*** zz_dimtruck is now known as dimtruck | 00:10 | |
*** woodster_ has quit IRC | 00:40 | |
*** dimtruck is now known as zz_dimtruck | 00:48 | |
*** zz_dimtruck is now known as dimtruck | 00:55 | |
*** kebray has quit IRC | 01:02 | |
*** everjeje has quit IRC | 01:06 | |
*** dimtruck is now known as zz_dimtruck | 01:59 | |
*** kebray has joined #openstack-barbican | 02:00 | |
*** zz_dimtruck is now known as dimtruck | 02:27 | |
openstackgerrit | Ade Lee proposed openstack/barbican: Base64 encode the cert returned from the Dogtag plugin https://review.openstack.org/181786 | 02:34 |
---|---|---|
*** dimtruck is now known as zz_dimtruck | 02:40 | |
*** zz_dimtruck is now known as dimtruck | 02:44 | |
*** SheenaG has joined #openstack-barbican | 02:48 | |
*** dimtruck is now known as zz_dimtruck | 02:59 | |
*** dave-mccowan has quit IRC | 03:00 | |
*** SheenaG has quit IRC | 03:01 | |
*** SheenaG has joined #openstack-barbican | 03:30 | |
*** kebray has quit IRC | 04:09 | |
*** kebray has joined #openstack-barbican | 04:16 | |
*** SheenaG has quit IRC | 04:32 | |
openstackgerrit | John Wood proposed openstack/barbican-specs: Add Crypto/HSM MKEK Rotation Support https://review.openstack.org/178926 | 05:01 |
*** chlong has quit IRC | 05:09 | |
openstackgerrit | John Wood proposed openstack/barbican-specs: Add Crypto/HSM MKEK Rotation Support (Light) https://review.openstack.org/181598 | 05:13 |
*** woodster_ has joined #openstack-barbican | 05:24 | |
*** kebray has quit IRC | 05:27 | |
*** kebray has joined #openstack-barbican | 05:28 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Imported Translations from Transifex https://review.openstack.org/181714 | 06:07 |
*** jaosorior has joined #openstack-barbican | 06:53 | |
*** tkelsey has joined #openstack-barbican | 07:23 | |
*** kebray has quit IRC | 07:23 | |
*** woodster_ has quit IRC | 07:40 | |
*** everjeje has joined #openstack-barbican | 10:00 | |
*** darrenmoffat has quit IRC | 10:16 | |
*** darrenmoffat has joined #openstack-barbican | 10:17 | |
*** woodster_ has joined #openstack-barbican | 12:03 | |
*** dave-mccowan has joined #openstack-barbican | 12:12 | |
dave-mccowan | jaosorior ping | 12:20 |
jaosorior | dave-mccowan: pong | 13:01 |
dave-mccowan | jaosorior i saw you opened a bug on stackalytics missing liberty commits for barbican. do you know the latest? bug looks closed, but my liberty commits are still missing. | 13:11 |
jaosorior | dave-moccowan: I think they're going to the kilo release | 13:17 |
*** chlong has joined #openstack-barbican | 13:22 | |
dave-mccowan | jaosorior do you think it's working as intended? | 13:23 |
*** rellerreller has joined #openstack-barbican | 13:23 | |
*** alee_ has quit IRC | 13:56 | |
jaosorior | I don't think so | 13:58 |
jaosorior | woodster_: got time to check this one out? https://review.openstack.org/#/c/181025/ It's related to one of your blueprints that I ended up taking | 14:03 |
*** pglass has joined #openstack-barbican | 14:05 | |
*** openstackgerrit has quit IRC | 14:06 | |
*** openstackgerrit has joined #openstack-barbican | 14:07 | |
*** alee_ has joined #openstack-barbican | 14:08 | |
*** zz_dimtruck is now known as dimtruck | 14:11 | |
*** SheenaG has joined #openstack-barbican | 14:12 | |
*** dave-mccowan has quit IRC | 14:14 | |
*** openstack has joined #openstack-barbican | 14:18 | |
woodster_ | jaosorior: I'll take a look, thanks! | 14:19 |
*** xaeth_afk is now known as xaeth | 14:19 | |
*** dave-mccowan has joined #openstack-barbican | 14:29 | |
jaosorior | woodster_, jvrbanac: Do you know why in app.py, which is in barbican/api for the root controller pecan.make_app is used, and for the rest the contructor to the Pecan class is used? https://github.com/openstack/barbican/blob/master/barbican/api/app.py#L67 | 14:30 |
