openstackgerrit | Venkat Sundaram proposed a change to openstack/python-barbicanclient: remove tenant-id from uri https://review.openstack.org/112149 | 00:01 |
---|---|---|
*** nkinder has quit IRC | 00:10 | |
*** gyee has quit IRC | 00:25 | |
*** bdpayne has quit IRC | 00:58 | |
*** xianghuihui has quit IRC | 01:21 | |
*** woodster_ has quit IRC | 01:25 | |
*** xianghui has joined #openstack-barbican | 01:26 | |
*** xianghui has quit IRC | 01:34 | |
*** xianghuihui has joined #openstack-barbican | 01:34 | |
*** nkinder has joined #openstack-barbican | 01:51 | |
*** bdpayne has joined #openstack-barbican | 02:20 | |
*** juantwo has quit IRC | 02:23 | |
*** juantwo has joined #openstack-barbican | 02:24 | |
*** blpoulos_ has quit IRC | 02:36 | |
*** akoneru_afk has quit IRC | 03:31 | |
*** crc32 has quit IRC | 03:41 | |
*** woodster_ has joined #openstack-barbican | 03:44 | |
hockeynut | tsv can we abandon https://review.openstack.org/#/c/100141/ (tenant ID from uri validation in rbac) since https://review.openstack.org/#/c/112149/ (remove tenant ID from url) is almost ready? | 04:01 |
*** jamielen- has joined #openstack-barbican | 05:07 | |
*** jamielennox has quit IRC | 05:08 | |
*** jamielen- is now known as jamielennox | 05:15 | |
openstackgerrit | A change was merged to openstack/barbican: autodoc import error for plugin.rst https://review.openstack.org/112390 | 05:22 |
*** bdpayne has quit IRC | 05:33 | |
openstackgerrit | Ravi Sankar Penta proposed a change to openstack/barbican: Install sqlite-devel package on fedora https://review.openstack.org/113404 | 05:34 |
*** bdpayne has joined #openstack-barbican | 05:35 | |
*** juantwo has quit IRC | 05:36 | |
*** jamielen| has joined #openstack-barbican | 05:44 | |
*** jamielen| has quit IRC | 05:44 | |
*** woodster_ has quit IRC | 05:45 | |
*** jamielen| has joined #openstack-barbican | 05:45 | |
*** jamielen| has quit IRC | 05:45 | |
*** jamielennox has quit IRC | 05:46 | |
*** jamielennox has joined #openstack-barbican | 05:47 | |
openstackgerrit | Ravi Sankar Penta proposed a change to openstack/barbican: Install sqlite-devel package on fedora https://review.openstack.org/113404 | 05:47 |
*** alee_out has quit IRC | 05:51 | |
*** bdpayne has quit IRC | 05:58 | |
*** jamielen- has joined #openstack-barbican | 06:01 | |
*** jamielennox has quit IRC | 06:05 | |
openstackgerrit | OpenStack Proposal Bot proposed a change to openstack/barbican: Imported Translations from Transifex https://review.openstack.org/112764 | 06:09 |
*** jaosorior has joined #openstack-barbican | 07:29 | |
*** jamielen- is now known as jamielennox|away | 08:24 | |
*** erw has quit IRC | 09:46 | |
*** codekobe_ has quit IRC | 09:49 | |
*** jraim has quit IRC | 09:51 | |
*** erw has joined #openstack-barbican | 09:52 | |
*** jaosorior has quit IRC | 09:52 | |
*** codekobe_ has joined #openstack-barbican | 09:53 | |
*** jraim has joined #openstack-barbican | 09:54 | |
*** jaosorior has joined #openstack-barbican | 09:57 | |
*** erw has quit IRC | 09:57 | |
*** codekobe_ has quit IRC | 09:58 | |
*** codekobe_ has joined #openstack-barbican | 10:01 | |
*** erw has joined #openstack-barbican | 10:01 | |
*** jamielennox|away has quit IRC | 11:34 | |
*** jamielennox|away has joined #openstack-barbican | 11:37 | |
*** SheenaG1 has joined #openstack-barbican | 12:31 | |
*** alee has joined #openstack-barbican | 13:01 | |
*** SheenaG1 has quit IRC | 13:09 | |
*** nkinder has quit IRC | 13:11 | |
*** SheenaG1 has joined #openstack-barbican | 13:13 | |
openstackgerrit | John Wood proposed a change to openstack/barbican-specs: Add Version Responses Consistent with Openstack https://review.openstack.org/108163 | 13:22 |
*** SheenaG1 has quit IRC | 13:26 | |
*** ayoung has joined #openstack-barbican | 13:32 | |
*** akoneru has joined #openstack-barbican | 13:34 | |
openstackgerrit | John Wood proposed a change to openstack/barbican-specs: Add Version Responses Consistent with Openstack https://review.openstack.org/108163 | 13:38 |
*** gerchardon has quit IRC | 13:48 | |
*** gerchardon has joined #openstack-barbican | 13:48 | |
*** nkinder has joined #openstack-barbican | 13:56 | |
*** juantwo has joined #openstack-barbican | 14:03 | |
*** juantwo has quit IRC | 14:03 | |
*** juantwo has joined #openstack-barbican | 14:03 | |
*** SheenaG1 has joined #openstack-barbican | 14:05 | |
openstackgerrit | Juan Antonio Osorio Robles proposed a change to openstack/barbican: Refactor secret_store for cosistency https://review.openstack.org/113531 | 14:05 |
