| *** mordred has quit IRC | 00:49 | |
| *** annp has quit IRC | 02:04 | |
| *** Luzi has joined #openstack-barbican | 06:23 | |
| *** pcaruana has joined #openstack-barbican | 07:22 | |
| *** jaosorior has joined #openstack-barbican | 07:41 | |
| *** velizarx has joined #openstack-barbican | 08:10 | |
| *** xek has joined #openstack-barbican | 08:42 | |
| *** Emine has joined #openstack-barbican | 09:41 | |
| *** zigo has joined #openstack-barbican | 10:02 | |
| moguimar | Luzi: are you around? | 10:03 |
|---|---|---|
| Luzi | yes | 10:03 |
| moguimar | do you have a minute? | 10:04 |
| moguimar | on the oslo.encrypt spec | 10:04 |
| Luzi | moguimar: sure, what's up? | 10:04 |
| *** mahe has joined #openstack-barbican | 10:04 | |
| moguimar | right now castellan supports both barbican and hashicorp vault | 10:04 |
| *** mahe has left #openstack-barbican | 10:04 | |
| *** mhen has joined #openstack-barbican | 10:04 | |
| moguimar | as a generic key manager | 10:04 |
| moguimar | vault is also moving towards encryption as a service capabilities | 10:05 |
| moguimar | do we really need a new library for that? | 10:05 |
| moguimar | why not put encryption/decryption as a service also in castellan? | 10:06 |
| mhen | moguimar, interesting! Does it provide methods to encrypt and decrypt files directly? | 10:06 |
| Luzi | well, we had that kind of discussion at the Summit | 10:06 |
| moguimar | mhen: I can research that | 10:07 |
| Luzi | talking to the Castellan team, it seemed they prefer an extra library for encryption / decryption... | 10:08 |
| Luzi | which would make sense according to the scope of what Castellan should do and what we want the library to do | 10:08 |
| moguimar | by the way, who is the castellan team? 😅 | 10:09 |
| Luzi | basically the Barbican / Security SIG team | 10:10 |
| moguimar | vault only provides data encryption as a service =T | 10:10 |
| Luzi | that's what we have been told at least | 10:10 |
| mhen | moguimar, the library we are proposing is for file encryption specifically. However, we intend to use a driver-based approach. I could see the encryption-as-a-service interface to be used as a driver backend in the future. | 10:12 |
| moguimar | also why oslo.encrypt over oslo.crypt? | 10:12 |
| moguimar | as you probably would like to encrypt/decrypt sign/verify | 10:13 |
| moguimar | all those stuff around crypto, not only encryption | 10:13 |
| mhen | signature stuff is usually handled by cursive | 10:13 |
| Luzi | the name came up at the summit and we kept it so that everone we talked to knows, this is the library we talked about | 10:14 |
| mhen | the library is a requirement for the image encryption we are currently proposing | 10:14 |
| mhen | we don't plan to replace the current signature mechanism for images | 10:15 |
| Luzi | and the name can still be changed, I think - the library doen't exists right now :D | 10:15 |
| moguimar | good | 10:15 |
| moguimar | then I'll put my sugestion on the spec | 10:15 |
| moguimar | I'm new at openstack | 10:16 |
| moguimar | recently got oslo core | 10:16 |
| moguimar | basically tacling oslo.config and now castellan | 10:16 |
| moguimar | tackling* | 10:16 |
| moguimar | on security related stuff | 10:17 |
| Luzi | well it seems that the people we talked to at the summit are all on vacation right now - it's thanksgiving in the US | 10:18 |
| moguimar | who did you guys talked to? | 10:19 |
| moguimar | ade? | 10:19 |
| Luzi | yes | 10:19 |
| moguimar | cool, he is no my team | 10:19 |
