*** abaindur__ has quit IRC | 00:00 | |
*** abaindur has quit IRC | 00:05 | |
*** abaindur has joined #openstack-lbaas | 00:05 | |
*** abaindur_ has joined #openstack-lbaas | 00:08 | |
*** celebdor1 has quit IRC | 00:08 | |
*** abaindur has quit IRC | 00:10 | |
*** yamamoto_ has quit IRC | 00:10 | |
openstackgerrit | Michael Johnson proposed openstack/python-octaviaclient master: Add enable_tls option into Pool CLI https://review.openstack.org/624265 | 00:10 |
---|---|---|
*** yamamoto has joined #openstack-lbaas | 00:14 | |
*** yamamoto has quit IRC | 00:20 | |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Add 2 new fields into Pool API for support re-encryption https://review.openstack.org/614447 | 00:20 |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Add boolean tls_enabled option into Pool https://review.openstack.org/624264 | 00:20 |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Amp driver support sni option to send the hostname to backend https://review.openstack.org/624267 | 00:20 |
openstackgerrit | Michael Johnson proposed openstack/octavia master: Fix an amphora driver bug for TLS client auth https://review.openstack.org/640232 | 00:38 |
*** trown is now known as trown|outtypewww | 00:39 | |
*** yamamoto has joined #openstack-lbaas | 00:46 | |
*** yamamoto has quit IRC | 00:50 | |
*** strigazi has quit IRC | 00:55 | |
*** strigazi has joined #openstack-lbaas | 00:56 | |
*** strigazi has quit IRC | 01:05 | |
*** strigazi has joined #openstack-lbaas | 01:05 | |
*** abaindur has joined #openstack-lbaas | 01:24 | |
*** abaindur_ has quit IRC | 01:25 | |
*** abaindur_ has joined #openstack-lbaas | 01:28 | |
*** henriqueof has quit IRC | 01:30 | |
*** abaindu__ has joined #openstack-lbaas | 01:31 | |
*** abaindu__ is now known as abaindur__ | 01:31 | |
*** abaindur has quit IRC | 01:31 | |
*** abaindur_ has quit IRC | 01:33 | |
*** abaindur has joined #openstack-lbaas | 01:34 | |
*** abaindur_ has joined #openstack-lbaas | 01:36 | |
*** abaindur__ has quit IRC | 01:36 | |
*** abaindur has quit IRC | 01:38 | |
*** abaindur has joined #openstack-lbaas | 01:39 | |
*** abaindur_ has quit IRC | 01:41 | |
*** yamamoto has joined #openstack-lbaas | 02:00 | |
*** Dinesh_Bhor has joined #openstack-lbaas | 02:21 | |
*** abaindur_ has joined #openstack-lbaas | 02:40 | |
*** abaindu__ has joined #openstack-lbaas | 02:43 | |
*** abaindur has quit IRC | 02:43 | |
*** abaindu__ is now known as abaindur__ | 02:43 | |
*** abaindur_ has quit IRC | 02:45 | |
*** hongbin has joined #openstack-lbaas | 02:46 | |
*** abaindur has joined #openstack-lbaas | 02:47 | |
*** abaindur_ has joined #openstack-lbaas | 02:50 | |
*** abaindur__ has quit IRC | 02:50 | |
*** abaindur has quit IRC | 02:52 | |
*** abaindur_ has quit IRC | 02:52 | |
*** yamamoto has quit IRC | 03:04 | |
*** fnaval has quit IRC | 03:08 | |
*** fnaval has joined #openstack-lbaas | 03:11 | |
*** fnaval has quit IRC | 03:11 | |
*** psachin has joined #openstack-lbaas | 03:12 | |
*** ramishra has joined #openstack-lbaas | 03:14 | |
*** yamamoto has joined #openstack-lbaas | 03:48 | |
*** ramishra has quit IRC | 04:09 | |
*** ramishra has joined #openstack-lbaas | 04:09 | |
*** yamamoto has quit IRC | 04:10 | |
*** Dinesh_Bhor has quit IRC | 04:29 | |
*** hongbin has quit IRC | 04:40 | |
*** yamamoto has joined #openstack-lbaas | 04:49 | |
*** Dinesh_Bhor has joined #openstack-lbaas | 04:50 | |
*** yamamoto has quit IRC | 04:54 | |
*** yamamoto has joined #openstack-lbaas | 05:53 | |
*** yamamoto has quit IRC | 05:58 | |
*** abaindur has joined #openstack-lbaas | 05:58 | |
*** abaindur has quit IRC | 05:59 | |
*** Dinesh_Bhor has quit IRC | 05:59 | |
*** abaindur has joined #openstack-lbaas | 05:59 | |
*** Dinesh_Bhor has joined #openstack-lbaas | 06:02 | |
*** ivve has joined #openstack-lbaas | 06:34 | |
*** mkuf has quit IRC | 07:05 | |
openstackgerrit | Merged openstack/neutron-lbaas master: Update neutron quota_driver path https://review.openstack.org/639829 | 07:05 |
