[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-03-23 Thread James Page
2.4.0 uploaded (as requested in security review) with repoze-who support disabled in testing and pushed back to a suggests at runtime. Please can this MIR be reviewed on this basis. ** Changed in: python-repoze.who (Ubuntu) Status: Incomplete = Invalid ** Summary changed: - [MIR]

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-03-23 Thread James Page
2.4.0 uploaded (as requested in security review) with repoze-who support disabled in testing and pushed back to a suggests at runtime. Please can this MIR be reviewed on this basis. ** Changed in: python-repoze.who (Ubuntu) Status: Incomplete = Invalid ** Summary changed: - [MIR]

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-03-20 Thread James Page
Seth Bumping pysaml2 to 2.3.0 is probably not to much of a stretch this late in cycle, but repoze.who 1.0.18 - 2.2 does feel like a big jump post freeze - esp as it has reverse-depends outside of this chain. Keystone federation (requring pysaml2) landed as part of core in kilo-3 so will focus on

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-03-20 Thread James Page
Seth Bumping pysaml2 to 2.3.0 is probably not to much of a stretch this late in cycle, but repoze.who 1.0.18 - 2.2 does feel like a big jump post freeze - esp as it has reverse-depends outside of this chain. Keystone federation (requring pysaml2) landed as part of core in kilo-3 so will focus on

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-03-20 Thread James Page
Here's an idea - I'm not sure keystone is using the repoze.who feature, so we could disable this as a BD (and the assocated test) and push it back to Suggests. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to python-pysaml2 in Ubuntu.

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-03-20 Thread James Page
Here's an idea - I'm not sure keystone is using the repoze.who feature, so we could disable this as a BD (and the assocated test) and push it back to Suggests. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-03-18 Thread Seth Arnold
I got a response from Tres Seaver to some of the issues I raised in this MIR: Thanks for the report! 1.0.18 is a long time ago now (almost 4 1/2 years). The latest release is 2.2, and there will likely be a 2.2.1 released in the near future. We are pretty unlikely to make another 1.x

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-03-18 Thread Seth Arnold
I got a response from Tres Seaver to some of the issues I raised in this MIR: Thanks for the report! 1.0.18 is a long time ago now (almost 4 1/2 years). The latest release is 2.2, and there will likely be a 2.2.1 released in the near future. We are pretty unlikely to make another 1.x

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-03-12 Thread Seth Arnold
I reviewed python-repoze.who version 1.0.18-4 from Ubuntu vivid. This should not be considered a full security audit but instead a quick gauge of maintainability. - python-repoze,who is a generic authentication middleware for python applications; it sits between a wsgi server and application

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-03-12 Thread Seth Arnold
I reviewed python-pysaml2 version 2.2.0-0ubuntu2 as found in Ubuntu vivid. This should not be considered a full security audit, but rather a quick gauge of maintainability. - python-pysaml2 is a middleware designed to handle SAML2 authentication, a competitor to oauth and FIDO. SAML2 is popular

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-03-12 Thread Seth Arnold
I reviewed python-repoze.who version 1.0.18-4 from Ubuntu vivid. This should not be considered a full security audit but instead a quick gauge of maintainability. - python-repoze,who is a generic authentication middleware for python applications; it sits between a wsgi server and application

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-03-12 Thread Seth Arnold
I reviewed python-pysaml2 version 2.2.0-0ubuntu2 as found in Ubuntu vivid. This should not be considered a full security audit, but rather a quick gauge of maintainability. - python-pysaml2 is a middleware designed to handle SAML2 authentication, a competitor to oauth and FIDO. SAML2 is popular

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-03-12 Thread James Page
Michael RE repoze.who; I'm not overly concerned at it being orphaned in Debian; the package is a little out-of-date but I think its manageable within the server team I'll look at the xmlsec test suite/build failure issue soon -- You received this bug notification because you are a member of

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-03-12 Thread James Page
Michael RE repoze.who; I'm not overly concerned at it being orphaned in Debian; the package is a little out-of-date but I think its manageable within the server team I'll look at the xmlsec test suite/build failure issue soon -- You received this bug notification because you are a member of

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-02-24 Thread Seth Arnold
** Changed in: xmlsec1 (Ubuntu) Assignee: Seth Arnold (seth-arnold) = (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1407695 Title: [MIR] python-saml2, python-repoze.who, xmlsec1

