*** JAHoagie has quit IRC | 00:08 | |
*** edtubill has joined #openstack-security | 00:11 | |
*** knangia has quit IRC | 00:11 | |
*** bigdogstl has joined #openstack-security | 00:15 | |
*** sdake has joined #openstack-security | 00:16 | |
*** bigdogstl has quit IRC | 00:21 | |
*** bigdogstl has joined #openstack-security | 00:21 | |
*** ccneill has quit IRC | 00:33 | |
*** bigdogstl has quit IRC | 00:37 | |
*** bigdogstl has joined #openstack-security | 00:38 | |
*** bigdogstl has quit IRC | 00:41 | |
*** bigdogstl has joined #openstack-security | 00:43 | |
*** bigdogst_ has joined #openstack-security | 00:47 | |
*** bigdogstl has quit IRC | 00:48 | |
*** bigdogst_ has quit IRC | 00:53 | |
*** diazjf has joined #openstack-security | 01:00 | |
*** bigdogstl has joined #openstack-security | 01:01 | |
*** bigdogstl has quit IRC | 01:06 | |
*** sdake_ has joined #openstack-security | 01:06 | |
*** sdake has quit IRC | 01:10 | |
*** jamielennox is now known as jamielennox|away | 01:11 | |
*** salv-orl_ has joined #openstack-security | 01:15 | |
*** jamielennox|away is now known as jamielennox | 01:16 | |
*** salv-orlando has quit IRC | 01:18 | |
*** sdake_ has quit IRC | 01:19 | |
*** sdake has joined #openstack-security | 01:22 | |
*** salv-orl_ has quit IRC | 01:26 | |
*** diazjf has quit IRC | 01:34 | |
*** hockeynut has quit IRC | 01:36 | |
*** markvoelker has joined #openstack-security | 01:44 | |
*** markvoelker_ has joined #openstack-security | 01:46 | |
*** zhihui has joined #openstack-security | 01:46 | |
*** markvoelker has quit IRC | 01:50 | |
*** aastha has quit IRC | 01:57 | |
*** yuanying has quit IRC | 02:10 | |
*** dave-mccowan has joined #openstack-security | 02:34 | |
*** jamielennox is now known as jamielennox|away | 02:49 | |
*** dave-mccowan has quit IRC | 02:56 | |
*** dave-mccowan has joined #openstack-security | 02:59 | |
*** jamielennox|away is now known as jamielennox | 03:06 | |
*** dave-mccowan has quit IRC | 03:21 | |
*** vinaypotluri has quit IRC | 03:21 | |
*** diazjf has joined #openstack-security | 03:24 | |
*** salv-orlando has joined #openstack-security | 03:30 | |
*** bigdogstl has joined #openstack-security | 03:31 | |
*** diazjf has quit IRC | 03:32 | |
*** salv-orlando has quit IRC | 03:38 | |
*** bigdogstl has quit IRC | 03:41 | |
*** zul has quit IRC | 03:41 | |
*** bigdogstl has joined #openstack-security | 03:44 | |
*** dikonoor has joined #openstack-security | 03:45 | |
*** zul has joined #openstack-security | 03:46 | |
*** vinaypotluri has joined #openstack-security | 03:54 | |
*** yuanying has joined #openstack-security | 03:59 | |
*** markvoelker has joined #openstack-security | 04:21 | |
*** markvoelker_ has quit IRC | 04:22 | |
*** markvoelker has quit IRC | 04:28 | |
*** salv-orlando has joined #openstack-security | 04:37 | |
*** adminator has joined #openstack-security | 04:40 | |
*** adminator has quit IRC | 04:42 | |
*** salv-orlando has quit IRC | 04:49 | |
*** jamielennox is now known as jamielennox|away | 04:49 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding a script to generate README.rst from docs https://review.openstack.org/358818 | 04:50 |
---|---|---|
