To Software Software - To Software-Assessment - Software/Assessment - To previous meeting - To next meeting
Minutes of the MiniTOP on the 2011-09-13
Setting
The MiniTOP will be held via telco 22:00 CEST
Attendees: dirk, marcus, uli, michael, magu
Topics
(skip to agenda)
Action items from last meeting Meeting Action Items
Software/Assessment/ActionItems
Marcus
cap.php review different languages, from meeting 2012-04-24, contact translators
uli
Experience points for ATE attendance
check board motions and/or trigger if not yet passed
uli
Infrastructure separation, to contact secure-u (Frank, Mario, Ted, Sebastian) for discussion, prepare a plan, started 2011-12-18
current state: see Funding Landing Page
All
1. next: strategy for "New Roots & Escrow" - using indirect crl's ?
indirect CRL: RFC 5280 http://tools.ietf.org/html/rfc5280 (chapter 5) - test deployment
dirk, Michael
3. next: strategy for "New Roots & Escrow" - how does debian work?
to contact, deferred to next events (?)
Uli, Michael
Documentation Bugs.cacert.org Review, documentation I (bugs handbook) svg files to convert to jpg or png
Development, Deployment, Discussion
dirk Brian
DEV: bug#918 (Part II) (a20110312.1) Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php)
new bug#964
current state: test /account/4.php added to testserver
Marcus will do detailed tests on Wed
some references added to bug#964 done.
proposal patch from Brian rcvd
OAO, Ted
bug #943 change OA admin/assurer text
needs 2nd test -> Fabian, Marc, Alex?
/ needs 2nd review -> Ted, rejected
uli, Ted
bug #824 Org User cert fix Case study
Organisation User Certificates: Need UI improvement for proper production usage
uli
bug #988 TTP cap form deployment Case study
sneak preview
for local testserver deployment only
uli, ted
bug #823 email address removal fix
No warning when removing e-mail address from account that certificates will be revoked
checked by 4, needs 2nd review, deploy
rejected
inopiae
bug #920 Join - single name only (eg Indonesian)
details under bug number
uli
bug #859 admin console interface
feature request: show activity on an account in the admin interface
rejected, certs login doesn't modify "modified" field
All
bug #1034 files to remove from webdb
eg wot/14
Software Assessors: Review 1 / add to cacert-devel, add to testserver
Software-Assessors task
uli
bug #977 admin console text fix
admin console Sysadmin - find domain - lists 2 tables - one for user accounts, one for org accounts, naming issue
Testing
Testers task
gagern
bug #440 Problem with subjectAltName (CSR, renew certs)
There seems to be a problem with the subjectAltName. Dupes, missing entries, and more
neo
bug #922 CAcert application code problem causing missing "certificate about to expire" messages
Ted
bug #835 Assurer challenge (on testserver)
needs testing
Michael
bug #1003 Provide a possibility to regularly review the permissions in the system
also bug #1038 Provide a script for board/tverify reset flags by arbitration a20110118.1
neo
bug #1025 Domain Dispute issue
disputes rc and rc2 var prob
Software Assessors: 2nd Review, Bundle Package to Critical Team
Software-Assessors task
uli, ted
bug #789 OA edit domain fix
Editing domain for organisations does not work
new update 2011-09-26
2 tests, needs 2nd review, deploy
more fixes, more testing6
uli
bug #967 OA isassurer check
Give an OA the opportunity to check if a designated Organisation Administrator is a CAcert assurer
neo
bug #978 Invalid SPKAC requests are not properly validated
recheck full certs signing procedures
duplicate report to bug#540
Michael
p20111113 CPS #7.1.2 "Certificate Extensions" adjustments - testing
uli, marcus: needs full cert create tests
duplicate report to bug#978
neo
bug #1024 Assurer flag is not set correctly on updatesort.php run
tested by 4, ok
dirk
bug #1023 Consolidate changes into the Assure Someone page
6.php global re-design project
assurance, wot area (Thawte points removal effective)
inopiae
New layout of view for Organisation Administrators in account/id35
Software Assessors: Bundle Package to Critical Team
Software-Assessors task
Awaiting Response from Critical Team
Agenda
Software-Assessors blockage - The List of open / running / unhandled bugs - Part I
- request by Joost for variable fields
- next steps:
- preparing PR, support (see below)
- Thawte Patch - PR strategy
- alex to prepare blog post
- if the patch goes active, this needs support
- wiki faq (existing page? thawte topic?)
blog (-> alex)
- mailing list
- press release? probably not at this state
- Support: could be better, but is ok
- Triage: where to forward Thawte patch requests?
