)]}'
{"id":"openstack%2Fsecurity-doc~788278","triplet_id":"openstack%2Fsecurity-doc~master~I8c4eaaa42262797632ce4c4296c04a4fe62b8fcf","project":"openstack/security-doc","branch":"master","hashtags":[],"change_id":"I8c4eaaa42262797632ce4c4296c04a4fe62b8fcf","subject":"Fix Barbican PKCS#11 description","status":"MERGED","created":"2021-04-27 12:34:15.000000000","updated":"2021-05-19 15:31:52.000000000","submitted":"2021-05-19 15:30:36.000000000","submitter":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"total_comment_count":3,"unresolved_comment_count":3,"has_review_started":true,"submission_id":"788278","meta_rev_id":"863843b5e5192fab1f66a8e92a71ac1cc5c63bb6","_number":788278,"virtual_id_number":788278,"owner":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"actions":{},"labels":{"Verified":{"approved":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"all":[{"value":0,"_account_id":6547,"name":"Andreas Jaeger","email":"jaegerandi@gmail.com","username":"jaegerandi"},{"tag":"autogenerated:zuul:gate","value":2,"date":"2021-05-19 15:30:35.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Fails","-1":"Doesn\u0027t seem to work"," 0":"No score","+1":"Works for me","+2":"Verified"},"description":"","default_value":0,"optional":true},"Code-Review":{"approved":{"_account_id":6547,"name":"Andreas Jaeger","email":"jaegerandi@gmail.com","username":"jaegerandi"},"all":[{"value":2,"date":"2021-05-19 15:24:38.000000000","permitted_voting_range":{"min":2,"max":2},"_account_id":6547,"name":"Andreas Jaeger","email":"jaegerandi@gmail.com","username":"jaegerandi"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-2":"Do not merge","-1":"This patch needs further work before it can be merged"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me (core reviewer)"},"description":"","default_value":0,"optional":true},"Workflow":{"approved":{"_account_id":6547,"name":"Andreas Jaeger","email":"jaegerandi@gmail.com","username":"jaegerandi"},"all":[{"value":1,"date":"2021-05-19 15:24:38.000000000","permitted_voting_range":{"min":1,"max":1},"_account_id":6547,"name":"Andreas Jaeger","email":"jaegerandi@gmail.com","username":"jaegerandi"},{"value":0,"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}],"values":{"-1":"Work in progress"," 0":"Ready for reviews","+1":"Approved"},"description":"","default_value":0,"optional":true}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":6547,"name":"Andreas Jaeger","email":"jaegerandi@gmail.com","username":"jaegerandi"},{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2021-04-27 12:43:03.000000000","updated_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"reviewer":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"state":"REVIEWER"},{"updated":"2021-04-27 15:46:19.000000000","updated_by":{"_account_id":6547,"name":"Andreas Jaeger","email":"jaegerandi@gmail.com","username":"jaegerandi"},"reviewer":{"_account_id":6547,"name":"Andreas Jaeger","email":"jaegerandi@gmail.com","username":"jaegerandi"},"state":"REVIEWER"}],"messages":[{"id":"6af7331b7033c7010272a54c3369621b5bd446f6","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"date":"2021-04-27 12:34:15.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"989f9b87f201fca5cb78a72720a4b54815fe2492","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-04-27 12:43:03.000000000","message":"Patch Set 1: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-linters https://zuul.opendev.org/t/openstack/build/ac5b31df99844e7cb72b4d9dd6939c70 : SUCCESS in 3m 55s\n- build-tox-manuals-publishdocs https://zuul.opendev.org/t/openstack/build/ceae6ebf826e4dc19684cf7dd303a025 : SUCCESS in 4m 21s","accounts_in_message":[],"_revision_number":1},{"id":"144fb4a39402b6e018a141376741160cbe187e5b","author":{"_account_id":6547,"name":"Andreas Jaeger","email":"jaegerandi@gmail.com","username":"jaegerandi"},"date":"2021-04-27 15:46:19.000000000","message":"Patch Set 1: Code-Review-1\n\n(2 comments)","accounts_in_message":[],"_revision_number":1},{"id":"7a7bbc3f89a57e4609f0593e5fd2e6f8217132c4","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"date":"2021-04-27 16:23:59.000000000","message":"Patch Set 2: Published edit on patch set 1.","accounts_in_message":[],"_revision_number":2},{"id":"70b683629b8c1015492f7393c5005551c507a17f","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-04-27 16:32:31.000000000","message":"Patch Set 2: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-linters https://zuul.opendev.org/t/openstack/build/55d6a13155df49458d0fed9b76c60023 : SUCCESS in 5m 27s\n- build-tox-manuals-publishdocs https://zuul.opendev.org/t/openstack/build/a646c6704a3f490388218194e344a4ac : SUCCESS in 4m 46s","accounts_in_message":[],"_revision_number":2},{"id":"42e4786f32f97ec73b032c8f29932a8b86deee41","author":{"_account_id":6547,"name":"Andreas Jaeger","email":"jaegerandi@gmail.com","username":"jaegerandi"},"date":"2021-05-05 07:16:58.