*** zz_dimtruck is now known as dimtruck | 00:16 | |
*** kebray has quit IRC | 00:32 | |
*** mixos has joined #openstack-barbican | 00:44 | |
*** dimtruck is now known as zz_dimtruck | 00:54 | |
*** zz_dimtruck is now known as dimtruck | 00:55 | |
*** gyee has quit IRC | 00:57 | |
*** su_zhang_ has quit IRC | 00:59 | |
*** jhfeng has joined #openstack-barbican | 01:08 | |
*** mixos has quit IRC | 01:17 | |
*** vivek-ebay has quit IRC | 01:18 | |
*** vivek-ebay has joined #openstack-barbican | 01:18 | |
*** dimtruck is now known as zz_dimtruck | 01:21 | |
*** mixos has joined #openstack-barbican | 01:46 | |
*** stevemar_ has quit IRC | 01:59 | |
*** stevemar_ has joined #openstack-barbican | 02:00 | |
*** kebray has joined #openstack-barbican | 02:18 | |
*** jhfeng has quit IRC | 02:24 | |
*** stevemar_ has quit IRC | 02:41 | |
*** stevemar_ has joined #openstack-barbican | 02:42 | |
*** stevemar_ has quit IRC | 02:43 | |
*** stevemar_ has joined #openstack-barbican | 02:43 | |
*** dave-mccowan has quit IRC | 02:44 | |
*** jamielennox has quit IRC | 02:51 | |
*** kebray has quit IRC | 03:02 | |
*** jhfeng has joined #openstack-barbican | 03:07 | |
*** vivek-ebay has quit IRC | 03:11 | |
*** jamielennox has joined #openstack-barbican | 03:13 | |
*** kebray has joined #openstack-barbican | 03:18 | |
*** kebray has quit IRC | 03:18 | |
*** kebray has joined #openstack-barbican | 03:18 | |
*** stevemar_ has quit IRC | 03:21 | |
*** stevemar_ has joined #openstack-barbican | 03:22 | |
*** su_zhang_ has joined #openstack-barbican | 03:27 | |
*** su_zhang_ has quit IRC | 03:27 | |
*** su_zhang_ has joined #openstack-barbican | 03:28 | |
*** jhfeng has quit IRC | 03:43 | |
*** vivek-ebay has joined #openstack-barbican | 04:11 | |
*** jaosorior has joined #openstack-barbican | 04:39 | |
*** su_zhang_ has quit IRC | 04:40 | |
*** xaeth_afk is now known as xaeth | 04:51 | |
jaosorior | redrobot: Still awake? | 04:55 |
---|---|---|
*** morgan has quit IRC | 05:02 | |
*** redrobot has quit IRC | 05:03 | |
*** atiwari1 has joined #openstack-barbican | 05:03 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Add RBAC docs for Cloud Administrator Guide https://review.openstack.org/231222 | 05:03 |
*** atiwari has quit IRC | 05:03 | |
*** vivek-ebay has quit IRC | 05:06 | |
*** morgan has joined #openstack-barbican | 05:06 | |
*** redrobot has joined #openstack-barbican | 05:08 | |
*** redrobot is now known as Guest28678 | 05:09 | |
stevemar_ | jaosorior: o/ | 05:39 |
stevemar_ | jaosorior: when are you all going to release barbicanclient :) | 05:39 |
stevemar_ | https://github.com/openstack/python-barbicanclient/releases august 24th is old and no bueno | 05:39 |
*** xaeth is now known as xaeth_afk | 05:47 | |
jaosorior | stevemar_ Good question dude, gotta ping redrobot for that | 05:48 |
jaosorior | stevemar_ Only thing I'm thinking about is the naming we used for commands; since at the moment they're all the same; both for our CLI and for the OSC plugin | 05:49 |
jaosorior | we recently added ACL support, and that might get confusing in the OSC | 05:49 |
*** edtubill has joined #openstack-barbican | 05:51 | |
stevemar_ | jaosorior: /me shrugs | 05:52 |
stevemar_ | nothing else went in? | 05:52 |
jaosorior | stevemar_ Well, the osc plugin, ACL support, a bunch of CA-related operations and bug-fixes | 05:53 |
jaosorior | but the CA stuff is quite self-explanatory and shouldn't be an issue | 05:53 |
* stevemar_ shrugs | 05:57 | |
stevemar_ | just thought i'd give you guys a heads up ^_^ | 05:57 |
