14:01:46 #startmeeting Security Group 25/05/2016 14:01:46 Meeting started Wed May 25 14:01:46 2016 UTC. The chair is lhinds. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:01:46 Useful Commands: #action #agreed #help #info #idea #link #topic. 14:01:46 The meeting name has been set to 'security_group_25_05_2016' 14:01:49 Hi 14:01:59 Hi 14:02:05 #topic agenda 14:02:11 #link https://etherpad.opnfv.org/p/opnfv-sec-meetings 14:02:31 anyone want to add / change anything in the agenda? 14:02:55 badge program 14:03:04 that's in there 14:03:23 all good 14:03:44 #topic functest 14:04:40 Been hard at this the past couple of weeks. I now have the tool running in the Apex deployment, and about to check the next load of code in today / tomorrow I expect 14:05:08 by tool, do you mean openscap? 14:05:08 means it will be available for sharing at the OPNFV Summit. Might do a recorded demo even. 14:05:14 Sona, yep. 14:05:21 very good :) 14:06:02 It quries all the overcloud nodes using nova api ,and the scans them all, downloading html reports to the opnfv dashboard 14:06:15 so will OpenSCAP check for compliance & scan vulnerabilities ( CVEs)? 14:06:18 s/quries/queries 14:06:23 Sona, yes 14:06:41 how often is this running? 14:07:16 everytime jenkins does a build 14:07:25 sounds good 14:07:29 well done 14:07:48 excellent 14:07:53 where can I see the result? 14:07:58 yep, its good to have our own project developed. 14:08:12 I have an early prototype..one minute 14:09:05 #link https://asciinema.org/a/8ynzgzr4c293filqscvgkstyu 14:09:21 not the final version, an earlier one, so its been made better since then 14:10:16 thanks :) 14:11:02 I think the next project will be scanning security groups to check the rules are correct. 14:11:24 Can Openscap do that? 14:12:04 I will use the python nmap library to do that 14:12:16 and a small vm I expect 14:12:45 do we need to have a security policy? 14:13:28 that will be set in nova / openstack - when you create a VM, you assign a security group to the vm. 14:13:39 which then pushes the logic to iptables. 14:14:01 I see 14:14:27 so we will pull out the rules set in nova (allow / deny - egress / ingress) and then do a nmap scan to insure the ports really are closed. 14:15:03 very goos 14:15:07 ok.. 14:15:14 #topic badge program 14:15:14 who will run nmap? 14:15:24 Sona, programatcally 14:15:30 will call it inside code 14:15:51 aha 14:16:01 good 14:16:02 http://xael.org/pages/python-nmap-en.html 14:17:29 it seems good progress on security functest front 14:18:49 yep. its nice to have something out there 14:19:17 so badge test, I have not had much time to look into this...has much progress been made? 14:19:33 not much 14:19:58 I went through all tsks yesterday and send email to everyone 14:20:23 I saw that. I really do plan to give it a good look over end of this week / early next week. 14:20:37 try and get as much ticked off as we can before the summit 14:20:39 I hope to get some feedback from everyone 14:20:49 if not, we can grab those concerned at the summit 14:20:58 yes :) 14:21:06 aric will do a lot when you sit down with him. 14:21:19 we have done progress 14:21:42 maybe we should get a room / slot reserved to go over all this in person 14:21:55 that would be good 14:22:23 I think if we have right people, we can just finish most tasks/stories 14:22:51 we can focus on badge program next week 14:24:46 just sent an email about getting a room reserved so we can all sit round a table and hack through the list 14:24:59 thanks 14:25:02 how is it going with PTL questionnaire? 14:25:02 np 14:25:17 anymore on badge p? 14:26:01 one question 14:26:09 sorry, just seen that 14:26:14 about seurity-19 14:26:35 https://jira.opnfv.org/browse/SECURITY-19 14:26:45 PTL Q, I need to tweak my script...kvm project has over a thousand libraries 14:26:57 wow 14:27:03 but I will kill that off as I look at my tasks this week 14:27:33 no more on badge p 14:27:34 yep, they pretty much copied the kernel tree for kvm. so we can likely ignore most of it 14:28:01 #topic Opnfv Summit Talk 14:28:21 we need to start with our presentation slide 14:28:24 mainly for you and me Sona. I guess we have a bout three weeks. 14:29:09 for the timing, I thought we could leave 10 minutes at the end for questions..and we can work out how much we both need when we are nearer having are slides complete. 14:29:26 how long do we have total 14:29:31 1 hour I think 14:29:40 let me chec 14:29:44 ok, good 14:30:29 I think it is good to start with presentation slide as soon as possible 14:30:42 30 minutes 14:31:08 we have 30 minutes for the talk 14:32:02 yep 14:32:07 should we have one slide? I think it is better with one slide 14:32:46 one single slide, or one shared slide deck? 14:33:33 one single slide 14:33:40 you start 14:34:06 and at the end I can 5-10 min talk about badge program 14:34:26 short description about what badge program is, back ground and then update of OPNFV badge p 14:34:26 ok sounds good. we can then do questions 14:34:32 yes 14:35:01 ok, I will get to work on the google hosted deck you shared 14:35:15 I will also show a demo of the security scan as well.# 14:35:23 ok, check if it is good 14:36:05 if you want to write from start, please go ahead and do it :) 14:37:12 ok 14:37:27 shall we move to next topic? 14:37:45 yes 14:37:58 #topic TIA NFV Security Group 14:38:18 What does TIA mean? 14:39:08 Telecommunications Industry Association (TIA) 14:39:51 They have started a NFV Security sub-team which I got pulled into. I am there for red-hat, but also as a PTL of this group/ 14:40:01 aha :) 14:40:18 So far the plan is to do stuff like an infographic, but they also might get involved here. 14:40:22 good for you :) 14:40:30 #link https://www.sdxcentral.com/articles/news/tia-nfv-security-group-reflects-carriers-open-source-worries/2016/04/ 14:40:52 you can give us some update 14:41:00 what is going on there 14:41:33 sure 14:42:02 thanks 14:42:03 ok, final topic 14:42:08 #topic outreach 14:42:24 been trying to think what we can do to attract more members. 14:42:42 maybe there is something we could do that the summit 14:42:58 open to ideas here, so have a think about it 14:43:07 could maybe do some press stuff 14:43:23 yes 14:45:15 ok, i think we are done. 14:45:27 yes 14:46:09 thanks for your time. Sona I will contact you on google talk about badge program 14:46:20 thanks 14:46:21 also I am always online in here (freenode) 14:46:26 bye 14:46:32 see you aripie Sona 14:46:37 #endmeeting