Wednesday, 2020-11-11

*** d34dh0r53 has quit IRC03:34
openstackgerritwu.shiming proposed openstack/barbican master: Replace deprecated UPPER_CONSTRAINTS_FILE variable  https://review.opendev.org/76229106:29
openstackgerritwu.shiming proposed openstack/castellan master: Replace deprecated UPPER_CONSTRAINTS_FILE variable  https://review.opendev.org/76229306:40
*** tosky has joined #openstack-barbican07:23
*** prernadembla05 has joined #openstack-barbican08:09
*** jaosorior has joined #openstack-barbican09:06
*** iurygregory has quit IRC10:19
*** iurygregory has joined #openstack-barbican10:36
*** iurygregory has quit IRC11:11
*** iurygregory_ has joined #openstack-barbican11:35
*** iurygregory_ is now known as iurygregory11:35
*** jaosorior has quit IRC12:01
*** jaosorior has joined #openstack-barbican12:02
*** raildo has joined #openstack-barbican12:33
*** d34dh0r53 has joined #openstack-barbican13:05
*** jaosorior has quit IRC13:40
*** jaosorior has joined #openstack-barbican13:41
openstackgerritNayara Souza proposed openstack/barbican master: [WIP]Barbican new default roles  https://review.opendev.org/75516315:37
*** jaosorior has quit IRC15:46
noonedeadpunkhey! sorry for bothering you, but never interacted with hsm before... I getting this now http://paste.openstack.org/show/799925/15:55
noonedeadpunkthe only missing mechanism seems to be for hmac_key_type15:55
noonedeadpunkbut I have only these supported http://paste.openstack.org/show/799926/15:56
noonedeadpunkand there seems to be no allowed according to https://opendev.org/openstack/barbican/src/branch/master/barbican/plugin/crypto/pkcs11.py#L50-L5415:56
noonedeadpunkor maybe I'm looking at wrong direction?15:56
*** strigazi has quit IRC15:58
*** jaosorior has joined #openstack-barbican15:59
redrobotnoonedeadpunk, so, the defaults should work with Thales Luna Network HSM (previously Safenet Luna)15:59
openstackgerritNayara Souza proposed openstack/barbican master: [WIP]Barbican new default roles  https://review.opendev.org/75516315:59
redrobotnoonedeadpunk, The CKK_* values are for Key Types16:00
redrobotnoonedeadpunk, mechanisms start with CKM_*16:00
redrobotnoonedeadpunk, https://opendev.org/openstack/barbican/src/branch/master/barbican/plugin/crypto/pkcs11.py#L138-L14616:00
redrobotnoonedeadpunk, default wrapping mechanism is CKM_SHA256_HMAC, which is listed as supported in your paste https://opendev.org/openstack/barbican/src/branch/master/barbican/plugin/crypto/p11_crypto.py#L8316:03
*** strigazi has joined #openstack-barbican16:04
noonedeadpunkyeah, it's Safenet Luna16:07
noonedeadpunkprobably I haven't configured client properly...16:08
redrobotnoonedeadpunk, sorry, looking at the stacktrace, it looks like your encryption mechanism is not supported, not the HMAC one16:08
noonedeadpunkas right before it I have uwsgi[16354]: dGVtcDEyMyM= /opt/barbican/etc/CAFile.pem16:08
noonedeadpunkbut I hav16:09
noonedeadpunk*have CKM_AES_CBC in the list....16:09
noonedeadpunkeventualy I don't have /opt/barbican/etc/CAFile.pem16:10
noonedeadpunk think that might be a reason16:12
noonedeadpunkwas actually trying to follow https://cpl.thalesgroup.com/sites/default/files/content/integration_guides/field_document/2020-05/007-013570-001_OpenStackBarbican_SafeNetLunaHSM_IntegrationGuide_RevB.pdf :(16:14
redrobotoh wow, I didn't know that was a thing. :-O16:15
redrobotnoonedeadpunk, what release are you using?16:15
noonedeadpunkI faced it while googling lol16:15
noonedeadpunkI think I'm kind of on master or U at the moment16:15
noonedeadpunkplaying in sandbox16:15
