Tuesday, 2017-11-28

*** salv-orlando has quit IRC00:12
*** salv-orlando has joined #openstack-security00:13
*** AlexeyAbashkin has joined #openstack-security00:17
*** salv-orlando has quit IRC00:17
*** AlexeyAbashkin has quit IRC00:21
*** liverpooler has joined #openstack-security01:11
*** salv-orlando has joined #openstack-security01:14
*** salv-orlando has quit IRC01:19
*** liujiong has joined #openstack-security01:23
*** chyka_ has quit IRC01:29
*** dave-mccowan has joined #openstack-security01:36
*** aselius has quit IRC02:08
*** chyka has joined #openstack-security02:13
*** salv-orlando has joined #openstack-security02:15
*** AlexeyAbashkin has joined #openstack-security02:16
*** chyka has quit IRC02:18
*** salv-orlando has quit IRC02:21
*** AlexeyAbashkin has quit IRC02:21
*** gagehugo has quit IRC02:42
*** gyee_ has quit IRC02:55
*** dave-mccowan has quit IRC03:12
*** dave-mccowan has joined #openstack-security03:13
*** dave-mcc_ has joined #openstack-security03:16
*** salv-orlando has joined #openstack-security03:17
*** dave-mccowan has quit IRC03:18
*** salv-orlando has quit IRC03:23
*** AlexeyAbashkin has joined #openstack-security04:16
*** salv-orlando has joined #openstack-security04:19
*** chyka has joined #openstack-security04:21
*** AlexeyAbashkin has quit IRC04:21
*** salv-orlando has quit IRC04:25
*** chyka has quit IRC04:26
*** gouthamr has quit IRC04:31
*** liverpooler has quit IRC04:36
*** dave-mcc_ has quit IRC04:42
*** threestrands has quit IRC05:10
*** threestrands has joined #openstack-security05:10
*** threestrands has quit IRC05:10
*** threestrands has joined #openstack-security05:10
*** threestrands has quit IRC05:12
*** threestrands has joined #openstack-security05:12
*** threestrands has quit IRC05:12
*** threestrands has joined #openstack-security05:12
*** salv-orlando has joined #openstack-security05:20
*** salv-orlando has quit IRC05:27
*** pcaruana has joined #openstack-security06:06
*** pcaruana has quit IRC06:06
*** salv-orlando has joined #openstack-security06:22
*** salv-orlando has quit IRC06:28
*** salv-orlando has joined #openstack-security06:49
*** salv-orlando has quit IRC06:50
*** salv-orlando has joined #openstack-security06:50
*** gagehugo has joined #openstack-security06:51
*** threestrands has quit IRC07:04
*** vds has joined #openstack-security07:14
*** spectr has joined #openstack-security07:18
*** spectr has quit IRC07:21
*** BR5C003Y_D00 has joined #openstack-security07:48
*** BR5C003Y_D00 has quit IRC07:51
*** AlexeyAbashkin has joined #openstack-security07:52
*** rcernin has quit IRC07:53
*** d0ugal has joined #openstack-security07:55
*** pcaruana has joined #openstack-security08:28
*** vds has quit IRC08:35
*** vds_ has joined #openstack-security08:35
*** AlexeyAbashkin has quit IRC08:48
*** AlexeyAbashkin has joined #openstack-security08:51
*** murphy_zhao has quit IRC09:17
*** vds_ has quit IRC09:26
*** salv-orlando has quit IRC09:33
*** salv-orlando has joined #openstack-security09:33
*** salv-orlando has quit IRC09:38
*** openstackgerrit has quit IRC09:48
*** rcernin has joined #openstack-security09:55
*** chyka has joined #openstack-security09:57
*** chyka has quit IRC10:02
*** vds_ has joined #openstack-security10:22
*** murphy_zhao has joined #openstack-security10:26
*** vds_ has quit IRC10:32
*** openstackgerrit has joined #openstack-security10:59
openstackgerritMerged openstack/bandit master: Migrate to zuul V3  https://review.openstack.org/52245810:59
*** salv-orlando has joined #openstack-security11:01
*** vds has joined #openstack-security11:02
*** liujiong has quit IRC11:07
*** salv-orlando has quit IRC11:07
*** salv-orlando has joined #openstack-security11:08
*** salv-orlando has quit IRC11:13
*** salv-orlando has joined #openstack-security11:14
*** vds has quit IRC11:17
*** chyka has joined #openstack-security11:47
*** chyka has quit IRC11:51
*** vds has joined #openstack-security12:02
*** d0ugal has quit IRC12:04
*** d0ugal has joined #openstack-security12:08
*** pgomes has joined #openstack-security12:13
*** dave-mccowan has joined #openstack-security13:06
*** liverpooler has joined #openstack-security13:06
*** edmondsw has joined #openstack-security13:22
*** salv-orlando has quit IRC13:57
*** pcaruana has quit IRC14:13
*** pcaruana has joined #openstack-security14:17
*** pgomes has left #openstack-security14:32
*** salv-orlando has joined #openstack-security14:51
*** salv-orl_ has joined #openstack-security14:56
*** salv-orlando has quit IRC14:59
*** d0ugal has quit IRC15:28
*** d0ugal has joined #openstack-security15:42
*** gouthamr has joined #openstack-security15:45
*** gagehugo has quit IRC16:05
*** gagehugo has joined #openstack-security16:26
*** salv-orlando has joined #openstack-security16:28
*** salv-orl_ has quit IRC16:31
*** salv-orlando has quit IRC16:42
*** salv-orlando has joined #openstack-security16:42
*** salv-orlando has quit IRC16:46
*** AlexeyAbashkin has quit IRC16:49
*** chyka has joined #openstack-security16:56
*** pcaruana has quit IRC17:53
*** aselius has joined #openstack-security18:09
*** liverpooler has quit IRC18:25
*** liverpooler has joined #openstack-security18:28
*** AlexeyAbashkin has joined #openstack-security18:35
*** AlexeyAbashkin has quit IRC18:40
*** AlexeyAbashkin has joined #openstack-security18:56
*** AlexeyAbashkin has quit IRC19:04
*** salv-orlando has joined #openstack-security19:17
*** ssathaye has quit IRC19:45
*** ssathaye has joined #openstack-security19:46
*** solus has quit IRC19:50
*** gouthamr_ has joined #openstack-security19:53
*** gouthamr has quit IRC19:56
*** pcaruana has joined #openstack-security20:21
*** edmondsw_ has joined #openstack-security20:52
*** edmondsw has quit IRC20:56
*** gouthamr_ is now known as gouthamr21:21
*** pcaruana has quit IRC21:21
*** edmondsw_ is now known as edmondsw21:27
*** rcernin has quit IRC21:33
*** liverpooler has quit IRC21:37
*** liverpooler has joined #openstack-security21:38
*** openstack has joined #openstack-security21:43
*** ChanServ sets mode: +o openstack21:43
*** rcernin has joined #openstack-security22:23
*** edmondsw has quit IRC22:36
*** edmondsw has joined #openstack-security22:39
dave-mccowanmhayden ping22:40
mhaydenhowdy22:40
dave-mccowanmhayden: i have a quick question on file permissions in the security guide, if you have a sec.22:40
dave-mccowansome chapters say config files (cinder.conf) should have owner of root, group of cinder.22:41
dave-mccowansome chapters (keystone) say owner and group of keystone (not root).22:41
mhaydenthat's unusual22:41
dave-mccowanany thoughts on right/wrong/better?22:41
mhaydeni'm trying to think of a situation where that's necessary22:41
mhaydenwell, i guess if you're setting something like 0640 on the files, that's better than allowing everyone to read22:42
dave-mccowanmhayden it seems slightly more secure (root to write a config file, service user can only read)...22:43
mhaydenallowing nova to have group ownership of its own config files allows nova to read it but nobody else22:43
mhaydenwell, if /etc/nova/nova.conf is root:nova and 0640, then root can read/write, and nova can read22:43
mhaydennobody else can read it22:43
mhayden(or write)22:43
*** edmondsw has quit IRC22:43
mhaydenif you made it root:root, then you'd have to open the permissions up to 064422:44
mhaydenwhich allows anyone to read it22:44
dave-mccowanyep.  that's the recommendation (root:nova 640).  do you think that's better (or just different) than nova:nova 640 ?22:44
mhaydenwell nova should never have write access to its own config file22:45
mhaydenonly root22:45
mhaydenand nova should be running as the nova user22:45
mhaydeni just had to sit and think about the reasoning for a minute ;)22:46
dave-mccowanmhayden yep.  it makes sense.  the big question... if you had a system that did it the other way (nova:nova 640), would you patch it? :-)22:48
mhaydenfor sure ;)22:49
mhaydenopenstack-ansible ensures those permissions are set each time it runs22:49
* mhayden just checked22:49
dave-mccowanmhayden thanks!22:51
*** lbragstad has quit IRC23:17
*** edmondsw has joined #openstack-security23:18
*** edmondsw has quit IRC23:23
*** lbragstad has joined #openstack-security23:24
*** salv-orl_ has joined #openstack-security23:37
*** salv-orlando has quit IRC23:40
*** lbragstad has quit IRC23:56

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!