*** kebray has quit IRC | 00:09 | |
*** nkinder__ has joined #openstack-barbican | 00:44 | |
*** dimtruck is now known as zz_dimtruck | 00:50 | |
*** zz_dimtruck is now known as dimtruck | 00:58 | |
*** nkinder__ has quit IRC | 01:15 | |
*** woodster_ has joined #openstack-barbican | 01:27 | |
*** dimtruck is now known as zz_dimtruck | 01:56 | |
*** kebray has joined #openstack-barbican | 02:27 | |
*** nkinder__ has joined #openstack-barbican | 02:29 | |
*** zz_dimtruck is now known as dimtruck | 02:44 | |
*** kfarr has joined #openstack-barbican | 02:54 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/191559 | 03:22 |
---|---|---|
*** kfarr has left #openstack-barbican | 03:23 | |
*** kfarr1 has joined #openstack-barbican | 03:32 | |
*** dimtruck is now known as zz_dimtruck | 03:58 | |
*** kfarr1 has quit IRC | 04:09 | |
*** elmiko has joined #openstack-barbican | 04:39 | |
*** kebray has quit IRC | 05:43 | |
*** nickrmc83 has joined #openstack-barbican | 05:59 | |
*** shohel has joined #openstack-barbican | 06:54 | |
*** woodster_ has quit IRC | 07:21 | |
*** chlong has quit IRC | 07:34 | |
*** everjeje has quit IRC | 07:57 | |
*** jorge_munoz has quit IRC | 08:26 | |
*** jorge_munoz has joined #openstack-barbican | 08:28 | |
*** shohel1 has joined #openstack-barbican | 09:31 | |
*** shohel has quit IRC | 09:31 | |
*** shohel1 has quit IRC | 09:36 | |
*** shohel has joined #openstack-barbican | 09:50 | |
*** shohel has quit IRC | 10:13 | |
*** shohel has joined #openstack-barbican | 10:14 | |
*** shohel1 has joined #openstack-barbican | 10:15 | |
*** shohel has quit IRC | 10:15 | |
*** nickrmc84 has joined #openstack-barbican | 12:05 | |
*** nickrmc83 has quit IRC | 12:06 | |
*** shohel1 has quit IRC | 12:13 | |
*** chlong has joined #openstack-barbican | 12:20 | |
*** kfarr has joined #openstack-barbican | 12:30 | |
*** shohel has joined #openstack-barbican | 12:34 | |
*** woodster_ has joined #openstack-barbican | 12:45 | |
*** nelsnelson has joined #openstack-barbican | 12:58 | |
*** nelsnelson has quit IRC | 12:58 | |
*** jaosorior has joined #openstack-barbican | 13:10 | |
*** nickrmc84 has quit IRC | 13:17 | |
*** SheenaG1 has quit IRC | 13:21 | |
*** nickrmc83 has joined #openstack-barbican | 13:30 | |
*** zz_dimtruck is now known as dimtruck | 14:11 | |
*** pglass has joined #openstack-barbican | 14:14 | |
*** Kevin_Bishop has joined #openstack-barbican | 14:21 | |
*** openstackgerrit has quit IRC | 14:24 | |
*** rellerreller has joined #openstack-barbican | 14:24 | |
*** openstackgerrit has joined #openstack-barbican | 14:24 | |
*** xaeth_afk is now known as xaeth | 14:29 | |
*** elmiko has quit IRC | 14:33 | |
openstackgerrit | Nathan Reller proposed openstack/barbican: Added certificate support to KMIP secret store https://review.openstack.org/190299 | 14:34 |
*** silos has joined #openstack-barbican | 14:34 | |
openstackgerrit | Merged openstack/barbican: Updated from global requirements https://review.openstack.org/191559 | 14:37 |
*** SheenaG has joined #openstack-barbican | 14:44 | |
*** kebray has joined #openstack-barbican | 14:52 | |
*** kebray has quit IRC | 14:56 | |
*** diazjf has joined #openstack-barbican | 14:56 | |
*** kfox1111_ has quit IRC | 15:13 | |
*** igueths has joined #openstack-barbican | 15:14 | |
*** kebray has joined #openstack-barbican | 15:15 | |
*** kebray has quit IRC | 15:21 | |
*** rellerreller_ has joined #openstack-barbican | 15:28 | |
*** rellerreller has quit IRC | 15:31 | |
*** kebray has joined #openstack-barbican | 15:37 | |
*** kebray has quit IRC | 15:42 | |
*** jaosorior has quit IRC | 15:45 | |
*** kfox1111 has joined #openstack-barbican | 15:49 | |
*** nkinder__ has quit IRC | 15:50 | |
*** kebray has joined #openstack-barbican | 15:50 | |
*** stanzi has joined #openstack-barbican | 15:53 | |
*** stanzi has quit IRC | 15:59 | |
*** stanzi has joined #openstack-barbican | 15:59 | |
*** Guest67074 is now known as redrobot | 16:02 | |
*** nickrmc83 has quit IRC | 16:03 | |
kfox1111 | the nova guys would be much more comfortable with the instance user if barbican folks would weigh in. | 16:08 |
kfox1111 | can you please? | 16:08 |
kfox1111 | https://review.openstack.org/#/c/186617 | 16:08 |
