*** lisa2 has joined #openstack-barbican | 00:00 | |
*** lisa1 has quit IRC | 00:01 | |
*** ametts has quit IRC | 00:02 | |
*** lisa2 has quit IRC | 00:08 | |
*** rm_work is now known as rm_work|away | 00:21 | |
*** david-lyle is now known as david-lyle_afk | 00:35 | |
*** kebray has quit IRC | 00:52 | |
*** kebray has joined #openstack-barbican | 00:59 | |
*** kgriffs is now known as kgriffs|afk | 01:02 | |
*** kebray has quit IRC | 01:11 | |
*** SheenaG1 has joined #openstack-barbican | 01:13 | |
*** ryanpetrello has quit IRC | 01:27 | |
*** ryanpetrello has joined #openstack-barbican | 01:32 | |
*** bdpayne has quit IRC | 01:46 | |
*** gyee has quit IRC | 02:09 | |
*** ryanpetrello has quit IRC | 02:19 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Delete secret from plugin only if there's metadata https://review.openstack.org/141963 | 02:30 |
---|---|---|
openstackgerrit | greghaynes proposed openstack/barbican: WIP Create snakoil certificate plugin https://review.openstack.org/140575 | 02:30 |
openstackgerrit | greghaynes proposed openstack/barbican: Create snakoil certificate plugin https://review.openstack.org/140575 | 02:31 |
*** lisaclark has joined #openstack-barbican | 02:37 | |
*** SheenaG1 has quit IRC | 02:40 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Delete secret from plugin only if there's metadata https://review.openstack.org/141963 | 02:48 |
*** jaosorior has joined #openstack-barbican | 02:52 | |
*** SheenaG1 has joined #openstack-barbican | 03:30 | |
*** kebray has joined #openstack-barbican | 03:45 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Actually run type order creation test https://review.openstack.org/141974 | 03:51 |
*** stanzi has joined #openstack-barbican | 03:56 | |
*** Stanzi_ has joined #openstack-barbican | 03:56 | |
openstackgerrit | John Wood proposed openstack/barbican: Add I18n-related unit tests (Part 3) https://review.openstack.org/141535 | 04:17 |
*** lisaclark has quit IRC | 04:23 | |
*** reaperhulk has quit IRC | 04:34 | |
*** reaperhulk_ has joined #openstack-barbican | 04:34 | |
*** zz_dimtruck has quit IRC | 04:35 | |
*** lbragstad has quit IRC | 04:35 | |
*** jraim_ has quit IRC | 04:36 | |
*** zz_dimtruck has joined #openstack-barbican | 04:38 | |
*** lbragstad has joined #openstack-barbican | 04:38 | |
*** jraim has joined #openstack-barbican | 04:38 | |
*** zz_dimtruck is now known as dimtruck | 04:38 | |
*** ayoung has quit IRC | 04:52 | |
*** kebray has quit IRC | 04:52 | |
*** kebray has joined #openstack-barbican | 04:53 | |
openstackgerrit | greghaynes proposed openstack/barbican-specs: WIP Snakeoil CA https://review.openstack.org/141981 | 05:21 |
*** ajc___ has joined #openstack-barbican | 05:24 | |
openstackgerrit | greghaynes proposed openstack/barbican: Create snakeoil certificate plugin https://review.openstack.org/140575 | 05:42 |
openstackgerrit | greghaynes proposed openstack/barbican: Create snakeoil certificate plugin https://review.openstack.org/140575 | 05:43 |
*** Stanzi_ has quit IRC | 05:51 | |
*** stanzi has quit IRC | 05:51 | |
*** stanzi_ has joined #openstack-barbican | 05:52 | |
*** Stanzi has joined #openstack-barbican | 05:52 | |
*** stanzi_ has quit IRC | 05:56 | |
*** Stanzi has quit IRC | 05:56 | |
*** Stanzi_ has joined #openstack-barbican | 06:01 | |
*** stanzi has joined #openstack-barbican | 06:01 | |
*** jaosorior has quit IRC | 06:03 | |
*** Stanzi_ has quit IRC | 06:17 | |
*** stanzi has quit IRC | 06:17 | |
*** stanzi_ has joined #openstack-barbican | 06:18 | |
*** Stanzi has joined #openstack-barbican | 06:18 | |
*** stanzi_ has quit IRC | 06:22 | |
*** Stanzi has quit IRC | 06:22 | |
openstackgerrit | John Wood proposed openstack/barbican: Add I18n-related unit tests (Part 3) https://review.openstack.org/141535 | 06:26 |
