Minutes of the MiniTOP on the 2011-12-20

Setting

The MiniTOP will be held via telco 22:00 CET

Attendees: Magu, Marcus, Michael, uli, dirk, alex

Topics

(skip to agenda)

Action items from last meeting Meeting Action Items

Agenda

1. bug#794 Display certs in admin console

2. bug #827 - New Points calculation / Thawte patch

3. Patches queue

  1. Translingo bug #985

    • https://translations.cacert.org (http://translations.cacert.org/) (replacement for translingo)

    • the translingo.cacert.org had been in operation far longer, so I think it is possible that some users migrated to translingo.cacert.org, without telling us.
    • I would suggest to mass-mail the email addresses of the translation-project leaders in the translingo database, to inform them, and to ask them to speak up if they still need it
    • last foreign uploads 2008 on about 13 + cacert projects
    • whohas translingo server console access?
      • mario
    • req for console access for michael to contact project leaders, Updates?
    • Transfer In, Transfer Out problems
    • Update from new deployment ?
    • opened for: create an account can now be started
    • Michael current state:
      • import and export routine works
      • script to incorporate updates needs fixed
    • next: complete language handling needs to be updated
    • accept lang handler needs fix
      • FF de, de_de
      • IE 6 de, 8,9 de_de
    • working session within last meeting: michael, marcus
      • infos from meeting 2011-10-18
        • pdf code needs rewrite (uni code library, move to external server (outsourcing))
        • message cert notification - uses perl code, text source not avail (get bind-text-domain)
    • current state?
    • Marcus sent mailing to translators, no response so far, no tests so far (week 3)
      • Morten NO
      • Emanuel IT
    • current state:
      • create test system accounts dutch@test, espania@test and so on, let users do their tests
      • Magu, Marcus will give it a try
      • a couple of testers has started testing and reporting within the last 7 days
      • results: de, fr, en, pl, es, pl
    • last meeting: working session bug#985 translingo transfer

      • Michael: needs 2nd review
    • needs 2nd review by dirk or ted

  2. bug#540 No key usage attribute in cacert org certs anymore?

    • also: bug#905

    • Policy group discussion - Extended key usage -> p20111113, motion CARRIED

    • deployment
      1. prepare fixes -> Michael to prepare diffs, against svn

      2. sending to testserver
      3. transfer to critical system
    • (2011-12-13) approx 2 weeks to write the fix, approx 2 months to go
  3. Marcus: working session bug#789 OA field extension

    • magu to test
  4. Marcus: working session bug#859 Activity on Account

    • Michael: needs 1st review + transfer to testserver
  5. bug #920 Join - single name only (eg Indonesian)

    • details under bug number
    • presented to Policy Group
    • first results from policy group?

4. Michaels workqueue

  1. OCSP server - timeout 10 min too short, 3 days to long, recommendation is 24-48 hours max, verisign: 7 days, startssl: 2d
  2. Build + Document Emergency Patches Path
  3. New function to TMS - edit notary table record
    • bug #980

    • infos from last meeting
    • testers needs editing individual notary records: fields "method", "awarded", "points"
    • easier to create notary records with testserver (add F2F), and edit existing record, doesn't need to check for assurer-from, assuree-to and so on
    • Update?
    • Michael (2011-11-15): after some other bug reviews

5. Dirks workqueue - The List of open / running / unhandled bugs

  1. VBscript for Vista/Win7 (select keysize >= 1024) - reminder to dirk

    • x1 Dirk, new bug#964
      DEV: bug#918 (Part II) (a20110312.1) Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEV

      current state: test /account/4.php added to testserver
      Marcus will do detailed tests on Wed
      some references added to bug#964

      {0}

    • as part of
    • x1 Arbitration case a20110312.1 Weak keys bug #918 / bug #954 / bug#964

    • Current state:
      • {g}

        pre mailing sent

        {g}

        keys revocation script to bulk revoke weak keys, new bug #954, finished

        {-}

        dirk: DEV: a20110312.1 bug#918 Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEV
        vbscript needs to be improved with select box key size and lower limit to 2048 (based on https://wiki.mozilla.org/CA:MD5and1024)
        Api CertEnroll (MS crypto provider)
        new bug#964
        current state: test /account/4.php added to testserver
        Marcus will do detailed tests on Wed
        some references added to bug#964 - codename "BlackJack"

        {g}

        Weak keys blog post, published

        {g}

        Weak keys article published by Hanno(July 28), link is in CAcert's blog post (July 30)

        {b}

        weak keys: problems with cryptostick (to test at Froscon with Juergen ?)

