Re: [openstack-dev] Regarding cache-based cross-VM side channel attacks in OpenStack

2018-08-24 Thread Adam Heczko
> OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://lists.openstack.org/cgi-bin/mailman/li

Re: [openstack-dev] [freezer] PTG planning Etherpad

2018-02-12 Thread Adam Heczko
questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev > > -- Adam Heczko Security Engineer @ Mirantis Inc. __ Op

Re: [openstack-dev] [keystone] Upcoming Deadlines

2017-12-11 Thread Adam Heczko
penstack.org/#/c/512505/ > > [2] https://review.openstack.org/#/c/464763/ > > [3] https://review.openstack.org/#/c/500207/ > > > ______ > OpenStack Developmen

Re: [openstack-dev] [keystone] multiple federated keystones with single Identity Provider

2017-12-08 Thread Adam Heczko
> > Without replicating revocation events, or syncing the assignment table, > > this will lead to security concerns. > > There is also cache invalidation issue. And that would make tokens of > various scope behave in a different manner. A year ago i was -2 on this, > and i sti

Re: [openstack-dev] [all] [tc] Policy Goal Queens-2 Update

2017-12-01 Thread Adam Heczko
> > >> ___ > > >>> OpenStack Development Mailing List (not for usage questions) > > >>> Unsubscribe: > > >>> openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > > >>> http://list

Re: [openstack-dev] [hyper-v] Hyper-V Support Will be Removed Forever ?

2017-11-24 Thread Adam Heczko
ge questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev > > -- Adam Heczko Security Engineer @ Mirantis Inc. ___

Re: [openstack-dev] [security] [api] Script injection issue

2017-11-17 Thread Adam Heczko
Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject: > unsubscribe > > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev > > > > > > -- > Davanum Srinivas :: https://twitter.com/dims > > ______ &

Re: [openstack-dev] [policy] AWS IAM session

2017-10-04 Thread Adam Heczko
gt; >> > >> > >> __ >> > OpenStack Development Mailing List (not for usage questions) >> > Unsubscribe: >> > openstack-dev-requ...@lists.openstack.org?subject:unsubscribe >> > http://lists.openstack.org/cgi-bin/mai

Re: [openstack-dev] Security of Meta-Data

2017-10-03 Thread Adam Heczko
-dev-requ...@lists.openstack.org?subject: > unsubscribe > > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev > > > > __ > OpenStack Development Mailing List (not for usage questions) > Unsubscrib

Re: [openstack-dev] [Glance][Security] Secure Hash Algorithm Spec

2017-09-29 Thread Adam Heczko
_ > OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev > > -- Adam Heczko Security En

Re: [openstack-dev] [api-wg][glance] call for comments on Glance spec for Queens

2017-09-29 Thread Adam Heczko
List (not for usage questions) >> Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscrib >> <http://openstack-dev-requ...@lists.openstack.org?subject:unsubscribe> >> > > __ > OpenStack Development Mailing List (not for usa

Re: [openstack-dev] Janney 2.0 "Data Protection in OpenStack" Summary Presentation

2017-09-22 Thread Adam Heczko
Pages/JanneyTalks_KaitlineFarr.aspx > > Thanks! > > Kaitlin > > __ > OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://li

Re: [openstack-dev] [Glare][TC][All] Past, Present and Future of Glare project

2017-06-27 Thread Adam Heczko
z (ttx) > > __ > OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://lists.openstack.org/cgi-bin/mailman/listinfo/

Re: [openstack-dev] [all] Policy rules for APIs based on "domain_id"

2017-06-20 Thread Adam Heczko
; __ > OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://list

Re: [openstack-dev] [tc][appcat] The future of the App Catalog

2017-03-11 Thread Adam Heczko
n a VM provisioned by Nova. > > > > +1 for "apps that know they're in the cloud", and further apps that know > how to talk to their cloud. > > And also +1 for listening to folks who want a little more help in > interacting with their cloud from inside their VMs. If I've squelched > anyone in t

Re: [openstack-dev] [tc][appcat] The future of the App Catalog

2017-03-09 Thread Adam Heczko
elopment Mailing List (not for usage questions) > > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject: > unsubscribe > > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev > > __ > Op

Re: [openstack-dev] [tc][appcat][murano][app-catalog] The future of the App Catalog

2017-03-08 Thread Adam Heczko
already deployed Murano and are counting on finding > the apps in the app catalog. > > -Christopher > > > > > -- > > Thierry Carrez (ttx) > > > > ____

Re: [openstack-dev] [chef] Making the Kitchen Great Again: A Retrospective on OpenStack & Chef

2017-02-16 Thread Adam Heczko
> OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev > > > > _

Re: [openstack-dev] [openstack-ansible] Ocata deployed on CentOS 7!

2017-01-19 Thread Adam Heczko
Major, thanks for sharing this! On Thu, Jan 19, 2017 at 5:24 PM, Major Hayden wrote: > On 01/19/2017 10:04 AM, Adam Heczko wrote: > > BTW are you implying that Ubuntu LTS is unstable or not stable enough to > run OpenStack? > > I think that it would be valuable if you could

Re: [openstack-dev] [openstack-ansible] Ocata deployed on CentOS 7!

