[JIRA] (OVIRT-2262) Apply fixes for Jenkins Security Advisory 2018-06-25

2018-06-27 Thread Evgheni Dereveanchin (oVirt JIRA)
ins Security Advisory 2018-06-25 > > > Key: OVIRT-2262 > URL: https://ovirt-jira.atlassian.net/browse/OVIRT-2262 > Project: oVirt - virtualization made easy > Issue Type: Task

[JIRA] (OVIRT-2262) Apply fixes for Jenkins Security Advisory 2018-06-25

2018-06-27 Thread Evgheni Dereveanchin (oVirt JIRA)
Evgheni Dereveanchin created OVIRT-2262: --- Summary: Apply fixes for Jenkins Security Advisory 2018-06-25 Key: OVIRT-2262 URL: https://ovirt-jira.atlassian.net/browse/OVIRT-2262 Project: oVirt

[JIRA] (OVIRT-2199) Set content security policy at Jenkins startup

2018-06-15 Thread Evgheni Dereveanchin (oVirt JIRA)
[ https://ovirt-jira.atlassian.net/browse/OVIRT-2199?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Evgheni Dereveanchin reassigned OVIRT-2199: --- Assignee: Evgheni Dereveanchin (was: infra) > Set content security pol

[JIRA] (OVIRT-2199) Set content security policy at Jenkins startup

2018-06-14 Thread Daniel Belenky (oVirt JIRA)
[ https://ovirt-jira.atlassian.net/browse/OVIRT-2199?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Daniel Belenky updated OVIRT-2199: -- Labels: jenkins standard-ci stdci-summary (was: ) > Set content security policy at Jenk

[JIRA] (OVIRT-2199) Set content security policy at Jenkins startup

2018-06-14 Thread Daniel Belenky (oVirt JIRA)
[ https://ovirt-jira.atlassian.net/browse/OVIRT-2199?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Daniel Belenky updated OVIRT-2199: -- Epic Link: OVIRT-403 > Set content security policy at Jenkins star

[JIRA] (OVIRT-2199) Set content security policy at Jenkins startup

2018-06-14 Thread Daniel Belenky (oVirt JIRA)
Daniel Belenky created OVIRT-2199: - Summary: Set content security policy at Jenkins startup Key: OVIRT-2199 URL: https://ovirt-jira.atlassian.net/browse/OVIRT-2199 Project: oVirt - virtualization made

[JIRA] (OVIRT-1231) Security: do we need HSTS for oVirt services?

2018-06-12 Thread eyal edri (oVirt JIRA)
> Security: do we need HSTS for oVirt services? > - > > Key: OVIRT-1231 > URL: https://ovirt-jira.atlassian.net/browse/OVIRT-1231 > Project: oVirt - virtualization made easy > Is

[JIRA] (OVIRT-1231) Security: do we need HSTS for oVirt services?

2018-06-12 Thread eyal edri (oVirt JIRA)
[ https://ovirt-jira.atlassian.net/browse/OVIRT-1231?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] eyal edri updated OVIRT-1231: - Epic Link: (was: OVIRT-403) > Security: do we need HSTS for oVirt servi

[JIRA] (OVIRT-1231) Security: do we need HSTS for oVirt services?

2018-06-12 Thread eyal edri (oVirt JIRA)
[ https://ovirt-jira.atlassian.net/browse/OVIRT-1231?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] eyal edri updated OVIRT-1231: - Epic Link: (was: OVIRT-403) > Security: do we need HSTS for oVirt servi

[JIRA] (OVIRT-1912) Apply fixes for Jenkins Security Advisory 2018-02-26

2018-02-26 Thread Evgheni Dereveanchin (oVirt JIRA)
Evgheni Dereveanchin created OVIRT-1912: --- Summary: Apply fixes for Jenkins Security Advisory 2018-02-26 Key: OVIRT-1912 URL: https://ovirt-jira.atlassian.net/browse/OVIRT-1912 Project: oVirt

[JIRA] (OVIRT-1912) Apply fixes for Jenkins Security Advisory 2018-02-26

2018-02-26 Thread Evgheni Dereveanchin (oVirt JIRA)
ins Security Advisory 2018-02-26 > > > Key: OVIRT-1912 > URL: https://ovirt-jira.atlassian.net/browse/OVIRT-1912 > Project: oVirt - virtualization made easy > Issue Type: Task

