openstackgerrit | Fernando Diaz proposed openstack/barbican: User Metadata API and tests https://review.openstack.org/275885 | 00:18 |
---|---|---|
*** reaperhulk has joined #openstack-barbican | 00:45 | |
*** reaperhulk has quit IRC | 00:45 | |
*** reaperhulk has joined #openstack-barbican | 00:46 | |
*** mp1 has quit IRC | 00:52 | |
*** cheneydc has joined #openstack-barbican | 01:03 | |
*** insequent has quit IRC | 01:25 | |
*** mp1 has joined #openstack-barbican | 01:39 | |
*** insequent has joined #openstack-barbican | 01:52 | |
*** damia_pi has joined #openstack-barbican | 02:01 | |
*** Kevin_Zheng has joined #openstack-barbican | 02:04 | |
*** insequent has quit IRC | 02:33 | |
*** insequent has joined #openstack-barbican | 02:37 | |
*** mp1 has quit IRC | 02:52 | |
*** mp1 has joined #openstack-barbican | 02:57 | |
*** nelsnels_ has joined #openstack-barbican | 03:09 | |
*** nelsnelson has quit IRC | 03:12 | |
*** damia_pi has quit IRC | 03:41 | |
*** dave-mccowan has quit IRC | 03:42 | |
*** Nirupama has joined #openstack-barbican | 03:43 | |
*** tkelsey has joined #openstack-barbican | 03:44 | |
*** tkelsey has quit IRC | 03:49 | |
*** stevemar has joined #openstack-barbican | 03:53 | |
*** damia_pi has joined #openstack-barbican | 03:58 | |
*** dimtruck is now known as zz_dimtruck | 04:07 | |
*** mp1 has quit IRC | 04:07 | |
*** damia_pi has quit IRC | 04:08 | |
*** david-lyle has joined #openstack-barbican | 04:13 | |
*** damia_pi has joined #openstack-barbican | 04:28 | |
*** david-lyle has quit IRC | 04:36 | |
*** david-lyle has joined #openstack-barbican | 04:50 | |
*** david-lyle has quit IRC | 04:56 | |
*** panatl has quit IRC | 05:04 | |
*** panatl has joined #openstack-barbican | 05:05 | |
*** mp1 has joined #openstack-barbican | 05:12 | |
*** yuanying has quit IRC | 05:24 | |
*** yuanying_ has joined #openstack-barbican | 05:24 | |
*** mp1 has quit IRC | 05:42 | |
*** fawadkhaliq has joined #openstack-barbican | 05:54 | |
*** sidx64 has joined #openstack-barbican | 06:15 | |
*** damia_pi has quit IRC | 06:55 | |
*** jaosorior has joined #openstack-barbican | 07:01 | |
*** damia_pi has joined #openstack-barbican | 07:01 | |
*** fnaval has joined #openstack-barbican | 07:12 | |
*** fawadk has joined #openstack-barbican | 07:15 | |
*** fawadkhaliq has quit IRC | 07:15 | |
*** fawadkhaliq has joined #openstack-barbican | 07:15 | |
*** fawadk has quit IRC | 07:20 | |
*** scheuran has joined #openstack-barbican | 07:30 | |
*** tkelsey has joined #openstack-barbican | 07:37 | |
*** tkelsey has quit IRC | 07:41 | |
*** pcaruana has joined #openstack-barbican | 07:43 | |
*** fawadkhaliq has quit IRC | 07:43 | |
*** fnaval has quit IRC | 07:50 | |
*** fnaval has joined #openstack-barbican | 07:59 | |
*** fnaval has quit IRC | 08:04 | |
*** fnaval has joined #openstack-barbican | 08:07 | |
*** fnaval has quit IRC | 08:11 | |
*** fawadkhaliq has joined #openstack-barbican | 08:27 | |
openstackgerrit | Dmitry Ratushnyy proposed openstack/barbican: Fix typo in word "initialization" https://review.openstack.org/284595 | 08:29 |
*** fawadkhaliq has quit IRC | 08:38 | |
*** tkelsey has joined #openstack-barbican | 09:13 | |
openstackgerrit | Merged openstack/barbican: Updating the project name to barbican https://review.openstack.org/276951 | 09:44 |
*** cheneydc has quit IRC | 10:01 | |
*** damia_pi has quit IRC | 10:10 | |
*** xek has joined #openstack-barbican | 11:12 | |
*** damia_pi has joined #openstack-barbican | 11:28 | |
*** damia_pi has quit IRC | 11:38 | |
*** dave-mccowan has joined #openstack-barbican | 11:55 | |
*** spotz_zzz is now known as spotz | 12:03 | |
-openstackstatus- NOTICE: Infra currently has a long backlog. Please be patient and where possible avoid rechecks while it catches up. | 12:05 | |
