Minutes of the MiniTOP on the 2011-08-02

Setting

The MiniTOP will be held via telco 22:00 CEST

Attendees: Magu, Benedikt F, Marcus, Dirk, Uli, Ted, Michael, Alex

Topics

(skip to agenda)

Action items from last meeting Meeting Action Items

Agenda

  1. PRO
  2. Milestone 3 of Software-Assessment project team reached? "Build + Document Emergency Patches Path"
    • As a side effect on writing the AGM 2010-2011 report, the reach of milestone 3 comes to question
    • The side effect becomes possible by the last meeting vote on parallele processing of patches
    • how about documentation?
  3. how to handle / work with git
    • git pull
    • git diff origin/release...origin/bug-921>bug921.patch

    • send to critical team by email (with template)
    • link to bug, who reviewed, people to cc
  4. Workshop - The List of open / running / unhandled bugs
    1. x1 Arbitration case a20110312.1 Weak keys bug #918 / bug #954 / bug#964

      • Current state:

        {g}

        pre mailing sent

        {g}

        keys revocation script to bulk revoke weak keys, new bug #954, finished

        {-}

        dirk: DEV: a20110312.1 bug#918 Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEV
        vbscript needs to be improved with select box key size and lower limit to 2048 (based on https://wiki.mozilla.org/CA:MD5and1024)
        Api CertEnroll (MS crypto provider)
        new bug#964
        current state: test /account/4.php added to testserver
        Marcus will do detailed tests on Wed
        some references added to bug#964

        {g}

        Weak keys blog post, published

        {0}

        Weak keys article not yet published by Hanno

        {b}

        weak keys: problems with cryptostick (to test at Froscon with Juergen ?)

    2. x2 Bug# 827 and bug #959 "Thawte" patch - Points-Count-Order-Change project - 2nd Review + deploy

      • Next step(s) ?
        • current state on production system? table points: count(id) > 150 points ?

        • fix points < 0 and points > 150 in bug 827 ?

        • included
      • missing: bug #959 2nd review

        • dirk to add note in bugtracker, done
      • todo:
        1. NEO: 2nd review of Bug# 827

        2. NEO: bundling Bug# 827 and bug #959 to critical team

      • bug #959 deployed

    3. x3 Bug #637 and bug #953 and bug #963 : Weak Passwords - 2nd Review + deploy

      • Overall result: Please evaluate if the session problem can be fixed!
      • if password changed, cached info - reminder plz change pwd
      • session reset and error messages in system log
      • new bug #963

        • /includes/loggedin.php line 140 ff. to fix
        • Ted: checked-in cacert-devel, added to testserver
        • needs review, re-testing
      • Next steps:
      • {-} maybe we have a potential problem here: Bug #637 is transfered to critical system, bug #953 and bug #963 aren't. 637 depends on 653 and 963. On testserver this _complete_ bundle works.

    4. x4 bug #841 Problems on cert login

      • needs 2nd review - Ted, done
        needs bundling, done

      • NEO: did restructuring (sql query to subroutine), (Update 2011-07-26)
      • needs re-tested
      • needs 2nd review, bundling
    5. Dirk reminder (from last meeting) assure someone patches (checkboxes)

      • Dirk

        DEV: bug #894 problems with check-boxes on website forms (Assure someone) -> a20091118.3

        {0}

    6. Review 1: review, add to cacert-devel, transfer to testserver
    7. Review bugs under testing (finished testing?) (Review 2?)
      • x2 bug #827 "Thawte" patch (still running)
        related bug #959

        needs 1 more test, needs 2nd review
        2nd review: also check -x
        tests done, 2nd review outstanding

        {0}
        {g}

        x3 bug #637 and bug #953 and bug #963 weak password

        needs 2nd review, not Micha -> Ted, done
        Overall result: Please evaluate if the session problem can be fixed! (new bug #963)