- add to Support team meeting agenda
- Thawte Patch - PR strategy
- reviewed last meeting. needs transfer to critical team
- transfer to critical team, done.
- mailing to people: Ted, Florian F, PG, Wytze, Carsten L, Jeff F, Frank K (ask Marcus) 120 pts, Sebastian K, done.
- report by Wytze: problem with Unknown, Trusted Third Parties, Assurances before 2006 (0,0)
- preparing PR, support (see below)
- Michael, Ted - action items last week
- bug 846
- and others in the queue
- bug 846
- PR work
- thawte patch - blog post
- newsletter mailings
- thawte patch details
- infos about thawte points removal
- infos about points counting
- Update ? Text proposal ?
- Security campaign, Newsletters (1 month later, 6-8 weeks later)
- weak passwords (bug 637)
- password reset w/ Assurance replaces pwd reset thru paypal
- cert login security fix (bug 841)
- weak keys disabled (bug 918)
- class3 re-sign with sha256
- check your CAcert account
- create a client cert for client cert login (also needed for CATS)
- check your secret questions
- check your password
- check your notification settings
- check your location settings
- thawte patch details
- Mozilla Communication: Immediate action requested
- Wytze: system upgrade on production and cacert1.it-sls.de (cont. from last meeting)
- proposed next upgrade step lenny to squeeze
- Action item: who informs Wytze?
- Translingo
- the translingo.cacert.org had been in operation far longer, so I think it is possible that some users migrated to translingo.cacert.org, without telling us.
- I would suggest to mass-mail the email addresses of the translation-project leaders in the translingo database, to inform them, and to ask them to speak up if they still need it
- last foreign uploads 2008 on about 13 + cacert projects
- whohas translingo server console access?
- mario
- req for console access for michael to contact project leaders, Updates?
- Transfer In, Transfer Out problems
- Question from Lambert (by email): Is CAcert's ocsp server a blacklist or a whitelist ocsp ? (cont. from last meeting)
- CAcert is probably a blacklist ocsp, cause the server delivers infos derived from current crl's interactively
- Is this for Software-Assessment project group ? Next action step?
- Dirks workqueue - The List of open / running / unhandled bugs
VBscript for Vista/Win7 (select keysize >= 1024) - reminder to dirk
x1 Dirk, new bug#964
DEV: bug#918 (Part II) (a20110312.1) Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEVcurrent state: test /account/4.php added to testserver
Marcus will do detailed tests on Wed
some references added to bug#964
- as part of
x1 Arbitration case a20110312.1 Weak keys bug #918 / bug #954 / bug#964
- Current state:
pre mailing sent
keys revocation script to bulk revoke weak keys, new bug #954, finished
dirk: DEV: a20110312.1 bug#918 Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEV
vbscript needs to be improved with select box key size and lower limit to 2048 (based on https://wiki.mozilla.org/CA:MD5and1024)
Api CertEnroll (MS crypto provider)
new bug#964
current state: test /account/4.php added to testserver
Marcus will do detailed tests on Wed
some references added to bug#964
Weak keys blog post, published
Weak keys article published by Hanno(July 28), link is in CAcert's blog post (July 30)
weak keys: problems with cryptostick (to test at Froscon with Juergen ?)
cert enroll infos under bug#964
vista and win7 works with other engine !CryptoAPI (?) => Cryptography API: Next Generation
http://msdn.microsoft.com/en-us/library/aa833130%28v=VS.85%29.aspx
Marcus: added notes for Win7 https://bugs.cacert.org/view.php?id=964#c2249
- Update (3rd week) ?
