*** holser has joined #rdo | 00:03 | |
*** zzzeek has quit IRC | 00:04 | |
*** zzzeek has joined #rdo | 00:05 | |
rdogerrit | rdo-trunk proposed rdoinfo master: Bump rdoinfo victoria tags to latest upper-constraints https://review.rdoproject.org/r/31750 | 00:06 |
---|---|---|
rdogerrit | rdo-trunk proposed rdoinfo master: Promote CBS tags update for train-testing https://review.rdoproject.org/r/31754 | 00:09 |
rdogerrit | rdo-trunk proposed rdoinfo master: Promote CBS tags update for train-8-testing https://review.rdoproject.org/r/31755 | 00:10 |
rdogerrit | rdo-trunk proposed rdoinfo master: Promote CBS tags update for victoria-8-testing https://review.rdoproject.org/r/31756 | 00:11 |
*** holser has quit IRC | 00:45 | |
*** spatel has joined #rdo | 01:28 | |
*** spatel has quit IRC | 01:28 | |
*** pppingme has quit IRC | 01:34 | |
*** spatel has joined #rdo | 01:52 | |
*** spatel has quit IRC | 02:02 | |
*** rcernin has quit IRC | 02:21 | |
*** rcernin has joined #rdo | 02:36 | |
*** rcernin has quit IRC | 02:45 | |
*** rcernin has joined #rdo | 02:45 | |
*** imcleod has quit IRC | 03:16 | |
*** imcleod has joined #rdo | 03:17 | |
*** imcleod_ has joined #rdo | 03:21 | |
*** imcleod has quit IRC | 03:21 | |
*** imcleod_ has quit IRC | 03:39 | |
*** imcleod_ has joined #rdo | 03:42 | |
*** imcleod_ has quit IRC | 03:49 | |
*** rcernin has quit IRC | 04:00 | |
*** rcernin has joined #rdo | 04:02 | |
*** imcleod_ has joined #rdo | 04:07 | |
rdogerrit | Chandan Kumar proposed rdo-infra/ci-config master: Added --config-root flag https://review.rdoproject.org/r/31700 | 04:10 |
*** imcleod_ has quit IRC | 04:13 | |
*** imcleod_ has joined #rdo | 04:13 | |
*** ysandeep|afk is now known as ysandeep | 04:22 | |
*** ykarel has joined #rdo | 04:25 | |
*** imcleod_ has quit IRC | 04:27 | |
*** rcernin has quit IRC | 04:27 | |
*** rcernin has joined #rdo | 04:35 | |
rdogerrit | Merged rdoinfo master: Promote CBS tags update for victoria-8-testing https://review.rdoproject.org/r/31756 | 04:36 |
rdogerrit | Merged rdoinfo master: Promote CBS tags update for train-8-testing https://review.rdoproject.org/r/31755 | 04:36 |
*** pppingme has joined #rdo | 04:37 | |
rdogerrit | Merged rdoinfo master: Bump rdoinfo victoria tags to latest upper-constraints https://review.rdoproject.org/r/31750 | 04:38 |
rdogerrit | Merged rdoinfo master: Promote CBS tags update for train-8-release https://review.rdoproject.org/r/31752 | 04:38 |
rdogerrit | Chandan Kumar created rdo-jobs master: Added initial jobs for container build dependency pipeline https://review.rdoproject.org/r/31757 | 04:39 |
rdogerrit | rdo-trunk created openstack/sushy-distgit victoria-rdo: python-sushy-3.4.2-1 https://review.rdoproject.org/r/31758 | 04:41 |
*** pppingme has quit IRC | 04:41 | |
rdogerrit | Chandan Kumar proposed rdo-jobs master: Added initial jobs for container build dependency pipeline https://review.rdoproject.org/r/31757 | 04:42 |
rdogerrit | Chandan Kumar proposed rdo-infra/ci-config master: Added --config-root flag https://review.rdoproject.org/r/31700 | 04:43 |
*** skramaja has joined #rdo | 04:45 | |
*** dmacpher has quit IRC | 04:47 | |
*** gchamoul- has joined #rdo | 04:57 | |
*** gchamoul- has quit IRC | 04:58 | |
*** pppingme has joined #rdo | 05:08 | |
*** pppingme has quit IRC | 05:12 | |
*** pppingme has joined #rdo | 05:28 | |
rdogerrit | Yatin Karel proposed openstack/sushy-distgit victoria-rdo: python-sushy-3.4.2-1 https://review.rdoproject.org/r/31758 | 05:29 |
*** pppingme has quit IRC | 05:33 | |
*** ykarel_ has joined #rdo | 05:51 | |
*** ykarel has quit IRC | 05:53 | |
*** pppingme has joined #rdo | 05:54 | |
rdogerrit | Chandan Kumar proposed rdo-jobs master: Added initial jobs for container build dependency pipeline https://review.rdoproject.org/r/31757 | 05:56 |
*** gchamoul- has joined #rdo | 05:58 | |
*** pppingme has quit IRC | 05:58 | |
*** marios has joined #rdo | 06:09 | |
*** jfrancoa has joined #rdo | 06:22 | |
*** jpodivin has joined #rdo | 06:35 | |
*** matbu has joined #rdo | 06:38 | |
*** ykarel_ is now known as ykarel | 06:40 | |
*** pppingme has joined #rdo | 06:44 | |
*** TheJulia has quit IRC | 06:44 | |
*** TheJulia has joined #rdo | 06:45 | |
*** lmiccini has joined #rdo | 06:46 | |
*** ysandeep is now known as ysandeep|afk | 06:58 | |
*** bandini has joined #rdo | 07:06 | |
*** ccamposr__ has joined #rdo | 07:08 | |
*** ccamposr has quit IRC | 07:10 | |
*** rcernin has quit IRC | 07:25 | |
rdogerrit | Merged rdoinfo master: Promote CBS tags update for train-release https://review.rdoproject.org/r/31751 | 07:32 |
