openstackgerrit | Steve Heyman proposed openstack/barbican: Update queries to use proper offset and limit https://review.openstack.org/193698 | 00:11 |
---|---|---|
*** darrenmoffat has quit IRC | 00:31 | |
*** darrenmoffat has joined #openstack-barbican | 00:31 | |
openstackgerrit | Steve Heyman proposed openstack/barbican: Update queries to use proper offset and limit https://review.openstack.org/193698 | 00:37 |
*** woodster_ has quit IRC | 00:51 | |
*** david-ly_ has joined #openstack-barbican | 01:06 | |
*** david-lyle has quit IRC | 01:09 | |
*** zz_dimtruck is now known as dimtruck | 01:30 | |
*** crc32 has quit IRC | 02:04 | |
*** SheenaG has joined #openstack-barbican | 02:13 | |
*** d0ugal has quit IRC | 02:29 | |
*** d0ugal has joined #openstack-barbican | 02:29 | |
*** d0ugal is now known as Guest5335 | 02:30 | |
*** SheenaG has quit IRC | 02:36 | |
*** nkinder has quit IRC | 02:37 | |
openstackgerrit | Dave McCowan proposed openstack/barbican: Refactor Stored Key Certificate Order Validator Code https://review.openstack.org/171023 | 02:55 |
*** gyee has quit IRC | 02:58 | |
*** woodster_ has joined #openstack-barbican | 03:16 | |
*** claudiub|2 has quit IRC | 03:22 | |
*** dimtruck is now known as zz_dimtruck | 03:41 | |
*** david-ly_ is now known as david-lyle | 03:51 | |
*** arunkant_ has joined #openstack-barbican | 04:54 | |
*** arunkant__ has quit IRC | 04:58 | |
*** arunkant has joined #openstack-barbican | 04:58 | |
*** arunkant_ has quit IRC | 05:01 | |
*** rm_work|away is now known as rm_work | 05:01 | |
*** dave-mccowan has quit IRC | 05:05 | |
*** woodster_ has quit IRC | 05:21 | |
*** rm_work is now known as rm_work|away | 06:27 | |
*** shohel has joined #openstack-barbican | 06:29 | |
*** arunkant_ has joined #openstack-barbican | 06:33 | |
*** shohel has quit IRC | 06:33 | |
*** Guest5335 is now known as d0ugal | 06:34 | |
*** d0ugal has quit IRC | 06:34 | |
*** d0ugal has joined #openstack-barbican | 06:34 | |
*** arunkant has quit IRC | 06:37 | |
*** arunkant__ has joined #openstack-barbican | 06:38 | |
*** arunkant_ has quit IRC | 06:41 | |
*** shohel has joined #openstack-barbican | 06:47 | |
*** arunkant_ has joined #openstack-barbican | 06:48 | |
*** arunkant__ has quit IRC | 06:51 | |
*** rm_work|away is now known as rm_work | 07:51 | |
*** chlong has quit IRC | 07:55 | |
*** rm_work is now known as rm_work|away | 08:07 | |
*** rm_work|away is now known as rm_work | 08:12 | |
*** stanzi has joined #openstack-barbican | 08:25 | |
*** stanzi has quit IRC | 08:49 | |
*** stanzi has joined #openstack-barbican | 08:50 | |
*** stanzi has quit IRC | 08:55 | |
*** stanzi has joined #openstack-barbican | 10:00 | |
*** shohel has quit IRC | 10:01 | |
*** arunkant__ has joined #openstack-barbican | 10:03 | |
*** stanzi has quit IRC | 10:05 | |
*** shohel has joined #openstack-barbican | 10:05 | |
*** arunkant_ has quit IRC | 10:07 | |
*** mmdurrant has quit IRC | 10:09 | |
*** tkelsey has joined #openstack-barbican | 10:20 | |
*** shohel has quit IRC | 10:38 | |
*** tkelsey has quit IRC | 11:01 | |
*** SheenaG has joined #openstack-barbican | 11:27 | |
*** shohel has joined #openstack-barbican | 11:34 | |
*** mmdurrant has joined #openstack-barbican | 11:59 | |
*** dave-mccowan has joined #openstack-barbican | 12:35 | |
*** SheenaG has quit IRC | 13:27 | |
*** arunkant_ has joined #openstack-barbican | 13:38 | |
*** kfarr has joined #openstack-barbican | 13:39 | |
*** arunkant__ has quit IRC | 13:41 | |
*** woodster_ has joined #openstack-barbican | 13:44 | |
*** SheenaG has joined #openstack-barbican | 13:59 | |
*** zz_dimtruck is now known as dimtruck | 14:01 | |
*** pglass has joined #openstack-barbican | 14:04 | |
*** kebray has joined #openstack-barbican | 14:49 | |
*** kebray has quit IRC | 14:50 | |
*** kfarr has quit IRC | 14:52 | |
*** kfarr has joined #openstack-barbican | 14:57 | |
*** kebray has joined #openstack-barbican | 14:58 | |
*** shohel has quit IRC | 14:59 | |
*** silos has joined #openstack-barbican | 15:27 | |
*** silos has quit IRC | 16:03 | |
*** silos has joined #openstack-barbican | 16:05 | |
*** gyee has joined #openstack-barbican | 16:31 | |
*** SheenaG has quit IRC | 16:31 | |
*** silos has left #openstack-barbican | 16:32 | |
*** shohel has joined #openstack-barbican | 16:35 | |
openstackgerrit | Chelsea Winfree proposed openstack/barbican: Update unwrap key to accept specific variables https://review.openstack.org/196141 | 16:46 |