*** ccamposr has joined #openstack-lbaas | 07:05 | |
*** yamamoto has joined #openstack-lbaas | 07:08 | |
*** yamamoto has quit IRC | 07:13 | |
*** mkuf has joined #openstack-lbaas | 07:21 | |
*** yamamoto has joined #openstack-lbaas | 07:46 | |
*** Dinesh_Bhor has quit IRC | 08:01 | |
*** abaindur has quit IRC | 08:01 | |
*** Dinesh_Bhor has joined #openstack-lbaas | 08:08 | |
*** AlexStaf has joined #openstack-lbaas | 08:09 | |
*** luksky has joined #openstack-lbaas | 08:34 | |
*** celebdor1 has joined #openstack-lbaas | 08:40 | |
*** ramishra has quit IRC | 08:52 | |
*** AlexStaf has quit IRC | 08:54 | |
*** salmankhan has quit IRC | 09:01 | |
*** yamamoto has quit IRC | 09:04 | |
*** yamamoto has joined #openstack-lbaas | 09:05 | |
*** AlexStaf has joined #openstack-lbaas | 09:27 | |
*** jiteka has quit IRC | 10:20 | |
*** eandersson has quit IRC | 10:20 | |
*** jiteka has joined #openstack-lbaas | 10:25 | |
*** celebdor1 has quit IRC | 10:26 | |
*** salmankhan has joined #openstack-lbaas | 10:29 | |
*** AlexStaf has quit IRC | 10:32 | |
*** salmankhan1 has joined #openstack-lbaas | 10:33 | |
*** salmankhan has quit IRC | 10:36 | |
*** salmankhan1 is now known as salmankhan | 10:36 | |
*** yamamoto has quit IRC | 10:45 | |
*** luksky has quit IRC | 10:56 | |
*** ramishra has joined #openstack-lbaas | 10:57 | |
*** luksky has joined #openstack-lbaas | 11:09 | |
zigo | Hi there. | 11:21 |
zigo | Anyone around? | 11:21 |
zigo | johnsom: Are you there? | 11:21 |
*** yamamoto has joined #openstack-lbaas | 11:21 | |
*** luksky has quit IRC | 11:22 | |
*** Dinesh_Bhor has quit IRC | 11:24 | |
*** yamamoto has quit IRC | 11:32 | |
*** yamamoto has joined #openstack-lbaas | 11:35 | |
*** yamamoto has quit IRC | 11:35 | |
cgoncalves | zigo, can I be of any help? johnsom is located in western US. | 11:38 |
zigo | cgoncalves: I'm still having issue with the Octavia PKI. | 11:38 |
zigo | octavia-worker gets a SSL: CERTIFICATE_VERIFY_FAILED. | 11:38 |
zigo | I'm trying to figure out why... | 11:38 |
zigo | cgoncalves: When trying with Curl, I get: | 11:39 |
zigo | curl: (35) error:0407008A:rsa routines:RSA_padding_check_PKCS1_type_1:invalid padding | 11:39 |
zigo | I'm guessing my root CA is badly configured ... | 11:40 |
cgoncalves | zigo, I didn't follow previous discussions you might have had about that. | 11:41 |
cgoncalves | zigo, when does that happen? what are you curling? | 11:42 |
zigo | cgoncalves: The amphora-agent.service on port 9443. | 11:42 |
*** yamamoto has joined #openstack-lbaas | 11:43 | |
cgoncalves | zigo, have you followed the certificate guide? https://docs.openstack.org/octavia/latest/admin/guides/certificates.html | 11:46 |
zigo | cgoncalves: I did, and it failed on me... | 11:46 |
*** yamamoto has quit IRC | 11:47 | |
cgoncalves | I must confess I am not super familiar with this area so apologies for random questions | 11:47 |
zigo | With SSL: CERTIFICATE_VERIFY_FAILED | 11:47 |
zigo | Ok. | 11:47 |
cgoncalves | hmm ok. let me check | 11:47 |
zigo | # curl https://10.52.234.8:9443/0.5/info | 11:49 |
