*** kgriffs is now known as kgriffs|afk | 00:20 | |
*** kgriffs|afk is now known as kgriffs | 00:23 | |
*** zz_dimtruck is now known as dimtruck | 00:40 | |
*** lisaclark1 has joined #openstack-barbican | 00:54 | |
*** bdpayne has quit IRC | 01:07 | |
*** woodster_ has quit IRC | 01:10 | |
*** codekobe_____ has joined #openstack-barbican | 01:32 | |
*** jorge_munoz has joined #openstack-barbican | 01:33 | |
*** dougwig has quit IRC | 01:33 | |
*** dougwig has joined #openstack-barbican | 01:33 | |
*** codekobe____ has quit IRC | 01:33 | |
*** dougwig has quit IRC | 01:33 | |
*** dougwig has joined #openstack-barbican | 01:33 | |
*** codekobe_____ is now known as codekobe____ | 01:33 | |
*** openstack has joined #openstack-barbican | 01:42 | |
*** lisaclark1 has quit IRC | 01:42 | |
*** jorge_munoz has quit IRC | 01:42 | |
*** insequen1 has joined #openstack-barbican | 01:42 | |
*** dougwig has quit IRC | 01:42 | |
*** insequent has quit IRC | 01:42 | |
*** anteaya has quit IRC | 01:42 | |
*** dougwig has joined #openstack-barbican | 01:42 | |
*** dougwig has quit IRC | 01:42 | |
*** dougwig has joined #openstack-barbican | 01:42 | |
*** anteaya has joined #openstack-barbican | 01:52 | |
*** openstackgerrit has joined #openstack-barbican | 01:52 | |
*** jorge_munoz has joined #openstack-barbican | 01:52 | |
*** jorge_munoz has quit IRC | 01:52 | |
*** jorge_munoz has joined #openstack-barbican | 01:56 | |
*** jorge_munoz has quit IRC | 02:01 | |
*** insequen1 is now known as insequent | 02:29 | |
*** rm_you| has quit IRC | 02:38 | |
*** insequent has quit IRC | 02:43 | |
*** insequent has joined #openstack-barbican | 02:43 | |
*** ayoung has joined #openstack-barbican | 03:12 | |
*** ayoung has quit IRC | 03:14 | |
*** ayoung has joined #openstack-barbican | 03:14 | |
*** bubbva has quit IRC | 03:34 | |
*** bubbva has joined #openstack-barbican | 03:34 | |
*** woodster_ has joined #openstack-barbican | 04:11 | |
*** dimtruck is now known as zz_dimtruck | 04:18 | |
*** gyee has quit IRC | 04:34 | |
*** kgriffs is now known as kgriffs|afk | 05:44 | |
*** rm_you has joined #openstack-barbican | 05:53 | |
*** insequent has quit IRC | 06:08 | |
*** insequent has joined #openstack-barbican | 06:10 | |
*** woodster_ has quit IRC | 06:20 | |
*** Guest86578 is now known as d0ugal | 07:04 | |
*** d0ugal has quit IRC | 07:05 | |
*** d0ugal has joined #openstack-barbican | 07:05 | |
*** juantwo_ has joined #openstack-barbican | 07:10 | |
*** rm_you| has joined #openstack-barbican | 07:10 | |
*** juantwo_ has quit IRC | 07:10 | |
*** juantwo_ has joined #openstack-barbican | 07:11 | |
*** juantwo has quit IRC | 07:13 | |
*** rm_you has quit IRC | 07:14 | |
*** alee has quit IRC | 07:14 | |
*** alee has joined #openstack-barbican | 07:17 | |
*** davidhadas_ has joined #openstack-barbican | 07:50 | |
*** davidhadas_ is now known as davidhadas | 08:14 | |
*** davidhadas__ has joined #openstack-barbican | 11:31 | |
*** davidhadas__ has quit IRC | 11:32 | |
*** davidhadas has quit IRC | 11:34 | |
*** davidhadas has joined #openstack-barbican | 11:35 | |
*** alee has quit IRC | 12:32 | |
*** SheenaG1 has joined #openstack-barbican | 13:04 | |
*** SheenaG1 has left #openstack-barbican | 13:06 | |
*** SheenaG11 has joined #openstack-barbican | 13:09 | |
*** nkinder has quit IRC | 13:10 | |
*** woodster_ has joined #openstack-barbican | 13:29 | |
*** lisaclark1 has joined #openstack-barbican | 13:39 | |
*** paul_glass has joined #openstack-barbican | 13:43 | |
*** alee has joined #openstack-barbican | 13:46 | |
*** paul_glass has quit IRC | 13:46 | |
*** SheenaG11 has quit IRC | 13:49 | |
*** nkinder has joined #openstack-barbican | 13:54 | |
*** lisaclark1 has quit IRC | 13:57 | |
*** ayoung has quit IRC | 13:59 | |
*** tdink has joined #openstack-barbican | 13:59 | |
*** SheenaG1 has joined #openstack-barbican | 14:16 | |
*** kgriffs|afk is now known as kgriffs | 14:20 | |
*** jorge_munoz has joined #openstack-barbican | 14:21 | |
*** davidhadas__ has joined #openstack-barbican | 14:25 | |
*** davidhadas has quit IRC | 14:25 | |
openstackgerrit | Tim Kelsey proposed a change to openstack/barbican: Bumping default ssl_version to TLSv1, in light of POODLE. https://review.openstack.org/128665 | 14:28 |
---|---|---|
*** lisaclark1 has joined #openstack-barbican | 14:31 | |
*** akoneru has joined #openstack-barbican | 14:31 | |
*** lisaclark1 has joined #openstack-barbican | 14:31 | |
*** zz_dimtruck is now known as dimtruck | 14:32 | |
*** lisaclark1 has quit IRC | 14:37 | |
*** lisaclark1 has joined #openstack-barbican | 14:37 | |
*** paul_glass has joined #openstack-barbican | 14:40 | |
openstackgerrit | Tim Kelsey proposed a change to openstack/barbican: Bumping default ssl_version to TLSv1, in light of POODLE https://review.openstack.org/128665 | 14:50 |
*** dimtruck is now known as zz_dimtruck | 14:52 | |
*** paul_glass has quit IRC | 15:00 | |
*** paul_glass has joined #openstack-barbican | 15:12 | |
*** kebray has joined #openstack-barbican | 15:31 | |
*** kebray has quit IRC | 15:31 | |
*** zz_dimtruck is now known as dimtruck | 15:33 | |
*** lisaclark1 has quit IRC | 15:42 | |
*** lisaclark1 has joined #openstack-barbican | 15:45 | |
*** lisaclark1 has quit IRC | 15:46 | |
*** lisaclark1 has joined #openstack-barbican | 15:46 | |
alee | woodster_, ? | 15:49 |
*** ayoung has joined #openstack-barbican | 15:56 | |
*** lisaclark1 has quit IRC | 16:06 | |
*** lisaclark1 has joined #openstack-barbican | 16:08 | |
*** tdink has quit IRC | 16:08 | |
*** tdink_ has joined #openstack-barbican | 16:08 | |
rm_work | redrobot: I assume no tacos today since last night woodster_ said he wasn't going to make it and chellygel said she'd be in austin | 16:15 |
rm_work | chellygel: are you actually in austin? :P | 16:15 |
chellygel | yes rm_work | 16:15 |
rm_work | kk | 16:26 |
rm_work | well I mean, that's not to say redrobot and I couldn't do tacos by our lonesome :P but yeah, hopefully catch you guys next week | 16:26 |
*** paul_glass has quit IRC | 16:29 | |
*** paul_glass has joined #openstack-barbican | 16:31 | |
*** jorge_munoz has quit IRC | 16:33 | |
*** lisaclark1 has quit IRC | 16:33 | |
*** paul_glass has quit IRC | 16:34 | |
*** rellerreller has joined #openstack-barbican | 16:35 | |
*** lisaclark1 has joined #openstack-barbican | 16:36 | |
*** kebray has joined #openstack-barbican | 16:37 | |
*** paul_glass has joined #openstack-barbican | 16:47 | |
*** ayoung has quit IRC | 16:53 | |
*** paul_glass has quit IRC | 16:53 | |
jvrbanac | rellerreller, yo | 16:54 |