openstackgerrit | Chelsea Winfree proposed openstack/barbican: Update unwrap key to accept specific variables https://review.openstack.org/196141 | 16:49 |
*** SheenaG has joined #openstack-barbican | 16:58 | |
*** atiwari has joined #openstack-barbican | 17:02 | |
*** atiwari has quit IRC | 17:03 | |
*** atiwari has joined #openstack-barbican | 17:03 | |
*** kebray has quit IRC | 17:16 | |
dave-mccowan | Happy Friday everyone! I have a couple CRs open, if anyone has time to review this afternoon. https://review.openstack.org/171023 and https://review.openstack.org/181291 | 18:00 |
*** arunkant__ has joined #openstack-barbican | 18:07 | |
*** arunkant_ has quit IRC | 18:08 | |
*** arunkant__ has quit IRC | 18:13 | |
*** diazjf has joined #openstack-barbican | 18:13 | |
*** jhfeng has joined #openstack-barbican | 18:16 | |
kfox1111 | can you create a cert outside of barbican and have barbican sign it with its ca? | 18:19 |
redrobot | kfox1111 no, current api accepts a CSR, and we defer to the CA to create the cert. | 18:21 |
kfox1111 | thats what I ment I think? | 18:22 |
kfox1111 | in the instance user workflow, could the vm itself create the private key, | 18:22 |
kfox1111 | then we submit the csr to barbican somehow to create the cert? | 18:23 |
kfox1111 | redrobot: The nova folks finally started lookin at the spec. and are trying to figure out how nova could not be part of the picture. :/ | 18:23 |
redrobot | kfox1111 yeah, that's a possible workflow. you create the key, sign a CSR and send it to barbican. The resulting cert will have information taken from the CSR | 18:23 |
kfox1111 | ok. | 18:24 |
kfox1111 | now, here's one more crazy one... | 18:24 |
kfox1111 | they want another service somewhere that allows creating one time urls where a csr could be uploaded and signed. :/ | 18:24 |
kfox1111 | would that be reasonable to be part of barbican, or do we need yet another service? | 18:25 |
redrobot | not sure I understand.... | 18:26 |
kfox1111 | ie, heat -> barbican (i need a tmp url for a cert), heat -> nova launch vm with tmp url, vm creates private key, hands csr to tmp url, gets back cert. | 18:26 |
redrobot | why one-time urls? | 18:26 |
kfox1111 | vm -> keystone I want a token, here's my cert. | 18:26 |
kfox1111 | because they don't want to change the metadata server/config drive and passing a cert through userdata is bad. :/ | 18:26 |
kfox1111 | just exploring alternate workflows on their insistance. | 18:27 |
kfox1111 | the advantage of a tmp url is that it be made to work only once. | 18:27 |
kfox1111 | so if its done through a semi insecure chanel, its ok. | 18:27 |
redrobot | hmm... I need to think about it more... I'll catch up on the nova spec. | 18:29 |
kfox1111 | and the recent nova logs. we just had a very long conversation a few minutes ago about it. :/ | 18:30 |
kfox1111 | we got all the way up to the point where we have the chicken and egg problem, and then john had to go. :/ | 18:30 |
kfox1111 | but there is a lot of pushback on the spec now about why not another service instead of changing nova. | 18:32 |
kfox1111 | this stuff's killing me. :/ | 18:32 |
*** jhfeng has quit IRC | 18:32 | |
*** kebray has joined #openstack-barbican | 18:34 | |
*** shohel has quit IRC | 18:46 | |
*** shohel has joined #openstack-barbican | 18:47 | |
*** shohel has quit IRC | 18:48 | |
*** arunkant has joined #openstack-barbican | 18:52 | |
*** kfarr has left #openstack-barbican | 19:02 | |
*** woodster_ has quit IRC | 19:21 | |
*** atiwari has quit IRC | 19:37 | |
rm_work | kfox1111: i believe this is a case of "welcome to OpenStack" :P | 19:44 |
