*** ryanpetrello has joined #openstack-barbican | 00:08 | |
*** ryanpetrello has quit IRC | 00:23 | |
*** akoneru has joined #openstack-barbican | 00:30 | |
*** bdpayne_ has joined #openstack-barbican | 00:31 | |
*** bdpayne has quit IRC | 00:33 | |
*** nkinder has joined #openstack-barbican | 00:47 | |
*** ryanpetrello has joined #openstack-barbican | 00:56 | |
*** bdpayne_ has quit IRC | 00:56 | |
*** morganfainberg has joined #openstack-barbican | 01:04 | |
morganfainberg | ooh i wasn't lurking in this channel already | 01:04 |
---|---|---|
dstufft | lurker | 01:06 |
dstufft | :D | 01:06 |
morganfainberg | ^_^ | 01:06 |
morganfainberg | http://goo.gl/forms/4W7xVM9x49 if anyone is interested in the KEystone mid-cycle | 01:18 |
*** gyee has quit IRC | 01:27 | |
*** ryanpetrello has quit IRC | 01:39 | |
rm_you | hmm, if that's at RS again I might stop by just out of principle | 01:53 |
morganfainberg | rm_you, likely it'll be in Sunnyvale or Mountain View. but it's still up in the air. | 02:16 |
morganfainberg | rm_you, we'll see what the survey results say | 02:17 |
*** dave-mccowan_ has joined #openstack-barbican | 02:18 | |
*** dave-mccowan has quit IRC | 02:19 | |
*** dave-mccowan_ is now known as dave-mccowan | 02:19 | |
*** ayoung has joined #openstack-barbican | 02:29 | |
*** openstackgerrit has quit IRC | 02:34 | |
*** rsyed is now known as rsyed_away | 02:40 | |
*** SheenaG1 has joined #openstack-barbican | 03:16 | |
*** akoneru has quit IRC | 03:59 | |
*** dave-mccowan has quit IRC | 04:26 | |
*** akoneru has joined #openstack-barbican | 05:11 | |
*** liam_ has joined #openstack-barbican | 07:22 | |
*** liam_ is now known as Guest46061 | 07:23 | |
*** Guest46061 has quit IRC | 07:28 | |
*** rm_you| has joined #openstack-barbican | 07:35 | |
*** rm_you has quit IRC | 07:38 | |
*** akoneru has quit IRC | 11:14 | |
*** rm_you| has quit IRC | 11:17 | |
*** rm_you| has joined #openstack-barbican | 11:17 | |
*** dave-mccowan has joined #openstack-barbican | 11:58 | |
*** dave-mccowan has quit IRC | 12:02 | |
*** dave-mccowan has joined #openstack-barbican | 12:03 | |
*** rm_you| has quit IRC | 12:08 | |
*** rm_you| has joined #openstack-barbican | 12:08 | |
*** jaosorior has joined #openstack-barbican | 12:15 | |
*** ryanpetrello has joined #openstack-barbican | 12:38 | |
*** rellerreller has joined #openstack-barbican | 13:01 | |
*** akoneru has joined #openstack-barbican | 13:41 | |
*** dave-mccowan has quit IRC | 13:47 | |
*** rsyed_away is now known as rsyed | 13:48 | |
*** rellerreller has quit IRC | 13:53 | |
*** joesavak has joined #openstack-barbican | 14:07 | |
*** nkinder has quit IRC | 14:18 | |
*** openstackgerrit has joined #openstack-barbican | 14:40 | |
*** SheenaG1 has quit IRC | 14:43 | |
*** ametts has joined #openstack-barbican | 14:50 | |
*** paul_glass has joined #openstack-barbican | 15:01 | |
*** tdink has joined #openstack-barbican | 15:01 | |
*** SheenaG1 has joined #openstack-barbican | 15:03 | |
*** SheenaG11 has joined #openstack-barbican | 15:07 | |
*** SheenaG1 has quit IRC | 15:07 | |
*** nkinder has joined #openstack-barbican | 15:10 | |
chellygel | rm_work, rm_you| | 15:14 |
openstackgerrit | Tim Kelsey proposed openstack/barbican: Fix communication of secret_type info https://review.openstack.org/133695 | 15:17 |
