*** markvoelker has quit IRC | 00:20 | |
*** winterIsLeaving has quit IRC | 00:21 | |
*** winterIsLeaving has joined #openstack-security | 00:22 | |
*** pdesai has quit IRC | 00:29 | |
*** shakamunyi has quit IRC | 00:35 | |
*** shakamunyi has joined #openstack-security | 00:35 | |
*** bpokorny_ has joined #openstack-security | 00:45 | |
*** bpokorny has quit IRC | 00:49 | |
*** hyakuhei has joined #openstack-security | 00:56 | |
*** barra204 has joined #openstack-security | 00:56 | |
*** hyakuhei has quit IRC | 00:56 | |
*** shakamunyi has quit IRC | 00:57 | |
*** hyakuhei has joined #openstack-security | 00:59 | |
*** jhfeng has joined #openstack-security | 01:01 | |
*** austin987 has quit IRC | 01:10 | |
*** barra204 has quit IRC | 01:14 | |
*** shakamunyi has joined #openstack-security | 01:15 | |
*** markvoelker has joined #openstack-security | 01:21 | |
*** austin987 has joined #openstack-security | 01:22 | |
*** markvoelker has quit IRC | 01:25 | |
*** markvoelker has joined #openstack-security | 01:25 | |
*** barra204 has joined #openstack-security | 01:31 | |
*** shakamunyi has quit IRC | 01:32 | |
*** shakamunyi has joined #openstack-security | 01:36 | |
*** barra204 has quit IRC | 01:38 | |
*** barra204 has joined #openstack-security | 01:38 | |
*** shakamunyi has quit IRC | 01:39 | |
*** shakamunyi has joined #openstack-security | 01:44 | |
*** barra204 has quit IRC | 01:45 | |
*** shakamunyi has quit IRC | 01:48 | |
*** shakamunyi has joined #openstack-security | 01:48 | |
*** shakamunyi has quit IRC | 01:54 | |
*** shakamunyi has joined #openstack-security | 02:08 | |
*** shakamunyi has quit IRC | 02:10 | |
*** shakamunyi has joined #openstack-security | 02:12 | |
*** bpokorny_ has quit IRC | 02:13 | |
*** bpokorny has joined #openstack-security | 02:14 | |
*** shakamunyi has quit IRC | 02:22 | |
*** shakamunyi has joined #openstack-security | 02:23 | |
*** bpokorny_ has joined #openstack-security | 02:30 | |
*** shakamunyi has quit IRC | 02:32 | |
*** bpokorny has quit IRC | 02:34 | |
*** bpokorny_ has quit IRC | 02:35 | |
*** salv-orlando has quit IRC | 02:47 | |
*** hyakuhei has quit IRC | 02:56 | |
*** salv-orlando has joined #openstack-security | 02:58 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 03:22 | |
*** salv-orl_ has joined #openstack-security | 04:10 | |
*** pdesai has joined #openstack-security | 04:11 | |
*** salv-orlando has quit IRC | 04:13 | |
*** pdesai has quit IRC | 04:17 | |
*** jhfeng has quit IRC | 04:36 | |
*** jhfeng has joined #openstack-security | 04:49 | |
*** markvoelker has quit IRC | 04:58 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 05:18 | |
*** jhfeng has quit IRC | 05:27 | |
*** markvoelker has joined #openstack-security | 05:59 | |
*** edmondsw has quit IRC | 06:02 | |
*** markvoelker has quit IRC | 06:06 | |
*** salv-orl_ has quit IRC | 06:50 | |
*** salv-orlando has joined #openstack-security | 06:50 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/266229 | 06:53 |
---|---|---|
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/266229 | 07:08 |
*** salv-orl_ has joined #openstack-security | 08:01 | |
*** salv-orlando has quit IRC | 08:05 | |
*** salv-orl_ has quit IRC | 08:06 | |
*** winterIsLeaving has quit IRC | 08:27 | |
*** liverpooler has joined #openstack-security | 08:35 | |
openstackgerrit | venkatamahesh proposed openstack/security-doc: Fix rst markups https://review.openstack.org/258846 | 08:47 |
openstackgerrit | venkatamahesh proposed openstack/security-doc: Fix rst markups https://review.openstack.org/258846 | 08:50 |
