*** zz_dimtruck is now known as dimtruck | 00:24 | |
*** Jiahao has quit IRC | 01:10 | |
openstackgerrit | zhangyanxian proposed openstack/barbican: Fix typos in alembic.ini & kmip_secret_store.py https://review.openstack.org/374470 | 01:24 |
---|---|---|
openstackgerrit | zhangyanxian proposed openstack/barbican: Fix typos in alembic.ini & kmip_secret_store.py https://review.openstack.org/374470 | 01:26 |
*** woodster_ has quit IRC | 01:50 | |
*** david-lyle has quit IRC | 03:03 | |
*** kberger has quit IRC | 04:15 | |
*** kberger has joined #openstack-barbican | 04:16 | |
*** alee_afk is now known as alee | 04:30 | |
*** kberger has quit IRC | 04:45 | |
*** kberger has joined #openstack-barbican | 04:46 | |
openstackgerrit | Tony Xu proposed openstack/python-barbicanclient: Add oslo.config to requirements https://review.openstack.org/374526 | 05:02 |
*** jaosorior has joined #openstack-barbican | 05:07 | |
*** dimtruck is now known as zz_dimtruck | 05:22 | |
*** andreas_s has joined #openstack-barbican | 06:35 | |
*** jamielennox is now known as jamielennox|away | 08:09 | |
*** jamielennox|away is now known as jamielennox | 09:18 | |
*** ig0r_ has joined #openstack-barbican | 09:20 | |
*** kberger has quit IRC | 10:47 | |
*** kberger has joined #openstack-barbican | 10:48 | |
*** zigo has quit IRC | 11:54 | |
*** zigo has joined #openstack-barbican | 11:58 | |
*** zigo is now known as Guest83601 | 11:59 | |
*** Guest83601 has quit IRC | 12:03 | |
*** zigo_ has joined #openstack-barbican | 12:12 | |
*** zigo_ has quit IRC | 12:17 | |
*** zigo_ has joined #openstack-barbican | 12:18 | |
*** alee has quit IRC | 12:23 | |
*** zigo_ has quit IRC | 12:48 | |
*** zigo_ has joined #openstack-barbican | 12:51 | |
*** david-lyle has joined #openstack-barbican | 12:57 | |
*** jperry has joined #openstack-barbican | 13:09 | |
*** jaosorior has quit IRC | 13:12 | |
*** jaosorior has joined #openstack-barbican | 13:13 | |
*** woodster_ has joined #openstack-barbican | 13:20 | |
*** zz_dimtruck is now known as dimtruck | 13:20 | |
*** alee has joined #openstack-barbican | 13:33 | |
*** spotz_zzz is now known as spotz | 13:56 | |
*** ngupta has joined #openstack-barbican | 13:58 | |
*** tdink has joined #openstack-barbican | 14:01 | |
*** tdink has quit IRC | 14:03 | |
*** jmckind has joined #openstack-barbican | 14:09 | |
*** panatl has quit IRC | 14:12 | |
*** dimtruck is now known as zz_dimtruck | 14:23 | |
*** jaosorior has quit IRC | 14:29 | |
*** panatl has joined #openstack-barbican | 14:32 | |
woodster_ | alee: dave-mccowan FYI, here's a spec related to that cert validation use case and testing mentioned yesterday: https://review.openstack.org/#/c/357151/ | 14:33 |
*** randallburt has joined #openstack-barbican | 14:37 | |
*** tdink has joined #openstack-barbican | 14:40 | |
dave-mccowan | woodster_ thanks. i missed the conversation on Cursive. Looks like it does does signing as a service. Do you know if it plans to use Barbican for certificate storage? | 14:41 |
*** randallburt1 has joined #openstack-barbican | 14:41 | |
*** edtubill has joined #openstack-barbican | 14:43 | |
*** randallburt has quit IRC | 14:44 | |
*** catintheroof has joined #openstack-barbican | 14:50 | |
*** nkinder has joined #openstack-barbican | 14:59 | |
*** zz_dimtruck is now known as dimtruck | 14:59 | |
*** nkinder has quit IRC | 15:09 | |
*** zigo_ is now known as zigo | 15:14 | |
*** andreas_s has quit IRC | 15:17 | |
*** andreas_s has joined #openstack-barbican | 15:17 | |
*** nkinder has joined #openstack-barbican | 15:20 | |
*** diazjf has joined #openstack-barbican | 15:37 | |
*** andreas_s has quit IRC | 15:42 | |
*** kfarr has joined #openstack-barbican | 15:55 | |
*** ngupta has quit IRC | 15:58 | |
*** ngupta has joined #openstack-barbican | 15:59 | |
*** ngupta has quit IRC | 16:00 | |
*** ngupta has joined #openstack-barbican | 16:00 | |
kfarr | dave-mccowan woodster_ cursive uses castellan, so yes it can use barbican to store certs | 16:01 |
