14:00:38 #startmeeting Security Team Meeting - Agenda: https://fedoraproject.org/wiki/Security_Team_meetings 14:00:39 Meeting started Thu Dec 3 14:00:38 2015 UTC. The chair is Sparks. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:00:39 Useful Commands: #action #agreed #halp #info #idea #link #topic. 14:00:39 The meeting name has been set to 'security_team_meeting_-_agenda:_https://fedoraproject.org/wiki/security_team_meetings' 14:00:42 #meetingname Fedora Security Team 14:00:42 The meeting name has been set to 'fedora_security_team' 14:00:52 #topic Roll Call 14:00:54 * Sparks 14:01:38 * Astradeus (more or less) 14:02:21 Astradeus: I feel the same way 14:05:27 * d-caf 14:05:36 mhayden: Are you here? 14:05:48 aaah, yes 14:05:50 .hello mhayden 14:05:51 mhayden: mhayden 'Major Hayden' 14:06:06 * mhayden switched to evolution this week and is getting used to its quirky calendar 14:06:56 mhayden, may gawd have mercy on you 14:07:47 Southern_Gentlem: thanks -- my work life is in MS Exchange :/ 14:08:12 mhayden: oh, I'm so sorry 14:08:28 mhayden, i am lucky that we have not had to do that yet ( i have 5 secretaries that use exchange) 14:08:52 Southern_Gentlem: ah, for some reason i thought you worked for RHT 14:09:11 sorry for sending us wildly OT, Sparks ;) 14:09:16 mhayden, i thought you came to Fudcon Blacksburg 14:09:32 ops sorry 14:09:48 nah, i couldn't make that one 14:10:00 interested to hear where fudcon will be in 2016 14:10:01 * linuxmodder here 14:10:02 mhayden: What'd I do? 14:10:04 :) 14:10:09 Okay, lets get started 14:10:13 Sparks broke bugzilla 14:10:26 #info Participants are reminded to make liberal use of #info #link #help in order to make the minutes "more better" 14:10:43 * Sparks did not broke bugzilla 14:10:45 mhayden: https://bugzilla.redhat.com/show_bug.cgi?id=1288076 14:10:59 #topic Follow up on last week's tasks 14:11:15 And by "last week" I mean a few weeks ago 14:11:21 Sparks to talk with mattdm regarding private security tickets in BZ. 14:11:26 Yep, I did this (and more). 14:11:40 #link https://lists.fedoraproject.org/archives/list/security-team%40lists.fedoraproject.org/message/FVBWBSP34J7Y5CFM4TI5BF7VIHBDXZCO/ 14:11:47 We'll talk more about this later. 14:11:55 #action pjp to give a status update on security policy in the wiki (carried over) 14:12:12 Sparks to work with PST to get our mailing list included on BZ tickets for critical and important CVEs. 14:12:43 #info Not sure we can dynamically add FST to crtical and important CVEs with the current tool set. 14:12:55 #action Sparks to figure out how FST members can get access to Fedora security bugs 14:13:04 Did I miss anything else? 14:14:03 i think that's it 14:14:45 #topic Education and Training 14:14:58 #link https://fedoraproject.org/wiki/Information_Security_Training 14:15:18 I don't think anyone has added any resources to this page, yet, but please do. 14:15:31 can we add non-free stuff? 14:15:54 #info The Information Security Training page is available to provide educational links to help people become more security literate. 14:16:08 Sparks: I had added some links regarding OWASP, but not much more than that 14:16:23 mhayden: Ummm... I'd like to keep it all free if at all possible. I want it to be easy access for people. 14:16:24 FST ? 14:16:43 mhayden: Books can be found at libraries but also can be purchased so I think they are okay. 14:16:47 linuxmodder: FST = Fedora Security Team 14:17:14 Sparks: got it 14:17:22 i added a link for STIG's 14:17:32 mhayden: Perhaps we have a separate area for non-free stuff? There are some good resources out there. 