rm_you|wtf | redrobot: :) | 00:06 |
---|---|---|
*** rm_you|wtf is now known as rm_you | 00:07 | |
*** alee_ has joined #openstack-barbican | 00:14 | |
*** SheenaG1 has joined #openstack-barbican | 00:15 | |
*** tdink has joined #openstack-barbican | 00:15 | |
*** SheenaG11 has joined #openstack-barbican | 00:16 | |
*** rm_you has quit IRC | 00:19 | |
*** SheenaG1 has quit IRC | 00:19 | |
*** tdink has quit IRC | 00:20 | |
*** rm_you has joined #openstack-barbican | 00:23 | |
*** rm_you has quit IRC | 00:23 | |
*** rm_you has joined #openstack-barbican | 00:23 | |
*** lecalcot_ has joined #openstack-barbican | 00:23 | |
*** rsyed is now known as rsyed_away | 00:25 | |
*** lecalcot_ has quit IRC | 00:27 | |
*** lecalcot has quit IRC | 00:27 | |
*** lecalcot has joined #openstack-barbican | 00:27 | |
*** lecalcot has quit IRC | 00:31 | |
*** SheenaG11 has quit IRC | 00:33 | |
*** SheenaG1 has joined #openstack-barbican | 00:44 | |
*** SheenaG11 has joined #openstack-barbican | 00:49 | |
*** SheenaG1 has quit IRC | 00:51 | |
*** lecalcot has joined #openstack-barbican | 00:58 | |
*** lecalcot has quit IRC | 01:00 | |
*** lecalcot has joined #openstack-barbican | 01:01 | |
*** lecalcot has quit IRC | 01:06 | |
*** SheenaG11 has quit IRC | 01:51 | |
*** SheenaG1 has joined #openstack-barbican | 02:12 | |
*** lecalcot has joined #openstack-barbican | 02:25 | |
*** lecalcot has quit IRC | 02:26 | |
*** lecalcot has joined #openstack-barbican | 02:27 | |
*** rsyed_away is now known as rsyed | 02:44 | |
*** lecalcot has quit IRC | 02:45 | |
*** rsyed is now known as rsyed_away | 03:22 | |
*** tdink has joined #openstack-barbican | 05:09 | |
*** akoneru has joined #openstack-barbican | 06:19 | |
*** akoneru has quit IRC | 06:37 | |
*** rm_you| has joined #openstack-barbican | 06:42 | |
*** rm_you has quit IRC | 06:44 | |
*** chellygel-abroad has joined #openstack-barbican | 07:04 | |
*** chellygel-abroa1 has joined #openstack-barbican | 07:13 | |
*** chellygel-abroad has quit IRC | 07:13 | |
*** lecalcot has joined #openstack-barbican | 07:18 | |
*** chellygel-abroad has joined #openstack-barbican | 07:28 | |
*** chellygel-abroa1 has quit IRC | 07:28 | |
*** chellygel-abroad has quit IRC | 07:28 | |
*** liam_ has joined #openstack-barbican | 07:55 | |
*** liam_ is now known as Guest77235 | 07:55 | |
*** tdink has quit IRC | 08:08 | |
*** lecalcot has quit IRC | 08:12 | |
*** Guest77235 has quit IRC | 08:47 | |
*** Guest77235 has joined #openstack-barbican | 08:52 | |
*** kebray has joined #openstack-barbican | 08:53 | |
*** Guest77235 has quit IRC | 08:58 | |
*** rcarrillocruz has joined #openstack-barbican | 09:10 | |
rcarrillocruz | hi folks | 09:10 |
rcarrillocruz | i attended chellygel and others barbican session at the summit (kudos btw!) and would like to get involved | 09:11 |
rcarrillocruz | i've followed the developer guide of barbican and would like to set it up with keystone, but the documentation from https://github.com/cloudkeep/barbican/wiki/Developer-Guide-for-Keystone states i should made some ammendments to paste and admin-paste ini files that don't seem to be updated somehow | 09:11 |
*** rellerreller has joined #openstack-barbican | 09:12 | |
reaperhulk | rcarrillocruz let me poke some people who might be able to assist | 09:12 |
reaperhulk | cc hockeynut, redrobot | 09:12 |
rcarrillocruz | awesome, if i could just get a gist for a paste an admin-paste init for keystone that would be great | 09:13 |
