |
*** jamielennox is now known as jamielennox|away | 03:26 | |
*** jamielennox|away is now known as jamielennox | 03:31 | |
*** dave-mccowan has quit IRC | 03:34 | |
*** [_Bill_] has joined #openstack-security | 03:36 | |
*** [_Bill_] has left #openstack-security | 03:36 | |
openstackgerrit | Michael Xin proposed openstack/syntribos: Update tox.ini to include venv and add .gitreview https://review.openstack.org/258790 | 04:12 |
*** tmcpeak has quit IRC | 04:25 | |
*** bpokorny has joined #openstack-security | 05:08 | |
*** bpokorny has quit IRC | 05:49 | |
*** SEXY has joined #openstack-security | 06:13 | |
SEXY | hola q tal | 06:14 |
SEXY | airen | 06:14 |
*** SEXY has left #openstack-security | 06:16 | |
*** shohel has joined #openstack-security | 06:59 | |
openstackgerrit | Jamie Finnigan proposed openstack/bandit: Remove show_progress_every from Bandit config file https://review.openstack.org/258834 | 07:00 |
openstackgerrit | venkatamahesh proposed openstack/security-doc: Fix rst markups https://review.openstack.org/258846 | 07:27 |
*** gocrazy has quit IRC | 07:53 | |
*** browne has quit IRC | 08:15 | |
*** rcernin has joined #openstack-security | 08:26 | |
*** rcernin has quit IRC | 08:40 | |
*** rcernin has joined #openstack-security | 08:41 | |
*** evand has quit IRC | 09:10 | |
*** evand has joined #openstack-security | 09:12 | |
*** evand has quit IRC | 09:16 | |
openstackgerrit | Merged openstack/bandit: Add docs for formatters https://review.openstack.org/258696 | 09:25 |
openstackgerrit | Merged openstack/anchor: Replace assertEqual(None, *) with assertIsNone in tests https://review.openstack.org/258394 | 09:28 |
*** salv-orlando has joined #openstack-security | 09:28 | |
*** evand has joined #openstack-security | 09:42 | |
*** openstackgerrit has quit IRC | 09:47 | |
*** openstackgerrit has joined #openstack-security | 09:47 | |
*** shakamunyi has quit IRC | 10:20 | |
*** shakamunyi has joined #openstack-security | 10:21 | |
*** superflyy has quit IRC | 10:21 | |
*** barra204 has joined #openstack-security | 10:21 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/anchor: Add spec for CMC + related rfcs https://review.openstack.org/255106 | 10:41 |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Adding test IDs https://review.openstack.org/258938 | 10:43 |
*** salv-orlando has quit IRC | 11:08 | |
*** salv-orlando has joined #openstack-security | 11:11 | |
*** salv-orlando has quit IRC | 11:12 | |
*** salv-orlando has joined #openstack-security | 11:12 | |
*** salv-orl_ has joined #openstack-security | 11:15 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Adding new screen formatter https://review.openstack.org/250764 | 11:17 |
*** salv-orlando has quit IRC | 11:18 | |
*** shohel has quit IRC | 11:32 | |
*** Pic_Sky has joined #openstack-security | 11:42 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Adding new screen formatter https://review.openstack.org/250764 | 11:47 |
*** evand has quit IRC | 11:48 | |
*** evand has joined #openstack-security | 11:57 | |
*** rcernin has quit IRC | 12:00 | |
*** Pic_Sky has quit IRC | 12:01 | |
*** evand has quit IRC | 12:03 | |
*** rcernin has joined #openstack-security | 12:15 | |
*** evand has joined #openstack-security | 12:40 | |
*** salv-orl_ has quit IRC | 13:04 | |
*** salv-orlando has joined #openstack-security | 13:09 | |
*** dave-mccowan has joined #openstack-security | 13:09 | |
*** rcernin has quit IRC | 13:21 | |
*** evand has quit IRC | 13:22 | |
*** evand has joined #openstack-security | 13:22 | |
*** evand_ has joined #openstack-security | 13:30 | |
*** nkinder has quit IRC | 13:38 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:39 | |
*** markvoelker has quit IRC | 14:21 | |
*** markvoelker has joined #openstack-security | 14:29 | |
*** dslev has joined #openstack-security | 15:01 | |
*** evand_ has quit IRC | 15:02 | |
*** tmcpeak has joined #openstack-security | 15:19 | |
*** timkennedy has joined #openstack-security | 15:23 | |
michaelxin | hi, guys | 15:31 |
