Sunday, 2010-10-31

*** xfaf has joined #openstack00:06
*** mischer has quit IRC00:07
alekibangonicht? hitler is dead, long live obama00:09
alekibango:)00:09
Orman_Yeah I have different political views00:19
Orman_:P00:19
rds__hi guys00:23
Orman_hey00:23
rds__i'm just installed nova00:23
rds__with nova.sh on ubuntu 10.1000:23
rds__i have nova up and running00:24
Orman_Ok00:24
rds__i have generated one key00:25
rds__and lanched one instance, but i can't connect00:25
rds__i get this error00:26
rds__Host key verification failed.00:26
Orman_Really?00:27
rds__yes :(00:27
alekibangords__: very strange00:28
Orman_Have you checked the host?00:28
alekibangoplz put it on pastebin00:29
Orman_Yes it might be bug.00:29
Orman_Would love to see it.00:29
rds__i can ping the vm00:29
rds__but i can't connect via ssh00:29
rds__just after ssh -i key.pem root@10.0.0.300:30
Orman_Hmmm weird00:30
alekibangotry ssh  -vvvv00:30
alekibango:)00:30
alekibangobut that is not the problem00:30
alekibangois the machine having 10.0.0.300:30
alekibangois it running really?00:30
rds__yes i can ping the machine00:31
Orman_Good00:32
*** Cybodog has joined #openstack00:37
rds__i tried ssh -vvvv00:38
rds__i get this00:38
rds__http://pastebin.com/L5AwTK5S00:38
rds__any idea? :)00:39
Orman_Thanks for pasting it.00:40
Orman_:)00:40
Orman_will look at it.00:40
rds__thanks00:41
alekibangords__: what if you say 'y'00:44
alekibangoyes i mean00:44
alekibangodebug3: Not a RSA1 key file key.pem. ????00:45
*** Ryan_Lane|away has quit IRC00:45
rds__i get Host key verification failed00:47
*** Cybodog has quit IRC00:48
rds__i have the key.pem key00:48
*** Ryan_Lane|away has joined #openstack00:49
rds__generated with euca-add-keypair key > key.pem00:50
alekibangoyou didnt type yes, did you00:50
rds__yes i did00:52
alekibangodidnt :)00:52
alekibangoyes - not y00:52
rds__ok not on pastebin :)00:53
alekibangoplease paste all :)00:53
alekibangoor edit your ~/.ssh/known_hosts00:53
alekibangoand remove offending line00:53
Orman_In order for us to see your problem yoo are having we need to see the code. ;D00:54
alekibangothis more likely sounds like ssh key problem00:54
alekibangounrelated to openstack00:54
Orman_Right00:54
Orman_Key  seems to be the problem or the host.00:56
Orman_ssh.00:56
*** anneg has joined #openstack01:03
Orman_Hey anneg01:03
Orman_;D01:03
*** khussein has quit IRC01:05
rds__sorry for the delay01:06
rds__i'm having some copy/paste problem with screen01:06
rds__http://pastebin.com/1YpWdHfU01:06
alekibangords__: you are in01:07
alekibangotype ps faxwww01:07
alekibangoand see01:08
alekibangocongrats :)01:08
alekibangotry ls /home01:08
alekibangoor getent passwd01:08
rds__yes i'm in :)01:09
Orman_Cool01:09
rds__i feel a little bit stupid :)01:09
Orman_Good job alekibango!!!01:09
Orman_;D01:09
alekibangords__: thats ok. we all are stupid in our own way01:10
Orman_lol01:10
Orman_So true.01:10
rds__thank you very much01:11
alekibangonp01:12
rds__but i don't understand01:13
alekibangowas glad to do something good after strange discussion on #turbogears01:13
rds__it's the same think i have done all day :)01:13
alekibangords__: you need to accept the key when you are connecting for the first time01:13
alekibangoby typing yes01:13
alekibango(not y)01:13
alekibangonot enter01:13
rds__yes i see :)01:15
*** ChrisAM has quit IRC01:17
*** xtoddx has quit IRC01:17
rds__thanks anyway01:17
*** devcamcar has quit IRC01:17
*** anotherjesse has quit IRC01:18
alekibangords__: just try to help someone else01:18
alekibango:)01:18
*** devcamcar has joined #openstack01:18
*** vishy has quit IRC01:18
rds__yes, i hope01:18
*** vishy has joined #openstack01:19
rds__ i like this project01:19
*** xtoddx has joined #openstack01:19
alekibangords__: (joke)   they say that nova means:  no other viable alternative01:19
