Re: [openstack-dev] [security] FIPS compliance

2017-01-17 Thread Ian Cordasco
-Original Message- From: Doug Hellmann Reply: OpenStack Development Mailing List (not for usage questions) Date: January 17, 2017 at 10:53:06 To: openstack-dev Subject:  Re: [openstack-dev] [security] FIPS compliance > Excerpts from Ian Cordasco's message of 2017-01-17 05:59:

Re: [openstack-dev] [security] FIPS compliance

2017-01-17 Thread Yolanda Robla Mota
I completely agree that this shall be upstream first. So the main effort will be on landing this python patch first. This has been up since 2010, so more effort in terms of code contribution and reviews is needed, I'm happy to collaborate in amending the patch as the reviews are requesting. But th

Re: [openstack-dev] [security] FIPS compliance

2017-01-17 Thread Doug Hellmann
Excerpts from Ian Cordasco's message of 2017-01-17 05:59:13 -0600: > On Tue, Jan 17, 2017 at 4:11 AM, Yolanda Robla Mota > wrote: > > Hi, in previous threads, there have been discussions about enabling FIPS, > > and the problems we are hitting with md5 inside OpenStack: > > http://lists.openstack

Re: [openstack-dev] [security] FIPS compliance

2017-01-17 Thread Jeremy Stanley
On 2017-01-17 05:59:13 -0600 (-0600), Ian Cordasco wrote: [...] > I think people should work on the Python patches *first*. Once they're > merged, *then* we should potentially create a wrapper (if it's still > necessary at that point) to do this. Yes, I encourage everyone to think back to the freq

Re: [openstack-dev] [security] FIPS compliance

2017-01-17 Thread Ian Cordasco
On Tue, Jan 17, 2017 at 4:11 AM, Yolanda Robla Mota wrote: > Hi, in previous threads, there have been discussions about enabling FIPS, > and the problems we are hitting with md5 inside OpenStack: > http://lists.openstack.org/pipermail/openstack-dev/2016-November/107035.html > > It is important fro

Re: [openstack-dev] [security] FIPS compliance

2017-01-17 Thread Luke Hinds
On Tue, Jan 17, 2017 at 10:11 AM, Yolanda Robla Mota wrote: > Hi, in previous threads, there have been discussions about enabling FIPS, > and the problems we are hitting with md5 inside OpenStack: > http://lists.openstack.org/pipermail/openstack-dev/2016- > November/107035.html > > It is importan

[openstack-dev] [security] FIPS compliance

2017-01-17 Thread Yolanda Robla Mota
Hi, in previous threads, there have been discussions about enabling FIPS, and the problems we are hitting with md5 inside OpenStack: http://lists.openstack.org/pipermail/openstack-dev/2016-November/107035.html It is important from a security perspective to enable FIPS, however OpenStack cannot boo

Re: [openstack-dev] [security] FIPS Compliance (Was: [requirements][kolla][security] pycrypto vs cryptography)

2016-11-19 Thread Luke Hinds
On Fri, Nov 18, 2016 at 4:14 PM, Dean Troyer wrote: > > -Original Message- > > From: Luke Hinds > [...] > >> for non security related functions, but when it comes to government > >> compliance and running OpenStack on public clouds (and even private for > the > >> Telcos / NFV), not meet

Re: [openstack-dev] [security] FIPS Compliance (Was: [requirements][kolla][security] pycrypto vs cryptography)

2016-11-18 Thread John Dickinson
On 18 Nov 2016, at 8:14, Dean Troyer wrote: >> -Original Message- >> From: Luke Hinds > [...] >>> for non security related functions, but when it comes to government >>> compliance and running OpenStack on public clouds (and even private for the >>> Telcos / NFV), not meeting FIPS will

Re: [openstack-dev] [security] FIPS Compliance (Was: [requirements][kolla][security] pycrypto vs cryptography)

2016-11-18 Thread Ian Cordasco
-Original Message- From: Dean Troyer Reply: OpenStack Development Mailing List (not for usage questions) Date: November 18, 2016 at 10:15:44 To: OpenStack Development Mailing List (not for usage questions) Subject:  Re: [openstack-dev] [security] FIPS Compliance (Was: [requirements

Re: [openstack-dev] [security] FIPS Compliance (Was: [requirements][kolla][security] pycrypto vs cryptography)

2016-11-18 Thread Dean Troyer
> -Original Message- > From: Luke Hinds [...] >> for non security related functions, but when it comes to government >> compliance and running OpenStack on public clouds (and even private for the >> Telcos / NFV), not meeting FIPS will in some cases block production getting >> a green ligh

[openstack-dev] [security] FIPS Compliance (Was: [requirements][kolla][security] pycrypto vs cryptography)

2016-11-18 Thread Ian Cordasco
  -Original Message- From: Luke Hinds Reply: OpenStack Development Mailing List (not for usage questions) Date: November 18, 2016 at 08:43:42 To: OpenStack Development Mailing List (not for usage questions) Subject:  Re: [openstack-dev] Fwd: Re: [requirements][kolla][security] pycrypt