*** gyee has quit IRC | 00:20 | |
*** zz_dimtruck is now known as dimtruck | 00:26 | |
*** juantwo_ has joined #openstack-barbican | 00:31 | |
*** juantwo_ has quit IRC | 00:32 | |
*** juantwo_ has joined #openstack-barbican | 00:32 | |
*** juantwo has quit IRC | 00:33 | |
*** dimtruck is now known as zz_dimtruck | 01:00 | |
*** jamielennox has joined #openstack-barbican | 01:54 | |
*** zz_dimtruck is now known as dimtruck | 02:06 | |
*** kebray has joined #openstack-barbican | 02:09 | |
*** kebray has quit IRC | 02:09 | |
*** kebray has joined #openstack-barbican | 02:10 | |
*** woodster_ has quit IRC | 02:21 | |
*** ryanpetrello has quit IRC | 03:14 | |
*** ryanpetrello has joined #openstack-barbican | 03:15 | |
*** dimtruck is now known as zz_dimtruck | 03:21 | |
*** kebray has quit IRC | 03:28 | |
*** kebray has joined #openstack-barbican | 03:33 | |
*** kebray has quit IRC | 03:40 | |
*** kebray has joined #openstack-barbican | 03:40 | |
*** ajc_ has joined #openstack-barbican | 03:50 | |
*** juantwo_ has quit IRC | 04:49 | |
*** zz_dimtruck is now known as dimtruck | 05:03 | |
*** jamielennox has quit IRC | 05:29 | |
*** kebray has quit IRC | 05:34 | |
*** ajc_ has quit IRC | 05:36 | |
*** jamielennox has joined #openstack-barbican | 05:40 | |
*** rm_you| has joined #openstack-barbican | 05:56 | |
*** rm_you|wtf has quit IRC | 06:00 | |
*** dimtruck is now known as zz_dimtruck | 06:37 | |
*** jaosorior has joined #openstack-barbican | 09:44 | |
openstackgerrit | Juan Antonio Osorio Robles proposed a change to openstack/barbican: Delete usage-indications from the model docstrings https://review.openstack.org/125050 | 09:46 |
---|---|---|
*** openstack has joined #openstack-barbican | 14:12 | |
*** rtom has joined #openstack-barbican | 14:13 | |
*** openstackstatus has joined #openstack-barbican | 14:13 | |
*** ChanServ sets mode: +v openstackstatus | 14:13 | |
*** JeffF has joined #openstack-barbican | 14:17 | |
*** kebray has quit IRC | 14:18 | |
*** juantwo has quit IRC | 14:19 | |
*** juantwo has joined #openstack-barbican | 14:20 | |
*** tdink_ has joined #openstack-barbican | 14:24 | |
*** tdink has quit IRC | 14:25 | |
*** tdink_ has quit IRC | 14:28 | |
*** tdink has joined #openstack-barbican | 14:28 | |
*** ametts has joined #openstack-barbican | 14:30 | |
*** zz_dimtruck is now known as dimtruck | 14:36 | |
*** paul_glass has quit IRC | 14:59 | |
*** joesavak has quit IRC | 15:01 | |
*** dimtruck is now known as zz_dimtruck | 15:03 | |
*** zz_dimtruck is now known as dimtruck | 15:05 | |
*** joesavak has joined #openstack-barbican | 15:30 | |
*** juantwo has quit IRC | 15:56 | |
*** juantwo has joined #openstack-barbican | 15:58 | |
*** juantwo has quit IRC | 16:03 | |
*** juantwo has joined #openstack-barbican | 16:03 | |
*** arunkant_work has joined #openstack-barbican | 16:14 | |
*** woodster_ has joined #openstack-barbican | 16:16 | |
*** kebray has joined #openstack-barbican | 16:24 | |
arunkant_work | woodster_, redrobot: Does this require more review https://review.openstack.org/#/c/110817/ before it can be merged? | 16:25 |
*** tdink_ has joined #openstack-barbican | 16:26 | |
*** tdink has quit IRC | 16:28 | |
*** juantwo has quit IRC | 16:45 | |
*** juantwo has joined #openstack-barbican | 16:50 | |
*** jraim has joined #openstack-barbican | 17:03 | |
woodster_ | arunkant_work: not from me :) I'll try to get ahold of redrobot for review though | 17:16 |
