blob: e485a24bca288be6219adfbb6a348e6ce6ff433a [file] [log] [blame]
Petr Jediný1ff6f562017-08-09 14:38:09 +02001barbican:
2 server:
Petr Jedinýdd6387a2017-08-01 15:50:17 +02003 enabled: true
Petr Jediný1ff6f562017-08-09 14:38:09 +02004 version: ocata
5 host_href: ''
6 is_proxied: true
Oleg Iurchenko622ef902017-12-13 01:40:04 +02007 dogtag_admin_cert:
8 engine: manual
9 key: 'some dogtag key'
Petr Jediný1ff6f562017-08-09 14:38:09 +020010 plugin:
11 simple_crypto:
12 kek: "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXoxMjM0NTY="
13 p11_crypto:
14 library_path: '/usr/lib/libCryptoki2_64.so'
15 login: 'mypassword'
16 mkek_label: 'an_mkek'
17 mkek_length: 32
18 hmac_label: 'my_hmac_label'
19 kmip:
20 username: 'admin'
21 password: 'password'
22 host: localhost
23 port: 5696
24 keyfile: '/path/to/certs/cert.key'
25 certfile: '/path/to/certs/cert.crt'
26 ca_certs: '/path/to/certs/LocalCA.crt'
27 dogtag:
28 pem_path: '/etc/barbican/kra_admin_cert.pem'
29 dogtag_host: localhost
Petr Jedinýdcc90f82017-10-02 13:46:10 +020030 dogtag_port: 8443
Petr Jediný1ff6f562017-08-09 14:38:09 +020031 nss_db_path: '/etc/barbican/alias'
32 nss_db_path_ca: '/etc/barbican/alias-ca'
33 nss_password: 'password123'
34 simple_cmc_profile: 'caOtherCert'
35 ca_expiration_time: 1
36 plugin_working_dir: '/etc/barbican/dogtag'
37 store:
38 software:
39 crypto_plugin: simple_crypto
40 store_plugin: store_crypto
41 global_default: True
42 kmip:
43 store_plugin: kmip_plugin
44 dogtag:
Petr Jedinýdcc90f82017-10-02 13:46:10 +020045 store_plugin: dogtag_crypto
Petr Jediný1ff6f562017-08-09 14:38:09 +020046 pkcs11:
47 store_plugin: store_crypto
48 crypto_plugin: p11_crypto
Petr Jedinýdd6387a2017-08-01 15:50:17 +020049 database:
Petr Jediný1ff6f562017-08-09 14:38:09 +020050 engine: "mysql+pymysql"
51 host: 10.0.106.20
Petr Jedinýdd6387a2017-08-01 15:50:17 +020052 port: 3306
Petr Jediný1ff6f562017-08-09 14:38:09 +020053 name: barbican
54 user: barbican
Petr Jedinýdd6387a2017-08-01 15:50:17 +020055 password: password
Petr Jediný1ff6f562017-08-09 14:38:09 +020056 bind:
57 address: 10.0.106.20
58 port: 9311
59 admin_port: 9312
Petr Jedinýdd6387a2017-08-01 15:50:17 +020060 identity:
61 engine: keystone
Petr Jediný1ff6f562017-08-09 14:38:09 +020062 host: 10.0.106.20
Petr Jedinýdd6387a2017-08-01 15:50:17 +020063 port: 35357
Petr Jediný1ff6f562017-08-09 14:38:09 +020064 domain: default
Petr Jedinýdd6387a2017-08-01 15:50:17 +020065 tenant: service
Petr Jediný1ff6f562017-08-09 14:38:09 +020066 user: barbican
67 password: password
Petr Jedinýdd6387a2017-08-01 15:50:17 +020068 message_queue:
69 engine: rabbitmq
Petr Jedinýdd6387a2017-08-01 15:50:17 +020070 user: openstack
71 password: password
72 virtual_host: '/openstack'
Petr Jediný1ff6f562017-08-09 14:38:09 +020073 members:
74 - host: 10.10.10.10
75 port: 5672
76 - host: 10.10.10.11
77 port: 5672
78 - host: 10.10.10.12
79 port: 5672
80 cache:
Oleksandr Bryndzii82d506e2019-03-14 11:19:06 +020081 engine: memcached
82 expiration_time: 600
83 backend_argument:
84 memcached_expire_time:
85 value: 660
Petr Jediný1ff6f562017-08-09 14:38:09 +020086 members:
87 - host: 10.10.10.10
88 port: 11211
89 - host: 10.10.10.11
90 port: 11211
91 - host: 10.10.10.12
92 port: 11211
Oleksandr Bryndzii1139fcc2018-10-04 12:58:30 +030093 security:
94 enabled: true
95 strategy: ENCRYPT
96 secret_key: secret
sgarbuza9931392018-07-19 10:44:20 +030097 logging:
98 log_appender: false
99 log_handlers:
100 watchedfile:
Michael Polenchuk38646112018-12-18 15:53:07 +0400101 enabled: false
sgarbuza9931392018-07-19 10:44:20 +0300102 fluentd:
103 enabled: false
104 ossyslog:
105 enabled: false
Martin Polreichb9481722018-01-22 12:08:23 +0100106apache:
107 server:
108 enabled: true
Vasyl Saienko88bc10b2018-03-03 04:22:03 +0200109 default_mpm: event
110 mpm:
111 prefork:
112 enabled: true
113 servers:
114 start: 5
115 spare:
116 min: 2
117 max: 10
118 max_requests: 0
119 max_clients: 20
120 limit: 20
Michael Polenchuk38646112018-12-18 15:53:07 +0400121 site:
122 barbican:
123 enabled: false
124 available: true
125 type: wsgi
126 name: barbican
127 wsgi:
128 daemon_process: barbican-api
129 processes: 3
130 threads: 10
131 user: barbican
132 group: barbican
133 display_name: '%{GROUP}'
134 script_alias: '/ /usr/bin/barbican-wsgi-api'
135 application_group: '%{GLOBAL}'
136 authorization: 'On'
137 host:
138 address: 127.0.0.1
139 name: 127.0.0.1
140 port: 9311
141 barbican_admin:
142 enabled: false
143 available: true
144 type: wsgi
145 name: barbican_admin
146 wsgi:
147 daemon_process: barbican-api-admin
148 processes: 3
149 threads: 10
150 user: barbican
151 group: barbican
152 display_name: '%{GROUP}'
153 script_alias: '/ /usr/bin/barbican-wsgi-api'
154 application_group: '%{GLOBAL}'
155 authorization: 'On'
156 host:
157 address: 127.0.0.1
158 name: 127.0.0.1
159 port: 9312