*** kgriffs|afk is now known as kgriffs | 00:32 | |
*** kgriffs is now known as kgriffs|afk | 00:42 | |
*** stanzi has joined #openstack-barbican | 00:43 | |
*** ryanpetrello has joined #openstack-barbican | 00:44 | |
*** ryanpetrello has quit IRC | 00:51 | |
*** stanzi has quit IRC | 00:52 | |
*** ryanpetrello has joined #openstack-barbican | 01:00 | |
openstackgerrit | John Wood proposed openstack/barbican: Update log messages to oslo.i18n https://review.openstack.org/138247 | 01:05 |
---|---|---|
openstackgerrit | John Wood proposed openstack/barbican: Fix diff-cover gate broken by parent CR https://review.openstack.org/139894 | 01:05 |
*** ryanpetrello has quit IRC | 01:37 | |
*** dave-mccowan has joined #openstack-barbican | 01:51 | |
openstackgerrit | John Wood proposed openstack/barbican: Fix diff-cover gate broken by parent CR https://review.openstack.org/139894 | 02:06 |
*** ryanpetrello has joined #openstack-barbican | 02:10 | |
*** woodster_ has joined #openstack-barbican | 02:41 | |
*** ryanpetrello has quit IRC | 02:44 | |
*** ryanpetrello has joined #openstack-barbican | 02:51 | |
*** ryanpetrello has quit IRC | 03:23 | |
*** david-lyle_afk has quit IRC | 03:31 | |
*** miqui_ has quit IRC | 03:40 | |
*** david-lyle_afk has joined #openstack-barbican | 03:43 | |
*** david-lyle_afk has quit IRC | 03:50 | |
*** david-lyle_afk has joined #openstack-barbican | 04:02 | |
*** david-lyle_afk has quit IRC | 04:02 | |
*** dave-mccowan has quit IRC | 04:08 | |
*** david-lyle_afk has joined #openstack-barbican | 05:01 | |
*** kebray has joined #openstack-barbican | 05:05 | |
*** kebray has quit IRC | 05:05 | |
*** kebray has joined #openstack-barbican | 05:09 | |
*** kebray has quit IRC | 05:54 | |
*** Nirupama has joined #openstack-barbican | 06:08 | |
*** zz_dimtruck is now known as dimtruck | 06:25 | |
*** Nirupama has quit IRC | 06:28 | |
*** Nirupama has joined #openstack-barbican | 06:28 | |
*** dimtruck is now known as zz_dimtruck | 07:10 | |
*** jamielennox is now known as jamielennox|away | 08:12 | |
*** woodster_ has quit IRC | 09:00 | |
openstackgerrit | Tim Kelsey proposed openstack/barbican: Adding client certificates to connection credentials https://review.openstack.org/135217 | 12:03 |
*** jamielennox|away is now known as jamielennox | 12:31 | |
*** dave-mccowan has joined #openstack-barbican | 12:35 | |
*** jamielennox is now known as jamielennox|away | 12:41 | |
*** woodster_ has joined #openstack-barbican | 12:42 | |
*** dave-mccowan_ has joined #openstack-barbican | 12:55 | |
*** dave-mccowan has quit IRC | 12:56 | |
*** dave-mccowan_ is now known as dave-mccowan | 12:56 | |
*** Nirupama has quit IRC | 13:32 | |
*** ametts has joined #openstack-barbican | 13:38 | |
openstackgerrit | Merged openstack/barbican-specs: Remove the tenant-secret association table https://review.openstack.org/135158 | 14:02 |
*** dave-mccowan_ has joined #openstack-barbican | 14:02 | |
reaperhulk | redrobot: we should update our channel topic since that meeting was last thursday | 14:05 |
*** dave-mccowan has quit IRC | 14:05 | |
*** dave-mccowan_ is now known as dave-mccowan | 14:05 | |
*** dave-mccowan_ has joined #openstack-barbican | 14:08 | |
*** dave-mccowan has quit IRC | 14:11 | |
*** dave-mccowan_ is now known as dave-mccowan | 14:11 | |
openstackgerrit | Merged openstack/barbican: Update log messages to oslo.i18n https://review.openstack.org/138247 | 14:15 |