*** openstackgerrit has quit IRC | 09:17 | |
*** openstackgerrit has joined #openstack-security | 09:17 | |
*** salv-orlando has joined #openstack-security | 09:19 | |
*** salv-orlando has quit IRC | 09:51 | |
*** salv-orlando has joined #openstack-security | 09:57 | |
*** markvoelker has joined #openstack-security | 10:02 | |
*** markvoelker has quit IRC | 10:07 | |
*** salv-orlando has quit IRC | 10:10 | |
*** austin987 has quit IRC | 10:16 | |
*** austin987 has joined #openstack-security | 10:17 | |
*** salv-orlando has joined #openstack-security | 10:28 | |
*** salv-orlando has quit IRC | 10:28 | |
*** openstackgerrit has quit IRC | 11:17 | |
*** openstackgerrit has joined #openstack-security | 11:17 | |
*** salv-orl_ has joined #openstack-security | 11:49 | |
*** markvoelker has joined #openstack-security | 12:03 | |
*** Windir has quit IRC | 12:05 | |
*** markvoelker has quit IRC | 12:08 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/266326 | 12:16 |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/266326 | 12:27 |
*** d0ugal has quit IRC | 12:42 | |
*** d0ugal has joined #openstack-security | 12:43 | |
*** d0ugal is now known as Guest58385 | 12:43 | |
*** salv-orl_ has quit IRC | 12:43 | |
*** Guest58385 is now known as d0ugal | 12:45 | |
*** d0ugal has quit IRC | 12:45 | |
*** d0ugal has joined #openstack-security | 12:45 | |
*** markvoelker has joined #openstack-security | 13:04 | |
*** shakamunyi has joined #openstack-security | 13:04 | |
*** markvoelker has quit IRC | 13:15 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:31 | |
*** edmondsw has joined #openstack-security | 13:32 | |
*** markvoelker has joined #openstack-security | 13:35 | |
*** liverpooler has quit IRC | 13:38 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 13:40 | |
*** dslev has joined #openstack-security | 13:42 | |
*** browne has joined #openstack-security | 13:47 | |
*** browne has quit IRC | 13:52 | |
*** dslev has quit IRC | 14:02 | |
*** salv-orlando has joined #openstack-security | 14:11 | |
*** jhfeng has joined #openstack-security | 14:27 | |
*** dslev has joined #openstack-security | 14:39 | |
*** pdesai has joined #openstack-security | 14:39 | |
*** salv-orlando has quit IRC | 14:42 | |
*** dslev has quit IRC | 14:49 | |
*** jhfeng has quit IRC | 14:50 | |
*** salv-orlando has joined #openstack-security | 14:54 | |
*** liverpooler has joined #openstack-security | 14:54 | |
*** salv-orlando has quit IRC | 14:56 | |
*** salv-orlando has joined #openstack-security | 14:56 | |
*** hyakuhei has joined #openstack-security | 14:56 | |
*** dslev has joined #openstack-security | 14:58 | |
*** salv-orl_ has joined #openstack-security | 15:05 | |
*** salv-orlando has quit IRC | 15:05 | |
*** ninag has joined #openstack-security | 15:09 | |
*** salv-orl_ has quit IRC | 15:11 | |
*** hyakuhei has quit IRC | 15:14 | |
*** dave-mccowan has joined #openstack-security | 15:17 | |
*** hyakuhei has joined #openstack-security | 15:18 | |
*** dave-mcc_ has joined #openstack-security | 15:19 | |
*** dave-mccowan has quit IRC | 15:22 | |
*** Windir has joined #openstack-security | 15:26 | |
*** hyakuhei has quit IRC | 15:30 | |
*** hyakuhei has joined #openstack-security | 15:37 | |
*** jhfeng has joined #openstack-security | 15:40 | |
*** tmcpeak has joined #openstack-security | 15:44 | |
*** pdesai has quit IRC | 15:49 | |
*** hyakuhei has quit IRC | 15:51 | |
*** hyakuhei has joined #openstack-security | 15:56 | |
*** jhfeng has quit IRC | 15:58 | |
*** liverpooler has quit IRC | 16:00 | |
*** mvaldes has joined #openstack-security | 16:04 | |
dave-mcc_ | https://wiki.openstack.org/wiki/Security/Security_Note_Process | 16:04 |
*** jhfeng has joined #openstack-security | 16:14 | |
tmcpeak | https://docs.google.com/presentation/d/13GG47EdoQCBEGqMe7ji_UzfO9okMTLgbnK5_UpoaXYA/edit | 16:14 |
tmcpeak | https://docs.google.com/presentation/d/13GG47EdoQCBEGqMe7ji_UzfO9okMTLgbnK5_UpoaXYA/edit?usp=sharing | 16:15 |
mhayden | i'm taking a few notes on the bottom of https://etherpad.openstack.org/p/security-mitaka-midcycle | 16:15 |
mhayden | feel free to add | 16:15 |
elmiko | if michaelxin is handing out stickers, make sure to save one for me! | 16:15 |
*** jhfeng has quit IRC | 16:15 | |
mhayden | elmiko: haven't seen stickers, but he did bring in Dorito's | 16:16 |
