To Software Software - To Software-Assessment - Software/Assessment - To previous meeting - To next meeting
Minutes of the MiniTOP on the 2011-11-22
2011-11-23 Continued
Setting
The MiniTOP will be held via telco 22:00 CET
Attendees: magu, dirk, uli, marcus, michael
Topics
(skip to agenda)
Action items from last meeting Meeting Action Items
Agenda
bug #976 - database restructure preperation
* raw transcript from meeting results: [[https://bugs.cacert.org/file_download.php?file_id=245&type=bug|sql structure modifications as discussed within meeting]] * New table to add: high potential domains to secure (mozilla blue print) * proposed testserver deployment - when ? * results from meeting 2011-10-18 * deletedwhen - to rename to deleted type datetime * from - to rename to creatorid * enum - or not enum for cca method * add table "mozilla blue print" domains * proposal michael: to add this as file, also to deploy to signer * sql update? or php script? * adding versioning number ? table verno, when type datetime * results from meeting 2011-10-25 * email addresses + domains verification on cert renewal: last verified (type datetime) * info from dirk regarding CCA table structure. structure defined in [[https://lists.cacert.org/wws/arc/cacert-devel/2009-06/msg00004.html]]. Current definition to compare with structure definition from mid 2009 * detailed discussion regarding CCA table * comment field to name as method? * type -> boolan * adding version table * latin-1 is db standard * sql script will be prepared by Michael * Update 1. script built by Michael 1. script reviewed by dirk 1. script tested localy, with one bug found (Org Client Cert - View doesn't work) 1. fix for Org Client Cert - View added to testserver, needs 2nd review 1. needs testing regarding notary table functions * notary table 0-150 pts variations tested manual and TMS assurances [[https://bugs.cacert.org/view.php?id=976#c2682|Report #c2682]] 1. state 2011-11-15: * added to testserver, migration script works * problem with org client certs view (org table) identified fixed. * further tests with notary table revealed no more problems * accounts/18.php needs review * instructions for running the script is written in bug #976 docu
- current state summary:
- transfered to critical system, patch has been applied
- outstanding: database upgrade, scheduled for Wed Nov 23rd
bug #827 - New Points calculation / Thawte patch
- The patch
- state 2011-11-15
review #827 + #882 fix-date 2006-09-01 -> dirk
- reviews done, needs transfer to critical team
- next steps:
mailing script not yet prepared -> dirk
- ascending user id's with high watermark file
- dirks work-queue: agm/sgn minutes
uli picksup agm/sgm minutes, dirk writes patch - deal => finished
- PR work - Update?
newsletter mailing: ok from board m20111016.2 and m20111023.2
newsletter and translations reviewed: English revision PR/News/NewPointsCalculation
- script sql query to prepare based on events/oa mailing
- request for statement by critical team
- proposal by critical team:
- to pace the email sending out a bit, e.g. by doing a chunk of 1000, then waiting 19 minutes (by a programmatic sleep) before starting the next chunk of 1000 etc
- pushing out the whole mailing will take somewhere between one and two full days
- reduce Postfix' maximal_queue_lifetime from the default 5 days to say 2 days
Basically a20100309.1 already gives permission for this mailing, except that it outlines a somewhat different technical implementation of such mailings. But policy-wise there doesn't seem to be a difference to me with what we are proposing here, so why bother with addtl arbitration?
- . Software-Assessors / developers to prepare a sql-query that can handle above requirements, also to handle localy translateded text
- script to use from events + OA mailing, SA's to build a sql query, sending to critical team
- dirk: script not yet deployed, will do till last weekend, Sunday: not yet written
- see top 2.1
- "Special case" - handling of 0:0 cases under arbitration
- New proposal: scripted mailing for 0:0 F2F cases with detailed instructions
- get information how many 0:0 cass we have ?
info from last years arbitration a20100822.1 ? (documentation is not yet avail)
- Lambert as Arbitrator, Martin as Case Manager and dirk in role as SA as Claimant should know the answer
- is it possible to update 15.php script to signal the 0:0 F2F assurance cases ?!? eg by color blue or background color light yellow ?
