*** tmcpeak has quit IRC | 00:02 | |
*** tmcpeak has joined #openstack-security | 00:02 | |
*** jamielennox is now known as jamielennox|away | 00:10 | |
*** zul__ has joined #openstack-security | 00:13 | |
*** zul_ has quit IRC | 00:15 | |
*** salv-orlando has quit IRC | 00:25 | |
*** diazjf1 has quit IRC | 00:34 | |
*** browne has quit IRC | 00:50 | |
*** browne has joined #openstack-security | 00:52 | |
openstackgerrit | KATO Tomoyuki proposed openstack/security-doc: Change SSL to TLS at checklist https://review.openstack.org/264707 | 01:11 |
---|---|---|
*** browne has quit IRC | 01:20 | |
*** hyakuhei has joined #openstack-security | 01:24 | |
*** browne has joined #openstack-security | 01:28 | |
*** avarner_ has quit IRC | 01:30 | |
*** ccneill has quit IRC | 01:32 | |
*** jamielennox|away is now known as jamielennox | 01:34 | |
*** bpokorny has quit IRC | 01:47 | |
*** hyakuhei has quit IRC | 01:52 | |
*** edmondsw has quit IRC | 01:57 | |
*** shakamunyi has joined #openstack-security | 01:58 | |
*** shakamunyi has quit IRC | 02:12 | |
*** shakamunyi has joined #openstack-security | 02:31 | |
*** browne has quit IRC | 02:33 | |
*** jhfeng has joined #openstack-security | 02:42 | |
*** diazjf has joined #openstack-security | 02:48 | |
*** salv-orlando has joined #openstack-security | 02:53 | |
*** dave-mccowan has quit IRC | 02:54 | |
*** salv-orlando has quit IRC | 02:55 | |
*** hyakuhei has joined #openstack-security | 02:57 | |
*** jhfeng has quit IRC | 03:00 | |
*** diazjf has quit IRC | 03:01 | |
*** hyakuhei has quit IRC | 03:20 | |
*** jhfeng has joined #openstack-security | 03:26 | |
*** hyakuhei has joined #openstack-security | 03:33 | |
*** dave-mccowan has joined #openstack-security | 03:35 | |
*** browne has joined #openstack-security | 03:45 | |
*** jhfeng has quit IRC | 03:49 | |
*** hyakuhei has quit IRC | 04:19 | |
*** hyakuhei has joined #openstack-security | 04:21 | |
*** dave-mccowan has quit IRC | 04:28 | |
*** jhfeng has joined #openstack-security | 04:35 | |
*** salv-orlando has joined #openstack-security | 04:37 | |
*** salv-orlando has quit IRC | 04:42 | |
*** browne has quit IRC | 05:08 | |
*** jhfeng has quit IRC | 05:08 | |
*** browne has joined #openstack-security | 05:08 | |
*** hockeynut has quit IRC | 05:10 | |
*** hockeynut has joined #openstack-security | 05:12 | |
*** winterIsLeaving has quit IRC | 05:29 | |
openstackgerrit | Merged openstack/security-doc: Change SSL to TLS at checklist https://review.openstack.org/264707 | 05:48 |
*** salv-orlando has joined #openstack-security | 05:54 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/anchor: Add the PKCS11-based signing backend https://review.openstack.org/277765 | 05:56 |
*** salv-orlando has quit IRC | 05:56 | |
openstackgerrit | Vikram Hosakote proposed openstack/security-doc: Security guide implicitly suggests that DHCP agent is mandatory https://review.openstack.org/279388 | 06:15 |
*** hyakuhei has quit IRC | 06:54 | |
*** salv-orlando has joined #openstack-security | 07:12 | |
openstackgerrit | KATO Tomoyuki proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/279069 | 07:22 |