*** edtubill has quit IRC | 04:50 | |
*** bigdogstl has quit IRC | 04:53 | |
*** bigdogstl has joined #openstack-security | 04:53 | |
*** bigdogstl has quit IRC | 04:56 | |
*** bigdogstl has joined #openstack-security | 04:56 | |
*** salv-orlando has joined #openstack-security | 04:58 | |
*** bigdogstl has quit IRC | 05:01 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding a script to generate README.rst from docs https://review.openstack.org/358818 | 05:06 |
*** bigdogstl has joined #openstack-security | 05:13 | |
*** bigdogstl has quit IRC | 05:17 | |
*** sdake_ has joined #openstack-security | 05:21 | |
*** jamielennox|away is now known as jamielennox | 05:23 | |
*** sdake has quit IRC | 05:24 | |
*** markvoelker has joined #openstack-security | 05:29 | |
*** markvoelker has quit IRC | 05:39 | |
*** sdake_ has quit IRC | 05:41 | |
*** dstufft has quit IRC | 05:53 | |
*** dstufft has joined #openstack-security | 05:54 | |
*** jamielennox is now known as jamielennox|away | 06:11 | |
*** pcaruana has joined #openstack-security | 06:14 | |
*** woodster_ has quit IRC | 06:19 | |
*** markvoelker has joined #openstack-security | 06:36 | |
*** markvoelker has quit IRC | 06:42 | |
*** shohel has joined #openstack-security | 07:13 | |
*** salv-orl_ has joined #openstack-security | 07:16 | |
*** tesseract- has joined #openstack-security | 07:18 | |
*** salv-orlando has quit IRC | 07:19 | |
*** salv-orl_ has quit IRC | 07:21 | |
*** vinaypotluri has quit IRC | 07:21 | |
*** salv-orlando has joined #openstack-security | 07:25 | |
*** dikonoor has quit IRC | 07:35 | |
*** dikonoor has joined #openstack-security | 07:36 | |
*** markvoelker has joined #openstack-security | 07:38 | |
*** markvoelker has quit IRC | 07:43 | |
*** JAHoagie has joined #openstack-security | 07:43 | |
*** JAHoagie has quit IRC | 07:48 | |
*** austin987 has quit IRC | 07:53 | |
*** rcernin has quit IRC | 07:56 | |
*** openstackgerrit has quit IRC | 08:03 | |
*** openstackgerrit has joined #openstack-security | 08:04 | |
*** yuanying has quit IRC | 08:05 | |
*** markvoelker has joined #openstack-security | 08:39 | |
*** salv-orl_ has joined #openstack-security | 08:44 | |
*** markvoelker has quit IRC | 08:44 | |
*** salv-orlando has quit IRC | 08:45 | |
*** salv-orl_ has quit IRC | 08:49 | |
*** salv-orlando has joined #openstack-security | 08:50 | |
*** d0ugal has quit IRC | 09:15 | |
*** d0ugal has joined #openstack-security | 09:16 | |
*** salv-orlando has quit IRC | 09:21 | |
*** salv-orlando has joined #openstack-security | 09:21 | |
*** markvoelker has joined #openstack-security | 09:40 | |
*** JAHoagie has joined #openstack-security | 09:44 | |
*** markvoelker has quit IRC | 09:44 | |
*** JAHoagie has quit IRC | 09:50 | |
*** dikonoor has quit IRC | 09:51 | |
*** dikonoor has joined #openstack-security | 09:52 | |
*** shohel has quit IRC | 10:07 | |
*** shohel has joined #openstack-security | 10:08 | |
*** markvoelker has joined #openstack-security | 11:09 | |
*** markvoelker has quit IRC | 11:20 | |
*** shohel has quit IRC | 11:30 | |
*** shohel has joined #openstack-security | 11:30 | |
*** rcernin has joined #openstack-security | 11:44 | |
*** JAHoagie has joined #openstack-security | 11:44 | |
*** JAHoagie has quit IRC | 11:48 | |
*** rcernin has quit IRC | 12:23 | |
*** rcernin has joined #openstack-security | 12:28 | |
*** nkinder has joined #openstack-security | 12:31 | |
*** edmondsw has joined #openstack-security | 12:40 | |
*** JAHoagie has joined #openstack-security | 12:44 | |
*** dave-mccowan has joined #openstack-security | 12:45 | |
*** JAHoagie has quit IRC | 12:48 | |
*** _elmiko is now known as elmiko | 12:52 | |
*** JAHoagie has joined #openstack-security | 12:56 | |
*** woodster_ has joined #openstack-security | 12:56 | |
*** rcernin has quit IRC | 13:03 | |
*** jass93 has quit IRC | 13:06 | |
*** tmcpeak has joined #openstack-security | 13:20 | |
