*** salv-orlando has joined #openstack-cinder | 00:20 | |
*** salv-orlando has quit IRC | 00:25 | |
*** wanghao has quit IRC | 00:29 | |
*** wanghao has joined #openstack-cinder | 00:29 | |
*** dalgaaf has quit IRC | 00:32 | |
*** dalgaaf has joined #openstack-cinder | 00:33 | |
*** kaisers_ has joined #openstack-cinder | 01:05 | |
*** jiaopeng_ has joined #openstack-cinder | 01:05 | |
*** kaisers__ has quit IRC | 01:09 | |
openstackgerrit | Peng Wang proposed openstack/cinder master: DS8K: correct behavior and return value for terminate_connection method https://review.openstack.org/578290 | 01:11 |
---|---|---|
*** edmondsw has joined #openstack-cinder | 01:13 | |
*** yangyapeng has joined #openstack-cinder | 01:15 | |
*** edmondsw has quit IRC | 01:18 | |
*** salv-orlando has joined #openstack-cinder | 01:21 | |
*** salv-orlando has quit IRC | 01:26 | |
*** whoami-rajat_ has joined #openstack-cinder | 02:06 | |
*** whoami-rajat has quit IRC | 02:09 | |
*** bkopilov has quit IRC | 02:14 | |
*** salv-orlando has joined #openstack-cinder | 02:22 | |
*** salv-orlando has quit IRC | 02:26 | |
*** psachin` has joined #openstack-cinder | 02:29 | |
*** edmondsw has joined #openstack-cinder | 03:02 | |
*** edmondsw has quit IRC | 03:06 | |
*** jmlowe has quit IRC | 03:10 | |
*** salv-orlando has joined #openstack-cinder | 03:23 | |
*** salv-orlando has quit IRC | 03:27 | |
*** lpetrut has joined #openstack-cinder | 03:44 | |
*** bkopilov has joined #openstack-cinder | 03:48 | |
*** stakeda has quit IRC | 03:57 | |
openstackgerrit | Vu Cong Tuan proposed openstack/python-cinderclient master: Replace unicode with six.text_type https://review.openstack.org/580281 | 04:22 |
*** salv-orlando has joined #openstack-cinder | 04:23 | |
*** lpetrut has quit IRC | 04:24 | |
*** salv-orlando has quit IRC | 04:28 | |
*** abhishekk has joined #openstack-cinder | 04:33 | |
*** lpetrut has joined #openstack-cinder | 04:33 | |
*** zzzeek has quit IRC | 04:40 | |
*** zzzeek has joined #openstack-cinder | 04:43 | |
*** edmondsw has joined #openstack-cinder | 04:51 | |
*** lpetrut has quit IRC | 04:53 | |
*** edmondsw has quit IRC | 04:55 | |
*** zzzeek has quit IRC | 05:10 | |
*** zzzeek has joined #openstack-cinder | 05:11 | |
*** vivsoni has joined #openstack-cinder | 05:11 | |
*** e0ne has joined #openstack-cinder | 05:18 | |
*** e0ne has quit IRC | 05:21 | |
*** salv-orlando has joined #openstack-cinder | 05:24 | |
*** lpetrut has joined #openstack-cinder | 05:27 | |
*** psachin` has quit IRC | 05:27 | |
*** salv-orlando has quit IRC | 05:28 | |
*** psachin` has joined #openstack-cinder | 05:28 | |
*** lpetrut has quit IRC | 05:33 | |
*** ianychoi has joined #openstack-cinder | 05:34 | |
openstackgerrit | Merged openstack/cinder master: NetApp ONTAP NFS: Enable multiattach capability https://review.openstack.org/577919 | 05:41 |
*** nicolasbock has joined #openstack-cinder | 05:49 | |
*** moshele has joined #openstack-cinder | 05:53 | |
*** Luzi has joined #openstack-cinder | 06:08 | |
*** josecastroleon has joined #openstack-cinder | 06:10 | |
*** salv-orlando has joined #openstack-cinder | 06:11 | |
*** armaan has joined #openstack-cinder | 06:13 | |
*** armaan has quit IRC | 06:15 | |
*** dpawlik has joined #openstack-cinder | 06:16 | |
*** armaan has joined #openstack-cinder | 06:16 | |
*** lpetrut has joined #openstack-cinder | 06:20 | |
