*** noslzzp has quit IRC | 00:30 | |
*** noslzzp has joined #openstack-barbican | 00:30 | |
*** catintheroof has quit IRC | 00:36 | |
*** cpuga has joined #openstack-barbican | 00:55 | |
*** cpuga has quit IRC | 01:05 | |
*** cpuga has joined #openstack-barbican | 01:05 | |
*** cpuga has quit IRC | 01:09 | |
*** liujiong has joined #openstack-barbican | 01:20 | |
*** cpuga has joined #openstack-barbican | 01:27 | |
*** salmankhan has joined #openstack-barbican | 02:16 | |
*** salmankhan has quit IRC | 02:38 | |
*** cpuga has quit IRC | 02:44 | |
*** cpuga has joined #openstack-barbican | 02:45 | |
*** cpuga_ has joined #openstack-barbican | 03:50 | |
*** cpuga has quit IRC | 03:53 | |
*** cpuga has joined #openstack-barbican | 03:54 | |
*** cpuga__ has joined #openstack-barbican | 03:56 | |
*** cpuga_ has quit IRC | 03:58 | |
*** cpuga has quit IRC | 03:59 | |
*** jaosorior_away has quit IRC | 04:44 | |
*** dimtruck is now known as zz_dimtruck | 05:03 | |
*** jaosorior has joined #openstack-barbican | 05:16 | |
*** salmankhan has joined #openstack-barbican | 05:52 | |
*** salmankhan has quit IRC | 05:57 | |
*** pcaruana has joined #openstack-barbican | 05:57 | |
*** pcaruana|afk| has joined #openstack-barbican | 06:11 | |
*** pcaruana has quit IRC | 06:12 | |
*** pcaruana|afk| has quit IRC | 06:12 | |
*** pcaruana has joined #openstack-barbican | 06:13 | |
*** cpuga__ has quit IRC | 06:16 | |
*** cpuga has joined #openstack-barbican | 06:16 | |
*** cpuga has quit IRC | 06:16 | |
*** cpuga has joined #openstack-barbican | 06:17 | |
*** cpuga has quit IRC | 06:17 | |
*** chlong has quit IRC | 06:23 | |
*** hieulq has quit IRC | 06:25 | |
*** hieulq has joined #openstack-barbican | 06:41 | |
*** andreas_s has joined #openstack-barbican | 06:52 | |
*** liujiong has quit IRC | 07:31 | |
*** Bjoern_ has joined #openstack-barbican | 09:03 | |
Bjoern_ | Hi folks, please could you provide me with some status for RSA-Token-Login/2FA in Horizon ? Is Mitaka able to ? Are there 3rd party tools ? Regards and thanks. | 09:05 |
---|---|---|
*** zz_dimtruck is now known as dimtruck | 11:30 | |
*** chlong has joined #openstack-barbican | 12:00 | |
*** dave-mccowan has joined #openstack-barbican | 12:42 | |
*** dave-mccowan has quit IRC | 12:47 | |
*** dave-mccowan has joined #openstack-barbican | 12:47 | |
*** salmankhan has joined #openstack-barbican | 12:52 | |
*** salmankhan has quit IRC | 12:55 | |
*** chlong has quit IRC | 13:10 | |
*** dave-mccowan has quit IRC | 13:15 | |
*** dave-mccowan has joined #openstack-barbican | 13:42 | |
*** cpuga has joined #openstack-barbican | 13:44 | |
*** dimtruck is now known as zz_dimtruck | 13:45 | |
*** cpuga_ has joined #openstack-barbican | 13:49 | |
*** cpuga has quit IRC | 13:50 | |
*** catintheroof has joined #openstack-barbican | 13:59 | |
*** salmankhan has joined #openstack-barbican | 14:00 | |
*** salmankhan has quit IRC | 14:05 | |
*** dave-mccowan has quit IRC | 14:05 | |
*** dave-mccowan has joined #openstack-barbican | 14:06 | |
*** zz_dimtruck is now known as dimtruck | 14:10 | |
*** dave-mccowan has quit IRC | 14:10 | |
*** chlong has joined #openstack-barbican | 14:23 | |
*** salmankhan has joined #openstack-barbican | 14:24 | |
*** salmankhan has quit IRC | 14:29 | |
*** catintheroof has quit IRC | 14:36 | |
*** catintheroof has joined #openstack-barbican | 15:02 | |
*** salmankhan has joined #openstack-barbican | 15:03 | |
*** nkinder has joined #openstack-barbican | 15:05 | |
*** andreas_s has quit IRC | 15:27 | |
*** cpuga_ has quit IRC | 15:37 | |
*** Bjoern_ has quit IRC | 15:41 | |
*** cpuga has joined #openstack-barbican | 15:41 | |
*** jaosorior is now known as jaosorior_away | 15:42 | |
*** dave-mccowan has joined #openstack-barbican | 15:42 | |
*** nkinder has quit IRC | 15:45 | |
*** salmankhan has quit IRC | 15:47 | |
*** salmankhan has joined #openstack-barbican | 15:49 | |
*** salmankhan has quit IRC | 15:52 | |
*** catintheroof has quit IRC | 15:54 | |
*** dave-mccowan has quit IRC | 16:21 | |
*** ssmith has joined #openstack-barbican | 16:25 | |
ssmith | Hello, we've gotten much further but now when creating a TERMINATED_HTTPS listener we get "Could not process TLS container https://accatl1.adaxatech.com:9311/v1/containers/c68d5b91-a86f-4a01-bbca-064e5a436737, The resource could not be found. (HTTP 404) | 16:26 |
