From dev-return-2036-archive-asf-public=cust-asf.ponee.io@orc.apache.org Wed Apr 11 16:41:06 2018 Return-Path: X-Original-To: archive-asf-public@cust-asf.ponee.io Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by mx-eu-01.ponee.io (Postfix) with SMTP id 0491418064A for ; Wed, 11 Apr 2018 16:41:05 +0200 (CEST) Received: (qmail 8623 invoked by uid 500); 11 Apr 2018 14:41:05 -0000 Mailing-List: contact dev-help@orc.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@orc.apache.org Delivered-To: mailing list dev@orc.apache.org Received: (qmail 8601 invoked by uid 99); 11 Apr 2018 14:41:04 -0000 Received: from pnap-us-west-generic-nat.apache.org (HELO spamd4-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 11 Apr 2018 14:41:04 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd4-us-west.apache.org (ASF Mail Server at spamd4-us-west.apache.org) with ESMTP id F11E2C012B for ; Wed, 11 Apr 2018 14:41:03 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd4-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: 1.879 X-Spam-Level: * X-Spam-Status: No, score=1.879 tagged_above=-999 required=6.31 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=2, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=disabled Authentication-Results: spamd4-us-west.apache.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com Received: from mx1-lw-us.apache.org ([10.40.0.8]) by localhost (spamd4-us-west.apache.org [10.40.0.11]) (amavisd-new, port 10024) with ESMTP id OM1FL08YTQll for ; Wed, 11 Apr 2018 14:41:02 +0000 (UTC) Received: from mail-ot0-f182.google.com (mail-ot0-f182.google.com [74.125.82.182]) by mx1-lw-us.apache.org (ASF Mail Server at mx1-lw-us.apache.org) with ESMTPS id 64E8F5FD38 for ; Wed, 11 Apr 2018 14:41:02 +0000 (UTC) Received: by mail-ot0-f182.google.com with SMTP id p33-v6so2231260otp.11 for ; Wed, 11 Apr 2018 07:41:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to; bh=rp46UyGqDFEGy1lRcMIdMkuFBPzad3Z9RHDvEca0HwE=; b=LRrXSFzGEaUfIUfJwd/Afclp2baZe2HKgwp+yc0T2VZjEw06RnxB/MCaT+B676ug97 /k/N71uotVABaIEGreW7gmTRlKZzvp2r83hS2zNKkc3LegX3fLIWTRGF7YKcpa5Fht4r 1R8oiiCVkeCLgBAauFl/qvTTXQh5ZZlp3MPvT69k2xbuQRW+bCyZs22e9bK1zDOmtl+x +TgDLx64VOVhnuKpxy5MEaDohhKvwPt7GQzSu1repbeZSJ5yZ5Qi5RDqesrsouNJO6ot yf12eLyngmIYQ+UZT2f88Q3J8X9YF1Zv/MQAOQO4Flv0ExOed+3hwvBUIUE/eYWCHNyx y23Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to; bh=rp46UyGqDFEGy1lRcMIdMkuFBPzad3Z9RHDvEca0HwE=; b=N8NvjNHpt71EBJl/1/TNHmZhsNKeOZ6fGqenUBMc/VK2JVJ67ZvDT8mcaipizEXrX4 HWZgwOAX7H/nt0YBnRPSl/n3hisjPPY+LXxhsCM9CMNGfX3bRvjqI1qN9FvYkMO39vCA mXwASfDtQIskQbKpebrmoKo/6LA6WpRkr5gtLLJxGstl8vUa2362Bz8BVVT+wEOlJKgg topUzTMRw3Mt4Ep5T8GeWuy6f4cCtqR2Efp+NaCXP18GdzvMVZdHpSoGcbudT2ZZVr7w 1TXegSTSoUkZ07jFWaqKtNnjNmXeQ2wmyIZrKMhSWodCBn//2GmSSCaURonR94Ug1Jj/ z0wQ== X-Gm-Message-State: ALQs6tCNZ2wWP9lU0SoHf/owEXyIXz+Rug0efBVOJPwq/bIoy7e9KMPg Pja1JheasZuQn+rs5HVSMy05FuG6wU5oWIly1uvtFOf2 X-Google-Smtp-Source: AIpwx4+kbQL6xUsQu2TQF3lrRiFlXWrFgYdyHCoCszakSd7goQx6ONEc38X8NrsOFw0Vio+v9eqOawXFuSIWP2jd708= X-Received: by 2002:a9d:1150:: with SMTP id p16-v6mr3138377otp.209.1523457656086; Wed, 11 Apr 2018 07:40:56 -0700 (PDT) MIME-Version: 1.0 Received: by 2002:a9d:155b:0:0:0:0:0 with HTTP; Wed, 11 Apr 2018 07:40:55 -0700 (PDT) In-Reply-To: References: From: "Owen O'Malley" Date: Wed, 11 Apr 2018 07:40:55 -0700 Message-ID: Subject: Re: [PROPOSAL] Creating security list for ORC To: dev@orc.apache.org Content-Type: multipart/alternative; boundary="0000000000006be6e4056993a004" --0000000000006be6e4056993a004 Content-Type: text/plain; charset="UTF-8" The biggest advantage is that email to security@TLP.apache.org is automatically forwarded to security@apache.org allowing them to track the issues. It also allows the project to include committers who aren't PMC members on the list and makes it easier to search your email for the relevant problems. Thanks, Owen On Tue, Apr 10, 2018 at 1:56 PM, Matt Burgess wrote: > Alan, > > We have a separate security list on the NiFi PMC, and it is mostly for > opt-in and for localizing the archive so you can quickly search for > security stuff on the security list and not see it all show up on the > private list. There tends to be a decent amount of discussion around > security issues that can clutter the private list. Not making a > recommendation here, just sharing what I know :) > > Regards, > Matt > > > On Tue, Apr 10, 2018 at 4:01 PM, Alan Gates wrote: > > What's the benefit of having this separate from the private list? > > > > Alan. > > > > On Tue, Apr 10, 2018 at 11:15 AM, Owen O'Malley > > wrote: > > > >> I'd like to move forward on this. Any comments? > >> > >> On Fri, Dec 1, 2017 at 1:40 PM, Owen O'Malley > >> wrote: > >> > >> > All, > >> > I think as we add column encryption in ORC-14, we'll need to start > >> > handling security issues. I think it would be good to create a > security > >> > list and policy before we need it. > >> > > >> > Thoughts? > >> > > >> > .. Owen > >> > > >> > --0000000000006be6e4056993a004--