*** Sheena_ has quit IRC | 01:19 | |
*** lisaclark_ has quit IRC | 01:20 | |
*** lisaclark has quit IRC | 01:20 | |
*** Sheena_ has joined #openstack-barbican | 01:20 | |
*** lisaclark_ has joined #openstack-barbican | 01:24 | |
*** lisaclark has joined #openstack-barbican | 01:24 | |
*** woodster_ has joined #openstack-barbican | 03:05 | |
*** kebray has quit IRC | 03:14 | |
*** dave-mccowan has quit IRC | 03:56 | |
*** nickrmc84 has quit IRC | 06:23 | |
*** woodster_ has quit IRC | 06:40 | |
*** jillysciarilly has quit IRC | 07:16 | |
*** jillysciarilly has joined #openstack-barbican | 07:18 | |
*** rm_work has quit IRC | 07:59 | |
*** rm_work|away has joined #openstack-barbican | 07:59 | |
*** rm_work|away is now known as rm_work | 07:59 | |
*** rm_work has joined #openstack-barbican | 07:59 | |
*** openstackstatus has joined #openstack-barbican | 08:05 | |
*** ChanServ sets mode: +v openstackstatus | 08:05 | |
-openstackstatus- NOTICE: Restarting gerrit because it stopped sending events (ETA 15 mins) | 08:09 | |
*** openstackgerrit has quit IRC | 08:13 | |
*** darrenmoffat has quit IRC | 08:14 | |
*** openstackgerrit has joined #openstack-barbican | 08:16 | |
*** russell_h has quit IRC | 08:17 | |
*** russell_h has joined #openstack-barbican | 08:20 | |
*** alkar has joined #openstack-barbican | 08:32 | |
*** darrenmoffat has joined #openstack-barbican | 08:34 | |
*** darrenmoffat has left #openstack-barbican | 08:38 | |
*** jaosorior has joined #openstack-barbican | 08:39 | |
*** alkar has quit IRC | 08:59 | |
*** alkar has joined #openstack-barbican | 09:04 | |
*** woodster_ has joined #openstack-barbican | 12:01 | |
*** openstackgerrit has quit IRC | 12:06 | |
*** openstackgerrit has joined #openstack-barbican | 12:06 | |
*** openstackgerrit has quit IRC | 12:37 | |
*** openstackgerrit has joined #openstack-barbican | 12:37 | |
*** elmiko_ is now known as elmiko | 13:09 | |
*** alkar has quit IRC | 13:15 | |
*** alkar has joined #openstack-barbican | 13:18 | |
*** openstackgerrit has quit IRC | 13:21 | |
*** openstackgerrit has joined #openstack-barbican | 13:22 | |
*** alee_afk is now known as alee | 13:32 | |
*** silos has joined #openstack-barbican | 13:40 | |
*** morganfainberg has quit IRC | 13:44 | |
*** jroll has quit IRC | 13:44 | |
*** jroll has joined #openstack-barbican | 13:44 | |
-openstackstatus- NOTICE: gerrit has been restarted to clear a problem with its event stream. change events between 13:09 and 13:36 utc should be rechecked or have approval votes reapplied as needed to trigger jobs | 13:46 | |
*** morganfainberg has joined #openstack-barbican | 13:47 | |
*** joesavak has joined #openstack-barbican | 13:59 | |
*** silos has left #openstack-barbican | 14:05 | |
*** paul_glass has joined #openstack-barbican | 14:06 | |
*** paul_glass is now known as Guest31161 | 14:06 | |
*** Guest31161 has quit IRC | 14:07 | |
*** pglass has joined #openstack-barbican | 14:08 | |
*** stanzi has joined #openstack-barbican | 14:08 | |
*** pglass is now known as Guest59146 | 14:08 | |
*** stanzi has quit IRC | 14:32 | |
*** stanzi has joined #openstack-barbican | 14:33 | |
*** nkinder has joined #openstack-barbican | 14:33 | |
*** stanzi has quit IRC | 14:37 | |
*** russell_h has quit IRC | 14:39 | |
*** russell_h has joined #openstack-barbican | 14:39 | |
*** dave-mccowan has joined #openstack-barbican | 14:40 | |
openstackgerrit | Amy Marrich proposed openstack/barbican: Improved error code handling for pkcs11 errors https://review.openstack.org/175568 | 14:42 |
