[Fiware-lab-federation-nodes] [CESNET #148600] Re: key generation

HENAR MUÑOZ FRUTOS henar.munozfrutos at telefonica.com
Mon Feb 8 11:05:57 CET 2016


Hi
When you send the POST request, you send the token id of your region admin user. With this token  aiakos obtains the region it belongs to. The request is the same for the sskkey or gpgkey. Aiakos detects if there is a ssh or gpg key according to the payload sent.

The POST request (with curl) would be:
curl --request POST --url http://aiakos.lab.fiware.org:3000/v1/support --header 'accept: text/plain' --header 'content-type: text/plain’ --header ‘X-Auth-Token: your token id’ —data your ssh key path or gpg key path

Regards,
Henar

De: "murp at zhaw.ch<mailto:murp at zhaw.ch>" <murp at zhaw.ch<mailto:murp at zhaw.ch>>
Fecha: lunes, 8 de febrero de 2016 10:29
Para: "xifi-support at rt.cesnet.cz<mailto:xifi-support at rt.cesnet.cz>" <xifi-support at rt.cesnet.cz<mailto:xifi-support at rt.cesnet.cz>>
CC: "fiware-lab-federation-nodes at lists.fiware.org<mailto:fiware-lab-federation-nodes at lists.fiware.org>" <fiware-lab-federation-nodes at lists.fiware.org<mailto:fiware-lab-federation-nodes at lists.fiware.org>>
Asunto: Re: [Fiware-lab-federation-nodes] [CESNET #148600] Re: key generation

Hi all,

Has anyone managed to do this?

I've generated our ssh and gpg keys. I don't know how to upload them.

If I understand from Henar, I should use the following endpoint:

http://aiakos.lab.fiware.org:3000/v1/support

However, I'm not sure how to generate the curl request. I don't understand
how I send my ssh keys and gpg keys to the endpoint; I also don't understand
how the endpoint can know for which node/region the keys apply.

@Henar (or anyone else!) - would you be able to provide a curl example of how to
post our keys to the endpoint above?

Thanks and rgds,
Seán.





On Wed, Feb 3, 2016 at 10:58 AM, HENAR MUÑOZ FRUTOS via RT <xifi-support at rt.cesnet.cz<mailto:xifi-support at rt.cesnet.cz>> wrote:
Hi
The endpoint for the POST request is http://aiakos.lab.fiware.org:3000/v1/support<http://aiakos.lab.fiware.org:3000/v1/support/Lannion2/gpgkey> not (http://aiakos.lab.fiware.org:3000/v1/support/Lannion2/gpgkey).
Regards,
Henar

De: Cristian CMECIU <ccmeciu at images-et-reseaux.com<mailto:ccmeciu at images-et-reseaux.com><mailto:ccmeciu at images-et-reseaux.com<mailto:ccmeciu at images-et-reseaux.com>>>
Fecha: miércoles, 3 de febrero de 2016 10:57
Para: "murp at zhaw.ch<mailto:murp at zhaw.ch><mailto:murp at zhaw.ch<mailto:murp at zhaw.ch>>" <murp at zhaw.ch<mailto:murp at zhaw.ch><mailto:murp at zhaw.ch<mailto:murp at zhaw.ch>>>
CC: "fiware-lab-federation-nodes at lists.fiware.org<mailto:fiware-lab-federation-nodes at lists.fiware.org><mailto:fiware-lab-federation-nodes at lists.fiware.org<mailto:fiware-lab-federation-nodes at lists.fiware.org>>" <fiware-lab-federation-nodes at lists.fiware.org<mailto:fiware-lab-federation-nodes at lists.fiware.org><mailto:fiware-lab-federation-nodes at lists.fiware.org<mailto:fiware-lab-federation-nodes at lists.fiware.org>>>
Asunto: Re: [Fiware-lab-federation-nodes] key generation

Hi all,

The Lannion node will use the same type of key: RSA 2048bits, valid for 2 years.

Have anyone succeeded to upload these keys to the Aiakos service?
When I'm trying to make a POST request I receive an 405 error: "Method not allowed"

I used a POST request as in the following example:
curl --request POST \
     --url http://aiakos.lab.fiware.org:3000/v1/support/Lannion2/gpgkey \
     --header 'accept: text/plain' \
     --header 'content-type: text/plain' \
     --data '-----BEGIN PGP PUBLIC KEY BLOCK-----\nVersion: GnuPG v1.4.11 (GNU/Linux)\n\nmQENBFawwG4BCADNFOwCWJOwOAoN2tGC2Gs5aMZSs5y7ZQzpQS5PZNRSbMQUEzF4\n-----END PGP PUBLIC KEY BLOCK-----'

Can anyone help me to solve it?

