)]}'
{"specs/liberty/encrypted-and-authenticated-image-support.rst":[{"author":{"_account_id":8119,"name":"Eric Brown","email":"eric_wade_brown@yahoo.com","username":"ericwb"},"change_message_id":"411a1d9dc8898be9b8505f1186c6fc1f05e2587c","unresolved":false,"context_lines":[{"line_number":20,"context_line":"verifying that an image has not been modified after the upload by the user."},{"line_number":21,"context_line":"This feature improves the enterprise-ready posture of OpenStack."},{"line_number":22,"context_line":""},{"line_number":23,"context_line":"Problem description"},{"line_number":24,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":25,"context_line":""},{"line_number":26,"context_line":"There are several use cases that this feature will support:"}],"source_content_type":"text/x-rst","patch_set":2,"id":"7a016987_ee395ea5","line":23,"updated":"2015-05-20 00:09:37.000000000","message":"Could you explain more of the why this is necessary?  What security problem does this solve?  Guess I\u0027m a little unclear.  \n\nI would think if an admin is concerned about the authenticity of images, he/she would not permit standard users to upload them (admin only).  In that case, its a simply policy.json change.","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":136,"name":"Tim Bell","email":"tim.bell@cern.ch","username":"tim-bell"},"change_message_id":"25aacd69eb559b1c944f601a32b20376d1bc59ee","unresolved":false,"context_lines":[{"line_number":20,"context_line":"verifying that an image has not been modified after the upload by the user."},{"line_number":21,"context_line":"This feature improves the enterprise-ready posture of OpenStack."},{"line_number":22,"context_line":""},{"line_number":23,"context_line":"Problem description"},{"line_number":24,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":25,"context_line":""},{"line_number":26,"context_line":"There are several use cases that this feature will support:"}],"source_content_type":"text/x-rst","patch_set":2,"id":"7a016987_131ecc6f","line":23,"in_reply_to":"7a016987_04725949","updated":"2015-05-24 15:52:07.000000000","message":"The new image catalog is also a great example (http://apps.openstack.org/) where I want to know where the original image came from, not only who uploaded it.","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"change_message_id":"c98eac0c0aedf7e553283abb16fb12ad32347779","unresolved":false,"context_lines":[{"line_number":20,"context_line":"verifying that an image has not been modified after the upload by the user."},{"line_number":21,"context_line":"This feature improves the enterprise-ready posture of OpenStack."},{"line_number":22,"context_line":""},{"line_number":23,"context_line":"Problem description"},{"line_number":24,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":25,"context_line":""},{"line_number":26,"context_line":"There are several use cases that this feature will support:"}],"source_content_type":"text/x-rst","patch_set":2,"id":"7a016987_04725949","line":23,"in_reply_to":"7a016987_ee395ea5","updated":"2015-05-20 02:16:42.000000000","message":"There are many more scenarios where this feature is beneficial.\n\nFor example, the end user wants (or requires) a mechanism to verify that the image hasn\u0027t been modified prior to boot. Image signing allows such verification even if there\u0027s a man-in-the-middle attack when the image is transferred to Nova or if Glance itself is untrusted (e.g., a hybrid cloud deployment).","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":13914,"name":"Darren J Moffat","email":"darren.moffat@oracle.com","username":"darrenmoffat"},"change_message_id":"814d976f1515b4fc322b12ff4053f4427195c153","unresolved":false,"context_lines":[{"line_number":26,"context_line":"There are several use cases that this feature will support:"},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"* An image is signed by an End User, using the user\u0027s private key.  The"},{"line_number":29,"context_line":"  user then uploads the image to Glance, along with the signature created, a"},{"line_number":30,"context_line":"  reference to the public key, and the hash method used when creating the"},{"line_number":31,"context_line":"  signature.  Glance uses this information to verify that the signature is"},{"line_number":32,"context_line":"  valid, and notifies the user if the signature is invalid."}],"source_content_type":"text/x-rst","patch_set":2,"id":"7a016987_22055345","line":29,"updated":"2015-05-19 16:07:02.000000000","message":"What about images that can already have an embeded signature ?  How should these integrate with Glance, should it additionally give the embedded signature to glance ?","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"81ed33ef6733025d41ed8fae791ac3149332dfef","unresolved":false,"context_lines":[{"line_number":26,"context_line":"There are several use cases that this feature will support:"},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"* An image is signed by an End User, using the user\u0027s private key.  The"},{"line_number":29,"context_line":"  user then uploads the image to Glance, along with the signature created, a"},{"line_number":30,"context_line":"  reference to the public key, and the hash method used when creating the"},{"line_number":31,"context_line":"  signature.  Glance uses this information to verify that the signature is"},{"line_number":32,"context_line":"  valid, and notifies the user if the signature is invalid."}],"source_content_type":"text/x-rst","patch_set":2,"id":"7a016987_6e168e4d","line":29,"in_reply_to":"7a016987_22055345","updated":"2015-05-20 05:44:17.000000000","message":"In the initial implementation, embedded signature support would not be included, but this could be included as a future improvement.","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},"change_message_id":"711302d0a3829b8f0cb75c6fa0f318736146f11a","unresolved":false,"context_lines":[{"line_number":26,"context_line":"There are several use cases that this feature will support:"},{"line_number":27,"context_line":""},{"line_number":28,"context_line":"* An image is signed by an End User, using the user\u0027s private key.  The"},{"line_number":29,"context_line":"  user then uploads the image to Glance, along with the signature created, a"},{"line_number":30,"context_line":"  reference to the public key, and the hash method used when creating the"},{"line_number":31,"context_line":"  signature.  Glance uses this information to verify that the signature is"},{"line_number":32,"context_line":"  valid, and notifies the user if the signature is invalid."}],"source_content_type":"text/x-rst","patch_set":2,"id":"7a016987_a2011cb1","line":29,"in_reply_to":"7a016987_6e168e4d","updated":"2015-05-22 01:24:30.000000000","message":"+1 for keeping this initially a small effort.","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":13914,"name":"Darren J Moffat","email":"darren.moffat@oracle.com","username":"darrenmoffat"},"change_message_id":"814d976f1515b4fc322b12ff4053f4427195c153","unresolved":false,"context_lines":[{"line_number":27,"context_line":""},{"line_number":28,"context_line":"* An image is signed by an End User, using the user\u0027s private key.  The"},{"line_number":29,"context_line":"  user then uploads the image to Glance, along with the signature created, a"},{"line_number":30,"context_line":"  reference to the public key, and the hash method used when creating the"},{"line_number":31,"context_line":"  signature.  Glance uses this information to verify that the signature is"},{"line_number":32,"context_line":"  valid, and notifies the user if the signature is invalid."},{"line_number":33,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"7a016987_c249dfb8","line":30,"updated":"2015-05-19 16:07:02.000000000","message":"When you say public key here do you really mean a naked public key or do you mean an X.509 (or similar) certificate ?\n\nPlease don\u0027t use naked public keys.","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},"change_message_id":"711302d0a3829b8f0cb75c6fa0f318736146f11a","unresolved":false,"context_lines":[{"line_number":27,"context_line":""},{"line_number":28,"context_line":"* An image is signed by an End User, using the user\u0027s private key.  The"},{"line_number":29,"context_line":"  user then uploads the image to Glance, along with the signature created, a"},{"line_number":30,"context_line":"  reference to the public key, and the hash method used when creating the"},{"line_number":31,"context_line":"  signature.  Glance uses this information to verify that the signature is"},{"line_number":32,"context_line":"  valid, and notifies the user if the signature is invalid."},{"line_number":33,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"7a016987_a218fc1e","line":30,"in_reply_to":"7a016987_2e33f6f7","updated":"2015-05-22 01:24:30.000000000","message":"I believe there was discussion today of possibly allowing the use of PSS too.","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"93e7efc6197cfb0c2370dc6670b21779e7bb9deb","unresolved":false,"context_lines":[{"line_number":27,"context_line":""},{"line_number":28,"context_line":"* An image is signed by an End User, using the user\u0027s private key.  The"},{"line_number":29,"context_line":"  user then uploads the image to Glance, along with the signature created, a"},{"line_number":30,"context_line":"  reference to the public key, and the hash method used when creating the"},{"line_number":31,"context_line":"  signature.  Glance uses this information to verify that the signature is"},{"line_number":32,"context_line":"  valid, and notifies the user if the signature is invalid."},{"line_number":33,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"5afe65bd_77724ee7","line":30,"in_reply_to":"7a016987_a218fc1e","updated":"2015-06-02 16:02:18.000000000","message":"I\u0027ve added a comment that multiple formats will be supported.","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"81ed33ef6733025d41ed8fae791ac3149332dfef","unresolved":false,"context_lines":[{"line_number":27,"context_line":""},{"line_number":28,"context_line":"* An image is signed by an End User, using the user\u0027s private key.  The"},{"line_number":29,"context_line":"  user then uploads the image to Glance, along with the signature created, a"},{"line_number":30,"context_line":"  reference to the public key, and the hash method used when creating the"},{"line_number":31,"context_line":"  signature.  Glance uses this information to verify that the signature is"},{"line_number":32,"context_line":"  valid, and notifies the user if the signature is invalid."},{"line_number":33,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"7a016987_2e33f6f7","line":30,"in_reply_to":"7a016987_c249dfb8","updated":"2015-05-20 05:44:17.000000000","message":"This would not be a naked public key, but one in the format of PKCS#1 or X.509","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},"change_message_id":"73279b50c6bd38b0bd9c248acf397cbe36d6dcda","unresolved":false,"context_lines":[{"line_number":41,"context_line":"  key are also provided.  Glance verifies the signature before storing the"},{"line_number":42,"context_line":"  image, and notifies Nova if the signature verification fails."},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"* A signed image is requested by Nova, and Glance provides the signature,"},{"line_number":45,"context_line":"  reference to the public key, and signature hash method to Nova along with"},{"line_number":46,"context_line":"  the image so that Nova can verify the signature before booting the image."},{"line_number":47,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"1aca2d91_84a2f9ac","line":44,"updated":"2015-05-08 17:23:54.000000000","message":"s/reference/a reference/","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"93e7efc6197cfb0c2370dc6670b21779e7bb9deb","unresolved":false,"context_lines":[{"line_number":41,"context_line":"  key are also provided.  Glance verifies the signature before storing the"},{"line_number":42,"context_line":"  image, and notifies Nova if the signature verification fails."},{"line_number":43,"context_line":""},{"line_number":44,"context_line":"* A signed image is requested by Nova, and Glance provides the signature,"},{"line_number":45,"context_line":"  reference to the public key, and signature hash method to Nova along with"},{"line_number":46,"context_line":"  the image so that Nova can verify the signature before booting the image."},{"line_number":47,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"5afe65bd_cb484030","line":44,"in_reply_to":"1aca2d91_84a2f9ac","updated":"2015-06-02 16:02:18.000000000","message":"Done","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},"change_message_id":"711302d0a3829b8f0cb75c6fa0f318736146f11a","unresolved":false,"context_lines":[{"line_number":58,"context_line":"These include a public key reference, a private key reference (if needed), a"},{"line_number":59,"context_line":"signature hash method, and the signature.  These are provided when the image"},{"line_number":60,"context_line":"is created, and are accessible when the image is uploaded.  Note that this"},{"line_number":61,"context_line":"proposed change will only support image uploads with the glance api v2 (and"},{"line_number":62,"context_line":"will not support using the glance api v1)."},{"line_number":63,"context_line":""},{"line_number":64,"context_line":"The key references will be used to access the keys from Barbican, where the"}],"source_content_type":"text/x-rst","patch_set":2,"id":"7a016987_cf8e6a2d","line":61,"updated":"2015-05-22 01:24:30.000000000","message":"+1","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},"change_message_id":"73279b50c6bd38b0bd9c248acf397cbe36d6dcda","unresolved":false,"context_lines":[{"line_number":236,"context_line":""},{"line_number":237,"context_line":"1. Enable Glance to verify signatures provided by the user during an image"},{"line_number":238,"context_line":"   upload initiated by the user."},{"line_number":239,"context_line":"2. Enable Glance to use its service-leve key-pair to generate a signature when"},{"line_number":240,"context_line":"   requested by the user."},{"line_number":241,"context_line":"3. Enable Glance to verify signatures provided by Nova during an image upload"},{"line_number":242,"context_line":"   of a snapshot taken by Nova."}],"source_content_type":"text/x-rst","patch_set":2,"id":"1aca2d91_44de2140","line":239,"updated":"2015-05-08 17:23:54.000000000","message":"s/leve/level/","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"93e7efc6197cfb0c2370dc6670b21779e7bb9deb","unresolved":false,"context_lines":[{"line_number":236,"context_line":""},{"line_number":237,"context_line":"1. Enable Glance to verify signatures provided by the user during an image"},{"line_number":238,"context_line":"   upload initiated by the user."},{"line_number":239,"context_line":"2. Enable Glance to use its service-leve key-pair to generate a signature when"},{"line_number":240,"context_line":"   requested by the user."},{"line_number":241,"context_line":"3. Enable Glance to verify signatures provided by Nova during an image upload"},{"line_number":242,"context_line":"   of a snapshot taken by Nova."}],"source_content_type":"text/x-rst","patch_set":2,"id":"5afe65bd_4b31f0a1","line":239,"in_reply_to":"1aca2d91_44de2140","updated":"2015-06-02 16:02:18.000000000","message":"Done","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":8119,"name":"Eric Brown","email":"eric_wade_brown@yahoo.com","username":"ericwb"},"change_message_id":"17d6dcd562f35010534cf782c3f845451af95edc","unresolved":false,"context_lines":[{"line_number":245,"context_line":"Dependencies"},{"line_number":246,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":247,"context_line":""},{"line_number":248,"context_line":"The pycrypto library, which will be used for hash creation and signature"},{"line_number":249,"context_line":"verification and creation, is already a part of the global-requirements of"},{"line_number":250,"context_line":"OpenStack and Glance.  