17:04:17 #startmeeting openstack security group 17:04:18 Meeting started Thu Oct 30 17:04:17 2014 UTC and is due to finish in 60 minutes. The chair is hyakuhei. Information about MeetBot at http://wiki.debian.org/MeetBot. 17:04:20 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 17:04:22 Stupid DST 17:04:23 The meeting name has been set to 'openstack_security_group' 17:04:26 or lack thereof 17:04:27 hi 17:04:35 hyakuhei: was wondering about the time change... :) 17:04:39 roll call :) 17:04:47 o/ 17:04:49 o/ 17:04:50 hi! 17:04:59 o/ 17:05:44 Ok, I expect this to be a short meeting, lets get started. Agenda ? 17:06:10 Summit 17:06:15 OSSN update 17:06:18 what else ? 17:06:30 tkelsey might have a Bandit update 17:06:42 i have a small question or two about preparing for audit 17:06:44 except he isn't here 17:06:53 so maybe I'll update on what he is working on 17:07:35 heh. dg__ and tkelsey joining 17:08:08 hey all, sorry i'm late 17:08:13 hey tkelsey 17:08:14 Ok, so summit, we are going to grab some space on Tuesday and basically unconference it. Relying heavily on etherpads for just about everything. 17:08:31 hyakuhei: any idea on what time? 17:08:38 I'll see what we can do lunch wise after I've scoped out the local food at the conference location 17:08:45 should we put a little more structure into our etherpad? 17:08:47 perhaps have some time slots people can sign up for? 17:09:16 Seems like an idea. I was thinking there might be some value in having short sessions 17:09:46 Also I like the idea of just having discussion topics and we'll manage time so it fits between other things 17:10:02 Physical location etc we won't know until we get there. 17:10:06 I think I'm leading a cross-project design session on Tuesday afternoon, so that's why I'd like to know what time slots we plan on for OSSG stuff 17:10:25 hyakuhei: are there official events in the sched for OSSG sessions? 17:10:31 It's all pretty loose atm 17:10:39 We are sharing the VMT design session 17:10:50 elmiko: no, nothing official other than the VMT session 17:11:00 not for lack of trying 17:11:31 Ok. So nkinder or someone else, I need someone to do some of the heavy lifting around our informal track 17:11:39 as I'm massively over-committed already this week 17:11:45 so perhaps we can use the etherpad to highlight when security sessions are happening 17:11:46 i'm not sure i have anything specific to contribute, but i am curious to learn more about OSSG process 17:11:47 like the security track in the conference 17:11:49 and the vmt track 17:11:50 informal and etherpad based is fine 17:11:52 hyakuhei: same here. I'm flying first thing tomorrow morning 17:11:58 Yeah figures. 17:12:12 TBH I'm happy with unconferencing in the morning and see how we go 17:12:17 I think many of us will be split in many directions... so having some specific times for the OSSG meetup sessions would be useful 17:12:20 The important thing is we get conversations going 17:12:29 Tuesday morning? 17:12:38 bdpayne: No objection to that, tuesday morning makes good sense 17:12:44 I think :) 17:12:50 I was just wondering which morning you were talking about above 17:12:59 bdpayne: what time? I have a 10am obligation on Tuesday 17:13:23 tuesday right after lunch is good for me (until about 3 when some of the barbican sessions start) 17:13:37 others from OSSG might be involved in those too 17:13:46 ...the joys of scheduling 17:13:47 so... let's pencil in some stuff on the etherpad Re time contraints / other stuff of interest to the group 17:13:51 and then we can find a time that works 17:14:05 we'll just need to keep checking the etherpad for the latest info 17:14:13 anyone have a link handy to the etherpad? 17:14:17 I can drop some suggestions in there later today 17:14:18 So We were looking at lunch on Tuesday, having space to follow on into might make sense 17:14:20 https://etherpad.openstack.org/p/ossg-kilo-summit 17:14:43 bdpayne: thanks 17:16:43 ok shall we move on? 17:17:17 sure 17:17:33 #topic OSSN 17:17:47 So the one DG had has been reassigned to sweston 17:17:51 Who wrote the patch :) 17:18:00 ahh sweet 17:18:21 Yeah, thanks sweston 17:18:31 anyone know why the gate exploded on this OSSN? #link https://review.openstack.org/#/c/128636/ 17:18:39 I take it dg doesn't mind... 17:18:42 tkelsey: checking 17:18:46 nkinder: thanks 17:19:53 nkinder: yeah dg is cool 17:19:54 tkelsey: looks like a sporadic failure pulling the change down from git 17:20:08 yeah ok, I'll do a recheck 17:20:11 thanks nkinder 17:20:31 tkelsey: I just kicked it with a recheck 17:21:08 tkelsey: ...and I'll re-review it. 17:21:20 tkelsey: you're still looking into the VMware driver part of it? 17:21:27 awesome, thanks. yup 17:21:39 Sweet. Anything else? 17:21:42 ok, cool. It looked pretty good, but that was the one confusing area. 17:21:57 OSSNs are quiet otherwise. Still a few in the queue that can be picked up. 17:22:40 Coolio. Don't imagine that'll change over the next 10 days or so :P 17:22:56 ok. cool. other business? 