michaelxin | Sorry that our team will not make to today's IRC meeting. | 15:31 |
michaelxin | We will have a team out. | 15:31 |
tmcpeak | michaelxin: cool, no worries | 15:32 |
tmcpeak | see you guys.. new year? | 15:33 |
michaelxin | yup. It is our holiday party before everyone takes off. | 15:33 |
elmiko | ooh, nice | 15:33 |
elmiko | michaelxin: have fun! | 15:34 |
michaelxin | elmiko: Thanks. | 15:34 |
michaelxin | tmcpeak: If the release of the project failed, how can I re-try? Thanks. | 15:38 |
tmcpeak | michaelxin: release of the project? | 15:42 |
michaelxin | http://docs.openstack.org/infra/manual/creators.html | 15:43 |
michaelxin | Trying to do an initial release for syntribos to pypi. | 15:43 |
michaelxin | I followed their instructions | 15:44 |
michaelxin | To verify that the release machinery works, push a signed tag to the “gerrit” remote. Use the smallest version number possible. If this is the first release, use “0.1.0”. If other releases of the project exist, choose an appropriate next version number | 15:44 |
michaelxin | $ git tag -s -m "descriptive message" $version | 15:44 |
michaelxin | $ git push gerrit $version | 15:44 |
tmcpeak | and it failed? | 15:44 |
michaelxin | It failed because of my tox.ini | 15:45 |
michaelxin | Is there a way to re-try it after fixing tox.ini? | 15:45 |
tmcpeak | which specific step failed though? | 15:45 |
michaelxin | http://logs.openstack.org/33/338b14b030a6557c3010db0d895e09ab78053ee8/release/syntribos-tarball/f1aaf10/console.html | 15:45 |
michaelxin | missing a defintion in tox.ini | 15:46 |
tmcpeak | can you just type the comment "recheck" in gerrit? | 15:46 |
michaelxin | tmcpeak: Will try it. | 15:50 |
openstackgerrit | Michael Xin proposed openstack/syntribos: Update tox.ini to include venv and add .gitreview https://review.openstack.org/258790 | 15:58 |
*** jhfeng has joined #openstack-security | 16:04 | |
*** gocrazy has joined #openstack-security | 16:21 | |
*** bpokorny has joined #openstack-security | 16:29 | |
prometheanfire | tmcpeak: bandit was released but not to pypi? | 16:31 |
tmcpeak | prometheanfire: it should be on pypi too | 16:31 |
tmcpeak | prometheanfire: oh crap, interesting | 16:31 |
prometheanfire | :D | 16:31 |
tmcpeak | I've got to ask the CI guys about that | 16:31 |
tmcpeak | thanks for pointing that out | 16:32 |
prometheanfire | have fun, thanks :D | 16:32 |
*** browne has joined #openstack-security | 16:38 | |
*** tkelsey has joined #openstack-security | 16:48 | |
*** tmcpeak has quit IRC | 16:51 | |
*** hyakuhei has joined #openstack-security | 17:03 | |
*** salv-orl_ has joined #openstack-security | 17:15 | |
*** salv-orlando has quit IRC | 17:18 | |
*** shohel has joined #openstack-security | 17:22 | |
*** elo has joined #openstack-security | 17:27 | |
*** jhfeng has quit IRC | 17:28 | |
*** jhfeng has joined #openstack-security | 17:30 | |
*** hyakuhei has quit IRC | 17:48 | |
*** jhfeng has quit IRC | 17:58 | |
*** browne has quit IRC | 18:09 | |
chair6 | i do quite like how the new gerrit makes the in-line comments visible on the main review screen.. | 18:16 |
