Minutes of the MiniTOP on the 2011-08-16

Setting

The MiniTOP will be held via telco 22:00 CEST

Attendees: dirk, magu, uli, alex, Michael

Topics

(skip to agenda)

Action items from last meeting Meeting Action Items

Software/Assessment/ActionItems

  • Marcus

    cap.php review different languages, from meeting 2012-04-24, contact translators

    {+}

    uli

    Experience points for ATE attendance
    check board motions and/or trigger if not yet passed

    {0}

    uli

    Infrastructure separation, to contact secure-u (Frank, Mario, Ted, Sebastian) for discussion, prepare a plan, started 2011-12-18
    current state: see Funding Landing Page

    {0}

    All

    1. next: strategy for "New Roots & Escrow" - using indirect crl's ?
    indirect CRL: RFC 5280 http://tools.ietf.org/html/rfc5280 (chapter 5) - test deployment

    {0}

    dirk, Michael

    3. next: strategy for "New Roots & Escrow" - how does debian work?
    to contact, deferred to next events (?)

    {o}

    Uli, Michael

    Documentation Bugs.cacert.org Review, documentation I (bugs handbook) svg files to convert to jpg or png

    {0}

Development, Deployment, Discussion

  • dirk Brian

    DEV: bug#918 (Part II) (a20110312.1) Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php)

    new bug#964
    current state: test /account/4.php added to testserver
    Marcus will do detailed tests on Wed
    some references added to bug#964 done.
    proposal patch from Brian rcvd

    {0}

    OAO, Ted

    bug #943 change OA admin/assurer text

    needs 2nd test -> Fabian, Marc, Alex? {g} / needs 2nd review -> Ted, rejected

    {-}

    uli, Ted

    bug #824 Org User cert fix Case study

    Organisation User Certificates: Need UI improvement for proper production usage

    {0}

    uli

    bug #988 TTP cap form deployment Case study

    sneak preview
    for local testserver deployment only

    {0}

    uli, ted

    bug #823 email address removal fix

    No warning when removing e-mail address from account that certificates will be revoked
    checked by 4, needs 2nd review, deploy
    rejected

    {-}

    inopiae

    bug #920 Join - single name only (eg Indonesian)

    details under bug number

    {0}

    uli

    bug #859 admin console interface

    feature request: show activity on an account in the admin interface
    rejected, certs login doesn't modify "modified" field

    {r}

    All

    bug #1034 files to remove from webdb

    eg wot/14

    {0}

Software Assessors: Review 1 / add to cacert-devel, add to testserver

  • Software-Assessors task

    uli

    bug #977 admin console text fix

    admin console Sysadmin - find domain - lists 2 tables - one for user accounts, one for org accounts, naming issue

    {0}

Testing

  • Testers task

    gagern

    bug #440 Problem with subjectAltName (CSR, renew certs)

    There seems to be a problem with the subjectAltName. Dupes, missing entries, and more

    {0}

    neo

    bug #922 CAcert application code problem causing missing "certificate about to expire" messages

    {0}

    Ted

    bug #835 Assurer challenge (on testserver)

    needs testing

    {0}

    Michael

    bug #1003 Provide a possibility to regularly review the permissions in the system

    also bug #1038 Provide a script for board/tverify reset flags by arbitration a20110118.1

    {0}

    neo

    bug #1025 Domain Dispute issue

    disputes rc and rc2 var prob

    {0}

Software Assessors: 2nd Review, Bundle Package to Critical Team

  • Software-Assessors task

    uli, ted

    bug #789 OA edit domain fix

    Editing domain for organisations does not work
    new update 2011-09-26
    2 tests, needs 2nd review, deploy
    more fixes, more testing

    6 {0}

    uli

    bug #967 OA isassurer check

    Give an OA the opportunity to check if a designated Organisation Administrator is a CAcert assurer

    {0}

    neo

    bug #978 Invalid SPKAC requests are not properly validated

    recheck full certs signing procedures
    duplicate report to bug#540

    {0}

    Michael

    bug #540

    p20111113 CPS #7.1.2 "Certificate Extensions" adjustments - testing
    uli, marcus: needs full cert create tests
    duplicate report to bug#978

