Re: Query String Request Authentication(QSRA) support by S3 providers

2013-07-19 Thread Min Chen
gt;>>>>user >> >>>>> >>>to >> >>>>> >>> > > >> download a template from S3, just like how Amazon >>provided >> >>>>>user >> >>>>> >>>a way to >> >>&

RE: Query String Request Authentication(QSRA) support by S3 providers

2013-07-19 Thread Jessica Wang
Sanjeev, Thanks for the confirmation. Jessica -Original Message- From: Sanjeev Neelarapu Sent: Thursday, July 18, 2013 11:05 PM To: dev@cloudstack.apache.org; Jessica Wang Cc: Edison Su; Thomas O'Dowd Subject: RE: Query String Request Authentication(QSRA) support by S3 provider

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-07-19 Thread Thomas O'Dowd
> >extractIso API. > > > >Jessica > > > > > >-Original Message- > >From: Min Chen > >Sent: Wednesday, July 03, 2013 5:53 PM > >To: dev@cloudstack.apache.org; Thomas O'Dowd > >Cc: Jessica Wang > >Subject: Re: Query Strin

RE: Query String Request Authentication(QSRA) support by S3 providers

2013-07-18 Thread Sanjeev Neelarapu
t;> >-min >>>>> > >>>>> >On 7/1/13 7:27 PM, "Thomas O'Dowd" wrote: >>>>> > >>>>> >>Yes thanks Jessica. I re-opened the bug again. I know its not a >>>>> >>gui problem per-say in that the

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-07-18 Thread Min Chen
;I just changed UI to not decode the URL returned in extractTemplate, >extractIso API. > >Jessica > > >-Original Message- >From: Min Chen >Sent: Wednesday, July 03, 2013 5:53 PM >To: dev@cloudstack.apache.org; Thomas O'Dowd >Cc: Jessica Wang >Subject: Re:

RE: Query String Request Authentication(QSRA) support by S3 providers

2013-07-08 Thread Jessica Wang
hen Sent: Wednesday, July 03, 2013 5:53 PM To: dev@cloudstack.apache.org; Thomas O'Dowd Cc: Jessica Wang Subject: Re: Query String Request Authentication(QSRA) support by S3 providers Jessica, would you please take a look at this to see if UI can disable decoding in displaying this download templat

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-07-03 Thread Min Chen
my "corrected" understanding is >>>>correct, >>>>I >>>> >>>would >>>> >>> > > >>like >>>> >>> > > >> >to amend my thoughts. Namely, I would like to see the >>>>driver >>&

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-07-03 Thread Min Chen
far as I can see, the objects in >>>the >>> >>S3 stores (AWS or Cloudian) are complete and from my perspective >>>"ready" >>> >>to download/use. It sounds like a bug when registering the template. >>> >> >>> >>Tom. >>> &

RE: Query String Request Authentication(QSRA) support by S3 providers

2013-07-03 Thread Edison Su
t;> >>S3 stores (AWS or Cloudian) are complete and from my perspective > >>"ready" > >> >>to download/use. It sounds like a bug when registering the template. > >> >> > >> >>Tom. > >> >> > >> >>

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-07-03 Thread Min Chen
t simply both sides of the >> >>>operation >> >>> > > >>by >> >>> > > >> >allowing the DataStore information to be treated opaquely >>until >> >>>it is >> >>>

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-07-02 Thread Thomas O'Dowd
The reason that the 2 templates("MyTiny", "AnotherTiny") have no > >>>download button is because they are not ready > >>> (i.e. their "isready" property is false). > >>> > >>> Download button is only available when "isready&

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-07-02 Thread Min Chen
that case, how do we keep backward compatibility of >>> > > >>extractTemplate >>> > > >> >> api, which requires a URL in the response? >>> > > >> >> >>> > > >> >> Thanks >>> > > >

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-07-02 Thread Min Chen
n "isready" property is true. >> >> Jessica >> >> -Original Message----- >> From: Thomas O'Dowd [mailto:tpod...@cloudian.com] >> Sent: Thursday, June 27, 2013 8:04 PM >> To: Min Chen >> Cc: dev@cloudstack.apache.org; Jessica W

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-07-01 Thread Thomas O'Dowd
riginal Message- > From: Thomas O'Dowd [mailto:tpod...@cloudian.com] > Sent: Thursday, June 27, 2013 8:04 PM > To: Min Chen > Cc: dev@cloudstack.apache.org; Jessica Wang > Subject: Re: Query String Request Authentication(QSRA) support by S3 providers > > Hi Min/Jessi

RE: Query String Request Authentication(QSRA) support by S3 providers

2013-07-01 Thread Jessica Wang
is true. Jessica -Original Message- From: Thomas O'Dowd [mailto:tpod...@cloudian.com] Sent: Thursday, June 27, 2013 8:04 PM To: Min Chen Cc: dev@cloudstack.apache.org; Jessica Wang Subject: Re: Query String Request Authentication(QSRA) support by S3 providers Hi Min/Jessica, I atta

RE: Query String Request Authentication(QSRA) support by S3 providers

2013-06-28 Thread Jessica Wang
omponents with actual > > >>resources > > >> >>> rather String references. Second, the current interface seems to > > >> >>>appears > > >> >>> to assume that an http/https URL will be returned. With I/O > > >>stream