*** mkam has joined #openstack-barbican | 17:19 | |
*** alee_afk is now known as alee | 17:35 | |
*** kebray_ has joined #openstack-barbican | 17:35 | |
*** kebray has quit IRC | 17:38 | |
*** jsavak has joined #openstack-barbican | 17:46 | |
*** kgriffs is now known as kgriffs|afk | 17:46 | |
*** joesavak has quit IRC | 17:49 | |
redrobot | arunkant_work merged. Thanks for being so patient with this CR | 17:55 |
openstackgerrit | A change was merged to openstack/barbican: Adding keystone notification listener support https://review.openstack.org/110817 | 18:09 |
openstackgerrit | A change was merged to openstack/barbican: Delete usage-indications from the model docstrings https://review.openstack.org/125050 | 18:09 |
rm_work | will you look at that, jaosorior and woodster_ have both given me positive reviews on https://review.openstack.org/#/c/124889/ | 18:12 |
rm_work | awesome | 18:12 |
rm_work | seems like it'd just require a couple of others now :) | 18:12 |
redrobot | rm_work I'm on it | 18:14 |
rm_work | :P | 18:14 |
*** jaosorior has quit IRC | 18:23 | |
*** jaosorior has joined #openstack-barbican | 18:29 | |
*** jsavak has quit IRC | 18:31 | |
*** joesavak has joined #openstack-barbican | 18:32 | |
*** kgriffs|afk is now known as kgriffs | 18:35 | |
*** gyee has joined #openstack-barbican | 18:41 | |
*** kgriffs is now known as kgriffs|afk | 18:45 | |
*** tdink_ has quit IRC | 18:47 | |
*** bubbva has quit IRC | 18:56 | |
*** bubbva has joined #openstack-barbican | 18:56 | |
hockeynut | rm_work - code looks good, a few comments on the comments. if you're going to push up another changeset then feel free to handle 'em :-) | 18:58 |
rm_work | lol nice, love comment/docstring typods | 18:59 |
rm_work | *typos | 18:59 |
rm_work | I | 18:59 |
rm_work | *I'll do those if people promise to look at it again soon :P | 18:59 |
redrobot | rm_work so hopeful that people are actually looking at his code... | 19:00 |
rm_work | hockeynut: what would the docstring for "payload_content_type" be? "The content type for the payload"? :P | 19:02 |
rm_work | oh, "Content type to use for payload decryption"? | 19:02 |
hockeynut | either of them are ok - we were just missing that 1 parameter | 19:03 |
hockeynut | "content type for people who are into that sort of thing" :-) | 19:03 |
rm_work | also, for docstrings, which is correct: no blank line before text, or one blank before text? | 19:03 |
rm_work | IE: | 19:03 |
rm_work | """Firstline | 19:03 |
rm_work | """ | 19:04 |
rm_work | Firstline | 19:04 |
rm_work | right now it's mixed | 19:04 |
redrobot | no blank line for single line docstring | 19:12 |
redrobot | blank line for a multiline docstring | 19:12 |
redrobot | I _think_ | 19:12 |
dolphm | so, how scary would it be if barbican got a read hit for every request into OpenStack, and at every service-to-service boundary? | 19:13 |
dolphm | for every HTTP request crossing a service-to-service boundary* | 19:14 |
reaperhulk | how scary is it to have a distributed service oriented architecture that has a centralized dependency that must be bigger than all other services combined? (I would say that's very scary) | 19:14 |
reaperhulk | I suppose as a former keystone PTL such critical path dependencies are not new to you though :) | 19:15 |
*** paul_glass has joined #openstack-barbican | 19:16 | |
dolphm | yeah... i'm staring down a long dark path at the moment | 19:17 |
openstackgerrit | Adam Harwell proposed a change to openstack/python-barbicanclient: Fix consistency between Order/Secret/Container https://review.openstack.org/124889 | 19:19 |
rm_work | hockeynut: addressed and more :) | 19:20 |