    • cert enroll infos under bug#964

    • vista and win7 works with other engine !CryptoAPI (?) => Cryptography API: Next Generation

    • dirk: has not started the virtual machine
    • Question from Marcus: did someone contacted illuminat?
      • No, Marcus: to contact illuminat
      • illuminat will give it a try, first needs download of testserver image
    • Update?
      • marcus: illuminat not yet seen last time
      • baseline requirement - keyssize >= 2048 to fix till end of 2011

      • how to proceed?
      • dirk: 1st step, to bring win test server localy online
      • marcus: to contact illuminat
      • Do we have other developers who may pick up this project?
    • Marcus -> dirk: announcement of vbscript bug to developers mailing list

      • change keysize
      • merge 2 scripts to one
      • fix on script 1 needs fix in 2nd script too, solutions: include, one file, or comment fix script 2 too
    • interrupt: bug#964 -> codename "BlackJack"

      • relates to IE8 problem, that certs cannot be created
      • is there a security issue with available fix? also bug#918

      • related 927, 901, 847
      • a patch is online on testserver, but cannot found
      • related patch files, /pages/account/ 3,4,16,17; /include/account.php
      • there are other vbscript pages: ../account/ 6 + 19

6. General Bugs List Overview

  1. Bugs to Review #1, transfer to testserver - Currently 4

    • uli

      bug #977 admin console text fix

      admin console Sysadmin - find domain - lists 2 tables - one for user accounts, one for org accounts, naming issue

      {0}

      uli

      bug #967 OA isassurer check

      Give an OA the oppertuntiy to check if a desiginated Organisation Admininistrator is a CAcert assurer

      {0}

      uli

      bug #859 admin console interface

      feature request: show activity on an account in the admin interface, new update /!\

      {0}

      inopiae

      bug #981 OA overview (dupe of bug #943)

      New layout of view for Organisation Administraors in account/id35

      {0}

      Brian

      new bug#964
      DEV: bug#918 (Part II) (a20110312.1) Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEV

      some references added to bug#964
      current state: first review, add to testserver

      {0}

  2. Bugs under testing: - Currently 3

    • uli

      bug #855 admin console interface "unknown" + "empty" assurance method fields, needed for correct testing on testserver

      admin console lists "empty" and "Unknown" assurance types on listing given Assurances

      {0}

      Michael

      bug #978 bug 978 (weak keys) (bug 918)

      invalid key format, no regular error message, something wrong, error code # identified
      debugging infos from user + infos from critical team with error code #
      was spkac routine

      {0}

  3. Needs 2nd review + transfer to Critical team, to bundle, to deploy - Currently 4

    • define priority eg. 10,2, and so on, proposed order: from 1 to 10

      8

      Ted, uli

      bug #957 Resize the comment field on https://secure.cacert.org/account.php?id=27 so more information is visible

      last update 2011-08-19
      tested 3 times
      ready to deploy?

      {0}

      ? / u8 / m8

      1

      uli, michael

      bug#794 display certs in admin console

      last update 2011-12-06
      tested by 2
      2nd review + transfer

      {0}

      1

      7

      uli, ted

      bug #789 OA edit domain fix

      Editing domain for organisations does not work
      new update 2011-09-26
      more fixes, more testing
      * testcase scenario
      * open org, edit 1st domain in new window, edit 2nd domain in new window
      * results in: change made in window 2, written to record in window 2
      * needs cross checking

      {0}

      ? / u7 / m7

      2

      neo

      bug #985 move translingo to translations

      check language settings under testserver

      {0}

      2

  4. Needs development, deployment, discussion, reminder
    1. bug #835 Migrate CATS onto testserver

      • bug #835 Assurer challenge (on testserver)

        asssigned to Ted, CATS to install on ca-mgr1, awaiting deployment

        {0}

7. Long term projects

  1. strategy plans ... next: strategy for "New Roots & Escrow"

    1. idea: using indirect crl's ?
      • 2 crl's needed, one valid, one invalid crl server
      • more infos available ? who ?
        1. build testserver with special certs
        2. Magu, Michael to send instructions for test deployment
      • meetings ago we've defined Testing requirements and a potential testszenario
      • to remind every meeting
      • Michael: testserver environment deployment
      • Michael will review after Certs extension policy group vote
    2. policy group: define requirements
      • multimember escrow method ?
        • needs risk analyze
        • potential candidates ?
          • Marcus to contacted Benedikt, will contact Thomas K
          • Next step(s)
  2. CI (Update)
    1. description to eclipse testpage, Webinar

