openstackgerrit | sapd proposed openstack/octavia master: Support REDIRECT_PREFIX action for L7Policy https://review.openstack.org/601086 | 02:07 |
---|---|---|
openstackgerrit | Merged openstack/octavia-dashboard master: Imported Translations from Zanata https://review.openstack.org/601050 | 02:50 |
*** yamamoto has joined #openstack-lbaas | 04:13 | |
*** reedipb has joined #openstack-lbaas | 05:00 | |
*** reedipb has quit IRC | 05:01 | |
*** reedipb has joined #openstack-lbaas | 05:01 | |
*** threestrands has joined #openstack-lbaas | 05:45 | |
*** threestrands has quit IRC | 05:45 | |
*** threestrands has joined #openstack-lbaas | 05:45 | |
*** annp has joined #openstack-lbaas | 06:07 | |
*** fnaval has quit IRC | 06:37 | |
*** rcernin has quit IRC | 07:02 | |
*** ccamposr has joined #openstack-lbaas | 07:02 | |
*** fnaval has joined #openstack-lbaas | 07:06 | |
*** fnaval has quit IRC | 07:11 | |
*** tesseract-RH has joined #openstack-lbaas | 07:17 | |
*** threestrands has quit IRC | 07:25 | |
*** pcaruana has joined #openstack-lbaas | 07:31 | |
*** velizarx has joined #openstack-lbaas | 07:34 | |
*** AlexeyAbashkin has joined #openstack-lbaas | 07:44 | |
*** velizarx has quit IRC | 07:50 | |
*** velizarx has joined #openstack-lbaas | 07:55 | |
*** dims has quit IRC | 07:57 | |
*** dims has joined #openstack-lbaas | 07:57 | |
*** celebdor has joined #openstack-lbaas | 08:01 | |
*** velizarx has quit IRC | 08:08 | |
*** velizarx has joined #openstack-lbaas | 08:17 | |
*** reedipb has quit IRC | 08:30 | |
*** annp has quit IRC | 08:40 | |
*** yamamoto has quit IRC | 09:29 | |
*** yamamoto has joined #openstack-lbaas | 09:32 | |
*** yamamoto has quit IRC | 09:37 | |
*** dolly has joined #openstack-lbaas | 09:44 | |
*** yamamoto has joined #openstack-lbaas | 10:28 | |
*** yamamoto has quit IRC | 11:45 | |
*** yamamoto has joined #openstack-lbaas | 11:48 | |
*** yamamoto has quit IRC | 11:53 | |
*** reedipb has joined #openstack-lbaas | 12:01 | |
*** amuller has joined #openstack-lbaas | 12:09 | |
*** velizarx has quit IRC | 12:11 | |
*** velizarx has joined #openstack-lbaas | 12:22 | |
*** yamamoto has joined #openstack-lbaas | 12:23 | |
*** fnaval has joined #openstack-lbaas | 14:09 | |
*** velizarx has quit IRC | 14:15 | |
*** velizarx has joined #openstack-lbaas | 14:26 | |
*** hongbin has joined #openstack-lbaas | 14:47 | |
*** velizarx has quit IRC | 14:50 | |
*** velizarx has joined #openstack-lbaas | 14:55 | |
*** sapd1_ has joined #openstack-lbaas | 14:55 | |
*** velizarx has quit IRC | 15:01 | |
rm_work | sapd1_: looks like your functional tests are still failing :( | 15:03 |
*** velizarx has joined #openstack-lbaas | 15:03 | |
sapd1_ | rm_work: yes. I'm trying to fix. Because I changed data model. So everything which associate with l7 policy will fail | 15:04 |
sapd1_ | Could you help me? | 15:04 |
rm_work | probably | 15:04 |
sapd1_ | rm_work: Do you attend PTG? | 15:05 |
rm_work | i was going to fix my barbican patch really quick as i'm in the barbican PTG meetup room right now | 15:05 |
rm_work | ^^ so that's your answer :P | 15:05 |
sapd1_ | rm_work: That's great. :D | 15:06 |
rm_work | are you? | 15:06 |
sapd1_ | no. I'm not a developer :D | 15:06 |
rm_work | i see | 15:07 |
rm_work | so you're just pretending to be a developer to make this L7 patch? :P | 15:07 |
sapd1_ | just system engineer in Vietnam. | 15:07 |
rm_work | anyone is a developer if they develop ^_^ | 15:08 |
sapd1_ | Sometimes I work as a developer, Sometimes I don't :D | 15:08 |
sapd1_ | two months ago, I tried with feature boot from volume. :D But I can't write unit test :D | 15:09 |
reedipb | rm_work : ping | 15:14 |
rm_work | pong | 15:14 |
reedipb | rm_work: Hi, long time , no chat :) | 15:15 |
rm_work | indeed | 15:15 |
reedipb | rm_work: since you are in the PTG, can you, johnsom and xgerman_ / xgerman get a chance to discuss https://review.openstack.org/#/c/599393/ ? | 15:15 |
rm_work | you make it to the PTG? | 15:15 |
rm_work | ah i guess not | 15:15 |