*** salv-orlando has quit IRC | 07:23 | |
*** austin987 has quit IRC | 07:26 | |
*** lmiccini|away is now known as lmiccini | 07:27 | |
*** austin987 has joined #openstack-security | 07:27 | |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/279069 | 07:37 |
*** Vivek has quit IRC | 07:51 | |
*** Vivek has joined #openstack-security | 08:02 | |
*** shohel has joined #openstack-security | 08:05 | |
*** shohel has quit IRC | 08:06 | |
*** salv-orlando has joined #openstack-security | 08:28 | |
*** salv-orlando has quit IRC | 08:35 | |
*** browne has quit IRC | 08:44 | |
*** ig0r_ has quit IRC | 08:45 | |
*** salv-orlando has joined #openstack-security | 09:05 | |
*** tmcpeak has quit IRC | 09:08 | |
*** salv-orlando has quit IRC | 09:52 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: old blacklist imports refered to 'qualnames' as 'imports' https://review.openstack.org/279443 | 09:53 |
openstackgerrit | Tim Kelsey proposed openstack/bandit: old blacklist imports refered to 'qualnames' as 'imports' https://review.openstack.org/279443 | 09:54 |
*** salv-orlando has joined #openstack-security | 10:03 | |
*** ig0r_ has joined #openstack-security | 10:13 | |
openstackgerrit | Merged openstack/bandit: Add test to compare help output with readme https://review.openstack.org/278918 | 10:15 |
*** openstackgerrit has quit IRC | 10:32 | |
*** openstackgerrit has joined #openstack-security | 10:32 | |
*** salv-orl_ has joined #openstack-security | 10:41 | |
*** salv-orlando has quit IRC | 10:45 | |
*** ig0r_ has quit IRC | 11:48 | |
*** ig0r_ has joined #openstack-security | 11:49 | |
*** dave-mccowan has joined #openstack-security | 12:08 | |
*** edmondsw has joined #openstack-security | 12:40 | |
*** salv-orl_ has quit IRC | 12:58 | |
*** ninag has joined #openstack-security | 13:40 | |
*** edmondsw has quit IRC | 13:53 | |
*** edmondsw has joined #openstack-security | 13:54 | |
*** hyakuhei has joined #openstack-security | 14:07 | |
*** salv-orlando has joined #openstack-security | 14:13 | |
*** localloop127 has joined #openstack-security | 14:20 | |
*** mvaldes has joined #openstack-security | 14:26 | |
openstackgerrit | Merged openstack/security-doc: Security guide implicitly suggests that DHCP agent is mandatory https://review.openstack.org/279388 | 14:34 |
*** jmckind has joined #openstack-security | 14:39 | |
*** jmckind_ has joined #openstack-security | 14:40 | |
*** cjschaef has joined #openstack-security | 14:41 | |
*** jmckind has quit IRC | 14:44 | |
*** austin987 has quit IRC | 14:47 | |
*** dave-mccowan has quit IRC | 15:01 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Adding docs for new style blacklist imports https://review.openstack.org/279580 | 15:03 |
*** edtubill has joined #openstack-security | 15:04 | |
*** jhfeng has joined #openstack-security | 15:15 | |
*** dave-mccowan has joined #openstack-security | 15:17 | |
*** rtmorgan has quit IRC | 15:26 | |
*** rtmorgan has joined #openstack-security | 15:26 | |
*** nkinder has joined #openstack-security | 15:28 | |
*** avarner_ has joined #openstack-security | 15:29 | |
*** tmcpeak has joined #openstack-security | 15:31 | |
openstackgerrit | Tim Kelsey proposed openstack/bandit: Adding docs for new style blacklist imports https://review.openstack.org/279580 | 15:44 |
openstackgerrit | Devon Boatwright proposed openstack/security-doc: Updated outdated link in Introduction https://review.openstack.org/279612 | 15:44 |