elmiko | mhayden: nice, sounds like a good breakfast ;) | 16:17 |
elmiko | the security presentation deck is looking really nice btw, +1 | 16:18 |
*** sigmavirus24_awa is now known as sigmavirus24 | 16:18 | |
michaelxin | elmiko: send me your address at michael.xin@rackspace.com. I will mail you a couple of them next week. | 16:21 |
elmiko | michaelxin: ooh, nice! | 16:21 |
michaelxin | They delayed our orders, we have not got them yet. | 16:21 |
elmiko | ah, no worries. i just saw the logo again on the presentation deck and remembered how fond i am of it ;) | 16:21 |
michaelxin | Our order was delayed, I do not think that we will be able to get them on time. | 16:22 |
elmiko | that's ok, i can wait | 16:22 |
michaelxin | elmiko: we already miss you. | 16:22 |
elmiko | haha, /me blushes | 16:22 |
elmiko | i hope it's nice and warm there, we got several inches of snow =( | 16:23 |
michaelxin | For anyone who want stickers, please send me an email with your address and I will mail them to you once they are here. my email is michael.xin@rackspace.com. | 16:23 |
michaelxin | Yes, it will be 64 today. | 16:23 |
elmiko | ooh, nice | 16:23 |
michaelxin | sunny outside. | 16:24 |
mhayden | perhaps he can toss in a bag of chips along with the sticker | 16:24 |
elmiko | lol, nice! | 16:24 |
michaelxin | We can use google hangout, if you are intersted. | 16:24 |
elmiko | i don't want to bog things down, but i'll be here, just ping me if i can help | 16:25 |
*** jhfeng has joined #openstack-security | 16:27 | |
michaelxin | https://talkgadget.google.com/hangouts/_/gz43wqtwiit4lu7uupm55yd3oma | 16:27 |
michaelxin | For anyone is interested. | 16:27 |
michaelxin | feel free to join google hangout for mid-cycle meeting. | 16:28 |
*** jamielennox is now known as jamielennox|away | 16:37 | |
sigmavirus24 | tmcpeak: hyakuhei is the Anchor sticky going to include Anchor in DevStack? As a requests core, I'm interested in helping make sure this work will be easier with how ingrained requests is for servers and clients alike | 16:39 |
tmcpeak | sigmavirus24: I think so... | 16:40 |
sigmavirus24 | This also ties into https://github.com/kennethreitz/requests/issues/2966 | 16:41 |
elmiko | sigmavirus24: that seems like a good chunk of work, re: full cross-platform trust stores | 16:42 |
sigmavirus24 | elmiko: yeah it's terrifying at the same time | 16:42 |
sigmavirus24 | We moved away from that pre-1.0 because it was absolutely ridiculous to manage all the different distros' variants on where trust stores live | 16:43 |
sigmavirus24 | Also Windows is a gigantic pain in the neck (as you might understand from that thread) | 16:43 |
elmiko | yea, i can't imagine the compat. matrix for that work | 16:43 |
mhayden | michaelxin: you have a ton of tabs open :) | 16:43 |
sigmavirus24 | mhayden: not enough tabs | 16:43 |
elmiko | can't believe you put me on the projector... | 16:44 |
sigmavirus24 | elmiko: you're welcome | 16:44 |
*** hockeynut_afk is now known as hockeynut | 16:45 | |
*** browne has joined #openstack-security | 16:47 | |
*** austin987 has quit IRC | 16:48 | |
sigmavirus24 | elmiko: you're the cause of and solution to all of life's problems | 16:52 |
sigmavirus24 | elmiko: where are you again? | 16:52 |
elmiko | sigmavirus24: haha, i'm in detroit | 16:53 |
elmiko | (wel, just outside the city) | 16:53 |
sigmavirus24 | Got it | 16:53 |
sigmavirus24 | It was -8 when I left MSN | 16:53 |
elmiko | ooph, much colder than here | 16:54 |
sigmavirus24 | I'm the person in the redshirt with his back to you | 16:54 |
elmiko | i kinda figured =) | 16:54 |
*** pdesai has joined #openstack-security | 17:00 | |
*** dslev has quit IRC | 17:01 | |
*** salv-orlando has joined #openstack-security | 17:03 | |
*** austin987 has joined #openstack-security | 17:04 | |
*** bpokorny has joined #openstack-security | 17:10 | |
*** hyakuhei has quit IRC | 17:10 | |
elmiko | +1 for better threat analysis stuff, i still think there is value in creating some examples of this per-project | 17:12 |
