*** gyee has quit IRC | 00:30 | |
*** dikonoor has joined #openstack-security | 00:37 | |
*** jamielennox is now known as jamielennox|away | 00:44 | |
*** salv-orlando has joined #openstack-security | 00:45 | |
*** salv-orlando has quit IRC | 00:54 | |
*** jamielennox|away is now known as jamielennox | 02:00 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/anchor master: Updated from global requirements https://review.openstack.org/438424 | 02:23 |
---|---|---|
openstackgerrit | OpenStack Proposal Bot proposed openstack/syntribos master: Updated from global requirements https://review.openstack.org/467210 | 02:38 |
*** salv-orlando has joined #openstack-security | 02:50 | |
*** salv-orlando has quit IRC | 03:02 | |
*** jamielennox is now known as jamielennox|away | 03:30 | |
*** unrahul has joined #openstack-security | 03:39 | |
*** salv-orlando has joined #openstack-security | 04:25 | |
*** salv-orlando has quit IRC | 04:37 | |
*** knangia_ has quit IRC | 04:43 | |
*** unrahul has quit IRC | 05:09 | |
*** gouthamr has quit IRC | 05:15 | |
*** rcernin has joined #openstack-security | 05:26 | |
*** markvoelker_ has joined #openstack-security | 05:27 | |
*** markvoelker has quit IRC | 05:28 | |
*** salv-orlando has joined #openstack-security | 05:33 | |
*** dikonoor has quit IRC | 06:25 | |
*** dikonoor has joined #openstack-security | 06:25 | |
*** aselius has quit IRC | 06:32 | |
*** salv-orlando has quit IRC | 06:35 | |
*** tesseract has joined #openstack-security | 07:04 | |
*** Serlex has joined #openstack-security | 07:09 | |
*** chas has joined #openstack-security | 07:26 | |
*** dikonoor has quit IRC | 07:28 | |
*** aselius has joined #openstack-security | 07:34 | |
*** jamielennox|away is now known as jamielennox | 08:21 | |
*** dikonoor has joined #openstack-security | 08:29 | |
*** jamielennox is now known as jamielennox|away | 08:49 | |
asettle | Morning hyakuhei | 08:54 |
asettle | I have a patch here: https://review.openstack.org/#/c/470059/1/security-guide/source/index.rst | 08:54 |
asettle | Regarding our discussion at the meeting last night | 08:55 |
*** dikonoor has quit IRC | 09:05 | |
*** chas_ has joined #openstack-security | 09:15 | |
*** chas has quit IRC | 09:19 | |
*** dikonoor has joined #openstack-security | 09:36 | |
*** aselius has quit IRC | 09:44 | |
*** salv-orlando has joined #openstack-security | 10:20 | |
*** dave-mccowan has joined #openstack-security | 11:03 | |
*** dikonoo has joined #openstack-security | 11:13 | |
*** dikonoor has quit IRC | 11:16 | |
*** salv-orlando has quit IRC | 11:29 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/anchor master: Updated from global requirements https://review.openstack.org/438424 | 11:31 |
*** liverpooler has joined #openstack-security | 12:07 | |
*** catintheroof has joined #openstack-security | 12:08 | |
*** chas_ has quit IRC | 12:25 | |
*** chas has joined #openstack-security | 12:25 | |
*** chas has quit IRC | 12:31 | |
*** vds has joined #openstack-security | 12:42 | |
*** salv-orlando has joined #openstack-security | 13:07 | |
*** chas has joined #openstack-security | 13:12 | |
*** chas has quit IRC | 13:16 | |
*** chas has joined #openstack-security | 13:18 | |
*** chas has quit IRC | 13:18 | |
*** chas has joined #openstack-security | 13:18 | |
*** salv-orl_ has joined #openstack-security | 13:27 | |
*** salv-orlando has quit IRC | 13:30 | |
*** gouthamr has joined #openstack-security | 13:51 | |
*** dikonoo has quit IRC | 14:14 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc master: Updated from openstack-manuals https://review.openstack.org/470313 | 14:41 |
*** catintheroof has quit IRC | 14:45 | |
openstackgerrit | Merged openstack/security-doc master: Updated from openstack-manuals https://review.openstack.org/470313 | 14:49 |
