*** chlong has joined #openstack-barbican | 00:00 | |
openstackgerrit | Steve Heyman proposed openstack/barbican: ** DO NOT MERGE ** https://review.openstack.org/146608 | 00:02 |
---|---|---|
*** dave-mccowan has joined #openstack-barbican | 00:07 | |
*** dave-mccowan has quit IRC | 00:19 | |
openstackgerrit | Steve Heyman proposed openstack/barbican: ** DO NOT MERGE ** https://review.openstack.org/146608 | 00:28 |
openstackgerrit | Merged openstack/barbican: Fix 500 error when PUTing an order https://review.openstack.org/125516 | 00:33 |
*** jkf has quit IRC | 00:44 | |
*** zz_dimtruck is now known as dimtruck | 00:44 | |
*** dave-mccowan has joined #openstack-barbican | 00:54 | |
*** kgriffs is now known as kgriffs|afk | 01:05 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 01:10 | |
*** alee has joined #openstack-barbican | 01:48 | |
*** atiwari has quit IRC | 02:09 | |
*** dimtruck is now known as zz_dimtruck | 02:19 | |
*** ayoung has quit IRC | 02:22 | |
*** atiwari has joined #openstack-barbican | 02:39 | |
*** woodster_ has quit IRC | 02:40 | |
*** atiwari has quit IRC | 02:44 | |
*** woodster_ has joined #openstack-barbican | 02:54 | |
*** zz_dimtruck is now known as dimtruck | 03:04 | |
*** dave-mccowan has quit IRC | 04:14 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 04:21 | |
*** crc32 has joined #openstack-barbican | 04:31 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-barbicanclient: Updated from global requirements https://review.openstack.org/149482 | 04:37 |
*** woodster_ has quit IRC | 05:00 | |
*** woodster_ has joined #openstack-barbican | 05:13 | |
*** dimtruck is now known as zz_dimtruck | 05:28 | |
*** crc32 has quit IRC | 05:45 | |
*** Nirupama has joined #openstack-barbican | 05:49 | |
*** chlong has quit IRC | 05:54 | |
*** jamielennox is now known as jamielennox|away | 06:00 | |
*** chlong has joined #openstack-barbican | 06:01 | |
*** jamielennox|away is now known as jamielennox | 06:02 | |
*** jamielennox is now known as jamielennox|away | 06:04 | |
*** woodster_ has quit IRC | 07:20 | |
*** chlong has quit IRC | 08:14 | |
*** jaosorior has joined #openstack-barbican | 10:14 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Fix content type validation if missing payload https://review.openstack.org/149570 | 11:12 |
openstackgerrit | Tim Kelsey proposed openstack/barbican-specs: Adding spec for Barbican MKEK Model. https://review.openstack.org/148948 | 11:14 |
openstackgerrit | Julien Danjou proposed openstack/barbican: Drop Python 2.6 support https://review.openstack.org/149585 | 11:35 |
*** chlong has joined #openstack-barbican | 11:51 | |
*** tkelsey has joined #openstack-barbican | 11:54 | |
jaosorior | tkelsey | 11:59 |
tkelsey | hey jaosorior :) | 12:00 |
jaosorior | The versioning issue is something that was actually brought up last summit... But I remember there was no concrete solution proposed | 12:00 |
jaosorior | I think this should be taken up in the next weekly | 12:01 |
jaosorior | to see if we should come up with a solution for the versioning of plugins right now, or if your implementation should be a separate plugin completely | 12:01 |
tkelsey | yeah, so I was actually thinking that this could be a new plugin rather then an incompatible enhancement of KMIPSecretStore, the HP ESKMs can store a _lot_ of keys so for some situations storing everything in the HSM may be desirable | 12:01 |
tkelsey | having two plugins lets deployers pick, perhaps for compliance issues, and side steps the problem of versioning (at least for now) | 12:03 |
