Thursday, 2022-06-02

opendevreviewJeremy Stanley proposed openstack/ossa master: repos-overseen: VMT is happy to assist any project  https://review.opendev.org/c/openstack/ossa/+/84444413:02
opendevreviewJeremy Stanley proposed openstack/ossa master: Drop references for the old security blog  https://review.opendev.org/c/openstack/ossa/+/84445113:17
opendevreviewJeremy Stanley proposed openstack/security-doc master: Use permalink for Barbican security analysis  https://review.opendev.org/c/openstack/security-doc/+/84446814:43
fungiremember, our monthly security sig meetings begins in 15 minutes!14:45
opendevreviewJeremy Stanley proposed openstack/security-analysis master: Retirement Step 2: Remove Project Content  https://review.opendev.org/c/openstack/security-analysis/+/84449014:49
fungijust a heads up, my broadband connection decided to die just before the top of the hour, so i'll be chairing the meeting from a wireless modem15:04
fungiapologies for the delay15:04
fungi#startmeeting security15:05
opendevmeetMeeting started Thu Jun  2 15:05:05 2022 UTC and is due to finish in 60 minutes.  The chair is fungi. Information about MeetBot at http://wiki.debian.org/MeetBot.15:05
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:05
opendevmeetThe meeting name has been set to 'security'15:05
gagehugoo/15:05
fungi#link https://etherpad.opendev.org/p/security-agenda Meeting Agenda15:05
fungi#topic Prior actions15:05
fungifungi adjust the repos-overseen doc to also mention the vmt is available to assist projects even if their repos are not explicitly opted into oversight15:06
fungi#link https://review.opendev.org/844444 (openstack/ossa) repos-overseen: VMT is happy to assist any project15:06
fungifungi push/amend sig chair update changes15:06
fungi#link https://review.opendev.org/844446 (openstack/governance-sigs) Security SIG chair rotation15:06
fungi#link https://review.opendev.org/844448 (opendev/irc-meetings) Security SIG chair rotation15:07
fungifungi propose change to remove security blog references from ossa repo15:07
fungi#link https://review.opendev.org/844451 (openstack/ossa) Drop references for the old security blog15:07
fungifungi send an announcement to the openstack-discuss list about moving documentation out of security-analysis to individual project repos15:08
fungi#link https://lists.openstack.org/pipermail/openstack-discuss/2022-June/028816.html Retiring security-analysis process and repo15:08
fungifungi follow retirement process from project teams guide/infra manual to retire security-analysis15:08
fungi#link https://review.opendev.org/844463 (openstack/governance) Remove security-analysis repo from Security SIG15:08
gagehugoI can review those today15:09
fungi#link https://review.opendev.org/844468 (openstack/security-doc) Use permalink for Barbican security analysis15:09
fungi#link https://review.opendev.org/844490 (openstack/security-analysis) Retirement Step 2: Remove Project Content15:09
fungithanks gagehugo!15:09
fungithere will be more, but my network outage was inconveniently timed to push the rest up yet15:09
fungi#action fungi complete retirement process for security-analysis15:10
fungialso i've been meaning to add d34dh0r53 and dmendiza[m] to the review group in gerrit so they can help review those as well15:12
fungi(sorry for the slowness on my end, this wireless modem is pretty terrible)15:12
fungi#action fungi add new volunteers to review groups15:12
d34dh0r53dmendiza[m] is on PTO but I can take a stab at reviewing those as well15:13
fungi#action fungi initiate openstack-discuss thread on the topic of xstatic packages and js dependency handling15:13
fungii did not get to that yet15:13
fungithanks d34dh0r53! i'll let you know once you have +2 privs, hopefully as soon as my isp pulls their head out of their socket15:13
d34dh0r53fungi: thanks!15:14
fungi#topic Activities: Publishing OSSNs15:14
fungias some of you may or may not be aware, we have redundant copies of security notes presently15:14
fungi#link https://opendev.org/openstack/security-doc/src/branch/master/security-notes Security Notes in Git15:15
fungi#link https://wiki.openstack.org/wiki/OSSN Security Notes in Wiki15:15
fungialso the process info is currently in the wiki rather than in git15:15
