To Software Software - To Software-Assessment - Software/Assessment - To previous meeting - To next meeting
Minutes of the MiniTOP on the 2011-09-06
Setting
The MiniTOP will be held via telco 22:00 CEST
Attendees: marc, marcus, uli, dirk, alex, michael, magu
Topics
(skip to agenda)
Action items from last meeting Meeting Action Items
Agenda
Software-Assessors blockage - The List of open / running / unhandled bugs - Part I
- Michael - action items last week
- bug 827
- bug 841
- bug 846
- and others in the queue
x4 bug #841 Problems on cert login
x4 NEO: bug #841 Problems on cert login
needs 2nd review - Ted, done
needs bundled
NEO will check to get sql query extracted
needs pushing
pushed to testserver
Needs 2nd Review & deploy by Dirk or Ted{-}
- started last meeting, not yet finished
- 2 sql queries
- dirk will do some rewrite later
- review ok
- needs transfer to critical team
x2 Bug# 827 and bug #959 "Thawte" patch - Points-Count-Order-Change project - 2nd Review + deploy
- request by Joost for variable fields
- next steps:
- preparing PR, support (see below)
- Thawte Patch - PR strategy
- alex to prepare blog post
- if the patch goes active, this needs support
- wiki faq (existing page? thawte topic?)
blog (-> alex)
- mailing list
- press release? probably not at this state
- Support: could be better, but is ok
- Triage: where to forward Thawte patch requests?
- add to Support team meeting agenda
- Thawte Patch - PR strategy
- reviewed last meeting. needs transfer to critical team
- mailing to people: Ted, Florian F, PG, Wytze, Carsten L, Jeff F, Frank K (ask Marcus) 120 pts, Sebastian K
- preparing PR, support (see below)
- Michael - action items last week
- PR work
- thawte patch - blog post
- newsletter mailings
- Security campaign, Newsletters
- weak passwords (bug 637)
- password reset w/ Assurance replaces pwd reset thru paypal
- cert login security fix (bug 841)
- weak keys disabled (bug 918)
- class3 re-sign with sha256
- check your CAcert account
- create a client cert for client cert login (also needed for CATS)
- check your secret questions
- check your password
- check your notification settings
- check your location settings
- thawte patch detailed (1 month later, 6-8 weeks later)
- infos about thawte points removal
- infos about points counting
- Security campaign, Newsletters
- Wytze: planned chroot environment upgrade on cacert1.it-sls.de
- upgrade of chroot environment on cacert1 like webdb upgrade last week
- Translingo
- the translingo.cacert.org had been in operation far longer, so I think it is possible that some users migrated to translingo.cacert.org, without telling us.
- I would suggest to mass-mail the email addresses of the translation-project leaders in the translingo database, to inform them, and to ask them to speak up if they still need it
- Dirks workqueue - The List of open / running / unhandled bugs
VBscript for Vista/Win7 (select keysize >= 1024) - reminder to dirk
x1 Dirk, new bug#964
DEV: bug#918 (Part II) (a20110312.1) Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEVcurrent state: test /account/4.php added to testserver
Marcus will do detailed tests on Wed
some references added to bug#964{-}
- as part of
x1 Arbitration case a20110312.1 Weak keys bug #918 / bug #954 / bug#964
- Current state:
{g}
pre mailing sent
{g}
keys revocation script to bulk revoke weak keys, new bug #954, finished
{-}
dirk: DEV: a20110312.1 bug#918 Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEV
vbscript needs to be improved with select box key size and lower limit to 2048 (based on https://wiki.mozilla.org/CA:MD5and1024)
Api CertEnroll (MS crypto provider)
new bug#964
current state: test /account/4.php added to testserver
Marcus will do detailed tests on Wed
some references added to bug#964{g}
Weak keys blog post, published
{g}
Weak keys article published by Hanno(July 28), link is in CAcert's blog post (July 30)
{b}
weak keys: problems with cryptostick (to test at Froscon with Juergen ?)
cert enroll infos under bug#964
vista and win7 works with other engine !CryptoAPI (?) => Cryptography API: Next Generation
http://msdn.microsoft.com/en-us/library/aa833130%28v=VS.85%29.aspx
Marcus: added notes for Win7 https://bugs.cacert.org/view.php?id=964#c2249
- Advertising
Prepare Advertising fix for testserver - reminder to dirk
Dirk
Advertising (from last board meeting), bug #958
add changes as discussed in last meeting to testserver
{0}
CAcertInc/LogosForSale/Rules wiki link exist
- "buy me" logo / "Logo For Sale" logo / "Monthly Auction on Logos" logo
- Logos and Links exist, needs deployment to testserver
- google ads, nobody knows about
http://google.de/adsense/ - needs google account
- ad client id: pab.*9860, email adress is needed
- board member to write email request to Robert, Philipp, Philpp, Teus, ernie
- contact google?