*** cheneydc has joined #openstack-barbican | 12:28 | |
*** jaosorior has quit IRC | 12:33 | |
*** jaosorior has joined #openstack-barbican | 12:34 | |
*** cheneydc has quit IRC | 12:39 | |
*** pcaruana has quit IRC | 12:53 | |
*** spotz is now known as spotz_zzz | 13:00 | |
*** pcaruana has joined #openstack-barbican | 13:08 | |
*** _jungh4ns has quit IRC | 13:16 | |
*** _jungh4ns has joined #openstack-barbican | 13:23 | |
*** fawadkhaliq has joined #openstack-barbican | 13:43 | |
*** rellerreller has joined #openstack-barbican | 14:01 | |
*** zz_dimtruck is now known as dimtruck | 14:12 | |
*** Nirupama has quit IRC | 14:12 | |
*** diazjf has joined #openstack-barbican | 14:17 | |
*** fredyx10 has joined #openstack-barbican | 14:30 | |
*** fredyx10 has quit IRC | 14:30 | |
*** fredyx10 has joined #openstack-barbican | 14:30 | |
*** fredyx10 has quit IRC | 14:30 | |
*** fredyx10 has joined #openstack-barbican | 14:30 | |
*** dimtruck is now known as zz_dimtruck | 14:37 | |
openstackgerrit | Merged openstack/castellan: Updated from global requirements https://review.openstack.org/285013 | 14:37 |
*** pcaruana has quit IRC | 14:38 | |
*** zz_dimtruck is now known as dimtruck | 14:39 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:42 | |
*** dimtruck is now known as zz_dimtruck | 14:47 | |
*** jmckind has joined #openstack-barbican | 14:48 | |
*** woodster_ has joined #openstack-barbican | 14:49 | |
openstackgerrit | Fernando Diaz proposed openstack/barbican: User Metadata Documentation https://review.openstack.org/283341 | 14:51 |
*** pcaruana has joined #openstack-barbican | 14:52 | |
*** edtubill has joined #openstack-barbican | 14:53 | |
openstackgerrit | Fernando Diaz proposed openstack/barbican: Introduce User-Meta table, model, and repo https://review.openstack.org/270963 | 15:01 |
openstackgerrit | Fernando Diaz proposed openstack/barbican: User Metadata API and tests https://review.openstack.org/275885 | 15:02 |
*** jhfeng has joined #openstack-barbican | 15:02 | |
*** fnaval has joined #openstack-barbican | 15:18 | |
*** kfarr has joined #openstack-barbican | 15:24 | |
*** fredyx10 has quit IRC | 15:26 | |
*** jorge_munoz has joined #openstack-barbican | 15:28 | |
*** spotz_zzz is now known as spotz | 15:28 | |
*** zz_dimtruck is now known as dimtruck | 15:30 | |
*** mp1 has joined #openstack-barbican | 15:35 | |
*** silos has joined #openstack-barbican | 15:36 | |
*** jaosorior is now known as jaosorior_away | 15:37 | |
openstackgerrit | Merged openstack/barbican: Update .gitignore for pyenv https://review.openstack.org/277944 | 15:41 |
openstackgerrit | Merged openstack/barbican: Simplify the development environment setup https://review.openstack.org/282212 | 15:44 |
*** randallburt has joined #openstack-barbican | 15:47 | |
edtubill | ping woodster_ | 15:50 |
*** fredyx10 has joined #openstack-barbican | 15:55 | |
*** sidx64 has quit IRC | 16:11 | |
*** fawadkhaliq has quit IRC | 16:17 | |
*** pcaruana has quit IRC | 16:17 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 16:25 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 16:25 | |
*** gariveradlt has joined #openstack-barbican | 16:37 | |
*** nkinder has joined #openstack-barbican | 16:38 | |
*** silos has quit IRC | 16:41 | |
*** silos has joined #openstack-barbican | 16:45 | |
woodster_ | edtubill: hey Elvin | 16:51 |
*** scheuran has quit IRC | 16:51 | |
edtubill | woodster_: hey, I was wondering if you could review https://review.openstack.org/#/c/269903/ and https://review.openstack.org/#/c/284821/ | 16:51 |
edtubill | woodster_: especially the database calls for cleaning up. I tried supporting sqllite and mysql. | 16:52 |
woodster_ | edtubill: I'll take a look | 16:52 |
edtubill | woodster_: thx!! | 16:53 |
