Re: [Openstack] [OpenStack][QA] Writing a test plan for blueprint: Use common RPC listener to consume messages

2013-07-25 Thread Thierry Carrez
OpenStack release, whereas this list is mostly focused on the current state of affairs. See https://wiki.openstack.org/wiki/Mailing_Lists for details. -- Thierry Carrez (ttx) ___ Mailing list: https://launchpad.net/~openstack Post to : openstack

Re: [Openstack] IMPORTANT: Openstack List Migration (Please read)

2013-07-25 Thread Thierry Carrez
subscription will not be available until the migration occurred. -- Thierry Carrez (ttx) ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https

[Openstack] Havana-2 development milestone available

2013-07-18 Thread Thierry Carrez
/cinder/havana/havana-2 https://launchpad.net/ceilometer/havana/havana-2 https://launchpad.net/heat/havana/havana-2 The next (and last) development milestone of the Havana cycle, havana-3, is scheduled for September 6th (final release is planned October 17th). Regards, -- Thierry Carrez (ttx

[Openstack] Minutes from the Technical Committee meeting (July 16)

2013-07-17 Thread Thierry Carrez
OpenStack in production, using OpenStack itself wherever possible. See details and full logs at: http://eavesdrop.openstack.org/meetings/tc/2013/tc.2013-07-16-20.02.html More information on the Technical Committee at: http://wiki.openstack.org/Governance/TechnicalCommittee -- Thierry Carrez

Re: [Openstack] [Horizon] [UX] phabriactor/pholio as a possible UX option

2013-07-15 Thread Thierry Carrez
suggestion was to use Discourse because I can see where our current setup (pure task tracking + pure MLs) is missing the needs of image-intensive multi-threaded discussions, and that sounds more reusable than GitHub issues which bleeds into task tracking a bit. Cheers, -- Thierry Carrez (ttx

[Openstack] Minutes from the Technical Committee meeting (July 2)

2013-07-03 Thread Thierry Carrez
/TechnicalCommittee -- Thierry Carrez (ttx) Chair, OpenStack Technical Committee ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https

Re: [Openstack] [Horizon] [UX] phabriactor/pholio as a possible UX option

2013-06-27 Thread Thierry Carrez
a discussion tool (including pretty advanced threading, post likes, etc.), and messages can contain images. See a design discussion for example at: http://test.ubuntu-discourse.org/t/a-ubuntu-ish-theme-for-the-site/177 -- Thierry Carrez (ttx

[Openstack] [OSSA 2013-017] Issues in Keystone middleware memcache signing/encryption feature (CVE-2013-2166, CVE-2013-2167)

2013-06-19 Thread Thierry Carrez
/1175368 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2167 - -- Thierry Carrez (ttx) OpenStack Vulnerability Management Team -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) Comment: Using GnuPG with undefined - http://www.enigmail.net/ iQIcBAEBCAAGBQJRwdC5AAoJEFB6

[Openstack] [OSSA 2013-015] Authentication bypass when using LDAP backend (CVE-2013-2157)

2013-06-13 Thread Thierry Carrez
/keystone/+bug/1187305 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2157 - -- Thierry Carrez (ttx) OpenStack Vulnerability Management Team -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) Comment: Using GnuPG with undefined - http://www.enigmail.net

Re: [Openstack] OpenStack CVE Wiki page

2013-06-05 Thread Thierry Carrez
://secstack.org/2013/04/openstack-common-vulnerability-database/ Hope this helps, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net

Re: [Openstack] OpenStack I release naming

2013-06-04 Thread Thierry Carrez
/+poll/i-release-naming Thanks to all participants to the poll. -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net

Re: [Openstack] [OSSA 2013-013] Keystone client local information disclosure (CVE-2013-2013)

2013-06-04 Thread Thierry Carrez
of downstream consumption of the fix) it makes sense to tag and trigger a new PyPI release after each security advisory. These were the first advisories on client libraries, but with Keystone middleware being shipped within python-keystoneclient, I expect more in the future. -- Thierry Carrez (ttx

[Openstack] Havana-1 development milestone available

2013-05-30 Thread Thierry Carrez
, is scheduled for July 18th. Regards, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https

[Openstack] [OSSA 2013-014] Missing expiration check in Keystone PKI tokens validation (CVE-2013-2104)