rm_work | fixed some more inconsistencies | 19:20 |
rm_work | (in docstrings) | 19:20 |
rm_work | woodster_: re-re-re-re-re-review :) | 19:20 |
hockeynut | sweet! | 19:20 |
hockeynut | woodster_ you stutter when you type | 19:20 |
* redrobot flips table | 19:20 | |
redrobot | I was about to +2, now I have to start over | 19:20 |
rm_work | redrobot: :P | 19:20 |
redrobot | rm_work It's actually looking pretty nice | 19:21 |
rm_work | redrobot: you should have told hockeynut to knock it off before he brought that to my attention :P | 19:21 |
hockeynut | (running and hiding) | 19:21 |
redrobot | my only beef is that exceptions from 400s don't include the returned error string. Not a big deal though, I can add that functionality later. | 19:21 |
rm_work | hmm | 19:21 |
rm_work | yes, well | 19:21 |
rm_work | exceptions in general are screwed right now if it comes from the server | 19:21 |
rm_work | because I have NO earthly idea what the message is | 19:22 |
rm_work | because the keystone layer eats it and throws its own exception | 19:22 |
rm_work | if you're talking about what I think you're talking about | 19:22 |
rm_work | I thought *you* were looking at fixing that particular issue :) | 19:23 |
redrobot | I'm just having to refer to barbican logs to figure out why the 400s are being thrown... would be nicer if we actually told the client how the fubared it... but yeah, not going to make you do that for this patch | 19:23 |
rm_work | yeah, because I don't even know, I have to infer what the issue probably is based on where in the sequence the exception happened | 19:24 |
rm_work | since all I get is a generic exception raised from the middleware layer not being able to parse the real error that came back | 19:24 |
rm_work | because it expects Keystone's error format | 19:24 |
rm_work | again, that's if you're talking about what I think you're talking about | 19:25 |
*** tdink has joined #openstack-barbican | 19:29 | |
*** kgriffs|afk is now known as kgriffs | 19:29 | |
*** mkam has left #openstack-barbican | 19:34 | |
*** tdink has quit IRC | 19:45 | |
*** tdink has joined #openstack-barbican | 19:46 | |
*** jsavak has joined #openstack-barbican | 19:47 | |
*** joesavak has quit IRC | 19:49 | |
*** tdink has quit IRC | 19:50 | |
*** tdink has joined #openstack-barbican | 19:50 | |
openstackgerrit | A change was merged to openstack/python-barbicanclient: Remove code from oslo-incubator https://review.openstack.org/126316 | 20:10 |
*** tdink has quit IRC | 20:11 | |
*** tdink has joined #openstack-barbican | 20:12 | |
rm_work | woodster_: gotta get me some more of that +2 lovin' | 20:21 |
*** paul_glass has quit IRC | 20:25 | |
*** dimtruck is now known as zz_dimtruck | 20:31 | |
*** kebray_ has quit IRC | 20:32 | |
*** jaosorior has quit IRC | 20:33 | |
*** paul_glass has joined #openstack-barbican | 20:37 | |
*** zz_dimtruck is now known as dimtruck | 20:46 | |
*** kebray has joined #openstack-barbican | 20:49 | |
*** dimtruck is now known as zz_dimtruck | 20:57 | |
openstackgerrit | Christian Berendt proposed a change to openstack/barbican: Remove extraneous vim editor configuration comments https://review.openstack.org/127020 | 21:03 |
*** juantwo has quit IRC | 21:04 | |
*** zz_dimtruck is now known as dimtruck | 21:09 | |
*** paul_glass has quit IRC | 21:14 | |
JeffF | I'm not sure who to ask this question to, so my apologies for the broadcast, but again, I'm a dev for DigiCert building the plugin and I'm wondering about the method supports(self, certificate_spec) in certificate_manager.py. What is certificate_spec and how will this method be used? | 21:18 |
