Thursday, 2021-12-02

gagehugo#startmeeting security15:00
opendevmeetMeeting started Thu Dec  2 15:00:45 2021 UTC and is due to finish in 60 minutes.  The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot.15:00
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:00
opendevmeetThe meeting name has been set to 'security'15:00
gagehugo#link https://etherpad.opendev.org/p/security-agenda agenda15:01
gagehugoo/15:01
fungiohai15:02
gagehugofungi: you around?15:03
fungiyes15:03
fungiare you seeing me?15:04
fungigagehugo: connectivity problems?15:05
gagehugoyour messages just appeared for me15:08
gagehugoo/15:08
fungisounds like oftc may have some lag between servers15:09
gagehugohmm maybe15:09
gagehugoNothing on the agenda, seems to have been a quiet month15:11
fungiyeah, there was some clarification obtained in the cinder meeting on forward progress for the image encryption effort15:11
fungialso the "trojan source" vulnerability ate a lot of discussion bandwidth in general15:12
fungifips testing is coming along, being disucssed in the tc meeting right now15:12
fungialso the opendev collaboratory has made a quiet/soft announcement about how to start using 2fa with launchpad/ubuntuone15:14
gagehugooh neat15:15
fungi#link http://lists.opendev.org/pipermail/service-discuss/2021-December/000304.html UbuntuOne/Launchpad two-factor authentication15:15
fungiper earlier messages in that thread, several of us have been trying it for more than a year now15:16
gagehugoI still have the items from the PTG on my todo list, I'll try to get to those this month.15:17
fungiyeah, i think i got some minor site updates pushed up15:17
gagehugohow's it working so far?15:17
fungican't remember if those merged before the last meeting or before this one15:17
fungiteh 2fa? no problems at all. i enrolled totp slots in two of my librem key devices and have been using those15:18
fungii spent more time working out viable command-line access (they're modified nitrokeys, but needs a very new nitrocli build to recognize them)15:19
gagehugoah ok15:19
fungii think clarkb is using google authenticator on an android phone15:19
fungii don't recall if ianw said what he's using15:19
fungianyway, follow up to that service-discuss thread if anyone wants to talk about it more15:20
fungioh, also we retooled the artifact signing key generation/rotation/attestation process for openstack releases15:20
fungibasically coping with the collapse of the sks keyserver network and switching to keys.openpgp.org15:21
fungisince no well-connected keyservers still carry third-party key signatures, we've moved to more of a caff-style attestation process, where you checkout the public key from git, import it, sign that, re-export it with your new signature and the ones which were already on it, commit that and push it for review15:22
fungipreviously we only included the self-sig in the export (since that's what sets the expiration)15:23
fungi#link https://docs.opendev.org/opendev/system-config/latest/signing.html Signing System15:23
gagehugohmm15:24
fungithat documentation is up to date, with the exception of the attestation section which we're still finalizing15:24
gagehugogood to know15:25
gagehugofungi: anything else you want to discuss?15:30
funginah, sucked into python 3.6 deprecation discussion in the tc meeting15:31
gagehugothanks for the updates! Have a good holiday if I don't talk you to before then!15:32
fungithanks, you too!15:33
gagehugo#endmeeting15:33
opendevmeetMeeting ended Thu Dec  2 15:33:05 2021 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:33
opendevmeetMinutes:        https://meetings.opendev.org/meetings/security/2021/security.2021-12-02-15.00.html15:33
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/security/2021/security.2021-12-02-15.00.txt15:33
opendevmeetLog:            https://meetings.opendev.org/meetings/security/2021/security.2021-12-02-15.00.log.html15:33
*** priteau is now known as Guest738816:38
*** priteau_ is now known as priteau16:38

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!