Tuesday, 2018-07-10

alee#startmeeting barbican12:02
openstackMeeting started Tue Jul 10 12:02:04 2018 UTC and is due to finish in 60 minutes.  The chair is alee. Information about MeetBot at http://wiki.debian.org/MeetBot.12:02
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.12:02
*** openstack changes topic to " (Meeting topic: barbican)"12:02
openstackThe meeting name has been set to 'barbican'12:02
alee#topic roll call12:02
*** openstack changes topic to "roll call (Meeting topic: barbican)"12:02
aleeLuzi, mhen hi12:02
Luzihi alee12:03
aleeanyone else here today?12:03
aleethere are a lot of folks that have been on holiday last week and this week12:04
aleeso not much has changed in the last week12:04
aleeI expect things will pick up more with reviews etc. this week.12:04
aleegiven that - I don't really have much of an agenda today other than to remind folks about the submission requuest deadline for the summit for talks12:05
aleeLuzi, mhen  -- anything you guys want to bring up?12:06
Luziah i just wanted to ask, if there was any discussion concerning the allowed bit lengths?12:07
aleeyeah - everyone has been on holiday -- so alas no12:08
aleefolks are coming back this week so I think we'll have discussion later this week12:08
aleeLuzi, either way - we'll definitely get a fix in in Rocky12:09
Luzialee, i just wanted to know, if i missed something :)12:09
Luziwe have another question: should there be a validation of user provided secrets and their meta-data?12:10
aleewhat kind of validation?12:10
Luzi2 possibilities:12:10
Luzi1. a validation of the combination of meta-data12:11
Luzifor example: aes - private key12:11
Luzithat is not a valid combination of meta-data12:12
Luzi2. a check of secrets against their meta-data (maybe through validator plugins?)12:12
aleeif I recall correctly, there is some validation that is in place12:13
aleebut its rather rudimentary12:13
Luzican you point it out for us?12:14
aleeLuzi, yup -- let me check --12:14
aleeLuzi, what I recall though is there is not a lot there -- certainly its an area that could be improved12:15
Luzibesides this: it is a question, if in general barbican should do things like that or not.12:16
aleeLuzi, so looking through the code, it looks like that type of validation is not there12:18
aleeI'm not opposed to adding the validation - and having some kind of validation plugin for folks to add their own is an interesting idea12:19
aleewe just have not have had a request for that yet.12:19
aleeoften there is validation that takes place in the backend plugins12:19
*** velizarx has quit IRC12:20
Luziwell that's a word :) we can investigate this a little more ...12:20
aleefor instance some hsms/ kmip devices will fail to archive something if the metadata is bad12:20
aleebut it would be nice to do some basic validations in barbican before it gets to that point12:21
aleewe do validate that the fields are correct, but not perhaps the content12:21
*** raildo has joined #openstack-barbican12:21
aleeLuzi, if you guys would like to add some validation code, it will certainly be welcome12:21
aleeraildo, hiu12:22
raildoalee, o/12:22
Luzialee, we had thought about a user wanting to upload and use a private key, but accidently providing the public key. so in that case the meta-data and the seret would differ and could not be used for encryption anymore12:22
aleeLuzi, seems like a reasonable use case12:22
Luzialee, that's a word :)12:23
aleeLuzi, need to look - I thought there was some validation for some of that12:23
aleeI 'll poke around for a bit12:24
aleeLuzi, iirc -- the code is in common/validators.py12:25
Luzialee, i take a look into this12:26
aleeLuzi, you can see what validators are in there -- that would be the place to expand on them12:26
aleeanything else?12:26
aleeLuzi, all good?12:27
Luzithat was everything from my side12:27
aleecool thanks all for attending.  hopefully more will happen this week as folks come back12:28
*** openstack changes topic to "Discussion about development of OpenStack Barbican and its client libraries. - Logs: http://eavesdrop.openstack.org/irclogs/%23openstack-barbican/"12:28
openstackMeeting ended Tue Jul 10 12:28:27 2018 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)12:28
openstackMinutes:        http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-07-10-12.02.html12:28
openstackMinutes (text): http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-07-10-12.02.txt12:28
openstackLog:            http://eavesdrop.openstack.org/meetings/barbican/2018/barbican.2018-07-10-12.02.log.html12:28
