17:05:42 #startmeeting security 17:05:43 unrahul: never was told that we were actually going to hold it 17:05:43 Meeting started Thu Feb 16 17:05:42 2017 UTC and is due to finish in 60 minutes. The chair is sigmavirus. Information about MeetBot at http://wiki.debian.org/MeetBot. 17:05:45 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 17:05:47 The meeting name has been set to 'security' 17:05:50 oooh lag is bad, eh? 17:05:51 o/ 17:05:55 o/ 17:05:58 o/ 17:05:58 yaay! 17:05:58 o/ 17:05:59 #topic Roll Call 17:06:05 o/ 17:06:08 o/ 17:06:09 o/ 17:06:17 Wow, great crowd today 17:06:22 o/ sorry Im late 17:06:51 You're not late at all capnoday 17:06:56 o/ 17:07:04 Welcome jessegler ! 17:07:22 #info We started 5 minutes late which means we have 25 min for our meeting now :) 17:07:32 #topic OSSN 17:07:39 Any Security Note updates lhinds ? 17:09:00 we have one public open, which I will knock this week 17:09:09 all will be closed then 17:09:33 that's it 17:10:06 lhinds: I believe Magnum added an OSSN task 17:10:10 But it's probably still private 17:10:17 let me check 17:10:24 strigazi was discussing a CVE they're workign on in #openstack-security 17:10:47 have they assigned OSSN to the LP bug yet? 17:11:16 oh sounds like its a OSSA if a CVE is in order 17:12:33 lhinds: they have obtaineda CVE already 17:12:41 * sigmavirus shrugs 17:12:54 They're not vulnerability:managed as far as strigazi could tell 17:13:31 that would explain why I am not seeing anything yet. sounds interesting,,will have a look 17:13:45 containers :-P 17:16:03 :D 17:16:11 #topic Security Guide 17:16:35 I think hyakuhei last week touched on the fact that we're now managing the bugs for this and working more closely with asettle and the manuals team 17:16:47 I think we still need some people who can help out and tackle some of those bugs 17:16:57 Anyone else have updates on this? 17:17:01 YOu rangggg 17:17:09 Oh yes! 17:17:10 Yes, Lurch, we did 17:17:21 I can certainly look at some (sec guide) 17:17:42 I have scheduled some time to chat about the sec-guide in the docs sessions on the Tuesday. https://etherpad.openstack.org/p/docs-i18n-ptg-pike 17:18:06 I'd like to talk about how we can work together, plan it appropriately, ensure the sec team doesn't feel like we've just dumped a guide on your doorstop, so to speak 17:18:07 asettle great, hyakuhei and I will come along to that 17:18:14 Graet thanks capnoday :) 17:18:16 cool 17:18:44 A lot of the issues with the guide are either in a bug, or are already identified by hyakuhei 17:19:01 we should be able to help with security guide 17:19:16 Swell :) michaelxin did your team take a look? 17:19:31 +1 michaelxin 17:19:51 We are testing Glance now. We did a look and did not find any bug related with Glance. 17:19:57 Rahul is interested in a SSL one. 17:20:09 But he has not assigned it yet. 17:20:27 yup michaelxin I was looking into the one, to update SSL/TLS intro 17:20:40 I shall be assigning that to myself 17:23:41 Great 17:23:47 Sorry, I'm managing 2 meetings and other work 17:23:50 I'm reading through a few bugs and will be assigning one to myelf soon 17:24:01 Moving along :) 17:24:10 #topic Barbican SimpleCrypto Spec 17:24:19 #link https://review.openstack.org/#/c/431228/2/specs/pike/enhance-simple-crypto.rst 17:24:35 hyakuhei: asked us to review that last week, figured I'd just remind you all to review it in anticipation for the PTG 17:24:41 I don't know if barbican will have a presence or not 17:25:06 I did a quick review on it mostly questions and a few comments. 17:26:25 The comment by hyakuhei on including simplecrypto as part of the barbican threat analysis seems valid 17:27:03 #topic Any Other Business 17:27:07 #info 3 minutes left 17:27:18 #link https://etherpad.openstack.org/p/ptg-security-team 17:28:20 sigmavirus: we are working on glance testing for this week, I am doing the source code review 17:28:55 i was investigating the http store for glance part... 17:28:57 with a few of us in the team doing manual testing of API and running syntribos, we have identified few 500 issues and are looking for anything more 17:29:42 unrahul: sounds like fun 17:29:42 I'm working on the multiple locations issue of glance and manually testing glance. 17:30:00 yeah knangia was working on the http_store part and with v2 glance API http_store seems disabled and also from horizon we can't access that feature.. 17:30:07 so I guess it is disabled.. 17:30:25 yes unrahul 17:30:30 #endmeeting