14:17:36 mhayden++ 14:17:37 Sparks: Karma for mhayden changed to 3 (for the f23 release cycle): https://badges.fedoraproject.org/tags/cookie/any 14:17:39 that would be good 14:17:49 i'd like to put a relevant SANS course in there 14:17:54 not free, but good knowledge there 14:17:58 true 14:18:02 mhayden: was justing thinking about SANS 14:18:02 * mhayden chomps on his cookie 14:18:07 nom nom nom 14:18:15 Mmmm... cookies 14:18:16 also, what about RHT's relevant security course(s) as part of the RHCA track? 14:18:20 mhayden: they do have free webinars, though often more product pitches 14:18:20 * Sparks still hasn't had breakfast 14:18:30 oh their webinars make me cry 14:18:36 mhayden: That would probably be good to add. 14:18:51 mhayden: And, really, any other Linux security training courses. 14:18:56 jsmith: moin 14:19:08 mhayden: I've seen an occasional good one like webbreachers stuff 14:19:55 Might consider adding regional/local group links/section for in person resources? 14:20:09 Local security focused meetups and such 14:20:42 Linux foundation has a few 14:20:46 d-caf: Yeah, that's a good idea, too. 14:20:50 more sysadmin ish but good 14:21:04 +1 for meetup idea 14:21:33 I know my area around DC is littered with them, i'll get some of the better ones listed 14:22:10 d-caf, we are both in the same locale (have you been to the new one on Tuesday in Adams Morgan? ) 14:22:38 d-caf: You are in DC? 14:22:49 linuxmodder: No, hadn't heard of anything in Adams Morgan 14:23:05 Sparks: Outside in the Northern Virginia area 14:23:14 d-caf: I'm in Maryland 14:23:21 Tysons /Falls Church 14:23:27 Okay, lets move on to other things... 14:23:32 Don't go into DC that much (prefer to keep my commute under 30 minutes..) 14:23:37 #topic Apprenticeship 14:23:46 And here's the really fun stuff 14:23:56 d-caf, indeed metro sucks but some good meets there 14:23:59 #link https://fedoraproject.org/wiki/Security_Team_Apprenticeship 14:24:20 will be looking to join 14:24:52 also anyone who has a minute this week looking to finish a audit /review of security guide for -docs 14:25:01 linuxmodder: Sure 14:25:13 So, the Apprenticeship page has been established. 14:25:24 It needs to be fleshed out more, though. 14:25:35 mostly the deep dive selinux stuff while I've gotten way better in the last few months some of it is still klingon to me 14:26:02 I'd like to have the Apprenticeship ready to go by 2016 14:26:14 can take a look this week Sparks wordpress and docs work has got me in groove 14:26:33 what all still needs to be setup ? 14:27:07 Well, we need to figure out the framework, the work that needs to be completed, and the certification process. 14:27:35 Are you going to setup formal "levls" of the FST? 14:27:53 level 9 dungeon master 14:28:04 mhayden: :-) 14:28:06 In the [U.S.] Navy we have PQSs that involve training and OJT which is followed by some sort of certification board that meets to review your paperwork and ask you questions. I think we should do something similar to this. 14:28:09 lol 14:28:15 that's a bunch of acronyms ;) 14:28:18 mhayden: +1 14:28:29 +1 14:28:37 at my company, we use empty cups of coffee and grey hair to figure out the levels of each security person :P 14:28:40 was thinking along the lines of apprentice/novice, normal contributors, and then those that have gotten "certified" and handle embargo stuff etc... 14:28:56 PQS == personnel qualification standards 14:29:04 OJT = on the job training 14:29:05 this gets tricky because Fedora doesn't legally exist as an entity, right? 14:29:11 thanks, Sparks 14:29:35 possible to have a tie in with sayt rhca i'm sure 14:30:00 Would prefer to keep a path that is free as in beer for people to work there way up 14:30:11 d-caf: +1 14:30:45 Though that doesn't excluce rhca as a possible alternative path to meet requirements 14:30:57 excluce/exclude 14:31:10 Well, that's more of a sysadmin thing. We're trying to work vulnerabilities. 