*** liujiong has joined #openstack-barbican | 00:50 | |
*** openstackgerrit has joined #openstack-barbican | 01:01 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican master: Updated from global requirements https://review.openstack.org/551453 | 01:01 |
---|---|---|
*** liujiong has quit IRC | 01:08 | |
*** liujiong has joined #openstack-barbican | 01:16 | |
*** namnh has joined #openstack-barbican | 01:39 | |
*** annp has joined #openstack-barbican | 02:13 | |
alee | barbican weekly meeting starting in a few minutes .. | 02:59 |
alee | #startmeeting barbican | 03:00 |
openstack | Meeting started Tue Mar 13 03:00:13 2018 UTC and is due to finish in 60 minutes. The chair is alee. Information about MeetBot at http://wiki.debian.org/MeetBot. | 03:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 03:00 |
*** openstack changes topic to " (Meeting topic: barbican)" | 03:00 | |
openstack | The meeting name has been set to 'barbican' | 03:00 |
alee | #topic roll call | 03:00 |
*** openstack changes topic to "roll call (Meeting topic: barbican)" | 03:00 | |
liujiong | hi alee | 03:00 |
alee | hello :) | 03:00 |
dave-mccowan | o/ | 03:01 |
liujiong | finally, I get chance to attend our weekly meeting | 03:01 |
alee | hi dave-mccowan | 03:01 |
liujiong | hi dave-mccowan | 03:01 |
dave-mccowan | hello all | 03:01 |
dave-mccowan | namnh ping | 03:01 |
namnh | dave-mccowan: pong | 03:01 |
alee | namnh, its the barbican weekly meeting now in case you'd like to join | 03:02 |
namnh | alee: yes, i'm going to join it | 03:02 |
alee | namnh, good to see you here | 03:03 |
alee | welcome everyone - good to see a good attendance for our new time | 03:04 |
alee | we'll keep it at this time from now onwards | 03:04 |
alee | #topic rocky | 03:05 |
*** openstack changes topic to "rocky (Meeting topic: barbican)" | 03:05 | |
alee | I have collected some thoughts on what could be our focuses in rocky | 03:05 |
alee | https://etherpad.openstack.org/p/barbican-tracker-rocky | 03:05 |
alee | as well as various important dates. | 03:06 |
openstackgerrit | Rajat Sharma proposed openstack/barbican master: [WIP]Retrieving DER DSA keys https://review.openstack.org/551967 | 03:06 |
alee | If there is anything else you'd like to add, or comment on, please go ahead | 03:06 |
alee | rajat__, hello :) | 03:07 |
alee | please add any bugs that concern youin particular to the list at the bottom as well. | 03:07 |
alee | I have not had a chance to go trough the bugs yet - but knowing which ones folks are working on/ or are affected by will help. | 03:08 |
alee | any questions /concerns/ comments? | 03:09 |
liujiong | ok | 03:09 |
namnh | yes, got it | 03:10 |
alee | cool | 03:10 |
dave-mccowan | do we want to try to match work items to milestones? i like deadlines to help prioritize work. it'll also help to know which items need high priority reviews, etc. | 03:10 |
alee | dave-mccowan, that dos sound like a good idea -- it would also be nice to match works items with folks too. | 03:11 |
alee | all, are there work items that folks would like to sign up for? or others they'd like to propose | 03:12 |
alee | ? | 03:12 |
alee | that way we can see who will work on various things through | 03:13 |
alee | i would also be nice to get any new specs written by milestone one too | 03:13 |
alee | dave-mccowan, certainly though I think though we can try to get all the queens carry-ovwer work done by milestone 1 | 03:14 |
alee | dave-mccowan, namnh is that possible? | 03:14 |
dave-mccowan | alee i'll commit to the three client item for m-1. | 03:16 |
alee | namnh, I know you've been waiting on reviews -- are there further patches needed afterwards for rolling upgrades? | 03:16 |
namnh | alee: well, i try my best to update OVO but there are so many unit-test need to be updated. | 03:17 |
alee | namnh, is milestone 2 a more realistic target? | 03:18 |
namnh | alee: i will trying my best | 03:18 |
