*** JeffF has quit IRC | 00:03 | |
*** bdpayne_ has joined #openstack-barbican | 00:03 | |
*** bdpayne has quit IRC | 00:05 | |
*** dimtruck is now known as zz_dimtruck | 00:17 | |
*** openstackgerrit has quit IRC | 00:18 | |
*** openstackgerrit has joined #openstack-barbican | 00:19 | |
*** lordbyron820 has joined #openstack-barbican | 00:21 | |
*** lordbyron820 has quit IRC | 00:25 | |
*** kebray has quit IRC | 00:28 | |
*** crc32 has quit IRC | 00:31 | |
*** bdpayne_ has quit IRC | 00:37 | |
openstackgerrit | Merged openstack/barbican: Updated from global requirements https://review.openstack.org/139224 | 00:53 |
---|---|---|
openstackgerrit | greghaynes proposed openstack/python-barbicanclient: Correctly set pbr version name https://review.openstack.org/139292 | 00:58 |
greghaynes | ^ is a pretty embarassing bug in that pip install python-barbicanclient currently fails with a traceback :) | 00:59 |
greghaynes | sorry, the pip install doesnt fail, running barbican after pip installing fails | 00:59 |
greghaynes | So, im hoping to use barbican to do some snakeoil CA/Cert generation and storage for tripleo. I spoke with someone at the summit who indicated that there was some kind of 'admin API' which might need a little bit of work but is a good way to do that | 01:07 |
greghaynes | any tips on where I should be looking for this? | 01:07 |
greghaynes | Also, does a client exist yet for this? | 01:07 |
*** stanzi has joined #openstack-barbican | 02:09 | |
*** stanzi has quit IRC | 02:10 | |
*** stanzi has joined #openstack-barbican | 02:11 | |
*** stanzi has quit IRC | 02:12 | |
*** zz_dimtruck is now known as dimtruck | 02:39 | |
*** ryanpetrello has quit IRC | 02:40 | |
*** ryanpetrello has joined #openstack-barbican | 02:43 | |
*** bubbva has quit IRC | 03:08 | |
*** gyee has quit IRC | 03:25 | |
*** bubbva has joined #openstack-barbican | 03:27 | |
*** rm_you has joined #openstack-barbican | 03:33 | |
*** rm_you has quit IRC | 03:33 | |
*** rm_you has joined #openstack-barbican | 03:33 | |
openstackgerrit | Jeremy Stanley proposed openstack/barbican: Workflow documentation is now in infra-manual https://review.openstack.org/139309 | 03:40 |
openstackgerrit | Jeremy Stanley proposed openstack/barbican-specs: Workflow documentation is now in infra-manual https://review.openstack.org/139310 | 03:40 |
openstackgerrit | Jeremy Stanley proposed openstack/castellan: Workflow documentation is now in infra-manual https://review.openstack.org/139311 | 03:40 |
openstackgerrit | Jeremy Stanley proposed openstack/kite: Workflow documentation is now in infra-manual https://review.openstack.org/139335 | 03:42 |
openstackgerrit | Jeremy Stanley proposed openstack/python-barbicanclient: Workflow documentation is now in infra-manual https://review.openstack.org/139368 | 03:44 |
*** kebray has joined #openstack-barbican | 03:49 | |
openstackgerrit | Jeremy Stanley proposed openstack/python-kiteclient: Workflow documentation is now in infra-manual https://review.openstack.org/139378 | 03:51 |
*** dave-mccowan has quit IRC | 04:52 | |
*** dimtruck is now known as zz_dimtruck | 05:38 | |
*** openstackgerrit has quit IRC | 06:49 | |
*** openstackgerrit has joined #openstack-barbican | 06:49 | |
*** tiger_toes has joined #openstack-barbican | 08:12 | |
*** woodster_ has quit IRC | 08:30 | |
*** tiger_toes has quit IRC | 09:01 | |
*** mikedillion has joined #openstack-barbican | 12:55 | |
*** woodster_ has joined #openstack-barbican | 13:00 | |
*** dave-mccowan has joined #openstack-barbican | 13:11 | |
*** mikedillion has quit IRC | 13:19 | |