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-06-27 Thread Marcus Sorensen
nderlying client > libraries > > > >> >>> provide. I/O streams provide a higher-level abstraction that > allows > > > >> >>> drivers to provide the orchestration components with actual > > > >>resources > > > >>

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-06-27 Thread Thomas O'Dowd
with actual > > >>resources > > >> >>> rather String references. Second, the current interface seems to > > >> >>>appears > > >> >>> to assume that an http/https URL will be returned. With I/O > > >>streams, > > >> &

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-06-27 Thread Thomas O'Dowd
gt;> >>> to assume that an http/https URL will be returned. With I/O > >>streams, > >> >>>we > >> >>> can support any client library capable of using the standard I/O > >> >>> framework -- enabling us to support other pr

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-06-27 Thread Min Chen
us to support other protocols for downloading >> >>> templates in the future (e.g. RBD, local filesystem, NBD, etc). >> >>> >> >>> Thanks, >> >>> -John >> >>> >> >>> On Jun 18, 2013, at 1:11 PM, Min Chen

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-06-27 Thread Thomas O'Dowd
gt;> -min > >>>> > >>>> On 6/18/13 8:29 AM, "Min Chen" wrote: > >>>> > >>>>> Yes, current code is in > >>>>>S3ImageStoreDriverImpl.createEntityExtractUrl, > >>>>> which has a security issue

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-06-21 Thread Min Chen
wrote: >>>> >>>>> Yes, current code is in >>>>>S3ImageStoreDriverImpl.createEntityExtractUrl, >>>>> which has a security issue mentioned in CLOUDSTACK-3030. I am going >>>>>to >>>>> change it to use generatePre

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-06-21 Thread John Burwell
am going to >>>> change it to use generatePresignedUrl api from AWS S3 api. >>>> >>>> Thanks >>>> -min >>>> >>>> From: John Burwell mailto:jburw...@basho.com>> >>>> Date: Tuesday, June 18, 2013 8:07 AM &g

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-06-18 Thread Min Chen
t; >>> Date: Tuesday, June 18, 2013 8:07 AM >>> To: Min Chen mailto:min.c...@citrix.com>> >>> Cc: Thomas O'Dowd mailto:tpod...@cloudian.com>>, >>> "dev@cloudstack.apache.org<mailto:dev@cloudstack.apache.org>" >>> mailto:d

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-06-18 Thread John Burwell
>> To: Min Chen mailto:min.c...@citrix.com>> >> Cc: Thomas O'Dowd mailto:tpod...@cloudian.com>>, >> "dev@cloudstack.apache.org<mailto:dev@cloudstack.apache.org>" >> mailto:dev@cloudstack.apache.org>> >> Subject: R

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-06-18 Thread Min Chen
od...@cloudian.com>>, >"dev@cloudstack.apache.org<mailto:dev@cloudstack.apache.org>" >mailto:dev@cloudstack.apache.org>> >Subject: Re: Query String Request Authentication(QSRA) support by S3 >providers > >Min, > >Is the code checked into the object_st

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-06-18 Thread Min Chen
3 8:07 AM To: Min Chen mailto:min.c...@citrix.com>> Cc: Thomas O'Dowd mailto:tpod...@cloudian.com>>, "dev@cloudstack.apache.org<mailto:dev@cloudstack.apache.org>" mailto:dev@cloudstack.apache.org>> Subject: Re: Query String Request Authentication(QSRA) suppo

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-06-18 Thread John Burwell
t for easy consumption. By using this method, I think that I > don't need to change ACL of S3 object to open a security hole. > > Thanks > -min > > From: John Burwell > Date: Monday, June 17, 2013 7:38 PM > To: Min Chen > Cc: Thomas O'Dowd , "dev@cloud

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-06-18 Thread Thomas O'Dowd
RA mentioned by Tom, by wrapped in > AmazonS3Client for easy consumption. By using this method, I think > that I don't need to change ACL of S3 object to open a security hole. > > > Thanks > -min > > > From: John Burwell > Date: Monday, June 17, 2013 7:38 PM &g

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-06-17 Thread Min Chen
Date: Monday, June 17, 2013 7:38 PM To: Min Chen mailto:min.c...@citrix.com>> Cc: Thomas O'Dowd mailto:tpod...@cloudian.com>>, "dev@cloudstack.apache.org<mailto:dev@cloudstack.apache.org>" mailto:dev@cloudstack.apache.org>> Subject: Re: Query String Reque

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-06-17 Thread John Burwell
Min, Why are we mucking with ACLs at all? The best security practice would be to create a bucket for CloudStack's use and assign it a dedicated access key and secret key pair with read/write access only to that bucket. Requiring an administrative account to an object store opens an unnecessarily

Re: Query String Request Authentication(QSRA) support by S3 providers

2013-06-17 Thread Thomas O'Dowd
Hi Min, RiakCS seems to support QSRA according to: http://docs.basho.com/riakcs/latest/cookbooks/Authentication/#Query-String-Authentication I'm not sure about other S3 AWS compatible providers. Perhaps others on the list can give feedback? I had a quick look at Ceph for example and they don't ex