Re: [oVirt/openshift-status-cachet] One of your dependencies may have a security vulnerability

2018-01-22 Thread Eyal Edri
Adding Duck who seems to be the owner of the repo. On Mon, Jan 22, 2018 at 5:50 PM, Yaniv Kaul wrote: > > -- Forwarded message -- > From: GitHub > Date: Mon, Jan 22, 2018 at 5:48 PM > Subject: [oVirt/openshift-status-cachet] One of your dependencies may &g

Fwd: [oVirt/openshift-status-cachet] One of your dependencies may have a security vulnerability

2018-01-22 Thread Yaniv Kaul
-- Forwarded message -- From: GitHub Date: Mon, Jan 22, 2018 at 5:48 PM Subject: [oVirt/openshift-status-cachet] One of your dependencies may have a security vulnerability To: oVirt/openshift-status-cachet < openshift-status-cac...@noreply.github.com> Cc: Security alert

[JIRA] (OVIRT-1718) Apply fixes for Jenkins Security Advisory 2017-10-23

2017-10-25 Thread Evgheni Dereveanchin (oVirt JIRA)
Evgheni Dereveanchin created OVIRT-1718: --- Summary: Apply fixes for Jenkins Security Advisory 2017-10-23 Key: OVIRT-1718 URL: https://ovirt-jira.atlassian.net/browse/OVIRT-1718 Project: oVirt

[JIRA] (OVIRT-1718) Apply fixes for Jenkins Security Advisory 2017-10-23

2017-10-25 Thread Evgheni Dereveanchin (oVirt JIRA)
ins Security Advisory 2017-10-23 > > > Key: OVIRT-1718 > URL: https://ovirt-jira.atlassian.net/browse/OVIRT-1718 > Project: oVirt - virtualization made easy > Issue Type: Bug

Re: Infineon firmware security issues

2017-10-17 Thread Michael Scherer
te: > > > Quack, > > > > So the news (thanks Misc for the alert): > > > > https://www.infineon.com/cms/en/product/promopages/rsa- > > update/rsa-background > > > > This affects Yubikeys and other hardware: > >   https://www.yubico.c

Re: Infineon firmware security issues

2017-10-17 Thread Michael Scherer
ews (thanks Misc for the alert): > > > > > > https://www.infineon.com/cms/en/product/promopages/rsa-update/rsa > > > -bac > > > kground > > > > > > This affects Yubikeys and other hardware: > > >   https://www.yubico.com/support/security-a

Re: Infineon firmware security issues

2017-10-17 Thread Eyal Edri
/rsa-bac > > kground > > > > This affects Yubikeys and other hardware: > > https://www.yubico.com/support/security-advisories/ysa-2017-01/ > > > > There's a nice tool to test if a key is vulnerable: > > https://github.com/crocs-muni/roca > > &

Re: Infineon firmware security issues

2017-10-17 Thread Eyal Edri
; update/rsa-background > > This affects Yubikeys and other hardware: > https://www.yubico.com/support/security-advisories/ysa-2017-01/ > > There's a nice tool to test if a key is vulnerable: > https://github.com/crocs-muni/roca > > I tested keys in the oVirt Puppet repo

Re: Infineon firmware security issues

2017-10-17 Thread Michael Scherer
ps://www.yubico.com/support/security-advisories/ysa-2017-01/ > > There's a nice tool to test if a key is vulnerable: >   https://github.com/crocs-muni/roca > > I tested keys in the oVirt Puppet repository and none are affected. > > You may check your other keys and ensu

Infineon firmware security issues

2017-10-17 Thread Duck
Quack, So the news (thanks Misc for the alert): https://www.infineon.com/cms/en/product/promopages/rsa-update/rsa-background This affects Yubikeys and other hardware: https://www.yubico.com/support/security-advisories/ysa-2017-01/ There's a nice tool to test if a key is vulnerable:

