*** jamielennox|away is now known as jamielennox | 00:06 | |
*** woodster_ has joined #openstack-barbican | 00:22 | |
*** igueths has joined #openstack-barbican | 01:23 | |
igueths | jvrbanac: Ping. | 01:23 |
---|---|---|
*** zz_dimtruck is now known as dimtruck | 02:21 | |
*** kebray has joined #openstack-barbican | 02:50 | |
*** woodster_ has quit IRC | 03:20 | |
*** woodster_ has joined #openstack-barbican | 03:47 | |
*** crc32 has joined #openstack-barbican | 03:54 | |
*** crc32 has quit IRC | 03:58 | |
*** rm_you has quit IRC | 04:08 | |
*** rm_you has joined #openstack-barbican | 04:12 | |
*** rm_you has joined #openstack-barbican | 04:12 | |
*** rm_work|away is now known as rm_work | 04:17 | |
*** gitorres has quit IRC | 05:02 | |
*** gitorres has joined #openstack-barbican | 05:03 | |
*** dimtruck is now known as zz_dimtruck | 05:24 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Imported Translations from Transifex https://review.openstack.org/172626 | 06:11 |
*** dave-mccowan has joined #openstack-barbican | 06:30 | |
*** dave-mccowan has quit IRC | 06:34 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Sign CSRs issued in SnakeOilCA tests https://review.openstack.org/172714 | 07:02 |
*** jaosorior has joined #openstack-barbican | 07:02 | |
*** kebray has quit IRC | 07:10 | |
*** jamielennox is now known as jamielennox|away | 07:11 | |
*** chlong has quit IRC | 07:25 | |
openstackgerrit | Dave McCowan proposed openstack/barbican: Fix handling of payload_content_encoding for orders https://review.openstack.org/172819 | 07:25 |
*** woodster_ has quit IRC | 07:40 | |
*** jamielennox|away is now known as jamielennox | 09:02 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Enable alternate error message for OpenSSL 1.0.2 https://review.openstack.org/172844 | 09:15 |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Enable alternate error message for OpenSSL 1.0.2 https://review.openstack.org/172844 | 09:19 |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Enable alternate error message for OpenSSL 1.0.2 https://review.openstack.org/172844 | 09:28 |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Sign CSRs issued in SnakeOilCA tests https://review.openstack.org/172714 | 09:28 |
openstackgerrit | Steve Heyman proposed openstack/python-barbicanclient: Initial setup for command line tests https://review.openstack.org/172604 | 12:09 |
*** jamielennox is now known as jamielennox|away | 12:12 | |
jaosorior | hockeynut: I didn't really get the comment in https://review.openstack.org/172844 | 12:29 |
jaosorior | * hockeynut_ | 12:31 |
hockeynut_ | the test for openssl version would give the wrong string if openssl was at v 1.0.20 right (since 1.0.2 is in 1.0.20) | 12:32 |
hockeynut_ | (wonder why I'm "away") | 12:32 |
jaosorior | well, I then it would be valid, since the change applies for 1.0.2 and above | 12:33 |
hockeynut_ | ah yes, I was thinking 102 and below. Not enough caffiene this morning :-) | 12:34 |
hockeynut_ | thx! | 12:34 |
jaosorior | hockeynut_: I know the feel :P | 12:42 |
*** jroll has quit IRC | 12:50 | |
*** jroll has joined #openstack-barbican | 12:50 | |
*** zz_dimtruck is now known as dimtruck | 12:52 | |
*** therve has joined #openstack-barbican | 12:53 | |
therve | Hi | 12:54 |
therve | Just opened #1443436, client seems to be broken | 13:00 |
therve | Should 5ed2e70f9f38e46c5af36d1e9c4eb4e24568bc5a be reverted? | 13:00 |
*** openstackgerrit has quit IRC | 13:00 | |
*** openstackgerrit has joined #openstack-barbican | 13:03 | |
*** dimtruck is now known as zz_dimtruck | 13:17 | |
*** woodster_ has joined #openstack-barbican | 13:33 | |
*** zz_dimtruck is now known as dimtruck | 13:54 | |
*** nkinder has joined #openstack-barbican | 14:05 | |
*** dave-mccowan has joined #openstack-barbican | 14:09 | |
*** paul_glass has joined #openstack-barbican | 14:23 | |
*** rellerreller has joined #openstack-barbican | 14:31 | |
jaosorior | therve: let's see | 14:33 |
