*** bpokorny has quit IRC | 01:10 | |
*** salv-orlando has quit IRC | 01:30 | |
*** tmcpeak has quit IRC | 01:35 | |
*** browne has quit IRC | 02:04 | |
*** elo1 has joined #openstack-security | 02:08 | |
*** salv-orlando has joined #openstack-security | 02:31 | |
*** salv-orlando has quit IRC | 02:38 | |
*** pdesai has joined #openstack-security | 02:50 | |
*** salv-orlando has joined #openstack-security | 02:57 | |
*** pdesai has quit IRC | 03:09 | |
*** salv-orlando has quit IRC | 03:10 | |
*** pdesai has joined #openstack-security | 03:12 | |
*** vozcelik has quit IRC | 03:30 | |
*** pdesai has quit IRC | 03:32 | |
*** elo1 has quit IRC | 03:41 | |
*** elo1 has joined #openstack-security | 04:13 | |
*** salv-orlando has joined #openstack-security | 04:57 | |
*** salv-orlando has quit IRC | 05:10 | |
*** salv-orlando has joined #openstack-security | 05:12 | |
*** salv-orlando has quit IRC | 05:16 | |
*** browne has joined #openstack-security | 05:16 | |
*** salv-orlando has joined #openstack-security | 05:29 | |
*** salv-orlando has quit IRC | 05:34 | |
*** salv-orlando has joined #openstack-security | 05:35 | |
*** salv-orlando has quit IRC | 05:35 | |
*** salv-orlando has joined #openstack-security | 05:41 | |
*** salv-orlando has quit IRC | 05:45 | |
*** salv-orlando has joined #openstack-security | 06:04 | |
*** salv-orlando has quit IRC | 06:08 | |
*** salv-orlando has joined #openstack-security | 06:15 | |
*** salv-orlando has quit IRC | 06:20 | |
*** salv-orlando has joined #openstack-security | 06:21 | |
*** salv-orlando has quit IRC | 06:26 | |
*** salv-orlando has joined #openstack-security | 06:27 | |
*** salv-orlando has quit IRC | 06:32 | |
*** salv-orlando has joined #openstack-security | 06:38 | |
*** salv-orlando has quit IRC | 06:43 | |
*** browne has quit IRC | 06:47 | |
*** rkgudboy has joined #openstack-security | 06:57 | |
*** rkgudboy has quit IRC | 07:28 | |
*** salv-orlando has joined #openstack-security | 08:05 | |
*** salv-orlando has quit IRC | 08:15 | |
*** rkgudboy has joined #openstack-security | 08:16 | |
*** rkgudboy has quit IRC | 08:17 | |
*** rkgudboy has joined #openstack-security | 08:18 | |
*** salv-orlando has joined #openstack-security | 08:25 | |
*** salv-orlando has quit IRC | 08:25 | |
*** rkgudboy has quit IRC | 08:34 | |
*** elo2 has joined #openstack-security | 09:21 | |
*** elo1 has quit IRC | 09:24 | |
*** salv-orlando has joined #openstack-security | 09:44 | |
*** salv-orlando has quit IRC | 09:46 | |
openstackgerrit | Merged stackforge/bandit: Fix a leftover tuple unpacking in reporting code https://review.openstack.org/163169 | 09:48 |
---|---|---|
*** salv-orlando has joined #openstack-security | 10:10 | |
*** rkgudboy has joined #openstack-security | 10:11 | |
*** rkgudboy has quit IRC | 10:12 | |
*** rkgudboy has joined #openstack-security | 10:13 | |
*** salv-orlando has quit IRC | 10:14 | |
*** salv-orl_ has joined #openstack-security | 10:15 | |
*** salv-orl_ has quit IRC | 10:15 | |
*** rohitkashyap has joined #openstack-security | 10:28 | |
*** rkgudboy has quit IRC | 10:30 | |
*** rohitkashyap has quit IRC | 10:33 | |
*** rohitkashyap has joined #openstack-security | 10:33 | |
*** rohitkashyap has quit IRC | 10:34 | |
*** rkgudboy has joined #openstack-security | 10:35 | |
*** rkgudboy has quit IRC | 10:38 | |
*** rkgudboy has joined #openstack-security | 10:38 | |
*** tmcpeak has joined #openstack-security | 10:43 | |
*** salv-orlando has joined #openstack-security | 10:48 | |
*** hyakuhei has joined #openstack-security | 10:54 | |
*** rkgudboy has quit IRC | 11:20 | |
*** markvoelker has joined #openstack-security | 12:14 | |
openstackgerrit | Merged stackforge/anchor: Adding more tests against X509 certificate code https://review.openstack.org/158521 | 12:26 |
