Bug 1489514 - Migrate encryption keys from conf key mgr to Barbican
Summary: Migrate encryption keys from conf key mgr to Barbican
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-cinder
Version: 13.0 (Queens)
Hardware: Unspecified
OS: Unspecified
Target Milestone: Upstream M2
: 13.0 (Queens)
Assignee: Alan Bishop
QA Contact: Avi Avraham
Depends On:
Blocks: 1412823
TreeView+ depends on / blocked
Reported: 2017-09-07 15:16 UTC by Eric Harney
Modified: 2018-06-27 13:37 UTC (History)
4 users (show)

Fixed In Version: openstack-cinder-12.0.0-0.20180227162609.7d27804.el7ost python-castellan-0.17.0-0.20180211160720.8e2929b.el7ost
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed: 2018-06-27 13:36:15 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
OpenStack gerrit 511900 0 None master: MERGED cinder-specs: Migrate ConfKeyManager's fixed-key to Barbican (I25f3c841d9f7a678dae649afc1fb2f6702c860ea) 2018-02-28 13:35:01 UTC
OpenStack gerrit 514734 0 None master: MERGED castellan: Support handling legacy all-zeros key ID (Ia5316490201c33e23a4206838d5a4fb3dd00f527) 2018-02-28 13:34:54 UTC
OpenStack gerrit 523225 0 None master: MERGED cinder: Consolidate code that manages encryption keys (I2108e77a8d07dddfb9ec284b3930a197854bd884) 2018-02-28 13:34:44 UTC
OpenStack gerrit 524720 0 None master: MERGED cinder: Migrate fixed_key encryption keys to Barbican (Ic70f45762cf4e426c222415e49b947a328282ca0) 2018-02-28 13:34:37 UTC
OpenStack gerrit 528833 0 None master: MERGED requirements: Bump castellan to 0.16.0 (Ib87ea4b5d07d775b2299dbc262051045e8cf09cc) 2018-02-28 13:34:30 UTC
Red Hat Product Errata RHEA-2018:2086 0 None None None 2018-06-27 13:37:07 UTC

Description Eric Harney 2017-09-07 15:16:24 UTC
Cinder needs to migrate conf key manager keys to Barbican, to handle deployments using volume encryption with conf key manager.

Comment 5 Alan Bishop 2017-12-15 07:59:44 UTC
Patches upstream have been merged.

Comment 6 Eric Harney 2017-12-18 22:25:26 UTC
Need to ensure that the Cinder RPM depends on Castellan >= 0.16.0 for this change.

Comment 7 Alan Bishop 2017-12-19 00:18:20 UTC
(In reply to Eric Harney from comment #6)
> Need to ensure that the Cinder RPM depends on Castellan >= 0.16.0 for this
> change.

Added reference to OpenStack gerrit that addresses this [1].

[1] https://review.openstack.org/528833

Comment 9 Avi Avraham 2018-05-03 11:49:35 UTC
Verified manually 
RPM package version: 
#docker exec -ti openstack-cinder-volume-docker-0 bash -c "rpm -q openstack-cinder" 

The following tests been preformed 

single volume migration
multiple volumes migration 
backups migration

Comment 11 errata-xmlrpc 2018-06-27 13:36:15 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.