18:04:00 #startmeeting OpenStack Security Group 18:04:01 Meeting started Thu Feb 14 18:04:00 2013 UTC. The chair is bdpayne. Information about MeetBot at http://wiki.debian.org/MeetBot. 18:04:02 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 18:04:04 The meeting name has been set to 'openstack_security_group' 18:04:17 good morning / evening everyone 18:04:45 I'd like to get started today with an update on the storage encryption work 18:04:50 #topic Storage Encryption 18:05:09 Anyone from Intel or JHU APL around to give an update? 18:05:31 yes, I'm here from APL 18:05:45 The volume encryption blue print was rejected for Grizzly release 18:06:07 ok, I saw some chatter about that… didn't know it was formal 18:06:15 The change was a bit too big at the last minute to make Grizzly 18:06:29 yeah, I know that is frustrating… but it does make some sense 18:06:38 so, let's plan for how to get it into H? 18:06:39 It's understandable 18:06:57 But there is interest, and we are hopeful to make Havana 18:07:05 we were encouraged to lead a design summit session specifically for the blueprint, so that is what we are planning 18:07:17 I think that's a good idea 18:07:29 are you guys moving forward with setting that up? 18:07:31 there will also likely be a second design session specifically for key management issues 18:07:36 Please share that here if/when its setup. I will attend. 18:07:47 ditto 18:07:47 The dev mailing list has some chatter about how to handle cloning and snapshotting if anyone is interested in that 18:08:37 ok, sounds good 18:08:53 I think that this will give us a little more time to "get it right" 18:09:09 if you guys need help with coding stuff post-summit, then please make an ask here with OSSG 18:09:22 I suspect that there are people around that can help with pieces, if desired 18:10:40 ok, so I guess we can move on to some of the documentation efforts 18:10:50 #topic Hardening Guide and OSN 18:11:08 the LXC OSN has been a slow process ;-) 18:11:35 Rob and I have been working to coordinate the release of the document and make it smoother in the future 18:11:45 I think that we're about there and this will roll more smoothly next time 18:11:50 LXC OSN == what? 18:12:03 the security note on using LXC 18:12:11 sorry, too man acronyms 18:12:18 s/man/many/ 18:12:26 Roger. I've got it now. 18:12:30 ok 18:12:57 so… looking forward, I encourage everyone here to bring forward ideas for future security notes 18:13:34 basically, if there's some brief security guidance that we can provide to help people do things better from a security viewpoint, then it would be nice to share 18:13:47 anything come to mind right now? 18:13:55 i will have some additions shortly.. 18:14:03 great, thanks 18:14:24 #action We can all think of ideas for more security notes 18:14:35 Now, turning to the hardening guide 18:14:46 Not much work has happened on that, unfortunately 18:15:02 I am happy to put in some cycles, but would like to get more of the community involved as well 18:15:10 Is there anyone that would like to help with that effort? 18:15:21 Or any suggestions for pushing that forward? 18:16:10 APL can provide suggestions. We were swamped trying to get into Grizzly. 18:16:20 unfortunately, I don't know Tex so getting setup with that has been a blocker. 18:16:22 We can have comments by next week 18:16:37 rellerreller thanks 18:16:47 Re Tex… please don't let that block you 18:17:04 you can submit stuff in plain text and I'll happily drop it into tex files 18:17:10 the delta is very small anyway 18:17:17 roger. 18:17:21 and the outline is actually in a plain text file too 18:17:32 and, I'm happy to teach people LaTeX ;-) 18:17:36 ;) 18:17:55 but, seriously… I can drop in plain text contributions very easily 18:18:14 gotcha.. i'll move forward with plain text for now.. 18:18:35 well… as always, please touch base with me if you'd like to help… I'd love to see some more momentum there 18:18:43 are you looking mainly for comments on the outline that is in place, or contributions for fleshed out sections (or both?) 18:18:47 #action Ramp up work on hardening guide 18:18:58 both would be great 18:19:10 okay 18:19:36 I don't expect the outline to change too much as I haven't gotten much feedback on it 18:19:42 so writing text is low risk 18:20:14 also, if anyone like drawing technical diagrams… I'd love to hear from you :-) 18:20:32 ok… moving onward 18:20:46 #topic OSSG and Core Projects 18:21:07 At the summit last fall, I expressive my desire to get OSSG tightly integrated into the core projects 18:21:24 the idea is to have people on OSSG working on the core projects 18:21:48 and that those people could bring security concerns back to the group for deeper analysis, design, and improvement 18:22:03 I would love to start seeing this happen 18:22:25 I think that the first step is to identify who we have in OSSG that is already tracking core projects 18:22:30 Does anyone fit that bill? 18:23:27 Ok… the next question, who would *like* to get integrated into a core project? 18:23:57 hrm 18:24:08 I'm too new. :) 18:24:28 Ok, I may need to approach this a little differently 18:24:59 I think that the plan will be to identify people already on the core projects that could be good and invite them to work with OSSG 18:25:22 #action Work with PTLs to get tighter integration between OSSG and core projects 18:25:32 #topic Discussion 18:25:49 It's been quiet today… anything else on people's minds? 18:26:50 #action All meeting attendees to drink coffee before next meeting :-) 18:27:00 are there any particular plans for OSSG at the next summit? 18:27:10 a few 18:27:31 Rob and I are planning to submit a talk to give an update on OSSG work 18:28:10 I've been debating setting up a design session to get discussion going around integrating OSSG and security thinking into the core projects (still need to flush that out) 18:28:33 And I'd love to get the group together informally at some point just so we can meet f2f… perhaps over a meal 18:28:51 I'm, of course, open to other ideas too! 18:29:19 those all sound good to me 18:29:27 Absolutely. f2f is a great way to get some serious momentum 18:29:37 I concur 18:29:45 great, looking forward to it 18:29:56 thanks everyone… til next time... 18:30:01 #endmeeting