Thursday, 2017-07-13

*** dave-mccowan has joined #openstack-barbican00:09
*** agrebennikov has joined #openstack-barbican00:09
*** liujiong has joined #openstack-barbican01:26
openstackgerritDavanum Srinivas (dims) proposed openstack/castellan master: [WIP] Vault based key manager  https://review.openstack.org/48308002:20
*** noslzzp has quit IRC03:21
*** dave-mccowan has quit IRC03:24
*** cpuga has joined #openstack-barbican03:26
*** cpuga has quit IRC03:30
*** cpuga has joined #openstack-barbican03:44
openstackgerritNam Nguyen Hoai proposed openstack/barbican-specs master: Specs rolling upgrade for Barbican  https://review.openstack.org/47261203:56
*** agrebennikov has quit IRC04:29
openstackgerritRajat Sharma proposed openstack/barbican master: switch to openstackdocs theme.  https://review.openstack.org/47925005:41
*** hieulq has quit IRC05:45
*** hieulq has joined #openstack-barbican05:46
*** pcaruana has joined #openstack-barbican06:52
*** andreas_s has joined #openstack-barbican07:36
*** cpuga has quit IRC08:18
*** salmankhan has joined #openstack-barbican09:01
*** salmankhan1 has joined #openstack-barbican09:04
*** salmankhan has quit IRC09:05
*** salmankhan1 is now known as salmankhan09:05
*** salmankhan has quit IRC10:07
*** salmankhan1 has joined #openstack-barbican10:07
*** salmankhan1 is now known as salmankhan10:09
*** liujiong has quit IRC10:22
*** raildo has joined #openstack-barbican11:06
*** dave-mccowan has joined #openstack-barbican12:01
*** catintheroof has joined #openstack-barbican12:56
openstackgerritOpenStack Proposal Bot proposed openstack/barbican master: Updated from global requirements  https://review.openstack.org/47791212:57
*** noslzzp has joined #openstack-barbican13:02
*** deep-book-gk_ has joined #openstack-barbican13:04
*** deep-book-gk_ has left #openstack-barbican13:04
openstackgerritJan Stodt proposed openstack/barbican master: WIP: PKCS11: Use correct attributes for key unwrapping  https://review.openstack.org/48338813:22
openstackgerritJan Stodt proposed openstack/barbican master: WIP: Use correct AES_GCM header in pkcs11  https://review.openstack.org/48337813:25
openstackgerritDavanum Srinivas (dims) proposed openstack/castellan master: [WIP] Vault based key manager  https://review.openstack.org/48308013:50
openstackgerritJan Stodt proposed openstack/barbican master: WIP: PKCS11: Add CKM_GENERIC_SECRET  https://review.openstack.org/48340013:54
openstackgerritJan Stodt proposed openstack/barbican master: WIP: PKCS11 key generation: Add CKM_GENERIC_KEY for generate HMAC  https://review.openstack.org/48340113:54
openstackgerritJan Stodt proposed openstack/barbican master: WIP: PoC: Implement CBC PAD as alternative to AES_GCM  https://review.openstack.org/48340414:03
openstackgerritOpenStack Proposal Bot proposed openstack/barbican master: Updated from global requirements  https://review.openstack.org/47791214:11
*** cpuga has joined #openstack-barbican14:16
*** cpuga has quit IRC14:18
*** cpuga has joined #openstack-barbican14:18
*** cpuga has quit IRC14:22
*** cpuga has joined #openstack-barbican14:41
*** cpuga has quit IRC14:44
*** cpuga has joined #openstack-barbican14:44
*** andreas_s has quit IRC14:55
*** diazjf has joined #openstack-barbican14:59
*** diazjf has quit IRC14:59
*** pcaruana has quit IRC15:38
openstackgerritPaul Bourke (pbourke) proposed openstack/castellan master: Fix retrieving barbican endpoint from service catalog  https://review.openstack.org/48345716:01
openstackgerritPaul Bourke (pbourke) proposed openstack/castellan master: Fix retrieving barbican endpoint from service catalog  https://review.openstack.org/48345716:05
*** agrebennikov has joined #openstack-barbican16:07
*** jamielennox has quit IRC16:19
openstackgerritDavanum Srinivas (dims) proposed openstack/castellan master: [WIP] Vault based key manager  https://review.openstack.org/48308016:28
*** kfarr has joined #openstack-barbican16:30
*** chlong has joined #openstack-barbican16:30
dave-mccowanhi kfarr16:31
kfarrhey dave-mccowan !16:31
