*** chlong has quit IRC | 00:32 | |
*** fredyx10 has joined #openstack-barbican | 00:45 | |
*** chlong has joined #openstack-barbican | 00:50 | |
*** mixos has joined #openstack-barbican | 00:53 | |
*** cheneydc has joined #openstack-barbican | 01:02 | |
*** chlong has quit IRC | 01:09 | |
*** mixos has quit IRC | 01:13 | |
*** mixos has joined #openstack-barbican | 01:15 | |
*** chlong has joined #openstack-barbican | 01:23 | |
*** kebray has quit IRC | 01:26 | |
*** kebray has joined #openstack-barbican | 01:26 | |
*** kebray has quit IRC | 01:29 | |
*** stanzi has joined #openstack-barbican | 01:37 | |
*** mixos has quit IRC | 01:39 | |
*** mixos has joined #openstack-barbican | 01:57 | |
*** stanzi has quit IRC | 02:11 | |
*** stanzi has joined #openstack-barbican | 02:24 | |
*** stanzi has quit IRC | 02:28 | |
*** stanzi has joined #openstack-barbican | 02:46 | |
*** zz_dimtruck is now known as dimtruck | 02:47 | |
*** cheneydc has quit IRC | 02:47 | |
*** fredyx10 has quit IRC | 02:49 | |
*** stanzi has quit IRC | 02:50 | |
*** cheneydc has joined #openstack-barbican | 02:51 | |
*** stanzi has joined #openstack-barbican | 02:56 | |
*** dimtruck is now known as zz_dimtruck | 02:57 | |
*** stanzi has quit IRC | 03:01 | |
*** zz_dimtruck is now known as dimtruck | 03:02 | |
*** kebray has joined #openstack-barbican | 03:14 | |
*** dimtruck is now known as zz_dimtruck | 03:15 | |
*** mragupat has joined #openstack-barbican | 03:19 | |
*** mragupat has quit IRC | 03:22 | |
*** mragupat has joined #openstack-barbican | 03:23 | |
*** zz_dimtruck is now known as dimtruck | 03:38 | |
*** sseago has quit IRC | 04:42 | |
*** stanzi has joined #openstack-barbican | 04:48 | |
openstackgerrit | ting wang proposed openstack/python-barbicanclient: Handle container list command correctly https://review.openstack.org/264659 | 04:49 |
---|---|---|
openstackgerrit | ting wang proposed openstack/python-barbicanclient: Handle container list command correctly https://review.openstack.org/264659 | 04:51 |
*** stanzi has quit IRC | 04:52 | |
*** stanzi has joined #openstack-barbican | 04:58 | |
*** sseago has joined #openstack-barbican | 04:58 | |
*** dimtruck is now known as zz_dimtruck | 04:58 | |
*** david-lyle has quit IRC | 05:00 | |
*** david-lyle has joined #openstack-barbican | 05:00 | |
*** mixos has quit IRC | 05:02 | |
*** stanzi has quit IRC | 05:03 | |
*** mragupat has quit IRC | 05:03 | |
*** mragupat has joined #openstack-barbican | 05:04 | |
*** zz_dimtruck is now known as dimtruck | 05:13 | |
openstackgerrit | Reedip proposed openstack/python-barbicanclient: Fix argument order for assertEqual to (expected, observed) https://review.openstack.org/263988 | 05:18 |
openstackgerrit | ting wang proposed openstack/python-barbicanclient: Handle container list command correctly https://review.openstack.org/264659 | 05:32 |
*** Nirupama has joined #openstack-barbican | 05:39 | |
openstackgerrit | Fernando Diaz proposed openstack/barbican-specs: Allow different Keystone Auth Support in Castellan https://review.openstack.org/241068 | 05:46 |
openstackgerrit | Fernando Diaz proposed openstack/barbican-specs: Allow different Keystone Auth Support in Castellan https://review.openstack.org/241068 | 05:50 |