sigmavirus24 | chair6: also related branches are all linked from each review's screen | 18:16 |
openstackgerrit | Merged openstack/bandit: Remove show_progress_every from Bandit config file https://review.openstack.org/258834 | 18:24 |
*** nkinder has joined #openstack-security | 18:41 | |
*** browne has joined #openstack-security | 18:55 | |
*** dslev has quit IRC | 19:22 | |
*** zul has quit IRC | 19:25 | |
*** zul has joined #openstack-security | 19:27 | |
*** c00p3r has quit IRC | 19:35 | |
*** c00p3r has joined #openstack-security | 19:38 | |
*** c00p3r has quit IRC | 19:40 | |
*** c00p3r has joined #openstack-security | 19:40 | |
*** salv-orl_ has quit IRC | 20:01 | |
*** hansw_ has joined #openstack-security | 20:08 | |
hansw_ | Hi all, anyone able to answer some questions regarding security audits? | 20:09 |
elmiko | potentially | 20:12 |
hansw_ | Ok, let's give it a shot. Currently we have a situation with another product. Scanned it with nessus and found issues. We are wondering if there have been larger projects (openstack) where nessus found lots of issues. We are even looking for a system (remote) we might be able to scan to see how openstack holds up. | 20:15 |
elmiko | i don't think i've heard of anyone using nessus against openstack | 20:15 |
elmiko | doesn't mean people aren't trying, but i don't think it is on the security project's radar currently | 20:16 |
elmiko | hansw_: i see that nessus is a for-pay product, do they have an open source offering as well? | 20:17 |
hansw_ | I would love to have a go at it, not to break it but to get an idea of how well it is. | 20:17 |
elmiko | sure | 20:17 |
elmiko | i'll bet the security project would love to hear reports back from anyone who runs nessus against an openstack installation | 20:18 |
hansw_ | Jups, a paid one, I am sure kali would have found simular issues | 20:18 |
hansw_ | I would be able to scan, but only with a written agreement from the owner :-) | 20:18 |
elmiko | ah, ok | 20:19 |
elmiko | might be worth sending an email to the openstack operators mailing list to see if anyone would be interested in participating | 20:19 |
hansw_ | Might ask someone from Fairbanks in the Netherlands to give permission | 20:19 |
elmiko | otherwise, i suppose you could run it against a devstack installation, but that's hardly got security tuning out of the box | 20:20 |
elmiko | likewise, you could play with something like the RDO installer to stand up a stack, then run | 20:20 |
*** shohel has quit IRC | 20:20 | |
hansw_ | Yes, suppose so. But I am looking for an alternative product (preferably opensource). Just need to make a case before I would bring it to manegemant | 20:21 |
hansw_ | damn English, sorry for the mistakes :-) | 20:21 |
elmiko | no worries, you write english quite well =) | 20:22 |
elmiko | ah, ok | 20:22 |
elmiko | are you trying to convince management to use openstack and need a security audit first? | 20:22 |
hansw_ | Switching 3 times a day between Dutch, English and German | 20:22 |
elmiko | ooph, better than i would do ;) | 20:23 |
hansw_ | That might be the idea yes | 20:23 |
elmiko | well, i don't think we have any published audits available. it is similar to a topic we have been discussing, namely threat analysis of openstack | 20:24 |
hansw_ | And yes, as a whitehat I would first contact the team, and not bring it out as zero days | 20:24 |
elmiko | if you are interested, here are our sites that contain most of our information about the security project practices (including vulnerability assessment) | 20:24 |