hockeynut | rcarrillocruz give me a moment and I'll put one up for you | 09:13 |
rcarrillocruz | sweet | 09:15 |
*** kebray has quit IRC | 09:17 | |
hockeynut | rcarrillocruz check out https://gist.github.com/sheyman/5ca1bd3e1ed93d455939 | 09:21 |
hockeynut | rcarrillocruz if you are doing a barbican install then this goes in your barbican etc/barbican/barbican-api-paste.ini which then gets copied up to system /etc/barbican/barbican-api-paste.ini when you run the barbican.sh install | 09:22 |
rcarrillocruz | ok, and that content would go to both paste and admin-paste ? | 09:22 |
hockeynut | not admin | 09:22 |
rcarrillocruz | admin i leave it as is then? | 09:23 |
hockeynut | y | 09:23 |
rcarrillocruz | awesome | 09:23 |
rcarrillocruz | thx! | 09:23 |
*** kebray has joined #openstack-barbican | 09:24 | |
*** alee_ has quit IRC | 09:25 | |
*** kebray has quit IRC | 09:28 | |
*** rellerreller has quit IRC | 09:39 | |
*** rellerreller has joined #openstack-barbican | 09:48 | |
*** rm_you| has quit IRC | 09:54 | |
*** chellygel-abroad has joined #openstack-barbican | 09:54 | |
*** rm_you| has joined #openstack-barbican | 09:54 | |
chellygel-abroad | we found ourselves a little spot | 09:54 |
chellygel-abroad | talk about insanity over there | 09:54 |
reaperhulk | I'm about to be in the sahara security session | 09:56 |
reaperhulk | Do you have a table? | 09:56 |
chellygel-abroad | so the barbicaneers have a table but its packed down there | 10:00 |
chellygel-abroad | we are on the first floor of the hotel | 10:00 |
chellygel-abroad | and its quiet — just chad, bananac, steve, myself, and some random dude | 10:00 |
chellygel-abroad | reaperhulk: ^ | 10:00 |
reaperhulk | bananac is a wonderful name. | 10:00 |
chellygel-abroad | I agree :) | 10:00 |
reaperhulk | I will be up there after this session | 10:01 |
*** tdink has joined #openstack-barbican | 10:04 | |
redrobot | we're brainstorming a name for the KeyManager repo | 10:05 |
jvrbanac | tdink, as you're on vacation I'm picking up and fixing your CR https://review.openstack.org/#/c/132576/ | 10:05 |
redrobot | so far the leading one is Yett | 10:05 |
redrobot | Yett: Iron gates at the entrance of a castle | 10:05 |
jvrbanac | redrobot, ask Jarret, he has a list | 10:05 |
redrobot | jvrbanac http://medievalcastles.stormthecastle.com/parts-of-a-medieval-castle.htm | 10:06 |
chellygel-abroad | sticking with the cloud keep theme? | 10:06 |
redrobot | chellygel-abroad of course! :D | 10:06 |
*** alee_ has joined #openstack-barbican | 10:07 | |
rellerreller | What do you guys think of calling the new key manager project "yett?" | 10:07 |
reaperhulk | It sounds like a yeti | 10:08 |
chellygel-abroad | redrobot: warden? | 10:08 |
reaperhulk | warden is heavily used for auth related stuff | 10:08 |
redrobot | reaperhulk the yeti can be our mascot :D | 10:08 |
rellerreller | I love the yeti mascot! | 10:08 |
*** tdink has quit IRC | 10:09 | |
chellygel-abroad | im sad we cant use murder hole yet | 10:11 |
redrobot | https://en.wikipedia.org/wiki/Yett | 10:12 |
chellygel-abroad | Baliff? Constable? | 10:16 |
redrobot | chellygel-abroad why don't you like yett? | 10:16 |
chellygel-abroad | Watchmen? | 10:16 |
chellygel-abroad | The word isnt attractive? | 10:16 |
chellygel-abroad | and it would be confused with yet | 10:17 |
chellygel-abroad | we dont have yett yet | 10:17 |
