Friday, 2017-03-10

*** ngupta has quit IRC00:09
*** ngupta has joined #openstack-barbican00:10
*** alee has joined #openstack-barbican00:13
*** ngupta has quit IRC00:14
*** hoangcx has joined #openstack-barbican00:22
*** catintheroof has quit IRC00:29
*** catintheroof has joined #openstack-barbican00:30
*** catintheroof has quit IRC00:30
*** jamielennox is now known as jamielennox|away00:36
*** jamielennox|away is now known as jamielennox00:37
*** catintheroof has joined #openstack-barbican00:42
*** dimtruck is now known as zz_dimtruck00:46
*** zhurong has joined #openstack-barbican00:56
*** liujiong has joined #openstack-barbican01:16
*** tdink has quit IRC01:33
*** chris_hultin is now known as chris_hultin|AWA01:34
*** agrebennikov has quit IRC02:21
openstackgerritOpenStack Proposal Bot proposed openstack/barbican master: Updated from global requirements  https://review.openstack.org/44407303:28
openstackgerritOpenStack Proposal Bot proposed openstack/castellan master: Updated from global requirements  https://review.openstack.org/44407403:28
openstackgerritOpenStack Proposal Bot proposed openstack/python-barbicanclient master: Updated from global requirements  https://review.openstack.org/43934403:37
*** noslzzp has quit IRC03:53
*** noslzzp has joined #openstack-barbican03:54
*** catintheroof has quit IRC03:57
*** catintheroof has joined #openstack-barbican03:58
*** catintheroof has quit IRC03:59
*** zz_dimtruck is now known as dimtruck04:49
openstackgerritMerged openstack/python-barbicanclient master: Change parent class of `WhenTestingCertificateOrders`  https://review.openstack.org/43814905:45
*** jaosorior has joined #openstack-barbican06:09
*** andreas_s has joined #openstack-barbican07:08
*** xek has quit IRC07:37
*** jaosorior is now known as jaosorior_breakf08:33
*** shohel has joined #openstack-barbican08:35
*** jaosorior_breakf is now known as jaosorior08:48
toabctljaosorior, hey09:06
toabctlis there anything I can do to get https://review.openstack.org/#/c/437981/ merged?09:06
jaosoriortoabctl: so, at least I would like to see the dogtag gate run09:08
jaosoriortoabctl: that last run you pointed out didn't. for some reason09:08
toabctljaosorior, but can I do anything to get it run?09:09
jaosoriortoabctl: now, it's even passed recently https://review.openstack.org/#/c/442344/ https://review.openstack.org/#/c/444073/09:09
jaosoriorand when it doesn't, it's usually a timeout https://review.openstack.org/#/c/434820/09:09
toabctljaosorior, so should I just do a recheck?09:09
jaosoriortoabctl: I did a recheck and lets see what happens there.09:10
toabctlok09:10
*** tinwood is now known as tinwood_swap09:18
*** dimtruck is now known as zz_dimtruck09:39
*** zz_dimtruck is now known as dimtruck09:39
*** dimtruck is now known as zz_dimtruck09:49
openstackgerritNam Nguyen Hoai proposed openstack/barbican master: Update barbican-worker to devstack plugin  https://review.openstack.org/44419010:04
*** zhurong has quit IRC10:10
jaosoriortoabctl: ok, it timed out, and it seems it was running the tests10:12
jaosoriorwow10:12
jaosoriorthough a lot of them failed10:12
jaosoriortoabctl: runned it again to see if it was a one-off. But if that happens again, then it seems that it breaks the dogtag config10:13
openstackgerritJeremy Liu proposed openstack/python-barbicanclient master: Refactor barbicanclient  https://review.openstack.org/40360410:20
*** liujiong has quit IRC10:23
*** openstackgerrit has quit IRC10:33
*** zz_dimtruck is now known as dimtruck10:40
*** zhubingbing_ has joined #openstack-barbican10:46
zhubingbing_hello guys10:46
zhubingbing_i can't find  /usr/lib/libCryptoki2_64.so10:46
zhubingbing_i can't find /usr/lib/libCryptoki2_64.so10:46
zhubingbing_who can help me ?10:47