        {g}
        {0}
        {0}

        x4 NEO: bug #841 Problems on cert login

        needs 2nd review - Ted, done
        needs bundled
        NEO will check to get sql query extracted
        needs pushing
        pushed to testserver
        Needs Review & testing

        {0}

        bug #910 Outsource board member list

        from Webdb to wiki (id=8) (Part II)

        {0}

        bug #955 change sort order Orga list

        Possibilty to change the sorting order for the organisation overview

        {0}

    8. (review), to bundle, to deploy
      • bug #942 CATS import (2)

        complete re-test as of code changes
        fully re-tested by 2 testers

        {0}

        bug #911 gpg bug

        gpg keys expires 1970
        tests started 2 weeks ago
        needs review, deploy

        {0}

        bug #940 help* to wiki

        Outsource Webdb text pages help.php?id=0..9 to wiki
        needs review, deploy

        {0}

        bug #953 failure on pwd change redirect

        needs 2nd review, deploy

        {0}

    9. Needs development, deployment, discussion
      • x1 Dirk, new bug#964
        DEV: bug#918 (Part II) (a20110312.1) Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEV

        current state: test /account/4.php added to testserver
        Marcus will do detailed tests on Wed
        some references added to bug#964

        {-}

        bug #835 Assurer challenge (on testserver)

        asssigned to Ted, set to needs work, CATS to install on ca-mgr1

        {0}

        bug #943 change OA admin/assurer text

        -> Ted, rejected, needs comment from OAO

        {-}

        bug #958

        ADS Challenge, Advertising

        {0}

    10. Deployed, Finished
  5. strategy plans ... next: strategy for "New Roots & Escrow"

    1. idea: using indirect crl's ?
      • 2 crl's needed, one valid, one invalid crl server
      • more infos available ? who ?
        1. build testserver with special certs
        2. Magu, Michael to send instructions for test deployment
      • meetings ago we've defined Testing requirements and a potential testszenario
      • to remind every meeting
    2. policy group: define requirements
      • multimember escrow method ?
        • needs risk analyze
        • potential candidates ?
          • Marcus to contacted Benedikt, will contact Thomas K
          • Next step(s)
    3. how does debian work ?
      • defered to Froscon (end of Aug), CCCcamp (around Aug 10th)
  6. AGM reports 2010-2011

    • Software-Assessment project team report finished, plz review
    • Weak keys / Weak passwords missing
    • Sections added:
      • Weak Keys / Weak Passwords Arbitration cases
      • The Software-Testteam
      • Software-Assessment Documentation
      • Statistics
      • Summary
  7. Documentation Bugs.cacert.org Review
    • discussion about states to define, redefine
    • bugs documentation I (bugs handbook)

    • bugs documentation II (to incorporate into the Software-Update-Cycle procedure/documentation)

    • Review, Update
    • svg pictures have cuted text under some browsers
      • u60: cant get it scaled
  8. CI (Update)
    • description to eclipse testpage, Webinar

    • deployment scenario:
      1. create testusers
      2. testing
      3. delete testusers
    • regression test for standard tests: eg 0,1,49,50,51,99,100,101 pts w/ and w/o CATS passed
    • reminder
  9. next meeting: Tuesday, August 9, 2011 22:00

Minutes

  1. PRO
    • question from board -> PR officer

    • request to Alex
    • support from all
  2. Milestone 3 of Software-Assessment project team reached? "Build + Document Emergency Patches Path"
    • As a side effect on writing the AGM 2010-2011 report, the reach of milestone 3 comes to question
    • The side effect becomes possible by the last meeting vote on parallele processing of patches
    • how about documentation?
    • git allows several branches
    • documentation
      • who decides that issue is an emergency patch ?
      • disconnect machine from network
      • what if a check of user data is needed?
      • simple case: Software Assessor requests emergency patch thru critical admin
  3. publishing "Weak key" issue
    • awaiting Hanno's publishing
  4. how to handle / work with git
    • git pull
    • git diff origin/release...origin/bug-921>bug921.patch