*** igueths1 has joined #openstack-barbican | 14:35 | |
jaosorior | hockeynut_: ping | 14:39 |
hockeynut_ | jaosorior yessir | 14:44 |
*** xaeth_afk is now known as xaeth | 14:44 | |
jaosorior | hockeynut_: I responded to your comment in this CR https://review.openstack.org/#/c/172714/ got a strong opinion about that? Actually I prefer the way it was written | 14:45 |
hockeynut_ | jaosorior nope, not a strong opinion on that one. I can live with it as-is and will not lose any sleep | 14:46 |
jaosorior | hockeynut_: alright | 14:46 |
jaosorior | therve: are you around | 14:46 |
jaosorior | ? | 14:46 |
therve | jaosorior, Yep | 14:47 |
jaosorior | are you using barbican with the unauthenticated-context? | 14:47 |
therve | How would I know? | 14:48 |
therve | I'm using whatever is in devstack by default | 14:48 |
*** darrenmoffat has quit IRC | 14:50 | |
jaosorior | therve: I see | 14:50 |
jaosorior | therve: alright, just asking. I'm looking into the issue you reported | 14:50 |
therve | jaosorior, Is it about having the endpoint in the environment? | 14:51 |
jaosorior | therve: we used to rely on a call to "session.getsession" to populate the endpoint if it wasn't provided | 14:52 |
jaosorior | therve: the commit hash that you pointed out removed that, and now there is that error | 14:53 |
jaosorior | therve: So I'm figuring out if this new adapter should have handled that, or if we need a similar call again | 14:53 |
jaosorior | therve: Anyway, will take care of it, thanks for finding this out | 14:53 |
therve | jaosorior, I believe at least one of the issue is that the endpoint default to '' | 14:55 |
jaosorior | therve: Indeed, and we used to rely that if the endpoint was None or '', we would let the keystoneclient populate it | 14:55 |
therve | Right, now the code believes it's set but it's not | 14:56 |
jaosorior | therve: exactly | 14:57 |
therve | jaosorior, http://paste.openstack.org/show/203597/ FWIW seems to be a possible solution | 14:58 |
therve | Need to check post too | 14:58 |
jaosorior | was thinking of using the adapter's get_session function | 14:59 |
jaosorior | therve: https://github.com/openstack/python-keystoneclient/blob/master/keystoneclient/adapter.py#L112 | 15:00 |
*** rellerreller has quit IRC | 15:00 | |
therve | Hum yeah I don't know about that :) | 15:03 |
*** dave-mccowan has quit IRC | 15:10 | |
jaosorior | therve: testing this at the moment http://paste.openstack.org/show/203598/ | 15:10 |
*** darrenmoffat has joined #openstack-barbican | 15:11 | |
jaosorior | therve: but I seem to be missing something | 15:12 |
therve | jaosorior, Yeah it's not managing the /v1 part of the URL | 15:12 |
jaosorior | therve: yeah, just noticed it | 15:13 |
*** dimtruck is now known as zz_dimtruck | 15:17 | |
igueths1 | jvrbanac: Ping. | 15:20 |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/python-barbicanclient: Use keystoneclient to get endpoint if it's empty https://review.openstack.org/172958 | 15:20 |
jaosorior | therve: fixed | 15:20 |
*** kebray has joined #openstack-barbican | 15:20 | |
therve | jaosorior, Cool. Works for orders and secrets, but containers are still broken though. | 15:27 |
*** dave-mccowan has joined #openstack-barbican | 15:30 | |
jaosorior | therve: wha O_O | 15:39 |
jaosorior | therve: aaaaand it doesn't pass the unit tests, which I didn't think were actually using the base_url | 15:40 |
*** gyee has joined #openstack-barbican | 15:41 | |
therve | That part is a good thing :) | 15:43 |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/python-barbicanclient: Use keystoneclient to get endpoint if it's empty https://review.openstack.org/172958 | 15:47 |
