*** markvoelker has joined #openstack-security | 00:25 | |
*** kutija_ is now known as kutija|away | 00:28 | |
*** markvoelker has quit IRC | 00:30 | |
*** tmcpeak has quit IRC | 00:32 | |
*** mitz has joined #openstack-security | 00:47 | |
*** jamielennox|away is now known as jamielennox | 01:07 | |
*** dave-mccowan has quit IRC | 01:24 | |
*** dave-mccowan has joined #openstack-security | 01:46 | |
*** JAHoagie has joined #openstack-security | 01:53 | |
*** markvoelker has joined #openstack-security | 02:14 | |
*** markvoelker has quit IRC | 02:19 | |
*** hyakuhei1 has quit IRC | 02:22 | |
*** hyakuhei has joined #openstack-security | 02:22 | |
*** JAHoagie has quit IRC | 02:39 | |
*** JAHoagie has joined #openstack-security | 02:54 | |
*** aswadr has joined #openstack-security | 03:04 | |
*** JAHoagie has quit IRC | 03:18 | |
*** hyakuhei has quit IRC | 03:25 | |
*** hyakuhei has joined #openstack-security | 03:26 | |
*** ankldrey has quit IRC | 03:34 | |
*** dave-mcc_ has joined #openstack-security | 03:55 | |
*** dave-mccowan has quit IRC | 03:57 | |
*** dave-mcc_ has quit IRC | 03:59 | |
*** hyakuhei has quit IRC | 04:06 | |
*** hyakuhei has joined #openstack-security | 04:06 | |
*** hyakuhei1 has joined #openstack-security | 04:22 | |
*** hyakuhei has quit IRC | 04:22 | |
*** hyakuhei1 has quit IRC | 05:02 | |
*** hyakuhei has joined #openstack-security | 05:02 | |
*** hyakuhei has quit IRC | 05:50 | |
*** hyakuhei1 has joined #openstack-security | 05:50 | |
*** markvoelker has joined #openstack-security | 05:52 | |
*** markvoelker has quit IRC | 05:56 | |
*** hyakuhei1 has quit IRC | 05:57 | |
*** hyakuhei has joined #openstack-security | 06:01 | |
*** hyakuhei has quit IRC | 06:27 | |
*** hyakuhei has joined #openstack-security | 06:27 | |
*** hyakuhei has quit IRC | 06:47 | |
*** hyakuhei has joined #openstack-security | 06:52 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/189207 | 07:08 |
---|---|---|
*** markvoelker has joined #openstack-security | 07:40 | |
*** markvoelker has quit IRC | 07:45 | |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/189207 | 07:58 |
*** hyakuhei1 has joined #openstack-security | 08:04 | |
*** hyakuhei has quit IRC | 08:04 | |
*** hyakuhei1 has quit IRC | 08:33 | |
*** hyakuhei has joined #openstack-security | 08:40 | |
*** hyakuhei1 has joined #openstack-security | 08:56 | |
*** hyakuhei has quit IRC | 08:56 | |
*** hyakuhei1 has quit IRC | 09:20 | |
*** hyakuhei has joined #openstack-security | 09:20 | |
*** markvoelker has joined #openstack-security | 09:29 | |
*** markvoelker has quit IRC | 09:34 | |
*** hyakuhei has quit IRC | 09:40 | |
*** hyakuhei has joined #openstack-security | 09:41 | |
*** openstackgerrit has quit IRC | 10:09 | |
*** openstackgerrit has joined #openstack-security | 10:09 | |
*** hyakuhei1 has joined #openstack-security | 10:10 | |
*** hyakuhei has quit IRC | 10:11 | |
*** hyakuhei1 has quit IRC | 11:11 | |
*** hyakuhei has joined #openstack-security | 11:11 | |
*** markvoelker has joined #openstack-security | 11:30 | |
*** hyakuhei has quit IRC | 11:34 | |
*** markvoelker has quit IRC | 11:35 | |
*** hyakuhei has joined #openstack-security | 11:35 | |
*** alex_klimov has joined #openstack-security | 11:46 | |
*** hyakuhei has quit IRC | 12:09 | |
*** hyakuhei has joined #openstack-security | 12:11 | |
*** hyakuhei has quit IRC | 12:47 | |
*** hyakuhei1 has joined #openstack-security | 12:47 | |
*** dave-mccowan has joined #openstack-security | 12:53 | |
*** singlethink has joined #openstack-security | 12:56 | |
*** hyakuhei1 has quit IRC | 13:14 | |
*** markvoelker has joined #openstack-security | 13:20 | |
*** hyakuhei has joined #openstack-security | 13:20 | |
*** nunbrs has quit IRC | 13:24 | |
*** markvoelker has quit IRC | 13:25 | |
*** tmcpeak has joined #openstack-security | 13:36 | |
chair6 | sigmavirus24: cool, i'll take a look a bit later on today.. launchpad is at https://launchpad.net/bandit | 14:07 |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:11 | |