*** dimtruck is now known as zz_dimtruck10:50
*** hoangcx has quit IRC10:50
*** zz_dimtruck is now known as dimtruck10:53
*** dimtruck is now known as zz_dimtruck11:02
*** liujiong has joined #openstack-barbican11:09
liujiongHi guys, do you know how can get this library "libCryptoki2_64.so" installed ?11:14
liujiongalee, jaosorior, redrobot, any idea on that ^11:16
jaosoriorliujiong: zhubingbing_: I'm not sure to be honest, but it would seem to me that it should be part of the openssl package. I don't know what distro you're trying to deploy barbican on.11:19
zhubingbing_distro  is centos7.211:20
zhubingbing_Package 1:openssl-devel-1.0.1e-60.el7_3.1.x86_64 already installed and latest version11:23
zhubingbing_Nothing to do11:23
jaosoriorlet me check11:25
jaosoriorzhubingbing_: what backend are you trying to use?11:25
zhubingbing_[secretstore]11:26
zhubingbing_namespace = barbican.secretstore.plugin11:26
zhubingbing_enabled_secretstore_plugins = store_crypto11:26
zhubingbing_[crypto]11:26
zhubingbing_namespace = barbican.crypto.plugin11:26
zhubingbing_enabled_crypto_plugins = p11_crypto11:26
zhubingbing_[p11_crypto_plugin]11:26
zhubingbing_library_path = /usr/lib/libCryptoki2_64.so11:26
jaosoriorzhubingbing_: that's the devel pacakge, what about the openssl package or the openssl-lib ?11:26
zhubingbing_login = FLe7YNP34RAV51CFVZzWoGmBvU09gvPdGIW1QjTe11:26
zhubingbing_mkek_label = kolla_master_kek11:26
zhubingbing_mkek_length = 3211:26
zhubingbing_hmac_label = kolla_hmac11:26
jaosoriorzhubingbing_: I'm not very acquainted with the p11 package to be honest11:26
zhubingbing_ openssl-devel11:27
zhubingbing_i install this package  openssl-devel11:27
zhubingbing_and i have install  openssl -lib11:27
jaosoriorzhubingbing_: but it might be that in centos it's another path https://access.redhat.com/documentation/en-US/Red_Hat_Certificate_System/8.1/html/Deploy_and_Install_Guide/using-tokens.html and not /usr/lib11:27
jaosoriorzhubingbing_: I guess it depends on the packages that your HSM provider has given you.11:28
zhubingbing_i look it11:29
zhubingbing_thanks11:29
liujiongzhubingbing_: can you check if you have "/usr/lib64/pkcs11/" on your machine11:37
*** zz_dimtruck is now known as dimtruck11:53
*** dimtruck is now known as zz_dimtruck12:03
*** catintheroof has joined #openstack-barbican12:34
*** databus23_ has joined #openstack-barbican12:53
*** zz_dimtruck is now known as dimtruck12:54
*** pkovar has joined #openstack-barbican12:55
*** andreas_s has quit IRC13:00
*** dimtruck is now known as zz_dimtruck13:04
*** kfarr has quit IRC13:24
*** dave-mccowan has joined #openstack-barbican13:33
*** zz_dimtruck is now known as dimtruck13:55
*** noslzzp has quit IRC13:58
*** openstackgerrit has joined #openstack-barbican13:58
openstackgerritKaitlin Farr proposed openstack/python-barbicanclient master: Add client list filter functionality  https://review.openstack.org/40037013:58
*** noslzzp has joined #openstack-barbican13:59
*** dimtruck is now known as zz_dimtruck14:05
*** zz_dimtruck is now known as dimtruck14:12
*** liujiong has quit IRC14:12
openstackgerritMerged openstack/python-barbicanclient master: Updated from global requirements  https://review.openstack.org/43934414:13
pkovarcould a core review this rather trivial change for me? https://review.openstack.org/#/c/422165/14:16
*** namnh has joined #openstack-barbican14:16
dave-mccowanpkovar done.  thanks for the patch!14:23
openstackgerritMerged openstack/barbican master: Correct the doc link  https://review.openstack.org/43286114:27
openstackgerritMerged openstack/castellan master: Updated from global requirements  https://review.openstack.org/44407414:28
openstackgerritMerged openstack/barbican master: Updated from global requirements  https://review.openstack.org/44407314:38
*** agrebennikov has joined #openstack-barbican14:46
*** namnh has quit IRC14:48
*** tdink has joined #openstack-barbican14:54
openstackgerritMerged openstack/python-barbicanclient master: Fix doc referencing --payload-content-type  https://review.openstack.org/42216514:58
