Thursday, 2016-07-07

openstackgerritOpenStack Proposal Bot proposed openstack/barbican: Updated from global requirements
openstackgerrithongzhezheng proposed openstack/python-barbicanclient: Fix argument order for assertEqual to (expected, observed)
openstackgerritMax Abidi proposed openstack/python-barbicanclient: Validate key order meta fields.
openstackgerritJiong Liu proposed openstack/barbican: Barbican tests fail because of incomplete test dependencies
openstackgerritBin Zhou proposed openstack/barbican: Correct reraising of exception
*** alee has joined #openstack-barbican13:03
qwebirc82289hi everyone13:13
qwebirc82289I am a university student and I configured barbicab with cinder and nova for Volume encryption. my question is: is it possible to rotate the key(s) used to encrypt the volume? how it works?13:13
qwebirc82289can I set yearly rotation schedule?13:14
openstackgerritJiong Liu proposed openstack/barbican: Move rabbit configurations to oslo_messaging_rabbit section
*** dave-mccowan has joined #openstack-barbican14:59
*** diazjf has joined #openstack-barbican15:03
alee_dave-mccowan, ping15:04
alee_hyakuhei, ping15:04
dave-mccowanalee_ hi ade15:05
alee_dave-mccowan, hey - are you using barbican for encrypted volumes?15:06
dave-mccowanalee_ only as a proof of concept15:06
alee_dave-mccowan, I'm just wondering what the latest config changes needed are for nova and cinder in order to work15:07
alee_dave-mccowan, I remember making a bunch of changes , but was not sure if they were still all needed15:07
dave-mccowanalee_ i haven't tried in a while.  i'm not sure if more is built-in now.15:11
alee_dave-mccowan, specifically I remember doing this --
alee_not sure if all the urls are needed -- well, guess I'll wait for kfarr15:12
dave-mccowanalee_ that's what i have too; i have the same config parameters in a devstack local.conf. i don't know if castellan integration has improved that since last year.15:16
alee_dave-mccowan, thats what I was wondering .. anyways I'll start with that15:17
diazjf1alee_, kfarr, redrobot, added you to some talks. Make sure you add a picture and profile information. Feel free to edit the abstract as well.16:01
alee_diazjf1, thanks - will do16:02
diazjf1redrobot, I will be sending an email to the mailing list about the midcycle tonight or friday morning. Its been hard getting everything setup but I think it will go well :)16:03
diazjf1hyakuhei, see you there man!!16:04
hyakuheiI’m very excited. So diazjf1 I can tell people to book plane tickets?16:05
diazjf1hyakuhei, sure! It'll be in Austin for sure! If worst comes to worst we can do it at a coffee shop lol16:06
hyakuheiWalking around Austin in the middle of August. What could go wrong?16:06
diazjf1hyakuhei, We have rooms booked, not the same room each day unfortunately. I still need to plan some "team-building" events, like visit the bars ;)16:07
jaosorioralee_dinner: ping18:20
openstackgerritPankaj Khandar proposed openstack/barbican: Insecure default PROTOCOL_TLSv1 version in KMIP plugin
alee_dinnerjaosorior, yo19:04
jaosorioralee_dinner: no worries. Pinged ayoung instead. How's stuff there?19:04
alee_dinnersame same .. you back?19:06
aleejaosorior, actually there might be smething you could help debug ..19:07
jaosorioralee: not really. Just needed to ping nkinder about some potential extra PTO in the end of July19:09
jaosoriorI'm actually having some beers in a bar in Mexico :P19:09
aleejaosorior, :)19:09
jaosoriorCheck the keystone endpoint list19:12
jaosoriorMight have https configured there19:12
aleejaosorior, yeah -- this is a puppet-barbican gate test19:15
aleejaosorior, in the test - keystone is set up without https19:15
jaosoriorWhere is barbican trying to use https to access keystone? Do you know if it's from the barbican client side or is it from the server?19:18
jaosoriorCause barbican client will initially access keystone to get the token19:18
aleejaosorior, it seems to be from the server19:19
aleejaosorior, I see it in the apache logs19:19
jaosoriorAnd the configuration is http?19:20
jaosoriorYou know if something might be setting the X-Forwarded-For or X-Forwarded-Proto header?19:21
aleejaosorior, not sure -- looking to see if something is coming from client side ..19:22
jaosoriorIs there a proxy in between?19:24
aleejaosorior, not sure19:25
woodster_the gate doesn't use the keystone middleware for auth?19:27
aleewoodster_, jaosorior so this is the gate job --
aleewoodster_, jaosorior -- and this is how barbican is configured in the paste file:19:30
aleepaste.filter_factory = keystonemiddleware.auth_token:filter_factory19:30
aleejaosorior, still enjoyinhg that beer?19:31
woodster_yeah so it should be using that auth_url there19:33
aleewoodster_, am I missing something there -- identity_url or somesuch?19:33
aleewoodster_, maybe something that for some reason is taking a default which has https?19:34
woodster_well, I don't see any keystone setup stuff here now:
* woodster_ I guess folks need to add that back when using keystone19:37
* woodster_ prefer to see commented out defaults in conf files19:38
jaosoriorI would need my machine to properly debug that19:38
jaosoriorAnd yeah19:38
aleejaosorior, nice19:44
woodster_jaosorior: where is that?19:46
jaosoriorVeracruz, Mexico19:47
jaosoriorGotta go19:53
jaosoriorHave a good one!19:53
aleejaosorior, have fun!19:55
openstackgerritPankaj Khandar proposed openstack/barbican: Insecure default PROTOCOL_TLSv1 version in KMIP plugin
