*** kgriffs|afk is now known as kgriffs | 00:01 | |
*** atiwari has quit IRC | 00:03 | |
*** zz_dimtruck is now known as dimtruck | 00:49 | |
*** kebray has quit IRC | 00:50 | |
*** david-lyle is now known as david-lyle_afk | 00:57 | |
*** kebray has joined #openstack-barbican | 01:15 | |
*** kebray has quit IRC | 01:15 | |
*** kgriffs is now known as kgriffs|afk | 01:19 | |
*** jamielennox is now known as jamielennox|away | 01:33 | |
*** lisaclark2 has joined #openstack-barbican | 01:46 | |
*** lisaclark1 has quit IRC | 01:47 | |
*** lisaclark2 has quit IRC | 02:13 | |
*** lisaclark1 has joined #openstack-barbican | 02:13 | |
*** lisaclark1 has quit IRC | 02:17 | |
*** lisaclark1 has joined #openstack-barbican | 02:18 | |
*** lisaclark1 has quit IRC | 02:26 | |
*** kgriffs|afk is now known as kgriffs | 02:29 | |
*** kgriffs is now known as kgriffs|afk | 02:39 | |
*** SheenaG1 has joined #openstack-barbican | 02:42 | |
*** woodster_ has quit IRC | 02:56 | |
*** xaeth_afk is now known as xaeth | 03:02 | |
*** bdpayne has quit IRC | 03:25 | |
*** ajc_ has joined #openstack-barbican | 03:25 | |
*** kgriffs|afk is now known as kgriffs | 03:31 | |
*** SheenaG1 has quit IRC | 03:55 | |
*** xaeth is now known as xaeth_afk | 04:10 | |
*** kebray has joined #openstack-barbican | 04:53 | |
*** kebray has quit IRC | 04:57 | |
*** kebray has joined #openstack-barbican | 05:03 | |
*** kgriffs is now known as kgriffs|afk | 05:11 | |
*** david-lyle_afk has quit IRC | 05:11 | |
*** david-lyle_afk has joined #openstack-barbican | 05:11 | |
*** woodster_ has joined #openstack-barbican | 05:27 | |
*** kgriffs|afk is now known as kgriffs | 06:21 | |
*** kgriffs is now known as kgriffs|afk | 06:30 | |
*** kebray_ has joined #openstack-barbican | 06:45 | |
*** kebray has quit IRC | 06:49 | |
*** chlong has joined #openstack-barbican | 07:07 | |
*** chlong has quit IRC | 07:28 | |
*** woodster_ has quit IRC | 07:36 | |
*** nkinder has joined #openstack-barbican | 08:08 | |
*** jaosorior has joined #openstack-barbican | 08:29 | |
*** kebray_ has quit IRC | 08:59 | |
*** darrenmoffat has joined #openstack-barbican | 09:15 | |
*** jaosorior has quit IRC | 10:46 | |
*** tkelsey has joined #openstack-barbican | 11:04 | |
*** david-lyle_afk is now known as david-lyle | 12:01 | |
*** tkelsey_ has joined #openstack-barbican | 12:12 | |
*** tkelsey has quit IRC | 12:20 | |
*** woodster_ has joined #openstack-barbican | 12:33 | |
*** david-lyle is now known as david-lyle_afk | 12:36 | |
*** david-lyle_afk is now known as david-lyle | 12:36 | |
*** david-lyle is now known as david-lyle_afk | 12:44 | |
*** david-lyle_afk is now known as david-lyle | 12:45 | |
*** jaosorior has joined #openstack-barbican | 12:45 | |
*** SheenaG1 has joined #openstack-barbican | 13:02 | |
*** nkinder has quit IRC | 13:10 | |
*** ajc_ has quit IRC | 13:24 | |
*** lisaclark1 has joined #openstack-barbican | 14:16 | |
*** SheenaG1 has quit IRC | 14:26 | |
jaosorior | hockeynut: I responded to your comments in my CRs | 14:27 |
---|---|---|
*** SheenaG1 has joined #openstack-barbican | 14:30 | |
*** nkinder has joined #openstack-barbican | 14:31 | |
*** darrenmoffat has quit IRC | 14:48 | |
*** darrenmoffat has joined #openstack-barbican | 14:55 | |
*** dimtruck is now known as zz_dimtruck | 15:01 | |
*** nkinder has quit IRC | 15:04 | |
*** nkinder has joined #openstack-barbican | 15:06 | |
*** paul_glass has joined #openstack-barbican | 15:08 | |
*** rm_work|away is now known as rm_work | 15:14 | |
*** lisaclark1 has quit IRC | 15:16 | |
hockeynut | jaosorior thanks - heading over now | 15:17 |