rdogerrit | Merged openstack/sushy-distgit victoria-rdo: python-sushy-3.4.2-1 https://review.rdoproject.org/r/31758 | 07:34 |
*** gchamoul is now known as gchamoul-tmp | 07:40 | |
*** gchamoul- is now known as gchamoul | 07:41 | |
*** jcapitao has joined #rdo | 07:41 | |
*** holser has joined #rdo | 07:44 | |
*** pcaruana has quit IRC | 07:56 | |
*** apevec has joined #rdo | 07:56 | |
*** apevec has quit IRC | 07:57 | |
*** apevec has joined #rdo | 07:59 | |
*** slaweq has joined #rdo | 07:59 | |
*** jcapitao has quit IRC | 08:00 | |
*** jcapitao has joined #rdo | 08:02 | |
*** rcernin has joined #rdo | 08:07 | |
*** pcaruana has joined #rdo | 08:08 | |
*** rpittau|afk is now known as rpittau | 08:11 | |
*** frenzy_friday has quit IRC | 08:11 | |
*** amoralej has joined #rdo | 08:16 | |
*** frenzy_friday has joined #rdo | 08:21 | |
*** adellam has joined #rdo | 08:23 | |
*** rcernin has quit IRC | 08:24 | |
*** rcernin has joined #rdo | 08:26 | |
*** rcernin has quit IRC | 08:31 | |
*** ykarel is now known as ykarel|lunch | 08:34 | |
*** holser has quit IRC | 08:36 | |
*** rcernin has joined #rdo | 08:37 | |
*** gfidente has joined #rdo | 08:39 | |
*** holser has joined #rdo | 08:40 | |
*** apetrich has joined #rdo | 08:41 | |
jcapitao | amoralej, ykarel|lunch: wrt https://review.rdoproject.org/r/#/c/31733/ I'm wondering if we should tag on -release as well in same patch | 08:41 |
*** xek has joined #rdo | 08:42 | |
amoralej | jcapitao, ci should fail if you tag into -release in the same review | 08:43 |
amoralej | as it checks if it's tagged in -testing first | 08:43 |
*** tosky has joined #rdo | 08:43 | |
jcapitao | amoralej: right makes sense | 08:46 |
rdogerrit | Chandan Kumar proposed rdo-infra/ci-config master: Added --config-root flag https://review.rdoproject.org/r/31700 | 08:47 |
*** jlibosva has joined #rdo | 08:49 | |
*** jpena|off is now known as jpena | 08:58 | |
amoralej | jcapitao, http://lists.openstack.org/pipermail/openstack-discuss/2021-January/020128.html | 09:07 |
amoralej | we may have broken when ssl is used over rabbitmq? | 09:07 |
*** jpich has joined #rdo | 09:07 | |
*** gchamoul has quit IRC | 09:07 | |
amoralej | we need to check if we have ssl on rabbitmq in some CI job | 09:07 |
jcapitao | amoralej: it ring me bells | 09:09 |
jcapitao | when we promoted deps | 09:09 |
jcapitao | i'll check | 09:09 |
amoralej | yes, that's my doubt | 09:09 |
amoralej | i'd say we test it with rabbit and ssl | 09:10 |
amoralej | but let's double check | 09:10 |
*** rcernin has quit IRC | 09:27 | |
*** derekh has joined #rdo | 09:30 | |
rdogerrit | rdo-trunk created openstack/tripleo-common-distgit rpm-master: openstack-tripleo-common: failed to build be7b2317 https://review.rdoproject.org/r/31760 | 09:37 |
*** gchamoul has joined #rdo | 09:38 | |
*** holser has quit IRC | 09:38 | |
*** rcernin has joined #rdo | 09:39 | |
*** ysandeep|afk is now known as ysandeep | 09:43 | |
*** ykarel|lunch is now known as ykarel | 09:44 | |
amoralej | jcapitao, we'll need https://review.opendev.org/q/project:openstack/puppet-nova+topic:c8s to get jobs passing in c8s in stable releases | 09:44 |
amoralej | jcapitao, https://review.opendev.org/c/openstack/puppet-openstack-integration/+/773336, let's see how that goes to test ssl | 09:51 |
amoralej | ykarel, you remember if we have ssl enabled in rabbitmq in some CI job? | 09:51 |
ykarel | amoralej, atleast in poi we disable that | 09:51 |
amoralej | yep, i just sent a review enabling it | 09:52 |
jcapitao | amoralej: ack | 09:52 |
amoralej | let's see | 09:52 |
ykarel | okk let's see | 09:52 |
amoralej | and in oooq? | 09:52 |
amoralej | it seems packstack scenario001 has it enabled | 09:53 |
ykarel | in oooq it is ssl, but it's backed with haproxy | 09:53 |
amoralej | rabbitmq is also accesed via haproxy | 09:53 |
ykarel | so there we hadn't had issue, i recall we had issues with ssl + python3+ eventlet +glance | 09:53 |
amoralej | ? | 09:53 |
amoralej | ykarel, this seems a different issue | 09:53 |
amoralej | see http://lists.openstack.org/pipermail/openstack-discuss/2021-January/020128.html | 09:53 |
ykarel | hmm ^ looks different | 09:54 |
