17:00:00 #startmeeting openstack security group 17:00:01 Meeting started Thu Apr 2 17:00:00 2015 UTC and is due to finish in 60 minutes. The chair is hyakuhei. Information about MeetBot at http://wiki.debian.org/MeetBot. 17:00:02 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 17:00:05 The meeting name has been set to 'openstack_security_group' 17:00:13 Hey everyone! 17:00:20 o/ 17:00:33 yo/ 17:00:36 o/ 17:00:42 o/ 17:00:49 Hello 17:00:54 Agenda and previous minutes over here: https://wiki.openstack.org/wiki/Meetings/OpenStackSecurity#Agenda_for_next_meeting 17:01:49 Hey dg_ 17:01:53 hey 17:01:58 Looks like I’m the only person who came here an hour early! 17:02:08 =( 17:02:22 i did too lol 17:02:22 lol we all did, but chair6 pointed out we are silly 17:02:24 I was definitely here 17:02:28 hehe 17:02:39 <- not silly 17:02:39 me too, but I just wanted to be early :) 17:02:51 o/ 17:03:05 Ok, I suppose we should get started, doesn’t look like we have nkinder 17:03:44 No Travis either. 17:04:03 So I guess we can talk about the OSSN Yaml stuff later if they roll up 17:04:15 sicarie: Want to talk about the security guide? 17:04:24 Sure 17:04:25 Travis sends his apologies and asked me get an update on the Bandit gate tests in Keystone 17:04:25 #topic Security Guide 17:04:46 elmiko and pdesai are taking a look at the identity chapter 17:05:04 we're still looking at the case studies making sure they're consistent (right now, they are not) 17:05:04 Great, probably time for an update and a tidy 17:05:19 yes, the goal is to do another physical book release for Liberty 17:05:42 So I think shelleea07 and nkinder were going to look at chapters as well 17:05:44 o/ 17:05:55 If anyone wants to take a look at the Dashboard chapter, that's one that needs a bit of work 17:06:12 I'm looking at the dashboard chapter and network chapter 17:06:15 Yeah shelleea007 has an action to look at the network section 17:06:45 So please, take a chapter, log a bug, or grab a bug 17:06:47 #link: https://bugs.launchpad.net/openstack-manuals/+bugs?field.tag=sec-guide 17:07:19 The etherpad for looking at case study consistency is in the bug: https://bugs.launchpad.net/openstack-manuals/+bug/1349540 17:07:20 Launchpad bug 1349540 in openstack-manuals "Ensure one case study per chapter in security guide" [Medium,In progress] - Assigned to N Dillon (sicarie) 17:07:36 And then I'm also trying to look at the Compute chapter (creating it) and that outline is here: https://bugs.launchpad.net/openstack-manuals/+bug/1412975 17:07:36 Launchpad bug 1412975 in openstack-manuals "Security Guide - Compute Section" [Low,Confirmed] - Assigned to N Dillon (sicarie) 17:07:48 sicarie I'll have some more time to look at the case studies now 17:07:57 Great work sicarie thank you! 17:08:38 Anything else on the guide sicarie ? 17:09:11 I don't think so 17:09:17 Thanks ljfisher! 17:09:41 ok, next up 17:09:46 #topic Governance Stuff 17:10:14 Ok, so some of you may have seen the announcement around the OSSG and VMT merging: http://lists.openstack.org/pipermail/openstack-dev/2015-April/060474.html 17:10:22 I think this is great news 17:10:44 hyakuhei: +1 17:11:12 I followed that up today with https://review.openstack.org/#/c/170172 - a request to make us recognised as an official OpenStack project 17:11:30 Here’s the mail to -dev which has had a couple of +1’s already. http://lists.openstack.org/pipermail/openstack-dev/2015-April/060510.html 17:11:44 nice 17:12:49 So we’ll see how that goes but it’s very much my hope that we become simply the security team within OpenStack 17:13:34 security team as a service? ;) 17:13:48 That’s the culmination of a fair bit of behind the scene work etc 17:14:34 all driven by hyakuhei .. *round of applause* 17:14:37 good work, thanks 17:14:51 hip hip 17:14:52 * elmiko claps 17:15:07 +1 17:15:12 We’ll have to change the way we do elections to be more inline with the proper way of doing things, we’ll also have to proably do this out of sync to catch up but as discussed previously I’ve put myself down as iterim PTL 17:15:32 Any thoughts or comments on this change? 17:16:03 aside from elections, are there other responsibilities that will change? 17:16:23 seems like a good step forwards. I particuarly like the idea of security.openstack as a source for all things security 17:16:24 So there’s a great deal of work to do with regards to rebranding, making sure documentation makes sense 17:16:41 ^ exactly dg_ I’m hoping we can really make use of that 17:17:05 chair6 i think we're going to need a logo... 17:17:18 Heh. 17:17:33 ok, lets talk about OSSN for a few moments 17:17:38 #topic OSSN 17:17:48 There’s a number of OSSN in the queue right now 17:17:58 #link https://bugs.launchpad.net/ossn 17:18:38 hyakuhei: how specific should I be that OSSN's match doc guidelines? 17:18:49 hyakuhei: Not. 17:18:56 For example, 46 uses "etc" which is a doc no-no 17:18:56 k 17:19:27 At least not today. OSSN are a lot more free form than everything else, however good language is encouraged, if you see things you don’t like, comment on the gerrit, we want the standards to be high 17:19:47 Nah, that's a nit I'm not a huge fan of, but enforce on the sec-guide 17:20:05 #link https://review.openstack.org/#/c/169388/3/security-notes/OSSN-0046 17:20:41 I’d appreciate more reviews on that. 17:20:52 Ang generally, if you can, please pick up an OSSN. 17:21:01 Good way to get yourself an ATC badge too. 17:21:27 tkelsey: want to talk about Bandit? 17:21:55 yup yup 17:22:00 #topic Bandit 17:22:36 so, Travis was asking about any update on the Keystone gate, anyone have any news? 17:23:43 bknudson: ^ ? 17:25:05 I didnt see bknudson on the roll call, so maybe not 17:25:20 I guess not 17:25:22 thats a shame :( 17:25:28 oh well, next time then 17:25:30 Short meeting today even though lots of exciting stuff happening :) 17:25:47 heh yeah, seems so 17:26:10 Ok well I’ll guess we’ll roll smartly on to AOB 17:26:19 #topic Any Other Business 17:27:16 OSSG + VMT == awesome, thats all I got :) its worth mentioning again 17:27:22 :D Cheers 17:27:24 hehe, +1 17:28:02 anything summit related? 17:28:04 We’ll I guess we’ll wrap up early! Cheers guys! 17:28:21 l8z 17:28:22 sicarie: good point, anyone got summit stuff ? 17:28:34 Oh yeah, I knew there was something else :) 17:29:11 Please take a look at https://etherpad.openstack.org/p/liberty-security-summit-ideas and add content. 17:30:08 That’s for things to discuss at the summit if we manage to get some dedicated time/space 17:30:34 Other than that I think we’re done :) 17:31:01 #endmeeting