However, it is not a part of glance_store, and will"},{"line_number":251,"context_line":"need to be added there."}],"source_content_type":"text/x-rst","patch_set":2,"id":"7a016987_2cde6cdd","line":248,"updated":"2015-05-19 14:59:14.000000000","message":"Can cryptography be used instead?  Many of the other openstack projects are using it now.\n\nhttps://cryptography.io/en/latest/","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"81ed33ef6733025d41ed8fae791ac3149332dfef","unresolved":false,"context_lines":[{"line_number":245,"context_line":"Dependencies"},{"line_number":246,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":247,"context_line":""},{"line_number":248,"context_line":"The pycrypto library, which will be used for hash creation and signature"},{"line_number":249,"context_line":"verification and creation, is already a part of the global-requirements of"},{"line_number":250,"context_line":"OpenStack and Glance.  However, it is not a part of glance_store, and will"},{"line_number":251,"context_line":"need to be added there."}],"source_content_type":"text/x-rst","patch_set":2,"id":"7a016987_6ed1ee22","line":248,"in_reply_to":"7a016987_2cde6cdd","updated":"2015-05-20 05:44:17.000000000","message":"Alternatives to pycrypto can be used, provided that signature verification can occur using a hash of the image (which is already being created in glance), rather than requiring re-hashing the image again as a part of the verification process.","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},"change_message_id":"711302d0a3829b8f0cb75c6fa0f318736146f11a","unresolved":false,"context_lines":[{"line_number":245,"context_line":"Dependencies"},{"line_number":246,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":247,"context_line":""},{"line_number":248,"context_line":"The pycrypto library, which will be used for hash creation and signature"},{"line_number":249,"context_line":"verification and creation, is already a part of the global-requirements of"},{"line_number":250,"context_line":"OpenStack and Glance.  However, it is not a part of glance_store, and will"},{"line_number":251,"context_line":"need to be added there."}],"source_content_type":"text/x-rst","patch_set":2,"id":"7a016987_4fa27a9a","line":248,"in_reply_to":"7a016987_6ed1ee22","updated":"2015-05-22 01:24:30.000000000","message":"It\u0027s also worth noting that I\u0027ve heard rumblings of PyCrypto being deprecated or moved into PyCA (or both).","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":8119,"name":"Eric Brown","email":"eric_wade_brown@yahoo.com","username":"ericwb"},"change_message_id":"17d6dcd562f35010534cf782c3f845451af95edc","unresolved":false,"context_lines":[{"line_number":250,"context_line":"OpenStack and Glance.  However, it is not a part of glance_store, and will"},{"line_number":251,"context_line":"need to be added there."},{"line_number":252,"context_line":""},{"line_number":253,"context_line":"Glance currently does not interact with Barbican.  Since Barbican is needed"},{"line_number":254,"context_line":"to manage the keys, changes will need to be made to allow Glance to create"},{"line_number":255,"context_line":"and retrieve keys using Barbican."},{"line_number":256,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"7a016987_ccf7d857","line":253,"updated":"2015-05-19 14:59:14.000000000","message":"Is Barbican an optional dependency for this feature?  I ask since Barbican is not currently a core project.  Or is Barbican expected to be ready for liberty?","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"change_message_id":"c98eac0c0aedf7e553283abb16fb12ad32347779","unresolved":false,"context_lines":[{"line_number":250,"context_line":"OpenStack and Glance.  However, it is not a part of glance_store, and will"},{"line_number":251,"context_line":"need to be added there."},{"line_number":252,"context_line":""},{"line_number":253,"context_line":"Glance currently does not interact with Barbican.  Since Barbican is needed"},{"line_number":254,"context_line":"to manage the keys, changes will need to be made to allow Glance to create"},{"line_number":255,"context_line":"and retrieve keys using Barbican."},{"line_number":256,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"7a016987_e4b85dca","line":253,"in_reply_to":"7a016987_ccf7d857","updated":"2015-05-20 02:16:42.000000000","message":"Some form of key management is required. With Barbican the key management service for OpenStack, that\u0027s the most likely choice for deployments, but the Castellan interface (http://git.openstack.org/cgit/openstack/castellan) provides a clean abstraction should a deployment want to use a different key manager.","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"93e7efc6197cfb0c2370dc6670b21779e7bb9deb","unresolved":false,"context_lines":[{"line_number":250,"context_line":"OpenStack and Glance.  However, it is not a part of glance_store, and will"},{"line_number":251,"context_line":"need to be added there."},{"line_number":252,"context_line":""},{"line_number":253,"context_line":"Glance currently does not interact with Barbican.  Since Barbican is needed"},{"line_number":254,"context_line":"to manage the keys, changes will need to be made to allow Glance to create"},{"line_number":255,"context_line":"and retrieve keys using Barbican."},{"line_number":256,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"5afe65bd_e13e7db7","line":253,"in_reply_to":"7a016987_cfbc2abd","updated":"2015-06-02 16:02:18.000000000","message":"I have modified this to reference Castellan.","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},"change_message_id":"711302d0a3829b8f0cb75c6fa0f318736146f11a","unresolved":false,"context_lines":[{"line_number":250,"context_line":"OpenStack and Glance.  However, it is not a part of glance_store, and will"},{"line_number":251,"context_line":"need to be added there."},{"line_number":252,"context_line":""},{"line_number":253,"context_line":"Glance currently does not interact with Barbican.  Since Barbican is needed"},{"line_number":254,"context_line":"to manage the keys, changes will need to be made to allow Glance to create"},{"line_number":255,"context_line":"and retrieve keys using Barbican."},{"line_number":256,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"7a016987_cfbc2abd","line":253,"in_reply_to":"7a016987_e4b85dca","updated":"2015-05-22 01:24:30.000000000","message":"Perhaps we should reference Castellan, although the initial implementation will require barbican as a consequence. IMO, even if Barbican is not a \"core\" project yet, it\u0027s a good feature to have, so regardless of Barbican\u0027s status, we should be adding this.","commit_id":"9aca39aef7cfa73639776166375ddf035e55f14a"},{"author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"change_message_id":"62bf29dba82970001898aea2d0a3c59dee3c539e","unresolved":false,"context_lines":[{"line_number":16,"context_line":"* Signing and signature validation of bootable images"},{"line_number":17,"context_line":"* Encrypted images"},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"Deploying both authentication and encryption will protect image integrity by"},{"line_number":20,"context_line":"verifying that an image has not been modified after the upload by the user."},{"line_number":21,"context_line":"This feature improves the enterprise-ready posture of OpenStack."},{"line_number":22,"context_line":""}],"source_content_type":"text/x-rst","patch_set":3,"id":"3afb71cf_aa6ee7fe","line":19,"updated":"2015-06-08 17:33:49.000000000","message":"And confidentiality if the image is encrypted.","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"4ba275c5e8d71f71f02efa5f8fafaf48aeb9a485","unresolved":false,"context_lines":[{"line_number":16,"context_line":"* Signing and signature validation of bootable images"},{"line_number":17,"context_line":"* Encrypted images"},{"line_number":18,"context_line":""},{"line_number":19,"context_line":"Deploying both authentication and encryption will protect image integrity by"},{"line_number":20,"context_line":"verifying that an image has not been modified after the upload by the user."},{"line_number":21,"context_line":"This feature improves the enterprise-ready posture of OpenStack."},{"line_number":22,"context_line":""}],"source_content_type":"text/x-rst","patch_set":3,"id":"3afb71cf_5c459a43","line":19,"in_reply_to":"3afb71cf_aa6ee7fe","updated":"2015-06-10 13:52:39.000000000","message":"Good point.","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"change_message_id":"62bf29dba82970001898aea2d0a3c59dee3c539e","unresolved":false,"context_lines":[{"line_number":54,"context_line":""},{"line_number":55,"context_line":"For the initial implementation, this change will use the property feature of"},{"line_number":56,"context_line":"Glance to store the metadata items needed for image signing and encryption."},{"line_number":57,"context_line":"These include a public key reference, a private key reference (if needed), and"},{"line_number":58,"context_line":"the signature.  These are provided when the image is created, and are accessible"},{"line_number":59,"context_line":"when the image is uploaded.  Note that this proposed change will only support"},{"line_number":60,"context_line":"image uploads with the glance api v2 (and will not support using the glance api"}],"source_content_type":"text/x-rst","patch_set":3,"id":"3afb71cf_05316cec","line":57,"updated":"2015-06-08 17:33:49.000000000","message":"Why is the private key metadata required?","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"4ba275c5e8d71f71f02efa5f8fafaf48aeb9a485","unresolved":false,"context_lines":[{"line_number":54,"context_line":""},{"line_number":55,"context_line":"For the initial implementation, this change will use the property feature of"},{"line_number":56,"context_line":"Glance to store the metadata items needed for image signing and encryption."},{"line_number":57,"context_line":"These include a public key reference, a private key reference (if needed), and"},{"line_number":58,"context_line":"the signature.  These are provided when the image is created, and are accessible"},{"line_number":59,"context_line":"when the image is uploaded.  Note that this proposed change will only support"},{"line_number":60,"context_line":"image uploads with the glance api v2 (and will not support using the glance api"}],"source_content_type":"text/x-rst","patch_set":3,"id":"3afb71cf_dcecea2b","line":57,"in_reply_to":"3afb71cf_05316cec","updated":"2015-06-10 13:52:39.000000000","message":"One iteration of this spec did not have Glance using a service-level key pair, and instead using the user\u0027s private key (if the user requested a signature but didn\u0027t create a signature themselves).  But since that isn\u0027t the case anymore, I\u0027ll remove this item.  Good catch!","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"change_message_id":"62bf29dba82970001898aea2d0a3c59dee3c539e","unresolved":false,"context_lines":[{"line_number":55,"context_line":"For the initial implementation, this change will use the property feature of"},{"line_number":56,"context_line":"Glance to store the metadata items needed for image signing and encryption."},{"line_number":57,"context_line":"These include a public key reference, a private key reference (if needed), and"},{"line_number":58,"context_line":"the signature.  These are provided when the image is created, and are accessible"},{"line_number":59,"context_line":"when the image is uploaded.  Note that this proposed change will only support"},{"line_number":60,"context_line":"image uploads with the glance api v2 (and will not support using the glance api"},{"line_number":61,"context_line":"v1).  Also note that multiple formats for the keys and for the signature will be"}],"source_content_type":"text/x-rst","patch_set":3,"id":"3afb71cf_654dc03d","line":58,"updated":"2015-06-08 17:33:49.000000000","message":"What is the format of the public key? Will it be an actual public key with SubjectPublicKeyInfo or a certificate?\n\nWhat is the format for the signature data? Will it be something like from RFC 2315?","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":8004,"name":"Paul Kehrer","email":"paul.l.kehrer@gmail.com","username":"reaperhulk"},"change_message_id":"b475182de08303deef913249ec030d0d666475fe","unresolved":false,"context_lines":[{"line_number":55,"context_line":"For the initial implementation, this change will use the property feature of"},{"line_number":56,"context_line":"Glance to store the metadata items needed for image signing and encryption."},{"line_number":57,"context_line":"These include a public key reference, a private key reference (if needed), and"},{"line_number":58,"context_line":"the signature.  These are provided when the image is created, and are accessible"},{"line_number":59,"context_line":"when the image is uploaded.  Note that this proposed change will only support"},{"line_number":60,"context_line":"image uploads with the glance api v2 (and will not support using the glance api"},{"line_number":61,"context_line":"v1).  Also note that multiple formats for the keys and for the signature will be"}],"source_content_type":"text/x-rst","patch_set":3,"id":"fa32b979_b71d69bf","line":58,"in_reply_to":"1af86dd1_69d39839","updated":"2015-06-14 19:36:52.000000000","message":"I\u0027d strongly advocate against using PKCS1v1.5 as a padding mechanism. It\u0027s very difficult to get correct (for the underlying libraries, not for Glance) and its presence in new cryptographic specifications is generally considered a code smell. PSS (which, as Nate notes, is specified in PKCS1 v2.0) is a much better choice. Those are both RSA padding constructions -- for elliptic curve based signatures you\u0027re best served with ECDSA (with deterministic k, see RFC 6979) for standard NIST-y curves (e.g. secp256r1).\n\nThere are some new curves coming down the wire (and, of course, curve25519 exists with the ed25519 signature scheme), but support for those is probably not a priority until they get further down the standards tracks (although ed25519 is nice and if you don\u0027t have compliance requirements it can be a very good choice).","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"4ba275c5e8d71f71f02efa5f8fafaf48aeb9a485","unresolved":false,"context_lines":[{"line_number":55,"context_line":"For the initial implementation, this change will use the property feature of"},{"line_number":56,"context_line":"Glance to store the metadata items needed for image signing and encryption."},{"line_number":57,"context_line":"These include a public key reference, a private key reference (if needed), and"},{"line_number":58,"context_line":"the signature.  These are provided when the image is created, and are accessible"},{"line_number":59,"context_line":"when the image is uploaded.  Note that this proposed change will only support"},{"line_number":60,"context_line":"image uploads with the glance api v2 (and will not support using the glance api"},{"line_number":61,"context_line":"v1).  Also note that multiple formats for the keys and for the signature will be"}],"source_content_type":"text/x-rst","patch_set":3,"id":"3afb71cf_f7bd7fd8","line":58,"in_reply_to":"3afb71cf_654dc03d","updated":"2015-06-10 13:52:39.000000000","message":"The format of a public key is of an actual public key with SubjectPublicKeyInfo.  If needed, support could also be added for a certificate.\n\nThe format of the signature data could be either PSS or PKCS1v15.","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"change_message_id":"9bd39f82b7b2c8c0b7dc3596b6e641520f1e0ed8","unresolved":false,"context_lines":[{"line_number":55,"context_line":"For the initial implementation, this change will use the property feature of"},{"line_number":56,"context_line":"Glance to store the metadata items needed for image signing and encryption."},{"line_number":57,"context_line":"These include a public key reference, a private key reference (if needed), and"},{"line_number":58,"context_line":"the signature.  