*** anotherjesse has joined #openstack01:20
*** ChrisAM1 has joined #openstack01:20
rds__and i'm thinking to spend the next three month studying and contributing01:20
alekibangogood01:20
rds__:)01:21
rds__ok, it's bed time in Italy01:23
rds__thanks again01:23
alekibangocz here :)01:23
alekibangogn801:23
rds__good night01:24
Orman_Night. rds. ;D01:44
*** rds__ has quit IRC01:59
Orman_alekibango: I'm adding more to the notes.01:59
*** anneg has quit IRC02:10
*** anneg has joined #openstack02:13
Orman_alekibango: http://nova.openstack.org/nova.html#module-nova.crypto02:14
Orman_Could help us when we are writing the Unencrypted Communications Section.02:16
Orman_anneg: Hey02:19
notmynamehotel wifi connections are so bad02:27
alekibangoOrman_: will look later :)02:27
Orman_I know just telling you.02:27
Orman_I just want to make sure I am highlighting what needs to be documented in the notes.02:28
notmynameI really don't get the need for the web proxy that hijacks my connection until I click a button to agree to something I didn't read about not cracking other people's computers or whatever02:28
*** sebastianstadil has quit IRC02:29
alekibangothats just to let you know you are watched02:29
Orman_Crypto needs to be used more and new things needs to be developed to help encrypt the communications.02:30
*** kevnfx has joined #openstack02:31
alekibangoand it needs to survive partition02:37
alekibangoof the network02:37
alekibangoOrman_: but really, is that needed?02:38
alekibangowhen we do not allow them to touch the network devices02:38
alekibangothey will nt be able to listen02:38
Orman_True02:38
Orman_I guess I am just too paranoid. ;D02:38
*** kevnfx has quit IRC02:38
alekibangowell it might have sense in some cases02:39
alekibangodistributed cloud02:39
alekibangohaving clusters in different  cities02:39
alekibangoyet connected02:39
Orman_Right, I agree.02:41
Orman_I am just trying to add new ideas to the table of encryption security.02:42
Orman_First priority is to document the holes that are in the communications that are unencrypted.02:45
alekibangoyou need to see who is able to listen to what communication02:45
alekibangowhere can atacker get wire to listen to it02:45
Orman_Right and then go from their.02:46
alekibango2) analyze what they can get02:46
alekibangoprepare some obstacles :)02:46
Orman_Do you think the Nova Auth Docs would help us?02:46
Orman_I believe they would.02:47
Orman_I first have to find the obstacles.02:47
Orman_;)02:47
*** khussein has joined #openstack02:53
*** jdmaturen has quit IRC02:59
*** anneg has quit IRC03:13
*** sophiap has quit IRC03:26
*** sophiap has joined #openstack03:26
*** miclorb_ has joined #openstack03:35
*** miclorb_ has quit IRC03:40
*** ivan has quit IRC03:49
*** ivan has joined #openstack03:51
*** sophiap has joined #openstack04:10
*** sophiap has quit IRC04:19
*** sophiap has joined #openstack04:23
*** sophiap_ has joined #openstack04:26
*** sophiap has quit IRC04:27
*** sophiap_ is now known as sophiap04:27
*** Orman_ has quit IRC04:59
*** kirkland has quit IRC05:09
*** kirkland has joined #openstack05:18
*** Orman has joined #openstack05:18
*** sophiap has quit IRC05:24
Ormanalekibango: You still here?05:42
alekibangoy06:02
OrmanJust wondering.06:07
alekibango:)06:07
OrmanI am trying to find some auth bugs.06:07
OrmanCan't find any that anyone filed.06:08
alekibangofirst we imho should talk about architecture06:08
alekibangowhich network where who can get what06:08
OrmanPermissions.06:08
alekibangothis will be very arch related06:08
alekibangoyes, rights, permissions06:09
alekibangoright != permission :)06:09
Orman:)06:09
alekibangopermission may be given, right is there from beginning06:10
OrmanSo first we develop the architecture for the Authentication and then list the problems we've found.06:10
alekibangoand everyone has right for privacy06:10