namnh | alee: i will try my best | 03:18 |
alee | I do plan to review your existing patch very soon - hopefully this week | 03:18 |
alee | namnh, all we can ask for :) | 03:19 |
alee | lets put milestone 2 for now and see how it goes .. | 03:19 |
namnh | alee: yes | 03:19 |
alee | if anyone is interested in any other topics/ features on the list, please fill in and propose milestone | 03:21 |
alee | or any other features they would like to work on | 03:21 |
alee | any other comments/questions on this topic? | 03:22 |
alee | #topic intros | 03:23 |
*** openstack changes topic to "intros (Meeting topic: barbican)" | 03:23 | |
*** rajat_ has joined #openstack-barbican | 03:24 | |
alee | I should have lead with this - but given that this is the first time we're having this meting at this time, | 03:24 |
alee | we are probably chatting for the first time with a few folks. | 03:24 |
alee | I'm particlatrly interested in what your interest in barbican is, whether you're using it and how, and what you'e interested in | 03:25 |
alee | I guess I'll start .. | 03:25 |
alee | I'm Ade Lee (PTL). I work for Red Hat . anwe;ll be releasing Barbican as part of OSP 13 very soon | 03:26 |
alee | so I have been working on integration of Barbican with tripleo | 03:26 |
alee | and will be working on doing things like performace testing esecially against the pkcs11 and dogtag plugins | 03:27 |
*** tajar has quit IRC | 03:27 | |
alee | and getting more inegration scenarios in place. | 03:27 |
alee | one of the things that might happen in the triple-o space is that we may put barbica in the undercloud to hndle secrets there | 03:28 |
alee | I'm also keeping tabs in the ongoing castellan /oslo integration work. | 03:28 |
alee | ok -- next up? | 03:28 |
alee | dave-mccowan, ? | 03:29 |
alee | namnh, liujiong , rajat_ ? | 03:31 |
liujiong | so i'll be the next one | 03:31 |
liujiong | I'm Jeremy Liu, work for GohighSec in China, a company aims to enhance security in cloud computing | 03:32 |
alee | liujiong, hey Jeremy - do you guys have deployments with barbican? | 03:33 |
liujiong | Recently, we've been integrating SGX with barbican to provide secure communication channel/secret transportation. | 03:33 |
alee | oh nice! | 03:34 |
dave-mccowan | i'm Dave. My focus is cloud security at my company. I started contributing to Barbican a few years ago and have been PTL and a core reviewer. I see Barbican as instrumental in OpenStack to enable data encryption. My company's offerings do not currently include Barbican, but I hope we can include it soon. (Support in OSP 13 will help.) | 03:34 |
dave-mccowan | liujiong Is there much extra code to use SGX? can that code be committed back to OpenStack? | 03:35 |
liujiong | That work is mostly a PoC, there's much to improve | 03:36 |
namnh | I am Nam, from Fujitsu VN which is IT company. For now, I am focusing on rolling upgrade for Barbican and i hope that i can implement this interesting feature. | 03:36 |
namnh | for Barbican | 03:36 |
alee | namnh, does your company use barbican? | 03:37 |
namnh | Yes, we do | 03:37 |
alee | do you guys use it with an hsm or other backend? | 03:37 |
alee | or just with simple crypto | 03:38 |
alee | ? | 03:38 |
namnh | i am not sure about this information. maybe HSM | 03:39 |
alee | namnh, just curious :) | 03:39 |
namnh | For now, Fujitsu Japan is using Barbican, that company is parent of Fujitsu VN | 03:40 |
alee | I'd like to try to find out if anyone is actually using barbican in production with an HSM so we can actually make sure its well tested | 03:40 |
alee | namnh, are there other features you're interested in - once we wrap up rolling upgrades? | 03:41 |
namnh | alee: ok, i will ask Fujitsu Japan about use-cases | 03:42 |
namnh | :)) all of my effort are focusing on rolling-upgrade | 03:42 |
alee | namnh, cool - that would be great to know. | 03:42 |
