*** ducnv has joined #openstack-barbican | 00:50 | |
*** namnh has joined #openstack-barbican | 00:58 | |
*** DongHM has joined #openstack-barbican | 01:31 | |
*** ducnv has left #openstack-barbican | 01:33 | |
*** ducnv has joined #openstack-barbican | 01:34 | |
*** mhen has quit IRC | 01:39 | |
*** mhen has joined #openstack-barbican | 01:41 | |
*** tovin07 has joined #openstack-barbican | 02:08 | |
*** tovin07 has quit IRC | 02:10 | |
*** annp has joined #openstack-barbican | 03:39 | |
*** ducnv has quit IRC | 03:54 | |
*** ducnv has joined #openstack-barbican | 04:19 | |
*** dims has quit IRC | 04:30 | |
*** dims has joined #openstack-barbican | 04:35 | |
*** ducnv has quit IRC | 04:42 | |
*** strigazi has quit IRC | 05:17 | |
*** strigazi has joined #openstack-barbican | 05:19 | |
*** strigazi_ has joined #openstack-barbican | 05:24 | |
*** strigazi has quit IRC | 05:27 | |
*** ducnv has joined #openstack-barbican | 06:00 | |
*** Luzi has joined #openstack-barbican | 06:01 | |
*** openstackgerrit has quit IRC | 06:04 | |
*** peereb has joined #openstack-barbican | 06:48 | |
*** peereb has quit IRC | 06:49 | |
*** peereb has joined #openstack-barbican | 06:49 | |
*** peereb has quit IRC | 06:50 | |
*** serlex has joined #openstack-barbican | 07:01 | |
*** ducnv has quit IRC | 07:06 | |
*** namnh has quit IRC | 07:06 | |
*** pcaruana has joined #openstack-barbican | 07:20 | |
*** jaosorior has quit IRC | 08:39 | |
*** salmankhan has joined #openstack-barbican | 09:01 | |
*** ducnv has joined #openstack-barbican | 09:42 | |
*** strigazi_ is now known as strigazi | 09:47 | |
*** ducnv_ has joined #openstack-barbican | 09:53 | |
*** ducnv has quit IRC | 09:54 | |
*** ducnv_ has left #openstack-barbican | 09:54 | |
*** ducnv_ has joined #openstack-barbican | 09:54 | |
*** ducnv_ has quit IRC | 09:55 | |
*** ducnv has joined #openstack-barbican | 09:55 | |
*** jaosorior has joined #openstack-barbican | 10:29 | |
*** DongHM has quit IRC | 10:38 | |
*** annp has quit IRC | 10:58 | |
*** tovin07 has joined #openstack-barbican | 11:30 | |
*** namnh has joined #openstack-barbican | 11:30 | |
*** openstackgerrit has joined #openstack-barbican | 11:34 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican master: Remove unused policy enforcer attributes https://review.openstack.org/578071 | 11:34 |
---|---|---|
*** asbishop has joined #openstack-barbican | 11:59 | |
redrobot | #startmeeting barbican | 12:00 |
openstack | Meeting started Tue Jun 26 12:00:09 2018 UTC and is due to finish in 60 minutes. The chair is redrobot. Information about MeetBot at http://wiki.debian.org/MeetBot. | 12:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 12:00 |
*** openstack changes topic to " (Meeting topic: barbican)" | 12:00 | |
openstack | The meeting name has been set to 'barbican' | 12:00 |
redrobot | #topic Roll Call | 12:00 |
*** openstack changes topic to "Roll Call (Meeting topic: barbican)" | 12:00 | |
namnh | hi | 12:00 |
namnh | o/ | 12:00 |
redrobot | ✋ | 12:01 |
redrobot | hi namnh! | 12:01 |
lxkong | hi guys | 12:01 |
namnh | hi redrobot :) | 12:01 |
Luzi | o/ | 12:01 |
Luzi | hi all | 12:01 |
ducnv | o/ | 12:02 |
redrobot | lots of folks here today! 😁 | 12:03 |
redrobot | Here is the link to the agenda: | 12:03 |
redrobot | #link https://wiki.openstack.org/wiki/Meetings/Barbican | 12:03 |
redrobot | which I'm not sure anyone uses... | 12:03 |