[JIRA] (OVIRT-1695) Apply fixes for Jenkins Security Advisory 2017-10-11

2017-10-13 Thread Evgheni Dereveanchin (oVirt JIRA)
ins Security Advisory 2017-10-11 > > > Key: OVIRT-1695 > URL: https://ovirt-jira.atlassian.net/browse/OVIRT-1695 > Project: oVirt - virtualization made easy > Issue Type: Bug

[JIRA] (OVIRT-1695) Apply fixes for Jenkins Security Advisory 2017-10-11

2017-10-13 Thread Evgheni Dereveanchin (oVirt JIRA)
Evgheni Dereveanchin created OVIRT-1695: --- Summary: Apply fixes for Jenkins Security Advisory 2017-10-11 Key: OVIRT-1695 URL: https://ovirt-jira.atlassian.net/browse/OVIRT-1695 Project: oVirt

[JIRA] (OVIRT-1231) Security: do we need HSTS for oVirt services?

2017-06-29 Thread Duck
too when all our vhosts are ready. And we must not create new vhosts without HTTPS support even for testing. Here are my recommendations. > Security: do we need HSTS for oVirt services? > - > > Key: OVIRT-1231 >

[JIRA] (OVIRT-1231) Security: do we need HSTS for oVirt services?

2017-06-28 Thread Evgheni Dereveanchin (oVirt JIRA)
this? > Security: do we need HSTS for oVirt services? > - > > Key: OVIRT-1231 > URL: https://ovirt-jira.atlassian.net/browse/OVIRT-1231 > Project: oVirt - virtualization made easy >

[JIRA] (OVIRT-1231) Security: do we need HSTS for oVirt services?

2017-03-06 Thread eyal edri [Administrator] (oVirt JIRA)
eyal edri [Administrator] created OVIRT-1231: Summary: Security: do we need HSTS for oVirt services? Key: OVIRT-1231 URL: https://ovirt-jira.atlassian.net/browse/OVIRT-1231 Project: oVirt

[JIRA] (OVIRT-1231) Security: do we need HSTS for oVirt services?

2017-03-06 Thread eyal edri [Administrator] (oVirt JIRA)
[ https://ovirt-jira.atlassian.net/browse/OVIRT-1231?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] eyal edri [Administrator] updated OVIRT-1231: - Epic Link: OVIRT-403 > Security: do we need HSTS for oVirt servi

Re: Security list cleanup

2016-03-23 Thread David Caro
On 03/23 08:28, Eyal Edri wrote: > FYI, > > Due to some error in the lists, some people might have been auto-subscribed > to the secur...@ovirt.org list, while others were already subscribed > without a reason (possibly spam joining by accident). As far as I can tell, everyone that has been subsc

Security list cleanup

2016-03-23 Thread Eyal Edri
FYI, Due to some error in the lists, some people might have been auto-subscribed to the secur...@ovirt.org list, while others were already subscribed without a reason (possibly spam joining by accident). If you were unsubscribed and feel you should remain on the list, please contact me in private

Re: Fwd: *** SECURITY information for linode01.ovirt.org ***

2015-01-21 Thread Sandro Bonazzola
Il 22/01/2015 02:02, Karsten Wade ha scritto: > Not sure who 'mvk' is, shouldn't this person know they're not in the > sudoers file? It was my fault, created the user yesterday to show Max Kovgan the release process > > Forwarded Message >

Fwd: *** SECURITY information for linode01.ovirt.org ***

2015-01-21 Thread Karsten Wade
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Not sure who 'mvk' is, shouldn't this person know they're not in the sudoers file? - Forwarded Message ---- Subject: *** SECURITY information for linode01.ovirt.org *** Date: Wed, 21 Jan 2015 04:33:26 -0500 (EST)

[engineering.redhat.com #319333] Re: [Security] System job to deploy rpms

2015-01-13 Thread Red Hat Product Security
> > Sent: Thursday, October 9, 2014 9:09:20 AM > > > Subject: Re: [engineering.redhat.com #319333] Re: [Security] > System job to deploy rpms > > > > > > Il 08/10/2014 18:18, Red Hat Product Security ha scritto: > > > > On Wed Oct 08 08:35:15 2

