dstanek | ccneill: i some ideas for a fix. maybe after these other bugs i'm working on | 00:01 |
---|---|---|
*** ccneill has quit IRC | 00:16 | |
*** vinaypotluri has quit IRC | 00:21 | |
*** hockeynut has joined #openstack-security | 00:22 | |
*** knangia has quit IRC | 00:31 | |
*** hockeynut has quit IRC | 01:02 | |
*** hockeynut has joined #openstack-security | 01:02 | |
*** zhh has joined #openstack-security | 01:18 | |
*** dave-mccowan has joined #openstack-security | 01:21 | |
*** sdake has quit IRC | 02:13 | |
*** sdake has joined #openstack-security | 02:13 | |
*** elo has quit IRC | 02:19 | |
*** yuanying has quit IRC | 02:50 | |
*** elo has joined #openstack-security | 02:50 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Fix blacklist filtering https://review.openstack.org/355772 | 02:52 |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Update defusedxml notification https://review.openstack.org/356199 | 03:15 |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Update defusedxml notification https://review.openstack.org/356199 | 03:17 |
*** sdake has quit IRC | 03:34 | |
*** jeisson has joined #openstack-security | 03:35 | |
*** dave-mccowan has quit IRC | 03:38 | |
*** jeisson has left #openstack-security | 03:38 | |
*** yuanying has joined #openstack-security | 03:49 | |
*** yuanying has quit IRC | 03:55 | |
*** dikonoor has joined #openstack-security | 03:57 | |
*** hockeynut has quit IRC | 04:03 | |
*** yuanying has joined #openstack-security | 04:16 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Fixed a bug in runner https://review.openstack.org/356217 | 04:20 |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Fixed a bug in runner https://review.openstack.org/356217 | 04:23 |
openstackgerrit | Merged openstack/syntribos: Fixed a bug in runner https://review.openstack.org/356217 | 04:42 |
*** yuanying_ has joined #openstack-security | 05:29 | |
*** yuanying has quit IRC | 05:29 | |
*** liverpooler has joined #openstack-security | 05:40 | |
*** rcernin has joined #openstack-security | 05:46 | |
*** zhh has quit IRC | 06:11 | |
*** zhh has joined #openstack-security | 06:16 | |
*** markvoelker has quit IRC | 07:00 | |
*** tesseract- has joined #openstack-security | 07:00 | |
*** jamielennox is now known as jamielennox|away | 07:45 | |
*** markvoelker has joined #openstack-security | 08:00 | |
*** markvoelker has quit IRC | 08:05 | |
*** jamielennox|away is now known as jamielennox | 08:50 | |
*** elo has quit IRC | 08:52 | |
*** markvoelker has joined #openstack-security | 09:01 | |
*** elo has joined #openstack-security | 09:02 | |
*** markvoelker has quit IRC | 09:06 | |
*** elo has quit IRC | 09:12 | |
*** elo has joined #openstack-security | 09:13 | |
*** jamielennox is now known as jamielennox|away | 09:43 | |
*** elo has quit IRC | 09:46 | |
*** elo has joined #openstack-security | 09:50 | |
*** elo has quit IRC | 09:55 | |
*** dikonoor has quit IRC | 09:56 | |
*** openstack has joined #openstack-security | 10:16 | |
*** sdake_ has quit IRC | 10:18 | |
*** sdake_ has joined #openstack-security | 10:19 | |
*** sdake has quit IRC | 10:19 | |
*** shohel1 has joined #openstack-security | 11:13 | |
*** shohel has quit IRC | 11:13 | |
*** sdake_ is now known as sdake | 11:24 | |
*** dave-mccowan has joined #openstack-security | 11:46 | |
*** sdake_ has joined #openstack-security | 12:01 | |
*** sdake has quit IRC | 12:05 | |
*** sdake_ is now known as sdake | 12:05 | |
*** markvoelker has joined #openstack-security | 12:09 | |
*** jamielennox|away is now known as jamielennox | 12:11 | |
*** elo has joined #openstack-security | 12:16 | |
*** zhh has quit IRC | 12:33 | |
*** jass93 has quit IRC | 12:38 | |
*** Gr33nW0lf has joined #openstack-security | 13:20 | |
*** Gr33nW0lf has quit IRC | 13:21 | |
openstackgerrit | Merged openstack/bandit: Update defusedxml notification https://review.openstack.org/356199 | 13:21 |
