Infineon firmware security issues
by Marc Dequènes (Duck)
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--Jo6QvEJXJfQCfDxTQMptqAWL0Ku1cee9q
Content-Type: multipart/mixed; boundary="euwd0OP654GGNcLdW6Guf5oX9JOBAWw2A";
protected-headers="v1"
From: =?UTF-8?B?TWFyYyBEZXF1w6huZXMgKER1Y2sp?= <duck(a)redhat.com>
To: oVirt Infra <infra(a)ovirt.org>
Message-ID: <5ca02ec3-9742-187e-9a93-ca50b03778aa(a)redhat.com>
Subject: Infineon firmware security issues
--euwd0OP654GGNcLdW6Guf5oX9JOBAWw2A
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable
Quack,
So the news (thanks Misc for the alert):
https://www.infineon.com/cms/en/product/promopages/rsa-update/rsa-backgro=
und
This affects Yubikeys and other hardware:
https://www.yubico.com/support/security-advisories/ysa-2017-01/
There's a nice tool to test if a key is vulnerable:
https://github.com/crocs-muni/roca
I tested keys in the oVirt Puppet repository and none are affected.
You may check your other keys and ensure keys are checked in other
projects.
\_o<
--euwd0OP654GGNcLdW6Guf5oX9JOBAWw2A--
--Jo6QvEJXJfQCfDxTQMptqAWL0Ku1cee9q
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEcpcqg+UmRT3yiF+BVen596wcRD8FAlnl08cACgkQVen596wc
RD+oEg/+PFTrAc13zzF6ldhn/U1oq1wzh2HYaGQ62vw2nmC3BHeXVUqAUIUbWsSs
UaQxDZRiuXxCnFgM45rWyiAjZiXg9Lgpt5gcCHOWJ6TsSzJh0j/gQFq75FPKYtrQ
Lob1v8KMv2bF7jEF7QgwaIj/BwEDnZ+XN53/2fg4lQ97wb6WBb3caSjejhPzcR6+
zg14uZHAe9bvMUk7qMn8ybCrb5TjQEeepV40mpRLvtY5tyLBzxs9ho1UmL4w3BL7
9Grdr2r2shKiWYPdUIP/F6OAavKR1MNmW2N8ZIYaHKFaN19YXAc71w4h9nHeD18Q
lM4p3hzT2/cHY/fnsmS5Y7jtUyXgPHJvlyi2AkMht9gfI2xn27yyQuaSh0JjU1M7
2NAW/h2Gssf3rAmmuc3P7Kbq6wEY+krWgJSlefjzeOTYrPMlPtij6DieMVwlyRhG
ct4buRHRlRFku1SFeYSoTNGieCamIVSQ9VH3Iyk0/tNwL9mdrOLv91VT/L8WUpvl
vV4qY8Vbh+8OF3lNhGHFPWhQkFW46yoBrbK4S/jxK+fIsy/h72+ZI8Nc3omw5t80
eKTb6FWLysDG0MJoYhl2zaP9wq86e9fIwXPfF75uO1z4w/5T0qbITnnCGReFgvVK
rq5gs4J4/S3qCQVZ45aaz0DNdvfNnOKBLN89x5gwtaXDYq/+8wE=
=+KxX
-----END PGP SIGNATURE-----
--Jo6QvEJXJfQCfDxTQMptqAWL0Ku1cee9q--
7 years, 1 month
[JIRA] (OVIRT-1708) Add a mirror for the FC27 'updates' repo.
by Barak Korren (oVirt JIRA)
This is a multi-part message in MIME format...
------------=_1508233487-11808-268
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Barak Korren created OVIRT-1708:
-----------------------------------
Summary: Add a mirror for the FC27 'updates' repo.
Key: OVIRT-1708
URL: https://ovirt-jira.atlassian.net/browse/OVIRT-1708
Project: oVirt - virtualization made easy
Issue Type: Improvement
Components: Repositories Mgmt
Reporter: Barak Korren
Assignee: infra
Just like we did for FC26, we recently added a mirror for FC27. And since its not released yet, we can't add an 'updates' mirror.
This ticket is for adding the FC27 'updates' mirror once FC27 is released.
--
This message was sent by Atlassian Jira
(v1001.0.0-SNAPSHOT#100066)
------------=_1508233487-11808-268
Content-Type: text/html; charset="UTF-8"
Content-Disposition: inline
Content-Transfer-Encoding: 7bit
<html><body>
<h3>Barak Korren created OVIRT-1708:</h3>
<pre> Summary: Add a mirror for the FC27 'updates' repo.