*** austin987 has joined #openstack-security | 15:45 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 15:48 | |
*** avarner has joined #openstack-security | 15:49 | |
*** avarner_ has quit IRC | 15:53 | |
*** jmckind has joined #openstack-security | 15:55 | |
*** jmckind__ has joined #openstack-security | 15:57 | |
*** jmckind_ has quit IRC | 15:59 | |
*** salv-orlando has quit IRC | 16:01 | |
*** jmckind has quit IRC | 16:01 | |
*** localloo1 has joined #openstack-security | 16:02 | |
*** localloop127 has quit IRC | 16:05 | |
*** localloop127 has joined #openstack-security | 16:06 | |
*** avarner_ has joined #openstack-security | 16:07 | |
*** avarner has quit IRC | 16:07 | |
*** localloo1 has quit IRC | 16:07 | |
openstackgerrit | Merged openstack/bandit: old blacklist imports refered to 'qualnames' as 'imports' https://review.openstack.org/279443 | 16:16 |
*** ig0r_ has quit IRC | 16:20 | |
*** avarner has joined #openstack-security | 16:20 | |
*** avarner_ has quit IRC | 16:21 | |
*** bpokorny has joined #openstack-security | 16:21 | |
openstackgerrit | Henry Yamauchi proposed openstack/syntribos: Check if user A can access user B's resource https://review.openstack.org/278764 | 16:22 |
*** rtmorgan has quit IRC | 16:32 | |
*** rtmorgan has joined #openstack-security | 16:33 | |
*** browne has joined #openstack-security | 16:36 | |
*** localloop127 has quit IRC | 16:40 | |
*** ccneill has joined #openstack-security | 16:40 | |
*** localloop127 has joined #openstack-security | 16:41 | |
*** ccneill_ has joined #openstack-security | 16:47 | |
*** localloop127 has quit IRC | 16:49 | |
*** ccneill has quit IRC | 16:50 | |
*** localloop127 has joined #openstack-security | 16:51 | |
*** avarner has quit IRC | 17:09 | |
*** localloop127 has quit IRC | 17:09 | |
*** avarner_ has joined #openstack-security | 17:09 | |
*** localloop127 has joined #openstack-security | 17:10 | |
*** ccneill_ has quit IRC | 17:14 | |
*** openstackgerrit has quit IRC | 17:17 | |
*** openstackgerrit has joined #openstack-security | 17:17 | |
*** browne has quit IRC | 17:20 | |
*** browne has joined #openstack-security | 17:59 | |
*** salv-orlando has joined #openstack-security | 18:16 | |
*** hyakuhei has quit IRC | 18:19 | |
*** hyakuhei has joined #openstack-security | 18:21 | |
*** openstack has joined #openstack-security | 18:25 | |
*** winterIsLeaving has joined #openstack-security | 18:30 | |
*** mvaldes has quit IRC | 18:43 | |
browne | tmcpeak: ping? | 18:46 |
tmcpeak | browne: yo, what's up | 18:46 |
*** openstackgerrit has quit IRC | 18:47 | |
*** openstackgerrit has joined #openstack-security | 18:47 | |
browne | so looking at httplib recently. seems newer versions of python do do cert verify and hostname validation | 18:47 |
browne | https://www.python.org/dev/peps/pep-0476/ | 18:47 |
browne | so i'm wondering how i should change bandit to handle this case where it varies by python version | 18:48 |
tmcpeak | hmm | 18:48 |
tmcpeak | so add python version checking into the plugin? | 18:49 |
tmcpeak | maybe we should just lower the severity and change the message to say "it depends on your python interpreter version" | 18:49 |
browne | i could, but the python version scanned by bandit is not necessarily the same what the operators run openstack on | 18:49 |
tmcpeak | just because somebody is running with a certain version of python doesn't mean they will in production, etc | 18:49 |
tmcpeak | yeah | 18:49 |
