*** chlong has joined #openstack-barbican | 00:26 | |
*** chlong has quit IRC | 01:03 | |
*** su_zhang has joined #openstack-barbican | 01:11 | |
*** hyakuhei has joined #openstack-barbican | 01:46 | |
*** chlong has joined #openstack-barbican | 02:06 | |
*** su_zhang has quit IRC | 02:07 | |
*** su_zhang has joined #openstack-barbican | 02:23 | |
*** hyakuhei has quit IRC | 02:29 | |
*** hyakuhei has joined #openstack-barbican | 02:32 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/277116 | 02:37 |
---|---|---|
*** mragupat has joined #openstack-barbican | 02:55 | |
*** mragupat has quit IRC | 03:09 | |
*** mragupat has joined #openstack-barbican | 03:10 | |
*** hyakuhei has quit IRC | 03:32 | |
*** hyakuhei has joined #openstack-barbican | 03:43 | |
*** mragupat has quit IRC | 04:22 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Add Credential Authentication Usage Documentation https://review.openstack.org/274183 | 04:24 |
*** david-lyle has quit IRC | 04:30 | |
*** david-lyle has joined #openstack-barbican | 04:45 | |
*** dimtruck is now known as zz_dimtruck | 04:50 | |
*** Nirupama has joined #openstack-barbican | 04:57 | |
*** hyakuhei has quit IRC | 05:01 | |
*** dave-mccowan has quit IRC | 05:31 | |
*** Nirupama has quit IRC | 05:43 | |
*** su_zhang has quit IRC | 05:50 | |
*** yfujioka has joined #openstack-barbican | 05:54 | |
*** Nirupama has joined #openstack-barbican | 05:56 | |
*** nkinder has joined #openstack-barbican | 06:23 | |
*** alee has joined #openstack-barbican | 06:33 | |
*** nkinder has quit IRC | 06:39 | |
*** su_zhang has joined #openstack-barbican | 06:44 | |
*** alee has quit IRC | 06:47 | |
*** chlong has quit IRC | 07:03 | |
*** alee has joined #openstack-barbican | 07:42 | |
*** nkinder has joined #openstack-barbican | 07:44 | |
*** Nirupama has quit IRC | 07:53 | |
*** jaosorior has joined #openstack-barbican | 07:57 | |
*** jaosorior has quit IRC | 08:05 | |
*** Nirupama has joined #openstack-barbican | 08:07 | |
*** scheuran has joined #openstack-barbican | 08:09 | |
*** jaosorior has joined #openstack-barbican | 08:13 | |
jaosorior | alee: You might want to take a look at this http://logs.openstack.org/24/274024/2/check/gate-barbican-dogtag-devstack-dsvm-f23/ba4fda7/logs/devstacklog.txt.gz#_2016-02-07_15_36_13_540 | 08:16 |
*** su_zhang has quit IRC | 08:21 | |
alee | jaosorior, hmm | 08:25 |
alee | jaosorior, were is the review that generated this log? | 08:29 |
jaosorior | alee: It's the one I did yesterday | 08:33 |
jaosorior | alee: https://review.openstack.org/#/c/274024/ | 08:33 |
alee | jaosorior, so - for some reason, we still fail rpm -i python-requests, but that may not be an issue given whats in pip | 08:44 |
jaosorior | alee: Indeed it's not an issue. the pip feeze shows it's installed. So it's good. It's a bogus message. | 08:44 |
alee | jaosorior, but its clear that what we thought was happening is happening | 08:45 |
jaosorior | alee: And python-nss is no longer sending an error message. so that's fixed. | 08:45 |
alee | that is there is a hostname without a domain set | 08:45 |
jaosorior | alee: Indeed... So we need the removal of that check or the introduction of that flag | 08:45 |
alee | can we patch pkispawn till this happens in dogtag code? | 08:45 |
*** shohel has joined #openstack-barbican | 08:46 | |
jaosorior | alee: We could patch that... though it's gonna be pretty damn dirty. And it will most likely break once you introduce that check | 08:46 |
jaosorior | so I had patched some dogtag code in the devstack script before to debug some things. But it was with a damn dirty sed | 08:47 |
alee | jaosorior, ok -we'll discuss .. | 08:47 |
jaosorior | So I rather have that flag in pkispawn or the removal of that check | 08:47 |