redrobot | we don't yet have a yett, but we could :) | 10:17 |
*** woodster_ has joined #openstack-barbican | 10:17 | |
rellerreller | Nova BP for trusted location control, https://review.openstack.org/#/c/132592/ | 10:17 |
* redrobot really likes the castle theme | 10:17 | |
chellygel-abroad | "go to the yett" repo | 10:17 |
chellygel-abroad | you aren't going to type yett | 10:17 |
reaperhulk | I like chellygel-abroad's phrasing | 10:17 |
reaperhulk | It definitely isn't an attractive word | 10:17 |
chellygel-abroad | Constable, watchman and baliff are all jobs in a castle | 10:17 |
reaperhulk | (I don't know that I really care, but it isn't aesthetically pleasing to me) | 10:18 |
woodster_ | there was talk of a mascot for it...can you guess? :) | 10:18 |
rellerreller | chellygel-abroad What about yeti? | 10:18 |
chellygel-abroad | thats totally unrelated to castles. lol | 10:18 |
reaperhulk | hyperbolicparabaloid | 10:18 |
redrobot | Corbel | 10:19 |
redrobot | Corbel - A stone projection from a wall. It supports the weight of a battlement. | 10:19 |
woodster_ | the coyote is totally unrelated to the Spurs team | 10:19 |
chellygel-abroad | Gong Farmer —>a latrine pit emptier | 10:19 |
reaperhulk | pineapple pit (are we just playing word association games now?) | 10:19 |
chellygel-abroad | http://www.ancientfortresses.org/medieval-occupations.htm | 10:19 |
reaperhulk | http://en.wikipedia.org/wiki/Pineapple_pit | 10:19 |
redrobot | Bartizan: A small turret at the corner of a tower or wall. It is usually at the top but not always. | 10:20 |
reaperhulk | haha, bartizan, the key manager for barbican. | 10:20 |
reaperhulk | that's just mean | 10:20 |
redrobot | Donjon - this is an old word for a great tower or a keep. | 10:21 |
chellygel-abroad | if the job is a Key Manager — it should be someone or something that… manages keys? | 10:21 |
chellygel-abroad | Porter | 10:21 |
chellygel-abroad | The Janitor, or Porter, was responsible for the main Castle entrance and for the guardrooms. The Porter also insured that no one entered or left the castle without permission | 10:21 |
chellygel-abroad | no jraim for this one? | 10:23 |
redrobot | chellygel-abroad already taken by some irc thing http://sourceforge.net/projects/porter/ | 10:23 |
jvrbanac | barbican-porter | 10:23 |
jraim | chellygel-abroad: I can come up with a name if people want :) | 10:23 |
jraim | I have a whole list | 10:23 |
redrobot | https://github.com/search?utf8=%E2%9C%93&q=porter | 10:23 |
chellygel-abroad | CASTELLAN? | 10:23 |
chellygel-abroad | Castellan was the occupation of the person who had been appointed as Custodian, or in charge of, the castle | 10:23 |
redrobot | jraim we need a name for the KeyManager interface repo | 10:24 |
chellygel-abroad | jraim: looking for ideas that sound nice :P for the Key Manager | 10:24 |
jraim | All castle themed, you guys are the best. My work here is done ::tear:: | 10:24 |
redrobot | apparently Yett was too ugly | 10:24 |
jraim | lemme see what i have | 10:24 |
jvrbanac | Yett is ugly | 10:24 |
chellygel-abroad | i like CASTELLAN | 10:24 |
jraim | chellygel-abroad: I do too actually | 10:25 |
chellygel-abroad | daddy approves | 10:25 |
jvrbanac | +! | 10:26 |
jvrbanac | +1 | 10:26 |
redrobot | I don't even know how to pronounce castellan. My hispanic side wants to pronounce it with a Y sound. Cas-te-yan | 10:26 |
chellygel-abroad | cas-teh-lyn | 10:27 |
jvrbanac | Cast-e-lon | 10:27 |