amoralej | i see packstack scenario001 has ssl en rabbit and it's passing | 09:56 |
ykarel | wrt rabbit and haproxy don't how how, i meant ssl+python3+eventlet+glance issue was not seen in oooq as there glance was backed with haproxy | 09:56 |
ykarel | ok good, in packstck all services are not running with ssl? | 09:56 |
amoralej | https://logserver.rdoproject.org/ci.centos.org/weirdo-generic-packstack-scenario001/12670/weirdo-project/logs/nova/nova-conductor.log.txt.gz | 09:57 |
amoralej | no, it's just rabbitmq | 09:57 |
amoralej | but that's the issue they are reporting, iiuc | 09:57 |
ykarel | okk | 09:57 |
amoralej | look at http://lists.openstack.org/pipermail/openstack-discuss/2021-January/020131.html | 09:57 |
amoralej | Jan 30 11:51:04 aio1 nova-conductor[97314]: 2021-01-30 11:51:04.543 97314 ERROR oslo.messaging._drivers.impl_rabbit [req-61609624-b577-475d-996e-bc8f9899eae0 - - - - -] Connection failed: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:897) | 09:57 |
ykarel | in which job u see ^ trace | 09:59 |
amoralej | ykarel, that's in the mail | 09:59 |
amoralej | i asked for more logs in the threade | 09:59 |
amoralej | thread | 09:59 |
ykarel | okk me checks more, i didn't see the trace, but just ssl.SSLError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:897) | 10:00 |
ykarel | now i see in next mails | 10:01 |
amoralej | let's see what we get | 10:01 |
ykarel | amoralej, looks like this is there job https://8b12a56eed7718b4557a-a6fefd00c349ad6bb352c93cc8d24645.ssl.cf1.rackcdn.com/773262/1/check/openstack-ansible-deploy-aio_distro_metal-centos-8/edfa078/logs/host/nova/nova-conductor.log.txt | 10:04 |
ykarel | got from https://review.opendev.org/c/openstack/openstack-ansible/+/773309 | 10:05 |
*** jpich has quit IRC | 10:05 | |
*** jpich has joined #rdo | 10:06 | |
*** rcernin has quit IRC | 10:06 | |
amoralej | it's not passing ssl_cert_file ssl_ca_file and ssl_key_file | 10:07 |
amoralej | https://8b12a56eed7718b4557a-a6fefd00c349ad6bb352c93cc8d24645.ssl.cf1.rackcdn.com/773262/1/check/openstack-ansible-deploy-aio_distro_metal-centos-8/edfa078/logs/etc/host/nova/nova.conf.txt | 10:07 |
amoralej | but apparently it was passing some days ago... | 10:08 |
ykarel | so that's seems the issue than in those jobs | 10:08 |
amoralej | curiously it passes in ussuri with same config | 10:10 |
ykarel | where you see those params are passed? | 10:10 |
amoralej | https://788ee6cdae9ba9a5b6f6-975c20b33c67795c3bd7e62c888a9c6f.ssl.cf2.rackcdn.com/773263/1/check/openstack-ansible-deploy-aio_distro_metal-centos-8/7ef7437/logs/etc/host/nova/nova.conf.txt | 10:10 |
amoralej | that's ussuri | 10:10 |
amoralej | it was passing before 28-jan | 10:11 |
amoralej | which is when we updated kombu/amqp | 10:11 |
noonedeadpunk | Hey folks! We recently started experiencing SSL error related issues | 10:11 |
amoralej | so it may be changing some default value | 10:11 |
noonedeadpunk | I guess you're discussing exactly this case currently... | 10:11 |
amoralej | yes noonedeadpunk | 10:11 |
amoralej | so, where are you seeing that? | 10:12 |
noonedeadpunk | in openstack-ansible. we have jobs which are installing source on centos 8 and with rdo packages | 10:12 |
noonedeadpunk | and rdo one fails | 10:12 |
amoralej | yep, that's what i've seen | 10:12 |
noonedeadpunk | I have both deployments in sandbox and tried to compare package versions in venv pip and provided by rdo, and they seems the same... | 10:13 |
amoralej | noonedeadpunk, so it fails only with packages? | 10:13 |
amoralej | not with pip? | 10:13 |
ykarel | amoralej, seems it's related to https://review.rdoproject.org/r/#/c/31661/ | 10:13 |
noonedeadpunk | yep, correct | 10:13 |
ykarel | wrt timing of failures | 10:13 |
amoralej | ykarel, yes, that's my guess too | 10:13 |
amoralej | noonedeadpunk, it fails when accessing rabbitmq over ssl, right? | 10:13 |
noonedeadpunk | exactly | 10:13 |
amoralej | we have a job with packstack which test that | 10:14 |
amoralej | so i was trying to compare | 10:14 |
amoralej | packstack deployment vs OSA | 10:14 |
amoralej | you have an environment to test? | 10:14 |
noonedeadpunk | in the meanwhile exact same setup but from source does not fail. and packages seems the same though, which is super frustrating | 10:14 |
noonedeadpunk | yep, sure | 10:14 |
amoralej | what i've found is that | 10:14 |
