17:00:00 #startmeeting security 17:00:02 Meeting started Thu Sep 8 17:00:00 2016 UTC and is due to finish in 60 minutes. The chair is tmcpeak. Information about MeetBot at http://wiki.debian.org/MeetBot. 17:00:03 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 17:00:05 The meeting name has been set to 'security' 17:00:07 #chair hyakuhei 17:00:07 Current chairs: hyakuhei tmcpeak 17:00:09 o/ 17:00:11 o/ 17:00:14 o/ 17:00:15 o/ 17:00:17 ohai o/ is this the cool peoples' rendevouz? 17:00:23 yups 17:00:27 hi 17:00:29 hola 17:00:29 o/ 17:00:37 good, just wanted to make sure I'm in the right place :D 17:00:38 #link https://etherpad.openstack.org/p/security-agenda 17:01:02 we'll give a couple minutes for people to stream in and then get going 17:01:05 o/ 17:01:06 o/ 17:01:09 o/ 17:01:18 o/ 17:01:35 stream? are we playing counterstrike? goodie! 17:01:37 how many underscores is that now? 17:02:12 i hear that everytime dg get's another underscore an angel gets it wings XD 17:02:27 lol 17:02:30 he adds one every time he secures something 17:02:35 haha 17:02:45 he needs waaaay more underscores then... 17:02:53 everybody, please add any topical items to the etherpad 17:03:19 jasonhullinger: did you want to discuss Bandit plugin again or you done on that for now? 17:03:30 No, done with taht 17:03:34 ok cool 17:03:36 #topic Anchor 17:03:48 browne brought up that there are a bunch of reviews just waiting for +A 17:03:49 so... 17:03:57 tkelsey: dg_____ underscore underscore underscore 17:03:58 what's up 17:04:04 yep, friendly reminder. please review some 17:04:15 browne: will do! 17:04:23 tkelsey: thx 17:04:34 sweet, that was easy 17:04:38 #topic Syntribos 17:04:39 sorry for the lag, will pay more attention to Anchor reviews 17:04:46 np 17:04:49 no worries man, been a while since any action on Anchor 17:04:51 browne ok sorry 17:04:54 thanks for reminding browne 17:04:57 yup 17:04:59 i was a bit supprised it was on the agenda 17:05:03 :P 17:05:08 unrahul: you're up 17:05:30 hey tmcpeak 17:05:38 so we are testing neutron this week 17:06:01 well we created the templates (manually :|) and was tweaking it a lil bit ysday 17:06:14 how's that all going? 17:06:40 As for neutron lot of the apis are admin only , we are getting lot of 404s.. so need to filter those out.. 17:06:56 we got a few 500s , but those might be false positive.. 17:07:05 Nothing as such to report for now.. 17:07:31 cool cool 17:07:33 we will keep on testing today and tomorrow and let you guys know if we find something cool. 17:07:45 Do you guys have any pointers on neutron testing.. 17:07:50 like which apis or something..? 17:08:06 that needs careful testing, possible attack surfaces.. etc..? 17:08:27 personally I know nothing about Neutron, probably less than a random dude off the street 17:08:34 sicarie: <3 Neutron 17:08:37 ? 17:08:47 lol 17:08:49 lol 17:08:55 sicarie: :D any pointers..? 17:09:08 like how I just randomly picked on sicarie? :D 17:09:15 hehe.. 17:09:17 rofl 17:09:19 thanks tmcpeak ! 17:09:22 he might at least know people, that's what I threw out his handle 17:09:23 unrahul: away from the security guide - we've been trying to get reviews on that for quite a while 17:09:43 you may want to ping tristanC, he did a great deal of api fuzz testing against neutron 17:09:48 elmiko: +1 17:09:49 also, found several bugs that way 17:10:08 oh cool will ping him then thanks elmiko .. 17:10:21 sweet 17:10:23 so thats it from us.. for this week..then 17:10:24 np, good luck! 17:10:28 cool, thanks for update 17:10:30 #topic OSSN 17:10:32 lhinds: 17:10:34 thank elmiko ! 