17:23:05 #topic Any Other Business 17:23:26 bandit? 17:23:47 we have working gate tests on bandit now :) 17:24:00 wootles. Can you say more about it? 17:24:21 which projects at using bandit for the gate? 17:24:27 s/at/are/ 17:24:35 none AFAIK 17:24:41 these are tests for bandit itself, not using bandit 17:24:55 the gate runs PEP8 tests and some 35 functional tests 17:25:03 tkelsey: cool 17:25:15 ah, I misread 17:25:20 still nice progress though 17:25:27 bdpayne: yeah its confusing when talking about bandit :) 17:26:00 I'll be adding more stuff as time goes by, but its nice to have working CI now :) 17:26:20 tkelsey: has been making some steady progress towards getting Bandit legit 17:27:06 well we need to get it into the global requirements list eventually, so other projects can pick it up for running as a gate test 17:28:24 so thats all I have on the subject, anyone interested should check out the code :) tmcpeak2 anything to add? 17:28:52 nope 17:29:46 cool 17:29:51 Anyone else ? 17:29:52 one more thing 17:30:01 I'm filling in some schedule details for next week 17:30:17 looks like Wed afternoon may be a good time for some additional OSSG unconference stuff 17:30:30 since we'll have limited time before the barbican sessions on Tuesday 17:30:38 Good point that'd be nice 17:30:47 so I'd encourage people to pencil that in now 17:30:48 I'm going to be doing lots of Barbican stuff this week 17:31:24 bdpayne: there are some keystone/horizon sessions starting at 3:30pm on wednesday that I want to be involved in, but before that is good for me 17:31:46 Trying to figure out how to support stronger auth methods in the dashboard 17:31:47 yeah 17:31:49 there will be conflict all week, I'm afraid 17:31:54 Yeah 17:32:05 nkinder 2fa? 17:32:27 bdpayne: well, making it generally extensible (SAML, kerberos, etc.) 17:32:34 ahh, ok 17:32:43 bdpayne: 2fa can be pretty easily done as is actually (for HOTP, etc.) 17:33:17 in some ways, yeah 17:33:18 bdpayne: ...depending what you plug in behind Keystone for LDAP. Some solutions like FreeIPA have native OTP now. 17:33:30 u2f support might need some work 17:33:47 I don't think the current 2fa stuff is very plugable 17:34:00 and then there's getting the UX right 17:34:05 alas... perhaps we are off topic now 17:34:15 ;-) 17:34:42 lol. 17:35:05 I'm really looking forward to the summit this year, going to be great to see everyone and hopefully a few new faces too 17:35:17 indeed! 17:35:24 =D 17:35:36 +1. Getting excited now 17:35:59 +1 17:36:04 my first summit heh 17:36:13 cool. 17:36:30 Ok I suppose we should all get back to packing/panicing etc :) 17:36:38 lol 17:36:38 See you guys next week! 17:36:40 i've got a couple small q's 17:36:48 go ahead elmiko 17:36:51 elmiko: yeah, you wanted to ask about auditing? 17:37:18 yea, i looked over the juno template for audit. when the kilo is ready, should we staart filling out as many details as possible for sahara? 17:37:40 elmiko: you can start filling it out anytime 17:37:44 cool 17:37:49 elmiko: it's sort of a living document 17:37:55 audit... are we talking about a crypto audit or ?? 17:38:06 bdpayne: the security info pages I started last cycle 17:38:15 bdpayne: so crypto, sensitive data handling, etc. 17:38:19 sort of a catch all 17:38:26 gotcha 17:38:49 as for high-level threat analysis, is there a starting point i could get familiar with? 17:39:19 elmiko: there are some docs that go over that process that shohel created 17:39:50 ok, cool. 17:39:56 elmiko: I think this is the latest that he is trying to get merged - https://review.openstack.org/#/c/121034/ 17:40:13 awesome 17:41:04 finally, i posted to the ML looking for some feedback on our session topics. didn't get any bites, but i have the summit version up and i'm still hungry for any feedback people have. https://etherpad.openstack.org/p/kilo-summit-sahara-integration-security 17:42:15 i realize there's some sahara specific plugin stuff on there, but i'm still learning where our vulnerability points are with respect to openstack. so really, any advice will be useful. 17:42:50 this looks nice at a quick glance 17:42:53 perhaps SSL usage should be TLS usage in this post-POODLE world ;-) 17:43:00 :) 17:43:09 bdpayne: thanks, good point! 17:43:27 we can finally get stop using SSL/TLS everywhere. 17:43:32 lol 17:43:50 although i just added SSL/TLS to the doc... /facepalm 17:44:01 that's going to be a tough acronym to kill :) 17:44:05 yea 17:44:05 indeed 17:44:34 thanks again for the help folks, i look forward to meeting up at summit =) 17:45:03 Rendez-vous à Paris! 17:45:13 oui oui! 17:45:16 TY all! 17:45:26 #endmeeting