*** jhfeng has quit IRC | 17:14 | |
*** hyakuhei has joined #openstack-security | 17:18 | |
elmiko | hyakuhei: has there been any talk of security related tags from the TC? | 17:23 |
hyakuhei | In what context? | 17:24 |
elmiko | listening to the discussion about increasing the visbility/involvement of ossp in various projects, i'm specifically wondering about tags like "bandit" or "syntribos" aware type tags. like "hey, this project is using bandit" | 17:25 |
elmiko | or, similar | 17:25 |
*** cjschaef has joined #openstack-security | 17:25 | |
hyakuhei | That’s interesting | 17:26 |
elmiko | right, "security-aware" or some such | 17:26 |
hyakuhei | So that’d be us pushing tags to the TC ? | 17:26 |
elmiko | i think so | 17:26 |
elmiko | we'd have to come up with some criteria and the propse it | 17:27 |
elmiko | s/the/then/ | 17:27 |
hyakuhei | Interesting | 17:27 |
elmiko | even just signalling that a project has full engagement with the ossp, i'm not sure on the granularity here. just spit-balling | 17:28 |
hyakuhei | Bandit tag seems to have some weight | 17:28 |
hyakuhei | Can you hear us on the mic elmiko ? | 17:28 |
elmiko | yes | 17:28 |
hyakuhei | excellent | 17:28 |
elmiko | i can just talk if it's easier | 17:29 |
elmiko | if we did start producing threat analysis material, we could even have a tag that would signal "hey this project has a threat analysis" | 17:30 |
elmiko | i'm trying to think about tags that would help operators or potential end-users select projects based on their security "features" | 17:30 |
hyakuhei | Yeah I like that idea | 17:31 |
hyakuhei | Speak up dude :) | 17:31 |
elmiko | so, like "voting-bandit-gate" "threat-analysis" etc | 17:31 |
elmiko | hyakuhei: +1, exactly! | 17:36 |
elmiko | "pen tested, ossp approved" ;) | 17:37 |
mvaldes | like Life cereal "elmiko likes it" | 17:40 |
elmiko | mvaldes: you get it ;) | 17:40 |
chair6 | "certified 100% no 0days" | 17:41 |
elmiko | hahaha | 17:43 |
elmiko | awesome, chair6++ | 17:44 |
elmiko | hyakuhei: a tag for indicate that a project has a chapter in the sec guide | 17:45 |
elmiko | a tag to indicate that a project has an ossp liaison | 17:46 |
tmcpeak | elmiko: is there a link to join that hangout? how did you get on | 17:50 |
hyakuhei | Lets add these to the etherpad | 17:50 |
hyakuhei | https://etherpad.openstack.org/p/security-mitaka-midcycle | 17:50 |
elmiko | tmcpeak: michaelxin shared it | 17:50 |
tmcpeak | michaelxin: ^ | 17:50 |
elmiko | tmcpeak: https://talkgadget.google.com/hangouts/_/gz43wqtwiit4lu7uupm55yd3oma | 17:50 |
tmcpeak | elmiko: than you | 17:51 |
hyakuhei | Added all the ones I can remember | 17:53 |
sigmavirus24 | elmiko: how do you pronounce your screenname? el-me-ko or el-my-ko? | 17:58 |
tmcpeak | ^ +1 | 18:03 |
elmiko | sigmavirus24: i take no authoritative stance on pronounciation ;) | 18:03 |
elmiko | it's open source | 18:04 |
*** dave-mcc_ has quit IRC | 18:04 | |
sigmavirus24 | elmiko: lol | 18:06 |
elmiko | tmcpeak: just let bandit tweet about all the things it finds >.< | 18:08 |
sigmavirus24 | Not sure if bandit wants to do that work itself | 18:08 |
tmcpeak | +1 and instagram | 18:08 |
sigmavirus24 | Or if we want the gate job to do that | 18:08 |
sigmavirus24 | tmcpeak: omg yes | 18:08 |
elmiko | haha, yes for instagram | 18:08 |
sigmavirus24 | tmcpeak: steganographic instagram pictures | 18:08 |
elmiko | haha | 18:08 |
elmiko | hyakuhei: teach a man to fish.... | 18:10 |
elmiko | crazy random idea, what about a pwn-to-own style compo for openstack? | 18:11 |
sigmavirus24 | https://hackerone.com/ for interested parties | 18:15 |
browne | +1 Slack bug bounty program uses hackerone | 18:15 |
elmiko | tmcpeak: what type of content you looking for? (re: blog posts) | 18:16 |