jamielennox | i'm not sure of fernando's nick: what's the difference between that and using an auth plugin from keystoneauth? | 05:50 |
*** jaosorior has joined #openstack-barbican | 05:50 | |
*** dave-mccowan has joined #openstack-barbican | 06:02 | |
*** dave-mcc_ has joined #openstack-barbican | 06:03 | |
*** dave-mccowan has quit IRC | 06:06 | |
*** dimtruck is now known as zz_dimtruck | 06:18 | |
*** dave-mcc_ has quit IRC | 06:21 | |
*** mragupat has quit IRC | 06:27 | |
openstackgerrit | Elvin Tubillara proposed openstack/barbican-specs: Create spec for cron job db garbage collector and secret undeletion https://review.openstack.org/243806 | 06:35 |
openstackgerrit | Merged openstack/barbican: Update ContainerValidator to Check for Name Max Length https://review.openstack.org/264859 | 07:03 |
openstackgerrit | yapeng Yang proposed openstack/python-barbicanclient: Replace assertEqual(None, *) with assertIsNone in tests https://review.openstack.org/265702 | 07:11 |
openstackgerrit | yapeng Yang proposed openstack/python-barbicanclient: Replace assertEqual(None, *) with assertIsNone in tests https://review.openstack.org/265702 | 07:12 |
*** chlong has quit IRC | 07:39 | |
*** stanzi has joined #openstack-barbican | 07:40 | |
*** stanzi has quit IRC | 07:44 | |
*** stanzi has joined #openstack-barbican | 08:00 | |
*** stanzi has quit IRC | 08:05 | |
*** stanzi has joined #openstack-barbican | 08:10 | |
*** stanzi has quit IRC | 08:15 | |
*** kebray has quit IRC | 08:32 | |
*** openstackgerrit has quit IRC | 08:32 | |
*** openstackgerrit has joined #openstack-barbican | 08:33 | |
*** stanzi has joined #openstack-barbican | 08:40 | |
*** stanzi has quit IRC | 08:45 | |
*** stanzi has joined #openstack-barbican | 09:00 | |
*** stanzi has quit IRC | 09:05 | |
openstackgerrit | ting wang proposed openstack/barbican: Add Name restrictions in ContainerValidator https://review.openstack.org/264222 | 09:20 |
*** cheneydc has quit IRC | 10:02 | |
*** jaosorior has quit IRC | 10:53 | |
*** jaosorior has joined #openstack-barbican | 10:54 | |
*** jaosorior has quit IRC | 10:57 | |
*** jaosorior has joined #openstack-barbican | 10:58 | |
*** fredyx10 has joined #openstack-barbican | 11:43 | |
*** fredyx10 has quit IRC | 11:44 | |
*** fredyx10 has joined #openstack-barbican | 11:44 | |
*** fredyx10 has quit IRC | 11:48 | |
*** chlong has joined #openstack-barbican | 11:57 | |
*** peter-hamilton has joined #openstack-barbican | 12:26 | |
*** jaosorior has quit IRC | 12:33 | |
*** jaosorior has joined #openstack-barbican | 12:34 | |
*** Nirupama has quit IRC | 12:35 | |
*** fredyx10 has joined #openstack-barbican | 12:51 | |
*** fredyx10 has quit IRC | 12:51 | |
*** fredyx10 has joined #openstack-barbican | 12:51 | |
*** stanzi has joined #openstack-barbican | 12:53 | |
*** fredyx10 has quit IRC | 12:54 | |
*** stanzi has quit IRC | 12:58 | |
*** fredyx101 has joined #openstack-barbican | 13:06 | |
*** fredyx101 has quit IRC | 13:13 | |
*** stanzi has joined #openstack-barbican | 13:13 | |
*** fredyx10 has joined #openstack-barbican | 13:14 | |
*** stanzi has quit IRC | 13:18 | |
*** stanzi has joined #openstack-barbican | 13:28 | |
*** fredyx10 has quit IRC | 13:36 | |
*** fredyx10 has joined #openstack-barbican | 13:36 | |
*** stanzi has quit IRC | 13:51 | |
*** stanzi has