Re: [ovs-dev] ovn: Improving southbound database security

2016-10-21 Thread Ben Pfaff
On Fri, Oct 21, 2016 at 04:38:43PM -0400, Lance Richardson wrote: > > From: "Ben Pfaff" > > To: "Russell Bryant" > > Cc: "ovs dev" > > Sent: Friday, October 21, 2016 4:33:33 PM > > Subject: Re: [ovs-dev] ovn: Improving southbound d

Re: [ovs-dev] ovn: Improving southbound database security

2016-10-21 Thread Lance Richardson
> From: "Ben Pfaff" > To: "Russell Bryant" > Cc: "ovs dev" > Sent: Friday, October 21, 2016 4:33:33 PM > Subject: Re: [ovs-dev] ovn: Improving southbound database security > > On Fri, Oct 21, 2016 at 04:10:58PM -0400, Russell Bryant wrote: &

Re: [ovs-dev] ovn: Improving southbound database security

2016-10-21 Thread Ben Pfaff
On Fri, Oct 21, 2016 at 04:10:58PM -0400, Russell Bryant wrote: > On Thu, Oct 20, 2016 at 5:52 PM, Han Zhou wrote: > > > > > On Thu, Oct 20, 2016 at 11:51 AM, Russell Bryant wrote: > > > > > > On Thu, Oct 20, 2016 at 1:47 PM, Ben Pfaff wrote: > > > > > > > On Thu, Oct 13, 2016 at 07:32:53PM +05

Re: [ovs-dev] ovn: Improving southbound database security

2016-10-21 Thread Russell Bryant
On Thu, Oct 20, 2016 at 5:52 PM, Han Zhou wrote: > > On Thu, Oct 20, 2016 at 11:51 AM, Russell Bryant wrote: > > > > On Thu, Oct 20, 2016 at 1:47 PM, Ben Pfaff wrote: > > > > > On Thu, Oct 13, 2016 at 07:32:53PM +0530, Numan Siddique wrote: > > > > > > > 5) Remove support from ovn-controller up

Re: [ovs-dev] ovn: Improving southbound database security

2016-10-20 Thread Han Zhou
On Thu, Oct 20, 2016 at 11:51 AM, Russell Bryant wrote: > > On Thu, Oct 20, 2016 at 1:47 PM, Ben Pfaff wrote: > > > On Thu, Oct 13, 2016 at 07:32:53PM +0530, Numan Siddique wrote: > > > > > 5) Remove support from ovn-controller updating the 'Chassis.hv_cfg' > > > column and handle the side effect

Re: [ovs-dev] ovn: Improving southbound database security

2016-10-20 Thread Russell Bryant
On Thu, Oct 20, 2016 at 1:47 PM, Ben Pfaff wrote: > On Thu, Oct 13, 2016 at 07:32:53PM +0530, Numan Siddique wrote: > > > ​5) Remove support from ovn-controller updating the 'Chassis.hv_cfg' > > column​ and handle the side effect in "--wait=hv" in ovn-nbctl. > > The ability to wait for hypervisor

Re: [ovs-dev] ovn: Improving southbound database security

2016-10-20 Thread Ben Pfaff
On Thu, Oct 13, 2016 at 07:32:53PM +0530, Numan Siddique wrote: > We may have to add one more item in the task breakdown list. Please see > below > > > On Wed, Oct 12, 2016 at 11:21 PM, Russell Bryant wrote: > > > Hello, I'm back to looking at southbound database security concerns in > > OVN.

Re: [ovs-dev] ovn: Improving southbound database security

2016-10-18 Thread Darrell Ball
On Wed, Oct 12, 2016 at 10:51 AM, Russell Bryant wrote: > Hello, I'm back to looking at southbound database security concerns in > OVN. A previous thread discussing approaches was here: > > http://openvswitch.org/pipermail/dev/2016-August/078106.html > > I'm now working with a few others on

Re: [ovs-dev] ovn: Improving southbound database security

2016-10-13 Thread Russell Bryant
I should have also noted who was already looking at each of these items ... On Thu, Oct 13, 2016 at 10:02 AM, Numan Siddique wrote: > We may have to add one more item in the task breakdown list. Please see > below > > > On Wed, Oct 12, 2016 at 11:21 PM, Russell Bryant wrote: > >> Hello, I'm bac

Re: [ovs-dev] ovn: Improving southbound database security

2016-10-13 Thread Lance Richardson
> From: "Andy Zhou" > To: "Ben Pfaff" > Cc: "ovs dev" , "Numan Siddique" , > "Babu Shanmugam" , > "Lance Richardson" , "Justin Pettit" , > "Russell Bryant" > Sent: Thursday, October 13, 2016 3:05:40 PM > Subject: Re: ovn: Improving southbound database security > > On Thu, Oct 13, 2016 at 11:2

Re: [ovs-dev] ovn: Improving southbound database security

2016-10-13 Thread Andy Zhou
On Thu, Oct 13, 2016 at 11:26 AM, Ben Pfaff wrote: > On Wed, Oct 12, 2016 at 01:51:39PM -0400, Russell Bryant wrote: > > 1) Add support to ovsdb-server for read-only remotes. The port reachable > > by ovn-controller would only accept read-only connections. > > Andy, is this something that you ca

Re: [ovs-dev] ovn: Improving southbound database security

2016-10-13 Thread Lance Richardson
> From: "Ben Pfaff" > To: "Andy Zhou" > Cc: "ovs dev" , "Numan Siddique" , > "Babu Shanmugam" , > "Lance Richardson" , "Justin Pettit" , > "Russell Bryant" > Sent: Thursday, October 13, 2016 2:26:13 PM > Subject: Re: ovn: Improving southbound database security > > On Wed, Oct 12, 2016 at 01:5

Re: [ovs-dev] ovn: Improving southbound database security

2016-10-13 Thread Ben Pfaff
On Wed, Oct 12, 2016 at 01:51:39PM -0400, Russell Bryant wrote: > 1) Add support to ovsdb-server for read-only remotes. The port reachable > by ovn-controller would only accept read-only connections. Andy, is this something that you can put on your to-do list? I guess that it is not a huge amoun

Re: [ovs-dev] ovn: Improving southbound database security

2016-10-13 Thread Numan Siddique
We may have to add one more item in the task breakdown list. Please see below On Wed, Oct 12, 2016 at 11:21 PM, Russell Bryant wrote: > Hello, I'm back to looking at southbound database security concerns in > OVN. A previous thread discussing approaches was here: > > http://openvswitch.org

[ovs-dev] ovn: Improving southbound database security

2016-10-12 Thread Russell Bryant
Hello, I'm back to looking at southbound database security concerns in OVN. A previous thread discussing approaches was here: http://openvswitch.org/pipermail/dev/2016-August/078106.html I'm now working with a few others on implementing a proposed solution. The overview is that we'd like to