*** lisaclark1 has joined #openstack-barbican | 15:19 | |
*** lisaclark1 has quit IRC | 15:25 | |
*** lisaclark1 has joined #openstack-barbican | 15:32 | |
*** zz_dimtruck is now known as dimtruck | 15:34 | |
*** rellerreller has joined #openstack-barbican | 15:34 | |
openstackgerrit | Merged openstack/barbican-specs: Change GET decrypted secrets to unique URI https://review.openstack.org/125798 | 15:47 |
rm_work | YEEEHAW | 15:47 |
alee | rm_work, woodster_ had a couple more questions on the per-secret spec | 15:51 |
alee | woodster_, several more code reviews out there too | 15:52 |
*** kgriffs|afk is now known as kgriffs | 15:54 | |
openstackgerrit | Thomas Dinkjian proposed openstack/python-barbicanclient: Adds base behaviors, secret behaviors and the secret smoke tests https://review.openstack.org/151777 | 15:59 |
*** lisaclark1 has quit IRC | 16:01 | |
*** nkinder has quit IRC | 16:02 | |
*** xaeth_afk is now known as xaeth | 16:02 | |
*** lisaclark1 has joined #openstack-barbican | 16:05 | |
*** kebray has joined #openstack-barbican | 16:06 | |
*** nkinder has joined #openstack-barbican | 16:06 | |
*** gyee has joined #openstack-barbican | 16:47 | |
*** rellerreller has quit IRC | 16:48 | |
*** nkinder has quit IRC | 16:57 | |
*** nkinder has joined #openstack-barbican | 17:07 | |
*** atiwari has joined #openstack-barbican | 17:07 | |
*** gyee has quit IRC | 17:15 | |
openstackgerrit | Thomas Dinkjian proposed openstack/python-barbicanclient: All of the containers behaviors and container smoke tests https://review.openstack.org/151787 | 17:17 |
openstackgerrit | Thomas Dinkjian proposed openstack/python-barbicanclient: Adds base behaviors, secret behaviors and the secret smoke tests https://review.openstack.org/151777 | 17:17 |
openstackgerrit | Steve Heyman proposed openstack/barbican: Run functional tests against any barbican server https://review.openstack.org/152986 | 17:17 |
openstackgerrit | Steve Heyman proposed openstack/barbican: Run functional tests against any barbican server https://review.openstack.org/152986 | 17:19 |
*** lisaclark2 has joined #openstack-barbican | 17:25 | |
*** lisaclark1 has quit IRC | 17:25 | |
*** gyee has joined #openstack-barbican | 17:30 | |
*** nkinder has quit IRC | 17:30 | |
*** kgriffs is now known as kgriffs|afk | 17:52 | |
*** lisaclark2 has quit IRC | 17:53 | |
*** kgriffs|afk is now known as kgriffs | 17:54 | |
*** ametts has joined #openstack-barbican | 17:56 | |
*** dkingshott has joined #openstack-barbican | 18:11 | |
*** lisaclark1 has joined #openstack-barbican | 18:18 | |
*** jaosorior has quit IRC | 18:26 | |
*** lisaclark1 has quit IRC | 18:29 | |
*** bdpayne has joined #openstack-barbican | 18:34 | |
*** lisaclark1 has joined #openstack-barbican | 18:34 | |
*** lisaclark1 has quit IRC | 18:35 | |
alee | SheenaG1, ping | 19:03 |
*** lisaclark1 has joined #openstack-barbican | 19:03 | |
SheenaG1 | Hi alee, what's up? | 19:04 |
alee | SheenaG1, just got the abstract -- who will be the speakers? (me and chelsea? woodster?) | 19:04 |
SheenaG1 | You, Chelsea, Wood | 19:04 |
SheenaG1 | Yep | 19:04 |
alee | SheenaG1, ok - did not see him copied on abstract - so just checking | 19:05 |
alee | I'll make comments and send back soon | 19:05 |
SheenaG1 | alee: good point, I forgot him on that one, feel free to add him to it | 19:05 |
alee | SheenaG1, my immediate comment is SSL Cert != asymmetric key | 19:06 |
tkelsey_ | hey Barbican folks, anyone fancy casting an eye over the MKEK spec? https://review.openstack.org/#/c/148948/ (shameless fishing for reviews :) ) | 19:06 |
