*** markvoelker has joined #openstack-security | 00:12 | |
*** markvoelker has quit IRC | 00:17 | |
openstackgerrit | Stanislaw Pitucha proposed stackforge/anchor: Force absolute imports rather than relative ones https://review.openstack.org/190877 | 00:34 |
---|---|---|
*** sigmavirus24 is now known as sigmavirus24_awa | 00:39 | |
*** salv-orlando has joined #openstack-security | 00:55 | |
*** salv-orlando has quit IRC | 01:01 | |
*** browne has quit IRC | 01:23 | |
*** bpokorny has quit IRC | 01:25 | |
openstackgerrit | Stanislaw Pitucha proposed stackforge/anchor: Add explicit decoding to asn1 data https://review.openstack.org/190890 | 01:27 |
openstackgerrit | Stanislaw Pitucha proposed stackforge/anchor: Explicit long is not needed https://review.openstack.org/190892 | 01:37 |
*** sigmavirus24_awa is now known as sigmavirus24 | 01:43 | |
openstackgerrit | Stanislaw Pitucha proposed stackforge/anchor: Explicit long is not needed https://review.openstack.org/190892 | 01:47 |
openstackgerrit | Stanislaw Pitucha proposed stackforge/anchor: Add explicit decoding to asn1 data https://review.openstack.org/190890 | 01:47 |
*** markvoelker has joined #openstack-security | 02:01 | |
*** markvoelker has quit IRC | 02:07 | |
*** browne has joined #openstack-security | 02:07 | |
*** bknudson has quit IRC | 02:10 | |
*** salv-orlando has joined #openstack-security | 02:36 | |
*** salv-orlando has quit IRC | 02:41 | |
*** tmcpeak has quit IRC | 03:14 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 03:18 | |
*** markvoelker has joined #openstack-security | 03:50 | |
*** markvoelker has quit IRC | 03:55 | |
*** alex_klimov has quit IRC | 04:38 | |
*** salv-orlando has joined #openstack-security | 04:50 | |
*** salv-orlando has quit IRC | 04:53 | |
*** salv-orlando has joined #openstack-security | 05:03 | |
*** hyakuhei has quit IRC | 05:39 | |
*** markvoelker has joined #openstack-security | 05:39 | |
*** hyakuhei has joined #openstack-security | 05:43 | |
*** markvoelker has quit IRC | 05:44 | |
*** zz_naotok has quit IRC | 05:54 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Imported Translations from Transifex https://review.openstack.org/190491 | 06:01 |
*** sdake has quit IRC | 06:08 | |
*** shohel has joined #openstack-security | 06:14 | |
*** shohel has quit IRC | 06:19 | |
*** shohel has joined #openstack-security | 06:34 | |
*** browne has quit IRC | 06:53 | |
*** markvoelker has joined #openstack-security | 07:28 | |
*** markvoelker has quit IRC | 07:33 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/190973 | 08:32 |
*** markvoelker has joined #openstack-security | 09:16 | |
*** markvoelker has quit IRC | 09:21 | |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/190973 | 09:50 |
openstackgerrit | Merged openstack/security-doc: Imported Translations from Transifex https://review.openstack.org/190491 | 09:51 |
*** hyakuhei has quit IRC | 10:08 | |
*** hyakuhei1 has joined #openstack-security | 10:08 | |
*** hyakuhei has joined #openstack-security | 10:33 | |
*** hyakuhei1 has quit IRC | 10:33 | |
*** hyakuhei has quit IRC | 10:39 | |
*** hyakuhei has joined #openstack-security | 10:46 | |
*** jian5397 has joined #openstack-security | 11:38 | |
*** markvoelker has joined #openstack-security | 11:50 | |
*** shohel has quit IRC | 12:04 | |
*** shohel has joined #openstack-security | 12:04 | |
*** shohel has quit IRC | 12:11 | |
*** bknudson has joined #openstack-security | 12:25 | |
*** jian5397 has quit IRC | 12:26 | |
*** shohel has joined #openstack-security | 12:27 | |
*** salv-orl_ has joined #openstack-security | 12:54 | |
*** salv-orlando has quit IRC | 12:54 | |
*** shohel has quit IRC | 12:56 | |
*** shohel has joined #openstack-security | 12:58 | |
*** singlethink has joined #openstack-security | 13:00 | |
*** shohel has quit IRC | 13:06 | |
*** hyakuhei1 has joined #openstack-security | 13:14 | |
*** hyakuhei has quit IRC | 13:15 | |
*** tmcpeak has joined #openstack-security | 13:17 | |
*** shohel has joined #openstack-security | 13:18 | |
*** sdake has