*** cleong has joined #openstack-security | 13:33 | |
*** edmondsw has joined #openstack-security | 13:37 | |
*** ametts has joined #openstack-security | 13:40 | |
*** shohel1 has quit IRC | 13:48 | |
*** sdake has quit IRC | 13:50 | |
*** mvaldes has joined #openstack-security | 13:58 | |
*** sdake_ has joined #openstack-security | 14:01 | |
*** _elmiko is now known as elmiko | 14:06 | |
*** crystal has joined #openstack-security | 14:12 | |
*** crystal is now known as Guest48853 | 14:13 | |
*** hockeynut has joined #openstack-security | 14:20 | |
*** edtubill has joined #openstack-security | 14:35 | |
hyakuhei | info for the midcycle https://etherpad.openstack.org/p/barbican-security-midcycle-N | 14:36 |
*** diazjf has joined #openstack-security | 14:36 | |
unrahul | Ccneill u @ibm? | 14:43 |
unrahul | We are waiting outside in the lobby | 14:44 |
*** diazjf has quit IRC | 14:44 | |
hyakuhei | Hey. Fernando is on his way. | 14:44 |
unrahul | Awesome hyakuhei! | 14:44 |
*** Guest48853 is now known as szh | 14:45 | |
*** elo has quit IRC | 14:59 | |
*** openstackgerrit has quit IRC | 15:03 | |
*** openstackgerrit has joined #openstack-security | 15:04 | |
*** mdong has joined #openstack-security | 15:07 | |
*** diazjf has joined #openstack-security | 15:23 | |
*** mdong has quit IRC | 15:27 | |
*** mdong has joined #openstack-security | 15:28 | |
*** vinaypotluri has joined #openstack-security | 15:30 | |
*** szh has quit IRC | 15:31 | |
hyakuhei | unrahul so you're with the intel folks? | 15:31 |
*** kfarr has joined #openstack-security | 15:33 | |
mdong | https://etherpad.openstack.org/p/syntribos-overview | 15:33 |
vinaypotluri | https://etherpad.openstack.org/p/syntribos-overview | 15:33 |
*** knangia has joined #openstack-security | 15:33 | |
*** ccneill has joined #openstack-security | 15:33 | |
*** tmcpeak has joined #openstack-security | 15:33 | |
redrobot | https://hangouts.google.com/call/tcl3ze55djdrrgsjdml6jxe46ue | 15:34 |
redrobot | ccneill ^^ | 15:34 |
*** aastha has joined #openstack-security | 15:36 | |
*** rcernin has quit IRC | 15:58 | |
*** sdake_ is now known as sdake | 16:00 | |
*** sdake is now known as sdake_ | 16:00 | |
openstackgerrit | Robert Clark proposed openstack/security-analysis: Adding .DS_Store to .gitignore https://review.openstack.org/356574 | 16:07 |
*** Cormite has joined #openstack-security | 16:10 | |
*** Cormite has quit IRC | 16:15 | |
*** Cormite has joined #openstack-security | 16:15 | |
*** Cormite has quit IRC | 16:22 | |
openstackgerrit | Merged openstack/security-analysis: Adding .DS_Store to .gitignore https://review.openstack.org/356574 | 16:22 |
*** Cormite has joined #openstack-security | 16:22 | |
*** Cormite has quit IRC | 16:23 | |
*** Cormite has joined #openstack-security | 16:24 | |
diazjf | https://github.com/openstack/barbican/blob/master/doc/source/setup/dev.rst | 16:26 |
kfarr | ccneill, if you want to launch barbican w devstack, you can use a local.conf like this one: https://github.com/openstack/barbican/blob/master/devstack/local.conf.example | 16:27 |
kfarr | ^^ it only enables rabbit, mysql, keystone, and barbican (disables all others) | 16:27 |
kfarr | and on line 4, should probably use stable/mitaka instead of stable/liberty. or remove the stable/* part to download the latest master | 16:28 |
