*** dave-mccowan has joined #openstack-barbican | 03:06 | |
*** dave-mccowan has quit IRC | 03:32 | |
*** Luzi has joined #openstack-barbican | 06:50 | |
*** dpawlik has joined #openstack-barbican | 07:08 | |
*** graeb has joined #openstack-barbican | 07:22 | |
*** pcaruana has joined #openstack-barbican | 08:32 | |
*** jaosorior has joined #openstack-barbican | 09:06 | |
*** graeb has quit IRC | 09:16 | |
*** graeb has joined #openstack-barbican | 09:20 | |
*** moguimar has joined #openstack-barbican | 09:34 | |
*** graeb has quit IRC | 10:14 | |
*** graeb has joined #openstack-barbican | 10:24 | |
*** dpawlik has quit IRC | 11:00 | |
*** dpawlik has joined #openstack-barbican | 11:52 | |
*** raildo has joined #openstack-barbican | 12:15 | |
*** moguimar has quit IRC | 12:18 | |
*** moguimar has joined #openstack-barbican | 12:19 | |
*** moguimar has quit IRC | 12:25 | |
*** moguimar has joined #openstack-barbican | 12:26 | |
*** dave-mccowan has joined #openstack-barbican | 13:10 | |
*** ade_lee has quit IRC | 13:28 | |
*** dpawlik has quit IRC | 13:51 | |
*** jmlowe has quit IRC | 14:01 | |
*** moguimar has quit IRC | 14:04 | |
*** moguimar has joined #openstack-barbican | 14:04 | |
*** mmethot has joined #openstack-barbican | 14:06 | |
*** dpawlik has joined #openstack-barbican | 14:14 | |
*** jmlowe has joined #openstack-barbican | 14:17 | |
*** jmlowe has quit IRC | 14:17 | |
*** jmlowe has joined #openstack-barbican | 14:29 | |
*** ade_lee has joined #openstack-barbican | 14:38 | |
*** Luzi has quit IRC | 15:27 | |
*** dpawlik has quit IRC | 15:55 | |
*** graeb has quit IRC | 16:06 | |
ade_lee | redrobot, yo | 16:16 |
---|---|---|
redrobot | ade_lee, \o | 16:16 |
ade_lee | redrobot, so right now, we do save the label of the mkek and hmac is the kek_datum | 16:17 |
ade_lee | redrobot, so that you can use the right mkek to extract a pkek | 16:17 |
*** dave-mccowan has quit IRC | 16:17 | |
ade_lee | redrobot, what we dont store is the mkek_type and hmac_type | 16:18 |
redrobot | oof | 16:18 |
redrobot | sounds like a bug :( | 16:18 |
ade_lee | redrobot, looks like at this point, we implicitly assume AES for mkek | 16:18 |
ade_lee | and whatever is configured for hmac | 16:18 |
ade_lee | is this a reasonable assumption though? | 16:19 |
redrobot | ade_lee, I think MKEK is fine, IIRC only the Mechanism is configurable, not the Key Type | 16:19 |
ade_lee | redrobot, yeah but changing the type of the hmac is really only to support different HSMs | 16:20 |
ade_lee | redrobot, would we expect a migration from one hsm type to another? | 16:20 |
ade_lee | even if we did have that -- its likely that the old key would need to be exported from the old hsm and placed in the new one | 16:21 |
ade_lee | with likely the same key type (old and new) | 16:21 |
redrobot | I don't think we should worry about migrating between different hsm vendors | 16:22 |
redrobot | but I do think a Firmware update may add mechanisms to the same HSM | 16:22 |
redrobot | so, since the type is configurable for HMAC we should probably store what the config value was when the hmac was created. | 16:22 |
ade_lee | well - we might as well store the mkek ttype too then -- future proof .. | 16:23 |
redrobot | ade_lee, ++ | 16:23 |
*** abishop has joined #openstack-barbican | 16:29 | |
*** dpawlik has joined #openstack-barbican | 16:30 | |
*** dpawlik has quit IRC | 16:34 | |
*** jmlowe has quit IRC | 16:43 | |
*** moguimar has quit IRC | 16:59 | |
*** dpawlik has joined #openstack-barbican | 17:15 | |
*** raildo has quit IRC | 17:19 | |
*** dpawlik has quit IRC | 17:19 | |
*** raildo has joined #openstack-barbican | 17:43 | |
*** raildo has quit IRC | 17:48 | |
*** jmlowe has joined #openstack-barbican | 18:03 | |
*** pcaruana has quit IRC | 19:14 | |
*** dpawlik has joined #openstack-barbican | 19:16 | |
*** dpawlik has quit IRC | 19:20 | |
*** whoami-rajat has quit IRC | 19:20 | |
*** abishop has quit IRC | 19:38 | |
*** raildo has joined #openstack-barbican | 19:42 | |
*** dpawlik has joined #openstack-barbican | 19:50 | |
*** dpawlik has quit IRC | 19:54 | |
*** dpawlik has joined #openstack-barbican | 21:51 | |
*** dpawlik has quit IRC | 21:55 | |
*** ade_lee has quit IRC | 22:15 | |
*** dpawlik has joined #openstack-barbican | 22:29 | |
*** dpawlik has quit IRC | 22:34 | |
*** raildo has quit IRC | 22:42 | |
*** ade_lee has joined #openstack-barbican | 22:55 | |
*** nadeem has quit IRC | 23:53 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!