    {0}

    neo

    bug #1024 Assurer flag is not set correctly on updatesort.php run

    tested by 4, ok

    {0}

    dirk

    bug #1023 Consolidate changes into the Assure Someone page

    6.php global re-design project
    assurance, wot area (Thawte points removal effective)

    {0}

    inopiae

    bug #981 OA overview (dupe of bug #943)

    New layout of view for Organisation Administrators in account/id35

    {0}

Software Assessors: Bundle Package to Critical Team

  • Software-Assessors task

Awaiting Response from Critical Team


Agenda

  1. Workshop - The List of open / running / unhandled bugs - Part I
    1. Working Session - Action Items to start
      1. x4 bug #841 Problems on cert login

        • needs 2nd review - Ted, done
          needs bundling, done

        • NEO: did restructuring (sql query to subroutine), (Update 2011-07-26), re-tested, reviewed
        • needs bundling
      2. annoying gpg bug #911
        • bug #911 gpg bug

          gpg keys expires 1970
          tests started 2 weeks ago
          needs review, deploy

          {0}

    2. VBscript for Vista/Win7 (select keysize >= 1024)

  2. Needs development, deployment, discussion
    1. Advertising
        • bug #958

          ADS Challenge, Advertising

          {0}

        • CAcertInc/LogosForSale/Rules wiki link exist

        • "buy me" logo / "Logo For Sale" logo / "Monthly Auction on Logos" logo
        • Logos and Links exist, needs deployment to testserver
      1. google ads, nobody knows about
        • http://google.de/adsense/ - needs google account

          • ad client id: pab.*9860, email adress is needed
          • board member to write email request to Robert, Philipp, Philpp, Teus, ernie
          • contact google?
          • account recovery?
  3. Thawte Patch - PR strategy
    1. x2 Bug# 827 and bug #959 "Thawte" patch - Points-Count-Order-Change project - 2nd Review + deploy

      • bug #959 deployed

      • bug #827 awaiting response from critical team

      • next steps:
        1. preparing PR, support
        2. report from Wytze, Hans: review, rebundle
      • if the patch goes active, this needs support
        • wiki faq (existing page? thawte topic?)
        • blog (-> alex)

          • mailing list
          • press release? probably not at this state
        • Support: could be better, but is ok
          • Triage: where to forward Thawte patch requests?
          • add to Support team meeting agenda
  4. PRO
    • question from board -> PR officer

    • request to Alex
    • support from all
    • Board meeting was 2011-08-07, but no PR officer nominated/appointed
  5. Workshop - The List of open / running / unhandled bugs - Part II
    1. Dirk reminder (from last meeting) assure someone patches (checkboxes)

      • Dirk

        DEV: bug #894 problems with check-boxes on website forms (Assure someone) -> a20091118.3

        {0}

    2. Bugs under testing:
    3. Review bugs under testing (finished testing?) (Review 2?)
      • bug #910 Outsource board member list

        from Webdb to wiki (id=8) (Part II)

        {0}

        bug #955 change sort order Orga list

        Possibilty to change the sorting order for the organisation overview

        {0}

    4. (review), to bundle, to deploy
      • bug #940 help* to wiki

        Outsource Webdb text pages help.php?id=0..9 to wiki
        needs review, deploy

        {0}

    5. Needs review, transfer to Critical team
      1. x4 bug #841 Problems on cert login

        • needs 2nd review - Ted, done
          needs bundling, done

        • NEO: did restructuring (sql query to subroutine), (Update 2011-07-26)
        • needs re-tested
        • needs 2nd review, bundling
          • => Ted on Wed, not done

        x4 NEO: bug #841 Problems on cert login

        needs 2nd review - Ted, done
        needs bundled
        NEO will check to get sql query extracted
        needs pushing
        pushed to testserver
        Needs Review & testing

        {0}

    6. Needs development, deployment, discussion
      1. bug #835 Assurer challenge (on testserver)

        bug #835 Assurer challenge (on testserver)

        asssigned to Ted, set to needs work, CATS to install on ca-mgr1

        {0}

      2. bug #943 change OA admin/assurer text

        • bug #943 change OA admin/assurer text

          -> Ted, rejected, needs comment from OAO

          {-}

        • webdb names OrgAdmins as OrgAssurers and names OrgAssurers as OrgAdmins.