*** jaosorior_away is now known as jaosorior | 17:08 | |
*** jmckind has quit IRC | 17:14 | |
*** rhagarty has joined #openstack-barbican | 17:14 | |
*** openstackgerrit has quit IRC | 17:18 | |
*** sidx64 has joined #openstack-barbican | 17:18 | |
*** openstackgerrit has joined #openstack-barbican | 17:18 | |
*** sidx64_Cern has joined #openstack-barbican | 17:19 | |
*** sid_cerner has joined #openstack-barbican | 17:22 | |
*** sidx64 has quit IRC | 17:23 | |
*** sidx64_Cern has quit IRC | 17:23 | |
*** sid_cerner has quit IRC | 17:26 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 17:26 | |
*** david-lyle has joined #openstack-barbican | 17:30 | |
*** fawadkhaliq has joined #openstack-barbican | 17:36 | |
diazjf | rellerreller, I updated https://review.openstack.org/#/c/275885/ fixed some tests and added validators. Let me know what you think | 17:42 |
*** david-lyle has quit IRC | 17:55 | |
*** david-lyle_ has joined #openstack-barbican | 17:55 | |
*** randallburt has quit IRC | 18:05 | |
*** mp1 has quit IRC | 18:07 | |
rellerreller | diazjf I left comments there. | 18:18 |
rellerreller | diazjf I'm cool with everything but policy.json. I'm not sure that everyone should be allowed to see the metadata for a secret. | 18:19 |
*** silos has quit IRC | 18:36 | |
*** mp1 has joined #openstack-barbican | 18:53 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 18:53 | |
*** jaosorior has quit IRC | 18:54 | |
diazjf | rellerreller, thanks I'll take a look. We can discuss it during the meeting if anything | 18:54 |
*** jaosorior has joined #openstack-barbican | 18:58 | |
*** fnaval_ has joined #openstack-barbican | 18:58 | |
*** jmckind has joined #openstack-barbican | 18:59 | |
*** fnaval has quit IRC | 19:01 | |
*** fnaval_ has quit IRC | 19:03 | |
*** fnaval has joined #openstack-barbican | 19:04 | |
*** jaosorior has quit IRC | 19:07 | |
openstackgerrit | Fernando Diaz proposed openstack/barbican: User Metadata Documentation https://review.openstack.org/283341 | 19:11 |
openstackgerrit | Fernando Diaz proposed openstack/barbican: User Metadata API and tests https://review.openstack.org/275885 | 19:11 |
*** fredyx10 has quit IRC | 19:29 | |
*** silos has joined #openstack-barbican | 19:36 | |
*** tkelsey has quit IRC | 19:41 | |
*** gariveradlt has quit IRC | 19:42 | |
*** jhfeng has quit IRC | 19:52 | |
*** Guest71383 is now known as redrobot | 20:01 | |
openstackgerrit | Fernando Diaz proposed openstack/barbican: User Metadata API and tests https://review.openstack.org/275885 | 20:06 |
*** david-lyle_ is now known as david-lyle | 20:12 | |
diazjf | rellerreller, I updated the policy file to all_but_audit. Seems I will need to rewrite the tests for a different policy. See my note in https://review.openstack.org/#/c/275885/24 | 20:13 |
*** hockeynut_afk is now known as hockeynut | 20:13 | |
rellerreller | diazjf I saw that. Thanks. | 20:14 |
diazjf | rellerreller, no prob thanks for looking | 20:16 |
*** nkinder has quit IRC | 20:19 | |
*** jhfeng has joined #openstack-barbican | 20:21 | |
*** fawadkhaliq has quit IRC | 20:22 | |
*** mixos has joined #openstack-barbican | 20:34 | |
*** fnaval has quit IRC | 20:43 | |
*** fnaval has joined #openstack-barbican | 20:44 | |
*** fredyx10 has joined #openstack-barbican | 20:57 | |
openstackgerrit | Fernando Diaz proposed openstack/barbican: User Metadata Documentation https://review.openstack.org/283341 | 20:59 |
*** chlong_ has joined #openstack-barbican | 21:01 | |
*** rellerreller has quit IRC | 21:03 | |
*** fredyx10 has quit IRC | 21:03 | |
*** fredyx10 has joined #openstack-barbican | 21:17 | |
diazjf | kfarr, ping | 21:23 |
kfarr | diazjf pong! | 21:23 |
diazjf | kfarr, hey so I'm looking at implementing the tests for the Barbican Key Manager with the new auth | 21:23 |
kfarr | diazjf, nice! | 21:24 |
diazjf | kfarr, Do you suggest that I make new classes to test all the functions with the new auth system? | 21:24 |
kfarr | new test classes, you mean? | 21:24 |
diazjf | like there's BarbicanKeyManagerTestcase with the setup method | 21:25 |
diazjf | I'll write new ones witha different setup | 21:25 |
diazjf | that uses different KS credentials | 21:25 |
kfarr | Oh yeah sure, I think that would be good | 21:26 |