*** silos has joined #openstack-barbican | 14:36 | |
*** jsavak has joined #openstack-barbican | 14:38 | |
*** kfarr has joined #openstack-barbican | 14:40 | |
woodster_ | jaosorior: I'm not sure I follow you...create_main_app() -> build_wsgi_app() -> pecan.Pecan(...) | 14:46 |
jaosorior | Yup | 14:46 |
jaosorior | I was just wandering if there's a reason why pecan.Pecan (the object constructor) is used of the factory method pecan.make_app | 14:48 |
jaosorior | Though that also seems to be a good thing. Since because of the way we have that call, that doesn't allow extra config for pecan, we then don't have this problem https://wiki.openstack.org/wiki/OSSN/OSSN-0046 | 14:51 |
woodster_ | jaosorior: hmmm, not really sure actually. I think jvrbanac reworked that module to clean it up. | 14:55 |
jaosorior | woodster_: well, we don't have that security issue, yay | 15:01 |
alee | woodster_, redrobot , jaosorior - quick one https://review.openstack.org//#/c/181786/ please/ | 15:06 |
woodster_ | jaosorior: nice! | 15:07 |
woodster_ | alee: will do | 15:08 |
*** nelsnelson has joined #openstack-barbican | 15:11 | |
alee | woodster_, thanks | 15:11 |
alee | jaosorior, quick question .. | 15:11 |
alee | jaosorior, using the barbican cli -- how do I retrieve the payload of a secret? | 15:12 |
*** kebray has joined #openstack-barbican | 15:12 | |
redrobot | alee barbican secret get --payload | 15:16 |
openstackgerrit | Grzegorz Grasza (xek) proposed openstack/barbican-specs: Use oslo.versionedobjects to help with upgrades https://review.openstack.org/174318 | 15:17 |
jaosorior | Yup, there is that flag. To get more info about whats available you can do $ barbican help secret get | 15:17 |
alee | redrobot, jaosorior thanks - let me try that | 15:23 |
woodster_ | jaosorior: I added a long explanation to your CR...please take a look and see what you think though | 15:28 |
jaosorior | woodster_: I'll look into it.Though I think it would be possible to migrate the data and just have one more CR to remove the old functionality | 15:34 |
jaosorior | woodster_: thanks for taking a look into it. If you have time, there is also the first patch up there for the fix-version-api blueprint: https://review.openstack.org/#/c/178601/ | 15:36 |
alee | dave-mccowan, see my comment | 15:37 |
jaosorior | woodster_: thanks for taking a look into it. If you have time, there is also the first patch up there for the fix-version-api blueprint: https://review.openstack.org/#/c/178601/ | 15:38 |
*** igueths has joined #openstack-barbican | 15:39 | |
*** gyee has joined #openstack-barbican | 15:41 | |
*** atiwari2 has quit IRC | 15:42 | |
jaosorior | alee: left a question on your CR | 15:46 |
alee | jaosorior, looking | 15:46 |
alee | jaosorior, yes | 15:47 |
jaosorior | alee: done | 15:48 |
alee | jaosorior, thanks | 15:48 |
therve | alee, The lower call on the constants is unnecessary | 16:02 |
alee | therve, eh? | 16:03 |
therve | alee, sstore.KeyAlgorithm.AES.lower() | 16:03 |
therve | You don't need that lower() call | 16:03 |
alee | therve, ah - are they all lower already? | 16:03 |
therve | Yeah | 16:04 |
therve | Also, well, tests, but you probably know about that :) | 16:04 |
alee | therve, yeah - thing is though - those constants change sometimes - and there is no guarantee someone will not make something with mixed case. | 16:04 |
therve | alee, "those constants change sometimes" I should frame that :D | 16:05 |
alee | nothing -- other than convention right now says those should be lowercase. so to be safe, I'd rather leave the "now unnecessary" lower() | 16:06 |
alee | :) | 16:06 |