*** ryanpetrello has quit IRC | 15:19 | |
*** zz_dimtruck is now known as dimtruck | 15:23 | |
*** ryanpetrello has joined #openstack-barbican | 15:25 | |
openstackgerrit | Tim Kelsey proposed openstack/barbican: Fix communication of secret_type info https://review.openstack.org/133695 | 15:31 |
*** ayoung is now known as ayoung-afk | 15:53 | |
*** JeffF has joined #openstack-barbican | 15:56 | |
*** paul_glass has quit IRC | 15:59 | |
openstackgerrit | Tim Kelsey proposed openstack/barbican: Fix communication of secret_type info https://review.openstack.org/133695 | 16:02 |
*** david-lyle has joined #openstack-barbican | 16:04 | |
*** kebray has joined #openstack-barbican | 16:09 | |
chellygel | redrobot, YT? | 16:12 |
*** kebray has quit IRC | 16:16 | |
*** alee has quit IRC | 16:18 | |
*** dave-mccowan has joined #openstack-barbican | 16:24 | |
*** dave-mccowan_ has joined #openstack-barbican | 16:26 | |
redrobot | chellygel YT? | 16:28 |
*** dave-mccowan has quit IRC | 16:29 | |
*** dave-mccowan_ is now known as dave-mccowan | 16:29 | |
SheenaG11 | redrobot: stand up! | 16:29 |
*** alee has joined #openstack-barbican | 16:30 | |
chellygel | redrobot, just looking for the blueprint for CA discovery API -- didnt see a link to it and im on LP looking for it. | 16:30 |
SheenaG11 | chellygel: that's my fault, I'll add those to the stories | 16:30 |
redrobot | SheenaG11 but I like sitting down. | 16:31 |
SheenaG11 | STAND UP FOR WHAT | 16:31 |
SheenaG11 | related: i had coffee this morning | 16:31 |
*** gyee has joined #openstack-barbican | 16:45 | |
alee | redrobot, ping | 16:55 |
redrobot | alee pong | 16:55 |
alee | redrobot, I'm trying to figure out how to start barbican | 16:56 |
alee | that is -- I have a fresh vm in which I have installed the barbican libs etc. | 16:56 |
redrobot | alee barbican.sh not working? | 16:56 |
alee | via an rpm -- and am trying to figuere out how barbican.sh works | 16:57 |
redrobot | ah... was the rpm built from the SPEC in the repo? | 16:57 |
*** ayoung-afk is now known as ayoung | 16:57 | |
alee | redrobot, no - from my own spec based on what is there. | 16:57 |
alee | redrobot, so just trying to understand barbican.sh | 16:58 |
redrobot | so, the spec file pre-dates barbican.sh | 16:58 |
alee | redrobot, start_barbican essentially calls .. | 16:58 |
*** tdink_ has joined #openstack-barbican | 16:58 | |
redrobot | alee the RPM was configured to use Upstart to run the service. https://github.com/openstack/barbican/blob/master/etc/init/barbican-api.conf | 16:59 |
redrobot | you should be able to just do: | 16:59 |
redrobot | service barbican-api start | 16:59 |
alee | uwsgi --master --die-on-term --emperor /etc/barbican/vassals --logto /var/log/barbican/barbican-api.log --stats localhost:9314 | 16:59 |
alee | so its basically doing that ^^ | 17:00 |
alee | in your example .. | 17:00 |
redrobot | alee yup. Although the assumption that everyone will be using uwsgi may not be true for a general use RPM. | 17:00 |
alee | redrobot, or I tried doing .. | 17:00 |
alee | uwsgi --master --emperor /etc/barbican/vassals | 17:01 |
alee | now - when I do that -- I see uwsgi come up but no app is loaded | 17:01 |
*** tdink has quit IRC | 17:01 | |
alee | redrobot, so what tells uwsgi what to load up? | 17:02 |
*** rm_you| has quit IRC | 17:02 | |
redrobot | alee --emperor /etc/barbican/vassals tells uwsgi to run in emperor mode. It looks at all files in the vassals directory and spins up a process for each file. | 17:02 |