*** dave-mccowan has joined #openstack-security | 12:40 | |
*** hyakuhei has quit IRC | 13:03 | |
*** dave-mccowan has quit IRC | 13:06 | |
*** dave-mccowan has joined #openstack-security | 13:07 | |
openstackgerrit | Travis McPeak proposed openstack/security-doc: Add OSSN-0045 for FREAK attack on TLS connections https://review.openstack.org/163041 | 13:15 |
*** dave-mccowan has quit IRC | 13:20 | |
*** singlethink has joined #openstack-security | 13:32 | |
*** dave-mccowan has joined #openstack-security | 13:32 | |
openstackgerrit | Travis McPeak proposed stackforge/bandit: Fixing uncaught 'InvalidModulePath' exception https://review.openstack.org/163431 | 13:34 |
*** singlethink has quit IRC | 13:36 | |
*** sicarie has joined #openstack-security | 13:40 | |
*** singleth1nk has joined #openstack-security | 13:43 | |
*** singleth1nk has quit IRC | 13:43 | |
*** singleth1nk has joined #openstack-security | 13:43 | |
openstackgerrit | Travis McPeak proposed stackforge/bandit: Fixing uncaught 'InvalidModulePath' exception https://review.openstack.org/163431 | 13:52 |
*** dave-mccowan has quit IRC | 14:02 | |
*** singleth1nk is now known as singlethink | 14:04 | |
*** hyakuhei has joined #openstack-security | 14:20 | |
*** salv-orlando has quit IRC | 14:23 | |
*** bknudson has joined #openstack-security | 14:24 | |
*** salv-orlando has joined #openstack-security | 14:31 | |
*** elo2 has quit IRC | 14:32 | |
*** voodookid has joined #openstack-security | 14:43 | |
*** dwyde has joined #openstack-security | 14:46 | |
*** voodookid has quit IRC | 14:47 | |
*** voodookid has joined #openstack-security | 15:01 | |
openstackgerrit | Merged stackforge/bandit: Fixing uncaught 'InvalidModulePath' exception https://review.openstack.org/163431 | 15:06 |
tmcpeak | nkinder, bknudson: if you get a chance could you have a look at https://review.openstack.org/163041 | 15:18 |
nkinder | tmcpeak: I have it up and have been reviewing it | 15:19 |
bknudson | is getting sick of these SSL attacks. | 15:19 |
tmcpeak | lol | 15:19 |
tmcpeak | nkinder: cool, sounds good, thanks nkinder | 15:19 |
bknudson | stop using it since it doesn't do anything anyways. | 15:19 |
bknudson | luckily we don't use java. | 15:19 |
tmcpeak | I think what we have is a behavior problem, not a tech problem. If we could all just agree not to MITM eachother's traffic the world would be a much better place | 15:20 |
bknudson | direct connections. | 15:20 |
bknudson | line of sight | 15:20 |
*** bpokorny has joined #openstack-security | 15:24 | |
bknudson | tmcpeak: do the configurations in http://docs.openstack.org/security-guide/content/tls-proxies-and-http-services.html disable export ciphers? | 15:25 |
bknudson | SSLCipherSuite HIGH:!RC4:!MD5:!aNULL:!eNULL:!EXP:!LOW:!MEDIUM has !EXP | 15:25 |
tmcpeak | yeah, I assume that's what this line does | 15:25 |
tmcpeak | yep, that's the one I was going to paste :) | 15:25 |
tmcpeak | !EXP | 15:26 |
tmcpeak | Disallows export encryption algorithms, which by design tend to be weak, typically using 40 and 56 bit keys. | 15:26 |
tmcpeak | US Export restrictions on cryptography systems have been lifted and no longer need to be supported. | 15:26 |
openstack | tmcpeak: Error: "EXP" is not a valid command. | 15:26 |
