openstackgerrit | Michael Simo proposed openstack/security-doc: Removed unneeded word from security-guide https://review.openstack.org/177625 | 00:23 |
---|---|---|
*** salv-orlando has joined #openstack-security | 00:43 | |
*** salv-orlando has quit IRC | 00:50 | |
*** vozcelik has joined #openstack-security | 01:15 | |
*** sdake has joined #openstack-security | 01:32 | |
*** sdake_ has joined #openstack-security | 01:48 | |
*** sdake has quit IRC | 01:51 | |
*** sdake_ has quit IRC | 02:35 | |
*** salv-orlando has joined #openstack-security | 02:46 | |
*** sdake has joined #openstack-security | 02:52 | |
*** salv-orlando has quit IRC | 02:56 | |
*** salv-orlando has joined #openstack-security | 03:02 | |
*** salv-orlando has quit IRC | 03:04 | |
*** sdake_ has joined #openstack-security | 03:28 | |
*** sdake has quit IRC | 03:32 | |
*** dave-mccowan has quit IRC | 03:56 | |
*** BOYSODOMY has joined #openstack-security | 04:56 | |
*** BOYSODOMY has quit IRC | 05:04 | |
*** browne has joined #openstack-security | 05:09 | |
*** subscope_ has joined #openstack-security | 05:30 | |
*** subscope_ has quit IRC | 05:31 | |
*** sweston has quit IRC | 05:44 | |
*** sweston has joined #openstack-security | 05:45 | |
*** salv-orlando has joined #openstack-security | 05:46 | |
*** salv-orlando has quit IRC | 05:54 | |
*** sdake_ has quit IRC | 05:56 | |
*** sdake has joined #openstack-security | 05:56 | |
*** salv-orlando has joined #openstack-security | 06:42 | |
*** salv-orlando has quit IRC | 06:44 | |
*** sdake has quit IRC | 06:58 | |
*** browne has quit IRC | 07:20 | |
*** markvoelker has joined #openstack-security | 07:26 | |
*** markvoelker has quit IRC | 07:30 | |
*** salv-orlando has joined #openstack-security | 07:36 | |
*** sdake has joined #openstack-security | 07:42 | |
*** sdake has quit IRC | 07:42 | |
*** sdake has joined #openstack-security | 07:42 | |
*** openstackgerrit has quit IRC | 08:13 | |
*** openstackgerrit has joined #openstack-security | 08:16 | |
*** markvoelker has joined #openstack-security | 08:27 | |
*** markvoelker has quit IRC | 08:32 | |
*** sdake_ has joined #openstack-security | 08:51 | |
*** sdake has quit IRC | 08:55 | |
*** sdake_ has quit IRC | 09:13 | |
*** sdake has joined #openstack-security | 09:15 | |
*** markvoelker has joined #openstack-security | 09:27 | |
*** markvoelker has quit IRC | 09:36 | |
*** markvoelker has joined #openstack-security | 10:28 | |
*** markvoelker has quit IRC | 10:33 | |
*** sdake has quit IRC | 10:41 | |
*** sdake has joined #openstack-security | 10:52 | |
*** tmcpeak has joined #openstack-security | 10:55 | |
*** sdake has quit IRC | 11:10 | |
*** salv-orlando has quit IRC | 11:23 | |
*** markvoelker has joined #openstack-security | 11:29 | |
*** markvoelker has quit IRC | 11:33 | |
*** markvoelker has joined #openstack-security | 11:38 | |
*** salv-orlando has joined #openstack-security | 11:45 | |
*** openstackgerrit has quit IRC | 12:06 | |
*** openstackgerrit has joined #openstack-security | 12:06 | |
*** bknudson has quit IRC | 12:31 | |
*** openstackgerrit has quit IRC | 12:37 | |
*** openstackgerrit has joined #openstack-security | 12:37 | |
*** bknudson has joined #openstack-security | 12:56 | |
*** elmiko_ is now known as elmiko | 13:09 | |
*** openstackgerrit has quit IRC | 13:21 | |
*** openstackgerrit has joined #openstack-security | 13:22 | |
*** singlethink has joined #openstack-security | 13:24 | |
*** dwyde has joined #openstack-security | 13:46 | |
*** edmondsw has joined #openstack-security | 14:02 | |
*** gmurphy_ is now known as gmurphy | 14:02 | |
*** vozcelik has quit IRC | 14:15 | |
*** voodookid has joined #openstack-security | 14:16 | |
*** salv-orl_ has joined #openstack-security | 14:22 | |
*** salv-orlando has quit IRC | 14:23 | |
openstackgerrit | tianzichen306 proposed openstack/security-doc: commit 503993fc9e08c5e8014c468d94f47547549dd7a6 Author: tianzichen306 Date: Mon Apr 27 22:20:46 2015 https://review.openstack.org/177788 | 14:24 |
openstackgerrit | tianzichen306 proposed openstack/security-doc: Sentences order adjustment of networking services security best practices https://review.openstack.org/177788 | 14:27 |
