Wednesday, 2018-02-07

*** hoangcx has joined #openstack-vpnaas00:57
*** ChanServ sets mode: +o hoangcx00:57
*** huntxu has joined #openstack-vpnaas01:14
hoangcxhuntxu: hi01:30
huntxuhoangcx: morning~01:30
hoangcxhuntxu: thanks for pushed the patch.01:30
hoangcxhuntxu: I have just check bug report https://bugs.launchpad.net/neutron/+bug/174765401:30
openstackLaunchpad bug 1747654 in neutron "VPNaaS: enable sha384/sha512 auth algorithms for *Swan drivers" [Medium,New] - Assigned to Hunt Xu (huntxu)01:30
hoangcxI think it is not need to add REF to the title01:31
huntxuhoangcx: hmmm, I can remove that prefix then01:32
hoangcxhuntxu: I removed it for you already and add important status to it01:32
hoangcxhuntxu: :)01:32
hoangcxhuntxu: let me check the patch and post comments on it01:32
huntxuhoangcx: thx, I will see what I can do with LibreSwan, I applied it locally yesterday and for StrongSwan it worked like a charm01:34
hoangcxhuntxu: perfect. Thanks a lot :)01:35
hoangcxhuntxu: waiting for your info for LibreSwan :)01:35
hoangcxhuntxu: commented you your patch. And I also confirmed with StrongSwan in my local env :)02:10
hoangcxs/commented you/commented on :P02:11
huntxuhoangcx: have already read that, will handle it later02:11
*** openstackgerrit has joined #openstack-vpnaas02:27
openstackgerritzhouguowei proposed openstack/neutron-vpnaas-dashboard master: Modify the language for zh_CN  https://review.openstack.org/54151702:27
*** hoangcx has quit IRC02:33
*** hoangcx has joined #openstack-vpnaas02:34
*** ChanServ sets mode: +o hoangcx02:34
*** yamamoto has joined #openstack-vpnaas02:52
*** yamamoto has quit IRC02:55
*** yamamoto has joined #openstack-vpnaas02:56
*** hoangcx has quit IRC03:31
*** openstackgerrit has quit IRC04:04
*** hoangcx has joined #openstack-vpnaas04:21
*** hoangcx has quit IRC04:29
*** hoangcx has joined #openstack-vpnaas05:46
*** ChanServ sets mode: +o hoangcx05:46
*** openstackgerrit has joined #openstack-vpnaas06:03
openstackgerritzhouguowei proposed openstack/neutron-vpnaas-dashboard master: Change support to supported  https://review.openstack.org/54155106:03
openstackgerritOpenStack Proposal Bot proposed openstack/neutron-vpnaas-dashboard master: Imported Translations from Zanata  https://review.openstack.org/54159007:15
openstackgerritHunt Xu proposed openstack/neutron-vpnaas master: Add IPv6 VPNaaS scenario tests  https://review.openstack.org/53317207:30
openstackgerritHunt Xu proposed openstack/neutron-vpnaas master: Remove ikelifetime in %default section of ipsec.conf templates  https://review.openstack.org/54160408:10
*** hoangcx has quit IRC08:14
*** hoangcx has joined #openstack-vpnaas08:15
*** ChanServ sets mode: +o hoangcx08:15
huntxuhoangcx: now I can confirm that both sha384 and sha512 also work for LibreSwan08:39
hoangcxhuntxu: Perfect. Thanks for your info.08:40
hoangcxhuntxu:  I confirmed with StrongSwan this morning. Need to prepare env for LibreSwan08:40
huntxuhoangcx: it takes me quite some time to make it work in LibreSwan, some handy changes are needed if you use similar env as I08:42
huntxuhoangcx: I use CentOS 7.4 with libreswan-3.20-5.el7_4.x86_64, devstack cloned in this morning08:43
huntxuhoangcx: https://paste.ubuntu.com/26534617/ https://review.openstack.org/#/c/495284/ these two changes are needed for the new libreswan08:46
huntxuhoangcx: and you might need https://review.openstack.org/#/c/535208/ if you use devstack as the neutron-l3 is run by the devstack user08:47
hoangcxhuntxu: OK. Let me try08:49
openstackgerritHunt Xu proposed openstack/neutron-vpnaas master: Remove ikelifetime in %default section of ipsec.conf templates  https://review.openstack.org/54160408:51
hoangcxhuntxu: I confirmed with LibreSwan too. It really needs to apply those change you mentioned.09:11
hoangcxhuntxu: see log here http://paste.openstack.org/show/664667/09:12
hoangcxhuntxu: So, Could you please update the patch with merging those necessary change?09:12
huntxuhoangcx: nice, I'm on the way updating it09:13
openstackgerritHunt Xu proposed openstack/neutron-vpnaas master: Enable sha384/sha512 auth algorithms for *Swan drivers  https://review.openstack.org/54125009:34
hoangcxhuntxu: Don't you need to merge https://paste.ubuntu.com/26534617/ to ^^?09:42
huntxuhoangcx: it is not related, I think this should be merged to https://review.openstack.org/#/c/495284/09:43
hoangcxhuntxu: I'm asking relevant members on the patch to see09:45
huntxuhoangcx: we still have to check it also works for older versions... I would take over 495284 if we don't get a reply from the owner09:46
hoangcxhuntxu: Yeah. The patch is not updated for several months. I think you can take it over :)09:47
huntxuhoangcx: by the way what do you think about adding functional tests for LibreSwan, it seems zuul supports using CentOS as the base system09:53
hoangcxhuntxu: you mean we should add a new job like "neutron-vpnaas-dsvm-functional-lswan" ?09:55
huntxuhoangcx: yes, LibreSwan is taken less care of than it should be IMHO09:58
hoangcxhuntxu: Yes. But I'm not a maintainer of the driver. https://docs.openstack.org/neutron-vpnaas/latest/devref/team.html#driver-maintainers10:00
openstackgerritHunt Xu proposed openstack/neutron-vpnaas master: Enable sha384/sha512 auth algorithms for *Swan drivers  https://review.openstack.org/54125010:00
hoangcxhuntxu: If you are willing, please volunteer to help it be improved10:00
huntxuhoangcx: ok, I can try that10:01
hoangcxhuntxu: I'm not sure if zuul supports using CentOS as the base system10:01
hoangcxhuntxu: awesome :)10:01
huntxuhoangcx: I add functional tests for strongswan to verify sha384 and sha51210:01
hoangcxhuntxu: Please push a patch to add your name to the driver maintainer list10:01
* hoangcx needs to leave office early. See huntxu tomorrow :)10:10
openstackgerritHunt Xu proposed openstack/neutron-vpnaas master: Enable sha384/sha512 auth algorithms for *Swan drivers  https://review.openstack.org/54125010:32
*** yamamoto has quit IRC12:17
*** yamamoto has joined #openstack-vpnaas12:17
*** huntxu has quit IRC12:21
*** yamamoto has quit IRC15:10
*** yamamoto has joined #openstack-vpnaas15:26
*** yamamoto has quit IRC15:30
*** yamamoto has joined #openstack-vpnaas16:50
*** yamamoto has quit IRC16:57
openstackgerritMerged openstack/neutron-vpnaas-dashboard master: Imported Translations from Zanata  https://review.openstack.org/54159023:08

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!