*** austin987 has quit IRC | 00:00 | |
*** sdake_ has joined #openstack-security | 00:00 | |
*** sdake has quit IRC | 00:02 | |
*** austin987 has joined #openstack-security | 00:13 | |
*** browne has quit IRC | 00:19 | |
*** markvoelker has joined #openstack-security | 00:29 | |
*** tkelsey has joined #openstack-security | 00:30 | |
*** bpokorny has quit IRC | 00:31 | |
*** tkelsey has quit IRC | 00:35 | |
*** markvoelker has quit IRC | 00:36 | |
*** mdong has joined #openstack-security | 00:36 | |
*** browne has joined #openstack-security | 00:46 | |
*** browne has quit IRC | 00:46 | |
*** diazjf has joined #openstack-security | 00:58 | |
*** diazjf1 has joined #openstack-security | 01:02 | |
*** diazjf has quit IRC | 01:04 | |
*** mdong_ has joined #openstack-security | 01:34 | |
*** diazjf1 has quit IRC | 01:34 | |
*** mdong has quit IRC | 01:37 | |
*** mdong_ is now known as mdong | 01:37 | |
*** vinaypotluri has quit IRC | 01:40 | |
*** sdake has joined #openstack-security | 01:45 | |
*** tmcpeak has quit IRC | 01:47 | |
*** sdake_ has quit IRC | 01:48 | |
*** bpokorny has joined #openstack-security | 02:06 | |
*** bpokorny_ has joined #openstack-security | 02:08 | |
*** nkinder has quit IRC | 02:08 | |
*** bpokorny has quit IRC | 02:11 | |
*** bpokorny_ has quit IRC | 02:12 | |
*** tmcpeak has joined #openstack-security | 02:20 | |
*** tmcpeak1 has joined #openstack-security | 02:22 | |
*** tmcpeak1 has quit IRC | 02:23 | |
*** ccneill has quit IRC | 02:23 | |
*** tmcpeak1 has joined #openstack-security | 02:24 | |
*** tmcpeak has quit IRC | 02:25 | |
*** sdake_ has joined #openstack-security | 02:26 | |
*** sdake has quit IRC | 02:28 | |
*** openstackgerrit has quit IRC | 02:36 | |
*** hockeynut has quit IRC | 02:36 | |
*** hockeynut has joined #openstack-security | 02:37 | |
*** openstackgerrit has joined #openstack-security | 02:42 | |
*** yuanying has quit IRC | 02:50 | |
*** openstackgerrit has quit IRC | 02:56 | |
*** jamielennox is now known as jamielennox|away | 03:01 | |
*** hockeynut has quit IRC | 03:04 | |
*** sdake has joined #openstack-security | 03:07 | |
*** hockeynut has joined #openstack-security | 03:08 | |
*** sdake_ has quit IRC | 03:11 | |
*** openstackgerrit has joined #openstack-security | 03:18 | |
*** dave-mccowan has quit IRC | 03:22 | |
*** mdong has quit IRC | 03:35 | |
*** bpokorny has joined #openstack-security | 03:41 | |
*** yuanying has joined #openstack-security | 03:48 | |
*** tmcpeak1 has quit IRC | 03:51 | |
*** diazjf has joined #openstack-security | 04:05 | |
*** diazjf has quit IRC | 04:05 | |
*** sdake_ has joined #openstack-security | 04:25 | |
*** edtubill has joined #openstack-security | 04:26 | |
*** edtubill has quit IRC | 04:27 | |
*** sdake has quit IRC | 04:27 | |
*** sdake has joined #openstack-security | 04:31 | |
*** tkelsey has joined #openstack-security | 04:32 | |
*** markvoelker has joined #openstack-security | 04:32 | |
*** sdake_ has quit IRC | 04:33 | |
*** tkelsey has quit IRC | 04:36 | |
*** markvoelker has quit IRC | 04:37 | |
*** bpokorny has quit IRC | 04:44 | |
*** salv-orlando has joined #openstack-security | 05:33 | |
*** sdake_ has joined #openstack-security | 05:53 | |
*** sdake_ has quit IRC | 05:53 | |
*** sdake_ has joined #openstack-security | 05:53 | |
*** sdake has quit IRC | 05:56 | |
*** sdake_ has quit IRC | 05:59 | |
*** rcernin has joined #openstack-security | 06:05 | |
*** rcernin has quit IRC | 06:15 | |
*** rcernin has joined #openstack-security | 06:20 | |
*** salv-orlando has quit IRC | 06:24 | |
*** markvoelker has joined #openstack-security | 06:33 | |
*** tkelsey has joined #openstack-security | 06:34 | |
*** markvoelker has quit IRC | 06:38 | |