These are provided when the image is created, and are accessible"},{"line_number":59,"context_line":"when the image is uploaded.  Note that this proposed change will only support"},{"line_number":60,"context_line":"image uploads with the glance api v2 (and will not support using the glance api"},{"line_number":61,"context_line":"v1).  Also note that multiple formats for the keys and for the signature will be"}],"source_content_type":"text/x-rst","patch_set":3,"id":"1af86dd1_69d39839","line":58,"in_reply_to":"3afb71cf_f7bd7fd8","updated":"2015-06-12 19:51:08.000000000","message":"If we add support for certificate then I think that would give us some extra trust. Then we know the key pair has been certified. Otherwise anyone could generate a key pair and use a public key.\n\nI\u0027m not as familiar with those. A quick Google search showed they both seem related to PKCS#1. That would limit us to RSA keys. I\u0027ll look around to see what is out there.","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"b68e66912f13e976c03d4cd26d8a5e0e63f60d51","unresolved":false,"context_lines":[{"line_number":55,"context_line":"For the initial implementation, this change will use the property feature of"},{"line_number":56,"context_line":"Glance to store the metadata items needed for image signing and encryption."},{"line_number":57,"context_line":"These include a public key reference, a private key reference (if needed), and"},{"line_number":58,"context_line":"the signature.  These are provided when the image is created, and are accessible"},{"line_number":59,"context_line":"when the image is uploaded.  Note that this proposed change will only support"},{"line_number":60,"context_line":"image uploads with the glance api v2 (and will not support using the glance api"},{"line_number":61,"context_line":"v1).  Also note that multiple formats for the keys and for the signature will be"}],"source_content_type":"text/x-rst","patch_set":3,"id":"fa32b979_72392441","line":58,"in_reply_to":"fa32b979_b71d69bf","updated":"2015-06-19 22:38:09.000000000","message":"I think adding support for certificates will be a good future addition, but that it doesn\u0027t need to be part of this initial implementation.\n\nIt\u0027s great to get a cryptographer\u0027s perspective on different signature padding mechanisms.  I\u0027ll mention PSS in next update of the spec, and avoid mention of PKCS1v15.  The format will be configurable, but ideally we\u0027ll only include support for options that are still considered secure.","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":13914,"name":"Darren J Moffat","email":"darren.moffat@oracle.com","username":"darrenmoffat"},"change_message_id":"77b362a15c2d90d5888e04c467e7394fe22240a9","unresolved":false,"context_lines":[{"line_number":69,"context_line":""},{"line_number":70,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":71,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"},{"line_number":72,"context_line":"by default is MD5) will be used for the signature verification."},{"line_number":73,"context_line":""},{"line_number":74,"context_line":"Since the checksum is computed in glance_store (when the image data is"},{"line_number":75,"context_line":"uploaded), it makes sense for the signature verification to be computed in"}],"source_content_type":"text/x-rst","patch_set":3,"id":"5afe65bd_4579a62e","line":72,"updated":"2015-06-03 15:29:58.000000000","message":"For signatures then they shouldn\u0027t be based of an MD5 hash, MD5 is really too weak now, this is a good time to change this.   This should be SHA256 hash or better.","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},"change_message_id":"5781a1d91fac41a7908b087ed9af1fed06a9c0d9","unresolved":false,"context_lines":[{"line_number":69,"context_line":""},{"line_number":70,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":71,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"},{"line_number":72,"context_line":"by default is MD5) will be used for the signature verification."},{"line_number":73,"context_line":""},{"line_number":74,"context_line":"Since the checksum is computed in glance_store (when the image data is"},{"line_number":75,"context_line":"uploaded), it makes sense for the signature verification to be computed in"}],"source_content_type":"text/x-rst","patch_set":3,"id":"3afb71cf_6eccc735","line":72,"updated":"2015-06-05 14:58:31.000000000","message":"I agree with Brianna. Allowing the image checksum algorithm to be configurable is complimentary to this work but not a prerequisite. We\u0027ve been adding the ability configure these algorithms slowly (e.g., I9236cc85f4e9881ac1aa35d69bc6761a59c1b6c8) and choosing backwards compatible defaults by default with the intent of changing those defaults in future releases.","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"b68e66912f13e976c03d4cd26d8a5e0e63f60d51","unresolved":false,"context_lines":[{"line_number":69,"context_line":""},{"line_number":70,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":71,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"},{"line_number":72,"context_line":"by default is MD5) will be used for the signature verification."},{"line_number":73,"context_line":""},{"line_number":74,"context_line":"Since the checksum is computed in glance_store (when the image data is"},{"line_number":75,"context_line":"uploaded), it makes sense for the signature verification to be computed in"}],"source_content_type":"text/x-rst","patch_set":3,"id":"fa32b979_3292bc58","line":72,"in_reply_to":"1af86dd1_89c13431","updated":"2015-06-19 22:38:09.000000000","message":"Correct, though the configurability will be done with a different spec/blueprint (see https://review.openstack.org/191542).","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"change_message_id":"62bf29dba82970001898aea2d0a3c59dee3c539e","unresolved":false,"context_lines":[{"line_number":69,"context_line":""},{"line_number":70,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":71,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"},{"line_number":72,"context_line":"by default is MD5) will be used for the signature verification."},{"line_number":73,"context_line":""},{"line_number":74,"context_line":"Since the checksum is computed in glance_store (when the image data is"},{"line_number":75,"context_line":"uploaded), it makes sense for the signature verification to be computed in"}],"source_content_type":"text/x-rst","patch_set":3,"id":"3afb71cf_e5d41021","line":72,"in_reply_to":"3afb71cf_6eccc735","updated":"2015-06-08 17:33:49.000000000","message":"Does this apply to all use cases or only the ones where Glance generates the hash and signature? This seems like only for use case 2 and not 1. The use cases I pulled for the top description.","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"change_message_id":"9bd39f82b7b2c8c0b7dc3596b6e641520f1e0ed8","unresolved":false,"context_lines":[{"line_number":69,"context_line":""},{"line_number":70,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":71,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"},{"line_number":72,"context_line":"by default is MD5) will be used for the signature verification."},{"line_number":73,"context_line":""},{"line_number":74,"context_line":"Since the checksum is computed in glance_store (when the image data is"},{"line_number":75,"context_line":"uploaded), it makes sense for the signature verification to be computed in"}],"source_content_type":"text/x-rst","patch_set":3,"id":"1af86dd1_89c13431","line":72,"in_reply_to":"3afb71cf_9c40b208","updated":"2015-06-12 19:51:08.000000000","message":"So first cut is that user can only use MD5 hash, and then later we make it configurable to allow a specified hash algorithm from some sort of enumeration we create?","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"4ba275c5e8d71f71f02efa5f8fafaf48aeb9a485","unresolved":false,"context_lines":[{"line_number":69,"context_line":""},{"line_number":70,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":71,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"},{"line_number":72,"context_line":"by default is MD5) will be used for the signature verification."},{"line_number":73,"context_line":""},{"line_number":74,"context_line":"Since the checksum is computed in glance_store (when the image data is"},{"line_number":75,"context_line":"uploaded), it makes sense for the signature verification to be computed in"}],"source_content_type":"text/x-rst","patch_set":3,"id":"3afb71cf_9c40b208","line":72,"in_reply_to":"3afb71cf_e5d41021","updated":"2015-06-10 13:52:39.000000000","message":"This would apply to all use cases, since the hash is used not only when creating the signature but also when verifying the signature.","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"1b6161c0e46110eb79564fc7775d43dc7f738923","unresolved":false,"context_lines":[{"line_number":69,"context_line":""},{"line_number":70,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":71,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"},{"line_number":72,"context_line":"by default is MD5) will be used for the signature verification."},{"line_number":73,"context_line":""},{"line_number":74,"context_line":"Since the checksum is computed in glance_store (when the image data is"},{"line_number":75,"context_line":"uploaded), it makes sense for the signature verification to be computed in"}],"source_content_type":"text/x-rst","patch_set":3,"id":"5afe65bd_a513ba65","line":72,"in_reply_to":"5afe65bd_4579a62e","updated":"2015-06-03 15:36:56.000000000","message":"I agree that MD5 is too weak.  We plan to add the ability to configure which type of hash is used for the checksum (and by extension, this signature) as a separate blueprint/spec that is related to this but not dependent.\n\nIn the interest of having a straightforward initial implementation, I think it is best to leave as MD5 now (which is what Glance currently uses), with the intention of changing it as a part of a separate patch set in the near future.","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"change_message_id":"62bf29dba82970001898aea2d0a3c59dee3c539e","unresolved":false,"context_lines":[{"line_number":74,"context_line":"Since the checksum is computed in glance_store (when the image data is"},{"line_number":75,"context_line":"uploaded), it makes sense for the signature verification to be computed in"},{"line_number":76,"context_line":"glance_store.  glance_store also has the mechanism to abort an image upload"},{"line_number":77,"context_line":"if a failure occurs."},{"line_number":78,"context_line":""},{"line_number":79,"context_line":"In order for the signature to be verified by the store backend, the backend"},{"line_number":80,"context_line":"must have access to the public key and the signature.  The Glance frontend"}],"source_content_type":"text/x-rst","patch_set":3,"id":"3afb71cf_8539dc43","line":77,"updated":"2015-06-08 17:33:49.000000000","message":"If glance is provided with a digest would it still compute a checksum or would it reuse the digest provided by the caller?","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},"change_message_id":"69c57ffa5c2546be3412d5a12d8a22ae88d2fe4a","unresolved":false,"context_lines":[{"line_number":74,"context_line":"Since the checksum is computed in glance_store (when the image data is"},{"line_number":75,"context_line":"uploaded), it makes sense for the signature verification to be computed in"},{"line_number":76,"context_line":"glance_store.  glance_store also has the mechanism to abort an image upload"},{"line_number":77,"context_line":"if a failure occurs."},{"line_number":78,"context_line":""},{"line_number":79,"context_line":"In order for the signature to be verified by the store backend, the backend"},{"line_number":80,"context_line":"must have access to the public key and the signature.  The Glance frontend"}],"source_content_type":"text/x-rst","patch_set":3,"id":"fa32b979_bddb314e","line":77,"in_reply_to":"1af86dd1_692b98ec","updated":"2015-06-18 22:08:30.000000000","message":"The \u0027checksum hash\u0027 is the same thing as the image hash in Glance.  I think Image hash is a more accurate term for this application, but the term checksum is still sometimes used.","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"4ba275c5e8d71f71f02efa5f8fafaf48aeb9a485","unresolved":false,"context_lines":[{"line_number":74,"context_line":"Since the checksum is computed in glance_store (when the image data is"},{"line_number":75,"context_line":"uploaded), it makes sense for the signature verification to be computed in"},{"line_number":76,"context_line":"glance_store.  glance_store also has the mechanism to abort an image upload"},{"line_number":77,"context_line":"if a failure occurs."},{"line_number":78,"context_line":""},{"line_number":79,"context_line":"In order for the signature to be verified by the store backend, the backend"},{"line_number":80,"context_line":"must have access to the public key and the signature.  The Glance frontend"}],"source_content_type":"text/x-rst","patch_set":3,"id":"3afb71cf_fc70c641","line":77,"in_reply_to":"3afb71cf_8539dc43","updated":"2015-06-10 13:52:39.000000000","message":"Glance will always compute the checksum hash.  The user cannot provide the checksum hash.","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"change_message_id":"9bd39f82b7b2c8c0b7dc3596b6e641520f1e0ed8","unresolved":false,"context_lines":[{"line_number":74,"context_line":"Since the checksum is computed in glance_store (when the image data is"},{"line_number":75,"context_line":"uploaded), it makes sense for the signature verification to be computed in"},{"line_number":76,"context_line":"glance_store.  glance_store also has the mechanism to abort an image upload"},{"line_number":77,"context_line":"if a failure occurs."},{"line_number":78,"context_line":""},{"line_number":79,"context_line":"In order for the signature to be verified by the store backend, the backend"},{"line_number":80,"context_line":"must have access to the public key and the signature.  The Glance frontend"}],"source_content_type":"text/x-rst","patch_set":3,"id":"1af86dd1_692b98ec","line":77,"in_reply_to":"3afb71cf_fc70c641","updated":"2015-06-12 19:51:08.000000000","message":"Is the checksum hash going to be different from the image hash? I expect them to be the same. What if they are different?","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":8004,"name":"Paul Kehrer","email":"paul.l.kehrer@gmail.com","username":"reaperhulk"},"change_message_id":"b475182de08303deef913249ec030d0d666475fe","unresolved":false,"context_lines":[{"line_number":241,"context_line":"Dependencies"},{"line_number":242,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":243,"context_line":""},{"line_number":244,"context_line":"The pycrypto library, which will be used for hash creation and signature"},{"line_number":245,"context_line":"verification and creation, is already a part of the global-requirements of"},{"line_number":246,"context_line":"OpenStack and Glance.  However, it is not a part of glance_store, and will"},{"line_number":247,"context_line":"need to be added there."}],"source_content_type":"text/x-rst","patch_set":3,"id":"fa32b979_5795fde1","line":244,"updated":"2015-06-14 19:36:52.000000000","message":"(Full disclosure, I am a developer on https://github.com/pyca/cryptography)\n\nPyCrypto is a mostly moribund project that uses custom written C with somewhat limited testing. There is a loose plan to make pycrypto depend on pyca/cryptography (https://lists.dlitz.net/pipermail/pycrypto/2014q3/000814.html) in the future, although there\u0027s no timeline on that action.\n\ncryptography is part of global requirements and used quite a bit within openstack. It provides both ECDSA and RSA signature primitives via OpenSSL bindings. If you need to independently hash and then sign the hash cryptography can\u0027t currently do that, although you can help us define the API for that here: https://github.com/pyca/cryptography/issues/1648","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"b68e66912f13e976c03d4cd26d8a5e0e63f60d51","unresolved":false,"context_lines":[{"line_number":241,"context_line":"Dependencies"},{"line_number":242,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":243,"context_line":""},{"line_number":244,"context_line":"The pycrypto library, which will be used for hash creation and signature"},{"line_number":245,"context_line":"verification and creation, is already a part of the global-requirements of"},{"line_number":246,"context_line":"OpenStack and Glance.  