*** markvoelker has quit IRC | 00:03 | |
*** ljfisher has joined #openstack-security | 00:07 | |
*** singlethink has quit IRC | 00:08 | |
*** voodookid has quit IRC | 00:08 | |
*** bknudson has joined #openstack-security | 00:37 | |
*** markvoelker has joined #openstack-security | 01:04 | |
*** JAHoagie has quit IRC | 01:09 | |
*** markvoelker has quit IRC | 01:13 | |
*** bpokorny_ has joined #openstack-security | 01:23 | |
*** ljfisher has quit IRC | 01:25 | |
*** bpokorny has quit IRC | 01:26 | |
*** tmcpeak has joined #openstack-security | 01:30 | |
*** tmcpeak has quit IRC | 01:38 | |
*** fletcher has quit IRC | 01:41 | |
*** tmcpeak has joined #openstack-security | 01:43 | |
*** bdpayne has quit IRC | 01:45 | |
*** tmcpeak has quit IRC | 01:45 | |
*** pdesai has joined #openstack-security | 01:49 | |
*** bpokorny_ has quit IRC | 02:14 | |
*** pdesai has quit IRC | 02:22 | |
*** markvoelker has joined #openstack-security | 02:26 | |
*** browne has quit IRC | 02:59 | |
*** bdpayne has joined #openstack-security | 03:07 | |
*** bdpayne has quit IRC | 03:21 | |
*** vozcelik has joined #openstack-security | 03:31 | |
*** vozcelik has quit IRC | 03:34 | |
*** bpokorny has joined #openstack-security | 03:37 | |
*** browne has joined #openstack-security | 03:39 | |
*** d0m3n1c has joined #openstack-security | 04:01 | |
*** d0m3n1c has left #openstack-security | 04:02 | |
*** bpokorny has quit IRC | 04:48 | |
*** bpokorny has joined #openstack-security | 04:49 | |
*** bpokorny has quit IRC | 04:58 | |
*** markvoelker has quit IRC | 04:59 | |
*** markvoelker has joined #openstack-security | 05:00 | |
*** markvoelker has quit IRC | 05:04 | |
*** JAHoagie has joined #openstack-security | 05:23 | |
*** markvoelker has joined #openstack-security | 05:30 | |
*** markvoelker has quit IRC | 05:35 | |
*** dave-mccowan has quit IRC | 05:38 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Imported Translations from Transifex https://review.openstack.org/160643 | 06:01 |
---|---|---|
*** redrobot has quit IRC | 06:21 | |
*** redrobot has joined #openstack-security | 06:25 | |
*** redrobot is now known as Guest32544 | 06:25 | |
*** markvoelker has joined #openstack-security | 06:31 | |
*** markvoelker has quit IRC | 06:36 | |
*** J1nn has joined #openstack-security | 06:38 | |
J1nn | hows it going | 06:39 |
J1nn | nice | 06:40 |
*** JAHoagie has quit IRC | 06:42 | |
J1nn | anyone know how to bypass av for reverse tcp pdf | 06:45 |
*** J1nn has left #openstack-security | 06:49 | |
openstackgerrit | Merged openstack/security-doc: Imported Translations from Transifex https://review.openstack.org/160643 | 06:55 |
*** dstufft has quit IRC | 07:08 | |
*** dstufft has joined #openstack-security | 07:15 | |
*** openstackgerrit has quit IRC | 07:22 | |
*** openstackgerrit has joined #openstack-security | 07:22 | |
*** markvoelker has joined #openstack-security | 07:32 | |
*** markvoelker has quit IRC | 07:37 | |
*** browne has quit IRC | 08:07 | |
*** markvoelker has joined #openstack-security | 08:33 | |
*** markvoelker has quit IRC | 08:39 | |
*** markvoelker has joined #openstack-security | 09:35 | |
*** markvoelker has quit IRC | 09:39 | |
*** markvoelker has joined #openstack-security | 10:35 | |
*** markvoelker has quit IRC | 10:40 | |
*** markvoelker has joined #openstack-security | 11:36 | |
*** markvoelker has quit IRC | 11:41 | |
*** tmcpeak has joined #openstack-security | 12:25 | |
*** markvoelker has joined #openstack-security | 12:38 | |
*** markvoelker has quit IRC | 12:42 | |
*** dave-mccowan has joined #openstack-security | 12:48 | |
*** markvoelker has joined #openstack-security | 13:04 | |
*** ljfisher has joined #openstack-security | 14:17 | |
*** nkinder has quit IRC | 14:24 | |
*** salv-orlando has joined #openstack-security | 14:43 | |
*** sicarie has joined #openstack-security | 15:07 | |
*** nkinder has joined #openstack-security | 15:08 | |
openstackgerrit | Merged stackforge/bandit: Return the full name used in calls https://review.openstack.org/160546 | 15:39 |