joined #openstack-security | 13:21 | |
*** nkinder__ has quit IRC | 13:23 | |
*** localloo1 has joined #openstack-security | 13:50 | |
*** singleth_ has joined #openstack-security | 13:58 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:01 | |
*** singlethink has quit IRC | 14:01 | |
*** localloo1 has quit IRC | 14:02 | |
*** jian5397 has joined #openstack-security | 14:09 | |
*** shohel has quit IRC | 14:10 | |
*** browne has joined #openstack-security | 14:11 | |
*** shohel has joined #openstack-security | 14:15 | |
*** nkinder__ has joined #openstack-security | 14:20 | |
*** singleth_ has quit IRC | 14:26 | |
*** shohel has quit IRC | 14:35 | |
*** hyakuhei1 has quit IRC | 14:37 | |
*** hyakuhei has joined #openstack-security | 14:38 | |
*** singlethink has joined #openstack-security | 14:41 | |
*** salv-orl_ has quit IRC | 14:47 | |
*** dwyde has joined #openstack-security | 14:59 | |
*** sdake_ has joined #openstack-security | 15:05 | |
*** sdake has quit IRC | 15:09 | |
*** sdake has joined #openstack-security | 15:10 | |
*** salv-orlando has joined #openstack-security | 15:14 | |
*** sdake_ has quit IRC | 15:14 | |
*** bpokorny has joined #openstack-security | 15:16 | |
*** singlethink has quit IRC | 15:34 | |
openstackgerrit | janonymous proposed openstack/security-doc: [security-guide]Change to generalized term database. https://review.openstack.org/191119 | 15:41 |
*** shohel has joined #openstack-security | 15:50 | |
*** kutija has joined #openstack-security | 15:51 | |
*** kutija_ has quit IRC | 15:55 | |
*** shohel has quit IRC | 15:56 | |
*** sdake_ has joined #openstack-security | 16:12 | |
*** sdake has quit IRC | 16:16 | |
*** shohel has joined #openstack-security | 16:23 | |
*** singlethink has joined #openstack-security | 16:36 | |
*** browne has quit IRC | 16:43 | |
*** PupUser2beeb1 has joined #openstack-security | 16:50 | |
PupUser2beeb1 | hello | 16:50 |
sigmavirus24 | hi PupUser2beeb1 | 16:50 |
PupUser2beeb1 | how are you | 16:50 |
sigmavirus24 | not bad. yourself? | 16:50 |
PupUser2beeb1 | exactly | 16:52 |
PupUser2beeb1 | where are you from | 16:52 |
sigmavirus24 | Why do you ask? | 16:52 |
PupUser2beeb1 | i wondereded | 16:53 |
PupUser2beeb1 | muhabbet olsun be aga | 16:56 |
*** dwyde has quit IRC | 17:00 | |
sigmavirus24 | gmurphy: within the context of https://review.openstack.org/#/c/189537/, would we publish an OSSN? If so, when would it be published? And would it be okay if I authored it? | 17:02 |
*** salv-orl_ has joined #openstack-security | 17:08 | |
*** salv-orlando has quit IRC | 17:11 | |
PupUser2beeb1 | hi | 17:18 |
PupUser2beeb1 | does they speak turkish | 17:18 |
* sigmavirus24 does not speak turkish but can not say whether other people here do or do not speak turkish | 17:20 | |
*** browne has joined #openstack-security | 17:20 | |
*** salv-orlando has joined #openstack-security | 17:25 | |
*** salv-orl_ has quit IRC | 17:28 | |
*** dwyde has joined #openstack-security | 17:33 | |
*** PupUser2beeb1 has quit IRC | 17:33 | |
*** shohel has quit IRC | 17:33 | |
*** hyakuhei has quit IRC | 17:34 | |
tmcpeak | lol | 17:40 |
tmcpeak | (sigh) | 17:41 |
tmcpeak | sigmavirus24: gmurphy is currently in Aussie-land | 17:41 |
tmcpeak | his timezone is a little different ;) | 17:41 |
sigmavirus24 | Aha | 17:41 |
sigmavirus24 | That's fine | 17:41 |
* sigmavirus24 is just curious | 17:41 | |
sigmavirus24 | The bug that the refactor is related to (which I need to add to the spec because I forgot there was one) is linked to a mega CVE for a bunch of services that insecurely talk to backends | 17:42 |
tmcpeak | sigmavirus24: this looks like solid OSSN territory though | 17:42 |
tmcpeak | and yeah, if you want to write it that would be awesome | 17:42 |
sigmavirus24 | tmcpeak: Yeah, especially since the Glance team is leaning towards insecure by default for the Liberty release | 17:42 |
sigmavirus24 | Which grinds my gears but upgrades are important too | 17:42 |
tmcpeak | sigmavirus24: yep, insecure default warnings are one of the primary functions of OSSN | 17:42 |
