*** dave-mccowan has joined #openstack-barbican | 00:46 | |
alee | jmlowe_, so hows it going? | 02:15 |
---|---|---|
alee | sounds like you're making progress | 02:16 |
alee | that error sounds like a bug I fixed .. what version do you have? | 02:17 |
*** dave-mccowan has quit IRC | 02:56 | |
*** openstackgerrit has joined #openstack-barbican | 03:01 | |
openstackgerrit | Jeremy Liu proposed openstack/barbican master: Add os-testr as test dependency https://review.openstack.org/559936 | 03:01 |
*** jaosorior has joined #openstack-barbican | 04:21 | |
openstackgerrit | Jackie Truong proposed openstack/barbican-tempest-plugin master: Add certificate validation scenario tests https://review.openstack.org/515210 | 05:10 |
*** test_test has joined #openstack-barbican | 06:52 | |
*** XueFeng has joined #openstack-barbican | 06:52 | |
XueFeng | hi | 06:52 |
openstackgerrit | Andreas Jaeger proposed openstack/castellan master: Add barbican-tempest experimental job https://review.openstack.org/550984 | 07:07 |
openstackgerrit | Vu Cong Tuan proposed openstack/barbican master: Apply pep8 check to app.wsgi https://review.openstack.org/523340 | 07:37 |
*** livelace has joined #openstack-barbican | 07:40 | |
openstackgerrit | Jeremy Liu proposed openstack/barbican master: Add os-testr as test dependency https://review.openstack.org/559936 | 07:41 |
*** pcaruana has joined #openstack-barbican | 08:13 | |
*** livelace has quit IRC | 08:17 | |
*** salmankhan has joined #openstack-barbican | 08:19 | |
*** annp has quit IRC | 08:35 | |
*** annp has joined #openstack-barbican | 08:42 | |
*** salmankhan has quit IRC | 08:49 | |
*** salmankhan has joined #openstack-barbican | 09:19 | |
*** salmankhan1 has joined #openstack-barbican | 09:37 | |
*** salmankhan has quit IRC | 09:38 | |
*** salmankhan1 is now known as salmankhan | 09:38 | |
*** annp has quit IRC | 09:40 | |
*** annp has joined #openstack-barbican | 09:40 | |
*** salmankhan has quit IRC | 09:50 | |
*** salmankhan has joined #openstack-barbican | 09:59 | |
*** pbourke has joined #openstack-barbican | 10:14 | |
*** annp has quit IRC | 10:14 | |
*** annp has joined #openstack-barbican | 10:15 | |
openstackgerrit | Jeremy Liu proposed openstack/barbican master: Add os-testr as test dependency https://review.openstack.org/559936 | 10:32 |
*** annp has quit IRC | 10:36 | |
*** serlex has joined #openstack-barbican | 11:01 | |
*** abishop has joined #openstack-barbican | 11:18 | |
*** vegarl has quit IRC | 11:55 | |
*** vegarl has joined #openstack-barbican | 11:56 | |
*** raildo has joined #openstack-barbican | 11:58 | |
*** dave-mccowan has joined #openstack-barbican | 12:35 | |
*** salmankhan has quit IRC | 12:49 | |
*** salmankhan has joined #openstack-barbican | 12:50 | |
*** salmankhan has quit IRC | 12:54 | |
*** salmankhan has joined #openstack-barbican | 13:16 | |
jmlowe_ | alee: I'm on a pike release from rdo | 13:50 |
alee | jmlowe_, ok - in a meeting right no - but there is a small fix I added to master | 14:03 |
alee | jmlowe_, https://github.com/openstack/barbican/commit/0861657fc1ea2d04faad2b7180fae0d0e59fb09c | 14:07 |
jaosorior | alee: could be backported though | 14:11 |
jmlowe_ | ooh, thanks, I'll give cherry picking a try | 14:16 |
openstackgerrit | caoyuan proposed openstack/barbican master: Update auth_uri option to www_authenticate_uri https://review.openstack.org/560446 | 14:35 |
