12:00:09 #startmeeting barbican 12:00:10 Meeting started Tue Jun 26 12:00:09 2018 UTC and is due to finish in 60 minutes. The chair is redrobot. Information about MeetBot at http://wiki.debian.org/MeetBot. 12:00:11 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 12:00:13 The meeting name has been set to 'barbican' 12:00:19 #topic Roll Call 12:00:53 hi 12:00:58 o/ 12:01:06 ✋ 12:01:09 hi namnh! 12:01:32 hi guys 12:01:54 hi redrobot :) 12:01:54 o/ 12:01:58 hi all 12:02:00 o/ 12:03:08 lots of folks here today! 😁 12:03:25 Here is the link to the agenda: 12:03:27 #link https://wiki.openstack.org/wiki/Meetings/Barbican 12:03:41 which I'm not sure anyone uses... 12:03:46 so we're just going to wing it again 12:04:07 :) 12:04:46 Let's see.. 12:04:52 #topic Action Items from last meeting 12:04:53 LOL, sorry, i did not append my topic today, so can I still discuss as usual 12:05:01 #link http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-06-19-12.01.html 12:05:19 "Luzi to add a story to Storyboard for adding AES 512 keys to barbican" 12:05:37 done 12:05:43 and up for review 12:05:58 https://review.openstack.org/#/c/577096/ 12:06:00 #link https://storyboard.openstack.org/#!/story/2002612 12:06:14 #link https://review.openstack.org/#/c/577096/ 12:06:32 I have not had a chance to review, unfortunately. But I'll try to get to it this week for sure. 12:06:53 anything you need to mention Luzi ? 12:07:40 not really 12:07:47 ok, moving on 12:08:08 "redrobot to follow up with infra team regarding the meeting time change on the eavesdrop website" 12:08:23 I didn't talk to the infra folks... but the time has been updated on the eavesdrop site: 12:08:40 #link http://eavesdrop.openstack.org/#Barbican_Meeting 12:08:45 so I think we're good on that 12:08:57 ok, moving on 12:09:41 #topic Castellan key store as base service 12:09:47 #link https://review.openstack.org/#/c/572656/ 12:10:16 looks like the patch to openstack/governance has merged 12:10:18 which is awesome 12:10:30 🎉🎉🎉 12:11:01 I think Castellan still needs some TLC, but I don't have any patches to talk about right now. 12:11:02 great news 12:12:11 that's all I have for Castellan... 12:12:15 any questions/comments? 12:13:44 ok, moving on 12:13:52 namnh, you said you had a topic to talk about? 12:14:28 yeah, for rolling upgrade in barbican. that I am taking care 12:14:41 #topic Rolling Upgrades 12:14:43 namnh, go ahead 12:15:03 some patch sets. https://review.openstack.org/#/c/500244 12:15:31 which i would like to get some reviews 12:15:53 redrobot: would you mind helping me to review the patch sets. 12:16:29 normally, Ade will review the patches for me. but i don't see him recently 12:16:56 I've started looking at the OVO[3] patch. Unfortunately, my review has been quite slow as I am not familiar with a lot of the stuff that is being changed. 12:17:00 do you know reasons? 12:17:14 yeah, Ade has been on vacation for about 2 weeks 12:17:22 I think he _may_ be back next week? 12:17:44 that's why I've been doing the meetings the last couple of weeks. 😬 12:18:08 I understood, thanks :) 12:18:26 Luzi, ducnv lxkong please feel free to review as well ☝ 12:19:04 anything else you want to comment about namnh ? 12:19:16 moreover, I am writing unit-tests for it. you can review it, and i think it will be easy for you to understand 12:19:31 https://review.openstack.org/#/c/576409 12:19:48 i will push more patch set about unit-test on this week. 12:20:11 #help we need more reviews on namnh's OVO patches 12:20:12 it will be great to get your comment. 12:20:20 redrobot: thanks :) 12:20:24 redrobot, i am quite new :)) 12:20:58 redrobot: duc is my co-worker, he will join barbican team for now on :) 12:21:12 ducnv, welcome! 😁 12:21:50 :)) 12:22:05 okay, that's all my comments 12:22:11 this is first day I join channel 12:23:16 ducnv, well, I'm glad you've decided to join us. 😁 12:23:20 ok, moving on 12:23:52 anyone else have topics that didn't make it to the Agenda? 12:25:23 I'll take that as a no. 12:25:38 I can't think of anything else off the top of my head 12:25:52 guys, may i ask a question? I asked several days ago but didn't get any answer. Not sure it's a good chance 12:26:04 lxkong, sure, what's up? 12:26:14 Did anyone of you already deploy Barbican in production? 12:26:33 I'm asking because we are going to deploy barbican in our cloud 12:27:06 but we are happy to know if there is anyone already done that, pitfalls, experiences, etc. 12:27:10 no but we are planning to do so 12:27:13 I deployed Barbican to production at Rackspace a couple of years ago. Unfortunately, it's not online anymore. 12:27:34 redrobot: which secret store backend were you using? 12:27:49 PKCS#11 backed by Safenet Luna SA HSMs 12:27:57 we had 2x HSMs per deployment 12:28:00 for HA 12:28:26 as well as offsite key backups of the master keys in Safenet backup devices 12:29:02 there is an open source HSM implementation named SoftHSM, anyone has experince of it? 12:29:19 we are a small company relies on open source software 12:29:29 so maybe the hardware HSM is not our option :-( 12:30:16 I've played around with SoftHSM before 12:30:39 redrobot: did you try to integrate that with Barbican? 12:30:47 does that work? 12:30:50 to be honest, I think it may be more trouble than it's worth... I think you may be able to get the same level of security with the SimpleCrypto backend 12:31:10 SoftHSM had some issues, as the mechanisms available are different than Safenet Luna's 12:31:23 even though they're both PKCS#11 12:31:36 but at the end of the day, SoftHSM is just a key in memory, just like SimpleCrypto 12:32:07 hmm... 12:32:10 SoftHSM v2 is supposed to be a lot better, but I'm not sure what the status of it is 12:32:35 it's been a couple of years since I looked at it, and v2 was just starting to be developed back then. 12:32:56 yeah, we are jsut going to evaluate v2 12:33:58 using PKCS#11 + SoftHSM will make it possible to migrate to hardware HSM in future, right? 12:34:37 lxkong, yes, I think so... especially if you can extract the master key from SoftHSM and store it in the real HSM 12:34:45 the p11 plugin may need some work 12:35:11 depending on what mechanisms SoftHSM v2 makes available 12:35:21 seems we will have a lot of work to do 12:35:37 yup 😬 12:36:04 redrobot: thanks so much for your answer 12:36:08 let me know if you run into issues with PKCS#11 as it is something that I'm super interested in 12:36:44 Luzi: you said you are also going to deploy barbican, anything wanna share? 12:36:50 we want 12:37:36 we are currently evaluating Safenet HSM 12:37:59 ok, you are rich :-) 12:38:25 i am not... i just work in a nice team :) 12:38:39 Luzi: good to know anyway, thanks 12:39:36 redrobot: i'm done 12:39:41 cool 12:39:45 any other topics? 12:40:54 alrighty then... looks like we're finished with 20 minutes to spare! 😁 12:40:59 #endmeeting