*** kebray has quit IRC | 19:55 | |
elmiko | hey barbicaneers, could someone help me understand the bin/barbican-keystone-listener.py, is that file still used? | 20:01 |
*** kebray has joined #openstack-barbican | 20:04 | |
openstackgerrit | Arun Kant proposed openstack/barbican: Fix for admin and creator user access for secret/container read calls https://review.openstack.org/196227 | 20:09 |
arunkant | elmiko, yes...that is used for listening keystone project delete events | 20:09 |
elmiko | arunkant: ah, ok. | 20:10 |
arunkant | when the listener configuration is enabled in barbican configuration and assuming keystone is generating events | 20:10 |
elmiko | this is for when barbican is using keystone to do token validation? | 20:11 |
*** jhfeng has joined #openstack-barbican | 20:11 | |
elmiko | arunkant: ok, i think i understand ;) | 20:13 |
elmiko | thanks | 20:13 |
arunkant | Its not related to keystone token validation anyway. If barbican is not using keystone, not sure if there is any benefit of listening for project delete happening on keystone side | 20:14 |
elmiko | yea | 20:14 |
elmiko | i'm just doing some cleanup on the fedora packaging attempt, and trying to understand some of these extra files | 20:15 |
elmiko | like barbican-worker.py as well | 20:15 |
arunkant | that's worker thread/processes for async order processing | 20:15 |
elmiko | ok, cool. i figured it was something like that =) | 20:16 |
*** xaeth_afk is now known as xaeth | 20:18 | |
elmiko | hey xaeth, i'm just running through some tests on a patch that i hope to send your way soon =) | 20:22 |
xaeth | elmiko, awesome | 20:22 |
elmiko | i also talked with the rdo folks, and they are ok with requiring uwsgi for the first version of this | 20:23 |
xaeth | fair enough, should be fairly easy | 20:23 |
elmiko | yea, i hope so | 20:24 |
elmiko | jkf was nice enough to share a systemd file that incorporates the uwsgi stuff | 20:24 |
xaeth | sweet | 20:25 |
xaeth | elmiko, do you know where my spec file is kewl? | 20:27 |
xaeth | err is kept | 20:27 |
xaeth | or are you just extracing from the srpm | 20:27 |
elmiko | xaeth: i got it here https://github.com/gregswift/barbican-spec/blob/master/openstack-barbican.spec | 20:28 |
elmiko | is that accurate? | 20:28 |
xaeth | yep, kew | 20:28 |
elmiko | awesome | 20:28 |
elmiko | i just need to brush up on my systemd a bit ;) | 20:30 |
arunkant | dave-mccowan: Added change for ACL bug fix ..https://review.openstack.org/196227 . Have a look when you get the chance | 20:32 |
*** jhfeng has quit IRC | 20:41 | |
dave-mccowan | arunkant thanks. how strongly do you fell about changing creator_only to project_access_disabled ? i think "creator_only" is more clear, since it explains what "project access disabled" does. | 20:53 |
dave-mccowan | arunkant, ironically, when the flag was "creator-only", i named the test cases "private". when the flag changed to "project-access", i changed the test cases to "creator_only". :-) | 21:00 |
*** woodster_ has joined #openstack-barbican | 21:02 | |
*** SheenaG has quit IRC | 21:11 | |
*** kebray has quit IRC | 21:18 | |
*** openstack has joined #openstack-barbican | 21:24 | |
*** SheenaG has joined #openstack-barbican | 21:30 | |
chellygel | can i get a +1 workflow? https://review.openstack.org/#/c/193698/ | 21:32 |
*** xaeth is now known as xaeth_afk | 21:43 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/194830 | 21:46 |
*** dave-mcc_ has joined #openstack-barbican | 22:10 | |
*** dave-mccowan has quit IRC | 22:12 | |
*** kebray has joined #openstack-barbican | 22:21 | |
*** kebray has quit IRC | 22:22 | |
*** pglass has quit IRC | 22:24 | |
*** diazjf has left #openstack-barbican | 22:31 | |
openstackgerrit | John Vrbanac proposed openstack/barbican: Adding script for rewrapping p11 KEKs https://review.openstack.org/196270 | 22:43 |
*** kebray has joined #openstack-barbican | 22:45 | |
*** kebray has quit IRC | 22:49 | |
*** kebray has joined #openstack-barbican | 22:50 | |
*** gyee has quit IRC | 23:21 | |
*** dimtruck is now known as zz_dimtruck | 23:21 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!