To Software Software - To Software-Assessment - Software/Assessment - To previous meeting - To next meeting
Minutes of the MiniTOP on the 2011-05-24
Setting
The MiniTOP will be held via telco 22:00 CEST
Attendees: Martin, Alexander, Uli, Marcus, dirk, Michael
Topics
new items in last meeting:
- dirk: Barcamp Karlsruhe 18./19. Jumi, testers workshop, invite npapa
- uli, markus: testers how-to regarding testserver roots: live-cd ? how-to, 2nd profile add to Welcome Pack
- Dirk, Michael, Mawa: bug#942 (cats test) (ted), triage test on CATS (Update), to review, to test
Ted, Michael: CATS system, add onto mgr server, add ted as console admin on mgr server -> Michael
- Uli: add Michael to host console (firewall add) (fixed within meeting)
Dirk: strategy for: "Certificates Class3" problem and "New Roots & Escrow" - Press release, Announcements to be presented to board by Community: contact alex
- Uli: "Rewarding testers" post proposal, publish with updated infos
- Michael: signer on testserver doesn't work currently (problem is triggered gpp key that crashes signer), needs fixing (fixed within meeting)
- Michael: fix Root_Certs table on cacert1.it-sls.de (fixed within meeting)
Action items from last meeting Meeting Action Items
- triage test on CATS (Update)
- State Testserver Update, Current Patches on Testserver, current running Arbitrations:
Arbitration case a20110312.1 Weak keys
Arbitration case a20110419.1 Bug #637: Weak Passwords
"Thawte" patch Bug# 827 Points-Count-Order-Change project
- strategy plans ...
strategy for: "Certificates Class3" problem and "New Roots & Escrow" - proposal to board, done in last board meeting
- upgrade plan: Press release, Announcements to be presented to board by Community
m20110515.2 "Class 3 Certificate Resign"
m20110515.3 "Prepare press statement about Class 3 Resign"
That we ask the community to prepare a press statement, to be sent to various groups, and to be accepted by Board before sending out.
- Testgroup: (to contact by phone ?), update
m20110515.4 "Rewarding testers"
- CI app.test (Update)
- next meeting: Tuesday, May 31, 2011 22:00
Minutes
- Barcamp Karlsruhe 18./19. June, testers workshop - is running
- testers how-to regarding testserver roots, no update
- bug#942 (cats test) (ted), triage test on CATS (Update), to review, to test, no update
strategy for: "Certificates Class3" problem and "New Roots & Escrow" - Press release, Announcements to be presented to board by Community: contact alex
- Press release to send out with date of replacement
- Alex will pickup the task to write a press release
- dirk: short summary about class3 replacement project
- Michael will send the fingerprint to Alex
- date when release ?
- change cap form (only capnew.php), in old cap.php only class1
- website root certs to update
- /pages/index/3.php, 16.php
- coapnew.php, capnew.php to remove or to replace
- dirk: printout with new fingerprint EN, DE, NL, FR, save to svn
- capnew.php to execute on eg community.cacert.org
- flyers: create labels with new fingerprint for old flyers
- cca printouts (svn)
- 1., 15., 30.6. ?
- 1. don't fit to prepare
- 30.6. is too late
- rollout date: 15.6. +/- 5 days - between 15.6. and 20.6.
- Mon 6.6. or Mon 20.6. ct release date
- blog post 1-2 days earlier
- blog post and patch at the same time
- todo list: prepare patches, blog post (Alex, Ian, Pieter)
- NL magazines ?
