*** SheenaG has quit IRC | 00:00 | |
*** nkinder has joined #openstack-barbican | 00:14 | |
*** everjeje has quit IRC | 00:16 | |
*** stanzi has joined #openstack-barbican | 00:17 | |
*** tkelsey has joined #openstack-barbican | 00:18 | |
*** tkelsey has quit IRC | 00:23 | |
*** zz_dimtruck is now known as dimtruck | 00:34 | |
*** kebray_ has quit IRC | 00:38 | |
*** stanzi has quit IRC | 00:48 | |
*** stanzi has joined #openstack-barbican | 00:49 | |
*** stanzi has quit IRC | 00:53 | |
openstackgerrit | Merged openstack/barbican: Adding MySQL fixes to migrations https://review.openstack.org/173617 | 00:56 |
---|---|---|
*** nkinder has quit IRC | 01:05 | |
*** nkinder has joined #openstack-barbican | 01:49 | |
openstackgerrit | Merged openstack/barbican: Refactor dogtag gate scripts https://review.openstack.org/161935 | 01:56 |
*** alee_ has quit IRC | 02:03 | |
*** nkinder has quit IRC | 02:24 | |
*** dimtruck is now known as zz_dimtruck | 02:34 | |
*** stanzi has joined #openstack-barbican | 02:45 | |
*** woodster_ has quit IRC | 02:50 | |
*** stanzi has quit IRC | 02:53 | |
*** stanzi has joined #openstack-barbican | 02:54 | |
*** stanzi has quit IRC | 02:58 | |
*** nkinder has joined #openstack-barbican | 03:00 | |
*** stanzi has joined #openstack-barbican | 03:18 | |
*** nkinder has quit IRC | 03:18 | |
*** crc32 has joined #openstack-barbican | 03:20 | |
*** dave-mccowan has joined #openstack-barbican | 03:23 | |
*** stanzi has quit IRC | 03:26 | |
*** stanzi has joined #openstack-barbican | 03:27 | |
*** stanzi has quit IRC | 03:32 | |
*** kebray has joined #openstack-barbican | 03:41 | |
*** kebray has quit IRC | 03:41 | |
*** kebray has joined #openstack-barbican | 03:46 | |
*** xaeth_afk is now known as xaeth | 03:48 | |
*** gyee has quit IRC | 03:52 | |
*** stanzi has joined #openstack-barbican | 04:15 | |
*** tkelsey has joined #openstack-barbican | 04:19 | |
*** stanzi has quit IRC | 04:20 | |
*** tkelsey has quit IRC | 04:24 | |
*** nkinder has joined #openstack-barbican | 04:32 | |
*** xaeth is now known as xaeth_afk | 04:37 | |
*** crc32 has quit IRC | 04:38 | |
*** crc32 has joined #openstack-barbican | 04:38 | |
*** crc32 has quit IRC | 04:45 | |
*** crc32 has joined #openstack-barbican | 05:15 | |
*** openstackgerrit has quit IRC | 05:21 | |
*** openstackgerrit has joined #openstack-barbican | 05:21 | |
*** rm_work is now known as rm_work|away | 06:03 | |
openstackgerrit | Dave McCowan proposed openstack/barbican: Refactor RSA Functional Smoke Tests https://review.openstack.org/174722 | 06:20 |
*** tkelsey has joined #openstack-barbican | 06:21 | |
openstackgerrit | Dave McCowan proposed openstack/barbican: Refactor Translation Code for PER and DER Formats https://review.openstack.org/174724 | 06:22 |
*** tkelsey has quit IRC | 06:25 | |
*** dave-mccowan has quit IRC | 06:51 | |
*** jaosorior has joined #openstack-barbican | 07:09 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: Readability-related changes to secret store functions https://review.openstack.org/172378 | 07:16 |
*** tkelsey has joined #openstack-barbican | 07:18 | |
*** chlong has quit IRC | 07:33 | |
*** kebray has quit IRC | 07:36 | |
*** crc32 has quit IRC | 08:23 | |
*** jamielennox is now known as jamielennox|away | 09:49 | |
*** woodster_ has joined #openstack-barbican | 12:19 | |
*** dave-mccowan has joined #openstack-barbican | 12:26 | |
*** zz_dimtruck is now known as dimtruck | 12:59 | |
*** rellerreller has joined #openstack-barbican | 13:08 | |
alee | dave-mccowan, are you going to rebase https://review.openstack.org/#/c/171023/ ? | 13:28 |