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"b0ebb1be084fe52a61620348f3cdba3889052c5a","author":{"_account_id":6547,"name":"Andreas Jaeger","email":"jaegerandi@gmail.com","username":"jaegerandi"},"date":"2021-05-12 06:10:45.000000000","message":"Patch Set 2: Code-Review-1\n\nsee my grammar comments","accounts_in_message":[],"_revision_number":2},{"id":"ddabc02ed7d93a15f8a258396de53a2f6c5be1a4","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"date":"2021-05-12 10:07:55.000000000","message":"Patch Set 3: Published edit on patch set 2.","accounts_in_message":[],"_revision_number":3},{"id":"9bdb91387babf952f24e6016861b1b76c9c280a7","tag":"autogenerated:zuul:check","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-05-12 10:17:13.000000000","message":"Patch Set 3: Verified+1\n\nBuild succeeded (check pipeline).\n\n- openstack-tox-linters https://zuul.opendev.org/t/openstack/build/08b89fcc22a44f1294136e2db353551c : SUCCESS in 3m 51s\n- build-tox-manuals-publishdocs https://zuul.opendev.org/t/openstack/build/a966df4d810843a6b3d82a30d288d01c : SUCCESS in 4m 06s","accounts_in_message":[],"_revision_number":3},{"id":"f6acab42693accfc978211a18fc925a175faad25","author":{"_account_id":6547,"name":"Andreas Jaeger","email":"jaegerandi@gmail.com","username":"jaegerandi"},"date":"2021-05-19 15:24:38.000000000","message":"Patch Set 3: Code-Review+2 Workflow+1\n\nthanks","accounts_in_message":[],"_revision_number":3},{"id":"250d0c19e9e1d5d9694b1503ac62022b55431c38","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-05-19 15:25:03.000000000","message":"Patch Set 3: -Verified\n\nStarting gate jobs.","accounts_in_message":[],"_revision_number":3},{"id":"7473c42ea2594fbc1ce81146ebbe0ccfe30b5e33","tag":"autogenerated:zuul:gate","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-05-19 15:30:35.000000000","message":"Patch Set 3: Verified+2\n\nBuild succeeded (gate pipeline).\n\n- openstack-tox-linters https://zuul.opendev.org/t/openstack/build/835e10382a87427fbb07fd6990c1440a : SUCCESS in 4m 13s\n- build-tox-manuals-publishdocs https://zuul.opendev.org/t/openstack/build/11f9ace632184816940858582d1a6abf : SUCCESS in 3m 59s","accounts_in_message":[],"_revision_number":3},{"id":"bcba30c60a3a8869eceb97941c6c2ba7e3b02eb9","tag":"autogenerated:gerrit:merged","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-05-19 15:30:36.000000000","message":"Change has been successfully merged by Zuul","accounts_in_message":[],"_revision_number":3},{"id":"863843b5e5192fab1f66a8e92a71ac1cc5c63bb6","tag":"autogenerated:zuul:promote","author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"date":"2021-05-19 15:31:52.000000000","message":"Patch Set 3:\n\nBuild succeeded (promote pipeline).\n\n- promote-openstack-manuals https://zuul.opendev.org/t/openstack/build/5401fc604a294d36bb4906c5a985ef81 : SUCCESS in 1m 00s","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"8dbacc7b42019e803f4086f192984326558fa024","revisions":{"cb7cd0c78638ae818c797bbb8d787b5fdd8711c4":{"kind":"REWORK","_number":1,"created":"2021-04-27 12:34:15.000000000","uploader":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"ref":"refs/changes/78/788278/1","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/security-doc","ref":"refs/changes/78/788278/1","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/788278/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/788278/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/788278/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/security-doc refs/changes/78/788278/1"}}},"commit":{"parents":[{"commit":"8b27aa09eef3ba43ae53c6cfaadf1abfde2c458b","subject":"OSSN-0089: Missing configuration option in Secure Live Migration guide","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/8b27aa09eef3ba43ae53c6cfaadf1abfde2c458b"}]}],"author":{"name":"Dmitriy Rabotyagov","email":"dmitriy.rabotyagov@citynetwork.eu","date":"2021-04-27 12:33:52.000000000","tz":180},"committer":{"name":"Dmitriy Rabotyagov","email":"dmitriy.rabotyagov@citynetwork.eu","date":"2021-04-27 12:34:12.000000000","tz":180},"subject":"Fix Barbican PKCS#11 description","message":"Fix Barbican PKCS#11 description\n\nCurrent description is incorrect, since barbican does not store each\nprojects KEK in HSM. As eventually, that would mean having\nthousand of keys, while Thales Luna Network HSM has limit of 100 keys\nfor DPoD, so it will be unable to use big part of HSM solutions\nwith that approach.\nInstead only MKEK and HMAC are stored in HSM and used to encrypt/decrypt\nKEKs.