Tuesday, 2018-08-21

*** livelace has quit IRC00:43
*** livelace has joined #openstack-dns00:43
*** abaindur has quit IRC01:05
openstackgerritMerged openstack/designate stable/queens: import zuul job settings from project-config  https://review.openstack.org/59331402:09
*** abaindur has joined #openstack-dns04:04
openstackgerritNguyen Hai proposed openstack/python-designateclient stable/queens: import zuul job settings from project-config  https://review.openstack.org/59286304:42
openstackgerritMerged openstack/designate stable/rocky: import zuul job settings from project-config  https://review.openstack.org/59331605:30
openstackgerritMerged openstack/designate stable/ocata: import zuul job settings from project-config  https://review.openstack.org/59331005:30
*** abaindur has quit IRC05:38
*** abaindur has joined #openstack-dns05:38
openstackgerritMerged openstack/designate stable/pike: import zuul job settings from project-config  https://review.openstack.org/59331205:39
*** pcaruana has joined #openstack-dns06:42
*** abaindur has quit IRC07:22
*** ginopc has joined #openstack-dns07:42
*** phasespace has joined #openstack-dns09:28
phasespaceHi! Does designate support using TSIG to sign messages to bind9 slaves? If so, where do I configure it?09:30
openstackgerritTytus Kurek proposed openstack/designate master: NAPTR DNS records  https://review.openstack.org/59412610:53
mugsiephasespace: create a tsigkey with openstack tsigkey create --name <name> --algorithm <algorithm> --secret <secret> --scope POOL --resource-id <POOL-ID>12:20
phasespacemugsie, thanks for answering. I've done so already. Does this mean mDNS will automatically sign notify messages using this key?12:23
phasespace(btw, i'm using the ocata version)12:24
mugsiephasespace: oh - no it will just enforce that the bind slave uses that key to request a zone transfer12:25
mugsiethat does seem like a good addition though, if you file a bug, we should add that to the back log12:25
phasespaceOk, thank you for clarifying12:31
phasespaceIf an attacker knows the ip of a designate master, wouldn't it then be possible to spoof a dns notify packet and cause the slave to trigger a full zone transfer? (since there is no TSIG signature check)12:50
mugsiephasespace: yes, but it will do a zone transfer from the listed master13:41
mugsieso, it may be a potentional DOS area, but the data should be consistent13:42
phasespaceYes, it was the DOS aspect of it I was thinking about. Thanks for answering my questions14:12
*** phasespace has quit IRC14:17
*** phasespace has joined #openstack-dns14:40
*** Leo_m has joined #openstack-dns14:54
*** ginopc has quit IRC15:01
*** pcaruana has quit IRC15:09
eanderssonmugsie, https://review.openstack.org/#/c/593096/ https://review.openstack.org/#/c/594126/16:06
eanderssonI assume these two needs to include a sql upgrade path?16:06
mugsieyup16:06
mugsieI need to review - the change is wrong for the DB schema (in CAA anyway)16:07
*** phasespace has quit IRC16:48
openstackgerritPavlo Shchelokovskyy proposed openstack/designate-tempest-plugin master: Add test for quota set for invalid project  https://review.openstack.org/58014217:14
openstackgerritPavlo Shchelokovskyy proposed openstack/designate master: Add docs for project-id verification feature  https://review.openstack.org/58850917:19
*** abaindur has joined #openstack-dns18:36
*** abaindur has quit IRC18:36
*** abaindur has joined #openstack-dns18:37
*** andrewbogott has quit IRC18:37
*** Chealion has quit IRC18:42
*** fyx has quit IRC18:42
*** therve has quit IRC18:42
*** bnemec has quit IRC19:20
*** bnemec has joined #openstack-dns19:20
*** ullbeking has quit IRC19:33
*** harmw has quit IRC19:34
*** ullbeking has joined #openstack-dns19:35
*** w|zzy has quit IRC19:39
*** ntr0py_ has quit IRC19:39
*** bauruine has quit IRC19:46
*** w|zzy has joined #openstack-dns19:49
*** bauruine has joined #openstack-dns19:58
*** Tahvok_ has joined #openstack-dns20:12
*** Tahvok has quit IRC20:19
*** Tahvok_ is now known as Tahvok20:19
*** blake has joined #openstack-dns20:29
*** blake has quit IRC20:53
*** blake has joined #openstack-dns20:54
*** blake_ has joined #openstack-dns21:55
*** blake_ has quit IRC21:55
*** blake has quit IRC21:59
*** Leo_m has quit IRC22:44

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!