browne | yeah, i'm leaning the "lower the severity" way too | 18:50 |
tmcpeak | actually it would probably be lower confidence | 18:50 |
tmcpeak | technically | 18:50 |
tmcpeak | hmm | 18:50 |
tmcpeak | well | 18:50 |
tmcpeak | that's gray area | 18:50 |
browne | yeah, i think lower confidence, but not sure blacklist can do lower | 18:50 |
tmcpeak | we're sure we found something but not sure if it's an issue for you | 18:50 |
tmcpeak | you're right, I don't think we do have lower confidence in blacklist | 18:51 |
tmcpeak | severity works | 18:51 |
browne | maybe just an update to the issue text | 18:51 |
tmcpeak | what is it, currently high? | 18:51 |
browne | i think all blacklist are fixed to high confidence. not sure what default severity is | 18:52 |
browne | let me check | 18:52 |
tmcpeak | cool | 18:52 |
tmcpeak | I'm pulling out my hair on unicode | 18:52 |
tmcpeak | run Bandit against this file in Keystone: | 18:52 |
browne | ha, yeah | 18:52 |
browne | unicode and py27 vs py34 must be fun | 18:52 |
tmcpeak | keystone/keystone/tests/unit/test_backend_ldap.py | 18:52 |
tmcpeak | for a good time | 18:52 |
browne | ha, i'll try it later. just tell bknudson to remove the file | 18:53 |
tmcpeak | the question is what's the best way to handle it, we obviously need to get it encoded safely somewhere, I'm leaning towards upstream (in the code) as much as possible | 18:53 |
tmcpeak | yeah, or that | 18:53 |
tmcpeak | bknudson_: can we plz just not do unicode anymore? | 18:53 |
tmcpeak | I should write a pep for that | 18:54 |
tmcpeak | no unicode | 18:54 |
browne | default severity of a blacklist issue is medium | 18:56 |
browne | confidence is fixed at high | 18:56 |
*** localloo1 has joined #openstack-security | 18:58 | |
tmcpeak | ok | 18:59 |
tmcpeak | change message is fine | 18:59 |
*** localloop127 has quit IRC | 19:01 | |
*** localloo1 has quit IRC | 19:02 | |
*** localloo1 has joined #openstack-security | 19:04 | |
*** mvaldes has joined #openstack-security | 19:13 | |
*** localloop127 has joined #openstack-security | 19:17 | |
*** localloo1 has quit IRC | 19:19 | |
*** bpokorny_ has joined #openstack-security | 19:27 | |
*** bpokorny_ has quit IRC | 19:29 | |
*** bpokorny_ has joined #openstack-security | 19:30 | |
*** bpokorny has quit IRC | 19:31 | |
*** mvaldes has quit IRC | 19:33 | |
*** mvaldes has joined #openstack-security | 19:45 | |
*** edmondsw has quit IRC | 19:46 | |
*** bpokorny_ has quit IRC | 19:46 | |
*** bpokorny has joined #openstack-security | 19:47 | |
*** bpokorny has quit IRC | 19:50 | |
*** bpokorny has joined #openstack-security | 19:51 | |
*** winterIsLeaving is now known as winterIsBees | 19:51 | |
*** winterIsBees is now known as winterIsLeaving | 19:51 | |
*** bpokorny has quit IRC | 19:52 | |
*** browne has quit IRC | 19:52 | |
*** bpokorny has joined #openstack-security | 19:53 | |
*** ccneill_ has joined #openstack-security | 20:02 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Fixing bug with output chars in formatters https://review.openstack.org/279767 | 20:14 |
*** KriSstaL has joined #openstack-security | 20:16 | |
KriSstaL | hola | 20:18 |
tmcpeak | plz | 20:18 |
KriSstaL | ??? | 20:19 |
*** ccneill_ has quit IRC | 20:19 | |
tmcpeak | please do not hola me | 20:20 |
tmcpeak | elmiko likes holas | 20:20 |
*** localloop127 has quit IRC | 20:20 | |
KriSstaL | no hablo imgles | 20:21 |