*** andreas_s has joined #openstack-cinder | 06:20 | |
*** armaan has quit IRC | 06:21 | |
*** salv-orlando has quit IRC | 06:24 | |
*** salv-orlando has joined #openstack-cinder | 06:24 | |
*** salv-orlando has quit IRC | 06:25 | |
*** lvdombrkr has joined #openstack-cinder | 06:32 | |
*** moshele has quit IRC | 06:44 | |
*** kaisers_ has quit IRC | 07:04 | |
*** yangyapeng has quit IRC | 07:10 | |
*** gkadam has joined #openstack-cinder | 07:11 | |
*** lpetrut has quit IRC | 07:12 | |
*** arnewiebalck_ has joined #openstack-cinder | 07:13 | |
*** lpetrut has joined #openstack-cinder | 07:21 | |
*** peereb has joined #openstack-cinder | 07:22 | |
*** salv-orlando has joined #openstack-cinder | 07:26 | |
*** tswanson has quit IRC | 07:27 | |
*** salv-orlando has quit IRC | 07:31 | |
*** yangyapeng has joined #openstack-cinder | 07:32 | |
*** kaisers_ has joined #openstack-cinder | 07:32 | |
*** yangyapeng has quit IRC | 07:34 | |
*** e0ne has joined #openstack-cinder | 07:46 | |
*** alexchadin has joined #openstack-cinder | 07:54 | |
*** rcernin has quit IRC | 07:54 | |
*** mszwed has joined #openstack-cinder | 07:56 | |
*** alexchad_ has joined #openstack-cinder | 08:00 | |
*** alexchadin has quit IRC | 08:02 | |
*** moshele has joined #openstack-cinder | 08:08 | |
*** andreas_s has quit IRC | 08:13 | |
*** andreas_s has joined #openstack-cinder | 08:19 | |
*** vivsoni_ has joined #openstack-cinder | 08:22 | |
*** vivsoni has quit IRC | 08:22 | |
*** salv-orlando has joined #openstack-cinder | 08:27 | |
*** edmondsw has joined #openstack-cinder | 08:28 | |
*** Luzi has quit IRC | 08:28 | |
*** salv-orlando has quit IRC | 08:31 | |
*** edmondsw has quit IRC | 08:32 | |
*** Luzi has joined #openstack-cinder | 08:45 | |
pooja_jadhav | smcginnis, jungleboyj: Kindly review this https://review.openstack.org/#/c/573093/ | 09:08 |
*** alexchad_ has quit IRC | 09:11 | |
*** alexchadin has joined #openstack-cinder | 09:15 | |
*** wanghao has quit IRC | 09:16 | |
*** e0ne has quit IRC | 09:21 | |
*** e0ne has joined #openstack-cinder | 09:23 | |
*** salv-orlando has joined #openstack-cinder | 09:28 | |
*** salv-orlando has quit IRC | 09:34 | |
*** armaan has joined #openstack-cinder | 09:44 | |
*** spsurya_ has quit IRC | 09:49 | |
*** whoami-rajat__ has joined #openstack-cinder | 10:00 | |
*** alexchadin has quit IRC | 10:03 | |
*** vishakha has quit IRC | 10:03 | |
*** whoami-rajat_ has quit IRC | 10:03 | |
*** armaan has quit IRC | 10:06 | |
*** vishakha has joined #openstack-cinder | 10:17 | |
*** _Adary has joined #openstack-cinder | 10:18 | |
*** alexchadin has joined #openstack-cinder | 10:19 | |
*** arnewiebalck_ has quit IRC | 10:26 | |
*** bkopilov has quit IRC | 10:28 | |
*** e0ne has quit IRC | 10:28 | |
*** salv-orlando has joined #openstack-cinder | 10:30 | |
*** salv-orlando has quit IRC | 10:34 | |
*** lpetrut_ has joined #openstack-cinder | 10:39 | |
*** wanghao has joined #openstack-cinder | 10:41 | |
*** lpetrut has quit IRC | 10:42 | |
*** ganso has joined #openstack-cinder | 10:45 | |
*** jiaopeng_ has quit IRC | 10:56 | |
*** jiaopengju has joined #openstack-cinder | 10:56 | |
*** gcb has joined #openstack-cinder | 10:58 | |
*** alexchadin has quit IRC | 10:58 | |
*** jiaopengju has quit IRC | 11:01 | |
*** gcb has quit IRC | 11:13 | |
*** luizbag has joined #openstack-cinder | 11:19 | |
*** armaan has joined #openstack-cinder | 11:22 | |
*** edmondsw has joined #openstack-cinder | 11:29 | |
*** salv-orlando has joined #openstack-cinder | 11:31 | |
*** salv-orlando has quit IRC | 11:36 | |
*** alexchadin has joined #openstack-cinder | 11:36 | |
*** lifeless has quit IRC | 11:45 | |
*** abishop has joined #openstack-cinder | 11:48 | |
*** bkopilov has joined #openstack-cinder | 11:57 | |
*** wanghao has quit IRC | 11:57 | |
*** lvdombrkr89 has joined #openstack-cinder | 11:58 | |
*** lvdombrkr has quit IRC | 11:59 | |
*** e0ne has joined #openstack-cinder | 12:07 | |
*** edmondsw has quit IRC | 12:07 | |
openstackgerrit | Chuck Short proposed openstack/cinder master: Port nvmet driver to use privsep https://review.openstack.org/580226 | 12:11 |
*** edmondsw has joined #openstack-cinder | 12:13 | |
*** edmondsw_ has joined #openstack-cinder | 12:16 | |
*** edmondsw has quit IRC | 12:19 | |
*** whoami-rajat_ has joined #openstack-cinder | 12:28 | |
*** jmlowe has joined #openstack-cinder | 12:28 | |
openstackgerrit | Merged openstack/cinder master: INFINIDAT: change create_child to create_snapshot https://review.openstack.org/579863 | 12:29 |
*** mriedem has joined #openstack-cinder | 12:31 | |
*** whoami-rajat__ has quit IRC | 12:31 | |
*** salv-orlando has joined #openstack-cinder | 12:31 | |
*** vishakha has quit IRC | 12:31 | |
*** whoami-rajat__ has joined #openstack-cinder | 12:34 | |
*** salv-orlando has quit IRC | 12:36 | |
*** whoami-rajat_ has quit IRC | 12:38 | |
*** whoami-rajat_ has joined #openstack-cinder | 12:39 | |
*** alexchad_ has joined #openstack-cinder | 12:39 | |
*** alexchadin has quit IRC | 12:41 | |
*** whoami-rajat__ has quit IRC | 12:42 | |
*** lseki has joined #openstack-cinder | 12:45 | |
*** vishakha has joined #openstack-cinder | 12:46 | |
*** armaan has quit IRC | 12:46 | |
*** armaan has joined #openstack-cinder | 12:47 | |
*** e0ne has quit IRC | 12:48 | |
*** jmlowe has quit IRC | 12:51 | |
*** salv-orlando has joined #openstack-cinder | 12:53 | |
*** whoami-rajat has joined #openstack-cinder | 12:53 | |
*** salv-orl_ has joined #openstack-cinder | 12:54 | |
*** vishakha has quit IRC | 12:55 | |
*** arnewiebalck_ has joined #openstack-cinder | 12:55 | |
*** salv-orlando has quit IRC | 12:56 | |
*** whoami-rajat_ has quit IRC | 12:56 | |
*** salv-orlando has joined #openstack-cinder | 12:57 | |
*** salv-orl_ has quit IRC | 12:59 | |
*** jmlowe has joined #openstack-cinder | 13:00 | |
*** eharney has joined #openstack-cinder | 13:05 | |
openstackgerrit | Felipe Monteiro proposed openstack/cinder master: Add policy in code documentation for os-set_bootable API https://review.openstack.org/580045 | 13:07 |
*** vishakha has joined #openstack-cinder | 13:08 | |
*** salv-orlando has quit IRC | 13:15 | |
*** armaan has quit IRC | 13:16 | |
*** salv-orlando has joined #openstack-cinder | 13:16 | |
*** armaan has joined #openstack-cinder | 13:17 | |
*** armaan has quit IRC | 13:21 | |
*** armaan has joined #openstack-cinder | 13:24 | |
openstackgerrit | Lucio Seki proposed openstack/cinder master: NetApp ONTAP: Remove NFS driver online volume extending support https://review.openstack.org/578196 | 13:28 |