[engineering.redhat.com #319333] Re: [Security] System job to deploy rpms

2015-01-13 Thread Red Hat Product Security
On Thu Oct 09 00:09:25 2014, sbona...@redhat.com wrote: > Il 08/10/2014 18:18, Red Hat Product Security ha scritto: > > On Wed Oct 08 08:35:15 2014, sbona...@redhat.com wrote: > >> Il 08/10/2014 12:02, Ohad Basan ha scritto: > >>> Hello everyone. > >>&g

[engineering.redhat.com #319333] Re: [Security] System job to deploy rpms

2015-01-13 Thread Red Hat Product Security
; > for this I've sent this patch http://gerrit.ovirt.org/#/c/33863/ > > that will add the "resources" user. it will have permissions only > for the static rpms directory and will scp the files to there. > > is it acceptable by everybody security-wise? > > >

Re: [engineering.redhat.com #319333] Re: [Security] System job to deploy rpms

2014-10-13 Thread David Caro
On 10/12, Eyal Edri wrote: > > > - Original Message - > > From: "Sandro Bonazzola" > > To: secal...@redhat.com > > Cc: secur...@ovirt.org, infra@ovirt.org > > Sent: Thursday, October 9, 2014 9:09:20 AM > > Subject: Re: [engineering

Re: [engineering.redhat.com #319333] Re: [Security] System job to deploy rpms

2014-10-11 Thread Eyal Edri
- Original Message - > From: "Sandro Bonazzola" > To: secal...@redhat.com > Cc: secur...@ovirt.org, infra@ovirt.org > Sent: Thursday, October 9, 2014 9:09:20 AM > Subject: Re: [engineering.redhat.com #319333] Re: [Security] System job to > deploy rpms &

Re: [engineering.redhat.com #319333] Re: [Security] System job to deploy rpms

2014-10-08 Thread Sandro Bonazzola
Il 08/10/2014 18:18, Red Hat Product Security ha scritto: > On Wed Oct 08 08:35:15 2014, sbona...@redhat.com wrote: >> Il 08/10/2014 12:02, Ohad Basan ha scritto: >>> Hello everyone. >>> >>> I've created a small job (not yet enabled) >>> that get

Re: Fwd: [foreman-announce] Foreman 1.5.1 security, bug fix and enhancement update

2014-06-19 Thread Ewoud Kohl van Wijngaarden
minutes. I should have sent an email right after the update, but the upgrade went smooth. If you notice any issues, please report them. > > > > > Original Message > > Subject: [foreman-announce] Foreman 1.5.1 security, bug fix and enhancement > > up

Re: Fwd: [foreman-announce] Foreman 1.5.1 security, bug fix and enhancement update

2014-06-19 Thread Ewoud Kohl van Wijngaarden
On Wed, Jun 18, 2014 at 03:30:52PM +0200, David Caro wrote: > Maybe it's worth updating foreman Given we already run 1.5.0 and I'm doing so now. Foreman may be unavailable for a few minutes. > > Original Message > Subject: [foreman-announce] Foreman 1.5.1

Fwd: [foreman-announce] Foreman 1.5.1 security, bug fix and enhancement update

2014-06-18 Thread David Caro
Maybe it's worth updating foreman Original Message Subject: [foreman-announce] Foreman 1.5.1 security, bug fix and enhancement update Date: Wed, 18 Jun 2014 13:25:10 +0100 From: Dominic Cleal Reply-To: foreman-users To: foreman-announce ,foreman-users Foreman

Re: infra security update

2014-06-09 Thread Michael Scherer
Le dimanche 08 juin 2014 à 02:55 -0400, Eyal Edri a écrit : > > - Original Message - > > From: "Michael Scherer" > > To: infra@ovirt.org > > Sent: Friday, June 6, 2014 2:29:44 PM > > Subject: infra security update > > > > Hi, > &g

Re: infra security update

2014-06-07 Thread Eyal Edri
- Original Message - > From: "Michael Scherer" > To: infra@ovirt.org > Sent: Friday, June 6, 2014 2:29:44 PM > Subject: infra security update > > Hi, > > Due to CVE on openssl and on kernel, I did upgrade various piece of the > infrastructur