*** bigdogstl has joined #openstack-security | 13:24 | |
*** tmcpeak1 has joined #openstack-security | 13:25 | |
*** tmcpeak has quit IRC | 13:28 | |
*** sdake has joined #openstack-security | 13:36 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/359201 | 13:36 |
*** sdake_ has joined #openstack-security | 13:37 | |
*** sdake has quit IRC | 13:41 | |
*** bigdogstl has quit IRC | 13:43 | |
*** bigdogstl has joined #openstack-security | 13:57 | |
*** bigdogstl has quit IRC | 14:02 | |
*** pcaruana has quit IRC | 14:02 | |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/359201 | 14:05 |
*** Munawwar has joined #openstack-security | 14:12 | |
*** Munawwar has left #openstack-security | 14:12 | |
*** cleong has joined #openstack-security | 14:14 | |
*** pcaruana has joined #openstack-security | 14:17 | |
*** edtubill has joined #openstack-security | 14:17 | |
*** mvaldes has joined #openstack-security | 14:33 | |
*** sdake_ has quit IRC | 14:35 | |
*** sdake has joined #openstack-security | 14:41 | |
*** JAHoagie has quit IRC | 14:46 | |
*** bigdogstl has joined #openstack-security | 14:52 | |
openstackgerrit | Andreas Jaeger proposed openstack/security-doc: Update to openstack-doc-tools 1.0 https://review.openstack.org/359253 | 14:55 |
*** shohel has quit IRC | 14:56 | |
*** bigdogstl has quit IRC | 14:57 | |
*** hockeynut has joined #openstack-security | 14:58 | |
*** vinaypotluri has joined #openstack-security | 15:01 | |
*** edtubill has quit IRC | 15:07 | |
*** salv-orlando has quit IRC | 15:08 | |
*** salv-orlando has joined #openstack-security | 15:08 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Standardizing the way we diff signals https://review.openstack.org/349403 | 15:24 |
*** knangia has joined #openstack-security | 15:24 | |
*** tesseract- has quit IRC | 15:46 | |
*** bigdogstl has joined #openstack-security | 15:46 | |
*** dikonoor has quit IRC | 15:49 | |
*** bigdogstl has quit IRC | 15:53 | |
*** pcaruana has quit IRC | 15:56 | |
*** aastha has joined #openstack-security | 15:57 | |
*** mdong has joined #openstack-security | 15:57 | |
*** ccneill has joined #openstack-security | 16:05 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Standardizing the way we diff signals https://review.openstack.org/349403 | 16:07 |
*** pcaruana has joined #openstack-security | 16:09 | |
*** nkinder has quit IRC | 16:11 | |
*** bigdogstl has joined #openstack-security | 16:23 | |
*** austin987 has joined #openstack-security | 16:24 | |
*** bigdogstl has quit IRC | 16:27 | |
*** zul has quit IRC | 16:36 | |
*** woodburn has quit IRC | 16:36 | |
*** austin987 has quit IRC | 16:43 | |
*** zul has joined #openstack-security | 16:48 | |
*** woodburn has joined #openstack-security | 16:55 | |
*** nkinder has joined #openstack-security | 17:05 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Standardizing the way we diff signals https://review.openstack.org/349403 | 17:07 |
*** ibmchas has joined #openstack-security | 17:08 | |
*** ibmchas has quit IRC | 17:13 | |
*** zhihui has quit IRC | 17:13 | |
*** bigdogstl has joined #openstack-security | 17:15 | |
openstackgerrit | Vinay Potluri proposed openstack/security-doc: Updated OSSN-0069 https://review.openstack.org/356712 | 17:16 |