*** elefrancois has joined #openstack-cinder | 13:30 | |
*** salv-orlando has quit IRC | 13:35 | |
*** dustins has joined #openstack-cinder | 13:39 | |
*** pchavva has joined #openstack-cinder | 13:39 | |
*** e0ne has joined #openstack-cinder | 13:59 | |
*** moshele has quit IRC | 14:08 | |
*** arnewiebalck_ has quit IRC | 14:15 | |
*** arnewiebalck_ has joined #openstack-cinder | 14:16 | |
*** arnewiebalck_ has quit IRC | 14:16 | |
*** Luzi has quit IRC | 14:19 | |
*** kaisers_ has quit IRC | 14:21 | |
*** lpetrut_ has quit IRC | 14:24 | |
openstackgerrit | Chuck Short proposed openstack/cinder master: Drop rootwrap from quobyte driver https://review.openstack.org/580395 | 14:24 |
*** armaan has quit IRC | 14:29 | |
*** dpawlik has quit IRC | 14:30 | |
*** salv-orlando has joined #openstack-cinder | 14:36 | |
*** salv-orlando has quit IRC | 14:40 | |
*** itlinux has quit IRC | 14:40 | |
*** abhishekk has quit IRC | 14:51 | |
*** salv-orlando has joined #openstack-cinder | 15:01 | |
*** salv-orlando has quit IRC | 15:01 | |
*** namnh has joined #openstack-cinder | 15:01 | |
*** markstur has joined #openstack-cinder | 15:05 | |
*** armaan has joined #openstack-cinder | 15:08 | |
*** peereb has quit IRC | 15:22 | |
*** itlinux has joined #openstack-cinder | 15:25 | |
*** alexchadin has joined #openstack-cinder | 15:25 | |
*** alexchad_ has quit IRC | 15:28 | |
*** e0ne has quit IRC | 15:42 | |
*** lpetrut_ has joined #openstack-cinder | 15:46 | |
openstackgerrit | Chuck Short proposed openstack/cinder master: Remove mkdir from volume.filters https://review.openstack.org/580427 | 15:47 |
*** dpawlik has joined #openstack-cinder | 15:50 | |
*** jmlowe has quit IRC | 16:01 | |
*** lvdombrkr89 has quit IRC | 16:14 | |
*** moshele has joined #openstack-cinder | 16:17 | |
*** gcb has joined #openstack-cinder | 16:28 | |
*** dpawlik has quit IRC | 16:36 | |
*** gcb has quit IRC | 16:36 | |
*** andreas_s has quit IRC | 16:37 | |
*** andreas_s has joined #openstack-cinder | 16:42 | |
*** alexchadin has quit IRC | 16:44 | |
*** andreas_s_ has joined #openstack-cinder | 16:44 | |
*** armaan_ has joined #openstack-cinder | 16:45 | |
*** armaan has quit IRC | 16:45 | |
*** andreas_s has quit IRC | 16:47 | |
*** andreas_s_ has quit IRC | 16:48 | |
*** armaan_ has quit IRC | 16:50 | |
*** psachin` has quit IRC | 16:52 | |
*** e0ne has joined #openstack-cinder | 17:03 | |
*** lseki has quit IRC | 17:03 | |
*** lpetrut_ has quit IRC | 17:10 | |
*** moshele has quit IRC | 17:13 | |
*** v12aml has quit IRC | 17:19 | |
*** namnh has quit IRC | 17:22 | |
*** v12aml has joined #openstack-cinder | 17:26 | |
*** lpetrut_ has joined #openstack-cinder | 17:33 | |
*** e0ne has quit IRC | 17:36 | |
*** lpetrut_ has quit IRC | 17:41 | |
*** bkopilov has quit IRC | 17:43 | |
*** jmlowe has joined #openstack-cinder | 17:44 | |
*** lpetrut_ has joined #openstack-cinder | 17:52 | |
*** bkopilov has joined #openstack-cinder | 17:52 | |
*** moshele has joined #openstack-cinder | 17:56 | |
*** e0ne has joined #openstack-cinder | 18:01 | |
*** moshele has quit IRC | 18:02 | |
*** e0ne_ has joined #openstack-cinder | 18:03 | |
*** e0ne__ has joined #openstack-cinder | 18:05 | |
*** e0ne has quit IRC | 18:06 | |
*** dpawlik has joined #openstack-cinder | 18:07 | |
*** e0ne_ has quit IRC | 18:08 | |
*** tswanson has joined #openstack-cinder | 18:15 | |
*** dpawlik has quit IRC | 18:20 | |
*** lpetrut_ has quit IRC | 18:27 | |
openstackgerrit | Chuck Short proposed openstack/cinder master: Drop rootwrap from quobyte driver https://review.openstack.org/580395 | 18:27 |
