- To Software Software - To Software-Assessment - Software/Assessment - To previous meeting - To next meeting 
Minutes of the MiniTOP on the 2011-09-13
Setting
The MiniTOP will be held via telco 22:00 CEST
Attendees: dirk, marcus, uli, michael, magu
Topics
(skip to agenda)
Action items from last meeting Meeting Action Items
Software/Assessment/ActionItems
- all - proposed Apache config SSLCipherSuite settings for CAcert SSL enabled infrastructure systems 
 see also BEAST migration https://community.qualys.com/blogs/securitylabs/2011/10/17/mitigating-the-beast-attack-on-tls
 Proposal from Sysadm list 2013-09-06- {0} - SA - documentation server cert design concept to SystemAdministration/Systems/Development/Prepare - {0} - all - {0} - BenBE, Marcus - documentation: developer git repos under github 
 bug #1131 history @ github
 CAcertOrg @ github
 started under Software/Assessment/Documentation/UpdateCycle/step1- {0} - NEO - {0} - all - read x509 guide - {0} - all - bug#1068 blog problem (also relates to community) 
 debian lenny - edge - squeeze upgrades needed
 alternate: new server with squeeze, install wordpress, transfer domain
 workaround: configure your FF FAQ/BrowserClients- {g} - uli - Experience points for ATE attendance 
 check board motions and/or trigger if not yet passed- {0} - uli - Infrastructure separation, to contact secure-u (Frank, Mario, Ted, Sebastian) for discussion, prepare a plan, started 2011-12-18 
 current state: see Funding Landing Page
 May 2013: tk-server sponsoring, tk-server rcvd, deployment: WIP, project not yet finished- {0} - All - 1. next: strategy for "New Roots & Escrow" - using indirect crl's ? 
 indirect CRL: RFC 5280 http://tools.ietf.org/html/rfc5280 (chapter 5) - test deployment- {0} - dirk, Michael - 3. next: strategy for "New Roots & Escrow" - how does debian work? 
 to contact, deferred to next events (?)
 next round: picked up by Benedikt new proposal 2013-06-02- {0} - Uli, Michael - Documentation Bugs.cacert.org Review, documentation I (bugs handbook) svg files to convert to jpg or png - {0} 
Development, Deployment, Discussion
- OAO, Ted - bug #943 change OA admin/assurer text - needs 2nd test -> Fabian, Marc, Alex? {g} / needs 2nd review -> Ted, rejected - {-} - uli, Ted - bug #824 Org User cert fix Case study - Organisation User Certificates: Need UI improvement for proper production usage - {0} - uli, ted - bug #823 email address removal fix - No warning when removing e-mail address from account that certificates will be revoked 
 checked by 4, needs 2nd review, deploy
 rejected- {-} - inopiae - bug #920 Join - single name only (eg Indonesian) - details under bug number - {0} - uli - bug #859 admin console interface - feature request: show activity on an account in the admin interface 
 rejected, certs login doesn't modify "modified" field- {r} - Michael - p20111113 CPS #7.1.2 "Certificate Extensions" adjustments - testing 
 uli, marcus: needs full cert create tests
 duplicate report to bug#978
 tested by 3, 2nd review done, transfered
 Ken reported: still has problems, bug kept open- {0} - gagern, NEO - bug #440 Problem with subjectAltName (CSR, renew certs) - There seems to be a problem with the subjectAltName. Dupes, missing entries, and more, rejected, needs further development - {r} - neo - bug #1025 Domain Dispute issue - disputes rc and rc2 var prob 
 needs work- {r} - dirk - bug #1054 0001054: Review the code regarding the new point calculation - Thawte patch part II 
 needs further work- {r} 
Software Assessors: Review 1 / add to cacert-devel, add to testserver
- Software-Assessors task 
Testing
- Testers task - neo - bug #1004 Stats page improvement - tested by 2, needs 2nd review - {0} - neo - Bugs #1159 it might be possible to execute commands on the signing server - {0} - inopiae - bug #1065 Wrong wording when sending mails during the assurance process - {0} - inopiae - bug #1162 calcutate (the passwords) hash in php instead of in mysql - create test scenarios for the software testers   
 Full testing  - {0} - inopiae - bug #0028 Wrong language for you've been assured & [CAcert.org] Client Certificate emails - {0} - inopiae - bug #988 TTP cap form deployment - {0} 
Software Assessors: 2nd Review, Bundle Package to Critical Team
- Software-Assessors task - Ted - bug #500 Get contact mail adress after resolving test - tested by 3, requires review - {0} - Ted - bug #1140 Show if a test is passed in learnprogress - tested by 3, requires review - {0} - magu - bug #1131 Rename _all_ Policies from .php to .html and fix all links - global policy directory maintenance and update - {0} - inopiae - bug #1010 Reorder the view on organisation certificates - tested by 3 - {0} 
Software Assessors: Bundle Package to Critical Team
- Software-Assessors task - inopiae - bug #1139 Add new fields to the database - tests through #500 and #1140, 2nd review done, requires transfer - {0} 
Awaiting Response from Critical Team
- inopiae - bug #411 Wrong text is made into link - {g} 
Agenda
- Software-Assessors blockage - The List of open / running / unhandled bugs - Part I - request by Joost for variable fields
- next steps: - preparing PR, support (see below) - Thawte Patch - PR strategy - alex to prepare blog post
- if the patch goes active, this needs support
- wiki faq (existing page? thawte topic?)
- blog (-> alex) 
- mailing list
- press release? probably not at this state
- Support: could be better, but is ok - Triage: where to forward Thawte patch requests?
- add to Support team meeting agenda
 