amoralej | in packstack we pass some cert related parameters | 10:15 |
amoralej | ssl_key_file=/etc/pki/tls/private/ssl_amqp_nova.key | 10:15 |
amoralej | ssl_cert_file=/etc/pki/tls/certs/ssl_amqp_nova.crt | 10:15 |
amoralej | ssl_ca_file=/etc/pki/tls/certs/packstack_cacert.crt | 10:15 |
amoralej | https://logserver.rdoproject.org/ci.centos.org/weirdo-generic-packstack-scenario001/12670/weirdo-project/logs/etc/nova/nova.conf.txt.gz | 10:15 |
amoralej | osa is not setting those | 10:15 |
amoralej | how is cacert handled to verify it? | 10:15 |
noonedeadpunk | I think we disabled client verification. we're using certs to encrypt messages only I guess | 10:16 |
*** Caterpillar has joined #rdo | 10:17 | |
noonedeadpunk | and this client part is for using certs for auth I guess? | 10:17 |
noonedeadpunk | we were going to change approach of our ssl usage actually during this cycle but not ready at the moment:) | 10:18 |
noonedeadpunk | https://zuul.opendev.org/t/openstack/build/cbbee71debf3496c89bdca1b97a00cf1/log/logs/etc/host/rabbitmq/rabbitmq.config.txt#22 | 10:19 |
noonedeadpunk | oh, in source install I do have amqp 5.0.2 for some reason... | 10:28 |
ykarel | noonedeadpunk, can u share log url for source install | 10:29 |
noonedeadpunk | sure | 10:29 |
noonedeadpunk | https://zuul.opendev.org/t/openstack/build/ec49eebd78834915bd1a149cf66fd491 | 10:29 |
amoralej | noonedeadpunk, noonedeadpunk i see amqp 5.0.3 changed some stuff related to SSL certs | 10:29 |
amoralej | https://github.com/celery/py-amqp/blob/master/Changelog#L42 | 10:29 |
amoralej | i wonder if it's related | 10:29 |
amoralej | but i'm not sure why it doesn't happen with pip installation | 10:30 |
ykarel | https://github.com/celery/py-amqp/pull/350/commits/e4f1f1df5d45dd2ef9821571e503dade5a2e79e7 also seems related | 10:30 |
noonedeadpunk | as I have 5.02.... | 10:30 |
amoralej | oh | 10:30 |
amoralej | may you try with 5.0.3? | 10:30 |
ykarel | which fixed in 5.0.5 | 10:30 |
noonedeadpunk | not sure yet how I ended up having 5.02 though | 10:30 |
noonedeadpunk | yeah, upper contraints for master is now on 5.0.5 | 10:31 |
noonedeadpunk | and for V on 5.0.2 | 10:31 |
ykarel | yes we also need to rebase to that | 10:31 |
amoralej | that may axplain why it works if we set cacert manually | 10:31 |
amoralej | but not if it's unset | 10:31 |
ykarel | mmm i see 5.0.1 for V | 10:31 |
amoralej | if ca_certs is None ... | 10:31 |
noonedeadpunk | agree 5.0.1 sorry | 10:32 |
noonedeadpunk | yep, 5.0.3 breaks the same way | 10:34 |
rdogerrit | Yatin Karel created rdoinfo master: Rebuild amqp-5.0.5 for wallaby to match u-c https://review.rdoproject.org/r/31761 | 10:34 |
ykarel | and 5.0.5? | 10:34 |
*** sshnaidm|off is now known as sshnaidm|ruck | 10:35 | |
amoralej | ykarel, jcapitao there is 5.0.5 in fedora | 10:35 |
amoralej | we can bump | 10:35 |
* noonedeadpunk waiting for service restart | 10:35 | |
ykarel | amoralej, yeap proposed ^ | 10:35 |
amoralej | ah, i just saw, sorry :) | 10:36 |
noonedeadpunk | well, 5.0.5 doesn't fix it :( | 10:36 |
amoralej | ouch | 10:36 |
ykarel | :( | 10:36 |
amoralej | noonedeadpunk, may you try to set ssl_ca_file= | 10:37 |
noonedeadpunk | I need to have it first lol... we don't generate CA atm... | 10:37 |
*** jbadiapa has joined #rdo | 10:40 | |
noonedeadpunk | ok, but it feels as completely our problem.... | 10:40 |
noonedeadpunk | ssl_ca_file is supposed to be root ca right? | 10:41 |
amoralej | i'm checking if there is something about self-signed and python-amqp | 10:41 |
amoralej | didn't find so far | 10:41 |
amoralej | noonedeadpunk, yes | 10:41 |
noonedeadpunk | I'd say it feels like oslo needs to have an option to override ctx.verify_mode ? | 10:43 |
rdogerrit | Bogdan Dobrelya created rdo-jobs master: DCN test custom mirrors setup https://review.rdoproject.org/r/31762 | 10:50 |
rdogerrit | Joel Capitao created rdo-jobs master: Add weirdo jobs for Victoria on stream tags update https://review.rdoproject.org/r/31763 | 10:51 |
rdogerrit | Bogdan Dobrelya proposed rdo-jobs master: DNM test custom mirrors setup https://review.rdoproject.org/r/31762 | 10:51 |
amoralej | noonedeadpunk, yep, something like that | 10:52 |
amoralej | but see https://github.com/celery/py-amqp/commit/343a00e828d9d2d33998ccaf96dca0b9417f04af | 10:52 |
amoralej | Checking the hostname depends on | 10:52 |
amoralej | having support of the SNI TLS extension and being provided with a | 10:52 |
