)]}'
{"id":"openstack%2Fglance-specs~177948","triplet_id":"openstack%2Fglance-specs~master~I305b2ae86415c8d256c641abb2795af663bee56a","project":"openstack/glance-specs","branch":"master","topic":"bp/image-signing-and-verification-support","hashtags":[],"change_id":"I305b2ae86415c8d256c641abb2795af663bee56a","subject":"Image Signing and Verification Support","status":"MERGED","created":"2015-04-27 19:48:36.000000000","updated":"2015-08-26 15:50:45.000000000","submitted":"2015-08-26 15:50:40.000000000","submitter":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"total_comment_count":114,"unresolved_comment_count":0,"has_review_started":true,"meta_rev_id":"c3eeaf9ac36e71f0e7765b91cb79085162e9186a","_number":177948,"virtual_id_number":177948,"owner":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"all":[{"value":0,"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},{"value":2,"date":"2015-08-26 15:50:40.000000000","_account_id":3,"name":"Jenkins","username":"jenkins"},{"value":0,"_account_id":8004,"name":"Paul Kehrer","email":"paul.l.kehrer@gmail.com","username":"reaperhulk"},{"value":0,"_account_id":4,"name":"Dolph Mathews","email":"dolph.mathews@gmail.com","username":"dolph"},{"value":0,"_account_id":455,"name":"Stuart McLaren","email":"stuart.mclaren@hpe.com","username":"stuart-mclaren"},{"value":0,"_account_id":136,"name":"Tim Bell","email":"tim.bell@cern.ch","username":"tim-bell"},{"value":0,"_account_id":9098,"name":"Nathan Kinder","email":"nkinder@redhat.com","username":"nkinder"},{"value":0,"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},{"value":0,"_account_id":6482,"name":"Steve Martinelli","email":"s.martinelli@gmail.com","username":"stevemar"},{"value":0,"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},{"value":0,"_account_id":7063,"name":"Robert Clark","email":"hyakuhei@gmail.com","username":"hyakuhei"},{"value":0,"_account_id":7575,"name":"Sabari","email":"smurugesan@vmware.com","username":"sabari"},{"value":0,"_account_id":13914,"name":"Darren J Moffat","email":"darren.moffat@oracle.com","username":"darrenmoffat"},{"value":0,"_account_id":11356,"name":"Louis Taylor","email":"louis@kragniz.eu","username":"kragniz"},{"value":0,"date":"2015-08-11 19:52:48.000000000","_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},{"value":0,"_account_id":15524,"name":"dane-fichter","email":"dane.fichter@jhuapl.edu","username":"dane-fichter"},{"value":0,"date":"2015-08-19 15:11:19.000000000","_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},{"value":0,"_account_id":2537,"name":"Nikhil Komawar","email":"nik.komawar@gmail.com","username":"nikhil-komawar"},{"value":0,"_account_id":2218,"name":"Adam Young","email":"adam@younglogic.com","username":"ayoung"},{"value":0,"_account_id":15022,"name":"dane-fichter","email":"Dane.Fichter@JHUAPL.EDU"},{"value":0,"_account_id":6896,"name":"Loganathan Parthipan","email":"parthi@hpe.com","username":"parthipan"},{"value":0,"date":"2015-08-19 23:10:28.000000000","_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},{"value":0,"_account_id":8119,"name":"Eric Brown","email":"eric_wade_brown@yahoo.com","username":"ericwb"},{"value":0,"date":"2015-08-22 01:39:52.000000000","_account_id":11642,"name":"Jesse J. Cook","email":"jesse.cook@rackspace.com","username":"crashenx"},{"value":0,"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},{"value":0,"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":455,"name":"Stuart McLaren","email":"stuart.mclaren@hpe.com","username":"stuart-mclaren"},"recommended":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"all":[{"value":1,"date":"2015-08-12 14:51:12.000000000","permitted_voting_range":{"min":1,"max":2},"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},{"value":0,"_account_id":3,"name":"Jenkins","username":"jenkins"},{"value":0,"_account_id":8004,"name":"Paul Kehrer","email":"paul.l.kehrer@gmail.com","username":"reaperhulk"},{"value":0,"_account_id":4,"name":"Dolph Mathews","email":"dolph.mathews@gmail.com","username":"dolph"},{"value":2,"date":"2015-08-12 13:05:40.000000000","_account_id":455,"name":"Stuart McLaren","email":"stuart.mclaren@hpe.com","username":"stuart-mclaren"},{"value":0,"_account_id":136,"name":"Tim Bell","email":"tim.bell@cern.ch","username":"tim-bell"},{"value":0,"_account_id":9098,"name":"Nathan Kinder","email":"nkinder@redhat.com","username":"nkinder"},{"value":1,"date":"2015-08-13 18:00:11.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},{"value":0,"_account_id":6482,"name":"Steve Martinelli","email":"s.martinelli@gmail.com","username":"stevemar"},{"value":1,"date":"2015-08-12 13:03:00.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},{"value":0,"_account_id":7063,"name":"Robert Clark","email":"hyakuhei@gmail.com","username":"hyakuhei"},{"value":0,"_account_id":7575,"name":"Sabari","email":"smurugesan@vmware.com","username":"sabari"},{"value":0,"_account_id":13914,"name":"Darren J Moffat","email":"darren.moffat@oracle.com","username":"darrenmoffat"},{"value":0,"_account_id":11356,"name":"Louis Taylor","email":"louis@kragniz.eu","username":"kragniz"},{"value":2,"date":"2015-08-25 14:12:53.000000000","_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},{"value":1,"date":"2015-08-12 12:48:41.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":15524,"name":"dane-fichter","email":"dane.fichter@jhuapl.edu","username":"dane-fichter"},{"value":0,"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},{"value":2,"date":"2015-08-26 15:46:51.000000000","_account_id":2537,"name":"Nikhil Komawar","email":"nik.komawar@gmail.com","username":"nikhil-komawar"},{"value":0,"_account_id":2218,"name":"Adam Young","email":"adam@younglogic.com","username":"ayoung"},{"value":0,"_account_id":15022,"name":"dane-fichter","email":"Dane.Fichter@JHUAPL.EDU"},{"value":0,"_account_id":6896,"name":"Loganathan Parthipan","email":"parthi@hpe.com","username":"parthipan"},{"value":1,"date":"2015-08-24 20:07:57.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},{"value":0,"_account_id":8119,"name":"Eric Brown","email":"eric_wade_brown@yahoo.com","username":"ericwb"},{"value":0,"_account_id":11642,"name":"Jesse J. Cook","email":"jesse.cook@rackspace.com","username":"crashenx"},{"value":0,"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},{"value":1,"date":"2015-08-20 00:55:28.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","value":1,"default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":2537,"name":"Nikhil Komawar","email":"nik.komawar@gmail.com","username":"nikhil-komawar"},"all":[{"value":0,"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},{"value":0,"_account_id":3,"name":"Jenkins","username":"jenkins"},{"value":0,"_account_id":8004,"name":"Paul Kehrer","email":"paul.l.kehrer@gmail.com","username":"reaperhulk"},{"value":0,"_account_id":4,"name":"Dolph Mathews","email":"dolph.mathews@gmail.com","username":"dolph"},{"value":0,"_account_id":455,"name":"Stuart McLaren","email":"stuart.mclaren@hpe.com","username":"stuart-mclaren"},{"value":0,"_account_id":136,"name":"Tim Bell","email":"tim.bell@cern.ch","username":"tim-bell"},{"value":0,"_account_id":9098,"name":"Nathan Kinder","email":"nkinder@redhat.com","username":"nkinder"},{"value":0,"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},{"value":0,"_account_id":6482,"name":"Steve Martinelli","email":"s.martinelli@gmail.com","username":"stevemar"},{"value":0,"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},{"value":0,"_account_id":7063,"name":"Robert Clark","email":"hyakuhei@gmail.com","username":"hyakuhei"},{"value":0,"_account_id":7575,"name":"Sabari","email":"smurugesan@vmware.com","username":"sabari"},{"value":0,"_account_id":13914,"name":"Darren J Moffat","email":"darren.moffat@oracle.com","username":"darrenmoffat"},{"value":0,"_account_id":11356,"name":"Louis Taylor","email":"louis@kragniz.eu","username":"kragniz"},{"value":0,"_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},{"value":0,"_account_id":15524,"name":"dane-fichter","email":"dane.fichter@jhuapl.edu","username":"dane-fichter"},{"value":0,"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},{"value":1,"date":"2015-08-26 15:46:51.000000000","_account_id":2537,"name":"Nikhil Komawar","email":"nik.komawar@gmail.com","username":"nikhil-komawar"},{"value":0,"_account_id":2218,"name":"Adam Young","email":"adam@younglogic.com","username":"ayoung"},{"value":0,"_account_id":15022,"name":"dane-fichter","email":"Dane.Fichter@JHUAPL.EDU"},{"value":0,"_account_id":6896,"name":"Loganathan Parthipan","email":"parthi@hpe.com","username":"parthipan"},{"value":0,"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},{"value":0,"_account_id":8119,"name":"Eric Brown","email":"eric_wade_brown@yahoo.com","username":"ericwb"},{"value":0,"_account_id":11642,"name":"Jesse J. Cook","email":"jesse.cook@rackspace.com","username":"crashenx"},{"value":0,"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},{"value":0,"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":3,"name":"Jenkins","username":"jenkins"},{"_account_id":4,"name":"Dolph Mathews","email":"dolph.mathews@gmail.com","username":"dolph"},{"_account_id":136,"name":"Tim Bell","email":"tim.bell@cern.ch","username":"tim-bell"},{"_account_id":455,"name":"Stuart McLaren","email":"stuart.mclaren@hpe.com","username":"stuart-mclaren"},{"_account_id":2218,"name":"Adam Young","email":"adam@younglogic.com","username":"ayoung"},{"_account_id":2537,"name":"Nikhil Komawar","email":"nik.komawar@gmail.com","username":"nikhil-komawar"},{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},{"_account_id":6482,"name":"Steve Martinelli","email":"s.martinelli@gmail.com","username":"stevemar"},{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},{"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},{"_account_id":6896,"name":"Loganathan Parthipan","email":"parthi@hpe.com","username":"parthipan"},{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},{"_account_id":7063,"name":"Robert Clark","email":"hyakuhei@gmail.com","username":"hyakuhei"},{"_account_id":7575,"name":"Sabari","email":"smurugesan@vmware.com","username":"sabari"},{"_account_id":8004,"name":"Paul Kehrer","email":"paul.l.kehrer@gmail.com","username":"reaperhulk"},{"_account_id":8119,"name":"Eric Brown","email":"eric_wade_brown@yahoo.com","username":"ericwb"},{"_account_id":9098,"name":"Nathan Kinder","email":"nkinder@redhat.com","username":"nkinder"},{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},{"_account_id":11356,"name":"Louis