However, it is not a part of glance_store, and will"},{"line_number":247,"context_line":"need to be added there."}],"source_content_type":"text/x-rst","patch_set":3,"id":"fa32b979_725b642f","line":244,"in_reply_to":"fa32b979_5795fde1","updated":"2015-06-19 22:38:09.000000000","message":"With all the feedback I\u0027ve received about pycrypto vs. cryptography, I\u0027ve decided to use cryptography instead.  This will be mentioned in the upcoming spec.  Thank you for the suggestion!","commit_id":"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"},{"author":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"change_message_id":"8c9f0cc7c7aacfa729c76eb06f8057b87fb4d2a7","unresolved":false,"context_lines":[{"line_number":316,"context_line":""},{"line_number":317,"context_line":"[1] http://goo.gl/Y3u3lK"},{"line_number":318,"context_line":"[2] https://review.openstack.org/191542"},{"line_number":319,"context_line":"[2] http://git.openstack.org/cgit/openstack/castellan"}],"source_content_type":"text/x-rst","patch_set":4,"id":"fa32b979_6a780b2c","line":319,"updated":"2015-06-22 22:33:50.000000000","message":"nit: 2 -\u003e 3","commit_id":"c1fe7ca32aaadba74dfea65e9562ad01342435d9"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"45766c441acd5fd0e25fb6209bae581d2a893a33","unresolved":false,"context_lines":[{"line_number":316,"context_line":""},{"line_number":317,"context_line":"[1] http://goo.gl/Y3u3lK"},{"line_number":318,"context_line":"[2] https://review.openstack.org/191542"},{"line_number":319,"context_line":"[2] http://git.openstack.org/cgit/openstack/castellan"}],"source_content_type":"text/x-rst","patch_set":4,"id":"fa32b979_4a40a7a5","line":319,"in_reply_to":"fa32b979_6a780b2c","updated":"2015-06-22 22:38:40.000000000","message":"Thank you for the catch and fix, Joel!","commit_id":"c1fe7ca32aaadba74dfea65e9562ad01342435d9"},{"author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"change_message_id":"d076666853756a5293883b4aed4fe4edf605c231","unresolved":false,"context_lines":[{"line_number":72,"context_line":"when the image is created, and are accessible when the image is uploaded.  Note"},{"line_number":73,"context_line":"that this proposed change will only support image uploads with the glance api v2"},{"line_number":74,"context_line":"(and will not support using the glance api v1).  Also note that multiple formats"},{"line_number":75,"context_line":"for the key (such as SubjectPublicKeyInfo) and for the signature (such as PSS)"},{"line_number":76,"context_line":"will be supported."},{"line_number":77,"context_line":""},{"line_number":78,"context_line":"The key references will be used to access the keys from a key manager, where the"}],"source_content_type":"text/x-rst","patch_set":5,"id":"ba3cc151_e396c593","line":75,"updated":"2015-06-29 19:48:54.000000000","message":"What about using the signed-data content type as defined in RFC 5652 for the signature object? See section five for more details. This would contain the public key reference and the signature. The structure will define the hashing algorithm and public key information in it as well. This should give us lots of flexibility for future formats.","commit_id":"730d2cf196b47ca4ab4a12c4766649f8836e591c"},{"author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"change_message_id":"3792bb9eea7df3b28e4cb10d8888e4725ea32949","unresolved":false,"context_lines":[{"line_number":72,"context_line":"when the image is created, and are accessible when the image is uploaded.  Note"},{"line_number":73,"context_line":"that this proposed change will only support image uploads with the glance api v2"},{"line_number":74,"context_line":"(and will not support using the glance api v1).  Also note that multiple formats"},{"line_number":75,"context_line":"for the key (such as SubjectPublicKeyInfo) and for the signature (such as PSS)"},{"line_number":76,"context_line":"will be supported."},{"line_number":77,"context_line":""},{"line_number":78,"context_line":"The key references will be used to access the keys from a key manager, where the"}],"source_content_type":"text/x-rst","patch_set":5,"id":"3a50d1a3_afe2852d","line":75,"in_reply_to":"3a50d1a3_69424e12","updated":"2015-07-21 21:57:29.000000000","message":"I think if you do not use the CMS format then need to specify the signature structure as a string. The caller will need this to know how to interpret the signature blob. The nice part about CMS is that it encapsulates that information. I\u0027m not sure what to put for some of these strings. Perhaps hash algorithm and asymmetric algorithm are enough.","commit_id":"730d2cf196b47ca4ab4a12c4766649f8836e591c"},{"author":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"change_message_id":"5f58920c9b0c2de2acbb9d23195d65cbfe7b211a","unresolved":false,"context_lines":[{"line_number":72,"context_line":"when the image is created, and are accessible when the image is uploaded.  Note"},{"line_number":73,"context_line":"that this proposed change will only support image uploads with the glance api v2"},{"line_number":74,"context_line":"(and will not support using the glance api v1).  Also note that multiple formats"},{"line_number":75,"context_line":"for the key (such as SubjectPublicKeyInfo) and for the signature (such as PSS)"},{"line_number":76,"context_line":"will be supported."},{"line_number":77,"context_line":""},{"line_number":78,"context_line":"The key references will be used to access the keys from a key manager, where the"}],"source_content_type":"text/x-rst","patch_set":5,"id":"3a50d1a3_69424e12","line":75,"in_reply_to":"ba3cc151_7bed98ee","updated":"2015-07-21 15:51:40.000000000","message":"I concur with Nate\u0027s comments, but I think this decision can be deferred until implementation. But if the cryptographic message syntax (CMS) format isn\u0027t followed initially, then there should be an easy migration path to it.","commit_id":"730d2cf196b47ca4ab4a12c4766649f8836e591c"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"846018541d75ed2940d39df11f32c477dbadde8c","unresolved":false,"context_lines":[{"line_number":72,"context_line":"when the image is created, and are accessible when the image is uploaded.  Note"},{"line_number":73,"context_line":"that this proposed change will only support image uploads with the glance api v2"},{"line_number":74,"context_line":"(and will not support using the glance api v1).  Also note that multiple formats"},{"line_number":75,"context_line":"for the key (such as SubjectPublicKeyInfo) and for the signature (such as PSS)"},{"line_number":76,"context_line":"will be supported."},{"line_number":77,"context_line":""},{"line_number":78,"context_line":"The key references will be used to access the keys from a key manager, where the"}],"source_content_type":"text/x-rst","patch_set":5,"id":"ba3cc151_7bed98ee","line":75,"in_reply_to":"ba3cc151_e396c593","updated":"2015-07-06 17:08:38.000000000","message":"While it looks like a signed-data content type could be useful, I can\u0027t seem to find any good python support for it (do you know of any?), and I would hesitate to create something from scratch.  Also, it looks like the size could vary widely, and there is potential for multiple signatures to be included at once, which could potentially be confusing (what happens if one signature verifies properly but not another?).","commit_id":"730d2cf196b47ca4ab4a12c4766649f8836e591c"},{"author":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"change_message_id":"5f58920c9b0c2de2acbb9d23195d65cbfe7b211a","unresolved":false,"context_lines":[{"line_number":152,"context_line":"be improved upon as needed."},{"line_number":153,"context_line":""},{"line_number":154,"context_line":"An alternative to requiring the user to provide the signature separate from the"},{"line_number":155,"context_line":"image is to support signatures that already have an embedded signature."},{"line_number":156,"context_line":"Although this could be included as a future improvement, the initial"},{"line_number":157,"context_line":"implementation will not provide embedded signature support, since it is"},{"line_number":158,"context_line":"advantageous to keep the initial effort focused and small."}],"source_content_type":"text/x-rst","patch_set":5,"id":"3a50d1a3_09c5ca59","line":155,"updated":"2015-07-21 15:51:40.000000000","message":"typo: signatures -\u003e images?","commit_id":"730d2cf196b47ca4ab4a12c4766649f8836e591c"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"b78134cd7e903e5c0884ec5f1b53b6632301705f","unresolved":false,"context_lines":[{"line_number":152,"context_line":"be improved upon as needed."},{"line_number":153,"context_line":""},{"line_number":154,"context_line":"An alternative to requiring the user to provide the signature separate from the"},{"line_number":155,"context_line":"image is to support signatures that already have an embedded signature."},{"line_number":156,"context_line":"Although this could be included as a future improvement, the initial"},{"line_number":157,"context_line":"implementation will not provide embedded signature support, since it is"},{"line_number":158,"context_line":"advantageous to keep the initial effort focused and small."}],"source_content_type":"text/x-rst","patch_set":5,"id":"3a50d1a3_2a1d150f","line":155,"in_reply_to":"3a50d1a3_09c5ca59","updated":"2015-07-29 03:58:04.000000000","message":"Correct, good catch.","commit_id":"730d2cf196b47ca4ab4a12c4766649f8836e591c"},{"author":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"change_message_id":"0d7c46b843ea20678f258e19a5c5201239209579","unresolved":false,"context_lines":[{"line_number":32,"context_line":""},{"line_number":33,"context_line":"There are several use cases that this feature will support:"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"* An image is signed by an End User, using the user\u0027s private key.  The   user"},{"line_number":36,"context_line":"  then uploads the image to Glance, along with the signature created and a"},{"line_number":37,"context_line":"  reference to the user\u0027s public key certificate.  Glance uses this"},{"line_number":38,"context_line":"  information to verify that the   signature is valid, and notifies the user"}],"source_content_type":"text/x-rst","patch_set":6,"id":"1a4dcd0f_51255706","line":35,"updated":"2015-08-06 20:26:32.000000000","message":"nit: extra space before \"user\"","commit_id":"88036d33cd5e5c4fae24aeb5e6fac5393a2523fe"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"b747634c05c79fe224e9c04e5affe56119bad0b6","unresolved":false,"context_lines":[{"line_number":32,"context_line":""},{"line_number":33,"context_line":"There are several use cases that this feature will support:"},{"line_number":34,"context_line":""},{"line_number":35,"context_line":"* An image is signed by an End User, using the user\u0027s private key.  The   user"},{"line_number":36,"context_line":"  then uploads the image to Glance, along with the signature created and a"},{"line_number":37,"context_line":"  reference to the user\u0027s public key certificate.  Glance uses this"},{"line_number":38,"context_line":"  information to verify that the   signature is valid, and notifies the user"}],"source_content_type":"text/x-rst","patch_set":6,"id":"1a4dcd0f_db2981e7","line":35,"in_reply_to":"1a4dcd0f_51255706","updated":"2015-08-06 22:03:27.000000000","message":"Done","commit_id":"88036d33cd5e5c4fae24aeb5e6fac5393a2523fe"},{"author":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"change_message_id":"0d7c46b843ea20678f258e19a5c5201239209579","unresolved":false,"context_lines":[{"line_number":35,"context_line":"* An image is signed by an End User, using the user\u0027s private key.  The   user"},{"line_number":36,"context_line":"  then uploads the image to Glance, along with the signature created and a"},{"line_number":37,"context_line":"  reference to the user\u0027s public key certificate.  Glance uses this"},{"line_number":38,"context_line":"  information to verify that the   signature is valid, and notifies the user"},{"line_number":39,"context_line":"  if the signature is invalid."},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"* An image is uploaded by an End User, along with an indication that it should"}],"source_content_type":"text/x-rst","patch_set":6,"id":"1a4dcd0f_516c7734","line":38,"updated":"2015-08-06 20:26:32.000000000","message":"nit: extra space before \"signature\"","commit_id":"88036d33cd5e5c4fae24aeb5e6fac5393a2523fe"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"b747634c05c79fe224e9c04e5affe56119bad0b6","unresolved":false,"context_lines":[{"line_number":35,"context_line":"* An image is signed by an End User, using the user\u0027s private key.  The   user"},{"line_number":36,"context_line":"  then uploads the image to Glance, along with the signature created and a"},{"line_number":37,"context_line":"  reference to the user\u0027s public key certificate.  Glance uses this"},{"line_number":38,"context_line":"  information to verify that the   signature is valid, and notifies the user"},{"line_number":39,"context_line":"  if the signature is invalid."},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"* An image is uploaded by an End User, along with an indication that it should"}],"source_content_type":"text/x-rst","patch_set":6,"id":"1a4dcd0f_9b1f79b6","line":38,"in_reply_to":"1a4dcd0f_516c7734","updated":"2015-08-06 22:03:27.000000000","message":"Done","commit_id":"88036d33cd5e5c4fae24aeb5e6fac5393a2523fe"},{"author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"change_message_id":"85f4e5c76513737fc452dfbb1ef5423778fc2117","unresolved":false,"context_lines":[{"line_number":129,"context_line":"image, it would need to have access to the key used to create the signature."},{"line_number":130,"context_line":"This access would enable Glance to modify the image and create a new signature"},{"line_number":131,"context_line":"without the user\u0027s knowledge.  Using asymmetric keys enables Glance to verify"},{"line_number":132,"context_line":"the signature without given Glance the power to modify the image and"},{"line_number":133,"context_line":"signature."},{"line_number":134,"context_line":""},{"line_number":135,"context_line":"An alternative to using the Glance properties to store and retrieve the"}],"source_content_type":"text/x-rst","patch_set":6,"id":"1a4dcd0f_b2fbaa7a","line":132,"updated":"2015-08-06 03:56:08.000000000","message":"\"given\" should be \"giving\"","commit_id":"88036d33cd5e5c4fae24aeb5e6fac5393a2523fe"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"b747634c05c79fe224e9c04e5affe56119bad0b6","unresolved":false,"context_lines":[{"line_number":129,"context_line":"image, it would need to have access to the key used to create the signature."},{"line_number":130,"context_line":"This access would enable Glance to modify the image and create a new signature"},{"line_number":131,"context_line":"without the user\u0027s knowledge.  Using asymmetric keys enables Glance to verify"},{"line_number":132,"context_line":"the signature without given Glance the power to modify the image and"},{"line_number":133,"context_line":"signature."},{"line_number":134,"context_line":""},{"line_number":135,"context_line":"An alternative to using the Glance properties to store and retrieve the"}],"source_content_type":"text/x-rst","patch_set":6,"id":"1a4dcd0f_1b59298e","line":132,"in_reply_to":"1a4dcd0f_b2fbaa7a","updated":"2015-08-06 22:03:27.000000000","message":"Done","commit_id":"88036d33cd5e5c4fae24aeb5e6fac5393a2523fe"},{"author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"change_message_id":"85f4e5c76513737fc452dfbb1ef5423778fc2117","unresolved":false,"context_lines":[{"line_number":133,"context_line":"signature."