openstackgerrit | Deepti Navale proposed a change to openstack/security-doc: Include glossterm tags for Federated Identity topic https://review.openstack.org/128792 | 00:19 |
---|---|---|
*** bdpayne has quit IRC | 00:50 | |
*** tmcpeak has joined #openstack-security | 01:12 | |
*** bpokorny has quit IRC | 01:28 | |
*** salv-orlando has quit IRC | 02:05 | |
*** tmcpeak has quit IRC | 02:13 | |
*** vdreamarkitex has quit IRC | 03:37 | |
*** vdreamarkitex has joined #openstack-security | 06:10 | |
*** vdreamarkitex has quit IRC | 06:32 | |
*** salv-orlando has joined #openstack-security | 08:23 | |
openstackgerrit | Tim Kelsey proposed a change to openstack/security-doc: Adding OSSN-0038: Suds local cache poisoning. https://review.openstack.org/128636 | 09:11 |
openstackgerrit | Tim Kelsey proposed a change to openstack/security-doc: Adding OSSN-0038: Suds local cache poisoning. https://review.openstack.org/128636 | 09:17 |
*** openstackgerrit has quit IRC | 10:19 | |
*** openstackgerrit has joined #openstack-security | 10:19 | |
*** salv-orlando has quit IRC | 10:48 | |
*** vdreamarkitex has joined #openstack-security | 11:07 | |
*** amrith is now known as _amrith_ | 11:11 | |
*** dave-mccowan has joined #openstack-security | 12:25 | |
*** bknudson has joined #openstack-security | 12:47 | |
*** tmcpeak has joined #openstack-security | 12:49 | |
*** tmcpeak has quit IRC | 13:19 | |
*** dave-mccowan has quit IRC | 13:53 | |
*** elo1 has quit IRC | 13:59 | |
*** dave-mccowan has joined #openstack-security | 14:06 | |
*** tmcpeak has joined #openstack-security | 14:28 | |
*** voodookid has joined #openstack-security | 14:30 | |
*** openstackgerrit has quit IRC | 14:48 | |
*** openstackgerrit has joined #openstack-security | 14:49 | |
*** _amrith_ is now known as amrith | 14:53 | |
*** elo1 has joined #openstack-security | 15:53 | |
*** vdreamarkitex has quit IRC | 16:06 | |
*** sicarie has joined #openstack-security | 16:11 | |
*** bdpayne has joined #openstack-security | 16:23 | |
*** rlpple has joined #openstack-security | 16:57 | |
*** shohel02 has joined #openstack-security | 17:00 | |
*** dipak has joined #openstack-security | 17:40 | |
openstackgerrit | A change was merged to openstack/security-doc: Update SSL/TTL section in the security guide https://review.openstack.org/127419 | 17:40 |
*** rlpple has quit IRC | 17:57 | |
nkinder | bdpayne: so I just saw that firefox is going to disable SSLv3 in the 31esr release - https://bugzilla.mozilla.org/show_bug.cgi?id=1076983#c73 | 17:57 |
bdpayne | yeah, Chrome is disabling it too | 17:57 |
bdpayne | hopefully this is the final nail in the coffin on v3 | 17:58 |
nkinder | update is still about a month out though AFAIK | 17:58 |
nkinder | yeah, would be nice for it to die | 17:58 |
bdpayne | now if only people would implement TLS 1.2 | 17:58 |
nkinder | the main mod_nss developer (rcrit) is disabling v3 and adding TLS 1.2 | 17:59 |
nkinder | mod_ssl has 1.2 | 17:59 |
nkinder | so we're good on the httpd side of things at least | 17:59 |
*** tmcpeak1 has joined #openstack-security | 18:01 | |
*** tmcpeak has quit IRC | 18:01 | |
shohel02 | bdpayne, did you already sent me email regarding the election | 18:05 |
shohel02 | i did not get one yet | 18:05 |
bdpayne | yeah | 18:05 |
bdpayne | hrm | 18:05 |
bdpayne | can you PM me your preferred email address? | 18:05 |
shohel02 | okey... i check other mail in yahoo.. got it now | 18:06 |
shohel02 | thanks | 18:06 |
bdpayne | ah great | 18:06 |
bdpayne | shohel02 btw, I have a script that will figure out how many meetings someone has attended... so perhaps I can fill in that col on the spreadsheet once you have added any new names to check | 18:08 |
bdpayne | shohel02 actually, let me back up | 18:08 |
bdpayne | step 1 is probably to look at the launchpad group and figure out who has joined since last election | 18:09 |
bdpayne | step 2 is to add those names to the spreadsheet at the bottom | 18:09 |
