To Software Software - To Software-Assessment - Software/Assessment - To previous meeting - To next meeting
Minutes of the MiniTOP on the 2011-08-30
Setting
The MiniTOP will be held via telco 22:00 CEST
Attendees: dirk, magu, uli, Marcus, Michael
Topics
(skip to agenda)
Action items from last meeting Meeting Action Items
Agenda
- Workshop - The List of open / running / unhandled bugs - Part I
- Working Session - Action Items to start
x4 bug #841 Problems on cert login
needs 2nd review - Ted, done
needs bundling, done- NEO: did restructuring (sql query to subroutine), (Update 2011-07-26), re-tested, reviewed
- needs 2nd review, bundling
=> Ted on Wed, not done
x4 NEO: bug #841 Problems on cert login
needs 2nd review - Ted, done
needs bundled
NEO will check to get sql query extracted
needs pushing
pushed to testserver
Needs 2nd Review & deploy by Dirk or Ted{-}
- started last meeting, not yet finished
- Working Session - Action Items to start
- Class3 Re-sign - responses - The "Bjoern" case
- Jubula Test-Tool (by Michael)
- PR work
- thawte patch - blog post
- newsletter mailings
- thawte patch, Security campaign, Newsletters
- thawte patch, check new points count
- Security campaign
- weak passwords (bug 637)
- password reset w/ Assurance replaces pwd reset thru paypal
- cert login security fix (bug 841)
- weak keys disabled (bug 918)
- class3 re-sign with sha256
- check your CAcert account
- create a client cert for client cert login (also needed for CATS)
- check your secret questions
- check your password
- check your notification settings
- check your location settings
- thawte patch detailed (1 month later)
- infos about thawte points removal
- infos about points counting
- thawte patch, Security campaign, Newsletters
- Workshop - The List of open / running / unhandled bugs - Part II
VBscript for Vista/Win7 (select keysize >= 1024) - reminder to dirk
x1 Dirk, new bug#964
DEV: bug#918 (Part II) (a20110312.1) Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEVcurrent state: test /account/4.php added to testserver
Marcus will do detailed tests on Wed
some references added to bug#964{-}
- as part of
x1 Arbitration case a20110312.1 Weak keys bug #918 / bug #954 / bug#964
- Current state:
{g}
pre mailing sent
{g}
keys revocation script to bulk revoke weak keys, new bug #954, finished
{-}
dirk: DEV: a20110312.1 bug#918 Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEV
vbscript needs to be improved with select box key size and lower limit to 2048 (based on https://wiki.mozilla.org/CA:MD5and1024)
Api CertEnroll (MS crypto provider)
new bug#964
current state: test /account/4.php added to testserver
Marcus will do detailed tests on Wed
some references added to bug#964{g}
Weak keys blog post, published
{g}
Weak keys article published by Hanno(July 28), link is in CAcert's blog post (July 30)
{b}
weak keys: problems with cryptostick (to test at Froscon with Juergen ?)
cert enroll infos under bug#964
vista and win7 works with other engine !CryptoAPI (?) => Cryptography API: Next Generation
http://msdn.microsoft.com/en-us/library/aa833130%28v=VS.85%29.aspx
Marcus: added notes for Win7 https://bugs.cacert.org/view.php?id=964#c2249
- Advertising
Prepare Advertising fix for testserver - reminder to dirk
Dirk
Advertising (from last board meeting), bug #958
add changes as discussed in last meeting to testserver
{0}
CAcertInc/LogosForSale/Rules wiki link exist
- "buy me" logo / "Logo For Sale" logo / "Monthly Auction on Logos" logo
- Logos and Links exist, needs deployment to testserver
- google ads, nobody knows about
http://google.de/adsense/ - needs google account
- ad client id: pab.*9860, email adress is needed
- board member to write email request to Robert, Philipp, Philpp, Teus, ernie
- contact google?
- account recovery?
- Thawte Patch - PR strategy
x2 Bug# 827 and bug #959 "Thawte" patch - Points-Count-Order-Change project - 2nd Review + deploy
needs 1 more test, needs 2nd review
2nd review: also check -x
tests done, 2nd review outstanding{0}
{g}bug #959 deployed
bug #827 awaiting response from critical team
- next steps:
- preparing PR, support
- report from Wytze, Hans: review, rebundle
- if the patch goes active, this needs support
- wiki faq (existing page? thawte topic?)
blog (-> alex)
- mailing list
- press release? probably not at this state
- Support: could be better, but is ok
- Triage: where to forward Thawte patch requests?