*** mikedillion has joined #openstack-barbican | 14:17 | |
*** stanzi has joined #openstack-barbican | 14:17 | |
*** ryanpetrello has joined #openstack-barbican | 14:22 | |
*** ayoung has joined #openstack-barbican | 14:26 | |
*** ayoung has quit IRC | 14:26 | |
*** ayoung has joined #openstack-barbican | 14:33 | |
*** zz_dimtruck is now known as dimtruck | 15:22 | |
openstackgerrit | Merged openstack/python-barbicanclient: Trivial change to docs https://review.openstack.org/139265 | 15:29 |
*** SheenaG1 has joined #openstack-barbican | 15:29 | |
*** nkinder has joined #openstack-barbican | 15:30 | |
alee_ | redrobot, ping | 15:31 |
*** JeffF has joined #openstack-barbican | 15:33 | |
*** jorge_munoz has joined #openstack-barbican | 15:40 | |
*** mikedillion has quit IRC | 15:40 | |
openstackgerrit | Ade Lee proposed openstack/barbican-specs: Add Cert API Spec. https://review.openstack.org/135490 | 15:48 |
*** dave-mccowan has quit IRC | 15:51 | |
*** dave-mccowan has joined #openstack-barbican | 15:52 | |
*** nkinder has quit IRC | 15:57 | |
*** paul_glass has joined #openstack-barbican | 15:58 | |
*** nkinder has joined #openstack-barbican | 15:58 | |
*** stanzi has quit IRC | 16:04 | |
*** stanzi has joined #openstack-barbican | 16:04 | |
*** david-lyle_afk is now known as david-lyle | 16:06 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/140048 | 16:16 |
*** jorge_munoz has quit IRC | 16:17 | |
*** jorge_munoz has joined #openstack-barbican | 16:19 | |
*** paul_glass has quit IRC | 16:19 | |
*** stanzi has quit IRC | 16:19 | |
*** mikedillion has joined #openstack-barbican | 16:22 | |
*** jorge_munoz has quit IRC | 16:39 | |
*** stanzi has joined #openstack-barbican | 16:41 | |
*** darrenmoffat has quit IRC | 16:42 | |
*** darrenmoffat has joined #openstack-barbican | 16:44 | |
*** paul_glass has joined #openstack-barbican | 16:44 | |
*** stanzi has quit IRC | 16:48 | |
*** lordbyron8201 has joined #openstack-barbican | 16:49 | |
*** ametts has quit IRC | 16:51 | |
*** lordbyron8201 has quit IRC | 16:53 | |
*** jorge_munoz has joined #openstack-barbican | 17:07 | |
*** lordbyron8201 has joined #openstack-barbican | 17:08 | |
*** crc32 has joined #openstack-barbican | 17:09 | |
*** ametts has joined #openstack-barbican | 17:10 | |
*** SheenaG1 has quit IRC | 17:17 | |
*** SheenaG1 has joined #openstack-barbican | 17:18 | |
*** redrobot changes topic to "Incubated OpenStack Barbican" | 17:18 | |
*** openstackgerrit has quit IRC | 17:19 | |
*** openstackgerrit has joined #openstack-barbican | 17:19 | |
*** jorge_munoz has quit IRC | 17:26 | |
*** kebray has joined #openstack-barbican | 17:37 | |
openstackgerrit | Merged openstack/python-barbicanclient: Correctly set pbr version name https://review.openstack.org/139292 | 17:37 |
*** kebray has quit IRC | 18:12 | |
*** paul_glass has quit IRC | 18:14 | |
*** mikedillion has quit IRC | 18:19 | |
*** mikedillion has joined #openstack-barbican | 18:20 | |
openstackgerrit | Merged openstack/python-barbicanclient: Workflow documentation is now in infra-manual https://review.openstack.org/139368 | 18:20 |
*** mikedillion has quit IRC | 18:22 | |
*** stanzi has joined #openstack-barbican | 18:31 | |
*** stanzi has quit IRC | 18:35 | |
*** JeffF has left #openstack-barbican | 18:44 | |
*** jaosorior has joined #openstack-barbican | 18:45 | |
*** ametts has quit IRC | 18:51 | |
*** paul_glass has joined #openstack-barbican | 18:58 | |
*** kebray has joined #openstack-barbican | 19:01 | |
*** ametts has joined #openstack-barbican | 19:04 | |
*** kebray has quit IRC | 19:13 | |
*** kebray has joined #openstack-barbican | 19:23 | |
*** jorge_munoz has joined #openstack-barbican | 19:48 | |
*** nkinder has quit IRC | 19:50 | |
*** tkelsey has joined #openstack-barbican | 19:53 | |
*** kebray has quit IRC | 19:54 | |
*** rellerreller has joined #openstack-barbican | 19:58 | |
redrobot | weekly barbican meeting is starting now in #openstack-meeting-alt | 20:01 |