*** dave-mccowan_ has joined #openstack-barbican | 13:36 | |
*** dave-mccowan has quit IRC | 13:37 | |
*** dave-mccowan_ is now known as dave-mccowan | 13:37 | |
*** miqui_ has joined #openstack-barbican | 14:04 | |
*** mikedillion has joined #openstack-barbican | 14:45 | |
*** SheenaG1 has joined #openstack-barbican | 14:57 | |
*** SheenaG11 has joined #openstack-barbican | 15:04 | |
*** SheenaG1 has quit IRC | 15:05 | |
openstackgerrit | Tim Kelsey proposed openstack/barbican: Adding client certificates to connection credentials https://review.openstack.org/135217 | 15:13 |
*** ryanpetrello has quit IRC | 15:21 | |
*** kgriffs|afk is now known as kgriffs | 15:25 | |
*** ryanpetrello has joined #openstack-barbican | 15:26 | |
*** zz_dimtruck is now known as dimtruck | 15:30 | |
*** kebray has quit IRC | 15:39 | |
*** stanzi has joined #openstack-barbican | 15:40 | |
*** JeffF has joined #openstack-barbican | 15:54 | |
alee_ | dave-mccowan, ping | 16:00 |
dave-mccowan | alee_ pong | 16:01 |
alee_ | dave-mccowan, correct me if I'm wrong, but it seems to me that neither cmc nor rfc 7030 have any fields for a requestor to provide contact information (ie. email address, phone number ) for the requestor? | 16:02 |
*** stanzi has quit IRC | 16:02 | |
dave-mccowan | alee_, the RFC allows for a preamble section that can contain this. There is an example in appendix A.4. | 16:05 |
alee_ | dave-mccowan, ok - so there are no specific fields defined .. | 16:07 |
alee_ | dave-mccowan, I'm curious how that information would be passed from an EST RA to a CA | 16:08 |
alee_ | given that it has no defined format | 16:08 |
*** stanzi has joined #openstack-barbican | 16:08 | |
alee_ | might be something to think about to improve the RFC | 16:08 |
*** kebray has joined #openstack-barbican | 16:09 | |
dave-mccowan | alee_, good question. i'll ask the author if he has thought of this. | 16:09 |
alee_ | dave-mccowan, thanks | 16:09 |
*** kebray has quit IRC | 16:17 | |
*** stanzi has quit IRC | 16:21 | |
alee_ | dave-mccowan, did you get that list of ca's that support cmc? | 16:27 |
dave-mccowan | alee_, i asked some folks who have looked into it. they said it was a complicated question. for example, Microsoft uses CMC, but they use a proprietary transport. so, even among CAs that use CMC, it will not be plug and play. | 16:29 |
alee_ | dave-mccowan, yup understood | 16:29 |
SheenaG11 | woodster_, redrobot: stand up? | 16:30 |
redrobot | SheenaG11 yep, booting up Mumble | 16:30 |
alee_ | dave-mccowan, that kind of complication would have to be handled by the backend plugin | 16:30 |
*** kebray has joined #openstack-barbican | 16:34 | |
openstackgerrit | Ade Lee proposed openstack/barbican-specs: Add Cert API Spec. https://review.openstack.org/135490 | 16:38 |
alee_ | woodster_, rellerreller, reaperhulk , redrobot , dave-mccowan , rm_work , chellygel , jvrbanac - latest version of the cert api spec based on feedback yesterday. | 16:39 |
rm_work | k | 16:39 |
alee_ | lets see if we can put this one to bed today .. | 16:40 |
rm_work | no objections here, looks pretty good | 16:47 |
alee_ | rm_work, cool beans thanks | 16:47 |
*** kebray has quit IRC | 16:48 | |
alee_ | rm_work, take a look at https://review.openstack.org/#/c/129048 and see if it works for you as well. | 16:52 |
*** stanzi has joined #openstack-barbican | 16:56 | |
*** kebray has joined #openstack-barbican | 17:09 | |
openstackgerrit | Ade Lee proposed openstack/barbican-specs: Spec for identifying CAs https://review.openstack.org/129048 | 17:13 |
