14:05:41 <lhinds> #startmeeting Security Group 23/03/2016 14:05:41 <collabot> Meeting started Wed Mar 23 14:05:41 2016 UTC. The chair is lhinds. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:05:41 <collabot> Useful Commands: #action #agreed #help #info #idea #link #topic. 14:05:41 <collabot> The meeting name has been set to 'security_group_23_03_2016' 14:05:49 <lhinds> ok, agenda: 14:05:53 <lhinds> #link https://etherpad.opnfv.org/p/opnfv-sec-meetings 14:06:26 <lhinds> #topic agenda 14:06:30 <lhinds> any additions? 14:07:27 <lhinds> #topic Security Guide 14:07:55 <lhinds> I must be frank, I have no made any new changes as yet. Been hectic as settling into a new company 14:08:04 <lhinds> Sona did you have some inputs? 14:18:30 <Sona> I updated https://jira.opnfv.org/browse/SECURITY-2 14:18:31 <Sona> I was a litlle unsecure about my contribution to the compute section 14:18:31 <Sona> I wanted to be sure what I write is relevant 14:18:31 <lhinds> I would advise, if you're not sure on any aspect, just make sure you link upstream. 14:18:31 <lhinds> this is a whole new tech, so we can't know it all and are still learning ourselves. 14:18:31 <Sona> I will add all links/ existing documentation in the issues 14:18:32 <lhinds> That's what I will be / am doing. 14:18:32 <Sona> Then we can see what is missing 14:18:32 <lhinds> sounds good 14:18:32 <Sona> ok :) 14:18:32 <lhinds> we also have the possible introduction of SCAP profiles, so they will take a seat next to the security guide 14:18:32 <Sona> I can add my text in Jira (SECURITY-2) then you guys can review and give me feedback 14:18:32 <lhinds> sure, sounds good 14:18:32 <lhinds> let me check I am watching the issue 14:18:32 <lhinds> ok, I reported so I will get a notification 14:18:33 <Sona> yes 14:18:33 <Sona> I have just worked a little with documentation 14:18:33 <Sona> I think we should keep working, as much as we can, otherwise nothing will be done :) 14:18:33 <Sona> we need this guide for LF badging Program as well 14:18:33 <lhinds> agree, I will make sure I get back on the horse next week. I have some local stuff, just need to set up repos again 14:18:34 <lhinds> ok badge program / moving on? 14:18:34 <Sona> yes, we can move on 14:18:34 <aripie> yes 14:18:34 <lhinds> #topic badge program 14:18:34 <lhinds> over to you Sona 14:18:35 <Sona> I have been updating some issues in Jira, 14:18:35 <Sona> just formatting, adding some more info 14:18:35 <Sona> I have been digging into some of them 14:18:35 <Sona> do you have Emily's email? 14:18:35 <lhinds> I asked Ray too forward this too you, lost it in my old email account 14:18:58 <lhinds> have Uli or Fatih updated any issues, or Ray Aric? 14:19:15 <Sona> yes some 14:20:47 <Sona> We need some security contact list 14:21:16 <lhinds> For the OSVM? 14:21:41 <lhinds> GPG contacts? 14:21:51 <Sona> if someone want to report sensitive information encrypted 14:22:03 <lhinds> ah ok, did you see the email I sent earlier? 14:22:37 <lhinds> you already have a GPG key Sona? 14:22:54 <Sona> yes I have 14:23:06 <lhinds> ok, so we can use mine and yours for now 14:23:06 <Sona> I can be one 14:23:14 <lhinds> +1 14:23:18 <Sona> can you or Ari be on the contact list as well? 14:23:26 <lhinds> I will be yes. 14:23:33 <Sona> good 14:23:53 <aripie> I can 14:24:19 <lhinds> ok, so when you can send me your public keys and I will add to the wiki 14:24:21 <Sona> good Ari :) 14:24:30 <aripie> will do 14:24:42 <lhinds> #action all supply GPG keys for OSVM wiki page 14:25:34 <Sona> https://pgp.mit.edu/pks/lookup?op=get&search=0x60FFAF3315BD5928 14:26:00 <lhinds> thanks! 