Thursday, 2015-06-18

*** stanzi has joined #openstack-barbican00:15
*** kfarr has joined #openstack-barbican00:20
*** kfarr has left #openstack-barbican00:22
*** gyee has quit IRC00:23
*** zz_dimtruck is now known as dimtruck00:28
*** jamielennox|away is now known as jamielennox00:35
*** kebray has quit IRC00:40
*** kfox1111 has quit IRC00:43
*** stanzi has quit IRC00:47
*** stanzi has joined #openstack-barbican00:48
*** jamielennox is now known as jamielennox|away01:00
*** jamielennox|away is now known as jamielennox01:08
*** woodster_ has quit IRC02:01
*** jamielennox is now known as jamielennox|away02:20
openstackgerritJuan Antonio Osorio Robles proposed openstack/barbican: Display all versions info in versions controller  https://review.openstack.org/17860102:21
*** rm_you| has joined #openstack-barbican02:46
*** rm_you has quit IRC02:47
openstackgerritArun Kant proposed openstack/barbican: Addred unit test around bug related to who can modify ACL.  https://review.openstack.org/17954702:54
openstackgerritArun Kant proposed openstack/barbican: Added unit test around bug related to who can modify ACL.  https://review.openstack.org/17954702:56
*** jamielennox|away is now known as jamielennox03:03
*** arunkant1 has joined #openstack-barbican03:05
*** arunkant1 has left #openstack-barbican03:06
*** stanzi has quit IRC03:08
*** arunkant__ has joined #openstack-barbican03:13
*** stanzi has joined #openstack-barbican03:14
*** jamielennox is now known as jamielennox|away03:15
*** stanzi_ has joined #openstack-barbican03:15
*** arunkant__ has quit IRC03:17
*** woodster_ has joined #openstack-barbican03:18
*** stanzi_ has quit IRC03:19
*** stanzi has quit IRC03:19
*** jhfeng_ has joined #openstack-barbican03:25
*** jamielennox|away is now known as jamielennox03:25
*** jhfeng_ has quit IRC03:39
*** diazjf has joined #openstack-barbican03:46
*** dimtruck is now known as zz_dimtruck03:52
*** jaosorior has joined #openstack-barbican03:57
jaosoriorwoodster_: If you're still around, I updated this CR with the comment you pointed out https://review.openstack.org/#/c/178601/03:58
jaosoriorfor some reason (probably the excessive sun in summer here) my brain decided 5am was a good time to wake up, so now I'm here haha03:59
*** stanzi has joined #openstack-barbican04:24
*** stanzi has quit IRC04:32
openstackgerritMerged openstack/barbican: Update version for Liberty  https://review.openstack.org/19241304:33
*** diazjf has quit IRC05:19
*** jamielennox is now known as jamielennox|away05:23
*** jamielennox|away is now known as jamielennox05:26
*** chlong has quit IRC05:38
*** chlong has joined #openstack-barbican05:53
*** jaosorior has quit IRC06:35
*** shohel has joined #openstack-barbican06:36
*** woodster_ has quit IRC06:51
*** Nirupama has joined #openstack-barbican06:57
*** nickrmc83 has joined #openstack-barbican07:05
*** chlong has quit IRC07:18
*** stanzi has joined #openstack-barbican07:30
*** stanzi has quit IRC07:35
*** dave-mccowan has joined #openstack-barbican10:21
*** dave-mccowan has quit IRC10:26
*** dave-mccowan has joined #openstack-barbican10:27
*** shohel has quit IRC12:00
*** kfarr has joined #openstack-barbican12:20
*** Nirupama has quit IRC12:26
openstackgerritNathan Reller proposed openstack/barbican: Stanardized Functional Tests  https://review.openstack.org/19309912:28
*** woodster_ has joined #openstack-barbican12:45
*** xaeth_afk is now known as xaeth13:04
*** kfarr has quit IRC13:16
*** xaeth is now known as xaeth_afk13:17
*** xek has quit IRC13:19
*** xaeth_afk is now known as xaeth13:25
*** SheenaG1 has joined #openstack-barbican13:26
*** SheenaG has quit IRC13:26
*** alee has joined #openstack-barbican13:36
*** elmiko has joined #openstack-barbican13:37
*** xek has joined #openstack-barbican13:47
*** kfarr has joined #openstack-barbican14:00
*** pglass has joined #openstack-barbican14:04
*** Kevin_Bishop has joined #openstack-barbican14:25
openstackgerritAde Lee proposed openstack/barbican-specs: Added spec for copy constructor for secrets and containers  https://review.openstack.org/12782314:28
*** zz_dimtruck is now known as dimtruck14:33
*** stanzi has joined #openstack-barbican14:34
aleewoodster_, ping14:36
woodster_Hey Ade14:36
aleewoodster_, hey modified spec as above ^^14:37
aleewoodster_, about to make mods to https://review.openstack.org/#/c/187236/1/specs/liberty/add-cas.rst,cm ..14:37