---|---|---|
*** kebray has joined #openstack-barbican | 14:50 | |
*** tkelsey has joined #openstack-barbican | 14:52 | |
tkelsey | hello barbican folks, I should probably know this but how do I pull down the "official" barbican code that formed part of Juno release? | 14:53 |
tkelsey | as apposed to the current | 14:54 |
jvrbanac | tkelsey, it should be on the stable/juno branch | 14:55 |
jvrbanac | s/juno/kilo | 14:56 |
jvrbanac | tkelsey, https://github.com/openstack/barbican/tree/stable/kilo | 14:56 |
tkelsey | ah right, thanks jvrbanac | 14:56 |
tkelsey | so thats the official Juno code then | 14:56 |
tkelsey | ? | 14:57 |
jvrbanac | tkelsey, I believe so. I wouldn't use Juno though ;) | 14:57 |
jvrbanac | It's kinda old | 14:57 |
jvrbanac | The Kilo branch was split off a few days ago | 14:58 |
tkelsey | sure :) I just needed to look it over to answer some question | 14:58 |
tkelsey | thanks jvrbanac | 14:58 |
jvrbanac | tkelsey, got it. np | 14:58 |
openstackgerrit | Kaitlin Farr proposed openstack/castellan: Add Barbican key manager https://review.openstack.org/171918 | 15:09 |
openstackgerrit | Kaitlin Farr proposed openstack/castellan: Add Barbican key manager https://review.openstack.org/171918 | 15:21 |
*** Guest59146 is now known as pglass | 15:22 | |
*** pglass is now known as Guest35930 | 15:22 | |
*** Guest35930 has left #openstack-barbican | 15:22 | |
*** joesavak has quit IRC | 15:23 | |
*** Asha has joined #openstack-barbican | 15:27 | |
*** paul_glass has joined #openstack-barbican | 15:29 | |
*** paul_glass is now known as pglass | 15:30 | |
*** joesavak has joined #openstack-barbican | 15:32 | |
*** silos has joined #openstack-barbican | 15:34 | |
*** silos has left #openstack-barbican | 15:35 | |
*** silos has joined #openstack-barbican | 15:36 | |
*** jroll has quit IRC | 15:44 | |
*** jroll has joined #openstack-barbican | 15:46 | |
*** jroll has quit IRC | 15:53 | |
*** jroll has joined #openstack-barbican | 15:53 | |
*** pglass has quit IRC | 15:53 | |
*** gyee has joined #openstack-barbican | 15:55 | |
*** stanzi has joined #openstack-barbican | 16:01 | |
*** david-ly_ is now known as david-lyle | 16:01 | |
*** rellerreller has joined #openstack-barbican | 16:07 | |
openstackgerrit | Merged openstack/barbican: Fix for missing id check in ACL count query. https://review.openstack.org/177344 | 16:09 |
*** stanzi has quit IRC | 16:13 | |
*** stanzi has joined #openstack-barbican | 16:13 | |
*** stanzi has quit IRC | 16:18 | |
*** joesavak has quit IRC | 16:19 | |
openstackgerrit | Chelsea Winfree proposed openstack/python-barbicanclient: Refactored barbican.py for better testability https://review.openstack.org/177511 | 16:20 |
*** kfarr has joined #openstack-barbican | 16:29 | |
*** pglass has joined #openstack-barbican | 16:32 | |
*** igueths has joined #openstack-barbican | 16:36 | |
*** kebray has quit IRC | 16:38 | |
*** alkar has quit IRC | 16:38 | |
*** alkar_ has joined #openstack-barbican | 16:38 | |
*** alkar_ has quit IRC | 16:38 | |
*** kebray has joined #openstack-barbican | 16:38 | |
*** chadlung has joined #openstack-barbican | 16:47 | |
*** SheenaG has joined #openstack-barbican | 16:49 | |
*** stanzi has joined #openstack-barbican | 16:59 | |
*** stanzi has quit IRC | 17:01 | |
*** stanzi has joined #openstack-barbican | 17:02 | |
*** stanzi has quit IRC | 17:06 | |
*** igueths has quit IRC | 17:07 | |
*** igueths has joined #openstack-barbican | 17:07 | |
openstackgerrit | Kaitlin Farr proposed openstack/castellan: Add Barbican key manager https://review.openstack.org/171918 | 17:09 |
