Wednesday, 2021-11-10

*** diablo_rojo is now known as Guest547501:59
opendevreviewTakashi Kajinami proposed openstack/governance master: Retire puppet-senlin  https://review.opendev.org/c/openstack/governance/+/81732902:24
ade_leeclarkb, fungi so it seems we can get paramiko to be mostly fips compatible - we just need to allow the md5 notforsecurity parameter03:35
ade_leehttps://github.com/vakwetu/paramiko/commit/b4beb535d7293447f25afd12051dbc45bb1e6ddc03:35
ade_leeI plan to put that up for paramiko tonight - though of course the pull you mentioned would work for us too.03:36
ade_leefingerprints appear to be the one part where they use md5s regardless of which key type they use03:37
ade_leeand with either patch they can be worked around03:37
ade_leethey also use md5 when creating a key while decrypting a encrypted pem file - which is not something that we work around - but thats only if using keys in an encrypted pem file not generated by openssh.03:38
ade_leeso if we run into this, we just need to find the place where the key is generated and replace it.03:39
ade_leebut this brings up the other salient point though - which is, that paramiko implements a bunch of its own crypto - and as far as I understand, that makes it something that will not be fips certified - without someone spending $$ of money and time03:41
ade_leeso while we can get to fips compatibility with paramiko - we can't get to fips compliance03:41
ade_leefor that we need libssh or pylibssh or something else03:42
*** akahat|rover is now known as akahat|lunch08:44
*** ykarel is now known as ykarel|lunch08:51
*** akahat|lunch is now known as akahat|rover09:13
*** ykarel|lunch is now known as ykarel09:57
*** melwitt is now known as Guest550810:12
*** whoami-rajat__ is now known as whoami-rajat14:00
gmannade_lee: I can add it as separate topic too. will you be there to join tomorrow meeting for giving a brief ? 14:10
gmannade_lee: done https://wiki.openstack.org/wiki/Meetings/TechnicalCommittee#Agenda_Suggestions14:16
ade_leegmann, thanks.  I do plan to be there14:29
gmannade_lee: thanks14:30
gmanntc-members: lbragstad : reminder just in case, RBAC discussion continuing in ~20 from now @ https://meet.google.com/uue-adpp-xsm14:41
jungleboyjgmann:  I had a conflict scheduled over that again.  :-(  14:42
jungleboyjNothing on my calendar is sacred.14:42
gmannjungleboyj: ohk, it will be for 1 hr in case you join late, or this is etherpad we will use , feel free to add any query/comment you have https://etherpad.opendev.org/p/policy-popup-yoga-ptg14:43
jungleboyj++14:43
*** ykarel is now known as ykarel|away15:12
lbragstadgmann new meeting link?15:58
gmannlbragstad: https://meet.google.com/agv-hdpy-pmx15:58
gmannjust in case, we are continuing RBAC discussion @ https://meet.google.com/agv-hdpy-pmx15:58
*** akahat|rover is now known as akahat|lunch16:03
*** akahat|lunch is now known as akahat|dinner16:03
*** akahat|dinner is now known as akahat|rover16:52
opendevreviewLance Bragstad proposed openstack/governance master: Rework the yoga secure RBAC community goal  https://review.opendev.org/c/openstack/governance/+/81515821:52
gmannlbragstad: dansmith added meetpad link to continue the rbac biweekly video meeting here https://wiki.openstack.org/wiki/Consistent_and_Secure_Default_Policies_Popup_Team#Meeting22:52
gmannit is Thursday biweekly-even at 18:00 UTC. next meeting I on 25th Nov22:52
gmannlet me know if time is ok. we can change in case of any conflict 22:53
lbragstadnov 25th is a US holiday - just a heads up22:53
gmannohk22:53
gmannwe can continue skip that one and continue from 9th Dec onwards? or you want to schedule on different day so that we meet after 2 weeks from today call?22:55
gmann*we can skip22:55
lbragstadi can meet next week and i'll adjust my schedule to work23:02
lbragstadi can be flexible23:02
lbragstadi'm willing to meet as soon as possible so we can keep making progress23:02
gmannok, so let's move that to biweekly odd then so that we meet next week. and Thursday 16 UTC ok or we change time?23:03
gmannmeans next meetings on 18th Nov, 2nd Dec ....23:04
lbragstadthat time works for me23:05
lbragstadbut again  - i can shuffle my schedule if a better time works for others23:05
gmannthat time is ok for me too. dansmith ?23:06
gmannor any other member interested to join?23:06
gmanntc-members: please vote on 'decoupling goal from release cycle', so that we can migrate RBAC goal with new template https://review.opendev.org/c/openstack/governance/+/81638723:10
dansmithgmann: I haven't done my calculations yet, but I will probably be out for most/all of december, unfortunately :/23:39
dansmithso other than not being around for a long time, that time on thursday works for me :D23:40
gmanndansmith: thanks, sounds good. 23:40
opendevreviewGhanshyam proposed openstack/governance master: Remove office hours in favour of weekly meetings  https://review.opendev.org/c/openstack/governance/+/81749323:45
opendevreviewMerged openstack/governance master: Propose changes to the stable core team  https://review.opendev.org/c/openstack/governance/+/81072123:54

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!