Taylor","email":"louis@kragniz.eu","username":"kragniz"},{"_account_id":11642,"name":"Jesse J. Cook","email":"jesse.cook@rackspace.com","username":"crashenx"},{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},{"_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},{"_account_id":13914,"name":"Darren J Moffat","email":"darren.moffat@oracle.com","username":"darrenmoffat"},{"_account_id":15022,"name":"dane-fichter","email":"Dane.Fichter@JHUAPL.EDU"},{"_account_id":15524,"name":"dane-fichter","email":"dane.fichter@jhuapl.edu","username":"dane-fichter"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2015-04-27 19:50:08.000000000","updated_by":{"_account_id":4,"name":"Dolph Mathews","email":"dolph.mathews@gmail.com","username":"dolph"},"reviewer":{"_account_id":4,"name":"Dolph Mathews","email":"dolph.mathews@gmail.com","username":"dolph"},"state":"REVIEWER"},{"updated":"2015-04-27 19:50:16.000000000","updated_by":{"_account_id":6482,"name":"Steve Martinelli","email":"s.martinelli@gmail.com","username":"stevemar"},"reviewer":{"_account_id":6482,"name":"Steve Martinelli","email":"s.martinelli@gmail.com","username":"stevemar"},"state":"REVIEWER"},{"updated":"2015-04-27 19:50:34.000000000","updated_by":{"_account_id":15022,"name":"dane-fichter","email":"Dane.Fichter@JHUAPL.EDU"},"reviewer":{"_account_id":15022,"name":"dane-fichter","email":"Dane.Fichter@JHUAPL.EDU"},"state":"REVIEWER"},{"updated":"2015-04-28 20:01:43.000000000","updated_by":{"_account_id":2218,"name":"Adam Young","email":"adam@younglogic.com","username":"ayoung"},"reviewer":{"_account_id":2218,"name":"Adam Young","email":"adam@younglogic.com","username":"ayoung"},"state":"REVIEWER"},{"updated":"2015-05-01 13:38:23.000000000","updated_by":{"_account_id":9098,"name":"Nathan Kinder","email":"nkinder@redhat.com","username":"nkinder"},"reviewer":{"_account_id":9098,"name":"Nathan Kinder","email":"nkinder@redhat.com","username":"nkinder"},"state":"REVIEWER"},{"updated":"2015-05-01 13:49:36.000000000","updated_by":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"reviewer":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"state":"REVIEWER"},{"updated":"2015-05-19 14:49:42.000000000","updated_by":{"_account_id":7063,"name":"Robert Clark","email":"hyakuhei@gmail.com","username":"hyakuhei"},"reviewer":{"_account_id":7063,"name":"Robert Clark","email":"hyakuhei@gmail.com","username":"hyakuhei"},"state":"REVIEWER"},{"updated":"2015-05-19 14:59:14.000000000","updated_by":{"_account_id":8119,"name":"Eric Brown","email":"eric_wade_brown@yahoo.com","username":"ericwb"},"reviewer":{"_account_id":8119,"name":"Eric Brown","email":"eric_wade_brown@yahoo.com","username":"ericwb"},"state":"REVIEWER"},{"updated":"2015-05-20 00:05:06.000000000","updated_by":{"_account_id":7575,"name":"Sabari","email":"smurugesan@vmware.com","username":"sabari"},"reviewer":{"_account_id":7575,"name":"Sabari","email":"smurugesan@vmware.com","username":"sabari"},"state":"REVIEWER"},{"updated":"2015-05-21 00:14:44.000000000","updated_by":{"_account_id":11356,"name":"Louis Taylor","email":"louis@kragniz.eu","username":"kragniz"},"reviewer":{"_account_id":11356,"name":"Louis Taylor","email":"louis@kragniz.eu","username":"kragniz"},"state":"REVIEWER"},{"updated":"2015-05-24 15:47:18.000000000","updated_by":{"_account_id":136,"name":"Tim Bell","email":"tim.bell@cern.ch","username":"tim-bell"},"reviewer":{"_account_id":136,"name":"Tim Bell","email":"tim.bell@cern.ch","username":"tim-bell"},"state":"REVIEWER"},{"updated":"2015-06-03 12:51:24.000000000","updated_by":{"_account_id":6896,"name":"Loganathan Parthipan","email":"parthi@hpe.com","username":"parthipan"},"reviewer":{"_account_id":6896,"name":"Loganathan Parthipan","email":"parthi@hpe.com","username":"parthipan"},"state":"REVIEWER"},{"updated":"2015-06-03 15:29:58.000000000","updated_by":{"_account_id":13914,"name":"Darren J Moffat","email":"darren.moffat@oracle.com","username":"darrenmoffat"},"reviewer":{"_account_id":13914,"name":"Darren J Moffat","email":"darren.moffat@oracle.com","username":"darrenmoffat"},"state":"REVIEWER"},{"updated":"2015-06-14 19:36:52.000000000","updated_by":{"_account_id":8004,"name":"Paul Kehrer","email":"paul.l.kehrer@gmail.com","username":"reaperhulk"},"reviewer":{"_account_id":8004,"name":"Paul Kehrer","email":"paul.l.kehrer@gmail.com","username":"reaperhulk"},"state":"REVIEWER"},{"updated":"2015-08-11 19:52:48.000000000","updated_by":{"_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},"reviewer":{"_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},"state":"REVIEWER"},{"updated":"2015-08-12 12:48:41.000000000","updated_by":{"_account_id":15524,"name":"dane-fichter","email":"dane.fichter@jhuapl.edu","username":"dane-fichter"},"reviewer":{"_account_id":15524,"name":"dane-fichter","email":"dane.fichter@jhuapl.edu","username":"dane-fichter"},"state":"REVIEWER"},{"updated":"2015-08-12 13:03:00.000000000","updated_by":{"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},"reviewer":{"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},"state":"REVIEWER"},{"updated":"2015-08-12 13:05:40.000000000","updated_by":{"_account_id":455,"name":"Stuart McLaren","email":"stuart.mclaren@hpe.com","username":"stuart-mclaren"},"reviewer":{"_account_id":455,"name":"Stuart McLaren","email":"stuart.mclaren@hpe.com","username":"stuart-mclaren"},"state":"REVIEWER"},{"updated":"2015-08-12 14:51:12.000000000","updated_by":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"reviewer":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"state":"REVIEWER"},{"updated":"2015-08-13 18:00:11.000000000","updated_by":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"reviewer":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"state":"REVIEWER"},{"updated":"2015-08-19 23:10:28.000000000","updated_by":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"reviewer":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"state":"REVIEWER"},{"updated":"2015-08-20 00:55:28.000000000","updated_by":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"reviewer":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"state":"REVIEWER"},{"updated":"2015-08-22 01:39:52.000000000","updated_by":{"_account_id":11642,"name":"Jesse J. Cook","email":"jesse.cook@rackspace.com","username":"crashenx"},"reviewer":{"_account_id":11642,"name":"Jesse J. Cook","email":"jesse.cook@rackspace.com","username":"crashenx"},"state":"REVIEWER"},{"updated":"2015-08-26 15:46:51.000000000","updated_by":{"_account_id":2537,"name":"Nikhil Komawar","email":"nik.komawar@gmail.com","username":"nikhil-komawar"},"reviewer":{"_account_id":2537,"name":"Nikhil Komawar","email":"nik.komawar@gmail.com","username":"nikhil-komawar"},"state":"REVIEWER"},{"updated":"2015-08-26 15:50:40.000000000","updated_by":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"reviewer":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"state":"REVIEWER"}],"messages":[{"id":"911ae9947e340caedd8a62e261aed665fe15fb4d","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-04-27 19:48:36.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"d4cf16968c595b41e31c76eac09a5655c43339ee","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-04-27 20:17:59.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"353f106fe9fa3e55fdc5604e956166e9136cac38","author":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"date":"2015-04-28 04:51:04.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\n\n- gate-glance-specs-docs http://docs-draft.openstack.org/48/177948/2/check/gate-glance-specs-docs/d1cebe3//doc/build/html/ : SUCCESS in 2m 44s\n- gate-glance-specs-python27 http://logs.openstack.org/48/177948/2/check/gate-glance-specs-python27/fb2ea4e/ : SUCCESS in 2m 41s","accounts_in_message":[],"_revision_number":2},{"id":"9e8c22cdf3b28219b9ffc89947e7971fec3cd04b","author":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"date":"2015-04-30 15:45:39.000000000","message":"Patch Set 2: Code-Review+1","accounts_in_message":[],"_revision_number":2},{"id":"8f9f20ba5b535725999eebf8dc8c047d8799fcc6","author":{"_account_id":15524,"name":"dane-fichter","email":"dane.fichter@jhuapl.edu","username":"dane-fichter"},"date":"2015-04-30 15:59:30.000000000","message":"Patch Set 2: Code-Review+1","accounts_in_message":[],"_revision_number":2},{"id":"73279b50c6bd38b0bd9c248acf397cbe36d6dcda","author":{"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},"date":"2015-05-08 17:23:54.000000000","message":"Patch Set 2:\n\n(2 comments)\n\nBrianna, this looks very good.  I have two nit suggestions if you need to create a patch update anyway.","accounts_in_message":[],"_revision_number":2},{"id":"002149223c12b63c7a4a266a1f553eb766578521","author":{"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},"date":"2015-05-19 14:40:04.000000000","message":"Patch Set 2: Code-Review+1","accounts_in_message":[],"_revision_number":2},{"id":"db0ecc6e468bbf0f139aecf30497acfe9c108f34","author":{"_account_id":7063,"name":"Robert Clark","email":"hyakuhei@gmail.com","username":"hyakuhei"},"date":"2015-05-19 14:49:42.000000000","message":"Patch Set 2: Code-Review+1","accounts_in_message":[],"_revision_number":2},{"id":"17d6dcd562f35010534cf782c3f845451af95edc","author":{"_account_id":8119,"name":"Eric Brown","email":"eric_wade_brown@yahoo.com","username":"ericwb"},"date":"2015-05-19 14:59:14.000000000","message":"Patch Set 2:\n\n(2 comments)","accounts_in_message":[],"_revision_number":2},{"id":"814d976f1515b4fc322b12ff4053f4427195c153","author":{"_account_id":13914,"name":"Darren J Moffat","email":"darren.moffat@oracle.com","username":"darrenmoffat"},"date":"2015-05-19 16:07:02.000000000","message":"Patch Set 2: Code-Review+1\n\n(2 comments)","accounts_in_message":[],"_revision_number":2},{"id":"411a1d9dc8898be9b8505f1186c6fc1f05e2587c","author":{"_account_id":8119,"name":"Eric Brown","email":"eric_wade_brown@yahoo.com","username":"ericwb"},"date":"2015-05-20 00:09:37.