18:00:17 #startmeeting Openstack Security Group 18:00:18 Meeting started Thu Mar 28 18:00:17 2013 UTC. The chair is hyakuhei. Information about MeetBot at http://wiki.debian.org/MeetBot. 18:00:19 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 18:00:21 The meeting name has been set to 'openstack_security_group' 18:00:40 Good Morning/Afternoon/Evening everyone. 18:00:57 Any agenda items you'd like adding while we wait for a few more folks to join? 18:01:00 quit 18:01:41 ok, we'll give it about a minute then get started 18:02:16 #topic OSSG meetup 18:02:55 So it looks like we're going to meet up for food/beer on the Monday night of the summit, we need to have a rough idea of how many people are coming. 18:03:11 4 from APL 18:03:26 great, there'll be 2-3 from HP. 18:04:20 Ok, I'll send an email around to get a better idea on headcount. 18:04:50 #action hyakuhei to gather headcount for food. 18:05:14 #info I'll see what we can do about HP sponsoring the group meal 18:05:23 #topic Mailing List 18:05:42 We now have a super-shiny 'OpenStack Official' mailing list! 18:06:02 #info Go subscribe: http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-security 18:06:39 For discussions on topics within OpenStack that require a strong security focus or issues that should be brought to the attention of the security community within OpenStack. Home of the OpenStack Security Group and a central point for co-ordinating security projects. 18:07:23 This list should also receive any 'security' tagged bugs that come in 18:07:41 Any thoughts/comments on this before we move on? 18:07:42 $chan.usercount 18:08:03 Ok, exciting stuff. 18:08:13 #topic OpenStack Security Notes 18:08:49 As you probably know we maintain a list of 'Security Notes' like advisories. 18:09:04 They speak to common configuration issues, insecure 3rd party software and other fun stuff 18:09:21 #link https://launchpad.net/osn 18:10:00 We need ideas and content for a few more of these. Would anyone like to finish the Keystone OOM DoS one? 18:10:11 If not I'll do it tomorrow. 18:10:30 Quiet room today... 18:11:00 #action hyakuhei publish Keystone DoS OSN. 18:11:24 #topic OpenStack Summit 18:11:37 So we already touched on the summit with regard to everyone meeting up. 18:11:58 It strikes me that there are a bunch of interesting topics that we should probably make some progress on before the summit. 18:12:14 such as? 18:12:26 Perhaps some online presentations or walkthroughs for some of the more difficult issues, Volume Encryption being one. 18:12:32 The KeyManager being another 18:12:44 Summit sessions aren't particularly long afterall 18:13:10 true 18:13:32 And while all the content may be in the ML, reading those threads is an art in iteslf. 18:13:38 there isn't a lot of time before the summit itself, however, not sure how technically deep we'd be able to get 18:14:03 ML? 18:14:33 MailingList 18:14:49 Thanks 18:14:52 So last summit, because of the mixed audience, I found crypto discussions went nowhere fast. 18:15:13 With everyone who'd ever used certificates having an opinion. 18:16:22 #action hyakuhei to provide online meeting space, presentation and telecoms for anyone wanting to demo/preview/walkthrough content with the OSSG before the summit 18:16:39 Anyone else want an action while I'm handing them out? 18:16:59 #topic Hardening Guide 18:17:39 So thanks to Kieth for migrating the Hardening guide over to Markdown 18:17:45 #link https://github.com/hyakuhei/OSSG_Hardening_Guide 18:18:06 That should make contributing far less painful. I think I'll rm the .tex files soon 18:18:42 Bryan had mentioned engaging in a documentation sprint to try and drive forward progress on the guide. Any thoughts on that? 18:19:36 #topic AoB 18:19:48 while I can't speak for everyone, it would be hard for us to travel to attend a documentation sprint 18:19:55 I think it's a good idea, but I don't think we can contribute 18:19:57 us = APL 18:20:27 Fair enough, well if a few of us can get some core documentation down then it should make it easier to contribute around the edges. 18:21:15 Ok, so lets do a quick roll-call. Who's here ? 18:21:43 <- HPCS 18:22:54 #link http://lists.openstack.org/pipermail/openstack-dev/2013-March/007023.html 18:22:55 <- HPCS 18:23:07 There was an email thread on HSM. I thought it was interesting. 18:23:20 <- APL 18:24:41 Yeah, I did wonder if anyone had comments on the HSM stuff 18:25:03 low attendance today it seems 18:25:07 I've been wondering about cloud HSM for a while, kind of thinking VPC with rack affinity and some nasty bridging. 18:25:20 Yeah, I guess a lot of people are taking a long weekend. 18:25:45 Well, we've got a few actions. Shame they're all against me. 18:25:58 Anyone got anything they'd like to bring up? 18:26:16 Are you thinking of doing demos next week or the following week? 18:26:50 Can do any time, the sooner the better I suppose. Can provide a 'virtual room' which lets you present and an audio bridge with various international dial-ins. 18:27:25 OK, just wondering because summit is not far away. 18:27:40 Will you send an email out about how to set one up or how should we coordinate? 18:28:06 Sure, I'm just offering because with the volume encryption and key management discussions will barely get started in the 40-minute windows available. 18:28:14 I'll send a mail around the new ML 18:28:36 Similarly, you can reach out to me directly robert.clark@hp.com if you're interested in doing something 18:29:13 Cool. I think it will be a good idea to discuss these items more. 18:29:27 Great, progress! 18:29:48 Ok, I guess that'll do it for today. Any last-minute items? 18:30:10 #endmeeting