17:10:55 so the big 0069 got merged 17:10:57 https://review.openstack.org/#/c/356712/ 17:11:01 well done vinaypotluri 17:11:07 woot! 17:11:14 we did it lhinds ... cheers !!! 17:11:15 we have yet to get a +2 from neutrong, but.... 17:11:18 the longest email threat I've ever seen :P 17:11:37 Brian Haley made a small nit 17:11:39 vinaypotluri++ 17:11:40 oh, did I merge it prematurely? 17:11:48 good work vinaypotluri! 17:11:49 congrats vinaypotluri 17:11:49 and said he was happy it that was fixed (whcih is was) 17:11:55 so for me, this is good enough 17:12:04 thank you singlethink :) 17:12:08 but though prudent to just check wit you guys as well 17:12:39 you can see Brian at patch-set 18 17:12:46 he is Neutron core 17:13:19 lhinds: should we change the status of the bug on the launchpad ? 17:13:36 so I will send out the email this eve and populate the wiki - unless any objections? 17:13:36 https://bugs.launchpad.net/ossn/+bug/1534652 17:13:38 Launchpad bug 1534652 in OpenStack Security Notes "Host machine exposed to tenant networks via IPv6" [Undecided,Confirmed] - Assigned to Vinay Potluri (vinay-potluri) 17:13:45 lhinds: sounds good! 17:13:50 great 17:14:16 other then that I have a few more I am just trying to shepard cores into reviewing. 17:14:24 the other thing is I spoke with haleyb 17:14:27 duh! 17:14:28 cool, how's our queue look? 17:14:33 whodat? 17:14:46 that was a failed autocomplete then 17:15:12 queue last time I checked was around 4-5 with embargoes 17:15:13 lhinds: what did i do? :) 17:15:20 lol 17:15:21 sorry haleyb 17:15:31 I tapped and got the wrong nick ! 17:15:38 so we just have embargoed notes in the queue? 17:15:42 no, it was me, just didn't see s/b 17:16:33 I see 8... 17:16:36 there is a couple of others non, a horizon one, and one on mongoDB I need to talk with michaelxin about 17:16:42 I think I have two in progress, Rob has a couple in progress 17:17:03 I have one embargo to work on as well. 17:17:17 honestly we could probably still use a 4th to work on embargoed notes, given the prevalence of them these days 17:17:19 any takers? 17:17:58 allright :P 17:17:58 the other thing was I chatted with Rob about having an API for notes 17:18:06 API? 17:18:10 tmcpeak: does it require a lot of experience ..? 17:18:17 where operators could query by release etc. 17:18:34 started to work on something, its very rough still, so a side project 17:18:37 hmm 17:18:44 lhinds that really is quite a good idea 17:18:44 #link http://lukehinds.pythonanywhere.com/ 17:18:51 unrahul: it requires pretty good security experience… 17:19:04 it has web front end, but i don't mean it to replace the wiki 17:19:05 lhinds: oh, this is cool 17:19:18 I tend to design the front end, and then layer a rest-framework on top 17:19:24 tmcpeak: ah.. so I am just starting ,so moving on 17:19:25 helps me sketch out the model well 17:19:54 but its rough! so don't look at it as anything beyond a half complete prototype 17:20:04 dg_____: you seem like a natural candidate, you interested? 17:20:23 for the embargoed notes? 17:20:23 for security core? 17:20:25 yeah 17:20:38 yeh im defintiely interestest 17:20:42 dg_____: +1 17:20:47 voluntold! 17:20:49 apart from a complete inability to spell 17:20:52 haha thanks 17:20:56 spelling is optional 17:21:02 see what hyakuhei says? 17:21:23 yeah, we can wait until next week to confirm, but you have a good mix of security experience and track record of OS participation 17:21:38 agree 17:21:47 ok cool, happy to help out more 17:22:29 sweet! 