*** tkelsey has quit IRC | 06:39 | |
*** B_Smith has quit IRC | 07:00 | |
*** B_Smith has joined #openstack-security | 07:15 | |
*** tesseract has joined #openstack-security | 07:36 | |
*** salv-orlando has joined #openstack-security | 07:50 | |
*** lhinds has joined #openstack-security | 08:11 | |
*** lhinds has quit IRC | 08:30 | |
*** lhinds has joined #openstack-security | 08:36 | |
*** tkelsey has joined #openstack-security | 08:42 | |
*** dmk0202 has joined #openstack-security | 08:46 | |
*** yuanying has quit IRC | 08:47 | |
*** lhinds has quit IRC | 08:48 | |
*** yuanying has joined #openstack-security | 08:53 | |
*** yuanying has quit IRC | 08:54 | |
*** lhinds has joined #openstack-security | 09:05 | |
*** lhinds has quit IRC | 09:08 | |
*** lhinds has joined #openstack-security | 09:10 | |
*** yuanying has joined #openstack-security | 09:10 | |
*** yuanying has quit IRC | 09:15 | |
*** lhinds is now known as lhinds|afk | 09:15 | |
lhinds|afk | just going out , I have my phone and will be back in hour | 09:15 |
---|---|---|
*** tkelsey has quit IRC | 09:25 | |
*** salv-orl_ has joined #openstack-security | 09:38 | |
*** salv-orlando has quit IRC | 09:40 | |
*** yuanying has joined #openstack-security | 10:11 | |
*** markvoelker has joined #openstack-security | 10:34 | |
*** markvoelker has quit IRC | 10:39 | |
*** openstackgerrit has quit IRC | 10:47 | |
*** openstackgerrit has joined #openstack-security | 10:48 | |
*** lhinds|afk is now known as lhinds | 11:09 | |
lhinds | derp, wrong channel | 11:10 |
*** openstackgerrit has quit IRC | 11:47 | |
*** openstackgerrit has joined #openstack-security | 11:48 | |
*** lhinds has quit IRC | 12:03 | |
*** markvoelker has joined #openstack-security | 12:08 | |
*** lhinds has joined #openstack-security | 12:08 | |
*** salv-orl_ has quit IRC | 12:13 | |
*** salv-orlando has joined #openstack-security | 12:16 | |
*** aurelien__ has joined #openstack-security | 12:41 | |
*** openstackgerrit has quit IRC | 12:48 | |
*** openstackgerrit has joined #openstack-security | 12:48 | |
*** edmondsw has joined #openstack-security | 12:49 | |
*** dave-mccowan has joined #openstack-security | 13:14 | |
*** cleong has joined #openstack-security | 13:23 | |
*** aurelien__ has quit IRC | 13:26 | |
*** aurelien__ has joined #openstack-security | 13:27 | |
*** bknudson has left #openstack-security | 13:33 | |
*** aurelien__ has quit IRC | 13:34 | |
*** aurelien__ has joined #openstack-security | 13:34 | |
*** bknudson has joined #openstack-security | 13:36 | |
*** aurelien__ has quit IRC | 13:47 | |
*** jhfeng has joined #openstack-security | 14:01 | |
*** mvaldes has joined #openstack-security | 14:04 | |
*** jmckind has joined #openstack-security | 14:06 | |
*** aurelien__ has joined #openstack-security | 14:09 | |
*** openstackgerrit has quit IRC | 14:18 | |
*** openstackgerrit has joined #openstack-security | 14:18 | |
*** tmcpeak has joined #openstack-security | 14:23 | |
*** salv-orlando has quit IRC | 14:24 | |
*** jhfeng has quit IRC | 14:30 | |
*** aurelien__ has quit IRC | 14:30 | |
*** jhfeng has joined #openstack-security | 14:32 | |
*** dmk0202 has quit IRC | 14:35 | |
*** nkinder has joined #openstack-security | 14:42 | |
*** vinaypotluri has joined #openstack-security | 14:44 | |
*** tesseract has quit IRC | 15:11 | |
*** yaya has joined #openstack-security | 15:17 | |
*** mvaldes has quit IRC | 15:21 | |
*** salv-orlando has joined #openstack-security | 15:23 | |
*** rcernin has quit IRC | 15:24 | |
*** austin987 has quit IRC | 15:34 | |
*** salv-orl_ has joined #openstack-security | 15:37 | |
*** rous has joined #openstack-security | 15:40 | |
*** salv-orlando has quit IRC | 15:40 | |
rous | k | 15:41 |