kfox1111 | the keystone core's don't even seem to fully understand how other openstack projects have been using keystone for over a year. :/ | 16:09 |
*** stanzi has quit IRC | 16:09 | |
*** stanzi has joined #openstack-barbican | 16:14 | |
openstackgerrit | Nathan Reller proposed openstack/barbican: Added passphrase support to KMIP secret store https://review.openstack.org/191527 | 16:17 |
*** stanzi has quit IRC | 16:20 | |
*** shohel has quit IRC | 16:28 | |
*** diazjf1 has joined #openstack-barbican | 16:29 | |
*** diazjf has quit IRC | 16:29 | |
*** gyee_ has joined #openstack-barbican | 16:30 | |
*** kebray has quit IRC | 16:31 | |
*** diazjf1 has quit IRC | 16:31 | |
*** stanzi has joined #openstack-barbican | 16:33 | |
*** kfarr1 has joined #openstack-barbican | 16:44 | |
*** kfarr has quit IRC | 16:47 | |
openstackgerrit | Kaitlin Farr proposed openstack/castellan: Add managed objects hierarchy https://review.openstack.org/191884 | 16:54 |
openstackgerrit | Kaitlin Farr proposed openstack/castellan: Add managed objects hierarchy https://review.openstack.org/191884 | 16:56 |
openstackgerrit | John Wood proposed openstack/barbican-specs: Add List of Group-IDs to ACL for Secrets/Containers https://review.openstack.org/191076 | 16:56 |
*** elmiko has joined #openstack-barbican | 16:57 | |
*** shohel has joined #openstack-barbican | 16:58 | |
*** kfarr1 has quit IRC | 16:58 | |
*** kfarr has joined #openstack-barbican | 17:14 | |
*** elmiko has quit IRC | 17:23 | |
*** stanzi has quit IRC | 17:27 | |
*** crc32 has joined #openstack-barbican | 17:27 | |
*** kfarr has quit IRC | 17:30 | |
*** rellerreller_ has quit IRC | 17:33 | |
*** stanzi has joined #openstack-barbican | 17:34 | |
*** stanzi has quit IRC | 17:34 | |
*** crc32 has quit IRC | 17:35 | |
kfox1111 | Has Barbican and Designate talked through how https certs should be managed? | 18:15 |
kfox1111 | it would be great if you could issue http certs that matched up with domains you managed through Designate. | 18:15 |
chellygel | kfox1111, that doesn't sound familiar to me. not sure that discussion has been had... anyone else? | 18:17 |
*** kebray has joined #openstack-barbican | 18:27 | |
kfox1111 | bummer. :/ | 18:28 |
*** Kevin_Bishop has quit IRC | 18:36 | |
*** Kevin_Bishop has joined #openstack-barbican | 18:37 | |
*** arunkant has joined #openstack-barbican | 18:47 | |
*** crc32 has joined #openstack-barbican | 18:58 | |
*** crc32 has quit IRC | 19:18 | |
*** nkinder__ has joined #openstack-barbican | 19:20 | |
*** silos has left #openstack-barbican | 19:22 | |
kfox1111 | ]#@$#(@*! | 19:28 |
*** jaosorior has joined #openstack-barbican | 19:29 | |
kfox1111 | All the way back around again! | 19:29 |
kfox1111 | "How do you get a keystone secret to a vm so that it can talk to keystone"! | 19:29 |
jaosorior | Lol seems I arrived at an interesting time | 19:32 |
*** stanzi has joined #openstack-barbican | 19:38 | |
*** silos has joined #openstack-barbican | 19:44 | |
*** rellerreller has joined #openstack-barbican | 19:47 | |
*** everjeje has joined #openstack-barbican | 19:48 | |
*** stanzi has quit IRC | 19:49 | |
kfox1111 | ahhhh... ok. I have a path forward.... and interestingly, it involves more barbican! :) | 19:52 |
*** kfarr has joined #openstack-barbican | 19:52 | |
kfox1111 | So barbican would become an identity provider of Keystone. :) | 19:53 |
redrobot | hmm... interesting | 19:53 |
kfox1111 | Nova would be modified to request pub/priv keys from barbican, | 19:53 |
kfox1111 | with attributes of the username = the instance uuid. | 19:53 |
morganfainberg | redrobot: kfox1111: thre is a bit more to it than that | 19:54 |
morganfainberg | you can use the CA -> keystone mapping engine, would *possibly* just need standard certs | 19:54 |
morganfainberg | no magic attributes | 19:54 |
kfox1111 | (yeah. just trying to whitle down what Barbican needs to know) | 19:54 |
* redrobot makes a note to go read the keystone log | 19:54 | |
morganfainberg | barbican should need to allow nova user to create a cert from a known CA | 19:55 |
kfox1111 | redrobot: I'm going to update the spec too. | 19:55 |
morganfainberg | keystone needs tokenless-auth spec to be implemented | 19:55 |