*** chlong has joined #openstack-barbican | 08:49 | |
jaosorior | alee: Anyway, for now. I will trim down the patch to only remove that python-nss error. | 08:51 |
alee | ok | 08:52 |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Remove erroneous installing of python-nss https://review.openstack.org/274024 | 08:55 |
jaosorior | alee; ^^ | 08:55 |
*** jaosorior has quit IRC | 08:57 | |
*** openstackgerrit has quit IRC | 09:02 | |
*** openstackgerrit has joined #openstack-barbican | 09:02 | |
*** jaosorior has joined #openstack-barbican | 09:03 | |
*** spotz_zzz is now known as spotz | 09:21 | |
*** yuanying is now known as yuanying_influen | 09:25 | |
*** yuanying_influen is now known as yuanying_flu | 09:25 | |
openstackgerrit | Tobias Zatti proposed openstack/barbican: Applied Jason Fritchers changes https://review.openstack.org/273590 | 10:13 |
*** sidx64 has joined #openstack-barbican | 10:20 | |
*** jaosorior has quit IRC | 11:41 | |
*** jaosorior has joined #openstack-barbican | 11:43 | |
*** sidx64 has quit IRC | 11:56 | |
*** jaosorior has quit IRC | 12:17 | |
*** krotscheck_dcm is now known as krotscheck | 12:39 | |
*** spotz is now known as spotz_zzz | 12:45 | |
*** jaosorior has joined #openstack-barbican | 12:46 | |
*** jaosorior has quit IRC | 12:51 | |
*** krotscheck has quit IRC | 13:06 | |
*** dave-mccowan has joined #openstack-barbican | 13:12 | |
*** krotscheck has joined #openstack-barbican | 13:18 | |
openstackgerrit | Merged openstack/castellan: Updated from global requirements https://review.openstack.org/272779 | 13:40 |
*** su_zhang has joined #openstack-barbican | 13:56 | |
*** alee has quit IRC | 13:59 | |
*** shohel has quit IRC | 14:02 | |
*** hyakuhei has joined #openstack-barbican | 14:05 | |
*** sidx64 has joined #openstack-barbican | 14:07 | |
openstackgerrit | Merged openstack/castellan: Introduce Castellan Credential Objects https://review.openstack.org/270602 | 14:09 |
*** Nirupama has quit IRC | 14:09 | |
*** jaosorior has joined #openstack-barbican | 14:11 | |
*** alee has joined #openstack-barbican | 14:12 | |
*** hyakuhei has quit IRC | 14:13 | |
*** sidx64_Cern has joined #openstack-barbican | 14:14 | |
*** alee has quit IRC | 14:14 | |
*** alee has joined #openstack-barbican | 14:14 | |
*** sidx64 has quit IRC | 14:16 | |
*** jaosorior has quit IRC | 14:21 | |
*** jaosorior has joined #openstack-barbican | 14:21 | |
*** hyakuhei has joined #openstack-barbican | 14:22 | |
*** edtubill has joined #openstack-barbican | 14:23 | |
*** su_zhang has quit IRC | 14:28 | |
*** peter-hamilton has joined #openstack-barbican | 14:34 | |
*** rellerreller has joined #openstack-barbican | 14:42 | |
*** sidx64_Cern has quit IRC | 14:49 | |
*** nelsnelson has quit IRC | 14:50 | |
*** hyakuhei has quit IRC | 15:02 | |
*** nkinder has quit IRC | 15:09 | |
*** nkinder has joined #openstack-barbican | 15:10 | |
*** hyakuhei has joined #openstack-barbican | 15:11 | |
*** Nirupama has joined #openstack-barbican | 15:16 | |
*** spotz_zzz is now known as spotz | 15:17 | |
*** mragupat has joined #openstack-barbican | 15:21 | |
*** Nirupama has quit IRC | 15:23 | |
*** alee has quit IRC | 15:23 | |
*** nelsnelson has joined #openstack-barbican | 15:24 | |
*** alee has joined #openstack-barbican | 15:27 | |
*** zz_dimtruck is now known as dimtruck | 15:31 | |
*** silos has joined #openstack-barbican | 15:32 | |
*** jhfeng has joined #openstack-barbican | 15:44 | |
*** hyakuhei has quit IRC | 16:01 | |
*** mp1 has joined #openstack-barbican | 16:02 | |
*** mp1 has quit IRC | 16:03 | |
*** mp1 has joined #openstack-barbican | 16:04 | |
redrobot | gong hey fat choy barbicaneers | 16:06 |
*** tkelsey has joined #openstack-barbican | 16:08 | |
elmiko | gong xi facai to you too ;) | 16:11 |
spotz | Hayy Chinese New YEars redrobot:) | 16:13 |
jaosorior | I was pretty confused for a bit | 16:13 |
