Friday, 2018-09-14

johnsomcolin- Sadly barbican does not provide CA capabilities.00:02
*** hogepodge has quit IRC01:00
*** mjblack has quit IRC01:00
*** hogepodge_ has joined #openstack-lbaas01:00
*** mjblack has joined #openstack-lbaas01:01
*** abaindur has quit IRC01:24
*** fnaval_ has joined #openstack-lbaas02:16
*** fnaval has quit IRC02:16
*** yamamoto has joined #openstack-lbaas02:46
*** nmagnezi has quit IRC03:02
*** nmagnezi has joined #openstack-lbaas03:02
openstackgerritMerged openstack/octavia master: Validate member address for batch update members
*** annp has joined #openstack-lbaas04:04
*** rcernin has quit IRC04:16
*** reedipb has quit IRC04:16
*** ramishra has joined #openstack-lbaas04:21
*** fnaval_ has quit IRC04:24
*** reedipb has joined #openstack-lbaas05:33
*** velizarx has joined #openstack-lbaas06:16
*** AlexeyAbashkin has joined #openstack-lbaas06:39
*** velizarx has quit IRC07:04
*** luksky has joined #openstack-lbaas07:05
*** yamamoto has quit IRC07:06
*** celebdor has joined #openstack-lbaas07:08
*** velizarx has joined #openstack-lbaas07:12
sapd1johnsom: How about PTG? Everything are ok?07:17
*** yamamoto has joined #openstack-lbaas07:22
*** yamamoto has quit IRC07:22
openstackgerritOpenStack Proposal Bot proposed openstack/octavia-dashboard master: Imported Translations from Zanata
*** ccamposr has joined #openstack-lbaas07:26
*** tesseract has joined #openstack-lbaas07:33
*** sapd1 has quit IRC07:33
*** sapd1 has joined #openstack-lbaas07:34
*** ducnc has joined #openstack-lbaas07:35
*** velizarx has quit IRC07:37
*** velizarx has joined #openstack-lbaas07:41
openstackgerritLuis Tomas Bolivar proposed openstack/octavia master: Enabling SG customization on loadbalancer listerners
openstackgerritOpenStack Proposal Bot proposed openstack/neutron-lbaas-dashboard master: Imported Translations from Zanata
*** yamamoto has joined #openstack-lbaas08:18
*** pcaruana has joined #openstack-lbaas08:33
*** ducnc has quit IRC08:48
*** AlexeyAbashkin has quit IRC08:51
*** AlexeyAbashkin has joined #openstack-lbaas08:53
*** luksky has quit IRC09:01
*** yamamoto has quit IRC09:24
*** ispp has joined #openstack-lbaas09:43
*** yamamoto has joined #openstack-lbaas09:46
tobias-urdinim out of ideas, i can't even get the simplest of setup working, by replicating what devstack does09:48
tobias-urdinrunning all octavia services on the same node, queens v2.0.109:48
tobias-urdingenerating certs using; git clone octavia; cd bin/; ./create-certif... certs ~/octavia/etc/certificates/openssl.conf; cp -R certs/* /etc/octavia/certs/; chown -R octavia: /etc/octavia/certs09:49
tobias-urdingetting these errors:
tobias-urdinonly thing I can think could cause this is some weird openssl version or smth09:50
tobias-urdincurl -v -k --cert /etc/octavia/certs/client.pem
tobias-urdincurl: (35) Peer's certificate has an invalid signature.09:50
tobias-urdinopenssl s_connect09:51
tobias-urdinverify return:109:51
tobias-urdin140190414870416:error:0407006A:rsa routines:RSA_padding_check_PKCS1_type_1:block type is not 01:rsa_pk1.c:103:09:51
tobias-urdin140190414870416:error:04067072:rsa routines:RSA_EAY_PUBLIC_DECRYPT:padding check failed:rsa_eay.c:773:09:51
tobias-urdin140190414870416:error:1408D07B:SSL routines:ssl3_get_key_exchange:bad signature:s3_clnt.c:2032:09:51
tobias-urdini can't see how my config or certificate would be wrong since i've used the same create-cert.. script and went through every single line in the devstack/ and set the config options the same09:53
*** moei11 has joined #openstack-lbaas10:12
*** yamamoto has quit IRC10:42
*** velizarx has quit IRC11:05
*** velizarx has joined #openstack-lbaas11:07
*** annp has quit IRC11:17
*** rtjure has joined #openstack-lbaas11:18
*** yamamoto has joined #openstack-lbaas11:31
*** yamamoto has quit IRC11:38
*** yamamoto has joined #openstack-lbaas11:38
tobias-urdinjohnsom: sorry, you're prob busy with ptg or traveling but could you check my messages some lines above this one11:40