tkelsey | but perhaps we should be thinking about that anyway | 12:03 |
jaosorior | indeed | 12:04 |
jaosorior | so, lets bring it up in the next weekly | 12:04 |
tkelsey | make sense to me :) | 12:04 |
tkelsey | i'll update the meeting agenda | 12:04 |
jaosorior | Here's the link https://wiki.openstack.org/wiki/Meetings/Barbican | 12:04 |
tkelsey | awesome, thanks | 12:04 |
tkelsey | so hows things anyway jaosorior? | 12:05 |
jaosorior | quite good man | 12:05 |
jaosorior | chilling out, working at a café | 12:06 |
jaosorior | gonna move to another place in a bit though | 12:06 |
jaosorior | then a bar, most likely :P | 12:06 |
tkelsey | sounds nice :) Im quite looking forward to the weekend personally, flying back to Newcastle to see some friends | 12:06 |
tkelsey | haha good plan :) | 12:06 |
jaosorior | not bad! | 12:07 |
jaosorior | I need myself some travel, wanderlust is kicking in :P | 12:07 |
tkelsey | :) got to be done | 12:08 |
tkelsey | right, updated, should be an interesting discussion | 12:12 |
tkelsey | so jaosorior, when I refer to you in comments how do you like to be address? as Juan or Juan Antonio or what? | 12:15 |
tkelsey | just think its polite to get it right :) | 12:15 |
jaosorior | Haha people usually call me Ozz | 12:16 |
tkelsey | heh ok :) I'll do that than lol | 12:16 |
tkelsey | so re your comment about HSMs for CI/CD HP is planning to make some ESKMs available for testing, we already got access for the JH guys to test PyKMIP | 12:19 |
tkelsey | not sure of all the details, but there is a plan | 12:19 |
jaosorior | Niiiice | 12:26 |
jaosorior | tkelsey: so wazzup man, gonna hit the barbican mid cycle? | 12:43 |
*** Nirupama has quit IRC | 12:48 | |
*** woodster_ has joined #openstack-barbican | 12:52 | |
tkelsey | jaosorior: I would, but im at the OSSG mid-cycle so I cant make it in person :( | 12:55 |
jaosorior | Fair enough. There is a section about barbican in the OSSG meeting, but I'm actually not sure how the collaboration will work regarding that | 12:56 |
tkelsey | yeah, im not sure either, but it would be good if something gets worked out | 12:57 |
reaperhulk | cc redrobot --^^^ | 12:57 |
*** darrenmoffat has quit IRC | 13:37 | |
*** darrenmoffat has joined #openstack-barbican | 13:38 | |
*** dave-mccowan has joined #openstack-barbican | 13:55 | |
jaosorior | tkelsey: you around? | 13:56 |
tkelsey | yo | 13:56 |
jaosorior | Have you tried the Beavertown 8 Ball IPA? (Just moved from the café to a bar) | 13:56 |
jaosorior | It's damn good | 13:57 |
jaosorior | hockeynut: I haven't found much regarding the JSONDecoderError thingy, have you? | 13:57 |
tkelsey | haha :D no I dont think i have, I am still working my way through the Williams Bros stuff :) | 13:58 |
tkelsey | I'll have to keep an eye out if it comes in as a guest ale somewhere :) | 13:58 |
tkelsey | thanks for the tip jaosorior :) | 13:59 |
reaperhulk | so much opportunity for micro optimization in this experiment...must resist | 14:04 |
jaosorior | reaperhulk: what experiment? | 14:06 |
reaperhulk | I'm replacing PyKCS11 | 14:06 |
reaperhulk | in the pkcs11 plugin | 14:06 |
reaperhulk | with a cffi implementation that doesn't infuriate me. | 14:07 |
reaperhulk | (and should fix some race condition issues we're seeing in our testing) | 14:07 |
reaperhulk | I am resisting the urge to do things like reuse the plaintext char buffers to write ciphertext to gain efficiency for now | 14:07 |
reaperhulk | Once this is all working the way I want I'll figure out how much optimization is worth doing | 14:08 |
