15:00:24 #startmeeting security 15:00:24 Meeting started Thu Mar 21 15:00:24 2019 UTC and is due to finish in 60 minutes. The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:00:25 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:00:28 The meeting name has been set to 'security' 15:00:40 ping fungi gagehugo lhinds nickthetait browne redrobot 15:00:52 #link https://etherpad.openstack.org/p/security-agenda agenda 15:01:14 ohai 15:01:24 \o 15:02:19 o/ 15:02:44 o/ 15:04:02 hey fungi redrobot Luzi 15:04:46 igau' 15:04:49 *ohai 15:05:17 Only got a couple things on the agenda for today 15:05:29 https://bugs.launchpad.net/nova/+bug/1816727 15:05:31 Launchpad bug 1816727 in OpenStack Compute (nova) "nova-novncproxy does not handle TCP RST cleanly when using SSL " [Medium,In progress] - Assigned to melanie witt (melwitt) 15:05:39 was made public recently 15:06:08 #link https://launchpad.net/bugs/1816727 nova-novncproxy does not handle TCP RST cleanly when using SSL 15:06:45 thanks fungi 15:07:06 this was classified as a security hardening opportunity, since the impact is assumed to be roughly the same as someone intentionally opening a lot of connections to the service and not closing them cleanly 15:07:55 it's more just a fix to avoid people using certain kinds of load balancer health checks from unintentionally dos'ing their novnc 15:09:03 it's still recommended to have some sort of rate limiting/mitigating proxy in front of the service anyway, as it's not really robust in the face of intentional attacks 15:11:25 i didn't really have anything else to say on that one 15:12:25 ok, thanks again fungi 15:12:49 #topic Denver Summit 15:13:12 * gagehugo is bad about remembering to do the topics 15:13:23 So I reserved a room for 1 day at the summit for the security sig 15:13:42 once the schedule gets made I can send out an email to the mailing list 15:13:56 (just a heads up, i added something else to the agenda now) 15:14:12 :) 15:14:32 #topic ossa-2019-001 15:14:45 #link https://security.openstack.org/ossa/OSSA-2019-001.html OSSA report 15:15:14 OSSA-2019-001: Unsupported dport option prevents applying security groups 15:15:21 patch up! 15:15:30 it's our first ossa of the year 15:15:58 and patches made available by the neutron devs all the way back to stable/ocata 15:18:26 nice 15:18:50 fungi anything else? 15:19:45 not on my end 15:20:01 #topic open discussion 15:20:12 Anyone have anything they want to bring up? 15:20:32 #link https://etherpad.openstack.org/p/DEN-securitysig-topics 15:20:41 ^ if anyone has a topic for the summit session or PTG 15:21:31 otherwise I have nothing else for this week 15:25:37 thanks for coming everyone! 15:25:39 have a good weekend 15:25:43 #endmeeting