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"c98eac0c0aedf7e553283abb16fb12ad32347779","author":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"date":"2015-05-20 02:16:42.000000000","message":"Patch Set 2:\n\n(2 comments)","accounts_in_message":[],"_revision_number":2},{"id":"81ed33ef6733025d41ed8fae791ac3149332dfef","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-05-20 05:44:17.000000000","message":"Patch Set 2:\n\n(3 comments)","accounts_in_message":[],"_revision_number":2},{"id":"711302d0a3829b8f0cb75c6fa0f318736146f11a","author":{"_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},"date":"2015-05-22 01:24:30.000000000","message":"Patch Set 2: Code-Review+1\n\n(5 comments)","accounts_in_message":[],"_revision_number":2},{"id":"25aacd69eb559b1c944f601a32b20376d1bc59ee","author":{"_account_id":136,"name":"Tim Bell","email":"tim.bell@cern.ch","username":"tim-bell"},"date":"2015-05-24 15:52:07.000000000","message":"Patch Set 2: Code-Review+1\n\n(1 comment)\n\nWithin cloud federations, this is a very interesting feature for multi-clouds.","accounts_in_message":[],"_revision_number":2},{"id":"9a1f3099c003c49c0f8c1675f9da3c4653cbcfe4","author":{"_account_id":455,"name":"Stuart McLaren","email":"stuart.mclaren@hpe.com","username":"stuart-mclaren"},"date":"2015-05-26 15:25:00.000000000","message":"Patch Set 2:\n\n@Tim\n\nYou beat me to it.\n\nIf you have just Cloud A, then trusting some parts of that cloud but not others (ie not trusting glance, but trusting nova) is sort of interesting.\n\nBut if you have Cloud A as an image source, and cloud B consuming images from Cloud A (and potentially becoming a source for the image itself), then you are isolating Cloud B (and other consuming clouds) from any part of Cloud A being compromised. And we can check for \u0027bad clouds\u0027 publishing malware ie verify that image X really does come from vendor Y (eg Debian/Ubuntu/SAP etc).\n\nIf appropriate, I\u0027d be interested in seeing updates to the spec to consider the cross-cloud side of this.","accounts_in_message":[],"_revision_number":2},{"id":"93e7efc6197cfb0c2370dc6670b21779e7bb9deb","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-06-02 16:02:18.000000000","message":"Patch Set 2:\n\n(4 comments)\n\nI\u0027ve added a few minor updates in the upcoming patch, including adding the two Core Reviewers and noting that the existing MD5 hash of the image data will be used (instead of creating a new one).","accounts_in_message":[],"_revision_number":2},{"id":"a175259e1fe7ac8a3cb881d5b85d2a4103cd84d3","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-06-02 16:02:50.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"4701b9863d20ba7c2738595b8bdf7abcb2d312b1","author":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"date":"2015-06-02 16:44:39.000000000","message":"Patch Set 3: Verified+1\n\nBuild succeeded (check pipeline).\n\n- gate-glance-specs-docs http://docs-draft.openstack.org/48/177948/3/check/gate-glance-specs-docs/8c4b4d6//doc/build/html/ : SUCCESS in 2m 06s\n- gate-glance-specs-python27 http://logs.openstack.org/48/177948/3/check/gate-glance-specs-python27/4d59acc/ : SUCCESS in 1m 47s","accounts_in_message":[],"_revision_number":3},{"id":"3960a27064815a94db22474705a3397ea0d3092d","author":{"_account_id":15524,"name":"dane-fichter","email":"dane.fichter@jhuapl.edu","username":"dane-fichter"},"date":"2015-06-02 17:33:55.000000000","message":"Patch Set 3: Code-Review+1","accounts_in_message":[],"_revision_number":3},{"id":"dcb3ef4e34ae38c5221e6c831e747d1dd459617c","author":{"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},"date":"2015-06-02 17:53:46.000000000","message":"Patch Set 3: Code-Review+1","accounts_in_message":[],"_revision_number":3},{"id":"5969a43ba4367e25b125b7d3bb8223c42f359095","author":{"_account_id":6896,"name":"Loganathan Parthipan","email":"parthi@hpe.com","username":"parthipan"},"date":"2015-06-03 12:51:24.000000000","message":"Patch Set 3: Code-Review+1","accounts_in_message":[],"_revision_number":3},{"id":"77b362a15c2d90d5888e04c467e7394fe22240a9","author":{"_account_id":13914,"name":"Darren J Moffat","email":"darren.moffat@oracle.com","username":"darrenmoffat"},"date":"2015-06-03 15:29:58.000000000","message":"Patch Set 3: Code-Review-1\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"1b6161c0e46110eb79564fc7775d43dc7f738923","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-06-03 15:36:56.000000000","message":"Patch Set 3:\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"5781a1d91fac41a7908b087ed9af1fed06a9c0d9","author":{"_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},"date":"2015-06-05 14:58:31.000000000","message":"Patch Set 3: Code-Review+1\n\n(1 comment)\n\nI\u0027m very very much in favor of this, but I want to give it one more read over before giving it a +2. Thanks Brianna!","accounts_in_message":[],"_revision_number":3},{"id":"d7c04ccf17ed29283dea692af0fdd4d535166f81","author":{"_account_id":13914,"name":"Darren J Moffat","email":"darren.moffat@oracle.com","username":"darrenmoffat"},"date":"2015-06-05 15:10:38.000000000","message":"Patch Set 3:\n\nI disagree with the assertion that this work and making the hash something other than MD5 are separable.  Glance using MD5 as a \"this hasn\u0027t been corrupted\" checksum is fine.  However using MD5 as the basis for a security assertion using a cryptographic signature is not.\n\nI do agree that this blueprint doesn\u0027t need to be the one to make the checksum/hash configurable per say but it does depend on it and it must not use MD5 as the basis of a cryptographic signature. I really don\u0027t want to see a case were we end up with an RSA-MD5 signature it should be RSA-SHA256 or an Elliptic Curve + SHA256 signature.  Or something else equivalently strong.","accounts_in_message":[],"_revision_number":3},{"id":"62bf29dba82970001898aea2d0a3c59dee3c539e","author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"date":"2015-06-08 17:33:49.000000000","message":"Patch Set 3: Code-Review-1\n\n(5 comments)\n\nI think you should define the formats for the signature blocks and the keys.","accounts_in_message":[],"_revision_number":3},{"id":"4ba275c5e8d71f71f02efa5f8fafaf48aeb9a485","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-06-10 13:52:39.000000000","message":"Patch Set 3:\n\n(5 comments)\n\nThank you for the feedback, Nate.","accounts_in_message":[],"_revision_number":3},{"id":"9bd39f82b7b2c8c0b7dc3596b6e641520f1e0ed8","author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"date":"2015-06-12 19:51:08.000000000","message":"Patch Set 3:\n\n(3 comments)\n\nOne last big item is the format of the signature block. Other than that most everything else looks pretty good to me. This is going to be a cool feature.","accounts_in_message":[],"_revision_number":3},{"id":"d1b6fca99a228f8fbe8f5a5f99cdf395106d8ac9","author":{"_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},"date":"2015-06-14 04:14:34.000000000","message":"Patch Set 3:\n\nNote that https://review.openstack.org/191542 is going to address the checksum problem.","accounts_in_message":[],"_revision_number":3},{"id":"b475182de08303deef913249ec030d0d666475fe","author":{"_account_id":8004,"name":"Paul Kehrer","email":"paul.l.kehrer@gmail.com","username":"reaperhulk"},"date":"2015-06-14 19:36:52.000000000","message":"Patch Set 3:\n\n(2 comments)","accounts_in_message":[],"_revision_number":3},{"id":"0ad4270eb68c1bddb0fb59b19da8422e52df584c","author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"date":"2015-06-14 22:04:25.000000000","message":"Patch Set 3:\n\nI\u0027m lvh; I\u0027m a cryptographer at Rackspace. I agree that this is a very\nimportant feature, and would like to lend my assistance in any way\npossible. First off, thanks for all of you for working on this,\nespecially Brianna for putting the base text together. I have some\nobservations I believe will lead to issues down the line, and would\nlike to provide a solution for them.\n\nFirstly, we\u0027ve been discussing tiny aspects of cryptosystems. PKCSv15,\nRSA, MD5, SHA-256, elliptic curves... have all come up in this\ndiscussion. What we\u0027re trying to accomplish is a complete\nauthenticated encryption system. It\u0027s fairly easy to take some of the\n\"broken\" components we\u0027ve discussed (like MD5) to produce secure\nsystems (HMAC-MD5 is still a secure MAC, hence why I put \"broken\" in\nquotes). It is also quite easy to take perfectly serviceable\ncomponents like RSA and produce insecure cryptosystems (like\nRSA+PKCSv15, which I believe was suggested at one point during the\ndiscussion, or, even worse, textbook RSA).\n\nTrying to design such a complete, secure cryptosystem is highly\ncomplex and specialized work. Unless the specific kind of cryptosystem\nyou need doesn\u0027t exist (and this one does), I would strongly recommend\nagainst it. To illustrate this difficulty, this standard doesn\u0027t\nappear to address how to encrypt those images. The only encryption\nprimitives that have been mentioned so far is RSA, but you can\u0027t just\nuse RSA to encrypt a large disk image (you\u0027re limited at least to the\nsize of the modulus), so now we have to define a symmetric\nauthenticated encryption system, and a way to encode those symmetric\nkeys in the ciphertext... Oy vey!\n\nSecondly, we\u0027ve been discussing algorithmic agility. It\u0027s a very\ntempting idea for a variety of reasons, including the main one here:\n\"we don\u0027t have to solve *this* problem right now, we can solve it\nlater\". That\u0027s a fine reason, but I\u0027d caution against it; many a\ncryptosystem has been plagued by algorithmic agility. Not just in the\nspecific case of \"some of the crypto is weak\", like TLS\u0027 export grade\nciphersuites, but also in modern standards where the developers didn\u0027t\nimagine that suite would ever get chosen under those circumstances,\nlike with the JWT token spec. While the idea of signing a hash is\nperfectly sound, the obvious attack requires collision resistance,\nwhich MD5 doesn\u0027t have. (As noted above, just because MD5 is insecure,\ndoesn\u0027t necessarily mean that replacing it solves your problem.)\n\nAs I\u0027m sure you\u0027ve discovered, this information can be very hard to\nfind. If you\u0027d like to learn more about cryptography to satisfy your\npersonal curiosity, I\u0027m writing a book called Crypto 101, which is\nfreely available: https://www.crypto101.io.\n\nI\u0027d like to make the following concrete suggestions:\n\n- As my learned colleague Paul Kehrer has pointed out, if it does\n  become necessary to build our own from basic components,\n  pyca/cryptography is a better choice than PyCrypto is.\n\n- Could we use libsodium\u0027s API? It satisfies all of the requirements\n  in this document so far, and also provides a highly efficient\n  encryption API that doesn\u0027t have the issues addressed above.