tmcpeak | anything about the work we do, things to improve security, summaries of current state, etc | 18:16 |
elmiko | ack, cool | 18:18 |
elmiko | i'm curious to get involved, might need to discuss a little more about what to write though | 18:18 |
tmcpeak | elmiko: cool, I think we're doing a separate bit on that now | 18:22 |
elmiko | k | 18:22 |
gmurphy | regarding bug bounties - openstack was mistakenly listed on bugcrowd and the only thing that ever happened was haxors reporting xss bugs in the openstack wiki | 18:26 |
gmurphy | it took a lot for us to get off that list | 18:26 |
elmiko | lol, ouch... | 18:26 |
gmurphy | it could be a cool idea though if done right. | 18:26 |
elmiko | so... is there a Hot Topic at the rackspace castle >.< | 18:28 |
elmiko | and does it actually look like an old mal inside? | 18:29 |
elmiko | *mall | 18:29 |
elmiko | bbl, getting some lunch | 18:32 |
*** ibravo has quit IRC | 18:43 | |
*** ibravo has joined #openstack-security | 18:43 | |
openstackgerrit | Doug Chivers proposed openstack/security-doc: Adding documentation for security threat analysis https://review.openstack.org/220712 | 18:46 |
*** bpokorny_ has joined #openstack-security | 19:00 | |
*** bpokorny has quit IRC | 19:04 | |
*** bpokorny_ has quit IRC | 19:15 | |
*** bpokorny has joined #openstack-security | 19:15 | |
*** salv-orlando has quit IRC | 19:17 | |
*** salv-orlando has joined #openstack-security | 19:18 | |
*** hyakuhei has quit IRC | 19:21 | |
*** yarkot has joined #openstack-security | 19:22 | |
*** hyakuhei has joined #openstack-security | 19:23 | |
*** yarkot has quit IRC | 19:25 | |
*** dave-mccowan has joined #openstack-security | 19:36 | |
openstackgerrit | Doug Chivers proposed openstack/security-doc: Adding documentation for security threat analysis https://review.openstack.org/220712 | 19:37 |
elmiko | hyakuhei: https://bugs.launchpad.net/openstack-manuals/+bugs?field.searchtext=&orderby=-importance&field.status%3Alist=NEW&field.status%3Alist=CONFIRMED&field.status%3Alist=TRIAGED&field.status%3Alist=INCOMPLETE_WITH_RESPONSE&field.status%3Alist=INCOMPLETE_WITHOUT_RESPONSE&assignee_option=none&field.assignee=&field.bug_reporter=&field.bug_commenter=&field.subscriber=&field.structural_subscriber=&field.tag=sec-guide+&field.tags_combina | 19:38 |
elmiko | whoa.. | 19:38 |
hyakuhei | lol | 19:38 |
elmiko | that's our open buglist | 19:38 |
*** jhfeng has joined #openstack-security | 19:38 | |
elmiko | er, link to | 19:38 |
elmiko | if any of those bugs look interesting to folks, we'd be happy to accept patches =) | 19:39 |
*** jhfeng has quit IRC | 19:39 | |
*** tkelsey has joined #openstack-security | 19:40 | |
tkelsey | o/ | 19:40 |
tkelsey | ping? | 19:41 |
*** sicarie has joined #openstack-security | 19:41 | |
hyakuhei | yo | 19:41 |
hyakuhei | https://bugs.launchpad.net/openstack-manuals/+bugs?field.searchtext=&orderby=-importance&field.status%3Alist=NEW&field.status%3Alist=CONFIRMED&field.status%3Alist=TRIAGED&field.status%3Alist=INCOMPLETE_WITH_RESPONSE&field.status%3Alist=INCOMPLETE_WITHOUT_RESPONSE&assignee_option=none&field.assignee=&field.bug_reporter=&field.bug_commenter=&field.subscriber=&field.structural_subscriber=&field.tag=sec-guide+&field.tags_combina | 19:41 |
*** jhfeng has joined #openstack-security | 19:43 | |
*** aheczko-mirantis has joined #openstack-security | 19:49 | |
*** aheczko-mirantis has quit IRC | 19:50 | |
* mhayden snags his first security guide bug https://bugs.launchpad.net/openstack-manuals/+bug/1459820 | 19:52 | |
openstack | Launchpad bug 1459820 in openstack-manuals "OpenStack Security Guide - Mandatory Access Control policy guidance" [Medium,Triaged] - Assigned to Major Hayden (rackerhacker) | 19:52 |
*** tkelsey has quit IRC | 19:53 | |
*** jhfeng has quit IRC | 19:53 | |
elmiko | mhayden: \o/ | 19:53 |
*** hyakuhei has quit IRC | 19:54 | |
mhayden | elmiko: i wonder if this bug could be closed... apparmor/selinux are discussed thoroughly in the guide already | 19:54 |