jaosorior | therve: buuuuut, does it fail with the same error? | 15:48 |
openstackgerrit | Igor Gueths proposed openstack/barbican: Potential resource exhaustion when registering consumers to containers https://review.openstack.org/170693 | 15:49 |
jaosorior | therve: and there is some weird usage of that _base_url variable... Gotta look into that | 15:53 |
therve | jaosorior, I'd be tempted to remove _base_url usage if possible | 15:54 |
jaosorior | therve: you could submit a patch that depends on mine | 15:56 |
jaosorior | therve: wouldn't be a bad idea | 15:57 |
therve | Sure | 15:58 |
*** zz_dimtruck is now known as dimtruck | 16:04 | |
*** kebray has quit IRC | 16:20 | |
openstackgerrit | Merged openstack/barbican: Imported Translations from Transifex https://review.openstack.org/172626 | 16:45 |
*** rellerreller has joined #openstack-barbican | 16:55 | |
*** dimtruck is now known as zz_dimtruck | 17:00 | |
*** dave-mccowan has quit IRC | 17:11 | |
*** dave-mccowan has joined #openstack-barbican | 17:12 | |
*** joesavak has joined #openstack-barbican | 17:48 | |
*** zz_dimtruck is now known as dimtruck | 17:52 | |
*** rellerreller_ has joined #openstack-barbican | 18:03 | |
*** rellerreller has quit IRC | 18:05 | |
*** kebray has joined #openstack-barbican | 18:17 | |
openstackgerrit | Steve Heyman proposed openstack/python-barbicanclient: Initial setup for command line tests https://review.openstack.org/172604 | 18:35 |
*** rellerreller has joined #openstack-barbican | 18:48 | |
*** tkelsey has joined #openstack-barbican | 18:48 | |
rellerreller | dave-mccowan Where do we stand with the bug reports on content types? | 18:51 |
*** rellerreller_ has quit IRC | 18:51 | |
rellerreller | I saw that you submitted one. Are there others that have been filed? | 18:52 |
dave-mccowan | rellerreller, i opened 5 bugs and proposed a fix for 1 of them. to recreate any of them, remove an @skip from functionaltestes/api/v1/smoke/test_rsa.py | 18:57 |
*** hockeynut_ has quit IRC | 18:57 | |
*** tdink_ has quit IRC | 18:57 | |
*** hockeynut has joined #openstack-barbican | 18:58 | |
dave-mccowan | rellerreller, https://bugs.launchpad.net/barbican 5 of the bottom 6. | 18:58 |
*** tdink has joined #openstack-barbican | 18:58 | |
rellerreller | dave-mccowan what about the issue #1441866 public type secret creation fails with 400? | 19:02 |
dave-mccowan | rellerreller, redrobot marked that invalid | 19:06 |
redrobot | o/ | 19:06 |
redrobot | rellerreller dave-mccowan yeah, I was originally trying to use "application/pkcs8" as the content-type | 19:07 |
redrobot | but since we decided to use "application/octet-stream" instead, the bug is invalid | 19:07 |
dave-mccowan | rellerreller, redrobot that failure could be covered by #1443009 now, to cover all creates that fail when the decided encoding is used. | 19:09 |
rellerreller | redrobot OK, but I don't see anything about pkcs8 in that bug report. | 19:09 |
redrobot | rellerreller oh, oops, wrong one | 19:10 |
dave-mccowan | rellerreller, when functionaltests.api.v1.smoke.test_rsa.RSATestCase.test_rsa_create_and_get_private_key works then we're good on pkcs8 | 19:10 |
redrobot | rellerreller should've looked at the actual bug... 1441866 is a bug. I did invalidate another one that used pcks8 | 19:10 |
*** joesavak has quit IRC | 19:18 | |
rellerreller | redrobot dave-mccowan So who is working on what? | 19:25 |
rellerreller | I don't want to work on anything that someone else is already working on. | 19:25 |
redrobot | I'm working on https://bugs.launchpad.net/barbican/+bug/1441866 | 19:26 |
openstack | Launchpad bug 1441866 in Barbican "public type secret creation fails with 400" [Critical,Confirmed] - Assigned to Douglas Mendizábal (dougmendizabal) | 19:26 |
