*** diazjf has joined #openstack-barbican | 00:28 | |
*** chlong has joined #openstack-barbican | 01:18 | |
*** hockeynut has quit IRC | 01:43 | |
*** woodster_ has quit IRC | 01:59 | |
*** edtubill has joined #openstack-barbican | 02:28 | |
*** dimtruck is now known as zz_dimtruck | 02:30 | |
*** jamielennox|away is now known as jamielennox | 02:41 | |
*** zz_dimtruck is now known as dimtruck | 02:47 | |
*** su_zhang has joined #openstack-barbican | 02:53 | |
*** dave-mccowan has quit IRC | 02:58 | |
*** dave-mccowan has joined #openstack-barbican | 03:02 | |
*** dimtruck is now known as zz_dimtruck | 03:02 | |
*** zz_dimtruck is now known as dimtruck | 03:23 | |
*** dave-mccowan has quit IRC | 03:41 | |
*** su_zhang has quit IRC | 03:48 | |
*** su_zhang has joined #openstack-barbican | 03:48 | |
*** su_zhang has quit IRC | 03:53 | |
*** jamielennox is now known as jamielennox|away | 04:05 | |
*** su_zhang has joined #openstack-barbican | 04:07 | |
*** diazjf has quit IRC | 04:13 | |
*** dimtruck is now known as zz_dimtruck | 04:22 | |
*** edtubill has quit IRC | 04:24 | |
*** su_zhang has quit IRC | 04:24 | |
*** su_zhang has joined #openstack-barbican | 04:24 | |
*** su_zhang has quit IRC | 04:28 | |
*** jraim has quit IRC | 04:36 | |
*** jraim has joined #openstack-barbican | 04:36 | |
*** zz_dimtruck is now known as dimtruck | 04:42 | |
*** pcaruana has quit IRC | 04:57 | |
*** cargonza has quit IRC | 05:04 | |
*** jamielennox|away is now known as jamielennox | 05:04 | |
*** cargonza has joined #openstack-barbican | 05:05 | |
*** dimtruck is now known as zz_dimtruck | 05:06 | |
*** zz_dimtruck is now known as dimtruck | 05:42 | |
*** pcaruana has joined #openstack-barbican | 06:30 | |
*** shohel has joined #openstack-barbican | 06:59 | |
*** andreas_s has joined #openstack-barbican | 07:05 | |
*** jamielennox is now known as jamielennox|away | 07:17 | |
*** nkinder has quit IRC | 07:21 | |
*** dimtruck is now known as zz_dimtruck | 07:22 | |
*** nkinder has joined #openstack-barbican | 07:24 | |
*** shohel has quit IRC | 07:38 | |
*** jaosorior has joined #openstack-barbican | 08:04 | |
*** shohel has joined #openstack-barbican | 08:10 | |
*** shohel has quit IRC | 08:11 | |
*** toabctl_ has joined #openstack-barbican | 08:57 | |
*** DandyPandy has quit IRC | 08:58 | |
*** toabctl has quit IRC | 08:58 | |
*** jgrassler has quit IRC | 08:58 | |
*** toabctl_ is now known as toabctl | 08:58 | |
*** toabctl has quit IRC | 08:59 | |
*** tkelsey has joined #openstack-barbican | 09:01 | |
*** DandyPandy has joined #openstack-barbican | 09:03 | |
*** jgrassler has joined #openstack-barbican | 09:05 | |
*** tkelsey has quit IRC | 09:05 | |
*** sigmavirus|awa is now known as sigmavirus | 10:37 | |
*** dave-mccowan has joined #openstack-barbican | 11:03 | |
*** Kevin_Zheng has quit IRC | 11:42 | |
*** Kevin_Zheng has joined #openstack-barbican | 11:56 | |
*** jaosorior has quit IRC | 12:06 | |
*** jaosorior has joined #openstack-barbican | 12:06 | |
*** alee has quit IRC | 12:16 | |
*** arunkant has quit IRC | 13:08 | |
*** su_zhang has joined #openstack-barbican | 13:15 | |
*** drico has joined #openstack-barbican | 13:15 | |
drico | Hi | 13:16 |
---|---|---|
drico | I'm trying to setup barbican for LbaaS and I get this error : | 13:16 |
drico | Could not load 'simple_certificate_event': cannot import name certificate_manager / cannot import name certificate_manager | 13:16 |
drico | I guess it's from : | 13:17 |
drico | [certificate_event] | 13:17 |
drico | namespace = barbican.certificate.event.plugin | 13:17 |
drico | enabled_certificate_event_plugins = simple_certificate_event | 13:17 |
drico | can someone tell me what this certificate_event is for ? | 13:17 |
drico | + is there any documentation to get a barbican production ready somewhere? | 13:17 |
*** alee has joined #openstack-barbican | 13:29 | |
*** openstackgerrit has quit IRC | 13:49 | |
*** openstackgerrit has joined #openstack-barbican | 13:49 | |
*** zz_dimtruck is now known as dimtruck | 14:00 | |
*** su_zhang has quit IRC | 14:01 | |
*** su_zhang has joined #openstack-barbican | 14:01 | |
*** michauds has joined #openstack-barbican | 14:03 | |
*** jaosorior has quit IRC | 14:04 | |
*** su_zhang has quit IRC | 14:06 | |
drico | apparently I have the same problem than here http://eavesdrop.openstack.org/irclogs/%23openstack-barbican/%23openstack-barbican.2016-06-15.log.html | 14:07 |
drico | barbican-keystone-listener | 14:12 |