*** tkelsey has joined #openstack-security | 19:55 | |
*** aheczko-mirantis has joined #openstack-security | 19:58 | |
* elmiko takes another look | 20:00 | |
elmiko | sicarie: take a look at that one | 20:01 |
sigmavirus24 | elmiko: mhayden is in the room. You two can talk over video if you wanted to | 20:01 |
elmiko | it seems so peaceful in there though... | 20:02 |
sigmavirus24 | it is | 20:02 |
sigmavirus24 | silent hum of centrail hvac | 20:02 |
elmiko | everyone is slowing nodding off into the post lunch food coma | 20:02 |
sigmavirus24 | *central | 20:02 |
sigmavirus24 | not me | 20:02 |
mhayden | why talk when there's IRC | 20:03 |
sigmavirus24 | why talk when there's american sign language? | 20:04 |
elmiko | anyways, i think since sicarie opened that bug we should get his input | 20:04 |
elmiko | lol | 20:04 |
mvaldes | i'm looking at https://bugs.launchpad.net/openstack-manuals/+bug/1441229 | 20:13 |
openstack | Launchpad bug 1441229 in openstack-manuals "Chapter 7. Dashboard in OpenStack Security Guide - Add best practice around pw managers" [Medium,Confirmed] | 20:13 |
elmiko | mvaldes: great! | 20:13 |
mvaldes | the initial comments mention password mgmt, but someone else mentions password policy type stuff | 20:13 |
* elmiko looks at the bug | 20:14 | |
*** jhfeng has joined #openstack-security | 20:15 | |
elmiko | mvaldes: i think idealls we could have a small section on passwords with 2 subsections; password managment, and password quality | 20:15 |
elmiko | s/idealls/ideally/ | 20:15 |
mvaldes | i see | 20:15 |
elmiko | so, a paragraph or two discussing both. i think sicarie's original idea was to talk about using password managers to aid with the process of storing credentials for the dashboard, so something like keepassx | 20:16 |
elmiko | dannyh's comment about password strength is nice, and it might be worth adding a small note about that. policy is tricky as it might be superseeded by the guidelines of an openstack installer | 20:17 |
mvaldes | right. i thought keystone had some password policy capabilities | 20:17 |
elmiko | i'm not sure about that | 20:18 |
mvaldes | but could definitely be wrong | 20:18 |
mvaldes | it could make sense to include password quality in the identity authentication section | 20:19 |
elmiko | good idea | 20:19 |
elmiko | it's probably worth noting somewhere | 20:20 |
mvaldes | maybe it's the same info in both sections.. | 20:20 |
mvaldes | or a link from one to the other anyway | 20:20 |
elmiko | +1 for a link | 20:20 |
mvaldes | ok. i think i can handle this. the requirements seem pretty generic :) | 20:21 |
*** dslev has joined #openstack-security | 20:22 | |
elmiko | cool! | 20:22 |
*** jhfeng has quit IRC | 20:25 | |
*** dslev has quit IRC | 20:25 | |
sigmavirus24 | elmiko: where's your helmet? http://img1.wikia.nocookie.net/__cb20121008105956/lotr/images/e/ec/Gimli_-_FOTR.png | 20:35 |
elmiko | sigmavirus24: it's with my axe ;) | 20:37 |
sigmavirus24 | I thought when you got up just now you were either going to get your helmet or your axe | 20:37 |
elmiko | closest i have is this | 20:38 |
sigmavirus24 | A+ sir | 20:38 |
elmiko | am i still up on the projector? | 20:38 |
mvaldes | yum install hat | 20:38 |
sigmavirus24 | elmiko: how do you feel about selinux? | 20:38 |
sigmavirus24 | elmiko: you are | 20:38 |
elmiko | lol | 20:38 |
sigmavirus24 | elmiko: setenforce=0, right? | 20:38 |
elmiko | pretty much | 20:38 |
mhayden | y'all are going to make dwalsh cry, you know | 20:39 |
sigmavirus24 | who? | 20:39 |
elmiko | yea... i know, but it's downright impossible to run devstack without doing that | 20:39 |
*** salv-orlando has quit IRC | 20:39 | |
*** salv-orlando has joined #openstack-security | 20:40 | |
mhayden | sigmavirus24: http://stopdisablingselinux.com/ | 20:42 |
elmiko | lol, hadn't seen that before | 20:42 |