openstackgerrit | Steve Heyman proposed openstack/barbican-specs: Add spec to support running functional tests as different users https://review.openstack.org/135724 | 20:05 |
*** gyee has joined #openstack-barbican | 20:13 | |
*** kebray has joined #openstack-barbican | 20:30 | |
*** JeffF has joined #openstack-barbican | 20:34 | |
openstackgerrit | Merged openstack/castellan: Workflow documentation is now in infra-manual https://review.openstack.org/139311 | 20:38 |
openstackgerrit | greghaynes proposed openstack/barbican: Dont set debug and verbose as our example https://review.openstack.org/140140 | 20:42 |
*** kebray has quit IRC | 20:43 | |
*** stanzi has joined #openstack-barbican | 20:49 | |
*** lordbyron8201 has quit IRC | 20:53 | |
*** stanzi has quit IRC | 20:53 | |
greghaynes | hyakuhei: Hey O/ | 20:59 |
greghaynes | hyakuhei: I was hoping to get to say Hi at the summit but never was able to run into you, fellow hper doing tripleo TLS stuffs | 21:00 |
*** nkinder has joined #openstack-barbican | 21:02 | |
greghaynes | So, I was wondering if someone could take a minute to answer a few (probably silly newcomer) questions I have about trying to use barbican for tripleo's use case | 21:02 |
alee_ | greghaynes, hey - I think I ran into another triple-O dev on the way back from Paris. I think she said you were looking into trying to get certs? | 21:02 |
greghaynes | yes! | 21:02 |
alee_ | greghaynes, cool -- so tell us a little more about your use case | 21:03 |
greghaynes | So, our use case is essentially that we need to be able to do snakeoil CA and cert generation for devs/CI while allowing prod users to have a good way to integrate with their own pki | 21:03 |
*** kebray has joined #openstack-barbican | 21:04 | |
greghaynes | as is right now we have a some bash + python that do this and we tell the users they can provide some json with their certs/keys if they want to use their own pki... but ideally we can use something else (barbican) for this | 21:04 |
greghaynes | its purely TLS certs, to specify a bit more | 21:05 |
alee_ | greghaynes, these are long lasting certs? | 21:05 |
alee_ | ie. tls certs for real servers | 21:05 |
alee_ | that you might want to renew for instance? or rekey? | 21:06 |
greghaynes | initially, yes. There is talk about doing some of the more fancy stuff I think hyakuhei is working on but we dont really support TLS much right now so walking first | 21:06 |
alee_ | greghaynes, how often do these cert requests come in? | 21:07 |
alee_ | so let me explain the state of certs right now in barbican, and where it is going .. | 21:08 |
alee_ | barbican has an orders interface that can be used to generate a cert given certain parameters (like for example a cert-request) | 21:09 |
greghaynes | so for the dev/ci use case there is 2 snakeoil CA's that we need to make certs off of. then after we make each CA theres a whole slew of cert requests we need to make (for all the various services) and then we need a good way to ask "what was cert/key for service foo". Ideally there is a good decoupling layer where a user could then upload a "service foo" cert/key and then we simply notice that | 21:09 |
