Earlier  
Posted Nick Remark
#openstack-nova - 2020-10-29
17:32:34 gmann we convert it to 200 or new error code then yes
17:32:38 legochen that would be great to clearly explain what’s going on in the error message :) do you think it is worth to do
17:33:01 sean-k-mooney gmann: today it would be a 200 but then later it will fail with no valid host
17:33:08 sean-k-mooney the az filter would block it
17:33:18 sean-k-mooney so it would be a 200 to 400 or 403
17:33:23 sean-k-mooney on server create
17:34:11 sean-k-mooney legochen: gmann lets talk about this in the ptg tomorow if we have time
17:34:55 gmann sean-k-mooney: i see then we need microversion bump hoping server creation happening successfully previously
17:35:21 legochen okay, I’ll attend.
17:35:22 gmann sean-k-mooney: I will be in TC sessions tomorrow but discussing in PTG good idea
17:35:46 sean-k-mooney gmann: it would need a spec in anycase
17:36:12 gmann yeah
17:37:29 sean-k-mooney it would be very similar to https://github.com/openstack/nova/commit/732e202e81142a8ea462a9ebcde9a7226a62a60b
17:37:49 sean-k-mooney except based on domains not project_ids but otherwise identical
17:41:26 sean-k-mooney added right at the end of https://etherpad.opendev.org/p/nova-wallaby-ptg
17:41:44 sean-k-mooney legochen: ^ line 862 currently.
17:41:56 sean-k-mooney legochen: feel free to add addtional detail
17:42:43 legochen okay, will do in the morning, it is about 2:00am in my time :)
17:42:49 legochen ttyl
17:43:23 legochen and thank you!
19:59:53 openstackgerrit Ade Lee proposed openstack/nova master: Replace md5 with oslo version https://review.opendev.org/756434
20:38:58 openstackgerrit Lee Yarwood proposed openstack/nova-specs master: WIP/DNM - Image defined ephemeral storage encryption https://review.opendev.org/752284
20:55:01 openstack bugzilla.redhat.com bug 1884920 in openssh "Cannot ssh into CentOS 6 using ssh key authentication" [Low,Closed: notabug] - Assigned to jjelen
20:55:01 lyarwood PSA for anyone upgrading to F33, you will need https://bugzilla.redhat.com/show_bug.cgi?id=1884920#c2
20:57:56 openstackgerrit Lee Yarwood proposed openstack/nova master: WIP image_meta: Add ephemeral encryption properties https://review.opendev.org/760454
20:57:56 openstackgerrit Lee Yarwood proposed openstack/nova master: WIP Add encryption fields to BlockDeviceMapping https://review.opendev.org/760453
20:57:57 openstackgerrit Lee Yarwood proposed openstack/nova master: WIP scheduler: Add an ephemeral encryption pre filter https://review.opendev.org/760456
20:57:57 openstackgerrit Lee Yarwood proposed openstack/nova master: WIP virt: Add ephemeral encryption flag https://review.opendev.org/760455
22:20:06 sean-k-mooney lyarwood: wait why are rsa keys not accepted
22:21:58 sean-k-mooney oh its just rsa with sha1
22:22:59 sean-k-mooney rsa-sha2-512/256 should be accpeted
22:23:15 openstack bugzilla.redhat.com bug 1881301 in openssh "openssh-clients do not accept PubkeyAcceptedKeyTypes rsa-sha2-512/256" [Unspecified,Post] - Assigned to jjelen
22:23:15 sean-k-mooney https://bugzilla.redhat.com/show_bug.cgi?id=1881301 really does seam like a bug
22:24:39 sean-k-mooney ECDSA isnt nessisarlly more secure then rsa dpening on the key lenght
22:30:41 sean-k-mooney NIST SP800-90 Dual Ec for example should not be used https://en.wikipedia.org/wiki/Dual_EC_DRBG
22:38:39 sean-k-mooney https://en.wikipedia.org/wiki/EdDSA#Ed25519 and https://en.wikipedia.org/wiki/Curve448 are secure and standraised in https://tools.ietf.org/html/rfc7748 i assume fedora has disabled the orginil nist algortiom
#openstack-nova - 2020-10-30
03:05:49 openstackgerrit Shi Yan proposed openstack/nova master: Remove unused bindir config option https://review.opendev.org/760331
03:52:24 openstackgerrit wu.shiming proposed openstack/os-vif master: Remove the unused coding style modules https://review.opendev.org/760491
04:33:49 openstackgerrit Shi Yan proposed openstack/nova master: Remove unused bindir config option https://review.opendev.org/760331
07:30:47 openstackgerrit Xinran WANG proposed openstack/nova-specs master: SRIOV Enabled Nic Support Specification https://review.opendev.org/742785
08:00:33 bauzas good morning Nova
08:10:12 gibi good morning
09:12:31 openstackgerrit Balazs Gibizer proposed openstack/nova master: Prevent starting services with older than N-1 computes https://review.opendev.org/738482
09:17:31 gibi dansmith: updated for W ^^
