*** su_zhang has joined #openstack-barbican | 00:06 | |
openstackgerrit | Tuan proposed openstack/barbican: Fix order of arguments in assertEqual https://review.openstack.org/356283 | 00:40 |
---|---|---|
*** dimtruck is now known as zz_dimtruck | 00:45 | |
*** jamielennox is now known as jamielennox|away | 00:48 | |
*** randallburt has quit IRC | 00:53 | |
*** jamielennox|away is now known as jamielennox | 01:04 | |
*** su_zhang has quit IRC | 01:21 | |
*** su_zhang has joined #openstack-barbican | 01:22 | |
*** dave-mccowan has quit IRC | 01:25 | |
*** su_zhang has quit IRC | 01:26 | |
*** zz_dimtruck is now known as dimtruck | 01:31 | |
*** hockeynut has joined #openstack-barbican | 01:41 | |
*** haplo37__ has joined #openstack-barbican | 01:50 | |
*** haplo37__ has quit IRC | 02:20 | |
*** arunkant__ has joined #openstack-barbican | 02:36 | |
*** arunkant_ has quit IRC | 02:39 | |
*** jamielennox is now known as jamielennox|away | 02:42 | |
*** hockeynut has quit IRC | 03:06 | |
*** jamielennox|away is now known as jamielennox | 03:07 | |
*** diazjf has joined #openstack-barbican | 03:31 | |
*** diazjf has quit IRC | 03:34 | |
openstackgerrit | Arun Kant proposed openstack/barbican-specs: Adding spec for supporting multiple secret store backends https://review.openstack.org/263972 | 04:26 |
*** su_zhang has joined #openstack-barbican | 04:42 | |
openstackgerrit | Arun Kant proposed openstack/barbican: Adding API docs for multiple backend support changes. https://review.openstack.org/341803 | 04:52 |
openstackgerrit | Nguyen Hung Phuong proposed openstack/barbican: Clean imports in code https://review.openstack.org/356863 | 04:53 |
openstackgerrit | Arun Kant proposed openstack/barbican: Adding multiple backend db model and repository support https://review.openstack.org/348092 | 04:53 |
openstackgerrit | Arun Kant proposed openstack/barbican: Adding central logic to manage multiple backend feature. https://review.openstack.org/354285 | 04:53 |
openstackgerrit | Arun Kant proposed openstack/barbican: Adding API docs for multiple backend support changes. https://review.openstack.org/341803 | 04:55 |
*** jaosorior has joined #openstack-barbican | 05:03 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/352315 | 05:24 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements https://review.openstack.org/352315 | 05:48 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/castellan: Updated from global requirements https://review.openstack.org/352316 | 05:48 |
*** pcaruana has joined #openstack-barbican | 06:52 | |
*** xek__ has quit IRC | 07:08 | |
openstackgerrit | Jiong Liu proposed openstack/python-barbicanclient: Use international logging message https://review.openstack.org/356979 | 07:19 |
openstackgerrit | Jiong Liu proposed openstack/castellan: Use international logging message https://review.openstack.org/356983 | 07:31 |
*** f13o has joined #openstack-barbican | 07:34 | |
*** su_zhang has quit IRC | 08:30 | |
*** su_zhang has joined #openstack-barbican | 08:31 | |
*** su_zhang has quit IRC | 08:35 | |
*** jaosorior has quit IRC | 08:37 | |
*** jsheeren has joined #openstack-barbican | 08:42 | |
*** jsheeren has quit IRC | 09:34 | |
*** lixiaoy1 has joined #openstack-barbican | 10:07 | |
*** haplo37__ has joined #openstack-barbican | 11:42 | |
*** su_zhang has joined #openstack-barbican | 11:43 | |
*** su_zhang has quit IRC | 11:48 | |
*** dave-mccowan has joined #openstack-barbican | 11:59 | |
*** woodster_ has joined #openstack-barbican | 12:10 | |
*** haplo37__ has quit IRC | 12:21 | |
*** alee has quit IRC | 12:21 | |
*** alee has joined #openstack-barbican | 13:20 | |
*** f13o has quit IRC | 13:28 | |
*** f13o has joined #openstack-barbican | 13:28 | |
*** dimtruck is now known as zz_dimtruck | 13:41 | |
*** zz_dimtruck is now known as dimtruck | 13:41 | |
*** dimtruck is now known as zz_dimtruck | 13:51 | |
*** edtubill has joined #openstack-barbican | 13:57 | |
*** arunkant__ has quit IRC | 14:07 | |
*** zz_dimtruck is now known as dimtruck | 14:10 | |
*** edtubill has quit IRC | 14:10 | |
openstackgerrit | Ade Lee proposed openstack/barbican: Add install guide https://review.openstack.org/356221 | 14:16 |
