13:00:12 #startmeeting barbican 13:00:13 Meeting started Tue Dec 4 13:00:12 2018 UTC and is due to finish in 60 minutes. The chair is redrobot. Information about MeetBot at http://wiki.debian.org/MeetBot. 13:00:14 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 13:00:16 The meeting name has been set to 'barbican' 13:00:21 #topic Roll Call 13:00:59 Courtesy ping for Luzi lxkong moguimar rm_work xek 13:01:05 \o 13:01:07 o/ 13:01:11 o/\o 13:01:11 o/ 13:01:57 As per usual, our agenda is here: 13:01:59 #link https://wiki.openstack.org/wiki/Meetings/Barbican 13:02:19 And as usual there's nothing for today ... 😅 13:02:25 So we'll make it up as usual 13:03:36 We didn't have any action items last week ... so nothing to talk about there. 13:04:06 #topic HSM Support in TripleO 13:04:41 I'm not sure if you're aware, Luzi, but we've been working on getting support for a couple of HSMs in TripleO 13:04:55 that's nice 13:05:13 which one are you supporting? 13:05:35 or wanting to support 13:05:41 The first one we're working on is Thales 13:05:52 and we are also working on getting an ATOS one working as well 13:05:59 We have 3 patches for the Thales support 13:06:03 this one already merged: 13:06:05 #link https://review.openstack.org/#/c/608339/ 13:06:22 These two still need reviews: 13:06:23 #link https://review.openstack.org/#/c/610629/ 13:06:33 #link https://review.openstack.org/#/c/610634/ 13:07:19 I'm also working on a patch for the Kolla project to get a new group added to the barbican user account inside the images. 13:07:40 We'll need it so that Barbican is able to talk to the Thales daemon that communicates with the HSM. 13:08:10 Luzi, I'm not sure about the specific models for those, but I can probably find out if you're curious. 13:08:36 We also got Yubico to send us a couple of YubiHSM 2s. 13:09:06 But their support for PKCS#11 is somewhat limited, and it won't work with our current PKCS#11 backend implementation. 13:09:37 o/ 13:10:44 well it's certainly good to know, what HSMs are working with Barbican, and which ones doesn't right now 13:10:47 hi moguimar 13:11:46 The PKCS#11 plugin was originally written for the Safenet Luna SA (now Gemalto Network HSM). I haven't tested it since I left Rackspace, but I expect it to still work. 13:12:26 I think it would be good to document which specific models have been tested. We'll probably add it to the Barbican and/or TripleO docs as part of this effort. 13:12:44 it definitly works as we tested it with a gemalto HSM 13:13:09 Awesome! 😎 13:13:16 I'm glad we haven't broken anything, lol 13:16:15 OK, moving on 13:16:32 ... 13:17:02 #topic Reviews 13:17:05 #link https://tinyurl.com/yctfozgh 13:17:17 Just the usual weekly reminder to review things 13:18:40 ... and that's all the topics I can think of given the small amount of coffee I've consumed today. 13:18:54 Anything y'all want to talk about Luzi or moguimar ? 13:19:45 nope 13:20:26 not really 13:20:46 Alrighty, I think we can wrap it up for the meeting then. 13:20:51 Thanks for coming, guys! 13:20:58 #endmeeting