aleebefore I submit though, should I change the ca_id parameter to ca_ref ?14:37
aleewoodster_, this would be to refer to the parent ca -- for consistency ..14:38
woodster_alee: agreed14:41
aleewoodster_, ok - will do.14:42
*** diazjf has joined #openstack-barbican14:48
*** stanzi has quit IRC14:59
*** stanzi has joined #openstack-barbican15:00
openstackgerritAde Lee proposed openstack/barbican-specs: Added spec for add-cas  https://review.openstack.org/18723615:04
aleewoodster_, ^^15:06
aleejvrbanac, ping15:06
*** stanzi has quit IRC15:13
*** dimtruck is now known as zz_dimtruck15:16
*** arunkant_ has quit IRC15:21
*** xaeth is now known as xaeth_afk15:23
jvrbanacalee, yo15:23
aleejvrbanac, just trying to understand what I need to change in the cert-api doc spec15:24
aleejvrbanac, there aren't that many javascript blocks in the docs15:24
aleeif I understand your comment correctly - I need it for places where I provide a large server response.15:25
aleealso I dont know what full pretty print means15:25
*** kebray has joined #openstack-barbican15:26
jvrbanacalee, the json is only partially pretty-printed15:26
jvrbanacalee, my comments are pretty much around making sure the style aligns with the existing quickstart guides15:27
aleejvrbanac, can you give me an exmaple of what a fully pretty printed json would look like?15:27
jvrbanachttp://docs.openstack.org/developer/barbican/api/quickstart/containers.html15:28
aleejvrbanac, ok - by the way -- all those have code-style::bash15:29
aleeas do all the rest of the quick start guides15:29
jvrbanacalee, really? We really need to change those.15:29
*** kfox1111 has joined #openstack-barbican15:30
aleeI'm ok with using javascript if thats what we want to change to15:30
aleebut if we're being consistent, it should be bash15:30
jvrbanacWe really shouldn't be using bash highlighting in json blocks15:31
aleejvrbanac, thats fine - I'll use javascript15:31
*** gyee has joined #openstack-barbican15:32
jvrbanac alee it looks like we're doing it properly on the reference docs, just not the quickstarts15:33
aleejvrbanac, some of them at least ..15:33
jvrbanacalee, lol yeah15:34
*** xaeth_afk is now known as xaeth15:36
openstackgerritAde Lee proposed openstack/barbican: Added Certificate API Docs and Quick Start Guides  https://review.openstack.org/18677115:41
aleejvrbanac, woodster_ done ^^15:41
aleechellygel, ^^15:41
jvrbanacalee, I'll take a look after I get out of this meeting15:41
aleethanks15:41
*** stanzi has joined #openstack-barbican15:43
*** arunkant_ has joined #openstack-barbican15:45
*** stanzi has quit IRC15:48
*** zz_dimtruck is now known as dimtruck15:52
*** dimtruck is now known as zz_dimtruck15:53
*** zz_dimtruck is now known as dimtruck15:55
*** stanzi has joined #openstack-barbican15:55
*** nickrmc83 has quit IRC15:59
*** xaeth is now known as xaeth_afk16:21
*** openstackgerrit has quit IRC16:22
*** openstackgerrit has joined #openstack-barbican16:23
*** xaeth_afk is now known as xaeth16:29
openstackgerritKevin Bishop proposed openstack/barbican: Replace oslo incubator code with oslo_service  https://review.openstack.org/19289516:34
*** ryanpetrello has quit IRC16:37
*** stanzi has quit IRC16:41
openstackgerritDave Walker proposed openstack/barbican: Drop file extensions for /usr/bin/*  https://review.openstack.org/19320816:42
*** crc32 has joined #openstack-barbican16:56
*** diazjf has quit IRC17:05
*** alee is now known as alee_food17:45
*** openstackgerrit has quit IRC17:50
*** openstackgerrit has joined #openstack-barbican17:51
*** kfarr1 has joined #openstack-barbican17:53
*** kfarr has quit IRC17:56
*** kfarr1 has quit IRC17:59
*** stanzi has joined #openstack-barbican18:01
*** kfarr has joined #openstack-barbican18:14
*** stanzi has quit IRC18:19
*** SheenaG1 has quit IRC18:22
*** stanzi has joined #openstack-barbican18:23
*** elmiko has quit IRC18:27
*** stanzi has quit IRC18:28
*** elmiko has joined #openstack-barbican18:29
jvrbanacalee_food, looks good! thx!18:35
*** silos has joined #openstack-barbican18:39
*** xaeth is now known as xaeth_afk18:46
*** kfox1111 has quit IRC18:47
*** alee_food is now known as alee18:49
*** stanzi has joined #openstack-barbican18:50
aleejvrbanac, thanks18:50
aleewoodster_, chellygel https://review.openstack.org/#/c/186771/ needs some love please18:50