jaosorior | stevemar_ I'll ping redrobot about it when he's awake. It's around 1am over there | 05:58 |
jaosorior | stevemar_ But thanks. How's stuff otherwise? | 05:58 |
stevemar_ | jaosorior: crazy as always :) | 05:58 |
stevemar_ | jaosorior: how you liking RH? | 05:58 |
jaosorior | really good so far :) | 05:59 |
jaosorior | Gonna get my red hat this month | 05:59 |
stevemar_ | jaosorior: wear it with pride! | 06:04 |
jaosorior | stevemar_ haha sure will :d | 06:11 |
jaosorior | * :D | 06:11 |
*** Nirupama has joined #openstack-barbican | 06:12 | |
*** stevemar_ has quit IRC | 06:38 | |
*** jamielennox is now known as jamielennox|away | 06:41 | |
*** x3k has quit IRC | 06:42 | |
*** woodster_ has quit IRC | 06:49 | |
*** kebray has quit IRC | 07:19 | |
*** edtubill has quit IRC | 07:37 | |
*** xek_ is now known as xek | 07:53 | |
*** mixos has quit IRC | 07:59 | |
*** jaosorior has quit IRC | 08:48 | |
*** jaosorior has joined #openstack-barbican | 08:49 | |
*** darrenmoffat has quit IRC | 09:19 | |
*** darrenmoffat has joined #openstack-barbican | 09:20 | |
*** pksingh has joined #openstack-barbican | 09:21 | |
pksingh | jaosorior, Hi Good Morning :) | 09:23 |
jaosorior | pksingh: Hey, what's up? | 10:07 |
*** mmdurrant has quit IRC | 10:09 | |
*** jamielennox|away is now known as jamielennox | 10:14 | |
*** dave-mccowan has joined #openstack-barbican | 10:24 | |
pksingh | jaosorior, how's the day? | 10:39 |
jaosorior | pksingh: Pretty good, just got back from lunch and now back to coding. How about yours? | 10:40 |
pksingh | jaosorior, just about to leave from office in 50 minutes | 10:41 |
pksingh | todays work ended | 10:42 |
jaosorior | not bad! | 10:42 |
jaosorior | I still have some hours ahead | 10:42 |
jaosorior | But no worries, there's enough coffee :P | 10:43 |
pksingh | great :) | 10:44 |
*** pksingh has quit IRC | 11:30 | |
*** mmdurrant has joined #openstack-barbican | 11:59 | |
*** alee_dinner has quit IRC | 12:24 | |
*** jhfeng has joined #openstack-barbican | 12:47 | |
*** jhfeng has quit IRC | 12:59 | |
*** shohel has joined #openstack-barbican | 13:02 | |
*** jhfeng has joined #openstack-barbican | 13:13 | |
*** jhfeng has quit IRC | 13:14 | |
*** dave-mccowan has quit IRC | 13:19 | |
*** alee has joined #openstack-barbican | 13:20 | |
*** jhfeng has joined #openstack-barbican | 13:24 | |
*** woodster_ has joined #openstack-barbican | 13:25 | |
*** jhfeng has quit IRC | 13:28 | |
*** Nirupama has quit IRC | 13:28 | |
*** Praston has joined #openstack-barbican | 13:34 | |
*** dave-mccowan has joined #openstack-barbican | 13:34 | |
Guest28678 | good mornin' barbican! :) | 14:12 |
*** Guest28678 is now known as redrobot | 14:13 | |
*** zz_dimtruck is now known as dimtruck | 14:19 | |
*** spotz_zzz is now known as spotz | 14:24 | |
*** stevemar_ has joined #openstack-barbican | 14:28 | |
*** silos has joined #openstack-barbican | 14:39 | |
*** jaosorior has quit IRC | 14:39 | |
*** jaosorior has joined #openstack-barbican | 14:39 | |
*** xaeth_afk is now known as xaeth | 14:41 | |
*** edtubill has joined #openstack-barbican | 14:45 | |
*** mixos has joined #openstack-barbican | 14:46 | |
*** david-ly_ is now known as david-lyle | 15:06 | |
*** diazjf has joined #openstack-barbican | 15:12 | |
*** diazjf has quit IRC | 15:22 | |
*** Daviey_ has quit IRC | 15:30 | |
*** Daviey has joined #openstack-barbican | 15:30 | |
*** kebray has joined #openstack-barbican | 15:32 | |
*** ccneill has joined #openstack-barbican | 15:32 | |
openstackgerrit | Arun Kant proposed openstack/python-barbicanclient: Part 3: Adding ACL functional tests. https://review.openstack.org/208344 | 15:42 |