*** joesavak has joined #openstack-barbican | 17:09 | |
*** stanzi has joined #openstack-barbican | 17:33 | |
openstackgerrit | Steve Heyman proposed openstack/python-barbicanclient: Update stdout and stderr capture in functional tests https://review.openstack.org/175150 | 17:35 |
*** stanzi has quit IRC | 17:41 | |
*** joesavak has quit IRC | 17:41 | |
openstackgerrit | Steve Heyman proposed openstack/python-barbicanclient: Update stdout and stderr capture in functional tests https://review.openstack.org/175150 | 17:44 |
*** joesavak has joined #openstack-barbican | 17:50 | |
*** stanzi has joined #openstack-barbican | 17:59 | |
*** rellerreller has quit IRC | 18:03 | |
openstackgerrit | Steve Heyman proposed openstack/python-barbicanclient: Add Secret CLI smoke tests https://review.openstack.org/177906 | 18:05 |
*** silos has left #openstack-barbican | 18:13 | |
*** stanzi_ has joined #openstack-barbican | 18:23 | |
*** stanzi has quit IRC | 18:23 | |
*** stanzi_ has quit IRC | 18:24 | |
*** stanzi has joined #openstack-barbican | 18:25 | |
*** chadlung_ has joined #openstack-barbican | 18:27 | |
*** chadlung has quit IRC | 18:27 | |
*** xaethl is now known as xaeth | 18:45 | |
openstackgerrit | Merged openstack/barbican: Improved error code handling for pkcs11 errors https://review.openstack.org/175568 | 18:50 |
arunkant | In local mysql setup seeing this error with migration script..any indication what is wrong in local setup..OperationalError: (OperationalError) near "ALTER": syntax error u'ALTER TABLE order_barbican_metadata ALTER COLUMN value TYPE TEXT' () | 19:02 |
*** SheenaG has quit IRC | 19:02 | |
arunkant | its failing when it tries to alter order metadata from String to Text | 19:03 |
*** SheenaG has joined #openstack-barbican | 19:05 | |
*** rellerreller has joined #openstack-barbican | 19:07 | |
*** rellerreller has quit IRC | 19:20 | |
*** rellerreller has joined #openstack-barbican | 19:20 | |
openstackgerrit | Steve Heyman proposed openstack/python-barbicanclient: Add Secret CLI smoke tests https://review.openstack.org/177906 | 19:25 |
*** joesavak has quit IRC | 19:28 | |
openstackgerrit | Chelsea Winfree proposed openstack/python-barbicanclient: Refactored barbican.py for better testability https://review.openstack.org/177511 | 19:33 |
hockeynut | chellygel did you have any issues with authentication for CLI in the gate? I am getting 401 trying to do my secret CLI tests | 19:57 |
redrobot | Weekly meeting is starting now in #openstack-meeting-alt | 19:59 |
*** stanzi has quit IRC | 20:01 | |
*** stanzi has joined #openstack-barbican | 20:02 | |
chellygel | all the tests came back fine? not sure hockeynut -- have a link i can see? | 20:03 |
*** mdarby has joined #openstack-barbican | 20:03 | |
hockeynut | https://jenkins07.openstack.org/job/gate-python-barbicanclient-devstack-dsvm/32/consoleText | 20:03 |
hockeynut | look for functionaltests.cli.v1.smoke.test_secret:SecretTestCase: INFO: updated command string | 20:04 |
*** joesavak has joined #openstack-barbican | 20:04 | |
*** stanzi has quit IRC | 20:06 | |
chellygel | hockeynut, what change is this for? | 20:12 |
hockeynut | chellygel this is to add the secrets CLI tests | 20:14 |
hockeynut | (functional tests) | 20:14 |
chellygel | so, im going to go off a wild hair, we may want to try running these tests against the refactor we just did... | 20:17 |