*** serlex has quit IRC | 14:50 | |
alee | jaosorior, yes - I think so | 15:29 |
alee | jaosorior, I'll open a review later today to do that | 15:29 |
*** salmankhan has quit IRC | 15:57 | |
*** randomhack has joined #openstack-barbican | 15:58 | |
*** salmankhan has joined #openstack-barbican | 15:59 | |
openstackgerrit | Doug Hellmann proposed openstack/barbican master: uncap eventlet https://review.openstack.org/560481 | 15:59 |
*** alee is now known as alee_afk | 17:12 | |
*** salmankhan has quit IRC | 17:13 | |
jmlowe_ | http://paste.openstack.org/show/718970/ | 17:32 |
*** XueFeng has quit IRC | 17:38 | |
*** test_test has quit IRC | 17:39 | |
*** pcaruana has quit IRC | 18:55 | |
*** livelace has joined #openstack-barbican | 19:12 | |
openstackgerrit | Doug Hellmann proposed openstack/barbican master: uncap eventlet https://review.openstack.org/560481 | 19:17 |
openstackgerrit | Doug Hellmann proposed openstack/barbican master: fix lower constraints https://review.openstack.org/560582 | 19:17 |
*** livelace has quit IRC | 19:45 | |
jmlowe_ | alee_afk: ^^^ | 20:05 |
*** v1k0d3n_ has joined #openstack-barbican | 20:21 | |
*** andreaf_ has joined #openstack-barbican | 20:27 | |
*** v1k0d3n has quit IRC | 20:28 | |
*** andreaf has quit IRC | 20:28 | |
*** johnsom has quit IRC | 20:28 | |
*** v1k0d3n_ is now known as v1k0d3n | 20:28 | |
*** johnsom has joined #openstack-barbican | 20:29 | |
*** andreaf_ is now known as andreaf | 20:29 | |
*** alee_afk is now known as alee | 20:30 | |
alee | jmlowe_, so that happens even with the fix I suggestd? | 20:30 |
jmlowe_ | correct | 20:30 |
alee | jmlowe_, let me see if I missed something | 20:31 |
alee | jmlowe_, are you generating a secret or storing one? | 20:33 |
jmlowe_ | I am trying to store one | 20:34 |
alee | jmlowe_, ok - from the cli? | 20:34 |
jmlowe_ | first crack at this so it's entirely possible I got something wrong | 20:34 |
jmlowe_ | yes, copied and pasted from the install doc verify operation section | 20:35 |
alee | jmlowe_, yeah - I'm wondering if the error is hapening on the dogtag side | 20:35 |
alee | jmlowe_, so is tyour dogtag instance on the same machine? at pki-tomcat? | 20:35 |
jmlowe_ | very possible, muddled through getting dogtag running in a docker container | 20:35 |
jmlowe_ | different machine in a docker container based on https://vakwetu.wordpress.com/2015/11/30/barbican-and-dogtagipa/ | 20:36 |
alee | ok so its a docker container .. lets confirm a few thigs | 20:36 |
alee | first your barbican nss cert db | 20:36 |
alee | what directory is it in? | 20:36 |
jmlowe_ | always possible I didn't get ports correct or I did the bootstrap wrong | 20:36 |
alee | ack | 20:37 |
alee | thats what I'm trying to see .. | 20:37 |
alee | jmlowe_, first lets see if dogtag is up and accesible | 20:38 |
alee | jmlowe_, so you should be able to do something like this -- pki -h <host> -p <port> cert-find | 20:38 |
alee | and get a list of certs | 20:39 |
jmlowe_ | I've always used openssl s_client, this seems much easier once I finally get it installed | 20:42 |
alee | jmlowe_, yup- what I'll ask you to do next if dogtag seems to be up is to tail the dogtag kra debug log when trying to store the secret - ans see if anything is happening . | 20:44 |