BR,
Cristian

De : fiware-lab-federation-nodes-bounces at lists.fiware.org<mailto:fiware-lab-federation-nodes-bounces at lists.fiware.org><mailto:fiware-lab-federation-nodes-bounces at lists.fiware.org<mailto:fiware-lab-federation-nodes-bounces at lists.fiware.org>> [mailto:fiware-lab-federation-nodes-bounces at lists.fiware.org<mailto:fiware-lab-federation-nodes-bounces at lists.fiware.org>] De la part de Vicent Borja Torres
Envoyé : jeudi 28 janvier 2016 11:04
À : Sean Murphy; fiware-lab-federation-nodes at lists.fiware.org<mailto:fiware-lab-federation-nodes at lists.fiware.org><mailto:fiware-lab-federation-nodes at lists.fiware.org<mailto:fiware-lab-federation-nodes at lists.fiware.org>>
Objet : Re: [Fiware-lab-federation-nodes] key generation

Hello Sean,

>From Gent node, we are going to use same as you. At least, we are two nodes on the same page.

Regards,

Vicent.
On 25/01/16 09:16, Sean Murphy wrote:
Hi all,

(I could put this on the ticket, but then I think that many folks
would not see it).

Quick q around the help ticket relating to keys: what key types
and durations should we generate? (I know this is up to us, but
I guess it's good if we are reasonably consistent and solve the
problem together instead of all solving it individually).

I guess for SSH we should go with 2048 bit RSA and the same
for GPG with a 2 year duration. Is this what the rest of you are
thinking?

BR,
Seán.





_______________________________________________

Fiware-lab-federation-nodes mailing list

Fiware-lab-federation-nodes at lists.fiware.org<mailto:Fiware-lab-federation-nodes at lists.fiware.org><mailto:Fiware-lab-federation-nodes at lists.fiware.org<mailto:Fiware-lab-federation-nodes at lists.fiware.org>>

https://lists.fiware.org/listinfo/fiware-lab-federation-nodes


________________________________

Este mensaje y sus adjuntos se dirigen exclusivamente a su destinatario, puede contener información privilegiada o confidencial y es para uso exclusivo de la persona o entidad de destino. Si no es usted. el destinatario indicado, queda notificado de que la lectura, utilización, divulgación y/o copia sin autorización puede estar prohibida en virtud de la legislación vigente. Si ha recibido este mensaje por error, le rogamos que nos lo comunique inmediatamente por esta misma vía y proceda a su destrucción.

The information contained in this transmission is privileged and confidential information intended only for the use of the individual or entity named above. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this transmission in error, do not read it. Please immediately reply to the sender that you have received this communication in error and then delete it.

Esta mensagem e seus anexos se dirigem exclusivamente ao seu destinatário, pode conter informação privilegiada ou confidencial e é para uso exclusivo da pessoa ou entidade de destino. Se não é vossa senhoria o destinatário indicado, fica notificado de que a leitura, utilização, divulgação e/ou cópia sem autorização pode estar proibida em virtude da legislação vigente. Se recebeu esta mensagem por erro, rogamos-lhe que nos o comunique imediatamente por esta mesma via e proceda a sua destruição



________________________________

Este mensaje y sus adjuntos se dirigen exclusivamente a su destinatario, puede contener información privilegiada o confidencial y es para uso exclusivo de la persona o entidad de destino. Si no es usted. el destinatario indicado, queda notificado de que la lectura, utilización, divulgación y/o copia sin autorización puede estar prohibida en virtud de la legislación vigente. Si ha recibido este mensaje por error, le rogamos que nos lo comunique inmediatamente por esta misma vía y proceda a su destrucción.

The information contained in this transmission is privileged and confidential information intended only for the use of the individual or entity named above. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this transmission in error, do not read it. Please immediately reply to the sender that you have received this communication in error and then delete it.

Esta mensagem e seus anexos se dirigem exclusivamente ao seu destinatário, pode conter informação privilegiada ou confidencial e é para uso exclusivo da pessoa ou entidade de destino. Se não é vossa senhoria o destinatário indicado, fica notificado de que a leitura, utilização, divulgação e/ou cópia sem autorização pode estar proibida em virtude da legislação vigente. Se recebeu esta mensagem por erro, rogamos-lhe que nos o comunique imediatamente por esta mesma via e proceda a sua destruição
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.fiware.org/private/fiware-lab-federation-nodes/attachments/20160208/4950e0f8/attachment.html>


More information about the Fiware-lab-federation-nodes mailing list

You can get more information about our cookies and privacy policies clicking on the following links: Privacy policy   Cookies policy