zigo | curl: (35) error:0407008A:rsa routines:RSA_padding_check_PKCS1_type_1:invalid padding | 11:49 |
cgoncalves | zigo, which python version are you running? | 11:49 |
zigo | Python 3.5. | 11:49 |
zigo | The Debian packages that I take care of (since Cactus in 2011) have long moved to Python 3. | 11:49 |
zigo | In the semi-official stretch-backport repo that I maintain, it's 3.5, and Sid/Buster has 3.7. | 11:50 |
zigo | Here, in my PoC, it's 3.5. | 11:50 |
cgoncalves | ok. asked because seems that server certificate verification has been introduced in 2.7.9 from what I read | 11:50 |
zigo | Ok. | 11:50 |
zigo | Well, it doesn't look like a python problem, since curl has the issue too. | 11:51 |
zigo | cgoncalves: Is there a way to ignore ssl errors with requests? | 11:52 |
zigo | I'd like to at least validate that everything else works ... | 11:52 |
cgoncalves | requests.get(url, verify=False) | 11:53 |
cgoncalves | also: curl --insecure url | 11:54 |
zigo | Yeah, this worked ! :) | 11:54 |
zigo | I guess, what I'm searching, is where to add the verify=False in the octavia's code. | 11:55 |
zigo | There's no requests.get in /usr/lib/python3/dist-packages/octavia/amphorae/drivers/haproxy/rest_api_driver.py | 11:55 |
*** henriqueof has joined #openstack-lbaas | 11:55 | |
zigo | Maybe requests.Session(verify=False) ? | 11:56 |
zigo | Looks like it. Let's try ! :) | 11:57 |
*** yamamoto has joined #openstack-lbaas | 12:11 | |
*** luksky has joined #openstack-lbaas | 12:18 | |
*** yamamoto has quit IRC | 12:50 | |
*** trown|outtypewww is now known as trown | 13:16 | |
*** yamamoto has joined #openstack-lbaas | 13:27 | |
*** yamamoto has quit IRC | 13:30 | |
*** yamamoto has joined #openstack-lbaas | 13:30 | |
*** celebdor1 has joined #openstack-lbaas | 13:31 | |
rm_work | You should not do that | 14:15 |
rm_work | The verification code is specifically required for safety there | 14:15 |
rm_work | If you're getting failures, it is because of a misconfiguration, which you should resolve | 14:16 |
rm_work | Unfortunately it is a bit complicated with the certs, but I promise if you follow the certificate setup guide 100% accurately, it *will* work | 14:17 |
rm_work | zigo: https://docs.openstack.org/octavia/latest/admin/guides/certificates.html#creating-the-certificate-authorities | 14:18 |
zigo | rm_work: I promise you that I followed it by the letter !!! | 14:18 |
zigo | Like, 3 times... | 14:19 |
rm_work | It's also possible you have time sync issues? Did you check the clock on the controller versus the clock on the amphora? | 14:19 |
zigo | Nop. | 14:20 |
zigo | Sync is done correctly. | 14:20 |
rm_work | I know I have seen that exact error before, with the bad padding... | 14:20 |
rm_work | I'm trying to remember exactly what it was | 14:21 |
rm_work | But I do remember that I was able to resolve it | 14:21 |
rm_work | If you disable the verification there, you will cause a severe vulnerability | 14:21 |
rm_work | I personally followed that cert guide when i reviewed the patch adding it to our docs about two months ago, and it absolutely worked. So if you followed it exactly and it's not working, and there are no clock drift issues, then there must be something broken in one of the Debian-specific libs involved, possibly the ssl lib itself | 14:26 |
rm_work | Are you doing your testing on a cloud instance somewhere that you could give me access to? I don't have any clouds at the moment that include Debian images | 14:27 |
rm_work | Ah, I'm out for a while unfortunately, I'll be back on in ~5 hours | 14:30 |