aleekfarr, jvrbanac , redrobot , chellygel https://review.openstack.org/#/c/127823/ also needs some love :)18:51
*** xaeth_afk is now known as xaeth18:53
*** dimtruck is now known as zz_dimtruck18:56
*** zz_dimtruck is now known as dimtruck18:57
*** pglass has quit IRC18:57
*** silos1 has joined #openstack-barbican18:59
*** SheenaG has joined #openstack-barbican19:01
*** silos has quit IRC19:02
*** stanzi has quit IRC19:02
*** diazjf has joined #openstack-barbican19:02
*** stanzi has joined #openstack-barbican19:02
*** kfarr1 has joined #openstack-barbican19:03
*** kfarr has quit IRC19:06
*** stanzi has quit IRC19:07
openstackgerritArun Kant proposed openstack/barbican: Added unit test around bug related to who can modify ACL.  https://review.openstack.org/17954719:14
*** kfarr has joined #openstack-barbican19:14
*** kfarr1 has quit IRC19:16
arunkant_alee: there?19:19
aleearunkant, hi, whats up?19:20
*** ryanpetrello has joined #openstack-barbican19:20
arunkant_For add-copy-constructor spec, in case of containers..is consumers data going to be cloned as well ?19:20
arunkant_alee, was not sure from reading the spec and that's why trying to clarify it19:21
aleearunkant, thats a good question -- I had not even thought about consumers19:22
aleearunkant, my immediate thought would be no - but I dont have a strong opinion either way19:23
arunkant_alee, either copy it..or may be have add new container_id to existing container-consumers relationship19:23
*** kfarr has quit IRC19:24
aleearunkant, sure - I guess we can copy it19:25
arunkant_alee, Okay.. No is because this new container is not being referred by anybody . Is that the reason ?19:25
aleearunkant, I really have no opinion either way -- I could see arguments either way19:25
aleearunkant, but yes - because its a brand new container that is not being referred to by antbody19:26
aleearunkant, on the other hand, I could see an argument to make it an exact clone19:26
aleewoodster_, redrobot , rm_work any thoughts?19:27
redrobot+1 "No is because this new container is not being referred by anybody"19:28
*** SheenaG has quit IRC19:28
*** SheenaG has joined #openstack-barbican19:29
redrobotconsumers is metadata that could be used by reach, for example, to warn a user about other resources that are using the secret.19:29
woodster_arunkant_: redrobot +1, I'd say no to copying consumers as well...this is a different instance and UUID19:29
redrobots/reach/horizon19:29
*** stanzi has joined #openstack-barbican19:33
aleearunkant, seems like a consensus.19:34
arunkant_alee, yes. Are you planning to clarify this in spec?19:36
*** kfarr has joined #openstack-barbican19:39
aleearunkant, aargh .. I was hoping to not have to submit yet another version .. yeah - I guess I need to19:39
aleearunkant, submitting change in a couple of mins ..19:40
*** stanzi has quit IRC19:42
openstackgerritAde Lee proposed openstack/barbican-specs: Added spec for copy constructor for secrets and containers  https://review.openstack.org/12782319:44
aleearunkant, woodster_ , redrobot , kfarr  , jvrbanac ^^19:44
alee+2s please19:45
rm_workalee / redrobot / arunkant_: correct, do not copy consumers19:57
rm_workreading now19:57
*** silos1 has quit IRC19:58
rm_work+1 with comment20:00
*** diazjf has quit IRC20:02
*** pglass has joined #openstack-barbican20:04
openstackgerritKevin Bishop proposed openstack/barbican: Refactor Barbican model registration  https://review.openstack.org/19329020:10
*** chadlung has joined #openstack-barbican20:19
openstackgerritMerged openstack/barbican: Added Certificate API Docs and Quick Start Guides  https://review.openstack.org/18677120:22
*** pglass has quit IRC20:38
openstackgerritKevin Bishop proposed openstack/barbican: Refactor Barbican model registration  https://review.openstack.org/19329020:46
*** elmiko is now known as _elmiko20:46
*** chadlung has quit IRC20:56
*** pglass has joined #openstack-barbican20:57
*** kfarr has left #openstack-barbican21:00
*** jamielennox is now known as jamielennox|away21:01
*** kfox1111 has joined #openstack-barbican21:04
kfox111123'rds cutoff day for the instance users spec. Please +1 or raise issues now.21:04
redrobotkfox1111 heya!21:05
redrobotkfox1111 I've been catching up on the keystone side of things21:05
* morganfainberg throws glitter in the air in the channel.21:06