\n\nI look forward to hearing from you, contributing to this, and seeing\nthis awesome feature land in Glance :-)","accounts_in_message":[],"_revision_number":3},{"id":"69c57ffa5c2546be3412d5a12d8a22ae88d2fe4a","author":{"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},"date":"2015-06-18 22:08:30.000000000","message":"Patch Set 3: -Code-Review\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"b68e66912f13e976c03d4cd26d8a5e0e63f60d51","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-06-19 22:38:09.000000000","message":"Patch Set 3:\n\n(3 comments)\n\nThank you for the feedback and comments, they are much appreciated.\n\nI have included updates to address the comments in the upcoming spec.\n\n@lvh -- The updated spec will reference cryptography instead of pycrypto.  I hesitate to use libsodium because it is not yet used elsewhere in openstack (I didn\u0027t see it in openstack/requirements).  I also appreciate the reference to Crypto 101 -- it is good to know that such a resource is available.","accounts_in_message":[],"_revision_number":3},{"id":"f55c1c9a167a64e7c378c53f90224db5859467d2","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-06-19 22:42:58.000000000","message":"Uploaded patch set 4.","accounts_in_message":[],"_revision_number":4},{"id":"3de4fbd72b2427d3df1a5ea857428043ea37ed29","author":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"date":"2015-06-19 22:50:35.000000000","message":"Patch Set 4: Verified+1\n\nBuild succeeded (check pipeline).\n\n- gate-glance-specs-docs http://docs-draft.openstack.org/48/177948/4/check/gate-glance-specs-docs/7bbcbed//doc/build/html/ : SUCCESS in 2m 40s\n- gate-glance-specs-python27 http://logs.openstack.org/48/177948/4/check/gate-glance-specs-python27/29b737e/ : SUCCESS in 1m 53s","accounts_in_message":[],"_revision_number":4},{"id":"23ca937d74b09202a694201b65458a2fe4834d35","author":{"_account_id":15524,"name":"dane-fichter","email":"dane.fichter@jhuapl.edu","username":"dane-fichter"},"date":"2015-06-22 15:29:31.000000000","message":"Patch Set 4: Code-Review+1","accounts_in_message":[],"_revision_number":4},{"id":"5dfa43a74cbaba8653af083cb0bafbe22a7ecd66","author":{"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},"date":"2015-06-22 15:42:06.000000000","message":"Patch Set 4: Code-Review+1","accounts_in_message":[],"_revision_number":4},{"id":"8c9f0cc7c7aacfa729c76eb06f8057b87fb4d2a7","author":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"date":"2015-06-22 22:33:50.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"df85f60471c903a638f63f9dcdd0ca7c0cb48370","author":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"date":"2015-06-22 22:34:45.000000000","message":"Uploaded patch set 5.","accounts_in_message":[],"_revision_number":5},{"id":"45766c441acd5fd0e25fb6209bae581d2a893a33","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-06-22 22:38:40.000000000","message":"Patch Set 4:\n\n(1 comment)","accounts_in_message":[],"_revision_number":4},{"id":"8f63a6c21fddd3786ad95431b1a804eddcf4e2d9","author":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"date":"2015-06-22 22:43:43.000000000","message":"Patch Set 5: Verified+1\n\nBuild succeeded (check pipeline).\n\n- gate-glance-specs-docs http://docs-draft.openstack.org/48/177948/5/check/gate-glance-specs-docs/918d1df//doc/build/html/ : SUCCESS in 2m 40s\n- gate-glance-specs-python27 http://logs.openstack.org/48/177948/5/check/gate-glance-specs-python27/d135b96/ : SUCCESS in 2m 20s","accounts_in_message":[],"_revision_number":5},{"id":"7c79d76d3447ea044bee2c7166274ecdbee0e9fa","author":{"_account_id":15524,"name":"dane-fichter","email":"dane.fichter@jhuapl.edu","username":"dane-fichter"},"date":"2015-06-23 12:48:24.000000000","message":"Patch Set 5: Code-Review+1","accounts_in_message":[],"_revision_number":5},{"id":"525fc2f477b6b21ae846a7e24e0baedfe82dc44f","author":{"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},"date":"2015-06-23 15:34:51.000000000","message":"Patch Set 5: Code-Review+1","accounts_in_message":[],"_revision_number":5},{"id":"17844f0cea6d248d077a0662d2a480f39f30101d","author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"date":"2015-06-24 04:10:53.000000000","message":"Patch Set 5:\n\nThanks for your continued efforts, Brianna!\n\nFrom a cryptographic perspective, the answer is emphatically \"depend on libsodium\". I would be more than happy to make the necessary changes to pyca/cryptography to support libsodium if that\u0027s what enables this project to be libsodium-powered.\n\nWhile \"do something with RSA\" is not the best cryptographic answer, I do want this project to end up with reasonable cryptographic options. Therefore, if libsodium is a complete non-starter, I will design an asymmetric cryptosystem a-la Fernet (but with RSA keys instead of the usual symmetric key) so that you can continue with just pyca/cryptography+libssl.","accounts_in_message":[],"_revision_number":5},{"id":"d076666853756a5293883b4aed4fe4edf605c231","author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"date":"2015-06-29 19:48:54.000000000","message":"Patch Set 5: Code-Review-1\n\n(1 comment)","accounts_in_message":[],"_revision_number":5},{"id":"846018541d75ed2940d39df11f32c477dbadde8c","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-07-06 17:08:38.000000000","message":"Patch Set 5:\n\n(1 comment)","accounts_in_message":[],"_revision_number":5},{"id":"ae176930bb03d9d2c7ec3fee53c88fe28780cb7c","author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"date":"2015-07-06 23:33:43.000000000","message":"Patch Set 5: Code-Review-1\n\nThe discussion around PSS somewhat further highlights my concern. While PSS is the \"right answer\" if you want RSA signatures, judging by the requirements, encrypting the secret key is a better approach. This is how most similar systems (like GPG, and, arguably, like TLS without PFS) work.\n\nAgain, if you\u0027d like me to develop an off-the-shelf thing that does what you want and isn\u0027t libsodium, I\u0027d be more than happy to do so; but only if libsodium is actually a non-starter :)","accounts_in_message":[],"_revision_number":5},{"id":"521bd4d4f686ab829900251c89fe138ae21e1ca4","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-07-07 20:35:51.000000000","message":"Patch Set 5:\n\n@lvh: Thank you for your feedback.  One of the main reasons to use an asymmetric key pair for the signature is so that Glance is able to verify the signature but unable to create a signature of its own (in a situation where Glance is not trusted).  I do however agree that having a symmetric key is preferable for encrypted images (in which case Glance never needs access to the encryption key, only Nova needs access when the image is decrypted before boot).\n\nAs for using libsodium, my main hesitation is that no one else in OpenStack is currently using it.","accounts_in_message":[],"_revision_number":5},{"id":"c4dce16468185b84f5c4970275b20f8174fd0370","author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"date":"2015-07-07 20:55:37.000000000","message":"Patch Set 5:\n\nI believe I wasn\u0027t clear, my apologies.\n\nThe way this works is that you use a symmetric system to encrypt/authenticate, and then *asymmetrically* encrypt the relevant keys for relevant recipients. That can include just an authentication key, or both an encryption and an authentication key.","accounts_in_message":[],"_revision_number":5},{"id":"affc43d228dad4af07737785648ad819c7ae13cc","author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"date":"2015-07-07 20:56:08.000000000","message":"Patch Set 5:\n\nTo clarify: the external interface would only involve asymmetric keys; I am suggesting that internally, it should use symmetric keys.","accounts_in_message":[],"_revision_number":5},{"id":"5f58920c9b0c2de2acbb9d23195d65cbfe7b211a","author":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"date":"2015-07-21 15:51:40.000000000","message":"Patch Set 5: Code-Review+1\n\n(2 comments)","accounts_in_message":[],"_revision_number":5},{"id":"3792bb9eea7df3b28e4cb10d8888e4725ea32949","author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"date":"2015-07-21 21:57:29.000000000","message":"Patch Set 5:\n\n(1 comment)","accounts_in_message":[],"_revision_number":5},{"id":"69c56cc61ab8613d3df0d2395916f3315e44e01d","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-07-29 03:54:10.000000000","message":"Uploaded patch set 6.","accounts_in_message":[],"_revision_number":6},{"id":"b78134cd7e903e5c0884ec5f1b53b6632301705f","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-07-29 03:58:04.000000000","message":"Patch Set 5:\n\n(1 comment)\n\nThe latest patch set is in response to the glance mid-cycle meet-up discussion on 2015.07.28, and includes clarification of the following:\n\n1. Removal of the mention of encryption.\n2. Adding nikhil as a reviewer.\n3. Using certificates instead of the public key directly.\n4. A comment about using key-value pairs for now, with possibly CMS in the future.","accounts_in_message":[],"_revision_number":5},{"id":"518bce2838c375d03fb11af0c9bc1f34c6ca9ba7","author":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"date":"2015-07-29 05:16:45.000000000","message":"Patch Set 6: Verified+1\n\nBuild succeeded (check pipeline).\n\n- gate-glance-specs-docs http://docs-draft.openstack.org/48/177948/6/check/gate-glance-specs-docs/02c8bfa//doc/build/html/ : SUCCESS in 2m 41s\n- gate-glance-specs-python27 http://logs.openstack.org/48/177948/6/check/gate-glance-specs-python27/c5de059/ : SUCCESS in 2m 26s","accounts_in_message":[],"_revision_number":6},{"id":"709e7dbbe3f11e695ab60c61aec657824b5550db","author":{"_account_id":15524,"name":"dane-fichter","email":"dane.fichter@jhuapl.edu","username":"dane-fichter"},"date":"2015-07-29 12:44:43.000000000","message":"Patch Set 6: Code-Review+1","accounts_in_message":[],"_revision_number":6},{"id":"e806325114aa7ad95475f22926873e327bce3d00","author":{"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},"date":"2015-07-29 12:58:50.000000000","message":"Patch Set 6: Code-Review+1","accounts_in_message":[],"_revision_number":6},{"id":"b5e55706a1947059adf1ad5a49f3b221e6aafd59","author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"date":"2015-08-03 14:24:54.000000000","message":"Patch Set 6:\n\nThanks for working on this! I\u0027ll be traveling today, and will be reviewing the draft on the way.","accounts_in_message":[],"_revision_number":6},{"id":"85f4e5c76513737fc452dfbb1ef5423778fc2117","author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"date":"2015-08-06 03:56:08.000000000","message":"Patch Set 6:\n\n(4 comments)\n\nI think this is on the right track.  