2017-01-19 Thread Adam Heczko
bject:unsubscribe > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev > -- Adam Heczko Security Engineer @ Mirantis Inc. __ OpenStack Development Mailing List (not for usage questions) Unsubscribe: openstack-d

Re: [openstack-dev] [security] [telemetry] How to handle security bugs

2017-01-17 Thread Adam Heczko
oftware hacker >https://julien.danjou.info */ > > __ > OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://lists.openstack.org/cgi-bin/mailman/listinfo/open

Re: [openstack-dev] [Fuel] - Nominate Maksim Malchuk to Fuel Library Core

2016-06-28 Thread Adam Heczko
; >>> __ >>> >> OpenStack Development Mailing List (not for usage questions) >>> >> Unsubscribe: >>> openstack-dev-requ...@lists.openstack.org?subject:unsubscribe >>> >> http://lists.openstack.org/cgi-bin/mailman/

Re: [openstack-dev] [Fuel] [Shotgun] Decoupling Shotgun from Fuel

2016-06-07 Thread Adam Heczko
gt;> > > OpenStack Development Mailing List (not for usage questions) > >>>> > > Unsubscribe: > >>>> > > openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > >>>> > > http://lists.openstack.org/cgi-bin/

Re: [openstack-dev] [Fuel] [Plugins] Netconfig tasks changes

2016-05-25 Thread Adam Heczko
odes won't even have > "Public" network on node interface configuration UI. > > Regards, > Alex > > On Wed, May 25, 2016 at 9:43 AM, Adam Heczko wrote: > >> Hello Alex, >> I have a question about the proposed changes. >> Is it possible to introduce

Re: [openstack-dev] [Fuel] [Plugins] Netconfig tasks changes

2016-05-25 Thread Adam Heczko
w.openstack.org/#/q/I229957b60c85ed94c2d0ba829642dd6e465e9eca,n,z >> > > > ______ > OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe &

Re: [openstack-dev] [Fuel] [Shotgun] Decoupling Shotgun from Fuel

2016-03-30 Thread Adam Heczko
_ >> > OpenStack Development Mailing List (not for usage questions) >> > Unsubscribe: >> openstack-dev-requ...@lists.openstack.org?subject:unsubscribe >> > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev >> >> __

Re: [openstack-dev] [Fuel] [Openstack] Problem after reboot fuel-master VM

2016-03-30 Thread Adam Heczko
y fuel > > Thanks in advance. > > > > > ______ > OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http:

Re: [openstack-dev] [keystone] Single Sign On integration research

2016-03-08 Thread Adam Heczko
s, Kseniya >> >> >> __ >> OpenStack Development Mailing List (not for usage questions) >> Unsubscribe: >> openstack-dev-requ...@lists.openstack.org?subject:unsubscribe >> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstac

Re: [openstack-dev] [kolla][security] Obtaining the vulnerability:managed tag

2016-03-01 Thread Adam Heczko
ng List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev > > -- Adam Heczko Security Engineer @ Mirantis Inc. _

Re: [openstack-dev] [Fuel][Fuel-Library] Nominating Matthew Mosesohn for Fuel Library Core

2016-02-24 Thread Adam Heczko
daev >> >> >> ______ >> OpenStack Development Mailing List (not for usage questions) >> Unsubscribe: >> openstack-dev-requ...@lists.openstack.org?subject:unsubscribe >> http:/

Re: [openstack-dev] [Fuel] Extend FFE for "Disable queue mirroring for RPC queues in RabbitMQ"

2015-12-07 Thread Adam Heczko
equ...@lists.openstack.org?subject:unsubscribe > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev > > -- Adam Heczko Security Engineer @ Mirantis Inc. __ OpenStack Development Mailing List (not for

Re: [openstack-dev] [fuel][plugins]Security problem in Fuel 7.0

2015-12-07 Thread Adam Heczko
penstack.org?subject:unsubscribehttp://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev >>> >>> >>> -- >>> Eugene Korekin >>> Partner Enablement Team Deployment Engineer >>> >>> >>> ______ &

[openstack-dev] [Fuel] API services available on public VIP

2015-11-13 Thread Adam Heczko
uel. Thank you, -- Adam Heczko Security Engineer @ Mirantis Inc. __ OpenStack Development Mailing List (not for usage questions) Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe http://lists.openstack.org/

Re: [openstack-dev] [Fuel] Running Fuel node as non-superuser

2015-11-09 Thread Adam Heczko
t; > __ > OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev &g

Re: [openstack-dev] [Product] [fuel] Life cycle management use cases

2015-10-15 Thread Adam Heczko
g List (not for usage questions) >> > Unsubscribe: >> openstack-dev-requ...@lists.openstack.org?subject:unsubscribe >> > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev >> ___ >> Product-wg mailing list >> product...@lists.openstack.org &

Re: [openstack-dev] FW: [Fuel] 8.0 Region name support / Multi-DC

2015-10-07 Thread Adam Heczko
> >> >> Thanks >> >> >> >> -- >> >> Roman Sokolkov, >> >> Deployment Engineer, >> >> Mirantis, Inc. >> Skype rsokolkov, >> rsokol...@mirantis.com >> >> -- >> >> Chris Clason >> >> Director of Architecture >> >&

Re: [openstack-dev] Apache2 vs uWSGI vs ...