morganfainbergquick make changes on the keystone side while folks are cleaning up the glitter >.>21:07
morganfainbergredrobot: :P21:07
redrobotlol21:07
*** chadlung has joined #openstack-barbican21:08
*** jamielennox|away is now known as jamielennox21:09
redrobotSo, if I'm understanding this right, Keystone would have a trusted root cert in the config file?21:09
redrobotand then trust any certs signed by the trusted root?21:09
morganfainbergredrobot: that is the idea. i think we want to expand this a little more though - and let the full federated mapping system work with more than a single CA (long term)21:11
kfox1111redrobot: correct.21:12
kfox1111I think we should firm up the spec just far enough to get itin by the 23rd deadline,21:12
*** chadlung has quit IRC21:12
kfox1111and I'd be happy to further discuss the little details.21:12
kfox1111once we can still target it for this cycle.21:12
redrobotsince Nova will be storing both the cert and the private key, then the CA could be either Barbican or Anchor?21:13
kfox1111I guess it could be Anchor... if it does user certs.21:13
redrobotor do the certs need to be long-lived?21:13
kfox1111long lived.21:14
redrobothmmm.... I don't think we've talked about CRLs in barbican yet21:15
*** diazjf has joined #openstack-barbican21:15
*** kebray has quit IRC21:15
redrobotbarbican is not in itself a CA.21:15
kfox1111Does it matter for the spec? We can always add that functionality later otherwise.21:16
kfox1111so if the ca barbican uses supports CRL's, then we're still ok?21:17
redrobotkfox1111 yeah... barbican could send the revokation request to the ca21:18
kfox1111k21:18
redrobotas long as the cert has the right CRL it should be fine21:18
kfox1111I've got a meeting in 5.21:19
redrobotkfox1111 np, I think I'm on board to +1 the spe21:19
redrobotspec21:20
kfox1111Awesome. Thanks. :)21:20
*** stanzi has joined #openstack-barbican21:21
kfox1111please do let me know if you need anything else or have any questions asap. The spec's dead for 6 months on the 23rd if we can't get enough concensus. :/21:21
kfox1111bbiab21:22
*** kfox1111 is now known as kfox1111_afk21:22
*** _elmiko is now known as elmiko21:23
rm_workkfox1111_afk: that is starting to sound less like what you were describing to me at the summit, and more like what I was describing to you at the summit -- which concerns me, because you had pretty thoroughly convinced me that the cert way wouldn't be as clean, i thought O_o21:29
rm_workand that sounds very much like the system we're working with for our service-vms in Octavia21:29
rm_workimmediately after the summit i had to step away from Openstack again briefly to fight internal fires (one of these days I might actually be free) but I would like to see what you're doing -- i will try to review that today/tonight if possible21:31
*** silos has joined #openstack-barbican21:38
*** silos has left #openstack-barbican21:38
*** stanzi has quit IRC21:45
*** stanzi has joined #openstack-barbican21:46
*** stanzi has quit IRC21:50
*** Kevin_Bishop has quit IRC21:55
*** stanzi has joined #openstack-barbican21:57
*** kebray has joined #openstack-barbican22:00
*** kebray has quit IRC22:01
*** kebray has joined #openstack-barbican22:02
*** diazjf has quit IRC22:03
*** kebray has quit IRC22:08
*** kebray has joined #openstack-barbican22:10
*** xaeth is now known as xaeth_afk22:15
*** chadlung has joined #openstack-barbican22:20
*** pglass has quit IRC22:21
*** SheenaG has quit IRC22:22
*** chadlung has quit IRC22:24
woodster_alee, are you there?22:25
*** SheenaG has joined #openstack-barbican22:25
aleewoodster_, just briefly22:25
woodster_alee, I had added some comments to the renew/reissue bp CR in response to your comments22:26
woodster_alee: I think the long and the short is that you are dealing with delta changes...so changes you submit on the reissue/renew request, and changes since the original certificate request. I think validating those changes makes those cases different enough to warrant a new order type.  I think that is true for having separate methods to handle these cases on22:27
woodster_the cert plugin22:27
*** diazjf has joined #openstack-barbican22:27
aleewoodster_, thinking ..22:29
*** dimtruck is now known as zz_dimtruck22:29
aleewoodster_, what does symantec allow in terms of renewals?22:30
aleewoodster_, does it actually allow you to change stuff?22:30