*** lpetrut_ has joined #openstack-cinder | 18:27 | |
*** armaan has joined #openstack-cinder | 18:32 | |
*** imacdonn has quit IRC | 18:41 | |
*** imacdonn has joined #openstack-cinder | 18:41 | |
*** armaan has quit IRC | 18:44 | |
*** zul has joined #openstack-cinder | 18:45 | |
*** armaan has joined #openstack-cinder | 18:45 | |
*** armaan has quit IRC | 18:49 | |
*** hemna_ has joined #openstack-cinder | 18:50 | |
hemna_ | mep | 18:50 |
hemna_ | anyone working today? | 18:50 |
smcginnis | o/ | 18:50 |
tswanson | hemna_, I'm not. | 18:51 |
smcginnis | tswanson: Hah, nothing else to do but hang out on IRC? | 18:51 |
tswanson | smcginnis, I've like a million windows open. I can just see when something new peeks out on this. | 18:52 |
hemna_ | heh | 18:59 |
hemna_ | so I have a question related to a series of security bugs that a few of our drivers are guilty of doing | 18:59 |
hemna_ | https://bugs.launchpad.net/cinder/+bug/1662558 | 18:59 |
openstack | Launchpad bug 1662558 in Cinder "Nexenta disabling certificate verification" [Undecided,Confirmed] | 18:59 |
hemna_ | basically disabling SSL cert verification in making connections to their backends | 19:00 |
hemna_ | this is bad mmmkay | 19:00 |
hemna_ | and 1 vendor in particular refuses to fix it | 19:00 |
smcginnis | I think for some it is difficult to set up certification validation to their array. | 19:01 |
smcginnis | Or just hasn't been a concern for their customers. | 19:01 |
smcginnis | That's my assumption at least. Not saying it's good though. | 19:01 |
hemna_ | there are a handful of drivers doing this | 19:02 |
hemna_ | why can't they just unset that flag that disables it? | 19:02 |
e0ne__ | it should be configurable, IMO | 19:02 |
e0ne__ | hemna_: +1 | 19:02 |
hemna_ | I think this is bad for cinder in general to allow this | 19:02 |
hemna_ | anyway, I'm trying to figure out what to do with it for our packaging for our distro | 19:03 |
hemna_ | we have customers complaining about it | 19:03 |
hemna_ | and our security team too. | 19:03 |
smcginnis | Maybe direct those customers to make those complaints to their storage vendors to get them to fix it? | 19:04 |
hemna_ | https://bugs.launchpad.net/cinder/+bug/1662561 | 19:04 |
openstack | Launchpad bug 1662561 in Cinder "Solidfire disabling certificate verification" [Wishlist,Triaged] | 19:04 |
smcginnis | Really up to the driver maintains I think. | 19:04 |
smcginnis | *maintainers | 19:04 |
hemna_ | re: refusing to fix it | 19:05 |
tswanson | I think the Dell SC driver has that configurable cause its former owner couldn't get the certs setup in his test environment. | 19:07 |
smcginnis | What a slacker. :D | 19:08 |
tswanson | Dell was right to whack him. | 19:08 |
eharney | why don't we just patch those drivers ourselves at this point? | 19:10 |
e0ne__ | hemna_: from our distro's perspective, we don't care about vendor-specific drivers a lot | 19:13 |
e0ne__ | hemna_: only if some customer asks to backport some bugfix from upstream | 19:13 |
eharney | why is this about distros? this is code in cinder that is just wrong | 19:13 |
e0ne__ | hemna_: it's a general rule with few exceptions | 19:14 |
*** moshele has joined #openstack-cinder | 19:14 | |
e0ne__ | eharney: +1. IMO, we should do it configurable and add warnings in case of insecure usage is enabled | 19:14 |