*** stanzi has quit IRC | 17:14 | |
alee_ | woodster_, rellerreller, jvrbanac , rm_work , dave-mccowan , chellygel , reaperhulk , redrobot - updated spec for identifying ca's based on comments yesterday. | 17:14 |
rm_work | commenting | 17:15 |
rm_work | damnit | 17:15 |
alee_ | those two specs should cover the basic cert API | 17:15 |
rm_work | well | 17:15 |
rm_work | commenting on the previous patchset | 17:15 |
alee_ | rm_work, sorry :/ | 17:15 |
rm_work | >_< | 17:15 |
*** SheenaG11 has quit IRC | 17:16 | |
rm_work | posted | 17:16 |
rm_work | i guess I'll read the new one to see if you already addressed any of my comments | 17:16 |
rm_work | though if you want to read my comments it might be easier for you to say immediately whether you did or not :) | 17:17 |
rm_work | alee_: ^^ | 17:17 |
alee_ | rm_work, reading -- I did address some of them | 17:18 |
alee_ | rm_work, looking at the rest .. | 17:18 |
rm_work | heh first time https://review.openstack.org/#/c/129048/2..3/specs/kilo/identify-cas.rst has actually been helpful | 17:20 |
rm_work | (changing the base) | 17:20 |
alee_ | :) | 17:20 |
rm_work | so yeah, POST /cas/{ca_id}/unset-preferred doesnt make sense now | 17:21 |
alee_ | rm_work, agreed. | 17:21 |
alee_ | rm_work, woodster_ - I'm not a database guy -- so I think I need woodster_ to comment on the other suggestions. | 17:21 |
rm_work | yeah, I used to do a lot of DB work at my last job, and we did the sort of thing I am suggesting *a lot* | 17:22 |
alee_ | ie. the unique table for hard enforcement, and the key value pair thing | 17:22 |
rm_work | because AFAIK storing blobs in a DB is an absolute last resort | 17:22 |
alee_ | I know we did that for secrets -> secret metadata | 17:23 |
rm_work | but people here tend to not care as much it seems <_< | 17:23 |
rm_work | or maybe my view is outdated | 17:23 |
rm_work | I used to work with SAP / ABAP, so everything else was definitely outdated :P | 17:23 |
alee_ | rm_work, I think your view is reasonable -- but I'll defer to the real DB folks. | 17:24 |
alee_ | woodster_, redrobot , jvrbanac ^^ | 17:24 |
* rm_work is currently fighting against JSON BLOB storaging in his own project, too | 17:24 | |
*** mikedillion has quit IRC | 17:24 | |
alee_ | rm_work, can you add your remaining comments to the new patchset for convenience ? | 17:24 |
rm_work | err, apparently storage + storing = storaging :P | 17:24 |
rm_work | heh, I can try to pick things out | 17:25 |
alee_ | thanks! | 17:25 |
*** mikedillion has joined #openstack-barbican | 17:25 | |
rm_work | k yeah moving them all | 17:26 |
rm_work | don't comment on them in the last patchset :P | 17:26 |
alee_ | rm_work, cool - thanks | 17:31 |
*** kgriffs is now known as kgriffs|afk | 17:31 | |
rm_work | alee_: ok, published new comments | 17:35 |
rm_work | please read/comment on those instead :) | 17:36 |
*** mikedillion has quit IRC | 17:40 | |
*** ayoung has quit IRC | 17:44 | |
*** ayoung has joined #openstack-barbican | 18:20 | |
alee_ | rm_work, thanks - will comment | 18:23 |
*** gyee has joined #openstack-barbican | 18:25 | |
*** stanzi_ has joined #openstack-barbican | 18:27 | |
*** kgriffs|afk is now known as kgriffs | 18:31 | |
*** gyee has quit IRC | 18:35 | |
alee_ | rm_work, thanks - commented | 18:37 |
