Monday, 2018-03-19

*** salv-orl_ has joined #openstack-security02:51
*** salv-orlando has quit IRC02:53
*** rcernin_ has joined #openstack-security03:23
*** rcernin has quit IRC03:25
*** rcernin_ has quit IRC03:29
*** rcernin has joined #openstack-security03:29
*** rcernin has quit IRC03:33
*** rcernin has joined #openstack-security03:49
*** mihero has left #openstack-security04:20
*** openstackgerrit has quit IRC05:49
*** d0ugal has joined #openstack-security07:00
*** d0ugal has quit IRC07:00
*** d0ugal has joined #openstack-security07:00
*** rcernin has quit IRC07:07
*** pcaruana has joined #openstack-security07:39
*** AlexeyAbashkin has joined #openstack-security07:54
*** liujiong has joined #openstack-security07:56
*** tesseract has joined #openstack-security08:17
*** vds has joined #openstack-security08:20
*** jaosorior has joined #openstack-security08:40
*** salv-orl_ has quit IRC09:09
*** salv-orlando has joined #openstack-security09:09
*** salv-orlando has quit IRC09:14
*** uhscinawa has joined #openstack-security09:21
*** uhscinawa has quit IRC09:22
*** liujiong has quit IRC09:59
*** salv-orlando has joined #openstack-security11:05
*** edmondsw has joined #openstack-security11:14
*** edmondsw has quit IRC11:18
*** edmondsw has joined #openstack-security12:15
*** atoth has joined #openstack-security12:18
*** casynfinatic has joined #openstack-security12:30
*** tobberydberg_ has joined #openstack-security12:30
*** tobberydberg_ has quit IRC12:35
*** liverpooler has joined #openstack-security12:39
*** liverpooler has quit IRC12:40
*** liverpooler has joined #openstack-security12:40
*** salv-orlando has quit IRC14:32
*** salv-orlando has joined #openstack-security14:33
*** salv-orlando has quit IRC14:46
*** salv-orlando has joined #openstack-security14:47
*** salv-orlando has quit IRC14:51
*** chyka has joined #openstack-security14:55
*** atoth has quit IRC15:04
*** atoth has joined #openstack-security15:05
*** liverpooler has quit IRC15:08
*** liverpooler has joined #openstack-security15:26
*** chyka has quit IRC15:30
*** chyka has joined #openstack-security15:30
*** jhfeng has joined #openstack-security15:49
*** jhfeng has quit IRC15:52
*** markvoelker_ has joined #openstack-security15:56
*** markvoelker has quit IRC15:56
*** markvoelker has joined #openstack-security15:59
*** jhfeng has joined #openstack-security16:00
*** markvoelker_ has quit IRC16:01
*** salv-orlando has joined #openstack-security16:05
*** pcaruana has quit IRC16:07
*** salv-orlando has quit IRC16:09
*** salv-orlando has joined #openstack-security16:18
*** gyee has joined #openstack-security16:49
*** dikonoor has joined #openstack-security16:51
*** AlexeyAbashkin has quit IRC16:51
dikonoorfungi: Hi fungi. I have a query around sudo and OpenStack. Would this be the right channel to ask this query16:54
fungidikonoor: as good a place as any, probably16:54
dikonoorfungi: Sure. I am not sure if there has been any discussion around this, which can be shared. This is basically about OpenStack tight coupling with sudo via oslo rootwrap or privsep. I believe both of them uses sudo16:55
fungithat sounds right16:56
dikonoorfungi: Even though sudo seems to be the most common escalated privilege mechanism that gets used, enterprises are moving towards other advanced solutions that provides support for centralized tracking, version management and lot of other features.16:57
fungihave you read the docs for them both? https://docs.openstack.org/oslo.rootwrap/ and https://docs.openstack.org/oslo.privsep/16:57
fungiactually, their documentation seems to be pretty sparse16:58
dikonoorI did read them both last day but is there something that you think I might have missed reading in this regard ?16:58
dikonooroslo rootwrap documentation is good..it explains how sudo gets used16:59
dikonoorprivsep is sparse16:59
funginope, i'm not deeply familiar with either of them (and i'm not a developer of openstack services which use them, nor do i regularly deploy/manage such services)16:59
fungithere are likely some people in here who have a firmer grasp of how they're used in various services, but if you're looking to discuss changing their backend implementation the #openstack-oslo channel might be a more appropriate place to reach the maintainers of those libraries17:00