*** stanzi has joined #openstack-barbican | 06:49 | |
*** Stanzi_ has joined #openstack-barbican | 06:49 | |
*** Stanzi_ has quit IRC | 06:57 | |
*** stanzi has quit IRC | 06:57 | |
*** jamielennox is now known as jamielennox|away | 07:01 | |
*** lisa1 has joined #openstack-barbican | 07:55 | |
*** lisa1 has quit IRC | 07:59 | |
*** darrenmoffat has quit IRC | 08:47 | |
*** darrenmoffat has joined #openstack-barbican | 08:48 | |
*** lisa3 has joined #openstack-barbican | 08:49 | |
*** lisa3 has quit IRC | 08:54 | |
*** woodster_ has quit IRC | 09:10 | |
*** lisa3 has joined #openstack-barbican | 09:44 | |
*** lisa3 has quit IRC | 09:48 | |
*** darrenmoffat has quit IRC | 10:11 | |
*** darrenmoffat has joined #openstack-barbican | 10:18 | |
*** Stanzi has joined #openstack-barbican | 10:18 | |
*** Stanzi has quit IRC | 10:22 | |
*** lisa3 has joined #openstack-barbican | 11:32 | |
*** lisa3 has quit IRC | 11:37 | |
*** jraim_ has joined #openstack-barbican | 12:12 | |
*** dougwig_ has joined #openstack-barbican | 12:12 | |
*** erw_ has joined #openstack-barbican | 12:13 | |
*** jraim has quit IRC | 12:14 | |
*** jraim_ is now known as jraim | 12:14 | |
*** dougwig has quit IRC | 12:14 | |
*** erw has quit IRC | 12:14 | |
*** dougwig_ is now known as dougwig | 12:14 | |
*** ajc___ has quit IRC | 12:29 | |
*** woodster_ has joined #openstack-barbican | 12:51 | |
openstackgerrit | Tim Kelsey proposed openstack/barbican: Adding client certificates to connection credentials https://review.openstack.org/135217 | 12:59 |
openstackgerrit | Tim Kelsey proposed openstack/barbican: Removing conditional logic around KMIP tests https://review.openstack.org/142096 | 13:14 |
openstackgerrit | John Wood proposed openstack/barbican: Add I18n-related unit tests (Part 3) https://review.openstack.org/141535 | 13:16 |
*** alee has quit IRC | 13:18 | |
openstackgerrit | John Wood proposed openstack/barbican: Add I18n-related unit tests (Part 3) https://review.openstack.org/141535 | 13:20 |
*** reaperhulk_ is now known as reaperhulk | 13:22 | |
*** alee has joined #openstack-barbican | 13:28 | |
*** alee has quit IRC | 13:34 | |
*** SheenaG1 has quit IRC | 13:58 | |
*** kebray has quit IRC | 14:37 | |
*** ametts has joined #openstack-barbican | 14:47 | |
*** alee has joined #openstack-barbican | 14:48 | |
*** dimtruck is now known as zz_dimtruck | 14:49 | |
alee | woodster_, ping | 14:52 |
*** ayoung has joined #openstack-barbican | 14:53 | |
woodster_ | alee: good morning | 14:53 |
alee | woodster_, morning | 14:53 |
alee | woodster_, I started working on the cert api patches and have changed my mind on the whole separate methods on the plugin interface thing | 14:54 |
alee | woodster_, that is -- I no longer think that we need to implement different methods issue_cmc_*() | 14:55 |
*** kgriffs|afk is now known as kgriffs | 14:55 | |
alee | but rather continue to use issue_cert_request() | 14:55 |
alee | woodster_, there were two reasons I originally thought we should do that .. | 14:56 |
alee | 1. the outputs of those methods would be different as they would be handling cmc responses. We've decided that would no longer happen. | 14:57 |
alee | 2. I wanted to solve the "out-of-date" plugin problem | 14:57 |
alee | what I realized though is that having separate methods would not solve the out-of date plugin problem. | 14:58 |
alee | woodster_, so imagine that a year from now we decide we want to support ACME requests. | 14:59 |
woodster_ | alee that makes sense | 14:59 |