*** ccneill has joined #openstack-barbican | 16:17 | |
*** silos has quit IRC | 16:19 | |
*** kebray has joined #openstack-barbican | 16:19 | |
*** hyakuhei has joined #openstack-barbican | 16:22 | |
*** kebray_ has joined #openstack-barbican | 16:23 | |
*** kebray has quit IRC | 16:24 | |
*** silos has joined #openstack-barbican | 16:24 | |
*** kebray_ has quit IRC | 16:27 | |
*** mragupat has quit IRC | 16:32 | |
*** mragupat has joined #openstack-barbican | 16:32 | |
*** kebray has joined #openstack-barbican | 16:32 | |
*** kebray has quit IRC | 16:37 | |
*** kebray has joined #openstack-barbican | 16:38 | |
*** diazjf has joined #openstack-barbican | 16:39 | |
*** alee has quit IRC | 16:43 | |
*** nkinder has quit IRC | 16:44 | |
*** gyee has joined #openstack-barbican | 16:48 | |
*** mragupat_ has joined #openstack-barbican | 16:51 | |
*** su_zhang has joined #openstack-barbican | 16:52 | |
*** mragupat has quit IRC | 16:54 | |
openstackgerrit | Christopher Solis proposed openstack/barbican-specs: Add a KMIP key manager interface in Castellan https://review.openstack.org/246546 | 16:57 |
*** fnaval has joined #openstack-barbican | 17:03 | |
*** su_zhang has quit IRC | 17:05 | |
*** scheuran has quit IRC | 17:12 | |
arunkant | rellerreller : ping? | 17:12 |
*** edtubill has quit IRC | 17:14 | |
*** kebray has quit IRC | 17:16 | |
*** kebray has joined #openstack-barbican | 17:16 | |
*** mp1 has quit IRC | 17:41 | |
*** edtubill has joined #openstack-barbican | 17:47 | |
*** kebray has quit IRC | 17:59 | |
*** su_zhang has joined #openstack-barbican | 18:00 | |
*** su_zhang has quit IRC | 18:01 | |
*** kebray has joined #openstack-barbican | 18:06 | |
rellerreller | arunkant pong | 18:06 |
*** mp1 has joined #openstack-barbican | 18:08 | |
arunkant | rellerreller: just replied to your comment on https://review.openstack.org/#/c/263972 . Please check. | 18:09 |
rellerreller | arunkant why can't there be multiple KMIP secret stores? | 18:10 |
arunkant | rellerreller: there is one KMIP plugin configuration supported at conf and plugin instance level | 18:11 |
rellerreller | arunkant so your spec is limited to only one instance of each type of secret store? | 18:12 |
arunkant | rellerreller: I am not talking about my spec, I am talking about current barbican impl | 18:13 |
rellerreller | arunkant then you can change the scenario to have key A in KMIP and key B in Dogtag. | 18:13 |
rellerreller | arunkant I understand that. It is another issue that we will have to tackle if this spec is approved. | 18:14 |
arunkant | rellereller: What issue you are referring to? Its just providing option to use different plugin at project level among whatever plugins are available. Type of plugin should not matter. | 18:16 |
rellerreller | arunkant I would like details on how key wrapping would work for keys stored in two different secret stores. | 18:17 |
*** su_zhang has joined #openstack-barbican | 18:17 | |
rellerreller | arunkant I would like to see a sequence diagram that shows storing the keys in different projects, which means different secret stores, and then retrieving one key that is wrapped with another key. | 18:18 |
rellerreller | arunkant I want to know if your spec will support that type of scenario. | 18:18 |
arunkant | rellerreller: I am not working on adding key wrapping support. This is something you are talking about. | 18:18 |
rellerreller | arunkant I understand that, but I believe your spec will have impact on key wrapping spec. | 18:19 |
rellerreller | arunkant I want to know if that will be an issue and how we would deal with that. | 18:19 |
arunkant | rellerreller: Okay..so I would not the details of key wrapping . If you think that's an issue, may be don't enable multiple backend support with key wrapping | 18:20 |
arunkant | rellerreller: Its not requirement to use multiple backend. Its going to be disabled by default. | 18:21 |