},{"line_number":134,"context_line":""},{"line_number":135,"context_line":"An alternative to using the Glance properties to store and retrieve the"},{"line_number":136,"context_line":"signature metadata would be to create an API extension support signatures."},{"line_number":137,"context_line":"Then, instead of the user setting the metadata using the property key value"},{"line_number":138,"context_line":"pairs, the API extension would be used. Currently, if a user were to use the"},{"line_number":139,"context_line":"metadata keys (for the certificate and signature) for other purposes, the"}],"source_content_type":"text/x-rst","patch_set":6,"id":"1a4dcd0f_1267fe4d","line":136,"updated":"2015-08-06 03:56:08.000000000","message":"\"extension that supports signatures\" ?","commit_id":"88036d33cd5e5c4fae24aeb5e6fac5393a2523fe"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"b747634c05c79fe224e9c04e5affe56119bad0b6","unresolved":false,"context_lines":[{"line_number":133,"context_line":"signature."},{"line_number":134,"context_line":""},{"line_number":135,"context_line":"An alternative to using the Glance properties to store and retrieve the"},{"line_number":136,"context_line":"signature metadata would be to create an API extension support signatures."},{"line_number":137,"context_line":"Then, instead of the user setting the metadata using the property key value"},{"line_number":138,"context_line":"pairs, the API extension would be used. Currently, if a user were to use the"},{"line_number":139,"context_line":"metadata keys (for the certificate and signature) for other purposes, the"}],"source_content_type":"text/x-rst","patch_set":6,"id":"1a4dcd0f_3b5c257c","line":136,"in_reply_to":"1a4dcd0f_1267fe4d","updated":"2015-08-06 22:03:27.000000000","message":"Done","commit_id":"88036d33cd5e5c4fae24aeb5e6fac5393a2523fe"},{"author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"change_message_id":"85f4e5c76513737fc452dfbb1ef5423778fc2117","unresolved":false,"context_lines":[{"line_number":141,"context_line":"allow for the management of multiple signatures per image, which is not"},{"line_number":142,"context_line":"possible with the properties approach. Although adding the API extension would"},{"line_number":143,"context_line":"remedy these issues, the properties provide a more straightforward initial"},{"line_number":144,"context_line":"approach that can be improved upon as needed."},{"line_number":145,"context_line":""},{"line_number":146,"context_line":"Another alternative to using the Glance properties to store and retrieve the"},{"line_number":147,"context_line":"signature metadata would be to the CMS (cryptographic message syntax) format"}],"source_content_type":"text/x-rst","patch_set":6,"id":"1a4dcd0f_52e02696","line":144,"updated":"2015-08-06 03:56:08.000000000","message":"Don\u0027t know that you need to mention this, but one problem with the API extension approach is that the Images API doesn\u0027t support extensions.","commit_id":"88036d33cd5e5c4fae24aeb5e6fac5393a2523fe"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"b747634c05c79fe224e9c04e5affe56119bad0b6","unresolved":false,"context_lines":[{"line_number":141,"context_line":"allow for the management of multiple signatures per image, which is not"},{"line_number":142,"context_line":"possible with the properties approach. Although adding the API extension would"},{"line_number":143,"context_line":"remedy these issues, the properties provide a more straightforward initial"},{"line_number":144,"context_line":"approach that can be improved upon as needed."},{"line_number":145,"context_line":""},{"line_number":146,"context_line":"Another alternative to using the Glance properties to store and retrieve the"},{"line_number":147,"context_line":"signature metadata would be to the CMS (cryptographic message syntax) format"}],"source_content_type":"text/x-rst","patch_set":6,"id":"1a4dcd0f_db618106","line":144,"in_reply_to":"1a4dcd0f_52e02696","updated":"2015-08-06 22:03:27.000000000","message":"I\u0027ve mentioned it in the latest version.","commit_id":"88036d33cd5e5c4fae24aeb5e6fac5393a2523fe"},{"author":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"change_message_id":"0d7c46b843ea20678f258e19a5c5201239209579","unresolved":false,"context_lines":[{"line_number":144,"context_line":"approach that can be improved upon as needed."},{"line_number":145,"context_line":""},{"line_number":146,"context_line":"Another alternative to using the Glance properties to store and retrieve the"},{"line_number":147,"context_line":"signature metadata would be to the CMS (cryptographic message syntax) format"},{"line_number":148,"context_line":"as defined in RFC 5652 Section 5.  However, the size for this would be"},{"line_number":149,"context_line":"variable, and could not use the existing Glance properties, which would"},{"line_number":150,"context_line":"require API modifications.  For the initial implementation, Glance properties"}],"source_content_type":"text/x-rst","patch_set":6,"id":"1a4dcd0f_71e733ac","line":147,"updated":"2015-08-06 20:26:32.000000000","message":"typo: would be to the CMS -\u003e would be to *use* the CMS","commit_id":"88036d33cd5e5c4fae24aeb5e6fac5393a2523fe"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"b747634c05c79fe224e9c04e5affe56119bad0b6","unresolved":false,"context_lines":[{"line_number":144,"context_line":"approach that can be improved upon as needed."},{"line_number":145,"context_line":""},{"line_number":146,"context_line":"Another alternative to using the Glance properties to store and retrieve the"},{"line_number":147,"context_line":"signature metadata would be to the CMS (cryptographic message syntax) format"},{"line_number":148,"context_line":"as defined in RFC 5652 Section 5.  However, the size for this would be"},{"line_number":149,"context_line":"variable, and could not use the existing Glance properties, which would"},{"line_number":150,"context_line":"require API modifications.  For the initial implementation, Glance properties"}],"source_content_type":"text/x-rst","patch_set":6,"id":"1a4dcd0f_bb4835b4","line":147,"in_reply_to":"1a4dcd0f_71e733ac","updated":"2015-08-06 22:03:27.000000000","message":"Done","commit_id":"88036d33cd5e5c4fae24aeb5e6fac5393a2523fe"},{"author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"change_message_id":"85f4e5c76513737fc452dfbb1ef5423778fc2117","unresolved":false,"context_lines":[{"line_number":268,"context_line":"The feature will be tackled in the following stages:"},{"line_number":269,"context_line":""},{"line_number":270,"context_line":"1. Enable Glance to verify signatures provided by the user during an image"},{"line_number":271,"context_line":"   upload initiated by the user."},{"line_number":272,"context_line":"2. Enable Glance to use its service-level key-pair to generate a signature"},{"line_number":273,"context_line":"   when requested by the user."},{"line_number":274,"context_line":"3. Enable Glance to verify signatures provided by Nova during an image upload"}],"source_content_type":"text/x-rst","patch_set":6,"id":"1a4dcd0f_f59cbcc1","line":271,"updated":"2015-08-06 03:56:08.000000000","message":"Who\u0027s the target user here? Is it a glance admin, or a \"normal\" end user?  It would be worth thinking about how the signature code could be integrated into the import task.","commit_id":"88036d33cd5e5c4fae24aeb5e6fac5393a2523fe"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"b747634c05c79fe224e9c04e5affe56119bad0b6","unresolved":false,"context_lines":[{"line_number":268,"context_line":"The feature will be tackled in the following stages:"},{"line_number":269,"context_line":""},{"line_number":270,"context_line":"1. Enable Glance to verify signatures provided by the user during an image"},{"line_number":271,"context_line":"   upload initiated by the user."},{"line_number":272,"context_line":"2. Enable Glance to use its service-level key-pair to generate a signature"},{"line_number":273,"context_line":"   when requested by the user."},{"line_number":274,"context_line":"3. Enable Glance to verify signatures provided by Nova during an image upload"}],"source_content_type":"text/x-rst","patch_set":6,"id":"1a4dcd0f_bb29159d","line":271,"in_reply_to":"1a4dcd0f_f59cbcc1","updated":"2015-08-06 22:03:27.000000000","message":"This initial implementation would support the \"upload\" path but not the \"import\" path, though I think it would be valuable to support imports in a future implementation.","commit_id":"88036d33cd5e5c4fae24aeb5e6fac5393a2523fe"}],"specs/liberty/image-signing-and-verification-support.rst":[{"author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"change_message_id":"d7df2ab82a4adc47070c7179a3c2ca8b3a53faa8","unresolved":false,"context_lines":[{"line_number":57,"context_line":"uploaded.  Note that this proposed change will only support image uploads with"},{"line_number":58,"context_line":"the glance api v2 (and will not support using the glance api v1).  Also note"},{"line_number":59,"context_line":"that multiple formats for the key (such as SubjectPublicKeyInfo) and for the"},{"line_number":60,"context_line":"signature (such as PSS) will be supported."},{"line_number":61,"context_line":""},{"line_number":62,"context_line":"The certificate reference will be used to access the certificate from a key"},{"line_number":63,"context_line":"manager, where the certificate will be stored.  This certificate is added to"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_5072fa4a","line":60,"updated":"2015-08-07 20:37:32.000000000","message":"While multiple schemes is arguably a good thing, it\u0027s important to limit these to a small number of very good options. Algorithmic agility has repeatedly proven itself to be the downfall of cryptographic standards.\n\nWhich specs will govern what standards are supported?","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"change_message_id":"adfdb265436e4e204d4a3064a224f977d86d2b0a","unresolved":false,"context_lines":[{"line_number":57,"context_line":"uploaded.  Note that this proposed change will only support image uploads with"},{"line_number":58,"context_line":"the glance api v2 (and will not support using the glance api v1).  Also note"},{"line_number":59,"context_line":"that multiple formats for the key (such as SubjectPublicKeyInfo) and for the"},{"line_number":60,"context_line":"signature (such as PSS) will be supported."},{"line_number":61,"context_line":""},{"line_number":62,"context_line":"The certificate reference will be used to access the certificate from a key"},{"line_number":63,"context_line":"manager, where the certificate will be stored.  This certificate is added to"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_9325e70b","line":60,"in_reply_to":"1a4dcd0f_072af9e7","updated":"2015-08-08 00:21:26.000000000","message":"Is it intentional that this spec does not specify what that signature looks like? That seems important, especially since we\u0027re expanding it later.","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"ff8701c9e6701869a25c6c4ed837945b01278848","unresolved":false,"context_lines":[{"line_number":57,"context_line":"uploaded.  Note that this proposed change will only support image uploads with"},{"line_number":58,"context_line":"the glance api v2 (and will not support using the glance api v1).  Also note"},{"line_number":59,"context_line":"that multiple formats for the key (such as SubjectPublicKeyInfo) and for the"},{"line_number":60,"context_line":"signature (such as PSS) will be supported."},{"line_number":61,"context_line":""},{"line_number":62,"context_line":"The certificate reference will be used to access the certificate from a key"},{"line_number":63,"context_line":"manager, where the certificate will be stored.  This certificate is added to"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_072af9e7","line":60,"in_reply_to":"1a4dcd0f_5072fa4a","updated":"2015-08-07 21:16:18.000000000","message":"Initially, only PSS will be supported for the signature, but the format of the signature will be configurable to allow for the addition of other formats in the future.\n\nI agree that we don\u0027t want to allow too many formats, and I don\u0027t intend to allow PKCS1v15 to be one of them unless I receive pushback.","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"ea0afa037127601d8555fd246734f324a9c137e1","unresolved":false,"context_lines":[{"line_number":57,"context_line":"uploaded.  Note that this proposed change will only support image uploads with"},{"line_number":58,"context_line":"the glance api v2 (and will not support using the glance api v1).  Also note"},{"line_number":59,"context_line":"that multiple formats for the key (such as SubjectPublicKeyInfo) and for the"},{"line_number":60,"context_line":"signature (such as PSS) will be supported."},{"line_number":61,"context_line":""},{"line_number":62,"context_line":"The certificate reference will be used to access the certificate from a key"},{"line_number":63,"context_line":"manager, where the certificate will be stored.  This certificate is added to"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_ba374b4c","line":60,"in_reply_to":"1a4dcd0f_9325e70b","updated":"2015-08-10 21:04:01.000000000","message":"The plan is to take the signature in binary form, encode it with base64, and then provide this encoded signature when uploading the image.  Is that what you were asking?\n\nOne of the properties that will be stored and required during upload is the format of the signature.\n\nI didn\u0027t want to include too many implementation-specific details.","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"change_message_id":"d7df2ab82a4adc47070c7179a3c2ca8b3a53faa8","unresolved":false,"context_lines":[{"line_number":62,"context_line":"The certificate reference will be used to access the certificate from a key"},{"line_number":63,"context_line":"manager, where the certificate will be stored.  This certificate is added to"},{"line_number":64,"context_line":"the key manager by the end user before uploading the image.  Note that the"},{"line_number":65,"context_line":"signature is done offline."},{"line_number":66,"context_line":""},{"line_number":67,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":68,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_70f7f68c","line":65,"updated":"2015-08-07 20:37:32.000000000","message":"What are the constraints on the size of the certificate reference?","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"ea0afa037127601d8555fd246734f324a9c137e1","unresolved":false,"context_lines":[{"line_number":62,"context_line":"The certificate reference will be used to access the certificate from a key"},{"line_number":63,"context_line":"manager, where the certificate will be stored.  This certificate is added to"},{"line_number":64,"context_line":"the key manager by the end user before uploading the image.  Note that the"},{"line_number":65,"context_line":"signature is done offline."},{"line_number":66,"context_line":""},{"line_number":67,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":68,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_e6ab0b1d","line":65,"in_reply_to":"1a4dcd0f_331653a8","updated":"2015-08-10 21:04:01.000000000","message":"You are correct -- 255 characters is the limit.  And although we could store a public key in Glance, using a certificate (with a certificate authority connected to the key manager) means that an attacker would have to infiltrate both Glance and the key manager in order to create a signature that will validate properly.","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"change_message_id":"adfdb265436e4e204d4a3064a224f977d86d2b0a","unresolved":false,"context_lines":[{"line_number":62,"context_line":"The certificate reference will be used to access the certificate from a key"},{"line_number":63,"context_line":"manager, where the certificate will be stored.  This certificate is added to"},{"line_number":64,"context_line":"the key manager by the end user before uploading the image.  Note that the"},{"line_number":65,"context_line":"signature is done offline."