15:00:39 #startmeeting security 15:00:40 Meeting started Thu Nov 12 15:00:39 2020 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:00:41 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:00:43 The meeting name has been set to 'security' 15:01:35 #link https://etherpad.opendev.org/p/security-agenda agenda 15:01:47 ohai 15:01:56 o/ 15:06:47 might be just us 15:07:00 people may have been confused by local time changes 15:07:30 I am still confused 15:07:39 #topic Nov 26th meeting 15:07:54 Since it's thanksgiving in the US, I will cancel that week's meeting 15:11:12 works for me 15:11:27 i'll likely be around, but will probably be trying to stay off the computer 15:11:42 same 15:11:52 #topic open discussion 15:11:57 fungi: anything for this week? 15:13:24 #link https://launchpad.net/bugs/1901207 Application credentials of other users can be deleted when knowing the ID 15:13:26 Launchpad bug 1901207 in OpenStack Identity (keystone) "Application credentials of other users can be deleted when knowing the ID" [High,In progress] - Assigned to Lance Bragstad (lbragstad) 15:13:35 #link https://launchpad.net/bugs/1902917 Anti-spoofing bypass using Open vSwitch 15:13:36 Launchpad bug 1902917 in OpenStack Security Advisory "Anti-spoofing bypass using Open vSwitch" [Undecided,Incomplete] 15:13:46 #link https://launchpad.net/bugs/1903531 Update of neutron-server breaks compatibility to previous neutron-agent version 15:13:47 Launchpad bug 1903531 in neutron "Update of neutron-server breaks compatibility to previous neutron-agent version" [Critical,Confirmed] 15:13:57 those have all been made public since the last meeting, i think 15:15:15 i don't see any others 15:18:08 administrative changes for opendev's gerrit have been proceeding too 15:18:58 #link https://docs.opendev.org/opendev/system-config/latest/sysadmin.html#gerrit-admins Split admin/non-admin Gerrit accounts 15:19:53 the gerrit admin accounts no longer have openids logins, and admins are using separate accounts for non-administrative day to day interactions 15:20:20 we're also trying out launchpad's two-factor authentication option 15:21:29 i've purchased a pair of purism librem keys (nitrokey clones with some additional features in firmware) as totp authenticators, but running into typical bleeding-edge/early-adopter hardware support challenges 15:22:46 interesting 15:24:31 yeah, 2FA is probably a good path forward haha 15:27:02 https://review.opendev.org/#/c/759940/ is still in review 15:27:03 patch 759940 - keystone - Hide AccountLocked exception from end users - 3 patch sets 15:28:05 is the tempest failure related or random? 15:28:37 random I think, it failed 4 mins in running 15:28:51 ahh, okay 15:29:05 just wondering if that's why it's not garnered any reviews yet 15:29:28 might be worth bringing the security relevancy to the attention of keystone reviewers 15:29:43 Once it passes I'll bug some keystone reviewers 15:33:16 thanks fungi: have a good rest of the week! 15:33:21 #endmeeting