*** reedipb has quit IRC11:50
*** amarok has joined #openstack-lbaas11:55
*** amarok has quit IRC12:00
*** ChanServ sets mode: +rf #openstack-unregistered12:35
*** yamamoto has quit IRC12:57
*** yamamoto has joined #openstack-lbaas12:59
*** yamamoto has quit IRC13:04
*** ccamposr has quit IRC13:21
*** ispp has quit IRC13:46
*** luksky has joined #openstack-lbaas13:47
*** yamamoto has joined #openstack-lbaas13:52
*** dayou has quit IRC13:55
*** dayou has joined #openstack-lbaas13:56
*** ramishra has quit IRC14:12
*** rpittau has quit IRC14:46
*** jmccrory has joined #openstack-lbaas15:04
*** velizarx has quit IRC15:08
*** ivve has joined #openstack-lbaas15:48
*** AlexeyAbashkin has quit IRC16:17
*** amuller has quit IRC16:18
rm_worktobias-urdin: sorry we are distracted this week due to the summit, but probably we can help you when we're back to normal next week16:25
rm_worktobias-urdin: the HMAC error in the health-manager may be due to a bug that we fixed in Rocky, need to see if we backported the fix properly...16:26
rm_work(and it isn't actually a problem, just a log message that shouldn't show up)16:27
rm_worktobias-urdin: though in your config for `heartbeat_key=insecure` you actually want to set that to some random string when you go to production, 'insecure' doesn't MEAN insecure, it just uses that string as the key for the HMAC encrypt/decrypt16:30
rm_worktobias-urdin: in [haproxy_amphora], for `client_cert = /etc/octavia/certs/client.pem`16:34
rm_workcan you tell me what is in client.pem?16:34
rm_workit should be two things, a cert AND a pk, concatenated together16:34
rm_workis that the case?16:34
rm_workyou can see examples of what the files are supposed to look like, by checking here:
rm_workand the parent directory has the config that uses those16:37
openstackgerritCarlos Goncalves proposed openstack/octavia-tempest-plugin master: Add octavia-v2-dsvm-py3-scenario-fedora-latest job
*** sapd1_ has joined #openstack-lbaas17:45
*** yamamoto has quit IRC17:48
*** yamamoto has joined #openstack-lbaas17:48
*** yamamoto has quit IRC17:48
*** hogepodge_ is now known as hogepodge18:23
openstackgerritAdam Harwell proposed openstack/neutron-lbaas master: Update L7-proxy gate to allow new Octavia features
*** sapd1_ has quit IRC18:27
*** yamamoto has joined #openstack-lbaas18:28
tobias-urdinrm_work: thanks, i went through all settings that devstack does just to try to get it working18:55
rm_workyeah, it's just useful usually to actually be able to SEE a working config+example certs18:55
tobias-urdinthe client.pem file is client-.pem and client.key concatenated, all my certificates are created with the script18:55
tobias-urdinexactly like devstack18:55
rm_workhmm, k18:55
tobias-urdinim just trying to get it to work right now really, by replicating devstack18:56
tobias-urdinstarting to feel like it's some issue with some python dependency, openssl package or something18:57
tobias-urdini ssh'd into the amphora and pulled out all certificates, config files, log files etc so i'm gonna see if i can very the certificates from there18:58
tobias-urdinthis is verifying the client.pem on the controller and the CA and client cert from inside the amphora
tobias-urdinare you aware of any similar bugs lately? or something in 2.0.2 release which might fix something similar?19:01
tobias-urdini've got 2.0.1 from RDO but will get 2.0.2 soon19:01
tobias-urdini should probably look through all commits there19:01
tobias-urdinthe amphora-agent log and config (which doesn't really say anything)
*** tesseract has quit IRC19:15
*** celebdor has quit IRC19:16
tobias-urdinhere is some validation of the certs
*** yamamoto has quit IRC19:27
*** yamamoto has joined #openstack-lbaas19:27
openstackgerritAdam Harwell proposed openstack/octavia master: Amphora initial heartbeat fix
*** yamamoto has quit IRC19:32
*** yamamoto has joined #openstack-lbaas20:13
openstackgerritAdam Harwell proposed openstack/octavia master: Amphora initial heartbeat fix
rm_workjohnsom: metaclass magic!
*** KeithMnemonic has quit IRC22:00
*** luksky has quit IRC22:26
openstackgerritMerged openstack/octavia master: Update amphora-agent to report UDP listener health
openstackgerritMerged openstack/octavia master: Set some amphora driver optimizations
openstackgerritMerged openstack/octavia master: Add the missing markup for the hyperlink title
openstackgerritGerman Eichberger proposed openstack/octavia master: Delete zombie amphora when detected