eharney | a lot of these drivers are using the requests library, we know how to turn it on there | 19:15 |
smcginnis | Some of these may not have instructions or even the ability for customers to get things set up right to actually do validation. | 19:16 |
e0ne__ | the question is: how many drivers will be broke after it? | 19:17 |
eharney | smcginnis: what kind of instructions do you mean? | 19:17 |
eharney | the instructions are, 1) get the cert, 2) point driver_ssl_cert_path to the cert, and 3) enable driver_ssl_cert_verify | 19:18 |
smcginnis | eharney: How to do step 1. | 19:19 |
eharney | depends on the deployment, it's not something for us to solve in Cinder | 19:20 |
smcginnis | My point is, some vendors don't have an easy way to be able to do step 1. So defaulting these drivers to complain and warn that it isn't set up when they don't have a way to do it isn't helping anyone. | 19:21 |
smcginnis | Other than being able to check a box saying the driver can be configured. | 19:21 |
*** lpetrut_ has quit IRC | 19:21 | |
*** Chealion has quit IRC | 19:21 | |
eharney | i think it helpful to alert deployers that their SSL connections are not secure | 19:21 |
*** lpetrut_ has joined #openstack-cinder | 19:22 | |
hemna_ | eharney, well, my security team here wants an answer as what to do with these poor drivers | 19:22 |
hemna_ | because we are packaging all this up, just like you guys are | 19:22 |
eharney | hemna_: IMO we should just land patches to enable SSL cert verification for them | 19:23 |
hemna_ | sounds good to me | 19:23 |
smcginnis | That's why I think it needs to go to the driver maintainers, and the best way for them to get things done is for those customers complaining to complain to them, not their OS distro. | 19:23 |
smcginnis | Making security teams happy isn't changin a thing in this case. | 19:23 |
hemna_ | smcginnis, the problem with it is, some maintainers refuse to address it. | 19:23 |
hemna_ | and yet it makes a security hole for cinder | 19:24 |
smcginnis | Customer is still screwed whether the security team is all happy with their check boxes or not. | 19:24 |
eharney | i don't have to ask a security team to know that it's ridiculous to ship code in 2018 that doesn't work right with SSL | 19:24 |
hemna_ | eharney, +1 | 19:24 |
*** Chealion has joined #openstack-cinder | 19:24 | |
hemna_ | I guess I'm raising it here for us to discuss as a team | 19:24 |
hemna_ | to see what to do with those maintainers that haven't fixed it, or refuse to fix it. | 19:24 |
smcginnis | Missing the point though. We can do all we want about it being not right, but unless the vendor gives the actual end user a way to set it up right, it's all a waste of time. | 19:25 |
hemna_ | and as a policy moving forward for future reviews and future drivers. | 19:25 |
hemna_ | I think it's just lazy on the maintainer's standpoint | 19:25 |
hemna_ | because they don't want to setup a valid SSL cert on their dev environments | 19:25 |
openstackgerrit | Sean McGinnis proposed openstack/cinder stable/queens: Update auth_url value in install docs https://review.openstack.org/566790 | 19:26 |
smcginnis | Or can't. | 19:26 |
eharney | i disagree that the goal has to be documenting this for the end user -- IMO patching up the drivers that we can to check the certs is quite useful in itself | 19:28 |
hemna_ | eharney, +1 | 19:29 |
hemna_ | I'd like to see the drivers fixed | 19:29 |