redrobot | so we're just going to wing it again | 12:03 |
namnh | :) | 12:04 |
redrobot | Let's see.. | 12:04 |
redrobot | #topic Action Items from last meeting | 12:04 |
namnh | LOL, sorry, i did not append my topic today, so can I still discuss as usual | 12:04 |
*** openstack changes topic to "Action Items from last meeting (Meeting topic: barbican)" | 12:04 | |
redrobot | #link http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-06-19-12.01.html | 12:05 |
redrobot | "Luzi to add a story to Storyboard for adding AES 512 keys to barbican" | 12:05 |
Luzi | done | 12:05 |
Luzi | and up for review | 12:05 |
Luzi | https://review.openstack.org/#/c/577096/ | 12:05 |
redrobot | #link https://storyboard.openstack.org/#!/story/2002612 | 12:06 |
redrobot | #link https://review.openstack.org/#/c/577096/ | 12:06 |
redrobot | I have not had a chance to review, unfortunately. But I'll try to get to it this week for sure. | 12:06 |
redrobot | anything you need to mention Luzi ? | 12:06 |
Luzi | not really | 12:07 |
redrobot | ok, moving on | 12:07 |
redrobot | "redrobot to follow up with infra team regarding the meeting time change on the eavesdrop website" | 12:08 |
redrobot | I didn't talk to the infra folks... but the time has been updated on the eavesdrop site: | 12:08 |
redrobot | #link http://eavesdrop.openstack.org/#Barbican_Meeting | 12:08 |
redrobot | so I think we're good on that | 12:08 |
redrobot | ok, moving on | 12:08 |
redrobot | #topic Castellan key store as base service | 12:09 |
*** openstack changes topic to "Castellan key store as base service (Meeting topic: barbican)" | 12:09 | |
redrobot | #link https://review.openstack.org/#/c/572656/ | 12:09 |
redrobot | looks like the patch to openstack/governance has merged | 12:10 |
redrobot | which is awesome | 12:10 |
redrobot | 🎉🎉🎉 | 12:10 |
redrobot | I think Castellan still needs some TLC, but I don't have any patches to talk about right now. | 12:11 |
namnh | great news | 12:11 |
redrobot | that's all I have for Castellan... | 12:12 |
redrobot | any questions/comments? | 12:12 |
*** raildo has joined #openstack-barbican | 12:12 | |
redrobot | ok, moving on | 12:13 |
redrobot | namnh, you said you had a topic to talk about? | 12:13 |
namnh | yeah, for rolling upgrade in barbican. that I am taking care | 12:14 |
redrobot | #topic Rolling Upgrades | 12:14 |
*** openstack changes topic to "Rolling Upgrades (Meeting topic: barbican)" | 12:14 | |
redrobot | namnh, go ahead | 12:14 |
namnh | some patch sets. https://review.openstack.org/#/c/500244 | 12:15 |
namnh | which i would like to get some reviews | 12:15 |
namnh | redrobot: would you mind helping me to review the patch sets. | 12:15 |
namnh | normally, Ade will review the patches for me. but i don't see him recently | 12:16 |
redrobot | I've started looking at the OVO[3] patch. Unfortunately, my review has been quite slow as I am not familiar with a lot of the stuff that is being changed. | 12:16 |
namnh | do you know reasons? | 12:17 |
redrobot | yeah, Ade has been on vacation for about 2 weeks | 12:17 |
redrobot | I think he _may_ be back next week? | 12:17 |
redrobot | that's why I've been doing the meetings the last couple of weeks. 😬 | 12:17 |
namnh | I understood, thanks :) | 12:18 |
redrobot | Luzi, ducnv lxkong please feel free to review as well ☝ | 12:18 |
redrobot | anything else you want to comment about namnh ? | 12:19 |