jaosorior | I'm not acquainted at all with cffi, mind sending a link? | 14:09 |
reaperhulk | https://cffi.readthedocs.org | 14:09 |
reaperhulk | It's by far the best way to do C FFI from Python | 14:10 |
reaperhulk | (it's the core of how we do things in https://github.com/pyca/cryptography as well) | 14:10 |
tkelsey | having played with it extending pyca/cryptography X509 stuff, I totally agree with reaperhulk | 14:11 |
reaperhulk | tkelsey: next release of cryptography will have subject/issuer DN parsing and maybe one or two other X509 features. Not sure yet. Still a ways until we have hazmat interfaces for certificate generation though (although let's encrypt wants that now as well) | 14:12 |
tkelsey | reaperhulk: awesome :) longterm we plan to move over Anchor to using all cryptography stuff and kill our internal stuff off | 14:13 |
tkelsey | I'll look forward to the new version landing | 14:14 |
*** rellerreller has joined #openstack-barbican | 14:18 | |
reaperhulk | 0.8 should be mid-Feb. A bit delayed since I'll be on vacation first week of February | 14:19 |
tkelsey | sounds good :) though I'll be at some state-side meeting and the OSSG mid cycle then, so probs pick it up end of Feb | 14:20 |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Fix content type validation if missing payload https://review.openstack.org/149570 | 14:23 |
hockeynut | jaosorior yes, its solved. putting up the CR now | 14:32 |
reaperhulk | hockeynut: you working from home today? | 14:32 |
jaosorior | oooh dude, nice! | 14:33 |
jaosorior | You have earned yourself a beer | 14:33 |
*** hyakuhei has joined #openstack-barbican | 14:33 | |
hockeynut | reaperhulk yes. combine Friday and rain and its the defintion of WFH | 14:34 |
reaperhulk | heh | 14:34 |
reaperhulk | we'll see who comes in today. I am here because I wanted to work on the cffi stuff. I'm pretty much to the point where I could test in staging | 14:35 |
hockeynut | awesome. This is the 5% issue? | 14:35 |
reaperhulk | yep | 14:36 |
reaperhulk | the code I have to test is a prototype that replaces all of pykcs11 | 14:36 |
hockeynut | wow | 14:36 |
reaperhulk | +413 -182 bleh | 14:37 |
*** ayoung has joined #openstack-barbican | 14:45 | |
*** chlong has quit IRC | 14:54 | |
*** lisaclark1 has joined #openstack-barbican | 14:54 | |
*** hyakuhei has left #openstack-barbican | 14:57 | |
*** lisaclark1 has quit IRC | 14:59 | |
*** lisaclark1 has joined #openstack-barbican | 15:11 | |
*** tkelsey has quit IRC | 15:12 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 15:12 | |
*** SheenaG1 has joined #openstack-barbican | 15:12 | |
*** lisaclark1 has quit IRC | 15:18 | |
SheenaG1 | lisaclark: ping, where'd you go in the other channel? | 15:19 |
woodster_ | reaperhulk, hockeynut, sounds like progress for sure | 15:19 |
rellerreller | Does anyone have the link for the mid-cycle details etherpad? | 15:19 |
jvrbanac | rellerreller, https://wiki.openstack.org/wiki/Sprints/BarbicanKiloSprint | 15:21 |
jvrbanac | rellerreller, they should be a link on there some where | 15:21 |
rellerreller | jvrbananac Thanks! | 15:21 |
jvrbanac | rellerreller, last I checked, there wasn't much on there yet | 15:21 |
rellerreller | jvrbanac That's ok. I really just needed the location. I'm booking travel now. | 15:22 |
*** rtom has joined #openstack-barbican | 15:22 | |
*** lisaclark1 has joined #openstack-barbican | 15:22 | |
jvrbanac | rellerreller, got it | 15:22 |