09:44:51 openstackgerrit Balazs Gibizer proposed openstack/nova master: Add upgrade check about old computes https://review.opendev.org/760520
09:46:00 gibi dansmith: and here is the related upgrade check ^
10:20:56 bauzas lyarwood: interesting, got a publickey perm issue when trying to upload to gerrit after upgrading
10:21:01 bauzas lyarwood: to F33, I mean
10:21:18 bauzas I guess my pubkey was revoked because of the exposure
10:22:27 bauzas oh my fingerprint probably changeed
10:22:47 openstackgerrit Marcin Juszkiewicz proposed openstack/nova master: libvirt: check for AMD SEV only on x86-64 https://review.opendev.org/714425
10:25:06 bauzas debug1: send_pubkey_test: no mutual signature algorithm
10:25:06 bauzas debug1: Offering public key: /home/sbauza/.ssh/id_rsa RSA SHA256:<something> agent
10:25:12 bauzas mmmmm
10:29:02 bauzas looks like it's a known issue https://twitter.com/dmsimard/status/1037354741959991296
10:29:30 bauzas that's going to be fun
10:31:42 bauzas huzzah https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/1790963
10:31:43 openstack Launchpad bug 1790963 in openssh (Fedora) "Unable to connect with openssh 7.8 client and certificates" [Undecided,Confirmed]
10:32:04 bauzas my openssh client is more recent tho (8.4p1)
11:18:58 bauzas hmm, better explanation of the issue https://www.reddit.com/r/Fedora/comments/jh9iyi/f33_openssh_no_mutual_signature_algorithm/
11:19:00 bauzas lyarwood: ^
11:23:41 bauzas okay, got the workaround by setting the ssh-rsa keytype with PubkeyAcceptedKeyTypes
11:25:13 bauzas lyarwood: http://paste.openstack.org/show/799536/
11:27:24 openstack bugzilla.redhat.com bug 1884920 in openssh "Cannot ssh into CentOS 6 using ssh key authentication" [Low,Closed: notabug] - Assigned to jjelen
11:27:24 bauzas hah https://bugzilla.redhat.com/show_bug.cgi?id=1884920
11:29:30 bauzas while the move to remove SHA1 hashes is certainly understandable, I think there is a big user impact that I would have preffered to see better in the relnotes
12:26:24 kashyap stephenfin: Hey
12:27:07 kashyap stephenfin: On documentation: In the past you posted some notes somewhere about how Postgres (or is it some other?) has different kinds of documentation guides?
12:51:20 gibi nova PTG continues in 10 minutes
13:10:48 tosky gibi: in the "next W cycle goals" slot, are you going to talk also about "completing the V cycle goals"? :) (and in case, do I need to be around?)
13:17:04 stephenfin lyarwood: noddy nova-net-related patch here https://review.opendev.org/#/c/760331/
13:17:16 stephenfin if you've a sec
13:58:09 gibi tosky: sorry I missed your comment
13:58:30 gibi tosky: I can circle back to this after the current topic
14:01:47 bauzas suffered a laptop crash, rejoining
14:02:05 tosky gibi: unless you have other topics of course (the list is huuuge); in case, feel free to ping me
14:02:28 gibi tosky: if you can join now then I think we can get to this in about 10 minutes
14:03:43 tosky gibi: oh, jumping in
14:03:48 gibi tosky: ack
14:11:01 kashyap gibi: /me was participating in KVM Forum BoFs and sessions; so been away here
14:11:19 kashyap (Too many things happening at the same time...)
14:11:24 gibi kashyap: ack
14:13:44 gibi kashyap: I think we haven't encountered any topics from you yet
14:14:17 kashyap gibi: The main thing I have is the long-running Secure Boot spec -- for repproval -- I put it on the back burner due to other things
14:14:28 kashyap So it should be fairly uncontroversial
14:15:35 kashyap We have various infra bits in-tree, and in-flight. (Aside: I have another conflict in an hour or so ... if I'm not around, please leave questions for me in the Etherpad)
14:15:40 kashyap (I'll come back and answer)
14:17:24 gibi kashyap: OK. I it good if we bring the secure boot up right after the current break?
14:20:42 kashyap gibi: Current break is how long? I have a hard-break at 16:20 CET
14:21:26 kashyap I can pay more attention back here again at 17:30 CET
14:21:58 gibi we are back at 14:26 UTC
14:22:03 gibi so in like 4 minutes
14:23:08 kashyap Ah, sure; that works
14:23:23 kashyap gibi: But I feel like I'm cheating by moving a topic up
14:23:29 kashyap So feel free to say "no"
14:24:06 kashyap (I don't mean, I literally moved it on the Etherpad :))
14:25:08 gibi kashyap: not cheating, it is dynamic scheduling of the topic based on availability :)
14:25:23 kashyap Hehe, reframing, is it
14:25:26 kashyap Thanks a lot!
14:26:06 gibi I moved your topic up in the etherpd

Earlier   Later