14:05:41 #startmeeting Security Group 23/03/2016 14:05:41 Meeting started Wed Mar 23 14:05:41 2016 UTC. The chair is lhinds. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:05:41 Useful Commands: #action #agreed #help #info #idea #link #topic. 14:05:41 The meeting name has been set to 'security_group_23_03_2016' 14:05:49 ok, agenda: 14:05:53 #link https://etherpad.opnfv.org/p/opnfv-sec-meetings 14:06:26 #topic agenda 14:06:30 any additions? 14:07:27 #topic Security Guide 14:07:55 I must be frank, I have no made any new changes as yet. Been hectic as settling into a new company 14:08:04 Sona did you have some inputs? 14:18:30 I updated https://jira.opnfv.org/browse/SECURITY-2 14:18:31 I was a litlle unsecure about my contribution to the compute section 14:18:31 I wanted to be sure what I write is relevant 14:18:31 I would advise, if you're not sure on any aspect, just make sure you link upstream. 14:18:31 this is a whole new tech, so we can't know it all and are still learning ourselves. 14:18:31 I will add all links/ existing documentation in the issues 14:18:32 That's what I will be / am doing. 14:18:32 Then we can see what is missing 14:18:32 sounds good 14:18:32 ok :) 14:18:32 we also have the possible introduction of SCAP profiles, so they will take a seat next to the security guide 14:18:32 I can add my text in Jira (SECURITY-2) then you guys can review and give me feedback 14:18:32 sure, sounds good 14:18:32 let me check I am watching the issue 14:18:32 ok, I reported so I will get a notification 14:18:33 yes 14:18:33 I have just worked a little with documentation 14:18:33 I think we should keep working, as much as we can, otherwise nothing will be done :) 14:18:33 we need this guide for LF badging Program as well 14:18:33 agree, I will make sure I get back on the horse next week. I have some local stuff, just need to set up repos again 14:18:34 ok badge program / moving on? 14:18:34 yes, we can move on 14:18:34 yes 14:18:34 #topic badge program 14:18:34 over to you Sona 14:18:35 I have been updating some issues in Jira, 14:18:35 just formatting, adding some more info 14:18:35 I have been digging into some of them 14:18:35 do you have Emily's email? 14:18:35 I asked Ray too forward this too you, lost it in my old email account 14:18:58 have Uli or Fatih updated any issues, or Ray Aric? 14:19:15 yes some 14:20:47 We need some security contact list 14:21:16 For the OSVM? 14:21:41 GPG contacts? 14:21:51 if someone want to report sensitive information encrypted 14:22:03 ah ok, did you see the email I sent earlier? 14:22:37 you already have a GPG key Sona? 14:22:54 yes I have 14:23:06 ok, so we can use mine and yours for now 14:23:06 I can be one 14:23:14 +1 14:23:18 can you or Ari be on the contact list as well? 14:23:26 I will be yes. 14:23:33 good 14:23:53 I can 14:24:19 ok, so when you can send me your public keys and I will add to the wiki 14:24:21 good Ari :) 14:24:30 will do 14:24:42 #action all supply GPG keys for OSVM wiki page 14:25:34 https://pgp.mit.edu/pks/lookup?op=get&search=0x60FFAF3315BD5928 14:26:00 thanks! 14:26:14 just need to generate a new one for myself 14:26:28 good 14:27:04 you need to get the new one signed by some people 14:27:42 nah, just set up generate the keys, upload to a keyserver and set up thunderbird 14:27:43 maybe we can have a keysignings party at OPNFV summit and sign each others gpg key 14:27:51 sure! good idea 14:28:02 #action sign each others keys 14:28:36 #undo 14:28:36 Removing item from minutes: 14:28:43 #action sign each others keys @ summit 14:29:03 shall we move on to the summit, or is there anything you want to go through before the call tomorrow? 14:29:18 yes we can move to the summit 14:29:53 #topic opnfv-summit 14:30:39 ok, so we need to agree an outline for the talk. I think you captured it well... 14:30:55 LF Badge Program & Update on the Group 14:31:45 yes, it sounds good 14:32:20 rgistration page: 14:32:23 #link http://events.linuxfoundation.org/events/opnfv-summit/attend/registration 14:32:50 we need to clean / update OPNFV security page 14:33:20 also work with issues in Jira as much as we can 14:33:29 we can also mention security guide 14:33:41 hopefully we have written alot by then :) 14:33:59 we can encourage people to contribut 14:34:51 Jira issue, for the summit, or in general? 14:35:43 jira issues for security related issues (mainly badge program & security guide) 14:36:20 we are going to present our work, what we have done/what we are doing 14:36:47 back to the registration 14:36:48 got you now..do you have public holiday Friday / Monday? 14:36:57 yes 14:37:39 when we register, do we need a code? 14:37:42 So I will try to get some text together tonight or tomorrow for the summit talk proposal and send it to you 14:38:04 ok, good 14:38:34 Lets check with Ray tomorrow. I think I just submitted my talk proposal and booked hotel. 14:38:48 ok, 14:38:50 if you do a talk I don't believe you need to pay for registration 14:39:02 unless I got a freebie 14:39:05 please let me know when you have booked hotel 14:39:36 I think it is good to be close to each other 14:39:44 sure, there is always a recommended hotel on the summit page 14:40:23 Intercontinental, Berlin 14:40:34 Ari, are you going to attend the OPNFV summit? 14:40:40 try to get there, as you just wake up and go downstairs for the events 14:40:46 unfortunately not 14:42:17 next time :) 14:42:45 its well worth it if you can, very educational 14:43:26 I haven't talk to my boss yet 14:44:19 A good way to put it to your boss, is that he gets a company representative talking as an authority under their brand 14:44:27 something like that :P 14:44:40 hehe :) 14:44:51 k, so I think that is it for the summit, lets make the summit a weekly topic on-going nw 14:44:58 any more on the summit? 14:45:03 ok, good 14:46:21 #topic any other business ? 14:47:29 no, not from me 14:47:42 ok, thanks all. catch you on the call tomorrow Sona 14:47:47 #endmeeting