redrobotnoonedeadpunk, I'm trying to match your stacktrace's line numbers to the code16:16
redrobotnoonedeadpunk, seems it's not master?16:16
noonedeadpunk10.1.0.dev4416:16
noonedeadpunkshould be SHA 3f6f9e7cdf8b601e3110c0f744260a99c56313c016:17
noonedeadpunkoh, ok, I should probably remove FIPS according to that doc, which I've probably missed16:19
redrobotOh, yeah, I have not used the Lunas under FIPS16:19
redrobotthe Mechanism in question is https://opendev.org/openstack/barbican/src/commit/3f6f9e7cdf8b601e3110c0f744260a99c56313c0/barbican/plugin/crypto/pkcs11.py#L63516:19
noonedeadpunkseems I have it:(16:20
noonedeadpunkredrobot: yeah needed to disable fips16:32
noonedeadpunkotherwise I get this trace16:32
redrobotInteresting.16:32
redrobotade_lee, ^^^ Somewhat related to our FIPS work, seems the keywrap mechanism used in Lunas is not FIPS compliant16:33
noonedeadpunkdoc says `The OpenStack Barbican integration does not work with a SafeNet Luna HSM or Data Protection on Demand HSM on Demand services operating in FIPS mode. To integrate an HSMoD service with OpenStack barbican you must create a non-FIPS HSMoD service. ` just didn't notice at once16:34
ade_leeredrobot, interesting - so we need a different key mechanism?17:04
ade_leekeywrap mechanism ..17:04
ade_leeredrobot, good to know - this would have eventually shown up in our testing - good to know now17:06
*** jaosorior has quit IRC17:07
redrobotade_lee, well, we'll only see it if the HSM itself is FIPS-enabled17:10
redrobotade_lee, so I'm not sure if we need to worry about it, but definitely good to know.17:10
ade_leeredrobot, ack17:16
*** jaosorior has joined #openstack-barbican17:23
*** prernadembla05 has quit IRC17:32
*** raildo has quit IRC18:58
*** raildo has joined #openstack-barbican18:58
openstackgerritNayara Souza proposed openstack/barbican master: [WIP]Barbican new default roles  https://review.opendev.org/75516319:45
*** jaosorior has quit IRC19:56
*** jaosorior has joined #openstack-barbican20:15
openstackgerritAde Lee proposed openstack/barbican master: DNM: testing FIPS gate job  https://review.opendev.org/76066520:24
openstackgerritAde Lee proposed openstack/barbican master: DNM: testing FIPS gate job  https://review.opendev.org/76066521:15
*** osmanlicilegi has quit IRC21:37
*** timburke has quit IRC21:37
*** osmanlicilegi has joined #openstack-barbican21:37
*** timburke has joined #openstack-barbican21:37
*** tosky has quit IRC21:40
*** tosky has joined #openstack-barbican21:41
*** strigazi has quit IRC21:41
*** strigazi has joined #openstack-barbican21:42
*** iurygregory has quit IRC21:46
*** frickler has quit IRC21:46
*** icey has quit IRC21:46
*** trident has quit IRC21:46
*** iurygregory has joined #openstack-barbican21:47
*** frickler has joined #openstack-barbican21:47
*** johnsom has quit IRC21:48
*** gagehugo has quit IRC21:48
*** johnsom has joined #openstack-barbican21:50
*** gagehugo has joined #openstack-barbican21:50
*** icey has joined #openstack-barbican21:50
*** trident has joined #openstack-barbican21:50
*** raildo has quit IRC21:51
*** noonedeadpunk has quit IRC21:51
*** jaosorior has quit IRC21:51
*** moguimar has quit IRC21:51
*** jaosorior has joined #openstack-barbican21:53
*** moguimar has joined #openstack-barbican21:53
*** raildo has joined #openstack-barbican21:53
*** noonedeadpunk has joined #openstack-barbican21:53
*** d34dh0r53 has quit IRC21:53
*** bbezak has quit IRC21:53
*** jamespage has quit IRC21:53
*** d34dh0r53 has joined #openstack-barbican21:53
*** bbezak has joined #openstack-barbican21:53