*** catintheroof has quit IRC15:00
*** catintheroof has joined #openstack-barbican15:01
*** dimtruck is now known as zz_dimtruck15:05
*** chlong_ has joined #openstack-barbican15:15
*** jaosorior has quit IRC15:24
*** zz_dimtruck is now known as dimtruck15:36
*** chris_hultin|AWA is now known as chris_hultin15:43
*** chris_hultin is now known as chris_hultin|AWA15:52
*** chris_hultin|AWA is now known as chris_hultin15:55
*** shohel has quit IRC16:18
*** chlong_ has quit IRC16:19
*** jaosorior has joined #openstack-barbican16:34
*** jaosorior has quit IRC16:42
*** zhubingbing_ has quit IRC16:45
*** pkovar1 has joined #openstack-barbican16:54
*** pkovar has quit IRC16:56
*** catintheroof has quit IRC17:07
*** catintheroof has joined #openstack-barbican17:08
*** zhubingbing has joined #openstack-barbican17:08
redrobotzhubingbing hi!17:31
redrobotzhubingbing RE: libCryptoki2_64.so17:31
zhubingbinghi17:31
zhubingbingyes17:31
zhubingbingi don‘t find it ;)17:32
redrobotzhubingbing that library is provided by SafeNET as part of the service agreement when you purchase a SafeNET Luna SA HSM17:33
redrobotzhubingbing it's the default in our conf file because most folks using the PKCS#11 backend are usinge SafeNET Lunas17:33
zhubingbingSO17:33
redrobotzhubingbing are you using SafeNET Lunas as well?17:33
zhubingbingso i should support this17:33
zhubingbingno i don;t use safeness17:34
redrobotzhubingbing if you are using a different HSM, then your HSM vendor will provide a PKCS#11 library for you to use17:34
zhubingbingi thinks we should support safenet in kolla17:34
zhubingbinghow to install HSM?17:34
redrobotzhubingbing HSM stands for Hardware Security Module17:35
redrobotzhubingbing this is the product page by the vendor: https://safenet.gemalto.com/data-encryption/hardware-security-modules-hsms/safenet-network-hsm/17:35
zhubingbingthanks17:35
redrobotzhubingbing if I recall correctly, you need to have purchased the HSM to be able to download the SO file17:37
zhubingbing;)17:37
redrobotzhubingbing our PTL dave-mccowan is a Kolla contributor also.17:37
redrobotdave-mccowan what is the kolla policy for vendor solutions?  Not sure if you need to have SafeNET (Gemalto) support?17:38
zhubingbingi think 问17:38
zhubingbingwe should remove support SafeNET17:39
zhubingbingi think17:39
zhubingbingthanks you redrobot17:39
zhubingbingdave-mccowan17:39
zhubingbingok thanks17:40
zhubingbingI'll talk to him ;)17:40
openstackgerritKaitlin Farr proposed openstack/barbican master: Fix KMIP gate  https://review.openstack.org/43774717:41
*** zhubingbing has quit IRC17:50
*** zhubingbing has joined #openstack-barbican17:51
dave-mccowanhi zhubingbing18:06
dave-mccowanzhubingbing i think for a default configuration for barbican in Kolla, you'll need to use SimpleCrypto.  You can provide documentation to users on how to change their configuration file to use an HSM if they have one.18:07
*** sapcc-bot2 has quit IRC18:10
*** zhubingbing has quit IRC18:10
*** sapcc-bot has joined #openstack-barbican18:11
*** zhubingbing_ has joined #openstack-barbican18:22
*** zhubingbing_ has quit IRC18:42
*** zhubingbing has joined #openstack-barbican18:44
*** pkovar1 has quit IRC18:46
*** zhubingbing has quit IRC18:46
*** chlong_ has joined #openstack-barbican19:43
*** tdink has quit IRC19:46
*** tdink has joined #openstack-barbican19:47
*** dave-mccowan has quit IRC21:57
*** chlong_ has quit IRC22:21
*** catintheroof has quit IRC22:23
*** dimtruck is now known as zz_dimtruck22:26
*** Guest4533 has joined #openstack-barbican22:46
*** Guest4533 has quit IRC22:49
*** Kevin_Zheng has quit IRC22:53
*** tdink has quit IRC23:05
*** zz_dimtruck is now known as dimtruck23:20
*** dimtruck is now known as zz_dimtruck23:46
*** chris_hultin is now known as chris_hultin|AWA23:49

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!