- dirk: 15.php can be easily upgraded - not only color also italic
- to prepare an arbitration process for a scripted mailing announcement
- to the assuree's who may loose points caused by 0:0 cases
- to the assurers, who can re-apply their assurance over assuree's with the 0:0 problem
- arbitration initiated
wiki faq created: FAQ/NewPointsCount#YellowLines
- No CM/A picked up this case yet
- Questions from last 9 meetings:
- dirk: when will 827 goes to production ?
- The patch
bug #968 documentation, action required?
- Testers workqueue
Translingo bug #985
https://translations.cacert.org (http://translations.cacert.org/) (replacement for translingo)
- the translingo.cacert.org had been in operation far longer, so I think it is possible that some users migrated to translingo.cacert.org, without telling us.
- I would suggest to mass-mail the email addresses of the translation-project leaders in the translingo database, to inform them, and to ask them to speak up if they still need it
- last foreign uploads 2008 on about 13 + cacert projects
- whohas translingo server console access?
- mario
- req for console access for michael to contact project leaders, Updates?
- Transfer In, Transfer Out problems
- Update from new deployment ?
- opened for: create an account can now be started
- Michael current state:
- import and export routine works
- script to incorporate updates needs fixed
- next: complete language handling needs to be updated
- accept lang handler needs fix
- FF de, de_de
- IE 6 de, 8,9 de_de
- working session within last meeting: michael, marcus
- infos from meeting 2011-10-18
- pdf code needs rewrite (uni code library, move to external server (outsourcing))
- message cert notification - uses perl code, text source not avail (get bind-text-domain)
- infos from meeting 2011-10-18
- current state?
- Marcus sent mailing to translators, no response so far, no tests so far (week 3)
- Morten NO
- Emanuel IT
- current state:
- create test system accounts dutch@test, espania@test and so on, let users do their tests
- Magu, Marcus will give it a try
- a couple of testers has started testing and reporting within the last 7 days
bug#894 "Haeckchen bug" - review done, changes needs reviewed again
3
Dirk
bug#894 assure someone patches (checkbox)
(incl wot.php changes)
tested by 2, needs 2nd review, deploy
new test round{0}
? / u1 / m1
- review by dirk in session, review ok
- current state:
- needs testing
- Magu, Marcus will pickup the task
- one test and report done this week (in week 3)
Policy group discussion - Extended key usage -> p20111113 started, extended for 1 week
- new related topics
- ios5 bug
- new related topics
- OCSP server - timeout 10 min too short, 3 days to long, recommendation is 24-48 hours max, verisign: 7 days, startssl: 2d
- who has been informed, contacted?
- Michael will inform Wytze
- Build + Document Emergency Patches Path
Build + Document Emergency Patches Path
Andreas, Uli, Wytze
{0}
- Documentation written, reviewed by Wytze, Marcus
Michael: reminder for review Software/Assessment/Documentation/EmergencyPatches
- other reviews done ?
- Michaels workqueue
- New function to TMS - edit notary table record
- infos from last meeting
- testers needs editing individual notary records: fields "method", "awarded", "points"
- easier to create notary records with testserver (add F2F), and edit existing record, doesn't need to check for assurer-from, assuree-to and so on
- Update?
- Michael (2011-11-15): after some other bug reviews
- New function to TMS - edit notary table record
- Dirks workqueue - The List of open / running / unhandled bugs
VBscript for Vista/Win7 (select keysize >= 1024) - reminder to dirk
x1 Dirk, new bug#964
DEV: bug#918 (Part II) (a20110312.1) Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEVcurrent state: test /account/4.php added to testserver
Marcus will do detailed tests on Wed
some references added to bug#964{-}
- as part of
x1 Arbitration case a20110312.1 Weak keys bug #918 / bug #954 / bug#964
- Current state:
{g}
pre mailing sent
{g}
keys revocation script to bulk revoke weak keys, new bug #954, finished
{-}
dirk: DEV: a20110312.1 bug#918 Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEV
vbscript needs to be improved with select box key size and lower limit to 2048 (based on https://wiki.mozilla.org/CA:MD5and1024)
Api CertEnroll (MS crypto provider)
new bug#964
current state: test /account/4.php added to testserver
Marcus will do detailed tests on Wed
some references added to bug#964{g}
Weak keys blog post, published
{g}
Weak keys article published by Hanno(July 28), link is in CAcert's blog post (July 30)
{b}
weak keys: problems with cryptostick (to test at Froscon with Juergen ?)
