17:00:52 #startmeeting Security 17:00:52 Meeting started Thu Apr 30 17:00:52 2015 UTC and is due to finish in 60 minutes. The chair is hyakuhei. Information about MeetBot at http://wiki.debian.org/MeetBot. 17:00:53 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 17:00:56 The meeting name has been set to 'security' 17:01:04 o/ 17:01:09 o/ 17:01:12 o/ 17:01:18 I like being just "Security" - so much less typing at the start of the meeting :) 17:01:20 Hi all 17:01:28 nkinder: nice to see you :) 17:01:34 o/ 17:01:45 Sorry for missing last week. I was at the RSA conference 17:01:49 heyo/ 17:01:54 ooh neat! 17:01:55 it's sort of conference season lately for me 17:01:56 pfft, you crazy kids and your security conferences... 17:02:02 nkinder: speaking or attending? 17:02:17 booth at RSA, speaking at Linuxfest Northwest 17:02:42 Fancy! 17:03:40 ok cool, so as you're here nkinder should we start off with an overview of OSSN ? 17:03:46 Sure 17:04:09 #topic OSSN 17:04:19 I just published one that elmiko wrote (his first!) 17:04:24 \o/ 17:04:30 Fantastic, congratulations elmiko! 17:04:37 Yep, much thanks! 17:04:40 thanks =) 17:04:53 I think we can +A 0046 (the Pecan one) 17:05:09 Oh cool, I think that's mine 17:05:14 There's not really a single affected project that we would expect a +1 from 17:05:22 o/ 17:05:35 I wanted to see if others were OK with me giving it a +A and bypassing the normal +1 requirement 17:05:56 Fine with me, given that there's no single stakeholder who can approve. 17:06:06 +1 17:06:24 ok, cool. I'll +A and publish it today then 17:06:39 nkinder sicarie do we want another docs core to replace bdpayne? 17:06:59 +1 17:07:35 nkinder: What do you think? 17:07:37 I think one more doc core would definitely help with timely reviews 17:07:42 yeah, I think it would help 17:07:49 Personally I think we're doing ok but there's certainly space to add one without making things messy 17:08:00 Why don't we discuss in a few weeks at the Summit? 17:08:10 Seems reasonable 17:08:49 o/ 17:08:55 sorry i'm late.. 17:09:02 We have a few stagnant notes 17:09:13 I think one of them just needs a review from the affected project 17:09:17 Let me get a link... 17:09:56 https://review.openstack.org/136203 17:10:29 We need a Neutron reviewer 17:10:38 Agreed, anyone got a friendly one? 17:11:33 looks like this is LBaaS, and there are only 4 cores 17:11:43 I just added that group to the review 17:12:02 Kyle Mestery might be the best to reach out to 17:12:05 I can do that 17:12:13 Cool, good plan nkinder 17:12:23 nkinder: Also, dougwig and blogan 17:12:46 mestery: Hi! 17:12:52 nkinder: Howdy! 17:12:53 hello 17:12:58 mestery: Sure, the more the merrier :) 17:13:05 dougwig: Security issue with LBaaS, see review above 17:13:08 We need a review on an OSSN around LBaaS before we can publish 17:13:14 looking 17:13:44 nkinder: dougwig is the right buy for sure, and I'll review now as well. Thanks for pinging me! 17:13:57 Aside from that on OSSNs, there are a few bugs I need to close out for issues we published. I'll do that today so the list is accurate. 17:14:14 mestery, dougwig: Thanks guys! 17:14:35 I have no update on the OSSN parsing script. I need more hours in the day to hack on it. ;) 17:14:43 hehe 17:15:01 Is it at a point where you'd want to share it and maybe get some others to take a whack or still too early? 17:15:13 perhaps on the flight to the Summit. I can certainly demo what I have to others there. 17:15:16 nkinder: i have to run out for a bit. ok to review that in about 2 hours? 17:15:25 dougwig: absolutely 17:15:40 hyakuhei: I'll see about pushing what I have to github so others can take a look 17:15:47 +1 17:16:02 cool, no pressure, just if you think it would be useful nkinder 17:16:03 * nkinder adds to my todo list 17:16:38 That's it on OSSNs. 17:16:48 hey guys, sorry I'm late 17:16:58 dg_: hey 17:17:11 hey dg_ 17:17:26 Thanks for the work on the OSSN nkinder 17:18:05 tkelsey: Any updates on Bandit this week? tmcpeak isn't here. 17:18:24 hummm, nothing that im aware of 17:18:32 i have a small bandit request 17:18:36 Cool 17:18:38 elmiko: oh? 17:18:41 #link https://review.openstack.org/#/c/177855/ 17:18:44 #topic bandit 17:18:52 i'm working on creating the tox stuff for our bandit gating tests 17:19:03 ah awesome :) how can i help? 17:19:06 i would love an extra eye or two on that review to maybe advise about plugins we might want to use 17:19:18 ok i'll look it over 17:19:22 nothing major, thanks! 17:19:31 :) 17:19:33 bknudson: Anything to report on Bandit in the land of Keystone? 17:20:54 I guess he's not around :) 17:21:12 #topic security.openstack.org 17:21:33 #link https://github.com/gcmurphy/python-sec-guidance 17:21:39 --^ 17:21:45 gmurphy: I recall you were possibly going to talk to the rest of the VMT about whether this should continue to be in the OSSA repo? 17:21:58 is attempt to convert existing documentation to rst 17:22:18 now we need to figure out where to put it etc / how to merge it 17:23:03 also the content needs a bit of work 17:23:20 but that's just the security guidance stuff. 17:23:25 That looks pretty nice gmurphy, the RST are pretty tidy. 17:24:05 yea, very nice 17:24:22 Thank you gmurphy 17:25:10 i had a chat with fungi last week during after the meeting. i think he has some ideas about how we could host it. i'll try to follow up with him about it. 17:25:24 That's useful, thanks 17:25:26 please do (but not on kilo release day) 17:26:19 haha 17:26:28 Yeah - happy Kilo day everyone! 17:26:51 elmiko: LGTM on your Bandit gate patch 17:27:04 tkelsey: awesome, thanks 17:27:51 elmiko: my pleasure, feel free to ping me with any specific issues that arise or general questions 17:28:13 tkelsey: cool, will do. i have some ideas for plugins that might be useful for us. 17:28:23 I don't have much else to discuss today, I think everyone is busy getting ready for the summit 17:28:34 #topic Any Other Business 17:28:36 elmiko: :) 17:28:56 hyakuhei: do we have a schedule for what's going on in the summit areas for Security? 17:29:33 Yup 17:29:39 It's all in your email, one sec 17:30:18 #link http://libertydesignsummit.sched.org/type/design+summit/Security#.VToWqRPF_8k 17:30:51 no sec guide ? :) 17:31:48 Well, that's what the email I sent out was for, we've got three sessions, VMT needs one of them. Depending on who turns up to the work session that could be on the security guide or on rebranding 17:32:00 TBH historically we've never worked on the sec guide at the summit 17:32:02 It's too involved 17:32:39 hyakuhei: understood, we were thinking there'd be some planning around both the physical book state and format conversion 17:33:01 but we can always just grab some free space for that 17:33:52 I don't have strong feelings against it, we could use the work room for that? 17:34:02 Sure 17:35:28 Cool. 17:35:34 Anything else to discuss today? 17:36:17 Nothing else here. 17:37:13 Ok cool, I think we can probably wrap then :) 17:37:31 #endmeeting