*** localloop127 has joined #openstack-security | 14:22 | |
*** jamielennox is now known as jamielennox|away | 14:38 | |
*** voodookid has joined #openstack-security | 14:48 | |
*** voodookid has quit IRC | 14:53 | |
*** hyakuhei has quit IRC | 14:54 | |
*** hyakuhei has joined #openstack-security | 14:56 | |
*** dwyde has joined #openstack-security | 14:57 | |
*** nkinder has joined #openstack-security | 15:02 | |
*** voodookid has joined #openstack-security | 15:07 | |
*** markvoelker has joined #openstack-security | 15:08 | |
*** markvoelker has quit IRC | 15:13 | |
*** hyakuhei has quit IRC | 15:18 | |
*** bpokorny has joined #openstack-security | 15:18 | |
tmcpeak | dstufft: ping | 15:22 |
*** hyakuhei has joined #openstack-security | 15:23 | |
*** localloop127 has quit IRC | 15:32 | |
*** localloop127 has joined #openstack-security | 15:40 | |
*** sdake has joined #openstack-security | 15:47 | |
*** sdake_ has joined #openstack-security | 15:48 | |
*** singlethink has quit IRC | 15:51 | |
*** sdake has quit IRC | 15:52 | |
*** sdake_ is now known as sdake | 15:56 | |
*** dwyde has quit IRC | 16:14 | |
*** dwyde has joined #openstack-security | 16:19 | |
*** hyakuhei1 has joined #openstack-security | 16:21 | |
*** hyakuhei has quit IRC | 16:22 | |
*** singlethink has joined #openstack-security | 16:33 | |
*** dwyde has quit IRC | 16:52 | |
*** alex_klimov has quit IRC | 16:55 | |
*** pdesai has joined #openstack-security | 16:56 | |
*** markvoelker has joined #openstack-security | 16:57 | |
*** sicarie has joined #openstack-security | 16:58 | |
sicarie | hello | 17:00 |
elmiko | hi | 17:00 |
sicarie | Wow, it seems like forever since we’ve had a secguide meeting :) | 17:00 |
elmiko | yea, seriously! | 17:00 |
sicarie | wow, and it looks like we have a few more bugs too: https://bugs.launchpad.net/openstack/+bugs?field.tag=sec-guide | 17:01 |
elmiko | cool | 17:01 |
sicarie | pdesai: ping? | 17:01 |
*** shelleea007 has joined #openstack-security | 17:01 | |
sicarie | welcome shelleea007 | 17:01 |
sicarie | Okay, I’ll follow up with pdesai later - I think I missed an email from her I need to follow up on anyway | 17:02 |
elmiko | k | 17:02 |
pdesai | Hi everyone | 17:02 |
*** markvoelker has quit IRC | 17:02 | |
elmiko | hi | 17:02 |
sicarie | pdesai: ah, welcome! | 17:02 |
pdesai | thanks :) | 17:03 |
shelleea007 | hi | 17:03 |
sicarie | so we have a bunch of bugs, and the first one https://bugs.launchpad.net/openstack-manuals/+bug/1455678 | 17:03 |
openstack | Launchpad bug 1455678 in openstack-manuals "Tokens in Identity Chapter - Cover all types of tokens" [Undecided,Confirmed] | 17:03 |
sicarie | pdesai: care to give a quick overview? | 17:03 |
pdesai | Sure, i think we should add little background of different types of tokens and pros and cons of each from security standpoint | 17:04 |
sicarie | and what level of criticality were you thinking on this? | 17:04 |
pdesai | medium | 17:04 |
sicarie | looks like it would be great info to have | 17:04 |
elmiko | agreed, good bug | 17:05 |
pdesai | great | 17:05 |
sicarie | is everyone good with medium? | 17:05 |
elmiko | +1 | 17:06 |
sicarie | Cool, so next I have: https://bugs.launchpad.net/openstack-manuals/+bug/1459038 | 17:06 |
openstack | Launchpad bug 1459038 in openstack-manuals "Security Guide - Chapter 7. Dashboard - ngingx over Apache" [Undecided,Confirmed] | 17:06 |
sicarie | I opened this because in the Dashboard section they just say “we prefer Nginx" | 17:06 |
sicarie | No comparison of why or what else exists | 17:06 |
elmiko | hmm, that definitely needs an explanation | 17:06 |
shelleea007 | i agree | 17:06 |
pdesai | +1 | 17:07 |
sicarie | I’d like to break that out into “Nginx is good for quick stand-ups, but Apache + haproxy is better for HA….” etc... | 17:07 |
