*** salv-orlando has joined #openstack-security | 00:00 | |
*** alex8653 has quit IRC | 00:02 | |
*** alex8653 has joined #openstack-security | 00:04 | |
*** salv-orlando has quit IRC | 00:06 | |
*** liverpooler has joined #openstack-security | 00:11 | |
*** salv-orlando has joined #openstack-security | 01:02 | |
*** salv-orlando has quit IRC | 01:06 | |
*** liverpooler has quit IRC | 01:30 | |
*** browne1 has joined #openstack-security | 01:57 | |
*** browne has quit IRC | 02:00 | |
*** salv-orlando has joined #openstack-security | 02:02 | |
*** salv-orlando has quit IRC | 02:07 | |
*** alex8653 has quit IRC | 02:51 | |
*** salv-orlando has joined #openstack-security | 03:03 | |
*** salv-orlando has quit IRC | 03:08 | |
*** nicolasbock has quit IRC | 03:32 | |
*** salv-orlando has joined #openstack-security | 04:04 | |
*** salv-orlando has quit IRC | 04:09 | |
*** salv-orlando has joined #openstack-security | 05:05 | |
*** salv-orlando has quit IRC | 05:07 | |
*** salv-orlando has joined #openstack-security | 05:07 | |
*** AlexeyAbashkin has joined #openstack-security | 05:46 | |
*** Alexey_Abashkin has joined #openstack-security | 05:47 | |
*** AlexeyAbashkin has quit IRC | 05:51 | |
*** Alexey_Abashkin is now known as AlexeyAbashkin | 05:51 | |
*** AlexeyAbashkin has quit IRC | 05:55 | |
*** AlexeyAbashkin has joined #openstack-security | 05:55 | |
*** vds has joined #openstack-security | 06:00 | |
*** AlexeyAbashkin has quit IRC | 06:02 | |
*** AlexeyAbashkin has joined #openstack-security | 06:03 | |
*** dikonoor has joined #openstack-security | 06:26 | |
dikonoor | HI all , I am trying to understand if OpenStack works in FIPs mode.. well..I sort of know the answer to this. FIPS does not support algorithms like md5 to be used and OpenStack uses md5 and libraries that use md5 all over the place | 06:29 |
---|---|---|
*** pcaruana has joined #openstack-security | 06:33 | |
dikonoor | So the question is more of - Have there been any discussions and are these any plans on ensuring that OpenStack is FIPS compliant? | 06:35 |
*** browne1 has quit IRC | 06:38 | |
*** pcaruana has quit IRC | 06:50 | |
*** pcaruana has joined #openstack-security | 07:06 | |
*** rcernin has quit IRC | 07:17 | |
*** jaosorior has joined #openstack-security | 07:21 | |
*** tesseract has joined #openstack-security | 07:27 | |
*** edmondsw has joined #openstack-security | 07:36 | |
*** edmondsw has quit IRC | 07:41 | |
*** tesseract has quit IRC | 07:53 | |
*** tesseract has joined #openstack-security | 07:56 | |
*** pcaruana has quit IRC | 08:56 | |
*** pcaruana has joined #openstack-security | 09:07 | |
dikonoor | fungi: could you respond to my above query if you get a chance? | 09:58 |
*** AlexeyAbashkin has quit IRC | 10:11 | |
*** nicolasbock has joined #openstack-security | 10:30 | |
*** salv-orlando has quit IRC | 10:33 | |
*** salv-orlando has joined #openstack-security | 10:34 | |
*** salv-orlando has quit IRC | 10:38 | |
*** salv-orlando has joined #openstack-security | 10:40 | |
*** AlexeyAbashkin has joined #openstack-security | 10:46 | |
*** AlexeyAbashkin has quit IRC | 10:51 | |
*** AlexeyAbashkin has joined #openstack-security | 10:52 | |
*** v12aml has quit IRC | 11:18 | |
*** v12aml has joined #openstack-security | 11:19 | |
*** liverpooler has joined #openstack-security | 12:20 | |
*** atoth has quit IRC | 12:29 | |
*** atoth has joined #openstack-security | 12:29 | |
*** liverpooler has quit IRC | 12:36 | |
*** liverpooler has joined #openstack-security | 12:37 | |
*** liverpooler has joined #openstack-security | 12:38 | |
fungi | dikonoor: as far as i know the biggest "offender" is swift. it uses md5 as a means of indexing chunks of data, not in an integrity or security capacity, and so there has been some resistance to what is seen as needless "protocol worship" for lack of a nicer term | 12:51 |
fungi | i think there's a general lp bug covering remaining use of md5 in official projects; i'll see if i can find it real quick | 12:52 |
fungi | still not turning up the blanket bug (if we ever had one) | 13:03 |
fungi | keystone/horizon dropped md5-based token hashing 3-4 years ago, looks like | 13:07 |