bknudson | just make it the default for crying out loud. | 15:26 |
bknudson | no wonder everyone messes this up. | 15:26 |
bknudson | tmcpeak: read through https://review.openstack.org/#/c/163041/ and looks good to me. | 15:28 |
tmcpeak | lol, yeah. Insecure defaults suck | 15:28 |
tmcpeak | bknudson: cool, thank you sir | 15:28 |
*** singlethink has quit IRC | 15:35 | |
*** browne has joined #openstack-security | 15:40 | |
sicarie | OpenStack Operators meetup in Philly just happened - here's the security etherpad: #link https://etherpad.openstack.org/p/PHL-ops-security | 15:50 |
bknudson | sicarie: neat, thanks | 15:56 |
bknudson | sicarie: nkinder was working on some docs for policy.json | 15:56 |
bknudson | I was also working on some docs for keystone. | 15:57 |
nkinder | bknudson: some of those were merged (on the oslo side) | 15:57 |
bknudson | https://review.openstack.org/#/c/155919/ -- documents keystone policy.json | 15:57 |
tmcpeak | sicarie: cool stuff | 15:58 |
bknudson | damn, should have gone to the ops meetup. | 15:58 |
sicarie | The general page: #link http://superuser.openstack.org/articles/openstack-mid-cycle-meetup-day-one-roundup | 15:59 |
*** singlethink has joined #openstack-security | 16:01 | |
*** hyakuhei has quit IRC | 16:02 | |
*** hyakuhei has joined #openstack-security | 16:05 | |
*** browne1 has joined #openstack-security | 16:11 | |
*** browne has quit IRC | 16:14 | |
*** bdpayne has joined #openstack-security | 16:15 | |
*** pdesai has joined #openstack-security | 16:17 | |
*** singlethink has quit IRC | 16:18 | |
*** pdesai has quit IRC | 16:26 | |
tmcpeak | cool, so nkinder, hyakuhei, bdpayne: could use final thumbs up here: https://review.openstack.org/163041 | 16:27 |
* bdpayne looks | 16:27 | |
*** dwyde has quit IRC | 16:28 | |
bdpayne | tmcpeak lgtm | 16:33 |
tmcpeak | bdpayne: thanks! | 16:33 |
hyakuhei | The only concern I have is the services section | 16:34 |
hyakuhei | They layout is very different to how we normally do it | 16:34 |
tmcpeak | copied that from bdpayne's poodle note | 16:34 |
hyakuhei | and if we ever get around to pushing these all through some parser it’ll break | 16:34 |
hyakuhei | nkinder: not around? | 16:34 |
bdpayne | layout? | 16:34 |
hyakuhei | It’s kind of ok if it breaks the parser because it can be manually fixed up if we only have that issue with one or two notes and at least this is nice and readable. | 16:35 |
bdpayne | pretty sure the Poodle note started with the official template | 16:35 |
bdpayne | so if there's an issue, perhaps the template needs fixing? | 16:35 |
hyakuhei | No, if that’s how the poodle note does it it’s technically wrong too | 16:35 |
nkinder | hyakuhei: I'm around, but in a meeting | 16:36 |
hyakuhei | Services are normally just comma separated https://wiki.openstack.org/wiki/OSSN/OSSN-0042 | 16:36 |
tmcpeak | hyakuhei is talking about the list of services and versions | 16:36 |
tmcpeak | although that isn't really applicable to general TLS problems | 16:36 |
hyakuhei | Yeah, just the Affected Services / Software section | 16:36 |
hyakuhei | tmcpeak: that’s true | 16:36 |
hyakuhei | However, you probably want each of the openstack services listed in there and move the (very good) list of TLS stuff into some other section | 16:37 |
bdpayne | not sure I agree with that, tbh | 16:37 |
tmcpeak | hyakuhei: so every version and every service? | 16:37 |
bdpayne | it will make the note harder to parse | 16:37 |
tmcpeak | what about other components which might be using TLS | 16:37 |
