*** agrebennikov has quit IRC | 00:15 | |
*** dave-mccowan has quit IRC | 00:49 | |
openstackgerrit | Kien Nguyen proposed openstack/barbican master: [WIP] Implemente OVO [8] https://review.openstack.org/501050 | 01:02 |
---|---|---|
*** liujiong has joined #openstack-barbican | 01:24 | |
*** namnh has joined #openstack-barbican | 01:28 | |
*** daidv has quit IRC | 02:37 | |
*** daidv has joined #openstack-barbican | 02:43 | |
openstackgerrit | Kien Nguyen proposed openstack/barbican master: [WIP] Implemente OVO [9] https://review.openstack.org/501086 | 03:00 |
openstackgerrit | Kien Nguyen proposed openstack/barbican master: [WIP] Implemente OVO [3] https://review.openstack.org/499419 | 03:07 |
openstackgerrit | Kien Nguyen proposed openstack/barbican master: [WIP] Implemente OVO [4] https://review.openstack.org/500244 | 03:07 |
openstackgerrit | Kien Nguyen proposed openstack/barbican master: [WIP] Implemente OVO [5] https://review.openstack.org/500745 | 03:08 |
openstackgerrit | Kien Nguyen proposed openstack/barbican master: [WIP] Implemente OVO [6] https://review.openstack.org/500890 | 03:08 |
openstackgerrit | Kien Nguyen proposed openstack/barbican master: [WIP] Implemente OVO [7] https://review.openstack.org/500896 | 03:08 |
openstackgerrit | Kien Nguyen proposed openstack/barbican master: [WIP] Implemente OVO [8] https://review.openstack.org/501050 | 03:09 |
openstackgerrit | Kien Nguyen proposed openstack/barbican master: [WIP] Implemente OVO [8] https://review.openstack.org/501050 | 03:14 |
openstackgerrit | Kien Nguyen proposed openstack/barbican master: [WIP] Implemente OVO [9] https://review.openstack.org/501086 | 03:14 |
openstackgerrit | Kien Nguyen proposed openstack/barbican master: [WIP] Implemente OVO [10] https://review.openstack.org/501101 | 03:41 |
*** pcaruana has joined #openstack-barbican | 05:27 | |
*** serlex has joined #openstack-barbican | 07:00 | |
*** andreas_s has joined #openstack-barbican | 07:01 | |
*** serlex has quit IRC | 07:06 | |
*** serlex has joined #openstack-barbican | 07:06 | |
*** hieulq has quit IRC | 07:40 | |
*** hieulq has joined #openstack-barbican | 07:41 | |
*** liujiong_lj has joined #openstack-barbican | 08:23 | |
*** liujiong has quit IRC | 08:23 | |
*** jaosorior has quit IRC | 08:27 | |
*** openstackgerrit has quit IRC | 09:18 | |
*** jaosorior has joined #openstack-barbican | 10:14 | |
*** pbourke has quit IRC | 11:33 | |
*** pbourke has joined #openstack-barbican | 11:34 | |
*** dave-mccowan has joined #openstack-barbican | 11:40 | |
*** liujiong_lj has quit IRC | 11:40 | |
*** raildo has joined #openstack-barbican | 12:00 | |
*** openstackgerrit has joined #openstack-barbican | 13:08 | |
openstackgerrit | Merged openstack/castellan master: Add releasenotes for castellan https://review.openstack.org/500667 | 13:08 |
*** catintheroof has joined #openstack-barbican | 13:29 | |
*** jaosorior has quit IRC | 13:41 | |
*** jaosorior has joined #openstack-barbican | 13:58 | |
*** jaosorior_ has joined #openstack-barbican | 14:09 | |
*** aspiers has quit IRC | 14:21 | |
*** agrebennikov has joined #openstack-barbican | 14:32 | |
*** aspiers has joined #openstack-barbican | 14:33 | |
*** andreas_s_ has joined #openstack-barbican | 15:02 | |
*** andreas_s has quit IRC | 15:05 | |
*** diazjf has joined #openstack-barbican | 15:25 | |