*** dstanek has left #openstack-barbican | 15:25 | |
*** kebray has joined #openstack-barbican | 15:29 | |
*** zz_dimtruck is now known as dimtruck | 15:33 | |
*** paul_glass has joined #openstack-barbican | 15:46 | |
woodster_ | alee, btw we'll be putting up a blueprint for an 'automatic' order type...one that generates the private key and CSR as part of the cert order process, so one step above the stored key mode. | 16:04 |
alee | woodster_, ok | 16:05 |
*** kgriffs|afk is now known as kgriffs | 16:13 | |
*** rellerreller has quit IRC | 16:19 | |
woodster_ | we still need to get plugin validation working on the API side...we had discussed in Paris but no action on that yet | 16:21 |
*** arunkant has joined #openstack-barbican | 16:23 | |
*** dave-mccowan has quit IRC | 16:27 | |
*** dave-mccowan has joined #openstack-barbican | 16:28 | |
*** dave-mccowan has quit IRC | 16:29 | |
*** david-lyle_afk is now known as david-lyle | 16:35 | |
*** nkinder has quit IRC | 16:35 | |
*** paul_glass has quit IRC | 16:37 | |
alee | woodster_, plugin validation? | 16:37 |
woodster_ | alee, yep that's the ones. We discussed doing this in Paris but we probably need a blueprint to contend with that | 16:39 |
*** paul_glass has joined #openstack-barbican | 16:41 | |
alee | woodster_, sorry -- so many blueprints -- what kind of validation are you talking about? | 16:41 |
woodster_ | alee, we had talked about letting plugins perform validation on the API nodes...so if a dogtag CA plugin is to be used to process a given cert order, it would have a chance to validate the order data first before the worker nodes are assigned to work the order | 16:45 |
alee | woodster_, ah right | 16:49 |
alee | yeah -we can talk about that further in Austin | 16:49 |
woodster_ | alee, is all that supports() vs validate() method funness coming back to you now?? :) | 16:49 |
alee | oh -- so much fun -- just as long as no one says "content types" .. | 16:51 |
woodster_ | alee, that's barbican's 'voldemort'! | 16:55 |
*** kgriffs is now known as kgriffs|afk | 17:04 | |
*** SheenaG1 has quit IRC | 17:06 | |
*** kgriffs|afk is now known as kgriffs | 17:07 | |
*** SheenaG1 has joined #openstack-barbican | 17:08 | |
*** lisaclark1 has quit IRC | 17:16 | |
*** lisaclark1 has joined #openstack-barbican | 17:18 | |
*** lisaclark1 has quit IRC | 17:19 | |
*** lisaclark1 has joined #openstack-barbican | 17:23 | |
*** jkf has joined #openstack-barbican | 17:31 | |
*** paul_glass has quit IRC | 17:33 | |
*** paul_glass has joined #openstack-barbican | 17:36 | |
*** jaosorior has quit IRC | 17:44 | |
*** lisaclark1 has quit IRC | 17:45 | |
openstackgerrit | Steve Heyman proposed openstack/barbican: ** DO NOT MERGE ** https://review.openstack.org/146608 | 17:56 |
openstackgerrit | Steve Heyman proposed openstack/barbican: Resolve intermittent HTTP 404 in devstack gate https://review.openstack.org/146608 | 17:59 |
openstackgerrit | Steve Heyman proposed openstack/barbican: Resolve intermittent HTTP 404 in devstack gate https://review.openstack.org/146608 | 18:01 |
openstackgerrit | Steve Heyman proposed openstack/barbican: Resolve intermittent HTTP 404 in devstack gate https://review.openstack.org/146608 | 18:02 |
hockeynut | ok, the fix is up for the intermittent http404 - have at it please! | 18:08 |
*** lisaclark1 has joined #openstack-barbican | 18:15 | |
openstackgerrit | Steve Heyman proposed openstack/barbican: Include logging for barbican functional tests https://review.openstack.org/149697 | 18:15 |
reaperhulk | jvrbanac you around? | 18:19 |
openstackgerrit | Steve Heyman proposed openstack/barbican: Resolve intermittent HTTP 404 in devstack gate https://review.openstack.org/146608 | 18:19 |