},{"line_number":66,"context_line":""},{"line_number":67,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":68,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_331653a8","line":65,"in_reply_to":"1a4dcd0f_44923ff8","updated":"2015-08-08 00:21:26.000000000","message":"Sorry, I was unclear -- that\u0027s not quite what I meant. I think the answer I was looking for is \"255 bytes\". I was trying to explore if we can reasonably fit public keys in there. The answer is yes, but no, because we\u0027re allowing many different kinds of keys. (A libsodium key fits quite comfortably in those 255 bytes; an X509 cert generally does not.)","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"ff8701c9e6701869a25c6c4ed837945b01278848","unresolved":false,"context_lines":[{"line_number":62,"context_line":"The certificate reference will be used to access the certificate from a key"},{"line_number":63,"context_line":"manager, where the certificate will be stored.  This certificate is added to"},{"line_number":64,"context_line":"the key manager by the end user before uploading the image.  Note that the"},{"line_number":65,"context_line":"signature is done offline."},{"line_number":66,"context_line":""},{"line_number":67,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":68,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_44923ff8","line":65,"in_reply_to":"1a4dcd0f_70f7f68c","updated":"2015-08-07 21:16:18.000000000","message":"This certificate reference is a UUID, which can be used by the key manager backend to retrieve the certificate.","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"change_message_id":"d7df2ab82a4adc47070c7179a3c2ca8b3a53faa8","unresolved":false,"context_lines":[{"line_number":66,"context_line":""},{"line_number":67,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":68,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"},{"line_number":69,"context_line":"by default is MD5) will be used for the signature verification."},{"line_number":70,"context_line":""},{"line_number":71,"context_line":"Since the checksum hash is computed in glance_store (when the image data is"},{"line_number":72,"context_line":"uploaded), it makes sense for the signature verification to be computed in"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_70c9365a","line":69,"updated":"2015-08-07 20:37:32.000000000","message":"This raises concerns given that the spec doesn\u0027t specify concrete signature mechanisms. While there\u0027s nothing fundamentally wrong with sign-the-hash (which appears to be proposed here), that scheme does imply that the hash function is collision-resistant, which MD5 is not.\n\nEDIT: I should clarify that this depends on your threat model. If you\u0027re trying to protect against an attacker forging a signature on an arbitrary image of their choosing, this approach is fine. If you\u0027re trying to protect against an attacker being able to generate a valid (img\u0027, s) pair from a given (img, s) pair, the hash function needs to be secure against 2nd preimage attacks. These attacks are considered infeasible at present, even for MD5 -- although the margins are looking quite thin, and the research advancements are worrisome. If your threat model includes bait-and-switch, then MD5-PSS is insecure *today*.","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"change_message_id":"adfdb265436e4e204d4a3064a224f977d86d2b0a","unresolved":false,"context_lines":[{"line_number":66,"context_line":""},{"line_number":67,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":68,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"},{"line_number":69,"context_line":"by default is MD5) will be used for the signature verification."},{"line_number":70,"context_line":""},{"line_number":71,"context_line":"Since the checksum hash is computed in glance_store (when the image data is"},{"line_number":72,"context_line":"uploaded), it makes sense for the signature verification to be computed in"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_337df3e7","line":69,"in_reply_to":"1a4dcd0f_4480ff8b","updated":"2015-08-08 00:21:26.000000000","message":"Okay, I guess that\u0027s acceptable, since we can only twiddle one little thing at a time... Thanks for the reference; I\u0027ll review the other spec as well.","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"ff8701c9e6701869a25c6c4ed837945b01278848","unresolved":false,"context_lines":[{"line_number":66,"context_line":""},{"line_number":67,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":68,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"},{"line_number":69,"context_line":"by default is MD5) will be used for the signature verification."},{"line_number":70,"context_line":""},{"line_number":71,"context_line":"Since the checksum hash is computed in glance_store (when the image data is"},{"line_number":72,"context_line":"uploaded), it makes sense for the signature verification to be computed in"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_4480ff8b","line":69,"in_reply_to":"1a4dcd0f_70c9365a","updated":"2015-08-07 21:16:18.000000000","message":"I recognize that MD5 is not secure.  There is another spec in place (https://review.openstack.org/191542) that will allow for the configurability of this hash.\n\nAnd yes, the \"sign the hash\" approach is what is being proposed.","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"change_message_id":"d7df2ab82a4adc47070c7179a3c2ca8b3a53faa8","unresolved":false,"context_lines":[{"line_number":80,"context_line":"the signature to the backend. If the signature verification fails,"},{"line_number":81,"context_line":"glance_store will abort the change, allowing the user to update the signature"},{"line_number":82,"context_line":"property to a correct value before trying again."},{"line_number":83,"context_line":""},{"line_number":84,"context_line":"Alternatives"},{"line_number":85,"context_line":"------------"},{"line_number":86,"context_line":""}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_1016b2a7","line":83,"updated":"2015-08-07 20:37:32.000000000","message":"This doesn\u0027t appear to address how Nova would verify the images.\n\nA classic implementation gotcha with many of these systems, particularly the streaming variety, is using unauthenticated data before the entire signature is verified. This is likely, because we\u0027re talking about very large signed objects.","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"ff8701c9e6701869a25c6c4ed837945b01278848","unresolved":false,"context_lines":[{"line_number":80,"context_line":"the signature to the backend. If the signature verification fails,"},{"line_number":81,"context_line":"glance_store will abort the change, allowing the user to update the signature"},{"line_number":82,"context_line":"property to a correct value before trying again."},{"line_number":83,"context_line":""},{"line_number":84,"context_line":"Alternatives"},{"line_number":85,"context_line":"------------"},{"line_number":86,"context_line":""}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_e4158b49","line":83,"in_reply_to":"1a4dcd0f_1016b2a7","updated":"2015-08-07 21:16:18.000000000","message":"There is a partner spec in Nova (https://review.openstack.org/#/c/188874/) that includes further details on how Nova will verify the images.\n\nNova will compute a hash of the image data, and then this hash will be used to verify the signature.  This verification would occur before the image is booted.","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"change_message_id":"adfdb265436e4e204d4a3064a224f977d86d2b0a","unresolved":false,"context_lines":[{"line_number":80,"context_line":"the signature to the backend. If the signature verification fails,"},{"line_number":81,"context_line":"glance_store will abort the change, allowing the user to update the signature"},{"line_number":82,"context_line":"property to a correct value before trying again."},{"line_number":83,"context_line":""},{"line_number":84,"context_line":"Alternatives"},{"line_number":85,"context_line":"------------"},{"line_number":86,"context_line":""}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_8eae1ee6","line":83,"in_reply_to":"1a4dcd0f_e4158b49","updated":"2015-08-08 00:21:26.000000000","message":"Thanks for the link!","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"change_message_id":"d7df2ab82a4adc47070c7179a3c2ca8b3a53faa8","unresolved":false,"context_lines":[{"line_number":99,"context_line":"would be to store the actual public and private keys (or certificate) in"},{"line_number":100,"context_line":"Glance.  However, this approach would be insecure, since Glance, unlike a"},{"line_number":101,"context_line":"dedicated key manager, has not been created with storing keys or certificates"},{"line_number":102,"context_line":"in mind."},{"line_number":103,"context_line":""},{"line_number":104,"context_line":"An alternative to performing the signature verification/creation in the"},{"line_number":105,"context_line":"glance_store backend is to only perform the hash creation in the backend, and"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_f0778606","line":102,"updated":"2015-08-07 20:37:32.000000000","message":"I\u0027m not sure I understand how this is an alternative. Who\u0027s allegedly doing the signing in this scenario? Still the end-user?","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"change_message_id":"adfdb265436e4e204d4a3064a224f977d86d2b0a","unresolved":false,"context_lines":[{"line_number":99,"context_line":"would be to store the actual public and private keys (or certificate) in"},{"line_number":100,"context_line":"Glance.  However, this approach would be insecure, since Glance, unlike a"},{"line_number":101,"context_line":"dedicated key manager, has not been created with storing keys or certificates"},{"line_number":102,"context_line":"in mind."},{"line_number":103,"context_line":""},{"line_number":104,"context_line":"An alternative to performing the signature verification/creation in the"},{"line_number":105,"context_line":"glance_store backend is to only perform the hash creation in the backend, and"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_53767f07","line":102,"in_reply_to":"1a4dcd0f_471c816a","updated":"2015-08-08 00:21:26.000000000","message":"Storing the public key in Glance seems reasonable, but this paragraph suggests that we store the pair (i.e. also the private key) in Glance.","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"ea0afa037127601d8555fd246734f324a9c137e1","unresolved":false,"context_lines":[{"line_number":99,"context_line":"would be to store the actual public and private keys (or certificate) in"},{"line_number":100,"context_line":"Glance.  However, this approach would be insecure, since Glance, unlike a"},{"line_number":101,"context_line":"dedicated key manager, has not been created with storing keys or certificates"},{"line_number":102,"context_line":"in mind."},{"line_number":103,"context_line":""},{"line_number":104,"context_line":"An alternative to performing the signature verification/creation in the"},{"line_number":105,"context_line":"glance_store backend is to only perform the hash creation in the backend, and"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_862fa7a0","line":102,"in_reply_to":"1a4dcd0f_53767f07","updated":"2015-08-10 21:04:01.000000000","message":"You\u0027re right -- I should update this paragraph to remove the mention of \"private keys\"","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"ff8701c9e6701869a25c6c4ed837945b01278848","unresolved":false,"context_lines":[{"line_number":99,"context_line":"would be to store the actual public and private keys (or certificate) in"},{"line_number":100,"context_line":"Glance.  However, this approach would be insecure, since Glance, unlike a"},{"line_number":101,"context_line":"dedicated key manager, has not been created with storing keys or certificates"},{"line_number":102,"context_line":"in mind."},{"line_number":103,"context_line":""},{"line_number":104,"context_line":"An alternative to performing the signature verification/creation in the"},{"line_number":105,"context_line":"glance_store backend is to only perform the hash creation in the backend, and"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_471c816a","line":102,"in_reply_to":"1a4dcd0f_f0778606","updated":"2015-08-07 21:16:18.000000000","message":"This would still be the end-user creating the signature, but instead of storing the certificate in a key manager and a reference to the certificate in glance, this scenario would be storing the actual public key certificate in glance.","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"change_message_id":"d7df2ab82a4adc47070c7179a3c2ca8b3a53faa8","unresolved":false,"context_lines":[{"line_number":125,"context_line":"the image uploads would fail.  Another item of note is that an API extension"},{"line_number":126,"context_line":"would allow for the management of multiple signatures per image, which is not"},{"line_number":127,"context_line":"possible with the properties approach. However, the Images API does not"},{"line_number":128,"context_line":"support extensions, so this is not a valid approach."},{"line_number":129,"context_line":""},{"line_number":130,"context_line":"Another alternative to using the Glance properties to store and retrieve the"},{"line_number":131,"context_line":"signature metadata would be to use the CMS (cryptographic message syntax)"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_84dcc775","line":128,"updated":"2015-08-07 20:37:32.000000000","message":"Why can\u0027t we do multiple signatures with properties?","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"change_message_id":"adfdb265436e4e204d4a3064a224f977d86d2b0a","unresolved":false,"context_lines":[{"line_number":125,"context_line":"the image uploads would fail.  Another item of note is that an API extension"},{"line_number":126,"context_line":"would allow for the management of multiple signatures per image, which is not"},{"line_number":127,"context_line":"possible with the properties approach. However, the Images API does not"},{"line_number":128,"context_line":"support extensions, so this is not a valid approach."},{"line_number":129,"context_line":""},{"line_number":130,"context_line":"Another alternative to using the Glance properties to store and retrieve the"},{"line_number":131,"context_line":"signature metadata would be to use the CMS (cryptographic message syntax)"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_734a9bae","line":128,"in_reply_to":"1a4dcd0f_27be15d5","updated":"2015-08-08 00:21:26.000000000","message":"I\u0027m not sure I understand the concern. Are you considering cases like signature1 existing, signature4 existing, but not signature2 \u0026 signature3?","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"ea0afa037127601d8555fd246734f324a9c137e1","unresolved":false,"context_lines":[{"line_number":125,"context_line":"the image uploads would fail.  Another item of note is that an API extension"},{"line_number":126,"context_line":"would allow for the management of multiple signatures per image, which is not"},{"line_number":127,"context_line":"possible with the properties approach. However, the Images API does not"},{"line_number":128,"context_line":"support extensions, so this is not a valid approach."},{"line_number":129,"context_line":""},{"line_number":130,"context_line":"Another alternative to using the Glance properties to store and retrieve the"},{"line_number":131,"context_line":"signature metadata would be to use the CMS (cryptographic message syntax)"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_2129dd37","line":128,"in_reply_to":"1a4dcd0f_734a9bae","updated":"2015-08-10 21:04:01.000000000","message":"It would be possible to support multiple signatures using properties, but it doesn\u0027t seem like a very clean way to do it.  If all related information about a given signature were stored in a row in a database table, it\u0027d be easy to see exactly what related to what.  