*** tdink has joined #openstack-barbican | 00:09 | |
*** david-lyle_afk is now known as david-lyle | 00:10 | |
*** paul_glass has joined #openstack-barbican | 00:20 | |
*** rsyed is now known as rsyed_away | 00:20 | |
*** rm_you|wtf has joined #openstack-barbican | 00:21 | |
*** paul_glass has quit IRC | 00:25 | |
*** rm_you| has quit IRC | 00:26 | |
*** tdink has quit IRC | 00:27 | |
*** tdink has joined #openstack-barbican | 00:31 | |
*** zz_dimtruck is now known as dimtruck | 00:31 | |
*** tdink has quit IRC | 00:40 | |
*** rsyed_away is now known as rsyed | 00:42 | |
*** nkinder has joined #openstack-barbican | 01:07 | |
*** tdink has joined #openstack-barbican | 01:21 | |
*** gyee has quit IRC | 01:25 | |
*** tdink has quit IRC | 01:31 | |
*** rsyed is now known as rsyed_away | 01:34 | |
*** bdpayne has quit IRC | 01:47 | |
*** tdink has joined #openstack-barbican | 01:59 | |
*** ayoung has quit IRC | 02:04 | |
*** ayoung has joined #openstack-barbican | 02:05 | |
*** david-lyle is now known as david-lyle_afk | 02:08 | |
*** tdink has quit IRC | 02:09 | |
*** rm_you| has joined #openstack-barbican | 02:24 | |
*** rm_you|wtf has quit IRC | 02:28 | |
*** rm_you| has quit IRC | 02:47 | |
*** rm_you| has joined #openstack-barbican | 02:48 | |
*** dimtruck is now known as zz_dimtruck | 02:54 | |
*** rm_you| has quit IRC | 03:48 | |
*** rm_you| has joined #openstack-barbican | 03:48 | |
*** codekobe_ has joined #openstack-barbican | 04:08 | |
*** chellygel_ has joined #openstack-barbican | 04:11 | |
*** mordred_ has joined #openstack-barbican | 04:12 | |
*** chellygel has quit IRC | 04:12 | |
*** codekobe has quit IRC | 04:12 | |
*** redrobot has quit IRC | 04:12 | |
*** insequent has quit IRC | 04:12 | |
*** zz_dimtruck has quit IRC | 04:12 | |
*** mordred has quit IRC | 04:12 | |
*** mordred_ is now known as mordred | 04:12 | |
*** codekobe_ is now known as codekobe | 04:13 | |
*** redrobot has joined #openstack-barbican | 04:14 | |
*** zz_dimtruck has joined #openstack-barbican | 04:14 | |
*** redrobot is now known as Guest17627 | 04:14 | |
*** zz_dimtruck is now known as dimtruck | 04:14 | |
*** insequent has joined #openstack-barbican | 04:23 | |
*** ayoung is now known as ayoung-mia | 04:27 | |
*** kebray has quit IRC | 07:22 | |
*** akoneru has quit IRC | 08:30 | |
*** akoneru has joined #openstack-barbican | 09:19 | |
*** ajc_ has joined #openstack-barbican | 11:06 | |
*** ajc_ has quit IRC | 11:06 | |
*** akoneru has quit IRC | 12:48 | |
*** SheenaG1 has joined #openstack-barbican | 13:32 | |
*** alee has quit IRC | 13:34 | |
*** ryanpetrello has joined #openstack-barbican | 13:49 | |
*** ryanpetrello has quit IRC | 13:54 | |
*** SheenaG11 has joined #openstack-barbican | 13:54 | |
*** SheenaG1 has quit IRC | 13:57 | |
*** akoneru has joined #openstack-barbican | 14:04 | |
*** nkinder has quit IRC | 14:08 | |
*** alee has joined #openstack-barbican | 14:26 | |
*** kebray has joined #openstack-barbican | 14:32 | |
*** rsyed_away is now known as rsyed | 14:40 | |
*** ametts has joined #openstack-barbican | 14:45 | |
*** nkinder has joined #openstack-barbican | 14:54 | |
*** ryanpetrello has joined #openstack-barbican | 15:04 | |
*** tdink has joined #openstack-barbican | 15:05 | |
*** dave-mccowan has joined #openstack-barbican | 15:21 | |
chellygel_ | alee, ping | 15:22 |
---|---|---|
alee | chellygel_, pong | 15:23 |
chellygel_ | i'm reading your identify cas spec... still a little confused about the conversation woodster was having with you in it | 15:23 |
chellygel_ | he mentioned the ca_id should be a UUID from barbican instead of preset in the plugin... is that correct alee ? | 15:23 |
chellygel_ | or am i misreading that | 15:24 |
*** JeffF has joined #openstack-barbican | 15:24 | |
alee | chellygel_, right -- I'm ok with that. let me pull up the spec | 15:25 |
alee | chellygel_, which line? | 15:26 |
chellygel_ | 105 alee | 15:26 |