arunkant | jaosorior, silos: Can you review ^^^ . Addressed a typo identified by jaosorior in earlier patch. | 15:44 |
*** vivek-ebay has joined #openstack-barbican | 15:49 | |
silos | arunkant: looking now | 15:59 |
jaosorior | arunkant: +2ed | 16:04 |
arunkant | thanks jaosorior, silos | 16:05 |
*** gyee has joined #openstack-barbican | 16:12 | |
*** vivek-ebay has quit IRC | 16:23 | |
*** dimtruck is now known as zz_dimtruck | 16:34 | |
*** jaosorior has quit IRC | 16:51 | |
*** jaosorior has joined #openstack-barbican | 16:52 | |
*** gyee has quit IRC | 17:05 | |
*** ccneill has quit IRC | 17:18 | |
*** david-ly_ has joined #openstack-barbican | 17:21 | |
*** david-lyle has quit IRC | 17:21 | |
*** david-ly_ is now known as david-lyle | 17:22 | |
*** kebray has quit IRC | 17:28 | |
alee | dave-mccowan, ping | 17:40 |
*** su_zhang has joined #openstack-barbican | 17:40 | |
*** shohel has quit IRC | 17:41 | |
dave-mccowan | alee pong | 17:41 |
alee | dave-mccowan, have you played at all with using barbican for volume encryption> | 17:42 |
alee | ? | 17:42 |
alee | redrobot, ^^? | 17:42 |
dave-mccowan | alee not yet, but that is nearing the top of my to-do list. i definitely want to give it a try. | 17:43 |
alee | I'm trying to do it and running into a weird issue - its probably my config , but .. | 17:43 |
alee | anyone else here worked with volume encryption? | 17:44 |
alee | rm_work, jvrbanac_ ? ^^ I know rellerreller and kfarr have, but they're not here | 17:44 |
*** zz_dimtruck is now known as dimtruck | 17:46 | |
dave-mccowan | alee did you find cinder docs somewhere describing how it works? | 17:46 |
alee | dave-mccowan, http://docs.openstack.org/juno/config-reference/content/section_testing_encryption.html | 17:47 |
alee | dave-mccowan, there is some config -- I'll let you know when I get it working :) | 17:48 |
*** kebray has joined #openstack-barbican | 17:51 | |
*** dave-mccowan has quit IRC | 17:54 | |
*** su_zhang_ has joined #openstack-barbican | 17:58 | |
*** su_zhang has quit IRC | 18:02 | |
*** vivek-ebay has joined #openstack-barbican | 18:03 | |
*** vivek-ebay has quit IRC | 18:03 | |
*** vivek-ebay has joined #openstack-barbican | 18:04 | |
*** ccneill has joined #openstack-barbican | 18:04 | |
*** kebray has quit IRC | 18:05 | |
*** dave-mccowan has joined #openstack-barbican | 18:07 | |
*** su_zhang_ has quit IRC | 18:09 | |
*** su_zhang has joined #openstack-barbican | 18:10 | |
*** diazjf has joined #openstack-barbican | 18:11 | |
*** gyee has joined #openstack-barbican | 18:16 | |
*** su_zhang has quit IRC | 18:38 | |
*** su_zhang has joined #openstack-barbican | 18:41 | |
*** diazjf has left #openstack-barbican | 18:42 | |
*** su_zhang has quit IRC | 18:52 | |
*** kebray has joined #openstack-barbican | 18:55 | |
*** silos1 has joined #openstack-barbican | 19:00 | |
*** jaosorior has quit IRC | 19:00 | |
*** jaosorior has joined #openstack-barbican | 19:01 | |
*** silos has quit IRC | 19:04 | |
*** kebray has quit IRC | 19:08 | |
alee | redrobot, ping | 19:12 |
redrobot | alee pong | 19:12 |
alee | redrobot, is there a way to log any requests going into barbican ? ie . headers and everythiung ? | 19:13 |
alee | redrobot, I'm getting a rather cryptic message .. | 19:15 |
alee | Oct 06 15:03:31 rdo.rdodom.test uwsgi[11273]: {address space usage: 446566400 bytes/425MB} {rss usage: 75468800 bytes/71MB} [pid: 11279|app: 0|req: 14/14] 192.168.128.3 () {30 vars in 497 bytes} [Tue Oct 6 15:03:31 2015] GET /secrets/5ad957ed-8cff-4168-9b45-2ea9f5797bc7 => generated 54 bytes in 0 msecs (HTTP/1.1 404) 3 headers in 112 bytes (1 switches on core 0) | 19:15 |