greghaynes | and dont gen a snakeoil cert/key for that service | 21:09 |
greghaynes | alee_: yep, was just looking at that | 21:10 |
alee_ | this orders api talks to any number of back-end ca plugins -- which talk to a backend ca | 21:10 |
alee_ | on the backend ca, a cert request is made and then needs to be approved by that ca | 21:10 |
greghaynes | Has anyone made a sort of snakeoil ca plugin? | 21:11 |
alee_ | or if you happen to have a dogtag ca in the backend - then you can configure the cert request to be made by a trusted agent and have it get automatically approved. | 21:11 |
greghaynes | hrm | 21:12 |
alee_ | we have a few plugins there right now -- dogtag, symantec, digicert and a dev plugin. | 21:12 |
greghaynes | oh, whats the dev one called? I saw the others | 21:13 |
alee_ | greghaynes, its very basic -- I dont think it even gives you back a cert | 21:13 |
greghaynes | Theres a simple_cert_manager but that seems to be a little too simple ;) | 21:13 |
greghaynes | yea, thats the simple_cert_one | 21:13 |
alee_ | that the basic one. | 21:13 |
alee_ | now -- the order interface also has the limitation right now, that you have to know which ca you want to talk to | 21:14 |
alee_ | because the parameters are just passed as -is back to the ca | 21:14 |
alee_ | hence the need for a common cert API | 21:14 |
greghaynes | I really couldnt find any good docs on how to hit the orders interface to do cert gen, any pointers on that? | 21:15 |
greghaynes | ok | 21:15 |
alee_ | so that a client could create a generic order and it would go to whatever ca | 21:15 |
alee_ | thats the BP thats in review .. | 21:15 |
greghaynes | Yep, was just reading that | 21:15 |
alee_ | https://review.openstack.org/135490 | 21:15 |
alee_ | which we hope to land this week. | 21:15 |
alee_ | (and then start working on) | 21:16 |
greghaynes | so, how do you interact with the existing orders interface to do a cert request? | 21:16 |
alee_ | you'll notice in the bp, there are four different ways of gettign a cert | 21:16 |
alee_ | so the currently supported one is method 4 | 21:16 |
alee_ | ("custom") | 21:17 |
greghaynes | ok, gotcha | 21:17 |
alee_ | method 1 -- simple-cmc should actually be dead easy to write. | 21:17 |
alee_ | and will be the first one in there/ | 21:17 |
alee_ | so -- the plan is to get that interface in -- and then to work on clients to interact with the interface | 21:18 |
alee_ | greghaynes, now the client story is interesting | 21:18 |
alee_ | greghaynes, we plan to add functionality to barbican-client , but | 21:18 |
alee_ | I think that the right way to do it is to implement a barbican backend to certmonger | 21:19 |
alee_ | and I plan to work on that sometime. | 21:19 |
alee_ | you should check out certmonger | 21:19 |
greghaynes | hrm, im sure we would like the -client functionality for our use case | 21:19 |
alee_ | its pretty nice. | 21:19 |
greghaynes | If you do end up using it, I imagine it would be barbican-client -> dbus -> certmonger? | 21:20 |
alee_ | possibly -- I was actually thinking of adding something like a python front end to cert,onger | 21:21 |
alee_ | but thats intriguing .. | 21:21 |
greghaynes | Another question, how do CA's get into barbican | 21:21 |
alee_ | so it would be certmonger-python -> dbus -> certmonger -> barbican | 21:21 |
alee_ | https://review.openstack.org/129048 | 21:21 |
rm_work | I really hope cert-monger doesn't HAVE to be in the process... | 21:22 |
greghaynes | and additionally, is there any interface for requesting a CA to be generated | 21:22 |