sicarie | I don’t think this is critical though | 17:07 |
sicarie | So I’d say low? | 17:07 |
sicarie | maybe even wishlist? | 17:07 |
shelleea007 | or low hanging fruit | 17:08 |
shelleea007 | someone who likes to research might like it | 17:08 |
sicarie | shelleea007: maybe, but I think this would take a bit of research | 17:08 |
sicarie | +1 exactly! | 17:08 |
elmiko | might be tough as lhf, there could be a bunch of work to explain the reasoning | 17:08 |
shelleea007 | ok. Just a thought | 17:09 |
pdesai | +1 for wishlist | 17:09 |
sicarie | Sounds good, I’ll roll with wishlist - I want to sprint through these and modify them later if we need to - I’d like to discuss the migration at the end | 17:09 |
sicarie | so next: https://bugs.launchpad.net/openstack-manuals/+bug/1459040 | 17:10 |
openstack | Launchpad bug 1459040 in openstack-manuals "Security Guide - Chapter 7. Dashboard - Too Many Sections" [Undecided,In progress] - Assigned to The-Kid (speer-emett) | 17:10 |
sicarie | each section of the dashboard was broken out into its own file | 17:10 |
elmiko | this one is under review now | 17:10 |
sicarie | and doing an ls of security-doc/security-guide/ was HUGE | 17:10 |
elmiko | oh man... | 17:10 |
sicarie | yes, a new contributor I met at the summit grabbed it | 17:10 |
elmiko | nice! | 17:11 |
sicarie | Yeah, he’s very sharp | 17:11 |
pdesai | :) | 17:11 |
sicarie | Here’s the review for that | 17:11 |
sicarie | https://review.openstack.org/#/c/187092/ | 17:11 |
sicarie | I hope I already attached you all to it | 17:11 |
sicarie | yeah, I think so | 17:11 |
elmiko | yea, i didn't comment because i was curious to see the result of your request =) | 17:11 |
sicarie | Yeah, I just think brining them in under domains will flow a little better logically - we’ll see | 17:12 |
sicarie | hopefully I’m not sending him around in circles | 17:12 |
elmiko | i didn't quite follow how you wanted them organized, but i'm still reading through that chapter | 17:12 |
sicarie | So, I was thinking low criticality | 17:12 |
elmiko | low is probably fine since this change is mostly developer facing | 17:12 |
sicarie | and I was pulling down his changes and building the guide locally to take a look at it | 17:13 |
sicarie | if you have ‘maven’ installed you can cd into the security-doc/security-guide and run mvn clean build or something similar and both the pdf and html will be auto-generated in a tmp folder | 17:13 |
sicarie | just in case anyone didn’t already know | 17:14 |
pdesai | sicarie | 17:14 |
pdesai | http://docs-draft.openstack.org/92/187092/3/check/gate-security-doc-tox-doc-publish-checkbuild/c7559ee//publish-docs/security-guide/content/index.html | 17:14 |
sicarie | oh cool | 17:14 |
sicarie | I didn’t know the gate did that | 17:14 |
sicarie | pdesai: thanks! | 17:14 |
pdesai | you can find the layout here instead of pulling the changes down, if only care for reviewing | 17:14 |
pdesai | sure | 17:14 |
elmiko | i usually just run the local mvn build to ensure that things are working properly | 17:15 |
sicarie | Oh cool, you all were already on top of that | 17:15 |
sicarie | awesome | 17:15 |
sicarie | so next: https://bugs.launchpad.net/openstack-manuals/+bug/1455546 | 17:15 |
openstack | Launchpad bug 1455546 in openstack-manuals "Security Guide - Acknowledge Editor Contributions for last 2 years" [Undecided,Incomplete] | 17:15 |
sicarie | I thought it would be nice to acknowledge bdpayne and his stewardship of the guide for the last 2 years | 17:16 |
elmiko | +1 | 17:16 |
*** erw has left #openstack-security | 17:16 | |
sicarie | the location of this addition is interesting - the ‘acknowledgements’ page is a graphic with company logos :( | 17:16 |
pdesai | +1 | 17:16 |
pdesai | :( | 17:16 |
sicarie | So I read through the intro and thought this location was most appropriate | 17:16 |
elmiko | hmm | 17:16 |
sicarie | we might consider updating that at some point, or expanding it | 17:17 |