With using the properties you might have situations where you have signature1 and certificate_uuid2, and signature2 and certificate_uuid1 are missing.  I guess I prefer the data being organized more cleanly.","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"ff8701c9e6701869a25c6c4ed837945b01278848","unresolved":false,"context_lines":[{"line_number":125,"context_line":"the image uploads would fail.  Another item of note is that an API extension"},{"line_number":126,"context_line":"would allow for the management of multiple signatures per image, which is not"},{"line_number":127,"context_line":"possible with the properties approach. However, the Images API does not"},{"line_number":128,"context_line":"support extensions, so this is not a valid approach."},{"line_number":129,"context_line":""},{"line_number":130,"context_line":"Another alternative to using the Glance properties to store and retrieve the"},{"line_number":131,"context_line":"signature metadata would be to use the CMS (cryptographic message syntax)"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_27be15d5","line":128,"in_reply_to":"1a4dcd0f_84dcc775","updated":"2015-08-07 21:16:18.000000000","message":"It does not seem very robust to have keys like \"signature1, certificate_uuid1, signature2, certificate_uuid2\" etc.  Properties are also limited to 255 characters.","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"change_message_id":"d7df2ab82a4adc47070c7179a3c2ca8b3a53faa8","unresolved":false,"context_lines":[{"line_number":148,"context_line":"to MD5 that are more secure, a separate change is being proposed to allow for"},{"line_number":149,"context_line":"the configuring of this hash algorithm [2].  This will not be included as a"},{"line_number":150,"context_line":"part of this change, in the interest of having a straightforward initial"},{"line_number":151,"context_line":"implementation."},{"line_number":152,"context_line":""},{"line_number":153,"context_line":"An alternative to focusing on a single-cloud implementation would be to"},{"line_number":154,"context_line":"include support for multi-clouds in the initial implementation.  If images are"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_449ebf64","line":151,"updated":"2015-08-07 20:37:32.000000000","message":"Two concerns:\n\n1. Adding secure modes afterwards typically doesn\u0027t pan out well. Two examples of highly visible attacks within the last 6 months that were a direct consequence of allowing insecure modes:\n\nhttps://freakattack.com/\nhttps://auth0.com/blog/2015/03/31/critical-vulnerabilities-in-json-web-token-libraries/\n\n2. Were any measurements/experiments conducted to check to what extent BLAKE2-ing the message would impact performance?","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"ff8701c9e6701869a25c6c4ed837945b01278848","unresolved":false,"context_lines":[{"line_number":148,"context_line":"to MD5 that are more secure, a separate change is being proposed to allow for"},{"line_number":149,"context_line":"the configuring of this hash algorithm [2].  This will not be included as a"},{"line_number":150,"context_line":"part of this change, in the interest of having a straightforward initial"},{"line_number":151,"context_line":"implementation."},{"line_number":152,"context_line":""},{"line_number":153,"context_line":"An alternative to focusing on a single-cloud implementation would be to"},{"line_number":154,"context_line":"include support for multi-clouds in the initial implementation.  If images are"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_874a8926","line":151,"in_reply_to":"1a4dcd0f_449ebf64","updated":"2015-08-07 21:16:18.000000000","message":"1. The initial proposal of this feature was to create a separate hash, specifically for the use with signatures, distinct from the \"checksum hash.\"  However, this was met with opposition, because hashing twice is definitely going to negatively affect performance when compared with hashing once.\n\nAt the design summit session in Vancouver, it was determined that using MD5 for now was an acceptable risk, seeing as it will allow for a faster implementation and adoption of this feature, and having this feature even with MD5 was preferable to not having the feature at all.\n\n2. No, there have been no measurements conducted to investigate BLAKE2.","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"change_message_id":"adfdb265436e4e204d4a3064a224f977d86d2b0a","unresolved":false,"context_lines":[{"line_number":148,"context_line":"to MD5 that are more secure, a separate change is being proposed to allow for"},{"line_number":149,"context_line":"the configuring of this hash algorithm [2].  This will not be included as a"},{"line_number":150,"context_line":"part of this change, in the interest of having a straightforward initial"},{"line_number":151,"context_line":"implementation."},{"line_number":152,"context_line":""},{"line_number":153,"context_line":"An alternative to focusing on a single-cloud implementation would be to"},{"line_number":154,"context_line":"include support for multi-clouds in the initial implementation.  If images are"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_b3fee336","line":151,"in_reply_to":"1a4dcd0f_874a8926","updated":"2015-08-08 00:21:26.000000000","message":"I\u0027m assuming no measurements were done for any hash functions, and the claim that performing any two distinct hash functions simultaneously would be slower was taken at face value.\n\nGiven that there\u0027s a spec open for changing the hash function, I\u0027ll stop harping about this, but in many cases the above claim is factually incorrect, so I am a little sad to see it taken as truth without evidence. (I am not blaming you for it, I realize you are not necessarily the person making it, and understand the forces that led to that happening.)","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"change_message_id":"adfdb265436e4e204d4a3064a224f977d86d2b0a","unresolved":false,"context_lines":[{"line_number":189,"context_line":""},{"line_number":190,"context_line":"Other end user impact"},{"line_number":191,"context_line":"---------------------"},{"line_number":192,"context_line":"The user will be required to provide the appropriate information needed for"},{"line_number":193,"context_line":"the signing and verification in order to use this feature."},{"line_number":194,"context_line":""},{"line_number":195,"context_line":"There are no changes that need to be made to python-glanceclient."}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_eef6c2f8","line":192,"updated":"2015-08-08 00:21:26.000000000","message":"Nitpick: missing empty line?","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"ea0afa037127601d8555fd246734f324a9c137e1","unresolved":false,"context_lines":[{"line_number":189,"context_line":""},{"line_number":190,"context_line":"Other end user impact"},{"line_number":191,"context_line":"---------------------"},{"line_number":192,"context_line":"The user will be required to provide the appropriate information needed for"},{"line_number":193,"context_line":"the signing and verification in order to use this feature."},{"line_number":194,"context_line":""},{"line_number":195,"context_line":"There are no changes that need to be made to python-glanceclient."}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_21e0fdf9","line":192,"in_reply_to":"1a4dcd0f_eef6c2f8","updated":"2015-08-10 21:04:01.000000000","message":"Good catch.","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"change_message_id":"d7df2ab82a4adc47070c7179a3c2ca8b3a53faa8","unresolved":false,"context_lines":[{"line_number":262,"context_line":"The cryptography library, which will be used for hash creation and signature"},{"line_number":263,"context_line":"verification and creation, is already a part of the global-requirements of"},{"line_number":264,"context_line":"OpenStack.  However, it is not a part of glance or glance_store, and will"},{"line_number":265,"context_line":"need to be added there."},{"line_number":266,"context_line":""},{"line_number":267,"context_line":"Glance currently does not interact with any key managers.  Since a key manager"},{"line_number":268,"context_line":"is needed to manage the keys, changes will need to be made to allow Glance to"}],"source_content_type":"text/x-rst","patch_set":7,"id":"1a4dcd0f_240933de","line":265,"updated":"2015-08-07 20:37:32.000000000","message":"Thank heavens that we ended up being able to use cryptography :)","commit_id":"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"},{"author":{"_account_id":455,"name":"Stuart McLaren","email":"stuart.mclaren@hpe.com","username":"stuart-mclaren"},"change_message_id":"fc41c3efc071ce4022f1504f18f926121849088e","unresolved":false,"context_lines":[{"line_number":22,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":23,"context_line":""},{"line_number":24,"context_line":"There is no method for users to verify that a previously uploaded image has"},{"line_number":25,"context_line":"not been modified.  An image could potentially be modified in transit (such as"},{"line_number":26,"context_line":"when it is uploaded to glance or transferred to nova) or glance itself could"},{"line_number":27,"context_line":"be untrusted and modify images without a user\u0027s knowledge.  An image that is"},{"line_number":28,"context_line":"modified could include malicious code.  Providing support for image signatures"}],"source_content_type":"text/x-rst","patch_set":8,"id":"1a4dcd0f_66cb08a5","line":25,"updated":"2015-08-12 15:16:56.000000000","message":"Another query (sorry!)\n\nThe first sentence here implies there will be a method for users to \u0027verify that a previously uploaded image has not been modified\u0027.\n\nWhat will the recommended method for a user to \u0027verify that a previously uploaded image has not been modified\u0027 be?","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"941cee3ec29e97542f9c5d4bc029881817ed5378","unresolved":false,"context_lines":[{"line_number":22,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":23,"context_line":""},{"line_number":24,"context_line":"There is no method for users to verify that a previously uploaded image has"},{"line_number":25,"context_line":"not been modified.  An image could potentially be modified in transit (such as"},{"line_number":26,"context_line":"when it is uploaded to glance or transferred to nova) or glance itself could"},{"line_number":27,"context_line":"be untrusted and modify images without a user\u0027s knowledge.  An image that is"},{"line_number":28,"context_line":"modified could include malicious code.  Providing support for image signatures"}],"source_content_type":"text/x-rst","patch_set":8,"id":"fa1b9901_aa491fb9","line":25,"in_reply_to":"1a4dcd0f_66cb08a5","updated":"2015-08-19 15:11:19.000000000","message":"When the client (i.e., nova) retrieves the image from glance, the client can use the signature metadata to verify that the upload image has not been modified.","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":455,"name":"Stuart McLaren","email":"stuart.mclaren@hpe.com","username":"stuart-mclaren"},"change_message_id":"29f1187ae6d513c6d4b9cca3a45bf0e7beb4fd9c","unresolved":false,"context_lines":[{"line_number":22,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":23,"context_line":""},{"line_number":24,"context_line":"There is no method for users to verify that a previously uploaded image has"},{"line_number":25,"context_line":"not been modified.  An image could potentially be modified in transit (such as"},{"line_number":26,"context_line":"when it is uploaded to glance or transferred to nova) or glance itself could"},{"line_number":27,"context_line":"be untrusted and modify images without a user\u0027s knowledge.  An image that is"},{"line_number":28,"context_line":"modified could include malicious code.  Providing support for image signatures"}],"source_content_type":"text/x-rst","patch_set":8,"id":"fa1b9901_745093d4","line":25,"in_reply_to":"fa1b9901_aa491fb9","updated":"2015-08-20 14:44:43.000000000","message":"Ok, thanks.\n\nI just wanted to clarify that a user can\u0027t directly verify that their image is unmodified.","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"change_message_id":"6e7a456135b975a243df10abcc14160c49a02306","unresolved":false,"context_lines":[{"line_number":52,"context_line":""},{"line_number":53,"context_line":"For the initial implementation, this change will use the property feature of"},{"line_number":54,"context_line":"Glance to store the metadata items needed for image signing and verification."},{"line_number":55,"context_line":"These include a public key certificate reference, and the signature.  These"},{"line_number":56,"context_line":"are provided when the image is created, and are accessible when the image is"},{"line_number":57,"context_line":"uploaded.  Note that this proposed change will only support image uploads with"},{"line_number":58,"context_line":"the glance api v2 (and will not support using the glance api v1).  Also note"}],"source_content_type":"text/x-rst","patch_set":8,"id":"1a4dcd0f_c83bd5e8","line":55,"updated":"2015-08-13 13:21:18.000000000","message":"There will need to be metadata for the signature algorithm (i.e. SHA512withRSA).","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"941cee3ec29e97542f9c5d4bc029881817ed5378","unresolved":false,"context_lines":[{"line_number":52,"context_line":""},{"line_number":53,"context_line":"For the initial implementation, this change will use the property feature of"},{"line_number":54,"context_line":"Glance to store the metadata items needed for image signing and verification."},{"line_number":55,"context_line":"These include a public key certificate reference, and the signature.  These"},{"line_number":56,"context_line":"are provided when the image is created, and are accessible when the image is"},{"line_number":57,"context_line":"uploaded.  Note that this proposed change will only support image uploads with"},{"line_number":58,"context_line":"the glance api v2 (and will not support using the glance api v1).  Also note"}],"source_content_type":"text/x-rst","patch_set":8,"id":"fa1b9901_eae63714","line":55,"in_reply_to":"1a4dcd0f_c83bd5e8","updated":"2015-08-19 15:11:19.000000000","message":"Agreed. See response to other comment below.","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"change_message_id":"6e7a456135b975a243df10abcc14160c49a02306","unresolved":false,"context_lines":[{"line_number":67,"context_line":""},{"line_number":68,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":69,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"},{"line_number":70,"context_line":"by default is MD5) will be used for the signature verification."},{"line_number":71,"context_line":""},{"line_number":72,"context_line":"Since the checksum hash is computed in glance_store (when the image data is"},{"line_number":73,"context_line":"uploaded), it makes sense for the signature verification to be computed in"}],"source_content_type":"text/x-rst","patch_set":8,"id":"1a4dcd0f_d320669c","line":70,"updated":"2015-08-13 13:21:18.000000000","message":"Can you explain more about what this means? If the use computes the hash and signature before uploading the image then how does the Glance MD5 hash come into play?","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"941cee3ec29e97542f9c5d4bc029881817ed5378","unresolved":false,"context_lines":[{"line_number":67,"context_line":""},{"line_number":68,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":69,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"},{"line_number":70,"context_line":"by default is MD5) will be used for the signature verification."},{"line_number":71,"context_line":""},{"line_number":72,"context_line":"Since the checksum hash is computed in glance_store (when the image data is"},{"line_number":73,"context_line":"uploaded), it makes sense for the signature verification to be computed in"}],"source_content_type":"text/x-rst","patch_set":8,"id":"1a4dcd0f_da438412","line":70,"in_reply_to":"1a4dcd0f_d320669c","updated":"2015-08-19 15:11:19.000000000","message":"The signature is a signature of the hash of the image data.  