arunkant | rellerreller: I am not looking into key wrapping feature so don't know the internals of how it will work. Thinking out loud, if there is multiple backend and key wrapping support added, it will have to some mechanism (on barbican side) to tie them together (like we do for currently for secrets where we stamp backend information within secret) | 18:26 |
arunkant | rellerreller: What do you think? | 18:28 |
rellerreller | arunkant the key wrapping can happen on get and store. We can just consider the get case for now. You simply issue a get_secret command and specify a wrapping key that will encrypt the specified key before returning it. | 18:28 |
*** silos has quit IRC | 18:29 | |
rellerreller | arunkant You can look at the KMIP spec. I listed the section in my comments, but it is pretty straight forward to follow. | 18:29 |
rellerreller | arunkant any information to show how that would work would help the conversation move along. | 18:30 |
arunkant | rellerreller: As I said, there is always option that..don't enable multiple backend support with key wrapping if you think that's an issue. | 18:31 |
*** hyakuhei has quit IRC | 18:32 | |
rellerreller | arunkant why not see if it is an issue? | 18:33 |
arunkant | rellerreller: I think this will be looked into when key wrapping support is added as it will greatly vary across different plugins. So checking one specific may not be sufficient. | 18:34 |
rellerreller | arunkant I'm talking about existing plugins. We can choose PKCS#11 and KMIP. | 18:35 |
rellerreller | arunkant I would rather think about these scenarios up front, so that future specs that will be impacted by this one do not have to modify multiple secret store code. If we can take some time up front to think about this and have a good design to accomodate that then it can save time later on. | 18:36 |
*** mp1 has quit IRC | 18:37 | |
*** kebray has quit IRC | 18:38 | |
*** kebray has joined #openstack-barbican | 18:43 | |
*** kebray has quit IRC | 18:43 | |
krotscheck | I've got 3x +2 on https://review.openstack.org/#/c/255364/, anyone availble to kick the +A? | 18:45 |
*** hyakuhei has joined #openstack-barbican | 18:49 | |
*** mp1 has joined #openstack-barbican | 18:53 | |
*** su_zhang has quit IRC | 18:55 | |
*** su_zhang has joined #openstack-barbican | 18:56 | |
*** kebray has joined #openstack-barbican | 18:56 | |
*** kebray has quit IRC | 18:57 | |
*** ccneill has quit IRC | 18:58 | |
*** su_zhang has quit IRC | 18:58 | |
*** peter-hamilton has quit IRC | 18:58 | |
*** fnaval has quit IRC | 19:16 | |
*** mp1 has quit IRC | 19:16 | |
*** su_zhang has joined #openstack-barbican | 19:18 | |
*** hyakuhei has quit IRC | 19:22 | |
*** silos has joined #openstack-barbican | 19:23 | |
arunkant | rellerreller: As per quick browsing of wrapping key (http://docs.oasis-open.org/kmip/spec/v1.2/os/kmip-spec-v1.2-os.html#_Toc409613462) in kmip spec, key wrapping looks similar to transport key. | 19:25 |
arunkant | rellerreller: In that case, we can define wrapping key specific to plugin instance and then pass that key reference when doing related secret store operations. | 19:26 |
arunkant | rellerreller: So its always one to one mapping for specific plugin . I don't see issue with that as it seems similar to transport key behavior. | 19:28 |
*** ccneill has joined #openstack-barbican | 19:33 | |
*** hyakuhei has joined #openstack-barbican | 19:35 | |
*** kebray has joined #openstack-barbican | 19:35 | |
openstackgerrit | Fernando Diaz proposed openstack/barbican: WIP: User Metadata API and tests https://review.openstack.org/275885 | 19:36 |
