Security Team meeting minutes

Eric Christensen sparks at fedoraproject.org
Thu Oct 8 14:42:19 UTC 2015


======================================================================================================
#fedora-meeting: Security Team Meeting - Agenda: 
https://fedoraproject.org/wiki/Security_Team_meetings
======================================================================================================


Meeting started by Sparks at 14:00:11 UTC. The full logs are available
at
http://meetbot.fedoraproject.org/fedora-meeting/2015-10-08/fedora_security_team.2015-10-08-14.00.log.html
.



Meeting summary
---------------
* Roll Call  (Sparks, 14:00:16)
  * Participants are reminded to make liberal use of #info #link #help
    in order to make the minutes "more better"  (Sparks, 14:07:19)

* Follow up on last week's tasks  (Sparks, 14:07:26)
  * ACTION: Sparks to add "issues" to fedora-meeting-report on github
    (Sparks, 14:07:43)
  * ACTION: Sparks to talk with mattdm regarding private security
    tickets in BZ.  (Sparks, 14:07:54)
  * ACTION: FabioOlive to create a room for Fedora in appear.in, for
    videoconfs.  (FabioOlive, 14:21:38)

* Outstanding BZ Tickets  (Sparks, 14:22:54)
  * ACTION: Sparks to fix his script OR figure out how to make mhayden's
    script work  (Sparks, 14:23:31)
  * LINK:
    https://lists.fedoraproject.org/pipermail/security-team/2015-October/000375.html
    (mhayden, 14:24:18)
  * Thursday's numbers: Critical 0 (0), Important 43 (0), Moderate 418
    (+10), Low 150 (-3), Total 611  (Sparks, 14:26:14)
  * Current tickets owned: 88  (Sparks, 14:26:22)

* Handling embargoed issues  (Sparks, 14:28:22)

* Open floor discussion/questions/comments  (Sparks, 14:31:01)
  * ACTION: pjp to write up a security policy on the wiki for discussion
    (Sparks, 14:35:58)

Meeting ended at 14:40:34 UTC.




Action Items
------------
* Sparks to add "issues" to fedora-meeting-report on github
* Sparks to talk with mattdm regarding private security tickets in BZ.
* FabioOlive to create a room for Fedora in appear.in, for videoconfs.
* Sparks to fix his script OR figure out how to make mhayden's script
  work
* pjp to write up a security policy on the wiki for discussion




Action Items, by person
-----------------------
* FabioOlive
  * FabioOlive to create a room for Fedora in appear.in, for videoconfs.
* mhayden
  * Sparks to fix his script OR figure out how to make mhayden's script
    work
* pjp
  * pjp to write up a security policy on the wiki for discussion
* Sparks
  * Sparks to add "issues" to fedora-meeting-report on github
  * Sparks to talk with mattdm regarding private security tickets in BZ.
  * Sparks to fix his script OR figure out how to make mhayden's script
    work
* **UNASSIGNED**
  * (none)




People Present (lines said)
---------------------------
* Sparks (47)
* FabioOlive (19)
* pjp (11)
* zodbot (10)
* mhayden (5)
* Astradeus (4)

