csaikiahey I am trying to authenticate a keystone session for Barbican using the devstack deployment. I am not able to authenticate the session and it always gives me the error " The resource could not be found."18:18
csaikiaCan anyone help me out with it?18:18
csaikiaI am using a Python shell18:19
dave-mccowancsaikia do you have some more details on how you're trying to authenticate a keystone session?18:56
dave-mccowanHappy Monday Barbicaneers!  Reminder, weekly IRC meeting is today in one hour in #openstack-meting-alt18:56
csaikiadave-mccowan I am following Keystone API Version 3 authentication from this doc: and using the environment variables set by devstack.19:28
csaikiadave-mccowan my auth_url from devstack however looks like this: http://1X.1X.5X.1XX/identity19:30
dave-mccowancsaikia are you getting "resource not found" in the barbican logs, or as output from an openstack command you entered?19:38
csaikiaI am getting it as an exception when I am creating a secret object in the python shell and then doing a
csaikiadave-mccowan I am not using openstack command19:44
csaikiadave-mccowan I am using secret = barbican.secrets.create(<content>) and then doing a
dave-mccowancsaikia is returning 404?  or is it identity.V3Password()?19:47
csaikiadave-mccowan is. Also, following the doc link i mentioned, a sess.get_user_id() is also giving me the same exception19:51
csaikiaPlease let me know if I am using the correct auth_url19:51
csaikiaand correct credentials to create a session. I am using the env variables devstack had set19:52
dave-mccowancsaikia i know there has been some changes with keystone url recently.  i think /identity is right.  they removed support for :5000.20:03
dave-mccowancsaikia can you do other keystone commands?  i think the first step, before using barbican client, is to make sure keystone api is working.20:04
csaikia[stack@devstack3 devstack]$ systemctl | grep keystone20:05
csaikia  devstack@keystone.service                                                                 loaded    active running   Devstack devstack@keystone.service20:05
csaikiadave-mccowan it is running fine when I am using all the openstack/nova/cinder commands but not within the shell20:06
csaikiaI can see a set of conf variables in /etc/barbican/barbican.conf file which I also used to create a session, but that fails as well.20:07
dave-mccowancsaikia it sounds like it's not specific to barbican then?  maybe the keystone guys will know better.20:09
csaikiadave-mccowan okay thank you!20:19
dave-mccowancsaikia please come back and let us know what you find out, especially if it does seem to be a problem with barbican or barbican documentation.20:20
rfxnis a HSM absolutely needed w/ barbican?20:24
dave-mccowanrfxn there are configuration options that work without an HSM.  it depends on your security needs.20:28
rfxn@dave-mccowan any good examples that you can help point me too :) ?20:30
dave-mccowansimple_crypto and dogtag_plugin do not use an hsm20:32
dave-mccowanrfxn simple_crypto is generally considered not secure, since secrets are encrypted using a fixed key stored in the barbican.conf file. however, that is the quickest/easiest way to get going.20:34
rfxndave-mccowan, thx, gotcha!20:49
rfxndogtag is out but for now think simple_crypto will be just fine20:49
kfarrdave-mccowan I am seeing that error from the uwsgi branch in barbican-tempest-plugin now21:04
dave-mccowankfarr yea, it looks like glance is failing on a PUT image.21:08
openstackLaunchpad bug 1703856 in Glance "502 Bad gateway error on image-create" [High,Confirmed]21:09
kfarrdave-mccowan oh great, glad you found that bug report.  glad it's not a barbican issue21:12
dave-mccowankfarr the comments in the bug show that we can increase the socket timeout in glance-api.conf as a workaround.  maybe that is something we can do for tempest tests.21:14
kfarrdave-mccowan, ok I will look into that! gotta go for now21:17
-openstackstatus- NOTICE: The Gerrit service on will be offline momentarily at 00:00 utc for a quick reconfiguration-related restart23:32