namnh | alee: ^^ | 03:43 |
alee | anyone else for intros? | 03:43 |
alee | rajat_, ? | 03:43 |
namnh | sorry, but "intros?", what do that mean? | 03:43 |
namnh | introduction? | 03:44 |
alee | yup introductions | 03:44 |
namnh | :) thanks | 03:44 |
alee | np:) | 03:45 |
alee | #topic sgx | 03:45 |
*** openstack changes topic to "sgx (Meeting topic: barbican)" | 03:45 | |
alee | liujiong, I'm pretty interested in the sgx stuff. | 03:46 |
alee | neat to know that you're working on it | 03:46 |
alee | I've seen the code, but yeah - its all poc -- and needs work to actually get it into the upsteam barbican | 03:47 |
liujiong | yeah, much to improve to meet upstream requirements | 03:47 |
liujiong | and deployment requirements | 03:48 |
alee | liujiong, would you guys be interested in taking some of that on? | 03:49 |
alee | I know its a lot, and the intel guys seem to want to throw it over the wall as it were. | 03:49 |
liujiong | yes, I do, but not sure for R cycle | 03:50 |
alee | yeah I think it would be too much for that. | 03:50 |
alee | would be really useful though - especially if you add the attestation bits as well | 03:51 |
liujiong | yup, we tested RA feature | 03:51 |
liujiong | works fine | 03:51 |
alee | good to know .. | 03:52 |
dave-mccowan | SGX could be a good Forum talk at summit | 03:52 |
alee | I know they have proposed a talk at the summit -- if that gets accepted, we can certainly open a forum talk for them there too. | 03:53 |
alee | I'll continue to let them know that folks are interested and trying their stuff out .. | 03:54 |
liujiong | cool | 03:54 |
alee | #topic anything else? | 03:54 |
*** openstack changes topic to "anything else? (Meeting topic: barbican)" | 03:54 | |
alee | any other topics? | 03:54 |
namnh | yes | 03:55 |
namnh | https://review.openstack.org/#/c/547120/ | 03:55 |
namnh | For there are a error during upgrade Barbican database with maridbdb 10.2.12 | 03:55 |
liujiong | that's all from me, and it's lunch time, thank you all for this meeting | 03:55 |
alee | liujiong, thats Jeremy! | 03:56 |
alee | thanks | 03:56 |
namnh | I already checkit, it will be fixed at mariadb 10.2.13 | 03:56 |
*** dave-mccowan has quit IRC | 03:56 | |
alee | namnh, oh - thats really good to know --I've been trying to reproduce this | 03:56 |
alee | namnh, whats the issue in mariadb 10.2.12? | 03:57 |
namnh | here is the bug which was fixed at 10.2.13 | 03:58 |
namnh | https://jira.mariadb.org/browse/MDEV-13508 | 03:58 |
alee | namnh, nice detctive work -- I see a koji build https://koji.fedoraproject.org/koji/buildinfo?buildID=1054329 | 03:59 |
alee | for 10.2.13-2 -- so maybe that update is not pushed yet? | 04:00 |
*** daidv has joined #openstack-barbican | 04:01 | |
namnh | yes, i check in devstack.log in gate barbican-dogtag-devstack-functional-fedora-27 | 04:01 |
namnh | it is using mariadb 10.2.12 | 04:02 |
namnh | http://logs.openstack.org/20/547120/2/check/barbican-dogtag-devstack-functional-fedora-27/8f93ca1/logs/devstacklog.txt.gz | 04:02 |
alee | namnh, ok - thanks for tracking down the issue -- I can follow up with the maintainer for mariadb to find out the status of the update - and maybe get it pushed out sooner rather than later | 04:03 |
alee | cheecking bodhi | 04:04 |
alee | namnh, https://bodhi.fedoraproject.org/updates/FEDORA-2018-00647ae0d5 | 04:06 |
alee | namnh, so shoudl go to stable in looks like 3 days | 04:07 |
namnh | alee: yes, i just need to wait for now, right? | 04:08 |
alee | which should hopefully resolve this issue | 04:08 |
alee | namnh, I think so :) | 04:08 |
alee | namnh, I can check wth the maintainer if we need to hurry it up - do we? | 04:08 |
namnh | alee: i think no need :0 | 04:10 |
alee | cool - nice figuring it out :) | 04:10 |
alee | any other business? | 04:10 |
namnh | that's all to me | 04:10 |
namnh | :) | 04:11 |
alee | thank for coming, all ! see ya next week ! | 04:11 |