\n\nChange-Id: I8c4eaaa42262797632ce4c4296c04a4fe62b8fcf\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/cb7cd0c78638ae818c797bbb8d787b5fdd8711c4"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/cb7cd0c78638ae818c797bbb8d787b5fdd8711c4"}]},"branch":"refs/heads/master"},"36a6a0195fc7e4dbb024d7c14b1913dd663eb4f7":{"kind":"REWORK","_number":2,"created":"2021-04-27 16:23:59.000000000","uploader":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"ref":"refs/changes/78/788278/2","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/security-doc","ref":"refs/changes/78/788278/2","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/788278/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/788278/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/788278/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/security-doc refs/changes/78/788278/2"}}},"commit":{"parents":[{"commit":"8b27aa09eef3ba43ae53c6cfaadf1abfde2c458b","subject":"OSSN-0089: Missing configuration option in Secure Live Migration guide","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/8b27aa09eef3ba43ae53c6cfaadf1abfde2c458b"}]}],"author":{"name":"Dmitriy Rabotyagov","email":"dmitriy.rabotyagov@citynetwork.eu","date":"2021-04-27 12:33:52.000000000","tz":180},"committer":{"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@ya.ru","date":"2021-04-27 16:23:44.000000000","tz":0},"subject":"Fix Barbican PKCS#11 description","message":"Fix Barbican PKCS#11 description\n\nCurrent description is incorrect, since barbican does not store each\nprojects KEK in HSM. As eventually, that would mean having\nthousand of keys, while Thales Luna Network HSM has limit of 100 keys\nfor DPoD, so it will be unable to use big part of HSM solutions\nwith that approach.\nInstead only MKEK and HMAC are stored in HSM and used to encrypt/decrypt\nKEKs.\n\nChange-Id: I8c4eaaa42262797632ce4c4296c04a4fe62b8fcf\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/36a6a0195fc7e4dbb024d7c14b1913dd663eb4f7"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/36a6a0195fc7e4dbb024d7c14b1913dd663eb4f7"}]},"branch":"refs/heads/master"},"8dbacc7b42019e803f4086f192984326558fa024":{"kind":"REWORK","_number":3,"created":"2021-05-12 10:07:55.000000000","uploader":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"ref":"refs/changes/78/788278/3","fetch":{"anonymous http":{"url":"https://review.opendev.org/openstack/security-doc","ref":"refs/changes/78/788278/3","commands":{"Checkout":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/788278/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/788278/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://review.opendev.org/openstack/security-doc refs/changes/78/788278/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://review.opendev.org/openstack/security-doc refs/changes/78/788278/3"}}},"commit":{"parents":[{"commit":"8b27aa09eef3ba43ae53c6cfaadf1abfde2c458b","subject":"OSSN-0089: Missing configuration option in Secure Live Migration guide","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/8b27aa09eef3ba43ae53c6cfaadf1abfde2c458b"}]}],"author":{"name":"Dmitriy Rabotyagov","email":"dmitriy.rabotyagov@citynetwork.eu","date":"2021-04-27 12:33:52.000000000","tz":180},"committer":{"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@ya.ru","date":"2021-05-12 10:07:49.000000000","tz":0},"subject":"Fix Barbican PKCS#11 description","message":"Fix Barbican PKCS#11 description\n\nCurrent description is incorrect, since barbican does not store each\nprojects KEK in HSM. As eventually, that would mean having\nthousand of keys, while Thales Luna Network HSM has limit of 100 keys\nfor DPoD, so it will be unable to use big part of HSM solutions\nwith that approach.\nInstead only MKEK and HMAC are stored in HSM and used to encrypt/decrypt\nKEKs.\n\nChange-Id: I8c4eaaa42262797632ce4c4296c04a4fe62b8fcf\n","web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/8dbacc7b42019e803f4086f192984326558fa024"}],"resolve_conflicts_web_links":[{"name":"gitea","tooltip":"Open in GitWeb","url":"https://opendev.org/openstack/security-doc/commit/8dbacc7b42019e803f4086f192984326558fa024"}]},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[{"status":"CLOSED","labels":[{"label":"Verified","status":"OK","applied_by":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]}},{"label":"Code-Review","status":"OK","applied_by":{"_account_id":6547,"name":"Andreas Jaeger","email":"jaegerandi@gmail.com","username":"jaegerandi"}},{"label":"Workflow","status":"OK","applied_by":{"_account_id":6547,"name":"Andreas Jaeger","email":"jaegerandi@gmail.com","username":"jaegerandi"}}]}],"submit_requirements":[{"name":"Verified","status":"SATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Verified\u003dCustom-Rule","fulfilled":true,"status":"PASS","passing_atoms":["label:Verified\u003dCustom-Rule"],"failing_atoms":[],"atom_explanations":{}}},{"name":"Workflow","status":"SATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Workflow\u003dCustom-Rule","fulfilled":true,"status":"PASS","passing_atoms":["label:Workflow\u003dCustom-Rule"],"failing_atoms":[],"atom_explanations":{}}},{"name":"Code-Review","status":"SATISFIED","is_legacy":true,"submittability_expression_result":{"expression":"label:Code-Review\u003dCustom-Rule","fulfilled":true,"status":"PASS","passing_atoms":["label:Code-Review\u003dCustom-Rule"],"failing_atoms":[],"atom_explanations":{}}}]}