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-02-24 Thread Seth Arnold
** Changed in: xmlsec1 (Ubuntu) Assignee: Seth Arnold (seth-arnold) = (unassigned) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to python-pysaml2 in Ubuntu. https://bugs.launchpad.net/bugs/1407695 Title: [MIR] python-saml2,

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-02-20 Thread Michael Terry
python-pysaml2 is fine from a packaging point of view, but I'm also going to pass to Seth for a quick look. ** Changed in: python-pysaml2 (Ubuntu) Assignee: (unassigned) = Seth Arnold (seth-arnold) -- You received this bug notification because you are a member of Ubuntu Server Team, which

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-02-20 Thread Michael Terry
python-pysaml2 is fine from a packaging point of view, but I'm also going to pass to Seth for a quick look. ** Changed in: python-pysaml2 (Ubuntu) Assignee: (unassigned) = Seth Arnold (seth-arnold) -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-02-20 Thread Michael Terry
I was looking at xmlsec1 too, from a packaging perspective. And it looks like test failures don't fail the build. That should be addressed. ** Changed in: xmlsec1 (Ubuntu) Status: New = Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-02-20 Thread Michael Terry
I was looking at xmlsec1 too, from a packaging perspective. And it looks like test failures don't fail the build. That should be addressed. ** Changed in: xmlsec1 (Ubuntu) Status: New = Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team,

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-02-19 Thread Michael Terry
Regarding python-repoze.who... It looks fine (has tests, bug subscriber, no important bugs, etc). But it's orphaned in Debian. Can I get a comment on how much of a problem the server team thinks that will be? I'll also pass to Seth for a quick look, since this is an authentication module. **

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-02-19 Thread Michael Terry
Regarding python-repoze.who... It looks fine (has tests, bug subscriber, no important bugs, etc). But it's orphaned in Debian. Can I get a comment on how much of a problem the server team thinks that will be? I'll also pass to Seth for a quick look, since this is an authentication module. **

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-01-12 Thread Michael Terry
Passing xmlsec1 to Jamie, since it has security surface. ** Changed in: xmlsec1 (Ubuntu) Assignee: (unassigned) = Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-01-12 Thread Michael Terry
Passing xmlsec1 to Jamie, since it has security surface. ** Changed in: xmlsec1 (Ubuntu) Assignee: (unassigned) = Jamie Strandboge (jdstrand) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to python-pysaml2 in Ubuntu.

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-01-12 Thread Jamie Strandboge
** Changed in: xmlsec1 (Ubuntu) Assignee: Jamie Strandboge (jdstrand) = Seth Arnold (seth-arnold) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to python-pysaml2 in Ubuntu. https://bugs.launchpad.net/bugs/1407695 Title: [MIR]

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-01-12 Thread Jamie Strandboge
** Changed in: xmlsec1 (Ubuntu) Assignee: Jamie Strandboge (jdstrand) = Seth Arnold (seth-arnold) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1407695 Title: [MIR] python-saml2,

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-01-08 Thread James Page
** Description changed: python-pysaml2 Avaliability: In universe Rationale: New dependency for keystone. Security: No CVE's found. - Quality assurance: Unit tests executed as part of package build. + Quality assurance: Unit tests executed as part of package build (two xfails).

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-01-08 Thread James Page
** Description changed: python-pysaml2 Avaliability: In universe Rationale: New dependency for keystone. Security: No CVE's found. - Quality assurance: Unit tests executed as part of package build. + Quality assurance: Unit tests executed as part of package build (two xfails).

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-01-07 Thread James Page
Still working on pysaml2 test suite enablement. ** Changed in: python-pysaml2 (Ubuntu) Status: New = Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1407695 Title: [MIR]

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-01-07 Thread James Page
Still working on pysaml2 test suite enablement. ** Changed in: python-pysaml2 (Ubuntu) Status: New = Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to python-pysaml2 in Ubuntu. https://bugs.launchpad.net/bugs/1407695

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-01-05 Thread James Page
** Description changed: python-pysaml2 Avaliability: In universe Rationale: New dependency for keystone. Security: No CVE's found. Quality assurance: Unit tests executed as part of package build. Dependencies: All in main apart from those identified on this MIR Standards

[Bug 1407695] Re: [MIR] python-saml2, python-repoze.who, xmlsec1

2015-01-05 Thread James Page
** Description changed: python-pysaml2 Avaliability: In universe Rationale: New dependency for keystone. Security: No CVE's found. Quality assurance: Unit tests executed as part of package build. Dependencies: All in main apart from those identified on this MIR Standards