*** sdake_ has joined #openstack-security | 00:00 | |
*** bpokorny has quit IRC | 00:00 | |
*** sdake has quit IRC | 00:02 | |
*** sdake has joined #openstack-security | 00:09 | |
*** sdake_ has quit IRC | 00:13 | |
*** security_ has quit IRC | 00:51 | |
*** security-admin has joined #openstack-security | 00:52 | |
*** bpokorny_ has quit IRC | 01:01 | |
*** security-admin has quit IRC | 01:20 | |
*** security-admin has joined #openstack-security | 01:20 | |
*** security-admin has quit IRC | 01:25 | |
*** tamo has joined #openstack-security | 02:28 | |
tamo | hola | 02:29 |
---|---|---|
*** tmcpeak has quit IRC | 02:32 | |
tamo | hello | 02:33 |
*** tamo has left #openstack-security | 02:33 | |
*** security-admin has joined #openstack-security | 03:33 | |
*** security_ has joined #openstack-security | 03:34 | |
*** security-admin has quit IRC | 03:38 | |
*** security_ has quit IRC | 03:51 | |
*** security-admin has joined #openstack-security | 03:51 | |
*** security-admin has quit IRC | 03:55 | |
*** hyakuhei1 has joined #openstack-security | 04:35 | |
*** hyakuhei has quit IRC | 04:35 | |
*** hyakuhei1 has quit IRC | 04:44 | |
*** hyakuhei has joined #openstack-security | 04:51 | |
*** dave-mccowan has quit IRC | 04:52 | |
*** dave-mccowan has joined #openstack-security | 05:05 | |
*** elo has quit IRC | 05:16 | |
*** security-admin has joined #openstack-security | 05:20 | |
*** hyakuhei has quit IRC | 05:25 | |
*** hyakuhei has joined #openstack-security | 05:28 | |
*** dave-mccowan has quit IRC | 05:31 | |
*** elo has joined #openstack-security | 05:32 | |
*** hyakuhei has quit IRC | 05:41 | |
*** elo has quit IRC | 05:42 | |
*** hyakuhei has joined #openstack-security | 05:44 | |
*** ig0r_ has joined #openstack-security | 05:51 | |
*** ig0r__ has quit IRC | 05:55 | |
*** elo has joined #openstack-security | 06:10 | |
*** browne has quit IRC | 07:33 | |
*** security-admin has quit IRC | 07:43 | |
*** security-admin has joined #openstack-security | 07:56 | |
*** hyakuhei has quit IRC | 08:33 | |
*** hyakuhei has joined #openstack-security | 08:33 | |
*** elo has quit IRC | 08:40 | |
*** security-admin has quit IRC | 08:57 | |
*** security-admin has joined #openstack-security | 09:28 | |
*** security-admin has quit IRC | 09:35 | |
*** shohel has joined #openstack-security | 10:58 | |
*** vivcheri has joined #openstack-security | 11:26 | |
*** security-admin has joined #openstack-security | 11:32 | |
*** security-admin has quit IRC | 11:36 | |
*** markvoelker has quit IRC | 11:59 | |
*** markvoelker has joined #openstack-security | 11:59 | |
*** bknudson has quit IRC | 12:03 | |
*** dave-mccowan has joined #openstack-security | 12:13 | |
*** ramitsurana has joined #openstack-security | 12:18 | |
*** browne has joined #openstack-security | 12:18 | |
*** elo has joined #openstack-security | 12:23 | |
*** bknudson has joined #openstack-security | 12:27 | |
*** markvoelker has quit IRC | 12:31 | |
*** edmondsw has joined #openstack-security | 12:38 | |
*** ramitsurana has quit IRC | 12:38 | |
*** markvoelker has joined #openstack-security | 12:40 | |
*** tmcpeak has joined #openstack-security | 12:52 | |
*** browne has quit IRC | 13:10 | |
*** localloop127 has joined #openstack-security | 13:30 | |
*** browne has joined #openstack-security | 13:30 | |
*** security-admin has joined #openstack-security | 13:33 | |
*** singlethink has joined #openstack-security | 13:34 | |
*** singlethink has quit IRC | 13:38 | |
*** security-admin has quit IRC | 13:38 | |
*** singlethink has joined #openstack-security | 13:39 | |
*** singleth_ has joined #openstack-security | 13:49 | |
openstackgerrit | Nathan Kinder proposed openstack/security-doc: Correct typo in OSSN-0049 https://review.openstack.org/199105 | 13:49 |
*** singlethink has quit IRC | 13:52 | |
elmiko | nkinder: oops... | 13:53 |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:57 | |
nkinder | elmiko: :) | 13:59 |
nkinder | elmiko: the only reason I caught it was that thunderbird highlighted it when I was sending it out | 13:59 |
