19:00:01 #startmeeting Infrastructure (2011-10-13) 19:00:01 Meeting started Thu Oct 13 19:00:01 2011 UTC. The chair is nirik. Information about MeetBot at http://wiki.debian.org/MeetBot. 19:00:01 Useful Commands: #action #agreed #halp #info #idea #link #topic. 19:00:01 #meetingname infrastructure 19:00:01 The meeting name has been set to 'infrastructure' 19:00:01 #topic Robot Roll Call 19:00:01 #chair smooge skvidal codeblock ricky nirik abadger1999 lmacken 19:00:01 Current chairs: abadger1999 codeblock lmacken nirik ricky skvidal smooge 19:00:05 * skvidal is here 19:00:12 .fas pingou 19:00:13 pingou: pingou 'Pierre-YvesChibon' 19:00:17 * jsmith lurks 19:00:35 * CodeBlock 19:00:41 here 19:00:46 here 19:01:14 * athmane is around 19:01:43 ok, lets go ahead and start in... 19:01:52 #topic New folks introductions and Apprentice tasks 19:01:59 here 19:02:08 any new folks want to say hi? or any apprentice tickets anyone would like to bring up? 19:02:22 hi 19:02:38 hello Smilers_ 19:02:47 nirik: There was that ticket you created for me this past week, about some slight modifications to the login screen (for password recovery) 19:03:06 jsmith: yeah, someone already commited a fix. ;) It's not live yet tho 19:03:13 Oh, that was fast :-) 19:03:47 yeah. ;) 19:04:02 Smilers_: what sorts of things are you interested in working on? or whats your background? 19:04:39 * dgilmore is here 19:04:40 My background is working with t student run computin facility (geeksoc.org) 19:04:59 cool. 19:05:12 anything from deploying LDAP to general maintenence 19:05:47 nice. Well, welcome. ;) 19:05:54 thanks :) 19:06:29 do hang out in #fedora-admin and/or #fedora-noc and chime in and ask questions, etc. 19:06:34 #topic Password/Ssh-key/Cert reset fallout 19:06:45 So, our password/key change announcement went out. 19:06:59 There was some pushback, but overall I think it's gone ok. 19:07:12 any change will get some pushback 19:07:19 'some pushback' 19:07:30 ^ 19:07:32 #info Please do change your pass and upload a new ssh key before 2011-11-30. 19:07:43 * abadger1999 here 19:07:51 so, I figure we wait a bit and start nagging people more... 19:08:01 I was wondering reading abadger1999's mail if there is/should be a more strict policy for sysadmin 19:08:16 but that's more a separate question than the current one 19:08:23 yeah... 19:08:48 I'd like to move forward with finishing yubikeys setup... and look more at one time stuff like google authenticator... 19:09:21 Is there an easy way to get stats of who has changed them and who still needs to? (just numbers is fine) 19:09:22 my key is currently 4092 bits, i plan to make the new one bigger 19:09:33 dgilmore: 16384! 19:09:44 CodeBlock: not likely that big 19:09:55 knock yourself out. ;) 19:10:22 CodeBlock: skvidal has a script to check 19:10:42 that we discovered is not including users that are not cla_done 19:10:53 b/c fas's interface doesn't return those 19:11:03 * LoKoMurdoK here 19:11:10 * LoKoMurdoK late 19:11:11 * CodeBlock will poke you after meeting for that then, I think it would be neat to watch 19:11:12 :( 19:11:14 welcome LoKoMurdoK 19:11:38 ok, if nothing else on the password reset flames, will move on... 19:11:59 #topic Upcoming Tasks/Items 19:12:25 ? - make a new bastion02/nuke bastion04 ( smooge ?) 19:12:35 ? - move app02/04 19:13:02 with those done we can retire our xen boxes that went out of warentee. 19:13:22 2011-10-25 - 2011-11-08: Final change freeze 19:13:51 I'd like to look at dumping audit messages to our syslog for epylog processing. 19:14:17 also, as a note, I will be out next thursday/friday. ;) 19:15:10 on the rel-eng side it would be nice to get kojipkgs02 and releng04 fully operational 19:15:51 anyone have other items they would like to work on/get done before final freeze. 19:16:06 Oh, yeah, another one: reinstall ppc05-10 and hand them off to secondary arch folks. 19:16:24 * StylusEater is late ... sorry 19:16:25 value move ... in 1.25 hours ;) 19:17:31 cool. 19:18:00 #topic Meeting tagged tickets: 19:18:01 https://fedorahosted.org/fedora-infrastructure/report/10 19:18:02 nirik: I've got raffle working in staging. Going to finally deploy out to prod 19:18:08 abadger1999: excellent. 19:18:18 no meeting tickets marked. 19:18:20 nirik: Also need to deploy a fas hotfix that skvidal mentioned earlier. 19:18:32 (wrt fas not returning a complete list of users) 19:18:54 abadger1999: any idea how hard it will be to add a 'clear' button for ssh key? is that an easyfix thing? or more complex? 19:19:21 nirik: Probably easy fix but I'm not entirely sure. 19:19:40 ok 19:19:56 it'll be template (to add a checkbox) and a bit of python code in a single controller method to do something when that checkbox is set. 19:20:07 cool. 19:20:16 if you think it's easy, feel free to mark that ticket easyfix. 19:20:22 so someone who can mess a tiny bit with html and knows python should be able to do it. 19:20:44 will do 19:20:54 nirik: lmacken promised me bodhi updates before freeze 19:21:31 dgilmore: ok. releng04 needs some fix to handle /usr/share/bodhi/comps/ more correctly, otherwise it might be close. 19:22:05 nirik: yeah, we need updated bodhi i believe 19:22:46 yeah 19:22:52 #topic Open Floor 19:23:02 ok, anyone have anything for open floor? 