KriSstaL | ingles | 20:21 |
tmcpeak | me neither | 20:21 |
elmiko | yo hablo imgles | 20:21 |
elmiko | =D | 20:21 |
KriSstaL | en serio? | 20:21 |
*** edmondsw has joined #openstack-security | 20:21 | |
elmiko | is that like "fo'rizzle" ? | 20:21 |
tmcpeak | loool | 20:22 |
KriSstaL | jajaajja esta bien | 20:22 |
tmcpeak | :@ | 20:22 |
KriSstaL | mmm cuantos aƱos tienen? | 20:23 |
elmiko | no hablo :/ | 20:23 |
KriSstaL | :-( | 20:23 |
tmcpeak | aproximadamente seis | 20:24 |
KriSstaL | -.- si claro! | 20:24 |
tmcpeak | no hablo | 20:24 |
KriSstaL | JODANC entoncs | 20:25 |
elmiko | i'm so lost | 20:26 |
tmcpeak | sigmavirus24, chair6: got time to check this out? | 20:26 |
tmcpeak | https://review.openstack.org/279767 | 20:26 |
openstackgerrit | Travis McPeak proposed openstack/bandit: Adding JSON output for baseline results https://review.openstack.org/278794 | 20:28 |
tmcpeak | sigmavirus24, chair6: annnndd this: https://review.openstack.org/278794 | 20:28 |
*** localloop127 has joined #openstack-security | 20:30 | |
*** KriSstaL has left #openstack-security | 20:30 | |
sigmavirus24 | tmcpeak: you told them you were six years old? | 20:34 |
tmcpeak | yeah man | 20:34 |
tmcpeak | they didn't believe me though | 20:34 |
sigmavirus24 | 6 year olds don't like security | 20:34 |
tmcpeak | I'm sure some do | 20:34 |
sigmavirus24 | That's going to be one disappointed kid | 20:34 |
tmcpeak | the real go-getters | 20:34 |
sigmavirus24 | What adult would let their kid get into security? | 20:35 |
tmcpeak | 6 year olds don't like openstack though | 20:35 |
tmcpeak | that's for sure | 20:35 |
tmcpeak | good point | 20:35 |
sigmavirus24 | That kid's going to have such a bad time | 20:35 |
tmcpeak | lol, it is kind of dream crushing work, isn't it | 20:35 |
elmiko | this conversation rules | 20:36 |
tmcpeak | "oh look, I made a mistake, live and learn?" nope, totally owned | 20:36 |
*** ccneill_ has joined #openstack-security | 20:44 | |
*** dave-mccowan has quit IRC | 20:48 | |
openstackgerrit | Travis McPeak proposed openstack/bandit: Adding JSON output for baseline results https://review.openstack.org/278794 | 21:02 |
*** salv-orlando has quit IRC | 21:03 | |
*** hyakuhei has quit IRC | 21:05 | |
*** ccneill__ has joined #openstack-security | 21:06 | |
*** ccneill_ has quit IRC | 21:08 | |
*** hyakuhei has joined #openstack-security | 21:15 | |
tmcpeak | sigmavirus24: I don't know why I'm going to pick on you here, but you know things | 21:15 |
tmcpeak | what's the deal with this: https://review.openstack.org/#/c/279767/2 | 21:15 |
tmcpeak | like why is Zuul not giving me status on the review | 21:15 |
tmcpeak | why did that fail, etc | 21:16 |
tmcpeak | tox -e linters definitely passes locally for me | 21:16 |
tmcpeak | I'll go ask in infra | 21:18 |
sigmavirus24 | sorry tmcpeak | 21:19 |
sigmavirus24 | looking now | 21:19 |
tmcpeak | sigmavirus24: awesome, thank you | 21:19 |
sigmavirus24 | tmcpeak: http://logs.openstack.org/67/279767/2/check/gate-bandit-pep8/fe63feb/ says it can't find bandit-baseline | 21:19 |
sigmavirus24 | tmcpeak: looking at http://logs.openstack.org/67/279767/2/check/gate-bandit-pep8/fe63feb/console.html#_2016-02-12_21_06_50_128 I don't see bandit | 21:22 |
sigmavirus24 | Did we change the tox.ini recently and not include bandit in it? | 21:22 |