elmiko | nkinder: oh man... | 13:59 |
nkinder | elmiko: I just fixed it before publishing | 13:59 |
elmiko | lucky catch | 13:59 |
openstackgerrit | Merged openstack/security-doc: Correct typo in OSSN-0049 https://review.openstack.org/199105 | 14:00 |
Daviey | elmiko: did you see i responded to your comment on https://review.openstack.org/#/c/198328/ ? | 14:07 |
elmiko | Daviey: i had not, 1 sec | 14:08 |
elmiko | Daviey: https://wiki.openstack.org/wiki/Documentation/Conventions#backend.2C_back_end.2C_and_back-end | 14:08 |
Daviey | ta | 14:08 |
elmiko | not a huge deal, but it looked like the sentences would be the same without using back-end | 14:08 |
Daviey | elmiko: Ah, so I *should* use "back end" | 14:09 |
elmiko | if it can't be avoided, yes | 14:09 |
Daviey | hmm or should i | 14:09 |
Daviey | elmiko: Well why should it be avoided? It is cinder terminology | 14:09 |
elmiko | i wasn't aware of the cinder terminology, so this may be one of the cases where usage is acceptable | 14:10 |
Daviey | If i was talking about the backend of a website, that would be wrong.. I should say Django or something | 14:10 |
elmiko | right | 14:10 |
Daviey | But if i was talking about mod_backend, then it seems appropriate | 14:10 |
elmiko | definitely | 14:10 |
elmiko | thanks for the clarification, removing -1 | 14:10 |
Daviey | elmiko: Thanks! | 14:11 |
Daviey | elmiko: fancy changing it to +2 +A ? :)) | 14:11 |
openstackgerrit | Merged openstack/security-doc: Fix clunky sentence about front-end caching in Dashboard chapter https://review.openstack.org/198902 | 14:11 |
elmiko | hmm | 14:12 |
elmiko | is 2 x +2 enough for +A? | 14:12 |
elmiko | although, i can't imagine what issues folks might have with this | 14:12 |
Daviey | Unless doc's handle things different to other projects? | 14:13 |
Daviey | hyakuhei did +2 on an earlier change | 14:13 |
elmiko | good point | 14:13 |
*** sdake has quit IRC | 14:14 | |
elmiko | ok, added +A | 14:15 |
elmiko | but if anyone asks, i'll tell em you twisted my arm ;) | 14:15 |
*** sdake has joined #openstack-security | 14:15 | |
Daviey | elmiko: I did! And i appreciate it. Ta | 14:15 |
elmiko | np | 14:16 |
openstackgerrit | Merged openstack/security-doc: Introduce Block Storage / Cinder chapter https://review.openstack.org/198328 | 14:28 |
*** sicarie has joined #openstack-security | 14:31 | |
*** voodookid has joined #openstack-security | 14:54 | |
*** shohel has quit IRC | 14:59 | |
*** georgem1 has joined #openstack-security | 14:59 | |
georgem1 | I was doing a port scan against my public IP space and I noticed that port 9697 is exposed on the outside on all the IP's owned by neutron routers, and I'm trying to find a way to close this access | 15:01 |
georgem1 | I think it's a security issue to have a tenant lock down his instances but still open up a web service on his public IP space, what do you think? | 15:02 |
elmiko | georgem1: i'm not intimately familiar with neutron, but is 9697 the port it needs to access the service? | 15:05 |
elmiko | in general though, your premise seems reasonable | 15:06 |
georgem1 | 9697 is where the metadata service listens on, so the vms request metadata from 169.254.169.254:80 which gets redirected to 9697 and from there the neutron metadata service sends the request to nova on port 8775 | 15:07 |
georgem1 | my problem is that neutron listens on all IPs inside the qrouter namespace on port 9697 and this shows up in a port scan | 15:08 |
elmiko | interesting, have you talked with the folks in openstack-neutron about this? (i'm curious if this is intended behavior) | 15:09 |
georgem1 | and I couldn't find a way to block the traffic with iptables from outside the namespace, I would preferably block all traffic that comes over the public facing NIC on port 9697, but it doesn't work | 15:09 |
elmiko | seems like there should be a way to block that traffic | 15:10 |
georgem1 | hence here I am, in the security channel :) | 15:10 |