jvrbanac | reaperhulk, yep | 18:19 |
reaperhulk | guess what | 18:20 |
jvrbanac | reaperhulk, what? | 18:20 |
reaperhulk | wanna run gatling against keep-api-n01.dev.sat6.cidm.rackspace.net:9311 ? | 18:20 |
reaperhulk | because it's all working | 18:21 |
*** SheenaG1 has left #openstack-barbican | 18:21 | |
jvrbanac | k | 18:22 |
*** dave-mccowan has joined #openstack-barbican | 18:24 | |
*** lisaclark1 has quit IRC | 18:29 | |
*** lisaclark1 has joined #openstack-barbican | 18:33 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/149704 | 18:40 |
*** atiwari has joined #openstack-barbican | 18:41 | |
*** david-lyle has quit IRC | 18:46 | |
*** kebray has quit IRC | 19:01 | |
*** kebray has joined #openstack-barbican | 19:01 | |
*** SheenaG1 has joined #openstack-barbican | 19:08 | |
*** rellerreller has joined #openstack-barbican | 19:23 | |
arunkant | Hi..is there a way to store secrets in barbican under a different project other than token's project ? Working on a Keystone spec where its Credential API is going to use Barbican / HSM for credential storage. | 19:28 |
arunkant | Spec: https://review.openstack.org/#/c/148672/ | 19:30 |
*** lisaclark2 has joined #openstack-barbican | 19:34 | |
*** lisaclark1 has quit IRC | 19:37 | |
*** lisaclark2 has quit IRC | 19:54 | |
woodster_ | arunkant: currently there is no way to do so. Will take a look at the spec a bit later | 19:59 |
*** lisaclark1 has joined #openstack-barbican | 19:59 | |
arunkant | Thanks woodster_ . Looking forward to your inputs on this as Keystone can become barbican client for its Keystone credential API functionality. | 20:28 |
*** SheenaG1 has quit IRC | 20:44 | |
*** kebray has quit IRC | 21:00 | |
*** samueldmq has quit IRC | 21:01 | |
*** kebray has joined #openstack-barbican | 21:02 | |
rellerreller | woodster_ can you look at the content types spec when you get a chance? I have not received much feedback on it. | 21:05 |
openstackgerrit | Merged openstack/barbican: Resolve intermittent HTTP 404 in devstack gate https://review.openstack.org/146608 | 21:10 |
openstackgerrit | Merged openstack/barbican: Fix content type validation if missing payload https://review.openstack.org/149570 | 21:10 |
*** lisaclark1 has quit IRC | 21:20 | |
*** kebray has quit IRC | 21:22 | |
*** lisaclark1 has joined #openstack-barbican | 21:23 | |
woodster_ | rellerreller, yeah, I've been behind on reviews | 21:37 |
openstackgerrit | Merged openstack/barbican: Drop Python 2.6 support https://review.openstack.org/149585 | 21:45 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/149704 | 21:50 |
*** SheenaG1 has joined #openstack-barbican | 22:07 | |
*** gyee has joined #openstack-barbican | 22:07 | |
*** lisaclark1 has quit IRC | 22:11 | |
*** rellerreller has quit IRC | 22:14 | |
alee | rm_work, ping | 22:15 |
*** chlong has joined #openstack-barbican | 22:25 | |
*** SheenaG1 has quit IRC | 22:26 | |
*** dave-mccowan has quit IRC | 22:29 | |
*** SheenaG11 has joined #openstack-barbican | 22:32 | |
*** kebray has joined #openstack-barbican | 22:54 | |
*** rtom has quit IRC | 22:55 | |
*** paul_glass has quit IRC | 22:57 | |
*** SheenaG11 has quit IRC | 23:02 | |
*** david-ly_ has joined #openstack-barbican | 23:07 | |
openstackgerrit | Venkat Sundaram proposed openstack/barbican-specs: Add Quota support for Barbican resources https://review.openstack.org/132091 | 23:11 |
*** david-ly_ is now known as david-lyle | 23:11 | |
*** gyee has quit IRC | 23:32 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!