| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-nova - 2023-03-01 | |||
| 17:58:29 | bauzas | sean-k-mooney: my thought was that PubkeyAcceptedKeyTypes +ssh-rsa was only a temporary workaround until all OpenSSH clients were supposed new enough to drop this compat natively | |
| 17:58:59 | sean-k-mooney | yes but you can disable his on the server side too | |
| 17:59:25 | sean-k-mooney | for gerrit it did not supprot swaping to sha2 until very recently | |
| 18:00:17 | clarkb | bauzas: what that is saying is that ssh-rsa is going away which means rsa + sha1 is going away. There are no plans to remove rsa + sha2 as far as I know | |
| 18:00:44 | bauzas | anyway, for the grenade need, generating a ecdsa key is OK | |
| 18:00:51 | sean-k-mooney | bauzas: i fyou look at https://fedoraproject.org/wiki/Changes/StrongCryptoSettings2 | |
| 18:01:00 | bauzas | clarkb: yeah that's what I found | |
| 18:01:27 | sean-k-mooney | fedor aplanned to drop rsa for key excachange in a future defualt policy that was for f33 | |
| 18:01:35 | sean-k-mooney | i think that came intor affect aroudn f35 | |
| 18:01:52 | bauzas | that's not the RSA keys which are deprecated, that's the SHA1 signature algorithm which is (hence the +o PubkeyAcceptedKeyTypes +ssh-rsa be only a temporary workaround) | |
| 18:02:01 | clarkb | sean-k-mooney: thats only rsa + sha1 | |
| 18:02:17 | sean-k-mooney | key exchange: ECDHE, DHE | |
| 18:02:23 | sean-k-mooney | under FUture | |
| 18:02:50 | clarkb | wut | |
| 18:03:17 | clarkb | oh dhe is rsa iirc | |
| 18:03:28 | sean-k-mooney | anyway it sould liek a this is related to rsa/sha1 and we shoudl be able to fix that by using a ecdsa key which will work for fips too | |
| 18:03:43 | sean-k-mooney | instead of hacking in the old key type which wont | |
| 18:05:33 | clarkb | and if anyone can grok the openssh code better than I a PR to default to rsa + sha2 as teh fallback might generate interesting conversations | |
| 18:05:34 | sean-k-mooney | so we should just replace https://github.com/openstack/grenade/blob/master/projects/70_cinder/resources.sh#L121 | |
| 18:05:46 | sean-k-mooney | with a call to ssh-keygen | |
| 18:05:50 | clarkb | the rfc suggests this happen eventually but as far as I can tell it hasn't happened yet which leads to annoying failures n a lot of cases | |
| 18:06:51 | bauzas | sean-k-mooney: patch is up to change grenade https://review.opendev.org/c/openstack/grenade/+/875940/ | |
| 18:07:09 | sean-k-mooney | cool | |
| 18:07:18 | sean-k-mooney | so ye were just discussing why this is needed | |
| 18:07:24 | bauzas | yeah | |
| 18:07:25 | sean-k-mooney | rahter then trying to find a solution | |
| 18:07:27 | sean-k-mooney | ok | |
| 18:07:29 | dansmith | yeah because I definitely didn't | |
| 18:07:30 | bauzas | well | |
| 18:07:47 | bauzas | we are trying to untangle the oddness of ssh negociation | |
| 18:07:48 | dansmith | and I have a bunch of hacks in my own ssh_config that probably need revisiting now that more of my systems are upgraded | |
| 18:07:56 | bauzas | me too | |
| 18:08:10 | bauzas | this discussion is half-workwise, halp-personalwise | |
| 18:08:14 | sean-k-mooney | ok i got burned by this years ago and have helped other fix it in the past so i mostly just accpet it at this point | |
| 18:08:36 | bauzas | I just shamelessly tuned the signature negociation on the fly with my ssh_config | |
| 18:09:04 | bauzas | as I didn't wanted to generate a new pair of ECDSA or something else keys | |
| 18:09:15 | sean-k-mooney | ya i still have PubkeyAcceptedKeyTypes +ssh-rsa for one site in my config | |
| 18:09:20 | sean-k-mooney | but i think thats offline | |
| 18:09:41 | bauzas | but now if I understand correctly, I could rather continue to use my RSA keys but ask for a different signature | |
| 18:09:58 | sean-k-mooney | i also still have | |
| 18:10:01 | bauzas | using rsa-sha2 | |
| 18:10:01 | sean-k-mooney | host review.opendev.org | |
| 18:10:03 | sean-k-mooney | HostKeyAlgorithms ssh-rsa | |
| 18:10:05 | sean-k-mooney | KexAlgorithms +diffie-hellman-group1-sha1 | |
| 18:10:07 | sean-k-mooney | Ciphers +aes128-cbc | |
| 18:10:12 | sean-k-mooney | for some reason witch i relly dont need | |
| 18:10:46 | clarkb | bauzas: correct. The problem is that some servers don't know how to negotiate that with you like old dropbear and old gerrit | |
| 18:10:49 | sean-k-mooney | thats what i treid when PubkeyAcceptedKeyTypes +ssh-rsa stopped working for gerrit | |
| 18:11:17 | bauzas | clarkb: so the per-host config is still required, gotcha | |
| 18:11:19 | clarkb | the gerrit we have deployed at review.opendev.org should work fine though. ianw and I worked with gerrit and mina sshd upstream and got that all fixed and eventually got it backported to gerrit 3.5 (it was always on 3.6) | |
| 18:11:42 | clarkb | bauzas: if the servers don't know how to negotiate rsa + sha2 | |
| 18:11:48 | clarkb | review.opendev.org should not need this anymore | |
| 18:11:49 | bauzas | yeah got it | |
| 18:12:02 | bauzas | clarkb: how to enable rsa+sha2 globally in the config ? | |
| 18:12:24 | clarkb | bauzas: if your openssh client is new (like on fedora or jammy etc) then thats the only version they will use by default | |