alee | and we have five plugins we know of (and any number of private plugins we don't know of) | 14:59 |
alee | how do we ensure that ACME requests do not get routed accidentally to a plugin that does not support them? | 15:00 |
alee | (or that does not yet support them) | 15:00 |
*** zz_dimtruck is now known as dimtruck | 15:00 | |
alee | one way is to have different methods -- as I described in the BP | 15:01 |
alee | then when we route the request, we would call a method which the plugin has not yet implemented -- and the default implementation would say "NotImplemented" | 15:01 |
alee | thats not a very clean way of solving this though .. | 15:02 |
alee | a better way is to beef up the supports() method. | 15:02 |
alee | that is -- instead of supports() returning true/false, it would return a list of methods that it does support. | 15:04 |
alee | so something like {"request_type": ["simple-cmc", "full-cmc", "stored-key", "custom"]} | 15:05 |
alee | for example .. | 15:05 |
alee | then when a plugin supports "acme", it will add it to the string returned by supports() | 15:05 |
alee | woodster_, what do you think? | 15:06 |
alee | woodster_, for backwards compatibility - we can call the new method provides() .. | 15:08 |
alee | with a default implementation of "custom" .. | 15:08 |
*** lisaclark has joined #openstack-barbican | 15:10 | |
woodster_ | alee: that makes sense. Are you fine with plugins having type logic then when they support more than one? Works for me, but I recall that being a concern | 15:12 |
alee | woodster_, type logic? -- meaning they have to do different things based on request_type? I think thats inevitable. I was concerned with requests going to plugins that did support the type. | 15:14 |
alee | and trusting the plugin to have an up-to-date supports() method | 15:14 |
alee | woodster_, the mechanism I descibe above forces the plugin to update its supports() method if it wants to get requests of a different type. | 15:15 |
woodster_ | Oh got it. I thought up front verification to see if a plugin supported a request was already planned though? | 15:16 |
alee | woodster_, yeah - we had just left that vague and up to the plugin though | 15:16 |
alee | woodster_, that is -- we said something like this .. | 15:17 |
alee | your supports method should look like --- | 15:17 |
alee | if request_type == a, return true; if if b: return false; else return false | 15:18 |
alee | that would work because a new type "c" would return false | 15:18 |
alee | but - I think its poor design to specify the format of the plugin code. Rather we should specify the interface (input/output) | 15:19 |
alee | and the interface should be -- supports() will return the list of supported methods .. and the plugin will be selected accordingly | 15:20 |
alee | if we end up thinking of how a plugin should implement a method, then its probably a good idea to implement that method in barbican-core | 15:20 |
alee | woodster_, so yeah - I think I'm going to add a provides() method and use that instead of supports() and have it return as above. | 15:22 |
alee | woodster_, unless you think I can reuse supports()? | 15:22 |
woodster_ | alee: that makes sense to me. So those choices should be enums. That's also a contract break unless we also check for Boolean | 15:23 |
alee | woodster_, well - its a contract break unless I use a new method (provides()) | 15:24 |
alee | on the other hand -- very few plugins are out there right now | 15:24 |
*** alee has quit IRC | 15:25 | |
*** alee has joined #openstack-barbican | 15:25 | |
*** ayoung has quit IRC | 15:25 | |
*** ayoung has joined #openstack-barbican | 15:25 | |
alee | so if we want to break the contract, nows a good time. especically as the supports() method really did not do much at this point in any case. | 15:25 |