rellerreller | There is the API change to only accept PEM encoded private, public, and certificate secret types. | 19:26 |
rellerreller | redrobot So you are making the change to only accept PEM for private, public, and certificates? | 19:27 |
redrobot | rellerreller no, I'm working on fixing the base64 normalization so that base64(PEM) works | 19:28 |
rellerreller | redrobot Were you planning to make the changes in the backend to have the secret stores accept base64(pem)? | 19:28 |
redrobot | rellerreller haven't gotten that far yet. You can work on that if you'd like | 19:28 |
rellerreller | redrobot If you are working on the normalization then you must be doing the backend stuff as well. Unless I am missing something. How do you plan to do that? | 19:29 |
rellerreller | Because the data is normalized before going to secret store. | 19:29 |
redrobot | rellerreller I'm fixing the normalization such that a one-step POSTÂ does not return a 400 when payload="base64(PEM)" | 19:30 |
*** joesavak has joined #openstack-barbican | 19:33 | |
rellerreller | redrobot OK, I was not calling that a normalization change. I was calling that a validation change. | 19:33 |
redrobot | rellerreller gotcha. yes, validation makes more sense | 19:34 |
rellerreller | redrobot I need to run. I won't be at the status meeting, but I plan to be around tomorrow. | 19:37 |
*** rellerreller has quit IRC | 19:41 | |
redrobot | Weekly meeting starting now in #openstack-meeting-alt | 19:59 |
jaosorior | rm_work: thanks mr. | 21:00 |
rm_work | Sheena_ / redrobot: FYI looks like summit is GO for me, so I'll need to get some slides ready | 21:01 |
elmiko | redrobot: might take me a day or two to reconfigure my machine for mysql and rerun the tests. i want to make sure i don't hose mariadb lol | 21:01 |
*** dimtruck is now known as zz_dimtruck | 21:01 | |
*** tkelsey has quit IRC | 21:02 | |
Sheena_ | rm_work: excellent news! I'll kick that thread again today or tomorrow | 21:02 |
rm_work | elmiko: that's what VMs are for :P | 21:03 |
dave-mccowan | alee_, ping | 21:04 |
alee_ | dave-mccowan, pong | 21:05 |
dave-mccowan | alee_, i've been looking at the bug on order certificates. when doing a get order, the barbican_meta is not returned with original's order meta. seems like an easy fix, that i'm willing to patch. but, i can't find the code where the response to get order is built. can you point me? | 21:06 |
dave-mccowan | alee_, https://bugs.launchpad.net/barbican/+bug/1443007 | 21:06 |
openstack | Launchpad bug 1443007 in Barbican "Response to Get Certificate Order Requests Do Not Have Updated Meta" [Undecided,New] | 21:06 |
*** joesavak has quit IRC | 21:08 | |
alee_ | dave-mccowan, thats deliberate | 21:09 |
alee_ | dave-mccowan, barbican-meta is stuff that is created on the server and is not necessarily returned as part of the order | 21:09 |
dave-mccowan | alee_ the user can not get a copy of plugin_name or generated_csr? | 21:09 |
alee_ | dave-mccowan, right | 21:10 |
dave-mccowan | alee_ good news, one less bug. :-) | 21:10 |
alee_ | dave-mccowan, the plugin-name is internal to barbican, | 21:10 |
dave-mccowan | alee_ ok, so there is no way for functional tests to test that. only unit tests. right? | 21:10 |
alee_ | and we can expose the csr later if we have call to -- but I dont think we do | 21:10 |
alee_ | right | 21:11 |
alee_ | dave-mccowan, in the dogtag test, we have funcitonal tests to confirm that you actually get a cert back | 21:11 |
alee_ | dave-mccowan, for the regular case, there is no way to be absolutely sure -- although theoretically, it should not get to pending state without going through some measure of success in generating the csr | 21:12 |