*** diazjf has quit IRC | 16:01 | |
kfarr | also alee, catching up on the chat logs from yesterday, it wasn't my patch that broke cinder volume encryption >:-( though I worked on the fix | 16:03 |
alee | kfarr, sorry - my bad - I appreciate that you worked on the fix though :) | 16:04 |
*** tdink has quit IRC | 16:04 | |
*** tdink has joined #openstack-barbican | 16:05 | |
dave-mccowan | kfarr cool. should we have a Cursive/Barbican meetup at summit? do they want to be part of the big tent? | 16:06 |
kfarr | dave-mccowan, well, cursive is just a python utility library, similar to castellan | 16:07 |
woodster_ | kfarr: who created cursive? | 16:07 |
kfarr | really the only person who's been working on it who will be at the summit is dane-fichter, though I'm tangentially involved | 16:07 |
kfarr | Dane Fichter created it, on our APL team here | 16:07 |
woodster_ | kfarr: dane-fichter is tasked with adding a nova cert verify dev stack task, that's what started the conversations around this yesterday | 16:08 |
alee | kfarr, ah - I was wondering who Dane Fichter was .. | 16:08 |
kfarr | woodster_, yeah I heard about it | 16:08 |
kfarr | would be really great to have an upstream gate check that used Barbican | 16:09 |
dave-mccowan | if it makes sense to everyone, maybe Cursive could be added as a repo under the Barbican umbrella. signing as a service has been on the list for a while now. | 16:10 |
woodster_ | kfarr: there was also talk of just adding such integration tests to barbican...to demonstrate 'maturity' as one Nova core put it | 16:10 |
kfarr | dave-mccowan, it's not a service right now, though | 16:11 |
dave-mccowan | kfarr do you know if Cursive has talked to Magnum or Designate? (other projects who wanted to check signatures) | 16:13 |
kfarr | dave-mccowan, AFAIK, Dane hasn't talked to any Magnum or Designate folks | 16:13 |
kfarr | also redrobot alee diazjf (am I forgetting anyone?) I had an important meeting pop up at the same time as our meeting later today | 16:18 |
kfarr | Could we shift the meeting back an hour? Otherwise I will just try to catch the end of it | 16:19 |
alee | kfarr, ok with me | 16:20 |
redrobot | shift back == earlier or later? | 16:20 |
*** jperry has quit IRC | 16:20 | |
*** jperry has joined #openstack-barbican | 16:20 | |
alee | (I assumed that meant later) | 16:20 |
kfarr | oh yeah, sorry, shift later | 16:21 |
redrobot | yeah, I should be able to do that. just gotta move another meeting around. | 16:22 |
openstackgerrit | Merged openstack/python-barbicanclient: Add oslo.config to requirements https://review.openstack.org/374526 | 16:23 |
*** jperry has quit IRC | 16:28 | |
alee | kfarr, redrobot I don't think diazf is online | 16:28 |
alee | kfarr, redrobot -lets assume 3pm EST then pending further updates .. going to lunch now .. | 16:29 |
*** jperry has joined #openstack-barbican | 16:29 | |
*** alee is now known as alee_lunch | 16:29 | |
kfarr | ok thanks alee! | 16:29 |