*** rm_you| has quit IRC | 16:54 | |
*** paul_glass has joined #openstack-barbican | 16:54 | |
rellerreller | What's up | 16:55 |
jvrbanac | rellerreller, fyi, we're suppose to have 3 total core reviews for a CR | 16:55 |
jvrbanac | 2+'s and a +1 | 16:55 |
jvrbanac | from different people | 16:55 |
jvrbanac | ^+1 workflow | 16:56 |
openstackgerrit | A change was merged to openstack/barbican: Bumping default ssl_version to TLSv1, in light of POODLE https://review.openstack.org/128665 | 16:56 |
rellerreller | Oh, I did not know that. I thought just two +2's was all that is needed. | 16:56 |
rellerreller | Why does gerrit allow that to happen? | 16:56 |
rellerreller | jvrbanac OK, well do we need to do anything about this? | 16:57 |
jvrbanac | rellerreller, some projects only require 2 core reviews. My guess is for smaller projects with a limited number of core reviewers | 16:58 |
jvrbanac | rellerreller, it's fine, we don't need to do anything, but just keep that in mind for future reviews | 16:58 |
rellerreller | jvrbanac We should write a Gerrit patch to enforce policy. I'm surprised that it does not do this already. | 16:59 |
rellerreller | jvrbanac Will do. Sorry about that. | 16:59 |
jvrbanac | rellerreller, np. Everyone occasionally makes the mistake. I think it's a setting in Gerrit somewhere | 17:01 |
jvrbanac | rellerreller, we can take a look at it during the summit | 17:01 |
*** kgriffs is now known as kgriffs|afk | 17:03 | |
*** bdpayne has joined #openstack-barbican | 17:09 | |
*** kgriffs|afk is now known as kgriffs | 17:24 | |
*** kgriffs is now known as kgriffs|afk | 17:34 | |
*** lisaclark1 has quit IRC | 17:48 | |
*** alee is now known as alee_afk_food | 18:15 | |
*** kgriffs|afk is now known as kgriffs | 18:25 | |
*** kgriffs is now known as kgriffs|afk | 18:35 | |
*** ayoung has joined #openstack-barbican | 18:35 | |
*** ayoung has quit IRC | 18:36 | |
*** ayoung has joined #openstack-barbican | 18:36 | |
*** gyee has joined #openstack-barbican | 18:38 | |
*** davidhadas__ is now known as davidhadas | 18:39 | |
*** lisaclark1 has joined #openstack-barbican | 18:47 | |
*** alee_afk_food is now known as alee | 18:47 | |
*** lisaclark1 has quit IRC | 18:48 | |
*** kgriffs|afk is now known as kgriffs | 18:51 | |
*** nkinder has quit IRC | 18:51 | |
*** lisaclark1 has joined #openstack-barbican | 18:52 | |
*** mordred has joined #openstack-barbican | 18:55 | |
*** tdink_ has quit IRC | 19:02 | |
*** Constanze has joined #openstack-barbican | 19:03 | |
*** Constanze has quit IRC | 19:04 | |
*** tdink has joined #openstack-barbican | 19:05 | |
*** Stanzi has joined #openstack-barbican | 19:07 | |
rm_work | alee: did you look at my comment on https://review.openstack.org/#/c/127353/ ? | 19:08 |
alee | rm_work, I did - taking some time to digest it. | 19:09 |
*** tdink has quit IRC | 19:10 | |
alee | rm_work, on the outset though, I'm not opposed to a different method to achieve the same goal. I put the spec up for exactly this kind of discussion. | 19:10 |
rm_work | yeah I am more curious if you think it makes sense | 19:11 |
alee | I'd like other folks to chime in too though. | 19:11 |
rm_work | or if it is lacking | 19:11 |
rm_work | since it is a bit more ... basic | 19:11 |
