)]}'
{"specs/artifact-signing.rst":[{"author":{"_account_id":6316,"name":"Anita Kuno","email":"anteaya@anteaya.info","username":"anteaya"},"change_message_id":"12215848493f2540e20d37d9df713526a2f95ace","unresolved":false,"context_lines":[{"line_number":70,"context_line":"   private key with our other service credentials and add the"},{"line_number":71,"context_line":"   subkey in hiera"},{"line_number":72,"context_line":"2. Get all infra root admins to sign the artifact signing key and"},{"line_number":73,"context_line":"   publish those signatures to the keyserver network"},{"line_number":74,"context_line":"3. *openstack-infra/system-config*:"},{"line_number":75,"context_line":""},{"line_number":76,"context_line":"   1. Create a puppet class and node definition for"}],"source_content_type":"text/x-rst","patch_set":1,"id":"1a4dcd0f_36c92e26","line":73,"updated":"2015-08-14 18:42:56.000000000","message":"What would be the expiration date on the artifact signing key?","commit_id":"e622abbe9a511fe190ff0f3821575b94b2062d2d"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"b364a5c973901deb7c9d03894bbd8cb1617ddcb2","unresolved":false,"context_lines":[{"line_number":70,"context_line":"   private key with our other service credentials and add the"},{"line_number":71,"context_line":"   subkey in hiera"},{"line_number":72,"context_line":"2. Get all infra root admins to sign the artifact signing key and"},{"line_number":73,"context_line":"   publish those signatures to the keyserver network"},{"line_number":74,"context_line":"3. *openstack-infra/system-config*:"},{"line_number":75,"context_line":""},{"line_number":76,"context_line":"   1. Create a puppet class and node definition for"}],"source_content_type":"text/x-rst","patch_set":1,"id":"fa1b9901_63671726","line":73,"in_reply_to":"1a4dcd0f_36c92e26","updated":"2015-08-22 14:35:47.000000000","message":"The master key and signing subkey can be set to expire after the start of a new release cycle, and then we can manually extend the expiration before the end of each cycle. We\u0027ll also keep the revocation certificate on hand in the event the key is compromised.","commit_id":"e622abbe9a511fe190ff0f3821575b94b2062d2d"},{"author":{"_account_id":6316,"name":"Anita Kuno","email":"anteaya@anteaya.info","username":"anteaya"},"change_message_id":"12215848493f2540e20d37d9df713526a2f95ace","unresolved":false,"context_lines":[{"line_number":74,"context_line":"3. *openstack-infra/system-config*:"},{"line_number":75,"context_line":""},{"line_number":76,"context_line":"   1. Create a puppet class and node definition for"},{"line_number":77,"context_line":"      signing.slave.openstack.org"},{"line_number":78,"context_line":"   2. Add basic documentation of the infra root process for handling"},{"line_number":79,"context_line":"      and rotation of the artifact signing key"},{"line_number":80,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"1a4dcd0f_f6366650","line":77,"updated":"2015-08-14 18:42:56.000000000","message":"I thought we were working on removing references to slave.\n\nI propose:\n\n signing.server.openstack.org","commit_id":"e622abbe9a511fe190ff0f3821575b94b2062d2d"},{"author":{"_account_id":2,"name":"Monty Taylor","email":"mordred@inaugust.com","username":"mordred"},"change_message_id":"3fa3cd979c5e6575547812a622d1473f9d3c3e8d","unresolved":false,"context_lines":[{"line_number":74,"context_line":"3. *openstack-infra/system-config*:"},{"line_number":75,"context_line":""},{"line_number":76,"context_line":"   1. Create a puppet class and node definition for"},{"line_number":77,"context_line":"      signing.slave.openstack.org"},{"line_number":78,"context_line":"   2. Add basic documentation of the infra root process for handling"},{"line_number":79,"context_line":"      and rotation of the artifact signing key"},{"line_number":80,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"1a4dcd0f_bd5660cc","line":77,"updated":"2015-08-16 