2013-05-28 Thread Thierry Carrez
-keystoneclient/+bug/1179615 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2013-2104 - -- Thierry Carrez (ttx) OpenStack Vulnerability Management Team -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) Comment: Using GnuPG with undefined - http://www.enigmail.net

Re: [Openstack] [Keystone] Splitting the Identity Backend

2013-05-21 Thread Thierry Carrez
land. Cheers, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https://help.launchpad.net

Re: [Openstack] security blueprint related to os binaries

2013-05-14 Thread Thierry Carrez
specific path, and still have the option to specify the complete path. To interfere with that you actually need to be root already. So this makes the code more brittle (each distro would have to patch the code to apply their specific paths), for no security gain. -- Thierry Carrez (ttx) Release

Re: [Openstack] New code name for networks

2013-05-13 Thread Thierry Carrez
. I very much prefer to call it ceilometer. -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help

Re: [Openstack] New code name for networks

2013-05-13 Thread Thierry Carrez
/listinfo/legal-discuss -- Thierry Carrez (ttx) Chair, OpenStack Technical Committee ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https

Re: [Openstack] [OSSA 2013-011] Keystone tokens not immediately invalidated when user is deleted (CVE-2013-2059)

2013-05-10 Thread Thierry Carrez
, containing all security fixes and high-impact bugfixes, are regularly produced. It happens that 2013.1.1, the first Grizzly point release, shall be released today. - -- Thierry Carrez (ttx) Release Manager, OpenStack -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.12 (GNU/Linux) Comment: Using GnuPG

[Openstack] [OSSA 2013-010] Nova uses insecure keystone middleware tmpdir by default (CVE-2013-2030)

2013-05-09 Thread Thierry Carrez
://review.openstack.org/#/c/28568/ Grizzly fix: https://review.openstack.org/#/c/28569/ Folsom fix: https://review.openstack.org/#/c/28570/ References: https://bugs.launchpad.net/nova/+bug/1174608 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2013-2030 - -- Thierry Carrez (ttx) OpenStack Vulnerability

[Openstack] [OSSA 2013-011] Keystone tokens not immediately invalidated when user is deleted (CVE-2013-2059)

2013-05-09 Thread Thierry Carrez
://review.openstack.org/#/c/28677/ Grizzly fix: https://review.openstack.org/#/c/28678/ Folsom fix: https://review.openstack.org/#/c/28679/ References: https://bugs.launchpad.net/keystone/+bug/1166670 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2013-2059 - -- Thierry Carrez (ttx) OpenStack

[Openstack] Minutes from the Technical Committee meeting (May 7)

2013-05-08 Thread Thierry Carrez
at: https://wiki.openstack.org/wiki/Governance/NewProjects More information on the Technical Committee at: http://wiki.openstack.org/Governance/TechnicalCommittee -- Thierry Carrez (ttx) Chair, OpenStack Technical Committee ___ Mailing list: https

Re: [Openstack] I release naming (calling APAC community)

2013-05-06 Thread Thierry Carrez
where the design summit is held, single word of 10 characters or less). To have more than one option, we'll probably extend the rules to include other places (like street names) in Hong Kong itself. We'll go through name checks and set up a vote soon, I'll keep you posted. -- Thierry Carrez (ttx

Re: [Openstack] Related Projects

2013-05-03 Thread Thierry Carrez
? Doesn't this transcluded RelatedProjects wikipage kind of duplicate this effort ? I'd hate it if related projects had to register to multiple sites to get properly discovered. -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https

Re: [Openstack] Related Projects

2013-05-03 Thread Thierry Carrez
Jeremy Stanley wrote: On 2013-05-03 12:12:25 +0200 (+0200), Thierry Carrez wrote: Isn't that what stackmeat.org was supposed to cover ? Doesn't this transcluded RelatedProjects wikipage kind of duplicate this effort ? [...] Good point--I'd sadly forgotten about stackmeat.org... perhaps

[Openstack] I release naming (calling APAC community)

2013-05-02 Thread Thierry Carrez
Chinese members in particular, which are probably the best to let us know which transliteration crime could be acceptable or which name they would particularly like. Cheers, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https

Re: [Openstack] release process and sample configs

2013-04-29 Thread Thierry Carrez
option they want to use. I'll let Anne comment on that, but it sounds sane to me :) -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https

[Openstack] Heat PTL nominations are open

2013-04-23 Thread Thierry Carrez
development cycle, please send an email to *openstack@lists.launchpad.net* with subject Heat PTL candidacy and a description of your platform. This self-nomination period will end on Monday, April 29, 23:59 PST. [1] http://lists.openstack.org/pipermail/openstack-dev/2013-April/007396.html -- Thierry

Re: [Openstack] Patch not applied to grizzly?