chellygel | is it set up for v3 auth? i'd want to see the error we're getting in thet keystone logs | 20:18 |
*** pglass has quit IRC | 20:21 | |
hockeynut | chellygel yes its v3 | 20:22 |
hockeynut | and, of course, it runs just fine locally :-) | 20:22 |
chellygel | do we have access to the keystone logs on the server somehow? | 20:24 |
hockeynut | chellygel devstack goes away once its done :-( and i don't see specific keystone logs. | 20:25 |
hockeynut | I do see that I am using the expected id/pw/etc - which I do believe are the same creds we use in the python client tests | 20:25 |
hockeynut | this is the first CR for CLI that uses authentication so not too shocked that its being obstinant | 20:26 |
hockeynut | I'm poking thru the other logs to see if there is anything possibly interesting | 20:27 |
chellygel | just checked, my change has no issues in devstack -- so thats annoying! what is going on >:( | 20:30 |
chellygel | hockeynut, i dont think endpoint is required when using auth though | 20:30 |
chellygel | but i dont think that'd throw an error. | 20:30 |
hockeynut | you mean keystone or barbican uri? | 20:31 |
chellygel | the barbican --endpoint flag | 20:31 |
hockeynut | so it would get the endpt from service catalog? | 20:32 |
chellygel | yes, i believe so | 20:33 |
hockeynut | interesting if that's the problem. I'll give it a shot | 20:36 |
chellygel | i dont think it would be, but if it is -- you should punch it | 20:36 |
hockeynut | can't hurt to try | 20:37 |
openstackgerrit | Steve Heyman proposed openstack/python-barbicanclient: Add Secret CLI smoke tests https://review.openstack.org/177906 | 20:38 |
chellygel | oh the rock game w/ devstack :( | 20:38 |
hockeynut | indeed | 20:38 |
chellygel | did it work locally w/o endpoint steve? | 20:38 |
hockeynut | no | 20:38 |
hockeynut | I think I'll try local barbican with another keystone (not my local docker one) | 20:40 |
chellygel | well we could run the tests w/ --no-auth, right? | 20:40 |
* chellygel grasps at straws | 20:41 | |
*** pglass has joined #openstack-barbican | 20:41 | |
hockeynut | its odd that the same creds are used for python client. | 20:41 |
*** rellerreller has quit IRC | 20:42 | |
*** tkelsey has quit IRC | 21:00 | |
rm_work | So user Bob is created, and granted all of the default roles that users get, plus the new "read_other" role | 21:01 |
rm_work | User Tom has a secret on his project that he shares with Bob | 21:01 |
rm_work | When Bob reads the secret from Tom's project, we check the configured ACLs in Barbican, and also that Bob has the "read_other" role for Bob's own tenant (nothing to do with Tom) | 21:02 |
rm_work | No Tom-specific role needs to be added to Bob | 21:02 |
rm_work | and if Jill also shares a secret with Bob, he can read that one too | 21:02 |
rm_work | but if an admin removes the "read_other" role from Bob, then he can no longer access secrets from either Tom or Jill, even though both have valid ACLs granting Bob access, because Bob is no longer allowed to read any shared secrets | 21:03 |
rm_work | ^^ correct? | 21:03 |
woodster_ | rm_work I'd been thinking of that more simply...the policy would be the same as now, except that for ACL-related GETs, the policy would also require that the user has the new read-only role. This would be independent of project associations of the user. | 21:06 |
rm_work | err, that is what I was just saying | 21:07 |
rm_work | so obviously my example is not very clear :P | 21:07 |
woodster_ | rm_work: ha, sorry the 'tenant' mention up there threw me | 21:08 |