- account recovery?
- dirk: google ads account - to write mail to treasurer (address from invoice)
Dirk reminder (from last meeting) assure someone patches (checkboxes)
Dirk
DEV: bug #894 problems with check-boxes on website forms (Assure someone) -> a20091118.3
{0}
Software-Assessors blockage - Bugs to Review #1, transfer to testserver - Currently 13 (!!!)
uli
bug #977 admin console text fix
admin console Sysadmin - find domain - lists 2 tables - one for user accounts, one for org accounts, naming issue
{0}
uli
bug #975 admin console interface (2)
report potential database inconsistency in SE console (debug infos), new update
{0}
uli
bug #968 error logging cleanup (splitted bug #909)
split 0000909: too many error messages logged - part II - general.php
{0}
uli
bug #967 OA isassurer check
Give an OA the oppertuntiy to check if a desiginated Organisation Admininistrator is a CAcert assurer
{0}
uli, Ted
bug #965 0000965: Outsource / fix Webdb text pages id=12, 13
addtl. id=37, id=38, new update
{0}
uli, ted
display Assurance when field in list of assurances received, assurances given by a user in admin console interface, new update
{0}
uli
bug #859 admin console interface
feature request: show activity on an account in the admin interface, new update
{0}
uli
bug #855 admin console interface "unknown" + "empty" assurance method fields, needed for correct testing on testserver
admin console lists "empty" and "Unknown" Assurance types on listing given Assurances
{0}
uli
bug #824 Org User cert fix
Organisation User Certificates: Need UI improvement for proper production usage
{0}
uli
bug #823 email address removal fix
No warning when removing e-mail adres from acount that certificates wil be revoked
{0}
uli, ted
visibility over certificates for sysadm in account administration, new update
{0}
uli
bug #789 OA edit domain fix
Editing domain for organisations does not work
{0}
moh
bug #596 certs list advanced
display ser# in certs overview lists
{0}
Bugs under testing: - Currently only 2 (!!!)
uli, Michael
bug #966 cancel doesn't cancel but processes instead
potential workaround to fix all "Cancel" requests available
addtl. individual fixes
new update 2011-08-30{0}
uli, Ted
bug #957 Resize the comment field on https://secure.cacert.org/account.php?id=27 so more information is visible
new fix avail 2011-08-19
{0}
Software-Assessors blockage - Needs 2nd review + transfer to Critical team, to bundle, to deploy
uli, ted
bug #955 change sort order Orga list
Possibilty to change the sorting order for the organisation overview
{0}
uli, ted
bug #940 help* to wiki
Outsource Webdb text pages help.php?id=0..9 to wiki
needs review, deploy{0}
uli, ted
bug #910 Outsource board member list
from Webdb to wiki (id=8) (Part II)
{0}
Ted, uli
bug #846 Join Form restructure, help link
Better guidance of bonafide members in Join Form about Suffixes they doesn't have in their ID doxs (a20100207.2)
{0}
Software-Assessors blockage - Needs transfer to Critical team, to bundle, to deploy
Dirk, Michael
bug #827 and bug #959 Thawte patch/Points-Count-Order-Change project
related bug 959: needs 1 more test, needs 2nd review / 2nd review: also check -x / tests done, needs 2nd review
959 {g} reviewed, deployed
827 {g} reviewed, deployment in 2 steps
new fixes, reviewed, needs testing{0}
{0}Uli, Neo, Dirk
bug #841 Problems on cert login
needs 2nd review - Ted, done
needs bundled
NEO will check to get sql query extracted
needs pushing
pushed to testserver
Needs 2nd Review & deploy by Dirk or Ted{-}
- Needs development, deployment, discussion
bug #835 Migrate CATS onto testserver
bug #835 Assurer challenge (on testserver)
asssigned to Ted, CATS to install on ca-mgr1, awaiting deployment
{0}
bug #943 change OA admin/assurer text
bug #943 change OA admin/assurer text
-> Ted, rejected, needs comment from OAO
{-}
webdb names OrgAdmins as OrgAssurers and names OrgAssurers as OrgAdmins.