There are a few grammar things and a question inline.","accounts_in_message":[],"_revision_number":6},{"id":"0d7c46b843ea20678f258e19a5c5201239209579","author":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"date":"2015-08-06 20:26:32.000000000","message":"Patch Set 6: Code-Review+1\n\n(3 comments)","accounts_in_message":[],"_revision_number":6},{"id":"b747634c05c79fe224e9c04e5affe56119bad0b6","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-08-06 22:03:27.000000000","message":"Patch Set 6:\n\n(7 comments)\n\nThank you for the review and comments, Joel \u0026 Brian!  Modifications included in upcoming patch.","accounts_in_message":[],"_revision_number":6},{"id":"0d6ba8f76463735e4ffa77a502a20ebbe79a38a4","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-08-06 22:03:42.000000000","message":"Uploaded patch set 7.","accounts_in_message":[],"_revision_number":7},{"id":"268f16c72a182d99f3b1063f834bafb03f829218","author":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"date":"2015-08-06 22:06:56.000000000","message":"Patch Set 7: Verified+1\n\nBuild succeeded (check pipeline).\n\n- gate-glance-specs-docs http://docs-draft.openstack.org/48/177948/7/check/gate-glance-specs-docs/344e5c9//doc/build/html/ : SUCCESS in 2m 52s\n- gate-glance-specs-python27 http://logs.openstack.org/48/177948/7/check/gate-glance-specs-python27/4658376/ : SUCCESS in 2m 35s","accounts_in_message":[],"_revision_number":7},{"id":"d7df2ab82a4adc47070c7179a3c2ca8b3a53faa8","author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"date":"2015-08-07 20:37:32.000000000","message":"Patch Set 7: Code-Review-1\n\n(8 comments)\n\nThanks for your continued efforts on this, Brianna! I think this spec is moving in the right direction. Reducing scope to just signing is a big improvement from a complexity standpoint.\n\nI still have several cryptographic concerns, which I\u0027ve submitted as inline comments.","accounts_in_message":[],"_revision_number":7},{"id":"67dfcbda7e08fba03e01f93b5c406ff22c2cdb62","author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"date":"2015-08-07 20:39:24.000000000","message":"Patch Set 7:\n\nAs a generic question: how do we prevent lying by omission? Whoever the verifier ends up being (and it\u0027s looking like Nova, I suppose) would need to be told by whoever it\u0027s acting as the agent for (the end user, presumably) that it should insist on signatures.","accounts_in_message":[],"_revision_number":7},{"id":"ff8701c9e6701869a25c6c4ed837945b01278848","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-08-07 21:16:18.000000000","message":"Patch Set 7:\n\n(7 comments)\n\n@lvh -- Thank you for all of your comments and feedback!  I have replied to each of your comments, and feel free to comment back if I didn\u0027t address your concerns.\n\nRegarding the lying by omission, the plan is to allow the user to indicate that a particular image must be signed in order to boot it, and when the user indicates this, if the image does not have signature metadata and thus nova cannot verify the signature, nova won\u0027t boot the image.  This is mentioned in the partner nova spec at https://review.openstack.org/#/c/188874/.","accounts_in_message":[],"_revision_number":7},{"id":"adfdb265436e4e204d4a3064a224f977d86d2b0a","author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"date":"2015-08-08 00:21:26.000000000","message":"Patch Set 7:\n\n(8 comments)\n\nThanks for your continued efforts and patience :)\n\nI\u0027ve added more comments in line. I think this is mostly good to go; depending on where the exact format of the signature is specified.\n\nI\u0027ll take a look at the Nova spec. In the offline messes-with-Glance threat model we\u0027re considering, marking an image as signed isn\u0027t sufficient; you need to give Nova a trust root, too. Otherwise, Mallory just messes with the image, and then replaces the (key, signature) pair with their own.","accounts_in_message":[],"_revision_number":7},{"id":"b4645fd136e134f2638fded963dde9929059006b","author":{"_account_id":455,"name":"Stuart McLaren","email":"stuart.mclaren@hpe.com","username":"stuart-mclaren"},"date":"2015-08-10 13:37:41.000000000","message":"Patch Set 7:\n\n@Brianna \n\nI\u0027m trying to understand the behaviour in a glance-only (no nova) download scenario.\n\nImagine a user signs an image and uploads it via Glance into Cloud X. They have previously uploaded a cert to Cloud X\u0027s key manager (I assume the key manager referred to in the spec is one which is \u0027owned\u0027 by the same cloud). They set the image\u0027s cert reference metadata to point to the relevant certificate.\n\nIf they later come to download the image bytes is it the case that they will have to assume/trust that the Cloud has extracted the original cert correctly? eg that the cloud has not both maliciously set the cert reference to point to another cert and updated the signature?\n\nI\u0027m trying to distinguish between this and an alternative where the user would not have to assume the cloud used a legitimate cert/unchanged signature. Eg ff the cert is provided directly by the user to the client then the user can know for sure that the desired cert is being used to verify the signature (in this simple glance-only use case the certificate would never be sent to the cloud). This would be a little bit analogous to referencing a local TLS CA cert via --os-cacert.","accounts_in_message":[],"_revision_number":7},{"id":"ea0afa037127601d8555fd246734f324a9c137e1","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-08-10 21:04:01.000000000","message":"Patch Set 7:\n\n(5 comments)\n\n@lvh -- Thank you for your continued feedback.  I have responded to many of your comments in-line.\n\nRegarding the Nova trust root comment, part of the trust in this proposal is in the Certificate Authority that is tied to the key manager.  We trust this CA to only allow the creation of certificates by trusted people.  If an attacker is able to create a valid certificate, then the attacker can modify the signature and certificate reference, and modify the image data without us knowing.\n\n@Stuart\nSimilar to what I mentioned above, you are correct in assuming we are trusting that the certificate is valid, if we retrieve it from the key manager without issue, and the key manager still considers it valid.\n\nFor the time being, we will log the reference for the certificate used to verify the signature, and a user can also retrieve the certificate from the key manager directly using the certificate reference to confirm that it is the desired certificate.","accounts_in_message":[],"_revision_number":7},{"id":"2bf7ad78fcf80da6528d40a0b64838f053062bda","author":{"_account_id":15524,"name":"dane-fichter","email":"dane.fichter@jhuapl.edu","username":"dane-fichter"},"date":"2015-08-11 12:38:04.000000000","message":"Patch Set 7: Code-Review+1","accounts_in_message":[],"_revision_number":7},{"id":"ca2c261159e08dd85bdf90df6b9aedc07ab757a4","author":{"_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},"date":"2015-08-11 15:09:35.000000000","message":"Patch Set 7: Code-Review+1\n\nI think there are some nits from Laurens that Brianna mentioned she was going to fix up, but once that\u0027s done I\u0027m +2 on this.\n\n@Stuart, re \"eg that the cloud has not both maliciously set the cert reference to point to another cert and updated the signature?\" if we are thinking that a cloud provider is malicious that kind of throws any and every threat model for using an OpenStack cloud out the window.","accounts_in_message":[],"_revision_number":7},{"id":"6371eca7b1d5ff45d85c592d83202553553e7954","author":{"_account_id":455,"name":"Stuart McLaren","email":"stuart.mclaren@hpe.com","username":"stuart-mclaren"},"date":"2015-08-11 15:38:49.000000000","message":"Patch Set 7:\n\n@Ian\n\n\u003e re \"eg that the cloud has not both maliciously set the cert reference to point to another cert and updated the signature?\" if we are thinking that a cloud provider is malicious that kind of throws any and every threat model for using an OpenStack cloud out the window.\n\nI was thinking about the analogy of verification of the server\u0027s SSL cert (note: I\u0027m not talking here about the \u0027cert\u0027 mentioned in the spec, but the cert associated with the glance https URL). That happens on the client (\"where I can see it\") rather than inside the cloud. So I don\u0027t have to trust the cloud to tell me its https cert is legit. I was wondering if it would be possible to do something equivalent for the image/signature. You are likely to have the cert (now the \u0027cert\u0027 mentioned in the spec) lying around, and if you were paranoid, you could optionally pass your local copy of the cert to the client to have the signature verified \"where you can see it\" when you download, rather than having to trust the cloud. I may be off in the woods here, but I\u0027m interested to know -- from those who know more than I do -- whether having the option to do this is would be totally pointless or not.","accounts_in_message":[],"_revision_number":7},{"id":"abb70a0ece3d08e94cc49e8a4e15a519d429fcbe","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-08-11 19:48:58.000000000","message":"Uploaded patch set 8.","accounts_in_message":[],"_revision_number":8},{"id":"ff01b2244109444afc82abbdf72e9ac53895f798","author":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"date":"2015-08-11 19:51:57.000000000","message":"Patch Set 8: Verified+1\n\nBuild succeeded (check pipeline).\n\n- gate-glance-specs-docs http://docs-draft.openstack.org/48/177948/8/check/gate-glance-specs-docs/16d59a9//doc/build/html/ : SUCCESS in 2m 47s\n- gate-glance-specs-python27 http://logs.openstack.org/48/177948/8/check/gate-glance-specs-python27/92be2e0/ : SUCCESS in 2m 25s","accounts_in_message":[],"_revision_number":8},{"id":"5696d0c65c5d3d43db5e0cfa0b68d0c086873279","author":{"_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},"date":"2015-08-11 19:52:48.000000000","message":"Patch Set 8:\n\nStuart I don\u0027t think it\u0027s totally pointless, I just don\u0027t think it\u0027s necessary for this to be accepted at the moment since the primary consumer, in the eyes of this spec, is Nova. I can see a separate spec being proposed for the client to this kind of verification. That said, I suspect that if you know how to sign an image and you have the cert easily available, you could do the verification sans the glanceclient right now.","accounts_in_message":[],"_revision_number":8},{"id":"05edd0f844b125291df02b0148967ee66aa02d4f","author":{"_account_id":15524,"name":"dane-fichter","email":"dane.fichter@jhuapl.edu","username":"dane-fichter"},"date":"2015-08-12 12:48:41.000000000","message":"Patch Set 8: Code-Review+1","accounts_in_message":[],"_revision_number":8},{"id":"288a439199ff6b86da42bfe98eaf873c749fd3ff","author":{"_account_id":6804,"name":"bruce-benjamin","email":"bruce.benjamin@jhuapl.edu","username":"bruce-benjamin"},"date":"2015-08-12 13:03:00.000000000","message":"Patch Set 8: Code-Review+1","accounts_in_message":[],"_revision_number":8},{"id":"8127b987f5e2d80849784e369631d4593ba7bfed","author":{"_account_id":455,"name":"Stuart McLaren","email":"stuart.mclaren@hpe.com","username":"stuart-mclaren"},"date":"2015-08-12 13:05:40.000000000","message":"Patch Set 8: Code-Review+2\n\n@Ian\n\nThanks. Good to know I (roughly) understand things.