woodster_ | alee, arunkant are you guys ok with this new role/approach? | 21:09 |
arunkant | woodster_, if user has both non-ACL and ACL secrets (let's say secret is private and user is added in ACL user list) in a project, then to access ACL secret user need to have "read_other" role in that project as well if it want to same token to access both types of secrets | 21:10 |
alee | woodster_, I don;t have any objection to the new role | 21:10 |
rm_work | arunkant: read_other in their OWN project, not the target project | 21:11 |
woodster_ | arunkant: so in reality the default role should be the new read-other one (to allow any other user to grant secret access later). The existing roles handle project-wide access and are optional. | 21:14 |
arunkant | rm_work, yes..but if you have non-ACL secrets in a project and you want to access those secrets, then you need token scoped to that project. Now if you have ACL secret as mentioned above, then you cannot use same token if it does not have that role "read_other". So it may mean that you will need token with that project where you have that role | 21:14 |
arunkant | em_work, so user will need to switch token for ACL secrets vs. non-ACL secrets within same project. Don't know if that will be an issue or not? | 21:16 |
rm_work | err, so you're mixing using ACL to provide access to secrets, and Trusts to provide access to secrets? | 21:16 |
rm_work | if you have a token scoped to another project, it won't even go through the ACLs, since it'll have unlimited access to the project (not scoped to a single secret) | 21:17 |
rm_work | there wouldn't even be a point in using ACLs at all | 21:17 |
*** joesavak has quit IRC | 21:17 | |
arunkant | rm_work, its only in the case user has access to number of secrets in project and one of secret is marked private and then that user is provided access via ACL..but it should be okay as long as client can switch token when requesting ACL based secret. | 21:20 |
*** gyee has quit IRC | 21:20 | |
rm_work | arunkant: i still don't quite understand -- there is no such thing as "marked private" if you have a trust token scoped for that user | 21:23 |
rm_work | brb 30m | 21:24 |
arunkant | rm_work, I meant 'creator_only' flag as true which means the other users with project roles cannot access that secret (except creator user) | 21:24 |
openstackgerrit | Steve Heyman proposed openstack/python-barbicanclient: Add Secret CLI smoke tests https://review.openstack.org/177906 | 21:28 |
*** dave-mccowan has quit IRC | 21:30 | |
*** dave-mccowan has joined #openstack-barbican | 21:31 | |
*** mdarby has quit IRC | 21:31 | |
*** silos has joined #openstack-barbican | 21:40 | |
*** silos has left #openstack-barbican | 21:41 | |
*** dave-mccowan has quit IRC | 21:47 | |
*** dave-mccowan has joined #openstack-barbican | 21:48 | |
*** chadlung_ has quit IRC | 21:59 | |
*** xaeth is now known as xaeth_afk | 22:07 | |
*** pglass has quit IRC | 22:09 | |
*** kfarr has quit IRC | 22:10 | |
*** jaosorior has quit IRC | 22:32 | |
*** igueths has quit IRC | 22:47 | |
*** stanzi has joined #openstack-barbican | 22:59 | |
*** stanzi has quit IRC | 23:06 | |
*** stanzi has joined #openstack-barbican | 23:07 | |
*** dimtruck is now known as zz_dimtruck | 23:20 | |
*** SheenaG has quit IRC | 23:29 | |
*** stanzi has quit IRC | 23:43 | |
*** stanzi has joined #openstack-barbican | 23:44 | |
*** stanzi has quit IRC | 23:48 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!