woodster_ | alee, I added a suggesting on your CR | 16:06 |
alee | woodster_, ok - I'll add a comment | 16:07 |
alee | therve, I'll add a dogtag specific functional test -- this wasn't noticed before because the functional tests did not go far enough | 16:08 |
alee | ie. we got the container , but not the certs out of the container | 16:08 |
* therve nods | 16:08 | |
therve | alee, It's actually something that surprised me in barbican: sometimes storing a secret works, but not retrieving it | 16:09 |
alee | therve, yeah - thats a bug if you find it | 16:09 |
alee | therve, if you store a secret, you better be able to retrieve it. | 16:10 |
therve | Cool, will see if I reproduce it | 16:10 |
woodster_ | therve: yeah, I guess we can't be *that* secure | 16:10 |
therve | Heh heh | 16:11 |
alee | woodster_, maybe we can rename the project "Event Horizon"? | 16:11 |
woodster_ | alee: ha! | 16:12 |
openstackgerrit | Steve Heyman proposed openstack/python-barbicanclient: Create behaviors for secrets https://review.openstack.org/179609 | 16:27 |
openstackgerrit | Steve Heyman proposed openstack/python-barbicanclient: Add CLI smoke functional tests for containers https://review.openstack.org/179659 | 16:39 |
openstackgerrit | Steve Heyman proposed openstack/python-barbicanclient: Add CLI smoke functional tests for containers https://review.openstack.org/179659 | 16:40 |
openstackgerrit | Merged openstack/barbican: Fix snakeoil_ca plugin https://review.openstack.org/179374 | 16:46 |
openstackgerrit | Steve Heyman proposed openstack/python-barbicanclient: Remove tempest config dependency in functional tests https://review.openstack.org/180686 | 16:46 |
woodster_ | arunkant: I added comments to your CR: https://review.openstack.org/#/c/180888 I'd say that is looking good, but added comments about removing the on_post() call entirely | 16:49 |
arunkant | woodster_, thanks for review..let me check | 16:50 |
*** silos has left #openstack-barbican | 16:54 | |
alee | woodster_, Sheena_ download this .. https://vakwetu.fedorapeople.org/cert-demo.tar.gz | 16:57 |
alee | woodster_, Sheena_ untar somewhere and then point a browser to it. | 16:57 |
alee | woodster_, Sheena_ I'm thiinking examples/demo4.html and then examples/demo3.html | 16:58 |
*** jsavak has quit IRC | 16:59 | |
dave-mccowan | alee for the plugin CR, is the value returned by dogtag base64 of DER (one long string), or a header-less and footer-less PEM with line breaks every 65 characters? | 17:04 |
alee | dave-mccowan, header and footerless PEM | 17:05 |
alee | dave-mccowan, and just for intermediates -- the cert itself is valid pem. | 17:06 |
alee | (with headers) | 17:06 |
alee | dave-mccowan, I need to fix the dogtag output so that its valid pem for the intermediates | 17:06 |
woodster_ | alee, jaosorior, dave-mccowan,redrobot it would be good to get review on arunkant 's changes | 17:12 |
-openstackstatus- NOTICE: We have discovered post-upgrade issues with Gerrit affecting nova (and potentially other projects). Some changes will not appear and some actions, such as queries, may return an error. We are continuing to investigate. | 17:37 | |
*** ChanServ changes topic to "We have discovered post-upgrade issues with Gerrit affecting nova (and potentially other projects). Some changes will not appear and some actions, such as queries, may return an error. We are continuing to investigate." | 17:37 | |
jaosorior | woodster_: after climbing I'll dig into those CRs | 17:38 |
*** pglass has quit IRC | 17:53 | |
*** rellerreller has quit IRC | 18:02 | |
*** rellerreller has joined #openstack-barbican | 18:02 | |
openstackgerrit | Steve Heyman proposed openstack/python-barbicanclient: Remove tempest config dependency in functional tests https://review.openstack.org/180686 | 18:12 |