*** rous has left #openstack-security | 15:41 | |
*** sigmavirus24 is now known as m3du5a | 15:43 | |
*** m3du5a is now known as sigmavirus24 | 15:44 | |
*** austin987 has joined #openstack-security | 15:47 | |
*** dave-mccowan has quit IRC | 15:57 | |
*** mdong has joined #openstack-security | 15:58 | |
*** mvaldes has joined #openstack-security | 15:59 | |
*** bpokorny has joined #openstack-security | 16:00 | |
*** ccneill has joined #openstack-security | 16:02 | |
*** aurelien__ has joined #openstack-security | 16:08 | |
*** salv-orl_ has quit IRC | 16:12 | |
*** diazjf has joined #openstack-security | 16:33 | |
*** salv-orlando has joined #openstack-security | 16:33 | |
*** diazjf has quit IRC | 16:35 | |
*** aurelien__ has quit IRC | 16:41 | |
*** Mimhoz has joined #openstack-security | 16:44 | |
*** Mimhoz has quit IRC | 16:45 | |
*** can8dnSix has joined #openstack-security | 16:47 | |
*** sdake has joined #openstack-security | 16:52 | |
sdake | heyfolks | 16:52 |
sdake | https://github.com/openstack/security-doc | 16:52 |
*** mvaldes has quit IRC | 16:53 | |
sdake | where does this repo's documentation get publshed to on the internets? | 16:53 |
tmcpeak | sdake: the whole thing doesn't, it's a central repo for sec guide, OSSN, and other stuff | 16:57 |
tmcpeak | sec guide is published here: http://docs.openstack.org/security-guide/ | 16:57 |
tmcpeak | sdake: wiki form of OSSN: https://wiki.openstack.org/wiki/Security_Notes | 16:58 |
sdake | tmcpeak i am fixing the governance repo | 16:58 |
sdake | and someone asked me to link to the speicfic docs | 16:58 |
sdake | i guess i'll sort it out - thanks ;) | 16:59 |
tmcpeak | hmm | 16:59 |
tmcpeak | ok, no prob | 16:59 |
*** jhfeng has quit IRC | 17:11 | |
*** austin987 has quit IRC | 17:16 | |
sdake | tmcpeak who maintians security-doc repo? | 17:21 |
tmcpeak | hyakuhei or sicarie | 17:21 |
tmcpeak | I mean a bunch of us do, but depending on what you're after those are your best bet | 17:22 |
sdake | here is what i'm after | 17:22 |
sdake | https://review.openstack.org/#/c/321468/ | 17:22 |
sdake | see last comment from tristan | 17:22 |
sdake | they want me to change the VMT tagging to have all documentation go into the security-doc repo | 17:23 |
tmcpeak | I don't see a comment from tristan | 17:23 |
sdake | sorry wrong review | 17:23 |
sdake | https://review.openstack.org/#/c/300698/ | 17:23 |
sdake | I just updated the review | 17:24 |
sdake | with tristan | 17:24 |
*** salv-orlando has quit IRC | 17:24 | |
sdake | but i htink before we head down this road, we want to make sure the security team is good with all the reviews/tas/etc going into the security-doc repository | 17:24 |
tmcpeak | OK, yeah I think it's a good place for TA artifacts to live | 17:25 |
sdake | it may be more then just ta artifacts | 17:25 |
sdake | it may be audits or security reviews as well | 17:25 |
*** yojanset has joined #openstack-security | 17:25 | |
tmcpeak | hmm | 17:25 |
tmcpeak | my only concern would be the repo getting really large | 17:26 |
tmcpeak | but if we had to we could split it out I guess | 17:26 |
tmcpeak | TA could generate a lot of images and other binary data, I'm not sure git is the best solution for stuff like that | 17:26 |
*** yojanset has quit IRC | 17:27 | |
tmcpeak | I still don't see Tristan's comment btw | 17:27 |
tmcpeak | oh his link? | 17:27 |
tmcpeak | to this one? https://review.openstack.org/#/c/220712 | 17:27 |
sdake | tmcpeak say I want to add Rob as a reviewer | 17:28 |
sdake | but I am having trouble finding him in gerrit | 17:28 |
sdake | any tips on that? | 17:28 |
tmcpeak | hyakuhei | 17:28 |
tmcpeak | I'll add him | 17:28 |
sdake | tmcpeak i added him | 17:28 |