amoralej | server_hostname value. Another important thing to mention is that | 10:52 |
amoralej | enabling hostname checking automatically sets verify_mode from | 10:52 |
amoralej | ssl.CERT_NONE to ssl.CERT_REQUIRED in the stdlib ssl and it cannot | 10:52 |
amoralej | be set back to ssl.CERT_NONE as long as hostname checking is enabled. | 10:52 |
amoralej | i'm not sure if it's related, but looks suspictious | 10:52 |
rdogerrit | Bogdan Dobrelya proposed rdo-jobs master: DNM test custom mirrors setup https://review.rdoproject.org/r/31762 | 10:52 |
amoralej | noonedeadpunk, anyway, ask oslo guys, they know much more that me about this tbh | 10:53 |
*** dtantsur|afk is now known as dtantsur | 10:54 | |
noonedeadpunk | ok, yes, thanks for help! | 10:54 |
noonedeadpunk | at least now I have direction where to dig | 10:54 |
noonedeadpunk | and pretty specific one) | 10:56 |
rdogerrit | Joel Capitao proposed rdoinfo master: Cross-tag Victoria packages from CentOS 8 to CentOS Stream 8 https://review.rdoproject.org/r/31733 | 11:03 |
rdogerrit | User pojadhav created rdo-infra/ci-config master: WIP : Adding unit tests for storyboard module https://review.rdoproject.org/r/31764 | 11:07 |
amoralej | noonedeadpunk, look at https://github.com/celery/kombu/issues/1149 | 11:07 |
amoralej | it may be also related, it's tricky | 11:08 |
amoralej | mmm i'm not sure :( | 11:08 |
amoralej | it seems it was fixed in 4.6.8 and it was passwith with 4.6.11 | 11:09 |
amoralej | so i dunno | 11:09 |
*** rcernin has joined #rdo | 11:16 | |
*** holser has joined #rdo | 11:17 | |
noonedeadpunk | providing ssl_ca_file works | 11:20 |
noonedeadpunk | that would be pretty easy fix if only we shouldn't change every config of every service now :p | 11:20 |
amoralej | noonedeadpunk, we are hitting the same issue | 11:21 |
amoralej | in p-o-i if we enable ssh | 11:21 |
amoralej | noonedeadpunk, what value are you passing to noonedeadpunk ? | 11:21 |
amoralej | to ssl_ca_file, i meant | 11:21 |
noonedeadpunk | well, I manually generated Root CA, placed and generated new certificates with this new Root ca. And defined `ssl_ca_file = /etc/pki/ca-trust/source/anchors/rootCA.crt` under oslo_messaging_rabbit | 11:22 |
amoralej | ah, ok | 11:23 |
amoralej | anyway, it'd be good if that's a bug | 11:23 |
noonedeadpunk | You meant I can just set it to false or smth? | 11:23 |
amoralej | or a design decission | 11:23 |
amoralej | no, no, i was wondering if there is any trick that you have found :) | 11:23 |
noonedeadpunk | ah:) I haven't start serching yet, since was disturbed by other stuff... | 11:24 |
amoralej | ok | 11:24 |
rdogerrit | Merged openstack/scciclient-distgit rpm-master: Set minimum working version of pyghmi https://review.rdoproject.org/r/31697 | 11:29 |
*** chem has joined #rdo | 11:29 | |
amoralej | noonedeadpunk, may i propose you some test? | 11:41 |
noonedeadpunk | yeah, sure | 11:42 |
noonedeadpunk | I was just looking at this https://opendev.org/openstack/oslo.messaging/src/branch/master/oslo_messaging/_drivers/impl_rabbit.py#L717 but it's not very helpful | 11:43 |
amoralej | your self-signed is a .crt file, right? | 11:43 |
noonedeadpunk | yep | 11:43 |
amoralej | so first, backup your original /etc/ssl/certs/ca-bundle.crt file | 11:43 |
amoralej | replace it by your crt | 11:44 |
amoralej | run /usr/bin/update-ca-trust force-enable && /usr/bin/update-ca-trust extract | 11:44 |
amoralej | and test using python-amqp 5.0.5 | 11:44 |
amoralej | bit wotjpit ssñ_ca_file | 11:45 |
amoralej | ssl_ca_file | 11:45 |
amoralej | my point is addint your crt to the CA used by default | 11:46 |
amoralej | i dunno if it will work but there is some code in p-o-i which does exactly that | 11:46 |
amoralej | https://github.com/openstack/puppet-openstack-integration/blob/master/manifests/cacert.pp | 11:47 |
amoralej | it's worthy to test if it saves you of modifying all config files :) | 11:47 |
noonedeadpunk | I thought I should put it to /etc/pki/ca-trust/source/anchors/ nope? | 11:47 |
amoralej | that may work too | 11:47 |
amoralej | iirc when you update-ca it goes through all certs under anchors | 11:48 |
amoralej | ups | 11:49 |
amoralej | you are right noonedeadpunk | 11:49 |
noonedeadpunk | let me copy it to /etc/ssl/certs/ since in anchors it didn't get extracted for some reason | 11:49 |