*** kebray has quit IRC | 19:40 | |
*** kebray has joined #openstack-barbican | 19:40 | |
*** fnaval has joined #openstack-barbican | 19:42 | |
*** mp1 has joined #openstack-barbican | 19:53 | |
*** kfarr has joined #openstack-barbican | 19:54 | |
*** woodster_ has joined #openstack-barbican | 20:02 | |
*** maxabidi has joined #openstack-barbican | 20:03 | |
*** tkelsey has quit IRC | 20:14 | |
*** kebray has quit IRC | 20:20 | |
*** su_zhang has quit IRC | 20:21 | |
*** kebray has joined #openstack-barbican | 20:24 | |
*** kebray has quit IRC | 20:27 | |
*** alee has joined #openstack-barbican | 20:27 | |
*** edtubill_ has joined #openstack-barbican | 20:28 | |
*** su_zhang has joined #openstack-barbican | 20:28 | |
*** edtubill has quit IRC | 20:30 | |
*** su_zhang has quit IRC | 20:33 | |
*** su_zhang has joined #openstack-barbican | 20:33 | |
*** kebray has joined #openstack-barbican | 20:40 | |
*** kebray has quit IRC | 20:40 | |
*** kebray has joined #openstack-barbican | 20:47 | |
*** su_zhang has quit IRC | 20:50 | |
arunkant | woodster_ : Can you please check https://review.openstack.org/#/c/263972/ if it answers your review comments. | 20:58 |
jhfeng | redrobot: on barbican-manage cmd bp https://review.openstack.org/#/c/253719/, please have a look see if it's worth in Mitaka. if yes, just need workflow | 20:58 |
redrobot | jhfeng lgtm | 20:58 |
arunkant | alee: Same for you..https://review.openstack.org/#/c/263972/ . Can you please check if your earlier review comments response and latest patch. | 20:59 |
openstackgerrit | Merged openstack/barbican-specs: Adding a barbican-manage command https://review.openstack.org/253719 | 21:00 |
*** rellerreller has quit IRC | 21:01 | |
arunkant | rellerreller: please check my earlier messages in IRC above about key wrapping. Let me know if there are any further questions around it. | 21:01 |
*** kebray has quit IRC | 21:03 | |
jkf | redrobot: Can you take a look at this bugfix and give me a stamp of approval? Been trying to get this merged for a few weeks now. https://review.openstack.org/#/c/270572 | 21:05 |
jkf | That's in regards to the padding bug found in my new pkcs11 code. | 21:05 |
*** tkelsey has joined #openstack-barbican | 21:05 | |
*** kebray has joined #openstack-barbican | 21:06 | |
jhfeng | jkf: +1, it's needed for migration | 21:09 |
*** silos has quit IRC | 21:09 | |
*** tkelsey has quit IRC | 21:10 | |
*** kebray has quit IRC | 21:12 | |
*** kebray has joined #openstack-barbican | 21:14 | |
*** kebray has quit IRC | 21:17 | |
*** su_zhang has joined #openstack-barbican | 21:21 | |
*** nsun__ has joined #openstack-barbican | 21:23 | |
*** su_zhang has quit IRC | 21:26 | |
*** silos has joined #openstack-barbican | 21:26 | |
*** su_zhang has joined #openstack-barbican | 21:30 | |
*** jaosorior has quit IRC | 21:38 | |
*** nsun__ has quit IRC | 21:57 | |
*** jhfeng has quit IRC | 21:58 | |
*** jhfeng has joined #openstack-barbican | 22:07 | |
openstackgerrit | Fernando Diaz proposed openstack/barbican: Introduce User-Meta table, model, and repo https://review.openstack.org/270963 | 22:08 |
openstackgerrit | Fernando Diaz proposed openstack/barbican: WIP: User Metadata API and tests https://review.openstack.org/275885 | 22:10 |
*** jaosorior has joined #openstack-barbican | 22:12 | |
*** nelsnelson has quit IRC | 22:36 | |
*** diazjf has quit IRC | 22:36 | |
*** edtubill_ has quit IRC | 22:39 | |
*** silos has quit IRC | 22:41 | |
*** dimtruck is now known as zz_dimtruck | 22:53 | |
*** kfarr has quit IRC | 22:53 | |
*** mp1 has quit IRC | 23:00 | |
*** mragupat_ has quit IRC | 23:02 | |
*** jhfeng has quit IRC | 23:05 | |
*** jaosorior has quit IRC | 23:06 | |
*** nelsnelson has joined #openstack-barbican | 23:23 | |
*** alee has quit IRC | 23:27 | |
*** zz_dimtruck is now known as dimtruck | 23:27 | |
*** dimtruck is now known as zz_dimtruck | 23:28 | |
*** spotz is now known as spotz_zzz | 23:47 | |
*** alee has joined #openstack-barbican | 23:49 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!