*** zhihui has joined #openstack-security | 17:16 | |
*** bigdogstl has quit IRC | 17:20 | |
*** zul has quit IRC | 17:26 | |
*** hockeynut has quit IRC | 17:33 | |
*** ibmchas has joined #openstack-security | 17:50 | |
*** bigdogstl has joined #openstack-security | 17:51 | |
*** ibmchas has quit IRC | 17:54 | |
*** zul has joined #openstack-security | 17:55 | |
*** bigdogstl has quit IRC | 17:58 | |
*** jamielennox|away is now known as jamielennox | 18:01 | |
*** ibmchas has joined #openstack-security | 18:11 | |
*** hockeynut has joined #openstack-security | 18:13 | |
*** ibmchas has quit IRC | 18:15 | |
*** JAHoagie has joined #openstack-security | 18:28 | |
*** ibmchas has joined #openstack-security | 18:32 | |
*** diazjf has joined #openstack-security | 18:36 | |
*** ibmchas has quit IRC | 18:36 | |
*** zul has quit IRC | 18:46 | |
*** markvoelker has joined #openstack-security | 18:58 | |
*** zul has joined #openstack-security | 19:01 | |
*** markvoelker has quit IRC | 19:01 | |
openstackgerrit | Vinay Potluri proposed openstack/security-doc: Updated OSSN-0069 https://review.openstack.org/356712 | 19:04 |
*** ibmchas has joined #openstack-security | 19:13 | |
*** ibmchas has quit IRC | 19:18 | |
*** pcaruana has quit IRC | 19:20 | |
*** tmcpeak1 has quit IRC | 19:22 | |
*** salv-orlando has quit IRC | 19:28 | |
*** salv-orlando has joined #openstack-security | 19:28 | |
*** hockeynut has quit IRC | 19:28 | |
*** salv-orlando has quit IRC | 19:32 | |
*** singlethink has joined #openstack-security | 19:34 | |
*** ibmchas has joined #openstack-security | 19:34 | |
*** ibmchas_ has joined #openstack-security | 19:36 | |
*** ibmchas has quit IRC | 19:38 | |
*** markvoelker has joined #openstack-security | 19:57 | |
*** woodburn has left #openstack-security | 19:59 | |
openstackgerrit | Khanak Nangia proposed openstack/security-doc: Updated OSSN-0073 Added information about Horizon dashboard leaks https://review.openstack.org/357328 | 20:08 |
*** edmondsw has quit IRC | 20:13 | |
*** hockeynut has joined #openstack-security | 20:27 | |
*** sigmavirus is now known as sigmavirus|away | 20:29 | |
openstackgerrit | Merged openstack/security-doc: fix checklist summary https://review.openstack.org/345300 | 20:33 |
*** diazjf has quit IRC | 20:38 | |
*** nkinder has quit IRC | 20:40 | |
ccneill | aw, gerrit throws a 500 if you use emoji in comments lol :( | 20:41 |
unrahul | :D | 20:50 |
unrahul | I thought they always did `through` testing before it was deployed :D | 20:51 |
*** markvoelker has quit IRC | 20:52 | |
*** woodburn has joined #openstack-security | 20:53 | |
vinaypotluri | ^thorough | 20:56 |
knangia | *thorough | 20:56 |
unrahul | >< | 20:56 |
mdong | actually yeah, does that mean gerrit can’t handle unicode? | 20:57 |
vinaypotluri | (><) | 20:57 |
unrahul | that is kinda exciting .. :D | 20:57 |
*** diazjf has joined #openstack-security | 20:59 | |
ccneill | I'm sure we'd find some interesting stuff if we added gerrit to our list of projects to test lol | 21:02 |
unrahul | hehe.. yeah! like that time when whatsapp used to crash if some weird uttf8 chars r entered | 21:05 |
ccneill | so oslo-config-generator is pretty cool.. but it makes our example config huge | 21:08 |
unrahul | that was one of the problems and is still is for all core projects | 21:09 |
unrahul | the config given in the example is auto generated and a new person.. will not have much clue on what to do | 21:09 |
ccneill | yeah.. | 21:10 |
ccneill | :/ | 21:10 |
ccneill | --minimal is a little better | 21:11 |
ccneill | but it leaves off all the keystone stuff | 21:11 |
ccneill | would be cool if you could turn off the 3-line "From syntribos.config" comment too | 21:13 |