hyakuhei | That way if we ever have some tool that allows you to, for example, view all OSSNs that potentially affect Keystone it’ll come up in the search | 16:37 |
bdpayne | parse... by humans in this case | 16:37 |
hyakuhei | bdpayne: That’s the standard, we can talk about changing the standard but that’s an entirely separate conversation | 16:38 |
hyakuhei | one I want nkinder to be around for. | 16:38 |
tmcpeak | well, in this case I just chose to match what we already had for POODLE. IMO listing all services and versions will be horrible to look at, but yeah, makes it machine parseable. We really aren't using that currently though, so we'd need to do work in any case | 16:40 |
hyakuhei | So I’m ok with it going through but it will break the tooling we want to put around OSSNs later. | 16:42 |
tmcpeak | yeah, agree | 16:42 |
hyakuhei | Incidentally I think this is a very good OSSN, my comments are only a reflection on the standard schema we currently use | 16:42 |
tmcpeak | hyakuhei: thank you | 16:42 |
hyakuhei | and that we should adhere to in most cases until we fix the schema… | 16:43 |
*** hyakuhei has quit IRC | 16:45 | |
*** hyakuhei has joined #openstack-security | 16:47 | |
*** hyakuhei has quit IRC | 16:50 | |
*** hyakuhei has joined #openstack-security | 16:51 | |
*** openstack has joined #openstack-security | 16:54 | |
nkinder | tmcpeak: ok, out of my meeting... | 16:55 |
nkinder | tmcpeak: so the list of affected services is a bit odd, but these generic crypto vulnerability notes don't really fit the mold of real bugs/issues in OpenStack itself | 16:56 |
nkinder | I don't want to list every possible service, and this affects more than OpenStack services (messaging brokers, SSL terminators, etc.) | 16:57 |
*** singlethink has joined #openstack-security | 16:57 | |
tmcpeak | nkinder: yeah, I agree | 16:57 |
sicarie | nkinder: I think one of my comments led to this - I was trying to get a concrete method for determining exposure there | 16:58 |
tmcpeak | hyakuhei agrees also | 16:58 |
tmcpeak | it doesn't fit our traditional method of listing services and versions | 16:59 |
nkinder | well, I would love to have an automatic parsing tool | 16:59 |
nkinder | ...but we don't have one here today | 16:59 |
tmcpeak | so a smart parser could recognize when something doesn't parse and leave a smart comment instead | 16:59 |
nkinder | I think if we wanted a real format that could be parsed, it wouldn't be what we have today | 17:00 |
openstackgerrit | Merged openstack/security-doc: Add OSSN-0045 for FREAK attack on TLS connections https://review.openstack.org/163041 | 17:00 |
nkinder | There is a standard there I was looking at some time back | 17:01 |
*** salv-orlando has quit IRC | 17:03 | |
*** mgagne_PHL is now known as mgagne | 17:14 | |
*** dwyde has joined #openstack-security | 17:23 | |
nkinder | tmcpeak: fyi - your line-wrap width was too wide for the OSSN | 17:43 |
nkinder | tmcpeak: not a big deal (I'll reformat for the e-mail) | 17:43 |
tmcpeak | nkinder: crap, was it? thought I had it set for 80 | 17:43 |
nkinder | tmcpeak: just an FYI that the width is shorter than what we use for PEP8 | 17:43 |
nkinder | tmcpeak: it's 72 | 17:44 |
tmcpeak | ahhhh | 17:45 |
tmcpeak | forgot all about that :) | 17:45 |
nkinder | tmcpeak: I'm fixing it | 17:45 |
tmcpeak | nkinder: cool, thank you! | 17:45 |
openstackgerrit | Nathan Kinder proposed openstack/security-doc: Correct line-wrapping width for OSSN-0045 https://review.openstack.org/163547 | 17:56 |
nkinder | tmcpeak: ^^ | 17:56 |