alee | woodster_, rm_work , arunkant -- ready to put up a new version of the per-secret spec , but arunkant has raised a couple of good questions | 19:08 |
alee | need answers to those first. | 19:08 |
SheenaG1 | alee: an SSL certificate is not an asymmetric public/private key pair? | 19:09 |
alee | SheenaG1, an ssl certrificate is a document containing identifying info and a public key, signed by a certificate authority | 19:09 |
rm_work | erk k | 19:10 |
alee | certainly the prereq for a certificate is the generation of a public/private key pair. | 19:10 |
SheenaG1 | alee: the public key is represented by the certificate itself | 19:11 |
SheenaG1 | alee: only the information to derive the public key is passed in the CSR, IIRC | 19:11 |
*** kgriffs is now known as kgriffs|afk | 19:11 | |
SheenaG1 | alee: but I'm pretty sure it's considered an asymmetric key pair - the public key (certificate) and private key | 19:11 |
SheenaG1 | alee: https://www.digicert.com/ssl-cryptography.htm | 19:11 |
rm_work | SheenaG1: which abstract is that? did you end up putting me on one, or not? | 19:12 |
rm_work | just curious :P | 19:12 |
SheenaG1 | rm_work: it's for SSL, and yes there's still one for you - trying to get that one polished up too | 19:12 |
alee | SheenaG1, I'm just pointing out that its not correct to say a certificate IS a public/private key pair. The cert only contains the public key. A pub/private key pair is required to get a cert. | 19:13 |
rm_work | SheenaG1: yeah saying they're equal is a little bit weird | 19:14 |
SheenaG1 | alee: that seems like semantics, but feel free to amend it to your liking | 19:14 |
alee | SheenaG1, maybe the difference is semantic -- but its the first thing that struck me as I read it. | 19:14 |
SheenaG1 | alee: which is why I sent it to you. Please revise it to your standards. | 19:14 |
alee | yup - will do. | 19:15 |
rm_work | alee: only one comment, which is that I don't understand how/why groups and projects would work for ACL sharing anyway | 19:22 |
rm_work | alee: honestly didn't need them or ask for them for the LBaaS use-case... | 19:22 |
rm_work | not sure where they snuck in from, or how to really DO them | 19:22 |
alee | rm_work, I think they snuck in as -- well if you want to do users -- why not groups or projects .. certainly if you want a bunch of folks to access you secret. | 19:24 |
alee | they are not needed for lbaas - so maybe the answer is just to defer on them till we need them. | 19:25 |
*** lisaclark1 has quit IRC | 19:27 | |
openstackgerrit | Thomas Dinkjian proposed openstack/python-barbicanclient: Adds base behaviors, secret behaviors and the secret smoke tests https://review.openstack.org/151777 | 19:29 |
*** lisaclark1 has joined #openstack-barbican | 19:30 | |
*** lisaclark1 has quit IRC | 19:36 | |
*** lisaclark1 has joined #openstack-barbican | 19:50 | |
woodster_ | alee, rm_work user-only is certainly an option for Kilo. I'll take a look at CR *now* I promise :) | 19:50 |
*** lisaclark1 has quit IRC | 19:54 | |
*** lisaclark1 has joined #openstack-barbican | 19:56 | |
rm_work | hmm, i appear to have dropped off the mailing list again somehow | 19:57 |
rm_work | i know we switched which one, but... i thought i was getting emails from the new one, but I guess not T_T | 19:57 |
*** lisaclark1 has quit IRC | 19:58 | |
*** dkingshott has quit IRC | 19:58 | |
rm_work | SheenaG1: how do I make sure I'm on the Keep list? | 20:00 |