*** chellygel_ is now known as chellygel | 15:27 | |
alee | chellygel, ok - so I think I agreed that the ca-id could be a barbican uuid. | 15:28 |
chellygel | thats what it sounded like, i was trying to understand context | 15:28 |
chellygel | i get a little lost in your conversations haha | 15:28 |
alee | chellygel, the SKI is supposed to be unique though and may be more valuable for a client | 15:28 |
*** rtom has joined #openstack-barbican | 15:29 | |
chellygel | okay, another question alee -- the PCA is that a single entry for the entire table? | 15:29 |
chellygel | essentially allowing only one preferred CA? or could there be multiple? | 15:29 |
chellygel | ah, wait projects -- so its multiple projects | 15:30 |
chellygel | im bad at reading apparently | 15:30 |
alee | only one preferred ca per project | 15:30 |
alee | so it will be a table with project_id as the primary key and ca_id as the entry | 15:31 |
chellygel | gotcha | 15:31 |
chellygel | i might ping you with more as im reading through | 15:33 |
alee | np | 15:37 |
*** paul_glass has joined #openstack-barbican | 15:41 | |
*** paul_glass1 has joined #openstack-barbican | 15:44 | |
*** paul_glass has quit IRC | 15:48 | |
*** bdpayne has joined #openstack-barbican | 16:02 | |
*** tdink has quit IRC | 16:25 | |
*** tdink has joined #openstack-barbican | 16:26 | |
*** SheenaG11 has left #openstack-barbican | 16:30 | |
*** SheenaG11 has joined #openstack-barbican | 16:30 | |
*** Guest17627 is now known as redrobot | 16:34 | |
alee | redrobot, ping | 16:35 |
redrobot | alee png | 16:35 |
alee | redrobot, I'm making a lot of progress with my rpm packaging | 16:36 |
alee | redrobot, now a question about barbican.sh | 16:36 |
redrobot | alee good! | 16:36 |
alee | redrobot, so ... | 16:36 |
alee | if I look at barbican.sh install - I see we end up copying barbican-api.conf to the home directory of the user | 16:37 |
alee | whats up with that? | 16:37 |
alee | # Copy conf file to home directory so oslo.config can find it | 16:38 |
alee | cp $LOCAL_CONFIG ~ | 16:38 |
redrobot | alee I think the idea was that barbican.sh would only be used for development | 16:38 |
redrobot | alee it needs to be re-written for general-purpose use | 16:38 |
alee | redrobot, how can I get oslo.config to find the config file in /etc/barbican? | 16:38 |
redrobot | alee that's an excellent question, unfortunaltey I don't know the answer to that. | 16:39 |
alee | redrobot, any idea who might know? | 16:39 |
alee | oslo/uwsgi experts? | 16:39 |
redrobot | oslo folk should know for sure... It _should_ be documented somewhere in oslo.config | 16:40 |
redrobot | alee and just so that we're cleare, there is no hard dependency on uwsgi. Barbican should be able to run within any web server with a WSGI container. So it would be acceptable to remove that dependency from a general-use RPM. | 16:41 |
redrobot | some people may want to use nginx+gnunicorn | 16:42 |
redrobot | or even apache+mod_wsgi | 16:42 |
alee | redrobot, understood -- I'm just trying to get it working to begin with. I think we are likely to go with apache+wmod_wsgi | 16:42 |
alee | for the rhel/fedora rpms | 16:43 |
redrobot | alee cool. | 16:44 |
alee | redrobot, there is a proposal out there to put all the openstack services in apache/mod_wsgi with specified urls | 16:44 |
alee | so we dont have to have tons of ports to manage | 16:44 |
alee | so barbican would be under /keys or whatever | 16:44 |
redrobot | interesting. I think that could be easily achieved in the paste config | 16:45 |
redrobot | btw, did y'all see this? https://aws.amazon.com/about-aws/whats-new/2014/11/12/introducing-aws-key-management-service/ | 16:51 |
tiger_toes | It's a bit limited for now. *cough* | 16:52 |
openstackgerrit | Thomas Dinkjian proposed openstack/barbican: Added test to check that an expired secret cannot be retrieved https://review.openstack.org/134292 | 16:57 |
*** david-lyle_afk is now known as david-lyle | 16:58 | |
openstackgerrit | Thomas Dinkjian proposed openstack/barbican: Added test to check that an expired secret cannot be retrieved https://review.openstack.org/134292 | 17:02 |