dave-mccowan | alee, now i will. :-) thanks for reminder. | 13:29 |
alee | redrobot, jaosorior -- looked at the logs for the dogtag gate. Not quite sure its been "fixed". | 13:37 |
alee | redrobot, jaosorior - the original problem was that something was goin wrong with the kra install. | 13:37 |
alee | now the kra install is not taking place. | 13:37 |
alee | and when the tests run, they are not actually using dogtag kra or ca | 13:38 |
alee | which is why all the dogtag specific test cases are failing | 13:38 |
*** rellerreller has quit IRC | 13:40 | |
jaosorior | alee: yeah, the KRA install was having something weird, which is why I added the set -e in the beginning of the install script, to see exactly were it fails... not sure now if it helped much | 13:45 |
jaosorior | alee: Then I got distracted by trying to install dog tag in a docker container for easy testing, but it seems that crashes even in the pki-ca install | 13:46 |
alee | jaosorior, interesting - thats not a bad idea | 13:47 |
alee | jaosorior, I'm curious where it crashes. I'll work with you to help set one up next week. | 13:48 |
jaosorior | alee: sure, let me know when | 13:48 |
jaosorior | alee: now, I'm still not sure why the KRA install fails | 13:49 |
jaosorior | alee: referring to the gate | 13:49 |
alee | jaosorior, yeah -- we need to get the logs back from the gate in order for me to figure out why | 13:50 |
jaosorior | alee: uhm... I'm guessing there's no access to the /var/log/yum.log from the gate, right? | 13:54 |
alee | jaosorior, I think you can specify other logs to package up -- redrobot was going to look at how to do that. I'll need to help look into that next week. | 13:55 |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/barbican: ** DO NOT MERGE ** https://review.openstack.org/174880 | 13:56 |
*** stanzi has joined #openstack-barbican | 13:57 | |
*** stanzi has quit IRC | 13:58 | |
*** dimtruck is now known as zz_dimtruck | 13:58 | |
*** stanzi has joined #openstack-barbican | 13:58 | |
woodster_ | alee jaosorior I haven't been looking at the Dogtag gate but I'm wondering if you need to run it as a separate screen process maybe? | 14:04 |
*** zz_dimtruck is now known as dimtruck | 14:07 | |
alee | woodster_, perhaps | 14:11 |
openstackgerrit | Dave McCowan proposed openstack/barbican: Refactor Stored Key Certificate Order Validator Code https://review.openstack.org/171023 | 14:17 |
dave-mccowan | alee ^^^ | 14:18 |
alee | dave-mccowan, ok - waiting for it to pass the gate | 14:19 |
*** rellerreller has joined #openstack-barbican | 14:23 | |
rellerreller | redrobot dave-mccowan Is there anything left for the content type refactoring? | 14:24 |
rellerreller | I tested the changes with the new KMIP CR, and it all worked for me :) | 14:24 |
dave-mccowan | rellerreller, everything i've tested is working now too. :-) i have submitted two refactoring CRs, but they are functionally equivalent, just prettier. one touches KMIP, you'll want to review that: https://review.openstack.org/174724 | 14:26 |
rellerreller | dave-mccowan Glad to hear it is working for you too! You and redrobot have put in a lot of work on this. Good job and thanks! | 14:28 |
*** paul_glass has joined #openstack-barbican | 14:35 | |
*** stanzi has quit IRC | 14:47 | |
*** stanzi has joined #openstack-barbican | 14:47 | |
hockeynut | good morning barbicaneers - got a question about our cmd line client. | 14:48 |
hockeynut | currently you can do "barbican --help" and get help - awesomeness | 14:48 |