*** andreas_s_ has quit IRC | 15:35 | |
*** rmascena has joined #openstack-barbican | 15:38 | |
*** raildo has quit IRC | 15:41 | |
*** rmascena is now known as raildo | 15:42 | |
*** dave-mccowan has quit IRC | 16:17 | |
*** jaosorior has quit IRC | 16:18 | |
*** dave-mccowan has joined #openstack-barbican | 16:38 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/castellan master: Updated from global requirements https://review.openstack.org/497019 | 16:54 |
*** dave-mccowan has quit IRC | 16:56 | |
*** dave-mccowan has joined #openstack-barbican | 16:56 | |
*** jaosorior_ has quit IRC | 17:05 | |
*** serlex has quit IRC | 17:32 | |
*** randomhack has joined #openstack-barbican | 17:32 | |
randomhack | if we decide to put in an HSM later, how would this affect the keys stored using the simplecrypto plugin? is it possible to convert the mkek to HSM storage without corrupting all of the keys? | 17:35 |
*** mriedem has joined #openstack-barbican | 17:43 | |
mriedem | castellan 0.13.0 breaks cinder https://bugs.launchpad.net/castellan/+bug/1715451 | 17:43 |
openstack | Launchpad bug 1715451 in Cinder "Castellan 0.13.0 doesn't work with ConfKeyManager due to missing list() abstract method" [Undecided,New] | 17:43 |
randomhack | I see there was a blueprint for creating a migration tool and it describes the behavior fairly well. https://specs.openstack.org/openstack/barbican-specs/specs/liberty/add-crypto-mkek-rotation-support-lightweight.html | 17:48 |
*** mriedem has left #openstack-barbican | 17:49 | |
randomhack | It seems that a KEKDatum entry is created for each project which determines the active crypto plugin. If a project was created before an HSM was added, it is my understanding from the link that the project KEK will never be converted to use the HSM/pkcs11 crypto plugin, hence the need for that migration tool. | 17:54 |
*** randomhack has quit IRC | 18:18 | |
*** randomhack has joined #openstack-barbican | 18:25 | |
*** jaosorior has joined #openstack-barbican | 18:30 | |
randomhack | Ahh it appears that you can rewrap project mkek's with the barbican-manage utility. But it seems to be focused on rotating an existing HSM MKEK and not converting from simplecrypto to PKCS11 type crypto. | 18:53 |
*** jaosorior has quit IRC | 18:53 | |
*** catinthe_ has joined #openstack-barbican | 19:04 | |
*** catintheroof has quit IRC | 19:06 | |
*** catintheroof has joined #openstack-barbican | 19:06 | |
*** catinthe_ has quit IRC | 19:10 | |
*** diazjf has quit IRC | 19:11 | |
*** pcaruana has quit IRC | 19:34 | |
*** diazjf has joined #openstack-barbican | 19:35 | |
*** randomhack has quit IRC | 19:56 | |
*** dave-mccowan has quit IRC | 20:11 | |
*** tinwood has quit IRC | 20:22 | |
*** tinwood has joined #openstack-barbican | 20:23 | |
*** dave-mccowan has joined #openstack-barbican | 20:39 | |
*** dave-mcc_ has joined #openstack-barbican | 21:03 | |
*** dave-mccowan has quit IRC | 21:05 | |
*** randomhack has joined #openstack-barbican | 21:19 | |
*** diazjf has quit IRC | 21:19 | |
*** randomhack has quit IRC | 21:23 | |
*** catintheroof has quit IRC | 21:56 | |
*** dave-mcc_ has quit IRC | 21:57 | |
*** randomhack has joined #openstack-barbican | 22:52 | |
*** randomhack has quit IRC | 22:57 | |
*** raildo has quit IRC | 23:15 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!