| *** bdpayne_ has joined #openstack-barbican | 00:01 | |
| *** bdpayne has quit IRC | 00:04 | |
| *** bdpayne_ has quit IRC | 00:14 | |
| *** kebray has quit IRC | 00:46 | |
| hockeynut | redrobot catching up on the notes here - I see the stuff about tempest. The direction I was given (need to rack my brain to recall where it came from) was that tests are now supposed to be in project repos, not tempest repos | 01:02 |
|---|---|---|
| hockeynut | and you are correct, it works just fine+dandy | 01:02 |
| hockeynut | there was some discussion that woodster_ sent around about experimental gate - that seems to be relevant here | 01:03 |
| *** kebray has joined #openstack-barbican | 01:26 | |
| *** nkinder has joined #openstack-barbican | 01:29 | |
| *** denis_makogon has quit IRC | 02:10 | |
| *** denis_makogon has joined #openstack-barbican | 02:10 | |
| *** openstackgerrit has quit IRC | 02:33 | |
| *** bdpayne has joined #openstack-barbican | 02:33 | |
| *** kaitlin-farr has quit IRC | 02:34 | |
| *** ayoung has quit IRC | 02:45 | |
| *** SheenaG1 has joined #openstack-barbican | 02:47 | |
| *** SheenaG11 has joined #openstack-barbican | 02:47 | |
| *** SheenaG1 has quit IRC | 02:51 | |
| *** ayoung has joined #openstack-barbican | 03:07 | |
| *** bdpayne has quit IRC | 03:12 | |
| *** bdpayne has joined #openstack-barbican | 03:12 | |
| *** ajc_ has joined #openstack-barbican | 03:22 | |
| *** openstack has joined #openstack-barbican | 03:41 | |
| *** denis_makogon has joined #openstack-barbican | 03:46 | |
| *** dolphm has joined #openstack-barbican | 03:46 | |
| *** hockeynut_ has joined #openstack-barbican | 03:46 | |
| *** xaeth_ has joined #openstack-barbican | 03:46 | |
| *** SheenaG1 has joined #openstack-barbican | 03:46 | |
| *** juantwo_ has joined #openstack-barbican | 03:46 | |
| *** ajc_ has joined #openstack-barbican | 03:46 | |
| *** ayoung has joined #openstack-barbican | 03:46 | |
| *** nkinder has joined #openstack-barbican | 03:46 | |
| *** kebray has joined #openstack-barbican | 03:46 | |
| *** arunkant has joined #openstack-barbican | 03:46 | |
| *** bubbva has joined #openstack-barbican | 03:46 | |
| *** gyee has joined #openstack-barbican | 03:46 | |
| *** woodster_ has joined #openstack-barbican | 03:46 | |
| *** rm_work has joined #openstack-barbican | 03:46 | |
| *** jenkins-keep has joined #openstack-barbican | 03:46 | |
| *** toabctl has joined #openstack-barbican | 03:46 | |
| *** ryanpetrello has joined #openstack-barbican | 03:46 | |
| *** jamielennox has joined #openstack-barbican | 03:46 | |
| *** jillysciarilly has joined #openstack-barbican | 03:46 | |
| *** alee has joined #openstack-barbican | 03:46 | |
| *** reaperhulk has joined #openstack-barbican | 03:46 | |
| *** lisaclar- has joined #openstack-barbican | 03:46 | |
| *** insequent has joined #openstack-barbican | 03:46 | |
| *** dougwig has joined #openstack-barbican | 03:46 | |
| *** codekobe___ has joined #openstack-barbican | 03:46 | |
| *** erw_ has joined #openstack-barbican | 03:46 | |
| *** jraim__ has joined #openstack-barbican | 03:46 | |
| *** sld has joined #openstack-barbican | 03:46 | |
| *** redrobot has joined #openstack-barbican | 03:46 | |
| *** hyakuhei has joined #openstack-barbican | 03:46 | |
| *** dstufft has joined #openstack-barbican | 03:46 | |
| *** russellb has joined #openstack-barbican | 03:46 | |
| *** rm_you has joined #openstack-barbican | 03:46 | |
| *** russell_h has joined #openstack-barbican | 03:46 | |
| *** jvrbanac has joined #openstack-barbican | 03:46 | |
| *** chellygel has joined #openstack-barbican | 03:46 | |
| *** lifeless has joined #openstack-barbican | 03:46 | |