sdake | is this the review you are speaking of ? https://review.openstack.org/#/c/300698 | 17:28 |
tmcpeak | lol | 17:29 |
tmcpeak | I thought you were talking about this - https://review.openstack.org/#/c/220712 | 17:29 |
sdake | ya i had the wrong link i think | 17:29 |
sdake | this is sepcifically for the governance repository | 17:30 |
tmcpeak | I still think I'm missing context | 17:31 |
tmcpeak | so VMT is asking for guidance about where these things are going to live? | 17:31 |
sdake | ok basically VMT previously did not include threat analysis as an option | 17:31 |
tmcpeak | and you're asking if we're ok with having all of that in security-doc repo? | 17:31 |
tmcpeak | an option for what? | 17:31 |
sdake | so I added that as a review | 17:31 |
sdake | an option to get the vmt tag | 17:32 |
sdake | so yes, the tc wants the docs to live "somewhere" | 17:32 |
tmcpeak | ok based on our discussion at the summit you're saying you are adding TA as one of the ways to get a VMT tag, right? | 17:32 |
sdake | but its more then just tas, its also reviews and audits | 17:32 |
sdake | tmcpeak that has been in the review queue for about a month and has wide buyin from the tc | 17:32 |
sdake | we are just fine tuning at this point, and the fine tuning is around *where* to store the results | 17:33 |
tmcpeak | ok cool, so the only question is where to store these things? | 17:33 |
tmcpeak | gotcha | 17:33 |
tmcpeak | well can we start with them living in security doc and move them later if there's a problem? | 17:33 |
sdake | ok - as long as the security team doesn't mind it :) | 17:33 |
sdake | i'm good with it | 17:33 |
sdake | that is my concern - overload on docs submission | 17:33 |
tmcpeak | yeah | 17:34 |
tmcpeak | and git doesn't handle a bunch of binary very well | 17:34 |
sdake | the approval of the docs and submission of the docs are two separate things | 17:34 |
sdake | as the vmt section 5 change is worded | 17:34 |
tmcpeak | any reason we can't make a new repo for it? | 17:34 |
sdake | no reason at all | 17:34 |
tmcpeak | allright, let's do that just to be safe then | 17:35 |
sdake | assuming hyakuhei is good with that living under security governance | 17:35 |
tmcpeak | I don't know how big these things are going to get | 17:35 |
sdake | i dont just want a repo hanging out without being reviewed ;) | 17:35 |
tmcpeak | allright, probably double check with him but that sounds reasonable | 17:35 |
sdake | tmcpeak are you doug? | 17:35 |
sdake | i dont know nick->name mappings atm ;) | 17:36 |
tmcpeak | no, I'm Travis | 17:36 |
sdake | hey travis | 17:37 |
sdake | im sorry i dont recall if we met, I met like hundreds of people at summit :) | 17:38 |
sdake | to top it off i' mbad on names | 17:38 |
tmcpeak | no worries, dg is Doug | 17:39 |
tmcpeak | we did meet, on the last day I was working with a couple Kolla folks on snowflake mappings | 17:39 |
sdake | tmcpeak oh yes, for what you have done for me, I should remember your name | 17:46 |
sdake | my total and complete bad | 17:46 |
sdake | i was doing the snowflake mappings then too :) | 17:47 |
tmcpeak | sdake: heh, no worries, I'm crap with names myself | 17:48 |
tmcpeak | good times that snowflake mapping :) | 17:49 |
tmcpeak | we have plans to continue that work and finish the TA? | 17:49 |
*** mvaldes has joined #openstack-security | 17:49 | |
*** yaya has quit IRC | 17:52 | |
*** sdake_ has joined #openstack-security | 17:52 | |
*** sdake has quit IRC | 17:55 | |
*** jhfeng has joined #openstack-security | 17:56 | |
*** bpokorny_ has joined #openstack-security | 17:57 | |
*** yaya has joined #openstack-security | 17:59 | |
*** bpokorny has quit IRC | 18:01 | |
*** sdake_ is now known as sdake | 18:06 | |
*** mvaldes has quit IRC | 18:22 | |
*** yaya has quit IRC | 18:24 | |
*** jhfeng has quit IRC | 18:27 | |
*** jhfeng has joined #openstack-security | 18:30 | |
*** yaya has joined #openstack-security | 18:33 | |
sdake | tmcpeak i mailed the mailing list with a question regarding next steps | 18:47 |
