[Openstack] [OSSA 2013-016] Unchecked user input in Swift XML responses (CVE-2013-2161)

2013-06-13 Thread Jeremy Stanley
fix: https://review.openstack.org/32909 Folsom fix: https://review.openstack.org/32911 Notes: This fix will be included in the next release. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2161 https://bugs.launchpad.net/swift/+bug/1183884 -- Jeremy Stanley (fungi) OpenStack

Re: [Openstack] [OSSA 2013-013] Keystone client local information disclosure (CVE-2013-2013)

2013-06-03 Thread Jeremy Stanley
rver components (where we can predict release milestone dates fairly accurately). As a general rule I'm going to try to include the release version numbers in advance when I can do so safely, and otherwise rely on subsequent release announcements. -- Jeremy Stanley __

Re: [Openstack] [OSSA 2013-013] Keystone client local information disclosure (CVE-2013-2013)

2013-06-03 Thread Jeremy Stanley
rt term as they may have the fix in a client reporting to be running an older version. -- Jeremy Stanley ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https://help.launchpad.net/ListHelp

Re: [Openstack] Using openstack to manage dedicated servers in a service provider setting

2013-05-27 Thread Jeremy Stanley
ities and may have simply decided their risk analysis shows it's not worth mitigating in their situations, but many are not aware that this attack surface even exists to begin with. Now, whether can you trust that the computer manufacturing and software industries can solve t

[Openstack] [OSSA 2013-013] Keystone client local information disclosure (CVE-2013-2013)

2013-05-23 Thread Jeremy Stanley
://bugs.launchpad.net/python-keystoneclient/+bug/938315 -- Jeremy Stanley (fungi) OpenStack Vulnerability Management Team signature.asc Description: Digital signature ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net

Re: [Openstack] How can I change my username on openstack Gerrit

2013-05-17 Thread Jeremy Stanley
hange their username once it's been set. I'll follow up with you in a separate private E-mail message to work out the details. -- Jeremy Stanley ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.ne

Re: [Openstack] New code name for networks

2013-05-11 Thread Jeremy Stanley
On 2013-05-11 16:13:39 -0400 (-0400), Monty Taylor wrote: > Jeremy Stanly on IRC just suggested kumquat... [...] Only because I find them extremely tasty and fun to pronounce. -- Jeremy Stanley ___ Mailing list: https://launchpad.net/~openstack P

Re: [Openstack] Related Projects

2013-05-03 Thread Jeremy Stanley
://wiki.openstack.org/wiki/RelatedProjects should just be deleted, the project owners encouraged to register their entries on http://stackmeat.org/ (if they haven't already), and link that from https://wiki.openstack.org/wiki/Projects#Unofficial.2Frelated_projects to improve its discoverability

Re: [Openstack] Related Projects

2013-05-02 Thread Jeremy Stanley
#Unofficial.2Frelated_projects Hopefully this satisfies everyone involved, but if not we can easily change it. -- Jeremy Stanley ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstac

Re: [Openstack] Renting Datacenter Space

2013-04-22 Thread Jeremy Stanley
e to cover colocation of their own equipment at cost (zero margin) since they own and operate their facilities. -- Jeremy Stanley ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https://help.launchpad.net/ListHelp

Re: [Openstack] [DevStack] Does Devstack support grizilly already?

2013-04-15 Thread Jeremy Stanley
entially what we use to perform integration testing, to make sure patches to one component of OpenStack don't result in adverse interactions with another component. -- Jeremy Stanley ___ Mailing list: https://launchpad.net/~openstack Post

Re: [Openstack] Puppet modules for OpenStack?

2013-04-13 Thread Jeremy Stanley
mmunity contribution and attention. Hope that helps! -- Jeremy Stanley ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https://help.launchpad.net/ListHelp

Re: [Openstack] Gerrit Review + SSH

2013-04-05 Thread Jeremy Stanley
protocol, it's actually listening on port 29418 on the Gerrit server not 22 (the former is a Java-based SSH service built into Gerrit's JVM, while we use the latter to be able to remotely manage the underlying GNU/Linux server). -- Jeremy Stanley ___

Re: [Openstack] Gerrit Review + SSH

2013-04-04 Thread Jeremy Stanley
d to port 29418 on our Gerrit server for Git+SSH access on an alternate address and port. I don't think that would need any sort of buy-off from our Infrastructure Team (we can discuss if someone's actually interested in setting it up), but probably wouldn't be

Re: [Openstack] Gerrit Review + SSH

2013-04-04 Thread Jeremy Stanley
on a myriad of other protocols. For non-technology companies that might be fine, but for a technology company that's often a sign that it's going out of business pretty soon. -- Jeremy Stanley ___ Mailing list: https://launchpad.

Re: [Openstack] git review failure

2013-03-18 Thread Jeremy Stanley
ion > timed out [...] This looks more like you have a firewall or network issue preventing outgoing connections to remote systems on 29418/tcp. -- Jeremy Stanley ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchp

Re: [Openstack] Summit conference session?

2013-03-14 Thread Jeremy Stanley
On 2013-03-14 22:49:07 + (+), Jeremy Stanley wrote: > I expect it should be up in a day or two. The chairs have just > finished notifying the speakers and are putting polish on the final > schedule. Or not. The announcement just went out and has the URL to the prelimina

Re: [Openstack] Summit conference session?

2013-03-14 Thread Jeremy Stanley
finished notifying the speakers and are putting polish on the final schedule. -- Jeremy Stanley ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help

Re: [Openstack] Gerrit ssh access fails

2013-03-06 Thread Jeremy Stanley
be able to tell when I have a moment to go digging in Gerrit's DB. -- Jeremy Stanley ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : https://launchpad.net/~openstack More help : https

Re: [Openstack] Comparing OpenStack to OpenNebula

2013-02-25 Thread Jeremy Stanley
m their original domain of control) makes them even less effective of a system identifier from a security perspective. -- Jeremy Stanley ___ Mailing list: https://launchpad.net/~openstack Post to : openstack@lists.launchpad.net Unsubscribe : h

[Openstack] Ongoing post-migration wiki cleanup

2013-02-20 Thread Jeremy Stanley
he old wiki will be taken offline on Friday, March 1st. Hopefully that should be long enough to assist with any significant migration errors. As always, feel free to reply to this message or find us in #openstack-infra on the freenode IRC network if you have any related ques