Re: infra security update

2014-06-06 Thread Michael Scherer
Le vendredi 06 juin 2014 à 14:36 +0200, Ewoud Kohl van Wijngaarden a écrit : > On Fri, Jun 06, 2014 at 01:29:44PM +0200, Michael Scherer wrote: > > Due to CVE on openssl and on kernel, I did upgrade various piece of the > > infrastructure ( foreman, lists, stats, monitoring ), which implied a > > f

Re: infra security update

2014-06-06 Thread Ewoud Kohl van Wijngaarden
On Fri, Jun 06, 2014 at 01:29:44PM +0200, Michael Scherer wrote: > Due to CVE on openssl and on kernel, I did upgrade various piece of the > infrastructure ( foreman, lists, stats, monitoring ), which implied a > few reboots ( due to kernel lagging behind, which is not that great with > local root

infra security update

2014-06-06 Thread Michael Scherer
Hi, Due to CVE on openssl and on kernel, I did upgrade various piece of the infrastructure ( foreman, lists, stats, monitoring ), which implied a few reboots ( due to kernel lagging behind, which is not that great with local root exploit ). As this is friday and I assumed most of the Tel Aviv offi

Re: Security

2013-10-09 Thread Kiril Nesenko
I did this for all jenkins slaves on rackspace* servers. So +1 for the idea. - Kiril - Original Message - > From: "Ewoud Kohl van Wijngaarden" > To: infra@ovirt.org > Sent: Wednesday, October 9, 2013 12:18:02 PM > Subject: Re: Security > > On Wed, Oct

Re: Security

2013-10-09 Thread Ewoud Kohl van Wijngaarden
On Wed, Oct 09, 2013 at 10:41:36AM +0200, Vinzenz Feenstra wrote: > I see again quite a lot of "POSSIBLE BREAK-IN ATTEMPT" alerts lately > mainly originating from *hichina.com > > Could you guys please address this? Thanks What do you think of disabling SSH passwords and use just SSH keys? Fairly

Security

2013-10-09 Thread Vinzenz Feenstra
Hi, I see again quite a lot of "POSSIBLE BREAK-IN ATTEMPT" alerts lately mainly originating from *hichina.com Could you guys please address this? Thanks On 10/09/2013 09:15 AM, logwa...@linode01.ovirt.org wrote: SFTP subsystem requests: 2 Time(s) **Unmatched Entries** Address 198

A security issue in ovirt 3.2 on fedora - setup leaves a world-writable /etc/sysconfig/nfs

2013-10-08 Thread Yedidyah Bar David
ld the ISO domain. A fix for this bug was pushed to gerrit: http://gerrit.ovirt.org/19557 Security implications: This bug allows local users escalate their privileges by editing /etc/sysconfig/nfs and waiting until the nfs service will be started/stopped (e.g. a reboot of the machine)

Jenkins upgrade due to critical security notice

2012-11-23 Thread Eyal Edri
fyi, i've upgraded jenkins.ovirt.org to latest LTS version, due to security alert. [1] jenkins is now running 1.480.1 changelog: What's new in 1.480.1 (2012/11/17) FilePath.validateAntFileMask too slow for /configure (issue 7214) java.io.InvalidClassException (issue 14667) Log re

Re: Security issues when running gerrit patches on jenkins

2012-08-01 Thread Eyal Edri
- Original Message - > From: "Itamar Heim" > To: "Robert Middleswarth" > Cc: infra@ovirt.org > Sent: Wednesday, August 1, 2012 5:01:10 PM > Subject: Re: Security issues when running gerrit patches on jenkins > > On 08/01/2012 04:56 PM, Robert

Re: Security issues when running gerrit patches on jenkins

2012-08-01 Thread Itamar Heim
On 08/01/2012 04:56 PM, Robert Middleswarth wrote: On 08/01/2012 09:50 AM, Ewoud Kohl van Wijngaarden wrote: On Wed, Aug 01, 2012 at 09:35:39AM -0400, Robert Middleswarth wrote: On 08/01/2012 09:31 AM, Eyal Edri wrote: Itamar Heim wrote: wouldn't it be easier to maintain the whitelist via a g