*** shohel has joined #openstack-security | 21:14 | |
ccneill | also, since we don't load the options for the auth test in syntribos.config, they don't show up.. wonder how we could best add those to the function called in entry_points, or if we should have a separate namespace for them or something | 21:14 |
*** mdong_ has joined #openstack-security | 21:17 | |
*** mdong has quit IRC | 21:18 | |
*** mdong_ is now known as mdong | 21:18 | |
unrahul | hey did any of guys already do the sanitize secrets thing..? | 21:19 |
unrahul | in debug log? | 21:19 |
unrahul | ccneill: mdong ? | 21:21 |
ccneill | I think mdong was taking the debug log action items | 21:22 |
ccneill | but he already has a few on his plate, so maybe you can tackle that one | 21:22 |
unrahul | i was working on it.. | 21:23 |
unrahul | just making sure no one is doing it.. | 21:23 |
unrahul | :D | 21:23 |
*** cleong has quit IRC | 21:24 | |
*** mvaldes1 has joined #openstack-security | 21:25 | |
*** mvaldes has quit IRC | 21:26 | |
ccneill | yeah I think you're good to take it unless mdong chimes in | 21:27 |
ccneill | add your name to the Trello item so everyone knows what's taken and what's not | 21:27 |
unrahul | so ccneill is it like we have to sanitize any 'password'/'token' etc coming in the log..? | 21:31 |
unrahul | or only the config..? | 21:31 |
*** hockeynut has quit IRC | 21:31 | |
unrahul | because I think config is already done.. | 21:31 |
ccneill | right, config options you can just mark "secret" | 21:31 |
ccneill | I meant X-Auth-Token headers mostly | 21:31 |
ccneill | maybe "password" too.. | 21:32 |
ccneill | it should probably be configurable in the logging settings whether you want to sanitize or not | 21:32 |
unrahul | so what if are fuzzing it.. and the password and tokens..? | 21:32 |
*** salv-orlando has joined #openstack-security | 21:32 | |
ccneill | yeah, I'm not sure if we should be filtering the actual data we send, only the information in the auth requests really | 21:32 |
ccneill | like the password in the token request | 21:32 |
ccneill | hmm.. not sure how we could easily select that one thing to filter though | 21:33 |
unrahul | what i did was searching for a secret whitelist like password/token/secretkey and all that and sanitizing it.. | 21:33 |
unrahul | but then I realized that we might need that info when fuzzing | 21:33 |
ccneill | right | 21:33 |
unrahul | if a`unicode` password breaks the damn thing.. | 21:33 |
ccneill | haha yeah | 21:33 |
unrahul | hehe.. | 21:34 |
unrahul | so.. how do u think the approach should be.. :/ | 21:34 |
ccneill | we could have a property on RequestObject like "filter_secrets" or something | 21:34 |
ccneill | and modify the logging behavior based on that | 21:34 |
unrahul | or in config..? filter_secrets? | 21:35 |
unrahul | in logging section..? | 21:35 |
unrahul | because we would need to sanitize, if syntribos has to be used in gate jobs.. , otherwise.. all hell would break loose | 21:35 |
ccneill | I think we want a property on the RequestObjects to determine which requests to filter and which not to, and a config option in syntribos.config to toggle whether you want that filtering to do anything or not | 21:35 |
mdong | sorry, just saw this, yeah, I wasn’t working on that one | 21:36 |
ccneill | so we would add that property to all the keystone requests that we do to get tokens or do anything sensitive | 21:36 |
ccneill | but fuzz requests wouldn't be filtered at all | 21:36 |
ccneill | since it's assumed that you're not going to put your actual passwords into the templates... | 21:36 |
ccneill | if you do, well.. we can't really save you from all the ways you can shoot yourself in the foot :/ | 21:36 |