19:23:29 note somewhere to think about a policy regarding ssh key for sysadmin ? 19:23:50 pingou: you're welcome to open a discussion on the list... or we can talk some about it here. What policy would you suggest? 19:24:36 nirik: well based on what I have see/understood, some @rh need to change their ssh every x time 19:24:44 (I have 6 weeks in mind, not sure though) 19:24:59 no 19:25:03 pingou: no 19:25:05 not that I know of 19:25:19 sysadmin are a sensible group, them more than anyone else should be aware of the sensibility of ssh keys 19:25:29 id rathe be forced to use otp's 19:25:30 maybe it wasn't @rh then :) 19:25:37 I don't think forcing a change every X time is a good idea. 19:25:56 but I would like to move to yubikeys or googleauth or something like that... 19:26:02 i use my yubikey pretty much everyday 19:26:12 * nirik lost his. need to get another. 19:26:18 id rather have to use a yubikey to auth as sudo and for ssh 19:26:39 nirik: I am not sure how frequet yubikey are outside us 19:26:49 dgilmore: +1 19:26:50 well, everyone in sysadmin-main (aside from me) has a yubikey 19:26:54 but in the mean while ? 19:27:14 * dgilmore has 4 or 5 yubikeys 19:27:22 all but one person has a iOS or android device that could run googleauth 19:27:45 I dont know about all of sysadmin* 19:27:49 sysadmin or sysadmin-main 19:27:50 perhaps we should poll on the list. 19:27:57 pingou: thats just sysadmin-main... 19:27:57 nirik: personally id rather not use a service from google for auth 19:28:07 +1 there to 19:28:08 dgilmore: it doesn't use googles services. 19:28:10 but maybe its open and we can run it all ourselves 19:28:14 its open source 19:28:18 it's a pam module 19:28:22 nirik: ok, i honestly had not heard of it until just now 19:28:35 nirik: it has a server we could run? 19:28:35 downside of it is that it requires you to store a secret on the machines 19:28:46 no server, it looks locally for the secrets. 19:28:50 I'm torn as to whether the suggestion that yubikeys should be mandatory would be a good idea or fly in the face of Fedora and what it stands for... 19:28:52 ok 19:29:19 StylusEater: what about yubikeys is contrary? 19:29:24 StylusEater: there has not been such suggestions 19:29:30 StylusEater: yeah. In the case of sysadmin-main everyone has one, so we could require that for them only... 19:29:41 dgilmore: payment 19:29:56 25$ 19:30:03 StylusEater: fedora has some that can be provided 19:30:08 nirik: that's what I was thinking. 19:30:12 if cost is an issue 19:30:16 but larger groups like sysadmin or packager it would not be feasable to supply them to everyone 19:30:33 dgilmore: hrm, then maybe it would make sense to do that. As a congratulations for making it through the "ring of fire." :-) 19:30:44 nirik: right 19:30:49 nirik: +1 19:30:58 I'm all for finishing deploying yubikey as an optional... 19:31:06 nirik: we could feasibly do it for all people in groups that get sudo on boxes 19:31:09 maybe 19:31:10 nirik: with what dgilmore just mentioned I think it would be sensible to require for sysadmin-main. 19:31:14 not sure of the exact numbers 19:31:29 dgilmore: any box ? 19:31:33 including stagging ? 19:31:39 yeah. Not sure either. 19:31:41 maybe excepting public test boxes 19:31:53 pingou: staging but not public test 19:32:15 which one do you consider public? 19:32:25 http://fedoraproject.org/wiki/Test_Machine_Resources_For_Package_Maintainers -> these ? 19:32:33 pingou: no 19:33:12 pingou: the boxes labeled as public testing for developing and testing solutions to be used in fedora infra 19:33:22 ie publictestxx.fedoraproject.org 19:34:05 ok 19:34:09 pingou: the boxes referenced in that page are provided by community members for use of packagers 19:34:12 Ideally I would like to have yubikey setup for true 2 factor for those that want to use it, and add something like googleauth if we can get it setup in a way we like. Then we could require one or the other for specific groups perhaps. 19:34:19 the only tie in they have is to get the packager ssh keys to allow access 19:35:15 right. 19:35:40 so, if anyone has cycles to look at finishing yubikey deployment or seeing how we could best integrate googleauth, please do. 19:36:38 pingou: does that address your question at all? 19:36:54 nirik: it raises discussion, which was my intention :) 19:37:00 pingou: interesting topic, thanks. 19:37:18 yeah. I think moving to a 2factor setup is a good goal... 19:37:22 +1 19:37:39 * pingou considering investing $25 19:38:07 there's disadvantages to yubikey and googleauth, but advantages to both too... so I think ideally we will want to look at supporting either or. 19:38:30 or something like either 19:38:37 nirik: +1 19:39:02 supporting either, enforcing one over another in some cases I guess :) 19:39:50 yeah 19:40:09 ok, anything further? or shall we call it a meeting? 19:40:59 * nirik will close out in a minute if nothing more 19:41:46 * skvidal reads backscroll 19:41:55 * nirik waits 19:42:08 * dgilmore has nothing 19:42:46 nirik: I have a non-meeting question I'll ask in another channel. 19:42:51 StylusEater: ok. 19:42:57 * skvidal has nothing additional 19:43:04 thanks for coming everyone! 19:43:07 #endmeeting