CTI TAC Meeting Notes 2024-11-27

Carlos O'Donell <[email protected]> Mon, 2 Dec 2024 15:09:27 -0500
Newsgroups org.linuxfoundation.lists.cti-tac
Organization Red Hat
Message-ID <[email protected]>
​CTI TAC Meeting Notes 2024-11-27

Present:
 * Carlos O'Donell, Joseph Myers, David Edelsohn.

 Agenda:
 * Carlos: From previous meeting we now have glibc "passing" https://www.bestpractices.dev/en/projects/9644
  * Should discuss silver and gold review from last meeting and if they have infrastructure impact.
  * No binutils, or gdb.
  * Not all items were easy to check off.
 * Carlos: Still writing updates for the glibc community.
  * https://sourceware.org/glibc/wiki/CTI
  * https://sourceware.org/glibc/wiki/CTI/Policy/glibc
 * Questions for the TAC:
  * In writing up the 4 practices as defined in NIST SP 800-281, I naturally get to a place where we must document what it is that we we want from the services e.g. isolated services in distinct VMs that provide freedom from interference with other services. This yields a kind of axiomatic start to the whole process. Is this OK? I will assume it is OK, since we want state of the art secure infrastructure. This requires making some statements on behalf of glibc that we want particular things e.g. bugzilla harmony in a distinct VM.
  * [joseph] We should distinguish from external requirements made by standards such as NIST and how we interpret those requirements.
  * [joseph] Do we have documents we can point to that show that process/cgroup/namespace isolation is insufficient?
  * [carlos] Yes, there are other documents that describe best practices. We could leverage NIST SP 800-207 and ask for best-case zero trust architecture where we don't trust the kernel running hte services just like we would not trust the network. Thus we are asking for VMs for the services.
 * [david] Brainstorm having a discussion with a variety of stakeholders beyond the CTI TAC that can make their support shown. Discuss how that support is shown in various venues e.g. mailing lists, talks, industry meetings, customer meetings etc.
 * Next steps:
  * AI: Carlos to complete and publisize the glibc notes about specific NIST SSDF steps. (in progress)
  * AI: Siddhesh to look at GCC and OpenSSF Best Practices badge and infrastructure requirements. (status?)

-- 
Cheers,
Carlos.