*** kebray has quit IRC | 17:11 | |
*** SheenaG11 has left #openstack-barbican | 17:16 | |
*** SheenaG1 has joined #openstack-barbican | 17:21 | |
*** kebray has joined #openstack-barbican | 17:26 | |
*** dimtruck is now known as zz_dimtruck | 17:32 | |
*** openstackgerrit has quit IRC | 17:34 | |
*** openstackgerrit has joined #openstack-barbican | 17:34 | |
*** bdpayne has quit IRC | 17:37 | |
*** paul_glass1 has quit IRC | 17:39 | |
*** SheenaG1 has quit IRC | 17:52 | |
*** stanzi has joined #openstack-barbican | 17:57 | |
*** SheenaG1 has joined #openstack-barbican | 17:57 | |
*** openstackgerrit has quit IRC | 18:03 | |
*** openstackgerrit has joined #openstack-barbican | 18:04 | |
*** bdpayne has joined #openstack-barbican | 18:06 | |
*** stanzi has quit IRC | 18:35 | |
*** paul_glass has joined #openstack-barbican | 18:39 | |
*** paul_glass has quit IRC | 18:42 | |
*** paul_glass has joined #openstack-barbican | 18:43 | |
*** bdpayne_ has joined #openstack-barbican | 18:44 | |
*** bdpayne has quit IRC | 18:46 | |
*** tdink_ has joined #openstack-barbican | 18:47 | |
*** kebray has quit IRC | 18:48 | |
*** openstackgerrit has quit IRC | 18:49 | |
*** kebray has joined #openstack-barbican | 18:49 | |
*** openstackgerrit has joined #openstack-barbican | 18:49 | |
*** tdink has quit IRC | 18:50 | |
*** tdink_ has quit IRC | 18:51 | |
*** akoneru has quit IRC | 18:57 | |
*** rcarrill` has joined #openstack-barbican | 18:58 | |
*** kebray has quit IRC | 19:00 | |
*** rcarrillocruz has quit IRC | 19:00 | |
*** stanzi has joined #openstack-barbican | 19:02 | |
*** akoneru has joined #openstack-barbican | 19:08 | |
*** openstackgerrit has quit IRC | 19:18 | |
*** openstackgerrit has joined #openstack-barbican | 19:18 | |
*** paul_glass1 has joined #openstack-barbican | 19:22 | |
*** paul_glass1 has quit IRC | 19:23 | |
*** paul_glass has quit IRC | 19:23 | |
*** ayoung-mia is now known as ayoung | 19:25 | |
*** paul_glass has joined #openstack-barbican | 19:26 | |
*** stanzi has quit IRC | 19:32 | |
*** stanzi has joined #openstack-barbican | 19:32 | |
alee | redrobot, ping | 19:35 |
redrobot | alee pong | 19:36 |
*** stanzi has quit IRC | 19:36 | |
alee | redrobot, if I want to deploy barbican in apache using mod_wsgi , do I need some kind of barbican.wsgi file? | 19:36 |
alee | redrobot, just noticed no such file is created in the build .. | 19:37 |
redrobot | alee I think so? ... not sure if mod_wsgi can use a paste file. | 19:39 |
alee | redrobot, ok - so its not something ya'll have tried yet | 19:39 |
redrobot | alee nope. we've been battling uwsgi since day one | 19:39 |
alee | ok | 19:40 |
redrobot | alee Chad was able to get it running without uwsgi in devstack, but his CR never merged. | 19:40 |
alee | redrobot, which cr was this? | 19:40 |
redrobot | alee https://review.openstack.org/#/c/98490/ | 19:41 |
alee | redrobot, so this is using eventlet? or apache? | 19:43 |
redrobot | alee looks like he's loading the WSGI app, and then using paste.httpserver to serve it https://review.openstack.org/#/c/98490/14/bin/barbican_devstk_api.py,cm | 19:45 |
redrobot | alee so it's an all python server. | 19:45 |
redrobot | alee but I think setting up the wsgi app for mod_wsgi would be similar. | 19:45 |
alee | redrobot, paste.httpserver is yet another server? | 19:45 |
redrobot | alee yep. he was copying another service. maybe keystone? I think that's the server that DevStack services are using. | 19:46 |
alee | ok - in that case, it might make sense for devstack at least .. | 19:47 |
*** zz_dimtruck is now known as dimtruck | 19:47 | |
*** darrenmoffat has quit IRC | 19:49 | |
*** darrenmoffat has joined #openstack-barbican | 19:50 | |
*** kebray has joined #openstack-barbican | 20:00 | |
*** openstackgerrit has quit IRC | 20:04 | |
*** openstackgerrit has joined #openstack-barbican | 20:05 | |
*** tdink has joined #openstack-barbican | 20:05 | |
openstackgerrit | Thomas Dinkjian proposed openstack/barbican: Added test to check that an expired secret cannot be retrieved https://review.openstack.org/134292 | 20:28 |