 
 
- Thawte Patch - PR strategy 
- reviewed last meeting. needs transfer to critical team - transfer to critical team, done.
- mailing to people: Ted, Florian F, PG, Wytze, Carsten L, Jeff F, Frank K (ask Marcus) 120 pts, Sebastian K, done.
- report by Wytze: problem with Unknown, Trusted Third Parties, Assurances before 2006 (0,0)
 
 
- preparing PR, support (see below) 
 
- Michael, Ted - action items last week - bug 846 - and others in the queue
 
 
- bug 846 
 
- PR work - thawte patch - blog post
- newsletter mailings - thawte patch details - infos about thawte points removal
- infos about points counting - Update ? Text proposal ?
 
 
- Security campaign, Newsletters  (1 month later, 6-8 weeks later) - weak passwords (bug 637)
- password reset w/ Assurance replaces pwd reset thru paypal
- cert login security fix (bug 841)
- weak keys disabled (bug 918)
- class3 re-sign with sha256
- check your CAcert account - create a client cert for client cert login (also needed for CATS)
- check your secret questions
- check your password
- check your notification settings
- check your location settings
 
 
 
- thawte patch details 
 
- Mozilla Communication: Immediate action requested
- Wytze: system upgrade on production and cacert1.it-sls.de (cont. from last meeting) - proposed next upgrade step lenny to squeeze
- Action item: who informs Wytze?
 
- Translingo - the translingo.cacert.org had been in operation far longer, so I think it is possible that some users migrated to translingo.cacert.org, without telling us.
- I would suggest to mass-mail the email addresses of the translation-project leaders in the translingo database, to inform them, and to ask them to speak up if they still need it
- last foreign uploads 2008 on about 13 + cacert projects
- whohas translingo server console access? - mario
 
- req for console access for michael to contact project leaders, Updates?
- Transfer In, Transfer Out problems
 
- Question from Lambert (by email): Is CAcert's ocsp server a blacklist or a whitelist ocsp ? (cont. from last meeting) - CAcert is probably a blacklist ocsp, cause the server delivers infos derived from current crl's interactively
- Is this for Software-Assessment project group ? Next action step?
 
- Dirks workqueue - The List of open / running / unhandled bugs - VBscript for Vista/Win7 (select keysize >= 1024) - reminder to dirk - x1 Dirk, new bug#964 
 DEV: bug#918 (Part II) (a20110312.1) Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEV- current state: test /account/4.php added to testserver 
 Marcus will do detailed tests on Wed
 some references added to bug#964- {-} 
- as part of
- x1 Arbitration case a20110312.1 Weak keys bug #918 / bug #954 / bug#964 
- Current state: - {g} - pre mailing sent - {g} - keys revocation script to bulk revoke weak keys, new bug #954, finished - {-} - dirk: DEV: a20110312.1 bug#918 Weak keys: /pages/account/.. 4.php, 17.php to combine ? (/includes/keygen.php) DEV 
 vbscript needs to be improved with select box key size and lower limit to 2048 (based on https://wiki.mozilla.org/CA:MD5and1024)
 Api CertEnroll (MS crypto provider)
 new bug#964
 current state: test /account/4.php added to testserver
 Marcus will do detailed tests on Wed
 some references added to bug#964- {g} - Weak keys blog post, published - {g} - Weak keys article published by Hanno(July 28), link is in CAcert's blog post (July 30) - {b} - weak keys: problems with cryptostick (to test at Froscon with Juergen ?) 
 