| moguimar | but I'm based in Europe | 10:19 |
| Luzi | and dave-mccowan and gagehugo and ben nemec | 10:20 |
| Luzi | we (mhen and myself) are also from europe | 10:20 |
| moguimar | cool, I met dave as well, and lost the opportunity to meet gage =T | 10:21 |
| moguimar | been working with ben, dhellmann and other folks in the oslo.config drivers | 10:22 |
| moguimar | so you're both from SecuStack? | 10:24 |
| Luzi | yes :) | 10:24 |
| Luzi | where are you located in Europe? | 10:25 |
| moguimar | Brno | 10:25 |
| Luzi | ah not so far away | 10:25 |
| moguimar | that 9am was tough to attend | 10:25 |
| moguimar | are you guys in Germany? | 10:26 |
| mhen | correct | 10:26 |
| moguimar | I saw the GmbH in the website, but failed to find location | 10:27 |
| moguimar | I'm originally from Brazil | 10:27 |
| jaosorior | moguimar: arrived to this late. But yeah, the castellan team is basically Ade, dave mccowan and me (although I barely do stuff there anymore) | 10:34 |
| jaosorior | of the people left there. Every once in a while some other folks chime in | 10:34 |
| jaosorior | anyway, would be better to wait for next week to get the input of the folks that are on vacations right now | 10:36 |
| moguimar | sure | 10:36 |
| jaosorior | Luzi: got you a spec put up already? | 10:37 |
| jaosorior | I have some time to review it right now | 10:37 |
| Luzi | yes | 10:38 |
| Luzi | https://review.openstack.org/#/c/618754/ | 10:38 |
| Luzi | there you go | 10:38 |
| jaosorior | thanks, and sorry for the delay | 10:38 |
| * jaosorior brews some coffee | 10:38 | |
| Luzi | take some time for your coffee, mhen is still answering some questions doug had on this spec | 10:39 |
| *** salmankhan has joined #openstack-barbican | 10:49 | |
| *** salmankhan1 has joined #openstack-barbican | 10:52 | |
| *** salmankhan has quit IRC | 10:54 | |
| *** salmankhan1 is now known as salmankhan | 10:54 | |
| *** toabctl has joined #openstack-barbican | 10:54 | |
| *** dims has quit IRC | 11:45 | |
| *** raildo has joined #openstack-barbican | 11:50 | |
| *** velizarx has quit IRC | 12:26 | |
| *** moguimar has quit IRC | 12:42 | |
| *** moguimar has joined #openstack-barbican | 12:54 | |
| *** velizarx has joined #openstack-barbican | 13:06 | |
| *** moguimar has quit IRC | 13:17 | |
| *** pcaruana has quit IRC | 13:50 | |
| *** pbourke has quit IRC | 14:09 | |
| *** pbourke has joined #openstack-barbican | 14:11 | |
| *** dims has joined #openstack-barbican | 14:14 | |
| *** Luzi has quit IRC | 14:22 | |
| *** pcaruana has joined #openstack-barbican | 14:25 | |
| *** abishop has quit IRC | 14:28 | |
| *** emine__ has joined #openstack-barbican | 14:30 | |
| *** Emine has quit IRC | 14:30 | |
| *** emine__ has quit IRC | 15:02 | |
| *** velizarx has quit IRC | 15:08 | |
| *** moguimar has joined #openstack-barbican | 16:23 | |
| *** Emine has joined #openstack-barbican | 16:35 | |
| *** moguimar has quit IRC | 16:46 | |
| *** Emine has quit IRC | 17:34 | |
| *** salmankhan has quit IRC | 18:32 | |
| *** Emine has joined #openstack-barbican | 19:08 | |
| *** Emine has quit IRC | 19:48 | |
| *** raildo has quit IRC | 20:38 | |
| *** dave-mccowan has joined #openstack-barbican | 21:24 | |
| *** dave-mccowan has quit IRC | 21:28 | |
| *** xek_ has joined #openstack-barbican | 22:06 | |
| *** xek has quit IRC | 22:09 | |
| *** xek__ has joined #openstack-barbican | 22:25 | |
| *** xek_ has quit IRC | 22:27 | |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!