alee | (all existing plugins I think just return True) | 15:26 |
*** rellerreller has joined #openstack-barbican | 15:26 | |
woodster_ | Supports also performs validation | 15:31 |
alee | woodster_, yes -- although noone quite knows what that means that now .. | 15:32 |
alee | woodster_, what kind of validation did you have in mind? | 15:32 |
alee | woodster_, I'm ok with using another method provides() if we think that supports() will do something else useful. right now, I;m not sure what that is .. | 15:34 |
*** stanzi has joined #openstack-barbican | 15:35 | |
*** Stanzi_ has joined #openstack-barbican | 15:35 | |
alee | woodster_, for cases 1-3 , we will do a bunch of validation in pki-core | 15:35 |
alee | case 4 (custom) validation cannot be defintion be done in core -- but I would argue that its up to the plugin to do that validation in issue_cert_request() and then fail there. | 15:36 |
alee | certainly in the custom case, it can't go anywhere else. | 15:37 |
alee | sorry s/pki-core/barbican-core | 15:37 |
alee | (dogtag is delivered in a pki-core package :)) | 15:37 |
*** SheenaG1 has joined #openstack-barbican | 15:42 | |
*** Stanzi_ has quit IRC | 15:42 | |
*** stanzi has quit IRC | 15:42 | |
*** Stanzi has joined #openstack-barbican | 15:42 | |
*** stanzi_ has joined #openstack-barbican | 15:42 | |
alee | redrobot, ping | 15:46 |
alee | woodster_, ? | 15:46 |
*** stanzi_ has quit IRC | 15:47 | |
*** Stanzi has quit IRC | 15:47 | |
*** SheenaG1 has quit IRC | 15:49 | |
*** SheenaG1 has joined #openstack-barbican | 15:52 | |
*** stanzi has joined #openstack-barbican | 15:55 | |
*** Stanzi_ has joined #openstack-barbican | 15:55 | |
*** Stanzi_ has quit IRC | 15:58 | |
*** stanzi has quit IRC | 15:58 | |
*** Stanzi has joined #openstack-barbican | 15:58 | |
*** stanzi_ has joined #openstack-barbican | 15:58 | |
*** Stanzi has quit IRC | 16:06 | |
*** stanzi_ has quit IRC | 16:06 | |
*** Stanzi has joined #openstack-barbican | 16:07 | |
*** stanzi_ has joined #openstack-barbican | 16:07 | |
*** kebray has joined #openstack-barbican | 16:08 | |
*** stanzi_ has quit IRC | 16:11 | |
*** Stanzi has quit IRC | 16:11 | |
*** lisa2 has joined #openstack-barbican | 16:14 | |
*** stanzi_ has joined #openstack-barbican | 16:17 | |
*** Stanzi has joined #openstack-barbican | 16:17 | |
*** lisa2 has quit IRC | 16:19 | |
*** Stanzi has quit IRC | 16:24 | |
*** stanzi_ has quit IRC | 16:24 | |
*** Stanzi has joined #openstack-barbican | 16:24 | |
*** stanzi_ has joined #openstack-barbican | 16:24 | |
*** stanzi_ has quit IRC | 16:29 | |
*** Stanzi has quit IRC | 16:29 | |
*** Stanzi_ has joined #openstack-barbican | 16:36 | |
*** stanzi has joined #openstack-barbican | 16:36 | |
woodster_ | alee: sorry for the delay...I think we'll need to validate via plugin no matter what...even if the case 1-3 formats are correct, plugins still might take issue with the actual data provided in the call, and waiting until the worker processes pick that up would not be a great user experience. | 16:37 |
alee | woodster_, yeah - thats fine -- I started implementing with provides() in any case | 16:38 |
*** ryanpetrello has joined #openstack-barbican | 16:39 | |
*** Stanzi_ has quit IRC | 16:42 | |
*** stanzi has quit IRC | 16:42 | |
*** stanzi has joined #openstack-barbican | 16:43 | |
*** Stanzi_ has joined #openstack-barbican | 16:43 | |
woodster_ | alee, so would the API sequence be like this: client requests cert of type X, barbican looks for plugins that have the type available in the provides() call, barbican core does first-order validation based on type, barbican calls the selected plugin's supports() method to validate, and finally barbican enqueues the cert order for worker processing. | 16:43 |
