14:00:46 #startmeeting Security Team Meeting - Agenda: https://fedoraproject.org/wiki/Security_Team_meetings 14:00:46 Meeting started Thu Jun 9 14:00:46 2016 UTC. The chair is Sparks. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:00:46 Useful Commands: #action #agreed #halp #info #idea #link #topic. 14:00:46 The meeting name has been set to 'security_team_meeting_-_agenda:_https://fedoraproject.org/wiki/security_team_meetings' 14:00:49 #meetingname Fedora Security Team 14:00:49 The meeting name has been set to 'fedora_security_team' 14:00:51 #topic Roll Call 14:00:52 * Sparks 14:02:41 .fas linuxmodder 14:02:41 linuxmodder: linuxmodder 'Corey W Sheldon' 14:02:52 laggy connect today fyi 14:03:30 * zoglesby is here 14:03:57 .hello mhayden 14:03:58 mhayden: mhayden 'Major Hayden' 14:04:28 .fas jtaylor 14:04:29 jtaylor90: jraytay 'Jason Taylor' - jtaylor '' - jtaylor0175 'Jeffrey Scott Taylor' 14:04:45 lol there is more than one of me 14:06:48 jtaylor90: That's just scary 14:06:53 zoglesby: You here today? 14:06:57 jsmith: ^^^ 14:07:04 yes, I even said so 14:07:09 Yes, yes you did. 14:07:18 #chair linuxmodder mhayden jtaylor90 zoglesby 14:07:18 Current chairs: Sparks jtaylor90 linuxmodder mhayden zoglesby 14:07:24 I think I .hello nb 14:07:26 oops 14:07:29 .hello nb 14:07:30 nb: nb 'Nick Bebout' 14:07:36 howdy nb 14:07:41 * mhayden just sent out this week's stats 14:08:04 * linuxmodder looks in tb for email 14:09:19 that's alot of unowned NEW 14:10:22 Okay, I want to skip over all the meeting stuff and go straight into the meat of the meeting. 14:10:28 #topic Apprenticeship 14:10:35 zoglesby: Where are we on this? 14:11:15 We have a plan, it needs but into action, and I think we need to talk about how to do that. 14:11:30 Okay, lets talk 14:11:32 It is my opinion that this has stalled because we did not have a clear next step 14:12:41 zoglesby: What do you propose? 14:13:12 I don't have a good answer, or I would have just started to do it. 14:13:55 maybe we need a ginnie pig 14:14:05 * Sparks eyes nb 14:14:13 and by that I mean guinea pig 14:14:36 a guinea pig to test out the process? 14:14:41 yes 14:15:16 Sparks, hello 14:15:29 you were eying me? 14:15:38 missed that what we talking about atm? 14:15:52 guinea pigs 14:16:07 I would be willing to be a guinea pig 14:16:07 GP for what exactly? 14:16:09 they are cute, we want them. Not to eat 14:16:27 For testing the Apprenticeship process out 14:16:33 c0mrad3, you around ? 14:16:37 skamath, same 14:16:47 I can be a GP then 14:17:46 I am not saying no, but it would be best to have someone who was not a part of the setup of the process doing it. 14:17:58 hi, sorry for being late 14:19:43 zoglesby: Okay, looks like we have a few takers here. 14:20:37 sorry, trying to find the wiki page 14:21:18 Okay, if you want to be a guinea pig, please start working on the items on https://fedoraproject.org/wiki/Security_Team_Apprenticeship 14:21:30 At next weeks meeting we will talk about it. 14:21:41 Can I now get a list of people who are going to do so? 14:22:10 zoglesby: me 14:22:43 ! 14:22:50 zoglesby, I'm in 14:24:46 i can look at it again, but it's not really something i can solve as a task - i've already looked at most of the linked documents 14:24:53 but i'll do that until next meeting 14:25:11 #action linuxmodder and jtaylor90 to test the Fedora Security Apprenticeship training and report back next week 14:25:18 beat me to it 14:25:27 zoglesby: Sorry, I can undo it so you can do it. 14:25:32 no 14:27:15 zoglesby: Okay, anything else on this topic? 