bdpayne | step 3 is to then fill out the cols for each new person to see if they are eligible | 18:09 |
bdpayne | and I have a tool that can help with one of those cols, so let me know when it is time and I can run that and put the data into the spreadsheet | 18:10 |
shohel02 | okey | 18:10 |
shohel02 | i take step 1, step 2 | 18:10 |
shohel02 | then step three is the filling against criteria | 18:10 |
shohel02 | here are multiple criterias.. | 18:11 |
shohel02 | you are going to take all that part ? | 18:11 |
bdpayne | perhaps we can have multiple people help with that | 18:12 |
bdpayne | we can each take a col | 18:12 |
*** dipak has quit IRC | 18:12 | |
bdpayne | but I can certainly do the col for meeting attendance | 18:12 |
shohel02 | that sounds good.. | 18:12 |
shohel02 | okey let me first fill the new names... and see how many are there | 18:13 |
bdpayne | great, thanks for the help! | 18:13 |
shohel02 | no problem | 18:13 |
*** salv-orlando has joined #openstack-security | 18:15 | |
*** tmcpeak1 has quit IRC | 18:26 | |
*** tmcpeak has joined #openstack-security | 18:27 | |
*** tmcpeak has quit IRC | 18:52 | |
openstackgerrit | Nathaniel Dillon proposed a change to openstack/security-doc: Re-submitting OSSN 25 concerning Swift/Glance public images https://review.openstack.org/117928 | 18:53 |
*** xen_roger has joined #openstack-security | 19:35 | |
*** xen_roger has left #openstack-security | 19:36 | |
*** dipak has joined #openstack-security | 20:03 | |
*** bknudson has quit IRC | 20:14 | |
*** dipak has quit IRC | 20:19 | |
*** gabriela has joined #openstack-security | 20:26 | |
*** gabriela has left #openstack-security | 20:26 | |
*** amrith is now known as _amrith_ | 20:31 | |
*** tmcpeak has joined #openstack-security | 20:35 | |
*** dave-mccowan has quit IRC | 20:49 | |
*** shohel02 has quit IRC | 20:50 | |
*** bdpayne has quit IRC | 20:51 | |
*** bdpayne has joined #openstack-security | 20:51 | |
tmcpeak | hey | 20:53 |
tmcpeak | so that link that Mr. Payne put in the meeting | 20:53 |
tmcpeak | mentions that downgrades are a product of browser behavior | 20:54 |
tmcpeak | do we have any reason to think that Python libraries are vulnerable to the same behavior? | 20:54 |
*** bdpayne has quit IRC | 20:56 | |
*** bdpayne has joined #openstack-security | 20:56 | |
*** bdpayne has quit IRC | 21:01 | |
*** dave-mccowan has joined #openstack-security | 21:03 | |
tmcpeak | nkinder: ^ thoughts? | 21:03 |
nkinder | tmcpeak: they may not be (at least for the downgrade portion of this) | 21:05 |
nkinder | tmcpeak: I would think that the downgrade part is browser specific, but I haven't looked into it | 21:05 |
tmcpeak | nkinder: if a downgrade isn't possible, then it really shouldn't be much of an issue for OpenStack, surely client and server will agree on something better than SSL3, yeah? | 21:10 |
nkinder | tmcpeak: still would want to disable v3 | 21:11 |
nkinder | something better might be agreed upon, but the recommendation should be to disable v3 | 21:11 |
tmcpeak | nkinder: sure, might as well disable it, but… I don't see any urgency without the downgrade dance possibility | 21:12 |
nkinder | tmcpeak: though there's always horizon to worry about | 21:12 |
tmcpeak | nkinder: yeah, that's true | 21:16 |
*** bdpayne has joined #openstack-security | 21:41 | |
*** dave-mccowan_ has joined #openstack-security | 21:48 | |
*** dave-mccowan has quit IRC | 21:49 | |
*** dave-mccowan_ is now known as dave-mccowan | 21:49 | |
bdpayne | nkinder I'd like to start working on the ossn for poodle | 22:24 |
bdpayne | nkinder I don't see a bug filed for that yet... should I file a bug? | 22:24 |
*** tmcpeak has quit IRC | 22:30 | |
*** _amrith_ is now known as amrith | 22:40 | |
*** voodookid has quit IRC | 23:03 | |
*** bdpayne has quit IRC | 23:16 | |
nkinder | darn, missed bdpayne... | 23:27 |
*** sicarie has quit IRC | 23:41 | |
*** tmcpeak has joined #openstack-security | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!