2013-04-22 Thread Thierry Carrez
marked as fixed I still see this with my grizzly setup. That would be a regression, since the patch for that bug landed in Cinder and is apparently still there. Could you file a new bug, referencing the original bug, at: https://bugs.launchpad.net/cinder/+filebug Thanks in advance, -- Thierry

Re: [Openstack] ODS schedule app for Android?

2013-04-12 Thread Thierry Carrez
/details?id=org.sched.openstacksummitapril2013 -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help

Re: [Openstack] root_helper deprecated?

2013-04-09 Thread Thierry Carrez
, the message seems to point to configuration sections. The [DEFAULT] root_helper configuration option is now deprecated, it needs to be specified in the [AGENT] section of quantum.conf. See https://github.com/openstack/quantum/blob/master/etc/quantum.conf for an example. -- Thierry Carrez (ttx

Re: [Openstack] what would be the best wat to get security notifications for openstack

2013-04-09 Thread Thierry Carrez
is accepted), so that I may update the packages. Cross-posting is evil! Answers went to the openstack-security list. Cheers, - -- Thierry Carrez (ttx) Release Manager, OpenStack -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with undefined - http://www.enigmail.net

Re: [Openstack] [Cinder] Blueprint to be added for Cinder in G version

2013-04-08 Thread Thierry Carrez
. Added to the list. -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https://help.launchpad.net

[Openstack] OpenStack 2013.1 (Grizzly) is released !

2013-04-04 Thread Thierry Carrez
everyone on this awesome release ! -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https

Re: [Openstack] CY13-Q1 Community Analysis — OpenStack vs OpenNebula vs Eucalyptus vs CloudStack

2013-04-03 Thread Thierry Carrez
analysis. -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https://help.launchpad.net/ListHelp

[Openstack] Keystone Grizzly RC3 available

2013-04-02 Thread Thierry Carrez
a few days left to make Grizzly an awesome release ! -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More

[Openstack] [Quantum] OpenStack Networking Grizzly RC3 available

2013-04-02 Thread Thierry Carrez
and tag it *grizzly-rc-potential* to bring it to the release crew's attention. Two days left ! -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe

[Openstack] Nova and Glance Grizzly RC2 available !

2013-03-30 Thread Thierry Carrez
/openstack/glance/tree/milestone-proposed If you find a regression that could be considered release-critical, please file it on Launchpad and tag it *grizzly-rc-potential* to bring it to the release crew's attention. Release day is Thursday ! -- Thierry Carrez (ttx) Release Manager, OpenStack

[Openstack] Horizon and Swift Grizzly RC2 available !

2013-03-29 Thread Thierry Carrez
, please file it on Launchpad and tag it *grizzly-rc-potential* to bring it to the release crew's attention. Only a few days left! -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post

[Openstack] Keystone Grizzly RC2 available

2013-03-28 Thread Thierry Carrez
* to bring it to the release crew's attention. Happy regression hunting, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net

Re: [Openstack] what is the difference between 2013.1 and grizzly?

2013-03-27 Thread Thierry Carrez
2013.1.rcX. Cheers, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https

[Openstack] Cinder Grizzly RC3 available

2013-03-27 Thread Thierry Carrez
attention. Happy testing, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https

[Openstack] [Quantum] OpenStack Networking Grizzly RC2 available

2013-03-26 Thread Thierry Carrez
regression hunting, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https://help.launchpad.net

[Openstack] Cinder Grizzly RC2 available

2013-03-25 Thread Thierry Carrez
, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https://help.launchpad.net/ListHelp

[Openstack] [Keystone] OpenStack Identity Grizzly RC1 available

2013-03-22 Thread Thierry Carrez
, and feature freeze restrictions no longer apply. Regards, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help

Re: [Openstack] Technical Committee Nominations are Open

2013-03-21 Thread Thierry Carrez
! -- Thierry Carrez (ttx) Chair, OpenStack Technical Committee ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https://help.launchpad.net/ListHelp

[Openstack] [Glance] [Swift] RC1 available for Grizzly OpenStack Image service and Object Storage

2013-03-20 Thread Thierry Carrez
apply. Regards, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https://help.launchpad.net