joined #openstack-barbican | 14:01 | |
*** stanzi has quit IRC | 14:06 | |
*** jhfeng has joined #openstack-barbican | 14:07 | |
*** fredyx10 has quit IRC | 14:10 | |
*** stanzi has joined #openstack-barbican | 14:11 | |
*** jmckind has joined #openstack-barbican | 14:13 | |
*** stanzi has quit IRC | 14:15 | |
*** stanzi has joined #openstack-barbican | 14:18 | |
*** stanzi_ has joined #openstack-barbican | 14:23 | |
*** stanzi has quit IRC | 14:23 | |
*** stanzi has joined #openstack-barbican | 14:26 | |
*** stanzi_ has quit IRC | 14:26 | |
*** jmckind has quit IRC | 14:28 | |
*** jhfeng has quit IRC | 14:28 | |
*** fredyx10 has joined #openstack-barbican | 14:49 | |
*** stanzi has quit IRC | 14:55 | |
*** peter-hamilton has quit IRC | 15:02 | |
*** stanzi has joined #openstack-barbican | 15:05 | |
*** dave-mccowan has joined #openstack-barbican | 15:06 | |
*** peter-hamilton has joined #openstack-barbican | 15:07 | |
*** dave-mcc_ has joined #openstack-barbican | 15:07 | |
*** stanzi has quit IRC | 15:10 | |
*** dave-mccowan has quit IRC | 15:11 | |
*** mixos has joined #openstack-barbican | 15:16 | |
*** jhfeng has joined #openstack-barbican | 15:18 | |
*** lisaclark has joined #openstack-barbican | 15:19 | |
*** igueths has joined #openstack-barbican | 15:23 | |
igueths | Hi all. | 15:24 |
rm_work | for anyone who is curious, this has a list of attendees for the LBaaS/FWaaS midcycle which is ALSO at Rackspace this week: https://etherpad.openstack.org/p/lbaas-mitaka-midcycle | 15:24 |
*** jmckind has joined #openstack-barbican | 15:25 | |
*** mixos has quit IRC | 15:25 | |
*** mixos has joined #openstack-barbican | 15:27 | |
*** mragupat has joined #openstack-barbican | 15:27 | |
*** peter-hamilton has quit IRC | 15:32 | |
*** mp1 has joined #openstack-barbican | 15:34 | |
*** kebray has joined #openstack-barbican | 15:35 | |
*** kfarr has joined #openstack-barbican | 15:36 | |
*** kebray has quit IRC | 15:37 | |
*** zz_dimtruck is now known as dimtruck | 15:37 | |
*** kebray has joined #openstack-barbican | 15:38 | |
*** kebray has quit IRC | 15:40 | |
*** spotz_zzz is now known as spotz | 15:42 | |
*** spotz is now known as spotz_zzz | 15:52 | |
openstackgerrit | Fernando Diaz proposed openstack/barbican-specs: Allow different Keystone Auth Support in Castellan https://review.openstack.org/241068 | 15:55 |
*** jorge_munoz has quit IRC | 15:57 | |
*** kebray has joined #openstack-barbican | 16:04 | |
*** kebray has quit IRC | 16:05 | |
*** kebray has joined #openstack-barbican | 16:06 | |
*** jorge_munoz has joined #openstack-barbican | 16:08 | |
*** spotz_zzz is now known as spotz | 16:14 | |
*** jmckind has quit IRC | 16:24 | |
*** jmckind has joined #openstack-barbican | 16:24 | |
*** lisaclark has quit IRC | 16:25 | |
*** edtubill has joined #openstack-barbican | 16:26 | |
*** diazjf has joined #openstack-barbican | 16:27 | |
*** nkinder has joined #openstack-barbican | 16:27 | |
*** mixos has quit IRC | 16:30 | |
openstackgerrit | Christopher Solis proposed openstack/castellan: Update docs with parsing config files https://review.openstack.org/257499 | 16:34 |