- add to Support team meeting agenda
- patch review
- 10.php / 15.php ranking differs
- 15.php experience points links to assurer account
- patch applied to testserver, patch to transfer to critical system
- alex to prepare blog post
- 15.php to push, 10.php ? to set active ? or not?
- mailing to people: Ted, Florian F, PG, Wytze, Carsten L, Jeff F, Frank K (ask Marcus) 120 pts, Sebastian K
Dirk reminder (from last meeting) assure someone patches (checkboxes)
Dirk
DEV: bug #894 problems with check-boxes on website forms (Assure someone) -> a20091118.3
{0}
- Bugs to Review #1, transfer to testserver
uli
bug #968 error logging cleanup (splitted bug #909)
split 0000909: too many error messages logged - part II - general.php
{0}
uli
Give an OA the oppertuntiy to check if a desiginated Organisation Admininistrator is a CAcert assurer
{0}
uli
bug #859 admin console interface
feature request: show activity on an account in the admin interface, new update
{0}
uli
bug #975 admin console interface (2)
report potential database inconsistency in SE console (debug infos), new update
{0}
uli, ted
display Assurance when field in list of assurances received, assurances given by a user in admin console interface, new update
{0}
uli, ted
visibility over certificates for sysadm in account administration, new update
{0}
uli
bug #966 cancel doesn't cancel but processes instead
bug needs more work, selection currently clashes with language setting (Delete != Löschen)
general problem in /pages/account.php with process variable, transfer of "cancel" pushes any action
potential workaround to fix all "Cancel" requests available
read https://bugs.cacert.org/view.php?id=966#c2287 and attached fix
badly fixed 31.php, new update fix avail{0}
- Bugs under testing:
Dirk, Michael
bug #827 and bug #959 Thawte patch/Points-Count-Order-Change project
related bug 959: needs 1 more test, needs 2nd review / 2nd review: also check -x / tests done, needs 2nd review
959 {g} reviewed, deployed
827 {g} reviewed, deployment in 2 steps
new fixes, reviewed, needs testing{0}
{0}Ted
bug #965 0000965: Outsource / fix Webdb text pages id=12, 13
one more testing
{0}
Ted, uli
bug #957 Resize the comment field on https://secure.cacert.org/account.php?id=27 so more information is visible
new fix avail 2011-08-19
{0}
Ted, uli
bug #846 Join Form restructure, help link
Better guidance of bonafide members in Join Form about Suffixes they doesn't have in their ID doxs (a20100207.2)
{0}
- Needs review, transfer to Critical team, to bundle, to deploy
- Needs development, deployment, discussion
bug #835 Migrate CATS onto testserver
bug #835 Assurer challenge (on testserver)
asssigned to Ted, CATS to install on ca-mgr1, awaiting deployment
{0}
bug #943 change OA admin/assurer text
bug #943 change OA admin/assurer text
-> Ted, rejected, needs comment from OAO
{-}
webdb names OrgAdmins as OrgAssurers and names OrgAssurers as OrgAdmins.
- patch takes account about this issue
- problem with menu link Org Admin .. is Org Assurers menu
- but this menu includes one addtl. link "View" that is available for Org Admins
- and Org Admins with master flag to add new admins
master flag is not described in OAP
- addtl master flag to revoke ?
- rename to "Org Administration"
don't show menu to OrgAdmins
- but this menu includes one addtl. link "View" that is available for Org Admins
- Still awaiting response from Critical team
strategy plans ... next: strategy for "New Roots & Escrow"
- idea: using indirect crl's ?
- 2 crl's needed, one valid, one invalid crl server
- more infos available ? who ?
- build testserver with special certs
- Magu, Michael to send instructions for test deployment
indirect CRL: RFC 5280 http://tools.ietf.org/html/rfc5280 (chapter 5)
- meetings ago we've defined Testing requirements and a potential testszenario
- to remind every meeting
- policy group: define requirements
- multimember escrow method ?
- needs risk analyze
- potential candidates ?
- Marcus to contacted Benedikt, will contact Thomas K
- Next step(s)
- multimember escrow method ?
- how does debian work ?
- defered to Froscon (end of Aug), CCCcamp (around Aug 10th)
- The Bjoern report
- idea: using indirect crl's ?
