15:00:12 #startmeeting security 15:00:13 Meeting started Thu Jan 16 15:00:12 2020 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:00:15 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:00:17 The meeting name has been set to 'security' 15:00:21 #link https://etherpad.openstack.org/p/security-agenda agenda 15:01:12 aloha 15:01:13 o/ 15:03:09 #topic open discussion 15:03:38 I've not had much upstream time this week unfortunately, so I don't really have much 15:03:49 fungi: anything new on your end? 15:04:39 I did see the vmt process change got some more rc votes 15:05:11 yeah, it's getting close but hasn't merged yet so i haven't activated my followup todo list tasks for that 15:06:01 nothing especially exciting that i can recall. i think there's one public (nova?) vulnerability report which might be close to getting fixed in supported stable branches 15:06:20 do you have a link handy for that? 15:06:35 #link https://launchpad.net/bugs/1492140 consoleauth token displayed in log file 15:06:35 Launchpad bug 1492140 in OpenStack Security Advisory "consoleauth token displayed in log file" [Undecided,Triaged] - Assigned to Tristan Cacqueray (tristan-cacqueray) 15:06:38 danke 15:07:21 looks like a fix merged to stable-train a month ago and then a stable/stein fix was put up for review earlier this week 15:08:23 cool 15:12:59 I was sent a barbican bug that was created from their architecture review when they applied for vmt coverage 15:13:09 I'll try to find that link 15:13:25 👀👀👀 15:13:41 not sure why it wasn't marked as a security bug 15:13:45 redrobot: o/ 15:14:01 gagehugo, 👋 15:14:30 I assume those are emojis, haha 15:14:51 * gagehugo makes a note to figure out why emojis aren't working in his irc client 15:15:32 redrobot: anything you want to talk about? 15:17:43 nothing on my agenda, just curious about that barbican bug 15:19:25 it was something about ACL modification in the database 15:19:42 https://review.opendev.org/#/c/357978/13/doc/source/artifacts/barbican/newton/review-findings.rst #1 there 15:19:58 it's also a "bug" from 2016 haha 15:20:13 just something that someone internally here sent my way asking about 15:20:33 Oh, hehe, yeah, I remember that now ... 15:21:33 redrobot: was there any progress on that (that you can remember)? 15:21:49 it was 4 years ago now haha 15:22:19 I don't think so... 15:22:30 I took an OpenStack break shortly after that 15:22:38 heh 15:22:58 but I think it's still a concern that the Database could be manipulated by an attacker 15:23:06 I guess it was only 3 years 3 months 15:23:09 "only" 15:23:11 yeah 15:23:39 although if your database is vulnerable, that's another issue 15:24:22 Right. IIRC the plan was to implement some integrity checks on data coming from the database 15:24:39 maybe use the crypto backend to hmac the acl table rows 15:24:52 hmm ok 15:25:42 sorry got a hard stop here, thanks redrobot fungi! 15:25:44 I'll make a note to bring this up at the Barbican meeting next week. 15:25:54 redrobot: i'll make a note to attend 15:26:03 have a good rest of the week everyone 15:26:07 #endmeeting