*** chlong has joined #openstack-barbican | 00:33 | |
*** chlong has quit IRC | 00:43 | |
*** cpuga has joined #openstack-barbican | 00:43 | |
*** cpuga has quit IRC | 00:47 | |
*** zz_dimtruck is now known as dimtruck | 01:26 | |
*** liujiong has joined #openstack-barbican | 01:31 | |
*** jamielennox is now known as jamielennox|away | 01:50 | |
*** namnh has joined #openstack-barbican | 01:59 | |
*** jamielennox|away is now known as jamielennox | 02:04 | |
*** Kevin_Zheng has quit IRC | 05:07 | |
*** nkinder has quit IRC | 05:18 | |
*** nkinder has joined #openstack-barbican | 05:23 | |
*** Kevin_Zheng has joined #openstack-barbican | 06:12 | |
*** jroll has quit IRC | 06:19 | |
*** jrollen has joined #openstack-barbican | 06:19 | |
*** andreas_s has joined #openstack-barbican | 06:24 | |
*** dimtruck is now known as zz_dimtruck | 06:26 | |
*** nkinder has quit IRC | 07:24 | |
*** nkinder has joined #openstack-barbican | 07:27 | |
*** jaosorior has joined #openstack-barbican | 07:49 | |
openstackgerrit | cheng proposed openstack/barbican master: Fix enable list project_id in secrets https://review.openstack.org/463269 | 07:58 |
---|---|---|
openstackgerrit | Nam Nguyen Hoai proposed openstack/barbican master: Add guideline to upgrade for Operators https://review.openstack.org/449022 | 09:04 |
openstackgerrit | cheng proposed openstack/barbican master: Fix enable list project_id in secrets https://review.openstack.org/463269 | 09:59 |
*** liujiong has quit IRC | 10:08 | |
*** namnh has quit IRC | 10:31 | |
*** dave-mccowan has joined #openstack-barbican | 11:30 | |
*** dave-mcc_ has joined #openstack-barbican | 11:34 | |
*** dave-mccowan has quit IRC | 11:35 | |
*** jaosorior has quit IRC | 11:59 | |
*** jaosorior has joined #openstack-barbican | 12:02 | |
*** dave-mcc_ has quit IRC | 12:18 | |
*** nkinder has quit IRC | 12:22 | |
*** chlong has joined #openstack-barbican | 12:25 | |
*** Daviey has joined #openstack-barbican | 12:27 | |
*** cpuga has joined #openstack-barbican | 12:43 | |
*** zz_dimtruck is now known as dimtruck | 12:48 | |
*** chlong has quit IRC | 12:57 | |
*** databus23_ has joined #openstack-barbican | 13:08 | |
*** cpuga has quit IRC | 13:15 | |
*** cpuga has joined #openstack-barbican | 13:16 | |
*** kfarr has joined #openstack-barbican | 13:26 | |
openstackgerrit | cheng proposed openstack/barbican master: Fix enable list project_id in secrets https://review.openstack.org/463269 | 13:38 |
openstackgerrit | cheng proposed openstack/barbican master: Fix enable list project_id in secrets https://review.openstack.org/463269 | 13:40 |
*** kfarr_ has joined #openstack-barbican | 13:44 | |
*** kfarr has quit IRC | 13:45 | |
*** chlong has joined #openstack-barbican | 14:13 | |
*** andreas_s has quit IRC | 14:16 | |
*** noslzzp has joined #openstack-barbican | 14:17 | |
*** jrollen is now known as jroll | 14:18 | |
*** kfarr_ has quit IRC | 14:38 | |
*** slunkad has quit IRC | 15:02 | |
*** slunkad has joined #openstack-barbican | 15:04 | |
*** chlong has quit IRC | 15:41 | |
*** chlong has joined #openstack-barbican | 15:45 | |
*** slunkad has quit IRC | 15:50 | |
*** slunkad has joined #openstack-barbican | 15:53 | |
*** chlong has quit IRC | 15:53 | |
*** chlong has joined #openstack-barbican | 16:07 | |
*** dave-mccowan has joined #openstack-barbican | 16:10 | |
*** dave-mccowan has quit IRC | 16:22 | |
*** tinwood has quit IRC | 16:29 | |
*** rpi has quit IRC | 16:33 | |
*** rpi has joined #openstack-barbican | 16:34 | |
*** rpi has quit IRC | 16:34 | |
*** rpi has joined #openstack-barbican | 16:34 | |
*** dimtruck is now known as zz_dimtruck | 16:50 | |
*** dave-mccowan has joined #openstack-barbican | 17:06 | |
*** zz_dimtruck is now known as dimtruck | 17:15 | |
*** catintheroof has joined #openstack-barbican | 17:17 | |
*** dave-mccowan has quit IRC | 17:31 | |
*** catintheroof has quit IRC | 17:40 | |
*** jaosorior is now known as jaosorior_away | 17:43 | |
*** catintheroof has joined #openstack-barbican | 17:49 | |
*** alee has joined #openstack-barbican | 17:59 | |
*** catintheroof has quit IRC | 18:08 | |
*** dave-mccowan has joined #openstack-barbican | 18:10 | |
*** kfarr has joined #openstack-barbican | 18:17 | |
*** tinwood has joined #openstack-barbican | 18:29 | |
*** dave-mccowan has quit IRC | 18:36 | |
*** alee has quit IRC | 18:46 | |
*** alee has joined #openstack-barbican | 18:52 | |
*** alee has quit IRC | 19:02 | |
*** v1k0d3n has quit IRC | 19:15 | |
*** v1k0d3n has joined #openstack-barbican | 19:15 | |
*** kfarr has quit IRC | 19:24 | |
*** ssmith has joined #openstack-barbican | 19:50 | |
ssmith | Hello. We're on Newton and installed Barbican but it appears that a load balancer in the admin tenant can access the SSL cert? Is this normal operation? | 19:52 |