alee | redrobot, basically its a 404 on a secret I know is there -- would be nice to know what headers etc. are being passed in .. | 19:15 |
*** kfarr has joined #openstack-barbican | 19:28 | |
redrobot | alee I don't know a way to do it off the top of my head | 19:32 |
redrobot | alee I would try making a wsgi middleware to log the requests | 19:32 |
redrobot | alee or oldschool curl -vv | 19:33 |
alee | redrobot, yeah maybe middleware .. | 19:36 |
alee | kfarr, ping | 19:37 |
kfarr | alee pong! | 19:40 |
alee | kfarr, hey! I'm hoping you can solve all my problems! | 19:41 |
kfarr | alee I hope so, too! | 19:41 |
alee | kfarr, I'm trying to test volume encryption with barbican | 19:41 |
alee | and having some problems | 19:41 |
kfarr | alee, oh dear, what sort of problems? | 19:41 |
alee | kfarr, I think I must be missing something in my config | 19:42 |
alee | kfarr, so -- when I create an encrypted volume, I see a request come from cinder to create a symmetric key | 19:42 |
alee | and I see that key being created in dogtag and a reference returned to barbican | 19:42 |
alee | and I see the order being updated and cinder getting the right reference to the order and the secret | 19:43 |
alee | I am also able independently to retrieve the secret using a token issued for that project. | 19:44 |
alee | but now I try to attach that volume to a nova instance | 19:44 |
alee | and I see nova contact barbican | 19:44 |
alee | and I see barbican return a 404 for the secret .. | 19:44 |
alee | which makes me think that nova for some reason is not sending a token/ the right token to barbican .. | 19:45 |
kfarr | alee, and you can see that it is using the correct uuid? Have you tried seeing if you could request the key using either the python client or the command line? | 19:46 |
kfarr | Which user are you using? admin or a regular user? | 19:46 |
alee | kfarr, admin | 19:46 |
alee | kfarr, I can see barbican log the request coming in and specifying 404 . its the correct uuid | 19:47 |
alee | and I can retrieve that secret from the command line | 19:47 |
alee | kfarr, is there any special keystone setup required? | 19:48 |
alee | trusts perhaps? | 19:48 |
alee | kfarr, the only config I have done is in nova.conf | 19:49 |
alee | kfarr, [keymgr] | 19:50 |
alee | api_class = nova.keymgr.barbican.BarbicanKeyManager | 19:50 |
alee | encryption_auth_url = http://rdo.rdodom.test:5000/v3 | 19:50 |
alee | kfarr, what do you have in your nova config? | 19:50 |
kfarr | alee I do not currently have it set up, but I am looking through old notes to see, one sec | 19:51 |
kfarr | alee, you don't have encryption_auth_url specified in cinder? | 19:53 |
alee | oh I do .. | 19:53 |
alee | that was my nova config ... cinder config is .. | 19:53 |
alee | keymgr] | 19:54 |
alee | api_class = cinder.keymgr.barbican.BarbicanKeyManager | 19:54 |
alee | encryption_auth_url = http://rdo.rdodom.test:5000/v3 | 19:54 |
kfarr | alee are you using a default project or one you created? | 19:55 |
alee | default | 19:55 |
kfarr | alee, I do not know the answer immediately, but I can look into it some. My first guess is something with the auth tokens is not correct | 19:58 |
kfarr | You're not using devstack right? But admin user and default project. I can try to reproduce | 19:59 |
alee | kfarr, yup - that would be my guest .. if you take a look, that would be super .. | 19:59 |
alee | packstack | 19:59 |
alee | but admin user and default project | 19:59 |