Re: Security issues when running gerrit patches on jenkins

2012-08-01 Thread Robert Middleswarth
On 08/01/2012 09:50 AM, Ewoud Kohl van Wijngaarden wrote: On Wed, Aug 01, 2012 at 09:35:39AM -0400, Robert Middleswarth wrote: On 08/01/2012 09:31 AM, Eyal Edri wrote: Itamar Heim wrote: wouldn't it be easier to maintain the whitelist via a git repo on gerrit? you mean instead of putting it o

Re: Security issues when running gerrit patches on jenkins

2012-08-01 Thread Eyal Edri
- Original Message - > From: "Ewoud Kohl van Wijngaarden" > To: infra@ovirt.org > Sent: Wednesday, August 1, 2012 4:50:03 PM > Subject: Re: Security issues when running gerrit patches on jenkins > > On Wed, Aug 01, 2012 at 09:35:39AM -0400, Robert Middleswa

Re: Security issues when running gerrit patches on jenkins

2012-08-01 Thread Ewoud Kohl van Wijngaarden
On Wed, Aug 01, 2012 at 09:35:39AM -0400, Robert Middleswarth wrote: > On 08/01/2012 09:31 AM, Eyal Edri wrote: > > Itamar Heim wrote: > >> wouldn't it be easier to maintain the whitelist via a git repo on > >> gerrit? > > > > you mean instead of putting it on a wiki page? > > yes, make sense to ma

Re: Security issues when running gerrit patches on jenkins

2012-08-01 Thread Itamar Heim
On 08/01/2012 04:35 PM, Robert Middleswarth wrote: On 08/01/2012 09:31 AM, Eyal Edri wrote: - Original Message - From: "Itamar Heim" To: "Eyal Edri" Cc: "Robert Middleswarth" , infra@ovirt.org Sent: Wednesday, August 1, 2012 4:08:41 PM Subject: Re

Re: Security issues when running gerrit patches on jenkins

2012-08-01 Thread Robert Middleswarth
On 08/01/2012 09:31 AM, Eyal Edri wrote: - Original Message - From: "Itamar Heim" To: "Eyal Edri" Cc: "Robert Middleswarth" , infra@ovirt.org Sent: Wednesday, August 1, 2012 4:08:41 PM Subject: Re: Security issues when running gerrit patches on jenkins

Re: Security issues when running gerrit patches on jenkins

2012-08-01 Thread Eyal Edri
- Original Message - > From: "Itamar Heim" > To: "Eyal Edri" > Cc: "Robert Middleswarth" , infra@ovirt.org > Sent: Wednesday, August 1, 2012 4:08:41 PM > Subject: Re: Security issues when running gerrit patches on jenkins

Re: Security issues when running gerrit patches on jenkins

2012-08-01 Thread Itamar Heim
On 08/01/2012 02:56 PM, Eyal Edri wrote: - Original Message - From: "Robert Middleswarth" To: "Eyal Edri" Cc: infra@ovirt.org Sent: Tuesday, July 31, 2012 8:35:25 PM Subject: Re: Security issues when running gerrit patches on jenkins On 07/31/2012 01:19

Re: Security issues when running gerrit patches on jenkins

2012-08-01 Thread Eyal Edri
- Original Message - > From: "Robert Middleswarth" > To: "Eyal Edri" > Cc: infra@ovirt.org > Sent: Tuesday, July 31, 2012 8:35:25 PM > Subject: Re: Security issues when running gerrit patches on jenkins > > On 07/31/2012 01:19 PM, Eyal E

Re: Security issues when running gerrit patches on jenkins

2012-07-31 Thread Robert Middleswarth
On 07/31/2012 01:19 PM, Eyal Edri wrote: - Original Message - From: "Robert Middleswarth" To: infra@ovirt.org Sent: Tuesday, July 31, 2012 7:55:49 PM Subject: Re: Security issues when running gerrit patches on jenkins On 07/31/2012 10:37 AM, Karsten 'quaid' Wad

Re: Security issues when running gerrit patches on jenkins

2012-07-31 Thread Eyal Edri
- Original Message - > From: "Robert Middleswarth" > To: infra@ovirt.org > Sent: Tuesday, July 31, 2012 7:55:49 PM > Subject: Re: Security issues when running gerrit patches on jenkins > > On 07/31/2012 10:37 AM, Karsten 'quaid' Wade wr