- Advertising
Prepare Advertising fix for testserver - reminder to dirk
Dirk
Advertising (from last board meeting), bug #958
add changes as discussed in last meeting to testserver
CAcertInc/LogosForSale/Rules wiki link exist
- "buy me" logo / "Logo For Sale" logo / "Monthly Auction on Logos" logo
- Logos and Links exist, needs deployment to testserver
- Update (3rd week) ?
- google ads, nobody knows about
http://google.de/adsense/ - needs google account
- ad client id: pab.*9860, email adress is needed
- board member to write email request to Robert, Philipp, Philpp, Teus, ernie
- contact google?
- account recovery?
- dirk: google ads account - to write mail to treasurer (address from invoice)
- Update (3rd week) ?
Software-Assessors blockage - Bugs to Review #1, transfer to testserver - Currently 12 (!!!)
uli
bug #977 admin console text fix
admin console Sysadmin - find domain - lists 2 tables - one for user accounts, one for org accounts, naming issue
uli
bug #975 admin console interface (2)
report potential database inconsistency in SE console (debug infos), new update
uli
bug #968 error logging cleanup (splitted bug #909)
split 0000909: too many error messages logged - part II - general.php
uli
bug #967 OA isassurer check
Give an OA the oppertuntiy to check if a desiginated Organisation Admininistrator is a CAcert assurer
uli, Ted
bug #965 0000965: Outsource / fix Webdb text pages id=12, 13
addtl. id=37, id=38, new update
uli, ted
display Assurance when field in list of assurances received, assurances given by a user in admin console interface, new update
uli
bug #859 admin console interface
feature request: show activity on an account in the admin interface, new update
uli
bug #855 admin console interface "unknown" + "empty" assurance method fields, needed for correct testing on testserver
admin console lists "empty" and "Unknown" Assurance types on listing given Assurances
uli
bug #823 email address removal fix
No warning when removing e-mail adres from acount that certificates wil be revoked
uli, ted
visibility over certificates for sysadm in account administration, new update
uli
bug #789 OA edit domain fix
Editing domain for organisations does not work
moh
bug #596 certs list advanced
display ser# in certs overview lists
- 12 open fixes available (week 3), needs 1st review by 1st Software-Assessor
- Bugs under testing: - Currently 4
uli, Michael
bug #966 cancel doesn't cancel but processes instead
potential workaround to fix all "Cancel" requests available
addtl. individual fixes
new update 2011-08-30
at least one more test
uli, Ted
bug #957 Resize the comment field on https://secure.cacert.org/account.php?id=27 so more information is visible
new fix avail 2011-08-19
at least one more test
Dirk
bug #894 problems with check-boxes on website forms (Assure someone) -> a20091118.3
1st review still needed
two testers to test
uli
bug #824 Org User cert fix
Organisation User Certificates: Need UI improvement for proper production usage
needs some more fixes
Software-Assessors blockage - Needs 2nd review + transfer to Critical team, to bundle, to deploy - Currently 4 (!!!)
uli, ted
bug #955 change sort order Orga list
Possibilty to change the sorting order for the organisation overview
uli, ted
bug #940 help* to wiki
Outsource Webdb text pages help.php?id=0..9 to wiki
needs review, deploy
uli, ted
bug #910 Outsource board member list
from Webdb to wiki (id=8) (Part II)
Ted, uli
bug #846 Join Form restructure, help link
Better guidance of bonafide members in Join Form about Suffixes they doesn't have in their ID doxs (a20100207.2)
- Needs development, deployment, discussion
bug #835 Migrate CATS onto testserver
bug #835 Assurer challenge (on testserver)
asssigned to Ted, CATS to install on ca-mgr1, awaiting deployment
bug #943 change OA admin/assurer text
bug #943 change OA admin/assurer text
-> Ted, rejected, needs comment from OAO
webdb names OrgAdmins as OrgAssurers and names OrgAssurers as OrgAdmins.