*** SheenaG11 has joined #openstack-barbican | 14:10 | |
*** SheenaG1 has quit IRC | 14:11 | |
openstackgerrit | Kaitlin Farr proposed a change to openstack/barbican: Adds KMIPSecretStore and unit tests https://review.openstack.org/101582 | 14:16 |
*** SheenaG11 has quit IRC | 14:27 | |
jaosorior | alee: ping | 14:45 |
alee | jaosorior, pong | 14:46 |
*** SheenaG1 has joined #openstack-barbican | 14:46 | |
jaosorior | alee: regarding the CR 113531 . so, you're thinking that lines 420-421, 466-467 are not needed? what about 449-450? | 14:48 |
*** SheenaG11 has joined #openstack-barbican | 14:49 | |
jaosorior | alee: and also, I think the else statements should stay, since it becomes more explicit that the exception would be raised if the for doesn't return | 14:50 |
*** SheenaG1 has quit IRC | 14:51 | |
alee | jaosorior, yeah - 449-450 shoudl go too. | 14:51 |
*** paul_glass has joined #openstack-barbican | 14:53 | |
alee | jaosorior, I tend to favor more concise code. I'm ok with being overruled if there is a consensus think having the else is clearer. | 14:53 |
jaosorior | alee: Seems Kaitlin has a different opinion about the length check of the extensions. | 14:55 |
jaosorior | If the check if useful to someone, should it then be kept? | 14:56 |
alee | jaosorior, you didn't think your 3 line change was going to be so contentious :) | 14:58 |
jaosorior | I didn't | 14:58 |
jaosorior | as a matter of fact I started coding just after the workshop that I'm attending, thinking it would be a pretty easy change. But I'm really glad to see people reviewing stuff and and having thought in how things should be done :D | 14:59 |
jaosorior | now, hopefully we can get to a consensus before I go off the computer with the guys from the workshop | 15:00 |
jaosorior | for some goooood beers :D | 15:00 |
alee | jaosorior, I think a few of us have been in that code quite a bit recently - and so have formed opinions on how things should be done. | 15:03 |
jaosorior | hockeynut: ping | 15:13 |
hockeynut | greetings sir! | 15:14 |
jaosorior | yo Mr.! what's up? | 15:14 |
hockeynut | another day, another euro | 15:14 |
jaosorior | hey man, you mentioned using a decorator for this length check, and I dig that idea, just haven't figured out a good name for it, can you help? | 15:15 |
hockeynut | hmm...must think about that | 15:17 |
jaosorior | @_extensions_should_be_configured ? | 15:18 |
hockeynut | trying to see if I can come up with anything better than that - so far no, I like yours | 15:25 |
openstackgerrit | Juan Antonio Osorio Robles proposed a change to openstack/barbican: Refactor secret_store for consistency https://review.openstack.org/113531 | 15:29 |
hockeynut | enforce_configured_extensions perhaps? | 15:34 |
jaosorior | enforce_extensions_configured? | 15:35 |
hockeynut | ooh - even better | 15:35 |
hockeynut | + oo | 15:35 |
jaosorior | awesum | 15:37 |
openstackgerrit | Juan Antonio Osorio Robles proposed a change to openstack/barbican: Refactor secret_store for consistency https://review.openstack.org/113531 | 15:38 |
*** woodster_ has joined #openstack-barbican | 15:44 | |
openstackgerrit | A change was merged to openstack/barbican: Replace hard-coded setup version setting https://review.openstack.org/109580 | 15:53 |
openstackgerrit | Juan Antonio Osorio Robles proposed a change to openstack/barbican: Refactor secret_store for consistency https://review.openstack.org/113531 | 15:58 |
woodster_ | I'm curious about this CR to add a SQLite dep if it is a Fedora install: https://review.openstack.org/#/c/113404 I thought Devstack used MySQL under the hood and not SQLite? | 15:59 |
*** paul_glass1 has joined #openstack-barbican | 16:02 | |
*** paul_glass has quit IRC | 16:03 | |
*** paul_glass has joined #openstack-barbican | 16:04 | |
jaosorior | off now :D | 16:04 |
*** paul_glass1 has quit IRC | 16:07 | |
*** paul_glass has quit IRC | 16:23 | |
openstackgerrit | Christian Berendt proposed a change to stackforge/kite: Bump hacking to version 0.9.2 https://review.openstack.org/107421 | 16:25 |