\n\n\nI\u0027m hoping we\u0027re at a point where we have pretty good consensus on things and should be able to make a start on implementation.\n\nQuick query: Will users know that signature verification is supported/has happened? eg if they set the relevant params on a cloud running the existing code they will just be ignored. Will it just be a case of inferring support from the advertised API version (2.x)?","accounts_in_message":[],"_revision_number":8},{"id":"6a14160e7316477244982f9d5173febe05900ee3","author":{"_account_id":5314,"name":"Brian Rosmaita","email":"rosmaita.fossdev@gmail.com","username":"brian-rosmaita"},"date":"2015-08-12 14:51:12.000000000","message":"Patch Set 8: Code-Review+1\n\n(2 comments)\n\nI\u0027ve got a question inline about error conditions.  Just want to make sure there\u0027s really no API change on this, and then I\u0027m +2.\n\nBrianna, with regard to Stuart\u0027s most recent question above, my impression was that the verification on the glance side is simply a convenience for the user doing the uploading, so that they\u0027ll know right away if, e.g., they gave a reference to the wrong certificate, or specified the signature for some other image.  So the presence of signature-related image properties on an image doesn\u0027t tell an image consumer anything about the image, and also don\u0027t guarantee that, e.g., nova will treat the image in any special way (unless the consumer has independent knowledge that the deployment they\u0027re working in is set up to verify the image before using it).","accounts_in_message":[],"_revision_number":8},{"id":"fc41c3efc071ce4022f1504f18f926121849088e","author":{"_account_id":455,"name":"Stuart McLaren","email":"stuart.mclaren@hpe.com","username":"stuart-mclaren"},"date":"2015-08-12 15:16:56.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"6e7a456135b975a243df10abcc14160c49a02306","author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"date":"2015-08-13 13:21:18.000000000","message":"Patch Set 8: Code-Review-1\n\n(3 comments)","accounts_in_message":[],"_revision_number":8},{"id":"85061bcd19f147c584e6b4baa99c4e201aa57cba","author":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"date":"2015-08-13 18:00:11.000000000","message":"Patch Set 8: Code-Review+1\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"941cee3ec29e97542f9c5d4bc029881817ed5378","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-08-19 15:11:19.000000000","message":"Patch Set 8:\n\n(6 comments)","accounts_in_message":[],"_revision_number":8},{"id":"0d24293453ff1e23875c372b8ba8850822dc037e","author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"date":"2015-08-19 16:51:55.000000000","message":"Patch Set 8:\n\n(2 comments)","accounts_in_message":[],"_revision_number":8},{"id":"fb7056b2955cbeddf9fc4e36640b4eb8a11df7e9","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-08-19 19:41:15.000000000","message":"Patch Set 8:\n\n(3 comments)\n\n@Paul and @lvh\n\nI would like to get your input.  Currently, cryptography does not support doing the hash and the signature verification/creation separately (https://github.com/pyca/cryptography/issues/1648).\n\nIn order to use cryptography, the signature would need to be of the image checksum hash, rather than of the image checksum data, which is non-intuitive and has the potential to be confusing.\n\nIt may be preferable to use pycrypto for the moment, since it allows the hash creation separately, and use cryptography instead as soon as this support is added.","accounts_in_message":[],"_revision_number":8},{"id":"eeefedb57f5615ad0a6506ef0d2f64bd09907356","author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"date":"2015-08-19 23:10:28.000000000","message":"Patch Set 8:\n\nHi Brianna,\n\n\n\u003e In order to use cryptography, the signature would need to be of the image checksum hash, rather than of the image checksum data, which is non-intuitive and has the potential to be confusing.\n\nIn this context, image checksum data is the checksum itself (the MD5 currently already in Glance), and hash would be the hash of that, correct?\n\nSome thoughts:\n\nThe RSAPSS standard describes going from an arbitrary-length octet string M to a signature EM. The scheme that skips the initial hash isn\u0027t in the spec, which is why pyca/cryptography doesn\u0027t expose that API.  Because PSS is defined that way, and often people have a hash to sign, signing hashes is fairly common.\n\nIt would make sense to expose that API to allow for compatibility with frankenspecs like Chef\u0027s thing (mentioned in the ticket), but I am hesitant to put new such specs into the world.\n\nI feel sidestepping the initial hashing step in PSS would be _more_ confusing than just signing the hash, as the latter is PSS, and the former is not. cryptography not exposing the former is just a side-effect of that.\n\nI strongly recommend against using PyCrypto in all cases, as does the project\u0027s author. Hopefully my previous argument renders the point moot anyway, since there\u0027s no more reason not to use cryptography :-)\n\nTL;DR: I think signing the checksum is fine, where \"the checksum\" is \"the thing Glance currently stores, an MD5 digest of the image\", and \"signing\" means RSAPSS w/ MGF1-SHA1 \u0026 SHA256. Doing the MD5 -\u003e SHA256 extension is a little weird, but that\u0027s what the configurable hash spec is for.\n\nHopefully I got all of the moving Glance parts right!\n\n\nThanks for your continued efforts,\nlvh","accounts_in_message":[],"_revision_number":8},{"id":"286cda670e8bbb50582b491d324ef2c29223a130","author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"date":"2015-08-20 00:55:28.000000000","message":"Patch Set 8: Code-Review+1\n\n@lvh can you further explain the PSS argument? I think what Brianna wants to do is give the precomputed hash of the image (aka checksum) to cryptography for signing instead of calling update to recompute the hash. It seems like PSS should support this. The spec as found here, http://www.emc.com/emc-plus/rsa-labs/historical/raising-standard-rsa-signatures-rsa-pss.htm, shows that the first step is compute the hash of the message. In our case this will be checksum. Thus it seems like if we can provide that to cryptography then it should be able to run with that and generate a signature.\n\nThe function in the spec is S \u003d SigPrim (private key, Transform (Hash (M))). It seems like I should be able to give a precomputed hash to have it signed to short-circuit all of the update calls. Plus pycrypto provides this, so it also seems possible. But maybe I am missing something.\n\nOn a related note, I think from a user\u0027s perspective it is more intuitive to expect that an image signature will be Signature \u003d SigPrim(hash(image)) where S is some signature algorithm. I think SigPrim(hash(hash(image))) is not as intuitive. I think user\u0027s will question why they need to do the extra hash function. What would we tell them?","accounts_in_message":[],"_revision_number":8},{"id":"00686cb5fa7264117dda53fc161690a656e67d10","author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"date":"2015-08-20 04:15:31.000000000","message":"Patch Set 8:\n\nThe article you linked describes how RSA-PSS /works/, which is distinct from how it is intended to be used. The formula you cited also describes textbook RSA signing and PKCS#1v15.\n\nThe specification for PSS is PKCS#1, the current version of which is available here: https://www.emc.com/collateral/white-papers/h11300-pkcs-1v2-2-rsa-cryptography-standard-wp.pdf\n\nThe distinction between external and internal interface is much clearer in this document; they are in different sections. When I referred to PSS being defined as a function between messages of arbitrary length M and signatures EM, I was referring to the canonical definition of RSASA-PSS on page 27 of that document.\n\nPyCrypto provides this as an accidental consequence of its implementation. Because PyCrypto implements all of its cryptographic primitives from scratch (one of the many reasons why both I and its author are saying you should not use it anymore), these APIs are directly available. This is, alas, not the only footgun PyCrypto exposes.\n\nThis of course doesn\u0027t invalidate what you said about the first step being to hash the input message; that\u0027s certainly true. There are a number of pros and cons in skipping that first step:\n\n- As I mentioned before, signing hashes is the norm in other tools. This is what GPG\u0027s file signing feature does, for example. I can only guess what user\u0027s intuition will be, although my guess is that \"PSS an already well-defined string\" is perfectly acceptable.\n- I\u0027m not sure how many people will be writing implementations for this, and hence, how valid the \"implementor-friendly\" argument is. For the set of people that are doing it, I think saying that you\u0027re going to sign the already-extant Glance checksum is perfectly clear. If you\u0027re going to write a signer/verifier, you\u0027re going to have to read the spec. Intuitive is better than counter-intuitive, but specs are better than hunches.\n- Working under the assumption that ease of implementation /is/ important, using part-of-PSS (even if you incidentally end up doing all of PSS because of another operation you did previously) instead of actual-PSS makes it harder for third parties to implement the algorithm using tools that actually implement the PSS spec, as is evidenced by cryptography not exposing the API. Notably, anyone using OpenSSL will have to delve significantly deeper into its ichory heart to successfully compute or verify a signature.