sigmavirus24 | oh tmcpeak | 21:22 |
sigmavirus24 | look at the difference between linters and pep8: https://github.com/openstack/bandit/blob/master/tox.ini#L26 | 21:22 |
sigmavirus24 | we say "usedevelop = False" which won't auto install the project for us | 21:23 |
sigmavirus24 | So we need to add to the dependencies | 21:23 |
sigmavirus24 | one sec tmcpeak | 21:23 |
tmcpeak | sigmavirus24: awesome, I thought you'd be a good person to check with :D | 21:23 |
*** winterIsLeaving has quit IRC | 21:24 | |
openstackgerrit | Ian Cordasco proposed openstack/bandit: Add bandit to pep8 dependencies https://review.openstack.org/279801 | 21:24 |
sigmavirus24 | tmcpeak: ^ | 21:25 |
sigmavirus24 | Sorry that I wasn't paying attention to irc | 21:25 |
* sigmavirus24 goes back to not paying attention to IRC :P | 21:25 | |
tmcpeak | sigmavirus24: awesome, thank you | 21:25 |
sigmavirus24 | quite welcome | 21:26 |
*** jhfeng has quit IRC | 21:38 | |
*** jhfeng has joined #openstack-security | 21:38 | |
tmcpeak | sigmavirus24: looks a little wonky | 21:39 |
tmcpeak | it literally failed all the things | 21:39 |
*** hyakuhei has quit IRC | 21:43 | |
*** austin987 has quit IRC | 21:47 | |
*** hyakuhei has joined #openstack-security | 21:56 | |
sigmavirus24 | oh shit | 22:01 |
sigmavirus24 | I've seen this bug before | 22:01 |
sigmavirus24 | tmcpeak: that's a tox bug | 22:02 |
sigmavirus24 | one second | 22:02 |
tmcpeak | really? | 22:02 |
tmcpeak | sigmavirus24: I'm VERY glad you know about this stuf | 22:02 |
tmcpeak | f | 22:02 |
tmcpeak | I have NFI what I'm doing on that | 22:02 |
sigmavirus24 | So | 22:02 |
sigmavirus24 | tox is magic | 22:02 |
tmcpeak | thought so | 22:02 |
tmcpeak | always felt like a special little butterfly to me | 22:03 |
openstackgerrit | Ian Cordasco proposed openstack/bandit: Add bandit to pep8 dependencies https://review.openstack.org/279801 | 22:03 |
sigmavirus24 | ^ should work | 22:03 |
*** austin987 has joined #openstack-security | 22:03 | |
tmcpeak | cool, if it passes I'll just +A since you know what you're doing and I do not | 22:03 |
*** cjschaef has quit IRC | 22:04 | |
*** cjschaef has joined #openstack-security | 22:04 | |
*** browne has joined #openstack-security | 22:06 | |
*** austin987 has quit IRC | 22:13 | |
*** localloop127 has quit IRC | 22:16 | |
*** cjschaef has quit IRC | 22:20 | |
*** ccneill__ is now known as ccneill | 22:24 | |
*** hyakuhei has quit IRC | 22:27 | |
*** hyakuhei has joined #openstack-security | 22:30 | |
z | bknudson_ dg__: keeping LDAP separate from Keystone in things like Killick is appreciated, there are definitely environments where those tools are useful which do not have Keystone. | 22:34 |
*** hyakuhei has quit IRC | 22:41 | |
*** hyakuhei has joined #openstack-security | 22:43 | |
*** edmondsw has quit IRC | 22:43 | |
*** hyakuhei has quit IRC | 22:48 | |
*** jhfeng has quit IRC | 22:55 | |
*** mvaldes has quit IRC | 23:09 | |
*** hyakuhei has joined #openstack-security | 23:12 | |
*** jmckind__ has quit IRC | 23:12 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 23:22 | |
*** ccneill has quit IRC | 23:27 | |
*** hyakuhei has quit IRC | 23:32 | |
*** markvoelker has quit IRC | 23:41 | |
*** salv-orlando has joined #openstack-security | 23:44 | |
*** salv-orlando has quit IRC | 23:53 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!