- patch takes account about this issue
- problem with menu link Org Admin .. is Org Assurers menu
- but this menu includes one addtl. link "View" that is available for Org Admins
- and Org Admins with master flag to add new admins
master flag is not described in OAP
- addtl master flag to revoke ?
- rename to "Org Administration"
don't show menu to OrgAdmins
- but this menu includes one addtl. link "View" that is available for Org Admins
strategy plans ... next: strategy for "New Roots & Escrow"
- idea: using indirect crl's ?
- 2 crl's needed, one valid, one invalid crl server
- more infos available ? who ?
- build testserver with special certs
- Magu, Michael to send instructions for test deployment
indirect CRL: RFC 5280 http://tools.ietf.org/html/rfc5280 (chapter 5)
- meetings ago we've defined Testing requirements and a potential testszenario
- to remind every meeting
- policy group: define requirements
- multimember escrow method ?
- needs risk analyze
- potential candidates ?
- Marcus to contacted Benedikt, will contact Thomas K
- Next step(s)
- multimember escrow method ?
- how does debian work ?
- defered to Froscon (end of Aug), CCCcamp (around Aug 10th)
- The Bjoern report
- idea: using indirect crl's ?
- CI (Update)
description to eclipse testpage, Webinar
- deployment scenario:
- create testusers
- testing
- delete testusers
- regression test for standard tests: eg 0,1,49,50,51,99,100,101 pts w/ and w/o CATS passed
- reminder
- deployment scenario:
- Jubula Test-Tool (by Michael) - update?
instructions see under Minutes meeting 2011-08-30
- next meeting: Tuesday, September 13, 2011 22:00
Minutes
Software-Assessors blockage - The List of open / running / unhandled bugs - Part I
- Michael - action items last week
- bug 827
- bug 841
- just pushed
- next: mailing to people: Ted, Florian F, PG, Wytze, Carsten L, Jeff F, Frank K (ask Marcus) 120 pts, Sebastian K
- Michael - action items last week
- PR work
- thawte patch - mailing
- thawte patch infos
- newsletter settings
- newsletter mailings - security campaign
- defered after last board meeting motion
- so first info regarding thawte patch
- thawte patch - mailing
- Wytze: planned chroot environment upgrade on cacert1.it-sls.de
- upgrade of chroot environment on cacert1 like webdb upgrade last week
- problems on upgrade
- signer doesn't run
- mx record dns check
- char encoding utf8 vs latin1, server sent auto header
- account_stuff header needs updated
- dirk: request for new developer image
- proposed next upgrade step lenny to squeeze
- Translingo
- the translingo.cacert.org had been in operation far longer, so I think it is possible that some users migrated to translingo.cacert.org, without telling us.
- I would suggest to mass-mail the email addresses of the translation-project leaders in the translingo database, to inform them, and to ask them to speak up if they still need it
- last foreign uploads 2008 on about 13 + cacert projects
- whohas translingo server console access?
- mario
- req for console access for michael to contact project leaders
- Dirks workqueue - The List of open / running / unhandled bugs
VBscript for Vista/Win7 (select keysize >= 1024) - reminder to dirk
x1 Dirk, new bug#964
DEV: bug#918 (Part II) (a20110312.1) Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEVcurrent state: test /account/4.php added to testserver
Marcus will do detailed tests on Wed
some references added to bug#964{-}
- as part of
x1 Arbitration case a20110312.1 Weak keys bug #918 / bug #954 / bug#964
- Current state:
{g}
pre mailing sent
{g}
keys revocation script to bulk revoke weak keys, new bug #954, finished
{-}
dirk: DEV: a20110312.1 bug#918 Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEV
vbscript needs to be improved with select box key size and lower limit to 2048 (based on https://wiki.mozilla.org/CA:MD5and1024)
Api CertEnroll (MS crypto provider)
new bug#964
current state: test /account/4.php added to testserver
Marcus will do detailed tests on Wed
some references added to bug#964{g}
Weak keys blog post, published
{g}
Weak keys article published by Hanno(July 28), link is in CAcert's blog post (July 30)
{b}
weak keys: problems with cryptostick (to test at Froscon with Juergen ?)
cert enroll infos under bug#964
vista and win7 works with other engine !CryptoAPI (?) => Cryptography API: Next Generation
http://msdn.microsoft.com/en-us/library/aa833130%28v=VS.85%29.aspx
Marcus: added notes for Win7 https://bugs.cacert.org/view.php?id=964#c2249
- no update {-}
- Advertising
Prepare Advertising fix for testserver - reminder to dirk
Dirk
Advertising (from last board meeting), bug #958
add changes as discussed in last meeting to testserver
{0}
CAcertInc/LogosForSale/Rules wiki link exist
- "buy me" logo / "Logo For Sale" logo / "Monthly Auction on Logos" logo
- Logos and Links exist, needs deployment to testserver
- no update {-}
- google ads, nobody knows about
http://google.de/adsense/ - needs google account
- ad client id: pab.*9860, email adress is needed
- board member to write email request to Robert, Philipp, Philpp, Teus, ernie
- contact google?