elmiko | yea, i think that section makes sense | 17:17 |
sicarie | And then I was thinking low criticality (possibly even wishlist) | 17:17 |
elmiko | i'm good with either | 17:18 |
sicarie | shelleea007 or pdesai: any preference? | 17:18 |
shelleea007 | i concur with low | 17:18 |
pdesai | yup low | 17:18 |
sicarie | great | 17:18 |
*** dwyde has joined #openstack-security | 17:18 | |
sicarie | so next: https://bugs.launchpad.net/openstack-manuals/+bug/1459820 | 17:19 |
openstack | Launchpad bug 1459820 in openstack-manuals "OpenStack Security Guide - Mandatory Access Control policy guidance" [Undecided,Confirmed] | 17:19 |
sicarie | One of the things that’s always bugged me is recommending building MAC policies without any guidance on how | 17:19 |
shelleea007 | that is a good one | 17:19 |
sicarie | So I’d like to add some recommendation on SELinux/AppArmor/Grsecurity MAC policies to at least get poeple started | 17:20 |
sicarie | and I’d like to put this at medium priority | 17:20 |
shelleea007 | i concur with that one | 17:20 |
pdesai | +1 for medium | 17:20 |
elmiko | sounds good, which section would this add to? | 17:20 |
sicarie | elmiko: hit the nail on the head! | 17:20 |
elmiko | hehe | 17:20 |
sicarie | so this is also something that would cover multiple projects and require multiple policies | 17:20 |
sicarie | I think this needs to be on a per-project basis | 17:21 |
sicarie | Which may end up being per-chapter | 17:21 |
sicarie | Initially, I’d like to build this out as part of the Compute chapter as a general section | 17:21 |
sicarie | but as time goes on, I’d like to expand this to cover the core projects, and have a section per chapter | 17:21 |
elmiko | maybe this could eventually end up as part of the per-chapter checklist or something? | 17:21 |
sicarie | elmiko: good thought | 17:21 |
pdesai | yup sounds good | 17:22 |
elmiko | i guess we could even start building up an internal checklist for each chapter, case study (check), mac (check), etc... | 17:22 |
sicarie | I was going to put the bug on an “each chapter should have this” recommendation, but having done half of Alice’s case studies that’s a HUGE pain | 17:22 |
sicarie | elmiko: +1 can you open a bug to do so? | 17:23 |
elmiko | yea, open a bug to create a chapter checklist? | 17:23 |
sicarie | oh, yeah, or just comment on that bug | 17:24 |
sicarie | https://bugs.launchpad.net/openstack-manuals/+bug/1342993 | 17:24 |
openstack | Launchpad bug 1342993 in openstack-manuals "Adding Security Checklist in Security Guide" [Medium,In progress] - Assigned to Priti Desai (priti-desai) | 17:24 |
elmiko | definitely, i'll make a comment | 17:24 |
sicarie | Okay, I’m going to call it here because I want to discuss the rst migration | 17:24 |
sicarie | but if you have time, please feel free to take a look at the last 3 bugs we didn’t get to | 17:24 |
sicarie | so the rst migration is mostly automated, but there is definite manual work required after | 17:25 |
sicarie | build, validate, check links, check format, content, etc... | 17:25 |
pdesai | want to find out about migration, i have stalled 1342993 until the migration | 17:25 |
sicarie | pdesai: good to know! | 17:25 |
sicarie | so that’s the question in my mind | 17:26 |
sicarie | I’d really like to get the compute, network, and dashboard sections reviewed for up to date/accurate security guidance | 17:26 |
sicarie | but is docbook delaying that? | 17:26 |
sicarie | Or would migrating to rst now be a more significant delay due to the unknown follow-up work? | 17:27 |
elmiko | yea, we will need to break in current work when we decide to do the switch | 17:27 |
sicarie | elmiko: +1 | 17:27 |
elmiko | i think it might be best to do the change to rst, then start rereading everything | 17:28 |
elmiko | since we are already reading these chapters for correctness, why do it twice | 17:28 |
shelleea007 | +1 | 17:28 |
pdesai | agree | 17:28 |
