L

Differences between revisions 15 and 16
Revision 15 as of 2009-11-09 19:37:52
Size: 3447
Editor: pool-71-114-235-234
Comment:
Revision 16 as of 2009-11-09 19:45:28
Size: 3548
Editor: c-76-105-168-175
Comment: assigned!
Deletions are marked like this. Additions are marked like this.
Line 60: Line 60:
 * apport hooks (vs https://bugs.edge.launchpad.net/~ubuntu-security/+packagebugs, common security bugs, AA profiled packages, list of reasons why no hook, etc)
 * review sponsorship process and compare to security-sponsorship
 * http://fedoraproject.org/wiki/Features/LowerProcessCapabilities (foundations)
 * screen lock does not work (requires Gnome screen saver folks, Riddell, QA, create "DebuggingScreenLocking", triage borked systems)
 * "How can the Ubuntu Security Team help Debian better?" (debian folks?)
 * Notification of system BIOS failures (NX bit. Needs DX.)
 * apparmor abstractions cleanup
 * apparmor usability in Ubuntu (existing profiles, userspace tools, profile creation, upgrade tunables, reporting denials)
 * AppArmor upstream planning session(s)
 * Catch-all
 * 2-factor (Smartcard/USB token/fingerprint/Cert) authentication (soren)
 * (kees) apport hooks (vs https://bugs.edge.launchpad.net/~ubuntu-security/+packagebugs, common security bugs, AA profiled packages, list of reasons why no hook, etc)
 * (nxvl) review sponsorship process and compare to security-sponsorship
 * (kees) http://fedoraproject.org/wiki/Features/LowerProcessCapabilities (foundations)
 * (mdeslaur) screen lock does not work (requires Gnome screen saver folks, Riddell, QA, create "DebuggingScreenLocking", triage borked systems)
 * (jdstrand) "How can the Ubuntu Security Team help Debian better?" (debian folks?)
 * (kees) Notification of system BIOS failures (NX bit. Needs DX.)
 * (jdstrand) apparmor abstractions cleanup
 * (jdstrand) apparmor usability in Ubuntu (existing profiles, userspace tools, profile creation, upgrade tunables, reporting denials)
 * (kees) AppArmor upstream planning session(s)
 * (mdeslaur) Catch-all
 * (mdeslaur) 2-factor (Smartcard/USB token/fingerprint/Cert) authentication (soren)

Dumping ground for UDS ideas

KeesCook

JamieStrandboge

  • apparmor abstractions cleanup
  • apparmor usability
  • sort out apparmor upstream vs apparmor in ubuntu (is this still needed?)
  • ufw
    • usability improvements:
      • delete by number
      • reset
      • limit command options
      • show listening
      • rsyslog
      • more reporting
    • more work on ufw/upstart/boot integration
    • what does server team need/want (eg, ebtables?)
    • requested features (eg ufw-simple-gui, nat/rdr, etc)
  • libvirt/apparmor features, polishing and maintenance
    • bug fixing
    • add backing store support
    • make sure it works with newer releases
    • support features newly supported by the selinux driver
    • continue to develop test cases (eg pool-* and vol-* commands)
    • run qemu:///system VMs as non-root
  • we should generalize and improve the apparmor apport hook
  • update firefox profile to work better in KDE (and XFCE)
  • implement a way to automatically, but temporarily, subscribe ubuntu-security to package bugs for security uploads

MarcDeslauriers

  • Smartcard/USB token authentication
  • Certificate on USB disk authentication

Sessions

  • (kees) apport hooks (vs https://bugs.edge.launchpad.net/~ubuntu-security/+packagebugs, common security bugs, AA profiled packages, list of reasons why no hook, etc)

  • (nxvl) review sponsorship process and compare to security-sponsorship
  • (kees) http://fedoraproject.org/wiki/Features/LowerProcessCapabilities (foundations)

  • (mdeslaur) screen lock does not work (requires Gnome screen saver folks, Riddell, QA, create "DebuggingScreenLocking", triage borked systems)

  • (jdstrand) "How can the Ubuntu Security Team help Debian better?" (debian folks?)
  • (kees) Notification of system BIOS failures (NX bit. Needs DX.)
  • (jdstrand) apparmor abstractions cleanup
  • (jdstrand) apparmor usability in Ubuntu (existing profiles, userspace tools, profile creation, upgrade tunables, reporting denials)
  • (kees) AppArmor upstream planning session(s)

  • (mdeslaur) Catch-all
  • (mdeslaur) 2-factor (Smartcard/USB token/fingerprint/Cert) authentication (soren)

SecurityTeam/UDS/L (last edited 2010-04-26 17:52:01 by pool-71-114-231-221)