*** x3k has joined #openstack-barbican | 18:23 | |
*** smallbig has quit IRC | 18:25 | |
*** morganfainberg has quit IRC | 18:25 | |
*** smallbig has joined #openstack-barbican | 18:27 | |
*** morganfainberg has joined #openstack-barbican | 18:27 | |
*** tkelsey has quit IRC | 18:47 | |
*** rellerreller has quit IRC | 18:59 | |
*** SheenaG has quit IRC | 19:04 | |
*** SheenaG has joined #openstack-barbican | 19:04 | |
*** everjeje has quit IRC | 19:06 | |
openstackgerrit | Steve Heyman proposed openstack/python-barbicanclient: Pass in keystone version and correct v2 URL to CLI https://review.openstack.org/182024 | 19:13 |
*** kebray has quit IRC | 19:14 | |
*** SheenaG has quit IRC | 19:14 | |
jaosorior | woodster_, arunkant: which are the CRs again? | 19:15 |
jaosorior | before I side-track reading other stuff again :P | 19:15 |
*** dave-mccowan has quit IRC | 19:17 | |
arunkant | jaosorior, https://review.openstack.org/#/c/180888 | 19:17 |
jaosorior | arunkant: will check it out | 19:18 |
*** SheenaG has joined #openstack-barbican | 19:28 | |
SheenaG | alee can you also send me your picture for the deck? | 19:29 |
alee | SheenaG, sure - have to find one that catches my good side :/ | 19:30 |
*** kebray has joined #openstack-barbican | 19:30 | |
*** rellerreller has joined #openstack-barbican | 19:30 | |
*** dave-mccowan has joined #openstack-barbican | 19:31 | |
*** nkinder has joined #openstack-barbican | 19:32 | |
SheenaG | alee if all else fails I can make a stick-man Ade | 19:32 |
alee | SheenaG, ha! are you saying that me looking for a picture that captures my good side is futile? | 19:33 |
SheenaG | alee hardly! I just figured I'd give you a way worse option | 19:35 |
alee | fair enough :) | 19:35 |
*** pglass has joined #openstack-barbican | 19:50 | |
*** pglass has quit IRC | 19:51 | |
*** pglass has joined #openstack-barbican | 19:52 | |
elmiko | i forget, is the meeting cancelled today? | 20:03 |
rellerreller | elmiko I have the same question. I do not see anyone at the meeting. | 20:04 |
arunkant | redrobot, is there a barbican meeting today? | 20:04 |
elmiko | ok, glad to know i'm not in an alternate dimension ;) | 20:05 |
redrobot | sorry guys | 20:05 |
redrobot | totally missed the meeting alarm | 20:05 |
elmiko | hehe | 20:05 |
redrobot | meeting is starting now in #openstack-meeting-alt | 20:06 |
*** rellerreller has quit IRC | 20:36 | |
*** openstackgerrit_ has joined #openstack-barbican | 20:44 | |
*** kfarr has quit IRC | 20:52 | |
*** kebray has quit IRC | 21:26 | |
*** silos has joined #openstack-barbican | 21:38 | |
*** kebray has joined #openstack-barbican | 21:55 | |
*** kebray has quit IRC | 21:55 | |
*** kebray has joined #openstack-barbican | 21:57 | |
*** silos has left #openstack-barbican | 21:59 | |
*** pglass has quit IRC | 22:00 | |
*** xaeth is now known as xaeth_afk | 22:04 | |
*** x3k has quit IRC | 22:07 | |
*** alee is now known as alee_dinner | 22:12 | |
openstackgerrit | Merged openstack/barbican: Add Multi-user support for Functional Tests https://review.openstack.org/176615 | 22:14 |
*** dimtruck is now known as zz_dimtruck | 22:22 | |
*** igueths has quit IRC | 22:23 | |
*** nkinder has quit IRC | 22:37 | |
*** nelsnelson has quit IRC | 22:47 | |
*** jaosorior has quit IRC | 23:12 | |
*** SheenaG has quit IRC | 23:19 | |
*** nkinder has joined #openstack-barbican | 23:46 | |
-openstackstatus- NOTICE: Gerrit is going offline while we perform an emergency downgrade to version 2.8. | 23:52 | |
*** ChanServ changes topic to "Gerrit is going offline while we perform an emergency downgrade to version 2.8." | 23:52 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!