dave-mccowan | alee_ thanks. this is good news. this should get four more test cases passing. (at least to 'pending' state for ordered certs). | 21:17 |
elmiko | rm_work: yea, i should really just do that | 21:17 |
alee_ | dave-mccowan, great | 21:17 |
*** alee_ is now known as alee_afk | 21:18 | |
dave-mccowan | alee_afk, can you still point me to where that code is? after searching for a long time, i need closure. :-) | 21:19 |
alee_afk | dave-mccowan, back in a bit -- but in answer to your question -- if I were looking at where the get oder response comes from I'd look at controllers/orders.py | 21:24 |
alee_afk | dave-mccowan, my guess is there we just get the order and convert it into json output | 21:24 |
alee_afk | dave-mccowan, if you wanted - you could have modified the code there to add data from barbican-meta as well. | 21:25 |
alee_afk | dave-mccowan, or when generating the barbican-meta, you could have saved it in the order_meta instead. | 21:25 |
dave-mccowan | alee_afk, thanks. i see it now. i had my cursor left at exactly that function from last night. | 21:26 |
alee_afk | dave-mccowan, redrobot - I'll run through what you and redrobot come up with for fixes tommorow when you guys have something ready. some of these things need to be run against a real ca to make sure what is being generated (ie. the csr) is actually valid | 21:28 |
*** gyee has quit IRC | 21:32 | |
*** SheenaG has joined #openstack-barbican | 21:36 | |
*** xaeth is now known as xaeth_afk | 21:48 | |
*** rtom has joined #openstack-barbican | 21:49 | |
*** rtom has quit IRC | 21:49 | |
*** dave-mccowan has quit IRC | 21:55 | |
*** paul_glass has quit IRC | 21:55 | |
*** dave-mccowan has joined #openstack-barbican | 21:56 | |
*** nkinder has quit IRC | 22:05 | |
*** stanzi has joined #openstack-barbican | 22:10 | |
*** stanzi has quit IRC | 22:11 | |
*** stanzi has joined #openstack-barbican | 22:12 | |
*** stanzi has quit IRC | 22:13 | |
*** stanzi has joined #openstack-barbican | 22:13 | |
*** gyee has joined #openstack-barbican | 22:36 | |
*** rm_work is now known as rm_work|away | 22:37 | |
*** igueths1 has quit IRC | 22:38 | |
*** zz_dimtruck is now known as dimtruck | 22:44 | |
*** stanzi has quit IRC | 22:57 | |
*** stanzi has joined #openstack-barbican | 22:58 | |
woodster_ | alee_afk, dave-mccowan Just quick comments from above...the order is created in the PENDING state by the service before any cert processing happens. So the CSR would be generated *after* that PENDING order record is in the database. As for getting the CSR back from barbican, I guess we could add that as an optional secret ref on the certificate container? | 22:58 |
*** stanzi has quit IRC | 23:02 | |
dave-mccowan | woodster_, i the CSR is generated at request; the Certificate comes late. but, talked with alee about this. he said it is by design that the CSR is not returned. apparently it's between Barbican and the CA and none of the user's business. :-) | 23:02 |
woodster_ | dave-mccowan: yep, barbican meta is intended to be like a s | 23:05 |
woodster_ | dave-mccowan: ...scratchpad for processing the order | 23:05 |
*** dimtruck is now known as zz_dimtruck | 23:07 | |
dave-mccowan | woodster_ yes, i'm going to fix the test cases. no bug here on csr. | 23:07 |
*** chlong has joined #openstack-barbican | 23:15 | |
woodster_ | dave-mccowan: nice~! | 23:21 |
*** jamielennox|away is now known as jamielennox | 23:22 | |
*** kebray has quit IRC | 23:22 | |
redrobot | so there's two functional tests on HEAD that fail for me | 23:23 |
* redrobot wonders if it's related to https://review.openstack.org/#/c/172714/ | 23:24 | |
*** dave-mccowan has quit IRC | 23:28 | |
*** jaosorior has quit IRC | 23:32 | |
*** zz_dimtruck is now known as dimtruck | 23:49 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!