[Openstack] [Horizon] OpenStack Dashboard Grizzly RC1 available

2013-03-20 Thread Thierry Carrez
is now open for Havana development, and feature freeze restrictions no longer apply. We are expecting the last Grizzly RC1s (Keystone and Nova) to be published before the end of the week. Regards, -- Thierry Carrez (ttx) Release Manager, OpenStack

[Openstack] [OSSA 2013-009] Keystone PKI tokens online validation bypasses revocation check (CVE-2013-1865)

2013-03-20 Thread Thierry Carrez
/cvename.cgi?name=2013-1865 - -- Thierry Carrez (ttx) OpenStack Vulnerability Management Team -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with undefined - http://www.enigmail.net/ iQIcBAEBCAAGBQJRSdTdAAoJEFB6+JAlsQQj9sUQAL0y9zV5xWHDhAFpfaUGobq6

[Openstack] [Nova] OpenStack Compute Grizzly RC1 available

2013-03-20 Thread Thierry Carrez
, and feature freeze restrictions no longer apply. Regards, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack

[Openstack] [Cinder] OpenStack Block Storage Grizzly RC1 available

2013-03-15 Thread Thierry Carrez
for Havana development, and feature freeze restrictions no longer apply. Regards, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https

[Openstack] TC candidacy

2013-03-15 Thread Thierry Carrez
development. The challenges ahead of us include accommodating further growth, resist fragmentation, and maintaining efficiency and coherence as we grow well past Dunbar's number. I hope that you place me in a position where I can help us through those challenges. Thanks, -- Thierry Carrez (ttx

[Openstack] [Quantum] OpenStack Networking Grizzly RC1 available

2013-03-14 Thread Thierry Carrez
it to the release crew's attention. Note that the master branch of Quantum is now open for Havana development, and feature freeze restrictions no longer apply. Regards, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https

[Openstack] [OSSA 2013-007] Backend credentials leak in Glance v1 API (CVE-2013-1840)

2013-03-14 Thread Thierry Carrez
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2013-1840 - -- Thierry Carrez (ttx) OpenStack Vulnerability Management Team -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with undefined - http://www.enigmail.net/ iQIcBAEBCAAGBQJRQfdoAAoJEFB6+JAlsQQj0g4QAL

[Openstack] Entering DST madness zone again

2013-03-12 Thread Thierry Carrez
: http://www.timeanddate.com/worldclock/fixedtime.html?hour=21min=0sec=0 For our North American friends, that probably means meetings are occuring one hour later than last week. Regards, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing

[Openstack] Minutes from the Technical Committee meeting (Feb 26)

2013-03-05 Thread Thierry Carrez
://eavesdrop.openstack.org/meetings/tc/2013/tc.2013-02-26-20.03.html More information on the Technical Committee at: http://wiki.openstack.org/Governance/TechnicalCommittee -- Thierry Carrez (ttx) Chair, OpenStack Technical Committee ___ Mailing list: https

[Openstack] Grizzly-3 development milestone available (Keystone, Glance, Nova, Horizon, Quantum, Cinder)

2013-02-22 Thread Thierry Carrez
candidates. Please test, try the new features, report bugs and help fix them ! Regards, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https

Re: [Openstack] Grizzly-3 development milestone available (Ceilometer, Heat)

2013-02-22 Thread Thierry Carrez
Thierry Carrez wrote: The last milestone of the Grizzly development cycle, grizzly-3 is now available for testing. This milestone contains almost all of the features that will be shipped in the final 2013.1 (Grizzly) release on April 4, 2013. And with perfect sync now, our two grizzly

Re: [Openstack] Grizzly-3 development milestone available (Keystone, Glance, Nova, Horizon, Quantum, Cinder)

2013-02-22 Thread Thierry Carrez
to be the default Openstack for Raring? I suspect it will take a few days for grizzly-3 to appear in Ubuntu, as the tarballs were cut a few hours ago. As far as I know, Grizzly is indeed the planned default OpenStack for Raring. -- Thierry Carrez (ttx) Release Manager, OpenStack

Re: [Openstack] [Swift]A design draft of Storage Quota

2013-02-21 Thread Thierry Carrez
that should have happened on openstack-...@lists.openstack.org, since it is about future development rather than the current state of affairs. -- Thierry Carrez (ttx) On-topic mailing-list police ___ Mailing list: https://launchpad.net/~openstack Post

