fesco
LOGS
<@zbyszek:fedora.im>
17:01:13
!startmeeting
<@meetbot:fedora.im>
17:01:13
Meeting started at 2024-06-25 17:01:13 UTC
<@meetbot:fedora.im>
17:01:14
The Meeting name is 'Fedora Meeting'
<@zbyszek:fedora.im>
17:01:17
!meetingname fesco
<@meetbot:fedora.im>
17:01:18
The Meeting Name is now fesco
<@zbyszek:fedora.im>
17:01:26
Chairs: @conan_kudo:matrix.org, @ngompa:fedora.im, @nirik:matrix.scrye.com, @humaton:fedora.im, @zbyszek:fedora.im, @sgallagh:fedora.im, @jistone:fedora.im, @dcantrell:fedora.im, @decathorpe:fedora.im, @salimma:fedora.im
<@humaton:fedora.im>
17:01:33
!hi
<@zbyszek:fedora.im>
17:01:33
!topic Init Process
<@zodbot:fedora.im>
17:01:34
Tomáš Hrčka (humaton) - he / him / his
<@zbyszek:fedora.im>
17:01:35
!hi
<@zodbot:fedora.im>
17:01:36
Zbigniew Jędrzejewski-Szmek (zbyszek)
<@jistone:fedora.im>
17:01:36
!hi
<@zodbot:fedora.im>
17:01:38
Josh Stone (jistone) - he / him / his
<@nirik:matrix.scrye.com>
17:01:43
morning
<@decathorpe:fedora.im>
17:01:52
!hi
<@zodbot:fedora.im>
17:01:53
Fabio Valentini (decathorpe) - he / him / his
<@sgallagh:fedora.im>
17:02:16
!hi
<@zodbot:fedora.im>
17:02:17
Stephen Gallagher (sgallagh) - he / him / his
<@salimma:fedora.im>
17:02:52
!hi
<@zodbot:fedora.im>
17:02:53
Michel Lind (salimma) - he / him / his
<@zbyszek:fedora.im>
17:03:23
Let's wait a sec more for Neal, since he voted negatively in the ticket.
<@dcantrell:fedora.im>
17:03:31
!hi
<@zodbot:fedora.im>
17:03:33
David Cantrell (dcantrell) - he / him / his
<@zbyszek:fedora.im>
17:03:45
What are some dns domains that use sha-1? I need an example for testing…
<@salimma:fedora.im>
17:04:12
summoning Conan Kudo
<@dbelyavs:fedora.im>
17:04:18
ask Petr Mensik.
<@dbelyavs:fedora.im>
17:04:31
Unfortunately people still follow bad practice
<@dbelyavs:fedora.im>
17:04:39
Probably .vn
<@simo:fedora.im>
17:04:43
is this the right topic ?
<@sgallagh:fedora.im>
17:04:57
The topic hasn't formally begun yet
<@simo:fedora.im>
17:05:18
* Meet Bot The Meeting Topic is now Init Process <- above
<@dbelyavs:fedora.im>
17:05:24
zbyszek: https://mailarchive.ietf.org/arch/msg/dnsop/HFg5PHXmCJ7Psz2jWmjyVRJmEWI/
<@zbyszek:fedora.im>
17:06:11
!topic #3229 Change: Make OpenSSL distrust SHA-1 signatures by default
<@zbyszek:fedora.im>
17:06:18
!info ttps://mailarchive.ietf.org/arch/msg/dnsop/HFg5PHXmCJ7Psz2jWmjyVRJmEWI/
<@zbyszek:fedora.im>
17:06:32
!info https://mailarchive.ietf.org/arch/msg/dnsop/HFg5PHXmCJ7Psz2jWmjyVRJmEWI/
<@decathorpe:fedora.im>
17:07:16
lol @ Apple
<@zbyszek:fedora.im>
17:07:37
I didn't do my homework for this one…
<@nirik:matrix.scrye.com>
17:07:42
FWIW, I am +1 to this change...
<@sgallagh:fedora.im>
17:08:12
So, just catch me up: is the ONLY reason we're considering not disabling SHA-1 because of these few DNSSEC domains?
<@simo:fedora.im>
17:08:30
yes
<@simo:fedora.im>
17:08:36
and it is not a good reason
<@jistone:fedora.im>
17:08:47
can you add an info for the Change issue?