alekibango!06:10
OrmanRight privacy is key here.06:10
alekibangoimho we need some architecture design schemas first06:10
alekibangoand test installs ...06:11
alekibangoits good to monitor network uising wireshark or something06:11
alekibangoor ngrep06:11
OrmanJust so we're on the same page we are talking about Security architecture right?06:11
alekibangoor whatever06:11
alekibango?06:11
alekibangopage?06:11
OrmanWell I mean Authentication06:11
Ormanarchtitecture06:12
alekibangoi meant network architecture06:12
alekibangohow those machines will be connected06:12
OrmanOk06:12
alekibangoand those clusters06:12
alekibangothen we can build security architecture on top of that06:12
OrmanOh haha I was thinking Authentication.06:12
alekibangoand test it06:12
Ormanhaha I am tired06:12
alekibangome too06:12
OrmanOk now I got you06:12
alekibangoit was very long night for me06:13
OrmanPassion comes before sleep for me. ;)06:13
alekibangoi even got on ignore list of someone today06:13
Ormanlol06:13
OrmanReally?06:13
alekibangofor asking questions06:13
OrmanWhat that's dumb.06:14
alekibangoand pressing something06:14
alekibangolike failure in project management06:14
Orman?06:14
Orman:06:14
Orman:(06:14
alekibangowell, that made me totally out tonight06:14
OrmanYeah just shake it off.06:14
alekibangovery looong night06:14
Orman;)06:14
alekibangoOrman: i dont feel down, just tired06:15
alekibangomaybe the project might be down soon...06:15
alekibangowhich makes me sad06:15
Ormanalekibango: I know and I am just trying to lghiten the mood.06:15
alekibangowell, i must say openstackis really exceptional06:16
OrmanYeah it is06:16
OrmanI love the community. You all welcomed me in.06:17
alekibangoi hope it will keep being this way06:17
OrmanMe too.06:17
OrmanSmart people working together for the greater good. ;D06:18
OrmanSo for the Nova notes we will first start out with the network architecture and then move towards securing the stack.06:19
alekibangowe might even need more archs06:19
Orman:)06:19
alekibangoit differs for 4 servers06:19
alekibangoand for 5006:19
OrmanTo do that we will need more help.06:19
alekibangoand for distributed one06:19
alekibangoyes06:19
alekibangothats what we need06:19
OrmanI just need an outline to what we need to first write about.06:20
OrmanI have Unencrypted as the first one in the notes below everything else.06:21
alekibangoi think we might even delete the last paragraph :)06:22
alekibangoas we need input from devs here06:22
alekibangowe need to really define what is what, what needs protection06:22
alekibangoand how imporant it is06:22
alekibangoand in what network architecture setup it is06:23
alekibangoonly then we might come with reasonable solutions06:23
OrmanRight06:23
alekibangoOrman: imagine those different networks - vlans, flat, flat with dhcp06:23
alekibangodifferent needs!06:23
OrmanOk06:24
OrmanDifferent security solutions.06:24
alekibangoyes06:24
alekibangothats why we need architecture pictures06:24
alekibangoschemas06:24
OrmanVisio should help. ;D06:24
alekibangoouch06:25
alekibangono ms!06:25
Ormanlol06:25
alekibangoblindio06:25
OrmanYeah06:25
OrmanDevelopers should give us the in depth network info we need for the different networks.06:26
OrmanOnly then can we move on.06:26
OrmanI am going to delete the last paragraph.06:27
alekibangosee those 3 cliparts  http://www.openclipart.org/search/?query=dexMilano06:27
alekibangovery nice for making comp netwrok pictures06:28
alekibangousing for example inkscape06:28
alekibango(very nice app)06:28
OrmanYeah06:28
alekibangoyou can import those libs from menu06:29
alekibangojust search dex06:29
alekibango:)06:29
OrmanCode would really be nice to have along with those diagrams.06:29
alekibangoor the other way around06:29
alekibango:)06:29
Orman;)06:29
alekibangoOrman: those diagrams should be in deployment docs06:29