Re: [Openstack] security releases

2013-02-20 Thread Thierry Carrez
source code point releases (2012.2.4). Most distributions provide packages which include recent security fixes. Regards, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack

[Openstack] Minutes from the Technical Committee meeting (Feb 19)

2013-02-20 Thread Thierry Carrez
More information on the Technical Committee at: http://wiki.openstack.org/Governance/TechnicalCommittee -- Thierry Carrez (ttx) Chair, OpenStack Technical Committee ___ Mailing list: https://launchpad.net/~openstack Post to : openstack

[Openstack] [OSSA 2013-004] Information leak and Denial of Service using XML entities (CVE-2013-1664, CVE-2013-1665)

2013-02-19 Thread Thierry Carrez
- -- Thierry Carrez (ttx) OpenStack Vulnerability Management Team -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with undefined - http://www.enigmail.net/ iQIcBAEBCAAGBQJRI5+DAAoJEFB6+JAlsQQj2fQQALLE9GEOIRGcj9gXXQ5mDS3l /CWI6ljTlVWxXy143lAUbkpvW0AHx0S6wVU38Hh

[Openstack] [OSSA 2013-005] Keystone EC2-style authentication accepts disabled user/tenants (CVE-2013-0282)

2013-02-19 Thread Thierry Carrez
- -- Thierry Carrez (ttx) OpenStack Vulnerability Management Team -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with undefined - http://www.enigmail.net/ iQIcBAEBCAAGBQJRI7nbAAoJEFB6+JAlsQQjGHgP/2yHBH4Yvzl3Q0P4oMr2Vskb 9xroi6sEQTgP

[Openstack] Minutes from the Technical Committee meeting (Feb 12)

2013-02-14 Thread Thierry Carrez
://eavesdrop.openstack.org/meetings/tc/2013/tc.2013-02-12-20.03.html More information on the Technical Committee at: http://wiki.openstack.org/Governance/TechnicalCommittee -- Thierry Carrez (ttx) Chair, OpenStack Technical Committee ___ Mailing list: https

[Openstack] [OSSA 2013-003] Keystone denial of service through invalid token requests (CVE-2013-0247)

2013-02-05 Thread Thierry Carrez
://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2013-0247 - -- Thierry Carrez (ttx) OpenStack Vulnerability Management Team -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with undefined - http://www.enigmail.net/ iQIcBAEBCAAGBQJRETGUAAoJEFB6+JAlsQQjbC0QAIzjY1gNe/Lr2X

Re: [Openstack] (no subject)

2013-02-02 Thread Thierry Carrez
to the design summit and implemented in the months after, to be integrated in the release at the end of the 6-month cycle. Regards, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack

[Openstack] [OSSA 2013-001] Boot from volume allows access to random volumes (CVE-2013-0208)

2013-01-29 Thread Thierry Carrez
/1069904 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2013-0208 - -- Thierry Carrez (ttx) OpenStack Vulnerability Management Team -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with undefined - http://www.enigmail.net/ iQIcBAEBCAAGBQJRCCZCAAoJEFB6

Re: [Openstack] Poll: H release cycle naming

2013-01-29 Thread Thierry Carrez
Results are in: 1. Havana (120) 2. Hood (79) 3. Harbor (43) 4. Hatfield (41) Havana it is. https://launchpad.net/~openstack/+poll/h-release-naming -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack

[Openstack] [OSSA 2013-002] Backend password leak in Glance error message (CVE-2013-0212)

2013-01-29 Thread Thierry Carrez
/96a470be64adcef97f235ca96ed3c59ed954a4c1 Essex fix: http://github.com/openstack/glance/commit/37d4d96bf88c2bf3e7e9511b5e321cf4bed364b7 References: https://bugs.launchpad.net/glance/+bug/1098962 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2013-0212 - -- Thierry Carrez (ttx) OpenStack

Re: [Openstack] Progress on wiki migration to Mediawiki

2013-01-24 Thread Thierry Carrez
Thierry Carrez wrote: Ryan Lane wrote: Image location is fixed and the redirects are also in. I still have issues with image location. Everything works now. Beautified main page is up at: https://wiki-staging.openstack.org/wiki/Main_Page So my part is done :) -- Thierry

[Openstack] Poll: H release cycle naming

2013-01-24 Thread Thierry Carrez
on this list already are. -- Thierry Carrez (ttx) Chair, OpenStack Technical Committee ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https