Key: OVIRT-1708
URL: https://ovirt-jira.atlassian.net/browse/OVIRT-1708
Project: oVirt - virtualization made easy
Issue Type: Improvement
Components: Repositories Mgmt
Reporter: Barak Korren
Assignee: infra</pre>
<p>Just like we did for FC26, we recently added a mirror for FC27. And since its not released yet, we can't add an ‘updates’ mirror.</p>
<p>This ticket is for adding the FC27 ‘updates’ mirror once FC27 is released.</p>
<p>— This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100066)</p>
<img src="https://u4043402.ct.sendgrid.net/wf/open?upn=i5TMWGV99amJbNxJpSp2-2BCmpYL..." alt="" width="1" height="1" border="0" style="height:1px !important;width:1px !important;border-width:0 !important;margin-top:0 !important;margin-bottom:0 !important;margin-right:0 !important;margin-left:0 !important;padding-top:0 !important;padding-bottom:0 !important;padding-right:0 !important;padding-left:0 !important;"/>
</body></html>
------------=_1508233487-11808-268--
7 years, 1 month
[JIRA] (OVIRT-1708) Add a mirror for the FC27 'updates' repo.
by Barak Korren (oVirt JIRA)
This is a multi-part message in MIME format...
------------=_1508233485-25404-245
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
[ https://ovirt-jira.atlassian.net/browse/OVIRT-1708?page=com.atlassian.jir... ]
Barak Korren updated OVIRT-1708:
--------------------------------
Epic Link: OVIRT-403
> Add a mirror for the FC27 'updates' repo.
> -----------------------------------------
>
> Key: OVIRT-1708
> URL: https://ovirt-jira.atlassian.net/browse/OVIRT-1708
> Project: oVirt - virtualization made easy
> Issue Type: Improvement
> Components: Repositories Mgmt
> Reporter: Barak Korren
> Assignee: infra
> Labels: fedora, mirrors
>
> Just like we did for FC26, we recently added a mirror for FC27. And since its not released yet, we can't add an 'updates' mirror.
> This ticket is for adding the FC27 'updates' mirror once FC27 is released.
--
This message was sent by Atlassian Jira
(v1001.0.0-SNAPSHOT#100066)
------------=_1508233485-25404-245
Content-Type: text/html; charset="UTF-8"
Content-Disposition: inline
Content-Transfer-Encoding: 7bit
<html><body>
<pre>[ https://ovirt-jira.atlassian.net/browse/OVIRT-1708?page=com.atlassian.jir... ]</pre>
<h3>Barak Korren updated OVIRT-1708:</h3>
<pre>Epic Link: OVIRT-403</pre>
<blockquote><h3>Add a mirror for the FC27 ‘updates’ repo.</h3>
<pre> Key: OVIRT-1708
URL: https://ovirt-jira.atlassian.net/browse/OVIRT-1708
Project: oVirt - virtualization made easy
Issue Type: Improvement
Components: Repositories Mgmt
Reporter: Barak Korren
Assignee: infra
Labels: fedora, mirrors</pre>
<p>Just like we did for FC26, we recently added a mirror for FC27. And since its not released yet, we can't add an ‘updates’ mirror. This ticket is for adding the FC27 ‘updates’ mirror once FC27 is released.</p></blockquote>
<p>— This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100066)</p>
<img src="https://u4043402.ct.sendgrid.net/wf/open?upn=i5TMWGV99amJbNxJpSp2-2BCmpYL..." alt="" width="1" height="1" border="0" style="height:1px !important;width:1px !important;border-width:0 !important;margin-top:0 !important;margin-bottom:0 !important;margin-right:0 !important;margin-left:0 !important;padding-top:0 !important;padding-bottom:0 !important;padding-right:0 !important;padding-left:0 !important;"/>
</body></html>
------------=_1508233485-25404-245--
7 years, 1 month
[JIRA] (OVIRT-1707) The infra docs index page needs a face lift
by Barak Korren (oVirt JIRA)
This is a multi-part message in MIME format...
------------=_1508233258-13963-275
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Barak Korren created OVIRT-1707:
-----------------------------------
Summary: The infra docs index page needs a face lift
Key: OVIRT-1707
URL: https://ovirt-jira.atlassian.net/browse/OVIRT-1707
Project: oVirt - virtualization made easy
Issue Type: Improvement
Components: General
Reporter: Barak Korren
Assignee: infra
Priority: High
The infra-docs index page is the first page about the oVirt infra team that anyone will see, but it looks bad. Here are a few issues with it:
# The page title was probably auto-generated by GitHub and looks wrong
# The page contains no text. There needs to be some short 2-3 line explanation about what is this page and what could be found in it. The sub sections should probably also include 1-2 lines each about which documents can be found in them.
# Some links have opaque non-descriptive text. For example "Communication" should probably be "Communicating with the oVirt infra team".
# The documents and sections are listed in semi-random order. Instead, they should be ordered in such a way that the more important public-facing documents are closer to the top
# The "general" section is just a random collection of things. It should probably be split apart into more specific sections like "Gerrit", "Contribution guidelines" and "Procedures for infra-team members".