OrmanOk06:30
alekibangoi might draw them when someone will help me06:30
OrmanSo can I delete the first paragraph?06:30
OrmanI sthat fine with you?06:30
alekibangolast? :)06:30
alekibangothere is always history06:30
Ormanthe Unencrypted one I wrote.06:30
alekibangodont worry much06:30
alekibangosave revision06:31
OrmanOk well I just want to get off to the right step.06:31
alekibango?06:31
alekibangoOrman: maybe the right step should be the one which brings you to bed :)))06:31
alekibangoor some tea06:32
Ormanlol06:32
alekibangoyou are starting to talk in penglish06:32
alekibango:)06:32
OrmanI'm such a geek.06:32
alekibango(as much as i do heh)06:32
OrmanYeah tired.06:32
alekibangowe need automated cert. generation06:33
alekibangothats done by the nove crypto, right?06:33
OrmanSorry about speaking penglish.06:33
Ormanhehe.06:33
alekibangonp06:33
alekibangoingleeze06:33
alekibangoOrman: best what i learned from english was that when you speak too well06:34
alekibangoyou cant talk to locals06:34
alekibangoin egypt for example06:34
alekibangoimagine guy standing just near pyramids06:34
alekibangocalling loudly "WANDALA KOLA"06:34
OrmanRight I was looking at the nova crypto earlier.06:35
alekibangowhat would you do?06:35
alekibangoour best english speaker was not able to understand him06:35
OrmanOk06:35
alekibangobut we penglishersh knew immediatelly that he is selling cola for 1 dollar each06:35
OrmanRight06:36
alekibangoand from the time, i dont care much about grandma :)06:36
alekibangogramma i mean06:36
OrmanOk06:37
OrmanDiagrams will help and especially developers.06:38
alekibangowe need somehow to make them interested06:38
alekibangomaybe when they do not sleep06:38
alekibango:D06:38
Ormanlol06:38
alekibangowhich is in some 8 hours?06:39
*** pvo has quit IRC06:39
OrmanYeah it would help to have at least one or two to start.06:39
OrmanDevelopers are the key. ;)06:40
alekibangotry bugging hys!^  (name written upside down from right to left)06:41
alekibango(:  uewjo06:42
Ormanalekibango: His name is hys!?06:44
*** khussein has quit IRC06:44
alekibangoyou missed ^ = v06:45
OrmanOk06:45
alekibangoyou are uewjo.06:45
Ormanhys!^: Would you be interested in working on the Nova Security Notes? http://etherpad.openstack.org/NovaSecurityNotes06:47
alekibangohehe Orman you do not read me :)06:47
alekibangoi tried to avoid his name by turning it upside down06:47
alekibangotalk to him when he is alive06:47
alekibango(v!ishy)06:47
OrmanNot reading sleeping06:47
Ormanhaha06:47
OrmanSorry06:48
Ormanpenglish06:48
Ormanhehe06:48
alekibangoi should go bed too06:48
alekibangosoon06:48
OrmanWow I messed up there.06:49
alekibangowe all do :D06:49
alekibangoyou just need to fail better each and every day06:49
OrmanThanks makes me feel better06:49
alekibango:D06:50
OrmanWhat time is it their06:50
Orman?06:50
alekibangousa eastern06:51
OrmanHehe mine too.06:51
alekibangosun came up here hour ago06:51
OrmanWow06:52
OrmanWell I'll let you go. I am going to get some sleep so I can fuel up for tomorrow if indeed we collaborate with other people. ;D06:54
alekibangowell, in sunday its sleepy here06:57
alekibangoweekends -> ppl dont work much06:58
OrmanYeah me too06:58
OrmanSo I guess we just wait for developers to start working with us right?06:59
alekibangoOrman: its better to be proactive07:00
alekibangothat makes you win wars07:00
OrmanI know,but I mean to have more depth on the people side.07:00
alekibangodefine the place of the fight07:00
alekibangoyes i a gree07:00
alekibangobut not passive waiting07:00
OrmanRight.07:01
OrmanI love Technical writing.07:01
alekibangomaybe try to install it on 2-4 servers07:01
alekibango:D07:01
alekibangodo you have some?07:01
OrmanWell, no.07:02
OrmanI do have my people though.07:03
Orman;)07:03
alekibangodo you want some07:03