| 18:12:25 | bauzas | because I assume my current OS doesn't have its defaults changed | |
| 18:12:35 | bauzas | oh | |
| 18:12:52 | clarkb | thats why it failed to talk to cirros. jammy will only use rsa + sha2 by default, but cirros dropbear will only do rsa + sha1 | |
| 18:13:02 | clarkb | this mismatch leads to a failure to negotiate between them and no ssh connection | |
| 18:13:04 | sean-k-mooney | i think you would add PubkeyAcceptedKeyTypes rsa-sha2-256 | |
| 18:13:16 | sean-k-mooney | under "HOST *" | |
| 18:13:18 | clarkb | sean-k-mooney: that shouldn't be necessary its automatic | |
| 18:13:27 | clarkb | since all the new lcients only do sha2 | |
| 18:13:28 | bauzas | hmmm | |
| 18:13:43 | sean-k-mooney | ya it should not but if you wanted to force it that would be how | |
| 18:14:08 | bauzas | yeah got it | |
| 18:14:23 | bauzas | this chat is definitely a helper | |
| 18:14:26 | bauzas | clarkb: thanks a lot ! | |
| 18:15:37 | sean-k-mooney | i really would like to just upload a pulic key to keystone and use that to authenticate with osc | |
| 18:23:28 | sean-k-mooney | bauzas: for what its woth its in te seciryt enhancmetns secation fo the 22.04 release notes https://discourse.ubuntu.com/t/jammy-jellyfish-release-notes/24668 | |
| 18:25:45 | sean-k-mooney | it was disabled by defult in openssh https://www.openssh.com/txt/release-8.8 | |
| 18:26:35 | sean-k-mooney | after being deprecated in 8.3 https://lwn.net/Articles/821544/ | |
| 18:42:07 | clarkb | right but they didn't change the fallback key | |
| 18:42:33 | clarkb | so there are layers of problems here. The first is that you can no longer negotiate ssh-rsa with servers that need it. Second is that when that negotiate fails both sides expect ssh-rsa | |
| 18:42:40 | clarkb | which of course fails making the fallback useless | |
| 18:43:23 | clarkb | they should've changed the fallback to rsa-sha-256 so that clients would attempt that after a failed negotiation. This wold still fail on cirros but would've worked with gerrit | |
| 18:52:24 | opendevreview | Merged openstack/nova stable/victoria: Fix the wrong exception used to retry detach API calls https://review.opendev.org/c/openstack/nova/+/866086 | |
| 22:39:08 | opendevreview | Dan Smith proposed openstack/nova master: Add grenade-skip-level-always to nova https://review.opendev.org/c/openstack/nova/+/875773 | |
| 23:59:05 | opendevreview | melanie witt proposed openstack/nova master: testing: Reset affinity support global variables https://review.opendev.org/c/openstack/nova/+/875991 | |
| #openstack-nova - 2023-03-02 | |||
| 08:47:41 | opendevreview | Jorge San Emeterio proposed openstack/nova master: Have host look for CPU controller of cgroupsv2 location. https://review.opendev.org/c/openstack/nova/+/873127 | |
| 09:12:01 | opendevreview | Sylvain Bauza proposed openstack/nova master: Add service version for Antelope https://review.opendev.org/c/openstack/nova/+/874932 | |
| 09:12:02 | opendevreview | Sylvain Bauza proposed openstack/nova master: DNM (yet) Update min support for Bobcat https://review.opendev.org/c/openstack/nova/+/875621 | |
| 09:14:06 | bauzas | gibi: I'd appreciate your review on both https://review.opendev.org/c/openstack/nova/+/874932/5 and https://review.opendev.org/c/openstack/nova/+/875380 | |
| 09:33:37 | kgube | Hi! So, I ran out of time with the implementation of my specs that got accepted for antelope and I want to resubmit them for bobcat. | |
| 09:33:40 | kgube | Should I create a new change for this, or is it possible to reuse the old change, even though it was already merged, to keep previous discussions? | |
| 09:35:46 | gibi | bauzas: on it | |
| 09:37:00 | Uggla | Hi gibi, I need help regarding this comment https://review.opendev.org/c/openstack/nova/+/851029/19/doc/notification_samples/common_payloads/InstancePayload.json#42. As InstancePayload is the "root" of all notifications, I can not change it adding a share as it will impact all notifications tests. Is there a way to do that without copying this file and calling it only on specific cases ? | |
| 09:51:48 | gibi | bauzas: Im OK with the prelude, I left comments in the service version patch | |
| 09:52:08 | gibi | Uggla: looking | |
| 09:52:50 | gibi | Uggla: duplicate the file and use it for the share related notification samples | |
| 09:53:31 | gibi | Uggla: alternativel you could manipulate the sample in the test code but that would be missleading | |
| 09:54:09 | gibi | you are right we probably don't want to add shares for each notification test | |
| 09:54:31 | gibi | still we want to have samples with shares as that is basically our API definition | |
| 09:56:16 | Uggla | @gibi, ok if I duplicate, then it will be documented automatically or should I do something special ? | |
| 10:05:29 | gibi | Uggla: the doc generation happens via the @base.notification_sample decorators | |
| 10:06:21 | gibi | doc generation code is here https://github.com/openstack/nova/blob/master/doc/ext/versioned_notifications.py | |
| 10:07:33 | gibi | so if you create a sample that has shares | |
| 10:07:51 | gibi | then you need to add that to the related class via the @base.notification_sample | |
| 10:07:55 | gibi | decorator | |
| 10:08:31 | gibi | kgube: do you mean resubmitting the spec? | |