2015-09-25 Thread Adam Heczko
OK, sorry I mixed up nginx and uwsgi :) A. On Fri, Sep 25, 2015 at 2:54 PM, David Stanek wrote: > > On Fri, Sep 25, 2015 at 8:25 AM Adam Heczko wrote: > >> Are we discussing mod_wsgi and Keystone or OpenStack as a general? >> If Keystone specific use case, then pro

Re: [openstack-dev] Apache2 vs uWSGI vs ...

2015-09-25 Thread Adam Heczko
_ >> >> OpenStack Development Mailing List (not for usage questions) >> >> Unsubscribe: >> openstack-dev-requ...@lists.openstack.org?subject:unsubscribe >> >> http://lists.ope

Re: [openstack-dev] [Fuel] Bugs which we should accept in 7.0 after Hard Code Freeze

2015-09-17 Thread Adam Heczko
> -- > Mike Scherbakov > #mihgen > > __ > OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://lists.openstack.org/c

Re: [openstack-dev] [Fuel] Remove MOS DEB repo from master node

2015-09-10 Thread Adam Heczko
;> >> >>> This thread is not about internet connectivity, it is about aligning >> >>> things. >> >>> >> >> >> >> You are correct in that this thread

Re: [openstack-dev] [Fuel] Remove MOS DEB repo from master node

2015-09-10 Thread Adam Heczko
rect in that this thread is not explicitly about internet > >> connectivity, but they are related. Any changes to remove a local > repository > >> and only provide an internet based solution makes internet connectivity > >> something that needs to be incl

Re: [openstack-dev] [Fuel] SSL keys saving

2015-08-21 Thread Adam Heczko
;s > certificates we work in > absolutely different way and store them in absolutely different place. > And this > way leads to huge problems. > > Thanks, > > On Fri, Aug 21, 2015 at 1:33 PM, Adam Heczko wrote: > >> Hi Evgeniy, >> what you've proposed is all rig

Re: [openstack-dev] [Fuel] SSL keys saving

2015-08-21 Thread Adam Heczko
ement according fixes in fuel-library >> >> __ >> OpenStack Development Mailing List (not for usage questions) >> Unsubscribe: >> openstack-dev-requ...@lists.openstack.org?subject:unsubscribe >> http://lists.openstack.org/cgi-bin/mailman/li

Re: [openstack-dev] [Fuel] SSL keys saving

2015-08-21 Thread Adam Heczko
items: > > - Change UI logic that saving keypair into DB to logic that will save it > to local FS > - Implement according fixes in fuel-library > > __ > OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-req

Re: [openstack-dev] [Keystone][Fernet] HA SQL backend for Fernet keys

2015-08-05 Thread Adam Heczko
t; > Right. Here is the fixed version (please don't use it anyway): > http://paste.openstack.org/show/406862/ > > > > Note, this doesn't take into account the initial key repository creation, > does it? > > > > Here is a similar version that relies on rs

Re: [openstack-dev] Would people see a value in the cve-check-tool?

2015-08-03 Thread Adam Heczko
> OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev > > -- Adam Heczko Security Engineer @ Miranti

Re: [openstack-dev] [Keystone][Fernet] HA SQL backend for Fernet keys

2015-08-03 Thread Adam Heczko
ww.traceback.org > twitter: http://twitter.com/dstanek > www: http://dstanek.com > > __ > OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe > http://lists.openst

Re: [openstack-dev] [Keystone][Fernet] HA SQL backend for Fernet keys

2015-08-03 Thread Adam Heczko
main simple. >>>> >>>> >>>> ______ >>>> OpenStack Development Mailing List (not for usage questions) >>>> Unsubscribe: >>>> openstack-dev-requ...@lists.openstack.org?su

Re: [openstack-dev] [Cinder] encryption is not supported in ceph volume

2015-08-02 Thread Adam Heczko
should we prohibit to create a Ceph volume with encrypted > volume type. > > Best wishes > Lisa > > > __ > OpenStack Development Mailing List (not for usage questions) > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subj

Re: [openstack-dev] [fuel] OS_SERVICE_TOKEN usage in Fuel

2015-08-02 Thread Adam Heczko
t;>>>> Unsubscribe: >> >>>>> openstack-dev-requ...@lists.openstack.org?subject:unsubscribe >> >>>>> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev >> >>>> >> >>>> -- >> >>>

[openstack-dev] [Fuel] Add support for Keystone's Fernet encryption keys management: initialization, rotation

2015-07-16 Thread Adam Heczko
ilities will be implemented in Fuel by related blueprint [1]. [1] https://blueprints.launchpad.net/fuel/+spec/fernet-tokens-support [2] http://www.eetimes.com/document.asp?doc_id=1279619 Regards, -- Adam Heczko Security Engineer