Wednesday, 2021-10-13

rohit02hi team,We are deploying OSA Victoria with barbican plugin p11_crypto but where do we get these user defined library /opt/barbican/libs/libCryptoki2.so07:13
rohit02jrosser: noonedeadpunk: ,We are deploying OSA Victoria with barbican plugin p11_crypto but where do we get these user defined library /opt/barbican/libs/libCryptoki2.so07:15
jrosserrohit02: i think that library would be specific to a particular HSM for the PKCS#11 plugin?07:20
jrosserwhich secret store plugin are you wanting to use?07:21
rohit02jrosser: secret_store_plugin: store_crypto07:36
rohit02    crypto_plugin: p11_crypto07:36
noonedeadpunkrohit02: this lirary should be provided by HSM, yes07:38
noonedeadpunkso if we take thales luna network HSM, then when creating client for the service in THales, you will get client downloaded. While unpacking it you will find these libraries07:40
noonedeadpunkso this library is device-specific anyway afaik07:40
noonedeadpunkit also might have a bit different naming based on the HSM being used07:42
rohit02noonedeadpunk: means HSM is h/w device which provide u the library right?07:53
noonedeadpunkyep08:19
*** arxcruz is now known as arxcruz|rover08:48
*** arxcruz|rover is now known as arxcruz13:37
jamesdentonspatel around?14:17
opendevreviewMerged openstack/openstack-ansible stable/wallaby: Remove unnecessary pki step in haproxy install  https://review.opendev.org/c/openstack/openstack-ansible/+/81309914:46
spateljamesdenton give me few min.. dealing with production issue :)15:18
jamesdentonno worries15:23
opendevreviewJames Denton proposed openstack/openstack-ansible master: Remove OVN-related haproxy configuration  https://review.opendev.org/c/openstack/openstack-ansible/+/81385816:04
jrosserjamesdenton: i don't think that will remove them on a deployment, just won't add them in a new one16:06
jamesdentonthe haproxy configuration isn't overwritten?16:07
jrosserit drops a bunch of little files then glues them together for the total config16:07
jamesdentonahh ok, i didn't look. It's OK if they're there, just won't be used16:08
jamesdentoni can verify and add a note16:08
jrosserthere is a mechanism here https://github.com/openstack/openstack-ansible-haproxy_server/blob/96087b086749f293dde9fc4eaeee41fd9b514b47/tasks/haproxy_service_config.yml#L33-L4316:08
jrosseror indeed release note16:08
jamesdentonthank you16:10
jamesdentonhttps://github.com/openstack/openstack-ansible-haproxy_server/blob/96087b086749f293dde9fc4eaeee41fd9b514b47/tasks/haproxy_service_config.yml#L4016:14
jamesdentontypo?16:14
jamesdentonfalsy?16:15
jrosserthis? https://docs.ansible.com/ansible/latest/user_guide/playbooks_tests.html#testing-truthiness16:15
jamesdentongotcha, thanks16:16
mgariepylol. falsy is fun..16:45
mgariepyjamesdenton, https://review.opendev.org/c/openstack/openstack-ansible-haproxy_server/+/801910/2/tasks/haproxy_service_config.yml 16:55
jamesdenton:D16:55
mgariepylol. had the same reaction lol16:56
jamesdentoni'd never heard of it16:56
jamesdentonthat's why i defer to the experts!16:56
mgariepyi first heard of it on aug 24.. lol16:56
opendevreviewDmitriy Rabotyagov proposed openstack/openstack-ansible master: Fix manila haproxy manage  https://review.opendev.org/c/openstack/openstack-ansible/+/81388519:02
-opendevstatus- NOTICE: Both Gerrit and Zuul services are being restarted briefly for minor updates, and should return to service momentarily; all previously running builds will be reenqueued once Zuul is fully started again22:49

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!