<@sgallagh:fedora.im>
17:08:55
simo: I tend to agree. I just want to make sure there aren't other reasons I missed in the discussion somewhere
<@nirik:matrix.scrye.com>
17:09:09
!fesco 3229
<@zodbot:fedora.im>
17:09:10
● **Assignee:** asosedkin
<@zodbot:fedora.im>
17:09:10
● **Last Updated:** 16 minutes ago
<@zodbot:fedora.im>
17:09:10
● **Opened:** 4 days ago by amoloney
<@zodbot:fedora.im>
17:09:10
<@zodbot:fedora.im>
17:09:10
**fesco #3229** (https://pagure.io/fesco/issue/3229):**Change: Make OpenSSL distrust SHA-1 signatures by default**
<@simo:fedora.im>
17:09:13
besides dns tools could technically re-enable sha-1 on their own, if *really* needed
<@zodbot:fedora.im>
17:09:19
jistone gave a cookie to kevin. They now have 680 cookies, 21 of which were obtained in the Fedora 40 release cycle
<@decathorpe:fedora.im>
17:09:26
at this point I think no other important SHA1 users are left ... even the Google chrome RPM is now signed with non-sha1 too :O
<@salimma:fedora.im>
17:09:47
there's an unanswered question of when runcp will be packaged - it's now in COPR
<@zbyszek:fedora.im>
17:10:05
Does anyone know what runcp does under the hood?
<@simo:fedora.im>
17:10:16
we really MUST stop accepting signatures that use SHA-1 it is a liability, it takes not too much money to break them now, certainly nations tate actors can, but also some rich crooks
<@salimma:fedora.im>
17:10:19
the change owners should know, right?
<@nirik:matrix.scrye.com>
17:10:26
? a z80 simulator?
<@jistone:fedora.im>
17:11:05
that's runcpm
<@simo:fedora.im>
17:11:12
I do not think runcp is a required dependency for this change, it is only a nice to have
<@dbelyavs:fedora.im>
17:11:25
I think it provides an alternate OpenSSL configuration for this and only this run of a particular application
<@simo:fedora.im>
17:11:29
runCP/M you mean?
<@salimma:fedora.im>
17:11:41
nirik: it's mentioned in the change proposal - you can use it to run a single process under a different crypto policy
<@sgallagh:fedora.im>
17:12:01
Proposal: Accept the Change and disallow SHA-1 by default. Mitigations exist for individual applications to re-enable it if absolutely necessary.
<@zbyszek:fedora.im>
17:12:12
Yeah, but the problem in the past was that openssl wouldn't allow per-application configuration. So runcp provides that, but it sounds like it does in some strange fashion.
<@nirik:matrix.scrye.com>
17:12:37
ah, I remember now... right
<@dbelyavs:fedora.im>
17:12:42
It does. OPENSSL_CONF env variable still works :)
<@simo:fedora.im>
17:12:57
zbyszek: it absically created an overlay container that changes cryptopolicies only for that app, and leaves all other namespaces sane
<@nirik:matrix.scrye.com>
17:13:01
Stephen Gallagher +1
<@jistone:fedora.im>
17:13:06
+1
<@zbyszek:fedora.im>
17:13:14
Oh, bleh.
<@salimma:fedora.im>
17:13:19
all recent builds of runcp have failed which is... not reassuring - https://copr.fedorainfracloud.org/coprs/asosedkin/crypto-policies-extras/package/crypto-policies-extras/
<@hkario:fedora.im>
17:13:40
I fail to see how that's relevant: we're fine with exposing _all_ fedora users to SHA-1 attacks only because the few that need it can't be bothered to switch to LEGACY policy or would like ability to run one or two applications with specific policy??
<@decathorpe:fedora.im>
17:13:57
Stephen Gallagher: +1
<@simo:fedora.im>
17:14:03
Michel Lind 🎩: as mentioned above it is only a nice-ti-have not a hard require
<@zbyszek:fedora.im>
17:14:08
Stephen Gallagher: +1
<@hkario:fedora.im>
17:14:45
also latest build of it failed only on one arch: ppc64le
<@salimma:fedora.im>
17:14:48
fair. on further consideration given the small impact I think it's fine to change the default. but... just pointing out runcp as is _does not actually work_ even with the COPR
<@salimma:fedora.im>
17:14:57
ah... only ppc. fun
<@sgallagh:fedora.im>
17:15:02
I'm perfectly happy with disabling access to systems/software that are unwilling to follow good security practices.