| *** anteaya has joined #openstack-barbican | 03:46 | |
| *** d0ugal has joined #openstack-barbican | 03:46 | |
| *** dstanek has joined #openstack-barbican | 03:46 | |
| *** bdpayne has joined #openstack-barbican | 03:48 | |
| *** bdpayne has quit IRC | 03:50 | |
| *** woodster_ has quit IRC | 03:55 | |
| *** rm_work has quit IRC | 04:03 | |
| *** rm_work has joined #openstack-barbican | 04:08 | |
| *** rm_work is now known as rm_work|away | 04:08 | |
| *** juantwo_ has quit IRC | 04:41 | |
| *** bdpayne has joined #openstack-barbican | 05:05 | |
| *** ayoung has quit IRC | 05:10 | |
| *** gyee has quit IRC | 05:22 | |
| *** bdpayne has quit IRC | 05:23 | |
| *** jaosorior has joined #openstack-barbican | 06:04 | |
| *** kebray has quit IRC | 06:44 | |
| *** ajc__ has joined #openstack-barbican | 07:09 | |
| *** ajc_ has quit IRC | 07:10 | |
| *** ajc__ has quit IRC | 07:14 | |
| *** ajc_ has joined #openstack-barbican | 08:03 | |
| *** ajc_ has quit IRC | 08:05 | |
| *** ajc_ has joined #openstack-barbican | 08:07 | |
| *** ajc_ has quit IRC | 08:07 | |
| *** xianghuihui has joined #openstack-barbican | 08:45 | |
| *** xianghuihuihui has joined #openstack-barbican | 08:49 | |
| *** xianghuihui has quit IRC | 08:49 | |
| *** openstackgerrit has joined #openstack-barbican | 09:20 | |
| *** Guest22704 has joined #openstack-barbican | 10:32 | |
| *** xianghuihuihui has quit IRC | 10:40 | |
| *** Guest22704 has quit IRC | 11:03 | |
| *** denis_makogon has quit IRC | 11:59 | |
| *** denis_makogon has joined #openstack-barbican | 11:59 | |
| *** juantwo has joined #openstack-barbican | 12:08 | |
| *** SheenaG1 has quit IRC | 13:00 | |
| *** nkinder has quit IRC | 13:10 | |
| *** xaeth_ is now known as xaeth | 13:27 | |
| *** paul_glass has joined #openstack-barbican | 13:43 | |
| *** nkinder has joined #openstack-barbican | 13:59 | |
| *** Guest22704 has joined #openstack-barbican | 14:07 | |
| *** SheenaG1 has joined #openstack-barbican | 14:07 | |
| *** LarsN has joined #openstack-barbican | 14:15 | |
| *** jorge_munoz has joined #openstack-barbican | 14:22 | |
| *** lisaclark has joined #openstack-barbican | 14:34 | |
| *** atiwari has joined #openstack-barbican | 14:34 | |
| *** ayoung has joined #openstack-barbican | 14:37 | |
| openstackgerrit | Arvind Tiwari proposed a change to openstack/barbican: Add asymmtric order validator https://review.openstack.org/118697 | 14:41 |
| *** lisaclark has quit IRC | 14:52 | |
| *** SheenaG1 has quit IRC | 14:56 | |
| alee | atiwari, jvrbanac ping | 14:57 |
| atiwari | alee, yes | 14:57 |
| alee | atiwari, just to confirm, secrets are stored at the project (tenant) level, right? | 14:58 |
| atiwari | correct | 14:58 |
| alee | atiwari, did we ever make the change you suggested to restrict secret retrieval to the secret's owner? | 14:58 |
| atiwari | no, no one likes my that idea | 14:59 |
| atiwari | I still think we need it at some point of time | 14:59 |
| alee | atiwari, ok just confirming -- hard to remember what happened that long ago. | 15:00 |
| atiwari | k | 15:00 |
| alee | atiwari, I think we need a mechanism for solving this problem - just not sure that what you suggested is it | 15:00 |
| alee | worth revisiting in K. | 15:00 |
| atiwari | alee, I wd love to | 15:01 |
| *** paul_glass has quit IRC | 15:03 | |
| atiwari | alee, question | 15:04 |
| alee | atiwari, go ahead | 15:05 |
| atiwari | right now in config, passwords are in clear text. Thinking of adding infrastructure in Barbican system so that we can put encrypted password in config. | 15:06 |
| alee | atiwari, ok what did you have in mind? | 15:08 |