*** jamespage has joined #openstack-barbican21:53
*** d34dh0r53 has quit IRC21:53
*** bbezak has quit IRC21:53
*** jamespage has quit IRC21:53
*** raildo has quit IRC21:53
*** noonedeadpunk has quit IRC21:53
*** jaosorior has quit IRC21:53
*** moguimar has quit IRC21:53
*** icey has quit IRC21:53
*** trident has quit IRC21:53
*** johnsom has quit IRC21:53
*** gagehugo has quit IRC21:53
*** iurygregory has quit IRC21:53
*** frickler has quit IRC21:53
*** strigazi has quit IRC21:53
*** tosky has quit IRC21:53
*** osmanlicilegi has quit IRC21:53
*** timburke has quit IRC21:53
*** lxkong has quit IRC21:53
*** mnaser has quit IRC21:53
*** tinwood has quit IRC21:53
*** irclogbot_3 has quit IRC21:53
*** jmlowe has quit IRC21:53
*** hindret has quit IRC21:53
*** andrewbogott has quit IRC21:53
*** coreycb has quit IRC21:53
*** gmann has quit IRC21:53
*** ade_lee has quit IRC21:53
*** tkajinam has quit IRC21:53
*** dayou has quit IRC21:53
*** openstackgerrit has quit IRC21:53
*** mnasiadka has quit IRC21:53
*** rm_work has quit IRC21:53
*** knikolla has quit IRC21:53
*** zigo has quit IRC21:53
*** redrobot has quit IRC21:53
*** jamespage has joined #openstack-barbican21:54
*** bbezak has joined #openstack-barbican21:54
*** d34dh0r53 has joined #openstack-barbican21:54
*** noonedeadpunk has joined #openstack-barbican21:54
*** raildo has joined #openstack-barbican21:54
*** moguimar has joined #openstack-barbican21:54
*** jaosorior has joined #openstack-barbican21:54
*** trident has joined #openstack-barbican21:54
*** icey has joined #openstack-barbican21:54
*** gagehugo has joined #openstack-barbican21:54
*** johnsom has joined #openstack-barbican21:54
*** frickler has joined #openstack-barbican21:54
*** iurygregory has joined #openstack-barbican21:54
*** strigazi has joined #openstack-barbican21:54
*** tosky has joined #openstack-barbican21:54
*** timburke has joined #openstack-barbican21:54
*** osmanlicilegi has joined #openstack-barbican21:54
*** jmlowe has joined #openstack-barbican21:54
*** lxkong has joined #openstack-barbican21:54
*** mnaser has joined #openstack-barbican21:54
*** rm_work has joined #openstack-barbican21:54
*** mnasiadka has joined #openstack-barbican21:54
*** knikolla has joined #openstack-barbican21:54
*** hindret has joined #openstack-barbican21:54
*** andrewbogott has joined #openstack-barbican21:54
*** coreycb has joined #openstack-barbican21:54
*** gmann has joined #openstack-barbican21:54
*** ade_lee has joined #openstack-barbican21:54
*** tkajinam has joined #openstack-barbican21:54
*** tinwood has joined #openstack-barbican21:54
*** irclogbot_3 has joined #openstack-barbican21:54
*** dayou has joined #openstack-barbican21:54
*** openstackgerrit has joined #openstack-barbican21:54
*** zigo has joined #openstack-barbican21:54
*** redrobot has joined #openstack-barbican21:54
*** mnasiadka has quit IRC21:54
*** rm_work has quit IRC21:54
*** knikolla has quit IRC21:54
*** trident has quit IRC21:54
*** zigo has quit IRC21:54
*** redrobot has quit IRC21:54
*** raildo has quit IRC21:54
*** rm_work has joined #openstack-barbican21:54
*** mnasiadka has joined #openstack-barbican21:54
*** knikolla has joined #openstack-barbican21:54
*** raildo has joined #openstack-barbican21:54
*** zigo has joined #openstack-barbican21:55
*** redrobot has joined #openstack-barbican21:55
*** trident has joined #openstack-barbican21:55
*** mnasiadka has quit IRC21:57
*** mnasiadka has joined #openstack-barbican21:57
*** tosky has quit IRC23:08

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!