openstackgerrit | tianzichen306 proposed openstack/security-doc: Sentences order adjustment of networking services security best practices https://review.openstack.org/177788 | 14:28 |
*** nkinder has joined #openstack-security | 14:33 | |
*** v4s has quit IRC | 14:34 | |
*** browne has joined #openstack-security | 14:38 | |
*** voodookid has quit IRC | 14:39 | |
*** dave-mccowan has joined #openstack-security | 14:40 | |
*** v4s has joined #openstack-security | 14:45 | |
*** tkelsey has joined #openstack-security | 14:52 | |
*** salv-orl_ has quit IRC | 14:54 | |
*** voodookid has joined #openstack-security | 15:00 | |
*** dwyde has quit IRC | 15:01 | |
*** dwyde has joined #openstack-security | 15:06 | |
openstackgerrit | tianzichen306 proposed openstack/security-doc: Fix grammar errors of networking services security best practices https://review.openstack.org/177813 | 15:10 |
*** salv-orlando has joined #openstack-security | 15:16 | |
*** browne has quit IRC | 15:41 | |
*** sdake has joined #openstack-security | 15:47 | |
*** salv-orlando has quit IRC | 15:53 | |
*** browne has joined #openstack-security | 15:58 | |
*** salv-orlando has joined #openstack-security | 16:09 | |
*** salv-orl_ has joined #openstack-security | 16:10 | |
*** salv-orlando has quit IRC | 16:13 | |
*** singlethink has quit IRC | 16:28 | |
openstackgerrit | Merged stackforge/bandit: Add XML vulnerability checking https://review.openstack.org/176404 | 16:31 |
*** bpb has joined #openstack-security | 16:32 | |
*** Mike has joined #openstack-security | 17:00 | |
*** Mike is now known as Guest41976 | 17:00 | |
*** shelleea007 has joined #openstack-security | 17:00 | |
*** sicarie has joined #openstack-security | 17:00 | |
* sicarie waves | 17:01 | |
shelleea007 | O/ | 17:01 |
*** pdesai has joined #openstack-security | 17:02 | |
sicarie | hello! | 17:03 |
pdesai | hi | 17:03 |
sicarie | so elmiko has a conflict today - I think we’re ready | 17:04 |
pdesai | i see | 17:04 |
sicarie | We have two for triage | 17:04 |
sicarie | https://bugs.launchpad.net/openstack-manuals/+bug/1446756 | 17:04 |
openstack | Launchpad bug 1446756 in openstack-manuals "Integrity life-cycle in OpenStack Security Guide - current" [Undecided,New] | 17:04 |
sicarie | I thought inotify would be good to contribut to this section | 17:05 |
sicarie | Currently dmverity is listed, but no discussion of how it works | 17:05 |
sicarie | tripwire could also be mentioned there, again with discussion of hasing and how those are stored/checked and some of the performance tradeoffs | 17:05 |
pdesai | yup sounds good | 17:06 |
shelleea007 | that should be a good tasking | 17:06 |
pdesai | let me check the integrity life cycle ch. | 17:06 |
sicarie | Cool, so I was thinking low severity | 17:06 |
shelleea007 | i concur | 17:07 |
sicarie | http://docs.openstack.org/security-guide/content/integrity-life-cycle.html | 17:07 |
sicarie | The section in question is at the bottom of the page | 17:07 |
pdesai | aah | 17:07 |
pdesai | yeah definitely, we should add some discussion on dmverity and how it works | 17:08 |
sicarie | yep, i think a bit more on samhain/tripwire/dmverity/inotify would be good | 17:08 |
sicarie | pdesai: any thoughts on severity? | 17:09 |
pdesai | med, i think we can have a seperate subsection under fim | 17:10 |
sicarie | shelleea007: you said low, any thoughts on medium? | 17:10 |
sicarie | (or any thoughts from lurkers?) | 17:11 |
pdesai | something like, option 1) Samhain option 2) DMVerity option 3) inotify | 17:11 |
sicarie | pdesai: +1 | 17:11 |
sicarie | Cool, I’ll set this at medium until shelleea007 gets back | 17:12 |
pdesai | +1 | 17:12 |
sicarie | The second one is hers: https://bugs.launchpad.net/openstack-manuals/+bug/1447759 | 17:12 |
openstack | Launchpad bug 1447759 in openstack-manuals "Networking services in OpenStack Security Guide - Incomplete Sentences" [Undecided,Incomplete] | 17:12 |
shelleea007 | well, if you want to seperate this out then maybe it could be considered low, however i THINK IT IS FAIRLY IMPORTANT | 17:13 |
shelleea007 | blech my typo is on today | 17:13 |
sicarie | shelleea007: the file integrity management stuff, or the networking services? | 17:13 |