openstackgerrit | Thomas Dinkjian proposed openstack/barbican: Added test to check that an expired secret cannot be retrieved https://review.openstack.org/134292 | 20:31 |
*** rellerreller has joined #openstack-barbican | 20:33 | |
*** dimtruck is now known as zz_dimtruck | 20:44 | |
*** alee has quit IRC | 20:56 | |
*** kebray has quit IRC | 21:04 | |
*** kebray has joined #openstack-barbican | 21:04 | |
*** bubbva has quit IRC | 21:04 | |
*** bubbva has joined #openstack-barbican | 21:04 | |
*** openstackgerrit has quit IRC | 21:19 | |
*** openstackgerrit has joined #openstack-barbican | 21:19 | |
*** kebray has quit IRC | 21:31 | |
*** alee has joined #openstack-barbican | 21:41 | |
rm_work | reaperhulk: hey | 21:47 |
rm_work | reaperhulk: would you do me a huge favor and look over this CR for me? https://review.openstack.org/#/c/130659/ | 21:47 |
rm_work | reaperhulk: it's not Barbican, but it's a security thing, and I feel like you could provide useful feedback (like, YOU ARE DUMB DON'T DO THAT) | 21:48 |
rm_work | reaperhulk: err, can be found more legibly here: http://docs.octavia.io/review/130659/specs/version0.5/tls-data-security.html | 21:48 |
rm_work | but the review would be where comments could go :) | 21:49 |
dstufft | yay tls | 21:51 |
*** nkinder has quit IRC | 21:56 | |
*** stanzi has joined #openstack-barbican | 21:58 | |
*** zz_dimtruck is now known as dimtruck | 22:03 | |
*** stanzi has quit IRC | 22:04 | |
*** stanzi has joined #openstack-barbican | 22:05 | |
*** stanzi_ has joined #openstack-barbican | 22:06 | |
*** stanzi has quit IRC | 22:09 | |
*** ryanpetrello has quit IRC | 22:16 | |
alee | chellygel, ping | 22:19 |
chellygel | alee, pong | 22:19 |
alee | chellygel, so does symantec support cmc requests? | 22:19 |
chellygel | what is cmc alee ? | 22:20 |
alee | chellygel, its a request format for cert enrollments | 22:20 |
chellygel | do you have an example? i can look into it | 22:20 |
chellygel | not familiar with that | 22:20 |
alee | chellygel, this is relevant because rfc 7030 basically is a REST API around CMC requests | 22:21 |
alee | chellygel, CMC requests defined in http://tools.ietf.org/html/rfc5272#section-3.1 | 22:21 |
chellygel | checking their api docs alee | 22:23 |
chellygel | if i am reading this right CMS => CMC | 22:25 |
chellygel | same thing | 22:25 |
chellygel | PKCS7? | 22:25 |
*** akoneru is now known as akoneru_afk | 22:26 | |
*** akoneru_afk has quit IRC | 22:26 | |
*** stanzi_ has quit IRC | 22:26 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/134381 | 22:27 |
*** stanzi has joined #openstack-barbican | 22:27 | |
alee | chellygel, http://en.wikipedia.org/wiki/Certificate_Management_over_CMS | 22:30 |
*** stanzi has quit IRC | 22:31 | |
chellygel | alee, sorry for my ignorance -- im still trying to wrap my head around it | 22:35 |
alee | chellygel, no worries - me too :) | 22:36 |
alee | back in a bit | 22:36 |
*** gyee has joined #openstack-barbican | 22:37 | |
*** stanzi has joined #openstack-barbican | 22:38 | |
*** stanzi has quit IRC | 22:40 | |
*** stanzi has joined #openstack-barbican | 22:40 | |
*** kebray has joined #openstack-barbican | 22:41 | |
*** kebray has quit IRC | 22:41 | |
*** paul_glass has quit IRC | 22:41 | |
*** kebray has joined #openstack-barbican | 22:43 | |
*** alee is now known as alee_daycare | 22:44 | |
*** stanzi has quit IRC | 22:44 | |
*** rsyed is now known as rsyed_away | 22:51 | |
*** dave-mccowan has quit IRC | 22:58 | |
*** rellerreller has quit IRC | 23:00 | |
*** ametts has quit IRC | 23:07 | |
*** nkinder has joined #openstack-barbican | 23:17 | |
*** akoneru has joined #openstack-barbican | 23:37 | |
*** rtom has quit IRC | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!