- account recovery?
- dirk: google ads account - to write mail to treasurer (address from invoice)
- no update {-}
Dirk reminder (from last meeting) assure someone patches (checkboxes)
Dirk
DEV: bug #894 problems with check-boxes on website forms (Assure someone) -> a20091118.3
{0}
- if 827 is active, 894 becomes active
- dirk: transfer to git cacert-devel
- michael: transfer to testserver
Software-Assessors blockage - Bugs to Review #1, transfer to testserver - Currently 13 (!!!)
- 13 open fixes available, needs 1st review by 1st Software-Assessor
Software-Assessors blockage - Needs 2nd review + transfer to Critical team, to bundle, to deploy
uli, ted
bug #955 change sort order Orga list
Possibilty to change the sorting order for the organisation overview
{0}
uli, ted
bug #940 help* to wiki
Outsource Webdb text pages help.php?id=0..9 to wiki
needs review, deploy{0}
uli, ted
bug #910 Outsource board member list
from Webdb to wiki (id=8) (Part II)
{0}
Ted, uli
bug #846 Join Form restructure, help link
Better guidance of bonafide members in Join Form about Suffixes they doesn't have in their ID doxs (a20100207.2)
{0}
strategy plans ... next: strategy for "New Roots & Escrow"
- idea: using indirect crl's ?
- 2 crl's needed, one valid, one invalid crl server
- more infos available ? who ?
- build testserver with special certs
- Magu, Michael to send instructions for test deployment
indirect CRL: RFC 5280 http://tools.ietf.org/html/rfc5280 (chapter 5)
- meetings ago we've defined Testing requirements and a potential testszenario
- to remind every meeting
- Michael tries to prepare a vm testserver
- idea: using indirect crl's ?
- Question from Lambert (by email): Is CAcert's ocsp server a blacklist or a whitelist ocsp ?
- CAcert is probably a blacklist ocsp, cause the server delivers infos derived from current crl's interactively
- CI (Update)
description to eclipse testpage, Webinar
- deployment scenario:
- create testusers
- testing
- delete testusers
- regression test for standard tests: eg 0,1,49,50,51,99,100,101 pts w/ and w/o CATS passed
- reminder
- deployment scenario:
- Jubula Test-Tool (by Michael) - update?
instructions see under Minutes meeting 2011-08-30
- test deployment needs to be continued by software testers
- bug 824 effects
- account.php restructure plans
- dirk made still some coding, but not yet active
- from bug 824 analyze, many of the code is duplicated from other actions, so the idea here is to rethink about subfunctioning of subtasks eg split cert creation action into smaller parts and handle the transfer from each step to step with addtl. parameters
see discussion under https://lists.cacert.org/wws/arc/cacert-devel/2011-09/msg00013.html
Fixed Action Items since last or within meeting
- Awaiting Response from Critical Team (moved to next state)
Done: Michael, Dirk, Michael
ToDo:bug #841 Problems on cert login
needs 2nd review, deploy
{0}
Done: Dirk, Michael, Michael
ToDo:bug #827 and bug #959 Thawte patch/Points-Count-Order-Change project
related bug 959: needs 1 more test, needs 2nd review / 2nd review: also check -x / tests done, needs 2nd review
959 {g} reviewed, deployed
827 {g} reviewed, deployment in 2 steps{0}
{0} - Fix available to testserver (moved to next state)
uli, Ted
bug #824 Org User cert fix
Organisation User Certificates: Need UI improvement for proper production usage
{0}
Action Items New
uli
prepare cacert1 image for developers after proposed system update
{0}
uli
prepare ca-mgr1 image for developers
{0}
uli
prepare DEBIAN-Lenny image for developers (request by Michael)
{0}
uli
preview mailing to people: Ted, Florian F, PG, Wytze, Carsten L, Jeff F, Frank K (ask Marcus) 120 pts, Sebastian K
{0}
Action items: Meeting Action Items
Software/Assessment/ActionItems
all
proposed Apache config SSLCipherSuite settings for CAcert SSL enabled infrastructure systems
see also BEAST migration https://community.qualys.com/blogs/securitylabs/2011/10/17/mitigating-the-beast-attack-on-tls
Proposal from Sysadm list 2013-09-06{0}
SA
documentation server cert design concept to SystemAdministration/Systems/Development/Prepare
{0}
all
{0}
BenBE, Marcus
documentation: developer git repos under github
bug #1131 history @ github
CAcertOrg @ github
started under Software/Assessment/Documentation/UpdateCycle/step1{0}
NEO
{0}
all
read x509 guide
{0}
all
bug#1068 blog problem (also relates to community)
debian lenny - edge - squeeze upgrades needed
alternate: new server with squeeze, install wordpress, transfer domain
workaround: configure your FF FAQ/BrowserClients{g}
uli
Experience points for ATE attendance
check board motions and/or trigger if not yet passed{0}
uli
Infrastructure separation, to contact secure-u (Frank, Mario, Ted, Sebastian) for discussion, prepare a plan, started 2011-12-18
current state: see Funding Landing Page
May 2013: tk-server sponsoring, tk-server rcvd, deployment: WIP, project not yet finished{0}
All
1. next: strategy for "New Roots & Escrow" - using indirect crl's ?