alee | #endmeeting | 04:11 |
*** openstack changes topic to "Discussion about development of OpenStack Barbican and its client libraries. - Logs: http://eavesdrop.openstack.org/irclogs/%23openstack-barbican/" | 04:11 | |
openstack | Meeting ended Tue Mar 13 04:11:17 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 04:11 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-03-13-03.00.html | 04:11 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-03-13-03.00.txt | 04:11 |
openstack | Log: http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-03-13-03.00.log.html | 04:11 |
namnh | alee: bye for now | 04:12 |
alee | namnh, thanks - bye for now -- | 04:12 |
* alee going to bed :) | 04:12 | |
namnh | alee: :)) thank you so much for your changing time. it's good to me, but not good to you :(( | 04:13 |
alee | namnh, can you update the review to indicate your findings? so that others know what we're waiting for .. | 04:14 |
alee | namnh, no prob - I'm usually up late | 04:14 |
namnh | sure, i will | 04:14 |
alee | cool | 04:14 |
alee | I'll keep an eye on that update | 04:15 |
namnh | :)) | 04:16 |
*** daidv has quit IRC | 04:22 | |
*** daidv has joined #openstack-barbican | 04:22 | |
*** rajat__ has quit IRC | 05:08 | |
*** jaosorior has quit IRC | 05:22 | |
*** dpawar has joined #openstack-barbican | 05:24 | |
*** daidv has quit IRC | 06:04 | |
*** pbourke has quit IRC | 06:28 | |
*** pbourke has joined #openstack-barbican | 06:29 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican master: Updated from global requirements https://review.openstack.org/551453 | 06:47 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/barbican-tempest-plugin master: Updated from global requirements https://review.openstack.org/536305 | 06:47 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/castellan master: Updated from global requirements https://review.openstack.org/552308 | 06:48 |
*** jaosorior has joined #openstack-barbican | 07:02 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-barbicanclient master: Updated from global requirements https://review.openstack.org/545552 | 07:24 |
*** pcaruana has joined #openstack-barbican | 07:42 | |
*** liujiong has quit IRC | 09:07 | |
*** mburrows has quit IRC | 09:30 | |
*** namnh has quit IRC | 09:58 | |
*** salmankhan has joined #openstack-barbican | 10:12 | |
openstackgerrit | Rajat Sharma proposed openstack/python-barbicanclient master: Trouble accessing generated DSA keys https://review.openstack.org/552473 | 10:43 |
*** pcaruana has quit IRC | 10:45 | |
*** dpawar has quit IRC | 10:49 | |
*** dave-mccowan has joined #openstack-barbican | 11:43 | |
*** dpawar has joined #openstack-barbican | 11:43 | |
*** dpawar has quit IRC | 11:50 | |
*** noslzzp has joined #openstack-barbican | 12:00 | |
*** raildo has joined #openstack-barbican | 12:04 | |
*** annp has quit IRC | 12:07 | |
*** salmankhan has quit IRC | 12:12 | |
*** salmankhan has joined #openstack-barbican | 12:27 | |
*** zhurong has joined #openstack-barbican | 12:35 | |
*** zhurong has quit IRC | 12:42 | |
*** zhurong has joined #openstack-barbican | 12:45 | |
*** zhurong has quit IRC | 13:15 | |
*** jaosorior has quit IRC | 13:19 | |
*** jaosorior has joined #openstack-barbican | 13:55 | |
*** jaosorior has quit IRC | 15:34 | |
*** noslzzp has quit IRC | 16:33 | |
*** noslzzp has joined #openstack-barbican | 17:39 | |
*** pbourke has quit IRC | 17:42 | |
*** salmankhan has quit IRC | 18:08 | |
*** jaosorior has joined #openstack-barbican | 18:25 | |
*** AnnabailEBT7FR has joined #openstack-barbican | 19:34 | |
*** AnnabailEBT7FR has quit IRC | 19:36 | |
*** raildo has quit IRC | 19:58 | |
*** mburrows has joined #openstack-barbican | 20:52 | |
*** mburrows has quit IRC | 21:31 | |
*** mburrows has joined #openstack-barbican | 21:31 | |
*** noslzzp has quit IRC | 22:02 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!