*** rkgudboy has joined #openstack-security | 15:46 | |
*** voodookid has joined #openstack-security | 15:47 | |
*** tmcpeak1 has joined #openstack-security | 16:00 | |
*** rkgudboy has quit IRC | 16:02 | |
*** tmcpeak has quit IRC | 16:02 | |
tmcpeak1 | bknudson: where is the keystone meeting going to be? | 16:04 |
tmcpeak1 | also it's in about 2 hours, right? :) | 16:04 |
bknudson | #openstack-meeting | 16:04 |
tmcpeak1 | cool | 16:05 |
bknudson | y, it's in 2 hours | 16:05 |
tmcpeak1 | cool, see you then | 16:05 |
*** browne has joined #openstack-security | 16:14 | |
*** dave-mccowan has quit IRC | 16:15 | |
*** bpokorny_ has joined #openstack-security | 16:20 | |
*** pdesai has joined #openstack-security | 16:25 | |
openstackgerrit | Leon Zachery proposed openstack/security-doc: Add reference links to Openstack Security Guide - Securing Openstack networking services section https://review.openstack.org/160868 | 16:26 |
*** canaima_ has joined #openstack-security | 16:35 | |
*** canaima_ has quit IRC | 16:35 | |
openstackgerrit | Caio Oliveira proposed openstack/security-doc: Removal of unnecessary parts of the text about boot process using TSL https://review.openstack.org/160881 | 16:43 |
*** Guest32544 is now known as redrobot | 16:51 | |
*** bpokorny has joined #openstack-security | 17:01 | |
*** bpokorny_ has quit IRC | 17:05 | |
*** ljfisher has quit IRC | 17:05 | |
*** bpokorny has quit IRC | 17:05 | |
*** bpokorny has joined #openstack-security | 17:12 | |
openstackgerrit | Priti Desai proposed openstack/security-doc: Adding Security Checklist https://review.openstack.org/157164 | 17:24 |
*** rkgudboy has joined #openstack-security | 17:29 | |
openstackgerrit | Caio Oliveira proposed openstack/security-doc: Removal of unnecessary parts of the text about boot process using TLS https://review.openstack.org/160881 | 17:38 |
*** ljfisher has joined #openstack-security | 17:47 | |
*** bpokorny_ has joined #openstack-security | 17:54 | |
*** bpokorny has quit IRC | 17:57 | |
*** bdpayne has joined #openstack-security | 18:00 | |
tmcpeak1 | Bandit in #openstack-meeting during Keystone weekly | 18:01 |
*** browne has quit IRC | 18:02 | |
*** dave-mccowan has joined #openstack-security | 18:12 | |
tmcpeak1 | that went great, thanks bknudson | 18:27 |
ljfisher | yeah, good. | 18:28 |
bknudson | tmcpeak1: yes, thanks for answering the questions. | 18:28 |
bknudson | I think you can see that there would be some concerns if this just popped up. | 18:28 |
tmcpeak1 | :) I'm going to have a mini-party when this gets into Keystone gate | 18:28 |
tmcpeak1 | yeah, was great to talk to the folks ahead of time | 18:28 |
ljfisher | good to see everyone so receptive | 18:30 |
tmcpeak1 | yeah, definitely | 18:30 |
*** bpokorny has joined #openstack-security | 18:31 | |
ljfisher | it does raise the point of if we need to worry about adding new tests without running it at least on openstack projects first. But that is difficult to manage. | 18:31 |
tmcpeak1 | ljfisher: I usually have a run against my OpenStack project directory anyway | 18:31 |
ljfisher | and you examine all the results every time? | 18:32 |
ljfisher | every time you add a new test that is? | 18:32 |
tmcpeak1 | I run them for stability | 18:33 |
ljfisher | seems like a diff of the json output could be handy for that | 18:33 |
ljfisher | yeah, that is good | 18:33 |
tmcpeak1 | I'm not currently running them to check and make sure we aren't 0-daying somebody | 18:33 |
tmcpeak1 | but, yeah, we should :) | 18:33 |
*** bpokorny_ has quit IRC | 18:34 | |
ljfisher | maybe a tox test to pull OpenStack projects down, run bandit, save json result, and then next run diff against the last | 18:34 |
tmcpeak1 | yeah, that would be awesome | 18:35 |
ljfisher | do we have a list of desired features anywhere? | 18:35 |
tmcpeak1 | TODO here: https://wiki.openstack.org/wiki/Security/Projects/Bandit#TODO | 18:36 |
tmcpeak1 | I just added you as Bandit core on there too | 18:36 |
