15:04:58 #startmeeting security 15:04:59 Meeting started Thu Oct 25 15:04:58 2018 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:05:00 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:05:03 The meeting name has been set to 'security' 15:05:29 * gagehugo totally didn't lose track of time 15:05:47 #link https://etherpad.openstack.org/p/security-agenda 15:05:52 o/ 15:06:10 ping eeiden fungi gagehugo lhinds nickthetait browne redrobot 15:06:14 Luzi: o/ 15:06:52 * fungi is triple-booked between board of directors call, tc office hour and this meeting, just to set expectations ;) 15:09:28 probably will be a pretty quick meeting, there was one issue in glance 15:09:34 #link https://bugs.launchpad.net/glance/+bug/1799588 15:09:34 Launchpad bug 1799588 in OpenStack Security Advisory "non-admin users can see all tenants' images even when image is private" [Undecided,Incomplete] 15:10:10 could be a policy/configuration issue, but not sure 15:10:20 Luzi: Do you have anything? 15:10:28 these meetings are usually pretty informal 15:10:33 yes 15:10:36 cool 15:10:51 you might have already read it on the ml or in some projects irc meetings 15:11:07 we want to propose Image encryption to openstack 15:11:22 this is a cross project proposal and should adress the confidentiality of images 15:12:02 This thread: http://lists.openstack.org/pipermail/openstack-dev/2018-October/135387.html 15:12:05 ?* 15:12:19 yes 15:12:40 we have already written specs for nova, cinder and glance 15:13:03 do you have links for those on you? 15:13:10 #link http://lists.openstack.org/pipermail/openstack-dev/2018-October/135387.html 15:13:17 Glance: https://review.openstack.org/#/c/609667/ 15:13:26 Nova: https://review.openstack.org/#/c/608696/ 15:13:33 Cinder: https://review.openstack.org/#/c/608663/ 15:14:43 awesome 15:14:50 it would be nice to have also input from the security side :) 15:14:58 I'll put them on the agenda so I remember to read them later 15:15:01 :) 15:15:42 thank you, it would be nice to discuss this further maybe next week or in the scurity channel :) 15:16:12 Luzi: Sure, yeah I'll try to read them over before next meeting 15:16:29 gagehugo, thanks :) 15:17:01 fungi: Not to bug you, did you have anything for this week? 15:17:10 nothing really, no 15:17:12 thanks though! 15:17:21 ok 15:17:27 just barely keeping up with all the conversations going on at once, sorry 15:17:36 fungi: heh 15:17:46 I put the links on the security agenda for Luzi's specs 15:17:56 otherwise I think we can end early 15:18:13 appreciated! 15:19:39 Luzi fungi thanks for coming! 15:19:45 #endmeeting