*** jaosorior has quit IRC | 16:36 | |
*** jaosorior has joined #openstack-barbican | 16:36 | |
*** kebray has quit IRC | 16:39 | |
*** lisaclark has joined #openstack-barbican | 16:40 | |
*** alee has joined #openstack-barbican | 16:42 | |
*** lisaclark has quit IRC | 16:42 | |
openstackgerrit | Christopher Solis proposed openstack/castellan: Update docs with parsing config files https://review.openstack.org/257499 | 16:44 |
*** mixos has joined #openstack-barbican | 16:46 | |
*** lisaclark has joined #openstack-barbican | 16:47 | |
*** lisaclark has quit IRC | 16:53 | |
*** lisaclark has joined #openstack-barbican | 16:54 | |
*** Asha has joined #openstack-barbican | 16:55 | |
*** lisaclark has quit IRC | 16:56 | |
*** lisaclark has joined #openstack-barbican | 16:57 | |
*** lisaclark has quit IRC | 16:59 | |
*** kebray has joined #openstack-barbican | 17:01 | |
*** mixos has quit IRC | 17:01 | |
Asha | Why does the CURL response of the command : curl -X GET https://load.softlayer.com:9311 -H "Accept: application/json" -H "User-Agent:keystoneauth1/2.0.1" | 17:01 |
Asha | returns the response of href as "http://load.softlayer.com:9311/v1/" | 17:02 |
*** mixos has joined #openstack-barbican | 17:03 | |
Asha | even though barbican.conf is configured with host_href = https://load.softlayer.com:9311 | 17:03 |
*** jaosorior has quit IRC | 17:04 | |
Asha | The URL is not the actual barbican node but is the URL of the load balancer | 17:04 |
*** jaosorior has joined #openstack-barbican | 17:04 | |
Asha | Please find the command and response below : | 17:05 |
Asha | [asha ~]$ curl -X GET https://load.softlayer.com:9311 -H "Accept: application/json" -H "User-Agent:keystoneauth1/2.0.1" {"versions": {"values": [{"status": "stable", "updated": "2015-04-28T00:00:00Z", "media-types": [{"base": "application/json", "type": "application/vnd.openstack.key-manager-v1+json"}], "id": "v1", "links": [{"href": "http://load.softlayer.com:9311/v1/", "rel": "self"}, {"href": "http://docs.openstack.org/", | 17:05 |
Asha | Would require help , any help would highly be appreicated | 17:06 |
*** gyee has joined #openstack-barbican | 17:08 | |
*** mixos has quit IRC | 17:11 | |
*** mixos has joined #openstack-barbican | 17:12 | |
Asha | Hi Mixos | 17:13 |
mixos | HI, Asha | 17:13 |
Asha | Do you have any idea on this? | 17:13 |
mixos | Sungjin here. | 17:13 |
mixos | in meeting now. will read. | 17:14 |
Asha | Hi Sungjin ..Sure | 17:14 |
*** lisaclark has joined #openstack-barbican | 17:15 | |
*** lisaclark has quit IRC | 17:15 | |
*** lisaclark has joined #openstack-barbican | 17:16 | |
*** jorge_munoz has quit IRC | 17:16 | |
*** pdesai has joined #openstack-barbican | 17:20 | |
jaosorior | Asha, what's up? | 17:22 |
Asha | Hi jaosorior | 17:22 |
Asha | How are you? | 17:22 |
jaosorior | all good here, lots of work. Need any help? | 17:22 |
Asha | Thanks for asking ! Yeah would need your help | 17:23 |
rm_work | mixos: oh, you're here! didn't connect IRC name to real name during intro :P | 17:25 |
Asha | Hi jaosorior | 17:30 |
Asha | Would need your help for the query that I posted today in the chat room | 17:30 |
Asha | This is regarding the curl response of the command curl -X GET https://load.softlayer.com:9311 -H "Accept: application/json" -H "User-Agent:keystoneauth1/2.0.1" | 17:31 |
jaosorior | Asha, well, that will give you a list of the available versions | 17:32 |