--
This message was sent by Atlassian Jira
(v1001.0.0-SNAPSHOT#100066)
------------=_1508233258-13963-275
Content-Type: text/html; charset="UTF-8"
Content-Disposition: inline
Content-Transfer-Encoding: 7bit
<html><body>
<h3>Barak Korren created OVIRT-1707:</h3>
<pre> Summary: The infra docs index page needs a face lift
Key: OVIRT-1707
URL: https://ovirt-jira.atlassian.net/browse/OVIRT-1707
Project: oVirt - virtualization made easy
Issue Type: Improvement
Components: General
Reporter: Barak Korren
Assignee: infra
Priority: High</pre>
<p>The infra-docs index page is the first page about the oVirt infra team that anyone will see, but it looks bad. Here are a few issues with it: # The page title was probably auto-generated by GitHub and looks wrong # The page contains no text. There needs to be some short 2-3 line explanation about what is this page and what could be found in it. The sub sections should probably also include 1-2 lines each about which documents can be found in them. # Some links have opaque non-descriptive text. For example “Communication” should probably be “Communicating with the oVirt infra team”. # The documents and sections are listed in semi-random order. Instead, they should be ordered in such a way that the more important public-facing documents are closer to the top # The “general” section is just a random collection of things. It should probably be split apart into more specific sections like “Gerrit”, “Contribution guidelines” and “Procedures for infra-team members”.</p>
<p>— This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100066)</p>
<img src="https://u4043402.ct.sendgrid.net/wf/open?upn=i5TMWGV99amJbNxJpSp2-2BCmpYL..." alt="" width="1" height="1" border="0" style="height:1px !important;width:1px !important;border-width:0 !important;margin-top:0 !important;margin-bottom:0 !important;margin-right:0 !important;margin-left:0 !important;padding-top:0 !important;padding-bottom:0 !important;padding-right:0 !important;padding-left:0 !important;"/>
</body></html>
------------=_1508233258-13963-275--
7 years, 1 month
[JIRA] (OVIRT-1707) The infra docs index page needs a face lift
by Barak Korren (oVirt JIRA)
[ https://ovirt-jira.atlassian.net/browse/OVIRT-1707?page=com.atlassian.jir... ]
Barak Korren updated OVIRT-1707:
--------------------------------
Epic Link: OVIRT-403
> The infra docs index page needs a face lift
> -------------------------------------------
>
> Key: OVIRT-1707
> URL: https://ovirt-jira.atlassian.net/browse/OVIRT-1707
> Project: oVirt - virtualization made easy
> Issue Type: Improvement
> Components: General
> Reporter: Barak Korren
> Assignee: infra
> Priority: High
> Labels: documentation
>
> The infra-docs index page is the first page about the oVirt infra team that anyone will see, but it looks bad. Here are a few issues with it:
> # The page title was probably auto-generated by GitHub and looks wrong
> # The page contains no text. There needs to be some short 2-3 line explanation about what is this page and what could be found in it. The sub sections should probably also include 1-2 lines each about which documents can be found in them.
> # Some links have opaque non-descriptive text. For example "Communication" should probably be "Communicating with the oVirt infra team".
> # The documents and sections are listed in semi-random order. Instead, they should be ordered in such a way that the more important public-facing documents are closer to the top
> # The "general" section is just a random collection of things. It should probably be split apart into more specific sections like "Gerrit", "Contribution guidelines" and "Procedures for infra-team members".
--
This message was sent by Atlassian Jira
(v1001.0.0-SNAPSHOT#100066)
7 years, 1 month
[oVirt Jenkins] ovirt-system-tests_hc-basic-suite-4.1 - Build # 62 - Failure!
by jenkins@jenkins.phx.ovirt.org
Project: http://jenkins.ovirt.org/job/ovirt-system-tests_hc-basic-suite-4.1/
Build: http://jenkins.ovirt.org/job/ovirt-system-tests_hc-basic-suite-4.1/62/
Build Number: 62
Build Status: Failure
Triggered By: Started by timer
-------------------------------------
Changes Since Last Success:
-------------------------------------
Changes for Build #62
[Yaniv Kaul] Allow to skip sync, to work offline
[Eyal Edri] remove getbadges Jenkins integration
-----------------
Failed Tests:
-----------------
1 tests failed.