elmiko | would it be possible for us to focus on one chapter at a time? | 17:28 |
elmiko | like, convert a chapter to rst, then review, then move on to the next? | 17:28 |
sicarie | elmiko: that’s a good question | 17:28 |
elmiko | maybe we could use an alternate directory structure to hold the rst until we have completed the entire transition | 17:29 |
sicarie | I’ll join the docs meeting tomorrow or Wednesday (I think it’s wednesday this week), and ask | 17:29 |
elmiko | cool, was just about to ask that lol | 17:29 |
elmiko | they might have some good advice | 17:29 |
sicarie | elmiko: yes, there is a current process | 17:29 |
sicarie | I’ll figure out what is needed and we’ll focus on that as of next Monday, I’ll get some set milestones | 17:30 |
sicarie | Cool, thanks everyone! | 17:30 |
pdesai | thanks | 17:30 |
elmiko | i'm gonna be out next monday, spark summit | 17:30 |
sicarie | elmiko: I’ll make sure to send an email follow-up - have fun! | 17:30 |
elmiko | sicarie: awesome, thanks! | 17:30 |
*** hyakuhei1 has quit IRC | 17:33 | |
*** pdesai has quit IRC | 17:37 | |
*** hyakuhei has joined #openstack-security | 17:42 | |
*** aswadr has quit IRC | 17:51 | |
*** sdake has quit IRC | 18:02 | |
*** sdake has joined #openstack-security | 18:02 | |
*** openstackgerrit has quit IRC | 18:09 | |
*** openstackgerrit has joined #openstack-security | 18:09 | |
*** browne has joined #openstack-security | 18:19 | |
*** shelleea007 has quit IRC | 18:23 | |
*** sicarie has quit IRC | 18:45 | |
*** markvoelker has joined #openstack-security | 18:46 | |
*** markvoelker has quit IRC | 18:52 | |
*** bpokorny_ has joined #openstack-security | 19:12 | |
*** bpokorny has quit IRC | 19:15 | |
*** alex_klimov has joined #openstack-security | 19:56 | |
*** dave-mcc_ has joined #openstack-security | 19:59 | |
*** singleth_ has joined #openstack-security | 19:59 | |
*** singlethink has quit IRC | 20:02 | |
*** dave-mccowan has quit IRC | 20:02 | |
*** markvoelker has joined #openstack-security | 20:35 | |
*** markvoelker has quit IRC | 20:40 | |
*** dave-mccowan has joined #openstack-security | 20:50 | |
*** dave-mcc_ has quit IRC | 20:50 | |
*** hyakuhei has quit IRC | 20:50 | |
*** hyakuhei has joined #openstack-security | 20:51 | |
*** hyakuhei has quit IRC | 20:57 | |
*** hyakuhei has joined #openstack-security | 20:57 | |
*** nkinder_ has joined #openstack-security | 21:05 | |
*** dave-mcc_ has joined #openstack-security | 21:06 | |
*** nkinder has quit IRC | 21:09 | |
*** dave-mccowan has quit IRC | 21:10 | |
*** nkinder_ has quit IRC | 21:12 | |
*** nkinder_ has joined #openstack-security | 21:13 | |
*** sdake_ has joined #openstack-security | 21:19 | |
*** sdake has quit IRC | 21:23 | |
*** nkinder_ has quit IRC | 21:26 | |
*** nkinder_ has joined #openstack-security | 21:27 | |
*** localloop127 has quit IRC | 21:45 | |
*** singleth_ has quit IRC | 21:54 | |
*** nkinder__ has joined #openstack-security | 21:58 | |
*** nkinder_ has quit IRC | 22:02 | |
*** nkinder__ has quit IRC | 22:03 | |
*** nkinder__ has joined #openstack-security | 22:04 | |
*** dave-mccowan has joined #openstack-security | 22:15 | |
*** dave-mcc_ has quit IRC | 22:18 | |
*** markvoelker has joined #openstack-security | 22:21 | |
*** markvoelker has quit IRC | 22:26 | |
*** dwyde has quit IRC | 22:26 | |
*** bpokorny_ has quit IRC | 22:28 | |
*** bpokorny has joined #openstack-security | 22:28 | |
*** voodookid has quit IRC | 23:02 | |
*** nkinder__ has quit IRC | 23:18 | |
*** bpokorny has quit IRC | 23:19 | |
*** bpokorny has joined #openstack-security | 23:19 | |
*** dave-mcc_ has joined #openstack-security | 23:23 | |
openstackgerrit | Merged stackforge/bandit: Log the version of Python bandit is running under https://review.openstack.org/189140 | 23:24 |
*** dave-mccowan has quit IRC | 23:26 | |
*** alex_klimov has quit IRC | 23:29 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!