Re: [openstack-dev] [openstack-ansible] Security hardening

2015-09-14 Thread Major Hayden
s a rough draft of a spec. Feel free to throw some darts. https://review.openstack.org/#/c/222619/ -- Major Hayden __ OpenStack Development Mailing List (not for usage questions) Unsubscribe: openstack-dev-requ...@list

[openstack-dev] [openstack-ansible] Security hardening

2015-09-10 Thread Major Hayden
into documentation as things deployers should do locally? [1] https://benchmarks.cisecurity.org/ [2] https://bugs.launchpad.net/openstack-ansible/+bug/1491915 [3] https://bugs.launchpad.net/openstack-ansible/+bug/1493981 [4] https://en.wikipedia.org/wiki/Information_security#Key_concepts -- Major Hayden

Re: [openstack-dev] [openstack-ansible] Security hardening

2015-09-10 Thread Major Hayden
ist" of CIS benchmarks and try to tag them with one of the following: * Do this in OSAD * Tell deployers how to do this (in docs) * Tell deployers not to do this (in docs) That could be lumped in with a spec/blueprint of some sort. Would that be beneficial? - -- Major Hayden -BEG

Re: [openstack-dev] [openstack-ansible] Security hardening

2015-09-10 Thread Major Hayden
h. One should be able to have code > do the "turn it on" "turn it off" mechanics. I'm completely in agreement on this one. ;) - -- Major Hayden -BEGIN PGP SIGNATURE- Version: GnuPG v2 iQIcBAEBCAAGBQJV8fQcAAoJEHNwUeDBAR+x1BIP/jkq0Gd2SuPcWbMU53xADj1W ml8VtfkJwT/gs1v8Kfd/

<    1   2