| atiwari | some how encryption and decryption is done by same barbican system which is going to use the password. | 15:08 |
| atiwari | in real deployment the config files will be controlled by chef like system and we can not have password in clear text | 15:09 |
| atiwari | bottom line is passwords should not be in clear text in config | 15:10 |
| atiwari | thoughts? | 15:10 |
| alee | atiwari, solving this problem is tricky - basically there will always be the need for at least one password to unlock the others. | 15:11 |
| alee | in dogtag/ rhcs , we have solved this in the past in a number of ways | 15:11 |
| alee | 1. storing the passwords in a nss db and requiring just the password for unlocking the db | 15:12 |
| atiwari | I think we can solve this by having a separate project specific to Barbican and unwrapping keys will be scoped to that will solve this issue | 15:12 |
| alee | 2. using a daemon to collect the password from a user on startup | 15:12 |
| alee | the tricky thing for us is that we needed to ensure 100% uptime, | 15:13 |
| alee | so that if the server went down and was restarted automatically, the passwords would be available. | 15:13 |
| alee | atiwari, forred hat cert server, for our customers that require compliance with STIGs etc. , we have https://fedorahosted.org/nuxwdog/ | 15:14 |
| alee | which is a daemon that collects and caches passwords in the kernel keyring | 15:15 |
| *** SheenaG1 has joined #openstack-barbican | 15:15 | |
| atiwari | correct, let me put more thoughts there | 15:15 |
| alee | atiwari, I've been meaning to revisit that to see if there are other ways of doing it, but that approach seems to be working rather well. | 15:16 |
| alee | (or at least not breaking) | 15:16 |
| atiwari | ok | 15:17 |
| alee | anyways - definitely scope for a whole separate design - maybe even separate project | 15:17 |
| atiwari | I think you are correct | 15:17 |
| atiwari | separate project like the idea :) | 15:18 |
| *** mikedillion has joined #openstack-barbican | 15:27 | |
| *** lisaclark has joined #openstack-barbican | 15:28 | |
| *** lisaclark has quit IRC | 15:28 | |
| *** lisaclark has joined #openstack-barbican | 15:28 | |
| *** SheenaG1 has quit IRC | 15:28 | |
| *** Guest22704 has quit IRC | 15:30 | |
| openstackgerrit | Arvind Tiwari proposed a change to openstack/barbican: Add asymmtric order validator https://review.openstack.org/118697 | 15:30 |
| *** SheenaG1 has joined #openstack-barbican | 15:31 | |
| *** woodster_ has joined #openstack-barbican | 15:41 | |
| *** bklei has joined #openstack-barbican | 15:42 | |
| jvrbanac | alee, what's up? | 15:43 |
| alee | jvrbanac, no worries - atiwari answered my question | 15:43 |
| jvrbanac | alee, k | 15:43 |
| *** Guest22704 has joined #openstack-barbican | 15:43 | |
| *** bklei has left #openstack-barbican | 15:43 | |
| *** lisaclark has quit IRC | 15:56 | |
| atiwari | alee, should add the secret isolation within a project per owner in https://etherpad.openstack.org/p/barbican-kilo-design-sessions? | 16:04 |
| *** paul_glass has joined #openstack-barbican | 16:04 | |
| alee | atiwari, sure -- I think we should add all the possible ideas | 16:05 |
| *** paul_glass1 has joined #openstack-barbican | 16:05 | |
| atiwari | OK, then I will add this | 16:05 |
| alee | atiwari, we'll have time to select from them for actual sessions/ informal sessions | 16:05 |
| redrobot | alee atiwari So the PTL for Keystone pretty much told us that doing that in Barbican would be really bad idea | 16:05 |
| redrobot | alee atiwari I don't see the need for continuing to discuss that for Barbican | 16:06 |