nkinder | tmcpeak: ...might as well correct it in tree | 17:56 |
tmcpeak | I gave my +1 fwiw | 17:57 |
tmcpeak | :) | 17:57 |
nkinder | tmcpeak: you're fast | 17:57 |
nkinder | bdpayne: ^^ Given it's just white-space, I'm thinking we should just +A it without the standard "2 core" rule. | 17:58 |
nkinder | bdpayne: care to do the honors? | 17:58 |
bdpayne | sure | 17:58 |
bdpayne | done | 17:58 |
* bdpayne will approve anything ;-) | 17:58 | |
nkinder | bdpayne: thanks! | 18:00 |
nkinder | tmcpeak: I'll publish as soon as I see the merge come through | 18:00 |
tmcpeak | I need to start gaming my "positive response on reviews" in stackalytics | 18:01 |
tmcpeak | I have like 25% positive | 18:01 |
tmcpeak | nkinder: awesome, thank you | 18:01 |
tmcpeak | I'll throw up the wiki page | 18:01 |
nkinder | tmcpeak: that's good actually | 18:01 |
nkinder | if you had 90% positive, there's likely a problem with not being thorough enough :) | 18:01 |
tmcpeak | nkinder: not for my "not being perceived as an a-hole" goal | 18:02 |
*** salv-orlando has joined #openstack-security | 18:04 | |
*** salv-orlando has quit IRC | 18:14 | |
tmcpeak | nkinder: you beat me to it on the wiki? :) | 18:19 |
nkinder | tmcpeak: yep, I have it ready to pull the trigger :) | 18:20 |
tmcpeak | sweet! pull away | 18:20 |
*** dave-mccowan has joined #openstack-security | 18:24 | |
*** bknudson has quit IRC | 18:30 | |
*** salv-orlando has joined #openstack-security | 18:44 | |
openstackgerrit | Robert Clark proposed stackforge/anchor: Added tests to bring coverage up to 100% of validators https://review.openstack.org/163561 | 18:49 |
openstackgerrit | Robert Clark proposed stackforge/anchor: Added tests to bring coverage up to 100% of validators https://review.openstack.org/163561 | 18:51 |
*** bknudson has joined #openstack-security | 19:13 | |
*** bpokorny_ has joined #openstack-security | 19:39 | |
*** bpokorny has quit IRC | 19:42 | |
*** dwyde has quit IRC | 19:53 | |
*** bpokorny has joined #openstack-security | 19:58 | |
*** bpokorny_ has quit IRC | 20:01 | |
openstackgerrit | Merged openstack/security-doc: Correct line-wrapping width for OSSN-0045 https://review.openstack.org/163547 | 20:04 |
openstackgerrit | bruce-benjamin proposed openstack/security-doc: Added input about volume encryption feature https://review.openstack.org/161012 | 20:10 |
*** dwyde has joined #openstack-security | 20:16 | |
*** ljfisher has joined #openstack-security | 20:20 | |
*** sicarie has quit IRC | 20:32 | |
*** bpokorny has quit IRC | 20:33 | |
*** salv-orlando has quit IRC | 20:43 | |
openstackgerrit | bruce-benjamin proposed openstack/security-doc: Added input about volume encryption feature https://review.openstack.org/161012 | 21:15 |
openstackgerrit | Merged openstack/security-doc: MySQL TLS transport config example https://review.openstack.org/159668 | 21:25 |
*** salv-orlando has joined #openstack-security | 21:28 | |
*** singlethink has quit IRC | 21:28 | |
*** sicarie has joined #openstack-security | 21:35 | |
*** bpokorny has joined #openstack-security | 21:49 | |
*** sicarie has quit IRC | 22:12 | |
*** singlethink has joined #openstack-security | 22:31 | |
*** ljfisher has quit IRC | 22:41 | |
*** dwyde has quit IRC | 22:42 | |
*** singlethink has quit IRC | 22:43 | |
*** voodookid has quit IRC | 23:10 | |
*** dave-mccowan has quit IRC | 23:14 | |
*** bknudson has quit IRC | 23:31 | |
*** bknudson has joined #openstack-security | 23:52 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!