10:50:58.000000000","message":"Sure. But I disagree with \"server\" - it\u0027s not clear enough. \"worker\" would be fine, and is certainly non-judgemental, egalitarian, and is derived from gearman terminology.","commit_id":"e622abbe9a511fe190ff0f3821575b94b2062d2d"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"b364a5c973901deb7c9d03894bbd8cb1617ddcb2","unresolved":false,"context_lines":[{"line_number":74,"context_line":"3. *openstack-infra/system-config*:"},{"line_number":75,"context_line":""},{"line_number":76,"context_line":"   1. Create a puppet class and node definition for"},{"line_number":77,"context_line":"      signing.slave.openstack.org"},{"line_number":78,"context_line":"   2. Add basic documentation of the infra root process for handling"},{"line_number":79,"context_line":"      and rotation of the artifact signing key"},{"line_number":80,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"fa1b9901_0343bb6d","line":77,"in_reply_to":"1a4dcd0f_97e900ba","updated":"2015-08-22 14:35:47.000000000","message":"If there was a plan to rename our Jenkins slaves, I missed the discussion.\n\nOur existing long-lived workers are named proposal.slave.o.o and release.slave.o.o. I\u0027m fine with renaming them, though it will require a rebuild of the servers. I don\u0027t know that we really need an additional subdomain in the name, and could just rename them to proposal.o.o, release.o.o and make this one signing.o.o. However, it\u0027s orthogonal to this proposal, which is consistent with what we have now.","commit_id":"e622abbe9a511fe190ff0f3821575b94b2062d2d"},{"author":{"_account_id":6316,"name":"Anita Kuno","email":"anteaya@anteaya.info","username":"anteaya"},"change_message_id":"15fa0ad7d5db17112a57f7bfc16b785929769986","unresolved":false,"context_lines":[{"line_number":74,"context_line":"3. *openstack-infra/system-config*:"},{"line_number":75,"context_line":""},{"line_number":76,"context_line":"   1. Create a puppet class and node definition for"},{"line_number":77,"context_line":"      signing.slave.openstack.org"},{"line_number":78,"context_line":"   2. Add basic documentation of the infra root process for handling"},{"line_number":79,"context_line":"      and rotation of the artifact signing key"},{"line_number":80,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"1a4dcd0f_97e900ba","line":77,"in_reply_to":"1a4dcd0f_bd5660cc","updated":"2015-08-16 17:42:49.000000000","message":"I can get behind worker.","commit_id":"e622abbe9a511fe190ff0f3821575b94b2062d2d"},{"author":{"_account_id":6316,"name":"Anita Kuno","email":"anteaya@anteaya.info","username":"anteaya"},"change_message_id":"c521122a7de6ba1e80e654a6f082cc473f3bcd33","unresolved":false,"context_lines":[{"line_number":74,"context_line":"3. *openstack-infra/system-config*:"},{"line_number":75,"context_line":""},{"line_number":76,"context_line":"   1. Create a puppet class and node definition for"},{"line_number":77,"context_line":"      signing.slave.openstack.org"},{"line_number":78,"context_line":"   2. Add basic documentation of the infra root process for handling"},{"line_number":79,"context_line":"      and rotation of the artifact signing key"},{"line_number":80,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"fa1b9901_c657d1c8","line":77,"in_reply_to":"fa1b9901_0343bb6d","updated":"2015-08-24 21:57:09.000000000","message":"Sorry this is my fault.