amoralej | actually it's https://github.com/openstack/puppet-openstack-integration/blob/master/manifests/params.pp#L6 | 11:49 |
noonedeadpunk | it's first thing I tried - to put into acnhors :( | 11:51 |
amoralej | and you ran /usr/bin/update-ca-trust force-enable && /usr/bin/update-ca-trust extract ? | 11:52 |
noonedeadpunk | yeah. maybe it doesn't like name rootCA.crt | 11:53 |
rdogerrit | Sandeep Yadav created rdo-jobs master: Added initial jobs for pacemaker dependency pipeline https://review.rdoproject.org/r/31765 | 11:53 |
amoralej | my hope was that would incloud in default root ca and with 5.0.5 reads default ca location :( | 11:54 |
noonedeadpunk | ah, in 5.0.5 | 11:54 |
noonedeadpunk | I tried that in rdo env with 5.0.3 | 11:54 |
*** ysandeep is now known as ysandeep|afk | 11:56 | |
noonedeadpunk | let me check with 5.0.5 | 11:56 |
noonedeadpunk | actually what I was trying tyo look at is to make possible to override https://opendev.org/openstack/oslo.messaging/src/branch/master/oslo_messaging/_drivers/impl_rabbit.py#L717 with ssl.CERT_NONE. Then I guess this verifications hshould be passed https://github.com/celery/py-amqp/blob/master/amqp/transport.py#L538 | 11:57 |
*** chem has quit IRC | 11:58 | |
noonedeadpunk | but this does not happen | 12:00 |
*** jcapitao is now known as jcapitao_lunch | 12:03 | |
amoralej | noonedeadpunk, i've copied my crt into | 12:04 |
amoralej | ran those commands and now i can verify my crt | 12:04 |
amoralej | at least using openssl command | 12:04 |
amoralej | on it | 12:04 |
amoralej | not sure if that will be enough for python-amqp | 12:04 |
amoralej | but it's some progress | 12:04 |
noonedeadpunk | yeah on 5.0.5 seems it works nicely | 12:05 |
*** chem has joined #rdo | 12:05 | |
amoralej | so it may need we only need those two things | 12:05 |
amoralej | move to 5.0.5 | 12:05 |
noonedeadpunk | yeah, just generate rootca | 12:06 |
amoralej | yep | 12:06 |
amoralej | that'd be good | 12:06 |
*** chem has quit IRC | 12:12 | |
*** chem has joined #rdo | 12:14 | |
rdogerrit | Merged rdoinfo master: Rebuild amqp-5.0.5 for wallaby to match u-c https://review.rdoproject.org/r/31761 | 12:14 |
*** rlandy has joined #rdo | 12:16 | |
rdogerrit | Merged rdoinfo master: Bump python-memcached to 1.59 https://review.rdoproject.org/r/31717 | 12:24 |
*** jpena is now known as jpena|lunch | 12:30 | |
*** pcaruana has quit IRC | 12:30 | |
*** rcernin has quit IRC | 12:33 | |
rdogerrit | Bogdan Dobrelya proposed rdo-jobs master: DNM test custom mirrors setup https://review.rdoproject.org/r/31762 | 12:38 |
rdogerrit | Alfredo Moralejo created rdoinfo master: Update python-amqp to 5.0.5 in wallaby https://review.rdoproject.org/r/31766 | 12:39 |
amoralej | noonedeadpunk, ^ that will update the package in the repos | 12:39 |
*** pcaruana has joined #rdo | 12:42 | |
*** imcleod_ has joined #rdo | 12:43 | |
*** rcernin has joined #rdo | 12:47 | |
noonedeadpunk | awesome, thanks | 12:47 |
rdogerrit | Bogdan Dobrelya proposed rdo-jobs master: DNM test custom mirrors setup https://review.rdoproject.org/r/31762 | 12:50 |
*** ysandeep|afk is now known as ysandeep | 12:50 | |
rdogerrit | Sandeep Yadav proposed rdo-jobs master: Added initial jobs for pacemaker dependency pipeline https://review.rdoproject.org/r/31765 | 12:52 |
*** jcapitao_lunch is now known as jcapitao | 12:58 | |
*** amoralej is now known as amoralej|lunch | 13:01 | |
*** EmilienM has joined #rdo | 13:04 | |
*** dmacpher has joined #rdo | 13:20 | |
*** jpena|lunch is now known as jpena | 13:24 | |
rdogerrit | Bogdan Dobrelya proposed rdo-infra/ansible-role-tripleo-ci-reproducer master: Properly override custom vars for mirrors https://review.rdoproject.org/r/27758 | 13:24 |
*** rh-jelabarre has joined #rdo | 13:24 | |
*** rh-jelabarre has quit IRC | 13:25 | |
*** rh-jelabarre has joined #rdo | 13:25 | |
*** imcleod_ has quit IRC | 13:31 | |
*** imcleod_ has joined #rdo | 13:31 | |
rdogerrit | Sandeep Yadav proposed rdo-jobs master: Added initial jobs for pacemaker dependency pipeline https://review.rdoproject.org/r/31765 | 13:32 |
rdogerrit | Arx Cruz created rdo-jobs master: Update periodic scenario004 job https://review.rdoproject.org/r/31767 | 13:38 |
*** rcernin has quit IRC | 13:38 | |
rdogerrit | Bogdan Dobrelya proposed rdo-infra/ansible-role-tripleo-ci-reproducer master: Properly override custom vars for mirrors https://review.rdoproject.org/r/27758 | 13:41 |