*** edtubill has joined #openstack-barbican | 14:17 | |
*** spotz_zzz is now known as spotz | 14:18 | |
*** edtubill has quit IRC | 14:20 | |
*** edtubill has joined #openstack-barbican | 14:24 | |
*** edtubill has quit IRC | 14:27 | |
*** haplo37__ has joined #openstack-barbican | 14:28 | |
*** edtubill has joined #openstack-barbican | 14:34 | |
*** su_zhang has joined #openstack-barbican | 14:39 | |
*** edtubill has quit IRC | 14:41 | |
*** edtubill has joined #openstack-barbican | 14:44 | |
*** edtubill has quit IRC | 14:47 | |
*** edtubill has joined #openstack-barbican | 14:47 | |
*** randallburt has joined #openstack-barbican | 14:54 | |
*** f13o has quit IRC | 14:54 | |
*** randallburt1 has joined #openstack-barbican | 14:56 | |
*** randallburt has quit IRC | 14:58 | |
*** edtubill has quit IRC | 14:58 | |
*** edtubill has joined #openstack-barbican | 14:59 | |
*** michauds has joined #openstack-barbican | 15:00 | |
*** hockeynut has joined #openstack-barbican | 15:04 | |
*** diazjf has joined #openstack-barbican | 15:05 | |
*** f13o has joined #openstack-barbican | 15:06 | |
*** edtubill has quit IRC | 15:09 | |
openstackgerrit | Jiong Liu proposed openstack/barbican: Fix test suite cleanup https://review.openstack.org/357277 | 15:10 |
*** edtubill has joined #openstack-barbican | 15:15 | |
*** michauds has quit IRC | 15:19 | |
*** arunkant_ has joined #openstack-barbican | 15:21 | |
*** dave-mccowan has quit IRC | 15:24 | |
*** dave-mccowan has joined #openstack-barbican | 15:24 | |
*** f13o has quit IRC | 15:25 | |
*** f13o has joined #openstack-barbican | 15:25 | |
*** su_zhang has quit IRC | 15:28 | |
*** su_zhang has joined #openstack-barbican | 15:29 | |
*** diazjf has quit IRC | 15:30 | |
*** su_zhang has quit IRC | 15:33 | |
arunkant_ | alee, redrobot: I have made changes to multiple backend spec and API docs to reflect configuration changes. Can you review them? I have also updated my implementation review as well. | 15:33 |
arunkant_ | Spec review: https://review.openstack.org/#/c/263972/ , API doc review: https://review.openstack.org/#/c/341803/ | 15:34 |
alee | arunkant, arunkant_ will do | 15:39 |
*** michauds has joined #openstack-barbican | 15:52 | |
*** edtubill has quit IRC | 15:53 | |
*** edtubill has joined #openstack-barbican | 15:55 | |
*** edtubill has quit IRC | 16:01 | |
*** diazjf has joined #openstack-barbican | 16:06 | |
*** randallburt1 has quit IRC | 16:16 | |
*** randallburt has joined #openstack-barbican | 16:18 | |
*** diazjf has quit IRC | 16:24 | |
*** michauds has quit IRC | 16:25 | |
*** tkelsey has joined #openstack-barbican | 17:00 | |
*** su_zhang has joined #openstack-barbican | 17:01 | |
*** su_zhang has quit IRC | 17:06 | |
*** su_zhang has joined #openstack-barbican | 17:07 | |
*** diazjf has joined #openstack-barbican | 17:25 | |
*** tkelsey has quit IRC | 17:39 | |
*** hockeynut has quit IRC | 17:44 | |
*** diazjf has quit IRC | 18:09 | |
*** hockeynut has joined #openstack-barbican | 18:36 | |
*** diazjf has joined #openstack-barbican | 18:36 | |
*** michauds has joined #openstack-barbican | 18:38 | |
*** randallburt has quit IRC | 18:38 | |
redrobot | woodster_ we're about to start the threat modeling exercise for barbican | 18:41 |
woodster_ | can you all do hangouts | 18:42 |
* woodster_ I understand if no, but just curious | 18:42 | |
redrobot | woodster_ https://hangouts.google.com/call/pxmriirbzfd77dj3j6uv7v66b4e | 18:43 |