- cert enroll infos under bug#964 
- vista and win7 works with other engine !CryptoAPI (?) => Cryptography API: Next Generation - http://msdn.microsoft.com/en-us/library/aa833130%28v=VS.85%29.aspx 
- Marcus: added notes for Win7 https://bugs.cacert.org/view.php?id=964#c2249 
 
- Update (3rd week) ?
 
- Advertising - Prepare Advertising fix for testserver - reminder to dirk - Dirk - Advertising (from last board meeting), bug #958 - add changes as discussed in last meeting to testserver - {0} 
- CAcertInc/LogosForSale/Rules wiki link exist 
- "buy me" logo / "Logo For Sale" logo / "Monthly Auction on Logos" logo
- Logos and Links exist, needs deployment to testserver
- Update (3rd week) ?
 
- google ads, nobody knows about - http://google.de/adsense/ - needs google account - ad client id: pab.*9860, email adress is needed
- board member to write email request to Robert, Philipp, Philpp, Teus, ernie
- contact google?
- account recovery?
- dirk: google ads account - to write mail to treasurer (address from invoice)
 
- Update (3rd week) ?
 
 
 
- Software-Assessors blockage - Bugs to Review #1, transfer to testserver - Currently 12 (!!!) - uli - bug #977 admin console text fix - admin console Sysadmin - find domain - lists 2 tables - one for user accounts, one for org accounts, naming issue - {0} - uli - bug #975 admin console interface (2) - report potential database inconsistency in SE console (debug infos), new update   - {0} - uli - bug #968 error logging cleanup (splitted bug #909) - split 0000909: too many error messages logged - part II - general.php - {0} - uli - bug #967 OA isassurer check - Give an OA the oppertuntiy to check if a desiginated Organisation Admininistrator is a CAcert assurer - {0} - uli, Ted - bug #965 0000965: Outsource / fix Webdb text pages id=12, 13 - addtl. id=37, id=38, new update   - {0} - uli, ted - display Assurance when field in list of assurances received, assurances given by a user in admin console interface, new update   - {0} - uli - bug #859 admin console interface - feature request: show activity on an account in the admin interface, new update   - {0} - uli - bug #855 admin console interface "unknown" + "empty" assurance method fields, needed for correct testing on testserver - admin console lists "empty" and "Unknown" Assurance types on listing given Assurances - {0} - uli - bug #823 email address removal fix - No warning when removing e-mail adres from acount that certificates wil be revoked - {0} - uli, ted - visibility over certificates for sysadm in account administration, new update   - {0} - uli - bug #789 OA edit domain fix - Editing domain for organisations does not work - {0} - moh - bug #596 certs list advanced - display ser# in certs overview lists - {0} 
- 12 open fixes available (week 3), needs 1st review by 1st Software-Assessor
 
- Bugs under testing: - Currently 4 - uli, Michael - bug #966 cancel doesn't cancel but processes instead - potential workaround to fix all "Cancel" requests available 
 addtl. individual fixes
 new update 2011-08-30
 at least one more test- {0} - uli, Ted - bug #957 Resize the comment field on https://secure.cacert.org/account.php?id=27 so more information is visible - new fix avail 2011-08-19 
 at least one more test- {0} - Dirk - bug #894 problems with check-boxes on website forms (Assure someone) -> a20091118.3 
 1st review still needed
 two testers to test- {0} - uli - bug #824 Org User cert fix - Organisation User Certificates: Need UI improvement for proper production usage 
 needs some more fixes- {0} 
 
- Software-Assessors blockage - Needs 2nd review + transfer to Critical team, to bundle, to deploy - Currently 4 (!!!) - uli, ted - bug #955 change sort order Orga list - Possibilty to change the sorting order for the organisation overview - {0} - uli, ted - bug #940 help* to wiki - Outsource Webdb text pages help.php?id=0..9 to wiki 
 needs review, deploy- {0} - uli, ted - bug #910 Outsource board member list - from Webdb to wiki (id=8) (Part II) - {0} - Ted, uli - bug #846 Join Form restructure, help link - Better guidance of bonafide members in Join Form about Suffixes they doesn't have in their ID doxs (a20100207.2) - {0} 
 
- Needs development, deployment, discussion - bug #835 Migrate CATS onto testserver - bug #835 Assurer challenge (on testserver) - asssigned to Ted, CATS to install on ca-mgr1, awaiting deployment - {0} 
 