- CI (Update)
- deployment scenario:
- create testusers
- testing
- delete testusers
- regression test for standard tests: eg 0,1,49,50,51,99,100,101 pts w/ and w/o CATS passed
- reminder
- next meeting: Tuesday, September 6, 2011 22:00
Minutes
- Class3 Re-sign - responses - The "Bjoern" case
- responded to user
- user ignores request for help
- to keep an eye on
- ssl prob: mail to infrastructure team
- PR work
- thawte patch - blog post
- newsletter mailings
- thawte patch, Security campaign, Newsletters
- thawte patch, check new points count - should be removed from 1st patch
- Security campaign
- weak passwords (bug 637)
- password reset w/ Assurance replaces pwd reset thru paypal
- cert login security fix (bug 841)
- weak keys disabled (bug 918)
- class3 re-sign with sha256
- check your CAcert account
- create a client cert for client cert login (also needed for CATS)
- check your secret questions
- check your password
- check your notification settings
- check your location settings
- thawte patch detailed (1 month later, 6-8 weeks later)
- infos about thawte points removal
- infos about points counting
- thawte patch, Security campaign, Newsletters
- Jubula Test-Tool (by Michael)
with FF 3.5 ftp://ftp.mozilla.org/pub/firefox/releases/
- start aut agent (under win as service)
- start jubula (also on 64 machine)
- window preferences
- test
- database connections
- add
- ca-mgr1
- type: mysql
- host: ca-mgr1.it-sls.de
- OK
- OK
- add
- Test - open
- host: ca-mgr1.it-sls.de
- user: jubula
- pwd: (request from Software-Assessors, Testteam)
-> CAcert version 1.0
- OK
left upper corner -> test cases
- test suite browser
- standard task
connect to AUT (green button) -> connect
- Start AUT "cacert1 (cacert1) : cacert1"
- Test - Properties - AUTS - select cacert1 - edit - ok - ok
- Start AUT "cacert1 (cacert1_ie) : cacert1" + "cacert1 (cacert1_ff_neo) : cacert1"
- click "cacert1 (cacert1_ie) : cacert1"
- Remote control opens
- switch to jubula
- test suite browser
- right top corner - green selection - start exec cacert1_ie
- test exec relevance
remember my decision -> yes -> yes
change perspective -> yes -> yes
- program executes
- database connections
- new database tables and fields
- add new bug number with list of tables/fields for updates
- Bug 966, addtl. fix doesn't work 30.php, 31.php
uli
bug #966 cancel doesn't cancel but processes instead
bug needs more work, selection currently clashes with language setting (Delete != Löschen)
general problem in /pages/account.php with process variable, transfer of "cancel" pushes any action
potential workaround to fix all "Cancel" requests available
read https://bugs.cacert.org/view.php?id=966#c2287 and attached fix
badly fixed 31.php, new update fix avail{0}
x2 Bug# 827 and bug #959 "Thawte" patch - Points-Count-Order-Change project - 2nd Review + deploy
- request by Joost for variable fields
x4 bug #841 Problems on cert login
needs 2nd review - Ted, done
needs bundling, done- NEO: did restructuring (sql query to subroutine), (Update 2011-07-26), re-tested, reviewed
- needs 2nd review, bundling
=> Ted on Wed, not done
x4 NEO: bug #841 Problems on cert login
needs 2nd review - Ted, done
needs bundled
NEO will check to get sql query extracted
needs pushing
pushed to testserver
Needs 2nd Review & deploy by Dirk or Ted{-}
- started last meeting, not yet finished
- 2 sql queries
- dirk will do some rewrite later
- review ok
- info from critical team (thru Michael)
- upgrade of chroot environment on webdb by end of this week
- google ads, nobody knows about
http://google.de/adsense/ - needs google account
- ad client id: pab.*9860, email adress is needed
- board member to write email request to Robert, Philipp, Philpp, Teus, ernie
- contact google?
- account recovery?