hockeynut | should I be able to use "barbican help secret" for example to get secret help? Not sure if that's implemented or supported by cliff | 14:49 |
jaosorior | hockeynut: you should be able to do barbican help secret store. But not barbican help secret because of the way it's implemented | 14:50 |
hockeynut | jaosorior when I do that I get the basic barbican cmd help then ERROR: please specify authentication credentials | 14:51 |
*** igueths has joined #openstack-barbican | 14:51 | |
*** stanzi has quit IRC | 14:52 | |
hockeynut | so each of the cmds that you see when you do --help should have associated help, but its not working that way. Just wanted to be sure | 14:52 |
jaosorior | hockeynut: basically I took it from the way the openstackclient works. And the way out works is that underneath, "secret store" is one command, and the space is actually part of it. So just typing "help secret" won't match any command. So cliff won't be able to print help for that unless why hack around that | 14:53 |
jaosorior | hockeynut: then it's a bug | 14:53 |
hockeynut | gotcha | 14:53 |
hockeynut | I should have used "secret store" in my first query above, my bad (slaps self in head) | 14:53 |
jaosorior | For usability's sake a user should be able to get help, or at list a list of the commands that are related to secrets. But we don't have that yet | 14:55 |
woodster_ | It would be good to catch docs up to these latest changes too. I think redrobot has been doing work there | 15:03 |
*** SheenaG has joined #openstack-barbican | 15:09 | |
*** darrenmoffat has quit IRC | 15:16 | |
*** darrenmoffat has joined #openstack-barbican | 15:16 | |
*** rm_work|away is now known as rm_work | 15:18 | |
dave-mccowan | rellerreller, ping | 15:22 |
openstackgerrit | Chelsea Winfree proposed openstack/python-barbicanclient: Fix the clientrc file to match defaults and add docs https://review.openstack.org/174076 | 15:24 |
*** kebray has joined #openstack-barbican | 15:29 | |
dave-mccowan | rellerreller, looking at "openssl asn1parse -inform DER -in private.der", I see that it is PKCS#1. (there is no :rsaEncryption envelope). the current code is using PKCS#1 DER and seems to be working. (but is it wrong?) | 15:32 |
rellerreller | dave-mccowan pong | 15:38 |
rellerreller | Yes, it is wrong. The keys should be in PKCS#8 format. | 15:39 |
rellerreller | dave-mccowan There is a tool to convert PKCS#1 to PKCS#8. It is openssl pkcs8, https://www.openssl.org/docs/apps/pkcs8.html | 15:40 |
dave-mccowan | rellerreller, openssl pkcs8 -in private.pem -topk8 -outform DER -out private_pk8.der | 15:41 |
rellerreller | dave-mccown I'm surprised the KMIP device did not complain about that. | 15:41 |
rellerreller | dave-mccowan yes | 15:41 |
dave-mccowan | rellerreller, so now if i fix it, will it break KMIP plugin. :-) | 15:41 |
rellerreller | dave-mccown I hope not. | 15:41 |
*** SheenaG has quit IRC | 15:42 | |
dave-mccowan | rellerreller, next is to figure out if I can get pyCrypto to make a _pkcs8.der. | 15:42 |
rellerreller | dave-mccowan I believe that is true. I thought I had seen that. | 15:43 |
*** joesavak has joined #openstack-barbican | 15:43 | |
dave-mccowan | rellerreller, got it. funny how a nit in a code review can turn into a bug. :-) | 15:49 |
*** stanzi has joined #openstack-barbican | 15:50 | |
rellerreller | dave-mccowan Oh geez. That is coming from that. That is crazy :) | 15:50 |
dave-mccowan | rellerreller, and now i know more about asn1 than i ever wanted to. | 15:50 |
rellerreller | dave-mccowan Yes, asn1 is a beast. | 15:51 |