namnh | moreover, I am writing unit-tests for it. you can review it, and i think it will be easy for you to understand | 12:19 |
namnh | https://review.openstack.org/#/c/576409 | 12:19 |
namnh | i will push more patch set about unit-test on this week. | 12:19 |
redrobot | #help we need more reviews on namnh's OVO patches | 12:20 |
namnh | it will be great to get your comment. | 12:20 |
namnh | redrobot: thanks :) | 12:20 |
ducnv | redrobot, i am quite new :)) | 12:20 |
namnh | redrobot: duc is my co-worker, he will join barbican team for now on :) | 12:20 |
redrobot | ducnv, welcome! 😁 | 12:21 |
namnh | :)) | 12:21 |
namnh | okay, that's all my comments | 12:22 |
ducnv | this is first day I join channel | 12:22 |
redrobot | ducnv, well, I'm glad you've decided to join us. 😁 | 12:23 |
redrobot | ok, moving on | 12:23 |
redrobot | anyone else have topics that didn't make it to the Agenda? | 12:23 |
redrobot | I'll take that as a no. | 12:25 |
redrobot | I can't think of anything else off the top of my head | 12:25 |
lxkong | guys, may i ask a question? I asked several days ago but didn't get any answer. Not sure it's a good chance | 12:25 |
redrobot | lxkong, sure, what's up? | 12:26 |
lxkong | Did anyone of you already deploy Barbican in production? | 12:26 |
lxkong | I'm asking because we are going to deploy barbican in our cloud | 12:26 |
lxkong | but we are happy to know if there is anyone already done that, pitfalls, experiences, etc. | 12:27 |
Luzi | no but we are planning to do so | 12:27 |
redrobot | I deployed Barbican to production at Rackspace a couple of years ago. Unfortunately, it's not online anymore. | 12:27 |
lxkong | redrobot: which secret store backend were you using? | 12:27 |
redrobot | PKCS#11 backed by Safenet Luna SA HSMs | 12:27 |
redrobot | we had 2x HSMs per deployment | 12:27 |
redrobot | for HA | 12:28 |
redrobot | as well as offsite key backups of the master keys in Safenet backup devices | 12:28 |
lxkong | there is an open source HSM implementation named SoftHSM, anyone has experince of it? | 12:29 |
lxkong | we are a small company relies on open source software | 12:29 |
lxkong | so maybe the hardware HSM is not our option :-( | 12:29 |
redrobot | I've played around with SoftHSM before | 12:30 |
lxkong | redrobot: did you try to integrate that with Barbican? | 12:30 |
lxkong | does that work? | 12:30 |
redrobot | to be honest, I think it may be more trouble than it's worth... I think you may be able to get the same level of security with the SimpleCrypto backend | 12:30 |
redrobot | SoftHSM had some issues, as the mechanisms available are different than Safenet Luna's | 12:31 |
redrobot | even though they're both PKCS#11 | 12:31 |
redrobot | but at the end of the day, SoftHSM is just a key in memory, just like SimpleCrypto | 12:31 |
lxkong | hmm... | 12:32 |
redrobot | SoftHSM v2 is supposed to be a lot better, but I'm not sure what the status of it is | 12:32 |
redrobot | it's been a couple of years since I looked at it, and v2 was just starting to be developed back then. | 12:32 |
lxkong | yeah, we are jsut going to evaluate v2 | 12:32 |
lxkong | using PKCS#11 + SoftHSM will make it possible to migrate to hardware HSM in future, right? | 12:33 |
redrobot | lxkong, yes, I think so... especially if you can extract the master key from SoftHSM and store it in the real HSM | 12:34 |
redrobot | the p11 plugin may need some work | 12:34 |