FAILED: 002_bootstrap.add_hosts
Error Message:
[ERROR]::oVirt API connection failure, (7, 'TCP connection reset by peer')
-------------------- >> begin captured logging << --------------------
ovirtlago.testlib: ERROR: * Unhandled exception in <function _host_is_up at 0x4dfad70>
Traceback (most recent call last):
File "/usr/lib/python2.7/site-packages/ovirtlago/testlib.py", line 219, in assert_equals_within
res = func()
File "/home/jenkins/workspace/ovirt-system-tests_hc-basic-suite-4.1/ovirt-system-tests/hc-basic-suite-4.1/test-scenarios/002_bootstrap.py", line 144, in _host_is_up
cur_state = api.hosts.get(host.name()).status.state
File "/usr/lib/python2.7/site-packages/ovirtsdk/infrastructure/brokers.py", line 18338, in get
headers={"All-Content":all_content}
File "/usr/lib/python2.7/site-packages/ovirtsdk/infrastructure/proxy.py", line 46, in get
return self.request(method='GET', url=url, headers=headers, cls=cls)
File "/usr/lib/python2.7/site-packages/ovirtsdk/infrastructure/proxy.py", line 122, in request
persistent_auth=self.__persistent_auth
File "/usr/lib/python2.7/site-packages/ovirtsdk/infrastructure/connectionspool.py", line 81, in do_request
raise errors.ConnectionError(error)
ConnectionError: [ERROR]::oVirt API connection failure, (7, 'TCP connection reset by peer')
--------------------- >> end captured logging << ---------------------
Stack Trace:
File "/usr/lib64/python2.7/unittest/case.py", line 369, in run
testMethod()
File "/usr/lib/python2.7/site-packages/nose/case.py", line 197, in runTest
self.test(*self.arg)
File "/usr/lib/python2.7/site-packages/ovirtlago/testlib.py", line 129, in wrapped_test
test()
File "/usr/lib/python2.7/site-packages/ovirtlago/testlib.py", line 59, in wrapper
return func(get_test_prefix(), *args, **kwargs)
File "/home/jenkins/workspace/ovirt-system-tests_hc-basic-suite-4.1/ovirt-system-tests/hc-basic-suite-4.1/test-scenarios/002_bootstrap.py", line 163, in add_hosts
testlib.assert_true_within(_host_is_up, timeout=15 * 60)
File "/usr/lib/python2.7/site-packages/ovirtlago/testlib.py", line 263, in assert_true_within
assert_equals_within(func, True, timeout, allowed_exceptions)
File "/usr/lib/python2.7/site-packages/ovirtlago/testlib.py", line 219, in assert_equals_within
res = func()
File "/home/jenkins/workspace/ovirt-system-tests_hc-basic-suite-4.1/ovirt-system-tests/hc-basic-suite-4.1/test-scenarios/002_bootstrap.py", line 144, in _host_is_up
cur_state = api.hosts.get(host.name()).status.state
File "/usr/lib/python2.7/site-packages/ovirtsdk/infrastructure/brokers.py", line 18338, in get
headers={"All-Content":all_content}
File "/usr/lib/python2.7/site-packages/ovirtsdk/infrastructure/proxy.py", line 46, in get
return self.request(method='GET', url=url, headers=headers, cls=cls)
File "/usr/lib/python2.7/site-packages/ovirtsdk/infrastructure/proxy.py", line 122, in request
persistent_auth=self.__persistent_auth
File "/usr/lib/python2.7/site-packages/ovirtsdk/infrastructure/connectionspool.py", line 81, in do_request
raise errors.ConnectionError(error)
'[ERROR]::oVirt API connection failure, (7, \'TCP connection reset by peer\')\n-------------------- >> begin captured logging << --------------------\novirtlago.testlib: ERROR: * Unhandled exception in <function _host_is_up at 0x4dfad70>\nTraceback (most recent call last):\n File "/usr/lib/python2.7/site-packages/ovirtlago/testlib.py", line 219, in assert_equals_within\n res = func()\n File "/home/jenkins/workspace/ovirt-system-tests_hc-basic-suite-4.1/ovirt-system-tests/hc-basic-suite-4.1/test-scenarios/002_bootstrap.py", line 144, in _host_is_up\n cur_state = api.hosts.get(host.name()).status.state\n File "/usr/lib/python2.7/site-packages/ovirtsdk/infrastructure/brokers.py", line 18338, in get\n headers={"All-Content":all_content}\n File "/usr/lib/python2.7/site-packages/ovirtsdk/infrastructure/proxy.py", line 46, in get\n return self.request(method=\'GET\', url=url, headers=headers, cls=cls)\n File "/usr/lib/python2.7/site-packages/ovirtsdk/infrastructure/proxy.py", line 122, in request\n persistent_auth=self.__persistent_auth\n File "/usr/lib/python2.7/site-packages/ovirtsdk/infrastructure/connectionspool.py", line 81, in do_request\n raise errors.ConnectionError(error)\nConnectionError: [ERROR]::oVirt API connection failure, (7, \'TCP connection reset by peer\')\n--------------------- >> end captured logging << ---------------------'
7 years, 1 month