alee | rm_work, ok -- I'll give it a thorough look-see shortly and will comment | 19:11 |
rm_work | alee: no hurry, this one is going to need to stew for a while probably | 19:12 |
rm_work | I was just curious | 19:12 |
rm_work | and impatient for feedback :) | 19:12 |
alee | rm_work, by the way, did you notice https://review.openstack.org/#/c/128401/ ? | 19:12 |
*** Stanzi has quit IRC | 19:16 | |
rm_work | alee: yes but I am not an expert in that area :P | 19:17 |
*** kebray has quit IRC | 19:20 | |
rm_work | alee: did you copy-pasta that BP? the title is from the tenant->project refactor BP, lol | 19:28 |
alee | rm_work, oops - yup :/ | 19:28 |
*** lisaclark1 has quit IRC | 19:33 | |
*** lisaclark1 has joined #openstack-barbican | 19:34 | |
*** lisaclark1 has quit IRC | 19:34 | |
*** lisaclark1 has joined #openstack-barbican | 19:35 | |
*** tdink has joined #openstack-barbican | 19:35 | |
*** lisaclark1 has quit IRC | 19:36 | |
*** lisaclark1 has joined #openstack-barbican | 19:39 | |
*** dimtruck is now known as zz_dimtruck | 19:43 | |
*** kebray has joined #openstack-barbican | 19:49 | |
*** tdink has quit IRC | 19:56 | |
*** ayoung has quit IRC | 19:56 | |
*** tdink has joined #openstack-barbican | 20:03 | |
*** zz_dimtruck is now known as dimtruck | 20:10 | |
*** nkinder has joined #openstack-barbican | 20:11 | |
*** tdink has quit IRC | 20:17 | |
*** tdink_ has joined #openstack-barbican | 20:17 | |
*** tdink_ has quit IRC | 20:28 | |
*** paul_glass has quit IRC | 20:29 | |
*** paul_glass1 has joined #openstack-barbican | 20:32 | |
*** dimtruck is now known as zz_dimtruck | 20:38 | |
*** zz_dimtruck is now known as dimtruck | 20:44 | |
*** tdink has joined #openstack-barbican | 20:55 | |
SheenaG1 | reaperhulk: ping | 20:55 |
reaperhulk | what's up SheenaG1 | 20:55 |
*** tdink has quit IRC | 21:01 | |
*** tdink has joined #openstack-barbican | 21:02 | |
openstackgerrit | Douglas Mendizábal proposed a change to openstack/python-barbicanclient: Add sphinx docs https://review.openstack.org/127868 | 21:13 |
*** lisaclark1 has quit IRC | 21:17 | |
rm_work | need eyes on https://review.openstack.org/#/c/125798/ | 21:38 |
rm_work | reaperhulk / redrobot / alee / jvrbanac | 21:39 |
*** tdink has quit IRC | 21:41 | |
*** tdink has joined #openstack-barbican | 21:42 | |
*** alee has quit IRC | 21:43 | |
*** SheenaG1 has quit IRC | 21:52 | |
*** paul_glass1 has quit IRC | 21:56 | |
*** kebray has quit IRC | 21:57 | |
*** tdink has quit IRC | 21:58 | |
*** juantwo has joined #openstack-barbican | 22:01 | |
*** juantwo has quit IRC | 22:01 | |
*** juantwo has joined #openstack-barbican | 22:02 | |
*** juantwo_ has quit IRC | 22:04 | |
*** rellerreller has quit IRC | 22:11 | |
*** tdink has joined #openstack-barbican | 22:16 | |
*** SheenaG1 has joined #openstack-barbican | 22:23 | |
*** tdink has quit IRC | 22:26 | |
*** SheenaG1 has quit IRC | 22:29 | |
*** SheenaG1 has joined #openstack-barbican | 22:32 | |
*** ryanpetrello has quit IRC | 22:34 | |
*** ryanpetrello has joined #openstack-barbican | 22:35 | |
*** alee has joined #openstack-barbican | 22:46 | |
*** kgriffs is now known as kgriffs|afk | 22:49 | |
*** dimtruck is now known as zz_dimtruck | 22:57 | |
openstackgerrit | John Wood proposed a change to openstack/barbican-specs: Add worker retry and future updates support https://review.openstack.org/128113 | 23:05 |