drico | Could not load 'simple_certificate_event': cannot import name certificate_manager | 14:12 |
drico | cannot import name certificate_manager | 14:12 |
*** jmckind has joined #openstack-barbican | 14:30 | |
*** spotz_zzz is now known as spotz | 14:32 | |
*** dimtruck is now known as zz_dimtruck | 14:33 | |
*** zz_dimtruck is now known as dimtruck | 14:33 | |
*** dimtruck is now known as zz_dimtruck | 14:43 | |
*** haplo37__ has joined #openstack-barbican | 14:52 | |
*** edtubill has joined #openstack-barbican | 14:58 | |
*** pcaruana has quit IRC | 15:03 | |
*** zz_dimtruck is now known as dimtruck | 15:11 | |
*** daemontool has joined #openstack-barbican | 15:33 | |
daemontool | Hi, question: can Barican or Castellan be used to manage credentials for the Openstack services (i.e. the ones in the services.conf files_)? | 15:34 |
redrobot | hi daemontool | 15:34 |
daemontool | hi redrobot | 15:35 |
*** andreas_s has quit IRC | 15:35 | |
daemontool | old topic I know... | 15:36 |
redrobot | daemontool yes, that would be a good use case. You could store all passwords/passphrases in Barbican, then inject the keystone credentials into your service and retrieve all the relevant passwords | 15:36 |
redrobot | daemontool so instead of storing a passphrase in service.conf you'd store the barbican reference | 15:36 |
redrobot | hi drico | 15:37 |
drico | hi ! | 15:37 |
daemontool | does the services knows how to read those creds? for instance the issue mentioned here: https://bugs.launchpad.net/nova/+bug/1158328 | 15:37 |
openstack | Launchpad bug 1158328 in OpenStack Compute (nova) "passwords in config files stored in plaintext" [Wishlist,Won't fix] | 15:37 |
daemontool | that is what you are referring to right? | 15:37 |
daemontool | that is for mysql db creds for instance | 15:38 |
redrobot | daemontool yes, you could mostly solve for that bug using barbican | 15:38 |
daemontool | redrobot, brilliant, thanks | 15:39 |
daemontool | is castellan also needed to solve that? | 15:39 |
redrobot | daemontool so, castellan is an abstraction on top of barbican. it's purpose is to let people integrate with a key manager without having to take a hard dependency on barbican | 15:40 |
daemontool | ok ty | 15:40 |
redrobot | daemontool so you have to choose between using castellan or pyhton-barbicanclient directly | 15:40 |
redrobot | drico just now catching up on IRC for the day | 15:41 |
drico | yes I'm a bit lost with that issue | 15:41 |
drico | I'm using the package from ubuntu xenial for mitaka, maybe I should remove them and use some github branch | 15:42 |
redrobot | drico tbh I don't remember what the certificate event is for... I'll have to dig into the code to refresh my memory | 15:42 |
redrobot | drico we started working on installation guides during the midcycle a couple of weeks ago, so they're not quite ready yet... | 15:43 |
drico | well even if there is some draft somewhere I'll be happy to give some feedback | 15:43 |
redrobot | drico kinda barebones right now https://github.com/openstack/barbican/tree/master/install-guide/source | 15:46 |
drico | ah yes I was on it one hour ago | 15:46 |
redrobot | drico also these http://docs.openstack.org/developer/barbican/setup/index.html | 15:46 |
daemontool | redrobot, does Mitaka supports that solution? | 15:47 |
drico | yes the one on github where pretty useful | 15:47 |
redrobot | daemontool so, you'd have to make some changes in your config logic, but storage/retrieval of secret data is basically the main feature of barbican. | 15:48 |
redrobot | daemontool I think it would be cool if oslo.config supported using barbican out of the box | 15:48 |
redrobot | daemontool maybe something to talk to the oslo team about during the next summit. | 15:49 |
daemontool | redrobot, yes for the infrastructure side usage of Barbican, that'd be a huge win | 15:51 |
*** jmckind_ has joined #openstack-barbican | 15:53 | |
drico | if I try without the packages, should I go for master or the mitaka stable branch ? | 15:55 |
*** jmckind has quit IRC | 15:56 | |
redrobot | drico either one should work. we try to keep a working master at all times | 15:58 |
redrobot | drico there's a couple of new features in master that are not in mitaka | 15:58 |
redrobot | drico like filtering secrets by dates | 15:58 |
drico | well apparently the test of storing and getting a secret with curl is working | 16:03 |
drico | but not the barbican-keystone-listener | 16:04 |
drico | I'm not sure what this is for | 16:04 |
