Thursday, 2019-05-23

*** gyee has quit IRC00:04
*** markvoelker has joined #openstack-security00:50
*** ricolin has joined #openstack-security01:36
*** irclogbot_0 has quit IRC02:26
*** irclogbot_2 has joined #openstack-security02:30
*** batshadow has joined #openstack-security03:21
*** batshadow has quit IRC04:47
*** Luzi has joined #openstack-security06:02
*** tesseract has joined #openstack-security06:41
*** rcernin has quit IRC07:00
*** markvoelker has quit IRC07:03
*** markvoelker has joined #openstack-security07:03
*** pcaruana has joined #openstack-security07:07
*** markvoelker has quit IRC07:08
*** trident has quit IRC08:04
*** trident has joined #openstack-security08:05
*** markvoelker has joined #openstack-security09:04
*** ricolin has quit IRC09:15
*** markvoelker has quit IRC09:38
*** markvoelker has joined #openstack-security10:35
*** markvoelker has quit IRC11:08
*** dave-mccowan has joined #openstack-security11:33
*** markvoelker has joined #openstack-security11:59
*** Luzi has quit IRC12:54
*** dave-mccowan has quit IRC13:12
*** dave-mccowan has joined #openstack-security13:15
*** ricolin has joined #openstack-security13:49
*** pcaruana has quit IRC14:10
*** pcaruana has joined #openstack-security14:29
*** dave-mccowan has quit IRC14:52
*** dave-mccowan has joined #openstack-security14:53
gagehugosecurity SIG meeting in ~5 minutes14:54
*** macza has joined #openstack-security15:38
*** abhi89 has joined #openstack-security16:07
abhi89Hi All.. i recently observed that webob.dec is logging http request info as INFO in log files of various openstack services.. the request contains token also..16:08
abhi89we can always set the permissions of the log files to be very restrictive, but isn't it a bad practice to log the token info in log files.. its still a risk right!16:09
*** pcaruana has quit IRC16:09
gagehugoyeah, logging tokens to file isn't great16:10
abhi892019-05-23 02:58:08.717 3466 INFO webob.dec [req-xxx 2c9 db5f1545fbxxxa57 74e00bcc61b24a9489b261d279432a57] {'self': <wsgify at 70366983656144 wrappi        ng <bound method FaultWrapper.__call__ of <xx.api.middleware.fault.FaultWrapper object at 0x3fff962e3550>>>, 'args': (<function start_re        sponse at 0x3fff96317500>,), 'kw': {}, 'req': {'HTTP_X_FORWARDED_SERVER': 'xx', 'SCRIPT_NAME': '/v1.0', 'REQUEST_ME        THOD': 'GET',16:11
abhi89'PATH_INFO': '/server_data', 'SERVER_PROTOCOL': 'HTTP/1.0', 'QUERY_STRING': 'all_tenants=True&include_names=True', 'HTTP_X_AUTH_TOKEN        ': 'gAAAAABc5kSAe6tUgRTio4xxxxxxxxxxxAErvDey5ZCiFQx6Hp8eJy-geqnI9DgJsVd7yLG4TX        gm6NDXd6a0ygbiC0VhImSC-3pcm0NYxRDVIWChC4wxxxxxxOzXBpWGEBS2c2cHer_Q6t6zE6XVw-b3fWu_hgp-U5Ppj_nR6C', 'HTTP_USER_AGENT':middleware', 'HTTP_CONNECTION': 'Keep-Alive', 'REMOTE_PORT': '39356', 'SERVER_NAME': '127.0.0.1'16:11
abhi89gagehugo: can something be done about this! may be a bug16:11
*** gyee has joined #openstack-security16:16
gagehugothis is on INFO right?16:16
gagehugokeystoneclient redacts tokens in the header: https://github.com/openstack/python-keystoneclient/blob/master/keystoneclient/session.py#L16816:23
gagehugoso this kinda sounds like webob16:23
*** abhishek has joined #openstack-security16:32
abhishekgagehugo: may be.. i think that INFO is getting logged from webob library itself.. but i can't find where exactly16:33
*** abhi89 has quit IRC16:33
gagehugohmmm ok16:33
abhishekgagehugo: can anything be done to resolve it or we just have to live with it!16:36
gagehugoavoid logging INFO to file for now I would assume is a band-aid, or have something redact it16:37
abhishekgagehugo: yes, we can just avoid the INFO logging for webob objects.. any idea where exactly this is getting logged in code in webob? i tried to find but no luck..16:41
gagehugohmm16:46
abhishek i will open a LP bug for this.. we can discuss more there..16:51
*** ricolin has quit IRC16:55
*** pcaruana has joined #openstack-security17:00
*** abhishek has quit IRC18:05
*** tesseract has quit IRC19:05
*** pcaruana has quit IRC20:47
gagehugofungi nickthetait redrobot: https://etherpad.openstack.org/p/security-sig-newsletter from today's meeting20:52
gagehugowas thinking about sending it out each Friday20:53
redrobotgagehugo, I like it.20:58
fungiabhishek seems to have disappeared, but if they return i suspect webob.dec log verbosity can be adjusted with standard python logging configuration21:02
fungigagehugo: you might put the vmt report section before the open bugs list, since the latter is likely to be lengthy21:02
fungialso, consider making it a monthly newsletter if it's going to be sparse and non-time-sensitive. might be less work overall?21:03
fungibut can always start out weekly and then switch to biweekly or monthly later if warranted21:03
*** macza has quit IRC23:03
*** rcernin has joined #openstack-security23:19
*** batshadow has joined #openstack-security23:25
*** batshadow has quit IRC23:39
*** trident has quit IRC23:51
*** trident has joined #openstack-security23:53

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!