| redrobot | alee atiwari we should defer that functionality to Keystone. So this would make sense as a Keystone session, not for Barbican. | 16:06 |
| alee | redrobot, I'm not suggesting that the functionality necessarily need be in Barbican, only that a mechanism - keystone/policy / whatever - should probably be there. | 16:08 |
| *** paul_glass has quit IRC | 16:08 | |
| alee | if it makes sense as a keystone design session, then no prob | 16:08 |
| redrobot | alee I think we definitely need to get a better understanding of Keystone policy in barbican | 16:09 |
| redrobot | alee IIRC Aadm Young was concerned about the way our policy is set up now. | 16:09 |
| alee | yup - perhaps a design session around keystone policy in barbican then ? | 16:10 |
| redrobot | yeah, I think that would be very helpful. Especially if we can get a Keystone Policy SME to join us | 16:11 |
| alee | because we definitely need to understand what we can do/ what we cannot do/ and what we're missing. | 16:11 |
| alee | I then I can corrall ayoung | 16:11 |
| ayoung | alee, no one can corrall me | 16:11 |
| alee | ayoung, truer words were never spoken .. | 16:12 |
| ayoung | technically, those words weren't spoken either. I need to look into a Linux port of Dragon Speaking Naturally. | 16:12 |
| alee | redrobot, sorry - I've unleashed a monster .. | 16:13 |
| redrobot | lol | 16:13 |
| ayoung | redrobot, so we have a new feature that might make policy more interesting | 16:13 |
| ayoung | there is a the ability to assign a policy file to a specific endpoint | 16:13 |
| ayoung | now, Auth token middleware does not fetch policy files, so we can't really consume it yet. But 'yet' is the operative word | 16:14 |
| ayoung | redrobot, let me read up a bit...unles you can summarize the topic? | 16:14 |
| *** kebray has joined #openstack-barbican | 16:16 | |
| *** kebray has quit IRC | 16:16 | |
| atiwari | ayoung, in a nutshell we need ability to isolate secrets which are scoped to a single project based on owner. | 16:17 |
| ayoung | redrobot, OK, I think when atiwari and I disucssed this last summit, we were in accord. I've lost the braincells that held that particular discussion, though | 16:17 |
| redrobot | ayoung the discussion was that atiwari was suggesting that the check for this should happen in barbican | 16:18 |
| redrobot | ayoung and we agreed that this would be Keystone functionality bleeding into Barbican | 16:18 |
| redrobot | I'm interested in achieving that without adding authorization logic in barbican | 16:18 |
| *** kebray has joined #openstack-barbican | 16:19 | |
| *** kebray has joined #openstack-barbican | 16:19 | |
| *** kebray has quit IRC | 16:20 | |
| redrobot | It would be great if we can achieve it using Policy | 16:20 |
| atiwari | redrobot, I was proposing that has to be enforced by the policy engine running at Barbican | 16:20 |
| atiwari | and to support policy framework there has to be some improvement needed in Barbican. that was my proposal | 16:21 |
| *** kebray has joined #openstack-barbican | 16:21 | |
| redrobot | atiwari you do remember Dolph saying that the changes you proposed did not belong in Barbican, yes? | 16:21 |
| atiwari | yes | 16:21 |
| redrobot | ok, so I'd like to find a solution that Doplh and other Keystone folks agree is the correct way of doing things | 16:22 |
| atiwari | redrobot, but other projects like Nova is introducing the concept of owner in it (AFAIK) | 16:23 |
| atiwari | to handle Quota like use case | 16:23 |
| atiwari | redrobot, another topic | 16:24 |
| *** lisaclark has joined #openstack-barbican | 16:25 | |
| *** rm_work|away is now known as rm_work | 16:27 | |