*** dwyde has joined #openstack-security | 15:03 | |
*** rcernin has quit IRC | 15:05 | |
*** gyee has joined #openstack-security | 15:27 | |
*** Serlex has quit IRC | 15:36 | |
*** salv-orl_ has quit IRC | 15:57 | |
*** tesseract has quit IRC | 16:00 | |
*** aselius has joined #openstack-security | 16:01 | |
*** unrahul has joined #openstack-security | 16:05 | |
*** chas has quit IRC | 16:09 | |
*** chas has joined #openstack-security | 16:10 | |
*** chas has quit IRC | 16:14 | |
*** pcaruana has quit IRC | 16:16 | |
*** dwyde has quit IRC | 16:32 | |
*** knangia_ has joined #openstack-security | 16:35 | |
*** liverpooler has quit IRC | 16:46 | |
*** liverpooler has joined #openstack-security | 16:46 | |
*** unrahul has quit IRC | 17:12 | |
*** unrahul has joined #openstack-security | 17:15 | |
*** vds has quit IRC | 17:27 | |
*** Serlex has joined #openstack-security | 17:29 | |
*** unrahul has quit IRC | 17:37 | |
*** dwyde has joined #openstack-security | 17:43 | |
*** unrahul has joined #openstack-security | 18:07 | |
*** chas has joined #openstack-security | 18:11 | |
*** dwyde has quit IRC | 18:13 | |
*** chas has quit IRC | 18:15 | |
*** catintheroof has joined #openstack-security | 18:38 | |
*** unrahul has quit IRC | 18:56 | |
*** catintheroof has quit IRC | 19:02 | |
*** gyee has quit IRC | 19:14 | |
*** lbragstad has joined #openstack-security | 19:15 | |
lbragstad | hey folks - i have a question I'd like to get a security perspective on | 19:16 |
lbragstad | keystone is debating the prospect of adding global role assignments | 19:17 |
lbragstad | which can be found here - https://review.openstack.org/#/c/464763/ | 19:17 |
*** gyee has joined #openstack-security | 19:17 | |
lbragstad | we're trying to find the line between usability and security with global role assignments, and if that is something we can/should advertise in an unscoped token request (which isn't associated to a project), or if we should require a separate scope called "global" | 19:18 |
lbragstad | traditionally - unscoped tokens have really only been useful for getting tokens scoped to various projects | 19:21 |
lbragstad | one of the proposals is to make unscoped tokens relay global scope information - meaning it should eventually be possible to do operations with unscoped tokens that you previously wouldn't be able to. | 19:22 |
lbragstad | my question is if there anything from a security perspective that raises red flags with that approach, or if we should require a new scope and leave unscoped tokens the way they are? | 19:23 |
*** unrahul has joined #openstack-security | 19:34 | |
*** chas has joined #openstack-security | 20:12 | |
*** rcernin has joined #openstack-security | 20:12 | |
*** chas has quit IRC | 20:16 | |
*** gouthamr has quit IRC | 20:41 | |
*** unrahul has quit IRC | 20:53 | |
*** salv-orlando has joined #openstack-security | 20:58 | |
*** gouthamr has joined #openstack-security | 21:00 | |
*** unrahul has joined #openstack-security | 21:11 | |
*** lbragstad has quit IRC | 21:22 | |
*** unrahul has quit IRC | 21:35 | |
*** Serlex has quit IRC | 21:45 | |
*** unrahul has joined #openstack-security | 21:49 | |
*** salv-orlando has quit IRC | 21:52 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/bandit master: Updated from global requirements https://review.openstack.org/470449 | 21:53 |
*** unrahul has quit IRC | 22:12 | |
*** chas has joined #openstack-security | 22:12 | |
openstackgerrit | Merged openstack/bandit master: Updated from global requirements https://review.openstack.org/470449 | 22:16 |
*** chas has quit IRC | 22:17 | |
*** lbragstad has joined #openstack-security | 22:18 | |
*** unrahul has joined #openstack-security | 22:19 | |
*** unrahul_ has joined #openstack-security | 22:34 | |
*** unrahul has quit IRC | 22:36 | |
*** rcernin has quit IRC | 22:39 | |
*** gouthamr has quit IRC | 22:40 | |
*** gouthamr has joined #openstack-security | 22:42 | |
*** unrahul has joined #openstack-security | 23:08 | |
*** unrahul_ has quit IRC | 23:11 | |
*** unrahul has quit IRC | 23:15 | |
*** unrahul has joined #openstack-security | 23:19 | |
*** shri has left #openstack-security | 23:35 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!