*** gyee has joined #openstack-barbican | 18:38 | |
*** gyee has quit IRC | 18:38 | |
*** gyee has joined #openstack-barbican | 18:39 | |
*** kgriffs is now known as kgriffs|afk | 18:42 | |
*** paul_glass has joined #openstack-barbican | 18:54 | |
*** stanzi_ has quit IRC | 19:05 | |
*** stanzi has joined #openstack-barbican | 19:15 | |
*** mikedillion has joined #openstack-barbican | 19:17 | |
*** SheenaG1 has joined #openstack-barbican | 19:24 | |
*** ayoung has quit IRC | 19:25 | |
*** SheenaG11 has joined #openstack-barbican | 19:26 | |
*** lordbyron820 has joined #openstack-barbican | 19:27 | |
*** SheenaG1 has quit IRC | 19:29 | |
*** kgriffs|afk is now known as kgriffs | 19:33 | |
*** gyee has quit IRC | 19:34 | |
SheenaG11 | reaperhulk: ping | 19:34 |
alee_ | woodster_, ? | 19:41 |
*** bdpayne has joined #openstack-barbican | 19:41 | |
alee_ | redrobot, woodster_ when a secret is created, do we store the creator userid by default with the secret entry? | 19:42 |
*** ayoung has joined #openstack-barbican | 19:59 | |
*** darrenmoffat has quit IRC | 20:15 | |
*** darrenmoffat has joined #openstack-barbican | 20:16 | |
*** crc32 has joined #openstack-barbican | 20:44 | |
*** kebray has quit IRC | 20:45 | |
redrobot | alee_ I don't think so, I think we only store the project ID | 20:47 |
*** stanzi has quit IRC | 20:48 | |
*** kebray has joined #openstack-barbican | 20:49 | |
*** stanzi has joined #openstack-barbican | 20:51 | |
*** david-lyle has joined #openstack-barbican | 20:56 | |
openstackgerrit | Jeff Fischer proposed openstack/barbican: initial commit for DigiCert Barbican plugin https://review.openstack.org/138199 | 20:58 |
*** mikedillion has quit IRC | 21:03 | |
*** JeffF has quit IRC | 21:07 | |
*** JeffF has joined #openstack-barbican | 21:14 | |
alee_ | JeffF, ping | 21:18 |
JeffF | alee_: hey | 21:19 |
alee_ | JeffF, hey -- saw you put up a CR for digicert | 21:19 |
JeffF | yes | 21:19 |
alee_ | does DigiCert accept CMC requests? | 21:19 |
JeffF | yes we can | 21:20 |
alee_ | cool - you should take a look at https://review.openstack.org/135490 | 21:20 |
JeffF | I don't know that we have before, but I talked with our CA developer the other day and he verified that we can | 21:20 |
alee_ | and https://review.openstack.org/129048 | 21:21 |
alee_ | proposed common api for certs | 21:21 |
JeffF | oh, good. | 21:21 |
JeffF | I would love any and all information about this. | 21:21 |
alee_ | JeffF, yeah - please comment and +1/-1 | 21:22 |
JeffF | CMC requests will be the method used for the common API? | 21:22 |
alee_ | JeffF, yup - we'll still have the order interface - but it will use cmc as the vechicle | 21:24 |
alee_ | vehicle .. | 21:24 |
*** stanzi has quit IRC | 21:24 | |
JeffF | ok, I'll start reviewing and digesting this. | 21:25 |
alee_ | JeffF, thanks | 21:26 |
*** bubbva has quit IRC | 21:55 | |
*** stanzi_ has joined #openstack-barbican | 21:55 | |
*** gyee has joined #openstack-barbican | 22:03 | |
*** stanzi_ has quit IRC | 22:04 | |
*** ryanpetrello_ has joined #openstack-barbican | 22:06 | |
*** ryanpetrello has quit IRC | 22:06 | |
*** ryanpetrello_ is now known as ryanpetrello | 22:06 | |
*** ryanpetrello has quit IRC | 22:14 | |
*** lordbyron8201 has joined #openstack-barbican | 22:24 | |
*** JeffF has quit IRC | 22:25 | |
*** lordbyron8201 has quit IRC | 22:28 | |
*** lordbyron8201 has joined #openstack-barbican | 22:31 | |
*** dave-mccowan has quit IRC | 22:33 | |
*** paul_glass has quit IRC | 22:53 | |
*** lordbyron8201 has quit IRC | 22:55 | |
openstackgerrit | Merged openstack/barbican: Add functional tests for order https://review.openstack.org/136155 | 23:02 |
openstackgerrit | Merged openstack/barbican: Workflow documentation is now in infra-manual https://review.openstack.org/139309 | 23:07 |
*** jorge_munoz has quit IRC | 23:27 | |
*** kgriffs is now known as kgriffs|afk | 23:27 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!