Currently, only MD5 is supported as a hash for the \"checksum\" in glance, so only MD5 will be used for now.  This checksum hash is signed, creating the signature, which is then uploaded.  The signature is then verified using the MD5 hash generated by Glance when it uploads the image data.\n\nAn alternative would be to create the signature without hashing the hash (only one hash occurs, instead of two), but python cryptography currently doesn\u0027t support this approach (https://github.com/pyca/cryptography/issues/1648) although pycrypto did.","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"change_message_id":"0d24293453ff1e23875c372b8ba8850822dc037e","unresolved":false,"context_lines":[{"line_number":67,"context_line":""},{"line_number":68,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":69,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"},{"line_number":70,"context_line":"by default is MD5) will be used for the signature verification."},{"line_number":71,"context_line":""},{"line_number":72,"context_line":"Since the checksum hash is computed in glance_store (when the image data is"},{"line_number":73,"context_line":"uploaded), it makes sense for the signature verification to be computed in"}],"source_content_type":"text/x-rst","patch_set":8,"id":"fa1b9901_19e667b0","line":70,"in_reply_to":"1a4dcd0f_da438412","updated":"2015-08-19 16:51:55.000000000","message":"Is there another patch to make Glance configurable for which hash algorithm to use? How will that affect this? As a user will I be required to know which hashing algorithm glance is using and then sign that hash? Or will glance compute both hashes, say if I use SHA-256 and glance uses SHA-1?","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"fb7056b2955cbeddf9fc4e36640b4eb8a11df7e9","unresolved":false,"context_lines":[{"line_number":67,"context_line":""},{"line_number":68,"context_line":"Glance already supports computing checksums of images when an image is"},{"line_number":69,"context_line":"uploaded, and this checksum is stored with the image.  This same hash (which"},{"line_number":70,"context_line":"by default is MD5) will be used for the signature verification."},{"line_number":71,"context_line":""},{"line_number":72,"context_line":"Since the checksum hash is computed in glance_store (when the image data is"},{"line_number":73,"context_line":"uploaded), it makes sense for the signature verification to be computed in"}],"source_content_type":"text/x-rst","patch_set":8,"id":"fa1b9901_d14443b8","line":70,"in_reply_to":"fa1b9901_19e667b0","updated":"2015-08-19 19:41:15.000000000","message":"There\u0027s a spec out to make the glance image checksum configurable (https://review.openstack.org/#/c/191542/).","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"change_message_id":"6e7a456135b975a243df10abcc14160c49a02306","unresolved":false,"context_lines":[{"line_number":160,"context_line":"Data model impact"},{"line_number":161,"context_line":"-----------------"},{"line_number":162,"context_line":""},{"line_number":163,"context_line":"None."},{"line_number":164,"context_line":""},{"line_number":165,"context_line":"REST API impact"},{"line_number":166,"context_line":"---------------"}],"source_content_type":"text/x-rst","patch_set":8,"id":"1a4dcd0f_f3056279","line":163,"updated":"2015-08-13 13:21:18.000000000","message":"I think it would be useful to list the metadata that is expected to be stored. For example \"Signature\" will map to a signature blob. \"SignatureCertificate\" will map to URL that stores certificate. This will make it clearer as to what information is being stored because it is not clear to me what all of that is.\n\nI\u0027m not sure if you will be storing this information, but I think you will need a \"SignatureAlgorithm\" metadata. That string will contain what signature algorithm that was used to generate the signature. Then some where we need to define what those mean. That way if a user inserts \"SHA256withRSA\" then I know how signature was generated, and I can verify it.\n\nIn Java specification they have document of standardized algorithm names. Here is a link:\n\nhttps://docs.oracle.com/javase/7/docs/technotes/guides/security/StandardNames.html#Signature","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"941cee3ec29e97542f9c5d4bc029881817ed5378","unresolved":false,"context_lines":[{"line_number":160,"context_line":"Data model impact"},{"line_number":161,"context_line":"-----------------"},{"line_number":162,"context_line":""},{"line_number":163,"context_line":"None."},{"line_number":164,"context_line":""},{"line_number":165,"context_line":"REST API impact"},{"line_number":166,"context_line":"---------------"}],"source_content_type":"text/x-rst","patch_set":8,"id":"fa1b9901_aac35f56","line":163,"in_reply_to":"1a4dcd0f_7594c88b","updated":"2015-08-19 15:11:19.000000000","message":"You can see the different metadata options at https://review.openstack.org/#/c/183137/\n\nThe properties are:\n\ncertificate_uuid\n\nsignature_hash_method\n\nsignature\n\nsignature_format\n\n\nAnd for PSS-RSA specifically:\n\nmask_gen_algorithm","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"change_message_id":"85061bcd19f147c584e6b4baa99c4e201aa57cba","unresolved":false,"context_lines":[{"line_number":160,"context_line":"Data model impact"},{"line_number":161,"context_line":"-----------------"},{"line_number":162,"context_line":""},{"line_number":163,"context_line":"None."},{"line_number":164,"context_line":""},{"line_number":165,"context_line":"REST API impact"},{"line_number":166,"context_line":"---------------"}],"source_content_type":"text/x-rst","patch_set":8,"id":"1a4dcd0f_7594c88b","line":163,"in_reply_to":"1a4dcd0f_f3056279","updated":"2015-08-13 18:00:11.000000000","message":"I concur. The \"data model impact\" section might not be exactly the right place for this information, but it should be included in the documentation at some point.","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"fb7056b2955cbeddf9fc4e36640b4eb8a11df7e9","unresolved":false,"context_lines":[{"line_number":160,"context_line":"Data model impact"},{"line_number":161,"context_line":"-----------------"},{"line_number":162,"context_line":""},{"line_number":163,"context_line":"None."},{"line_number":164,"context_line":""},{"line_number":165,"context_line":"REST API impact"},{"line_number":166,"context_line":"---------------"}],"source_content_type":"text/x-rst","patch_set":8,"id":"fa1b9901_76bc45dc","line":163,"in_reply_to":"fa1b9901_241e9e5f","updated":"2015-08-19 19:41:15.000000000","message":"Since it appears that the \"signature_format\" name is confusing, I\u0027m going to change it to be \"signature_key_type\" instead.\n\nThis would either be \"RSA-PSS\" or \"ECDSA\" or \"DSA\"\n\nThe signature_hash_algorithm would be \"MD5\" or \"SHA-256\", etc.","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"change_message_id":"0d24293453ff1e23875c372b8ba8850822dc037e","unresolved":false,"context_lines":[{"line_number":160,"context_line":"Data model impact"},{"line_number":161,"context_line":"-----------------"},{"line_number":162,"context_line":""},{"line_number":163,"context_line":"None."},{"line_number":164,"context_line":""},{"line_number":165,"context_line":"REST API impact"},{"line_number":166,"context_line":"---------------"}],"source_content_type":"text/x-rst","patch_set":8,"id":"fa1b9901_241e9e5f","line":163,"in_reply_to":"fa1b9901_aac35f56","updated":"2015-08-19 16:51:55.000000000","message":"How many signature_hash_methods have \u003e1 signature_formats? We know *withRSA does, but do other algorithms? If not then I suggest stating the signature format for RSA and removing the signature_format metadata. That seems like better experience for user. Thoughts?\n\nI noticed that signature_format as in the code only contains RSA-PSS. What other values do you expect here?\n\nCould you provide example values of signature_hash_algorithm and signature_format for DSA and ECDSA?","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"change_message_id":"6a14160e7316477244982f9d5173febe05900ee3","unresolved":false,"context_lines":[{"line_number":166,"context_line":"---------------"},{"line_number":167,"context_line":""},{"line_number":168,"context_line":"No API changes will be needed for the initial implementation, provided that"},{"line_number":169,"context_line":"other services are able to retrieve all of the properties of a given image."},{"line_number":170,"context_line":""},{"line_number":171,"context_line":"Security impact"},{"line_number":172,"context_line":"---------------"}],"source_content_type":"text/x-rst","patch_set":8,"id":"1a4dcd0f_8ff98a82","line":169,"updated":"2015-08-12 14:51:12.000000000","message":"Some questions about error conditions.\n\nIf I understand correctly, the workflow is:\n\n(1) POST /v2/images\n\nwith body containing the usual stuff plus some signature-related properties (e.g., signature and cert reference).\n\nYou get back the usual stuff and the image id.\n\n(2) PUT /v2/images/IMAGE_ID/file\n\nuploads the image data.  Normally glance sets the checksum and makes the image active at this point (or returns an error).  If the signature-related image properties are present, after setting the checksum, glance will verify the signature.  If the verification fails, I guess this is a failed upload, the user gets an appropriate error message, the image is killed and the data is deleted from the backend?  What if the problem is that glance can\u0027t access the cert for some reason? Do we really want to kill \u0026 delete the image?  If not, how do we notify the end user of the situation, since we\u0027ll be returning a 204 for a successful upload?\n\nSuppose someone uploads an image, it goes active, and then they decide to put the signature-related metadata on it.  I guess there\u0027s nothing wrong with that?  The glance verification is a convenience for the end-user, it\u0027s not required.  It\u0027s up to the image consumer ultimately to read the signature-related metadata and verify the image anyway.","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"941cee3ec29e97542f9c5d4bc029881817ed5378","unresolved":false,"context_lines":[{"line_number":166,"context_line":"---------------"},{"line_number":167,"context_line":""},{"line_number":168,"context_line":"No API changes will be needed for the initial implementation, provided that"},{"line_number":169,"context_line":"other services are able to retrieve all of the properties of a given image."},{"line_number":170,"context_line":""},{"line_number":171,"context_line":"Security impact"},{"line_number":172,"context_line":"---------------"}],"source_content_type":"text/x-rst","patch_set":8,"id":"fa1b9901_8a1e9bb9","line":169,"in_reply_to":"1a4dcd0f_8ff98a82","updated":"2015-08-19 15:11:19.000000000","message":"Yes, you are correct about the workflow.  If the verification fails, then the user gets an error message, the image goes to a killed status, and the data is deleted.  This behavior can be seen with the latest patch at https://review.openstack.org/#/c/183137/.\n\nI think that this should occur regardless of what causes the verification failure (cert inaccessible, properties not defined correctly, actual verification failure, etc.).  \n\nIf the user thinks it is still important to set the metadata, but doesn\u0027t want the verification to occur, the user can add the metadata after the upload completes (i.e., the certificate is currently inaccessible, and the user doesn\u0027t care to verify).","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"fb7056b2955cbeddf9fc4e36640b4eb8a11df7e9","unresolved":false,"context_lines":[{"line_number":260,"context_line":"Dependencies"},{"line_number":261,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":262,"context_line":""},{"line_number":263,"context_line":"The cryptography library, which will be used for hash creation and signature"},{"line_number":264,"context_line":"verification and creation, is already a part of the global-requirements of"},{"line_number":265,"context_line":"OpenStack.  However, it is not a part of glance or glance_store, and will"},{"line_number":266,"context_line":"need to be added there."}],"source_content_type":"text/x-rst","patch_set":8,"id":"fa1b9901_36800df7","line":263,"updated":"2015-08-19 19:41:15.000000000","message":"On further analysis, the cryptography library does not yet support the ability to do the hash creation and signing separately (see https://github.com/pyca/cryptography/issues/1648).  Until this feature is added, pycrypto will be used, since it allows creating the hash and generating the signature separately.\n\nThe hash generation and the signature verification are done separately in order to avoid creating multiple hashes of the data.\n\nAlthough cryptography would allow creating a signature of the hash (which would create a new hash of the original checksum hash), this has the potential to be confusing, and is not the normal approach for signature creation and validation.","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"39145554c8b297579230708a43c6c6d48532245f","unresolved":false,"context_lines":[{"line_number":260,"context_line":"Dependencies"},{"line_number":261,"context_line":"\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d"},{"line_number":262,"context_line":""},{"line_number":263,"context_line":"The cryptography library, which will be used for hash creation and signature"},{"line_number":264,"context_line":"verification and creation, is already a part of the global-requirements of"},{"line_number":265,"context_line":"OpenStack.  However, it is not a part of glance or glance_store, and will"},{"line_number":266,"context_line":"need to be added there."}],"source_content_type":"text/x-rst","patch_set":8,"id":"fa1b9901_5afcfc3d","line":263,"in_reply_to":"fa1b9901_36800df7","updated":"2015-08-24 20:20:02.000000000","message":"After further discussion, it has been decided that the sign-the-hash method is acceptable, provided that proper documentation is provided which clearly explains how the signature is created (with several examples, of course).\n\nIt is also much preferable to use cryptography over pycrypto.","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"change_message_id":"6a14160e7316477244982f9d5173febe05900ee3","unresolved":false,"context_lines":[{"line_number":290,"context_line":""},{"line_number":291,"context_line":"Instructions for how to use the change will need to be documented.  These"},{"line_number":292,"context_line":"include instructions for the user on how to create keys and signatures"},{"line_number":293,"context_line":"offline before providing this information during the creation of an image."},{"line_number":294,"context_line":""},{"line_number":295,"context_line":""},{"line_number":296,"context_line":"References"}],"source_content_type":"text/x-rst","patch_set":8,"id":"1a4dcd0f_94d2fffe","line":293,"updated":"2015-08-12 14:51:12.000000000","message":"Don\u0027t need to add here, just don\u0027t forget that you\u0027ll also need to doc the naming convention for the signature-related image properties.","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"},{"author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"change_message_id":"941cee3ec29e97542f9c5d4bc029881817ed5378","unresolved":false,"context_lines":[{"line_number":290,"context_line":""},{"line_number":291,"context_line":"Instructions for how to use the change will need to be documented.  These"},{"line_number":292,"context_line":"include instructions for the user on how to create keys and signatures"},{"line_number":293,"context_line":"offline before providing this information during the creation of an image."},{"line_number":294,"context_line":""},{"line_number":295,"context_line":""},{"line_number":296,"context_line":"References"}],"source_content_type":"text/x-rst","patch_set":8,"id":"fa1b9901_8a9d3b68","line":293,"in_reply_to":"1a4dcd0f_94d2fffe","updated":"2015-08-19 15:11:19.000000000","message":"Agreed.","commit_id":"4a35f198f8e27c41bda9528589f40b8464f7d69d"}]}
