1. 14 Jun, 2022 1 commit
  2. 31 May, 2022 1 commit
  3. 30 Mar, 2022 1 commit
  4. 25 Mar, 2022 1 commit
  5. 11 Mar, 2022 3 commits
    • Thomas Goirand's avatar
      Add autopkgtest. · 7134e49b
      Thomas Goirand authored
      7134e49b
    • Thomas Goirand's avatar
      Now packaging 14.0.0_rc1 · 615808df
      Thomas Goirand authored
      615808df
    • Thomas Goirand's avatar
      Merge tag '14.0.0_rc1' into debian/yoga · 4f6b881d
      Thomas Goirand authored
      barbican 14.0.0.0rc1 release candidate
      
      meta:version: 14.0.0.0rc1
      meta:diff-start: -
      meta:series: yoga
      meta:release-type: release candidate
      meta:pypi: no
      meta:first: no
      meta:release:Author: Elod Illes <elod.illes@est.tech>
      meta:release:Commit: Elod Illes <elod.illes@est.tech>
      meta:release:Change-Id: I8f4509b4cf8d210e2b2013b211db4976f8bb2db6
      meta:release:Code-Review+2: Hervé Beraud <herveberaud.pro@gmail.com>
      meta:release:Code-Review+2: Elod Illes <elod.illes@est.tech>
      meta:release:Workflow+1: Elod Illes <elod.illes@est.tech>
      4f6b881d
  6. 14 Feb, 2022 1 commit
  7. 07 Feb, 2022 1 commit
    • Douglas Mendizábal's avatar
      Fix container consumers rbac policy · 96015933
      Douglas Mendizábal authored
      This patch modifies the Consumer controller to enable the use of
      ownership information in policy checks. e.g. policies that use a target
      container:
      
         project_id:%(target.container.project_id)
      
      Story: 2009664
      Task: 43872
      
      Depends-On: I8698fc7a9ac849b8c24adfe824ca44dd3e42b999
      Change-Id: I1724152839f0f5850f8d32d40b36d1670c0ad996
      96015933
  8. 31 Jan, 2022 1 commit
    • Douglas Mendizábal's avatar
      Allow secret delete by users with "creator" role · 2620d14c
      Douglas Mendizábal authored
      Users with the "creator" role on a project can now delete secrets owned
      by the project even if the user is different than the user that
      originally created the secret.  Previous to this fix a user with the
      "creator" role was only allowed to delete a secret owned by the project
      if they were also the same user that originally created, which was
      inconsistent with the way that deletes are handled by other OpenStack
      projects that integrate with Barbican.
      
      This change does not affect the policy for delting private secrets
      (i.e. secrets with the "project-access" flag set to "false").
      
      Story: 2009791
      Task: 44324
      Change-Id: Ie3e3adc1ee02d770de050f5cfa8110774bb1f661
      2620d14c
  9. 16 Dec, 2021 1 commit
  10. 14 Dec, 2021 1 commit
  11. 08 Dec, 2021 1 commit
  12. 07 Dec, 2021 1 commit
  13. 06 Dec, 2021 1 commit
    • Douglas Mendizábal's avatar
      Fix policy for Orders · 5d81a3c4
      Douglas Mendizábal authored
      This patch adds checks to make sure that the project_id of the token
      matches the project_id that owns the Order.
      
      Currently, having a role on any project will allow the request to be
      processed, which results in a 404 - Not Found instead of 401 -
      Forbidden.
      
      Change-Id: Ie0e6f6edae40e47d45afbe92fd509032cb091b1a
      5d81a3c4
  14. 02 Dec, 2021 1 commit
  15. 29 Nov, 2021 1 commit
    • Douglas Mendizábal's avatar
      Move DogTag functional tests to experimental · 9dbd8313
      Douglas Mendizábal authored
      Temporarily moving the Dogtag test to the experimental pipeline.  The
      tests has not passed in months and we won't be fixing it any time soon
      so we should stop wasting resources.
      
      Change-Id: Ie3fce8f4dda33d0eff166d1b1698f001f4d74e8f
      9dbd8313
  16. 13 Nov, 2021 1 commit
  17. 10 Nov, 2021 1 commit
  18. 15 Oct, 2021 1 commit
  19. 12 Oct, 2021 2 commits
  20. 11 Oct, 2021 2 commits
    • Douglas Mendizábal's avatar
      Fix secret metadata access rules (pt 2) · af262dc3
      Douglas Mendizábal authored
      This patch fixes the secure-rbac rules to ensure that the user making
      the request is authenticated for the project that owns the secret.
      
      Story: 2009253
      Task: 43451
      
      Change-Id: I8222ea2a55cdb72f1d9affe9fb0cf542c6b7c88c
      af262dc3
    • Douglas Mendizábal's avatar
      Fix secret metadata access rules · 7d270bac
      Douglas Mendizábal authored
      This patch fixes the legacy policy rules for accessing secret metadata
      by checking that the user making the request is authenticated for the
      project that owns the secret.
      
      Story: 2009253
      Task: 43451
      
      Change-Id: Ide37d64dff10d421817bf90b8e2e58bf6ac4f592
      7d270bac
  21. 09 Oct, 2021 1 commit
  22. 08 Oct, 2021 1 commit
  23. 06 Oct, 2021 1 commit
  24. 29 Sep, 2021 1 commit
  25. 23 Sep, 2021 3 commits
  26. 22 Sep, 2021 1 commit
  27. 20 Sep, 2021 3 commits
    • Thomas Goirand's avatar
      Fixed diff with upstream tag. · d08638fe
      Thomas Goirand authored
      d08638fe
    • Thomas Goirand's avatar
      Now packaging 13.0.0_rc1 · 6fa4d1ed
      Thomas Goirand authored
      6fa4d1ed
    • Thomas Goirand's avatar
      Merge tag '13.0.0_rc1' into debian/xena · c03f41b7
      Thomas Goirand authored
      barbican 13.0.0.0rc1 release candidate
      
      meta:version: 13.0.0.0rc1
      meta:diff-start: -
      meta:series: xena
      meta:release-type: release candidate
      meta:pypi: no
      meta:first: no
      meta:release:Author: Hervé Beraud <hberaud@redhat.com>
      meta:release:Commit: Douglas Mendizábal <dmendiza@redhat.com>
      meta:release:Change-Id: I16f87d6442dc21c308c3241806f19a5f1d4e6398
      meta:release:Code-Review+2: Hervé Beraud <herveberaud.pro@gmail.com>
      meta:release:Code-Review+2: Elod Illes <elod.illes@est.tech>
      meta:release:Workflow+1: Elod Illes <elod.illes@est.tech>
      c03f41b7
  28. 17 Sep, 2021 2 commits
    • Douglas Mendizábal's avatar
      Ignore network errors during C_Finalize · 70aac1f6
      Douglas Mendizábal authored
      The Trustway Proteccio HSM can somtimes return a network error when
      attempting to finalize the cryptoki library.
      
      The error can prevent reinitialization because we attempt to finalize
      the library before initalizing a new connection.  When a network error
      occurrs, barbican gets stuck in an error loop trying to finalize the
      dead connection before starting a new one.
      
      This patch adds code to ignore the network error when finalizing to
      ensure we are able to attempt to reinitialize.
      
      Connection errors during other operations will still result in 500
      errors as expected.
      
      Change-Id: I9ac6c7bbda0f81cb26e1c589803317df1ef11f39
      70aac1f6
    • Zuul's avatar
      476a5b73
  29. 16 Sep, 2021 3 commits