- patch takes account about this issue
- problem with menu link Org Admin .. is Org Assurers menu
- but this menu includes one addtl. link "View" that is available for Org Admins
- and Org Admins with master flag to add new admins
master flag is not described in OAP
- addtl master flag to revoke ?
- rename to "Org Administration"
don't show menu to OrgAdmins
- but this menu includes one addtl. link "View" that is available for Org Admins
strategy plans ... next: strategy for "New Roots & Escrow"
- idea: using indirect crl's ?
- 2 crl's needed, one valid, one invalid crl server
- more infos available ? who ?
- build testserver with special certs
- Magu, Michael to send instructions for test deployment
indirect CRL: RFC 5280 http://tools.ietf.org/html/rfc5280 (chapter 5)
- meetings ago we've defined Testing requirements and a potential testszenario
- to remind every meeting
- Michael: testserver environment deployment
- policy group: define requirements
- multimember escrow method ?
- needs risk analyze
- potential candidates ?
- Marcus to contacted Benedikt, will contact Thomas K
- Next step(s)
- multimember escrow method ?
- how does debian work ?
- defered to Froscon (end of Aug), CCCcamp (around Aug 10th)
- idea: using indirect crl's ?
- CI (Update)
description to eclipse testpage, Webinar
- deployment scenario:
- create testusers
- testing
- delete testusers
- regression test for standard tests: eg 0,1,49,50,51,99,100,101 pts w/ and w/o CATS passed
- reminder
- deployment scenario:
- Jubula Test-Tool (by Michael) - update?
instructions see under Minutes meeting 2011-08-30
- test deployment needs to be continued by software testers
- next meeting: Tuesday, September 20, 2011 22:00
Minutes
- Marcus: 43.php to add notary.id to bug#882
- dirk tries to upload new 43.php
- dirk: bug#827 update
- translingo: michael tries to deploy pootle
- michael: bug#846 reviewed, made some corrections, needs 2nd review
- PR: Alex not available, will prepare blog post, mailing
- Mozilla Communication: Immediate action requested
- blueprint for activities CAcert has to do on the way to browser inclusion
add https://lists.cacert.org/wws/arc/cacert-board/2011-09/msg00008.html topics as bug numbers
- Wytze: system upgrade on production and cacert1.it-sls.de (cont. from last meeting)
- proposed next upgrade step lenny to squeeze
- Action item: who informs Wytze?
-> Michael
- Testserver hosting: request to Funkfeuer directly ?
funkfeuer.at infos see http://funkfeuer.at/Eckdaten.243.0.html
- Question from Lambert (by email): Is CAcert's ocsp server a blacklist or a whitelist ocsp ? (cont. from last meeting)
- CAcert is probably a blacklist ocsp, cause the server delivers infos derived from current crl's interactively
- Is this for Software-Assessment project group ? Next action step?
- is topic for critical admin
- Jubula Test-Tool (by Michael) - update?
instructions see under Minutes meeting 2011-08-30
- test deployment needs to be continued by software testers
- no update
- bug#855 problem prevents testing of TTP entries
- needs to be activated at least on testserver
- next meeting: Tuesday, September 20, 2011 22:00
Fixed Action Items since last or within meeting
uli
prepare cacert1 image for developers after proposed system update
uli
prepare ca-mgr1 image for developers
uli
prepare DEBIAN-Lenny image for developers (request by Michael) - req cancled
uli
preview mailing to people: Ted, Florian F, PG, Wytze, Carsten L, Jeff F, Frank K (ask Marcus) 120 pts, Sebastian K
- Awaiting Response from Critical Team (moved to next state)
Done: Michael, Dirk, Michael
ToDo:bug #841 Problems on cert login
needs 2nd review, deploy
Done: Dirk, Michael, Michael
ToDo:bug #827 and bug #959 Thawte patch/Points-Count-Order-Change project
related bug 959: needs 1 more test, needs 2nd review / 2nd review: also check -x / tests done, needs 2nd review
959
reviewed, deployed
827
reviewed, deployment in 2 steps
Action Items New
Action items: Meeting Action Items
