To Software Software - To Software-Assessment - Software/Assessment - To previous meeting - To next meeting
Minutes of the MiniTOP on the 2011-08-02
Setting
The MiniTOP will be held via telco 22:00 CEST
Attendees: Magu, Benedikt F, Marcus, Dirk, Uli, Ted, Michael, Alex
Topics
(skip to agenda)
Action items from last meeting Meeting Action Items
Agenda
- PRO
- Milestone 3 of Software-Assessment project team reached? "Build + Document Emergency Patches Path"
- As a side effect on writing the AGM 2010-2011 report, the reach of milestone 3 comes to question
- The side effect becomes possible by the last meeting vote on parallele processing of patches
- how about documentation?
- how to handle / work with git
- git pull
git diff origin/release...origin/bug-921>bug921.patch
- send to critical team by email (with template)
- link to bug, who reviewed, people to cc
- Workshop - The List of open / running / unhandled bugs
x1 Arbitration case a20110312.1 Weak keys bug #918 / bug #954 / bug#964
- Current state:
{g}
pre mailing sent
{g}
keys revocation script to bulk revoke weak keys, new bug #954, finished
{-}
dirk: DEV: a20110312.1 bug#918 Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEV
vbscript needs to be improved with select box key size and lower limit to 2048 (based on https://wiki.mozilla.org/CA:MD5and1024)
Api CertEnroll (MS crypto provider)
new bug#964
current state: test /account/4.php added to testserver
Marcus will do detailed tests on Wed
some references added to bug#964{g}
Weak keys blog post, published
{0}
Weak keys article not yet published by Hanno
{b}
weak keys: problems with cryptostick (to test at Froscon with Juergen ?)
- Current state:
x2 Bug# 827 and bug #959 "Thawte" patch - Points-Count-Order-Change project - 2nd Review + deploy
x3 Bug #637 and bug #953 and bug #963 : Weak Passwords - 2nd Review + deploy
- Overall result: Please evaluate if the session problem can be fixed!
- if password changed, cached info - reminder plz change pwd
- session reset and error messages in system log
new bug #963
- /includes/loggedin.php line 140 ff. to fix
- Ted: checked-in cacert-devel, added to testserver
- needs review, re-testing
- Next steps:
{-} maybe we have a potential problem here: Bug #637 is transfered to critical system, bug #953 and bug #963 aren't. 637 depends on 653 and 963. On testserver this _complete_ bundle works.
x4 bug #841 Problems on cert login
needs 2nd review - Ted, done
needs bundling, done- NEO: did restructuring (sql query to subroutine), (Update 2011-07-26)
- needs re-tested
- needs 2nd review, bundling
Dirk reminder (from last meeting) assure someone patches (checkboxes)
Dirk
DEV: bug #894 problems with check-boxes on website forms (Assure someone) -> a20091118.3
{0}
- Review 1: review, add to cacert-devel, transfer to testserver
Dirk, Michael, Ted
bug #957 Resize the comment field on https://secure.cacert.org/account.php?id=27 so more information is visible
{0}
Dirk, Michael, Ted
bug #965 0000965: Outsource / fix Webdb text pages id=12, 13
{0}
- Review bugs under testing (finished testing?) (Review 2?)
