Friday, 2017-08-11

*** aselius has quit IRC00:32
*** tecnik has quit IRC01:03
*** markvoelker has joined #openstack-security01:03
*** tecnik has joined #openstack-security01:11
*** gyee has quit IRC01:14
*** gyee has joined #openstack-security01:14
*** murphy_zhao has quit IRC01:24
*** liujiong has joined #openstack-security01:32
*** vinaypotluri has quit IRC02:20
*** purp has quit IRC02:21
*** chyka has joined #openstack-security02:24
*** purp has joined #openstack-security02:24
*** austin_laptop has joined #openstack-security02:27
*** austin987 has quit IRC02:28
*** chyka has quit IRC02:28
*** dave-mccowan has quit IRC03:06
*** austin_laptop has quit IRC03:31
*** austin_laptop has joined #openstack-security03:32
*** murphy_zhao has joined #openstack-security04:27
*** liujiong_lj has joined #openstack-security04:33
*** liujiong has quit IRC04:35
*** gyee has quit IRC04:50
*** sudhirag0987 has joined #openstack-security05:29
*** murphy_zhao has quit IRC06:10
*** tesseract has joined #openstack-security06:16
*** rcernin has joined #openstack-security06:23
*** murphy_zhao has joined #openstack-security06:26
*** sxc731 has joined #openstack-security06:35
*** liujiong_lj is now known as liujiong06:47
*** sxc731 has quit IRC07:19
*** sxc731 has joined #openstack-security07:20
*** daidv has joined #openstack-security07:57
*** sudhirag0987 has quit IRC08:58
*** sxc731 has quit IRC09:07
*** markvoelker has quit IRC09:17
tristanCkencjohnston_: you can get fixed cve from the openstack/ossa repository, though this doesn't include severity09:18
*** daidv has quit IRC10:00
*** aym3ric has joined #openstack-security10:06
*** markvoelker has joined #openstack-security10:18
*** markvoelker has quit IRC10:23
*** liujiong has quit IRC10:27
*** markvoelker has joined #openstack-security10:39
*** aym3ric has quit IRC10:42
*** markvoelker_ has joined #openstack-security10:44
*** markvoelker has quit IRC10:44
*** markvoelker_ has quit IRC10:44
*** markvoelker has joined #openstack-security10:45
*** chyka has joined #openstack-security11:12
*** chyka has quit IRC11:17
*** liverpooler has joined #openstack-security11:45
*** dikonoor has joined #openstack-security11:49
dikonoorfungi:Hi11:50
dikonoorI am looking for information on enabling http compression and TLS compression with OpenStack services (running in Apache httpd which supports gzip encoding using the mod_deflate module)11:51
dikonoorWell.. Defense against CRIME and BREACH attacks recommend that compression be disabled but compression does help with performance improvement as the total traffic sent back from the server is considerably less11:52
dikonoorI am trying to understand if openstack security has any recommendations on this.11:53
*** sxc731 has joined #openstack-security12:02
*** d0048 has quit IRC12:07
*** markvoelker_ has joined #openstack-security12:10
*** markvoelker has quit IRC12:13
*** dikonoor has quit IRC12:15
*** dikonoor has joined #openstack-security12:16
*** gouthamr has joined #openstack-security12:20
*** purp has quit IRC12:21
*** dave-mccowan has joined #openstack-security12:25
*** purp has joined #openstack-security12:26
*** catintheroof has joined #openstack-security12:30
*** sxc731 has quit IRC12:47
*** sxc731 has joined #openstack-security13:10
*** dikonoo has joined #openstack-security13:11
*** dikonoor has quit IRC13:15
*** d0048 has joined #openstack-security13:17
*** sxc731 has quit IRC13:31
fungidikonoo: unless it's mentioned in https://docs.openstack.org/security-guide/ i don't really know. it's not a direct vulnerability in the software we produce so won't have any advisories at https://security.openstack.org/ossalist.html and the only ossn i can find of relevance is https://wiki.openstack.org/wiki/OSSN/OSSN-003713:34
fungiwhich is pretty brief and just about disabling compression13:35
fungi(and horizon-specific)13:35
*** markvoelker_ has quit IRC13:52
*** sxc731 has joined #openstack-security14:00
dikonoofungi : Thanks for getting back. There are public vulnerabilities available around this..14:13
fungidikonoo: i'm sure there are, but the vulnerability is in how the software is deployed, and not inherent to the software itself14:22
fungiperhaps that distinction is subtle to some14:22
fungiso in the case of OSSN-0037 the community has provided some example suggestions for how to configure django and apache or nginx to avoid crime/breach related issues with horizon, but we don't produce or distribute django, apache or nginx and are therefore not as well-placed to provide security recommendations around them as their own communities or collective distributions are14:25
*** mdavidson has quit IRC14:26
*** mdavidson has joined #openstack-security14:35
*** craigs__ has joined #openstack-security14:53
*** rcernin has quit IRC14:57
*** dikonoo has quit IRC15:02
*** sxc731 has quit IRC15:12
*** vds has quit IRC15:20
*** dikonoo has joined #openstack-security15:29
*** gyee has joined #openstack-security15:30
*** dikonoo has quit IRC15:33
*** sxc731 has joined #openstack-security15:34
*** chyka has joined #openstack-security15:37
*** chyka_ has joined #openstack-security15:41
*** dikonoo has joined #openstack-security15:42
*** chyka has quit IRC15:43
*** chyka has joined #openstack-security15:45
*** chyka_ has quit IRC15:46
*** aselius has joined #openstack-security15:51
*** dikonoo has quit IRC15:59
*** craigs__ has quit IRC16:14
*** dikonoo has joined #openstack-security16:17
*** aselius has quit IRC16:21
*** aselius has joined #openstack-security16:21
*** markvoelker has joined #openstack-security16:25
*** tesseract has quit IRC16:41
*** markvoelker has quit IRC16:59
*** dikonoor has joined #openstack-security17:21
*** dikonoo has quit IRC17:24
*** sxc731 has quit IRC17:47
*** markvoelker has joined #openstack-security17:55
*** robellison has joined #openstack-security17:57
*** markvoelker has quit IRC18:29
*** sxc731 has joined #openstack-security18:46
*** sxc731 has quit IRC18:47
*** aselius has quit IRC19:21
*** markvoelker has joined #openstack-security19:27
*** markvoelker has quit IRC19:59
*** gouthamr has quit IRC20:14
*** catintheroof has quit IRC20:15
*** gouthamr has joined #openstack-security20:33
*** dikonoor has quit IRC20:51
*** markvoelker has joined #openstack-security20:56
*** gyee has quit IRC21:02
*** dave-mccowan has quit IRC21:12
*** gyee has joined #openstack-security21:29
*** markvoelker has quit IRC21:30
*** markvoelker has joined #openstack-security22:10
*** lbragstad has quit IRC22:17
*** markvoelker has quit IRC22:33
*** chyka has quit IRC23:57

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!