Re: [Openstack] Poll: H release cycle naming

2013-01-24 Thread Thierry Carrez
Adam Young wrote: I think we have overlooked the most obvious answer: [...] To keep the single-choice poll efficient, the Technical Committee preselected 4 finalists from the list of 35 (!) valid options. Sorry your preferred option didn't make it. -- Thierry Carrez (ttx

Re: [Openstack] Progress on wiki migration to Mediawiki

2013-01-22 Thread Thierry Carrez
data returns 404 at: https://wiki-staging.openstack.org/w/images/2/25/Openstack-compute-icon.png https://wiki-staging.openstack.org/w/images/d/d5/Compute.png Regards, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https

Re: [Openstack] Progress on wiki migration to Mediawiki

2013-01-21 Thread Thierry Carrez
Anne Gentle wrote: - Make the landing page mo' better. (Thierry Carrez, ttx) While we won't be able to have the migration make the columns on all the pages lovely, he can make the first page beautious again. I pushed an optimized page at https://wiki-staging.openstack.org/wiki. There is still

Re: [Openstack] Nova root wrapper understanding

2013-01-14 Thread Thierry Carrez
Kun Huang wrote: Thanks, Thierry Carrez. Your explanation is easy to understand. I have got why we need such a mechanism. BTW, is root-wrap a general or popular way to keep security? I have no experience on security, but I have heard the /root /should be banned because of security. Ideally

Re: [Openstack] Nova root wrapper understanding

2013-01-11 Thread Thierry Carrez
instead!). Hope this clarifies, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https

Re: [Openstack] Nova root wrapper understanding

2013-01-11 Thread Thierry Carrez
in. -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https://help.launchpad.net/ListHelp

[Openstack] Grizzly-2 development milestone available (Keystone, Glance, Nova, Horizon, Quantum, Cinder)

2013-01-10 Thread Thierry Carrez
Features may be added until the next milestone, grizzly-3, which will be delivered on February 21st. Let's all make it awesome ! Regards, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post

[Openstack] Minutes from the Technical Committee meeting (Jan 8)

2013-01-09 Thread Thierry Carrez
growth in the number of projects. See details and full logs at: http://eavesdrop.openstack.org/meetings/tc/2013/tc.2013-01-08-20.02.html More information on the Technical Committee at: http://wiki.openstack.org/Governance/TechnicalCommittee -- Thierry Carrez (ttx) Chair, OpenStack Technical Committee

Re: [Openstack] [Cinder] cinder-agent

2013-01-07 Thread Thierry Carrez
be discussed on the openstack-dev mailing-list, since it's a bit forward-looking (discusses future development rather than current state). Thanks, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post

Re: [Openstack] Wiki content imported into MediaWiki - please check

2012-12-19 Thread Thierry Carrez
(in a sprint or in the following days/weeks) on various conversion issues on sub pages: * Table issues * Link issues * Image inclusions * etc. -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post

Re: [Openstack] Wiki content imported into MediaWiki - please check

2012-12-18 Thread Thierry Carrez
agreeable and we decide to press forward, I'll migrate the data again and we'll replace MoinMoin. I fear we are more than just a couple of days away from being able to migrate content in a mostly agreeable way, but you're the expert :) -- Thierry Carrez (ttx) Release Manager, OpenStack

Re: [Openstack] Blueprint proposal: Drop setuptools_git for including data/config files

2012-12-18 Thread Thierry Carrez
Thomas Goirand wrote: On 12/18/2012 12:17 AM, Thierry Carrez wrote: Thomas Goirand wrote: [No pun intended, but it'd be nice if stackers had a bit more consideration for our work in Debian, and stop thinking only with Ubuntu, Ubuntu, Ubuntu, Ubuntu, Ubuntu, Ubuntu, ... in mind

Re: [Openstack] Blueprint proposal: Drop setuptools_git for including data/config files

2012-12-17 Thread Thierry Carrez
uses the same process with success. I agree we can improve the tooling so that it's a bit more flexible to various use cases, but don't make it a question of supporting only Ubuntu vs. the rest of the world. It's been a long time since we only supported Ubuntu. Cheers, -- Thierry Carrez (ttx

Re: [Openstack] [Packagers] Adding psutils as a dependency for nova

2012-12-13 Thread Thierry Carrez
Michael Still wrote: Stand down. Padraig has suggested a better way. Also note that new dependency discussions are a better fit for openstack-dev. -- Thierry Carrez (ttx) Committee for the Usage of the Right Mailing-lists ___ Mailing list: https