jvrbanac | or that | 10:27 |
chellygel-abroad | https://www.google.com/search?q=CASTELLAN&oq=CASTELLAN&aqs=chrome..69i57j0l5.246j0j7&sourceid=chrome&es_sm=119&ie=UTF-8 | 10:27 |
chellygel-abroad | click the lil speaker icon | 10:27 |
chellygel-abroad | ;) | 10:27 |
chellygel-abroad | or CASTLE_LAN (Party) | 10:27 |
chellygel-abroad | :P | 10:27 |
reaperhulk | ftp is blocked on this wifi. gonna have to vpn so I can get things off the RSA ftp. I have made bad choices | 10:29 |
*** rm_you| has quit IRC | 10:30 | |
*** rm_you| has joined #openstack-barbican | 10:31 | |
chellygel-abroad | got too quiet redrobot :P | 10:35 |
redrobot | chellygel-abroad the pecan guys stopped by to say hi. | 10:36 |
*** SheenaG1 has quit IRC | 10:36 | |
*** openstackgerrit has joined #openstack-barbican | 10:39 | |
rcarrillocruz | it seems my dev barbican+keystone is not doing keystone auth. I modified the paste ini file to not use unathenticated method and use instead keystone | 10:51 |
rcarrillocruz | not no matter if i put a valid token | 10:51 |
rcarrillocruz | or a made up one | 10:51 |
rcarrillocruz | i get a valid response from barbican api: | 10:51 |
rcarrillocruz | curl -H "Accept: application/json" -H "X-Auth-Token:8075bd95ae944317b31bdf7081c878ef" http://localhost:9311 | 10:51 |
rcarrillocruz | works | 10:51 |
rcarrillocruz | curl -H "Accept: application/json" -H "X-Auth-Token:8075bd95ae94431" http://localhost:9311 | 10:51 |
rcarrillocruz | works | 10:51 |
rcarrillocruz | and i don't see anything logged on keystone coming from barbican api requests, looks like it's never hit | 10:52 |
openstackgerrit | Juan Antonio Osorio Robles proposed a change to openstack/barbican: Replace trivial instances of tenant for project https://review.openstack.org/132700 | 10:55 |
redrobot | http://www.rfc-editor.org/rfc/rfc7030.txt | 10:56 |
redrobot | rcarrillocruz you may have the unauthenticated context in your paste pipeline. Check barbican-api-paste.ini https://github.com/openstack/barbican/blob/master/etc/barbican/barbican-api-paste.ini#L14 | 10:59 |
rcarrillocruz | http://paste.openstack.org/show/130057/ | 11:02 |
openstackgerrit | Juan Antonio Osorio Robles proposed a change to openstack/barbican: Replace trivial instances of tenant for project https://review.openstack.org/132700 | 11:02 |
rcarrillocruz | looks good to me, that's my /etc/barbican/barbican-api-paste.ini file | 11:02 |
*** kebray has joined #openstack-barbican | 11:03 | |
rcarrillocruz | redrobot: ^ | 11:04 |
redrobot | rcarrillocruz hmm... yeah, that config looks right. | 11:06 |
*** jorge_munoz has joined #openstack-barbican | 11:06 | |
rcarrillocruz | i noticed this from barbican output, not sure if relevant | 11:08 |
rcarrillocruz | http://paste.openstack.org/show/130058/ | 11:08 |
redrobot | rcarrillocruz oh, I kno what's going on now | 11:10 |
redrobot | rcarrillocruz the output shows that the middleware is indeed configured | 11:10 |
redrobot | rcarrillocruz the root resource is not protected by auth | 11:10 |
redrobot | rcarrillocruz try hitting /v1/secrets | 11:11 |
rcarrillocruz | k | 11:12 |
openstackgerrit | Chelsea Winfree proposed a change to openstack/barbican: The last round of secrets functional tests https://review.openstack.org/132570 | 11:13 |
rcarrillocruz | 'Authentication required' | 11:13 |
rcarrillocruz | ok | 11:13 |
rcarrillocruz | sooo, that means it's configured just fine, just the URL i was hitting wouldn't go thru keystone to do auth | 11:13 |
