14:02:01 #startmeeting Security Group 01/06/16 14:02:01 Meeting started Wed Jun 1 14:02:01 2016 UTC. The chair is lhinds. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:02:01 Useful Commands: #action #agreed #help #info #idea #link #topic. 14:02:01 The meeting name has been set to 'security_group_01_06_16' 14:02:01 Hi Luke 14:02:20 #topic agenda 14:02:28 #link https://etherpad.opnfv.org/p/opnfv-sec-meetings 14:02:39 take a look all, and see if you want anything added 14:03:31 just info item on ETSI-NFV-SEC-013 14:03:55 aripie: pop it into etherpad please 14:04:02 sure 14:04:11 #topic functest 14:04:56 quick update here, my newer code was merged into master, and I just need to do some more tests before it is added as a jenkins job. 14:04:58 I added https://wiki.opnfv.org/display/security/results 14:05:28 I still hope to perform a live demo if I can (depends on the use of hardware being available) 14:05:47 that would be good 14:06:05 #topic badge program 14:06:56 over to you Sona 14:07:21 I have started to answer to questions 14:07:44 I have submitted Basics (done) 14:07:51 https://bestpractices.coreinfrastructure.org/projects/164/ 14:08:13 I think you can visit https://bestpractices.coreinfrastructure.org/projects/ 14:08:22 and search for OPNFV 14:08:28 you will see the progress 14:08:36 one question 14:08:49 regarding: The project MUST provide a process for users to submit bug reports .. 14:09:17 does OPNFV have a process for users to submit a bug report 14:09:36 I couldn't find 14:10:57 I can only find the following 14:11:01 #link https://wiki.opnfv.org/display/DEV/Developer+Getting+Started 14:11:22 oh hold on...I got it 14:11:26 #link https://wiki.opnfv.org/display/DEV/JIRA+Best+Practices+for+OPNFV 14:11:52 Maybe we should add some short text for how to send a bug report? 14:12:05 to the wiki page 14:12:15 that's what the link above does 14:12:31 Ok I can use that :) 14:12:37 another question: 14:12:50 The project SHOULD respond to most enhancement requests in the last 2-12 months (inclusive). 14:13:23 what do you think I should put here? 14:14:39 hmm, tricky, as these go upstream. I am not sure what to put there, might need to check with ray 14:15:00 paging: rpalik 14:15:15 not sure if he picks that up 14:16:01 ok 14:16:21 how about this question: The project's initial response time for any vulnerability report received in the last 6 months MUST be less than or equal to 14 days. 14:16:48 I will check if OSVM does menation days 14:17:29 you can just put 'agree' and we will adopt 14 days :) 14:17:49 ok, good :) 14:18:43 I will continue with answering to Badge questions and send you guys email if I stuck 14:18:48 I hope it is ok 14:18:57 sounds good, thanks Sona 14:19:06 ok we can move on 14:19:15 to the next topic 14:19:22 #topic Opnfv Summit Talk 14:19:38 Thanks for updating presentation 14:19:57 I will make sure my part fits in my time slot 14:20:02 Sona: you would have seen I merged your deck into mine, mainly as its a opnfv branded set I got from someone in marketing 14:20:09 I saw 14:20:27 very good, thanks 14:20:35 I think you might need to keep some slides as content for people to read afterwards (like FAQ) 14:21:01 one point, my deck might look a little long, but all the slides with the use case flow will go through quickly 14:21:06 yes, I will do 14:21:23 when do you arrive in Berlin? 14:21:41 on Sunday 14:21:57 when do you arrive? 14:22:17 Sunday too. 14:22:30 so we have time to tweak things together, before the talk 14:22:38 good, perhaps we can meet and synch a little 14:23:16 sure 14:23:35 #topic Code Audit 14:23:48 your topic Sona, did you have any questions? 14:23:58 I have look at https://wiki.opnfv.org/display/security/results 14:24:17 Is this some kind of code audit? 14:24:36 yes, languages used and modules / libaries imported 14:25:06 the idea then is we search though those to check if any have CVE's against them 14:25:20 all is only python & python modules, right? 14:25:48 there is also C and Java 14:25:59 aha , I missed that 14:26:44 can we use openscap to scan CVEs 14:27:08 for this 14:27:17 on a running system yes, but not against those files 14:27:32 its tricky to do, as we only know the names they use, not the versions. 14:28:15 not sure of what we do with the audit data, might be a good topic for at the summit when we meet with ray and co 14:29:29 ok, we can discuss this issue further in the sumit 14:29:35 is there any inventory function that could provide version information? 14:29:53 We can for instance track python vulnerabilities ex: http://www.cvedetails.com/vulnerability-list/vendor_id-10210/year-2016/Python.html 14:30:18 ... or should such a function be provided by Moon project? 14:30:21 and chech with your result database and see if OPNFV is using that module 14:31:07 I am not very familjar with moon, so I don't know if Moon can do this 14:31:37 its quite complex, and cross-checking systems will take some time. I recommend we check with the others how far they want to go with it 14:32:10 ok, agree 14:32:15 if they are very keen, then they will need to volunteer time / resources to help 14:32:37 I can help, but I need to know how :) 14:32:57 I am looking for automated, efficient way 14:33:11 not to spent hours in manual check 14:33:32 we discuss this in the summit 14:33:57 should we create a task in Jira and add topics we want to discuss? 14:34:24 an etherpad would be good 14:34:35 https://etherpad.opnfv.org/ 14:34:37 ok 14:35:34 ok..next topic 14:36:04 #topic ETSI NFV-SEC-013 draft 14:36:07 aripie: 14:36:30 Yes, there is a new rev of ETSI-NFV-SEC-013 14:36:35 #link https://docbox.etsi.org/ISG/NFV/Open/Drafts/SEC013_Sec_mgmt_and_Monitoring_Spec 14:36:54 what is new here? 14:37:29 seems to be maturing, introduces the concept of Security Controller and some new interfaces 14:38:09 and defines some prerequisites for creating trust in an NFV solution 14:38:31 ok, thanks. I will read it later 14:38:42 thanks aripie 14:38:44 also audit requirements towards the security monitoring function itself 14:39:02 yep, some of this may map to what we have beeen doing 14:39:46 that all on that front now 14:40:07 Luke, what were you refering to? 14:40:23 functest, secguide, etc 14:40:28 or something else? 14:41:22 Sona: functest scanning 14:41:37 ok, all good 14:41:50 thanks for attending all...catch you next week 14:41:51 yes, 14:42:00 unless there is AOB? 14:42:05 I created https://etherpad.opnfv.org/p/items-to-discuss-in-summit 14:42:18 thx Sona 14:42:21 to add items to discuss in the summit 14:42:34 nI am good now :) 14:42:36 thanks 14:42:45 can you share that with the email list discussing the badge program 14:42:54 yes 14:43:01 check that ray gets a room reserved too 14:43:26 so we can sit down and go through all the outstnading badge items 14:43:34 thanks! 14:43:44 ok...see you next week 14:43:54 #endmeeting