openstackgerrit | Major Hayden proposed openstack/security-doc: Adding link for SELinux policies https://review.openstack.org/266567 | 20:51 |
elmiko | mhayden: do you know if those fedora selinux policies are descended from a rhel or centos policy? | 20:54 |
mhayden | fedora ones are more modern | 20:54 |
mhayden | finding centos' upstream policies will be easier than RHT's | 20:55 |
elmiko | i'm only asking because i think centos, or rhel, are probably better end user targets for production openstack | 20:55 |
elmiko | right | 20:55 |
mhayden | my gut says they'll be somewhat similar, but i'll see what i can find centos-wise | 20:55 |
elmiko | awesome, thanks for checking it out. otherwise, the PR lgtm | 20:55 |
mvaldes | elmiko: this section references best practices from nist 800-118 http://docs.openstack.org/security-guide/identity/authentication-methods.html | 20:55 |
mvaldes | is it worth summarizing the high points for inclusion in the security guide? | 20:56 |
elmiko | mvaldes: great, that's probably the best advice we can pass on | 20:56 |
elmiko | mvaldes: no, i think a link to that would be good enough | 20:56 |
elmiko | hmm, if there isn't a link to the draft for 800-118, then it might be worth it to summarize, but i hate to create something that just needs to be updated as the nist docs are updated | 20:57 |
mvaldes | ok.. i can make it a link then :) piece of cake | 20:59 |
elmiko | thanks | 20:59 |
sicarie | elmiko and mvaldes: that looks pretty much like what I had been going for | 21:02 |
elmiko | sicarie: awesome =) | 21:02 |
sicarie | That bug was opened after a few articles on password managers (and after MOzilla had a bug where if you didnt' have the master set, it was trvial to access the pw store) | 21:03 |
elmiko | ah, interesting | 21:03 |
sicarie | So it was mainly intended to cover pw managers, but pw complexity should be addressed (though personally I'd say in a separate bug) | 21:03 |
mvaldes | sicarie: ah.. ok | 21:04 |
mvaldes | i was basically going to reference the specific chapter in the doc for each subsection | 21:05 |
sicarie | Yeah, I'd say go for it - we can always re-open a bug if clarity is needed | 21:06 |
sicarie | or create a new one | 21:06 |
*** dave-mccowan has quit IRC | 21:06 | |
elmiko | +1 | 21:07 |
*** dave-mccowan has joined #openstack-security | 21:07 | |
mvaldes | sounds good :) to be thorough, do we want a second but for the pw complexity? | 21:07 |
mvaldes | but = bug | 21:07 |
elmiko | i dunno, since dannyh references it in the bug discussion i don't mind including it now | 21:08 |
*** hyakuhei has joined #openstack-security | 21:08 | |
mvaldes | ok | 21:08 |
elmiko | sicarie: thoughts? | 21:08 |
*** jhfeng has joined #openstack-security | 21:10 | |
mhayden | slides link for osas -> https://docs.google.com/presentation/d/1OnMIIC8863eGftp1zvsHjlP-7LKhqz0ENwX-mIMSUU4/edit?usp=sharing | 21:10 |
*** sigmavirus24 is now known as sigmavirus24_awa | 21:12 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 21:13 | |
openstackgerrit | Eric Brown proposed openstack/security-doc: Add info about the VMware MKS console https://review.openstack.org/266576 | 21:17 |
openstackgerrit | Eric Brown proposed openstack/security-doc: Add info about the VMware MKS console https://review.openstack.org/266576 | 21:19 |
sicarie | elmiko: that seems more like a drive-by addition to me | 21:30 |
sicarie | I'm fine for including it - it should certainly be in Identity somewhere | 21:30 |
sicarie | but I'd like to maintain bug scope | 21:30 |
elmiko | sicarie: fair, i'm ok with including or leaving it out if you want more resolution on the bugs | 21:30 |
sicarie | not only does it look better on stackalytics, but really it's making sure that we don't just keep increasing workload on stuff that should be relativley minor | 21:31 |
sicarie | but really, it's my stackalytics profile i'm going for :) | 21:31 |
elmiko | hehe, but yeah, i agree | 21:32 |