*** lisaclark1 has joined #openstack-barbican | 20:01 | |
*** tkelsey_ has quit IRC | 20:01 | |
*** dkingshott has joined #openstack-barbican | 20:06 | |
*** kgriffs|afk is now known as kgriffs | 20:11 | |
*** jkf has joined #openstack-barbican | 20:15 | |
*** kgriffs is now known as kgriffs|afk | 20:20 | |
*** kgriffs|afk is now known as kgriffs | 20:23 | |
*** lisaclark1 has quit IRC | 20:24 | |
*** arunkant has quit IRC | 20:33 | |
rm_work | hey redrobot / woodster_: I ended up doing this ( https://review.openstack.org/#/c/146210/9/neutron_lbaas/common/cert_manager/barbican_cert_manager.py Line 100) and was wondering if you had run into similar issues, or if you are confident you know what will end up being raised in these cases | 20:38 |
redrobot | rm_work can't say that I'm aware of all exceptions that could be thrown | 20:40 |
rm_work | redrobot: yeah... what would you do in this situation? something similar to what I did? | 20:40 |
rm_work | normally catching "Exception" is really bad form, but... <_< | 20:40 |
redrobot | rm_work yeah... I've heard it called a "Pokemon Exception" | 20:41 |
rm_work | I can think of a few that could probably show up, and all of them essentially mean the same thing in this case... "it didn't work" | 20:41 |
rm_work | heh | 20:42 |
rm_work | nice | 20:42 |
*** kgriffs is now known as kgriffs|afk | 20:44 | |
*** kgriffs|afk is now known as kgriffs | 20:50 | |
*** lisaclark1 has joined #openstack-barbican | 20:50 | |
*** SheenaG1 has left #openstack-barbican | 21:00 | |
*** SheenaG1 has joined #openstack-barbican | 21:00 | |
*** lisaclark1 has quit IRC | 21:04 | |
*** lisaclark1 has joined #openstack-barbican | 21:06 | |
*** kebray has quit IRC | 21:09 | |
*** kebray has joined #openstack-barbican | 21:11 | |
*** lisaclark1 has quit IRC | 21:26 | |
*** kebray has quit IRC | 21:28 | |
*** kebray has joined #openstack-barbican | 21:28 | |
*** SheenaG1 has quit IRC | 21:35 | |
*** SheenaG1 has joined #openstack-barbican | 21:39 | |
*** lisaclark1 has joined #openstack-barbican | 21:44 | |
*** arunkant has joined #openstack-barbican | 21:48 | |
*** kebray has quit IRC | 21:56 | |
alee | hey all - just need a workflow on this one please .. https://review.openstack.org/#/c/150670/ :) | 22:34 |
openstackgerrit | Thomas Dinkjian proposed openstack/python-barbicanclient: Adds base behaviors, secret behaviors and the secret smoke tests https://review.openstack.org/151777 | 22:37 |
*** lisaclark1 has quit IRC | 22:44 | |
*** xaeth is now known as xaeth_afk | 23:04 | |
openstackgerrit | Thomas Dinkjian proposed openstack/python-barbicanclient: Adds base behaviors, secret behaviors and the secret smoke tests https://review.openstack.org/151777 | 23:06 |
woodster_ | alee, rm_work, arunkant I added comments/questions to the per-secret CR | 23:08 |
alee | woodster_, looking | 23:08 |
alee | woodster_, will add to order's too | 23:09 |
*** paul_glass has quit IRC | 23:09 | |
openstackgerrit | Steve Heyman proposed openstack/barbican: Run functional tests against any barbican server https://review.openstack.org/152986 | 23:09 |
alee | woodster_, doesn't the current search only get secrets within that project? | 23:10 |
alee | woodster_, ie for list? | 23:10 |
alee | woodster_, if so, then I would think that would not change -- the only difference is that you would not see secrets which are private that you do not own. | 23:12 |
*** dimtruck is now known as zz_dimtruck | 23:14 | |
rm_work | sounds correct to me | 23:16 |
woodster_ | alee, I'm fine with that, but there is an inconsistency: we let private secret users do things with secrets without having to have barbican roles on them, whereas the current list call requires a barbican role. For consistency, that private secret user with no barbican role should probably be able to see their private secrets, probably independent of | 23:16 |