redrobot | drico so barbican-keystone-listener is an optional daemon that subscribes to the Keystone event queue | 16:04 |
redrobot | drico it's used for clean up of our database | 16:04 |
redrobot | drico for example, when a project is deleted from Keystone, an event id emitted, which the barbican-keystone-listener can act upon to make sure that the project is also deleted from our DB | 16:05 |
drico | ok I get it | 16:05 |
drico | thanks! | 16:05 |
drico | how could I check if the link between my openstack keystone and barbican is correctly working ? | 16:06 |
redrobot | drico by link do you mean authentication/authorization? | 16:06 |
drico | yes | 16:06 |
drico | my idea is to use LB as a service so I will store some SSL certificates in barbican | 16:07 |
redrobot | drico if you try to curl https://barbican_host/v1/secrets without a token you should get a 401 | 16:07 |
drico | ok so it's not ;) thanks | 16:08 |
redrobot | drico your paste config may not have the keystone-auth middleware enabled | 16:08 |
*** diazjf has joined #openstack-barbican | 16:10 | |
drico | Authentication required ! fixed it :) | 16:11 |
drico | which plugin would you recommend for a production use ? | 16:11 |
*** alee is now known as alee_lunch | 16:28 | |
*** randallburt has joined #openstack-barbican | 16:36 | |
*** su_zhang has joined #openstack-barbican | 16:36 | |
*** randallburt1 has joined #openstack-barbican | 16:37 | |
*** daemontool has quit IRC | 16:40 | |
*** randallburt has quit IRC | 16:40 | |
*** su_zhang has quit IRC | 16:41 | |
*** su_zhang has joined #openstack-barbican | 16:41 | |
*** woodster_ has joined #openstack-barbican | 16:42 | |
*** diazjf has quit IRC | 16:48 | |
*** su_zhang has quit IRC | 16:57 | |
*** su_zhang has joined #openstack-barbican | 16:58 | |
*** su_zhang has quit IRC | 16:58 | |
*** diazjf has joined #openstack-barbican | 17:02 | |
*** edtubill has quit IRC | 17:06 | |
*** diazjf has quit IRC | 17:21 | |
*** alee_lunch is now known as alee | 17:28 | |
*** su_zhang has joined #openstack-barbican | 18:13 | |
*** openstackgerrit has quit IRC | 18:18 | |
*** openstackgerrit has joined #openstack-barbican | 18:19 | |
*** diazjf has joined #openstack-barbican | 18:41 | |
*** david-lyle has quit IRC | 18:49 | |
*** su_zhang has quit IRC | 18:50 | |
*** david-lyle has joined #openstack-barbican | 18:50 | |
*** arunkant_ has joined #openstack-barbican | 19:13 | |
*** arunkant has joined #openstack-barbican | 19:18 | |
*** arunkant_ has quit IRC | 19:20 | |
*** su_zhang has joined #openstack-barbican | 19:20 | |
*** arunkant_web has joined #openstack-barbican | 19:20 | |
*** su_zhang has quit IRC | 19:25 | |
redrobot | drico hey, sorry I missed your last question | 19:29 |
redrobot | drico we highly recommend using a Hardware Security Module for production deployments. | 19:29 |
redrobot | drico in theory any HSM with a KMIP or PKCS#11 interface should work. | 19:30 |
redrobot | drico in practice, most production deployments are using Safenet Luna HSMs | 19:30 |
redrobot | drico HSMs have cool security features, like encryption keys that can't be extracted, but they are quite pricey. | 19:31 |
*** su_zhang has joined #openstack-barbican | 19:54 | |
*** gyee has joined #openstack-barbican | 20:13 | |
*** jmckind has joined #openstack-barbican | 20:30 | |
*** jmckind_ has quit IRC | 20:33 | |
*** diazjf has quit IRC | 20:38 | |
*** arunkant_web has quit IRC | 21:00 | |
*** diazjf has joined #openstack-barbican | 21:10 | |
*** diazjf has quit IRC | 21:10 | |
*** diazjf has joined #openstack-barbican | 21:19 | |
*** su_zhang has quit IRC | 21:51 | |
*** jmckind has quit IRC | 21:52 | |
*** su_zhang has joined #openstack-barbican | 21:53 | |
*** haplo37__ has quit IRC | 21:59 | |
*** michauds has quit IRC | 22:04 | |
*** randallburt1 has quit IRC | 22:11 | |
*** randallburt has joined #openstack-barbican | 22:12 | |
*** diazjf has quit IRC | 22:33 | |
*** alee has quit IRC | 22:35 | |
*** su_zhang has quit IRC | 22:50 | |
*** su_zhang has joined #openstack-barbican | 22:52 | |
*** diazjf has joined #openstack-barbican | 22:57 | |
*** diazjf has quit IRC | 23:03 | |
*** dimtruck is now known as zz_dimtruck | 23:05 | |
*** zz_dimtruck is now known as dimtruck | 23:05 | |
*** spotz is now known as spotz_zzz | 23:07 | |
*** dimtruck is now known as zz_dimtruck | 23:15 | |
*** su_zhang has quit IRC | 23:16 | |
*** randallburt has quit IRC | 23:21 | |
*** chlong has quit IRC | 23:33 | |
*** arunkant has quit IRC | 23:41 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!