17:01:37 #startmeeting OpenStack Security Group 17:01:38 Meeting started Thu Nov 13 17:01:37 2014 UTC and is due to finish in 60 minutes. The chair is hyakuhei. Information about MeetBot at http://wiki.debian.org/MeetBot. 17:01:40 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 17:01:42 The meeting name has been set to 'openstack_security_group' 17:02:13 if it doubt, outlook is generally always wrong.. 17:02:18 Soo. Anyone else expecting a meeting to start now ? 17:02:18 s/it/in/ 17:02:19 :) 17:02:30 yup 17:02:31 hey chair6 - ready for awesomeness? 17:02:34 y 17:02:38 always 17:02:45 ok, roll call :) 17:03:11 I'm here! 17:03:15 me too 17:03:17 present 17:03:37 Quiet meeting 17:03:40 me 2 17:03:49 What do you guys want to cover today? 17:04:10 Summit roundup from the VMT meeting 17:04:12 Metrics 17:04:17 Mailing List 17:04:31 Bandit/OSSN ? 17:05:09 sounds good, nothing new here.. 17:05:10 * mvangund is up for anything (first meeting) 17:05:29 welcome mvangund ! 17:05:38 hey people 17:05:46 ok well, I'll get started :) 17:06:09 The summit went well, there was a lot of informal meeting up 17:06:24 We didn't have the traditional OSSG lunch, everyone was just too busy 17:06:34 which is a good thing because security was everywhere at this summit 17:06:56 The summit videos are all up, security track was Monday and Wednesday 17:07:20 good stuff @hyakuhei 17:07:43 I presented on ephemeral PKI, shohel02 did awesome work on threat analysis, malini did trusted bare metal 17:07:57 nkinder had a great talk Wendesday morning 17:08:41 thats all good stuff ... one advantage of having a dedicated security track 17:08:41 We had a good VMT discussion 17:09:06 They mentioned metrics again for OSSA 17:09:21 and I suggested we apply DREAD as we're doing that in Threat Modelling 17:09:30 #link https://wiki.openstack.org/wiki/Security/OSSA-Metrics 17:09:48 Needs some tidying up and the calibration being performed, please feel free to dive in. 17:10:17 +1 for using existing model rather than building another.. :) 17:10:53 So yeh, I drafted that wiki page and welcome any fixes 17:11:15 Next up I expressed my desire to see the OSSG be officially recognised as a supporting project in OpenStack 17:11:21 Like the docs group or others 17:11:35 which will mean we operate under the same charter and follow the same conventions. 17:11:42 That too was broadly accepted 17:11:43 any pushback? 17:11:59 sweet 17:12:00 +1 17:12:22 A big part of the reason it was accepted so readily is because of the hard work everyone here has done to add value during the last release 17:12:48 nice .. is there a formal acceptance step? 17:13:05 I'm not sure, I'm discussing with people next week 17:13:21 As it may be different for 'supporting' projects 17:13:41 also they're changing the organisational structure, there might not even be 'projects' soon 17:13:53 So watch this space but it's a good step forward 17:14:43 Next up I'd like to discuss the mailing list 17:15:07 I just want to add one thing related to OSSA 17:15:10 hyakuhei what will it look like without projects? 17:15:19 Teams under different umbrellas 17:15:23 shohel02: go ahead 17:15:30 there was a tiding up work going on related to OSSA... put them together 17:15:31 https://review.openstack.org/#/c/133202/ 17:15:32 s/umbrellas/tents 17:16:27 Thanks for mentioning that shohel02 I didn't know about it. 17:16:58 Ok, so next up is the mailing list 17:17:07 related comment 17:17:11 (re OSSA) 17:17:34 Why aren't security advisories linked from http://www.openstack.org/projects/openstack-security/ 17:18:09 maybe it's a noob question... but if I go to openstack.org and click on security... I'd at least expect to find a link to current advisories 17:18:32 i think now thats the plan... to get all OSSA from a single place 17:18:44 currently there distributed through mailing list 17:18:51 Oh 17:19:01 OSSN and OSSA will be listed on security.openstack.org 17:19:06 That's going to be a thing soon :) 17:19:09 ok... I'll +1 that 17:19:14 :D 17:22:19 ok so mailing list 17:22:47 We want to continue improving visibility and bringing in more discussion 17:23:41 So the proposal is to move the OSSG discussions to the -dev mailing list 17:23:53 dev is noisy 17:24:02 We'll retain the openstack-security mailing list for our automated notifications 17:24:05 tmcpeak: it is 17:24:23 but if that's not a problem for _every_ other technical contributor it shouldn't be a problem for you 17:24:34 :) 17:24:47 benefits to be had, for sure .. i guess we can get good at using an [OSSG] or similar label? 17:25:11 Automated notifications aside the mailing list is quiet 17:25:28 Yeah, we'll just tag everything with [OSSG] 17:25:34 fair enough 17:26:42 Does it mean no one is able to send email to ossg mailing list ? 17:26:51 So this is a proposal, I'd put it on the mailing list but noone reads it ;) 17:27:03 shohel02: yeah it'll be read only for everyone but our tooling 17:27:16 So it'll still get SecImpact notifications for example 17:27:43 It will improve discussion and visibility I think 17:28:21 Any other thoughts on that? 17:29:00 nope, ok great. 17:29:07 So I'll open it for other business 17:29:12 #topic any other business 17:29:48 Tim's OSSN is looking good https://review.openstack.org/#/c/128636/ 17:30:26 welcome to the party tkelsey ! 17:30:37 Sorry im late 17:30:40 I think we are close to a wrap here :) 17:30:43 Silly outlook 17:30:48 Yeah I know 17:30:52 Anyway, anyone? 17:30:59 tmcpeak: chair6 - bandit progress? 17:31:29 it's been quiet for a while 17:31:35 tkelsey is working on unit testing 17:31:46 we'll probably hit it hard again pretty soon 17:32:00 we have some features planned, just need some cycles 17:32:07 Yeah im trying to find time for more bandit stuff 17:32:27 seems like outlook is destroying today meetings 17:32:59 +1 barthalion 17:33:00 action: rob - fix outlook? 17:33:15 lol 17:33:17 Lol please do 17:33:23 ok. Anything else to cover guys? 17:33:28 dg__ tell microsoft 17:33:59 ok well lets wrap :) 17:34:13 #endmeeting