reaperhulk | oh you can know so much more. | 15:52 |
* reaperhulk cries | 15:52 | |
*** jsavak has joined #openstack-barbican | 15:55 | |
dave-mccowan | reaperhulk, do you have "asn1" on your keyword subscribe list? :-) | 15:58 |
*** chadlung has joined #openstack-barbican | 15:59 | |
*** joesavak has quit IRC | 15:59 | |
*** gyee has joined #openstack-barbican | 15:59 | |
*** stanzi has quit IRC | 16:01 | |
*** stanzi has joined #openstack-barbican | 16:02 | |
*** stanzi has quit IRC | 16:06 | |
*** paul_glass has quit IRC | 16:17 | |
*** SheenaG has joined #openstack-barbican | 16:23 | |
openstackgerrit | Merged openstack/python-barbicanclient: Porting over more documentation to RST from cli wiki https://review.openstack.org/174598 | 16:37 |
openstackgerrit | Merged openstack/python-barbicanclient: Updating client and client docs for accuracy https://review.openstack.org/174613 | 16:37 |
*** stanzi has joined #openstack-barbican | 16:46 | |
*** stanzi has quit IRC | 16:46 | |
*** stanzi has joined #openstack-barbican | 16:47 | |
openstackgerrit | Dave McCowan proposed openstack/barbican: Refactor and Fix Translation Code for PER and DER Formats https://review.openstack.org/174724 | 16:55 |
dave-mccowan | rellerreller ^^^ | 16:55 |
rellerreller | dave-mccowan Looks good! | 16:59 |
*** stanzi has quit IRC | 17:02 | |
*** stanzi has joined #openstack-barbican | 17:02 | |
*** stanzi has quit IRC | 17:03 | |
*** stanzi has joined #openstack-barbican | 17:03 | |
*** dimtruck is now known as zz_dimtruck | 17:05 | |
*** stanzi_ has joined #openstack-barbican | 17:05 | |
dave-mccowan | rellerreller, is there more testing to be done to make sure the new format works? | 17:05 |
rellerreller | dave-mccowan I'm not sure. I tested the previous stuff with KMIP and it worked. | 17:05 |
rellerreller | Your stuff looks good to me. Unfortunately I will not have time to test it until Monday. | 17:06 |
*** stanzi_ has quit IRC | 17:06 | |
rellerreller | dave-mccowan Did you have anything else mind? | 17:07 |
*** stanzi_ has joined #openstack-barbican | 17:07 | |
*** stanzi has quit IRC | 17:08 | |
*** stanzi_ has quit IRC | 17:08 | |
dave-mccowan | rellerreller, i didn't know if you had a testbed with an HSM that you were testing against. | 17:08 |
*** stanzi_ has joined #openstack-barbican | 17:10 | |
rellerreller | dave-mccowan I have not done so with 174724, but I did with the other patches. I should say that I tested with the latest code from master at about 10:00 AM ET. | 17:10 |
dave-mccowan | rellerreller, if you're happy with the change, i'm happy. :-) | 17:12 |
rellerreller | dave-mccowan It looks good to me. I can test it on Monday. I'm hoping that for Liberty we can have a gate check for this. | 17:12 |
rellerreller | dave-mccowan I have to leave now. My weekend has just started. Have a good weekend :) | 17:13 |
dave-mccowan | rellerreller, sounds good. you too! | 17:13 |
*** rellerreller has quit IRC | 17:13 | |
*** stanzi_ has quit IRC | 17:14 | |
*** stanzi has joined #openstack-barbican | 17:15 | |
*** tkelsey has quit IRC | 17:15 | |
*** SheenaG has quit IRC | 17:19 | |
*** stanzi has quit IRC | 17:20 | |
*** chadlung has quit IRC | 17:21 | |
*** chadlung has joined #openstack-barbican | 17:33 | |
openstackgerrit | Dave McCowan proposed openstack/barbican: Refactor and Fix Translation Code for PER and DER Formats https://review.openstack.org/174724 | 17:33 |