redrobot | depending on what mechanisms SoftHSM v2 makes available | 12:35 |
lxkong | seems we will have a lot of work to do | 12:35 |
redrobot | yup 😬 | 12:35 |
lxkong | redrobot: thanks so much for your answer | 12:36 |
redrobot | let me know if you run into issues with PKCS#11 as it is something that I'm super interested in | 12:36 |
*** _tovin07_ has joined #openstack-barbican | 12:36 | |
lxkong | Luzi: you said you are also going to deploy barbican, anything wanna share? | 12:36 |
Luzi | we want | 12:36 |
Luzi | we are currently evaluating Safenet HSM | 12:37 |
lxkong | ok, you are rich :-) | 12:37 |
Luzi | i am not... i just work in a nice team :) | 12:38 |
lxkong | Luzi: good to know anyway, thanks | 12:38 |
lxkong | redrobot: i'm done | 12:39 |
redrobot | cool | 12:39 |
redrobot | any other topics? | 12:39 |
redrobot | alrighty then... looks like we're finished with 20 minutes to spare! 😁 | 12:40 |
redrobot | #endmeeting | 12:40 |
*** openstack changes topic to "Discussion about development of OpenStack Barbican and its client libraries. - Logs: http://eavesdrop.openstack.org/irclogs/%23openstack-barbican/" | 12:41 | |
openstack | Meeting ended Tue Jun 26 12:40:59 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 12:41 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-06-26-12.00.html | 12:41 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-06-26-12.00.txt | 12:41 |
openstack | Log: http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-06-26-12.00.log.html | 12:41 |
redrobot | thanks for coming everyone! | 12:41 |
lxkong | thank you | 12:41 |
*** ducnv has left #openstack-barbican | 12:42 | |
*** _tovin07_ has quit IRC | 12:58 | |
*** namnh has quit IRC | 13:06 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican master: Remove unused policy enforcer attributes https://review.openstack.org/578071 | 13:30 |
*** jaosorior has quit IRC | 13:59 | |
*** Luzi has quit IRC | 14:31 | |
*** antosh has joined #openstack-barbican | 14:40 | |
*** namnh has joined #openstack-barbican | 14:53 | |
*** FrankZhang has joined #openstack-barbican | 15:02 | |
*** serlex has quit IRC | 15:09 | |
*** pcaruana has quit IRC | 15:42 | |
*** pbourke has quit IRC | 15:47 | |
*** pbourke has joined #openstack-barbican | 15:49 | |
*** jmlowe has quit IRC | 16:11 | |
*** namnh has quit IRC | 16:16 | |
*** salmankhan has quit IRC | 17:11 | |
*** jaosorior has joined #openstack-barbican | 18:13 | |
*** jmlowe has joined #openstack-barbican | 18:31 | |
*** antosh has quit IRC | 18:33 | |
*** antosh has joined #openstack-barbican | 18:50 | |
*** raildo has quit IRC | 20:20 | |
*** FrankZhang has quit IRC | 20:50 | |
*** jmlowe has quit IRC | 20:51 | |
*** asbishop is now known as abishop | 21:14 | |
*** jmlowe has joined #openstack-barbican | 21:17 | |
*** abishop has quit IRC | 21:19 | |
*** FrankZhang has joined #openstack-barbican | 21:21 | |
*** jmlowe has quit IRC | 21:29 | |
*** FrankZhang_ has joined #openstack-barbican | 21:29 | |
*** FrankZhang has quit IRC | 21:30 | |
*** antosh has quit IRC | 21:43 | |
*** antosh has joined #openstack-barbican | 22:12 | |
*** jmlowe has joined #openstack-barbican | 22:13 | |
*** FrankZhang_ has quit IRC | 22:41 | |
*** FrankZhang has joined #openstack-barbican | 22:42 | |
*** Kevin_Zheng has joined #openstack-barbican | 23:05 | |
*** antosh has quit IRC | 23:39 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!