elmiko | wish i could help more, but this is at the edge of my neutron knowledge :/ | 15:11 |
georgem1 | elmiko: thanks, I'll try in #openstack-neutron | 15:12 |
elmiko | gl! | 15:12 |
*** security-admin has joined #openstack-security | 15:19 | |
*** dwyde has joined #openstack-security | 15:21 | |
*** bpokorny has joined #openstack-security | 15:23 | |
*** security-admin has quit IRC | 15:31 | |
*** security-admin has joined #openstack-security | 15:31 | |
*** security-admin has quit IRC | 15:36 | |
*** sdake_ has joined #openstack-security | 15:48 | |
*** sdake has quit IRC | 15:48 | |
*** salv-orlando has joined #openstack-security | 15:58 | |
*** aswadr has joined #openstack-security | 16:02 | |
*** georgem1 has quit IRC | 16:09 | |
*** elo has quit IRC | 16:20 | |
*** singlethink has joined #openstack-security | 16:22 | |
*** singleth_ has quit IRC | 16:25 | |
*** sdake_ is now known as sdae | 16:35 | |
*** sdae is now known as sdake | 16:39 | |
*** georgem1 has joined #openstack-security | 16:45 | |
*** singlethink has quit IRC | 16:55 | |
*** georgem1 has quit IRC | 17:01 | |
*** aswadr has quit IRC | 17:07 | |
*** salv-orl_ has joined #openstack-security | 17:08 | |
*** salv-orlando has quit IRC | 17:11 | |
*** singlethink has joined #openstack-security | 17:11 | |
*** security-admin has joined #openstack-security | 17:19 | |
*** georgem1 has joined #openstack-security | 17:20 | |
*** browne has quit IRC | 17:22 | |
*** elo has joined #openstack-security | 17:23 | |
*** security-admin has quit IRC | 17:24 | |
*** security-admin has joined #openstack-security | 17:24 | |
*** security-admin has quit IRC | 17:29 | |
*** deepika has joined #openstack-security | 17:31 | |
*** security-admin has joined #openstack-security | 17:31 | |
*** shohel has joined #openstack-security | 17:52 | |
*** browne has joined #openstack-security | 17:59 | |
*** security-admin has quit IRC | 18:00 | |
*** georgem1 has quit IRC | 18:01 | |
*** georgem1 has joined #openstack-security | 18:01 | |
*** singleth_ has joined #openstack-security | 18:05 | |
*** singlethink has quit IRC | 18:08 | |
*** georgem1 has quit IRC | 18:11 | |
*** salv-orl_ has quit IRC | 18:22 | |
*** georgem1 has joined #openstack-security | 18:28 | |
*** georgem1 has quit IRC | 18:29 | |
*** security-admin has joined #openstack-security | 18:33 | |
*** georgem1 has joined #openstack-security | 18:34 | |
*** sdake has quit IRC | 18:36 | |
*** georgem1 has quit IRC | 18:38 | |
*** georgem1 has joined #openstack-security | 18:38 | |
*** georgem1 has quit IRC | 18:49 | |
*** salv-orlando has joined #openstack-security | 18:49 | |
*** dlitz has quit IRC | 18:51 | |
*** sdake has joined #openstack-security | 18:52 | |
*** georgem1 has joined #openstack-security | 18:52 | |
*** georgem1 has quit IRC | 18:56 | |
*** georgem1 has joined #openstack-security | 18:56 | |
*** sdake_ has joined #openstack-security | 18:56 | |
*** sdake has quit IRC | 19:00 | |
*** georgem11 has joined #openstack-security | 19:01 | |
*** georgem1 has quit IRC | 19:01 | |
*** singlethink has joined #openstack-security | 19:04 | |
*** singleth_ has quit IRC | 19:07 | |
*** dlitz has joined #openstack-security | 19:07 | |
openstackgerrit | Priti Desai proposed openstack/security-specs: Setup Security Specs Repo https://review.openstack.org/197735 | 19:09 |
*** jelle has left #openstack-security | 19:26 | |
*** jelle has joined #openstack-security | 19:26 | |
*** jelle has left #openstack-security | 19:26 | |
*** jelle has joined #openstack-security | 19:26 | |
*** bdpayne has joined #openstack-security | 19:28 | |
*** singleth_ has joined #openstack-security | 19:29 | |
*** singlet__ has joined #openstack-security | 19:30 | |
*** singlethink has quit IRC | 19:33 | |
*** singleth_ has quit IRC | 19:34 | |
*** security-admin has quit IRC | 19:35 | |
*** security-admin has joined #openstack-security | 19:35 | |
openstackgerrit | Dave Walker proposed openstack/security-doc: Document cinder wiping behavior with LVM backend https://review.openstack.org/199231 | 19:37 |
