14:00:43 #startmeeting Security Team Meeting - Agenda: https://fedoraproject.org/wiki/Security_Team_meetings 14:00:43 Meeting started Thu Apr 2 14:00:43 2015 UTC. The chair is Sparks. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:00:43 Useful Commands: #action #agreed #halp #info #idea #link #topic. 14:00:46 #meetingname Fedora Security Team 14:00:46 The meeting name has been set to 'fedora_security_team' 14:00:49 #topic Roll Call 14:00:50 * Sparks 14:04:00 .hellomynameis pjp 14:04:01 pjp: pjp 'None' 14:04:20 Oh good, we have someone. 14:04:24 .fas bvincent 14:04:25 bvincent: bvincent 'Brandon Vincent' 14:04:31 Sparks: He..he...:) 14:08:09 bvincent: whas is ASU ? 14:08:15 s/whas/what 14:08:47 pjp: Largest public university in the United States by enrollment. 14:09:03 Okay, lets get going. 14:09:13 bvincent: Arizona state ? 14:09:17 Sparks: Yep, 14:09:18 pjp: Correct. 14:09:21 #info Participants are reminded to make liberal use of #info #link #help in order to make the minutes "more better" 14:09:29 #topic Outstanding BZ Tickets 14:09:39 #info Thursday's numbers: Critical 1, Important 48 (+2), Moderate 379 (+3), Low 170 (+7), Total 598, Trend +12 14:09:45 #info Current tickets owned: 169 (~28%) 14:09:49 #info Tickets closed: 249 (+2) 14:10:03 That one critical bug has been there for a while. 14:10:10 * Sparks goes to update 14:10:15 * pjp checks what it is 14:10:28 rubygem-activesupport 14:10:48 jsmith: PING 14:10:58 Sparks: PONG 14:11:17 Wow, there is -> http://fedorasecurity.com/ :) 14:11:25 * pjp didn't know 14:11:53 jsmith: Can you take a look at https://bugzilla.redhat.com/show_bug.cgi?id=905374 and see if this is something you could take care of? 14:12:36 jsmith: There appears to be a fix available from upstream. 14:12:42 Sparks: I can easily apply the patch -- but I don't know how to test, etc. 14:12:59 * Sparks shrugs. 14:13:14 I guess you can apply the patch and see who yells if it breaks something. 14:13:17 jsmith: PoC exists. 14:13:24 WORKSFORME.... I'll take care of it 14:13:36 #link http://ronin-ruby.github.io/blog/2013/01/28/new-rails-poc.html 14:17:32 #action jsmith to patch rubygem-activesupport as provenpackager (BZ 905374) 14:18:30 jsmith: Should we also start a non-responsive maintainer request as well? 14:18:38 Sparks: Please :-) 14:18:53 Who want to handle that? 14:19:45 Sparks: non responsive maintainer against rubygem-activesupport ? 14:19:51 yes 14:20:00 Sparks: okay, I'll do that 14:20:20 #action pjp to start non-responsive maintainer against rubygem-activesupport in EPEL6 14:21:24 It looks like the majority of the Important (priority HIGH) cases are owned (54 of 63) but these are the cases that should all be owned and being actively worked. 14:22:21 I'm as much at fault for letting these fester. Can we set a goal of the beginning of June to have all old (circa 2014 and before) Important CVEs completed? 14:23:56 Sparks: I think June end is good, 14:24:13 pjp: Okay, so three months. 14:24:20 Sparks: Yep, 14:25:01 #action Team Goal: All important CVEs from 2014 and before should be fixed by the end of June. 14:25:15 #action Sparks to talk about the team goal to the list. 14:25:36 #action Sparks to complete the tickets of packages removed from EPEL earlier this year. 14:26:26 Anything else for the tickets? 14:26:40 None for me, 14:27:58 #topic Open floor discussion/questions/comments 14:28:05 Anyone have anything? 14:29:11 Can I ask a question about Luks? 14:29:28 striker: Sure 14:30:08 Is it possible to have the default Luks encryption that Anaconda uses changed to a tougher cipher? 14:30:32 striker: Yes. 14:30:55 striker: Are you asking for the default cipher to be stronger or that you just want it to be on your systems? 14:31:04 striker: And what cipher do you think it's using? 14:32:59 Asking that it be stronger on the ISOs - I think the default is aes-xts-plain64? 14:33:49 striker: That is the default for cryptsetup - aes-xts-plain64:sha256 with 512-bit keys. 14:33:56 striker: on the ISOs ? 14:35:02 I am sorry - I think I misunderstood what I was looking at. 14:35:09 Apologies for the noise. 14:35:24 striker: No problem, :) 14:35:25 striker: No worries. It's good to know. 14:36:26 Anyone have anything else? 14:38:19 * pjp none 14:39:31 Okay, we'll go ahead and end. I'll try to follow up on the action items early next week before the meeting. 14:39:36 Thanks everyone. 14:39:39 #endmeeting