    • send to critical team by email (with template)
    • link to bug, who reviewed, people to cc
    • git pull / git clone
      • git clone is from scratch, local branches that exists before not included
      • git pull
        • branches will be merged, but don't cover all branches
        • local changes not pushed to master
    • Ted: commited branch to wrong place instead of origin/release
  5. Froscon coordinations
  6. Workshop - The List of open / running / unhandled bugs
    1. x1 Arbitration case a20110312.1 Weak keys bug #918 / bug #954 / bug#964

      • Current state:

        {g}

        pre mailing sent

        {g}

        keys revocation script to bulk revoke weak keys, new bug #954, finished

        {-}

        dirk: DEV: a20110312.1 bug#918 Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEV
        vbscript needs to be improved with select box key size and lower limit to 2048 (based on https://wiki.mozilla.org/CA:MD5and1024)
        Api CertEnroll (MS crypto provider)
        new bug#964
        current state: test /account/4.php added to testserver
        Marcus will do detailed tests on Wed
        some references added to bug#964

        {g}

        Weak keys blog post, published

        {0}

        Weak keys article not yet published by Hanno

        {b}

        weak keys: problems with cryptostick (to test at Froscon with Juergen ?)

      • cert enroll infos under bug#964

      • vista and win7 works with other engine !CryptoAPI (?) => Cryptography API: Next Generation

      • Hanno published the article (July 28), link is in CAcert's blog post (July 30)
    2. x2 Bug# 827 and bug #959 "Thawte" patch - Points-Count-Order-Change project - 2nd Review + deploy

      • Next step(s) ?
        • current state on production system? table points: count(id) > 150 points ?

        • fix points < 0 and points > 150 in bug 827 ?

        • included
      • missing: bug #959 2nd review

        • dirk to add note in bugtracker, done
      • todo:
        1. NEO: 2nd review of Bug# 827

        2. NEO: bundling Bug# 827 and bug #959 to critical team

      • bug #959 deployed

      • 2nd review and bundling by Ted
        • bundling instruction to critical team, deploy 15.php, and 7 days later 10.php
    3. x3 Bug #637 and bug #953 and bug #963 : Weak Passwords - 2nd Review + deploy

      • Overall result: Please evaluate if the session problem can be fixed!
      • if password changed, cached info - reminder plz change pwd
      • session reset and error messages in system log
      • new bug #963

        • /includes/loggedin.php line 140 ff. to fix
        • Ted: checked-in cacert-devel, added to testserver
        • needs review, re-testing
      • Next steps:
      • {-} maybe we have a potential problem here: Bug #637 is transfered to critical system, bug #953 and bug #963 aren't. 637 depends on 653 and 963. On testserver this _complete_ bundle works.

      • 953: 2nd review, Dirk
        • go into repository
        • git fetch --all
          • no option all
        • git fetch origin
        • git diff origin/release...origin/bug-953
        • bundle: NEO
      • 963: addtl. for while loops ... Michael is checking
        • bundle: NEO
    4. x4 bug #841 Problems on cert login

      • needs 2nd review - Ted, done
        needs bundling, done

      • NEO: did restructuring (sql query to subroutine), (Update 2011-07-26)
      • needs re-tested
      • needs 2nd review, bundling
        • => Ted on Wed

    5. Needs development, deployment, discussion
      1. change OA admin/assurer text
        • bug #943 change OA admin/assurer text

          -> Ted, rejected, needs comment from OAO

          {-}

        • webdb names OrgAdmins as OrgAssurers and names OrgAssurers as OrgAdmins.

        • patch takes account about this issue
        • problem with menu link Org Admin .. is Org Assurers menu
          • but this menu includes one addtl. link "View" that is available for Org Admins
            • and Org Admins with master flag to add new admins
          • master flag is not described in OAP (!)