\n\nI mis-remembered something from before, though I can\u0027t remember where so so much for being able to link a reference, which left me with the impression moving to a different naming scheme was already in play. I see this is me introducing it which was not my intention. Yes whatever is in keeping with current structure is what is called for here. My apologies for introducing confusion.","commit_id":"e622abbe9a511fe190ff0f3821575b94b2062d2d"},{"author":{"_account_id":6316,"name":"Anita Kuno","email":"anteaya@anteaya.info","username":"anteaya"},"change_message_id":"12215848493f2540e20d37d9df713526a2f95ace","unresolved":false,"context_lines":[{"line_number":78,"context_line":"   2. Add basic documentation of the infra root process for handling"},{"line_number":79,"context_line":"      and rotation of the artifact signing key"},{"line_number":80,"context_line":""},{"line_number":81,"context_line":"4. Launch the new signing.slave.openstack.org server"},{"line_number":82,"context_line":"5. *openstack-infra/system-config*: Add signing.slave.openstack.org"},{"line_number":83,"context_line":"   to cacti"},{"line_number":84,"context_line":"6. Register the signing.slave.openstack.org in jenkins.openstack.org"}],"source_content_type":"text/x-rst","patch_set":1,"id":"1a4dcd0f_161192af","line":81,"updated":"2015-08-14 18:42:56.000000000","message":"Ditto.","commit_id":"e622abbe9a511fe190ff0f3821575b94b2062d2d"},{"author":{"_account_id":6554,"name":"Spencer Krum","email":"nibz@spencerkrum.com","username":"krum-spencer"},"change_message_id":"0e3fd3e69f68eaa2e219053334a2078c106e805d","unresolved":false,"context_lines":[{"line_number":81,"context_line":"4. Launch the new signing.slave.openstack.org server"},{"line_number":82,"context_line":"5. *openstack-infra/system-config*: Add signing.slave.openstack.org"},{"line_number":83,"context_line":"   to cacti"},{"line_number":84,"context_line":"6. Register the signing.slave.openstack.org in jenkins.openstack.org"},{"line_number":85,"context_line":"   and add a ``signing`` label to it"},{"line_number":86,"context_line":"7. *openstack-infra/project-config*:"},{"line_number":87,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"1a4dcd0f_4814539e","line":84,"updated":"2015-08-14 21:15:03.000000000","message":"As I understand it, jenkins slaves (sorry anita) can comprimise the master(sorry again). So if we have the \u0027publishing\u0027 slave or any other less trusted slave connected to jenkins.o.o they could comprimise this slave which is meant to be higher security.\n\nThis is the long way of asking, do we need a separate jenkins master for this.","commit_id":"e622abbe9a511fe190ff0f3821575b94b2062d2d"},{"author":{"_account_id":2,"name":"Monty Taylor","email":"mordred@inaugust.com","username":"mordred"},"change_message_id":"3fa3cd979c5e6575547812a622d1473f9d3c3e8d","unresolved":false,"context_lines":[{"line_number":81,"context_line":"4. Launch the new signing.slave.openstack.org server"},{"line_number":82,"context_line":"5. *openstack-infra/system-config*: Add signing.slave.openstack.org"},{"line_number":83,"context_line":"   to cacti"},{"line_number":84,"context_line":"6. Register the signing.slave.openstack.org in jenkins.openstack.org"},{"line_number":85,"context_line":"   and add a ``signing`` label to it"},{"line_number":86,"context_line":"7. *openstack-infra/project-config*:"},{"line_number":87,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"1a4dcd0f_dd59ecfe","line":84,"updated":"2015-08-16 10:50:58.000000000","message":"I don\u0027t think so. We treat all of the trusted slaves as trusted systemically. (it\u0027s a great question) We take care to not run any code on them that is from the internet, etc. So although they exist, I don\u0027t think they do a lot that would open them to attack.","commit_id":"e622abbe9a511fe190ff0f3821575b94b2062d2d"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"b364a5c973901deb7c9d03894bbd8cb1617ddcb2","unresolved":false,"context_lines":[{"line_number":81,"context_line":"4. Launch the new signing.slave.openstack.org server"},{"line_number":82,"context_line":"5. *openstack-infra/system-config*: Add signing.slave.openstack.org"},{"line_number":83,"context_line":"   to cacti"},{"line_number":84,"context_line":"6. Register the signing.slave.openstack.org in jenkins.openstack.org"},{"line_number":85,"context_line":"   and add a ``signing`` label to it"},{"line_number":86,"context_line":"7. *openstack-infra/project-config*:"},{"line_number":87,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"fa1b9901_033adbe7","line":84,"in_reply_to":"1a4dcd0f_dd59ecfe","updated":"2015-08-22 14:35:47.000000000","message":"Worst case, they compromise the signing subkey which we can revoke and reissue. We would not install the PGP master key on the worker.