Re: [openstack-dev] [Nova] FFE Request: Encrypt Cinder volumes

2013-09-09 Thread John Griffith
On Mon, Sep 9, 2013 at 1:20 PM, Jarret Raim wrote: > > > On 9/9/13 9:25 AM, "Russell Bryant" wrote: > > >On 09/09/2013 04:57 AM, Thierry Carrez wrote: > >> Russell Bryant wrote: > >>> I would be good with the exception for this, assuming that: > >>> > >>> 1) Those from nova-core that have reviewe

Re: [openstack-dev] [Nova] FFE Request: Encrypt Cinder volumes

2013-09-09 Thread Jarret Raim
On 9/9/13 9:25 AM, "Russell Bryant" wrote: >On 09/09/2013 04:57 AM, Thierry Carrez wrote: >> Russell Bryant wrote: >>> I would be good with the exception for this, assuming that: >>> >>> 1) Those from nova-core that have reviewed the code are still happy >>>with >>> it and would do a final revi

Re: [openstack-dev] [Nova] FFE Request: Encrypt Cinder volumes

2013-09-09 Thread Russell Bryant
On 09/09/2013 04:57 AM, Thierry Carrez wrote: > Russell Bryant wrote: >> I would be good with the exception for this, assuming that: >> >> 1) Those from nova-core that have reviewed the code are still happy with >> it and would do a final review to get it merged. >> >> 2) There is general consensus

Re: [openstack-dev] [Nova] FFE Request: Encrypt Cinder volumes

2013-09-09 Thread Thierry Carrez
Russell Bryant wrote: > I would be good with the exception for this, assuming that: > > 1) Those from nova-core that have reviewed the code are still happy with > it and would do a final review to get it merged. > > 2) There is general consensus that the simple config based key manager > (single

Re: [openstack-dev] [Nova] FFE Request: Encrypt Cinder volumes

2013-09-06 Thread Bhandaru, Malini K
Bruce - well-crafted message. Good work, looks like it is eliciting desired result. From: Benjamin, Bruce P. [mailto:bruce.benja...@jhuapl.edu] Sent: Friday, September 06, 2013 1:14 PM To: openstack-dev@lists.openstack.org Subject: [openstack-dev] [Nova] FFE Request: Encrypt Cinder volumes We

Re: [openstack-dev] [Nova] FFE Request: Encrypt Cinder volumes

2013-09-06 Thread Bhandaru, Malini K
) feature by default off. Regards malini -Original Message- From: Russell Bryant [mailto:rbry...@redhat.com] Sent: Friday, September 06, 2013 2:47 PM To: openstack-dev@lists.openstack.org Subject: Re: [openstack-dev] [Nova] FFE Request: Encrypt Cinder volumes On 09/06/2013 04:14 PM

Re: [openstack-dev] [Nova] FFE Request: Encrypt Cinder volumes

2013-09-06 Thread Bryan D. Payne
> 2) There is general consensus that the simple config based key manager > (single key) does provide some amount of useful security. I believe it > does, just want to make sure we're in agreement on it. Obviously we > want to improve this in the future. > I believe that it does add value. For e

Re: [openstack-dev] [Nova] FFE Request: Encrypt Cinder volumes

2013-09-06 Thread Joe Gordon
On Fri, Sep 6, 2013 at 4:17 PM, Bryan D. Payne wrote: > > 2) There is general consensus that the simple config based key manager >> (single key) does provide some amount of useful security. I believe it >> does, just want to make sure we're in agreement on it. Obviously we >> want to improve th

Re: [openstack-dev] [Nova] FFE Request: Encrypt Cinder volumes

2013-09-06 Thread Joe Gordon
On Fri, Sep 6, 2013 at 2:47 PM, Russell Bryant wrote: > On 09/06/2013 04:14 PM, Benjamin, Bruce P. wrote: > > We request that volume encryption [1] be granted an exception to the > > feature freeze for Havana-3. Volume encryption [2] provides a usable > > layer of protection to user data as it i

Re: [openstack-dev] [Nova] FFE Request: Encrypt Cinder volumes

2013-09-06 Thread Russell Bryant
On 09/06/2013 04:14 PM, Benjamin, Bruce P. wrote: > We request that volume encryption [1] be granted an exception to the > feature freeze for Havana-3. Volume encryption [2] provides a usable > layer of protection to user data as it is transmitted through a network > and when it is stored on disk.

[openstack-dev] [Nova] FFE Request: Encrypt Cinder volumes

2013-09-06 Thread Benjamin, Bruce P.
We request that volume encryption [1] be granted an exception to the feature freeze for Havana-3. Volume encryption [2] provides a usable layer of protection to user data as it is transmitted through a network and when it is stored on disk. The main patch [2] has been under review since the end