morganfainberg | mapping engine (in keystone) configured to map users from that CA to the right place | 19:55 |
kfox1111 | morganfainberg: just to double check, thats happening in Liberty for sure? | 19:55 |
morganfainberg | kfox1111 it is slated for liberty | 19:55 |
kfox1111 | ok. cool. | 19:55 |
morganfainberg | nothing is 100% until liberty release though | 19:55 |
* morganfainberg dodges | 19:55 | |
kfox1111 | fair enough. :) | 19:55 |
kfox1111 | morganfainberg: did you look at the unscoped token spec too. I think that still might help things too. | 19:56 |
morganfainberg | kfox1111: i'm officially on break this week | 19:56 |
kfox1111 | on the vm -> barbican side. | 19:56 |
morganfainberg | so.... | 19:56 |
morganfainberg | no | 19:56 |
morganfainberg | :P | 19:56 |
kfox1111 | ok. :) | 19:57 |
kfox1111 | I'll hit you up next week then. :) | 19:57 |
kfox1111 | sorry to bother you on your vacation. | 19:57 |
morganfainberg | i just jumped in for that convo so we could head off the "oh hell this wont work or be interoperable" part | 19:57 |
kfox1111 | yeah. I appreciate that. | 19:57 |
morganfainberg | since keystone is really really trying to get out of managing any identities directly | 19:57 |
kfox1111 | yeah. I don't blame you. :) | 19:57 |
*** stanzi has joined #openstack-barbican | 19:58 | |
*** stanzi has quit IRC | 19:58 | |
morganfainberg | focusing on the access management (which is what we're better at anyway) and consuming identity from lots of sources | 19:59 |
* redrobot steps away for the weekly meeting | 19:59 | |
*** stanzi has joined #openstack-barbican | 19:59 | |
redrobot | Weekly meeting is starting now in #openstack-meeting-alt | 19:59 |
kfox1111 | yeah. that should help matters a lot I think. | 19:59 |
*** elmiko has joined #openstack-barbican | 20:01 | |
*** stanzi_ has joined #openstack-barbican | 20:08 | |
openstackgerrit | Kevin Bishop proposed openstack/barbican: Replace oslo incubator code with oslo_utils https://review.openstack.org/191960 | 20:09 |
*** kfarr1 has joined #openstack-barbican | 20:12 | |
*** kfarr1 has left #openstack-barbican | 20:12 | |
*** stanzi has quit IRC | 20:12 | |
*** silos1 has joined #openstack-barbican | 20:12 | |
*** stanzi_ has quit IRC | 20:13 | |
*** stanzi has joined #openstack-barbican | 20:13 | |
*** silos has quit IRC | 20:15 | |
*** kfarr has quit IRC | 20:23 | |
*** kebray has quit IRC | 20:30 | |
*** kfarr has joined #openstack-barbican | 20:30 | |
*** kfarr_ has joined #openstack-barbican | 20:33 | |
*** igueths has quit IRC | 20:37 | |
*** rellerreller has quit IRC | 20:39 | |
*** silos1 has left #openstack-barbican | 20:44 | |
*** kebray has joined #openstack-barbican | 20:46 | |
*** kebray has quit IRC | 20:47 | |
*** kebray has joined #openstack-barbican | 20:50 | |
*** elmiko has quit IRC | 21:00 | |
*** elmiko has joined #openstack-barbican | 21:04 | |
*** elmiko has quit IRC | 21:06 | |
*** SheenaG has quit IRC | 21:35 | |
*** pglass has quit IRC | 21:45 | |
*** shohel has quit IRC | 21:57 | |
*** chlong has quit IRC | 21:57 | |
*** stanzi has quit IRC | 21:57 | |
*** xaeth is now known as xaeth_afk | 22:18 | |
*** kebray has quit IRC | 22:19 | |
*** dimtruck is now known as zz_dimtruck | 22:29 | |
*** david-lyle has quit IRC | 22:31 | |
*** SheenaG has joined #openstack-barbican | 22:31 | |
*** Kevin_Bishop has quit IRC | 22:32 | |
*** kfarr_ has quit IRC | 22:36 | |
*** kfarr has left #openstack-barbican | 22:37 | |
*** kfox1111 has quit IRC | 22:40 | |
*** stanzi has joined #openstack-barbican | 22:42 | |
*** darrenmoffat has quit IRC | 22:42 | |
*** darrenmoffat has joined #openstack-barbican | 22:43 | |
*** stanzi has quit IRC | 22:47 | |
*** stanzi has joined #openstack-barbican | 22:47 | |
*** stanzi has quit IRC | 23:04 | |
*** jaosorior has quit IRC | 23:05 | |
*** david-lyle has joined #openstack-barbican | 23:11 | |
*** kfox1111 has joined #openstack-barbican | 23:19 | |
*** stanzi has joined #openstack-barbican | 23:35 | |
*** stanzi has quit IRC | 23:43 | |
*** stanzi has joined #openstack-barbican | 23:45 | |
*** chlong has joined #openstack-barbican | 23:47 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!