hansw_ | hmm, might be interesting. | 20:24 |
elmiko | https://security.openstack.org/ | 20:24 |
*** markvoelker has quit IRC | 20:24 | |
elmiko | https://wiki.openstack.org/wiki/Security | 20:25 |
elmiko | not sure if you've seen those | 20:25 |
hansw_ | Been reading that one this evening, that is why I am here :-) | 20:25 |
elmiko | cool! | 20:25 |
hansw_ | Been to some of the openstack meetings too. | 20:25 |
elmiko | ooh nice =) | 20:25 |
hansw_ | The problem was they never discuss security there. | 20:26 |
elmiko | yea, it's been getting more and more attention over the last year | 20:26 |
elmiko | we've had a bunch of good security related sessions at the last 2 openstack summits | 20:26 |
*** jhfeng has joined #openstack-security | 20:26 | |
hansw_ | I will contact the fairbanks people and see if we can make a case there. | 20:27 |
elmiko | sadly, we just had our last meeting for the year, but if you want more engagement we have a security related mailing list you could post questions to, and our next meeting will be in the new year | 20:27 |
hansw_ | I am sure they have enough demo place to setup | 20:27 |
elmiko | k, good luck! | 20:28 |
hansw_ | Thanks for the info, might lurk a bit more in here :-) | 20:28 |
elmiko | please do, we are open to the public =) | 20:28 |
*** jhfeng has quit IRC | 20:32 | |
*** timkennedy has quit IRC | 20:36 | |
hansw_ | thnx | 20:36 |
*** tkelsey has quit IRC | 20:36 | |
elmiko | np | 20:40 |
*** dave-mccowan has quit IRC | 20:50 | |
*** salv-orl_ has joined #openstack-security | 21:06 | |
*** tkelsey has joined #openstack-security | 21:07 | |
*** dave-mccowan has joined #openstack-security | 21:13 | |
*** dave-mcc_ has joined #openstack-security | 21:15 | |
*** dave-mccowan has quit IRC | 21:18 | |
*** markvoelker has joined #openstack-security | 21:25 | |
*** jhfeng has joined #openstack-security | 21:27 | |
*** markvoelker has quit IRC | 21:30 | |
*** browne has quit IRC | 21:36 | |
*** browne has joined #openstack-security | 21:41 | |
*** jhfeng has quit IRC | 21:43 | |
*** hansw_ has quit IRC | 21:50 | |
*** tmcpeak has joined #openstack-security | 22:02 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Adding Bandit Baseline Tox Target https://review.openstack.org/259202 | 22:24 |
*** bpokorny_ has joined #openstack-security | 22:25 | |
*** bpokorny has quit IRC | 22:28 | |
*** alejandrito has joined #openstack-security | 22:32 | |
*** markvoelker has joined #openstack-security | 22:33 | |
*** tjt263 has quit IRC | 22:37 | |
tmcpeak | prometheanfire: it's fixed now :) | 22:43 |
prometheanfire | tmcpeak: yep, packaged already :p | 22:43 |
tmcpeak | wow, you're fast | 22:43 |
prometheanfire | did it 4 hours ago :P | 22:44 |
tmcpeak | I guess the fire in your name is deserved | 22:44 |
openstackgerrit | Merged openstack/bandit: Adding Bandit Baseline Tox Target https://review.openstack.org/259202 | 22:44 |
*** tkelsey has quit IRC | 22:57 | |
tmcpeak | sigmavirus24: you around? | 23:00 |
sigmavirus24 | tmcpeak: totes | 23:00 |
tmcpeak | lol | 23:00 |
sigmavirus24 | what's up buddy? | 23:00 |
tmcpeak | the tox target I just added for Bandit is not doing good things | 23:00 |
sigmavirus24 | In 259202? | 23:01 |
tmcpeak | yeah | 23:01 |
tmcpeak | it can't find the Bandit config file | 23:01 |
tmcpeak | so it seems like it isn't installing Bandit properly in the tox environment | 23:01 |
sigmavirus24 | O_o | 23:01 |
tmcpeak | the bandit config file is the bane of my existence | 23:02 |
sigmavirus24 | lol | 23:02 |
chair6 | totes | 23:02 |
tmcpeak | any ideas? | 23:02 |
