Monday, 2024-10-28

rajivHi15:01
xek#startmeeting barbican15:01
opendevmeetMeeting started Mon Oct 28 15:01:20 2024 UTC and is due to finish in 60 minutes.  The chair is xek. Information about MeetBot at http://wiki.debian.org/MeetBot.15:01
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:01
opendevmeetThe meeting name has been set to 'barbican'15:01
xek#topic Roll Call15:01
xeko/15:01
xekCourtesy ping for dmendiza[m] ade_lee d34dh0r53 Luzi tosky tobias-urdin jjung mharley lpiwowar15:01
xekAs usual our agenda can be found here:15:02
xek#link https://etherpad.openstack.org/p/barbican-weekly-meeting15:02
dmendiza[m]🙋15:02
xek#topic Review Past Meeting Action Items15:03
xek#link https://meetings.opendev.org/meetings/barbican/2024/barbican.2024-10-14-15.03.html15:03
xekThere were no action items15:03
xek#topic Liaison Updates15:03
xekNo updates from me15:04
xek#topic Open Discussion15:05
rajivHeylo!!15:06
rajivthe barbican release notes are not visible!15:06
rajivi raised this in previous PTG's but couldnt find any fix for it15:06
rajivhere : https://releases.openstack.org/dalmatian/index.html15:06
xekHm, I see release notes here: https://docs.openstack.org/releasenotes/barbican/2024.2.html15:07
rajivokay, then its mapping issue to the main link ?15:08
rajivsecond, i wanted to follow up on https://bugs.launchpad.net/barbican/+bug/203650615:09
xekyeah, looks like the link to the release notes is missing from that page15:09
rajivthanks for looking into this dmendiza[m] :) was this patch validated by Thales ?15:09
dmendiza[m]hi rajiv .  My patch is a WIP.  No plans to have Thales look at it, but I will be testing with an (ancient) Thales Luna HSM.15:10
dmendiza[m]My HSM is too old to test the new firmware, so you may want to download the patch and test it when it's working15:10
rajivah ok cool :) i tested the patch today and shared my analysis!15:11
rajivi have a Thales contact from Engineering to validate once the patch is merged :) 15:11
dmendiza[m]Sweet, yeah just keep an eye out on the review, I'll be updating it this week.15:13
rajivnice!15:14
rajivlast question, is it possible to support multiple vendors on Barbican ? Thales and Utimaco ?15:14
rajivi see an option for multi-secret store but not mutlti-vendor per secret store ?15:15
dmendiza[m]I think we've only tested multiple_secret_stores with different types e.g. SimpleCrypto + HSM, or SimpleCrypto + KMIP.  I'm not sure if 2x StoreCrypto + PKCS11 would work? 🤔15:16
rajivSimpleCrypto + HSM, is my current implementation and it definitely works15:17
rajivi couldnt find an option to validate 2x pkcs11 here https://docs.openstack.org/barbican/latest/install/barbican-backend.html15:18
rajivi see an overlap in Thales & Utimaco devices.15:18
dmendiza[m]Yeah, the main issue is going to be trying to instantiate two instances of StoreCryptoAdapter: https://opendev.org/openstack/barbican/src/branch/master/barbican/plugin/store_crypto.py#L5015:19
rajivyep, i guessed the same.15:19
rajivdoes this docu need updating ? https://docs.openstack.org/barbican/latest/configuration/plugin_backends.html when compared to https://docs.openstack.org/barbican/latest/install/barbican-backend.html15:20
rajivstores_lookup_suffix shows pkcs11 but other page its enabled_crypto_plugins = p11_crypto15:21
dmendiza[m]I think both need to be updated probably15:21
rajivokay, for SimpleCrypto + HSM config, this is fine correct ? https://github.com/sapcc/helm-charts/blob/barb_thales_test/openstack/barbican/templates/etc/_barbican.conf.tpl#L69-L8315:22
dmendiza[m]Not sure, you'd have to test it and make sure there's no funny business going on with the two instances of StoreCryptoAdapter.15:23
rajivokay sure.15:24
xekok, to finish up, let's quickly check the bugs15:27
xek#topic Bug Review15:27
xekI see one new bug15:28
xek#link https://bugs.launchpad.net/barbican/+bug/208469115:28
xekBarbican is not passing any name to the KMIP object so the default one is used15:28
dmendiza[m]Yeahh.... KMIP was on the way to deprecation IIRC.  Not surprised it's broken since we stopped testing it when PyKMIP started failing at the gate.15:29
xekdmendizacan you respond? maybe we should decide on deprecating it this cycle15:30
dmendiza[m]Sure15:30
xekThanks!15:30
xekOk, that's all for today15:31
xekHave a great rest of the week!15:31
xek#endmeeting15:31
opendevmeetMeeting ended Mon Oct 28 15:31:22 2024 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:31
opendevmeetMinutes:        https://meetings.opendev.org/meetings/barbican/2024/barbican.2024-10-28-15.01.html15:31
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/barbican/2024/barbican.2024-10-28-15.01.txt15:31
opendevmeetLog:            https://meetings.opendev.org/meetings/barbican/2024/barbican.2024-10-28-15.01.log.html15:31
dmendiza[m]Thanks Grzegorz Grasza !15:31
opendevreviewGhanshyam proposed openstack/barbican-tempest-plugin master: Support py3.12 and drop py3.8  https://review.opendev.org/c/openstack/barbican-tempest-plugin/+/93336017:58

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!