alekibangoi could give you 2 for a week07:03
OrmanWhat type of servers are they?07:04
alekibango8core xeons07:04
Ormanhmmm07:04
alekibango16 gb ram, 2 network cards07:04
alekibangoetc07:04
alekibango2 disks07:04
alekibangobut maybe i rather should finally make them install from fai :)07:05
OrmanAre running anything on them right now?07:05
alekibangoOrman: not atm07:05
OrmanI'll think about it.07:05
OrmanSounds like they're awesome. ;)07:06
alekibangobut maybe i should rather install 4 server clusters on all 407:06
alekibangoOrman:  i would give you access so you could test with me07:07
OrmanTesting OpenStack right or am I off?07:07
alekibangoyes07:07
alekibangoi would like to test it well07:08
OrmanOk07:08
OrmanRight07:08
alekibangofor few weeks -- and develop some improvements07:08
alekibangoheh, i should write some blueprint today07:08
alekibangofor my scheduler07:08
OrmanThe only thing is I am not the best at coding.07:08
alekibangoOrman: so do some python tutorials  when you wake up07:09
alekibangoit can be learned in 2-5 hours07:09
Orman;)07:09
alekibangono jokes07:09
alekibangomy 7 year old son is coding using it07:09
OrmanI know07:09
OrmanYeah you told me that. Genius.07:10
alekibangoso you can too07:10
OrmanYeah I will try some tutorials.07:10
alekibangoOrman: he is more likely good piano player :)07:10
OrmanWell it's good to have many talents.07:10
alekibangoOrman: i am teaching him jazz!07:11
OrmanI like Jazz.07:11
OrmanNice music.07:12
alekibangoOrman: he wants to play music like the one in transport tycoon07:12
alekibangodo you know?07:12
alekibangohttp://www.transporttycoon.net/music07:12
OrmanYou mean the game?07:12
alekibangoreally sweet music07:12
alekibangoyes07:12
alekibangoi think in 1-2 years he will be playing like that07:13
OrmanNot bad sound07:13
OrmanTT Deluxe Theme.07:13
Orman;)07:13
alekibangoi consider buying this for him http://www.playpianotoday.com/blues/07:13
OrmanThat can come in handy.07:14
alekibangomaybe next year, when he will have his own laptop :)07:14
OrmanSo he really would like to be musician in the future?07:15
alekibangoyep07:15
OrmanNice!07:15
alekibangohe is playing in public already :)07:15
OrmanGood get the buttefly's off.07:16
OrmanConfidence07:16
OrmanHave you seen the movie Catch me if you can?07:16
alekibangowell, he needs to learn loosing07:16
alekibangoyes i have07:16
OrmanOk07:16
alekibangonice one07:17
alekibangobut lying a bit :)07:17
OrmanThat's an excellent example of how  hacker works.07:17
Ormanin the movie at the end I mean.07:17
alekibangono, thats cracker :) social engeneering07:17
OrmanWell yeah07:17
alekibangoi know. i study that07:17
alekibangopsychology, the art of war, history etc07:18
OrmanBoth could be tied to that I mean that bad hackers work for security companies.07:18
OrmanRight07:18
alekibangothe art of war is very important to understand07:18
alekibangobecause we are in middle of many wars07:18
OrmanYeah07:18
alekibangoOrman: all wars are based on deception!07:19
OrmanOk07:19
alekibangoand you can bet deception means someone trying to control you, its war07:19
OrmanOut wit your opponent.07:19
alekibangoOrman: its not about opponents sometimes07:20
alekibangothe worst war is inside your mind and heart07:20
OrmanRight07:20
OrmanMental07:20
OrmanThose are the toughest I find personally.07:20
alekibangonot only mental... heart really07:21
alekibangoand stomach07:21
OrmanSo those servers would be test dummies to analyze the stack/07:22
Orman?07:22
alekibangowell i have 4 servers to play with07:22
alekibangojust for os07:22
OrmanBetter then none.07:22
OrmanXeon's are a brand.07:23
alekibangowell. memory is low, only 16gb07:23
Orman*good.07:23
alekibangoi would like to have at least twice07:23
alekibangoi would like to start public cloud soon07:23
OrmanPut the clusters up like you said07:23