*** lisaclark has quit IRC | 17:33 | |
Asha | I know that , but why is the value of href returned as "http://load.softlayer.com:9311/v1/" and not "https://load.softlayer.com:9311/v1/" | 17:33 |
*** lisaclark has joined #openstack-barbican | 17:34 | |
Asha | eventhough barbican.conf is configured with host_href = https://load.softlayer.com:9311 | 17:34 |
Asha | Please find the command and response below : | 17:35 |
Asha | [asha ~]$ curl -X GET https://load.softlayer.com:9311 -H "Accept: application/json" -H "User-Agent:keystoneauth1/2.0.1" {"versions": {"values": [{"status": "stable", "updated": "2015-04-28T00:00:00Z", "media-types": [{"base": "application/json", "type": "application/vnd.openstack.key-manager-v1+json"}], "id": "v1", "links": [{"href": "http://load.softlayer.com:9311/v1/", "rel": "self"}, {"href": "http://docs.openstack.org/", | 17:35 |
jaosorior | funky, that doesn't seem right\ | 17:37 |
Asha | yeah | 17:38 |
Asha | but URL https://load.softlayer.com:9311/ refers to the load balancer which routes the request to the barbican node and is not the actual barbican node | 17:39 |
*** lisaclark has quit IRC | 17:39 | |
Asha | Jaosorior ...Do u have any idea ? | 17:44 |
jaosorior | Asha: the json-home implementation that you're accessing takes the url that was received from the request | 17:45 |
jaosorior | so what happens is that the loadbalancer accesses barbican through http instead of https | 17:46 |
jaosorior | this won't be a problem for a lot of other operations, seems that only that one | 17:46 |
jaosorior | so there are two choices | 17:46 |
jaosorior | either you put the oslo_middleware ssl or http_proxy_to_wsgi in front of barbican | 17:47 |
jaosorior | and enable X-Forwarded-Proto passing to the server via your loadbalancer | 17:47 |
jaosorior | or we need to submit a fix to barbican to use host_href instead of the url that it gets from the request | 17:47 |
*** lisaclark has joined #openstack-barbican | 17:47 | |
*** stanzi has joined #openstack-barbican | 17:48 | |
jaosorior | Asha: Does it make sense? | 17:49 |
Asha | Thanks a lot JASORIOR :) for the response ..It means that the actual barbican node needs to be configued to SSL | 17:49 |
Asha | I had one question , the URI returned from the barbican response is not according to the URL configured in barbican.conf ..I am little confused on this | 17:53 |
Asha | It is according to the request that the load balancer sends to actual barbican node | 17:54 |
jaosorior | Asha, that is the case | 17:56 |
jaosorior | Asha, that is a problem in the implementation, it should be using the CONF.host_href instead | 17:57 |
jaosorior | Asha: Can you file a bug for that? | 17:57 |
Asha | oh k ..Thanks Jasosorior ...sure | 17:57 |
Asha | I shall file the bug for that | 17:57 |
Asha | This would happend only in case load balancer sits in front of barbican | 17:58 |
jaosorior | Asha, which is a reasonable use-case | 17:59 |
Asha | Yeah ... u are right This is problem only with the GET version and not any other API call say POST secret | 18:01 |
jaosorior | Asha, indeed, because on the other parts, the host_href should be used | 18:02 |
Asha | Thanks Jaosorior :) ..I appreciate ur help ... | 18:03 |
jaosorior | Asha: no problem | 18:10 |