*** stanzi has quit IRC | 16:43 | |
*** Stanzi_ has quit IRC | 16:43 | |
*** david-lyle_afk is now known as david-lyle | 16:44 | |
*** Stanzi has joined #openstack-barbican | 16:44 | |
*** stanzi_ has joined #openstack-barbican | 16:44 | |
*** jaosorior has joined #openstack-barbican | 16:44 | |
alee | woodster_, yup - I'll post some code for get_plugin() in just a sec | 16:45 |
*** kgriffs is now known as kgriffs|afk | 16:45 | |
woodster_ | alee: wonder what the performance of all that will be :) | 16:47 |
jaosorior | alee: what's up? Working on something cool? | 16:47 |
alee | woodster_, pretty minimal I think | 16:47 |
alee | jaosorior, working on first patches for cert api | 16:47 |
jaosorior | Niiiiice | 16:48 |
alee | jaosorior, should have something for initial review today | 16:48 |
alee | ie. framework (with lots of stuff to fill in) | 16:48 |
jaosorior | Ok, lemme know :O | 16:48 |
*** lisaclark has quit IRC | 16:51 | |
*** Stanzi has quit IRC | 16:55 | |
*** stanzi_ has quit IRC | 16:55 | |
*** stanzi has joined #openstack-barbican | 16:55 | |
*** Stanzi_ has joined #openstack-barbican | 16:55 | |
alee | woodster_, http://fpaste.org/160280/48931141/ | 16:55 |
*** rm_work|away is now known as rm_work | 16:55 | |
alee | redrobot, ? | 16:55 |
alee | redrobot, SheenaG1 : any deals on hotels for the mid cycle meetup? | 16:56 |
alee | I recall there was a racker rate for hotels in SA .. | 16:57 |
*** Stanzi_ has quit IRC | 17:00 | |
*** stanzi has quit IRC | 17:00 | |
*** paul_glass has joined #openstack-barbican | 17:06 | |
*** kebray has quit IRC | 17:06 | |
*** kebray has joined #openstack-barbican | 17:07 | |
*** Stanzi_ has joined #openstack-barbican | 17:07 | |
*** stanzi has joined #openstack-barbican | 17:07 | |
*** Stanzi_ has quit IRC | 17:11 | |
*** stanzi has quit IRC | 17:11 | |
*** stanzi has joined #openstack-barbican | 17:12 | |
*** Stanzi_ has joined #openstack-barbican | 17:12 | |
*** kgriffs|afk is now known as kgriffs | 17:16 | |
*** Stanzi_ has quit IRC | 17:16 | |
*** stanzi has quit IRC | 17:16 | |
*** rm_you|wtf has quit IRC | 17:29 | |
*** rm_you|wtf has joined #openstack-barbican | 17:30 | |
*** bdpayne has joined #openstack-barbican | 17:33 | |
SheenaG1 | alee: I'll have to check, I'm not aware of any off the top of my head for Austin since we're a smaller presence there | 17:41 |
alee | SheenaG1, thanks - let me know what you find out. | 17:42 |
*** lisaclark has joined #openstack-barbican | 17:51 | |
*** paul_glass has quit IRC | 17:53 | |
*** rm_mobile has joined #openstack-barbican | 17:56 | |
*** rm_mobile has quit IRC | 17:56 | |
*** rm_mobile has joined #openstack-barbican | 17:56 | |
*** lisaclark has quit IRC | 18:02 | |
*** kebray has quit IRC | 18:03 | |
*** jamielennox|away is now known as jamielennox | 18:08 | |
greghaynes | alee: Awesome (re: backscroll) :) | 18:12 |
greghaynes | alee: this means the request_type can also be optional when plugins support the cmc request api by deault | 18:13 |
alee | greghaynes, yeah - I figured you'd like that :) | 18:13 |
greghaynes | alee: I think im goingt to start work on barbican-client to support cmc requests very soo, fyi | 18:15 |
greghaynes | s/soo/soon | 18:15 |
alee | greghaynes, well .. right now, the default is "custom" to maintain backward compatibility | 18:15 |
alee | greghaynes, awesome | 18:15 |