openstackgerrit | John Wood proposed a change to openstack/barbican-specs: Add worker retry and future updates support https://review.openstack.org/128113 | 23:07 |
rm_work | woodster_: you there? | 23:08 |
woodster_ | rm_work: yep, trying to catch up on CRs.... | 23:09 |
rm_work | woodster_: do you know when the feature to Order up a TLS Certificate was going to be a reality? | 23:09 |
rm_work | Like, Hey Barbican! I need a nice new signed TLS Cert, please make one and return it to me! | 23:09 |
rm_work | IIRC people kept telling me "not available yet", but not a timeline | 23:09 |
woodster_ | rm_work: sometime in Kilo :) Actually that retry blueprint I just updated is one of the last technical pieces to that cert workflow puzzle. | 23:10 |
rm_work | ah ok, cool | 23:10 |
rm_work | As long as that's in Kilo, we can take advantage of it for Octavia | 23:10 |
rm_work | My plan is that on our API's initial spinup, it'll request that Barbican make it a cert, then retrieve the cert and use that cert for its API endpoint :) | 23:11 |
rm_work | and store the ContainerID in its config for later use | 23:11 |
woodster_ | rm_work, the design sessions regarding ssl cert plugin management will be the final piece...so what data is common across all CAs in a cert order, and what is specific to a CA. Then we would need a search discovery sort of API to say 'these are the CAs I support', and 'here are the specific parameters you need to pass in for a given cert'. | 23:11 |
rm_work | cool | 23:12 |
rm_work | so, since I won't be at that design session, make sure it goes well, eh? :P | 23:12 |
rm_work | because obviously you wouldn't care otherwise :P | 23:12 |
woodster_ | rm_work, just keep in mind though that the cert workflow process itself could take days/weeks to play out, depending on the cert type. If the CA needs to verify business stuff for example, that could take a while. | 23:13 |
woodster_ | rm_work, I care because SheenaG1 cares :) And it's a great feature for Barbican too | 23:14 |
rm_work | heh | 23:14 |
rm_work | ah so there's no way we could see a signed cert show up for us in, say, 10 seconds? :P | 23:14 |
woodster_ | rm_work, so there are some cert workflows that could generate the certificate right away (well, via the orders asynch api), but that might not be an officially certified one via a remote CA. If barbican itself is configured as a CA, then it could do it. Alee's Dogtag plugin generates the cert right away for example. | 23:15 |
rm_work | awesome | 23:16 |
rm_work | so, somewhat possible | 23:16 |
rm_work | not "out of the question" :P | 23:16 |
woodster_ | rm_work, yes if the expectation is just a cert that doesn't verify company info (so just a domain DV one I think). That would be good to ask SheenaG1 and chellygel about actually. | 23:17 |
woodster_ | rm_work, but if a customer wants a fancy expensive one on there that verifies first born and so forth, then >>> 10 seconds wait time. | 23:17 |
rm_work | we're talking about for internal communication between our service and our containers | 23:19 |
*** zz_dimtruck is now known as dimtruck | 23:52 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!