- dirk: to write mail to treasurer (address from invoice)
- Michael - action items
- bug 827
- bug 841
- bug 846
- and others in the queue
Fixed Action Items since last or within meeting
Uli
open fw rule port 3306 on ca-mgr1 (req by Michael)
{g}
Uli
to request dns entry for cats1.it-sls.de by Andreas (for bug #835)
{g}
Action Items New
dirk
google ads account - to write mail to treasurer (address from invoice)
{0}
Action items: Meeting Action Items
Software/Assessment/ActionItems
all
proposed Apache config SSLCipherSuite settings for CAcert SSL enabled infrastructure systems
see also BEAST migration https://community.qualys.com/blogs/securitylabs/2011/10/17/mitigating-the-beast-attack-on-tls
Proposal from Sysadm list 2013-09-06{0}
SA
documentation server cert design concept to SystemAdministration/Systems/Development/Prepare
{0}
all
{0}
BenBE, Marcus
documentation: developer git repos under github
bug #1131 history @ github
CAcertOrg @ github
started under Software/Assessment/Documentation/UpdateCycle/step1{0}
NEO
{0}
all
read x509 guide
{0}
all
bug#1068 blog problem (also relates to community)
debian lenny - edge - squeeze upgrades needed
alternate: new server with squeeze, install wordpress, transfer domain
workaround: configure your FF FAQ/BrowserClients{g}
uli
Experience points for ATE attendance
check board motions and/or trigger if not yet passed{0}
uli
Infrastructure separation, to contact secure-u (Frank, Mario, Ted, Sebastian) for discussion, prepare a plan, started 2011-12-18
current state: see Funding Landing Page
May 2013: tk-server sponsoring, tk-server rcvd, deployment: WIP, project not yet finished{0}
All
1. next: strategy for "New Roots & Escrow" - using indirect crl's ?
indirect CRL: RFC 5280 http://tools.ietf.org/html/rfc5280 (chapter 5) - test deployment{0}
dirk, Michael
3. next: strategy for "New Roots & Escrow" - how does debian work?
to contact, deferred to next events (?)
next round: picked up by Benedikt new proposal 2013-06-02{0}
Uli, Michael
Documentation Bugs.cacert.org Review, documentation I (bugs handbook) svg files to convert to jpg or png
{0}
Development, Deployment, Discussion
OAO, Ted
bug #943 change OA admin/assurer text
needs 2nd test -> Fabian, Marc, Alex? {g} / needs 2nd review -> Ted, rejected
{-}
uli, Ted
bug #824 Org User cert fix Case study
Organisation User Certificates: Need UI improvement for proper production usage
{0}
uli, ted
bug #823 email address removal fix
No warning when removing e-mail address from account that certificates will be revoked
checked by 4, needs 2nd review, deploy
rejected{-}
inopiae
bug #920 Join - single name only (eg Indonesian)
details under bug number
{0}
uli
bug #859 admin console interface
feature request: show activity on an account in the admin interface
rejected, certs login doesn't modify "modified" field{r}
Michael
p20111113 CPS #7.1.2 "Certificate Extensions" adjustments - testing
uli, marcus: needs full cert create tests
duplicate report to bug#978
tested by 3, 2nd review done, transfered
Ken reported: still has problems, bug kept open{0}
gagern, NEO
bug #440 Problem with subjectAltName (CSR, renew certs)
There seems to be a problem with the subjectAltName. Dupes, missing entries, and more, rejected, needs further development
{r}
neo
bug #1025 Domain Dispute issue
disputes rc and rc2 var prob
needs work{r}
dirk
bug #1054 0001054: Review the code regarding the new point calculation
Thawte patch part II
needs further work{r}
Software Assessors: Review 1 / add to cacert-devel, add to testserver
Software-Assessors task
Testing
Testers task
neo
bug #1004 Stats page improvement
tested by 2, needs 2nd review
{0}
neo
Bugs #1159 it might be possible to execute commands on the signing server
{0}
inopiae
bug #1065 Wrong wording when sending mails during the assurance process
{0}
inopiae
bug #1162 calcutate (the passwords) hash in php instead of in mysql
create test scenarios for the software testers
Full testing{0}
inopiae
bug #0028 Wrong language for you've been assured & [CAcert.org] Client Certificate emails
{0}
inopiae
bug #988 TTP cap form deployment
{0}
Software Assessors: 2nd Review, Bundle Package to Critical Team
Software-Assessors task
Ted
bug #500 Get contact mail adress after resolving test
tested by 3, requires review
{0}
Ted
bug #1140 Show if a test is passed in learnprogress
tested by 3, requires review
{0}
magu
bug #1131 Rename _all_ Policies from .php to .html and fix all links
global policy directory maintenance and update
{0}
inopiae
bug #1010 Reorder the view on organisation certificates
tested by 3
{0}
Software Assessors: Bundle Package to Critical Team
Software-Assessors task
inopiae
bug #1139 Add new fields to the database
tests through #500 and #1140, 2nd review done, requires transfer
{0}
Awaiting Response from Critical Team
inopiae
bug #411 Wrong text is made into link
{g}