Re: Security issues when running gerrit patches on jenkins

2012-07-31 Thread Robert Middleswarth
On 07/31/2012 10:37 AM, Karsten 'quaid' Wade wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 07/18/2012 04:05 AM, Eyal Edri wrote:> Hi, Following last infra meeting, i want to open for discussion the security issues that may arise if we allow Jenkins to run jobs (i.e a

Re: Security issues when running gerrit patches on jenkins

2012-07-31 Thread Karsten 'quaid' Wade
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 07/18/2012 04:05 AM, Eyal Edri wrote:> Hi, > > Following last infra meeting, i want to open for discussion the > security issues that may arise if we allow Jenkins to run jobs (i.e > any code) with every gerrit patch. > > -

Re: Security issues when running gerrit patches on jenkins

2012-07-18 Thread Itamar Heim
On 07/18/2012 11:47 PM, Karsten 'quaid' Wade wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 07/18/2012 10:00 AM, Robert Middleswarth wrote: I am on the opposite side of this issue. Maybe I have been attacked by 1 to many bot's or been a manager when someone I know and trusted stole f

Re: Security issues when running gerrit patches on jenkins

2012-07-18 Thread Karsten 'quaid' Wade
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 07/18/2012 10:00 AM, Robert Middleswarth wrote: >> I am on the opposite side of this issue. Maybe I have been >> attacked by 1 to many bot's or been a manager when someone I >> know and trusted stole from the company. I need trust to be >> earne

Re: Security issues when running gerrit patches on jenkins

2012-07-18 Thread Heiko W.Rupp
Am 18.07.2012 um 15:57 schrieb Heiko W.Rupp: > That would match the pattern of not automatically running every > submission directly on gerrit until they have proven that they > know what they are doing. Which is what they are used with not getting full commit access on day 1. -- Reg. Adresse:

Re: Security issues when running gerrit patches on jenkins

2012-07-18 Thread Heiko W.Rupp
Am 18.07.2012 um 13:43 schrieb Mike Burns: > It's not commit access that is being discussed. We're not giving that > away easily. Jenkins provides the ability to trigger builds/tests on > patch submission (just submission, not commit). A savvy attacker could > write a patch that could cause the

Re: Security issues when running gerrit patches on jenkins

2012-07-18 Thread Eyal Edri
- Original Message - > From: "Robert Middleswarth" > To: "Eyal Edri" > Cc: "Mike Burns" , infra@ovirt.org > Sent: Wednesday, July 18, 2012 10:17:36 PM > Subject: Re: Security issues when running gerrit patches on jenkins

Re: Security issues when running gerrit patches on jenkins

2012-07-18 Thread Robert Middleswarth
On 07/18/2012 03:10 PM, Eyal Edri wrote: - Original Message - From: "Mike Burns" To: "Eyal Edri" Cc: "Robert Middleswarth" , infra@ovirt.org Sent: Wednesday, July 18, 2012 8:45:05 PM Subject: Re: Security issues when running gerrit patches on jenkin

Re: Security issues when running gerrit patches on jenkins

2012-07-18 Thread Eyal Edri
- Original Message - > From: "Mike Burns" > To: "Eyal Edri" > Cc: "Robert Middleswarth" , infra@ovirt.org > Sent: Wednesday, July 18, 2012 8:45:05 PM > Subject: Re: Security issues when running gerrit patches on jenkins > >

Re: Security issues when running gerrit patches on jenkins

2012-07-18 Thread Mike Burns
On Wed, 2012-07-18 at 13:03 -0400, Eyal Edri wrote: > > - Original Message - > > From: "Robert Middleswarth" > > To: infra@ovirt.org > > Sent: Wednesday, July 18, 2012 8:00:44 PM > > Subject: Re: Security issues when running gerrit patches on

Re: Security issues when running gerrit patches on jenkins

2012-07-18 Thread Mike Burns
On Wed, 2012-07-18 at 13:34 -0400, Heiko W.Rupp wrote: > Am 18.07.2012 um 13:00 schrieb Robert Middleswarth: > > > I need trust to be earned so I +1 on whitelist. With that said I think > > getting on the whitelist should be pretty easy. > > Isn't that what you usually do on projects - have t