fungilooking for volunteers interested in moving the process documentation into git (i guess into the security-doc repo), and retiring all the content on the wiki15:16
fungito those of you here now, or anyone reading the minutes after the meeting, feel free to reach out to me if you want to help with that15:17
fungiit would be nice to get the ossn review process streamlined to be closer to how we review ossa documents, but even just moving the process documentation over and dropping the wiki copies will help15:18
fungii'll keep this topic on the meeting for next month, and can action any volunteers we happen to get15:18
fungier, on the agenda for the meeting next month i mean15:18
fungianybody have any input on the idea? if not, i'll move on to the next topic on the agenda15:19
fungi#topic Recently public security bug reports15:21
fungi#link https://launchpad.net/bugs/1975830 Horizon doesn't provide ACL on Instance level15:22
fungithis was more of a mis-filed feature request15:22
fungii switched it to a normal bug report and added the security tag for visibility15:23
fungithat's the only one i can think of since the last meeting15:24
fungiif someone with an interest in instance-level console access security (obviously the api is as much or more of a problem than the dashboard), feel free to follow up there15:25
fungi#topic Recent vulnerabilities in or related to OpenStack15:25
fungii'm not aware of any obvious new ones here, but if anything public has come to anyone's attention we can take some time in the meeting to discuss15:26
fungibuzz about the log4j vulnerabilities seems to have died down, so an ossn for that is probably no longer particularly urgent15:27
fungiokay, seems like nobody else has anything for this either15:30
fungi#topic Anything else?15:30
fungii'll give it a few minutes before i wrap it up, in case there are other issues folks want to bring up15:30
fungii'm in berlin next week for the open infrastructure summit, but will be trying to keep an eye on any immediate concerns (vmt-related or otherwise) as time allows15:31
fungiif anybody wants to catch up in-person and is also going to be there, i'm happy to coordinate schedules15:32
fungithere are also some infosec-oriented talks on the conference schedule we're likely to bump into one another at15:33
fungiwe actually have a "security" track again for the first time in a while15:33
fungi#link https://openinfra.dev/summit-schedule#track=390&view=calendar OpenInfra Summit Security Track Sessions15:34
fungi10 different talks in the track15:35
fungiif you filter by title keyword instead, there's another one in the containers track15:38
fungi"Lotsa security: confining the extra security layer"15:38
fungiand also of course, tons of security-relevant discussions happening at the forum15:39
fungi"Next Steps for FIPS in OpenStack"15:39
fungi"Unrestricted Ansible in Zuul"15:40
fungi"Deprivileging of Service Accounts Between Individual OpenStack Services"15:41
fungii expect there will be some ongoing rbac discussions too15:42
fungisince it doesn't appear anyone else has something to bring up, i'll close this down 15 minutes early. thanks everyone!15:45
fungi#endmeeting15:45
opendevmeetMeeting ended Thu Jun  2 15:45:06 2022 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:45
opendevmeetMinutes:        https://meetings.opendev.org/meetings/security/2022/security.2022-06-02-15.05.html15:45
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/security/2022/security.2022-06-02-15.05.txt15:45
opendevmeetLog:            https://meetings.opendev.org/meetings/security/2022/security.2022-06-02-15.05.log.html15:45
opendevreviewMerged openstack/ossa master: repos-overseen: VMT is happy to assist any project  https://review.opendev.org/c/openstack/ossa/+/84444416:06
opendevreviewMerged openstack/ossa master: Drop references for the old security blog  https://review.opendev.org/c/openstack/ossa/+/84445116:10
opendevreviewMerged openstack/security-doc master: Use permalink for Barbican security analysis  https://review.opendev.org/c/openstack/security-doc/+/84446816:12
opendevreviewJeremy Stanley proposed openstack/security-analysis master: Retirement Step 2: Remove Project Content  https://review.opendev.org/c/openstack/security-analysis/+/84449016:30

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!