needs 1 more test, needs 2nd review
2nd review: also check -x
tests done, 2nd review outstanding{0}
{g}needs 2nd review, not Micha -> Ted, done
Overall result: Please evaluate if the session problem can be fixed! (new bug #963){g}
{0}
{0}x4 NEO: bug #841 Problems on cert login
needs 2nd review - Ted, done
needs bundled
NEO will check to get sql query extracted
needs pushing
pushed to testserver
Needs Review & testing{0}
bug #910 Outsource board member list
from Webdb to wiki (id=8) (Part II)
{0}
bug #955 change sort order Orga list
Possibilty to change the sorting order for the organisation overview
{0}
- (review), to bundle, to deploy
bug #942 CATS import (2)
complete re-test as of code changes
fully re-tested by 2 testers{0}
bug #911 gpg bug
gpg keys expires 1970
tests started 2 weeks ago
needs review, deploy{0}
bug #940 help* to wiki
Outsource Webdb text pages help.php?id=0..9 to wiki
needs review, deploy{0}
bug #953 failure on pwd change redirect
needs 2nd review, deploy
{0}
- Needs development, deployment, discussion
x1 Dirk, new bug#964
DEV: bug#918 (Part II) (a20110312.1) Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEVcurrent state: test /account/4.php added to testserver
Marcus will do detailed tests on Wed
some references added to bug#964{-}
bug #835 Assurer challenge (on testserver)
asssigned to Ted, set to needs work, CATS to install on ca-mgr1
{0}
bug #943 change OA admin/assurer text
-> Ted, rejected, needs comment from OAO
{-}
ADS Challenge, Advertising
{0}
- Deployed, Finished
Ted
bug #921 Privacy Policy cleanup
Marcus: 2nd test {g} / Dirk, Ted: 2nd review {g}
{g}
Michael
bug #954 (a20110312.1) Next: script to bulk revoke weak keys
deployed
{g} {g}
Michael
x3 bug #637 weak password
{g}
Michael
x2 bug #959 - patch for bug #827 Thawte patch/Points-Count-Order-Change project
deployed w/o bug #827
{g}
strategy plans ... next: strategy for "New Roots & Escrow"
- idea: using indirect crl's ?
- 2 crl's needed, one valid, one invalid crl server
- more infos available ? who ?
- build testserver with special certs
- Magu, Michael to send instructions for test deployment
indirect CRL: RFC 5280 http://tools.ietf.org/html/rfc5280 (chapter 5)
- meetings ago we've defined Testing requirements and a potential testszenario
- to remind every meeting
- policy group: define requirements
- multimember escrow method ?
- needs risk analyze
- potential candidates ?
- Marcus to contacted Benedikt, will contact Thomas K
- Next step(s)
- multimember escrow method ?
- how does debian work ?
- defered to Froscon (end of Aug), CCCcamp (around Aug 10th)
- idea: using indirect crl's ?
- Software-Assessment project team report finished, plz review
- Weak keys / Weak passwords missing
- Sections added:
- Weak Keys / Weak Passwords Arbitration cases
- The Software-Testteam
- Software-Assessment Documentation
- Statistics
- Summary
- Documentation Bugs.cacert.org Review
- discussion about states to define, redefine
bugs documentation I (bugs handbook)
bugs documentation II (to incorporate into the Software-Update-Cycle procedure/documentation)
- Review, Update
- svg pictures have cuted text under some browsers
- u60: cant get it scaled
- CI (Update)
- deployment scenario:
- create testusers
- testing
- delete testusers
- regression test for standard tests: eg 0,1,49,50,51,99,100,101 pts w/ and w/o CATS passed
- reminder
- next meeting: Tuesday, August 9, 2011 22:00
Minutes
- PRO
question from board -> PR officer
- request to Alex
- support from all
- Milestone 3 of Software-Assessment project team reached? "Build + Document Emergency Patches Path"
- As a side effect on writing the AGM 2010-2011 report, the reach of milestone 3 comes to question
- The side effect becomes possible by the last meeting vote on parallele processing of patches
- how about documentation?
- git allows several branches
- documentation
- who decides that issue is an emergency patch ?
- disconnect machine from network
- what if a check of user data is needed?
- simple case: Software Assessor requests emergency patch thru critical admin
- publishing "Weak key" issue
- awaiting Hanno's publishing
- how to handle / work with git
- git pull
git diff origin/release...origin/bug-921>bug921.patch
- send to critical team by email (with template)
- link to bug, who reviewed, people to cc
- git pull / git clone
- git clone is from scratch, local branches that exists before not included
- git pull
- branches will be merged, but don't cover all branches
- local changes not pushed to master
- Ted: commited branch to wrong place instead of origin/release
- Froscon coordinations
- Workshop - The List of open / running / unhandled bugs
x1 Arbitration case a20110312.1 Weak keys bug #918 / bug #954 / bug#964
- Current state:
{g}
pre mailing sent
{g}
keys revocation script to bulk revoke weak keys, new bug #954, finished
{-}
dirk: DEV: a20110312.1 bug#918 Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEV
vbscript needs to be improved with select box key size and lower limit to 2048 (based on https://wiki.mozilla.org/CA:MD5and1024)
Api CertEnroll (MS crypto provider)
new bug#964
current state: test /account/4.php added to testserver
Marcus will do detailed tests on Wed
some references added to bug#964{g}
Weak keys blog post, published
{0}
Weak keys article not yet published by Hanno
{b}
weak keys: problems with cryptostick (to test at Froscon with Juergen ?)
cert enroll infos under bug#964
vista and win7 works with other engine !CryptoAPI (?) => Cryptography API: Next Generation
- Hanno published the article (July 28), link is in CAcert's blog post (July 30)
- Current state:
x2 Bug# 827 and bug #959 "Thawte" patch - Points-Count-Order-Change project - 2nd Review + deploy
- Next step(s) ?
current state on production system? table points: count(id) > 150 points ?
fix points < 0 and points > 150 in bug 827 ?