*** jsavak has quit IRC | 21:21 | |
*** alee has quit IRC | 21:24 | |
*** alee has joined #openstack-barbican | 21:27 | |
alee | JeffF, did you see my response? | 21:27 |
JeffF | alee: no | 21:27 |
*** tdink has quit IRC | 21:27 | |
alee | alee> JeffF, the idea of supports() is to determine whether or not the cert plugin supports the relevant cert request | 21:27 |
alee | <alee> right now its passed in the metadata that was passed into the order | 21:27 |
alee | <alee> as we standardize the interface, we'll flesh out exactly whats in there. | 21:27 |
alee | <alee> but for example, a particular cert plugin might or might not support certs with ECC keys for instance. | 21:27 |
JeffF | alee: ok. Is there a definition for how it looks now, the types of certs that will be requested, or is that still being figured out? | 21:29 |
alee | anyways what is going to be available to differentiate on is not yet well defined. but the idea is to return whether or not the cert_plugin supports the request (True or False) | 21:29 |
alee | thats still being worked out | 21:30 |
JeffF | alee: great. ok. Thanks! | 21:30 |
JeffF | alee: I'll just return true for now I guess then | 21:30 |
*** akoneru has quit IRC | 21:30 | |
alee | what you can do now is pass in the parameters specific to your ca | 21:30 |
JeffF | specific for each type of cert? | 21:30 |
alee | eventually we'll want to add some parameter to allow the user to select a ca potentially | 21:31 |
JeffF | yeah | 21:31 |
alee | JeffF, or maybe a SKI (signing key identifier) | 21:32 |
alee | you recall the sample json I sent you ? that had param that were specific to dogtag | 21:32 |
JeffF | yes | 21:32 |
alee | ifyou look in symantec, they are looking for params specific to them | 21:32 |
JeffF | I have put in our specific params and even started a rudimentary mapper expecting that there will be a generic interface of attributes that will come through one day and I'll need to map those to fit our api | 21:33 |
alee | anyways - supports() will make a lot more sense when a) we add ability to select ca b) we have a standard interface | 21:33 |
JeffF | alee: ok, that makes sense to me, yes. | 21:34 |
alee | fr now, I think dogtag just returns true. | 21:34 |
alee | prob same for symantec | 21:34 |
JeffF | so does the symantec plugin | 21:34 |
JeffF | yes | 21:34 |
JeffF | I'll do the same for now | 21:34 |
JeffF | alee: so to try this out in barbican, I should copy out the symantec and dogtag plugins, copy in my new plugin and then by sending a request to the orders resource, I should hit my plugin? | 21:34 |
alee | well there is config in barbican-api.conf | 21:35 |
JeffF | oh, ok | 21:35 |
alee | you want to add something like this -- | 21:36 |
alee | [certificate] | 21:36 |
alee | namespace = barbican.certificate.plugin | 21:36 |
alee | enabled_certificate_plugins = dogtag | 21:36 |
JeffF | there is one in /etc/init and /etc/barbican | 21:36 |
alee | in /etc/barbican | 21:36 |
JeffF | ok | 21:36 |
JeffF | does that name match up with the filename? | 21:37 |
JeffF | so if I specify enabled_certificate_plugins = digicert, my plugin would be named digicert.py? | 21:37 |
alee | no - there is a file .. | 21:37 |
*** tdink has joined #openstack-barbican | 21:38 | |
alee | setup.cfg | 21:38 |
rm_work | AGH | 21:38 |
rm_work | rebase time T_T | 21:38 |
alee | JeffF, where all the plugin entry points are defined | 21:39 |
alee | so under [entry points] | 21:39 |