14:00:11 <Sparks> #startmeeting Security Team Meeting - Agenda: 
https://fedoraproject.org/wiki/Security_Team_meetings
14:00:11 <zodbot> Meeting started Thu Oct  8 14:00:11 2015 UTC.  The chair is 
Sparks. Information about MeetBot at http://wiki.debian.org/MeetBot.
14:00:11 <zodbot> Useful Commands: #action #agreed #halp #info #idea #link 
#topic.
14:00:14 <Sparks> #meetingname Fedora Security Team
14:00:14 <zodbot> The meeting name has been set to 'fedora_security_team'
14:00:16 <Sparks> #topic Roll Call
14:00:17 * Sparks 
14:02:32 <pjp> Hi,
14:04:45 <Sparks> Doesn't look like too many people here today.
14:05:03 <Astradeus> .fas ^astra$
14:05:03 <zodbot> Astradeus: '^astra$' Not Found!
14:05:42 <Astradeus> doesn't work either^^
14:06:16 <FabioOlive> .fas fleite
14:06:16 <zodbot> FabioOlive: fleite 'Fabio Olive Leite' <fabio at olive.pro.br>
14:06:40 <FabioOlive> Astradeus: try with your email, or a part of it
14:06:52 <Astradeus> .fas astra at ionic.at
14:06:52 <zodbot> Astradeus: astra 'David Kaufmann' <astra at ionic.at>
14:06:58 <FabioOlive> .fas fabio@
14:06:59 <zodbot> FabioOlive: arkfabio 'Fabio Marques' <arkfabio at uol.com.br> - 
rover12 'Fabio Araya ' <josefabio at outlook.com> - fmarinho1980 'Fabio Marinho 
do Nascimento' <marinho.fabio at gmail.com> - dbfabio 'Del Bals Fabio' 
<fabio at pcemail.it> - gfabio 'Gilles Fabio' <gilles.fabio at gmail.com> - fleite 
'Fabio Olive Leite' <fabio at olive.pro.br> - oibaf 'Fabio Pedretti' 
<pedretti.fabio at gmail.com> - fabiocruz '' <cruz.m.fabio at gmail.com> - (1 more 
message)
14:07:03 <FabioOlive> ugh sorry
14:07:04 <FabioOlive> hehe
14:07:09 <Sparks> Okay, lets get started.
14:07:19 <Sparks> #info Participants are reminded to make liberal use of #info 
#link #help in order to make the minutes "more better"
14:07:26 <Sparks> #topic Follow up on last week's tasks
14:07:38 <Southern_Gentlem> .hello jbwillia
14:07:40 <zodbot> Southern_Gentlem: jbwillia 'Ben Williams' <vaioof at yahoo.com>
14:07:43 <Sparks> #action Sparks to add "issues" to fedora-meeting-report on 
github
14:07:54 <Sparks> #action Sparks to talk with mattdm regarding private 
security tickets in BZ.
14:08:04 <Sparks> #action Sparks to start a discussion on the FST list 
regarding an online video GPG key signing event.
14:08:25 <Sparks> #undo
14:08:25 <zodbot> Removing item from minutes: ACTION by Sparks at 14:08:04 : 
Sparks to start a discussion on the FST list regarding an online video GPG key 
signing event.
14:08:29 <pjp> Hi,
14:08:33 <Sparks> Sparks to start a discussion on the FST list regarding an 
online video GPG key signing event.
14:08:36 <Sparks> 14:08 -!- pjp [~pjp at 122.161.66.51] has joined #fedora-
meeting
14:08:39 <Sparks> grrr
14:09:06 <Sparks> Okay, I blogged about the idea of a video GPG key signing 
and only got positive feedback.  Anyone have any thoughts?
14:09:14 <pjp> Sparks: video event ? via hangout ?
14:09:15 <mhayden> sorry i'm late!
14:09:21 <Sparks> mhayden: Welcome
14:09:24 <mhayden> .fas mhayden
14:09:25 <zodbot> mhayden: mhayden 'Major Hayden' <major at mhtx.net>
14:09:33 <Sparks> pjp: I was thinking about using Bluejeans
14:10:44 <FabioOlive> Sparks: or we can use appear.in, which does not need 
plugins
14:10:55 <Sparks> FabioOlive: +1
14:11:04 <pjp> Sparks: Ah okay
14:11:12 <FabioOlive> I created a room there for my local LUG, but I have to 
say we never use it :(
14:11:15 <Sparks> FabioOlive: Yeah, I think I looked at that.  I was still 
trying to figure it all out.