*** lecalcot has joined #openstack-barbican | 16:29 | |
*** paul_glass has joined #openstack-barbican | 16:37 | |
*** bdpayne has joined #openstack-barbican | 16:41 | |
*** paul_glass1 has joined #openstack-barbican | 17:03 | |
*** paul_glass1 is now known as paul_glass_ | 17:04 | |
*** paul_glass has quit IRC | 17:06 | |
*** kaitlin-farr has joined #openstack-barbican | 17:08 | |
alee | woodster_, ping | 17:12 |
alee | dstufft, ping | 17:13 |
dstufft | alee: hello | 17:13 |
woodster_ | alee: hello | 17:15 |
alee | woodster_, dstufft - just wondering if any code has been written to add certificates to the api level? | 17:15 |
alee | woodster_, dstufft - that is -- I have reviewed arvind's changes but they are for adding containers and typed orders -- all needed things .. | 17:16 |
alee | but nothing that I can tell to implement .. | 17:16 |
alee | https://review.openstack.org/#/c/108429 | 17:16 |
alee | woodster_, dstufft - of course the spec is still in review, but I was wondering if anyone had started working on the implementation? | 17:18 |
dstufft | I dunno | 17:18 |
woodster_ | That is what this CR is doing: https://review.openstack.org/#/c/87405 | 17:18 |
alee | dstufft, sorry I thought you had been working on this :) | 17:18 |
alee | woodster_, there is nothing in that CR about certificate requests etc. unless I'm missing something .. | 17:19 |
alee | woodster_, in facte, most of the cert request stuff is place holdered as not implemented | 17:20 |
alee | woodster_, am I just totally confused? | 17:22 |
woodster_ | So https://review.openstack.org/#/c/87405 needs to get the revamped orders type/meta stuff in place first | 17:22 |
alee | yup - understood. its needed first. | 17:23 |
woodster_ | Then we planned to follow up Chelsea's CR (that added the certificate stuff) on top of that orders update | 17:23 |
woodster_ | that's why I've been curious if arvind was still working on that CR or not :) | 17:23 |
alee | woodster_, and that follow up CR will implement https://review.openstack.org/#/c/108429 ? | 17:24 |
woodster_ | The overall plan was to follow the work items in this blueprint: https://review.openstack.org/#/c/99221/8/specs/juno/orders-add-cert-workflow-plugin.rst,cm | 17:25 |
woodster_ | So it seems that https://review.openstack.org/#/c/108429 is refining that original blueprint, refining the actual meta parameters passed into certificate-type orders | 17:27 |
alee | right -- I just wanted to be clear on where things were. I have added a bunch of comments to https://review.openstack.org/#/c/108429 on the assumption that this is what would be used. | 17:27 |
woodster_ | I'll add a comment to that CR now to reference the original blueprint. I think the bottom line is we probably do need to standardize on some of the key/value info in the meta block of certificate orders...things all CA plugin vendors can agree on so to speak. | 17:28 |
woodster_ | Some of that data will be specific to a certificate type (and so probably to an issuer/CA/vendor plugin) | 17:29 |
alee | woodster_, yes - thats why I'm so interested .. | 17:29 |
alee | woodster_, it was a little surprising to me that we could write this --> https://review.openstack.org/#/c/110144/19/barbican/plugin/symantec.py,cm | 17:30 |
alee | woodster_, given that we don't know yet whats in the order_meta object coming in | 17:30 |
*** paul_glass_ has quit IRC | 17:30 | |
*** gyee has joined #openstack-barbican | 17:31 | |
alee | lines 143 - 152 have a bunch of fields which would be nice perhaps, but have not been defined yet. | 17:32 |
alee | and certainly are not all specified in the api. | 17:32 |
*** gyee has quit IRC | 17:34 | |
alee | and are very symantec specific -- things like partnercode and productcode .. what are these? | 17:34 |
*** lecalcot has quit IRC | 17:43 | |
woodster_ | alee: those are good points all, but I'm wondering what is the best process for determining just what *is* generic across cert plugin impls? Or is that too lofty a goal and we just fall back on a issuer/vendor field that is the criteria for selecting a plugin? | 17:50 |
*** paul_glass has joined #openstack-barbican | 17:53 | |
alee | woodster_, yeah - I think there are specific things that you are going to want to ask for - and https://review.openstack.org/#/c/108429 is an attempt to identify those. | 17:54 |
alee | those will map to certain fields | 17:55 |