| redrobot | alee atiwari Regarding the passwords in config files, we've already proposed a solution for this, however no progress has been made https://github.com/cloudkeep/postern | 16:28 |
| redrobot | alee atiwari for the general case, anyway... a bit of a chicken-and-egg problem for Barbican itself >_< | 16:29 |
| atiwari | redrobot, adding "Ability to manage master key encryption keys" to the etherpad. This will be a custom plugin but need some changes in models. | 16:31 |
| atiwari | let me know your thoughts? | 16:31 |
| redrobot | atiwari Are proposing adding a new class of plugins? Do you think there are enough different master key management strategies to justify such a plugin? It seems to me that if you have a specific need for a particular master key rotation scheme, then what you need to do is implement your own SecretStore. | 16:33 |
| redrobot | atiwari btw, did your talk get accepted? I forgot to ask when the emails went out. | 16:34 |
| atiwari | correct this will be customer secretstore, but it will be sharing the models and there we need some improvements. | 16:34 |
| atiwari | redrobot, No | 16:34 |
| redrobot | atiwari bummer :( | 16:43 |
| chellygel | hey alee -- would love to get your opinion: https://etherpad.openstack.org/p/barbican_metadata | 16:56 |
| chellygel | + all | 16:56 |
| *** kebray has quit IRC | 16:57 | |
| *** bdpayne has joined #openstack-barbican | 16:58 | |
| alee | chellygel, will look | 16:59 |
| chellygel | thank you! | 16:59 |
| *** lisaclark has quit IRC | 17:03 | |
| *** lisaclark has joined #openstack-barbican | 17:05 | |
| openstackgerrit | Constanze Kratel proposed a change to openstack/barbican: Update Getting Started Guide to include tech review feedback https://review.openstack.org/120156 | 17:10 |
| *** akoneru has joined #openstack-barbican | 17:11 | |
| openstackgerrit | Constanze Kratel proposed a change to openstack/barbican: removed whitespace from pom.xml https://review.openstack.org/120161 | 17:19 |
| *** paul_glass1 has quit IRC | 17:38 | |
| openstackgerrit | Constanze Kratel proposed a change to openstack/barbican: removed tenant id from code samples https://review.openstack.org/120163 | 17:38 |
| *** lisaclark has quit IRC | 17:41 | |
| *** lisaclark has joined #openstack-barbican | 17:46 | |
| *** gyee has joined #openstack-barbican | 17:46 | |
| alee | chellygel, woodster_ added a few comments on meta design | 17:46 |
| *** SheenaG1 has quit IRC | 17:47 | |
| chellygel | thanks alee ! will look :) | 17:47 |
| *** lisaclark has quit IRC | 18:00 | |
| *** lisaclark has joined #openstack-barbican | 18:04 | |
| *** lisaclark has quit IRC | 18:04 | |
| *** SheenaG1 has joined #openstack-barbican | 18:09 | |
| *** lisaclark has joined #openstack-barbican | 18:09 | |
| *** SheenaG11 has joined #openstack-barbican | 18:10 | |
| *** SheenaG1 has quit IRC | 18:13 | |
| *** paul_glass has joined #openstack-barbican | 18:25 | |
| *** jaosorior has quit IRC | 18:32 | |
| *** jaosorior has joined #openstack-barbican | 18:35 | |
| *** kebray has joined #openstack-barbican | 18:36 | |
| *** kebray has quit IRC | 18:36 | |
| *** kebray has joined #openstack-barbican | 18:37 | |
| *** Guest22704 has quit IRC | 18:46 | |
| *** Stanzi has joined #openstack-barbican | 18:47 | |
| *** ametts has joined #openstack-barbican | 19:00 | |
| *** Stanzi has quit IRC | 19:02 | |
| *** openstackgerrit has quit IRC | 19:02 | |
| *** paul_glass has quit IRC | 19:04 | |
| *** kebray has quit IRC | 19:12 | |
| rm_work | redrobot / woodster_: if one of you is not totally busy, could you pop into #openstack-keystone and at least monitor the conversation I'm having in there? | 19:16 |