14:32:33 make it a training path FOR rhca and the like then 14:33:00 So we need to come up with core "skills/experience" that a candidate should have 1 or more of 14:33:06 Can I get some volunteers to help put the apprenticeship together? 14:33:12 d-caf: Yes 14:33:16 donations (time or money always welcome) -- we train you to be secure / safe with option to get rhca and the like (you pay for cert ) 14:33:18 Sparks: more than willing to hel 14:33:25 Sparks, count me in 14:33:35 hel/help 14:33:36 Sparks: I can try 14:33:47 Okay, lets talk more about this on the list, then. 14:34:00 I've gone through enough certification process to have an idea of what does or doesn't work 14:34:51 Okay, moving on 14:34:54 #topic Outstanding BZ Tickets 14:35:07 #info Thursday's numbers: Critical 0 (-1), Important 36 (-5), Moderate 424 (-30), Low 145 (-33), Total 605 14:35:19 #info Current tickets owned: 80 14:35:29 +Tickets by Priority----+-------+---------+ 14:35:29 | Priority | Tickets | Owned | Unowned | 14:35:29 +-------------+---------+-------+---------+ 14:35:29 | medium | 424 | 45 | 379 | 14:35:29 | low | 145 | 13 | 132 | 14:35:31 | high | 36 | 22 | 14 | 14:35:34 | unspecified | 1 | 0 | 1 | 14:35:36 +-------------+---------+-------+---------+ 14:35:52 uh, somebody did quite much work o_O 14:36:03 Does anyone have any questions? 14:36:17 * Sparks needs to figure out the "unspecified" ticket. 14:36:25 noticed some old fedora tickets got aged out 14:36:27 what is the unspec one about? 14:36:43 with 21 going eol i assume? 14:36:47 linuxmodder: It's likely a community ticket that got started without a CVE 14:36:48 Sparks: probably another severity set but priority not 14:36:50 i think the unspec was an epel one 14:36:57 something w/RHEL 6 14:36:59 IIRC 14:37:09 d-caf: I thought we were going off of severity and not priority 14:37:14 nice :( 14:37:22 Sparks: not sure if the scritps got updated 14:37:23 oh. was thinking of the best, but yeah, i've seen the aging-out too 14:37:26 c6.4 and c7.2 only none Fedora I use 14:37:30 and we didn't get a firm consnensus 14:37:47 Yeah, the drop in tickets are likely from where F21 got EOL'd. 14:38:02 * Sparks wonders how many of those tickets should have been moved forward. 14:38:04 pardon the ignorance which scripts d-caf ? 14:38:25 The report scripts, and the links on the FST page 14:38:31 ah 14:39:03 at minimum I vote to have the scripts search on severity and priority, or just move to severity only 14:39:10 linuxmodder: https://git.fedorahosted.org/cgit/fedora-security-team.git 14:39:44 d-caf: I think just severity as the priority might change based on the priorities of the project but the severity shouldn't. 14:39:55 ...as that should be based off of the CVSS score. 14:40:01 what is the bar for priority ? 14:40:39 Sparks: true, but just in case someone miss used the tags (as there seemed to be some confusion even in our group to usage) it might be good to trigger on priority as well to catch edge cases 14:40:45 since security is all about edge cases 14:40:53 linuxmodder: The priority is usually set, by the tools, to whatever the severity is 14:41:12 which I don't see changing until EOL dates and since next is not for what 11 months that would be good idea in my book 14:41:40 d-caf: I'm just not sure how you would categorize a ticket that has mis-matched values 14:42:01 although we still run issue of user defiuned priority / real world with that dcmorton 14:42:03 d-caf, 14:42:11 * Sparks is a dolt 14:42:29 d-caf: Okay, that table is specifically "by Priority" (as indicated) 14:42:34 +Tickets by Severity-+-------+---------+ 14:42:34 | Severity | Tickets | Owned | Unowned | 14:42:34 +----------+---------+-------+---------+ 14:42:34 | medium | 424 | 45 | 379 | 14:42:34 | low | 145 | 13 | 132 | 14:42:36 | high | 37 | 22 | 15 | 14:42:39 +----------+---------+-------+---------+ 14:42:41 There's the count by severity 14:42:44 Ugh 14:42:48 can we still flag for further info like other bugs in that case tho ? 