sicarie | I figure if we get in the habit, then we can consistently ensure that we don't have someone new come in, pick up a bug, and suddenly get waylaid with extra sections that may/may not be over their head | 21:34 |
elmiko | yup, makes good sense | 21:34 |
mvaldes | +1 | 21:36 |
*** avarner has joined #openstack-security | 21:37 | |
*** avarner_ has joined #openstack-security | 21:37 | |
*** salv-orlando has quit IRC | 21:43 | |
*** salv-orlando has joined #openstack-security | 21:44 | |
mhayden | https://infrastructure.fedoraproject.org/cgit/ansible.git/tree/callback_plugins/fedmsg_callback.py | 21:58 |
elmiko | mhayden: thanks, that was very cool | 22:01 |
* elmiko is still an ansible noob, but wants to know more | 22:01 | |
michaelxin | elmiko: you can do it! | 22:02 |
mhayden | elmiko: thanks sir :) | 22:02 |
elmiko | michaelxin: yea, i need to find some time... ;) | 22:02 |
elmiko | mhayden: you mentioned that this was host oriented and that you wanted to do some server-based work. would that be ansible scripts to secure server installs? (i couldn't quite hear the audio) | 22:03 |
mhayden | ah, the role's goal is secure physical hosts | 22:04 |
mhayden | or virtual machines | 22:04 |
mhayden | it doesn't touch openstack services | 22:04 |
elmiko | ah, ok | 22:04 |
mhayden | so it configures things like auditd/nfs/sshd and such | 22:04 |
mhayden | but not nova/cinder/swift | 22:05 |
elmiko | right | 22:05 |
mhayden | but those changes were done carefully to ensure that a production openstack environment won't be affected | 22:05 |
mhayden | if the role does affect openstack environments, then you've found a bug :) | 22:05 |
elmiko | cool | 22:05 |
elmiko | michaelxin: i gotta drop, hopefully we can do this again tomorrow! | 22:06 |
elmiko | mhayden: thanks again for the extended explanation | 22:06 |
michaelxin | elmiko: sure | 22:09 |
*** salv-orl_ has joined #openstack-security | 22:09 | |
*** salv-orlando has quit IRC | 22:12 | |
mhayden | ah, so this works for getting data from ansible into a readable file: https://infrastructure.fedoraproject.org/cgit/ansible.git/plain/callback_plugins/logdetail.py | 22:15 |
mhayden | w/json | 22:15 |
mhayden | example -> http://paste.openstack.org/raw/483669/ | 22:16 |
mhayden | you could use readlines() on that fairly easily... break on tabs | 22:16 |
*** jamielennox|away is now known as jamielennox | 22:17 | |
michaelxin | mhayden: Thanks for sharing. | 22:18 |
mhayden | michaelxin: apparently that code is GPL'd | 22:21 |
* mhayden flips a table | 22:21 | |
michaelxin | haha | 22:21 |
*** pdesai has quit IRC | 22:25 | |
*** hyakuhei has quit IRC | 22:34 | |
*** hyakuhei has joined #openstack-security | 22:35 | |
*** austin987 has quit IRC | 22:44 | |
*** austin987 has joined #openstack-security | 22:44 | |
*** jhfeng has quit IRC | 22:52 | |
*** avarner has quit IRC | 22:55 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 23:01 | |
*** dave-mccowan has quit IRC | 23:15 | |
*** cjschaef has quit IRC | 23:17 | |
*** cjschaef has joined #openstack-security | 23:17 | |
*** aheczko-mirantis has quit IRC | 23:22 | |
*** winterIsLeaving has joined #openstack-security | 23:23 | |
*** cjschaef has quit IRC | 23:25 | |
*** hyakuhei has quit IRC | 23:27 | |
*** hyakuhei has joined #openstack-security | 23:29 | |
*** hyakuhei has quit IRC | 23:29 | |
*** browne has quit IRC | 23:29 | |
*** tkelsey has quit IRC | 23:33 | |
*** mvaldes has quit IRC | 23:33 | |
*** tmcpeak has quit IRC | 23:34 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 23:38 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 23:47 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 23:48 | |
*** ninag has quit IRC | 23:50 | |
*** ninag has joined #openstack-security | 23:51 | |
*** bpokorny_ has joined #openstack-security | 23:55 | |
*** bpokorny has quit IRC | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!