fungi | glance stopped signing image checksums (opting for signing the image content directly) over a year ago, but may still generate md5 checksums of images? regardless, signatures checking is encouraged instead of relying on comparing checksums there | 13:09 |
fungi | as for fips specifically, i have no idea. i've been out of the standards compliance industry for nearly a decade now, so i'll let someone else here weigh in on that. i haven't _heard_ of anyone working on documenting fips-compliant deployment/configuration options or tracking related bugs/specs but we have a lot of contributors and users at usa federal government agencies and contractors so | 13:14 |
fungi | presumably there is interest in it | 13:14 |
dikonoor | fungi: well..I was trying out of OpenStack on a FIPS compliant system and ran into a bunch of errors specifically around md5 | 13:38 |
dikonoor | fungi: there are lots of places where md5 still gets used , in many cases indirectly.. | 13:38 |
fungi | i expect a lot of those can be worked around, but documenting them all is probably the first step in documenting the various solutions for them | 13:39 |
*** edmondsw has joined #openstack-security | 13:51 | |
*** dave-mccowan has joined #openstack-security | 13:55 | |
*** dave-mccowan has quit IRC | 13:59 | |
*** dave-mccowan has joined #openstack-security | 14:01 | |
*** salv-orlando has quit IRC | 14:11 | |
*** salv-orlando has joined #openstack-security | 14:12 | |
*** salv-orlando has quit IRC | 14:16 | |
*** atoth has quit IRC | 14:36 | |
*** AlexeyAbashkin has quit IRC | 14:38 | |
*** dave-mccowan has quit IRC | 14:42 | |
*** dave-mccowan has joined #openstack-security | 14:43 | |
*** dave-mcc_ has joined #openstack-security | 14:46 | |
*** dave-mccowan has quit IRC | 14:48 | |
*** atoth has joined #openstack-security | 14:51 | |
*** browne has joined #openstack-security | 15:07 | |
*** pcaruana has quit IRC | 15:11 | |
*** salv-orlando has joined #openstack-security | 15:12 | |
*** salv-orlando has quit IRC | 15:17 | |
*** AlexeyAbashkin has joined #openstack-security | 15:29 | |
*** jaosorior has quit IRC | 15:35 | |
*** gyee has joined #openstack-security | 15:36 | |
*** browne1 has joined #openstack-security | 15:38 | |
*** browne has quit IRC | 15:40 | |
*** salv-orlando has joined #openstack-security | 16:13 | |
*** salv-orlando has quit IRC | 16:18 | |
*** dikonoor has quit IRC | 16:22 | |
fungi | adding https://launchpad.net/bugs/1734320 to the potential ossn watchlist | 16:44 |
openstack | Launchpad bug 1734320 in neutron "Eavesdropping private traffic" [High,Triaged] | 16:44 |
*** salv-orlando has joined #openstack-security | 17:09 | |
*** tesseract has quit IRC | 17:09 | |
*** vds has quit IRC | 17:27 | |
*** nickthetait has joined #openstack-security | 17:30 | |
*** AlexeyAbashkin has quit IRC | 17:43 | |
*** browne has joined #openstack-security | 17:52 | |
*** browne1 has quit IRC | 17:55 | |
*** salv-orlando has quit IRC | 17:55 | |
*** salv-orlando has joined #openstack-security | 17:56 | |
*** salv-orlando has quit IRC | 18:01 | |
*** salv-orlando has joined #openstack-security | 18:08 | |
*** vds has joined #openstack-security | 18:31 | |
*** salv-orlando has quit IRC | 18:50 | |
*** Jabb3rW00k13 has joined #openstack-security | 18:57 | |
*** salv-orlando has joined #openstack-security | 18:59 | |
*** Jabb3rW00k13 has left #openstack-security | 18:59 | |
*** vds has quit IRC | 19:40 | |
*** nickthetait has quit IRC | 20:59 | |
*** salv-orlando has quit IRC | 21:37 | |
*** salv-orlando has joined #openstack-security | 21:38 | |
*** salv-orlando has quit IRC | 21:42 | |
*** salv-orlando has joined #openstack-security | 21:42 | |
*** edmondsw has quit IRC | 22:06 | |
*** dave-mcc_ has quit IRC | 22:07 | |
*** salv-orlando has quit IRC | 22:41 | |
*** salv-orlando has joined #openstack-security | 22:42 | |
*** salv-orlando has quit IRC | 22:46 | |
*** liverpooler has quit IRC | 22:48 | |
*** lbragstad has quit IRC | 22:51 | |
*** nicolasbock has quit IRC | 23:25 | |
*** edmondsw has joined #openstack-security | 23:40 | |
*** salv-orlando has joined #openstack-security | 23:42 | |
*** edmondsw has quit IRC | 23:45 | |
*** liverpooler has joined #openstack-security | 23:46 | |
*** salv-orlando has quit IRC | 23:46 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!