\n- Using a hash makes it easier to sign other features of the Glance image, like metadata, later. You can continue updating an existing hash using fixation, but this API is also not widely implemented outside of cryptanalytic tools, because usually the only people who care about fixation are the people trying to break your crypto. For that reason, the SHA-3 era the option of doing fixation/length-extension is considered a security flaw, and is no longer possible in SHA-3-era hashes, like SHA-3 or BLAKE2.\n- Implementation difficulties are exacerbated by the fact that the checksum hash is mutable, and, in particular, MD5. Signing an arbitrary string with RSASSA-PSS \u0026 MGF-SHA1 \u0026 SHA1 is easy; it\u0027s the default as per the specification. Using a modern signature scheme like PSS with an outdated hash like MD5, to wit, something I can\u0027t recall an instance of, to wit.\n- Page 50 of the aforementioned official spec specifically recommends against MD2 and MD5. The literature doesn\u0027t conclusively demonstrate that PSS with MD5 directly is worse than MD5 -\u003e SHA1 (i.e. what just using PSS on the checksum would be), but extrapolating from other cryptanalytic advances in RSA, using PSS to sign the hash, instead of skipping the hashing step because you already have an MD5 digest lying around, is a prudent idea.\n\nIn conclusion, I don\u0027t think skipping the initial hash part of PSS is more intuitive, I think it\u0027s objectively harder on implementers (pyca/cryptography\u0027s lack of this API being evidence of this), and it might be a worse security choice. Therefore, I think RSAPSS-MGF1-SHA1, the default RSAPSS configuration, applied to the checksum glance already produces, is a fine choice.\n\n\nhth\nlvh","accounts_in_message":[],"_revision_number":8},{"id":"3093ded375f2d1af72ca018eca9de51a9919985d","author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"date":"2015-08-20 04:18:25.000000000","message":"Patch Set 8:\n\nI forgot to mention the possible pros:\n\n\n- Some people are suggesting it is more intuitive. (As mentioned above, I disagree.)\n- It is faster, because it involves one less hash. Given that we\u0027re talking about 32 bytes being hashed through a hash that\u0027s 5 cpb or faster, and hence we\u0027re talking less than 200 cycles, I don\u0027t think that\u0027s a good reason.\n\n(I don\u0027t mean to set up a straw-man here -- I realize no-one has made the performance arugment. I\u0027m playing advocate of the devil, and losing ;-))\n\n\nhth\nlvh","accounts_in_message":[],"_revision_number":8},{"id":"29f1187ae6d513c6d4b9cca3a45bf0e7beb4fd9c","author":{"_account_id":455,"name":"Stuart McLaren","email":"stuart.mclaren@hpe.com","username":"stuart-mclaren"},"date":"2015-08-20 14:44:43.000000000","message":"Patch Set 8:\n\n(1 comment)","accounts_in_message":[],"_revision_number":8},{"id":"178b977f6b0c2632c52e9d76c0ae4b8731eaf376","author":{"_account_id":11642,"name":"Jesse J. Cook","email":"jesse.cook@rackspace.com","username":"crashenx"},"date":"2015-08-22 01:39:52.000000000","message":"Patch Set 8:\n\nFeel free to /slap me since I haven\u0027t read the spec yet, but I wanted to share this super cool thing I learned today that seemed relevant and efficient:\n\n|| denotes concatenation\n\n1) Calculate: hash_function(Secret Key || Image || Secret Key) \u003d H0\n2) Send: Image || H0\n3) Retrieve Later: Image || H0\n4) Calculate: hash_function(Secret Key || Image || Secret Key) \u003d H1\n5) Compare: H0 \u003d\u003d H1 then authentic\n\nSource: Computer Security Principled and Practice 3E William Stallings\n\nNotice, no encryption....and you\u0027re probably using a library to basically do just this...but pretty neat huh?","accounts_in_message":[],"_revision_number":8},{"id":"7a418a319afed8a547f91e7c5a3aaf2ca1538761","author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"date":"2015-08-24 00:16:36.000000000","message":"Patch Set 8:\n\nHi Jesse,\n\n\nUnfortunately, that doesn\u0027t quite work.\n\n1) What you\u0027re describing is a MAC, not a signing algorithm. Specifically, the difference is that this uses a single secret key. As highlighted in the spec, this isn\u0027t what we want: we want verifiers and signers to use different keys part of a key pair.\n\n2) The MAC you are describing isn\u0027t the greatest. It\u0027s better than prefix-MAC (H(s || m)) because it\u0027s not vulnerable to extension. It is also better than just suffix-MAC (H(m || s)), because arbitrary collisions in H can\u0027t be extended to collisions in the MAC. This is particularly concerning for MD5, as MD5 has known collision attacks, particularly chosen prefix collision attacks. However, the construction you suggested, often called sandwich MAC, has seen some interesting cryptanalytic advances. While it does have a similar security proof to HMAC (in that the underlying hash function has to be a PRF, but not collision resistant), that proof suggests that the real-world requirements are quite different. Consequently, the state of the art (Sasaki \u0026 Wang, published in SAC2013) is a full key recovery attack against Sandwich-MD5, resulting in arbitrary forgeries. Unfortunately I was not able to find a freely available version of that paper; but it is available from IECIE \u0026 Springer.\n\nUnfortunately, as you\u0027ve discovered, bad advice is easy to find. Since you\u0027re interested in cryptography, you may want to consider https://www.crypto101.io/ -- I\u0027m writing a free book aimed at programmers to teach notions of cryptography. The short version is: consider HMAC, or libsodium\u0027s secretbox (Poly1305). For purposes of this spec, I still think you could do a lot worse than RSASSA-PSS.\n\n\nrespectfully,\nlvh","accounts_in_message":[],"_revision_number":8},{"id":"7c03f6baebe4fb1ea2c5c4b4d4edadf1d7bf2b44","author":{"_account_id":6783,"name":"Nathan Reller","email":"nathan.s.reller@gmail.com","username":"rellerreller"},"date":"2015-08-24 19:42:41.000000000","message":"Patch Set 8:\n\nI spoke with a few crypto experts here. They all agree without hesitation that signing the hash of the image is the best approach. This crow tastes delicious :)","accounts_in_message":[],"_revision_number":8},{"id":"84ea59a99251df474049845a1e00a8ef65c7b524","author":{"_account_id":11829,"name":"Laurens Van Houtven","email":"_@lvh.io","username":"lvh"},"date":"2015-08-24 20:07:57.000000000","message":"Patch Set 8: Code-Review+1\n\n@Nathan: Don\u0027t worry about it; I\u0027ll take discussion over fake consensus any day. Thanks again so much for your continued efforts on this spec, I understand how much work it is and deeply appreciate it :)","accounts_in_message":[],"_revision_number":8},{"id":"39145554c8b297579230708a43c6c6d48532245f","author":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"date":"2015-08-24 20:20:02.000000000","message":"Patch Set 8:\n\n(1 comment)\n\n@lvh: Thank you again for your continued feedback and support.\n\nAlthough this discussion has brought us right back to where we started, I think it has been valuable to flesh out exactly what this approach (and by \"this approach\" I mean signing the \"checksum hash\") is, and to agree that such an approach is legitimate.","accounts_in_message":[],"_revision_number":8},{"id":"0a0bdf8a7d3db32c70f763e3aa94317a9385cce3","author":{"_account_id":11642,"name":"Jesse J. Cook","email":"jesse.cook@rackspace.com","username":"crashenx"},"date":"2015-08-25 13:24:55.000000000","message":"Patch Set 8:\n\nI guess I shouldn\u0027t be surprised that full key recovery is possible. I wonder if it is brute force. Thanks lvh. It\u0027s only the first week of the security class, so wonder if this paper is covered later.\n\nI\u0027ll avoid any more advice and maybe save the review for after I complete the class ;)","accounts_in_message":[],"_revision_number":8},{"id":"e61bdbb544f7ba04e373bc4f425c4ef9fc3a3643","author":{"_account_id":12000,"name":"Ian Cordasco","email":"sigmavirus24@gmail.com","username":"sigmavirus24"},"date":"2015-08-25 14:12:53.000000000","message":"Patch Set 8: Code-Review+2","accounts_in_message":[],"_revision_number":8},{"id":"67d88d2c22bdfa921aa064ae2a15c869c232c920","author":{"_account_id":2537,"name":"Nikhil Komawar","email":"nik.komawar@gmail.com","username":"nikhil-komawar"},"date":"2015-08-26 15:46:51.000000000","message":"Patch Set 8: Code-Review+2 Workflow+1","accounts_in_message":[],"_revision_number":8},{"id":"16f57bc522c69447e88aef8a1caeb41a239ec5e9","author":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"date":"2015-08-26 15:47:07.000000000","message":"Patch Set 8: -Verified\n\nStarting gate jobs.\nhttp://status.openstack.org/zuul/","accounts_in_message":[],"_revision_number":8},{"id":"dbc62bd3da7efc686b80174262cdfd2628168d68","author":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"date":"2015-08-26 15:50:40.000000000","message":"Patch Set 8: Verified+2\n\nBuild succeeded (gate pipeline).\n\n- gate-glance-specs-docs http://docs-draft.openstack.org/48/177948/8/gate/gate-glance-specs-docs/b6ee464//doc/build/html/ : SUCCESS in 2m 06s\n- gate-glance-specs-python27 http://logs.openstack.org/48/177948/8/gate/gate-glance-specs-python27/33d7ed8/ : SUCCESS in 2m 52s","accounts_in_message":[],"_revision_number":8},{"id":"d3c4d13fe9fe31dfb3bec1cafa6217d26fea7a28","author":{"_account_id":3,"name":"Jenkins","username":"jenkins"},"date":"2015-08-26 15:50:45.000000000","message":"Change has been successfully merged into the git repository.","accounts_in_message":[],"_revision_number":8}],"current_revision_number":8,"current_revision":"4a35f198f8e27c41bda9528589f40b8464f7d69d","revisions":{"c4780d443ccd67e518de7eac688b2858c2281dae":{"kind":"REWORK","_number":1,"created":"2015-04-27 19:48:36.000000000","uploader":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"ref":"refs/changes/48/177948/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance-specs","ref":"refs/changes/48/177948/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/1"}}},"commit":{"parents":[{"commit":"c6b0603a3df2748afc5f08e10d81c32a03882d41","subject":"Liberty spec folder for tracking specs proposed","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/c6b0603a3df2748afc5f08e10d81c32a03882d41"}]}],"author":{"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","date":"2015-04-27 19:35:51.000000000","tz":-240},"committer":{"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","date":"2015-04-27 19:43:07.000000000","tz":-240},"subject":"Encrypted and Authenticated Image Support","message":"Encrypted and Authenticated Image Support\n\nThis spec describes a means to support signing and signature\nvalidation of bootable images, along with encrypted images.