- bug #943 change OA admin/assurer text - bug #943 change OA admin/assurer text - -> Ted, rejected, needs comment from OAO - {-} 
- webdb names OrgAdmins as OrgAssurers and names OrgAssurers as OrgAdmins. 
- patch takes account about this issue
- problem with menu link Org Admin .. is Org Assurers menu - but this menu includes one addtl. link "View" that is available for Org Admins - and Org Admins with master flag to add new admins
 
- master flag is not described in OAP   
- addtl master flag to revoke ?
- rename to "Org Administration"
- don't show menu to OrgAdmins 
 
- but this menu includes one addtl. link "View" that is available for Org Admins 
 
 
- strategy plans ... next: strategy for "New Roots & Escrow" - idea: using indirect crl's ? - 2 crl's needed, one valid, one invalid crl server
- more infos available ? who ? - build testserver with special certs
- Magu, Michael to send instructions for test deployment - indirect CRL: RFC 5280 http://tools.ietf.org/html/rfc5280 (chapter 5) 
 
 
- meetings ago we've defined Testing requirements and a potential testszenario
- to remind every meeting
- Michael: testserver environment deployment
 
- policy group: define requirements - multimember escrow method ? - needs risk analyze
- potential candidates ? - Marcus to contacted Benedikt, will contact Thomas K
- Next step(s)
 
 
 
- multimember escrow method ? 
- how does debian work ? - defered to Froscon (end of Aug), CCCcamp (around Aug 10th)
 
 
- idea: using indirect crl's ? 
- CI (Update) - description to eclipse testpage, Webinar - deployment scenario: - create testusers
- testing
- delete testusers
 
- regression test for standard tests: eg 0,1,49,50,51,99,100,101 pts w/ and w/o CATS passed
- reminder
 
- deployment scenario: 
- Jubula Test-Tool (by Michael) - update? - instructions see under Minutes meeting 2011-08-30 
- test deployment needs to be continued by software testers
 
 
- next meeting: Tuesday, September 20, 2011 22:00
Minutes
- Marcus: 43.php to add notary.id to bug#882 - dirk tries to upload new 43.php
 
- dirk: bug#827 update
- translingo: michael tries to deploy pootle
- michael: bug#846 reviewed, made some corrections, needs 2nd review
- PR: Alex not available, will prepare blog post, mailing
- Mozilla Communication: Immediate action requested - blueprint for activities CAcert has to do on the way to browser inclusion
- add https://lists.cacert.org/wws/arc/cacert-board/2011-09/msg00008.html topics as bug numbers 
 
- Wytze: system upgrade on production and cacert1.it-sls.de (cont. from last meeting) - proposed next upgrade step lenny to squeeze
- Action item: who informs Wytze?
- -> Michael 
 
- Testserver hosting: request to Funkfeuer directly ? - funkfeuer.at infos see http://funkfeuer.at/Eckdaten.243.0.html 
 
- Question from Lambert (by email): Is CAcert's ocsp server a blacklist or a whitelist ocsp ? (cont. from last meeting) - CAcert is probably a blacklist ocsp, cause the server delivers infos derived from current crl's interactively
- Is this for Software-Assessment project group ? Next action step?
- is topic for critical admin
 
- Jubula Test-Tool (by Michael) - update? - instructions see under Minutes meeting 2011-08-30 
- test deployment needs to be continued by software testers
- no update
 
- bug#855 problem prevents testing of TTP entries - needs to be activated at least on testserver
 
- next meeting: Tuesday, September 20, 2011 22:00
Fixed Action Items since last or within meeting
- uli - prepare cacert1 image for developers after proposed system update - {g} - uli - prepare ca-mgr1 image for developers - {g} - uli - prepare DEBIAN-Lenny image for developers (request by Michael) - req cancled - {b} - uli - preview mailing to people: Ted, Florian F, PG, Wytze, Carsten L, Jeff F, Frank K (ask Marcus) 120 pts, Sebastian K - {g} 
- Awaiting Response from Critical Team (moved to next state) Done: Michael, Dirk, Michael 
 ToDo:bug #841 Problems on cert login needs 2nd review, deploy {g} Done: Dirk, Michael, Michael 
 ToDo:bug #827 and bug #959 Thawte patch/Points-Count-Order-Change project related bug 959: needs 1 more test, needs 2nd review / 2nd review: also check -x / tests done, needs 2nd review 
 959 {g} reviewed, deployed
 827 {g} reviewed, deployment in 2 steps{g} 
 {0}
Action Items New
Action items: Meeting Action Items