shelleea007 | FIM stuff | 17:13 |
shelleea007 | thats a huge thing for compliance | 17:14 |
shelleea007 | especially in the PCI realm | 17:14 |
sicarie | so the current section already references Samhain and dm-verity | 17:14 |
shelleea007 | yeah... but those dont really report out well for what I am talking about | 17:14 |
sicarie | as well as giving (some) guidance on what to monitor with them | 17:14 |
sicarie | and for some reason I’m thinking it was set on low | 17:15 |
sicarie | Yes, it was set to medium priority | 17:15 |
shelleea007 | so I think it would be beneficial in setting it to medium based on consideration that there is some focus on compliance | 17:15 |
sicarie | sorry - i’ve only had one cup of coffee :) | 17:15 |
sicarie | great | 17:15 |
sicarie | shelleea007: do you want to give an overview of the networking services bug? | 17:15 |
shelleea007 | the one you just pasted? | 17:15 |
sicarie | yes | 17:16 |
shelleea007 | I see that aNDREAS asked why it was considered to have incomplete sentences | 17:16 |
sicarie | I’m inclined to agree - while these are complex ideas, I can make sense of the statements | 17:16 |
shelleea007 | I believe that the 1st set beginning with the term "however" appears to be incomplete | 17:17 |
sicarie | Though I’m all about clarity - I definitely think they could be explained a bit more | 17:17 |
sicarie | quote coming | 17:17 |
sicarie | If nodes that run either neutron-l3-agent or neutron-dhcp-agent use overlapping IP addresses, those nodes must use Linux network namespaces. By default, the DHCP and L3 agents use Linux network namespaces. However, if the host does not support these namespaces, run the DHCP and L3 agents on different hosts. | 17:17 |
shelleea007 | yeah | 17:17 |
shelleea007 | I still think the two could be concatenated togeter | 17:18 |
sicarie | i can see that | 17:18 |
sicarie | pdesai? | 17:18 |
shelleea007 | I kind of hate when people begin a sentence with "however" | 17:18 |
pdesai | +1 to quotes | 17:19 |
sicarie | My understanding is that is not against a grammatical rule, though | 17:19 |
shelleea007 | i know its not, its a personal preference | 17:19 |
sicarie | Hehe, I think we should stick to grammatical ruling for bugs - though I can definitely see one being opened to clarify these points a bit more | 17:20 |
Guest41976 | So I think the consensus is that it needs to be rewritten then. | 17:20 |
sicarie | Guest41976: you’re for re-writing? | 17:20 |
Guest41976 | No, shelleea007 seems to have a handle on it | 17:21 |
sicarie | So my preference is that a new bug be opened for clarity, this be marked ‘Invalid’ as it’s grammatically correct | 17:21 |
pdesai | +1 | 17:22 |
shelleea007 | ok, or I can just modify that bug | 17:22 |
sicarie | Guest41976: apologies, not looking for volunteers, but asking if you thought it should be rewritten by someone | 17:22 |
sicarie | shelleea007: not sure what convention on that is, I think a new bug would be easier to track | 17:22 |
Guest41976 | that it is being discussed here back and forth should be evidence enough that it needs to be rewritten | 17:22 |
shelleea007 | hmmm, i didnt know there was a convention. I change bugs often, usually before they are reviewed | 17:23 |
sicarie | shelleea007: cool, then go for it | 17:23 |
shelleea007 | ok so, change it to be re-written for clarity | 17:24 |
sicarie | +1 | 17:24 |
sicarie | And then we have a set of new changes that just came in | 17:25 |
sicarie | Looks like elmiko hit one, and Andreas hit another, but I still see a few with no reviews | 17:25 |
sicarie | (including none by me!) | 17:26 |
sicarie | So lots of links coming - eyes are appreciated on: | 17:26 |
sicarie | https://review.openstack.org/#/c/174727/ | 17:26 |
sicarie | https://review.openstack.org/#/c/177622/ | 17:26 |
*** salv-orlando has joined #openstack-security | 17:26 | |
sicarie | https://review.openstack.org/#/c/177624/ | 17:26 |
sicarie | https://review.openstack.org/#/c/177625/ | 17:26 |
sicarie | https://review.openstack.org/#/c/177623/ | 17:26 |
sicarie | https://review.openstack.org/#/c/177788/ | 17:26 |
sicarie | For the benefit of anyone who hasn’t watched the project | 17:26 |