greghaynes | Yep, so if a plugins custom API is a strict superset of the cmc request API (which might be a good way to try and design them when possible) then the cmc api 'just works' as well | 18:16 |
alee | greghaynes, yes - if your plugin's custom api simply does cmc , then it just works | 18:20 |
greghaynes | Might be a good thing to push for in new plugins :) | 18:21 |
*** rm_mobile has quit IRC | 18:28 | |
*** lisaclark has joined #openstack-barbican | 18:30 | |
*** gyee has joined #openstack-barbican | 18:31 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Support containers without a name https://review.openstack.org/142181 | 18:40 |
*** Stanzi_ has joined #openstack-barbican | 18:41 | |
*** stanzi has joined #openstack-barbican | 18:41 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Support containers without a name https://review.openstack.org/142181 | 18:41 |
*** kgriffs is now known as kgriffs|afk | 18:45 | |
*** dimtruck is now known as zz_dimtruck | 18:45 | |
*** paul_glass has joined #openstack-barbican | 18:49 | |
*** Stanzi_ has quit IRC | 18:50 | |
*** stanzi has quit IRC | 18:50 | |
*** Stanzi_ has joined #openstack-barbican | 18:50 | |
*** stanzi has joined #openstack-barbican | 18:50 | |
*** zz_dimtruck is now known as dimtruck | 18:52 | |
*** Stanzi_ has quit IRC | 18:55 | |
*** stanzi has quit IRC | 18:55 | |
*** ametts has quit IRC | 18:56 | |
*** lisa1 has joined #openstack-barbican | 18:57 | |
*** Stanzi_ has joined #openstack-barbican | 18:57 | |
*** stanzi has joined #openstack-barbican | 18:57 | |
*** Stanzi_ has quit IRC | 18:59 | |
*** stanzi has quit IRC | 18:59 | |
*** stanzi_ has joined #openstack-barbican | 19:00 | |
*** Stanzi has joined #openstack-barbican | 19:00 | |
*** Stanzi has quit IRC | 19:00 | |
*** stanzi_ has quit IRC | 19:00 | |
*** lisa1 has quit IRC | 19:01 | |
*** Stanzi_ has joined #openstack-barbican | 19:01 | |
*** stanzi has joined #openstack-barbican | 19:01 | |
*** kgriffs|afk is now known as kgriffs | 19:05 | |
*** Stanzi_ has quit IRC | 19:06 | |
*** stanzi has quit IRC | 19:06 | |
openstackgerrit | Merged openstack/barbican: Actually run type order creation test https://review.openstack.org/141974 | 19:19 |
*** ryanpetrello_ has joined #openstack-barbican | 19:30 | |
*** ryanpetrello has quit IRC | 19:31 | |
*** ryanpetrello_ is now known as ryanpetrello | 19:31 | |
*** kgriffs is now known as kgriffs|afk | 19:45 | |
thiagop | redrobot: I was reading about the need for Barbican to listen Keystone's notifications in order to delete secrets when the tenant is deleted | 19:46 |
thiagop | redrobot: I couldn't find anything related to implementation of this, although the spec is approved | 19:46 |
redrobot | thiagop the BP has been implemented https://blueprints.launchpad.net/barbican/+spec/consume-keystone-events | 19:47 |
redrobot | thiagop it will be released this week as part of the Kilo 1 Milestone | 19:47 |
redrobot | thiagop https://launchpad.net/barbican/+milestone/kilo-1 | 19:48 |
thiagop | redrobot: nice, but once the secret-tenant association is removed, is there a plan of how will Barbican handle it? | 19:49 |
*** Stanzi_ has joined #openstack-barbican | 19:50 | |
*** stanzi has joined #openstack-barbican | 19:50 | |
*** lisa1 has joined #openstack-barbican | 19:51 | |
*** Stanzi__ has joined #openstack-barbican | 19:51 | |
*** stanzi___ has joined #openstack-barbican | 19:51 | |
redrobot | thiagop I can't recall the spec mentioning it specifically... The spec is just to remove the table though, the secret->tenant association will still be there, it just won't have a separate table for it. | 19:52 |
thiagop | redrobot: I see... | 19:52 |
