14:03:16 #startmeeting OPNFV SEcurity Group 02/12/2015 14:03:17 Meeting started Wed Dec 2 14:03:16 2015 UTC. The chair is lhinds. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:03:17 Useful Commands: #action #agreed #help #info #idea #link #topic. 14:03:17 The meeting name has been set to 'opnfv_security_group_02_12_2015' 14:03:40 so agenda..I have the following 14:03:53 #topic agenda 14:04:01 1. OPNFV Security Guide 14:04:08 2. CI Badge Program 14:04:15 3. Inspector 14:04:21 4. Any other business 14:04:30 Anyone have any additions? 14:05:11 I have been looking at containers 14:05:16 did we conclude something on Moon earlier, i remember there was some discussion but have forgotten... 14:05:54 yes, we agreed to not merge inspector, as inspector was upstream, and it might end up being just a vehicle for moon to get things done upstream 14:06:26 so we keep it seperate, and of course moon would be welcome to use inspector as a project to get audit changes happening upstream 14:06:33 right, now I recall 14:06:40 moon is mainly all in its own repo now 14:06:55 ok, no need for agenda item on that 14:07:15 #info agreed agenda 14:07:27 #topic OPNFV Security Guide 14:08:24 ok, so I have a lot of stuff to push up to gerrit, so more content. 14:08:57 Sona is getting set up well, and so things are progressing there. I have been on IRC to help Sona get set up, so I can do the same for you aripie if you prefer 14:09:28 Also we get some good input from iben which I will go through 14:09:35 Thanks Luke 14:09:37 I have it cloned and sphinx works for me 14:09:42 ah good! 14:10:15 sphinx works for me too 14:10:44 so I know you have an interest in working on networking Sona. Could i recommend, you draw up what details of what you would like to cover? 14:11:13 you can use etherpad.opnfv.org/p/security-guide 14:11:31 and aripie, have you thought about what topics you would like to work on? 14:11:53 logging, monitoring, audit to start with 14:11:57 well I have looked at compute security :) 14:12:15 fine aripie, sounds good 14:12:17 have been looking at hypervisory vs containers security/performance 14:12:29 what part do you need most help? 14:12:54 Sona, wit you at enea, compute would be a good math 14:13:02 /s/math/match 14:13:09 I am not very good at writing, but I can review and give some input 14:13:14 thats ok! 14:13:30 how would you mean by performance? 14:14:14 #agreed aripie> logging, monitoring, audit to start with 14:14:47 containers are faster, easier than hypervisors ... 14:15:38 I would hold fire on that just for now, as containers are not in opnfv at the moment. 14:16:06 good topics for compute, are how to harden the hypervisor. 14:16:06 ok 14:16:21 yes, that is also good to look at 14:16:41 how to make hypervisor secure 14:16:48 so its good to frame everything under 'I am a customer, I have deployed this OPNFV platform, ahhhh! how to I make this platform secure' 14:16:53 Sona, yep 14:17:22 So SELinux (MAC / DAC) controls, patching, good Linux OS security - that sort of deal. 14:17:42 ok, I will focuse only to hardening hypervisor to start with 14:17:43 Or AppArmor, so the ubuntu peeps don't get upset as well :) 14:18:03 sure, I can help a lot there as well, as I have been focused on that area for a while. 14:18:14 we also have some very good stuff around. 14:18:40 introspection is a nicely controversial topic, too 14:18:53 what would also be good, is to chat with the KVM team, and see if there is anything new, that OPNFV brings into KVM that needs security consideration 14:19:09 agree, aripie, but can anyone do that yet? 14:19:27 not properly as far as I know 14:19:48 certainly can have a mention though, that could be under a 'if compromised' 14:20:02 #info lhinds> what would also be good, is to chat with the KVM team, and see if there is anything new, that OPNFV brings into KVM that needs security consideration 14:20:24 when I say KVM team, I mean the OPNFV KVM project 14:20:40 I think there might be someone from enea on there as well? 14:21:17 I will check 14:22:07 sounds cool, so just keep in mind, we are going for pragamtic advise that ops can pick up and use, more then thought leadership / cutting edge 14:22:52 ok.. 14:23:02 #topic Badge Program 14:23:26 so I spoke with the TSC yesterday, and they agreed to go for the linux foundation security badge program 14:23:43 #link https://www.coreinfrastructure.org/programs/badge-program 14:23:52 I spoke about this last week. 14:24:13 will be looking for volunteers here, as we will be driving this in the security group 14:24:27 have a read on what its about and will send out an email shortly. 14:24:31 I am interested 14:24:46 if you already have any questions, do please ask away. 14:25:33 i understood from LF CII that they also solicit input for the badges initiative, so if we feel something is weird or missing, we should indicate 14:26:05 yes, very much...its an opensource project, so we can push to them as well. 14:26:49 was there any ambition level statement on badges in TSC? 14:27:22 thinking in terms which projects come first etc 14:28:11 it will be an overall badge for the whole opnfv 14:28:28 understood 14:28:31 so projects will align, based on us putting the criteria into place 14:29:11 we are not that many so cannot simultaneously support many projects 14:29:20 so makes sense to focus on the criteria 14:29:57 yep, and Aric will help as well, for implementing some of the CI stuff (like code scanning) release changes etc 14:30:15 #topic inspector 14:30:36 quick note, I have to leave a little ealier again, but will be back online as well shortly 14:30:43 so I put myself as acting for now 14:31:08 thanks 14:31:08 I also rebuilt a celiometer based devstack instance, so I will try and get those two jira issues closed. 14:31:40 I will then work out what can be done next, I just need to align internally, as we have IPR checks and stuff, as I expect all you do as well. 14:32:09 yes 14:32:26 i think maybe, we start to look at opendaylight again 14:32:34 lets see, I should know more soon 14:33:21 and of course its very open for anyone to raise a jira issue, as acting PTL I won't try to gatekeep or reject (unless its something insanely out of scope, like 'replace keystone') 14:33:42 mmm... nice idea 14:33:46 what should we specificly look at in opendaylight? 14:34:03 Sona, check out the inspector wiki page. 14:34:11 its about audit contributions upstrea 14:34:14 *m 14:34:22 it is the gaps in auditability we are most interested at this stage 14:34:25 ok, I just need to pop out.. 14:34:36 I won't hash the meeting as ended yet 14:34:41 ok 14:34:47 so feel free to keep going, or raise new topics. 14:35:01 I will be about 25 mins (got to get my daughter from school) 14:35:11 right 14:35:20 ok, I need to go soon as well 14:36:37 Ari, can you explain a little about audit contributions? 14:36:39 Sona: you can check this 14:36:43 #link https://etherpad.opnfv.org/p/inspector_preliminary 14:37:25 and 14:37:29 #link https://wiki.opnfv.org/requirements_projects/inspector 14:38:30 Thanks Ari, I will need these 14:38:50 we aim to bridge the gap in upstream projects regarding audit capabilities by identifying the gaps 14:39:07 and then possibly contributing with code to bridge the gaps 14:39:40 also 14:39:44 #link https://jira.opnfv.org/secure/Dashboard.jspa 14:40:09 and 14:40:13 #link https://gerrit.opnfv.org/gerrit/inspector 14:41:09 I will read these, thanks 14:43:11 Ari, I need to go, I will look at hypervisor security until next week 14:44:08 OK, I will stay if Luke has something more when back 14:44:11 bye now 14:44:20 bye 15:16:02 ok, back now! 15:16:08 #endmeeting