*** gmann_afk is now known as gmann | 00:19 | |
*** spatel has quit IRC | 00:53 | |
*** spatel has joined #openstack-barbican | 03:04 | |
*** jmlowe has quit IRC | 04:37 | |
*** JohnnyRainbow has quit IRC | 04:37 | |
*** jmlowe has joined #openstack-barbican | 04:42 | |
*** JohnnyRainbow has joined #openstack-barbican | 04:42 | |
*** openstackstatus has quit IRC | 04:58 | |
*** openstack has joined #openstack-barbican | 04:59 | |
*** ChanServ sets mode: +o openstack | 04:59 | |
*** spatel has quit IRC | 05:19 | |
*** redrobot4 has joined #openstack-barbican | 05:34 | |
*** redrobot has quit IRC | 05:37 | |
*** redrobot4 is now known as redrobot | 05:37 | |
openstackgerrit | Ade Lee proposed openstack/barbican-tempest-plugin master: Initial patch to add barbican rbac tests https://review.opendev.org/c/openstack/barbican-tempest-plugin/+/774771 | 06:15 |
---|---|---|
*** tosky has joined #openstack-barbican | 09:12 | |
noonedeadpunk | hey everyone! I was wondering if it's possible to somehow switch between hsm stored keys? I guess that would require rotation of everything that is stored in barbican withing that HSM backend, right? | 11:33 |
noonedeadpunk | So you can't just switch to another slot (except taking key with you) | 11:33 |
*** raildo has joined #openstack-barbican | 11:57 | |
*** raildo_ has joined #openstack-barbican | 12:37 | |
*** raildo has quit IRC | 12:40 | |
*** iurygregory has quit IRC | 12:51 | |
*** raildo_ is now known as raildo | 12:52 | |
*** raildo_ has joined #openstack-barbican | 13:06 | |
*** raildo has quit IRC | 13:08 | |
*** spatel has joined #openstack-barbican | 13:57 | |
*** iurygregory has joined #openstack-barbican | 14:13 | |
*** rajivmucheli has joined #openstack-barbican | 15:12 | |
*** rajivmucheli has quit IRC | 15:54 | |
redrobot | noonedeadpunk right, for the MKEK and HMAC keys, you could use a different token (in a different slot) if your HSM provides a way to move the keys from one token to another. | 16:01 |
redrobot | noonedeadpunk otherwise you will need to rotate the MKEK and HMAC | 16:01 |
redrobot | because all PKEKs that are stored in the DB have been encrypted with the MKEK and signed with the HMAC keys | 16:01 |
redrobot | for key rotation see `barbican-manage hsm rewrap_pkek` command: https://docs.openstack.org/barbican/latest/admin/barbican_manage.html | 16:04 |
redrobot | although now that I think of it, I'm not sure it will work if the old keys are in a different slot as the new keys (because we need to decrypt and then re-encrypt) | 16:05 |
noonedeadpunk | oh, but if I can export/import there is rotation command | 16:12 |
noonedeadpunk | that's really nice, because I was afrtaid there wasn't:) | 16:12 |
noonedeadpunk | but I'm wondering how old keys will be retrieved? | 16:12 |
noonedeadpunk | I guess I need to create a new ones with new label? | 16:13 |
noonedeadpunk | or old label is stored somewhere? | 16:13 |
redrobot | noonedeadpunk IIRC, the PKEK row in the db has the label that was used to encrypt it. The label in conf is used for new encryptions. So on a rotate, the db knows what the old label was and the conf points to the new label. | 16:21 |
noonedeadpunk | aha, cool, thanks so much for the help! | 16:23 |
*** d34dh0r53 has quit IRC | 17:43 | |
*** d34dh0r53 has joined #openstack-barbican | 17:45 | |
*** raildo_ is now known as raildo | 18:10 | |
*** spatel has quit IRC | 18:40 | |
*** spatel has joined #openstack-barbican | 18:44 | |
*** raildo has quit IRC | 19:10 | |
*** raildo has joined #openstack-barbican | 19:11 | |
*** raildo has quit IRC | 19:11 | |
openstackgerrit | Ade Lee proposed openstack/ansible-role-thales-hsm master: Add support for configuring load_sharing mode https://review.opendev.org/c/openstack/ansible-role-thales-hsm/+/775018 | 21:04 |
*** xek has joined #openstack-barbican | 21:06 | |
*** xek has quit IRC | 22:02 | |
*** spatel has quit IRC | 22:09 | |
openstackgerrit | Merged openstack/barbican-tempest-plugin master: [goal] Keep barbican-tempest-plugin stable jobs to bionic https://review.opendev.org/c/openstack/barbican-tempest-plugin/+/756185 | 22:17 |
openstackgerrit | Ade Lee proposed openstack/ansible-role-thales-hsm master: Add support for configuring load_sharing mode https://review.opendev.org/c/openstack/ansible-role-thales-hsm/+/775018 | 22:19 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!