*** morazi has joined #rdo | 14:00 | |
rdogerrit | Merged rdoinfo master: Promote CBS tags update for victoria-8-release https://review.rdoproject.org/r/31753 | 14:02 |
*** amoralej|lunch is now known as amoralej | 14:08 | |
*** lbragstad has joined #rdo | 14:09 | |
*** lbragstad has quit IRC | 14:16 | |
*** lbragstad has joined #rdo | 14:22 | |
rdogerrit | Joel Capitao proposed rdo-jobs master: Add weirdo jobs for Victoria on stream tags update https://review.rdoproject.org/r/31763 | 14:38 |
rdogerrit | Joel Capitao proposed rdoinfo master: Cross-tag Victoria packages from CentOS 8 to CentOS Stream 8 https://review.rdoproject.org/r/31733 | 14:41 |
*** artom has joined #rdo | 14:41 | |
*** tmazur has joined #rdo | 14:46 | |
rdogerrit | rdo-trunk created openstack/octavia-dashboard-distgit train-rdo: openstack-octavia-ui-4.0.1-1 https://review.rdoproject.org/r/31768 | 14:50 |
rdogerrit | Merged rdo-infra/ci-config master: Add config files on promoter server https://review.rdoproject.org/r/31695 | 14:52 |
rdogerrit | Merged rdo-jobs master: Update periodic scenario004 job https://review.rdoproject.org/r/31767 | 15:08 |
jcapitao | ykarel: https://src.fedoraproject.org/rpms/python-pymemcache/pull-request/5 when you have a chance to review it | 15:21 |
*** ykarel has quit IRC | 15:22 | |
rdogerrit | rdo-trunk created openstack/networking-bagpipe-distgit train-rdo: python-networking-bagpipe-11.0.2-1 https://review.rdoproject.org/r/31769 | 15:30 |
rdogerrit | rdo-trunk created openstack/networking-sfc-distgit train-rdo: python-networking-sfc-9.0.1-1 https://review.rdoproject.org/r/31770 | 15:35 |
rdogerrit | rdo-trunk created openstack/tacker-distgit train-rdo: openstack-tacker-2.0.2-1 https://review.rdoproject.org/r/31771 | 15:40 |
rdogerrit | Michael Turek created rdo-infra/ci-config master: ppc64le: Update trigger times for disk image job https://review.rdoproject.org/r/31772 | 15:45 |
*** jbadiapa has quit IRC | 15:56 | |
*** gchamoul has quit IRC | 15:59 | |
*** gchamoul has joined #rdo | 16:01 | |
spotz | Hey all can we get reviews/workflows on - https://review.rdoproject.org/r/#/c/31650/ https://review.rdoproject.org/r/#/c/31707/ https://review.rdoproject.org/r/#/c/31734/ . I can go ahead and Workflow them if no one else can just want to get the website updated before this week's meeting:) | 16:07 |
*** lmiccini has quit IRC | 16:16 | |
jcapitao | spotz: I think only amoralej and jpena can +W it | 16:19 |
amoralej | merging | 16:19 |
spotz | jcapitao: Systemwise I can, just don't like to if it's my patch | 16:20 |
*** jpich has quit IRC | 16:21 | |
spotz | I've also got aa PR for the centos cloud Sig in their calendar repo. We'll need to repatch when we have real chaiir and co-chaiir vs interim contacts | 16:21 |
spotz | stupid i key!!! | 16:21 |
*** jpich has joined #rdo | 16:21 | |
*** alexmcleod has joined #rdo | 16:22 | |
*** paramite has joined #rdo | 16:22 | |
rdogerrit | User spotz proposed rdo-website master: Add Cloud SiG minutes https://review.rdoproject.org/r/31734 | 16:23 |
spotz | Good catch amoralej! | 16:24 |
jpena | just for reference https://review.rdoproject.org/r/#/admin/groups/3407,members is the list of people who can merge changes in rdo-website | 16:24 |
jpena | I can too, but that's because I have super-admin rights :D | 16:24 |
spotz | Ireally need to update my name for that account in GitHub:) | 16:25 |
*** jbadiapa has joined #rdo | 16:28 | |
rdogerrit | Merged rdo-website master: Last meeting added https://review.rdoproject.org/r/31650 | 16:28 |
rdogerrit | Merged rdo-website master: Update meeting list https://review.rdoproject.org/r/31707 | 16:28 |
*** ysandeep is now known as ysandeep|away | 16:28 | |
rdogerrit | Merged rdo-website master: Add Cloud SiG minutes https://review.rdoproject.org/r/31734 | 16:44 |
rdogerrit | Joel Capitao proposed rdo-jobs master: Add weirdo jobs for Victoria on stream tags update https://review.rdoproject.org/r/31763 | 16:48 |
rdogerrit | Joel Capitao proposed rdoinfo master: [WIP] Cross-tag Victoria packages from CentOS 8 to CentOS Stream 8 https://review.rdoproject.org/r/31733 | 16:49 |
*** gchamoul has quit IRC | 16:56 | |
*** dtantsur is now known as dtantsur|afk | 17:00 | |
rdogerrit | Joel Capitao proposed rdoinfo master: [WIP] Cross-tag Victoria packages from CentOS 8 to CentOS Stream 8 https://review.rdoproject.org/r/31733 | 17:03 |
