*** livelace has quit IRC | 00:28 | |
*** livelace has joined #openstack-barbican | 00:28 | |
*** ducnv has joined #openstack-barbican | 01:01 | |
*** phuongnh has joined #openstack-barbican | 01:17 | |
*** jaosorior has joined #openstack-barbican | 04:31 | |
*** phuongnh has quit IRC | 05:00 | |
*** phuongnh has joined #openstack-barbican | 05:00 | |
*** phuongnh has quit IRC | 05:44 | |
*** phuongnh has joined #openstack-barbican | 06:38 | |
*** pcaruana has joined #openstack-barbican | 06:46 | |
*** jaosorior has quit IRC | 07:17 | |
*** velizarx has joined #openstack-barbican | 07:25 | |
*** Luzi has joined #openstack-barbican | 07:31 | |
*** jaosorior has joined #openstack-barbican | 07:37 | |
*** livelace has quit IRC | 08:12 | |
*** livelace has joined #openstack-barbican | 08:16 | |
*** velizarx has quit IRC | 08:22 | |
*** velizarx has joined #openstack-barbican | 08:57 | |
*** phuongnh has quit IRC | 11:31 | |
*** dave-mccowan has joined #openstack-barbican | 11:34 | |
*** raildo has joined #openstack-barbican | 11:59 | |
*** abishop has joined #openstack-barbican | 13:11 | |
*** raildo_ has joined #openstack-barbican | 13:33 | |
*** raildo has quit IRC | 13:36 | |
*** Luzi has quit IRC | 13:36 | |
*** pbourke has quit IRC | 14:04 | |
*** pbourke has joined #openstack-barbican | 14:06 | |
*** redrobot has joined #openstack-barbican | 14:14 | |
*** ducnv_ has joined #openstack-barbican | 14:56 | |
*** fyx has joined #openstack-barbican | 15:02 | |
fyx | I'm deploying barbican with HSM backend, would there be any benefit choosing PKCS#11 over KMIP or the other? | 15:05 |
---|---|---|
*** pcaruana has quit IRC | 15:11 | |
*** velizarx has quit IRC | 15:21 | |
*** ducnv_ has quit IRC | 16:10 | |
*** strigazi has quit IRC | 16:19 | |
*** strigazi has joined #openstack-barbican | 16:24 | |
*** velizarx has joined #openstack-barbican | 16:36 | |
*** raildo has joined #openstack-barbican | 16:39 | |
*** raildo_ has quit IRC | 16:40 | |
redrobot | fyx, the PKCS#11 plugin is written in a way that secrets are wrapped and then stored in the DB, whereas the KMIP plugin stores everything in the HSM | 16:57 |
redrobot | fyx, if your hsm supports both, you may want to consider your expected usage. Some HSM have very limited storage and you could end up filling it quickly with the KMIP plugin | 16:58 |
*** raildo has quit IRC | 17:31 | |
*** raildo has joined #openstack-barbican | 17:32 | |
*** raildo has quit IRC | 17:33 | |
*** raildo has joined #openstack-barbican | 17:40 | |
*** raildo has quit IRC | 17:41 | |
*** raildo has joined #openstack-barbican | 17:45 | |
*** raildo has quit IRC | 18:01 | |
*** raildo has joined #openstack-barbican | 18:13 | |
*** raildo has quit IRC | 18:15 | |
*** raildo has joined #openstack-barbican | 18:17 | |
*** abishop has quit IRC | 18:21 | |
*** abishop has joined #openstack-barbican | 18:21 | |
*** velizarx has quit IRC | 18:23 | |
*** raildo has quit IRC | 18:30 | |
*** raildo has joined #openstack-barbican | 18:41 | |
*** raildo_ has joined #openstack-barbican | 18:52 | |
*** raildo_ has quit IRC | 18:52 | |
*** raildo has quit IRC | 18:53 | |
*** raildo has joined #openstack-barbican | 19:00 | |
*** raildo has quit IRC | 19:04 | |
*** serlex has joined #openstack-barbican | 19:10 | |
*** serlex has quit IRC | 19:14 | |
*** Dmitrii-Sh_ has joined #openstack-barbican | 20:02 | |
*** Dmitrii-Sh has quit IRC | 20:08 | |
*** v1k0d3n has quit IRC | 20:08 | |
*** Dmitrii-Sh_ is now known as Dmitrii-Sh | 20:09 | |
*** v1k0d3n has joined #openstack-barbican | 20:10 | |
*** raildo has joined #openstack-barbican | 20:19 | |
*** raildo has quit IRC | 20:21 | |
fyx | redrobot: I will check that, many thanks | 20:28 |
*** liquid_pascal has joined #openstack-barbican | 20:33 | |
liquid_pascal | Hey, quick question: I'm trying to add some more conditions for when barbican returns a secret. Am I right in trying to add these rules to the oslo_policy document? And if I am, could I have a pointer at where to start? | 20:34 |
redrobot | liquid_pascal, if you're trying to add role checks and such, then yes, that's the spot. Also see: https://docs.openstack.org/oslo.policy/latest/admin/index.html | 21:29 |
liquid_pascal | I'm trying to add checks on additional information. I have a database that includes date ranges, and I need to see if the role has access in those data ranges | 21:29 |
liquid_pascal | s/data/date | 21:30 |
*** liquid_pascal has quit IRC | 21:38 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!