rm_work | But good luck! If you're still having trouble, I can try to help you tomorrow. | 14:31 |
zigo | No worries. | 14:46 |
zigo | Thanks for the help so far. | 14:46 |
zigo | rm_work: I can't give out access, I'm afraid, no. | 14:47 |
zigo | I'd have to setup a specific system for this. | 14:47 |
zigo | This thing where I'm trying to have Octavia is half set in production, others are using it. | 14:47 |
*** ccamposr has quit IRC | 14:59 | |
*** ccamposr has joined #openstack-lbaas | 15:00 | |
*** ccamposr has quit IRC | 15:08 | |
*** ivve has quit IRC | 15:26 | |
mloza | Hello, I'm getting SSLError when I try access the octavia-dashboard in Horizon | 15:49 |
mloza | this is the log file http://sprunge.us/pmzrR0 | 15:49 |
*** luksky has quit IRC | 16:20 | |
*** yamamoto has quit IRC | 16:23 | |
*** yamamoto has joined #openstack-lbaas | 16:26 | |
*** yamamoto has quit IRC | 16:31 | |
*** sapd1 has quit IRC | 16:32 | |
*** psachin has quit IRC | 16:38 | |
*** luksky has joined #openstack-lbaas | 16:51 | |
*** yamamoto has joined #openstack-lbaas | 17:06 | |
*** ivve has joined #openstack-lbaas | 17:08 | |
*** yamamoto has quit IRC | 17:11 | |
*** fnaval has joined #openstack-lbaas | 17:16 | |
*** trown is now known as trown|lunch | 17:31 | |
*** roukoswarf has joined #openstack-lbaas | 17:35 | |
*** ramishra has quit IRC | 17:37 | |
*** irclogbot_1 has joined #openstack-lbaas | 18:11 | |
*** trown|lunch is now known as trown | 18:37 | |
*** ivve has quit IRC | 18:39 | |
*** yboaron_ has quit IRC | 18:42 | |
*** yamamoto has joined #openstack-lbaas | 18:54 | |
*** yamamoto has quit IRC | 18:59 | |
*** celebdor1 has quit IRC | 19:13 | |
*** dmellado has quit IRC | 19:44 | |
*** dmellado has joined #openstack-lbaas | 19:45 | |
*** ivve has joined #openstack-lbaas | 19:47 | |
*** irclogbot_1 has quit IRC | 19:50 | |
*** irclogbot_1 has joined #openstack-lbaas | 20:03 | |
*** salmankhan has quit IRC | 20:41 | |
*** yamamoto has joined #openstack-lbaas | 20:42 | |
*** yamamoto has quit IRC | 20:48 | |
*** abaindur has joined #openstack-lbaas | 20:55 | |
*** abaindur has quit IRC | 20:56 | |
*** abaindur has joined #openstack-lbaas | 20:57 | |
*** salmankhan has joined #openstack-lbaas | 21:09 | |
*** salmankhan has quit IRC | 21:14 | |
*** celebdor1 has joined #openstack-lbaas | 21:20 | |
*** irclogbot_1 has quit IRC | 21:36 | |
*** ivve has quit IRC | 22:16 | |
*** henriqueof has quit IRC | 22:27 | |
*** yamamoto has joined #openstack-lbaas | 22:31 | |
*** yamamoto has quit IRC | 22:35 | |
*** beisner_ has joined #openstack-lbaas | 22:45 | |
*** fnaval has quit IRC | 22:45 | |
*** celebdor1 has quit IRC | 22:47 | |
*** xgerman has quit IRC | 22:52 | |
*** beisner has quit IRC | 22:52 | |
*** beisner_ is now known as beisner | 22:52 | |
rm_work | zigo: yeah np figured you just had some test deployment on a VM you were using for packaging stuff | 22:58 |
rm_work | if it's a real prod deploy... yeah definitely don't skip that verification, lol | 22:58 |
*** roukoswarf has quit IRC | 23:15 | |
*** luksky has quit IRC | 23:15 | |
*** abaindur has quit IRC | 23:20 | |
*** sapd1 has joined #openstack-lbaas | 23:33 | |
*** abaindur has joined #openstack-lbaas | 23:36 | |
*** mloza has quit IRC | 23:42 | |
*** mloza has joined #openstack-lbaas | 23:43 | |
mloza | hello, I have a loadbalancer created with operating status offline but it works as I can connect to the VIP | 23:43 |
mloza | What triggers the operating status to go offline? | 23:44 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!