*** rm_you| has joined #openstack-barbican | 17:02 | |
*** joesavak has quit IRC | 17:03 | |
alee | redrobot, ok so this is whats in my vassals directory | 17:03 |
*** joesavak has joined #openstack-barbican | 17:04 | |
redrobot | alee https://github.com/openstack/barbican/tree/master/etc/barbican/vassals | 17:04 |
alee | [root@vm-056 SPECS]# ls /etc/barbican/vassals/ | 17:04 |
alee | barbican-admin.ini barbican-api.ini | 17:04 |
redrobot | ? | 17:04 |
alee | checking if they are the samme | 17:04 |
redrobot | alee looks right. Each INI file then points to a paste file. | 17:04 |
redrobot | also, as a sanity check you can start up a repl and make sure you can "import barbican" | 17:05 |
alee | redrobot, start up a repl? | 17:08 |
redrobot | alee python interactive session | 17:09 |
redrobot | alee my debug path is: Make sure confs are ok, then make sure that barbican is properly installed in the python packages. | 17:09 |
redrobot | if "import barbican" doesn't throw any errors, it means that Python can find the modules. | 17:10 |
alee | ok - pyhton can find the modules | 17:11 |
redrobot | "sudo start barbican-api" didn't work? | 17:12 |
alee | redrobot, ot using upstart | 17:13 |
redrobot | hmmm... anything helpful in the logs? | 17:13 |
alee | redrobot, let me paste my log | 17:14 |
*** paul_glass has joined #openstack-barbican | 17:18 | |
*** tdink_ has quit IRC | 17:24 | |
*** tdink has joined #openstack-barbican | 17:25 | |
alee | redrobot, http://fpaste.org/150135/81324414/ | 17:27 |
alee | redrobot, so it reads the config files but then loads nothing up afaics | 17:28 |
redrobot | alee that's really strange... I wonder if this is the problem? | 17:33 |
redrobot | !!! UNABLE to load uWSGI plugin: /usr/lib64/uwsgi/python_plugin.so: cannot open shared object file: No such file or directory !!! | 17:33 |
openstack | redrobot: Error: "!!" is not a valid command. | 17:33 |
redrobot | how did you install uwsgi? | 17:33 |
alee | redrobot, openstack does not like !! ! | 17:33 |
alee | redrobot, yum install uwsgi | 17:33 |
redrobot | is there a uwsgi-python perhaps? | 17:34 |
redrobot | not sure how uwsgi is packaged... we ended up having to FPM our own uwsgi | 17:34 |
rsyed | alee the yum version of uwsgi is modular...you'd have to install the python plugin (not sure what the package name is) | 17:34 |
rsyed | uwsgi-plugin-python it appears | 17:34 |
alee | rsyed, thanks - trying that | 17:36 |
rsyed | you may need other plugins, depending on how barbican runs uwsgi (i'm not familiar with it). for example if you wanted the http functionality, you'd need the http plugin | 17:37 |
alee | rsyed, yeah -- I'll try adding more modules | 17:38 |
alee | redrobot, rsyed - yeah adding the python module helped -- now at least its trying to load something (and failing) | 17:41 |
alee | but I have soemthing to debug now | 17:42 |
*** paul_glass has quit IRC | 17:42 | |
*** paul_glass has joined #openstack-barbican | 17:44 | |
*** paul_glass has quit IRC | 17:44 | |
*** paul_glass has joined #openstack-barbican | 17:47 | |
*** paul_glass has quit IRC | 17:49 | |
*** kebray has joined #openstack-barbican | 18:02 | |
*** atiwari has joined #openstack-barbican | 18:22 | |
*** bdpayne has joined #openstack-barbican | 18:24 | |
*** alee has quit IRC | 18:33 | |
*** alee has joined #openstack-barbican | 18:33 | |
morganfainberg | can anyone tell me where barbican midcycle is tentatively being planned for? | 18:40 |