*** mp1 has quit IRC | 18:14 | |
*** stanzi has quit IRC | 18:17 | |
*** stanzi has joined #openstack-barbican | 18:18 | |
*** lisaclark has quit IRC | 18:27 | |
*** diazjf has quit IRC | 18:29 | |
*** diazjf has joined #openstack-barbican | 18:40 | |
*** jmckind has quit IRC | 18:44 | |
*** jorge_munoz has joined #openstack-barbican | 18:45 | |
*** stanzi has quit IRC | 18:48 | |
* redrobot waves at jaosorior | 18:52 | |
redrobot | jaosorior Hi from the midcycle meetup! | 18:52 |
jaosorior | redrobot: Hey dude! | 18:53 |
jaosorior | what's up :D | 18:53 |
redrobot | jaosorior waiting for lunch to show up | 18:53 |
*** jaosorior has quit IRC | 18:53 | |
redrobot | jaosorior packed room for the midcycle | 18:53 |
*** jaosorior has joined #openstack-barbican | 18:54 | |
jaosorior | redrobot: nice! What's it gonna be? | 18:54 |
redrobot | jaosorior Jason's Deli - everyone got to pick their own, so it's going to be good. | 18:55 |
redrobot | jaosorior how was the birthday? | 18:55 |
redrobot | jaosorior lots of Salmiyakki? | 18:55 |
*** barra204 has joined #openstack-barbican | 18:55 | |
*** hyakuhei has joined #openstack-barbican | 18:55 | |
jaosorior | redrobot: lots of everything. We went to a brewery and had a bunch of beers, then hit another pub and it got blurrier and blurrier | 18:56 |
*** shakamunyi has quit IRC | 18:56 | |
redrobot | jaosorior hahaha, excellent! | 18:56 |
jaosorior | redrobot: You guys need to have shots in my absence | 18:57 |
*** lisaclark has joined #openstack-barbican | 18:57 | |
*** lisaclark has quit IRC | 18:57 | |
*** diazjf has quit IRC | 18:59 | |
*** lisaclark has joined #openstack-barbican | 19:02 | |
*** lisaclark has quit IRC | 19:02 | |
*** lisaclark has joined #openstack-barbican | 19:02 | |
*** nelsnels_ has quit IRC | 19:02 | |
*** nelsnelson has joined #openstack-barbican | 19:03 | |
*** fredyx10 has quit IRC | 19:08 | |
*** fredyx10 has joined #openstack-barbican | 19:09 | |
*** shakamunyi has joined #openstack-barbican | 19:12 | |
*** barra204 has quit IRC | 19:12 | |
*** lisaclark has quit IRC | 19:22 | |
*** diazjf has joined #openstack-barbican | 19:25 | |
*** jaosorior has quit IRC | 19:33 | |
*** stanzi has joined #openstack-barbican | 19:35 | |
*** mp1 has joined #openstack-barbican | 19:35 | |
*** lisaclark has joined #openstack-barbican | 19:38 | |
*** stanzi has quit IRC | 19:45 | |
*** darrenmoffat has quit IRC | 19:45 | |
*** stanzi has joined #openstack-barbican | 19:45 | |
*** darrenmoffat has joined #openstack-barbican | 19:46 | |
*** NazcaLines has joined #openstack-barbican | 19:58 | |
lisaclark | reaperhulk: ping | 20:05 |
reaperhulk | lisaclark: you rang? | 20:17 |
*** lisaclark has quit IRC | 20:20 | |
*** hyakuhei has quit IRC | 20:22 | |
*** hyakuhei has joined #openstack-barbican | 20:26 | |
*** NazcaLines has quit IRC | 20:29 | |
igueths | Anyone know why this is still open? https://bugs.launchpad.net/barbican/+bug/1259292 | 20:32 |
openstack | Launchpad bug 1259292 in OpenStack Dashboard (Horizon) "Some tests use assertEqual(observed, expected) , the argument order is wrong" [Wishlist,In progress] - Assigned to ChenZheng (chen-zheng) | 20:32 |
diazjf | igueths, there is a fix up https://review.openstack.org/#/c/263988/ | 20:40 |
kfarr | zigo you there? | 20:40 |
diazjf | igueths, it just needs to be reviewed and merged. | 20:41 |