ssmith | Neutron server returns request_ids: ['req-31d0b284-7cf7-4e2e-b634-e38cb5178817']" | 16:26 |
*** dave-mccowan has joined #openstack-barbican | 16:51 | |
*** cpuga has quit IRC | 17:03 | |
*** salmankhan has joined #openstack-barbican | 17:20 | |
*** arunkant has joined #openstack-barbican | 17:22 | |
*** arunkant_ has joined #openstack-barbican | 17:23 | |
*** salmankhan has quit IRC | 17:23 | |
*** arunkant_ has quit IRC | 17:24 | |
*** arunkant has quit IRC | 17:24 | |
*** arunkant has joined #openstack-barbican | 17:24 | |
*** arunkant_ has joined #openstack-barbican | 17:24 | |
*** salmankhan has joined #openstack-barbican | 17:25 | |
*** arunkant has quit IRC | 17:26 | |
*** arunkant_ has quit IRC | 17:26 | |
*** arunkant has joined #openstack-barbican | 17:27 | |
*** arunkant_ has joined #openstack-barbican | 17:27 | |
*** arunkant_ has quit IRC | 17:28 | |
*** cpuga has joined #openstack-barbican | 17:41 | |
*** cpuga_ has joined #openstack-barbican | 17:42 | |
*** nkinder has joined #openstack-barbican | 17:44 | |
*** alee has joined #openstack-barbican | 17:44 | |
*** cpuga has quit IRC | 17:46 | |
*** salmankhan has quit IRC | 17:46 | |
*** edtubill has joined #openstack-barbican | 17:49 | |
*** salmankhan has joined #openstack-barbican | 17:53 | |
*** salmankhan has quit IRC | 17:55 | |
*** salmankhan has joined #openstack-barbican | 18:02 | |
openstackgerrit | Kaitlin Farr proposed openstack/barbican master: Clean up a stray secret in the functional tests https://review.openstack.org/463844 | 18:15 |
openstackgerrit | Kaitlin Farr proposed openstack/barbican master: Add date filter functional tests https://review.openstack.org/436244 | 18:19 |
*** edtubill has quit IRC | 18:20 | |
*** salmankhan has quit IRC | 18:28 | |
*** dave-mccowan has quit IRC | 18:29 | |
*** dave-mccowan has joined #openstack-barbican | 18:33 | |
*** nkinder has quit IRC | 18:35 | |
*** salmankhan has joined #openstack-barbican | 18:43 | |
*** salmankhan has quit IRC | 18:47 | |
ssmith | OK, so now we've changed out the user to be "barbican" with the default project to be "service" and now getting this error "TLS container https://accatl1.adaxatech.com:9311/v1/containers/e46938eb-499d-4c5d-87f4-070d6a61b976 is invalid. Forbidden Neutron server returns request_ids: ['req-de5cde16-3828-44b0-9c30-66bcd1a176b2']" | 18:57 |
*** salmankhan has joined #openstack-barbican | 19:31 | |
*** dave-mccowan has quit IRC | 19:31 | |
*** alee has quit IRC | 19:32 | |
*** salmankhan has quit IRC | 19:35 | |
*** salmankhan has joined #openstack-barbican | 19:37 | |
*** salmankhan has quit IRC | 19:41 | |
*** catintheroof has joined #openstack-barbican | 20:08 | |
*** salmankhan has joined #openstack-barbican | 20:13 | |
*** salmankhan has quit IRC | 20:18 | |
*** salmankhan has joined #openstack-barbican | 20:19 | |
*** dimtruck is now known as zz_dimtruck | 20:21 | |
*** salmankhan has quit IRC | 20:23 | |
*** alee has joined #openstack-barbican | 20:30 | |
*** alee has quit IRC | 20:35 | |
*** salmankhan has joined #openstack-barbican | 20:37 | |
*** catintheroof has quit IRC | 20:41 | |
*** salmankhan has quit IRC | 20:41 | |
rm_work | ssmith: that's ... odd... what the heck is that error | 20:50 |
rm_work | forbidden Neutron server? >_> | 20:50 |
rm_work | ssmith: so when you say you changed out those users, what do you mean exactly | 20:51 |
rm_work | what user is configured as the service user in octavia? what user is creating the secrets in barbican? | 20:52 |
rm_work | ssmith: we actually just had a very good discussion at the summit a couple hours ago about how to improve this process, and there are a few things: | 20:52 |
rm_work | 1) Cascading ACLs will significantly reduce the number of calls | 20:52 |
rm_work | 2) Barbican allowing you to set ACLs based on a service-type and not requiring the userid will make things simpler for the end-user (and you don't have to publish your service-user name) | 20:53 |
*** pcaruana has quit IRC | 20:53 | |
rm_work | 3) Octavia may switch to using PKCS12 cert bundles as a single secret object, instead of using certificate containers at all, which greatly simplifies the process | 20:53 |
