13:55:53 #startmeeting OPNFV Security Group 13:55:53 Meeting started Wed Mar 4 13:55:53 2015 UTC. The chair is hinds. Information about MeetBot at http://wiki.debian.org/MeetBot. 13:55:53 Useful Commands: #action #agreed #help #info #idea #link #topic. 13:55:53 The meeting name has been set to 'opnfv_security_group' 13:59:42 #topic agenda bashing 14:01:28 #link https://etherpad.opnfv.org/p/opnfv-sec-meetings 14:02:45 #agree agenda bashing 14:03:10 #topic meeting minutes 14:03:26 #agree last weeks agenda 14:03:38 #topic Review Work Items 14:05:04 #topic work items - vuln mgmt 14:10:52 #link https://wiki.openstack.org/wiki/Vulnerability_Management 14:11:26 #info we discussed the existing openstack VMC Security Commitee Vulnerability process 14:11:47 #info we will have a similar process for OPNFV developed code 14:15:21 #info it is also important to have a known method to get security issues we find sent upstreamed 14:17:39 #info most of our “code” we generate is glue to script the installation, configuration, and testing of other upstream components <— what follows is that we won’t be creating very many binary artifacts that might have vulnerabilities 14:18:51 #info there may be some binary artifacts from code we create such as a vloop vm image or other vnf just for OPNFV project use 14:20:19 #info scripts could introduce security issues (configurations) 14:20:37 yes indeed 14:20:49 #agreed 14:20:55 #action to consider how we will interact (tool wise) with upstream groups 14:26:05 #info expected time for fix should be added (Mike) 14:33:38 #action Luke to continue to refine the OSVM and consider the points made about interactions and contingencies towards upstream projects 14:35:30 #topic Project Lead / Members Elections 14:40:07 #action Luke to draw up rough draft of a role / org structure for the security group 14:40:51 #agree Mike suggested that we defer elections of any sort to when more people attend 14:45:51 #info having some type of senior members to insure quality contibutions are accepted. 14:46:26 #topic irc == opnfv-security 14:47:29 #undo 14:47:29 Removing item from minutes: 14:47:49 #topic irc == opnfv-sec 14:48:53 #agree we will use the new irc channel called #opnfv-sec 14:49:08 #topic Any other business 14:52:13 #info etherpads available for each work item and can be used to reference materials relevant to the partcular work item 14:57:19 #closemeeting 14:57:50 #endmeeting