kfarr | alee, ok, I will get back to you tomorrow morning because I am working on something else right now! | 20:00 |
alee | kfarr, super thanks! | 20:00 |
alee | kfarr, if you get it set up, at least we'll be able to see the difference in our configs | 20:01 |
*** su_zhang has joined #openstack-barbican | 20:08 | |
*** su_zhang has quit IRC | 20:08 | |
*** kebray has joined #openstack-barbican | 20:08 | |
*** su_zhang has joined #openstack-barbican | 20:08 | |
kfarr | alee does packstack automatically install Barbican, and if not how do I configure it to do so? | 20:37 |
alee | kfarr, it doesn't - that I know of, but I just install a barbican server on top of it | 20:42 |
kfarr | alee ok, gotcha! | 20:43 |
*** jamielennox has quit IRC | 20:43 | |
*** zigo has quit IRC | 20:43 | |
*** DuncanT has quit IRC | 20:43 | |
*** eglute has quit IRC | 20:43 | |
*** lisaclark_ has quit IRC | 20:43 | |
*** jraim has quit IRC | 20:43 | |
*** jroll has quit IRC | 20:43 | |
*** lbragstad has quit IRC | 20:43 | |
*** hockeynut has quit IRC | 20:43 | |
*** jillysciarilly has quit IRC | 20:43 | |
*** tdink has quit IRC | 20:43 | |
*** silos1 has left #openstack-barbican | 20:44 | |
*** jamielennox has joined #openstack-barbican | 20:46 | |
*** zigo has joined #openstack-barbican | 20:46 | |
*** DuncanT has joined #openstack-barbican | 20:46 | |
*** eglute has joined #openstack-barbican | 20:46 | |
*** lisaclark_ has joined #openstack-barbican | 20:46 | |
*** jraim has joined #openstack-barbican | 20:46 | |
*** jroll has joined #openstack-barbican | 20:46 | |
*** lbragstad has joined #openstack-barbican | 20:46 | |
*** hockeynut has joined #openstack-barbican | 20:46 | |
*** jillysciarilly has joined #openstack-barbican | 20:46 | |
*** tdink has joined #openstack-barbican | 20:46 | |
*** morgan has quit IRC | 20:52 | |
*** morgan has joined #openstack-barbican | 20:52 | |
*** gyee has quit IRC | 21:01 | |
*** Praston has quit IRC | 21:11 | |
*** su_zhang has quit IRC | 21:36 | |
*** gyee has joined #openstack-barbican | 21:45 | |
*** mixos has quit IRC | 21:54 | |
*** stevemar_ has quit IRC | 21:55 | |
*** stevemar_ has joined #openstack-barbican | 21:56 | |
*** dave-mccowan has quit IRC | 21:57 | |
*** stevemar_ has quit IRC | 21:58 | |
*** kfarr has quit IRC | 22:01 | |
*** xaeth is now known as xaeth_afk | 22:06 | |
*** stevemar_ has joined #openstack-barbican | 22:07 | |
*** dimtruck is now known as zz_dimtruck | 22:07 | |
*** lisaclark has quit IRC | 22:09 | |
*** lisaclark_ has quit IRC | 22:09 | |
*** edtubill has quit IRC | 22:18 | |
*** spotz is now known as spotz_zzz | 22:23 | |
*** alee has quit IRC | 22:24 | |
*** su_zhang has joined #openstack-barbican | 22:25 | |
*** su_zhang has quit IRC | 22:34 | |
*** stevemar_ has quit IRC | 22:43 | |
*** stevemar_ has joined #openstack-barbican | 22:43 | |
*** stevemar_ has quit IRC | 22:46 | |
*** jhfeng has joined #openstack-barbican | 22:55 | |
*** lisaclark has joined #openstack-barbican | 23:03 | |
*** lisaclark_ has joined #openstack-barbican | 23:03 | |
*** vivek-ebay has quit IRC | 23:04 | |
*** chlong has quit IRC | 23:06 | |
*** su_zhang has joined #openstack-barbican | 23:07 | |
*** vivek-ebay has joined #openstack-barbican | 23:09 | |
*** alee has joined #openstack-barbican | 23:14 | |
*** kebray has quit IRC | 23:43 | |
*** stevemar_ has joined #openstack-barbican | 23:50 | |
*** dave-mccowan has joined #openstack-barbican | 23:51 | |
*** jhfeng has quit IRC | 23:58 | |
*** jhfeng has joined #openstack-barbican | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!