woodster_ | nice, thanks! alee arunkant_ ^^^^ | 18:44 |
*** su_zhang has quit IRC | 18:44 | |
woodster_ | dave-mccowan: ^^^^ | 18:46 |
*** randallburt has joined #openstack-barbican | 18:47 | |
*** catintheroof has joined #openstack-barbican | 18:49 | |
catintheroof | guys, quick question as a cloud admin (eg. user cloudadmin, project cloudadmin) how can i do to ask for the secrets of another project ?? | 18:50 |
catintheroof | i have doubts on how secrets are stored, those are per user? per project? | 18:52 |
catintheroof | diazjf, alee, redrobot ^^^ | 18:53 |
diazjf | catintheroof, Secrets are stored per Project, so as long a user has the correct permissions they can access payloads from others within the same project. | 19:01 |
diazjf | You must be part of and have a token scoped for the other project | 19:01 |
arunkant_ | catintheroof : in general, secrets access control is managed at per project roles level. You can use ACL if user from anoter project wants to access specific secret . That user needs to be added in secret's ACL list..http://developer.openstack.org/api-guide/key-manager/acls.html | 19:11 |
catintheroof | diazjf, terrific, thanks for the clarification | 19:11 |
diazjf | catintheroof your welcome :) | 19:16 |
*** su_zhang has joined #openstack-barbican | 19:32 | |
*** dgonzalez has quit IRC | 19:34 | |
*** su_zhang has quit IRC | 19:36 | |
*** dgonzalez has joined #openstack-barbican | 19:45 | |
alee | woodster_, ping | 19:50 |
*** diazjf has quit IRC | 19:53 | |
*** su_zhang has joined #openstack-barbican | 20:01 | |
*** su_zhang has quit IRC | 20:01 | |
*** su_zhang has joined #openstack-barbican | 20:01 | |
*** f13o has quit IRC | 20:02 | |
*** diazjf has joined #openstack-barbican | 20:09 | |
*** gyee has joined #openstack-barbican | 20:11 | |
*** f13o has joined #openstack-barbican | 20:16 | |
*** diazjf has quit IRC | 20:21 | |
*** diazjf has joined #openstack-barbican | 20:31 | |
*** f13o has quit IRC | 20:34 | |
*** f13o has joined #openstack-barbican | 20:35 | |
alee | woodster_, you there? | 20:37 |
woodster_ | alee: hey Ade, listening in on the barbican threat analysis | 20:37 |
alee | woodster_, ah, thats still going - figured they were done by now | 20:37 |
alee | woodster_, that many threats? | 20:38 |
woodster_ | alee: did my comments on CR make sense? | 20:38 |
alee | woodster_, did my counter-comments? | 20:38 |
woodster_ | alee: no new threats I don't think anyway | 20:38 |
woodster_ | alee: oh I'll check them out | 20:38 |
alee | woodster_, did you build the doc and see what it looked like? | 20:39 |
alee | I think its clearer if you look at it. | 20:39 |
woodster_ | alee: so the hierarchy of plugins is the secret store level ones: KMIP, Dogtag, and the crypto-adapter. That crypto-adapter implements the next level of plugins, the crypto plugins. The crypto plugins do the 'encrypted blobs within the database' stuff. In the doc now, this description is made at the secret store plug in level. | 20:42 |
woodster_ | alee: so maybe change 'Storage Plugins' section to 'Crypto Plugins' and good enough for now perhaps? | 20:45 |
alee | woodster_, well - I called them Storage Plugins because they store the data in the local barbican database | 20:46 |
alee | woodster_, and also because the plugin is called store_crypto iirc | 20:46 |
woodster_ | alee: the only issue is that we call the top level plugins that as well. the ones that store blobs in the db are the crypto plugins | 20:47 |
* woodster_ referring to the code mostly, but also naming in the conf file | 20:47 | |
woodster_ | alee: if we think this is hair splitting and we want to get this out, that's cool. Just trying to avoid having to explain that to folks in the future if possible. | 20:49 |