      • deployment scenario:
        1. create testusers
        2. testing
        3. delete testusers
      • regression test for standard tests: eg 0,1,49,50,51,99,100,101 pts w/ and w/o CATS passed
      • reminder
    2. Jubula Test-Tool (by Michael) - update?
    3. new proposal by Sven: Webdriver with Maven and Jenkins-CI
      1. Jubula vs. Webdriver
      2. testserver variants
        1. testserver for manual tests
        2. testserver of OS and application upgrades
        3. testserver for CI
      3. test methods
        1. unit test
          • test single modules, exceptions
        2. integration tests
          • test interaction of modules
        3. system tests
          • complete system test, with database interactions, module interactions and much more
      4. sven did some work regarding frontendtest (Webdriver with Maven and Jenkins-CI)
        • Michael did some review: probably needs some seperation
  3. Infrastructure seperation
    1. CAcert Inc statement - received
    2. Hosting/Housing Provider
      • 2011-12-01: Vienna response
      • questions answered
    3. contacting secure-u, oophaga started?
      • Frank, Mario, Ted, Uli, Sebastian ?
      • started 2011-12-19, awaiting response
    4. Hardware
      • alternate solutions
  4. Helping CAcert
    • How does recruitment work?
    • Newsletters, recuring notifications
    • Fosdem -> focus on Nucleus events

    • Recruitment on events?
    • Recruitment page eg events/Recruitment, HelpingCAcert, Jobs

    • Flyers?
    • re-design main page:
      • dirk: 3 news, upcoming events
      • michael: *
      • rss-feed script modification is simple
      • main page cms page, login to secure area
        • public: www.cacert.org
          • secure1: www.cacert.org
          • secure2: secure.cacert.org
  5. Discovery II a20110118.1 discussion

    • who should receive infos? list of appropiate recipients listed in discovery II table
    • possible software solutions:
      1. triggered info mailing eg board-private mailing list + support
      2. view page with current results (like hidden stats page?)
    • create bug# ?

8. next meeting

Minutes

  1. bug#794 Display certs in admin console ===
    • bug#794 display certs in admin console

    • request from SE: iCM's to transfer disputes from disputes queue to arbitration queue
    • if 2 weeks open 2nd review on bug #794 will be transfered to critical, all delete account cases (approx 40) can be moved to SE queue for review and working under precedent
  2. request move forward regarding shirts project
    • discussion:
      1. CAcert Inc's task
      2. risk regarding total account
      3. shirts are expensive, 25-30 Euro + shipping costs
      4. risk can be minimalized by planned income projects
        1. (new portal) (Benedikt, Karsten working on it)
        2. affilates program
  3. VBscript for Vista/Win7 (select keysize >= 1024)

    • x1 Dirk, new bug#964
      DEV: bug#918 (Part II) (a20110312.1) Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEV

      current state: test /account/4.php added to testserver
      Marcus will do detailed tests on Wed
      some references added to bug#964

      {0}

    • code from Brian needs some corrections, corrections to do, 4 + 17 inclusions, checkin
    • notification to Brian
  4. Translingo bug #985

  5. bug#540 No key usage attribute in cacert org certs anymore?

    • also: bug#905

    • Policy group discussion - Extended key usage -> p20111113, motion CARRIED

    • deployment
      1. prepare fixes -> Michael to prepare diffs, against svn

      2. sending to testserver
      3. transfer to critical system
    • (2011-12-13) approx 2 weeks to write the fix, approx 2 months to go
    • Michael will work on this in last week this year
  6. next meeting ?
    • Tuesday, December 27, 2011 22:00
    • trying 27th
  7. bug #920 Join - single name only (eg Indonesian)