dikonoorok. the basic problem here is that OpenStack is tightly coupled with sudo at the moment and I am exploring if there are any options to use anything other than sudo. I am sure there would be others who would have run into a similar problem but I can't find any threads / discussions around this17:01
dikonoorPerhaps I should try asking this in the oslo channel as well.17:01
fungido you have an example sudo alternative you're considering? i'm aware of the doas took in openbsd but beyond that not terribly familiar with sudo alternatives17:02
fungier, s/took/tool/17:02
fungihttps://man.openbsd.org/doas17:03
dikonoorfungi : I haven't used one myself..but I am aware that there are tools/softwares like PowerBroker and BOKS etc that offer to provide more advanced features compared to sudo17:03
fungihave a link to the source code for either of those? i'm interested to take a look at how they're implemented17:03
fungilooks like http://www.foxt.com/ may be the people who make boks17:05
fungithough seems to be closed/proprietary software from what i can tell17:05
dikonooryeah..both of them seem to be proprietary..17:07
fungihard to evaluate the merits of either, i'm afraid17:07
dikonoorhttps://www.beyondtrust.com/blog/you-could-be-sudoing-better-introducing-powerbroker-for-sudo/17:07
fungii guess https://www.beyondtrust.com/ is the company making powerbroker17:07
fungiyeah, just found it17:07
dikonoorthese software give a provision for centralized sudoer files, logging, monitoring , auditing , policy etc..17:08
fungibut anyway, if the question is about making oslo.privsep (oslo.rootwrap is mostly deprecated at this point i think) support pluggable backend drivers, the feasibility of that is probably a discussion for #openstack-oslo17:09
dikonooryeah..right..Let me check there..17:09
fungiit's worth noting that /etc/sudoers was originally designed with the idea that you could maintain one central copy of policy and then distribute that to multiple systems17:10
fungiwhich is why sudoers supports host matching (though people rarely rely on that usage model in practice)17:10
dikonoorok..good to know that..but copying around the file to many systems could be a pain..Also, the root in each system could go and make local changes17:12
*** d0ugal has quit IRC17:21
*** dikonoor has quit IRC17:45
*** tesseract has quit IRC18:07
fungiyep, i think its design recalls a time when all your servers had one central set of root admins responsible for configuring and maintaining your systems, who further delegated some "safe" commands their users could run18:14
fungiand also things like /etc (or even / in its entirety) consumed over nfs18:14
*** AlexeyAbashkin has joined #openstack-security18:20
*** AlexeyAbashkin has quit IRC18:24
*** dave-mccowan has joined #openstack-security18:27
*** AlexeyAbashkin has joined #openstack-security19:20
*** AlexeyAbashkin has quit IRC19:24
*** atoth has quit IRC19:29
*** liverpooler has quit IRC19:36
*** jhfeng has quit IRC19:39
*** jhfeng has joined #openstack-security19:39
*** jhfeng has quit IRC19:42
*** jhfeng has joined #openstack-security19:45
*** jhfeng has quit IRC19:49
*** jhfeng has joined #openstack-security20:14
*** jhfeng has quit IRC20:19
*** jhfeng has joined #openstack-security20:20
*** AlexeyAbashkin has joined #openstack-security20:21
*** jhfeng has quit IRC20:25
*** AlexeyAbashkin has quit IRC20:26
*** jhfeng has joined #openstack-security20:46
*** jhfeng has quit IRC20:55
*** Canaimero-e64b1 has joined #openstack-security21:25
*** Canaimero-e64b1 has quit IRC21:26
*** jessegler has joined #openstack-security21:27
*** gyee has quit IRC21:50
*** AlexeyAbashkin has joined #openstack-security22:20
*** AlexeyAbashkin has quit IRC22:25
*** rcernin has joined #openstack-security22:34
*** edmondsw has quit IRC22:49
*** AlexeyAbashkin has joined #openstack-security23:20
*** AlexeyAbashkin has quit IRC23:24
*** chyka has quit IRC23:30
*** chyka has joined #openstack-security23:31
*** jessegler has quit IRC23:52

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!