*** kebray has joined #openstack-barbican | 19:52 | |
thiagop | redrobot: another tricky question: I found a lot of sources saying that Barbican has a problem with PKI tokens on Keystone. Is it yet valid? What about PKIZ tokens? | 19:53 |
*** Stanzi_ has quit IRC | 19:54 | |
*** stanzi has quit IRC | 19:54 | |
redrobot | thiagop I don't think Barbican itself has a problem with them. PKI tokens are problematic because of their size, which tends to break many web servers. | 19:54 |
redrobot | thiagop we defer token processing to the keystone middleware, so if the webserver and middleware are configured correctly, PKI tokens should wokr. | 19:55 |
*** lisa1 has quit IRC | 19:56 | |
redrobot | thiagop *work | 19:56 |
*** stanzi___ has quit IRC | 19:56 | |
*** stanzi_ has joined #openstack-barbican | 19:56 | |
*** Stanzi has joined #openstack-barbican | 19:56 | |
thiagop | redrobot: Yeah, I was working on a Horizon stuff to bypass the token size problem. It was overflowing the session max size... | 19:56 |
*** Stanzi__ has quit IRC | 19:57 | |
*** paul_glass has quit IRC | 20:00 | |
*** Stanzi has quit IRC | 20:01 | |
*** stanzi_ has quit IRC | 20:01 | |
*** Stanzi_ has joined #openstack-barbican | 20:02 | |
*** stanzi has joined #openstack-barbican | 20:02 | |
*** lisaclark has quit IRC | 20:03 | |
*** rellerreller has quit IRC | 20:03 | |
*** lisaclark has joined #openstack-barbican | 20:06 | |
*** lisaclark has quit IRC | 20:06 | |
*** kgriffs|afk is now known as kgriffs | 20:07 | |
*** paul_glass has joined #openstack-barbican | 20:09 | |
*** lisaclark has joined #openstack-barbican | 20:10 | |
openstackgerrit | Ade Lee proposed openstack/barbican: Initial commit for certificate-order-api https://review.openstack.org/142209 | 20:16 |
*** lisaclark has quit IRC | 20:19 | |
*** lisaclark has joined #openstack-barbican | 20:21 | |
*** dstufft has quit IRC | 20:27 | |
openstackgerrit | Ade Lee proposed openstack/barbican: Second commit for Common Cert API https://review.openstack.org/142212 | 20:27 |
alee | woodster_, greghaynes , reaperhulk , rm_work , chellygel - ^^ let me know what ya'll think so far .. | 20:30 |
*** kgriffs is now known as kgriffs|afk | 20:37 | |
*** Stanzi_ has quit IRC | 20:44 | |
*** stanzi has quit IRC | 20:44 | |
*** stanzi has joined #openstack-barbican | 20:45 | |
*** Stanzi_ has joined #openstack-barbican | 20:45 | |
*** Stanzi_ has quit IRC | 20:49 | |
*** stanzi has quit IRC | 20:49 | |
*** lisaclark has quit IRC | 20:51 | |
*** rellerreller has joined #openstack-barbican | 20:53 | |
*** kgriffs|afk is now known as kgriffs | 20:57 | |
*** dstufft has joined #openstack-barbican | 21:01 | |
rm_work | alee: looking in a moment :) | 21:03 |
alee | thanks | 21:03 |
rm_work | we're talking about that (kinda) at Octavia hackathon | 21:03 |
alee | cool | 21:03 |
*** stanzi has joined #openstack-barbican | 21:04 | |
*** Stanzi_ has joined #openstack-barbican | 21:04 | |
*** kgriffs is now known as kgriffs|afk | 21:07 | |
*** Stanzi_ has quit IRC | 21:07 | |
*** stanzi has quit IRC | 21:07 | |
*** stanzi has joined #openstack-barbican | 21:08 | |
*** Stanzi_ has joined #openstack-barbican | 21:08 | |
*** mikedillion has joined #openstack-barbican | 21:27 | |
*** mikedillion has quit IRC | 21:27 | |
greghaynes | alee: Are you going to update the spec as well? | 21:29 |
alee | greghaynes, yes - once we get these commits in. | 21:30 |
alee | greghaynes, no point in updating until we get this all decided. Its a lot easier how the spec will work out once we actually have some code. | 21:31 |
*** lisaclark has joined #openstack-barbican | 21:32 | |
greghaynes | heh, yea, theres a real chicken and the egg issue that goes on with specs. This is why I always try to push for leaving out decision making where we dont have to | 21:32 |