    • details under bug number
    • presented to Policy Group
    • first results from policy group?
    • dirk has made some changes in 6.php last year
    • there are 4 possible choices:
      1. givenname
      2. lastname (as current fix)
      3. givenname or lastname
      4. brians proposal, mononym + checkbox
    • dirks proposal:
      • make name handling more AP conform (1 line names, multiple names)
    • 2 possible paths:
      1. allow multiple names (dirks proposal) is massive change (long term change)
      2. "simple" solution (short term change)
    • discussion about CAP form a) current form b) teus form
      • contract between member and CAcert Inc
    • critical / non-critical systems
      • non-critical portal - with login link to critical secure.cacert.org
      • cms system: own user base?
        • critical system userid includes @, cms userid does not include @
        • cms login adding userid from critical system may result in security leak that account data can be collected (MITM)
    • tasks of CAcert Inc
      • running the critical systems
      • running cacert.org
      • be the juristical contact partner on behalf of CAcert Community
    • transfer task of non-critical, country related services to community
  8. Translations
    • problems that relates to blocks translations
    • changes into translations database
    • contact NEO to transfer manualy to testserver
    • bug #985 needs 2nd review, so update script can run also on critical system

  9. Events Manchester, Blacksburg, Stockholm
  10. affiliate link to each event (template)
    1. addtl. link under main ads ?
    2. right near paypal links?
  11. VBscript for Vista/Win7 (select keysize >= 1024)

    • Brian bug#964

    • Michael: Marcus to test with IE
      • IE select provider only
  12. Xing entry as company CAcert Inc
    • defines clerks
    • companys aren't associations

Fixed Action Items since last or within meeting


Action Items New

Action items: Meeting Action Items

Software/Assessment/ActionItems

Development, Deployment, Discussion

  • OAO, Ted

    bug #943 change OA admin/assurer text

    needs 2nd test -> Fabian, Marc, Alex? {g} / needs 2nd review -> Ted, rejected

    {-}

    uli, Ted

    bug #824 Org User cert fix Case study

    Organisation User Certificates: Need UI improvement for proper production usage

    {0}

    uli, ted

    bug #823 email address removal fix

    No warning when removing e-mail address from account that certificates will be revoked
    checked by 4, needs 2nd review, deploy
    rejected

    {-}

    inopiae

    bug #920 Join - single name only (eg Indonesian)

    details under bug number

    {0}

    uli

    bug #859 admin console interface

    feature request: show activity on an account in the admin interface
    rejected, certs login doesn't modify "modified" field

    {r}

    Michael

    bug #540

    p20111113 CPS #7.1.2 "Certificate Extensions" adjustments - testing
    uli, marcus: needs full cert create tests
    duplicate report to bug#978
    tested by 3, 2nd review done, transfered
    Ken reported: still has problems, bug kept open

    {0}

    gagern, NEO

    bug #440 Problem with subjectAltName (CSR, renew certs)

    There seems to be a problem with the subjectAltName. Dupes, missing entries, and more, rejected, needs further development

    {r}

    neo

    bug #1025 Domain Dispute issue

    disputes rc and rc2 var prob
    needs work

    {r}

    dirk

    bug #1054 0001054: Review the code regarding the new point calculation

    Thawte patch part II
    needs further work

    {r}

Software Assessors: Review 1 / add to cacert-devel, add to testserver

  • Software-Assessors task

Testing

  • Testers task

    neo

    bug #1004 Stats page improvement

    tested by 2, needs 2nd review

    {0}

    neo

    Bugs #1159 it might be possible to execute commands on the signing server

    {0}

    inopiae

    bug #1065 Wrong wording when sending mails during the assurance process

    {0}

    inopiae

    bug #1162 calcutate (the passwords) hash in php instead of in mysql

    create test scenarios for the software testers /!\
    Full testing /!\

    {0}

    inopiae

    bug #0028 Wrong language for you've been assured & [CAcert.org] Client Certificate emails

    {0}

    inopiae

    bug #988 TTP cap form deployment

    {0}

Software Assessors: 2nd Review, Bundle Package to Critical Team

  • Software-Assessors task

    Ted

    bug #500 Get contact mail adress after resolving test

    tested by 3, requires review

    {0}

    Ted

    bug #1140 Show if a test is passed in learnprogress

    tested by 3, requires review

    {0}

    magu

    bug #1131 Rename _all_ Policies from .php to .html and fix all links

    global policy directory maintenance and update

    {0}

    inopiae

    bug #1010 Reorder the view on organisation certificates

    tested by 3

    {0}

Software Assessors: Bundle Package to Critical Team

  • Software-Assessors task

    inopiae

    bug #1139 Add new fields to the database

    tests through #500 and #1140, 2nd review done, requires transfer

    {0}

Awaiting Response from Critical Team

  • inopiae

    bug #411 Wrong text is made into link

    {g}



Software/Assessment/20111220-S-A-MiniTOP (last edited 2011-12-27 13:33:21 by UlrichSchroeter)