morganfainberg | is it San Antonio? (geekdom/rax)? | 18:40 |
chellygel | morganfainberg, last i heard was maybe San Francisco | 18:41 |
chellygel | no final decision yet though morganfainberg | 18:41 |
morganfainberg | chellygel, hm. ok. | 18:41 |
morganfainberg | if it's the bay that makes it easier for me to decide we're doing bay for Keystone as well. | 18:41 |
morganfainberg | even though (unfortunately) it means a few rackspace people can't come. | 18:42 |
chellygel | i think that was the hope | 18:42 |
chellygel | was to do them together | 18:42 |
morganfainberg | yeah, looks like if we're doing bay it'll be at RedHat for keystone | 18:42 |
morganfainberg | so mountain view | 18:42 |
chellygel | oh whoa | 18:42 |
redrobot | morganfainberg yeah, no concrete plans yet. SFO was tossed around as an option since we have Rackspace event space available to us for free. | 18:42 |
morganfainberg | and the overwhelming preference is Jan 19-21 for us (mon, tues, wed) | 18:43 |
morganfainberg | i mean, i'm also happy to occupy Rackspace event space ;) | 18:44 |
morganfainberg | but RH has offered to directly supply space as well. | 18:44 |
morganfainberg | who should i speak with for info on event space [if we can actually share the space that is] | 18:45 |
morganfainberg | ? | 18:45 |
redrobot | morganfainberg I can poke some people here on our end. I don't foresee any problems with sharing space. | 18:45 |
morganfainberg | redrobot, great i'll run with the assumption that Jan 19 - 21 is our preferred dates on keystone side [i have a committment to be elsewhere in the bay later that week and most people seem to prefer the earlier weekdays anyway] | 18:46 |
morganfainberg | redrobot, and if it doesn't work for us to use the same space i do also have RH space offered. | 18:47 |
redrobot | morganfainberg noted. I'll poke some people here and get back to you as soon as I have some answers. | 18:47 |
*** tdink_ has joined #openstack-barbican | 18:55 | |
*** jsavak has joined #openstack-barbican | 18:58 | |
*** tdink has quit IRC | 18:59 | |
*** tdink_ has quit IRC | 18:59 | |
*** joesavak has quit IRC | 19:02 | |
*** tdink has joined #openstack-barbican | 19:04 | |
*** paul_glass has joined #openstack-barbican | 19:07 | |
*** kebray has quit IRC | 19:08 | |
*** kebray has joined #openstack-barbican | 19:12 | |
rm_work | chellygel: you back? :P | 19:24 |
chellygel | aye rm_work | 19:24 |
rm_work | cool :) | 19:24 |
chellygel | que paso | 19:25 |
rm_work | chellygel: do you know if the serial number for cert signing matters at all if we're just doing a bunch of self signed certs for internal use? | 19:25 |
rm_work | someone said you were the Cert expert :P | 19:25 |
chellygel | ha | 19:25 |
chellygel | im working on being that person | 19:25 |
chellygel | im not sure about that though | 19:25 |
chellygel | im not even sure about a serial number rm_work | 19:26 |
SheenaG11 | rm_work: I don't know what that is either, is that just a unique identifier per cert? | 19:26 |
rm_work | yes | 19:26 |
rm_work | I believe it is used for revocations maybe? | 19:26 |
rm_work | though I don't know for sure | 19:26 |