          • addtl master flag to revoke ?
          • rename to "Org Administration"
          • don't show menu to OrgAdmins

    6. Marcus: OA Arb mailing case (a20110608.1: motion for mailing passed (=m20110731.2)

      • next: translations
    7. bug #966

      • tests ok, but the question is, is OrgAdmin allowed to remove other admins ? yes or no?

      • current scenario doesn't allow removal of other admin
      • NEO: reset testserver state to fix state before bugfix
      • NEO: re-add bug 966 to testserver
      • bug needs more work, selection currently clashes with language setting (Delete != Löschen)
      • general problem in /pages/account.php with process variable, transfer of "cancel" pushes any action

Fixed Action Items since last or within meeting


Action Items New

Action items: Meeting Action Items

Software/Assessment/ActionItems

Development, Deployment, Discussion

  • OAO, Ted

    bug #943 change OA admin/assurer text

    needs 2nd test -> Fabian, Marc, Alex? {g} / needs 2nd review -> Ted, rejected

    {-}

    uli, Ted

    bug #824 Org User cert fix Case study

    Organisation User Certificates: Need UI improvement for proper production usage

    {0}

    uli, ted

    bug #823 email address removal fix

    No warning when removing e-mail address from account that certificates will be revoked
    checked by 4, needs 2nd review, deploy
    rejected

    {-}

    inopiae

    bug #920 Join - single name only (eg Indonesian)

    details under bug number

    {0}

    uli

    bug #859 admin console interface

    feature request: show activity on an account in the admin interface
    rejected, certs login doesn't modify "modified" field

    {r}

    Michael

    bug #540

    p20111113 CPS #7.1.2 "Certificate Extensions" adjustments - testing
    uli, marcus: needs full cert create tests
    duplicate report to bug#978
    tested by 3, 2nd review done, transfered
    Ken reported: still has problems, bug kept open

    {0}

    gagern, NEO

    bug #440 Problem with subjectAltName (CSR, renew certs)

    There seems to be a problem with the subjectAltName. Dupes, missing entries, and more, rejected, needs further development

    {r}

    neo

    bug #1025 Domain Dispute issue

    disputes rc and rc2 var prob
    needs work

    {r}

    dirk

    bug #1054 0001054: Review the code regarding the new point calculation

    Thawte patch part II
    needs further work

    {r}

Software Assessors: Review 1 / add to cacert-devel, add to testserver

  • Software-Assessors task

Testing

  • Testers task

    neo

    bug #1004 Stats page improvement

    tested by 2, needs 2nd review

    {0}

    neo

    Bugs #1159 it might be possible to execute commands on the signing server

    {0}

    inopiae

    bug #1065 Wrong wording when sending mails during the assurance process

    {0}

    inopiae

    bug #1162 calcutate (the passwords) hash in php instead of in mysql

    create test scenarios for the software testers /!\
    Full testing /!\

    {0}

    inopiae

    bug #0028 Wrong language for you've been assured & [CAcert.org] Client Certificate emails

    {0}

    inopiae

    bug #988 TTP cap form deployment

    {0}

Software Assessors: 2nd Review, Bundle Package to Critical Team

  • Software-Assessors task

    Ted

    bug #500 Get contact mail adress after resolving test

    tested by 3, requires review

    {0}

    Ted

    bug #1140 Show if a test is passed in learnprogress

    tested by 3, requires review

    {0}

    magu

    bug #1131 Rename _all_ Policies from .php to .html and fix all links

    global policy directory maintenance and update

    {0}

    inopiae

    bug #1010 Reorder the view on organisation certificates

    tested by 3

    {0}

Software Assessors: Bundle Package to Critical Team

  • Software-Assessors task

    inopiae

    bug #1139 Add new fields to the database

    tests through #500 and #1140, 2nd review done, requires transfer

    {0}

Awaiting Response from Critical Team

  • inopiae

    bug #411 Wrong text is made into link

    {g}



Software/Assessment/20110802-S-A-MiniTOP (last edited 2011-09-23 00:00:28 by UlrichSchroeter)