*** chlong has quit IRC16:32
dave-mccowando you know what needs to be done before pike release of castellan?  release date for non-client libraries is in one week.16:32
*** chlong has joined #openstack-barbican16:34
dave-mccowankfarr (is castellan considered "non-client"?)16:34
kfarryes, it's non-client16:34
kfarrdave-mccowan I am not sure16:40
kfarrit would be nice to get this in: https://review.openstack.org/#/c/418019/616:40
kfarrbut it's only needed by the castellan-ui, which hasn't  been published yet16:40
openstackgerritPaul Bourke (pbourke) proposed openstack/castellan master: Improve docs around configuring Castellan  https://review.openstack.org/48346116:42
dave-mccowankfarr let me know if anything needs a review.16:43
dave-mccowankfarr did you notice i added you as a presenter for Barbican Workshop Part 3?16:43
kfarrdave-mccowan yes, thanks!16:44
kfarrdave-mccowan we will be sending one person, but it hasn't been decided yet16:44
kfarrit probably won't be me16:44
kfarrbut maybe whoever is going from our team could help with the presentation?16:44
dave-mccowansure, that'd be good.16:45
*** jaosorior has joined #openstack-barbican16:46
kfarrdave-mccowan did you see the vault plugin for castellan wip ??16:49
kfarrthat's exciting16:49
kfarrdims are you trying to get the vault plugin into this release?16:49
dave-mccowanyes, very cool.  RIP barbican maybe, but still very cool.16:50
dimskfarr : nope, just experimenting16:50
kfarrdims do you know if anyone is looking at adding a keystone authentication plugin to vault ?16:51
dimsdave-mccowan : why? ttx was talking about bring up barbican as base service. so i was looking at castellan and choices available16:51
dimskfarr : not that i know of16:51
kfarrokk thanks16:52
dimsthere's this one too in the queue (KMIP) https://review.openstack.org/#/c/298991/16:52
dave-mccowandims deployment choices are good.  a castellan+vault deployment wouldn't need barbican, but that's ok.  hopefully castellan+barbican+vault will also be choice (there's a WIP patch out for that too)16:54
dimsah cool16:54
dave-mccowandims for castellan+kmip and castellan+vault to work, there needs to be keystone auth plugin for kmip and vault.16:57
dimsi see. still reading docs etc. will see what they have16:58
dave-mccowandims thanks for the patch!  i know a lot of folks will be interested in getting this to work.17:00
dimsyw dave-mccowan17:03
*** raildo has quit IRC17:19
kfarrfor a proof-of-concept, it's possible to have a single set of vault credentials stored in the config file, and to use only those credentials when interacting withe key manager.  this isn't very secure, but it's a way to get around keystone auth tokens17:25
*** raildo has joined #openstack-barbican17:38
openstackgerritOctave Orgeron proposed openstack/barbican master: Use oslo.db options for database sync and upgrade  https://review.openstack.org/46386517:44
*** salmankhan has quit IRC18:00
*** jamielennox has joined #openstack-barbican18:37
*** rmascena has joined #openstack-barbican18:38
*** pcaruana has joined #openstack-barbican18:38
*** raildo has quit IRC18:40
*** rmascena has quit IRC18:44
*** raildo has joined #openstack-barbican18:45
*** jaosorior has quit IRC19:05
*** alee_ has joined #openstack-barbican19:13
*** kfarr has quit IRC19:17
*** alee_ has quit IRC19:34
*** alee_ has joined #openstack-barbican19:35
*** diazjf has joined #openstack-barbican19:46
*** pcaruana has quit IRC19:52
*** randomhack has joined #openstack-barbican19:54
randomhackso, I'm running openstack-newton and have gotten cinder, keystone, and barbican to work.  I can create luks volumes from glance images, but I cannot mount these images to any instances without getting either fixed_key not defined error or (if I set fixed_key = none in nova.conf) I get KeyError '3f23...-....-....-............' != 00000000-0000-0000-0000-0000000019:58
*** alee_ has quit IRC20:00
randomhackhttp://pasted.co/4e8a312w (my nova.conf lines specific to barbican)20:00