- mailing list: cacert, cacert-de
- scripted mailing: out of discussion
- wiki page: root certs (incl. subroot)
- notifications to: debian, gentoo, fedora, suse?, see supported roots wiki inclusion state page
- client certs class3 needs replacement of class3 subroot too
- m20110515.4 "Rewarding testers" post proposal, publish with updated infos, rolled out
- mantis bugs: notifications missing, bug #854
- Michael tries to fix it in the session
- New bug fixes:
- dirk: DEV: bug#827 regular Thawte patches: still open, 15.php - add assurers state at bottom of page Thursday ? next to upload
Org Arb case a20100404.1
- workaround: on adding domain, send email to: arb, board, org group
- next meeting: Tuesday, May 31, 2011 22:00
Fixed Action Items since last Meeting
dirk
Barcamp Karlsruhe 18./19. June, testers workshop, invite npapa
Ted, Michael
CATS system, add onto mgr server, add ted as console admin on mgr server -> Michael
Uli
add Michael to host console (firewall add)
Michael
signer on testserver doesn't work currently (problem is triggered gpp key that crashes signer), needs fixing
Michael
fix Root_Certs table on cacert1.it-sls.de
Action Items New
- Alex, Ian, Pieter - prepare pressrelease about class3 project
Uli - documentation: sources of class3 fingerprint
- Michael, Dirk, Uli - prepare patches, update wiki and other sources with new class3 fingerprint
- Michael - mantis bug: notification emails missing
- Michael - mantis bug: bug #854 (white page)
- Michael, Dirk, Ted - * New bug fixes:
Action items: Meeting Action Items
Software/Assessment/ActionItems
Marcus
cap.php review different languages, from meeting 2012-04-24, contact translators
uli
Experience points for ATE attendance
check board motions and/or trigger if not yet passed
uli
Infrastructure separation, to contact secure-u (Frank, Mario, Ted, Sebastian) for discussion, prepare a plan, started 2011-12-18
current state: see Funding Landing Page
All
1. next: strategy for "New Roots & Escrow" - using indirect crl's ?
indirect CRL: RFC 5280 http://tools.ietf.org/html/rfc5280 (chapter 5) - test deployment
dirk, Michael
3. next: strategy for "New Roots & Escrow" - how does debian work?
to contact, deferred to next events (?)
Uli, Michael
Documentation Bugs.cacert.org Review, documentation I (bugs handbook) svg files to convert to jpg or png
Development, Deployment, Discussion
dirk Brian
DEV: bug#918 (Part II) (a20110312.1) Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php)
new bug#964
current state: test /account/4.php added to testserver
Marcus will do detailed tests on Wed
some references added to bug#964 done.
proposal patch from Brian rcvd
OAO, Ted
bug #943 change OA admin/assurer text
needs 2nd test -> Fabian, Marc, Alex?
/ needs 2nd review -> Ted, rejected
uli, Ted
bug #824 Org User cert fix Case study
Organisation User Certificates: Need UI improvement for proper production usage
uli
bug #988 TTP cap form deployment Case study
sneak preview
for local testserver deployment only
uli, ted
bug #823 email address removal fix
No warning when removing e-mail address from account that certificates will be revoked
checked by 4, needs 2nd review, deploy
rejected
inopiae
bug #920 Join - single name only (eg Indonesian)
details under bug number
uli
bug #859 admin console interface
feature request: show activity on an account in the admin interface
rejected, certs login doesn't modify "modified" field
All
bug #1034 files to remove from webdb
eg wot/14
Software Assessors: Review 1 / add to cacert-devel, add to testserver
Software-Assessors task
uli
bug #977 admin console text fix
admin console Sysadmin - find domain - lists 2 tables - one for user accounts, one for org accounts, naming issue
Testing
Testers task
gagern
bug #440 Problem with subjectAltName (CSR, renew certs)
There seems to be a problem with the subjectAltName. Dupes, missing entries, and more
neo
bug #922 CAcert application code problem causing missing "certificate about to expire" messages
Ted
bug #835 Assurer challenge (on testserver)
needs testing
Michael
bug #1003 Provide a possibility to regularly review the permissions in the system
also bug #1038 Provide a script for board/tverify reset flags by arbitration a20110118.1
neo
bug #1025 Domain Dispute issue
disputes rc and rc2 var prob
Software Assessors: 2nd Review, Bundle Package to Critical Team
Software-Assessors task
uli, ted
bug #789 OA edit domain fix
Editing domain for organisations does not work
new update 2011-09-26
2 tests, needs 2nd review, deploy
more fixes, more testing6
uli
bug #967 OA isassurer check
Give an OA the opportunity to check if a designated Organisation Administrator is a CAcert assurer
neo
bug #978 Invalid SPKAC requests are not properly validated
recheck full certs signing procedures
duplicate report to bug#540
Michael
p20111113 CPS #7.1.2 "Certificate Extensions" adjustments - testing
uli, marcus: needs full cert create tests
duplicate report to bug#978
neo
bug #1024 Assurer flag is not set correctly on updatesort.php run
tested by 4, ok
dirk
bug #1023 Consolidate changes into the Assure Someone page
6.php global re-design project
assurance, wot area (Thawte points removal effective)
inopiae
New layout of view for Organisation Administrators in account/id35
Software Assessors: Bundle Package to Critical Team
Software-Assessors task
Awaiting Response from Critical Team
