15:02:18 #startmeeting security 15:02:19 Meeting started Thu Aug 2 15:02:18 2018 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:02:20 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:02:22 The meeting name has been set to 'security' 15:02:33 ping eeiden fungi gagehugo lhinds nickthetait browne redrobot 15:03:00 around but also in tc office hour as usual 15:03:09 (back from vacation at least!) 15:03:35 fungi o/ hope the vacation was good 15:05:00 I will be covering for lhinds chairing for the next 3 weeks, I believe he is out on PTO 15:05:27 nickthetait o/ 15:06:30 Hey 15:07:00 #topic bandit migration 15:07:23 I believe lhinds had this on his agenda, no updates from me 15:07:52 #topic OSSN/OSSA 15:08:10 fungi nickthetait any updates? 15:08:25 No 15:09:16 there's this: 15:09:35 #link https://review.openstack.org/586896 Remove Security project team 15:09:55 basically cleanup and reassigning its deliverable repos to the security sig 15:09:55 oh yeah 15:10:20 easier than bothernig to have someone volunteer to be ptl of a defunct team for another cycle 15:10:26 er, bothering 15:11:13 also there's been some followup discussion on ossa-2018-002 that it may be an incomplete fix 15:11:26 Hmm 15:11:40 https://bugs.launchpad.net/keystone/+bug/1779205 15:11:40 Launchpad bug 1779205 in OpenStack Identity (keystone) rocky "[OSSA-2018-002] GET /v3/OS-FEDERATION/projects leaks project information (CVE-2018-14432)" [Critical,Fix released] - Assigned to Lance Bragstad (lbragstad) 15:11:55 #link https://launchpad.net/bugs/1779205 15:12:03 yeah 15:12:30 anyone who wants to pitch in on that is welcome. it's all public 15:14:56 #topic documentation 15:15:16 nothing from me here 15:15:31 Same 15:15:36 nada 15:15:51 #topic threat analysis 15:16:24 https://review.openstack.org/#/q/project:openstack/security-analysis 15:16:43 there's some projects under the keystone umbrella that have drafts 15:16:53 I think the pycadf one should be close 15:17:02 it's a pretty simple library 15:17:53 not sure about the other two, I need to double check 15:18:09 but that's all I got for this 15:18:33 Ok 15:19:32 #topic PTG 15:19:48 little over a month away now 15:20:06 we're sharing a room with Barbican I believe Mon/Tue 15:20:13 * nickthetait gets excited 15:21:26 keystone is being weird this time and having Mon/Thur/Fri sessions, so Mon I will likely be more involved in there, but I should be around 15:21:51 I believe it's for a cross-project day 15:22:25 yeah, mon/tue are focused on cross-project activities 15:22:38 for the ptg in general i mean 15:22:44 I can reach out to Ade and we can figure out an agenda for us sharing 15:23:45 If anyone has anything they want to discuss there, please add it to the agenda 15:23:55 #link https://etherpad.openstack.org/p/security-agenda 15:24:28 #topic open discussion 15:24:35 floor is open 15:24:40 qq on #link https://bugs.launchpad.net/keystone/+bug/1779205 15:24:40 Launchpad bug 1779205 in OpenStack Identity (keystone) rocky "[OSSA-2018-002] GET /v3/OS-FEDERATION/projects leaks project information (CVE-2018-14432)" [Critical,Fix released] - Assigned to Lance Bragstad (lbragstad) 15:24:56 lbragstad o/ 15:24:58 the patches we merged were to all supported releases 15:25:33 and it makes the implementation consistent regardless of the branch - but i think people were a little confused about the vulnerability description 15:25:48 is there anyway to change that after disclosing the report? 15:25:54 or has that ship sailed? 15:25:59 the bit about enabling via policy.json? 15:26:05 yeah 15:26:13 fungi: ^ 15:26:16 and some of that gyee had input on is valueable 15:26:43 or do we just keep evolving the context in the bug report? 15:27:22 we issue errata in that case 15:27:59 Some relevant personal news... On Aug 20 I start as a Security Engineer for Red Hat focusing on OpenStack 😊 15:28:00 basically we update the ossa, add a history section to it noting the modification, and send another round of public announcements about the errata 15:28:35 it happens infrequently enough we might be lacking documentation about that process 15:28:35 fungi: ack - so is that some i can initiate? 15:28:38 nickthetait grats! 15:29:08 lbragstad: definitely! the openstack/ossa repo is in public code review for precisely that reason. we love having the community involved 15:29:08 thanks. I am pretty excited 15:29:14 fungi: yeah - i was going to say, i've never had to step through this after a disclosure goes public 15:29:24 fungi: ah ok 15:29:31 lbragstad: if you skim/git grep older ossas you should be able to find an errata example 15:29:38 if you can't, lmk and i'll dig one up 15:29:53 cool - i can try and get something worked up today and propose it for review 15:30:03 thanks! i'll be around 15:30:11 see if i can get gyee and kmalloc to weigh in on it 15:30:12 happy to review when you have it up 15:30:19 thanks for the help 15:32:17 thanks everyone! 15:32:22 #endmeeting