        • patch takes account about this issue
        • problem with menu link Org Admin .. is Org Assurers menu
          • but this menu includes one addtl. link "View" that is available for Org Admins
            • and Org Admins with master flag to add new admins
          • master flag is not described in OAP (!)

          • addtl master flag to revoke ?
          • rename to "Org Administration"
          • don't show menu to OrgAdmins

      3. bug #966

        • tests ok, but the question is, is OrgAdmin allowed to remove other admins ? yes or no?

        • current scenario doesn't allow removal of other admin
        • NEO: reset testserver state to fix state before bugfix
        • NEO: re-add bug 966 to testserver
        • bug needs more work, selection currently clashes with language setting (Delete != Löschen)
        • general problem in /pages/account.php with process variable, transfer of "cancel" pushes any action
        • potential workaround to fix all "Cancel" requests available
    7. Still awaiting response from Critical team
      • x2 bug #827 "Thawte" patch (still running)
        related bug #959

        needs 1 more test, needs 2nd review
        2nd review: also check -x
        tests done, 2nd review outstanding

        {0}
        {g}

      • x2 Bug# 827 and bug #959 "Thawte" patch - Points-Count-Order-Change project - 2nd Review + deploy

      • todo:
        1. NEO: 2nd review of Bug# 827

        2. NEO: bundling Bug# 827 and bug #959 to critical team

      • bug #959 deployed

      • 2nd review and bundling by Ted
        • bundling instruction to critical team, deploy 15.php, and 7 days later 10.php
      • awaiting response from critical team
  6. strategy plans ... next: strategy for "New Roots & Escrow"

    1. idea: using indirect crl's ?
      • 2 crl's needed, one valid, one invalid crl server
      • more infos available ? who ?
        1. build testserver with special certs
        2. Magu, Michael to send instructions for test deployment
      • meetings ago we've defined Testing requirements and a potential testszenario
      • to remind every meeting
    2. policy group: define requirements
      • multimember escrow method ?
        • needs risk analyze
        • potential candidates ?
          • Marcus to contacted Benedikt, will contact Thomas K
          • Next step(s)
    3. how does debian work ?
      • defered to Froscon (end of Aug), CCCcamp (around Aug 10th)
    4. The Bjoern report
  7. CI (Update)
    • description to eclipse testpage, Webinar

    • deployment scenario:
      1. create testusers
      2. testing
      3. delete testusers
    • regression test for standard tests: eg 0,1,49,50,51,99,100,101 pts w/ and w/o CATS passed
    • reminder
  8. next meeting: Tuesday, August 23, 2011 22:00

Minutes

  1. Froscon planning
  2. PRO
    • question from board -> PR officer

    • request to Alex
    • support from all
    • Board meeting was 2011-08-07, but no PR officer nominated/appointed
    • Uli to write nomination to board mailing list cc alex
  3. Thawte Patch - PR strategy
    1. x2 Bug# 827 and bug #959 "Thawte" patch - Points-Count-Order-Change project - 2nd Review + deploy

      • bug #959 deployed

      • bug #827 awaiting response from critical team

      • next steps:
        1. preparing PR, support
        2. report from Wytze, Hans: review, rebundle
      • if the patch goes active, this needs support
        • wiki faq (existing page? thawte topic?)
        • blog (-> alex)

          • mailing list
          • press release? probably not at this state
        • Support: could be better, but is ok
          • Triage: where to forward Thawte patch requests?
          • add to Support team meeting agenda
      • patch review
      • 10.php / 15.php ranking differs
        • 15.php experience points links to assurer account
      • alex to prepare blog post
  4. language translations - rethink to disable?
  5. Working sesson
    1. bug 827 - needs fix -> dirk (./)

    2. bug 841 - needs 2nd review -> dirk +

    3. bug 911 - needs 2nd review -> dirk +

    4. bug 966 - new fix -> Michael (./)

  6. use dev mailinglist for communication

Fixed Action Items since last or within meeting


Action Items New

  1. PRO
    • Uli to write nomination to board mailing list cc alex
  2. thawte patch 827
    • alex to prepare blog post
  3. use dev mailinglist for communication

Action items: Meeting Action Items


Software/Assessment/20110816-S-A-MiniTOP (last edited 2011-09-22 23:58:57 by UlrichSchroeter)