*** security-admin has quit IRC | 19:49 | |
*** security-admin has joined #openstack-security | 19:49 | |
*** security-admin has quit IRC | 19:53 | |
*** georgem11 has quit IRC | 19:54 | |
*** bpokorny has quit IRC | 20:02 | |
*** georgem1 has joined #openstack-security | 20:02 | |
*** bpokorny has joined #openstack-security | 20:02 | |
*** security-admin has joined #openstack-security | 20:05 | |
*** singlethink has joined #openstack-security | 20:10 | |
*** bdpayne has quit IRC | 20:12 | |
*** singlet__ has quit IRC | 20:12 | |
*** singleth_ has joined #openstack-security | 20:18 | |
*** georgem1 has quit IRC | 20:19 | |
*** bdpayne has joined #openstack-security | 20:19 | |
*** salv-orlando has quit IRC | 20:20 | |
*** singlethink has quit IRC | 20:22 | |
*** JAHoagie has joined #openstack-security | 20:29 | |
openstackgerrit | Tim Kelsey proposed stackforge/bandit: Removing statement buffer https://review.openstack.org/199249 | 20:29 |
openstackgerrit | Tim Kelsey proposed stackforge/bandit: Removing statement buffer https://review.openstack.org/199249 | 20:33 |
openstackgerrit | Tim Kelsey proposed stackforge/bandit: Removing statement buffer https://review.openstack.org/199249 | 20:37 |
openstackgerrit | Tim Kelsey proposed stackforge/bandit: Removing statement buffer https://review.openstack.org/199249 | 20:38 |
*** jamielennox is now known as jamielennox|away | 20:41 | |
openstackgerrit | Tim Kelsey proposed stackforge/bandit: Removing statement buffer https://review.openstack.org/199249 | 20:48 |
openstackgerrit | Nathaniel Dillon proposed openstack/security-doc: Adding hypervisor and issue handling section to compute chapter https://review.openstack.org/196200 | 20:49 |
*** jamielennox|away is now known as jamielennox | 20:52 | |
*** dlitz has quit IRC | 21:14 | |
*** dlitz has joined #openstack-security | 21:17 | |
*** sdake_ is now known as sdake | 21:20 | |
*** salv-orlando has joined #openstack-security | 21:22 | |
*** dlitz has quit IRC | 21:23 | |
*** dlitz has joined #openstack-security | 21:26 | |
*** salv-orlando has quit IRC | 21:29 | |
*** salv-orlando has joined #openstack-security | 21:30 | |
*** deepika has quit IRC | 21:41 | |
*** singlethink has joined #openstack-security | 21:43 | |
*** browne has quit IRC | 21:44 | |
*** singleth_ has quit IRC | 21:47 | |
*** singlethink has quit IRC | 21:47 | |
*** sdake_ has joined #openstack-security | 21:48 | |
*** sdake has quit IRC | 21:52 | |
*** dlitz has quit IRC | 21:53 | |
*** localloop127 has quit IRC | 21:54 | |
*** dlitz has joined #openstack-security | 21:56 | |
*** security-admin has quit IRC | 21:56 | |
*** JAHoagie has quit IRC | 22:00 | |
*** JAHoagie has joined #openstack-security | 22:02 | |
openstackgerrit | Merged openstack/security-specs: Setup Security Specs Repo https://review.openstack.org/197735 | 22:06 |
*** security-admin has joined #openstack-security | 22:11 | |
*** security_ has joined #openstack-security | 22:20 | |
*** bpokorny_ has joined #openstack-security | 22:21 | |
*** security-admin has quit IRC | 22:23 | |
*** bpokorny has quit IRC | 22:24 | |
*** shohel has quit IRC | 22:26 | |
*** bknudson has quit IRC | 22:31 | |
*** edmondsw has quit IRC | 22:33 | |
*** browne has joined #openstack-security | 22:37 | |
*** security_ has quit IRC | 22:43 | |
*** security-admin has joined #openstack-security | 22:43 | |
*** dwyde has quit IRC | 22:44 | |
openstackgerrit | Dave Walker proposed openstack/security-doc: Document cinder wiping behavior with LVM backend https://review.openstack.org/199231 | 22:48 |
*** sicarie has quit IRC | 22:55 | |
*** dlitz has quit IRC | 22:56 | |
*** dlitz has joined #openstack-security | 22:59 | |
*** voodookid has quit IRC | 23:01 | |
*** security-admin has quit IRC | 23:20 | |
*** security-admin has joined #openstack-security | 23:21 | |
*** salv-orlando has quit IRC | 23:26 | |
*** JAHoagie has quit IRC | 23:27 | |
*** JAHoagie has joined #openstack-security | 23:43 | |
*** bdpayne has quit IRC | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!