ljfisher | Can we create todos in launchpad? | 18:40 |
ljfisher | it seems very bug centric | 18:41 |
tmcpeak1 | ljfisher: yeah, that would be a good place for features too | 18:42 |
tmcpeak1 | wiki TODO kind of sucks | 18:42 |
ljfisher | esp as the list gets long | 18:42 |
ljfisher | I think todos are more blueprints in launchpad | 18:42 |
tmcpeak1 | yeah as it is I haven't looked at it in months | 18:42 |
tmcpeak1 | ick | 18:43 |
tmcpeak1 | blueprints | 18:43 |
tmcpeak1 | we need something less rigid than that | 18:43 |
ljfisher | can we just be less rigid with them? Not sure how much launchpad forces on you | 18:43 |
tmcpeak1 | hmm | 18:43 |
tmcpeak1 | good Q | 18:43 |
tmcpeak1 | let me dig | 18:43 |
tmcpeak1 | hmm ok | 18:44 |
tmcpeak1 | looks like it should work | 18:44 |
gmurphy | my 2c (not that it matters) is you should be able to expand most of those todos into bugs. you can always close them as wont-fix if they don't end up requiring code changes. also helps with tracking of who is working on what.. | 18:44 |
ljfisher | my only concern with doing as bugs is can we filter on just those | 18:45 |
tmcpeak1 | gmurphy: you're right, many of these are flat out bugs | 18:45 |
gmurphy | you mean group by todos? or group by bandit? | 18:46 |
tmcpeak1 | some are legit TODO though | 18:46 |
ljfisher | I want to see all todos in bandit | 18:46 |
ljfisher | in one list | 18:46 |
tmcpeak1 | such as: •Tie reporting / output back to https://wiki.openstack.org/wiki/Security/Guidelines. | 18:46 |
*** rkgudboy has quit IRC | 18:46 | |
ljfisher | if there are tags we could probably do it | 18:46 |
tmcpeak1 | Launchpad description seems in favor of using Blueprints for enhancements | 18:47 |
ljfisher | yeah it looked like that to me also | 18:48 |
ljfisher | we just don’t need to do all parts of the blueprint | 18:48 |
ljfisher | and can be brief as needed | 18:48 |
gmurphy | i think you can add tags.. then something like https://bugs.launchpad.net/bandit/+bugs?orderby=tag&start=0 | 18:49 |
*** bpokorny_ has joined #openstack-security | 18:49 | |
tmcpeak1 | https://blueprints.launchpad.net/bandit/+spec/profile-stacking | 18:49 |
tmcpeak1 | I present the worst written blueprint of all times | 18:49 |
tmcpeak1 | but yeah, it works as a TODO | 18:49 |
tmcpeak1 | so now TODOs are all here | 18:49 |
tmcpeak1 | https://blueprints.launchpad.net/bandit | 18:49 |
ljfisher | that is sufficient for where Bandit is at | 18:50 |
tmcpeak1 | yep, lgtm | 18:50 |
ljfisher | and we can link to it and get a list of things to work on | 18:50 |
tmcpeak1 | so me, we, somebody should go through TODO and file bugs or blueprints for all of what we have | 18:50 |
tmcpeak1 | yeah | 18:51 |
tmcpeak1 | anybody interested in chopping the wiki TODO with me? | 18:51 |
ljfisher | add it as a todo :) | 18:51 |
tmcpeak1 | haha | 18:51 |
tmcpeak1 | on wiki or in launchpad? | 18:51 |
ljfisher | oh bother… | 18:51 |
ljfisher | You want to start from top andn I’ll start from bottom? | 18:52 |
*** bpokorny has quit IRC | 18:52 | |
ljfisher | tie reporting is about middle | 18:53 |
tmcpeak1 | I'd call that enhancement | 18:53 |
tmcpeak1 | there's nothing wrong with it as is, it works. Just could be better | 18:53 |
tmcpeak1 | ljfisher: want to take first half of list (through consider helper funcs) | 18:54 |
tmcpeak1 | and I'll take second half? | 18:54 |
tmcpeak1 | just make a judgement call | 18:54 |
tmcpeak1 | also make sure whatever bug isn't already there :) | 18:54 |
tmcpeak1 | could be fun... | 18:54 |
ljfisher | ok | 18:55 |
tmcpeak1 | cool | 18:55 |
tmcpeak1 | thank you sir | 18:55 |
ljfisher | why did you want ot switch halfs? | 18:55 |
tmcpeak1 | oh I did | 18:55 |
tmcpeak1 | ? | 18:56 |
tmcpeak1 | we don't have to | 18:56 |
tmcpeak1 | oh, didn't see your comment | 18:56 |
tmcpeak1 | lol | 18:56 |
tmcpeak1 | yeah, I'll take first half | 18:56 |
tmcpeak1 | that's fine | 18:56 |
ljfisher | whatever | 18:56 |
tmcpeak1 | we'll stick with what you said ;) | 18:56 |