rcarrillocruz | ? | 11:13 |
redrobot | rcarrillocruz correct. :) | 11:14 |
rcarrillocruz | yay | 11:14 |
rcarrillocruz | thx :-) | 11:15 |
*** kebray has quit IRC | 11:16 | |
*** jaosorior has joined #openstack-barbican | 11:19 | |
*** chellygel-abroad has quit IRC | 11:20 | |
*** chellygel-abroad has joined #openstack-barbican | 11:20 | |
rcarrillocruz | sweet | 11:24 |
rcarrillocruz | i'm on business | 11:24 |
rcarrillocruz | getting 'barbican' token and using it to get secrets now i get a response | 11:24 |
rcarrillocruz | :-) | 11:24 |
*** jorge_munoz has quit IRC | 11:25 | |
redrobot | rcarrillocruz awesome! Let us know if you have more questions | 11:28 |
*** chellygel-abroad has quit IRC | 11:33 | |
*** openstackgerrit has quit IRC | 11:42 | |
*** alee_ has quit IRC | 11:51 | |
*** rellerreller has quit IRC | 11:51 | |
*** tdink has joined #openstack-barbican | 12:09 | |
*** tdink has quit IRC | 12:13 | |
*** juantwo has quit IRC | 12:23 | |
*** kne has joined #openstack-barbican | 13:11 | |
*** kne has quit IRC | 13:12 | |
*** jorge_munoz has joined #openstack-barbican | 13:17 | |
*** rellerreller has joined #openstack-barbican | 13:22 | |
redrobot | chellygel btw, did you hear we won the fall season? | 13:26 |
*** kebray has joined #openstack-barbican | 13:27 | |
*** kebray has quit IRC | 13:31 | |
*** alee_ has joined #openstack-barbican | 13:31 | |
*** kebray has joined #openstack-barbican | 13:34 | |
*** jorge_munoz has quit IRC | 13:36 | |
*** jorge_munoz has joined #openstack-barbican | 13:37 | |
rcarrillocruz | is it normal that using the barbican client to get secrets it inserts 'auth' in the POST url? cos I get a 404 because of that... | 13:38 |
rcarrillocruz | "POST /v2.0/auth/tokens HTTP/1.1" 404 | 13:38 |
*** kebray has quit IRC | 13:40 | |
rcarrillocruz | it looks like barbican client is using keystone v3 urls | 13:40 |
*** jorge_munoz has quit IRC | 13:44 | |
*** jorge_munoz has joined #openstack-barbican | 13:46 | |
*** jorge_munoz has quit IRC | 13:50 | |
*** rellerreller has quit IRC | 13:55 | |
*** juantwo has joined #openstack-barbican | 13:59 | |
*** rsyed_away is now known as rsyed | 14:10 | |
*** jorge_munoz has joined #openstack-barbican | 14:14 | |
*** paul_glass has joined #openstack-barbican | 14:48 | |
*** zz_dimtruck is now known as dimtruck | 14:57 | |
*** openstackstatus has quit IRC | 14:58 | |
*** openstack has joined #openstack-barbican | 14:59 | |
*** openstackstatus has joined #openstack-barbican | 14:59 | |
*** ChanServ sets mode: +v openstackstatus | 14:59 | |
*** dimtruck is now known as zz_dimtruck | 15:09 | |
hockeynut | jvrbanac chellygel redrobot reaperhulk would you be so kind as to peek at https://review.openstack.org/#/c/130921/3 | 15:10 |
*** alee_ has quit IRC | 15:16 | |
*** SheenaG1 has joined #openstack-barbican | 15:22 | |
*** JeffF has joined #openstack-barbican | 15:23 | |
*** SheenaG1 has quit IRC | 15:26 | |
*** mkam has joined #openstack-barbican | 15:28 | |
*** alee_ has joined #openstack-barbican | 15:35 | |
redrobot | rcarrillocruz what version of the client are you using? | 15:37 |
rm_work | rcarrillocruz: yes, the client defaults to using v3 as the auth method unless you specify to use v2 | 16:00 |
rm_work | (assuming you are using 3.0.0) | 16:00 |