hemna_ | no reason they should disable SSL cert checking by default | 19:29 |
hemna_ | if they really want to disable it, it should be a config option. | 19:29 |
smcginnis | Unless they can't ever enable it. So I disagree that the goal has to ignore the actual usefulness to someone trying to use this just so a security team can have a false sense of accomplishment. | 19:30 |
smcginnis | I wouldn't block anything, but it's a waste of time IMO unless the driver vendor supports it. | 19:30 |
eharney | again, i don't have to ask a security team to know that shipping code that always disables cert validation is ridiculous, especially when these drivers are using the requests library and we know how to go turn that option on | 19:31 |
hemna_ | config option to disable checking, is the answer IMHO. | 19:32 |
smcginnis | But a toggle switch that can never be toggled is useless. | 19:32 |
hemna_ | but defaulting it to disabled always is bad. | 19:32 |
eharney | i don't know why you think it can never be toggled | 19:32 |
*** gkadam has quit IRC | 19:32 | |
smcginnis | Or is broken by default is even worse. | 19:32 |
eharney | do we have backends that use SSL with no ability to configure it correctly? | 19:32 |
hemna_ | we already have a config option to disable requests warnings about SSL certs | 19:32 |
smcginnis | Yes, that was my whole pint - we have backends that use SSL with no ability to configure it correctly. | 19:33 |
smcginnis | SO toggle switch away, you;re still f'd. | 19:33 |
eharney | it would be nice to let deployers know that | 19:34 |
hemna_ | at a minimum cinder should force drivers to make it configurable for drivers. | 19:34 |
patrickeast | if we just to make drivers key off of https://github.com/openstack/cinder/blob/master/cinder/volume/driver.py#L210 (which defaults to False anyway) you get a standard way to toggle it for deployers to understand | 19:34 |
*** luizbag has quit IRC | 19:34 | |
eharney | patrickeast: yep | 19:34 |
patrickeast | easy for deployment tooling to have a big on/off for security regardless of backend | 19:34 |
hemna_ | I just think as a project we shouldn't allow drivers to always default it off. | 19:34 |
smcginnis | Ideally no, practically, I can't ever see a default of on working. | 19:35 |
hemna_ | I'm not sure I agree with that. | 19:35 |
smcginnis | How could it default to on if there is always at least some manual configuration steps specific to your backend? | 19:36 |
openstackgerrit | Merged openstack/cinder master: DS8K: correct behavior and return value for terminate_connection method https://review.openstack.org/578290 | 19:36 |
hemna_ | because you do those manual steps prior to starting cinder | 19:36 |
patrickeast | its kind of hard to swap the default though.. basically on upgrade all the drivers stop working if the deployer didn't configure certs beforehand | 19:37 |
hemna_ | or you configure cinder for you driver to disable the checking. | 19:37 |
eharney | you make people knowingly opt into an insecure configuration, which is what tons of software does | 19:37 |
patrickeast | for new drivers, sure, we can push for default on | 19:37 |
hemna_ | but defaulting to an insecure setup is just wrong IMHO | 19:37 |
hemna_ | especially with no way of turning it on, in the case of these drivers. | 19:37 |
eharney | drivers or backends? | 19:39 |