reedipb | Nope, sitting at home :) | 15:15 |
rm_work | Octavia is Wed-Fri | 15:15 |
xgerman_ | Yep | 15:16 |
rm_work | right now we're doing Barbican and Infra stuff mostly I think | 15:16 |
reedipb | xgerman_ your comment is there on the patch, do discuss and let me know how you( i.e. you rm_work, johnsom and others ) wish to proceed :) | 15:17 |
reedipb | And if there is any timeslot, please let me know so that I can also join the discussion | 15:17 |
rm_work | yeah, Octavia will be Wed-Fri | 15:32 |
rm_work | there's an etherpad for the PTG somewhere, so if i can find that we can add it to the agenda | 15:32 |
rm_work | johnsom: can you put that link in the topic maybe? | 15:33 |
dayou | https://etherpad.openstack.org/p/octavia-stein-ptg | 15:55 |
*** hongbin_ has joined #openstack-lbaas | 15:55 | |
*** hongbin has quit IRC | 15:56 | |
openstackgerrit | sapd proposed openstack/octavia master: Support REDIRECT_PREFIX action for L7Policy https://review.openstack.org/601086 | 15:58 |
*** AlexeyAbashkin has quit IRC | 16:11 | |
*** yamamoto has quit IRC | 16:14 | |
*** ccamposr has quit IRC | 16:14 | |
*** yamamoto has joined #openstack-lbaas | 16:14 | |
*** yamamoto has quit IRC | 16:19 | |
*** sapd1_ has quit IRC | 16:27 | |
*** velizarx has quit IRC | 16:33 | |
*** yamamoto has joined #openstack-lbaas | 16:43 | |
*** tesseract-RH has quit IRC | 16:46 | |
openstackgerrit | Michael Johnson proposed openstack/octavia-tempest-plugin master: DNM: Testing bionic nodes https://review.openstack.org/600539 | 16:46 |
openstackgerrit | Michael Johnson proposed openstack/octavia-tempest-plugin master: DNM: Testing bionic nodes https://review.openstack.org/600539 | 16:49 |
*** ChanServ changes topic to "OpenStack PTG etherpad: https://etherpad.openstack.org/p/octavia-stein-ptg" | 16:51 | |
johnsom | Done | 16:51 |
tobias-urdin | johnsom: i'm getting crazy over here, i used the generate script from the bin folder, in two different folders `client` and `server` | 16:59 |
tobias-urdin | then configured like this http://paste.openstack.org/show/729796/ | 16:59 |
tobias-urdin | i went through your link in slow-motion still, something is not right "bad handshake" | 16:59 |
tobias-urdin | i also set [certificates]/ca_private_key_passphrase to the proper passphrase for the /etc/octavia/certs/server/private/cakey.pem file. | 17:00 |
*** Swami has joined #openstack-lbaas | 17:04 | |
xgerman_ | tobias-urdin: you are at the PTG? | 17:21 |
tobias-urdin | no :( | 17:23 |
*** velizarx has joined #openstack-lbaas | 17:26 | |
xgerman_ | What you posted looks right… I have written the ansible part: https://github.com/openstack/openstack-ansible-os_octavia/blob/master/tasks/octavia_certs.yml — maybe that will help shed light on it | 17:28 |
xgerman_ | without having openssl outputs which certificates are which it’s hard for me to see what’s wrong | 17:29 |
tobias-urdin | ok, yeah i've checked the os_octavia ansible module many many times, and the irclog that johnsom sent but no success | 17:30 |
tobias-urdin | testing to use one CA now, just to see if it works | 17:30 |
xgerman_ | yeah, two CAs is tricky | 17:31 |
xgerman_ | I often have to debug the generated certs with openssl since (for instance the sensible cert module) was generating garbage | 17:31 |
tobias-urdin | seems like that didn't work either | 17:32 |
*** sanfern has joined #openstack-lbaas | 17:32 | |
xgerman_ | Yeah, this link helps me to find the right openssl https://www.sslshopper.com/article-most-common-openssl-commands.html | 17:33 |
xgerman_ | commands | 17:33 |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Update for DIB using bionic https://review.openstack.org/601329 | 17:38 |
openstackgerrit | Michael Johnson proposed openstack/octavia-tempest-plugin master: DNM: Testing bionic nodes https://review.openstack.org/600539 | 17:38 |
*** yamamoto has quit IRC | 17:43 | |
tobias-urdin | something is clearly wrong, used a simple generated using the script in the bin folder | 17:44 |