*** stanzi has joined #openstack-barbican | 17:34 | |
*** chadlung has quit IRC | 17:38 | |
*** stanzi_ has joined #openstack-barbican | 17:38 | |
*** stanzi has quit IRC | 17:38 | |
*** stanzi has joined #openstack-barbican | 17:41 | |
*** stanzi_ has quit IRC | 17:42 | |
*** stanzi_ has joined #openstack-barbican | 17:44 | |
openstackgerrit | Merged openstack/python-barbicanclient: Fix the clientrc file to match defaults and add docs https://review.openstack.org/174076 | 17:44 |
*** stanzi has quit IRC | 17:45 | |
*** stanzi_ has quit IRC | 17:48 | |
*** stanzi_ has joined #openstack-barbican | 17:52 | |
*** jaosorior has quit IRC | 17:52 | |
*** stanzi has joined #openstack-barbican | 17:55 | |
*** stanzi_ has quit IRC | 17:56 | |
*** stanzi has quit IRC | 17:59 | |
*** stanzi has joined #openstack-barbican | 17:59 | |
*** SheenaG has joined #openstack-barbican | 18:00 | |
*** stanzi has quit IRC | 18:05 | |
*** stanzi has joined #openstack-barbican | 18:06 | |
openstackgerrit | John Wood proposed openstack/barbican: Add order_retry_tasks migration per latest model https://review.openstack.org/169946 | 18:06 |
*** stanzi has quit IRC | 18:10 | |
*** stanzi has joined #openstack-barbican | 18:11 | |
*** stanzi has quit IRC | 18:15 | |
*** stanzi has joined #openstack-barbican | 18:15 | |
*** stanzi has quit IRC | 18:26 | |
*** stanzi has joined #openstack-barbican | 18:27 | |
*** stanzi_ has joined #openstack-barbican | 18:27 | |
*** stanzi__ has joined #openstack-barbican | 18:29 | |
*** stanzi has quit IRC | 18:31 | |
*** stanzi_ has quit IRC | 18:32 | |
*** stanzi__ has quit IRC | 18:33 | |
*** stanzi has joined #openstack-barbican | 18:34 | |
*** stanzi_ has joined #openstack-barbican | 18:36 | |
*** stanzi has quit IRC | 18:36 | |
*** stanzi_ has quit IRC | 18:39 | |
*** stanzi has joined #openstack-barbican | 18:40 | |
redrobot | dave-mccowan heya! | 18:45 |
dave-mccowan | redrobot o/ | 18:45 |
redrobot | dave-mccowan I'm trying to figure out how much more work still needs to be done for RC1 | 18:45 |
dave-mccowan | redrobot, good idea. let's bug scrub. | 18:46 |
redrobot | dave-mccowan ok, looking at https://bugs.launchpad.net/barbican/+bug/1443010 | 18:47 |
openstack | Launchpad bug 1443010 in Barbican "Ordered RSA Container Returns Secrets in Bad Format" [Undecided,New] - Assigned to Dave McCowan (dave-mccowan) | 18:47 |
redrobot | dave-mccowan is that still broken? | 18:47 |
dave-mccowan | redrebot 1443010, 1443009, and 1443008 were all fixed by the "big CR". bummer I forgot to add Closes-Bug tags. | 18:48 |
*** chadlung has joined #openstack-barbican | 18:48 | |
*** kebray has quit IRC | 18:49 | |
dave-mccowan | redrobot, 1445575 is needed per rellerreller. my DER format was wrong for KMIP, even though it worked. | 18:49 |
dave-mccowan | redrobot, if you don't mind, i was going to write a retrospective blueprint that you can mark complete for test_rsa.py. | 18:50 |
dave-mccowan | redrobot also, you can mark complete the bandit-gate blueprint. it runs as an experimental gate now and is working. we can promote that to non-voting check sometime in liberty. | 18:51 |
*** SheenaG has quit IRC | 18:55 | |
redrobot | dave-mccowan ok, I marked the big CR bugs as "fix commited" | 18:57 |
redrobot | dave-mccowan is there a CR already for the 1445575 fix? | 18:58 |
redrobot | dave-mccowan oh never mind, I see it | 18:59 |
*** kebray has joined #openstack-barbican | 18:59 | |
dave-mccowan | redrobot, rellerreller gave it +2, but it cleared when i pushed a patch for 100% coverage | 19:00 |
redrobot | dave-mccowan yeah, I have a pending question on it | 19:00 |