woodster_ | alee: the above distinction also tracks the architectural docs out there too | 20:50 |
alee | woodster_, understood -- if we make it clear, then we wont have to explain | 20:50 |
redrobot | woodster_ alee the terms that are already in use are "Secret Store Plugin", "Cryptographic Plugin Adapter" for store_crypto and "Cryptographic Plugin" | 20:50 |
* woodster_ http://docs.openstack.org/developer/barbican/plugin/#architecture | 20:51 | |
redrobot | woodster_ alee http://docs.openstack.org/developer/barbican/plugin/index.html#architecture | 20:51 |
woodster_ | #jinx | 20:51 |
redrobot | woodster_ lol | 20:51 |
redrobot | woodster_ alee http://docs.openstack.org/developer/barbican/plugin/secret_store.html#the-cryptographic-plugin-adapter | 20:51 |
* woodster_ was hoping that would do something cool | 20:51 | |
redrobot | woodster_ alee http://docs.openstack.org/developer/barbican/plugin/crypto.html#cryptographic-plugin-development | 20:51 |
alee | woodster_, so the suggestion is to rename "Storage Plugins" to "Crypto Plugins" ? | 20:52 |
alee | woodster_, that works for me - esp as we have Simple Crypto Plugin, and PKCS#11 Crypto Plugin | 20:53 |
woodster_ | alee: I think so, but you also need to add bits to Dogtag and KMIP configs...let me add to the CR.... | 20:53 |
alee | woodster_, eh? | 20:54 |
alee | woodster_, did you build it? | 20:54 |
alee | woodster_, are you adding more comments -- or are we all good? | 21:00 |
alee | woodster_, gotta meet some folks for dinner and want to push out these edits before I go .. | 21:01 |
woodster_ | alee: nope, so does that put 'enabled_secret_store_plugins = dogtag_crypto' or 'enabled_secret_store_plugins = kmip_crypto' lines in there? | 21:01 |
woodster_ | alee: my local env is borked right now, but if those lines are showing up in the dogtag and kmip sections, that's cool | 21:02 |
alee | oh - good catch -- defineitly need those .. | 21:02 |
alee | adding .. | 21:02 |
woodster_ | nice! | 21:02 |
alee | woodster_, actually all that is going to change anyways .. | 21:03 |
alee | but thats anther discussion ... | 21:03 |
woodster_ | alee: yeah well a snapshot in time, like all docs | 21:03 |
*** beisner is now known as beisner-biab | 21:05 | |
openstackgerrit | Ade Lee proposed openstack/barbican: Add install guide https://review.openstack.org/356221 | 21:09 |
alee | woodster_, redrobot diazjf - thar she goes ^^ | 21:10 |
* alee heading to dinner | 21:10 | |
woodster_ | alee: looking... | 21:10 |
*** hockeynut has quit IRC | 21:12 | |
*** catintheroof has quit IRC | 21:21 | |
*** beisner-biab is now known as beisner | 21:28 | |
*** dave-mccowan has quit IRC | 21:38 | |
*** spotz is now known as spotz_zzz | 21:50 | |
*** dave-mccowan has joined #openstack-barbican | 22:01 | |
*** dave-mccowan has quit IRC | 22:18 | |
*** su_zhang has quit IRC | 22:23 | |
*** dave-mccowan has joined #openstack-barbican | 22:24 | |
*** su_zhang has joined #openstack-barbican | 22:29 | |
*** ntpttr has quit IRC | 22:31 | |
*** su_zhang has quit IRC | 22:33 | |
*** diazjf has quit IRC | 22:34 | |
*** ntpttr has joined #openstack-barbican | 22:36 | |
*** su_zhang has joined #openstack-barbican | 22:38 | |
*** haplo37__ has quit IRC | 23:03 | |
*** dimtruck is now known as zz_dimtruck | 23:06 | |
*** michauds has quit IRC | 23:07 | |
*** f13o has quit IRC | 23:12 | |
*** chlong has quit IRC | 23:20 | |
openstackgerrit | Arun Kant proposed openstack/barbican: Adding multiple backend conf changes and friendly plugin names https://review.openstack.org/354285 | 23:50 |
*** randallburt has quit IRC | 23:50 | |
openstackgerrit | Arun Kant proposed openstack/barbican: Adding central logic to sync secret store data with conf data https://review.openstack.org/357544 | 23:50 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!