| *** lisaclark has quit IRC | 19:33 | |
| *** lisaclark has joined #openstack-barbican | 19:34 | |
| *** openstackgerrit has joined #openstack-barbican | 19:41 | |
| *** kebray has joined #openstack-barbican | 19:44 | |
| *** kebray has quit IRC | 20:00 | |
| *** alee has quit IRC | 20:03 | |
| *** bubbva has quit IRC | 20:04 | |
| *** bubbva has joined #openstack-barbican | 20:04 | |
| *** kebray has joined #openstack-barbican | 20:08 | |
| *** alee has joined #openstack-barbican | 20:09 | |
| *** lisaclark has quit IRC | 20:10 | |
| *** lisaclark has joined #openstack-barbican | 20:11 | |
| *** mikedillion has quit IRC | 20:25 | |
| *** dolphm has left #openstack-barbican | 20:49 | |
| *** lisaclark has quit IRC | 20:59 | |
| *** lisaclark has joined #openstack-barbican | 21:00 | |
| atiwari | redrobot, yt? | 21:01 |
| *** jaosorior has quit IRC | 21:02 | |
| *** juantwo has quit IRC | 21:03 | |
| *** kebray has quit IRC | 21:10 | |
| *** lisaclark has quit IRC | 21:11 | |
| *** ametts has quit IRC | 21:13 | |
| *** kebray has joined #openstack-barbican | 21:13 | |
| *** kebray has quit IRC | 21:13 | |
| *** lisaclark has joined #openstack-barbican | 21:14 | |
| *** kebray has joined #openstack-barbican | 21:14 | |
| *** kebray has quit IRC | 21:14 | |
| redrobot | atiwari what's up? | 21:18 |
| atiwari | redrobot, can you please validate my https://review.openstack.org/#/c/110817/17/barbican/tasks/keystone_consumer.py | 21:23 |
| atiwari | I think this is not the correct way of extending the calss | 21:23 |
| atiwari | class | 21:23 |
| atiwari | method signature in sub class is modified | 21:23 |
| atiwari | wd you mind taking a quick look? | 21:24 |
| atiwari | redrobot, ^ | 21:24 |
| redrobot | atiwari will do | 21:24 |
| atiwari | redrobot, thanks for your time | 21:25 |
| atiwari | no rush though | 21:25 |
| jamielennox | hey all, 2 +2s on kite stuff: https://review.openstack.org/#/c/119692/2 and https://review.openstack.org/#/c/119693/ its just process stuff for the gate tests | 21:28 |
| jamielennox | can someone leave the +A? | 21:28 |
| *** kebray has joined #openstack-barbican | 21:34 | |
| redrobot | jamielennox done | 21:36 |
| jamielennox | redrobot: cheers | 21:36 |
| openstackgerrit | A change was merged to openstack/kite: Explicitly import _ translation function https://review.openstack.org/119692 | 21:37 |
| *** dolphm has joined #openstack-barbican | 21:43 | |
| *** akoneru is now known as akoneru_lunch | 21:46 | |
| *** SheenaG11 has quit IRC | 21:54 | |
| *** nkinder has quit IRC | 22:02 | |
| *** bdpayne_ has joined #openstack-barbican | 22:02 | |
| *** bdpayne has quit IRC | 22:03 | |
| *** kebray has quit IRC | 22:04 | |
| *** lisaclark has quit IRC | 22:05 | |
| *** kebray has joined #openstack-barbican | 22:15 | |
| *** ayoung has quit IRC | 22:16 | |
| *** kebray has quit IRC | 22:16 | |
| *** atiwari has quit IRC | 22:23 | |
| *** juantwo has joined #openstack-barbican | 22:28 | |
| *** juantwo has quit IRC | 22:30 | |
| *** jorge_munoz has quit IRC | 22:30 | |
| *** juantwo has joined #openstack-barbican | 22:31 | |
| *** kebray has joined #openstack-barbican | 22:35 | |
| *** akoneru_lunch is now known as akoneru | 22:43 | |
| *** kebray has quit IRC | 22:53 | |
| *** bdpayne_ has quit IRC | 23:11 | |
| *** bdpayne has joined #openstack-barbican | 23:13 | |
| *** nkinder has joined #openstack-barbican | 23:18 | |
| openstackgerrit | Arun Kant proposed a change to openstack/barbican: Adding keystone notification listener support https://review.openstack.org/110817 | 23:18 |
| *** ayoung has joined #openstack-barbican | 23:28 | |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!