woodster_ | project. | 23:16 |
rm_work | i wish I could read/respond/comprehend but my brain is completely shot right now | 23:17 |
rm_work | and my eyes... | 23:17 |
rm_work | everything in gerrit just kinda blurs together <_< | 23:17 |
woodster_ | T_T?? | 23:17 |
woodster_ | gerrit the heck outta here then | 23:18 |
rm_work | 3rd day of hackathon | 23:18 |
alee | woodster_, well - I think its reasonale to assume some barbican role. | 23:18 |
alee | woodster_, so if we want to modify the policy for delets etc. accordingly , I'm ok with that. | 23:18 |
alee | not sure what that looks like | 23:19 |
alee | anyways I'll get a new version out that covers almost everything I think -- we are super close | 23:19 |
alee | why the heck did I write this spec anyways ? .. | 23:19 |
rm_work | alee: <3 | 23:20 |
woodster_ | you were the first one to open the door when someone left that flaming poop bag on the porch | 23:20 |
alee | woodster_, I need to remember not to open doors .. | 23:21 |
alee | or learn how to not step in poop. | 23:21 |
alee | being attacked by munchkins .. going to dinner .. | 23:21 |
*** alee is now known as alee_dinner | 23:21 | |
rm_work | lol | 23:21 |
woodster_ | and we're trying to get rm_work to implement it...that's ok, it will be a purdy painted poop by the time that bp is polished :) | 23:22 |
* rm_work cracks his knuckles in anticipation of 50+ patchsets | 23:22 | |
alee_dinner | y'all texans have a way with words .. | 23:22 |
woodster_ | rm_work, seriously though, what is the bare mininum needed for the lbaas interaction? Not that private secret stuff, just the user whitelist, correct? | 23:22 |
rm_work | I mean, I hope someone else is planning to implement the server side, because about all I have time for until Kilo3 is client changes <_< | 23:23 |
rm_work | woodster_: yeah, user whitelist for GET | 23:23 |
rm_work | on Secrets and Containers | 23:23 |
rm_work | the owner_only thing is ... not important to us | 23:23 |
woodster_ | then I'm of a mind to postpone the private secret stuff until after the meetup anyway...then we can really whiteboard the heck out of that one. | 23:24 |
woodster_ | So then we could maybe land the simpler whitelist bp | 23:24 |
woodster_ | rm_work which client changes are you talking about? | 23:25 |
rm_work | uhh, the ones that let you set ACLs :P | 23:25 |
rm_work | and read them :) | 23:25 |
rm_work | since there's new data in the returned json, and a new endpoint | 23:25 |
woodster_ | it takes two hands to clap my friend...client + server = ACL goodness | 23:25 |
rm_work | right :P | 23:26 |
rm_work | soooo I'll be one hand, and someone else can be the other :) | 23:26 |
woodster_ | ha! Take what we can get for sure | 23:26 |
rm_work | maybe if things calm down | 23:27 |
rm_work | though I am going to try to be at YOUR midcycle | 23:27 |
rm_work | that is next week, right? | 23:27 |
rm_work | uhh, anyone have a hotel room that'll accept a rollaway or has a couch? :P | 23:29 |
woodster_ | week after next I believe | 23:29 |
woodster_ | the extended stay was $135/night | 23:30 |
woodster_ | .3 miles away it says | 23:30 |
rm_work | yeah my budget is $0 :P | 23:30 |
rm_work | i can prolly drive in | 23:30 |
rm_work | I'm lucky if Jorge says I can actually go for more than like one day <_< | 23:31 |
woodster_ | oh that sucks...well if we get traction on an agenda, maybe we can your interest areas down to a day | 23:31 |
*** jkf has quit IRC | 23:55 | |
*** kebray has joined #openstack-barbican | 23:55 | |
*** rm_work is now known as rm_work|away | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!