cert enroll infos under bug#964
vista and win7 works with other engine !CryptoAPI (?) => Cryptography API: Next Generation
http://msdn.microsoft.com/en-us/library/aa833130%28v=VS.85%29.aspx
Marcus: added notes for Win7 https://bugs.cacert.org/view.php?id=964#c2249
- dirk: has not started the virtual machine
- Question from Marcus: did someone contacted illuminat?
- No, Marcus: to contact illuminat
- illuminat will give it a try, first needs download of testserver image
- Update?
Bugs to Review #1, transfer to testserver - Currently 4
uli
bug #977 admin console text fix
admin console Sysadmin - find domain - lists 2 tables - one for user accounts, one for org accounts, naming issue
{0}
uli
bug #967 OA isassurer check
Give an OA the oppertuntiy to check if a desiginated Organisation Admininistrator is a CAcert assurer
{0}
uli
bug #859 admin console interface
feature request: show activity on an account in the admin interface, new update
{0}
inopiae
New layout of view for Organisation Administraors in account/id35
{0}
Bugs under testing: - Currently 5
neo
bug #985 move translingo to translations
check language settings under testserver
{0}
inopiae
bug #920 Join - single name only (eg Indonesian)
details under bug number
present to Policy Group ?{0}
uli
bug #855 admin console interface "unknown" + "empty" assurance method fields, needed for correct testing on testserver
admin console lists "empty" and "Unknown" assurance types on listing given Assurances
{0}
3
Dirk
bug#894 assure someone patches (checkbox)
(incl wot.php changes)
tested by 2, needs 2nd review, deploy
new test round{0}
? / u1 / m1
7
uli, ted
bug #789 OA edit domain fix
Editing domain for organisations does not work
new update 2011-09-26
more fixes, more testing
* testcase scenario
* open org, edit 1st domain in new window, edit 2nd domain in new window
* results in: change made in window 2, written to record in window 2
* needs cross checking{0}
? / u7 / m7
Needs 2nd review + transfer to Critical team, to bundle, to deploy - Currently 2
- define priority eg. 10,2, and so on, proposed order: from 1 to 10
8
Ted, uli
bug #957 Resize the comment field on https://secure.cacert.org/account.php?id=27 so more information is visible
last update 2011-08-19
tested 3 times
ready to deploy?{0}
? / u8 / m8
10
uli, Ted
bug #965 0000965: Outsource / fix Webdb text pages id=12, 13
addtl. id=37, id=38, new update 2011-09-25
{0}
? / u10 / m10
- define priority eg. 10,2, and so on, proposed order: from 1 to 10
- Needs development, deployment, discussion, reminder
strategy plans ... next: strategy for "New Roots & Escrow"
- idea: using indirect crl's ?
- 2 crl's needed, one valid, one invalid crl server
- more infos available ? who ?
- build testserver with special certs
- Magu, Michael to send instructions for test deployment
indirect CRL: RFC 5280 http://tools.ietf.org/html/rfc5280 (chapter 5)
- meetings ago we've defined Testing requirements and a potential testszenario
- to remind every meeting
- Michael: testserver environment deployment
- Michael will review after Certs extension policy group vote
- policy group: define requirements
- multimember escrow method ?
- needs risk analyze
- potential candidates ?
- Marcus to contacted Benedikt, will contact Thomas K
- Next step(s)
- multimember escrow method ?
- idea: using indirect crl's ?
