14:00:11 #startmeeting Security Team Meeting - Agenda: https://fedoraproject.org/wiki/Security_Team_meetings 14:00:11 Meeting started Thu Feb 25 14:00:11 2016 UTC. The chair is Sparks. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:00:11 Useful Commands: #action #agreed #halp #info #idea #link #topic. 14:00:11 The meeting name has been set to 'security_team_meeting_-_agenda:_https://fedoraproject.org/wiki/security_team_meetings' 14:00:14 #meetingname Fedora Security Team 14:00:14 The meeting name has been set to 'fedora_security_team' 14:00:17 #topic Roll Call 14:00:18 * Sparks 14:01:33 .hello astra 14:01:34 Astradeus: astra 'David Kaufmann' 14:04:20 Astradeus: Do you have anything in particular to discuss? 14:04:52 yes, few things 14:04:57 hello 14:05:02 ohai :) 14:05:18 sorry running a little late 14:05:21 Sparks: in the last few meetings were a few points which you only had info 14:05:47 currently there is one issue on the mailing list (urgent packages push mechanism) 14:06:49 Okay, lets get started. 14:07:01 Astradeus: What is your topic? 14:08:19 #info Sparks is on leave this month and hasn't been following any activities. 14:08:48 i'd be interested in that fast-push-thing proposed on the mailinglist 14:09:20 esp. in opinions about that 14:09:43 and also the FAD, as it was planned to be in the beginning of march if i remember correctly 14:10:32 #topic Security FAD 14:10:57 #info We have space in DC for the Security FAD on March 4th. 14:11:12 I hope this isn't too short notice for the people that wanted to come. 14:11:33 zoglesby: Welcome! 14:11:37 hi 14:11:49 Comments? 14:11:59 yikes Friday next week... 14:12:04 Is it an all day thing? 14:12:11 times? 14:12:12 we have space, coffee, tea, soda 14:12:30 i just need to know who is coming 14:12:49 d-caf: I think the following Friday was also good with everyone. 14:12:52 i'd love to come, but for me only remotely is possible (europe..) 14:12:57 but i'd have time 14:13:13 we have a web came in the room as well fyi 14:13:53 Sparks: do you want to setup a bluejeans meeting for remote folks? 14:14:53 zoglesby: Yeah, we can do that. 14:15:35 zoglesby: Can you pass this information to the list today? 14:15:43 ...regarding the FAD 14:15:47 sure can 14:16:09 d-caf: we have space from 9-5 14:16:22 March 4th, is bad for me at this point unfortunately 14:16:22 which timezone would that be? 14:16:32 I would maybe be able to do the afternoon 14:16:33 EST 14:16:42 UTC-5:00 14:16:50 the 11th is better for me, but that depends on the group I guess 14:17:01 zoglesby: Would your space be available on the 11th? 14:17:34 we should be able to come up with something 14:18:43 would be okay for me too 14:19:58 d-caf: Is that good for you? 14:21:03 Yes, I should be able to get more time on that day, I still have to get MGMT approval 14:21:24 I know I have a all morning meeting on the 4th I can't get out of though 14:21:30 but no meetings on the 11th 14:24:35 #agreed Move the FAD to March 11th. 14:24:44 Okay, anything else on this topic? 14:25:15 i will confirm the move with work and send out an email with the info 14:25:32 zoglesby: Thank you! 14:25:47 \o/ 14:25:59 #topic Security package pushes 14:26:06 Astradeus: Okay, the floor is yours 14:26:33 zoglesby: thank you! 14:27:08 everyone familiar with the emails? 14:27:34 Astradeus: I'm not. 14:27:35 Astradeus: yes, read the ticket 14:27:46 Astradeus: Perhaps you can provide us with an executive summary? 14:28:12 link: https://fedorahosted.org/rel-eng/ticket/5886 14:28:29 Sparks: a year ago discussion was started to fast-push critical+urgent packages 14:28:29 #link https://fedorahosted.org/rel-eng/ticket/5886 14:28:38 always forget the method 14:29:19 and for the glibc-update the push to stable to be delivered to main repos took also almost a day, as it lingered in testing 14:29:27 so the discussion came up again 14:30:36 The rel-eng ticket seems to think we'd use this only a few times a year where I prefer the Debian model of 'if it's security put it there and the regular repos'. 14:31:36 I think this is going to be more than a few times a year even if it's just important/critical updates 14:31:50 we are seeing more and more crits comming out per year than we used to 14:32:00 true 14:32:22 i think the idea seems to be to drastically shorten testing time for critical updates, when a updated package is already available 14:32:58 Astradeus: Hopefully the security fix will be well tested before hand by upstream and RH. 14:34:41 exactly. i'd think that releng wants security-team to push or sign off those updates to be delivered without testing 14:35:52 i'd also prefer the solution that the security-team only signs off those updates, as almost always the maintainers just are way more informed about special cases of the respective tool 14:36:58 Wasn't this also to address the issue of maintainers of packages with critical patches who were unresponsive? 