alekibangook will try asap tomorrow07:24
OrmanLet me know what the status is.07:24
alekibangoon/off07:24
alekibango:)07:24
OrmanYeah07:24
OrmanTrial and error.07:24
OrmanIf you put the clusters together then you should be fine.07:25
alekibangowell not really. its still somehow young a lot07:25
alekibangobut i will feel better thats sure07:26
alekibango :D07:26
OrmanYeah07:26
OrmanRun security tests on them as well.07:26
alekibangocan be07:26
OrmanI have to get a some stuff done tomorrow on the Nova Security Notes.07:27
OrmanWell I should hit the hay.07:29
alekibango:D07:30
Orman3:29AM here in Florida.07:30
OrmanYoul will be on tomorrow right?07:30
alekibangosure07:30
OrmanOk07:30
OrmanWell till then my friend God bless you07:31
OrmanHave a good night. ;D07:31
OrmanBy the way I will look at the Python tutorials.07:33
Orman;)07:33
OrmanSee ya07:34
*** Orman has quit IRC07:34
*** allsystemsarego has joined #openstack07:48
*** eldarnugaev has joined #openstack08:55
*** anneg has joined #openstack09:10
*** anneg has quit IRC09:14
*** stewart has quit IRC09:32
*** gaveen has joined #openstack09:36
*** aimon has quit IRC09:56
*** aimon has joined #openstack09:56
*** sagactor has joined #openstack10:02
sagactorany homosexuals in here10:03
sagactori hate queers...and blacks...and all minorities10:04
*** sagactor has quit IRC10:04
*** miclorb has joined #openstack10:05
*** kashyapc has joined #openstack10:23
*** aimon_ has joined #openstack10:23
*** aimon has quit IRC10:26
*** aimon_ is now known as aimon10:26
*** eldarnugaev has quit IRC10:38
*** stewart has joined #openstack10:41
*** vladdy has joined #openstack10:42
*** eldarnugaev has joined #openstack10:56
*** tomo_bot has quit IRC10:59
*** eldarnugaev has quit IRC11:05
*** vladdy has quit IRC11:20
*** vladdy has joined #openstack11:22
*** tomo_bot has joined #openstack11:22
*** gaveen has quit IRC11:24
*** vladdy is now known as perestrelka11:25
*** omidhdl has joined #openstack11:30
*** omidhdl has joined #openstack11:32
*** miclorb has quit IRC11:41
*** krish has joined #openstack11:45
*** ctennis has quit IRC11:50
*** krish has quit IRC12:07
*** krish has joined #openstack12:19
*** ctennis has joined #openstack12:40
*** arcane has quit IRC12:47
*** arcane has joined #openstack12:48
*** ctennis has quit IRC12:56
*** gaveen has joined #openstack12:58
*** gaveen has joined #openstack12:58
*** pvo has joined #openstack13:03
*** ChanServ sets mode: +v pvo13:03
*** gaveen has joined #openstack13:07
*** ctennis has joined #openstack13:08
*** ctennis has joined #openstack13:08
*** omidhdl has left #openstack13:18
*** xfaf has quit IRC13:23
*** sophiap has joined #openstack13:28
*** pvo has quit IRC13:29
*** sophiap_ has joined #openstack13:35
*** sophiap has quit IRC13:35
*** sophiap_ is now known as sophiap13:35
*** pvo has joined #openstack14:19
*** pvo has joined #openstack14:19
*** ChanServ sets mode: +v pvo14:19
*** pvo has quit IRC14:21
*** coredump|br has quit IRC14:35
*** gondoi has joined #openstack14:43
*** kevnfx has joined #openstack14:44
*** kevnfx has quit IRC14:45
*** coredump|br has joined #openstack14:51
*** gondoi has quit IRC14:56
*** ChrisAM1 is now known as ChrisAM15:05
*** sophiap has quit IRC15:15
*** sophiap has joined #openstack15:27
*** xfaf has joined #openstack15:37
*** eldarnugaev has joined #openstack15:43
*** burris has joined #openstack15:51
*** anneg has joined #openstack16:12
*** Orman has joined #openstack16:19
*** burris has quit IRC16:21
OrmanHello all,16:24
Orman;)16:24
OrmanAny developers want to help us out on the Nova Security Notes? http://etherpad.openstack.org/NovaSecurityNotes16:25
OrmanWe would love the help.16:25
*** anneg has quit IRC16:28
Ormanalekibango: Hey16:30