- included
missing: bug #959 2nd review
- dirk to add note in bugtracker, done
- todo:
bug #959 deployed
- 2nd review and bundling by Ted
- bundling instruction to critical team, deploy 15.php, and 7 days later 10.php
- Next step(s) ?
x3 Bug #637 and bug #953 and bug #963 : Weak Passwords - 2nd Review + deploy
- Overall result: Please evaluate if the session problem can be fixed!
- if password changed, cached info - reminder plz change pwd
- session reset and error messages in system log
new bug #963
- /includes/loggedin.php line 140 ff. to fix
- Ted: checked-in cacert-devel, added to testserver
- needs review, re-testing
- Next steps:
{-} maybe we have a potential problem here: Bug #637 is transfered to critical system, bug #953 and bug #963 aren't. 637 depends on 653 and 963. On testserver this _complete_ bundle works.
- 953: 2nd review, Dirk
- go into repository
- git fetch --all
- no option all
- git fetch origin
- git diff origin/release...origin/bug-953
- bundle: NEO
- 963: addtl. for while loops ... Michael is checking
- bundle: NEO
x4 bug #841 Problems on cert login
needs 2nd review - Ted, done
needs bundling, done- NEO: did restructuring (sql query to subroutine), (Update 2011-07-26)
- needs re-tested
- needs 2nd review, bundling
=> Ted on Wed
- Needs development, deployment, discussion
- change OA admin/assurer text
bug #943 change OA admin/assurer text
-> Ted, rejected, needs comment from OAO
{-}
webdb names OrgAdmins as OrgAssurers and names OrgAssurers as OrgAdmins.
- patch takes account about this issue
- problem with menu link Org Admin .. is Org Assurers menu
- but this menu includes one addtl. link "View" that is available for Org Admins
- and Org Admins with master flag to add new admins
master flag is not described in OAP
- addtl master flag to revoke ?
- rename to "Org Administration"
don't show menu to OrgAdmins
- but this menu includes one addtl. link "View" that is available for Org Admins
- change OA admin/assurer text
Marcus: OA Arb mailing case (a20110608.1: motion for mailing passed (=m20110731.2)
- next: translations
tests ok, but the question is, is OrgAdmin allowed to remove other admins ? yes or no?
- current scenario doesn't allow removal of other admin
- NEO: reset testserver state to fix state before bugfix
- NEO: re-add bug 966 to testserver
- bug needs more work, selection currently clashes with language setting (Delete != Löschen)
- general problem in /pages/account.php with process variable, transfer of "cancel" pushes any action
Fixed Action Items since last or within meeting
Ted
bug #921 Privacy Policy cleanup
Marcus: 2nd test {g} / Dirk, Ted: 2nd review {g}
{g}
Michael
bug #954 (a20110312.1) Next: script to bulk revoke weak keys
awaiting 2nd response
{g} {g}
Dirk, Ted
bug #637 weak password
{g}
Neo
bug #959 - patch for bug #827 Thawte patch/Points-Count-Order-Change project
deployed w/o bug #827
{g}
Action Items New
Uli
"Build + Document Emergency Patches Path"
documentation
who decides that issue is an emergency patch ?
disconnect machine from network
what if a check of user data is needed?