sigmavirus24 | Cool | 17:43 |
tmcpeak | sigmavirus24: so create a LP bug for it and assign to yourself? | 17:43 |
tmcpeak | https://launchpad.net/ossn | 17:43 |
sigmavirus24 | Should I just mark the existing bug as affecting OSSN? | 17:43 |
tmcpeak | ahh, yeah, that's a good way to do it | 17:44 |
sigmavirus24 | Cool | 17:44 |
*** hyakuhei has joined #openstack-security | 17:45 | |
nkinder__ | sigmavirus24: yeah, just adding 'ossn' as an affected project is the right way to do it | 17:51 |
sigmavirus24 | So... as for timing, what's the process? | 17:53 |
sigmavirus24 | This won't be part of anything until Liberty is released. Do I write the note and wait until Liberty before it's merged? | 17:53 |
* sigmavirus24 is new to all of this | 17:54 | |
*** bpokorny_ has joined #openstack-security | 17:58 | |
*** bpokorn__ has joined #openstack-security | 18:01 | |
*** bpokorny has quit IRC | 18:02 | |
*** bpokorny_ has quit IRC | 18:04 | |
*** hyakuhei has quit IRC | 18:05 | |
*** hyakuhei has joined #openstack-security | 18:05 | |
*** sdake_ is now known as sdake | 18:34 | |
*** bknudson has quit IRC | 18:39 | |
*** sdake_ has joined #openstack-security | 19:18 | |
*** sdake has quit IRC | 19:21 | |
*** sdake_ is now known as sdake | 19:26 | |
*** tmcpeak has quit IRC | 19:47 | |
*** tmcpeak has joined #openstack-security | 19:59 | |
tmcpeak | sigmavirus24: interesting question, did you get an an answer? | 20:02 |
sigmavirus24 | nope | 20:02 |
tmcpeak | nkinder__ is probably the one who would know | 20:02 |
sigmavirus24 | not urgent either obviously | 20:02 |
tmcpeak | nkinder__ do we release notes for things that aren't an issue until Liberty? | 20:02 |
dstufft | sigmavirus24: insecure defaults should be abolished from the world | 20:06 |
sigmavirus24 | dstufft: preaching to the choir | 20:06 |
*** redrobot has quit IRC | 20:07 | |
sigmavirus24 | I'm tempted to point at Python 2.7.9 and such and be like "SEE! IT'S OKAY!" but I know someone, somewhere is going to throw a tantrum if I do that | 20:07 |
dstufft | 2.7.9-- I mean 2.8 | 20:08 |
sigmavirus24 | That said, the spec needs to be updated to reflect the final decision, e.g., "insecure during L with vocal warnings that M will be secure by default" | 20:08 |
*** redrobot has joined #openstack-security | 20:08 | |
*** redrobot is now known as Guest67074 | 20:08 | |
nkinder__ | sigmavirus24: I think it's fine to release an OSSN before the L release actually lands | 20:23 |
nkinder__ | sigmavirus24: people might be deploying test environments with pre-release code | 20:24 |
tmcpeak | ++ | 20:24 |
tmcpeak | and yeah, dstufft - amen | 20:24 |
sigmavirus24 | cool | 20:24 |
sigmavirus24 | I'll work on that stuff this weekend | 20:24 |
tmcpeak | sigmavirus24: awesome man! | 20:25 |
sigmavirus24 | Did everyone see https://securityblog.redhat.com/2015/06/10/the-hidden-costs-of-embargoes/ btw? | 20:31 |
sigmavirus24 | dstufft: 2.7.9̅ | 20:45 |
*** bpokorn__ has quit IRC | 20:56 | |
*** bpokorny has joined #openstack-security | 20:56 | |
*** voodookid has joined #openstack-security | 20:59 | |
*** edmondsw has joined #openstack-security | 21:14 | |
*** edmondsw_ has joined #openstack-security | 21:27 | |
*** sdake_ has joined #openstack-security | 21:36 | |
*** edmondsw_ has quit IRC | 21:36 | |
*** jian5397 has quit IRC | 21:38 | |
*** sdake has quit IRC | 21:40 | |
*** edmondsw has quit IRC | 21:40 | |
*** nkinder__ has quit IRC | 21:42 | |
*** sdake_ has quit IRC | 21:44 | |
*** dwyde has quit IRC | 22:00 | |
*** sdake has joined #openstack-security | 22:44 | |
*** JAHoagie has joined #openstack-security | 22:50 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 22:54 | |
*** JAHoagie has quit IRC | 23:01 | |
*** singlethink has quit IRC | 23:03 | |
*** voodookid has quit IRC | 23:07 | |
*** salv-orlando has quit IRC | 23:08 | |
*** tmcpeak has quit IRC | 23:14 | |
*** openstackgerrit has quit IRC | 23:22 | |
*** openstackgerrit has joined #openstack-security | 23:22 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!