tobias-urdin | 2018-09-10 19:43:15.312 15032 WARNING octavia.amphorae.drivers.haproxy.rest_api_driver [-] Could not connect to instance. Retrying.: SSLError: ("bad handshake: Error([('rsa routines', 'RSA_padding_check_PKCS1_type_1', 'block type is not 01'), ('rsa routines', 'RSA_EAY_PUBLIC_DECRYPT', 'padding check failed'), ('SSL routines', 'ssl3_get_key_exchange', 'bad signature')],)",) | 17:44 |
tobias-urdin | http://paste.openstack.org/show/729798/ | 17:44 |
tobias-urdin | maybe its my openssl version 1.0.2k or that i'm using the test-only image | 17:45 |
tobias-urdin | also generated from my local workstation though that has openssl 1.0.2g | 17:46 |
*** velizarx has quit IRC | 17:47 | |
openstackgerrit | Michael Johnson proposed openstack/octavia-tempest-plugin master: Use the infra mirrors for DIB https://review.openstack.org/601332 | 17:47 |
xgerman_ | yeah, once you have reviewed the the certs — you can look at the connection with curl | 17:48 |
xgerman_ | https://docs.google.com/presentation/d/1p8ekZ99E30XR6w1hkPufTQJKCwkX9tRctnCIWVlx4Zw/edit?usp=sharing | 17:50 |
xgerman_ | this describes how to access the amp and which certs it would be using | 17:50 |
xgerman_ | use -v so it show you the certs sends over | 17:50 |
tobias-urdin | Peer's certificate issuer has been marked as not trusted by the user. | 17:52 |
tobias-urdin | then with "-k" Peer's certificate has an invalid signature. | 17:52 |
xgerman_ | yeah, somehow those certs are shot | 17:53 |
tobias-urdin | after a quick google "The problem was that my CA DN was the same as the certificate DN." | 17:56 |
tobias-urdin | checking the create_certificates.sh script that seems the case, worth a try i guess | 17:56 |
tobias-urdin | xgerman_: thanks for the help, atleast one step closer now, it could connect to the amphora now, but still failed on something else | 18:08 |
tobias-urdin | but progress i guess | 18:08 |
tobias-urdin | http://paste.openstack.org/show/729801/ | 18:08 |
*** hongbin_ has quit IRC | 18:10 | |
*** yamamoto has joined #openstack-lbaas | 18:20 | |
*** abaindur has joined #openstack-lbaas | 18:23 | |
*** sanfern has quit IRC | 18:25 | |
*** yamamoto has quit IRC | 18:30 | |
*** fnaval has quit IRC | 18:30 | |
*** yamamoto has joined #openstack-lbaas | 18:30 | |
*** fnaval has joined #openstack-lbaas | 18:55 | |
*** yamamoto has quit IRC | 19:56 | |
*** pcaruana has quit IRC | 20:08 | |
*** yamamoto has joined #openstack-lbaas | 20:27 | |
*** celebdor has quit IRC | 20:53 | |
*** luksky has joined #openstack-lbaas | 20:57 | |
*** luksky has quit IRC | 21:17 | |
*** hongbin has joined #openstack-lbaas | 21:53 | |
*** fnaval has quit IRC | 21:58 | |
*** fnaval has joined #openstack-lbaas | 22:10 | |
lxkong | hey, could anybody please help review https://review.openstack.org/#/c/600912/? | 22:12 |
*** takamatsu has quit IRC | 22:23 | |
*** hongbin has quit IRC | 22:25 | |
abaindur | johnsom: some clarifcation about certs expiring | 22:35 |
abaindur | 1. We only need to failover the amphora if the client CA itself expires or changes, correct? | 22:36 |
abaindur | 2. If the self-genrated amphora server certs expire, octavia takes care of this automatically, injecting it into the amphora using the internal API and req. no intervention on our part, also correct? | 22:36 |
abaindur | 3. if the octavia controller's client cert expires, no failover or anything else needs to be also also, right? Besides obviously updating the cert in file on host and restarting services | 22:38 |
abaindur | 4. And finally regarding the server CA expiring - I can't seem to figure out what needs to be done in this case. If this changes it seems like we'd need to gen and refresh certs for all existing amphora (similar to all amphora expring at same time). But i can't find in the code where this is done | 22:40 |
*** rcernin has joined #openstack-lbaas | 22:46 | |
*** bcafarel has quit IRC | 23:37 | |
*** abaindur has quit IRC | 23:37 | |
*** abaindur has joined #openstack-lbaas | 23:38 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!