Thursday, 2024-04-18

*** mhen_ is now known as mhen01:10
opendevreviewMatúš Jenča proposed openstack/keystonemiddleware master: Support Redis and Redis Sentinel Cache  https://review.opendev.org/c/openstack/keystonemiddleware/+/91587207:57
*** jph5 is now known as jph10:15
*** jph6 is now known as jph12:45
lajoskatonaHi, a dumb question, we run through the security-guide, and found a strange check for the user:group setting for the services14:38
lajoskatonai.e.: for keystone the suggestion is to have keystone:keystone for cfg file for example ( https://docs.openstack.org/security-guide/identity/checklist.html#check-identity-01-is-user-group-ownership-of-config-files-set-to-keystone )14:38
lajoskatonabut for other (non-keystone) services to have root:<service-name> user:group setup: https://docs.openstack.org/security-guide/networking/checklist.html#check-neutron-01-is-user-group-ownership-of-config-files-set-to-root-neutron14:39
lajoskatonaDo you know  if there is some deeper for me unknown reason for this difference?14:41
lajoskatonajust for reference these parts of the docs were set in these patches: https://review.opendev.org/c/openstack/security-doc/+/204435  & https://review.opendev.org/c/openstack/security-doc/+/24038514:43
*** jph1 is now known as jph23:37

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!