rm_work | 4) Octavia may change strategies a bit, and create the ACL itself with the user's token on the initial request (feels a little icky to me, but I guess this is true to intent, and also validates that the user has the right permissions on the secret to be sharing it with us) | 20:54 |
ssmith | rm_work: should we or do we need to run Octavia? | 20:58 |
rm_work | Ah, you are using neutron-lbaas, right | 20:58 |
rm_work | it'd be the same thing | 20:58 |
rm_work | we would make the same change | 20:58 |
ssmith | yes neutron-lbaas with barbican | 20:59 |
*** tomtomtom has joined #openstack-barbican | 20:59 | |
rm_work | but, eventually you should be running Octavia, hopefully :) | 20:59 |
rm_work | This might be a good watch: https://www.openstack.org/videos/boston-2017/octavia-load-balancing-for-openstack | 20:59 |
rm_work | Also: https://www.openstack.org/videos/boston-2017/project-update-octavia | 21:00 |
rm_work | those were our two presentations today | 21:00 |
rm_work | They address some of that | 21:00 |
tomtomtom | so to answer questions you posted to ssmith, we have neutron configured as the service_name under service_auth in neutron.conf, does that answer you question to that? | 21:05 |
tomtomtom | also the user creating the secrets in barbican is that going to be defined by the user from our openrc? | 21:05 |
tomtomtom | I've also created ACL's for the certs with barbican acl user add --user <user> <https://<href> | 21:06 |
tomtomtom | Those ACL's don't appear to do anything, I also tried changing the Project Access from True to False, however, I cannot find out what that actually even does, I can only guess it allows projects to access the certs but how does it do that? | 21:07 |
ssmith | tomtomtom and I are working togethr on this | 21:07 |
*** zz_dimtruck is now known as dimtruck | 21:11 | |
openstackgerrit | Octave Orgeron proposed openstack/barbican master: Use oslo.db for database sync and upgrade https://review.openstack.org/463865 | 21:11 |
ssmith | Also, when we created the openstack secret store we didn't use $cat cert) on the payload either. We just corrected that | 21:12 |
ssmith | Maybe the error means TLS container is invalid? | 21:13 |
*** salmankhan has joined #openstack-barbican | 21:17 | |
*** salmankhan has quit IRC | 21:18 | |
*** salmankhan has joined #openstack-barbican | 21:19 | |
*** salmankhan has quit IRC | 21:23 | |
*** salmankhan has joined #openstack-barbican | 21:35 | |
*** salmankhan has quit IRC | 21:39 | |
openstackgerrit | Kaitlin Farr proposed openstack/barbican master: Add date filter functional tests https://review.openstack.org/436244 | 21:43 |
rm_work | hmm | 21:45 |
rm_work | hmm | 21:46 |
rm_work | no, it looks like barbican is denying you | 21:46 |
rm_work | the RBAC policies might have become broken over time | 21:46 |
openstackgerrit | Kaitlin Farr proposed openstack/barbican master: Add date filter functional tests https://review.openstack.org/436244 | 21:46 |
rm_work | i wonder if that's the case | 21:46 |
rm_work | but upon re-reading the error, it makes more sense | 21:46 |
rm_work | the bit about Neutron server is on another line | 21:47 |
rm_work | the only relevant error output it's giving you is "Invalid" >_> | 21:47 |
openstackgerrit | Kaitlin Farr proposed openstack/barbican master: Add date filter functional tests https://review.openstack.org/436244 | 21:51 |
tomtomtom | @rm_work I got the listener to create with a new cert. Our only issue now would be the RBAC policies, any ideas where a working one might be? | 22:00 |
tomtomtom | I have tried to modify it myself, but I've had no luck getting the policy to work the way I wanted. | 22:00 |
rm_work | hmm | 22:01 |
rm_work | yeah i'm bad at RBAC policy myself | 22:01 |
rm_work | but if you got it to create, then it must be good | 22:01 |
tomtomtom | yeah ok, I'll see if a non-admin user can create and use a cert as well. | 22:03 |
*** cpuga_ has quit IRC | 22:12 | |
*** catintheroof has joined #openstack-barbican | 22:38 | |
*** catintheroof has quit IRC | 22:56 | |
*** catintheroof has joined #openstack-barbican | 22:57 | |
*** catintheroof has quit IRC | 22:57 | |
*** dimtruck is now known as zz_dimtruck | 23:31 | |
*** salmankhan has joined #openstack-barbican | 23:36 | |
*** salmankhan has quit IRC | 23:40 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!