*** alee_ has joined #openstack-barbican20:19
*** diazjf has quit IRC20:31
*** raildo has quit IRC20:46
dave-mccowanrandomhack can check your paste link?  i get 40420:49
*** chlong has quit IRC20:52
dave-mccowanrandomhack https://docs.openstack.org/newton/config-reference/block-storage/volume-encryption.html20:55
randomhackdave-mccowan: hey, it's pasted.co/4e8a312e20:56
randomhacktypo on last character20:56
*** raildo has joined #openstack-barbican21:00
*** raildo has quit IRC21:02
randomhackdave-mccowan: nova error log from attaching volume: http://pasted.co/91119f6c21:05
openstackgerritDavanum Srinivas (dims) proposed openstack/castellan master: [WIP] Vault based key manager  https://review.openstack.org/48308021:18
*** diazjf has joined #openstack-barbican21:20
openstackgerritDavanum Srinivas (dims) proposed openstack/castellan master: [WIP] Vault based key manager  https://review.openstack.org/48308021:30
dave-mccowanrandomhack backtrace shows nova is trying to use conf_key_mgr (configured key) instead of castellan/barbican (what you want)21:38
randomhackIf I define a fixed key, it is able to mount a volume, but it's just using the fixed_key and not barbican. :/21:39
dave-mccowanrandomhack i don't think you need the [barbican] stanza in your nova.conf, and shouldn't need a fixed_line.  the only line needed is api_class.21:47
dave-mccowanrandomhack can you try it like that?  nova should be able to get everything else from the catalog21:48
*** diazjf has quit IRC21:48
*** cpuga has quit IRC21:52
randomhackI'll give it a shot21:53
*** diazjf has joined #openstack-barbican22:01
randomhackdave-mccowan: http://pasted.co/0a5424de (error output) - Still getting fixed_key not defined22:01
dave-mccowanrandomhack :-(  maybe a nova bug?  i'll give it a try tonight.  check back here tomorrow?22:03
*** alee_ has quit IRC22:04
*** alee_ has joined #openstack-barbican22:05
randomhackdave-mccowan: well, I'm running a hosted control-plane, so it's probably something to do with the control plane and data plane separation that they're doing - here's the nova startup options that it's using http://pasted.co/1d41c59822:07
randomhackplatform9.net22:08
*** diazjf has quit IRC22:09
dave-mccowanline 854 shows it's using conf_key_mgr, not castellan per nova.conf22:10
randomhackby jove, you're right.. what the heck22:14
dave-mccowanrandomhack are you sure Newton?  in ocata and before the section was called [keymgr] instead of [key_manager]22:26
dave-mccowanrandomhack nm.  the log even says key_manager22:27
randomhackdave-mccowan: they're looking into why my config override file isn't being read (pf9 support)22:36
openstackgerritDavanum Srinivas (dims) proposed openstack/castellan master: [WIP] Vault based key manager  https://review.openstack.org/48308022:51
*** alee_ has quit IRC22:52
openstackgerritDavanum Srinivas (dims) proposed openstack/castellan master: [WIP] Vault based key manager  https://review.openstack.org/48308022:53
openstackgerritDavanum Srinivas (dims) proposed openstack/castellan master: [WIP] Vault based key manager  https://review.openstack.org/48308022:57
dimskfarr : dave-mccowan : yep i have a token in the config file for now.23:01
dimskfarr  dave-mccowan : i think i now have test_vault_key_manager.py mirror exactly how test_barbican_key_manager.py is setup23:03
*** catintheroof has quit IRC23:03
dimskfarr : dave-mccowan : "tox -e functional-vault VaultKeyManagerOSLOContextTestCase" runs 33 tests23:03
*** randomhack has quit IRC23:04
*** alee_ has joined #openstack-barbican23:06
*** randomhack has joined #openstack-barbican23:20
*** randomhack has quit IRC23:27
dave-mccowandims cool. good stuff. this would be ok for a single-tenant private cloud, but without a keystone auth plugin, each user would have access to all secrets.  that's why we never got around to finishing the kmip plugin.23:30
dimsack dave-mccowan23:33
*** randomhack has joined #openstack-barbican23:34
*** randomhack has quit IRC23:44
*** randomhack has joined #openstack-barbican23:45
*** randomhack has quit IRC23:50

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!