ccneill | but if people write other extensions that they don't want to log secrets from, they can just toggle the "filter_secrets" property of the RequestObject too | 21:37 |
ccneill | make sense unrahul ? | 21:38 |
ccneill | might have to modify the way the identity extension works a little bit, but shouldn't be too much | 21:38 |
unrahul | yup that make sense ccneill ; gonna poke around it .. | 21:38 |
ccneill | just default it to False so you don't have to modify the calls in other places | 21:38 |
ccneill | cool cool | 21:39 |
unrahul | yup.. | 21:39 |
unrahul | i have a feeling someone out there.. will put the creds in a template.. | 21:39 |
unrahul | alryt ccneill thanks! | 21:40 |
ccneill | (;¬_¬) | 21:40 |
unrahul | +1 mdong | 21:40 |
unrahul | hehe | 21:40 |
ccneill | of course lol | 21:40 |
ccneill | we should probably add a line to the template creation documentation telling you not to do that | 21:40 |
unrahul | hehe.. when has a warning stopped anyone :D | 21:41 |
unrahul | hehe.. but yeah we should.. | 21:41 |
ccneill | hmmm... actually that brings up an interesting conundrum for my template generation script too.. it might dump actual creds into the templates it generates :X | 21:41 |
ccneill | at least when using it for keystone.. | 21:41 |
unrahul | :D.. whoa | 21:41 |
ccneill | sigh | 21:41 |
ccneill | guess I can just filter it out manually lol | 21:41 |
unrahul | :| .. i dont think that would be wise.. | 21:43 |
*** mvaldes1 has quit IRC | 21:44 | |
*** sdake has quit IRC | 21:45 | |
*** sdake has joined #openstack-security | 21:45 | |
*** sdake has quit IRC | 21:45 | |
*** sdake has joined #openstack-security | 21:46 | |
ccneill | yeah, probably best to filter out as many secrets as possible and replace them with dummy values | 21:47 |
ccneill | I'm already doing that with the X-Auth-Token header | 21:47 |
*** diazjf has quit IRC | 21:52 | |
*** diazjf has joined #openstack-security | 21:54 | |
openstackgerrit | Merged openstack/security-doc: Update to openstack-doc-tools 1.0 https://review.openstack.org/359253 | 22:12 |
*** singlethink has quit IRC | 22:13 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/anchor: Updated from global requirements https://review.openstack.org/314347 | 22:15 |
openstackgerrit | Michael Dong proposed openstack/syntribos: fixed results error and failure counting https://review.openstack.org/359463 | 22:18 |
openstackgerrit | Michael Dong proposed openstack/syntribos: fixed results error and failure counting https://review.openstack.org/359463 | 22:18 |
*** diazjf has quit IRC | 22:18 | |
*** shohel has quit IRC | 22:19 | |
openstackgerrit | Michael Dong proposed openstack/syntribos: Added config file improvements https://review.openstack.org/358856 | 22:24 |
*** mdong has quit IRC | 22:35 | |
*** elmiko is now known as _elmiko | 22:41 | |
*** sdake has quit IRC | 22:44 | |
*** sdake has joined #openstack-security | 22:44 | |
*** ibmchas_ has quit IRC | 22:49 | |
*** jass93 has joined #openstack-security | 23:08 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Fixed a trivial bug in keyboard interrupt part https://review.openstack.org/359472 | 23:10 |
*** bigdogstl has joined #openstack-security | 23:25 | |
*** bigdogstl has quit IRC | 23:29 | |
*** yuanying has joined #openstack-security | 23:30 | |
*** salv-orlando has quit IRC | 23:36 | |
*** bigdogstl has joined #openstack-security | 23:45 | |
*** bigdogstl has quit IRC | 23:50 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!