*** SheenaG has joined #openstack-barbican | 19:01 | |
dave-mccowan | redrobot ok, i can fix the decorator | 19:01 |
dave-mccowan | redrobot, i'm not sure if it's necessary, but there is still some more validator checks that can be done. for example, checking secret ACLs when storing a container or ordering a certificate. that requires, as a base, a CR that I have pending. | 19:08 |
redrobot | dave-mccowan do you think they are must-haves or nice-to-haves? | 19:09 |
dave-mccowan | redrobot, i think the symptom will be user gets a 500, instead of a 400. alee, what do you think? | 19:10 |
redrobot | dave-mccowan hmmm... yeah def sounds like a must-have | 19:13 |
redrobot | what's the CRs? | 19:13 |
dave-mccowan | https://review.openstack.org/171023 | 19:14 |
dave-mccowan | but that is just to get the project_id inside the validator. now the ACL checking code needs to be written. | 19:15 |
*** chadlung has quit IRC | 19:21 | |
*** SheenaG has quit IRC | 19:24 | |
*** kebray has quit IRC | 19:34 | |
jvrbanac | redrobot, https://review.openstack.org/#/c/171839/ | 19:38 |
woodster_ | alee, elmiko, please take a look when you can: https://review.openstack.org/#/c/169946/ | 19:41 |
elmiko | woodster_: ack, lgtm | 19:42 |
*** SheenaG has joined #openstack-barbican | 19:47 | |
openstackgerrit | Dave McCowan proposed openstack/barbican: Refactor RSA Functional Smoke Tests https://review.openstack.org/174722 | 19:55 |
openstackgerrit | Dave McCowan proposed openstack/barbican: Refactor and Fix Translation Code for PER and DER Formats https://review.openstack.org/174724 | 19:59 |
*** paul_glass has joined #openstack-barbican | 20:03 | |
*** kebray has joined #openstack-barbican | 20:04 | |
*** chadlung has joined #openstack-barbican | 20:06 | |
*** openstackgerrit has quit IRC | 20:22 | |
*** openstackgerrit has joined #openstack-barbican | 20:23 | |
*** gyee has quit IRC | 20:32 | |
*** stanzi has quit IRC | 20:35 | |
-openstackstatus- NOTICE: Gerrit will be unavailable between 22:00 and 23:59 UTC for project renames and a database update. | 21:03 | |
openstackgerrit | Dave McCowan proposed openstack/barbican: Refactor RSA Functional Smoke Tests https://review.openstack.org/174722 | 21:08 |
*** openstackgerrit has quit IRC | 21:23 | |
*** openstackgerrit has joined #openstack-barbican | 21:23 | |
*** igueths has quit IRC | 21:33 | |
*** alee has quit IRC | 21:35 | |
*** chadlung has quit IRC | 21:43 | |
*** jamielennox|away is now known as jamielennox | 21:48 | |
openstackgerrit | Merged openstack/barbican: Add order_retry_tasks migration per latest model https://review.openstack.org/169946 | 21:50 |
*** paul_glass has quit IRC | 21:58 | |
*** jsavak has quit IRC | 22:02 | |
-openstackstatus- NOTICE: Gerrit is unavailable until 23:59 UTC for project renames and a database update. | 22:03 | |
-openstackstatus- NOTICE: Gerrit is unavailable until 23:59 UTC for project renames and a database update. | 22:06 | |
*** ChanServ changes topic to "Gerrit is unavailable until 23:59 UTC for project renames and a database update." | 22:06 | |
*** dave-mccowan has quit IRC | 22:44 | |
*** kebray has quit IRC | 22:50 | |
*** ChanServ changes topic to "Kilo RC1 due April 9 https://launchpad.net/barbican/+milestone/kilo-rc1" | 23:03 | |
-openstackstatus- NOTICE: Gerrit is available again. | 23:03 | |
*** jamielennox is now known as jamielennox|away | 23:30 | |
openstackgerrit | Merged openstack/python-barbicanclient: Raising errors from the client instead of ksclient https://review.openstack.org/171839 | 23:45 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!