Re: Security Policy was: Query regarding where to store encryption keys

2012-07-01 Thread John Kinsella
I just noticed bugs.cloudstack.org has a "Security Level" field, but no options availableā€¦I'm guessing we want to put something there? John On Jun 29, 2012, at 12:43 PM, John Kinsella wrote: > I think that list looks about right. I'm open to ideas on how to manage and > share that PGP key. My

Re: Security Policy was: Query regarding where to store encryption keys

2012-06-29 Thread John Kinsella
I think that list looks about right. I'm open to ideas on how to manage and share that PGP key. My key can be found on the MIT key server, should be on the PGP server soon. Updated URL for wiki page (I removed "draft") http://wiki.cloudstack.org/display/COMM/Security+response+procedure John O

RE: Security Policy was: Query regarding where to store encryption keys

2012-06-29 Thread Clement Chen
A couple of action items: 1. Create an email address - secur...@cloudstack.org as the dedicated communication channel for security issues. 2. Create a PGP key for the above email address. 3. Create a webpage (for example, http://www.cloudstack.org/security) to publish the security policy John cr