Re: [Openstack] New build dependency on keyring

2012-12-13 Thread Thierry Carrez
mailing-list. -- Thierry Carrez (ttx) Committee for the Usage of the Right Mailing-lists ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https

[Openstack] [OSSA 2012-020] Information leak in libvirt LVM-backed instances (CVE-2012-5625)

2012-12-11 Thread Thierry Carrez
/a99a802e008eed18e39fc1d98170edc495cbd354 References: https://bugs.launchpad.net/nova/+bug/1070539 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2012-5625 - -- Thierry Carrez (ttx) OpenStack Vulnerability Management Team -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with undefined

Re: [Openstack] Blueprint proposal: Drop setuptools_git for including data/config files

2012-12-04 Thread Thierry Carrez
hate it if we went back to the previous situation. I'm not personally attached to setuptools_git, but any proposed replacement solution should keep its simplicity. -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net

[Openstack] [OSSA 2012-018] EC2-style credentials invalidation issue (CVE-2012-5571)

2012-11-28 Thread Thierry Carrez
- -- Thierry Carrez (ttx) OpenStack Vulnerability Management Team -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with undefined - http://www.enigmail.net/ iQIcBAEBCAAGBQJQtjAkAAoJEFB6+JAlsQQj+4sP/0uKJHxXeCY3HcAdMUtkYP+5 QyQGnscOhlggr9iE3ifPWkiLALPbfVrdwp

[Openstack] [OSSA 2012-019] Extension of token validity through token chaining (CVE-2012-5563)

2012-11-28 Thread Thierry Carrez
): https://github.com/openstack/keystone/commit/f9d4766249a72d8f88d75dcf1575b28dd3496681 References: https://bugs.launchpad.net/keystone/+bug/1079216 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2012-5563 - -- Thierry Carrez (ttx) OpenStack Vulnerability Management Team -BEGIN PGP SIGNATURE

[Openstack] Grizzly-1 development milestone available (Keystone, Glance, Nova, Horizon, Quantum, Cinder)

2012-11-23 Thread Thierry Carrez
development cycle is now in full swing. The next milestone, grizzly-2, is scheduled for delivery on January 10th. Regards, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack

Re: [Openstack] FIXED IT! Re: Floating ip addresses take forever to display

2012-11-22 Thread Thierry Carrez
of a backport. Did we identify the bug number (or commit id) of the Folsom fix, so that we can open an Essex task for it ? -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack

[Openstack] Minutes from the Technical Committee meeting (Nov 20)

2012-11-21 Thread Thierry Carrez
that the Board of Directors will form to discuss that issue. Russell Bryant and Thierry Carrez will act as substitutes if needed. [1] http://lists.openstack.org/pipermail/openstack-dev/2012-November/thread.html#2387 See details and full logs at: http://eavesdrop.openstack.org/meetings/tc/2012/tc.2012

[Openstack] Minutes from the Technical Committee meeting (Nov 13)

2012-11-14 Thread Thierry Carrez
on the Technical Committee at: http://wiki.openstack.org/Governance/TechnicalCommittee -- Thierry Carrez (ttx) Chair, OpenStack Technical Committee ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe

[Openstack] Minutes from the Technical Committee meeting (Nov 6)

2012-11-07 Thread Thierry Carrez
at: http://eavesdrop.openstack.org/meetings/tc/2012/tc.2012-11-06-20.02.html More information on the Technical Committee at: http://wiki.openstack.org/Governance/TechnicalCommittee -- Thierry Carrez (ttx) Chair, OpenStack Technical Committee ___ Mailing

Re: [Openstack] summit web site down?

2012-11-01 Thread Thierry Carrez
down in the future, but let's just wait for the Grizzly planning to be completed first :) -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https

Re: [Openstack] new mailing list for bare-metal provisioning

2012-10-30 Thread Thierry Carrez
to receive everything and do filtering client-side too. Topics are just an additional option, I guess. -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe

Re: [Openstack] new mailing list for bare-metal provisioning

2012-10-29 Thread Thierry Carrez
... or we also can setup a baremetal mailman topic so that you can directly filter using your ML preferences. -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net

Re: [Openstack] new mailing list for bare-metal provisioning

2012-10-28 Thread Thierry Carrez
a subject prefix instead ? Like [baremetal] ? Regards, -- Thierry Carrez (ttx) Release Manager, OpenStack ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help

  1   2   3   4   5   6   7   >