greghaynes | in tripleo we tend to get a super minimal spec out, write some code, add to spec, etx | 21:32 |
greghaynes | s/etx/etc | 21:32 |
*** paul_glass has quit IRC | 21:34 | |
*** bdpayne has quit IRC | 21:34 | |
rellerreller | woodster_ I commented on your comments on the content-types etherpad | 21:37 |
*** paul_glass1 has joined #openstack-barbican | 21:39 | |
alee | greghaynes, part of the problem is my tendency to write very detailed specs. that said, if the specs are detailed - deviations from the spec tend to be pretty small. | 21:43 |
*** paul_glass1 has quit IRC | 21:47 | |
*** paul_glass has joined #openstack-barbican | 21:48 | |
*** paul_glass has quit IRC | 21:52 | |
*** Stanzi_ has quit IRC | 21:58 | |
*** stanzi has quit IRC | 21:58 | |
*** Stanzi has joined #openstack-barbican | 21:59 | |
*** stanzi_ has joined #openstack-barbican | 21:59 | |
jaosorior | anybody familiar with stevedore? | 22:02 |
*** stanzi_ has quit IRC | 22:03 | |
*** Stanzi has quit IRC | 22:03 | |
*** ayoung has quit IRC | 22:04 | |
alee | rellerreller, I'll finish commenting later tonight | 22:05 |
*** ametts has joined #openstack-barbican | 22:08 | |
*** SheenaG1 has quit IRC | 22:08 | |
*** dimtruck is now known as zz_dimtruck | 22:10 | |
*** kebray has quit IRC | 22:11 | |
*** alee has quit IRC | 22:13 | |
*** kgriffs|afk is now known as kgriffs | 22:16 | |
rellerreller | alee thanks | 22:17 |
rellerreller | I'm trying to think if 'password' should be a new secret type. I lean toward no, but think about that while you are reading it. | 22:17 |
*** paul_glass has joined #openstack-barbican | 22:19 | |
*** lisaclark has quit IRC | 22:21 | |
*** lisa1 has joined #openstack-barbican | 22:31 | |
*** lisa1 has quit IRC | 22:35 | |
openstackgerrit | Merged openstack/barbican: Support containers without a name https://review.openstack.org/142181 | 22:35 |
woodster_ | jaosorior, are you still there? | 22:44 |
jaosorior | yup | 22:45 |
jaosorior | whattup? | 22:45 |
woodster_ | jaosorior, did you figure out stevedore then? | 22:49 |
jaosorior | more or less | 22:50 |
jaosorior | I haven't figured out a way for it to actually give a None object instead of a valid plugin | 22:51 |
jaosorior | but I think that would be a really obscure corner case | 22:51 |
jaosorior | this question was related to this CR: https://review.openstack.org/#/c/141963/ | 22:51 |
*** zz_dimtruck is now known as dimtruck | 22:57 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Use keystone v3 credentials for functional tests https://review.openstack.org/142254 | 23:04 |
*** rellerreller has quit IRC | 23:11 | |
openstackgerrit | greghaynes proposed openstack/barbican: Create snakeoil certificate plugin https://review.openstack.org/140575 | 23:22 |
*** bdpayne has joined #openstack-barbican | 23:23 | |
*** lisa1 has joined #openstack-barbican | 23:25 | |
*** paul_glass has quit IRC | 23:25 | |
openstackgerrit | greghaynes proposed openstack/barbican-specs: Snakeoil CA https://review.openstack.org/141981 | 23:26 |
greghaynes | woodster_: responded to your comments and uploaded new version ^ | 23:27 |
greghaynes | re: file locking | 23:27 |
*** lisa1 has quit IRC | 23:30 | |
*** kgriffs is now known as kgriffs|afk | 23:32 | |
*** dimtruck is now known as zz_dimtruck | 23:34 | |
*** alee has joined #openstack-barbican | 23:34 | |
*** zz_dimtruck is now known as dimtruck | 23:41 | |
*** lisaclark has joined #openstack-barbican | 23:43 | |
*** lisaclark has quit IRC | 23:51 | |
*** dimtruck is now known as zz_dimtruck | 23:53 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!