17:22:29 wait, dg_____ isn't sec-core...?!? 17:22:42 sec-core is way overloaded 17:22:48 ack 17:22:54 we have the docs cores, but then also embargoed notes people 17:22:57 elmiko im anchor core 17:23:11 elmiko: I think you were all of those things, but I, for example, am not a docs core 17:23:18 ah, ok 17:23:25 sorry to interrupt 17:23:27 just an embargoed notes creep 17:23:29 elmiko is all the things 17:23:35 heh 17:23:53 kewl, anything else for notes? 17:24:04 #topic Blog 17:24:07 bloggity blog blog 17:24:13 lhinds again 17:24:14 dg_____: etc 17:24:20 I still have something pending 17:24:26 s'sup to you guys now 17:24:32 where we at on that? 17:24:37 dg_____: did you get a chance to review? 17:24:48 had a couple of nit rounds, but should be ok now. 17:25:02 cool, merge it then 17:25:04 yolo 17:25:06 i gave it a brief look, but meant to go back 17:25:08 https://github.com/openstack-security/openstack-security.github.io/pull/25 17:25:09 yeah i commented on a bunch of nits, will take another look and we are good t ogo 17:25:14 lhinds ty 17:25:15 ok cool 17:25:20 thanks dg_____, elmiko 17:25:48 cool 17:25:52 #topic Security Review 17:25:58 TA is now known as security review 17:26:06 neat 17:26:07 dg_____: you're kind of leading this, where did we get? 17:26:46 waiting on me to push a couple of patches 17:27:09 ok, are we done with Barbican? 17:27:13 ive got one on redrobot's patch on barbican TA 17:27:20 and one on the docs for the process 17:27:34 tmcpeak - i think so, but lets see what it looks like when i push it up 17:27:40 it would be nice to get the designate one through soon as well 17:27:56 dg_____: Kolla wants to do it 17:28:21 designate was an internal one by HPE, which is quite a different process, but i think we pretty much rubber stamp it 17:28:28 is sdake here? 17:28:58 tmcpeak yeah, we hae talked to kolla a few times, really want to get that one through before the summit - shouldnt be long, althouhg the process is now very different to the one we discussed at the texas summit 17:29:19 dg_____: for sure, sdake_ showed up last meeting and said he'll set up a time for us to go through this 17:29:29 oh awesome 17:29:44 did you tell him not to bother making all the sequence diagrams we asked him to before..... 17:30:07 yes 17:30:48 ok awesome, thanks 17:31:18 cool, anything else for TA? 17:31:30 not from me 17:32:18 manila was expressing interest in maybe being an early adopter of the process 17:32:19 cool 17:32:30 fungi: that would be awesome, who's a good contact for them? 17:32:42 they just had their meeting a few minutes ago and were talking about it 17:32:57 bswartz is probably a good primary contact but there were several volunteers to work on it 17:32:59 who are manila? 17:33:03 let me pull up their minutes 17:34:06 #link http://eavesdrop.openstack.org/meetings/manila/2016/manila.2016-09-08-15.00.log.html#l-120 manila meeting log for ta topic from earlier today 17:34:39 fungi: thanks, we'll take a look 17:34:46 thanks fungi 17:34:51 tbarron and gouthamr seem to have volunteered 17:34:55 +1 17:35:00 dg_____: can you synch with them? 17:35:26 tmcpeak sure 17:35:36 #action dg_____ to reach out to Manilla 17:35:39 cool 17:35:44 #topic Summit Sessions 17:35:55 just a reminder, we're looking for security activities for those going to the Barcelona summit 17:36:24 #link https://etherpad.openstack.org/p/barcelona-security-sessions 17:36:28 if you're attending please add your name also 17:36:48 im going to put in a vote for PKI and Security Review 17:36:58 not sure if im going, budgets and politics 17:37:08 fair enough 17:37:42 i'll be there. got approval yesterday 17:38:00 browne: awesome 17:38:54 that's all I had 17:38:55 #topic AOB 17:38:58 open floor… 17:39:11 * dg_____ drops the mic 17:39:47 lhinds: body pops 17:39:51 allright 17:39:53 #endmeeting