indirect CRL: RFC 5280 http://tools.ietf.org/html/rfc5280 (chapter 5) - test deployment{0}
dirk, Michael
3. next: strategy for "New Roots & Escrow" - how does debian work?
to contact, deferred to next events (?)
next round: picked up by Benedikt new proposal 2013-06-02{0}
Uli, Michael
Documentation Bugs.cacert.org Review, documentation I (bugs handbook) svg files to convert to jpg or png
{0}
Development, Deployment, Discussion
OAO, Ted
bug #943 change OA admin/assurer text
needs 2nd test -> Fabian, Marc, Alex? {g} / needs 2nd review -> Ted, rejected
{-}
uli, Ted
bug #824 Org User cert fix Case study
Organisation User Certificates: Need UI improvement for proper production usage
{0}
uli, ted
bug #823 email address removal fix
No warning when removing e-mail address from account that certificates will be revoked
checked by 4, needs 2nd review, deploy
rejected{-}
inopiae
bug #920 Join - single name only (eg Indonesian)
details under bug number
{0}
uli
bug #859 admin console interface
feature request: show activity on an account in the admin interface
rejected, certs login doesn't modify "modified" field{r}
Michael
p20111113 CPS #7.1.2 "Certificate Extensions" adjustments - testing
uli, marcus: needs full cert create tests
duplicate report to bug#978
tested by 3, 2nd review done, transfered
Ken reported: still has problems, bug kept open{0}
gagern, NEO
bug #440 Problem with subjectAltName (CSR, renew certs)
There seems to be a problem with the subjectAltName. Dupes, missing entries, and more, rejected, needs further development
{r}
neo
bug #1025 Domain Dispute issue
disputes rc and rc2 var prob
needs work{r}
dirk
bug #1054 0001054: Review the code regarding the new point calculation
Thawte patch part II
needs further work{r}
Software Assessors: Review 1 / add to cacert-devel, add to testserver
Software-Assessors task
Testing
Testers task
neo
bug #1004 Stats page improvement
tested by 2, needs 2nd review
{0}
neo
Bugs #1159 it might be possible to execute commands on the signing server
{0}
inopiae
bug #1065 Wrong wording when sending mails during the assurance process
{0}
inopiae
bug #1162 calcutate (the passwords) hash in php instead of in mysql
create test scenarios for the software testers
Full testing{0}
inopiae
bug #0028 Wrong language for you've been assured & [CAcert.org] Client Certificate emails
{0}
inopiae
bug #988 TTP cap form deployment
{0}
Software Assessors: 2nd Review, Bundle Package to Critical Team
Software-Assessors task
Ted
bug #500 Get contact mail adress after resolving test
tested by 3, requires review
{0}
Ted
bug #1140 Show if a test is passed in learnprogress
tested by 3, requires review
{0}
magu
bug #1131 Rename _all_ Policies from .php to .html and fix all links
global policy directory maintenance and update
{0}
inopiae
bug #1010 Reorder the view on organisation certificates
tested by 3
{0}
Software Assessors: Bundle Package to Critical Team
Software-Assessors task
inopiae
bug #1139 Add new fields to the database
tests through #500 and #1140, 2nd review done, requires transfer
{0}
Awaiting Response from Critical Team
inopiae
bug #411 Wrong text is made into link
{g}