15:01:27 #startmeeting security 15:01:28 Meeting started Thu Oct 4 15:01:27 2018 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:01:29 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:01:31 The meeting name has been set to 'security' 15:01:49 #chair lhinds 15:01:49 Current chairs: gagehugo lhinds 15:02:04 ping eeiden fungi gagehugo lhinds nickthetait browne redrobot 15:02:10 howdy 15:02:12 heyo 15:02:15 o/ 15:02:16 agenda: https://etherpad.openstack.org/p/security-agenda 15:02:27 * redrobot is only half here... also in an IRL meeting. 15:03:32 efried: I don't see why we don't just have trait:HPET=require in the flavor extra specs? 15:03:48 jaypipes: move to -nova pls 15:03:59 #topic ossa/ossn 15:04:02 why add some magic "if I see hw:hpet extra spec, then create a trait:HPET=require" automatically? 15:04:33 https://bugs.launchpad.net/keystone/+bug/1795800 was made public yesterday I believe 15:04:33 Launchpad bug 1795800 in OpenStack Identity (keystone) "Username enumeration via response timing difference" [Undecided,New] 15:05:17 ah yes 15:06:48 getting the timings to match up was deemed not an easy task 15:07:24 #topic Documentation 15:07:55 I think doug pushed some tox changes to the security-doc repos 15:08:23 https://review.openstack.org/#/q/status:open+project:openstack/security-doc+branch:master+topic:python3-first 15:10:00 #topic Threat Analysis Docs 15:10:16 Same 3 are up for review 15:10:47 #topic general discussion 15:11:02 fungi nickthetait redrobot do you guys have anything? 15:11:07 no 15:12:05 other than that new security hardening bug you linked for keystone, nothing from me 15:12:07 thanks! 15:12:23 also the two cinder potential ossa public bugs we mentioned last week still need some help 15:12:55 fungi: Not sure I'm aware of those. 15:13:16 https://bugs.launchpad.net/cinder/+bug/1784871 15:13:16 Launchpad bug 1784871 in OpenStack Security Advisory "ScaleIO (thin) volumes contain previous data (follow-up to 1699573)" [Undecided,Confirmed] 15:13:45 gagehugo: Ah, thanks! 15:14:01 https://bugs.launchpad.net/cinder/+bug/1714858 15:14:02 Launchpad bug 1714858 in OpenStack Security Advisory "Some APIs don't check the owner policy" [Undecided,Incomplete] 15:14:31 one of them looks like it probably needs us to issue an advisory? less sure about the other one 15:14:45 fungi: ack, I'll look them over 15:15:05 (us being members of the vmt, but assistance from other interested parties is also welcome since they're public reports) 15:16:23 Is anyone going to be in Berlin? 15:17:27 next summit is little over a month away 15:18:07 I cant :'( 15:18:34 I don't think I will be either unfortunately 15:21:48 If no one else has anything, we can end early 15:22:01 give back a few mins 15:23:20 Thanks everyone, have a good weekend! 15:23:24 #endmeeting