*** khomkrit1499 has joined #openstack-barbican | 19:54 | |
*** nkinder has joined #openstack-barbican | 19:54 | |
ssmith | Sorry only a load balancer in the admin tenant can access the SSL cert. | 19:55 |
*** nkinder has quit IRC | 20:08 | |
*** khomkrit1499 has quit IRC | 20:10 | |
*** khomkrit1499 has joined #openstack-barbican | 20:15 | |
*** khomkrit1499 has quit IRC | 20:15 | |
*** khomkrit1499 has joined #openstack-barbican | 20:15 | |
rm_work | ssmith: So, if you want LBaaS to access certs, the user needs to create a Barbican ACL that specifically grants the LBaaS service account permission to use it | 20:26 |
rm_work | OR, you need add a role to the octavia service account that grants it universal access to all barbican secrets (which I personally believe is a horrible idea, but depending on the deployment it might make sense) | 20:27 |
rm_work | which might require mucking with the default policy definitions | 20:27 |
johnsom | This section of the docs talks about how to do the ACL approach: https://docs.openstack.org/developer/octavia/guides/basic-cookbook.html#deploy-a-tls-terminated-https-load-balancer | 20:29 |
johnsom | We hope to make this cleaner in Pike, we are just waiting on an enhancement in barbican for cascading ACLs | 20:29 |
rm_work | johnsom: why is subnet-id required by neutronclient | 20:29 |
rm_work | when creating a member :/ | 20:29 |
rm_work | subnet is not mandatory on members, right? | 20:30 |
rm_work | even in neutron-lbaas | 20:30 |
rm_work | oops, wrong channel | 20:30 |
johnsom | Grin | 20:31 |
ssmith | rm_work: I either use barbican or openstack client to create 3 secret stores for cert, key and intermediate from cli using my username and admin tenant (but tried with env set to other tenant) then create container but only the admin tenant can see the cert. No other tenant can see it in the lBaaS UI. | 20:31 |
rm_work | ah, in the horizon UI? | 20:32 |
rm_work | I actually don't know what that looks like, I haven't used it T_T | 20:32 |
rm_work | it's supposed to list your available secret containers? | 20:33 |
rm_work | unfortunately, barbican doesn't have a way to list containers that you have a valid ACL for, since you can only get a "list" of stuff that it actually on your project :/ | 20:33 |
*** nkinder has joined #openstack-barbican | 20:39 | |
johnsom | ssmith I'm not quite following you. So you created a barbican container with cert/key/etc. using a non-admin tenant, then logged into horizon as that non-admin tenant and the container is not visible when you create a load balancer? | 20:40 |
ssmith | That's correct but it is visible under the admin tenant | 20:41 |
johnsom | Hmm, that is really strange, I don't know how it could have been stored under the admin tenant instead of your user tenant. | 20:45 |
johnsom | It doesn't look like you can see the associated project_id for a secret via the barbican API | 20:45 |
ssmith | OK, my bad. I downloaded a fresh RC file fro the tenant and it worked. The tenant can see it now but thanks for pointing me in the right direction | 20:54 |
*** khomkrit1499 has quit IRC | 21:00 | |
*** cpuga has quit IRC | 21:03 | |
*** dave-mccowan has joined #openstack-barbican | 21:12 | |
*** nkinder has quit IRC | 21:30 | |
*** cpuga has joined #openstack-barbican | 21:35 | |
*** chlong has quit IRC | 21:40 | |
*** jraim_ has quit IRC | 21:50 | |
*** jraim_ has joined #openstack-barbican | 21:50 | |
*** ssmith has quit IRC | 21:51 | |
openstackgerrit | Jackie Truong proposed openstack/barbican-tempest-plugin master: Add ephemeral disk encryption scenario test https://review.openstack.org/455459 | 21:53 |
*** dave-mccowan has quit IRC | 22:02 | |
*** cpuga has quit IRC | 23:31 | |
*** cpuga has joined #openstack-barbican | 23:32 | |
*** cpuga has quit IRC | 23:37 | |
openstackgerrit | Jackie Truong proposed openstack/barbican-tempest-plugin master: Add ephemeral disk encryption scenario test https://review.openstack.org/455459 | 23:39 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!