alee | which can be passed into the plugins | 17:55 |
woodster_ | alee: I just added a comment to that bp asking for clarification from Stanislaw...I don't know his IRC handle | 17:55 |
alee | and the plugins will be responsible for breaking them out into whatever fields they need. | 17:55 |
alee | woodster_, I think we can make a credible start to this by limiting the initial implementation to specific types of certs. | 17:56 |
*** gyee has joined #openstack-barbican | 17:56 | |
alee | like ssl server certs say .. | 17:56 |
alee | and then go on from there. | 17:57 |
alee | woodster_, on the other hand, I suppose we could just fall back on issue/plugin specific metadata | 17:58 |
alee | woodster_, that would allow barbican to essentially be just a router above the ca's .. | 17:59 |
alee | woodster_, but it means that end users would have to know how to use symantec or dogtag or .. whatever .. | 18:00 |
*** gchardon has joined #openstack-barbican | 18:02 | |
alee | woodster_, was your original intention a issuer/vendor specific metadata? | 18:04 |
*** alee is now known as alee_lunch | 18:05 | |
gchardon | hi guys, someone can explain me why the workflow didnt launch https://review.openstack.org/#/c/112845/ (i tried to add a review 0 score) , thanks | 18:05 |
*** jamielennox|away is now known as jamielennox | 18:06 | |
woodster_ | gchardon: that CR needs a workflow +1....any core folks out there that can review/approve this CR?: https://review.openstack.org/#/c/112845 | 18:07 |
gchardon | woodster_: ok, i thinks it would be launch automatically when i add enough review , thanks | 18:08 |
woodster_ | gchardon: we've been requiring two +2s and a workflow +1 to merge things. I think the workflow +1 is the minimum required by gerrit to merge things | 18:10 |
*** jaosorior has quit IRC | 18:12 | |
*** juantwo has quit IRC | 18:15 | |
*** gchardon has quit IRC | 18:20 | |
*** gchardon has joined #openstack-barbican | 18:29 | |
openstackgerrit | A change was merged to openstack/barbican: Clean old comments (already implemented) https://review.openstack.org/112845 | 18:32 |
*** crc32 has joined #openstack-barbican | 18:32 | |
*** crc32 has quit IRC | 18:33 | |
*** crc32 has joined #openstack-barbican | 18:34 | |
*** ayoung has quit IRC | 18:36 | |
*** alee_lunch is now known as alee | 18:48 | |
*** lecalcot has joined #openstack-barbican | 18:52 | |
*** alee is now known as alee_afk | 19:39 | |
*** alee_afk has quit IRC | 19:43 | |
*** ayoung has joined #openstack-barbican | 19:46 | |
*** paul_glass has quit IRC | 19:59 | |
openstackgerrit | Venkat Sundaram proposed a change to openstack/barbican: remove project-id from resource URIs https://review.openstack.org/105562 | 20:17 |
*** paul_glass has joined #openstack-barbican | 20:27 | |
*** paul_glass has quit IRC | 20:37 | |
*** crc32 has quit IRC | 20:38 | |
*** paul_glass has joined #openstack-barbican | 20:40 | |
*** paul_glass1 has joined #openstack-barbican | 20:54 | |
*** paul_glass has quit IRC | 20:57 | |
*** SheenaG11 has quit IRC | 20:58 | |
*** paul_glass1 is now known as paul_glass | 21:05 | |
*** akoneru is now known as akoneru_afk | 21:19 | |
*** alee has joined #openstack-barbican | 21:19 | |
*** lecalcot has quit IRC | 21:20 | |
*** juantwo has joined #openstack-barbican | 21:21 | |
*** juantwo has quit IRC | 21:22 | |
*** juantwo has joined #openstack-barbican | 21:23 | |
*** nkinder has quit IRC | 21:28 | |
*** crc32 has joined #openstack-barbican | 21:36 | |
*** akoneru has joined #openstack-barbican | 21:51 | |
*** paul_glass has quit IRC | 21:57 | |
openstackgerrit | Venkat Sundaram proposed a change to openstack/barbican: remove project-id from resource URIs https://review.openstack.org/105562 | 22:18 |
*** kaitlin-farr has quit IRC | 22:28 | |
*** gchardon has quit IRC | 22:32 | |
openstackgerrit | Venkat Sundaram proposed a change to openstack/barbican: remove project-id from resource URIs https://review.openstack.org/105562 | 22:50 |
*** bdpayne has quit IRC | 22:57 | |
*** bdpayne has joined #openstack-barbican | 22:59 | |
*** bdpayne_ has joined #openstack-barbican | 23:01 | |
*** bdpayne has quit IRC | 23:04 | |
*** juantwo has quit IRC | 23:18 | |
*** bdpayne_ has quit IRC | 23:54 | |
*** bdpayne has joined #openstack-barbican | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!