diazjf | Ok perfect! I should have it ready for review sometime tomorrow :) | 21:26 |
kfarr | diazjf, awesome~ | 21:26 |
*** kebray has joined #openstack-barbican | 21:44 | |
*** fawadkhaliq has joined #openstack-barbican | 21:50 | |
*** silos has quit IRC | 21:55 | |
*** silos has joined #openstack-barbican | 21:57 | |
*** fredyx10 has quit IRC | 22:07 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Allow Barbican Key Manager to accept different auth credentials https://review.openstack.org/273872 | 22:09 |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Allow Barbican Key Manager to accept different auth credentials https://review.openstack.org/273872 | 22:09 |
*** phschwartz_ is now known as phschwartz | 22:14 | |
*** jmckind has quit IRC | 22:22 | |
*** fredyx10 has joined #openstack-barbican | 22:26 | |
*** mixos has quit IRC | 22:31 | |
openstackgerrit | Fernando Diaz proposed openstack/castellan: Allow Barbican Key Manager to accept different auth credentials https://review.openstack.org/273872 | 22:34 |
*** edtubill has quit IRC | 22:51 | |
*** fredyx10 has quit IRC | 22:52 | |
*** diazjf has quit IRC | 22:52 | |
*** kfarr has quit IRC | 22:53 | |
*** silos has quit IRC | 22:54 | |
openstackgerrit | Merged openstack/barbican: Fix typo in word "initialization" https://review.openstack.org/284595 | 23:08 |
*** dimtruck is now known as zz_dimtruck | 23:12 | |
*** qwebirc62353 has joined #openstack-barbican | 23:19 | |
*** spotz is now known as spotz_zzz | 23:24 | |
qwebirc62353 | hello, I upgraded barbican from stable/liberty to "c0c1833d3c18dcee1d44a2c88670b6668f7a68ab" Merge "Remove padding from legacy stored secrets" . I still cannnot decrypt secrets. Any ideas? | 23:25 |
qwebirc62353 | I meant old secrets | 23:25 |
qwebirc62353 | Any ideas? | 23:25 |
openstackgerrit | Douglas Mendizábal proposed openstack/barbican-specs: Add PUT support for Generic Containers https://review.openstack.org/286318 | 23:25 |
*** mp1 has quit IRC | 23:25 | |
redrobot | qwebirc62353 which SecretStore backend are you using? | 23:26 |
qwebirc62353 | pkcs/HSM | 23:27 |
openstackgerrit | Merged openstack/barbican: Make bandit voting as part of pep8 https://review.openstack.org/285485 | 23:27 |
openstackgerrit | Douglas Mendizábal proposed openstack/barbican-specs: Add PUT support for Generic Containers https://review.openstack.org/286318 | 23:29 |
*** mp1 has joined #openstack-barbican | 23:30 | |
jkf | qwebirc62353: I presume you're seeing CKR_SIGNATURE_INVALID errors in your logs? | 23:32 |
qwebirc62353 | 2016-02-29 17:38:05.822 29533 ERROR barbican.api.controllers code=ERROR_CODES.get(value, 'CKR_????'))) 2016-02-29 17:38:05.822 29533 ERROR barbican.api.controllers P11CryptoPluginException: HSM returned response code: 0xc0L CKR_SIGNATURE_INVALID | 23:41 |
qwebirc62353 | That is right. | 23:41 |
jkf | Cool, then the fix should be simple. A flaw was discovered in the project kek signatures that has been corrected for Mitaka, and your existing project keks needs to be migrated to the new signature scheme. | 23:43 |
jkf | In the barbican/cmd directory is a migration script that will do the work for you. | 23:43 |
jkf | This needs to be documented in the wiki, but basically shutdown your instances, back up your database and run that script. Then bring the instances back up and your secrets should be readable again. | 23:44 |
qwebirc62353 | You mean run: pkcs11_migrate_kek_signatures.py | 23:45 |
jkf | That's the one. | 23:45 |
qwebirc62353 | After shutting down barbican. | 23:45 |
qwebirc62353 | Ok. | 23:45 |
qwebirc62353 | I will try that. Thanks you. | 23:45 |
* redrobot makes a note to add that to the Mitaka Release Notes | 23:45 | |
qwebirc62353 | @qwebirc62353. That worked. Thank you, again. | 23:51 |
*** jmckind has joined #openstack-barbican | 23:52 | |
*** fnaval has quit IRC | 23:52 | |
*** jhfeng has quit IRC | 23:52 | |
*** mp1 has quit IRC | 23:53 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!