- CI (Update)
description to eclipse testpage, Webinar
- deployment scenario:
- create testusers
- testing
- delete testusers
- regression test for standard tests: eg 0,1,49,50,51,99,100,101 pts w/ and w/o CATS passed
- reminder
- deployment scenario:
- Jubula Test-Tool (by Michael) - update?
instructions see under Minutes meeting 2011-08-30
- test deployment needs to be continued by software testers
Jubula documentation started: Software/Jubula
- new proposal by Sven: Webdriver with Maven and Jenkins-CI
- Jubula vs. Webdriver
- testserver variants
- testserver for manual tests
- testserver of OS and application upgrades
- testserver for CI
- test methods
- unit test
- test single modules, exceptions
- integration tests
- test interaction of modules
- system tests
- complete system test, with database interactions, module interactions and much more
- unit test
- sven did some work regarding frontendtest (Webdriver with Maven and Jenkins-CI)
- Michael did some review: probably needs some seperation
- Infrastructure seperation
- contacting secure-u, oophaga started?
- Frank, Mario, Ted, Uli, Sebastian ?
- contacting secure-u, oophaga started?
- next meeting: Tuesday, November 29, 2011 22:00
Minutes
- dirk: votebot for agm active?
- source is in svn
- votebot running on irc
bug #976 - database restructure preperation
- current state summary:
- transfered to critical system, patch has been applied
- outstanding: database upgrade, scheduled for Wed Nov 23rd
- current state summary:
bug #827 - New Points calculation / Thawte patch
- next steps:
mailing script not yet prepared -> dirk
- ascending user id's with high watermark file
- dirks work-queue: agm/sgn minutes
uli picksup agm/sgm minutes, dirk writes patch - deal => finished
- plain test works, but mysql reports errors
- scripts needs to be uploaded
- uploaded to testserver
- hot deployment / testing on testserver
- first tests: lang splitting doesn't work, adding some fixes
- text coding ... utf8 ?
- mysql.php - extra parameter to send iso-8859-1
- utf8 doesn't work as expected, RU results in garbage, FR and DE halfway gargabled
- PR
- dirk: note from alex: german translation should have an error
- next steps:
bug #968 documentation, action required?
- Testers workqueue
Translingo bug #985
https://translations.cacert.org (http://translations.cacert.org/) (replacement for translingo)
- the translingo.cacert.org had been in operation far longer, so I think it is possible that some users migrated to translingo.cacert.org, without telling us.
- I would suggest to mass-mail the email addresses of the translation-project leaders in the translingo database, to inform them, and to ask them to speak up if they still need it
- last foreign uploads 2008 on about 13 + cacert projects
- whohas translingo server console access?
- mario
- req for console access for michael to contact project leaders, Updates?
- Transfer In, Transfer Out problems
- Update from new deployment ?
- opened for: create an account can now be started
- Michael current state:
- import and export routine works
- script to incorporate updates needs fixed
- next: complete language handling needs to be updated
- accept lang handler needs fix
- FF de, de_de
- IE 6 de, 8,9 de_de
- working session within last meeting: michael, marcus
- infos from meeting 2011-10-18
- pdf code needs rewrite (uni code library, move to external server (outsourcing))
- message cert notification - uses perl code, text source not avail (get bind-text-domain)
- infos from meeting 2011-10-18
- current state?
- Marcus sent mailing to translators, no response so far, no tests so far (week 3)
- Morten NO
- Emanuel IT
- current state:
- create test system accounts dutch@test, espania@test and so on, let users do their tests
- Magu, Marcus will give it a try
- a couple of testers has started testing and reporting within the last 7 days
- results: de, fr, en, pl, es
- pl: open question with special chars
bug#894 "Haeckchen bug" - review done, changes needs reviewed again
3
Dirk
bug#894 assure someone patches (checkbox)
(incl wot.php changes)
tested by 2, needs 2nd review, deploy
new test round{0}
? / u1 / m1
- review by dirk in session, review ok
- current state:
- needs testing
- Magu, Marcus will pickup the task
- one test and report done this week (in week 3)
- 965 outsource webdb pages
- needs retesting
- uli to ping testers
Policy group discussion - Extended key usage -> p20111113 started, extended for 1 week
- new related topics
- ios5 bug
- all sources regarding ios5 says: keyusage must be present
- so its likely that cps fix fixes ios5 bug too
- keysize
- keyusage is also referenced
- similiar to CAcert's new proposal
- ios5 bug
- new related topics
- OCSP server - timeout 10 min too short, 3 days to long, recommendation is 24-48 hours max, verisign: 7 days, startssl: 2d
- who has been informed, contacted?