*** edtubill has quit IRC | 16:39 | |
*** zigo has quit IRC | 16:41 | |
*** zigo has joined #openstack-barbican | 16:51 | |
*** zigo is now known as Guest18656 | 16:52 | |
*** Guest18656 has quit IRC | 16:56 | |
*** zigo_ has joined #openstack-barbican | 16:59 | |
*** tkelsey has joined #openstack-barbican | 17:02 | |
*** zigo_ has quit IRC | 17:07 | |
*** zigo_ has joined #openstack-barbican | 17:11 | |
*** edtubill has joined #openstack-barbican | 17:34 | |
*** diazjf has joined #openstack-barbican | 17:34 | |
*** tkelsey has quit IRC | 18:01 | |
*** diazjf has quit IRC | 18:06 | |
*** ngupta_ has joined #openstack-barbican | 18:09 | |
*** ig0r_ has quit IRC | 18:09 | |
*** jay_ has joined #openstack-barbican | 18:09 | |
jay_ | hi all | 18:10 |
jay_ | i am facing issue with listener create | 18:10 |
jay_ | with liberty barbican | 18:10 |
jay_ | passing default-tls-container-ref parameter while creating listener | 18:11 |
jay_ | it errors out | 18:11 |
jay_ | ERROR: neutronclient.shell Could not process TLS container http://x.x.x.x:9311/v1/containers/05b750e5-ef14-4afc-b4fe-2b4949cf3356, Invalid user / password (Disable debug mode to suppress these details.) | 18:12 |
*** ngupta has quit IRC | 18:12 | |
jay_ | i have configd this in neutron.conf | 18:12 |
jay_ | admin_tenant_name = admin admin_user = admin admin_password = password auth_version = v2 | 18:13 |
jay_ | under [keystone_authtoken] | 18:14 |
*** diazjf has joined #openstack-barbican | 18:14 | |
jay_ | any idea , anyone faced similar issue | 18:14 |
*** ngupta_ has quit IRC | 18:20 | |
*** ngupta has joined #openstack-barbican | 18:20 | |
jay_ | in neutron_lbaas.conf did the foll config | 18:21 |
jay_ | [service_auth] auth_uri = http://localhost:35357/v2.0 admin_tenant_name = admin admin_user = admin admin_password = password auth_version = 2 | 18:21 |
*** ngupta_ has joined #openstack-barbican | 18:22 | |
*** ngupta_ has quit IRC | 18:25 | |
*** ngupta_ has joined #openstack-barbican | 18:26 | |
*** arunkant__ has joined #openstack-barbican | 18:26 | |
*** ngupta has quit IRC | 18:26 | |
*** jay_ has quit IRC | 18:28 | |
*** diazjf has quit IRC | 18:30 | |
*** ngupta_ has quit IRC | 18:30 | |
*** jperry has quit IRC | 18:35 | |
*** jperry has joined #openstack-barbican | 18:35 | |
*** alee_lunch is now known as alee | 18:41 | |
*** jperry has quit IRC | 18:41 | |
*** jperry has joined #openstack-barbican | 18:42 | |
*** kfarr_ has joined #openstack-barbican | 18:46 | |
*** ngupta has joined #openstack-barbican | 18:53 | |
*** diazjf has joined #openstack-barbican | 18:59 | |
diazjf | alee, kfarr, redrobot, I'm here! saw the meeting was moved to 3:00PM EST | 19:01 |
alee | redrobot, is there a link for the google hangout? | 19:01 |
redrobot | \o/ | 19:01 |
redrobot | yeah, give me a sec | 19:01 |
kfarr_ | alee diazjf redrobot | 19:01 |
kfarr_ | I don't think there was one | 19:01 |
kfarr_ | but I just made one? | 19:01 |
kfarr_ | https://hangouts.google.com/call/5xvnj7nafjczfmdhn4eyo6ha4ae | 19:01 |
alee | cool | 19:01 |
redrobot | kfarr_ have you tried turning the volume up? | 19:05 |
kfarr_ | haha thank redrobot | 19:05 |
kfarr_ | yeah I can hear everything else | 19:05 |
arunkant__ | can someone please review and possibly merge this..https://review.openstack.org/#/c/353744/ | 19:12 |
*** zigo_ is now known as zigo | 19:30 | |
redrobot | alee https://etherpad.openstack.org/p/barbican-barcelona-hands-on | 19:33 |
openstackgerrit | dane-fichter proposed openstack/barbican: Improve devstack configuration https://review.openstack.org/375079 | 19:48 |
*** ngupta has quit IRC | 19:51 | |
*** ngupta has joined #openstack-barbican | 19:52 | |
*** ngupta_ has joined #openstack-barbican | 19:54 | |
*** ngupta has quit IRC | 19:56 | |
woodster_ | redrobot: dave-mccowan A bit of architectural discussion regarding Barbican at the arch-wg meeting today: http://eavesdrop.openstack.org/meetings/arch_wg/2016/arch_wg.2016-09-22-19.02.html | 20:02 |