14:26:14 <lhinds> just need to generate a new one for myself 14:26:28 <Sona> good 14:27:04 <Sona> you need to get the new one signed by some people 14:27:42 <lhinds> nah, just set up generate the keys, upload to a keyserver and set up thunderbird 14:27:43 <Sona> maybe we can have a keysignings party at OPNFV summit and sign each others gpg key 14:27:51 <lhinds> sure! good idea 14:28:02 <lhinds> #action sign each others keys 14:28:36 <lhinds> #undo 14:28:36 <collabot> Removing item from minutes: <MeetBot.ircmeeting.items.Action object at 0x30a9d90> 14:28:43 <lhinds> #action sign each others keys @ summit 14:29:03 <lhinds> shall we move on to the summit, or is there anything you want to go through before the call tomorrow? 14:29:18 <Sona> yes we can move to the summit 14:29:53 <lhinds> #topic opnfv-summit 14:30:39 <lhinds> ok, so we need to agree an outline for the talk. I think you captured it well... 14:30:55 <lhinds> LF Badge Program & Update on the Group 14:31:45 <Sona> yes, it sounds good 14:32:20 <lhinds> rgistration page: 14:32:23 <lhinds> #link http://events.linuxfoundation.org/events/opnfv-summit/attend/registration 14:32:50 <Sona> we need to clean / update OPNFV security page 14:33:20 <Sona> also work with issues in Jira as much as we can 14:33:29 <Sona> we can also mention security guide 14:33:41 <Sona> hopefully we have written alot by then :) 14:33:59 <Sona> we can encourage people to contribut 14:34:51 <lhinds> Jira issue, for the summit, or in general? 14:35:43 <Sona> jira issues for security related issues (mainly badge program & security guide) 14:36:20 <Sona> we are going to present our work, what we have done/what we are doing 14:36:47 <Sona> back to the registration 14:36:48 <lhinds> got you now..do you have public holiday Friday / Monday? 14:36:57 <Sona> yes 14:37:39 <Sona> when we register, do we need a code? 14:37:42 <lhinds> So I will try to get some text together tonight or tomorrow for the summit talk proposal and send it to you 14:38:04 <Sona> ok, good 14:38:34 <lhinds> Lets check with Ray tomorrow. I think I just submitted my talk proposal and booked hotel. 14:38:48 <Sona> ok, 14:38:50 <lhinds> if you do a talk I don't believe you need to pay for registration 14:39:02 <lhinds> unless I got a freebie 14:39:05 <Sona> please let me know when you have booked hotel 14:39:36 <Sona> I think it is good to be close to each other 14:39:44 <lhinds> sure, there is always a recommended hotel on the summit page 14:40:23 <lhinds> Intercontinental, Berlin 14:40:34 <Sona> Ari, are you going to attend the OPNFV summit? 14:40:40 <lhinds> try to get there, as you just wake up and go downstairs for the events 14:40:46 <aripie> unfortunately not 14:42:17 <Sona> next time :) 14:42:45 <lhinds> its well worth it if you can, very educational 14:43:26 <Sona> I haven't talk to my boss yet 14:44:19 <lhinds> A good way to put it to your boss, is that he gets a company representative talking as an authority under their brand 14:44:27 <lhinds> something like that :P 14:44:40 <Sona> hehe :) 14:44:51 <lhinds> k, so I think that is it for the summit, lets make the summit a weekly topic on-going nw 14:44:58 <lhinds> any more on the summit? 14:45:03 <Sona> ok, good 14:46:21 <lhinds> #topic any other business ? 14:47:29 <Sona> no, not from me 14:47:42 <lhinds> ok, thanks all. catch you on the call tomorrow Sona 14:47:47 <lhinds> #endmeeting