alee_ | (it will be by config) | 21:22 |
alee_ | rm_work, yeah - I know --- I think we'll end up with barbican-client-> barbican as well | 21:22 |
greghaynes | Yes, this is my concern with certmonger, im +1 on using it but we would probably have to support running without it and therefore we would want to test without it | 21:22 |
alee_ | yup definitely | 21:23 |
alee_ | I'm thinking there will be two methods .. | 21:23 |
greghaynes | so do you think making a snakeoil ca plugin seems reasonable? I could definitely work on deving that | 21:23 |
alee_ | certmonger-python-> dbus -> certmonger -> barbican | 21:23 |
alee_ | and barbcian-client -> barbican | 21:23 |
greghaynes | basically one that auto-approves all requets and just makes the openssl-python calls directly | 21:24 |
alee_ | greghaynes, definitely :) | 21:24 |
greghaynes | Awesome | 21:24 |
alee_ | we need that for our testing for sure | 21:24 |
greghaynes | Yep, thats exactly our use case | 21:24 |
alee_ | so if you want to dev that , that would be great. | 21:24 |
greghaynes | and then ill also probably try and fill in the python-barbicanclient because AFAICT its still needs to know about cert generation | 21:25 |
alee_ | greghaynes, its one of those things that had been planned | 21:25 |
alee_ | yes it does | 21:25 |
alee_ | as soon as we get the cert api landed , we know what to do in the clients | 21:25 |
alee_ | greghaynes, though of course, dogtag could already work as your snake oil ca | 21:26 |
alee_ | (but you'd need to install/configure dogtag) | 21:27 |
greghaynes | hrmm | 21:27 |
greghaynes | Ill look at it, its definitely a possibility | 21:27 |
alee_ | greghaynes, we still need a better dev plugin in any case though .. in case someone wants to test w/o dogtag | 21:28 |
greghaynes | Yep. The snakeoil thing is win for stuff like "getting started docs" | 21:28 |
greghaynes | as long as it has a big warning of "never actually use this in prod" | 21:29 |
alee_ | yup | 21:29 |
greghaynes | well, thanks a ton for the help! ill probably be back with questions eventually | 21:29 |
greghaynes | also, what time zone are you? | 21:29 |
alee_ | EST | 21:30 |
greghaynes | ok, im PSY | 21:30 |
greghaynes | er, PST | 21:30 |
alee_ | greghaynes, :) I was going to say --- you're a korean singer? | 21:30 |
greghaynes | Ive moved on since then :) | 21:30 |
alee_ | (and the world is a better place ... :) | 21:31 |
*** gyee has quit IRC | 21:32 | |
*** tkelsey has quit IRC | 21:36 | |
*** kebray has quit IRC | 21:51 | |
*** kebray has joined #openstack-barbican | 21:58 | |
*** alee_ has left #openstack-barbican | 22:07 | |
*** alee_ has joined #openstack-barbican | 22:07 | |
*** stanzi has joined #openstack-barbican | 22:27 | |
*** SheenaG1 has quit IRC | 22:29 | |
openstackgerrit | Merged openstack/barbican: Updated from global requirements https://review.openstack.org/140048 | 22:47 |
*** stanzi has quit IRC | 22:55 | |
*** paul_glass has quit IRC | 23:02 | |
*** ayoung has quit IRC | 23:03 | |
*** ryanpetrello has quit IRC | 23:12 | |
*** ryanpetrello has joined #openstack-barbican | 23:14 | |
*** jamielennox|away is now known as jamielennox | 23:15 | |
*** rellerreller has quit IRC | 23:16 | |
*** ryanpetrello has quit IRC | 23:20 | |
*** kebray has quit IRC | 23:22 | |
*** jaosorior has quit IRC | 23:23 | |
*** ametts has quit IRC | 23:35 | |
*** dimtruck is now known as zz_dimtruck | 23:56 | |
*** gyee has joined #openstack-barbican | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!