*** paul_glass has quit IRC | 16:01 | |
*** paul_glass has joined #openstack-barbican | 16:10 | |
*** zz_dimtruck is now known as dimtruck | 16:32 | |
*** jorge_munoz has joined #openstack-barbican | 16:34 | |
*** jorge_munoz has quit IRC | 16:38 | |
*** paul_glass has quit IRC | 16:50 | |
*** juantwo has quit IRC | 16:59 | |
*** jaosorior has quit IRC | 17:03 | |
*** paul_glass has joined #openstack-barbican | 17:29 | |
*** rtom has joined #openstack-barbican | 17:30 | |
*** SheenaG1 has joined #openstack-barbican | 17:37 | |
rcarrillocruz | i'm using the latest from pypi, it's 3 something | 17:39 |
*** rm_mobile has joined #openstack-barbican | 17:45 | |
*** rm_mobile has quit IRC | 17:45 | |
*** rm_mobile has joined #openstack-barbican | 17:45 | |
*** SheenaG11 has joined #openstack-barbican | 17:51 | |
*** SheenaG1 has quit IRC | 17:53 | |
*** SheenaG11 has quit IRC | 17:55 | |
*** SheenaG1 has joined #openstack-barbican | 18:02 | |
*** alee_ has quit IRC | 18:07 | |
*** dimtruck is now known as zz_dimtruck | 18:22 | |
*** zz_dimtruck is now known as dimtruck | 18:23 | |
*** rm_you| has quit IRC | 18:25 | |
*** rm_you| has joined #openstack-barbican | 18:25 | |
*** akoneru has joined #openstack-barbican | 18:36 | |
*** SheenaG1 has quit IRC | 18:39 | |
*** paul_glass has quit IRC | 18:50 | |
rcarrillocruz | i'm resorting to curl for doing my tests | 18:54 |
rcarrillocruz | if you know how to force the client to use v2 pls let me know, don't see it on the help | 18:54 |
*** paul_glass has joined #openstack-barbican | 19:22 | |
*** SheenaG1 has joined #openstack-barbican | 19:31 | |
*** SheenaG1 has quit IRC | 19:36 | |
*** SheenaG1 has joined #openstack-barbican | 19:44 | |
*** rm_mobile has quit IRC | 19:44 | |
*** paul_glass has quit IRC | 19:44 | |
*** paul_glass has joined #openstack-barbican | 19:52 | |
rm_work | rcarrillocruz: --os-identity-api-version | 19:53 |
rm_work | --os-identity-api-version <identity-api-version> │? -> Introduction and overview of IPython's features. | 19:53 |
rm_work | Specify Identity API version to use. Defaults to │%quickref -> Quick reference. | 19:53 |
rm_work | env[OS_IDENTITY_API_VERSION] or 3.0. | 19:53 |
rm_work | err whoopsw | 19:53 |
rm_work | --os-identity-api-version <identity-api-version> | 19:54 |
rm_work | Specify Identity API version to use. Defaults to | 19:54 |
rm_work | env[OS_IDENTITY_API_VERSION] or 3.0. | 19:54 |
rm_work | for devstack: | 19:54 |
rm_work | export OS_AUTH_URL="http://localhost:5000/v2.0/" | 19:54 |
rm_work | export BARBICAN_ENDPOINT="http://localhost:9311/v1/" | 19:54 |
rm_work | export OS_IDENTITY_API_VERSION="2.0" | 19:54 |
rm_work | rcarrillocruz: ^^ | 19:54 |
*** SheenaG1 has quit IRC | 19:56 | |
*** paul_glass has quit IRC | 20:05 | |
*** jorge_munoz has joined #openstack-barbican | 20:06 | |
*** jorge_munoz has quit IRC | 20:43 | |
*** rm_you| has quit IRC | 20:43 | |
*** rm_you| has joined #openstack-barbican | 20:43 | |
*** dimtruck is now known as zz_dimtruck | 20:54 | |
*** paul_glass has joined #openstack-barbican | 20:59 | |
*** paul_glass has quit IRC | 21:24 | |
*** ryanpetrello has joined #openstack-barbican | 21:35 | |
*** woodster_ has quit IRC | 22:00 | |
*** mkam has quit IRC | 22:34 | |
*** ryanpetrello has quit IRC | 22:40 | |
*** rsyed is now known as rsyed_away | 22:54 | |
*** kebray has joined #openstack-barbican | 22:56 | |
*** rsyed_away is now known as rsyed | 23:18 | |
*** ametts has quit IRC | 23:25 | |
*** rtom has quit IRC | 23:35 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!