ljfisher | you go first, I’ll take second | 18:56 |
tmcpeak1 | cool | 18:56 |
ljfisher | some other stuff to do so will work on through the day | 18:57 |
tmcpeak1 | yeah, no worries | 18:57 |
tmcpeak1 | ljfisher: this is fixed, right? | 18:57 |
ljfisher | what is ‘this’? | 18:58 |
tmcpeak1 | lol | 18:58 |
tmcpeak1 | oops | 18:58 |
tmcpeak1 | https://bugs.launchpad.net/bandit/+bug/1422887 | 18:58 |
openstack | Launchpad bug 1422887 in Bandit "Hundreds of "module not on sys.path" warnings" [Medium,Fix released] | 18:58 |
ljfisher | yes | 18:59 |
tmcpeak1 | we should start having a triage meeting or something | 19:00 |
ljfisher | yeah probably. Maybe on demand or not too often for now | 19:03 |
tmcpeak1 | yeah | 19:03 |
*** browne has joined #openstack-security | 19:05 | |
*** dwyde has joined #openstack-security | 19:15 | |
tmcpeak1 | ljfisher: is this one done? "Review / revisit result collection structure / format." | 19:20 |
tmcpeak1 | ljfisher: also I screwed up and ended doing the second half | 19:21 |
ljfisher | i don’t think so | 19:21 |
ljfisher | ok, good I didn’t start yet | 19:21 |
tmcpeak1 | had copied into textpad and forgot to update | 19:21 |
ljfisher | no worries | 19:21 |
tmcpeak1 | ljfisher: isn't that what you guys already did with the decorators for severity and stuff? | 19:22 |
*** amrith is now known as _amrith_ | 19:23 | |
ljfisher | not sure, actually. That would touch the results. In any case, I don’t know if that is done yet | 19:23 |
tmcpeak1 | ok, ill file and we'll kill it if it's done | 19:23 |
*** browne has quit IRC | 20:01 | |
*** browne has joined #openstack-security | 20:02 | |
*** tmcpeak1 has quit IRC | 21:14 | |
*** _amrith_ is now known as amrith | 21:15 | |
*** tmcpeak has joined #openstack-security | 21:21 | |
*** browne has quit IRC | 21:22 | |
*** browne has joined #openstack-security | 21:23 | |
*** browne has quit IRC | 21:39 | |
*** browne has joined #openstack-security | 21:39 | |
*** pdesai has quit IRC | 21:42 | |
*** pdesai has joined #openstack-security | 21:54 | |
*** edmondsw has joined #openstack-security | 22:07 | |
edmondsw | nkinder, do you know where I can find the .te, .fc, etc. files that go into keystone.pp on RHEL? | 22:09 |
*** dave-mccowan has quit IRC | 22:11 | |
nkinder | edmondsw: it should be in the source of the openstack-selinux package | 22:11 |
nkinder | edmondsw: ...but, there is also some policy in the base OS policy (selinux-policy-targeted) | 22:11 |
edmondsw | nkinder, right... meant for the OS | 22:15 |
edmondsw | nkinder, and why are there both? Will the openstack-selinux one go away? | 22:15 |
nkinder | edmondsw: maybe... It's sort of the way it is since there are two different release vehicles (the OS and OpenStack) | 22:17 |
nkinder | edmondsw: I think it will ultimately get to one or the other (not both) | 22:17 |
edmondsw | nkinder, so for the time being, apply the openstack-selinux package on top of whatever the base OS has... they shouldn't conflict, at least, I hope? | 22:18 |
edmondsw | is the source for the base OS's policy available somewhere so I can compare the two? | 22:19 |
openstackgerrit | David Wyde proposed stackforge/bandit: Refactor functional tests to clarify scoring. https://review.openstack.org/161005 | 22:25 |
openstackgerrit | bruce-benjamin proposed openstack/security-doc: Added input re- volume encryption feature https://review.openstack.org/161012 | 22:36 |
openstackgerrit | David Wyde proposed stackforge/bandit: Refactor functional tests to clarify scoring https://review.openstack.org/161005 | 22:46 |
*** openstackgerrit has quit IRC | 22:51 | |
*** openstackgerrit has joined #openstack-security | 22:51 | |
openstackgerrit | Jamie Finnigan proposed stackforge/bandit: Clean up test property decorators after refactor https://review.openstack.org/161024 | 23:01 |
*** nkinder has quit IRC | 23:04 | |
*** tmcpeak has quit IRC | 23:39 | |
*** edmondsw has quit IRC | 23:49 | |
*** dwyde has quit IRC | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!