\n\nDocImpact\nSecurityImpact\n\nImplements: blueprint encrypted-and-authenticated-image-support\nChange-Id: I305b2ae86415c8d256c641abb2795af663bee56a\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/c4780d443ccd67e518de7eac688b2858c2281dae"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/c4780d443ccd67e518de7eac688b2858c2281dae"}]},"branch":"refs/heads/master"},"9aca39aef7cfa73639776166375ddf035e55f14a":{"kind":"REWORK","_number":2,"created":"2015-04-27 20:17:59.000000000","uploader":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"ref":"refs/changes/48/177948/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance-specs","ref":"refs/changes/48/177948/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/2"}}},"commit":{"parents":[{"commit":"c6b0603a3df2748afc5f08e10d81c32a03882d41","subject":"Liberty spec folder for tracking specs proposed","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/c6b0603a3df2748afc5f08e10d81c32a03882d41"}]}],"author":{"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","date":"2015-04-27 19:35:51.000000000","tz":-240},"committer":{"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","date":"2015-04-27 20:17:03.000000000","tz":-240},"subject":"Encrypted and Authenticated Image Support","message":"Encrypted and Authenticated Image Support\n\nThis spec describes a means to support signing and signature\nvalidation of bootable images, along with encrypted images.\n\nDocImpact\nSecurityImpact\n\nImplements: blueprint encrypted-and-authenticated-image-support\nChange-Id: I305b2ae86415c8d256c641abb2795af663bee56a\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/9aca39aef7cfa73639776166375ddf035e55f14a"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/9aca39aef7cfa73639776166375ddf035e55f14a"}]},"branch":"refs/heads/master"},"fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50":{"kind":"REWORK","_number":3,"created":"2015-06-02 16:02:50.000000000","uploader":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"ref":"refs/changes/48/177948/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance-specs","ref":"refs/changes/48/177948/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/3"}}},"commit":{"parents":[{"commit":"a9001fce652d1008de415103bd7d17c45d67046c","subject":"Enable indexing for Kilo\u0027s specs","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/a9001fce652d1008de415103bd7d17c45d67046c"}]}],"author":{"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","date":"2015-04-27 19:35:51.000000000","tz":-240},"committer":{"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","date":"2015-06-02 15:56:49.000000000","tz":-240},"subject":"Encrypted and Authenticated Image Support","message":"Encrypted and Authenticated Image Support\n\nThis spec describes a means to support signing and signature\nvalidation of bootable images, along with encrypted images.\n\nDocImpact\nSecurityImpact\n\nImplements: blueprint encrypted-and-authenticated-image-support\nChange-Id: I305b2ae86415c8d256c641abb2795af663bee56a\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/fe7e82208a48a1b3ed5f5a9ce66c4d7ebe928b50"}]},"branch":"refs/heads/master"},"c1fe7ca32aaadba74dfea65e9562ad01342435d9":{"kind":"REWORK","_number":4,"created":"2015-06-19 22:42:58.000000000","uploader":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"ref":"refs/changes/48/177948/4","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance-specs","ref":"refs/changes/48/177948/4","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/4"}}},"commit":{"parents":[{"commit":"a9001fce652d1008de415103bd7d17c45d67046c","subject":"Enable indexing for Kilo\u0027s specs","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/a9001fce652d1008de415103bd7d17c45d67046c"}]}],"author":{"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","date":"2015-04-27 19:35:51.000000000","tz":-240},"committer":{"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","date":"2015-06-19 22:42:25.000000000","tz":-240},"subject":"Encrypted and Authenticated Image Support","message":"Encrypted and Authenticated Image Support\n\nThis spec describes a means to support signing and signature\nvalidation of bootable images, along with encrypted images.\n\nDocImpact\nSecurityImpact\n\nImplements: blueprint encrypted-and-authenticated-image-support\nChange-Id: I305b2ae86415c8d256c641abb2795af663bee56a\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/c1fe7ca32aaadba74dfea65e9562ad01342435d9"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/c1fe7ca32aaadba74dfea65e9562ad01342435d9"}]},"branch":"refs/heads/master"},"730d2cf196b47ca4ab4a12c4766649f8836e591c":{"kind":"REWORK","_number":5,"created":"2015-06-22 22:34:45.000000000","uploader":{"_account_id":6802,"name":"Joel Coffman","email":"jmc7tp@gmail.com","username":"joel-coffman"},"ref":"refs/changes/48/177948/5","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance-specs","ref":"refs/changes/48/177948/5","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/5"}}},"commit":{"parents":[{"commit":"a9001fce652d1008de415103bd7d17c45d67046c","subject":"Enable indexing for Kilo\u0027s specs","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/a9001fce652d1008de415103bd7d17c45d67046c"}]}],"author":{"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","date":"2015-04-27 19:35:51.000000000","tz":-240},"committer":{"name":"Joel Coffman","email":"joel.coffman@jhuapl.edu","date":"2015-06-22 22:35:12.000000000","tz":-240},"subject":"Encrypted and Authenticated Image Support","message":"Encrypted and Authenticated Image Support\n\nThis spec describes a means to support signing and signature\nvalidation of bootable images, along with encrypted images.\n\nDocImpact\nSecurityImpact\n\nImplements: blueprint encrypted-and-authenticated-image-support\nChange-Id: I305b2ae86415c8d256c641abb2795af663bee56a\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/730d2cf196b47ca4ab4a12c4766649f8836e591c"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/730d2cf196b47ca4ab4a12c4766649f8836e591c"}]},"branch":"refs/heads/master"},"88036d33cd5e5c4fae24aeb5e6fac5393a2523fe":{"kind":"REWORK","_number":6,"created":"2015-07-29 03:54:10.000000000","uploader":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"ref":"refs/changes/48/177948/6","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance-specs","ref":"refs/changes/48/177948/6","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/6"}}},"commit":{"parents":[{"commit":"9bdec1f6ef860dfee41a3092704faf3d2d0cf179","subject":"Merge \"Remove custom glance client SSL handling\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/9bdec1f6ef860dfee41a3092704faf3d2d0cf179"}]}],"author":{"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","date":"2015-04-27 19:35:51.000000000","tz":-240},"committer":{"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","date":"2015-07-29 03:54:40.000000000","tz":-240},"subject":"Image Signing and Verification Support","message":"Image Signing and Verification Support\n\nThis spec describes a means to support signing and signature\nvalidation of bootable images.\n\nDocImpact\nSecurityImpact\n\nImplements: blueprint encrypted-and-authenticated-image-support\nChange-Id: I305b2ae86415c8d256c641abb2795af663bee56a\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/88036d33cd5e5c4fae24aeb5e6fac5393a2523fe"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/88036d33cd5e5c4fae24aeb5e6fac5393a2523fe"}]},"branch":"refs/heads/master"},"17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1":{"kind":"REWORK","_number":7,"created":"2015-08-06 22:03:42.000000000","uploader":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"ref":"refs/changes/48/177948/7","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance-specs","ref":"refs/changes/48/177948/7","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/7"}}},"commit":{"parents":[{"commit":"dbf1df09eadbea2103af65ac394b7b7a34abd793","subject":"Merge \"HealthCheck Middleware\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/dbf1df09eadbea2103af65ac394b7b7a34abd793"}]}],"author":{"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","date":"2015-04-27 19:35:51.000000000","tz":-240},"committer":{"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","date":"2015-08-06 21:59:25.000000000","tz":-240},"subject":"Image Signing and Verification Support","message":"Image Signing and Verification Support\n\nThis spec describes a means to support signing and signature\nvalidation of bootable images.\n\nDocImpact\nSecurityImpact\n\nImplements: blueprint image-signing-and-verification-support\nChange-Id: I305b2ae86415c8d256c641abb2795af663bee56a\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/17eda5ab4e2b1dcc54f2d1a7956b471542bd75f1"}]},"branch":"refs/heads/master"},"4a35f198f8e27c41bda9528589f40b8464f7d69d":{"kind":"REWORK","_number":8,"created":"2015-08-11 19:48:58.000000000","uploader":{"_account_id":7012,"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","username":"brianna-poulos"},"ref":"refs/changes/48/177948/8","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/glance-specs","ref":"refs/changes/48/177948/8","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/8 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/8 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/8 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/glance-specs refs/changes/48/177948/8"}}},"commit":{"parents":[{"commit":"dbf1df09eadbea2103af65ac394b7b7a34abd793","subject":"Merge \"HealthCheck Middleware\"","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/dbf1df09eadbea2103af65ac394b7b7a34abd793"}]}],"author":{"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","date":"2015-04-27 19:35:51.000000000","tz":-240},"committer":{"name":"Brianna Poulos","email":"Brianna.Poulos@jhuapl.edu","date":"2015-08-11 19:46:37.000000000","tz":-240},"subject":"Image Signing and Verification Support","message":"Image Signing and Verification Support\n\nThis spec describes a means to support signing and signature\nvalidation of bootable images.\n\nDocImpact\nSecurityImpact\n\nImplements: blueprint image-signing-and-verification-support\nChange-Id: I305b2ae86415c8d256c641abb2795af663bee56a\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/4a35f198f8e27c41bda9528589f40b8464f7d69d"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/glance-specs/commit/4a35f198f8e27c41bda9528589f40b8464f7d69d"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