*** eldarnugaev has quit IRC16:41
*** anneg has joined #openstack16:51
*** anneg has quit IRC17:00
*** dagger has quit IRC17:06
*** dagger has joined #openstack17:08
*** dagger has joined #openstack17:08
*** jdmaturen has joined #openstack17:33
*** Orman has quit IRC17:36
*** krish has quit IRC18:17
alekibango:)18:28
*** anneg has joined #openstack18:33
*** Orman has joined #openstack18:42
OrmanHello18:42
OrmanAny developers online?18:43
notmynamebased on your earlier comments, I assume you're looking for nova devs? ;-)18:44
*** anneg has quit IRC18:44
Ormannotmyname: Yes I am looking for Nova devs to help with the Nova Security Notes.18:46
OrmanI hope I am not bugging people to much.18:46
notmynameyou certainly aren't bugging me. security notes sound like a good thing18:47
Ormannotmyname: Really any devs,but yes Nova devs especially. ;D18:48
notmynamebut if you have any questions about swift, I'll try to help18:48
alekibangonotmyname: that might help too18:48
alekibangowe started looking on nova, but the same for swift should be done18:48
OrmanWe have not started the Swift Security Notes yet.18:48
alekibangoplease see the etherpad :)18:48
*** eldarnugaev has joined #openstack18:49
alekibangoand make copy18:49
OrmanHere's what we have so far http://etherpad.openstack.org/NovaSecurityNotes18:49
alekibangomake swift one :)18:49
alekibangowe need to uderstand possible architectures18:49
OrmanJust need more devs to help us outline it.18:49
alekibangoand to see what needs protecting and from what18:49
alekibangothats what wee need devs for18:49
alekibangoto help us to draw some nice pictures of possible network designs18:50
alekibangoand from those designs we need to identify what could be problem18:50
OrmanYeah18:50
notmynameone of the nice things about swift is that users can't execute any code. so threats go way down18:50
alekibangothis can differ for small clouds (<4 machines) and for big ones18:50
alekibango(where it can be distributed on different places)18:51
OrmanYeah if we have different clouds then we might have different security problems.18:51
alekibangobut you need to be sure it will be safe when you will have swift installed in 2 cities in one cloud18:52
alekibangoif thats possible18:52
notmynamesure it's possible18:52
alekibangoyou do not want someone to intercept what is moving around18:52
alekibangoor change it18:52
creihtleave security to the security professionals :)18:52
alekibangothose guys with guns? :)18:53
OrmanYeah if they can intercept data going around then that could be a huge problem.18:53
notmynameright. but the traffic can be easily segregated into local and not-local. local traffic is anything between the storage nodes and should be protected (see your friendly neighborhood net sec professional)18:53
OrmanYeah if we're talking local then it should stay local which would put the threat of security down.18:54
notmynamebut local is "logically local"18:55
OrmanRight18:55
Ormanalekibango: Let's be productive. ;D18:55
notmynameand that depends on VPN or ssl tunnels or firewall rules or routing tables or whatever18:55
alekibangoi cant right now, still fighting with some prbolem18:56
Ormanalekibango: What's the problem?18:56
alekibangocreiht, notmyname:  network schemas, possible architecture diagrams can never harm18:56
OrmanA lot to consider for security I know.18:56
alekibangoOrman: my very own, local :)18:56
Ormanalekiango: Did you try clustering?18:57
alekibangoOrman: i am under pressure now, plese let me work :)18:58
Ormanalekibango: Oh sorry man realize. :D18:59
Orman*didn't18:59
Orman+notmyname: I will make a Swift Security Notes one soon.18:59
Orman+notmyname: Would love to have a Swift dev work on it.19:02
*** gaveen has quit IRC19:02
notmynamearen't you the security expert? ;-)19:03
notmynamebut, yes, when you make it, I'm sure some of us will look at it (including myself)19:04
Orman+notmyname: Well, I am more like security student. Still though I would like any dev help I can get.19:05