dstufft | you want some randomness in the serial number | 19:27 |
SheenaG11 | Symantec uses the cert to process the revoke | 19:27 |
rm_work | the best description i could find was essentially "bookkeeping purposes" | 19:27 |
SheenaG11 | But there is a uuid associated with the RAX order I think | 19:27 |
SheenaG11 | We should probably still have a serial number since domain isn't unique across certs | 19:27 |
dstufft | well a cert has to have a serial number afaik | 19:27 |
dstufft | https://github.com/saltstack/salt/issues/16744 | 19:27 |
rm_work | dstufft: but like, if i just set all of them to "0" will they not work or something? | 19:28 |
dstufft | ^^ some info on that ticket | 19:28 |
dstufft | that i'm too lazy to copy/paste | 19:28 |
rm_work | ok interesting | 19:28 |
dstufft | Note: Most of that was copy/pasted from reaperhulk telling me things | 19:28 |
rm_work | yeah I'm down for their randomization thing | 19:28 |
rm_work | binascii.hexlify(os.urandom(20)) seems good to me :) | 19:29 |
dstufft | https://github.com/python/psf-salt/blob/master/salt/_extensions/pillar/ca.py#L69-L70 | 19:29 |
dstufft | int(binascii.hexlify(os.urandom(20)), 16) techincally | 19:29 |
rm_work | kk | 19:29 |
rm_work | copy/pasting that whole method | 19:30 |
rm_work | hmm the licenses are compatible, right? :P | 19:30 |
rm_work | dstufft: thanks | 19:32 |
chellygel | rm_work, see not a cert master | 19:33 |
chellygel | lol | 19:33 |
rm_work | :P | 19:33 |
rm_work | that question was particularly specific and unusual tho :) | 19:33 |
*** tdink_ has joined #openstack-barbican | 19:33 | |
dstufft | the licenses on psf-salt is Apache 2 | 19:34 |
*** tdink has quit IRC | 19:34 | |
dstufft | and I wrote it | 19:34 |
dstufft | so if it wasn't I could just relicense it | 19:34 |
rm_work | heh | 19:34 |
rm_work | I don't think it matters much for a single line that's not particularly special :) | 19:34 |
dstufft | yea | 19:35 |
dstufft | I'd argue that particular line isn't a creative work and that copyright doesn't really apply | 19:35 |
*** tdink_ has quit IRC | 19:37 | |
*** tdink has joined #openstack-barbican | 19:45 | |
*** darrenmoffat has quit IRC | 19:48 | |
*** darrenmoffat has joined #openstack-barbican | 19:49 | |
*** bdpayne has quit IRC | 19:54 | |
*** tdink has quit IRC | 19:56 | |
*** jsavak has quit IRC | 20:01 | |
*** joesavak has joined #openstack-barbican | 20:03 | |
*** jaosorior has quit IRC | 20:03 | |
*** paul_glass has quit IRC | 20:05 | |
*** liam_ has joined #openstack-barbican | 20:05 | |
*** liam_ is now known as Guest39243 | 20:05 | |
*** Guest39243 has quit IRC | 20:06 | |
*** tdink has joined #openstack-barbican | 20:12 | |
*** tdink_ has joined #openstack-barbican | 20:13 | |
*** tdink has quit IRC | 20:16 | |
*** tdink_ has quit IRC | 20:18 | |
*** bdpayne has joined #openstack-barbican | 20:42 | |
redrobot | rm_work serial number matters to the issuer, since they need to reference it for revokation, etc. | 20:46 |
rm_work | ok | 20:46 |
rm_work | I'm not building any provisions for revocation into this | 20:47 |
rm_work | so, I suppose I don't care :P | 20:47 |
redrobot | rm_work in the TLS class I was talking about, we were using just a serial that started at A0000001 and incremented by one. | 20:47 |
*** dave-mccowan has quit IRC | 20:48 | |
rm_work | heh | 20:48 |
rm_work | yeah | 20:48 |