*** Cormite has quit IRC | 16:32 | |
*** Cormite has joined #openstack-security | 16:32 | |
*** tmcpeak has quit IRC | 16:40 | |
*** diazjf has quit IRC | 16:41 | |
*** mdong has quit IRC | 16:41 | |
*** ccneill has quit IRC | 16:46 | |
*** edtubill has quit IRC | 16:46 | |
*** kfarr has quit IRC | 16:46 | |
*** singlethink has joined #openstack-security | 16:55 | |
*** tesseract- has quit IRC | 17:00 | |
*** liverpooler has quit IRC | 17:07 | |
*** mvaldes has quit IRC | 17:24 | |
*** rcernin has joined #openstack-security | 17:26 | |
*** hockeynut has quit IRC | 17:48 | |
*** hockeynut has joined #openstack-security | 17:59 | |
*** Gr33nW0lf has joined #openstack-security | 18:14 | |
*** Gr33nW0lf has quit IRC | 18:17 | |
*** mvaldes has joined #openstack-security | 18:28 | |
*** mdong has joined #openstack-security | 18:35 | |
*** ccneill has joined #openstack-security | 18:35 | |
*** tmcpeak has joined #openstack-security | 18:36 | |
*** Cormite has quit IRC | 18:36 | |
*** liverpooler has joined #openstack-security | 18:38 | |
*** tmcpeak1 has joined #openstack-security | 18:45 | |
*** ametts has quit IRC | 18:45 | |
hyakuhei | OSSN bugs #link https://bugs.launchpad.net/ossn | 18:47 |
hyakuhei | OSSN Process #link https://wiki.openstack.org/wiki/Security/Security_Note_Process | 18:47 |
hyakuhei | OSSN list #link https://wiki.openstack.org/wiki/Security_Notes | 18:48 |
*** tmcpeak has quit IRC | 18:48 | |
*** ametts has joined #openstack-security | 18:56 | |
*** jamielennox has quit IRC | 19:06 | |
*** edtubill has joined #openstack-security | 19:06 | |
*** diazjf has joined #openstack-security | 19:09 | |
*** jamielennox has joined #openstack-security | 19:09 | |
tmcpeak1 | lhinds: around? | 19:10 |
*** Gr33nW0lf has joined #openstack-security | 19:10 | |
*** Gr33nW0lf has quit IRC | 19:19 | |
*** edmondsw has quit IRC | 19:28 | |
hyakuhei | michaelxin you around? | 19:32 |
hyakuhei | I wanted to know what's up with https://bugs.launchpad.net/ossn/+bug/1507841 | 19:32 |
openstack | Launchpad bug 1507841 in OpenStack Security Notes "mongodb guest instance allows any user to connect" [Undecided,Confirmed] - Assigned to Michael Xin (michael-xin) | 19:32 |
*** liverpooler has quit IRC | 19:42 | |
*** mvaldes has quit IRC | 19:52 | |
openstackgerrit | Travis McPeak proposed openstack/security-doc: Adding author field to the OSSN template https://review.openstack.org/356678 | 19:57 |
*** mvaldes has joined #openstack-security | 20:00 | |
*** diazjf has quit IRC | 20:01 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding a gitignore entry for dstore https://review.openstack.org/356684 | 20:04 |
openstackgerrit | Doug Chivers proposed openstack/security-analysis: Designate third-party security review artifacts https://review.openstack.org/356025 | 20:10 |
openstackgerrit | Merged openstack/security-doc: Adding author field to the OSSN template https://review.openstack.org/356678 | 20:14 |
hyakuhei | Gerrit is slow today. | 20:14 |
*** diazjf has joined #openstack-security | 20:15 | |
openstackgerrit | Robert Clark proposed openstack/security-doc: Updating ML information https://review.openstack.org/356689 | 20:19 |
hyakuhei | tmcpeak1 ^^ | 20:19 |
openstackgerrit | Merged openstack/security-doc: Updating ML information https://review.openstack.org/356689 | 20:34 |
*** rcernin has quit IRC | 20:40 | |
*** cleong has quit IRC | 20:46 | |
openstackgerrit | Vinay Potluri proposed openstack/security-doc: Updated OSSN-0072 https://review.openstack.org/356712 | 20:55 |
hyakuhei | tmcpeak1 elmiko lhinds ^^^ contribution from vinaypotluri - it's his first OSSN so play nice! :P | 20:56 |
vinaypotluri | :) | 20:56 |
elmiko | hyakuhei: ack | 20:57 |
* elmiko starts sharpening his axe | 20:57 | |
tmcpeak1 | vinaypotluri: awesome! | 20:57 |
vinaypotluri | thank you tmcpeak1 :) | 20:58 |
*** edmondsw has joined #openstack-security | 20:58 | |
*** edtubill has quit IRC | 21:02 | |
hyakuhei | lhinds you here? | 21:04 |