alee | dogtag = barbican.plugin.dogtag:DogtagCAPlugin | 21:39 |
alee | for example .. | 21:39 |
JeffF | that must be this area? barbican.certificate.plugin = | 21:39 |
JeffF | simple_certificate = barbican.plugin.simple_certificate_manager:SimpleCertificatePlugin | 21:39 |
JeffF | symantec = barbican.plugin.symantec:SymantecCertificatePlugin | 21:39 |
JeffF | dogtag = barbican.plugin.dogtag:DogtagCAPlugin | 21:39 |
alee | yup | 21:39 |
alee | so add one for digicert | 21:40 |
alee | and make sure its the only one enabled | 21:40 |
JeffF | and it's enabled in the certificate section you mentioned above, correct? | 21:41 |
alee | yup | 21:41 |
JeffF | in barbican-api.conf | 21:41 |
*** kebray has quit IRC | 21:41 | |
alee | exactly | 21:41 |
JeffF | ok, cool. anything else I should know? | 21:42 |
alee | I'm not sure :) | 21:42 |
JeffF | alee: well, here goes with my first test then. wish me luck! ;-) | 21:42 |
alee | just keep asking questions when you get stuck :) | 21:43 |
JeffF | alee: thanks so much! | 21:43 |
alee | np | 21:43 |
openstackgerrit | Adam Harwell proposed a change to openstack/python-barbicanclient: Fix consistency between Order/Secret/Container https://review.openstack.org/124889 | 21:45 |
rm_work | woodster_: redrobot: moar +2 | 21:45 |
redrobot | rm_work dagnabbit | 21:46 |
rm_work | forced to rebase because of that oslo CR merging T_T | 21:46 |
redrobot | rm_work this is why I don't like gerrit dependency chains -___- | 21:46 |
rm_work | mine was on master :P | 21:46 |
rm_work | and they're super easy to manage, I can come show you if you want :P | 21:46 |
rm_work | I am handling a 6-long chain in neutron-lbaas | 21:47 |
openstackgerrit | Douglas Mendizábal proposed a change to openstack/python-barbicanclient: Remove outdated examples https://review.openstack.org/127035 | 21:54 |
*** jkf has joined #openstack-barbican | 21:56 | |
* rm_work prods redrobot and woodster_ again for +2s | 21:56 | |
redrobot | rm_work trade you for a +1 https://review.openstack.org/#/c/127035/1 | 21:58 |
rm_work | whelp, that's an easy one | 22:00 |
rm_work | 0 lines of code to review :P | 22:00 |
rm_work | woodster_, give a brother some sweet sweet +2 love | 22:01 |
*** tdink has quit IRC | 22:03 | |
*** tdink has joined #openstack-barbican | 22:03 | |
redrobot | rm_work looksl ike woodster_ is deep in the rabbit hole. | 22:07 |
*** nkinder has quit IRC | 22:10 | |
rm_work | T_T | 22:12 |
rm_work | jvrbanac: got any +2s in ya today? | 22:12 |
*** kebray has joined #openstack-barbican | 22:27 | |
*** dimtruck is now known as zz_dimtruck | 22:27 | |
*** kebray has quit IRC | 22:27 | |
*** nkinder has joined #openstack-barbican | 22:27 | |
*** kebray has joined #openstack-barbican | 22:28 | |
*** juantwo has joined #openstack-barbican | 22:30 | |
*** juantwo has quit IRC | 22:30 | |
*** juantwo has joined #openstack-barbican | 22:31 | |
*** kgriffs is now known as kgriffs|afk | 22:39 | |
*** ayoung has quit IRC | 22:40 | |
*** tdink has quit IRC | 22:40 | |
*** tdink has joined #openstack-barbican | 22:48 | |
*** rtom has quit IRC | 22:54 | |
*** kgriffs|afk is now known as kgriffs | 22:58 | |
*** tdink has quit IRC | 22:58 | |
*** kgriffs is now known as kgriffs|afk | 23:08 | |
*** jorge_munoz has quit IRC | 23:13 | |
*** JeffF has quit IRC | 23:25 | |
*** jkf has quit IRC | 23:34 | |
*** arunkant_work has quit IRC | 23:42 | |
*** nkinder has quit IRC | 23:55 | |
*** kgriffs|afk is now known as kgriffs | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!