14:12:37 #startmeeting Security Group 15/06 14:12:37 Meeting started Wed Jun 15 14:12:37 2016 UTC. The chair is lhinds. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:12:37 Useful Commands: #action #agreed #help #info #idea #link #topic. 14:12:37 The meeting name has been set to 'security_group_15_06' 14:13:22 I have no had anytime to formulate and agenda, but I guess the main topic is the summit, scanning, and badge program>? 14:13:43 hi, ok with that 14:15:43 Sona: ? 14:16:00 #topic summit 14:17:24 ping Sona 14:20:33 outside of the meeting, how are you aripie ? traveling much? 14:20:57 have been, yes, just home from Madrid yesterday 14:21:06 ahh, nice 14:21:54 yes, the weather and food were great, but quite a lot of the time working 14:22:17 so not much time for tourism 14:22:45 sure, understand..its the same for me..eat late and then back to hotel to get up early again 14:22:47 hi 14:22:51 sorry :) 14:22:57 Hi Sona. thats ok 14:23:04 so topic was the summit 14:23:42 not sure if you noticed, I added some comments on your slides. Don't take them personally if they appear direct. Its just some quick bullet feedback 14:24:01 not at all, it is ok :) 14:24:14 I think on some slides they are very text heavy, and folk will not know if they should read the text on the slides or listen to you. 14:24:28 Thanks Luke 14:25:05 Have you submitted the slides? 14:25:07 I say it I got the same feedback, for the same thing, last year. 14:25:22 No, we have plenty of time, and you can replace them after as well 14:25:42 ok, good :) 14:25:45 I have still not finished myself. so mine need tidying up 14:26:11 where will you stay? 14:26:14 when do you arrive? 14:26:19 (In Berlin) 14:26:22 on Sunday 14:26:34 in which hotel :)? 14:26:54 I am in the intercontinental 14:27:02 (where the summit is) 14:27:17 the same for me 14:27:24 we can try and do breakfast together on Monday, as I get in late Sunday 14:27:42 Please use hangout or gmail to get in touch 14:27:48 sure, will do 14:28:01 ok 14:28:18 we then have two days before the talk, so we can settle into the summit and feel at home. 14:28:27 yes 14:28:40 can you attend the meeting on Tuesday? 14:28:58 what time is it? 14:29:21 let me check 14:29:59 Ray suggested 13:00-14:00 14:30:07 is it ok for you? 14:30:50 oh, thats difficult, there is a functest meeting I need to get too 14:31:52 after 3pm would be better for me. 14:31:55 ok, suggest a time 14:32:02 I will drop an email back to Ray 14:32:37 this is the design summit times https://wiki.opnfv.org/pages/viewpage.action?pageId=6819410 14:33:06 ok, 14:35:40 I had some questions about badge program I sent email to David A wheeler, I got very detailed answer very quickly :) 14:36:17 it is good to get prepared in case peope asks questions about badge p 14:36:38 when we have our presentation 14:37:00 Sona: yep that sounds good 14:37:06 ok.. 14:37:11 #topic scanning 14:38:06 any news about scannin? 14:39:15 still debugging it working int he build environment 14:39:26 I have it working manually now 14:39:43 one question 14:39:47 you can see the last run here : https://asciinema.org/a/b81awc0g7kkciwg18gku9vizr 14:40:28 does Openscap detects patches CVEs? 14:41:40 or does it only check the package versions and reports public vulnerabilities reported to that specific version? 14:43:23 I can't remember now 14:43:32 I think its patches 14:44:48 Some customers may not want to upgrade a package to address a CVE 14:45:01 they ask for a patch 14:45:30 I just wonder how Openscap detects this? 14:46:08 Some scanning tools does not detects these kind of pacthing 14:46:54 do you understand what I mean? 14:47:12 that would be distribution specific 14:47:38 for RHEL and Debian (which includes Ubuntu) they always patch from repo 14:48:15 ok 14:50:34 do you mean like applyting a C/C++ style .patch ? 14:50:52 and then make ; make install ? 14:51:18 yes 14:52:30 We are soon out of time, let's discuss this later 14:52:44 can we move on with with next topic? 14:56:07 sure 14:56:14 #topic badge 14:57:01 I added some text in the security wiki for the badge, could you please review it? 14:57:40 will do 14:57:53 thanks Ari 14:58:01 ok 14:58:39 just change anything you don't think it is appropriate or let me know so I can change it 14:58:47 anymore on the badge program Sona ? 14:59:04 no, 14:59:43 ok..so see you on Monday , if we don't speak before Sona , and catch you next week aripie 14:59:48 #endmeeting