elmiko | vinaypotluri: ok, added a few comments for you =) | 21:04 |
*** diazjf has quit IRC | 21:06 | |
*** kfarr has joined #openstack-security | 21:09 | |
*** diazjf has joined #openstack-security | 21:10 | |
*** edtubill has joined #openstack-security | 21:11 | |
*** kfarr has quit IRC | 21:13 | |
openstackgerrit | Aastha Dixit proposed openstack/syntribos: Sorting list of tests https://review.openstack.org/356735 | 21:16 |
hyakuhei | elmiko tmcpeak1 lhinds ^^^^ | 21:19 |
hyakuhei | I think we've got people stealing all lhinds bugs here.... | 21:19 |
hyakuhei | Yay opensource :) | 21:20 |
hyakuhei | I think because the bugs weren't marked as "in-progress" - I think I need to fix some docs. | 21:22 |
elmiko | hyakuhei: haven't been following syntribos dev, is that one lhinds reported? | 21:23 |
diazjf | unrahul https://github.com/openstack/barbican/blob/master/doc/source/setup/dev.rst | 21:25 |
diazjf | unrahul https://github.com/openstack/barbican/blob/master/doc/source/setup/keystone.rst | 21:26 |
vinaypotluri | elmiko: in the last comment you asked me if I can give an extended advice for an operator ... | 21:27 |
vinaypotluri | do i need to mention the steps to disable ipv6 ? | 21:27 |
elmiko | if that is most appropriate, in the past we have given code samples, or example configurations, something tangible to help the reader understand how to mitigate the described attack | 21:28 |
elmiko | i don't the domain as well as you do, but reading that note made sense to me, but i was left wondering how i would implement what you suggest at the end | 21:29 |
elmiko | *i don't know* | 21:29 |
elmiko | does that make sense? | 21:29 |
vinaypotluri | cool | 21:30 |
elmiko | =) | 21:30 |
vinaypotluri | will update that | 21:30 |
vinaypotluri | :) | 21:30 |
elmiko | thanks! | 21:30 |
vinaypotluri | elmiko: do you think adding a reference link to a stackoverflow page or any page also help ? | 21:31 |
elmiko | vinaypotluri: definitely, references are always appreciated when they fit | 21:32 |
vinaypotluri | awesome | 21:33 |
unrahul | thanks diazjf , trying to set it up now | 21:40 |
hyakuhei | So I've added some more process/documentation to https://wiki.openstack.org/wiki/Security/Security_Note_Process in response to the feedback we've had today. It's still a bit ropey in places and some text probably needs diagrams to help it along. | 21:42 |
*** mvaldes has quit IRC | 21:43 | |
elmiko | hyakuhei++ | 21:44 |
elmiko | hmm | 21:45 |
elmiko | mt | 21:45 |
*** edtubill has quit IRC | 21:51 | |
*** diazjf has quit IRC | 21:51 | |
*** ccneill has quit IRC | 21:56 | |
hyakuhei | vinaypotluri unrahul et al - dinner info in the etherpad: https://etherpad.openstack.org/p/barbican-security-midcycle-N | 21:57 |
elmiko | totally forgot you all are at the midcycle... /me facepalm | 21:59 |
openstackgerrit | Vinay Potluri proposed openstack/security-doc: Updated OSSN-0072 https://review.openstack.org/356712 | 22:00 |
*** ametts has quit IRC | 22:04 | |
*** mdong has quit IRC | 22:05 | |
*** sdake_ has quit IRC | 22:06 | |
*** tmcpeak1 has quit IRC | 22:08 | |
openstackgerrit | Merged openstack/security-analysis: Adding templates for security review artifacts https://review.openstack.org/356130 | 22:15 |
*** elo has joined #openstack-security | 22:18 | |
*** tmcpeak has joined #openstack-security | 22:21 | |
*** sdake has joined #openstack-security | 22:21 | |
*** hockeynut has quit IRC | 22:22 | |
*** sdake has quit IRC | 22:38 | |
unrahul | Thanks hyakuhei | 22:38 |
*** jass93 has joined #openstack-security | 22:47 | |
*** singlethink has quit IRC | 22:59 | |
*** elmiko is now known as _elmiko | 23:12 | |
*** tmcpeak has quit IRC | 23:40 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!