patrickeast | if we get drivers onto the standardized config option, leaving cinders default as-is, isn't it fair to say that the distro's and other deployment tooling can just as easily default to a secure deployment? | 19:39 |
*** lifeless has joined #openstack-cinder | 19:39 | |
eharney | yes | 19:39 |
*** jmlowe has quit IRC | 19:40 | |
smcginnis | Yeah, that's reasonable. | 19:40 |
*** dpawlik has joined #openstack-cinder | 19:40 | |
eharney | gotta run, bbl | 19:41 |
*** eharney has quit IRC | 19:41 | |
*** moshele has quit IRC | 19:46 | |
hemna_ | yup | 19:50 |
hemna_ | ok it's Miller time and back on the beach (OBX) | 19:50 |
hemna_ | l8s | 19:50 |
*** moshele has joined #openstack-cinder | 19:51 | |
smcginnis | o/ | 19:52 |
*** jmlowe has joined #openstack-cinder | 19:59 | |
*** crose has joined #openstack-cinder | 20:07 | |
*** dpawlik has quit IRC | 20:10 | |
*** crose has quit IRC | 20:12 | |
*** lpetrut_ has quit IRC | 20:12 | |
*** eharney has joined #openstack-cinder | 20:15 | |
*** moshele has quit IRC | 20:21 | |
*** gouthamr has quit IRC | 20:27 | |
*** mchlumsky has quit IRC | 20:36 | |
*** pchavva has quit IRC | 20:55 | |
*** jmlowe has quit IRC | 20:59 | |
*** jmlowe has joined #openstack-cinder | 21:00 | |
*** dpawlik has joined #openstack-cinder | 21:12 | |
*** abishop has quit IRC | 21:14 | |
*** dpawlik has quit IRC | 21:14 | |
*** armaan has joined #openstack-cinder | 21:23 | |
*** itlinux has quit IRC | 21:24 | |
*** gouthamr has joined #openstack-cinder | 21:35 | |
*** dustins has quit IRC | 21:35 | |
*** e0ne__ has quit IRC | 21:41 | |
*** e0ne has joined #openstack-cinder | 22:00 | |
*** rcernin has joined #openstack-cinder | 22:00 | |
*** eharney has quit IRC | 22:04 | |
*** hemna_ has quit IRC | 22:05 | |
*** nicolasbock has quit IRC | 22:17 | |
*** ganso has quit IRC | 22:20 | |
openstackgerrit | Merged openstack/os-brick master: Handle multiple errors in multipath -l parsing https://review.openstack.org/577741 | 22:21 |
openstackgerrit | Merged openstack/cinder master: Fix RBD incremental backup https://review.openstack.org/579606 | 22:33 |
openstackgerrit | Merged openstack/cinder master: NEC driver: Fix iscsi multipath initialize_connection tests https://review.openstack.org/578330 | 22:33 |
openstackgerrit | Merged openstack/cinder master: Remove mkdir from volume.filters https://review.openstack.org/580427 | 22:33 |
*** armaan has quit IRC | 22:36 | |
*** armaan has joined #openstack-cinder | 22:37 | |
*** edmondsw_ has quit IRC | 22:40 | |
*** edmondsw has joined #openstack-cinder | 22:41 | |
*** armaan has quit IRC | 22:41 | |
*** edmondsw has quit IRC | 22:45 | |
*** e0ne has quit IRC | 22:50 | |
*** e0ne has joined #openstack-cinder | 22:51 | |
*** e0ne has quit IRC | 22:55 | |
*** rcernin has quit IRC | 22:58 | |
*** rcernin has joined #openstack-cinder | 23:01 | |
*** ianychoi_ has joined #openstack-cinder | 23:01 | |
*** ianychoi has quit IRC | 23:04 | |
*** mriedem has quit IRC | 23:08 | |
openstackgerrit | Merged openstack/cinder master: Fix prophetstor drivers report value https://review.openstack.org/577033 | 23:24 |
*** tswanson has quit IRC | 23:27 | |
*** _alastor_ has quit IRC | 23:28 | |
*** tswanson has joined #openstack-cinder | 23:40 | |
*** s-shiono has joined #openstack-cinder | 23:51 | |
*** stakeda has joined #openstack-cinder | 23:52 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!