<@salimma:fedora.im>
17:15:51
oh it only fails for ppc64le only for c10s. I don't think we need to worry about that
<@zbyszek:fedora.im>
17:16:35
Tally so far: Neal -1, Stephen,Fabio,me,Kevin +1
<@zbyszek:fedora.im>
17:16:45
Josh +1
<@salimma:fedora.im>
17:16:49
+1 from me
<@dcantrell:fedora.im>
17:16:50
+1
<@salimma:fedora.im>
17:17:16
knowing runcp uses an overlay container, I think I'm fine keeping it in COPR :P
<@zbyszek:fedora.im>
17:17:39
Element puts so much vertical whitespace that doing a tally requires scrolling up two screens.
<@salimma:fedora.im>
17:17:54
switch it to IRC mode :)
<@simo:fedora.im>
17:18:04
(use the IRC like appearance and smaller font :p)
<@nirik:matrix.scrye.com>
17:18:15
nehko does a bit better
<@nirik:matrix.scrye.com>
17:18:47
fractal does a lot worse. ;)
<@zbyszek:fedora.im>
17:18:49
!agreed APPROVED: Accept the Change and disallow SHA-1 by default. Mitigations exist for individual applications to re-enable it if absolutely necessary (+7, 0, -1)
<@zbyszek:fedora.im>
17:19:26
!fesco 3229
<@zodbot:fedora.im>
17:19:27
<@zodbot:fedora.im>
17:19:27
**fesco #3229** (https://pagure.io/fesco/issue/3229):**Change: Make OpenSSL distrust SHA-1 signatures by default**
<@zodbot:fedora.im>
17:19:27
● **Opened:** 4 days ago by amoloney
<@zodbot:fedora.im>
17:19:27
● **Last Updated:** 26 minutes ago
<@zodbot:fedora.im>
17:19:27
● **Assignee:** asosedkin
<@zbyszek:fedora.im>
17:19:31
I forgot that line.
<@zbyszek:fedora.im>
17:19:37
!topic Next week's chair
<@dbelyavs:fedora.im>
17:19:50
Thank you!
<@sgallagh:fedora.im>
17:19:51
I will be away next week and cannot attend
<@simo:fedora.im>
17:20:00
🎆🍾🍾🍾
<@jistone:fedora.im>
17:20:01
I'll also be away
<@dcantrell:fedora.im>
17:20:10
and I will be away
<@zbyszek:fedora.im>
17:20:25
Dmitry Belyavskiy++ thank you for joining
<@zodbot:fedora.im>
17:20:26
zbyszek gave a cookie to dbelyavs. They now have 3 cookies, 1 of which were obtained in the Fedora 40 release cycle
<@sgallagh:fedora.im>
17:20:35
Next week is a US holiday, so it may be low attendance all-around
<@nirik:matrix.scrye.com>
17:20:39
probibly me too.
<@simo:fedora.im>
17:20:52
I failed at matrixing :-)
<@sgallagh:fedora.im>
17:20:55
Rather, next week *includes* a US holiday. Not Tuesday specifically
<@zbyszek:fedora.im>
17:21:03
OK, that's four down, so let's drop the next meeting.
<@zbyszek:fedora.im>
17:21:12
!info The next meeting will be in two weeks.
<@zbyszek:fedora.im>
17:21:28
So any volunteers for two weeks from now? :---]
<@jistone:fedora.im>
17:21:38
I can chair on the 9th
<@simo:fedora.im>
17:21:43
whatever this chat thing is called
<@simo:fedora.im>
17:21:43
or elementing?
<@zbyszek:fedora.im>
17:21:59
!action Josh Stone will chair the meeting in two weeks
<@zbyszek:fedora.im>
17:22:06
!topic Open Floor
<@zbyszek:fedora.im>
17:23:00
Nothing is on fire?
<@zbyszek:fedora.im>
17:23:06
No urgent complaints?
<@sgallagh:fedora.im>
17:23:21
Amazingly, we came to a good choice on the new time
<@decathorpe:fedora.im>
17:23:39
zbyszek don't jinx it
<@zbyszek:fedora.im>
17:23:41
Yeah, having a meeting while the sun is still out is so refreshing.
<@nirik:matrix.scrye.com>
17:24:02
just wait tho...
<@decathorpe:fedora.im>
17:24:07
isn't this the old old meeting time from like 3 years ago?
<@salimma:fedora.im>
17:24:41
it's lunchtime for me but having taken this meeting from Central Europe, the old meeting time is hell so... I'm happy to take lunch slightly late
<@zbyszek:fedora.im>
17:24:55
OK, so let's wrap this up.
<@zbyszek:fedora.im>
17:25:04
Thank y'all for coming.
<@zbyszek:fedora.im>
17:25:06
!endmeeting