rm_work | well, I implemented dstufft's thing, and as long as the certs it generates are valid, i couldn't care any less | 20:48 |
*** tdink has joined #openstack-barbican | 20:49 | |
*** tdink has quit IRC | 20:54 | |
*** gyee has quit IRC | 20:58 | |
*** bubbva has quit IRC | 21:04 | |
*** bubbva has joined #openstack-barbican | 21:04 | |
openstackgerrit | Merged openstack/barbican: Fix communication of secret_type info https://review.openstack.org/133695 | 21:06 |
*** gyee has joined #openstack-barbican | 21:14 | |
*** rtom has joined #openstack-barbican | 21:17 | |
*** rsyed is now known as rsyed_away | 21:19 | |
*** atiwari has quit IRC | 21:21 | |
redrobot | chellygel you coming into the Castle tomorrow? | 21:31 |
*** rsyed_away is now known as rsyed | 21:37 | |
*** dimtruck is now known as zz_dimtruck | 21:38 | |
*** dave-mccowan has joined #openstack-barbican | 21:40 | |
chellygel | redrobot, no, will be in austin | 21:40 |
chellygel | bringing the puppy home tomorrow | 21:41 |
redrobot | chellygel bah... they're asking people at Castle to wear Scorpions jerseys | 21:41 |
chellygel | aww lameeee!! | 21:41 |
chellygel | why for?? | 21:41 |
redrobot | no idea... message was a bit cryptic | 21:41 |
redrobot | "If you’re a big UTSA Roadrunners or Scorpions Fan.. You might just want to wear your team jersey/shirt/ tomorrow. | 21:41 |
redrobot | I’m just saying. :)" | 21:41 |
chellygel | weirdo emails | 21:42 |
redrobot | for reals | 21:42 |
redrobot | if I se Billy Forbes I'm going to pass out. | 21:42 |
redrobot | :-P | 21:42 |
chellygel | i gotta keep my jersey clean for saturday dood | 21:42 |
redrobot | crap, that's right... guess I'll just have to buy another jersey. | 21:43 |
chellygel | pfhahaa | 21:44 |
redrobot | Actually, I have a team shirt I can wear tomorrow. | 21:45 |
*** kebray has quit IRC | 21:49 | |
*** zz_dimtruck is now known as dimtruck | 22:00 | |
*** SheenaG11 has quit IRC | 22:04 | |
*** tdink has joined #openstack-barbican | 22:11 | |
*** JeffF has quit IRC | 22:13 | |
*** joesavak has quit IRC | 22:16 | |
*** SheenaG1 has joined #openstack-barbican | 22:24 | |
*** akoneru has quit IRC | 22:36 | |
*** akoneru has joined #openstack-barbican | 22:36 | |
*** tdink has quit IRC | 22:36 | |
*** tdink has joined #openstack-barbican | 22:37 | |
*** dimtruck is now known as zz_dimtruck | 22:42 | |
*** tdink has quit IRC | 22:44 | |
*** SheenaG1 has quit IRC | 22:57 | |
*** david-lyle is now known as david-lyle_afk | 23:12 | |
*** tdink has joined #openstack-barbican | 23:13 | |
*** nkinder has quit IRC | 23:18 | |
*** dave-mccowan has quit IRC | 23:27 | |
*** kebray has joined #openstack-barbican | 23:30 | |
*** rtom has quit IRC | 23:32 | |
*** ametts has quit IRC | 23:33 | |
*** ryanpetrello has quit IRC | 23:39 | |
*** nkinder has joined #openstack-barbican | 23:43 | |
reaperhulk | rm_work: randomizing your serial in that way is perfect. | 23:53 |
reaperhulk | To handle the comical paranoia you can also do stuff like https://github.com/r509/r509/blob/master/lib/r509/certificate_authority/signer.rb#L143 | 23:57 |
reaperhulk | although you could still collide if you issue ~2**48 certificates in a microsecond :D | 23:58 |
reaperhulk | (or get unbelievably unlucky) | 23:59 |
*** nkinder has quit IRC | 23:59 | |
*** tdink has quit IRC | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!