Orman+notyname: Thanks for the complement though.19:05
Orman;P19:05
*** ArdRigh has quit IRC19:05
alekibangonotmyname: problem is that even security expert needs lots of time for checking the code and understanding the architecture19:05
alekibangowe need to help make this clear19:06
OrmanRight thanks alekibango.19:06
OrmanWe need devs to help as well on the Nova one.19:06
alekibangoi am kind of security expert - older hacker, knowing much about the art of war and teacher of close combat, hehe19:07
Orman:)19:07
OrmanI just would like to find some Nova devs today which could help.19:08
OrmanHowever it's the weekend.19:08
alekibangotomorrow, cca 19 hours from now19:08
alekibangothey will come here in numbers19:08
Orman:(19:09
* alekibango is back to his work19:09
OrmanI guess in the mean time just keep on writing the outlines and architecture.19:10
alekibangoOrman: yes that what we did with nova manuals -- and it worked for the start19:10
OrmanOk19:11
Ormanalekibango: Even though I'd love to have the devs work on it we need to keep on moving forward with it.19:12
*** gaveen has joined #openstack19:15
notmynameanyone ever used dnspython? (http://www.dnspython.org/)19:21
OrmanDevelopers are one of the keys. ;D19:22
OrmanNo19:22
notmynameor know of a better set of DNS tools?19:22
notmynamespecifically, I need to follow a CNAME chain when given a host19:24
Orman+notmyname: I know you're Swift dev,but do you know Nova well?19:26
notmynamenot at all19:26
OrmanOk19:27
OrmanTrying to find a dev that knows.19:27
OrmanNot easy. ;D19:27
OrmanArchiture for Nova I guess would go first.19:32
OrmanThe outline is already made19:32
notmynamecreiht: I'm not adding my domain remapping middleware to the proxy pipeline in the example proxy-server.conf. Seems that these are optional (but nice to have) features. do you think they should be added?19:32
OrmanI think for the Nova notes we should start with Authorization.19:37
OrmanEveryone's busy. ;D19:51
*** jaypipes has quit IRC20:03
OrmanSee ya later guys20:11
*** Orman has quit IRC20:11
*** eldarnugaev has quit IRC20:12
*** metoikos has joined #openstack20:37
*** sophiap has quit IRC20:55
*** anneg has joined #openstack20:59
*** sophiap has joined #openstack21:01
*** pothos_ has quit IRC21:07
*** anneg has quit IRC21:07
*** anneg has joined #openstack21:08
*** pothos has joined #openstack21:09
*** joearnold has joined #openstack21:11
patri0tanyone know about security design of openstack, and where we should start to read?21:16
*** kevnfx has joined #openstack21:29
*** joearnold has quit IRC21:33
*** allsystemsarego has quit IRC21:36
*** joearnold has joined #openstack21:39
*** joearnold has quit IRC21:52
*** joearnold has joined #openstack21:52
*** joearnold has quit IRC21:59
*** perestrelka has quit IRC22:01
*** perestrelka has joined #openstack22:01
*** anneg has quit IRC22:10
*** Orman has joined #openstack22:13
OrmanHey22:13
*** miclorb_ has joined #openstack22:15
OrmanNetwork security architecture22:17
*** joearnold has joined #openstack22:21
*** ArdRigh has joined #openstack22:24
*** ArdRigh has joined #openstack22:24
OrmanNova devs on? I doubt it though because it's the weekend .;D22:26
*** joearnol_ has joined #openstack22:30
*** joearnold has quit IRC22:33
*** joearnol_ has quit IRC22:35
*** joearnold has joined #openstack22:35
*** joearnold has quit IRC22:40
OrmanI guess I will develop and design the network architecture first.22:54
OrmanThen developers could collaborate with it if they are interested.22:55
*** Cybodog has joined #openstack22:57
*** Cybodog has quit IRC23:01
*** matiu has joined #openstack23:13
*** gaveen_ has joined #openstack23:19
*** gaveen has quit IRC23:22
*** eldarnugaev has joined #openstack23:47
*** eldarnugaev has quit IRC23:54

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!