14:27:29 Nope, I think that is it. 14:27:42 Great, thanks. 14:27:46 zoglesby++ 14:27:58 linuxmodder++ 14:27:58 Sparks: Karma for linuxmodder changed to 15 (for the f23 release cycle): https://badges.fedoraproject.org/tags/cookie/any 14:28:00 any specific metrics or feedback Sparks zoglesby on the Apprentice track? 14:28:05 jtaylor90++ 14:28:21 linuxmodder: Yes, does it make you feel prepared. 14:28:22 :) 14:28:28 beyond the obvious this has dead link or needs clarity 14:30:14 linuxmodder: Did you see my comment? 14:30:19 yes 14:30:29 about preparedness 14:31:22 Okay 14:31:25 Moving on 14:31:28 #topic Windows/OS X Tools in F25 14:31:40 #link https://fedorahosted.org/fedora-security-team/ticket/1 14:31:43 #link https://fedorahosted.org/fedora-security-team/ticket/1 14:31:48 I dropped the ball on this one... 14:31:59 I need some input from others on this. 14:34:23 In the ticket? 14:35:18 Not signing binaries for any platform is not acceptable in my book. 14:35:52 If it costs a little money, Red Hat makes a lot of that. (and I am sure they have code signing keys already that could be used) 14:36:03 zoglesby: Right, and what about building them offsite (not in FP infrastructure)? 14:37:18 I don't think doing it at someones desk is a good idea, but I am sure we can find a way to deal with it. 14:37:35 mattdm: You around? 14:37:39 The issue is that it can't be built on Linux for windows correct? 14:37:46 I'm not sure. 14:38:53 14:35:26 koji supports windows natively and it may be possible for to use mingw to cross somplie if they switch to c++ 14:39:18 Well, that sounds like a rewrite of the software. 14:39:59 https://github.com/lmacken/liveusb-creator 14:40:16 python and pyqt 14:41:03 is the old FedoraUSBCreator not still a go for Windows? 14:41:04 what infra you thinking Sparks ? 14:41:06 for offsite build 14:41:09 https://bugzilla.redhat.com/show_bug.cgi?id=1310542 14:41:18 So I guess the overarching question for us is what should we enforce. Everything should be signed and for things to be signed it needs to be built in-house. That sound good? 14:41:33 cross compile is possible but security wise a utter pita and mess 14:41:47 Sparks: no 14:41:48 its presently in py yes? 14:41:55 I don't think we have the resources for a code review. 14:42:13 I am okay with using a 3rd party build infra for this item. I am not okay with using someones desktop pc for it 14:42:13 linuxmodder: I'm trying to think more generally than this specific piece of software. 14:42:47 I'm not sure we can validate the binary if we don't build it ourselves. 14:42:54 s/can/should 14:43:16 As long as infra can have people checking in on the build system (or us) I think it is okay to use something else for this. Doing it on a PC at someones home/work means they are the gatekeeper. 14:43:48 I would like to find out what the actual build process is. 14:44:10 zoglesby: Can you add these comments to the ticket? 14:44:39 Its python and pyqt. I can't think you need to build on windows for that. My reading is that koji has no support for it. 14:45:07 If that is the case I say they do it on a VM in fedora infra. 14:45:14 Sparks: sure 14:46:41 done 14:47:09 Okay, we're running a bit late... Lets just skip to the end. 14:47:10 #topic Open floor discussion/questions/comments 14:47:13 Anyone have anything? 14:48:13 only that hour has gone by very slow 14:48:24 heh 14:49:25 Anyone else? 14:51:00 Okay, lets go ahead and secure the meeting, then. Everyone have a good day! 14:51:35 #endmeeting