alee | tail -f /var/log/pki/pki-tomcat/kra/debug | 20:44 |
*** raildo has quit IRC | 20:47 | |
jmlowe_ | huh, pki hangs but sclient doesn't | 20:49 |
alee | jmlowe_ try .. | 20:49 |
alee | pki -h <host> -p <port> -P https cert-find | 20:50 |
jmlowe_ | that's better | 20:50 |
alee | ok so you got a bunch of certs? | 20:50 |
jmlowe_ | not exactly | 20:51 |
alee | well a bunch of cert entry lists - | 20:51 |
alee | you can see each cert with pki cert-show <serial_number> | 20:51 |
alee | with all the -h etc ... | 20:51 |
jmlowe_ | http://paste.openstack.org/show/718990/ | 20:52 |
alee | jmlowe_, is that the correct URI? | 20:52 |
jmlowe_ | yeah maybe not, should it be https and 8443? | 20:53 |
alee | it shouldn't matter but you can try it | 20:53 |
jmlowe_ | really kind of fuzzy on all the moving pieces for dogtag | 20:53 |
alee | sure - dogtag ca has secure and insecure ports | 20:54 |
alee | by default the unsecure port is 8080 | 20:54 |
alee | and secure is 843 | 20:54 |
alee | 8443 | 20:54 |
alee | so try to secure port and https | 20:54 |
jmlowe_ | really wondering where I got the list of ports from (it's been a few weeks), doesn't seem to be correct | 20:55 |
alee | jmlowe_, well you took a standard instal , right? | 20:55 |
alee | and did not chage any of the ports? | 20:56 |
jmlowe_ | I should say the list of ports to forward for the container | 20:56 |
jmlowe_ | hmm, still PKIException: Not Found | 20:57 |
alee | add a -v | 20:57 |
alee | thats will give verbose output | 20:57 |
alee | and see where its trying to connect | 20:58 |
alee | -vvv gives more output | 20:58 |
jmlowe_ | really kind of looking like a broken dogtag | 20:59 |
alee | jmlowe_, could be -- I'm not sure yet | 20:59 |
jmlowe_ | 404 errors | 20:59 |
alee | where is it trying to connect? | 20:59 |
jmlowe_ | http://172.16.130.50:8080 | 21:01 |
alee | right- what servlet? | 21:01 |
jmlowe_ | HTTP request: GET /pki/rest/info HTTP/1.1 | 21:03 |
jmlowe_ | is that what you mean? | 21:03 |
alee | yup | 21:03 |
alee | jmlowe_, ok -- it been awhile since I pulled down and tried this container .. let me try it now | 21:03 |
jmlowe_ | I'll need to go in a minute or two, pick this up tomorrow? | 21:04 |
alee | sure :) | 21:04 |
alee | in the meantime, I'll pul down the container | 21:04 |
jmlowe_ | Thanks for the help so far | 21:04 |
alee | jmlowe_, np - what platform are you running all this on? | 21:04 |
jmlowe_ | jetstream-cloud.org is my project | 21:05 |
jmlowe_ | centos mostly | 21:05 |
alee | jmlowe_, gotcha | 21:05 |
alee | now worries - we'll get it working | 21:05 |
jmlowe_ | maybe some day if it all goes well I can get a real big boy HSM | 21:06 |
alee | :) me too | 21:07 |
jmlowe_ | right now we turn away anybody with ephi, it would be really nice to be able to service those researchers especially with the new native to qemu luks stuff in queens for encrypted volumes | 21:09 |
alee | yup | 21:09 |
*** abishop has quit IRC | 21:17 | |
*** alee has quit IRC | 21:24 | |
*** alee has joined #openstack-barbican | 21:27 | |
*** noslzzp has quit IRC | 22:10 | |
-openstackstatus- NOTICE: zuul was restarted to updated to the latest code; you may need to recheck changes uploaded or approvals added between 21:30 and 21:45 | 22:29 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!