14:36:59 Astradeus: I'll follow up with pfrields on the issue. 14:37:31 That was an FST member could push though an update when the maintaner is missing in action 14:37:54 d-caf: Well, a proven-packager 14:40:00 #action Sparks to follow up with pfrields on pushing security updates 14:40:08 Anything else? 14:41:10 #topic Open Floor 14:41:17 Anyone have anything they'd like to discuss? 14:41:44 question about fedora-infrastructure: 14:42:31 does being in the fedora-team-fas-group give more information (like discussion group only available internally or something like that)? 14:43:03 there are very little forum/lists that are privates 14:43:15 or is the channel(s) + mailing list(s) the "regular" channels? 14:43:29 and those that are is because they handle things like subsidies or maintain some packages and thus may receive security-sensible bugs 14:44:02 so most things are in the open and being in FAS group will grant you more access, but not to info in the sense of lists/forums 14:44:31 okay, wasn't sure if i missed out on some topics or if just nothing happened in the mean time 14:44:34 thanks :) 14:44:55 I am aware of 1 irc channel with access restricted 14:45:04 Well if we are going to start trying to deal with embargoed security issues we need a private list 14:45:14 and it's the fedora-ops (iirc) where irc operators can coordinate their effort against trolls 14:45:42 zoglesby: these and the ones handling budgets are the only lists I know that are private/restricted 14:45:44 pingou: sounds useful 14:46:01 zoglesby: definitely. but nothing happened there so far it seems 14:46:02 Astradeus: sometime :) 14:46:07 zoglesby: we had some earlier talks about the securty email list 14:46:17 I'd like to use the PGP remailer thingy, too. 14:46:20 to deal with embargo'd tiems 14:46:22 items 14:47:12 Sparks: that discussion also seems to have been silent for some time, but I'd also see pgp-group-encryption for security@ a really important topic 14:47:54 one items related to that is figuring out the "trust" structure of who is on that list and handles those issues 14:48:22 d-caf: Just me. No one else. :) 14:48:26 lol 14:48:33 d-caf: I'll just send encrypted email to myself. 14:48:38 This is all part of the FAD converstation correct? 14:48:42 No trust issues there! 14:49:02 d-caf: yes, definitely needs to be done also. currently i'm also on security@lists.. without anyone of you really knowing me ;) 14:49:08 zoglesby: It should be discussed at FAD. 14:49:21 Sparks: sounds good :) 14:50:11 Ideally we would like more than just one person getting the security embargo alerts, incase they are on month long vacations ;-) 14:50:37 d-caf: Who would do such a thing? 14:50:56 Sparks: only a lucky few... 14:52:03 .fasinfo sparks 14:52:04 nb: User: sparks, Name: Eric Christensen, email: sparks@redhat.com, Creation: 2007-07-17, IRC Nick: Sparks, Timezone: US/Eastern, Locale: en, GPG key ID: 024BB3D1, Status: active 14:52:07 nb: Approved Groups: @gitfedora-security-team gitcsi cla_fedora cla_done sysadmin-keys @gitdocsglue cvsfedora @docs +gitfedora-wiki @gitfedora-cms fedorabugs packager @docs-publishers @gitweatheralert @docs-writers @gitamateur-radio-menus cla_fpca @gitkeysigning-party-manual @gitsecure-coding @gitcreate-tx-configuration sysadmin-hosted elections sysadmin sysadmin-docs gitpublican-fedora @security-team 14:52:36 Sparks, how would you feel about provenpackager? 14:52:46 nb: I wouldn't. I don't know what I'm doing. 14:52:47 * nb thinks it might be helpful if you could push security fixes to stuff 14:52:49 oh ok 14:52:58 * nb had confidence in you :) 14:53:04 nb: Plus we have more qualified people like jsmith 14:53:13 Sparks, when are our meetings? 14:53:17 * nb would like to get more involved 14:53:42 nb: Which meetings? 14:54:31 security team 14:54:32 nb: currently having a meeting right now 14:54:39 nb: always Thursday, 14:00 UTC 14:54:48 oh shit 14:54:54 * nb thought he was in #fedora-security-team 14:54:59 sorry 14:55:03 * nb feels like idiot :) 14:55:04 nb: no problem 14:55:31 Sparks: hey, not sure if I'm dialing back but I saw your ping earlier 14:55:33 nb: you have now attended part of your first security team meeting ;-) 14:55:36 Okay, anything else before we close for the day? 14:55:44 Sparks: have you seen the log/comment I posted in rel-eng ticket 5886? 14:55:48 there is a security-private list i think 14:56:02 stickster: Yes and I'm going to provide some feedback soon. 14:56:22 Sparks: Cool. I think we were thinking along the same lines, but happy to get you, mattdm, me together to discuss. 14:56:34 yes there is 14:56:40 not sure what it is currently used for 14:56:48 Sparks: feel free to shoot me an invitation or grab for IRC 14:56:57 stickster: Will do. 14:58:39 Okay, anything else? 14:59:54 Thanks, everyone, for coming out to play today! Catch you all next time. 15:00:00 #endmeeting