*** tkelsey has joined #openstack-security | 23:02 | |
*** yuanying has joined #openstack-security | 23:12 | |
sigmavirus24 | tmcpeak: I'm looking | 23:13 |
sigmavirus24 | (sorry, trying to also unwedge glance's gate) | 23:13 |
tmcpeak | sigmavirus24: cool, thanks man | 23:13 |
tmcpeak | :D | 23:13 |
*** tkelsey has quit IRC | 23:16 | |
*** bpokorny_ has quit IRC | 23:17 | |
*** bpokorny has joined #openstack-security | 23:17 | |
*** dave-mcc_ has quit IRC | 23:23 | |
*** ccneill has joined #openstack-security | 23:24 | |
sigmavirus24 | tmcpeak: so there's no etc. directory created in the virtualenv directory | 23:27 |
sigmavirus24 | i wonder | 23:27 |
tmcpeak | right, there definitely should be though, right? | 23:27 |
sigmavirus24 | well, I think I know what's happening | 23:28 |
sigmavirus24 | I'm just confirm | 23:28 |
sigmavirus24 | *confirming | 23:28 |
sigmavirus24 | tmcpeak: question, why can't a git repo be dirty? | 23:29 |
sigmavirus24 | Yep figured it out | 23:30 |
tmcpeak | sigmavirus24: because it's changing branches, unstaged changes would be wiped out | 23:30 |
* sigmavirus24 will push a review | 23:30 | |
sigmavirus24 | tmcpeak: is there a bug? | 23:30 |
tmcpeak | sigmavirus24: you are awesome | 23:30 |
tmcpeak | a bug? | 23:30 |
sigmavirus24 | for this work | 23:30 |
sigmavirus24 | or should I push a review sans bug? | 23:30 |
prometheanfire | sigmavirus24: hi | 23:30 |
tmcpeak | oh, yeah, should probably file a bug | 23:30 |
sigmavirus24 | prometheanfire: I'm on vacation. Get out of here :P | 23:31 |
prometheanfire | :P | 23:31 |
sigmavirus24 | prometheanfire: want to build a bug tracker for me? | 23:31 |
prometheanfire | who takes 'vacation' | 23:31 |
prometheanfire | LOL, nope | 23:31 |
sigmavirus24 | s/for/with/ | 23:31 |
prometheanfire | I don't think we'd be satisfied with anything, too many other systemic problems | 23:32 |
sigmavirus24 | prometheanfire: no I know | 23:35 |
prometheanfire | I love those meetings, talking in circles... | 23:36 |
sigmavirus24 | tmcpeak: bug#? | 23:41 |
tmcpeak | sigmavirus24: hang on, I'll file one | 23:42 |
tmcpeak | sigmavirus24: https://bugs.launchpad.net/bandit/+bug/1527415 | 23:43 |
openstack | Launchpad bug 1527415 in Bandit "Tox not installing Bandit correctly" [Undecided,New] | 23:43 |
openstackgerrit | Ian Cordasco proposed openstack/bandit: Fix codesec tox env https://review.openstack.org/259225 | 23:44 |
sigmavirus24 | tmcpeak: ^ | 23:44 |
*** tjt263 has joined #openstack-security | 23:44 | |
tmcpeak | sigmavirus24: you sir, are a freaking genius | 23:45 |
sigmavirus24 | tmcpeak: no | 23:45 |
sigmavirus24 | not a genius | 23:45 |
sigmavirus24 | just sadly experienced in the ways of python packaging | 23:45 |
sigmavirus24 | and all of its associated pain | 23:45 |
tmcpeak | it's a good thing somebody is | 23:46 |
tmcpeak | I have NFI about these things | 23:46 |
sigmavirus24 | And we thought we got spammed severely here, https://github.com/github/developer.github.com/pull/933#issuecomment-165614580 | 23:47 |
sigmavirus24 | quick before github deletes all of those comments | 23:47 |
tmcpeak | loool | 23:50 |
tmcpeak | "I need a new organization do you want to be my organization ?" | 23:50 |
tmcpeak | my new favorite pickup line | 23:50 |
elmiko | dude, wtf... | 23:50 |
sigmavirus24 | lmao | 23:53 |
sigmavirus24 | GitHub gets so much spam | 23:53 |
elmiko | i never realized | 23:53 |
openstackgerrit | Merged openstack/bandit: Fix codesec tox env https://review.openstack.org/259225 | 23:55 |
*** ccneill has quit IRC | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!