Re: Security issues when running gerrit patches on jenkins

2012-07-18 Thread Heiko W.Rupp
Am 18.07.2012 um 13:00 schrieb Robert Middleswarth: > I need trust to be earned so I +1 on whitelist. With that said I think > getting on the whitelist should be pretty easy. Isn't that what you usually do on projects - have the first few commits not directly go to master but being reviewe

Re: Security issues when running gerrit patches on jenkins

2012-07-18 Thread Eyal Edri
- Original Message - > From: "Robert Middleswarth" > To: infra@ovirt.org > Sent: Wednesday, July 18, 2012 8:00:44 PM > Subject: Re: Security issues when running gerrit patches on jenkins > > On 07/18/2012 10:40 AM, Karsten 'quaid' Wade wr

Re: Security issues when running gerrit patches on jenkins

2012-07-18 Thread Robert Middleswarth
On 07/18/2012 10:40 AM, Karsten 'quaid' Wade wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 07/18/2012 06:20 AM, Dan Kenigsberg wrote: On Wed, Jul 18, 2012 at 07:05:16AM -0400, Eyal Edri wrote: Hi, Following last infra meeting, i want to open for discussion the security i

Re: Security issues when running gerrit patches on jenkins

2012-07-18 Thread Karsten 'quaid' Wade
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 07/18/2012 06:20 AM, Dan Kenigsberg wrote: > On Wed, Jul 18, 2012 at 07:05:16AM -0400, Eyal Edri wrote: >> Hi, >> >> Following last infra meeting, i want to open for discussion the >> security issues that may arise if w

Re: Security issues when running gerrit patches on jenkins

2012-07-18 Thread Dan Kenigsberg
On Wed, Jul 18, 2012 at 07:05:16AM -0400, Eyal Edri wrote: > Hi, > > Following last infra meeting, i want to open for discussion the security > issues that may arise if we allow Jenkins > to run jobs (i.e any code) with every gerrit patch. > > The problem: > >

Security issues when running gerrit patches on jenkins

2012-07-18 Thread Eyal Edri
Hi, Following last infra meeting, i want to open for discussion the security issues that may arise if we allow Jenkins to run jobs (i.e any code) with every gerrit patch. The problem: In theory, any user that is registered to gerrit might send a patch to any ovirt project. That code might

Re: ovirt.org / security mailing lists

2012-01-23 Thread Petr Matousek
On Fri, Jan 20, 2012 at 12:26:43PM -0800, Karsten 'quaid' Wade wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > On 01/19/2012 09:46 AM, Petr Matousek wrote: > > Hi Karsten, > > > > we have a wiki page describing ovirt.org security mailing lists

Re: ovirt.org / security mailing lists

2012-01-20 Thread Karsten 'quaid' Wade
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/19/2012 09:46 AM, Petr Matousek wrote: > Hi Karsten, > > we have a wiki page describing ovirt.org security mailing lists > [1], but I think we should at least mention the security mailing > lists and how we handle securit

Re: ovirt.org / security mailing lists

2012-01-20 Thread Carl Trieloff
On 01/19/2012 06:59 PM, David Jorm wrote: > On 01/20/2012 03:46 AM, Petr Matousek wrote: >> Hi Karsten, >> >> we have a wiki page describing ovirt.org security mailing lists [1], but >> I think we should at least mention the security mailing lists and how we >&

Re: ovirt.org / security mailing lists

2012-01-20 Thread David Jorm
On 01/20/2012 03:46 AM, Petr Matousek wrote: Hi Karsten, we have a wiki page describing ovirt.org security mailing lists [1], but I think we should at least mention the security mailing lists and how we handle security issues on our community page [2]. [1] http://ovirt.org/wiki/Security

ovirt.org / security mailing lists

2012-01-19 Thread Petr Matousek
Hi Karsten, we have a wiki page describing ovirt.org security mailing lists [1], but I think we should at least mention the security mailing lists and how we handle security issues on our community page [2]. [1] http://ovirt.org/wiki/Security [2] http://www.ovirt.org/project/community/ In