simple case: Software Assessor requests emergency patch thru critical admin{0}
Action items: Meeting Action Items
Software/Assessment/ActionItems
all
proposed Apache config SSLCipherSuite settings for CAcert SSL enabled infrastructure systems
see also BEAST migration https://community.qualys.com/blogs/securitylabs/2011/10/17/mitigating-the-beast-attack-on-tls
Proposal from Sysadm list 2013-09-06{0}
SA
documentation server cert design concept to SystemAdministration/Systems/Development/Prepare
{0}
all
{0}
BenBE, Marcus
documentation: developer git repos under github
bug #1131 history @ github
CAcertOrg @ github
started under Software/Assessment/Documentation/UpdateCycle/step1{0}
NEO
{0}
all
read x509 guide
{0}
all
bug#1068 blog problem (also relates to community)
debian lenny - edge - squeeze upgrades needed
alternate: new server with squeeze, install wordpress, transfer domain
workaround: configure your FF FAQ/BrowserClients{g}
uli
Experience points for ATE attendance
check board motions and/or trigger if not yet passed{0}
uli
Infrastructure separation, to contact secure-u (Frank, Mario, Ted, Sebastian) for discussion, prepare a plan, started 2011-12-18
current state: see Funding Landing Page
May 2013: tk-server sponsoring, tk-server rcvd, deployment: WIP, project not yet finished{0}
All
1. next: strategy for "New Roots & Escrow" - using indirect crl's ?
indirect CRL: RFC 5280 http://tools.ietf.org/html/rfc5280 (chapter 5) - test deployment{0}
dirk, Michael
3. next: strategy for "New Roots & Escrow" - how does debian work?
to contact, deferred to next events (?)
next round: picked up by Benedikt new proposal 2013-06-02{0}
Uli, Michael
Documentation Bugs.cacert.org Review, documentation I (bugs handbook) svg files to convert to jpg or png
{0}
Development, Deployment, Discussion
OAO, Ted
bug #943 change OA admin/assurer text
needs 2nd test -> Fabian, Marc, Alex? {g} / needs 2nd review -> Ted, rejected
{-}
uli, Ted
bug #824 Org User cert fix Case study
Organisation User Certificates: Need UI improvement for proper production usage
{0}
uli, ted
bug #823 email address removal fix
No warning when removing e-mail address from account that certificates will be revoked
checked by 4, needs 2nd review, deploy
rejected{-}
inopiae
bug #920 Join - single name only (eg Indonesian)
details under bug number
{0}
uli
bug #859 admin console interface
feature request: show activity on an account in the admin interface
rejected, certs login doesn't modify "modified" field{r}
Michael
p20111113 CPS #7.1.2 "Certificate Extensions" adjustments - testing
uli, marcus: needs full cert create tests
duplicate report to bug#978
tested by 3, 2nd review done, transfered
Ken reported: still has problems, bug kept open{0}
gagern, NEO
bug #440 Problem with subjectAltName (CSR, renew certs)
There seems to be a problem with the subjectAltName. Dupes, missing entries, and more, rejected, needs further development
{r}
neo
bug #1025 Domain Dispute issue
disputes rc and rc2 var prob
needs work{r}
dirk
bug #1054 0001054: Review the code regarding the new point calculation
Thawte patch part II
needs further work{r}
Software Assessors: Review 1 / add to cacert-devel, add to testserver
Software-Assessors task
Testing
Testers task
neo
bug #1004 Stats page improvement
tested by 2, needs 2nd review
{0}
neo
Bugs #1159 it might be possible to execute commands on the signing server
{0}
inopiae
bug #1065 Wrong wording when sending mails during the assurance process
{0}
inopiae
bug #1162 calcutate (the passwords) hash in php instead of in mysql
create test scenarios for the software testers
Full testing{0}
inopiae
bug #0028 Wrong language for you've been assured & [CAcert.org] Client Certificate emails
{0}
inopiae
bug #988 TTP cap form deployment
{0}
Software Assessors: 2nd Review, Bundle Package to Critical Team
Software-Assessors task
Ted
bug #500 Get contact mail adress after resolving test
tested by 3, requires review
{0}
Ted
bug #1140 Show if a test is passed in learnprogress
tested by 3, requires review
{0}
magu
bug #1131 Rename _all_ Policies from .php to .html and fix all links
global policy directory maintenance and update
{0}
inopiae
bug #1010 Reorder the view on organisation certificates
tested by 3
{0}
Software Assessors: Bundle Package to Critical Team
Software-Assessors task
inopiae
bug #1139 Add new fields to the database
tests through #500 and #1140, 2nd review done, requires transfer
{0}
Awaiting Response from Critical Team
inopiae
bug #411 Wrong text is made into link
{g}