sicarie | pdesai: hows the barbican section/chapter coming? Anything we can help with? | 17:27 |
*** salv-orl_ has quit IRC | 17:27 | |
pdesai | i talked to Jason, who is going to be writing that ch., there is no progress yet, but he is coming to summit and would like to join us for our mini design session | 17:28 |
sicarie | awesome | 17:28 |
shelleea007 | ok i rewrote the task description | 17:28 |
shelleea007 | https://bugs.launchpad.net/openstack-manuals/+bug/1447759 | 17:28 |
openstack | Launchpad bug 1447759 in openstack-manuals "Networking services in OpenStack Security Guide - Rewrite for clarity" [Undecided,Incomplete] | 17:28 |
sicarie | I think we have our space confirmed, so I hope to get the guide session publicized | 17:28 |
sicarie | shelleea007: +1 | 17:29 |
sicarie | I’d say medium severity? | 17:29 |
sicarie | Well, we hit the half hour mark, so I’m going to drop this here: https://etherpad.openstack.org/p/sec-guide-case-studies | 17:30 |
shelleea007 | ok | 17:30 |
sicarie | Please feel free to grab a section or edit the ones marked as ready | 17:30 |
pdesai | yup | 17:30 |
shelleea007 | works for me | 17:30 |
sicarie | Guest41976: please feel free to take a look at the compliance section! | 17:31 |
shelleea007 | i will work on that since I now have both of the sections I took earlier completed | 17:31 |
sicarie | awesome, thanks | 17:31 |
sicarie | anything else? | 17:31 |
pdesai | nope, nothing from myside | 17:31 |
sicarie | awesome, sorry for going over, and thanks for all the good work! | 17:32 |
Guest41976 | I'll try as time allows | 17:33 |
Guest41976 | work is being work | 17:33 |
sicarie | thanks! | 17:33 |
pdesai | no worries, thanks everyone | 17:33 |
*** Guest41976 has quit IRC | 17:33 | |
*** sicarie has quit IRC | 17:33 | |
*** sdake_ has joined #openstack-security | 17:34 | |
*** shelleea007 has quit IRC | 17:34 | |
*** sdake has quit IRC | 17:36 | |
*** pdesai has quit IRC | 17:38 | |
*** sdake has joined #openstack-security | 17:45 | |
*** sdake_ has quit IRC | 17:48 | |
openstackgerrit | Michael Simo proposed openstack/security-doc: Fix grammatical errors in security-guide https://review.openstack.org/177624 | 18:08 |
openstackgerrit | Michael Simo proposed openstack/security-doc: Fix grammatical errors in security-guide https://review.openstack.org/177622 | 18:59 |
*** singlethink has joined #openstack-security | 19:01 | |
openstackgerrit | Michael Simo proposed openstack/security-doc: Fix unnecessary capitalization in security-guide https://review.openstack.org/177623 | 19:02 |
openstackgerrit | Michael Simo proposed openstack/security-doc: Removed unneeded word from security-guide https://review.openstack.org/177625 | 19:03 |
*** sdake_ has joined #openstack-security | 19:22 | |
*** sdake has quit IRC | 19:26 | |
*** sdake_ has quit IRC | 19:35 | |
*** sdake has joined #openstack-security | 19:35 | |
*** singlethink has quit IRC | 20:05 | |
*** singlethink has joined #openstack-security | 20:08 | |
*** tkelsey has quit IRC | 21:00 | |
*** singlethink has quit IRC | 21:05 | |
*** sdake_ has joined #openstack-security | 21:07 | |
*** sdake has quit IRC | 21:11 | |
*** sdake has joined #openstack-security | 21:15 | |
*** sdake_ has quit IRC | 21:19 | |
*** dave-mccowan has quit IRC | 21:30 | |
*** dave-mccowan has joined #openstack-security | 21:31 | |
*** sdake_ has joined #openstack-security | 21:46 | |
*** dave-mccowan has quit IRC | 21:47 | |
*** dave-mccowan has joined #openstack-security | 21:48 | |
*** sdake has quit IRC | 21:49 | |
*** yeison has joined #openstack-security | 21:50 | |
yeison | hola q hay :D | 21:52 |
yeison | .( | 21:52 |
*** yeison1 has joined #openstack-security | 21:54 | |
*** yeison has quit IRC | 21:54 | |
*** yeison1 has quit IRC | 22:02 | |
*** yeison has joined #openstack-security | 22:02 | |
*** yeison has left #openstack-security | 22:02 | |
*** bknudson has quit IRC | 22:03 | |
*** salv-orlando has quit IRC | 22:09 | |
*** salv-orlando has joined #openstack-security | 22:29 | |
*** bpb has quit IRC | 22:34 | |
*** dwyde has quit IRC | 22:51 | |
*** sdake_ has quit IRC | 22:57 | |
*** voodookid has quit IRC | 23:03 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!