18:01:47 #startmeeting OpenStack Security Group 18:01:48 thanks for comming folks, lets talk on #openstack-qa 18:01:48 Meeting started Thu Sep 12 18:01:47 2013 UTC and is due to finish in 60 minutes. The chair is bdpayne. Information about MeetBot at http://wiki.debian.org/MeetBot. 18:01:49 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 18:01:52 The meeting name has been set to 'openstack_security_group' 18:02:08 Hi OSSG 18:02:12 hey! 18:02:21 I know I've been out for a couple of weeks, so I have some catching up to do 18:02:23 hello! 18:02:31 Good morning! 18:02:49 #topic Status of Action Items 18:03:01 Let's start by reviewing where everyone is at with their work 18:03:05 Anyone have somethign to report? 18:03:51 sriramhere would you like to update on the security tagged of blueprints and what you learned there? 18:04:02 no progress on the automatic testing, too much work for my company ATM ;) 18:04:03 couple of things there 18:04:17 1) blueprints don't provide any easy way out there 18:04:56 2) so the work around was security group to actively track blueprints and followup with bugs to trigger notifications 18:05:15 i think rellerreller took action to look in to a way to trawl blueprints 18:05:28 crawl? 18:05:53 ah yes, I see that action from 8/29 18:05:54 yes 18:06:02 excellent 18:06:10 the APL people couldn't make it today 18:06:17 so we can sync on that next week 18:06:26 ok 18:06:34 so I have a few updates on my end 18:06:50 First, I got the wiki page up to help people with how to get involved 18:06:59 gr8 - where is the link? 18:07:13 https://wiki.openstack.org/wiki/Security/How_To_Contribute 18:07:24 since it is a wiki, feel free to update and improve 18:07:42 I tried to take people's comments from the google doc into account, but didn't get everything in there 18:08:08 i have a followup action on that - to add section on how OSSG can get involved early on 18:08:11 I also linked to this from the general how to contibute page https://wiki.openstack.org/wiki/How_To_Contribute 18:08:26 i couldn't make progress on that, will try to get something out before monday 18:08:42 great bpayne! 18:08:47 bpayne 18:08:48 by early on you mean during design phase? 18:08:49 sorry 18:08:53 yes 18:09:03 ah, excellent 18:09:24 personally, I'd like to take a couple of passes to make it more words and less bullets 18:09:31 but this is a nice starting place 18:09:36 and I'm happy to refine over time 18:10:00 #action sriramhere to add info to wiki about getting involved early in the design process 18:10:22 #action bdpayne to continue improving presentation / wording on how to contribute wiki page 18:10:46 My other news is about the OpenStack Security Guide 18:11:20 a few of the authors (myself included) were on a panel at a government conference last week 18:11:30 on a whim, we decided to do a book signing 18:11:42 Red Hat pitched in a bought 100 copies to give away 18:11:47 neat! 18:11:51 nicde 18:11:54 nice 18:12:06 the net result… we had a line out the door and gave away all of the books, signing them all, to very happy recipients 18:12:39 we also collected donations for the OpenStack Foundation, so a little money made it's way back to the cause 18:12:40 wow! have any pic? would be a great slide 18:12:53 you know, a pic would have been great, but I didn't get one 18:13:20 WOW!!!!!!!!!!!! 18:13:41 neat - can u share more abt the conference please (if its sharable)? 18:13:43 I am totally psyched, that was such a gcool idea and a line to grab the book signed! 18:14:01 oh, and there are pictures online from the book sprint now too http://www.flickr.com/photos/101584348@N06/ 18:14:05 for anyone interested 18:14:21 those are from all booksprints by our facilitator… but if you scroll down you'll see us in there 18:14:34 BTW, I pitched our book at Intel Developer Conference in San Francisco this week during my presentation 18:14:40 this was the conference http://www.oss-institute.org/calendar/upcoming-events/event/47 18:15:11 Mentioned the book at a customer visit too 18:15:15 awesome malini, how was the response? 