sdake | i think where we are is rob had done a sequence diagram | 18:47 |
sdake | i was going to get the kolla coresec team to do the speical snowflakes sequence diagrams | 18:47 |
sdake | but need an eample to work from | 18:47 |
sdake | rob had done the original sequence diagram for the least privileged case | 18:47 |
tmcpeak | sdake: gotcha | 18:48 |
sdake | so basically i need the src to the sequence diagram he created | 18:48 |
sdake | which i dont know where is located | 18:48 |
tmcpeak | hrmm, I expect he's out for the weekend | 18:49 |
sdake | after the sequence diagrams are done (a concrete next step) I dont know what follows next | 18:49 |
tmcpeak | probs check back Monday morning is the best | 18:49 |
sdake | i mailed the list monday ;) | 18:49 |
tmcpeak | we'll need to coordinate a time and place for us to at least hangouts | 18:49 |
tmcpeak | walk through them and do the analysis part of the TA | 18:49 |
sdake | i'd like to record it if possible so i can capture it in a doc | 18:50 |
sdake | would you be open to webex instead? | 18:50 |
tmcpeak | sure | 18:50 |
sdake | ok but first we need the sequence diagrms right? | 18:50 |
tmcpeak | yep yep | 18:51 |
sdake | is there anything else we need besides the sequence diagrams? | 18:51 |
tmcpeak | also I don't remember how far we got with a basic description of assets, etc | 18:51 |
tmcpeak | ^ | 18:51 |
sdake | we described all the assets | 18:51 |
sdake | I have a photograph | 18:52 |
tmcpeak | ok cool | 18:52 |
sdake | and I htink you took one too | 18:52 |
tmcpeak | yeah I do remember that | 18:52 |
sdake | i hope i took one | 18:52 |
sdake | i may hae menat to take one and didn't | 18:52 |
tmcpeak | let's double check with dg and hyakuhei but that should be enough to do analysis | 18:52 |
sdake | any chance you can send me the photo you toook? | 18:53 |
tmcpeak | sure, pm me email | 18:53 |
tmcpeak | let me make sure I have it | 18:53 |
sdake | stdake@cisco.com | 18:53 |
sdake | my phone is out of juice | 18:53 |
sdake | and i want to get rolling - aslo was thinking of twittering the photo :) | 18:54 |
tmcpeak | instagram <3 | 18:54 |
tmcpeak | sent | 18:55 |
sdake | ya i'm an old fuddyddudy | 18:55 |
sdake | still learning twitter :) | 18:55 |
tmcpeak | you're a braver man than I, I get enough spam as it is without dropping my email in the channel :P | 18:55 |
sdake | i have extremely effective filters | 18:55 |
tmcpeak | Twitter is good :) | 18:56 |
*** blackman_12345 has joined #openstack-security | 18:57 | |
*** blackman_12345 has left #openstack-security | 18:58 | |
*** bpokorny_ has quit IRC | 18:58 | |
*** bpokorny has joined #openstack-security | 18:59 | |
*** sdake_ has joined #openstack-security | 19:09 | |
*** sdake has quit IRC | 19:10 | |
*** mvaldes has joined #openstack-security | 19:11 | |
sdake_ | tmcpeak check this out - the threat analysis photo was my 100th tweet ;) | 19:12 |
tmcpeak | allright! | 19:12 |
tmcpeak | moving up in the world | 19:12 |
*** sdake has joined #openstack-security | 19:18 | |
*** sdake_ has quit IRC | 19:19 | |
*** nkinder has quit IRC | 19:23 | |
*** yaya has quit IRC | 19:31 | |
*** salv-orlando has joined #openstack-security | 19:39 | |
*** openstack has joined #openstack-security | 21:42 | |
*** unrahul has joined #openstack-security | 21:51 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!