*** stanzi has quit IRC | 20:43 | |
igueths | diazjf: Ah ok. | 20:47 |
dave-mcc_ | igueths there are two patches: one for barbican and one for barbican-client | 20:51 |
openstackgerrit | Elvin Tubillara proposed openstack/barbican-specs: Create spec for cron job db garbage collector, secret undeletion, hard del https://review.openstack.org/243806 | 20:53 |
*** diazjf has quit IRC | 20:56 | |
igueths | dave-mcc_: This diff I was looking at it looks like part of Barbican proper. | 20:57 |
*** rellerreller has joined #openstack-barbican | 21:02 | |
*** diazjf has joined #openstack-barbican | 21:08 | |
*** hyakuhei has quit IRC | 21:09 | |
*** hyakuhei has joined #openstack-barbican | 21:12 | |
*** lisaclark has joined #openstack-barbican | 21:14 | |
*** lisaclark has joined #openstack-barbican | 21:14 | |
kfarr | https://talkgadget.google.com/hangouts/_/22saadjqrvm4v2qpdhczvp2nima | 21:15 |
kfarr | rellerreller ^^ | 21:15 |
lisaclark | hi reaperhulk. we were doing a review of jkf's pkcs11 patch and there was a polling of the group over one particular method and whether it was truly needed | 21:23 |
lisaclark | i was pinging you to see if you were the original author and had insight into this. the group has moved onto other topics now though. | 21:23 |
reaperhulk | ah okay | 21:24 |
reaperhulk | midcycle runs through Wednesday correct? | 21:24 |
lisaclark | yes it does. would you be interested and able to join us? | 21:25 |
spotz | yes reaperhulk | 21:25 |
lisaclark | agenda is posted up here: https://etherpad.openstack.org/p/barbican-mitaka-midcycle | 21:25 |
spotz | Missed one of the sessions I voted for:( | 21:26 |
dave-mcc_ | reaperhulk it is this method. http://git.openstack.org/cgit/openstack/barbican/tree/barbican/plugin/crypto/pkcs11.py#n348 you added it in Jan 2015. | 21:27 |
reaperhulk | heh, the "ultra simple see if random is working" test | 21:28 |
reaperhulk | it may not be relevant to the codebase as it currently exists | 21:28 |
dave-mcc_ | reaperhulk we were mainly curious why 100 bytes of zeroes was special. | 21:28 |
reaperhulk | probability of getting 100 zero bytes in a row is (1/256)**100 is all | 21:29 |
reaperhulk | there was a failure mode at the time where a C_Initialize could fail and the buffer wouldn't fill with randomness and cffi zeroes memory that's allocated so an RNG failure would manifest as "all null bytes" | 21:29 |
jkf | Would C_Initialize fail, but still return CKR_OK? | 21:31 |
*** lisaclark has quit IRC | 21:32 | |
reaperhulk | jkf: memory is hazy but I believe the actual scenario was success on initialization but subsequent broken library? If I was looking at this code now I suspect I'd want to remove it in the absence of a reproducible test scenario though. | 21:34 |
reaperhulk | gotta run for now, but might be able to drop in Wednesday | 21:34 |
jkf | reaperhulk: cool, thanks for the answers. | 21:34 |
reaperhulk | got some fun news for you re: the edges of that mysql bug you found many months ago jkf | 21:35 |
reaperhulk | so if you see me remind me to tell you ;) | 21:35 |
jkf | Oh? Will do. | 21:35 |
*** hyakuhei has quit IRC | 21:38 | |
*** lisaclark has joined #openstack-barbican | 21:40 | |
*** hyakuhei has joined #openstack-barbican | 21:40 | |
hyakuhei | ^ conspiracy! | 21:48 |