woodster_alee, you can change limited things yes22:30
aleewoodster_, because dogtag doesn't for example22:30
aleewoodster_, like what for example?22:31
woodster_alee: yeah I'd have to look at my notes22:32
aleewoodster_, lets suppose that each ca plugin allows you to change various things and not others -- I'm ok with having different methods in the plugins and passing in the old and new requests.22:34
aleeor request params22:34
woodster_alee: that's what I was thinking...just pass the prev and new metadata and let the plugin decide what it supports22:35
aleebut I think that there is a bunch of code that would be duplicated by having different order types22:35
*** elmiko is now known as _elmiko22:35
woodster_alee: dup code on the plugin side or barbican core side?22:35
aleewoodster_, well likely both22:36
aleebut I was thinking on the barbican core side22:36
aleewoodster_, if you really want to treat the renewal and the reissue in the same way as initial issuances, then you neeed to go through the same kinds of validations22:37
aleeand that means writing code like ..22:37
aleeif order_type = cert or cert-reissue or cert-renew .. do X22:38
aleeif you want to treat them essentially the same, then there is no reason to have separate types22:38
aleejust have a metadata filed that indicates what what kind of subtype of issuance it is.22:39
aleewoodster_, but I really think renewal is different from issuance22:40
woodster_alee: that could work, and if it not specified then it is straight issue call22:40
aleeand reissuance is basically the same as issuance22:40
alee(delta considerations notwithstanding)22:40
aleewoodster_, thats why I'm curious what symantec accepts for changes for renewal22:41
woodster_alee: they are different from the plugin business process perspective, but less so from the core side I think22:41
aleeand what it requires for authentication22:41
aleewoodster_, depends on the requirements for approval/authentication22:41
aleewoodster_, for instance, in dogtag its possible to try to do a self-renewal22:42
aleewhere you provide proof of ownership of the cert and maybe one other auth to do a renewal22:42
woodster_alee: per notes with chellygel, Symantec allows sub-domains on SAN certs22:43
aleebutyou dont need any other request params22:43
aleeallows subdomains to change on renewals?22:43
woodster_alee, yep22:43
aleewoodster_, I need to think on this a bit more , but I've run out of time for today.  lets chat next week.  I'll be offline but you can call me.22:45
woodster_alee, will do. Have a good vacation!22:46
*** darrenmoffat has quit IRC22:46
aleethanks22:46
*** darrenmoffat has joined #openstack-barbican22:47
*** nkinder has quit IRC22:49
*** dave-mccowan has quit IRC22:50
*** openstackgerrit has quit IRC22:55
*** ngupta has quit IRC22:55
*** jkf has quit IRC22:55
*** nkinder has joined #openstack-barbican22:57
*** stanzi has quit IRC23:00
*** stanzi has joined #openstack-barbican23:00
*** stanzi has quit IRC23:04
*** dave-mcc_ has joined #openstack-barbican23:06
*** openstackgerrit has joined #openstack-barbican23:06
*** ngupta has joined #openstack-barbican23:06
*** jkf has joined #openstack-barbican23:06
*** diazjf has quit IRC23:07
*** SheenaG has quit IRC23:12
*** SheenaG has joined #openstack-barbican23:15
*** arunkant_ has quit IRC23:16
*** chadlung has joined #openstack-barbican23:24
*** chadlung has quit IRC23:26
*** chadlung has joined #openstack-barbican23:26
kfox1111_afkrm_work: I was worried at the summit that every project was going to be forced to be its own CA to hand out certs to the vm's to then be able to use the same cert to contact back that one service.23:27
kfox1111_afkHaving keystone in the process means that nova->keystone make the arangements, and its all Instance -> openstack service using keystones just like any other user.23:28
kfox1111_afkAnd I'd still somewhat like the user/password idea from the summit but the Keystone guys -2'ed it. So its something of a compromise.23:29
kfox1111_afkIt benefits them in that they really want to get out of being an identity provider. This lets Nova be an identity provider for the VM's its managing.23:29
*** kfox1111_afk is now known as kfox111123:30
*** SheenaG has quit IRC23:37
*** chlong has joined #openstack-barbican23:48
*** alee has quit IRC23:50

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!