woodster_ | It woudl be good to meet with these folks at the summit...might give Barbican more cred with the community, though they are skeptical of the value of barbican without HSMs of course. It seems we need a soft HSM option that is better than saving master keks in conf files :) | 20:04 |
* woodster_ ...as a default option that is | 20:04 | |
*** diazjf has quit IRC | 20:07 | |
woodster_ | alee: arunkant__ ^^^^ | 20:08 |
alee | woodster_, and of course dogtag allows you to do this without hsms .. | 20:15 |
*** ngupta_ has quit IRC | 20:16 | |
*** ngupta has joined #openstack-barbican | 20:17 | |
*** diazjf has joined #openstack-barbican | 20:18 | |
*** ngupta has quit IRC | 20:21 | |
dave-mccowan | woodster_ i think barbican provides some value over keys in conf files. 1) you can have different keys for different instances, 2) you can store the keys on a different drive than both the config file and the data. | 20:24 |
kfarr_ | dave-mccowan +1 +1 | 20:25 |
*** ngupta has joined #openstack-barbican | 20:30 | |
kfarr_ | redrobot, did you close on a house / was that a wall of the new house providing your backdrop during the video call? :) | 20:31 |
redrobot | kfarr_ unfortunately, we didn't :( | 20:32 |
kfarr_ | redrobot noooo :( | 20:32 |
redrobot | kfarr_ house needed a lot of repairs and the sellers didn't want to fix and/or lower the price. :-\ | 20:32 |
kfarr_ | redrobot ugh that's a bummer | 20:33 |
kfarr_ | diazjf is it possible you could send the flask code this week instead of next just so I could take a look at it sooner? | 20:33 |
kfarr_ | next week will be pretty hectic for me | 20:34 |
woodster_ | dave-mccowan: kfarr I mean the default simple crypto for barbican that stores the master kek in the barbican conf file | 20:35 |
woodster_ | redrobot: sorry to hear that! | 20:36 |
woodster_ | alee: doesn't dogtag use an hsm as its backend? | 20:36 |
redrobot | woodster_ ¯\_(ツ)_/¯ we'll find the right house one of these days... | 20:37 |
alee | woodster_, dogtag can use either hsm or nss db as backend | 20:37 |
dave-mccowan | woodster_ even then, as long as the key database is on a different drive than the barbican conf file, i think there is some additional security compared to have one encryption key in the nova config file. | 20:39 |
woodster_ | dave-mccowan: agreed. There are several gray levels of security. It would be good to find a home for Barbican for all of these levels (in the minds of deployers/other OS projects) | 20:40 |
woodster_ | redrobot: yeah don't give up | 20:40 |
woodster_ | alee: I'd forgotten about nss db | 20:41 |
alee | woodster_, yup | 20:43 |
alee | woodster_, redrobot we really need to get that deployment guide fixed up .. | 20:44 |
dave-mccowan | alee is the deployment guide in to repo? | 20:45 |
alee | dave-mccowan, yup in the barbican tree | 20:46 |
alee | dave-mccowan, its just not in a final form yet .. | 20:46 |
alee | parts missing .. | 20:46 |
alee | dave-mccowan, there is a tox target to build it .. | 20:47 |
alee | tox -e install-guide iirc .. | 20:47 |
dave-mccowan | alee doc/source/admin-guide-cloud? | 20:48 |
alee | dave-mccowan, no -- top-level install-guide | 20:49 |
*** spotz is now known as spotz_zzz | 20:50 | |
alee | dave-mccowan, tox -e install-guide | 20:51 |
dave-mccowan | alee got it. i was looking in an old branch | 20:51 |
alee | dave-mccowan, builds in install-guide/build/html | 20:52 |
*** diazjf has quit IRC | 20:56 | |
*** diazjf has joined #openstack-barbican | 20:59 | |
*** kfarr_ has quit IRC | 21:09 | |
*** diazjf has quit IRC | 21:15 | |
*** diazjf has joined #openstack-barbican | 21:22 | |
*** randallburt1 has quit IRC | 21:22 | |
*** gyee has joined #openstack-barbican | 21:27 | |
diazjf | kfarr sure I'll take a look tonight and see if I can find it | 21:32 |