*** diazjf has quit IRC | 21:51 | |
*** fredyx10 has quit IRC | 21:52 | |
*** lisaclark has quit IRC | 21:53 | |
*** lisaclark has joined #openstack-barbican | 21:58 | |
-openstackstatus- NOTICE: Gerrit is restarting to resolve java memory issues | 22:04 | |
*** ryanpetrello has quit IRC | 22:04 | |
*** woodster_ has joined #openstack-barbican | 22:06 | |
openstackgerrit | Dave McCowan proposed openstack/barbican: Refactor Base64 use and other changes for Python3 https://review.openstack.org/233633 | 22:06 |
*** rellerreller has quit IRC | 22:08 | |
*** lisaclark has quit IRC | 22:11 | |
dave-mcc_ | jkf can you take a look at ozz's comment here: https://review.openstack.org/#/c/233633/6/barbican/plugin/crypto/pkcs11.py | 22:12 |
jkf | dave-mcc_: I was just replying. :) | 22:13 |
*** diazjf has joined #openstack-barbican | 22:14 | |
jkf | dave-mcc_: btw, there is a subtle bug in the code there. If there is every a unicode char that encodes to multiple utf-8 bytes, then the wrong length value gets passed. See line 582 here for how I did it. https://review.openstack.org/#/c/243291/5/barbican/plugin/crypto/pkcs11.py | 22:16 |
*** kebray has quit IRC | 22:18 | |
*** lisaclark has joined #openstack-barbican | 22:19 | |
*** lisaclark has quit IRC | 22:23 | |
*** fredyx10 has joined #openstack-barbican | 22:24 | |
*** lisaclark has joined #openstack-barbican | 22:27 | |
openstackgerrit | Dave McCowan proposed openstack/barbican: Refactor Base64 use and other changes for Python3 https://review.openstack.org/233633 | 22:31 |
*** diazjf has quit IRC | 22:32 | |
*** jmckind has joined #openstack-barbican | 22:33 | |
*** kebray has joined #openstack-barbican | 22:34 | |
hyakuhei | dave-mcc_: https://wiki.openstack.org/wiki/Security/Security_Note_Process | 22:37 |
*** ryanpetrello has joined #openstack-barbican | 22:37 | |
hyakuhei | dave-mcc_: No one OSSN stands out as being a shining example but any recent OSSN from here should be a decent guide: https://wiki.openstack.org/wiki/Security_Notes | 22:40 |
*** edtubill has quit IRC | 22:48 | |
*** igueths has quit IRC | 22:49 | |
dave-mcc_ | hyakuhei https://developer.ibm.com/opentech/2015/12/15/dockerfile-for-barbican/ | 22:49 |
hyakuhei | That’s a bit more complex than mine | 22:50 |
*** mixos has quit IRC | 22:54 | |
*** Asha has quit IRC | 22:55 | |
*** hyakuhei has quit IRC | 22:56 | |
*** jhfeng has quit IRC | 22:56 | |
*** hyakuhei has joined #openstack-barbican | 22:56 | |
*** kfarr has quit IRC | 22:56 | |
*** alee has quit IRC | 23:00 | |
*** dave-mcc_ has quit IRC | 23:00 | |
*** jmckind has quit IRC | 23:02 | |
*** fredyx10 has quit IRC | 23:06 | |
*** fredyx10 has joined #openstack-barbican | 23:06 | |
*** mp1 has quit IRC | 23:12 | |
*** dimtruck is now known as zz_dimtruck | 23:16 | |
*** kebray has quit IRC | 23:20 | |
*** lisaclark has quit IRC | 23:26 | |
*** spotz is now known as spotz_zzz | 23:26 | |
*** hyakuhei has joined #openstack-barbican | 23:31 | |
*** stanzi has joined #openstack-barbican | 23:35 | |
*** mragupat has quit IRC | 23:38 | |
*** hyakuhei has quit IRC | 23:39 | |
*** fredyx10 has quit IRC | 23:43 | |
*** zz_dimtruck is now known as dimtruck | 23:51 | |
*** mragupat has joined #openstack-barbican | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!