*** marios is now known as marios|out | 17:04 | |
rdogerrit | Joel Capitao proposed rdoinfo master: [WIP] Cross-tag Victoria packages from CentOS 8 to CentOS Stream 8 https://review.rdoproject.org/r/31733 | 17:11 |
*** jpodivin has quit IRC | 17:12 | |
*** marios|out has quit IRC | 17:15 | |
rdogerrit | rdo-trunk created openstack/kolla-distgit train-rdo: openstack-kolla-9.3.1-1 https://review.rdoproject.org/r/31773 | 17:20 |
*** rpittau is now known as rpittau|afk | 17:21 | |
rdogerrit | Joel Capitao proposed rdoinfo master: Cross-tag Victoria packages from CentOS 8 to CentOS Stream 8 https://review.rdoproject.org/r/31733 | 17:24 |
*** jcapitao has quit IRC | 17:24 | |
*** jpich has quit IRC | 17:27 | |
rdogerrit | rdo-trunk created openstack/manila-distgit train-rdo: openstack-manila-9.1.5-1 https://review.rdoproject.org/r/31774 | 17:30 |
rdogerrit | rdo-trunk created openstack/manila-distgit victoria-rdo: openstack-manila-11.0.1-1 https://review.rdoproject.org/r/31775 | 17:31 |
*** jbadiapa has quit IRC | 17:34 | |
rdogerrit | User pojadhav proposed rdo-infra/ci-config master: WIP : Adding unit tests for storyboard module https://review.rdoproject.org/r/31764 | 17:37 |
rdogerrit | rdo-trunk created openstack/manila-distgit ussuri-rdo: openstack-manila-10.0.2-1 https://review.rdoproject.org/r/31776 | 17:40 |
*** derekh has quit IRC | 17:56 | |
*** jpena is now known as jpena|off | 18:04 | |
mjturek | amoralej could you review https://review.rdoproject.org/r/#/c/31772/ when you have a moment? it's a simple trigger timing change | 18:08 |
amoralej | merging | 18:10 |
*** amoralej is now known as amoralej|off | 18:10 | |
*** gfidente is now known as gfidente|afk | 18:11 | |
*** jlibosva has quit IRC | 18:12 | |
rdogerrit | Merged rdo-infra/ci-config master: ppc64le: Update trigger times for disk image job https://review.rdoproject.org/r/31772 | 18:16 |
rdogerrit | rdo-trunk created openstack/sahara-image-elements-distgit train-rdo: sahara-image-elements-11.0.1-1 https://review.rdoproject.org/r/31777 | 18:25 |
*** skramaja has quit IRC | 18:35 | |
rdogerrit | rdo-trunk created openstack/ironic-prometheus-exporter-distgit train-rdo: python-ironic-prometheus-exporter-1.1.2-1 https://review.rdoproject.org/r/31778 | 18:35 |
rdogerrit | rdo-trunk created openstack/ec2-api-distgit train-rdo: openstack-ec2-api-9.0.1-1 https://review.rdoproject.org/r/31779 | 18:35 |
rdogerrit | rdo-trunk created openstack/ironic-inspector-distgit train-rdo: openstack-ironic-inspector-9.2.4-1 https://review.rdoproject.org/r/31780 | 18:40 |
rdogerrit | rdo-trunk created openstack/ironic-python-agent-distgit train-rdo: openstack-ironic-python-agent-5.0.4-1 https://review.rdoproject.org/r/31781 | 18:41 |
*** bandini has quit IRC | 18:41 | |
*** dsneddon has joined #rdo | 18:42 | |
*** adellam has quit IRC | 18:44 | |
*** gchamoul has joined #rdo | 18:58 | |
rdogerrit | rdo-trunk created openstack/ceilometer-distgit train-rdo: openstack-ceilometer-13.1.2-1 https://review.rdoproject.org/r/31782 | 19:00 |
*** gchamoul has quit IRC | 19:01 | |
rdogerrit | Merged openstack/sahara-image-elements-distgit train-rdo: sahara-image-elements-11.0.1-1 https://review.rdoproject.org/r/31777 | 19:15 |
*** gchamoul has joined #rdo | 19:44 | |
*** zbr5 has joined #rdo | 19:46 | |
*** zbr has quit IRC | 19:47 | |
*** zbr5 is now known as zbr | 19:47 | |
*** Iambchop_ has joined #rdo | 20:18 | |
*** jrosser_ has joined #rdo | 20:18 | |
*** jrosser has quit IRC | 20:26 | |
*** Iambchop has quit IRC | 20:26 | |
*** zigo has quit IRC | 20:26 | |
*** jrosser_ is now known as jrosser | 20:26 | |
*** Iambchop_ is now known as Iambchop | 20:26 | |
*** zigo has joined #rdo | 20:34 | |
*** dsneddon has quit IRC | 21:15 | |
*** xek has quit IRC | 21:17 | |
*** paramite has quit IRC | 21:35 | |
*** ccamposr has joined #rdo | 21:45 | |
*** ccamposr__ has quit IRC | 21:48 | |
*** Caterpillar has quit IRC | 21:50 | |
*** apevec has quit IRC | 22:00 | |
*** jbadiapa has joined #rdo | 22:03 | |
*** jbadiapa has quit IRC | 22:07 | |
*** rcernin has joined #rdo | 22:20 | |
*** dsneddon has joined #rdo | 22:46 | |
*** slaweq has quit IRC | 23:01 | |
*** gchamoul-tmp has quit IRC | 23:33 | |
*** gfidente|afk has quit IRC | 23:36 | |
*** tosky has quit IRC | 23:52 | |
*** tmazur has quit IRC | 23:56 |
Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!