*** strigazi has quit IRC | 21:37 | |
*** DuncanT has quit IRC | 21:37 | |
*** diazjf has quit IRC | 21:37 | |
*** alee has quit IRC | 21:37 | |
*** vipul has quit IRC | 21:37 | |
*** jorgem has quit IRC | 21:37 | |
*** julian1 has quit IRC | 21:37 | |
*** madorn has quit IRC | 21:37 | |
*** kragniz has quit IRC | 21:37 | |
*** sigmavirus has quit IRC | 21:37 | |
*** rhagarty_ has quit IRC | 21:37 | |
*** stupidnic has quit IRC | 21:37 | |
*** stevemar has quit IRC | 21:37 | |
*** eglute has quit IRC | 21:37 | |
*** jvrbanac has quit IRC | 21:37 | |
*** jroll has quit IRC | 21:37 | |
*** jamielennox has quit IRC | 21:37 | |
*** beisner has quit IRC | 21:37 | |
*** cargonza has quit IRC | 21:37 | |
*** dimtruck has quit IRC | 21:37 | |
*** haplo37_ has quit IRC | 21:37 | |
*** spotz_zzz has quit IRC | 21:37 | |
*** diazjf has joined #openstack-barbican | 21:38 | |
*** alee has joined #openstack-barbican | 21:38 | |
*** vipul has joined #openstack-barbican | 21:38 | |
*** jorgem has joined #openstack-barbican | 21:38 | |
*** julian1 has joined #openstack-barbican | 21:38 | |
*** madorn has joined #openstack-barbican | 21:38 | |
*** kragniz has joined #openstack-barbican | 21:38 | |
*** sigmavirus has joined #openstack-barbican | 21:38 | |
*** jroll has joined #openstack-barbican | 21:40 | |
*** jamielennox has joined #openstack-barbican | 21:40 | |
*** beisner has joined #openstack-barbican | 21:40 | |
*** dimtruck has joined #openstack-barbican | 21:40 | |
*** haplo37_ has joined #openstack-barbican | 21:40 | |
*** spotz_zzz has joined #openstack-barbican | 21:40 | |
*** alee has quit IRC | 21:40 | |
*** strigazi has joined #openstack-barbican | 21:41 | |
*** rhagarty_ has joined #openstack-barbican | 21:42 | |
*** stupidnic has joined #openstack-barbican | 21:42 | |
*** stevemar has joined #openstack-barbican | 21:42 | |
*** eglute has joined #openstack-barbican | 21:42 | |
*** jvrbanac has joined #openstack-barbican | 21:42 | |
*** tdink has quit IRC | 21:47 | |
*** jmckind has quit IRC | 21:50 | |
*** jperry has quit IRC | 22:01 | |
*** cargonza has joined #openstack-barbican | 22:04 | |
*** DuncanT has joined #openstack-barbican | 22:08 | |
*** edtubill has quit IRC | 22:09 | |
*** nickchase has joined #openstack-barbican | 22:14 | |
*** nickchase has quit IRC | 22:15 | |
*** ngupta has quit IRC | 22:15 | |
*** ngupta has joined #openstack-barbican | 22:16 | |
*** nickchase has joined #openstack-barbican | 22:17 | |
nickchase | Hey, all, quick question: what is Castellan and how does it relate to Barbican? | 22:19 |
*** ngupta has quit IRC | 22:20 | |
*** diazjf has quit IRC | 22:22 | |
*** ngupta has joined #openstack-barbican | 22:30 | |
*** nickchase has quit IRC | 22:40 | |
*** alee has joined #openstack-barbican | 22:42 | |
*** ngupta has quit IRC | 22:54 | |
*** randallburt has joined #openstack-barbican | 22:54 | |
*** ngupta has joined #openstack-barbican | 22:54 | |
*** randallburt1 has joined #openstack-barbican | 22:58 | |
*** ngupta has quit IRC | 22:59 | |
*** ngupta has joined #openstack-barbican | 23:00 | |
*** randallburt has quit IRC | 23:02 | |
*** randallburt1 has quit IRC | 23:14 | |
*** ngupta has quit IRC | 23:18 | |
*** ngupta has joined #openstack-barbican | 23:18 | |
*** ngupta has quit IRC | 23:23 | |
*** ngupta has joined #openstack-barbican | 23:28 | |
*** ngupta has quit IRC | 23:51 | |
*** ngupta has joined #openstack-barbican | 23:51 | |
*** arunkant__ has quit IRC | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!