)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":10459,"name":"Luigi Toscano","email":"ltoscano@redhat.com","username":"ltoscano"},"change_message_id":"5113eba29207c8bed2f35f475d1a09d29f6e8913","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"19338861_95a4cf09","updated":"2022-12-16 15:27:34.000000000","message":"\u003e Change https://review.opendev.org/861573 is needed. \n\nBut that change is merged, uhm","commit_id":"070bc335b66e2cd195fc3e011705e052be4f4667"},{"author":{"_account_id":11090,"name":"Sergii Golovatiuk","email":"sgolovat@redhat.com","username":"holser"},"change_message_id":"84d559c05b814c9df04534d49d6144f4e52b8543","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"fc625dd6_0c6651f2","updated":"2022-10-18 12:14:44.000000000","message":"I\u0027d say this change defintely has upgrade impact and should be tested in upgrade scenarios. Let\u0027s imagine we have environment without these settings. Then,we change one node to use AES128-SHA256. Will current session be closed? Will we have a cluster split?","commit_id":"070bc335b66e2cd195fc3e011705e052be4f4667"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"8a4a4a59ea61fc0be16b860593910c66078502c6","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"2a341264_3d01b5ba","updated":"2022-10-17 08:02:37.000000000","message":"This is fine, although the crypto folks asked if there was a way in galera NOT to set a cipher, and rather have openssl do the negotiation instead.  Then we won\u0027t be subject to breakages like this whenever crypto policy changes.","commit_id":"070bc335b66e2cd195fc3e011705e052be4f4667"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"68952573c8e1a534705be7610f574519581a65ee","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"f64b3f16_858125a0","updated":"2022-11-30 09:50:33.000000000","message":"bump now that CI is passing.","commit_id":"070bc335b66e2cd195fc3e011705e052be4f4667"},{"author":{"_account_id":28223,"name":"Cedric Jeanneret","display_name":"cjeanner (Tengu)","email":"cjeanner@redhat.com","username":"cjeanner"},"change_message_id":"ebf65b69dcd77d23018369d7a7d6886e4af63285","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"7b897465_e9faeb27","updated":"2022-12-08 12:52:45.000000000","message":"imho Sergii concerns were sorted out by Ade and Luca answer.","commit_id":"070bc335b66e2cd195fc3e011705e052be4f4667"},{"author":{"_account_id":10459,"name":"Luigi Toscano","email":"ltoscano@redhat.com","username":"ltoscano"},"change_message_id":"d5e3cc1ca05f46f77362b848094d3b2b7f24cfd9","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"a062d2fc_34e91c6c","updated":"2022-12-16 15:27:45.000000000","message":"recheck","commit_id":"070bc335b66e2cd195fc3e011705e052be4f4667"},{"author":{"_account_id":30126,"name":"Luca Miccini","email":"lmiccini@redhat.com","username":"lmiccini2"},"change_message_id":"106059b15e1af713ef2bbe3aba3571752b64a8e1","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"cf0bc6b7_7afd45eb","updated":"2022-11-30 06:32:01.000000000","message":"recheck","commit_id":"070bc335b66e2cd195fc3e011705e052be4f4667"},{"author":{"_account_id":30002,"name":"Douglas Viroel","email":"viroel@gmail.com","username":"dviroel"},"change_message_id":"81d411492857fcb93002e69a80681cb296e254c7","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"a21f3855_b3a9220e","updated":"2022-12-13 18:28:25.000000000","message":"recheck\n\ngnuTLS issue was fixed and is available on centos9 repo","commit_id":"070bc335b66e2cd195fc3e011705e052be4f4667"},{"author":{"_account_id":30002,"name":"Douglas Viroel","email":"viroel@gmail.com","username":"dviroel"},"change_message_id":"aa47cf3e9ad22e8ab787deab0d2fc38e00857abb","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"c6f321f0_7d69203b","updated":"2022-11-17 11:59:26.000000000","message":"recheck\nzuul reports are old","commit_id":"070bc335b66e2cd195fc3e011705e052be4f4667"},{"author":{"_account_id":9914,"name":"Ade Lee","email":"alee@redhat.com","username":"alee"},"change_message_id":"68952573c8e1a534705be7610f574519581a65ee","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"7d20d3c9_88ed8849","in_reply_to":"adbe26fc_2bc0213d","updated":"2022-11-30 09:50:33.000000000","message":"Agreed - we need this to be able to have a FIPS enabled environment to begin with.\n\nThere was never the expectation that you could just turn FIPS on in an existing environment as part of an upgrade and things will just work.  While things will work for the most part, there could be issues like this one, which could result in downtime.","commit_id":"070bc335b66e2cd195fc3e011705e052be4f4667"},{"author":{"_account_id":30126,"name":"Luca Miccini","email":"lmiccini@redhat.com","username":"lmiccini2"},"change_message_id":"30668423c968276f0a83ae4774cd5d94b3e6e92a","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"adbe26fc_2bc0213d","in_reply_to":"fc625dd6_0c6651f2","updated":"2022-10-18 12:36:35.000000000","message":"you can\u0027t deploy wallaby with tls+fips because galera will not start at all, see https://bugzilla.redhat.com/show_bug.cgi?id\u003d2133866. \nin puppet-tripleo we have:\n# [*gcomm_cipher*]\n#   (Optional) When enable_internal_tls is true, defines the cipher\n#   used by Galera for the gcomm replication traffic.\n#   Defaults to \u0027AES128-SHA256\u0027\n\nand this needs to be overridden if you want a functional overcloud.\nI don\u0027t think it is feasible to simply enable fips on a already-deployed overcloud so I am not sure this is in scope for upgrades?","commit_id":"070bc335b66e2cd195fc3e011705e052be4f4667"}]}