14:12:42 <FabioOlive> I just logged into https://appear.in/oesc-livre in case 
you want to try it out
14:13:03 <pjp> FabioOlive: it says invite upto 8 people, is that an upper 
limit for a call?
14:13:33 <FabioOlive> pjp: I think it is, yes.  It is a free service.
14:14:15 <Sparks> Hmmm... I can't seem to make it come up
14:14:24 <pjp> FabioOlive: I see,
14:14:33 <Sparks> Tried FF and Konqueror
14:15:16 <FabioOlive> weird
14:15:34 <Sparks> The main pages loads fine
14:15:55 <mhayden> appear.in is kinda nifty
14:17:14 <Sparks> FabioOlive: I'll troubleshoot this later.
14:17:56 <FabioOlive> Sparks: I and Astradeus tested it and it worked :)
14:18:04 <FabioOlive> Astradeus: nice to meet you on video :)
14:18:20 <Astradeus> i had to refresh the page twice, but seemed to work, 
audio and video quality was good
14:18:24 <Sparks> IDK...
14:18:55 <Sparks> Okay, so do we want to do this maybe next week?
14:19:54 <FabioOlive> yeah, anytime should be fine.  would you like me to 
create a fedora room there?
14:20:00 <Sparks> Sure
14:21:38 <FabioOlive> #action FabioOlive to create a room for Fedora in 
appear.in, for videoconfs.
14:21:57 <FabioOlive> Sparks: should I call it Fedora, or Fedora Security 
Team? :)
14:22:12 <Sparks> FabioOlive: I'll leave that up to you.  :)
14:22:32 <FabioOlive> :)
14:22:54 <Sparks> #topic Outstanding BZ Tickets
14:23:31 <Sparks> #action Sparks to fix his script OR figure out how to make 
mhayden's script work
14:23:45 <Sparks> mhayden: Do you mind doing your stats?  I can't seem to make 
it work.
14:23:55 <mhayden> ah, i sent it to the ML a short while ago
14:24:10 <Sparks> Hey, look... I've got mail!
14:24:18 <mhayden> https://lists.fedoraproject.org/pipermail/security-team/2015-October/000375.html
14:26:14 <Sparks> #info Thursday's numbers: Critical 0 (0), Important 43 (0), 
Moderate 418 (+10), Low 150 (-3), Total 611
14:26:22 <Sparks> #info Current tickets owned: 88
14:26:39 <Sparks> Anyone have anything regarding tickets?
14:28:22 <Sparks> #topic Handling embargoed issues
14:28:52 <Sparks> FabioOlive: Do you have anything on this topic?
14:28:59 <FabioOlive> I was not able to advance that discussion about 
embargoed issues
14:29:35 * pjp followed up with few Qemu issues last week, updates were pushed 
to bodhi for them
14:29:45 * Sparks wasn't able to contact mattdm about his portion, either.
14:30:04 <Sparks> FabioOlive: I guess we'll come back to this next week.
14:30:39 <FabioOlive> yeah :( sorry
14:30:55 <Sparks> No worries
14:31:01 <Sparks> #topic Open floor discussion/questions/comments
14:31:07 <Sparks> Anyone have anything?
14:33:01 <pjp> We had little discussion about Fedora security policy on the 
list few days back, we need to start with it on the wiki
14:34:05 * pjp guess the security policy needs to be vetted and accepted by 
the council too,
14:34:31 <Sparks> pjp: You gonna write that up?
14:35:31 <pjp> Sparks: Yes, I'd start with it and will circulate it on the 
list for inputs
14:35:58 <Sparks> #action pjp to write up a security policy on the wiki for 
discussion
14:36:37 <Sparks> Anyone have anything else?
14:37:47 <FabioOlive> not me
14:39:39 <Sparks> Okay, we'll go ahead and close up for the day.
14:40:30 <pjp> Yep, thank you.
14:40:34 <Sparks> #endmeeting
* Southern_Gentlem (1)


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 473 bytes
Desc: This is a digitally signed message part.
URL: <http://lists.fedoraproject.org/pipermail/security-team/attachments/20151008/5bc7ecb8/attachment.sig>


More information about the security-team mailing list