- Michael will inform Wytze
- mail not yet written
- Build + Document Emergency Patches Path
Build + Document Emergency Patches Path
Andreas, Uli, Wytze
{0}
- Documentation written, reviewed by Wytze, Marcus
Michael: reminder for review Software/Assessment/Documentation/EmergencyPatches
- Michael: not reviewed yet
VBscript for Vista/Win7 (select keysize >= 1024) - reminder
- marcus: illuminat not yet seen last time
baseline requirement - keyssize >= 2048 to fix till end of 2011
- how to proceed?
- dirk: 1st step, to bring win test server localy online
- marcus: to contact illuminat
strategy plans ... next: strategy for "New Roots & Escrow"
- no update
- CI (Update)
- no update
- Infrastructure seperation
- no update
- next meeting: Tuesday, November 29, 2011 22:00
- Working session: mailing script
problem with revoke assurance - proposal for SE's: Support/Handbook/NewPointsCalculation
- [0:50] while working on the mailing script .... working session meeting adjourned to Wed 20:00 UTC (21 CET)
Minutes 2011-11-23 (Cont.)
- Meeting starts at 21:00 CET
- Attendees: Magu, Marcus, Dirk, Michael, Uli
- Text output from test run is ok also with special and utf chars
- Counter missing
- discussion if counter or not
- dirk: no spare time to add counter to the script
review of Support/Handbook/NewPointsCalculation instructions for SE's
- Mail from Support to Assurer
- Name and Email should be send in info mail
- 3 potential scenarios possible:
- orig email is identical to email addr on CAP form
- orig email is secondary email in account, assuree can set email addr from assurance to primary email
- orig email from assurance is no longer valid, assurer has to contact support
- addtl. documentation required
- new email addr to write onto assurers cap form, with ticket id, old assurance id, new assurance id
- addtl. documentation old id + ticket id to add in locations field
- addtl. documentation required
- 3 potential scenarios possible:
- review finished
Fixed Action Items since last or within meeting
Michael
bug #968 error logging cleanup (splitted bug #909)
split 0000909: too many error messages logged - part II - general.php
create certs,certs,certs
2 sessions: 2011-09-21 + 2011-09-25
more tests needed
create certs,certs,certs,certs
create client, server, gpg keys, org client and server certs
logs reviewed, ok
Michael to contact Ted for 2nd review{g}
Michael
bug #540 Policy group discussion - Extended key usage -> p20111113 started, addtl. mail to policy group with some more explanations, especialy which flags are for the Adobe bug, why this CPS update is neccessary
{g}
uli
to pick up dirks working items: agm/sgm minutes, so dirk can write the mailing script
{g}
Magu, Marcus
Translingo bug #985 prepare lang test accounts dutch@test, espania@test and so on, mail users doing some tests
{g}
dirk
mailing script for New points count project newsletter mailing
{g}
uli
{g}
Action Items New
Action items: Meeting Action Items
Software/Assessment/ActionItems
all
proposed Apache config SSLCipherSuite settings for CAcert SSL enabled infrastructure systems
see also BEAST migration https://community.qualys.com/blogs/securitylabs/2011/10/17/mitigating-the-beast-attack-on-tls
Proposal from Sysadm list 2013-09-06{0}
SA
documentation server cert design concept to SystemAdministration/Systems/Development/Prepare
{0}
all
{0}
BenBE, Marcus
documentation: developer git repos under github
bug #1131 history @ github
CAcertOrg @ github
started under Software/Assessment/Documentation/UpdateCycle/step1{0}
NEO
{0}
all
read x509 guide
{0}
all
bug#1068 blog problem (also relates to community)
debian lenny - edge - squeeze upgrades needed
alternate: new server with squeeze, install wordpress, transfer domain
workaround: configure your FF FAQ/BrowserClients{g}
uli
Experience points for ATE attendance
check board motions and/or trigger if not yet passed{0}
uli
Infrastructure separation, to contact secure-u (Frank, Mario, Ted, Sebastian) for discussion, prepare a plan, started 2011-12-18
current state: see Funding Landing Page
May 2013: tk-server sponsoring, tk-server rcvd, deployment: WIP, project not yet finished{0}
All
1. next: strategy for "New Roots & Escrow" - using indirect crl's ?