18:15:23 /msg mtreinish hi matthew, I thanks for your comment in https://review.openstack.org/#/c/46315/. After abandon that one, I send a new one: https://review.openstack.org/#/c/46324/ 18:15:26 18:15:39 150 attendees, hopefully some will get to the link 18:16:04 excellent 18:16:22 the book has been a great tool to get more people excited about OpenStack security and perhaps to get some involved 18:16:39 My other update is with the logo 18:16:45 absolutely! 18:16:49 I'm *still* awaiting approval from the powers that be 18:17:03 they tell me that they are discussing it and haven't forgotten about me 18:17:06 It turns out Dell has a product called Crossbar to set up among other things trusted book of platform, but for general openstack consumption it needs to be more a part of Chef/puppet 18:17:09 so, I'll continue to wait 18:17:30 :-) :-) 18:17:35 any other updates? 18:17:46 crowbar or crossbar? 18:18:00 crowbar, I imagine 18:18:10 I know of Crowbar as I am on that project 18:18:16 Thanks Bryan for looking at the glossary, my TODO there is to make references in the chapters to the Glossary, been busy with other things .. hopefully over the weekend a little more time on it 18:18:50 #action malini1 to work on linking glossary into security guide 18:18:57 Wow! we have experts on crowbar here 18:19:03 malini1 any update on the slide deck? 18:19:24 Randy-perryman -- do you thing we can make some openstack-friendly thing or would that be conflict of interest 18:19:47 malini1 I think Brian Schott may be able to help you with the slides, if that's useful 18:20:14 :-) slow, extremely sorry, i put in a few slides for customer visit, so we have more but not complete 18:20:43 perhaps for content generation we could put the slides up as a Google Doc? 18:20:48 i will ping Brian. SriramHere was SriramNoWhere .. on slides .. 18:20:49 i am also sorry, couldn't add more slides as malini and i were planning on? 18:21:09 I probably have a few that would be applicable that I could drop in 18:21:21 that would be good instead of flating around as a powerpoint 18:21:44 bryan, can powerpoint port to googledocs with a click? 18:22:02 yes 18:22:16 then you can export back to pptx when you are done with google docs, if you want 18:22:19 End of day will send you my latest set and then lets work via google docs on it 18:22:26 sounds good 18:22:50 ok great 18:22:55 so that was a lot of catching up 18:22:57 sriramnowhere will try be sriramhere 18:23:04 on slides :) 18:23:10 ha nice! 18:23:10 :-) 18:23:30 summit talk accepts / rejects should come out soon 18:23:50 do we have a google site somewhere, or just individual google drive, shared via email? 18:23:56 and I believe dev sessions are open for submission at this time? 18:24:02 fingers crossed 18:24:11 yes, they are 18:24:13 sriramhere just the latter 18:24:39 #action so, next week I'd like to chat a bit in this meeting about our strategy for the summit 18:25:00 anything else on people's minds for today? 18:25:46 any dev/ test submissions planned? 18:26:01 not that I'm aware of 18:26:15 but, I bet *someone* is 18:26:32 I may be involved in some RBAC work this cycle… stay tuned ;-) 18:26:59 really more security policy than RBAC… details are evolving a bit 18:27:11 cool! just to be clear, security related is what i meant. 18:27:30 yeah, I know that there's been some talk about automated security dev / test 18:27:34 open thought - may need to brainstorm 18:27:49 but I haven't seen anything concrete in place yes 18:27:53 s/yes/yet/ 18:27:58 any interest in compliance engine kind of work? 18:28:14 you mean to validate the compliance of a particular deployment? 18:28:25 an engine or appliance that would monitor your cloud to validate/ warn for compliance 18:28:26 yes 18:28:36 not just SCAP kind of 18:28:51 oh, heh 18:29:01 I was about to mention that the SCAP guys are working on some openstack specific stuff 18:29:05 but that's not what you mean? 18:29:33 yes 18:30:03 so yeah, there's work happening there 18:30:05 like, can scap monitor violations coming from guests? 18:30:16 bdpayne -- on the how to get involved "bullets" are fine, they are pithy and to the point 18:30:27 ok - may be needs a snippet, follow up via email 18:30:37 from guests… you'd probably want to run SCAP inside the guests then 18:30:42 cool - good to know on SCAP work 18:30:59 ok, thanks everyone… I think that's all for today 18:31:05 #endmeeting