\n\nAlso, if we end up upgrading our Jenkins masters, there is recently added mitigation against this risk.","commit_id":"e622abbe9a511fe190ff0f3821575b94b2062d2d"},{"author":{"_account_id":6316,"name":"Anita Kuno","email":"anteaya@anteaya.info","username":"anteaya"},"change_message_id":"12215848493f2540e20d37d9df713526a2f95ace","unresolved":false,"context_lines":[{"line_number":113,"context_line":"Servers"},{"line_number":114,"context_line":"-------"},{"line_number":115,"context_line":""},{"line_number":116,"context_line":"A new signing.slave.openstack.org server needs to be created. No"},{"line_number":117,"context_line":"existing servers will be affected."},{"line_number":118,"context_line":""},{"line_number":119,"context_line":"DNS Entries"}],"source_content_type":"text/x-rst","patch_set":1,"id":"1a4dcd0f_f68426d4","line":116,"updated":"2015-08-14 18:42:56.000000000","message":"Again, naming suggestion.","commit_id":"e622abbe9a511fe190ff0f3821575b94b2062d2d"},{"author":{"_account_id":2,"name":"Monty Taylor","email":"mordred@inaugust.com","username":"mordred"},"change_message_id":"3fa3cd979c5e6575547812a622d1473f9d3c3e8d","unresolved":false,"context_lines":[{"line_number":141,"context_line":"from the current situation. Specifically, the artifact signing key"},{"line_number":142,"context_line":"needs to be safeguarded closely as it provides indication of"},{"line_number":143,"context_line":"tampering post-release. Our existing secret management solutions"},{"line_number":144,"context_line":"should be sufficient for this purpose."},{"line_number":145,"context_line":""},{"line_number":146,"context_line":"Note that this spec does not attempt to address trust challenges"},{"line_number":147,"context_line":"earlier in the development, test and build toolchain. There are"}],"source_content_type":"text/x-rst","patch_set":1,"id":"1a4dcd0f_7d71b876","line":144,"updated":"2015-08-16 10:50:58.000000000","message":"It\u0027s out of scope of this spec - but since I yelled at the nodejs people about it - if we\u0027re going to sign artifacts, perhaps we should also serve them via HTTPS?","commit_id":"e622abbe9a511fe190ff0f3821575b94b2062d2d"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"b364a5c973901deb7c9d03894bbd8cb1617ddcb2","unresolved":false,"context_lines":[{"line_number":141,"context_line":"from the current situation. Specifically, the artifact signing key"},{"line_number":142,"context_line":"needs to be safeguarded closely as it provides indication of"},{"line_number":143,"context_line":"tampering post-release. Our existing secret management solutions"},{"line_number":144,"context_line":"should be sufficient for this purpose."},{"line_number":145,"context_line":""},{"line_number":146,"context_line":"Note that this spec does not attempt to address trust challenges"},{"line_number":147,"context_line":"earlier in the development, test and build toolchain. There are"}],"source_content_type":"text/x-rst","patch_set":1,"id":"fa1b9901_2316ff55","line":144,"in_reply_to":"1a4dcd0f_7d71b876","updated":"2015-08-22 14:35:47.000000000","message":"If we sign artifacts, we don\u0027t necessarily need to serve them via HTTPS because they can then be verified independent of the security of the channel through which they were obtained. Though having the signing machine retrieve them via HTTPS would be nice, so we ought to look into SNI for static.o.o or moving tarballs.o.o to a dedicated host anyway.","commit_id":"e622abbe9a511fe190ff0f3821575b94b2062d2d"}]}
