Tuesday, 2023-10-03

*** mhen_ is now known as mhen01:56
xek#startmeeting barbican12:00
opendevmeetMeeting started Tue Oct  3 12:00:52 2023 UTC and is due to finish in 60 minutes.  The chair is xek. Information about MeetBot at http://wiki.debian.org/MeetBot.12:00
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.12:00
opendevmeetThe meeting name has been set to 'barbican'12:00
xek#topic Roll Call12:01
xekCourtesy ping for dmendiza[m] ade_lee d34dh0r53 Luzi tosky tobias-urdin jjung mharley lpiwowar12:01
rajivhi12:01
mharleyo/12:02
rajivdo we have the weekly meeting today ?12:02
lpiwowaro/12:03
xekmorning :)12:04
xek@rajiv yep, it has just started12:04
rajivyo!12:04
xekAs usual our agenda can be found here:12:04
xek#link https://etherpad.openstack.org/p/barbican-weekly-meeting12:04
xekJust the usual items today12:04
xek#topic Review Past Meeting Action Items12:04
xek#link https://meetings.opendev.org/meetings/barbican/2023/barbican.2023-09-05-12.00.html12:05
xekThere was a patch fixing the python-barbicanclient gate, which is already merged12:05
xek#link https://review.opendev.org/c/openstack/python-barbicanclient/+/89473812:06
xek#topic Liaison Updates12:07
xekIt's the final week of Bobcat12:07
dmendiza[m]🙋12:07
dmendiza[m]Welcome back, Grzegorz Grasza !12:08
xekMorning @dmendiza :)12:08
xekDuring my PTO secret consumers were reverted in castellan bobcat https://review.opendev.org/q/topic:revert-castellan-bobcat12:08
xekas it broke services requirements cross-job12:09
xekNot much we can do at this point, but the changes are still on the main branch, so they're scheduled to go in in the next cycle12:09
xekThat's all from me12:10
xek@lpiwowar any updates from QA?12:12
lpiwowarFrom the QE side I do not have any updates12:12
lpiwowarBut if there is something urgent you need me to take a look at. I will do so:)12:12
xek@lpiwowar ack, thanks!12:13
xek#topic Open Discussion12:13
rajivHey, i have 3 questions.12:13
rajiv1. Can we upgrade from Zed to Bobcat directly now ?12:14
xekBarbican didn't have any breaking changes in Bobcat, so it should be fine12:14
rajivcool!12:15
rajiv2. is there a fix for CVE-2023-1636 ? the associated articles dont provide a fix yet12:15
xekThis CVE is related to how Barbican is deployed, presumably in TripleO12:17
rajivokay, i have a custom policy file with custom roles, which means i am not impacted ? will there be any details updated in the associated CVE links ?12:18
rajivmy barbican setup in production runs on kubernetes12:18
xekThere are some details here: https://access.redhat.com/security/cve/cve-2023-163612:18
xekif you are running in kubernetes this CVE doesn't apply to you12:19
rajivyes i was referring to this article but wasnt sure. Thanks for confirming.12:20
rajiv3. Any update on bug request : https://bugs.launchpad.net/barbican/+bug/203650612:20
xekthe main issue in TripleO is that the host network namespace is shared with the host and between containers12:20
rajivack12:21
xekI don't have any updates on the above bug12:22
xek@dmendiza is it on your radar?12:23
dmendiza[m]I saw the report but haven't looked into it12:25
rajivi have QA device if we wish to troubleshoot!12:25
rajivalso, i am running barbican on FIPS mode, docu says its not supported. Should i raise a bug request ?12:26
xekyeah, we'll probably need it to test that any fix is compatible with both versions12:26
rajivi approached Thales if they could push a commit but they denied to associate.12:27
rajivI also found SoftHSM also doesnt support CKM_AES_CBC_PAD wrapping mechanism, more details are provided here :12:27
rajivhttps://github.com/opendnssec/SoftHSMv2/issues/40512:27
rajivhttps://github.com/opendnssec/SoftHSMv2/issues/22912:27
rajivthanks, how do we plan to fix this ? is there a project workflow i need to setup ?12:28
xek@rajiv I think the documentation says it's not supported, since we don't have a voting set of tests for FIPS12:28
rajivokay, i can write few tests, but how can barbican test if FIPS mode is ON ? there isnt any API or DB to check right ?12:30
xekNext step is to submit a patch, but I can't make any estimate on when and who could create one12:30
rajivapart p11 plugin enabled, or few changes seen in the kek_data table to confirm, know ?12:31
xekThere were some tests using a centos image with fips enabled12:31
xekThose were running the usual functional test12:31
xekade_lee was working on that12:31
rajivi see, but i dont see any now, talking about tests, there isnt any here right ? https://github.com/openstack/barbican-tempest-plugin12:32
xekyeah, I don't see this either, those would show up as a separate job in the review board12:33
dmendiza[m]RE: Luna in FIPS mode, I'm not sure it's been tested in a long time.12:34
xekbut I suppose we could update the documentation with any pointers to how to run in fips, with a note that it's not currently tested in CI12:34
rajivokay, do i follow up bi-weekly for Thales patch ? or how do you recommend ?12:35
dmendiza[m]rajiv If you want to work on a patch we can review it when you have it ready12:35
dmendiza[m]RE: test, there are no HSM specific tests, we basically just run the same tests against a Barbican deployment that has an HSM12:35
dmendiza[m]the tests should work regardless of backend12:36
rajivi am unsure on how or where to start, any hints is highly appreciated ?12:36
dmendiza[m]the reason we don't test at the gate is because we don't have public access to an HSM that can be used on every patch that is submitted to barbican.12:36
rajivack wrt tests12:36
rajivmaybe send the patch across and i could test it ?12:37
xekI only evoked @dmendiza since he has more experience with HSMs, but I'm not expecting he has the time to prepare a patch12:41
xekI'm sure we'll have the time to review a patch, but I'm not sure about creating one12:42
rajivoh ok12:42
rajivdo we still support storyboard ? or do i need to raise another issue via opendev. 12:44
rajivThis is another of my old bugs : https://storyboard.openstack.org/#!/story/200932212:44
xekPlease re-add it to launchpad12:45
xekOk, let's continue to the last topic12:46
xek#topic Bug Review12:47
xekI don't see any new bugs, apart from those already mentioned12:47
xekLooks like that's it for today12:48
xekI'm on PTO for the next 2 weeks12:50
xekthis one was planned a while ago :)12:51
xekSo it looks like we'll be skipping the next 2 weekly meetings12:51
xekUnless @dmendiza wants to chair?12:52
dmendiza[m]I can cover for you 12:52
xekok, cool, thanks!12:52
xekWe skipped a bunch of meetings last month, but I just had to take this unexpected PTO...12:53
xekAnyway, thanks for attendance, see you in 3 weeks!12:53
xek#endmeeting12:54
opendevmeetMeeting ended Tue Oct  3 12:54:38 2023 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)12:54
opendevmeetMinutes:        https://meetings.opendev.org/meetings/barbican/2023/barbican.2023-10-03-12.00.html12:54
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/barbican/2023/barbican.2023-10-03-12.00.txt12:54
opendevmeetLog:            https://meetings.opendev.org/meetings/barbican/2023/barbican.2023-10-03-12.00.log.html12:54

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!