14:43:26 Yeah, so fine with both, but would update the search links on FST page to also include something like: 14:43:31 * Sparks would like to see all unowned "high" cases picked up by next week. 14:44:21 Sparks: noticed a few QEMU dropped this week, was going to pick those up but wasn't on a browser I could safely log into FAS with 14:44:34 will look today on the high pri 14:44:47 Okay, with only a few minutes left... 14:45:04 Would like to update our Bugzilla links on the FST page to pick up both high severity and priority when clicking on the respective unowned links 14:45:05 #topic Open floor discussion/questions/comments 14:45:17 d-caf: Do it 14:45:28 Okay, does anyone have anything of general interest? 14:45:30 ok, willdo 14:45:50 * Sparks is thinking about a DC meet up since there are so many people around the area that could come. 14:46:13 * Sparks also wonders if we have the budget to fly mhayden in for lunch 14:46:16 Sparks: like the idea, good pgp signing time as well ;-) 14:46:23 d-caf: +1 14:47:09 i always love the free roller coaster ride into Reagan! 14:47:17 * mhayden tightens the seatbelt 14:47:49 Everyone one should get shmocon tickets and make it a meetup and sec conference at the same time 14:47:57 that might not be a bad idea either 14:48:00 assuming they get there registration process up to speed 14:48:12 and we get enough lucky clicks 14:48:17 did the online keysigning happen and i've just missed it? 14:48:37 * d-caf already got my shmocon ticket during first round, luckily... 14:48:42 Astradeus: nope 14:48:43 shmocon++ 14:48:57 I'm never fast enough to get tickets 14:49:16 Astradeus: No one showed up for it. 14:49:17 I've been lucky and gotten tickets every years since year 2 14:49:23 d-caf: Nice 14:49:30 +1 to key signing 14:49:41 zoglesby: ^^^ 14:49:54 jsmith: I'm assuming you could come up as well? 14:50:21 Sparks: ACK! 14:50:49 Sparks, if you set one up and I miss it mentioned I'm game 14:50:54 Sparks: (Assuming the timing and my employment situation allows it) 14:52:03 Sparks: sorry for missing it :/ 14:52:23 #idea Host a FST DC Meet Up 14:52:54 Okay, does anyone have anything else? 14:53:18 You know, we could probably use the DC library for a meeting spot for a FAD. 14:53:28 They have space like that available. 14:54:10 Okay, does anyone have anything else? 14:54:46 Nope 14:55:00 will get on documentation the next few days and grab tickets 14:55:03 reading... 14:55:55 I am in! 14:56:24 Sparks: I might have a lead on another location to meet as well... 14:56:40 We could also use my office 14:56:59 They tend to be very nice about this kind of stuff 14:57:21 Ok, so apparently a lot more in this area than I knew... 14:57:37 d-caf: Yep, there are quite a few of us. 14:57:49 There's also the Red Hat space over in Tyson's 14:57:56 Sparks: I had assumed you were down in NC 14:58:02 d-caf: I used to be 14:58:12 d-caf: My heart still is. 14:58:14 Yeah, been by the Tyson's office 14:58:27 I used to live down there, still a TriLUG member 14:58:39 My office is on 14th and New York, near lots of metro stops 14:59:15 d-caf: I do miss TriLUG 14:59:43 #action Sparks to create a FST 2016 FAD page and start collecting info 15:00:02 Okay, any last minute thoughts before we run out of time 15:00:03 ? 15:00:09 s/minute/second 15:00:51 Okay, hearing none, we'll adjourn to #fedora-security-team and continue ranting there. 15:00:51 Sparks, the MLK one ? 15:00:54 Thanks everyone! 15:00:56 linuxmodder: yes 15:01:04 linuxmodder: The one with the 3D printer! :) 15:01:06 if so I CAN easily help with that 15:01:09 #endmeeting