indirect CRL: RFC 5280 http://tools.ietf.org/html/rfc5280 (chapter 5) - test deployment{0}
dirk, Michael
3. next: strategy for "New Roots & Escrow" - how does debian work?
to contact, deferred to next events (?)
next round: picked up by Benedikt new proposal 2013-06-02{0}
Uli, Michael
Documentation Bugs.cacert.org Review, documentation I (bugs handbook) svg files to convert to jpg or png
{0}
Development, Deployment, Discussion
OAO, Ted
bug #943 change OA admin/assurer text
needs 2nd test -> Fabian, Marc, Alex? {g} / needs 2nd review -> Ted, rejected
{-}
uli, Ted
bug #824 Org User cert fix Case study
Organisation User Certificates: Need UI improvement for proper production usage
{0}
uli, ted
bug #823 email address removal fix
No warning when removing e-mail address from account that certificates will be revoked
checked by 4, needs 2nd review, deploy
rejected{-}
inopiae
bug #920 Join - single name only (eg Indonesian)
details under bug number
{0}
uli
bug #859 admin console interface
feature request: show activity on an account in the admin interface
rejected, certs login doesn't modify "modified" field{r}
Michael
p20111113 CPS #7.1.2 "Certificate Extensions" adjustments - testing
uli, marcus: needs full cert create tests
duplicate report to bug#978
tested by 3, 2nd review done, transfered
Ken reported: still has problems, bug kept open{0}
gagern, NEO
bug #440 Problem with subjectAltName (CSR, renew certs)
There seems to be a problem with the subjectAltName. Dupes, missing entries, and more, rejected, needs further development
{r}
neo
bug #1025 Domain Dispute issue
disputes rc and rc2 var prob
needs work{r}
dirk
bug #1054 0001054: Review the code regarding the new point calculation
Thawte patch part II
needs further work{r}
Software Assessors: Review 1 / add to cacert-devel, add to testserver
Software-Assessors task
Testing
Testers task
neo
bug #1004 Stats page improvement
tested by 2, needs 2nd review
{0}
neo
Bugs #1159 it might be possible to execute commands on the signing server
{0}
inopiae
bug #1065 Wrong wording when sending mails during the assurance process
{0}
inopiae
bug #1162 calcutate (the passwords) hash in php instead of in mysql
create test scenarios for the software testers
Full testing{0}
inopiae
bug #0028 Wrong language for you've been assured & [CAcert.org] Client Certificate emails
{0}
inopiae
bug #988 TTP cap form deployment
{0}
Software Assessors: 2nd Review, Bundle Package to Critical Team
Software-Assessors task
Ted
bug #500 Get contact mail adress after resolving test
tested by 3, requires review
{0}
Ted
bug #1140 Show if a test is passed in learnprogress
tested by 3, requires review
{0}
magu
bug #1131 Rename _all_ Policies from .php to .html and fix all links
global policy directory maintenance and update
{0}
inopiae
bug #1010 Reorder the view on organisation certificates
tested by 3
{0}
Software Assessors: Bundle Package to Critical Team
Software-Assessors task
inopiae
bug #1139 Add new fields to the database
tests through #500 and #1140, 2nd review done, requires transfer
{0}
Awaiting Response from Critical Team
inopiae
bug #411 Wrong text is made into link
{g}