*** david-lyle is now known as david-lyle_afk | 00:26 | |
*** _cjones_ has quit IRC | 00:33 | |
*** _cjones_ has joined #openstack-keystone | 00:36 | |
crinkle | zigo: hmm, I think I'm either misunderstanding or I didn't communicate effectively - we're looking to consume python-openstackclient in the stackforge puppet modules, ideally without the user having to add a new repository, so my inquiry was about its status in the ubuntu standard package repositories or ubuntu cloud archive (and similarly for epel/rdo) | 00:45 |
---|---|---|
crinkle | it's great that we can use that package for development in the mean time though | 00:46 |
*** lhcheng has quit IRC | 00:46 | |
*** lhcheng has joined #openstack-keystone | 00:47 | |
zigo | crinkle: I do *not* control whatever crap they do at Canonical ! :) | 00:50 |
crinkle | zigo: :) | 00:51 |
zigo | I do my bugs only in Debian... :) | 00:51 |
zigo | crinkle: You probably want to ask james page about that. | 00:51 |
*** lhcheng has quit IRC | 00:52 | |
crinkle | zigo: does he have an irc nick? | 00:52 |
zigo | Yeah... jamespage ... :) | 00:52 |
crinkle | how unexpected | 00:52 |
zigo | Otherwise James Page <james.page@canonical.com> | 00:53 |
crinkle | awesome, thanks for your help! | 00:53 |
zigo | But he's currently logged on IRC (both OFTC and Freenode). | 00:53 |
zigo | crinkle: No problem, and please do consider switching to Debian ! :) | 00:53 |
crinkle | zigo: haha, we're trying to support Debian + Ubuntu + RHEL :) | 00:54 |
crinkle | will probably try to bug people after the holiday | 00:55 |
mgagne | crinkle: there is a list of packages available in Ubuntu Cloud Archive: http://reqorts.qa.ubuntu.com/reports/ubuntu-server/cloud-archive/juno_versions.html and http://reqorts.qa.ubuntu.com/reports/ubuntu-server/cloud-archive/icehouse_versions.html | 00:55 |
crinkle | that is useful | 00:56 |
mgagne | crinkle: unfortunately, python-openstackclient looks to not be packaged in UCA | 00:56 |
crinkle | hence my inquiry | 00:56 |
*** raildo_ has joined #openstack-keystone | 00:57 | |
*** ekarlso- has quit IRC | 01:12 | |
*** ekarlso- has joined #openstack-keystone | 01:13 | |
*** diegows has quit IRC | 01:13 | |
*** raildo_ has quit IRC | 01:26 | |
*** henrynash has quit IRC | 01:29 | |
*** henrynash has joined #openstack-keystone | 01:34 | |
*** ChanServ sets mode: +v henrynash | 01:34 | |
*** kobtea has joined #openstack-keystone | 01:34 | |
*** NM has joined #openstack-keystone | 01:37 | |
*** kobtea has quit IRC | 01:39 | |
*** r-daneel has quit IRC | 01:47 | |
*** NM has quit IRC | 01:57 | |
*** _cjones_ has quit IRC | 01:58 | |
*** tellesnobrega_ has quit IRC | 02:04 | |
*** stevemar has joined #openstack-keystone | 02:11 | |
*** ChanServ sets mode: +v stevemar | 02:11 | |
*** fifieldt has joined #openstack-keystone | 02:13 | |
*** htruta_ has quit IRC | 02:16 | |
*** tellesnobrega_ has joined #openstack-keystone | 02:18 | |
*** jorge_munoz has quit IRC | 02:18 | |
*** erkules_ has joined #openstack-keystone | 02:27 | |
*** erkules has quit IRC | 02:29 | |
*** tellesnobrega_ has quit IRC | 02:29 | |
*** tellesnobrega_ has joined #openstack-keystone | 02:44 | |
*** saipandi has quit IRC | 02:48 | |
*** KanagarajM has joined #openstack-keystone | 02:54 | |
*** erkules_ is now known as erkules | 02:58 | |
*** harlowja_ is now known as harlowja_away | 03:18 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Update docs to no longer show XML support https://review.openstack.org/125753 | 03:38 |
openstackgerrit | wanghong proposed openstack/keystone: move matching id check in policy update into controller https://review.openstack.org/132152 | 03:44 |
openstackgerrit | wanghong proposed openstack/keystone: move matching id check in policy update into controller https://review.openstack.org/132152 | 03:44 |
*** jdennis1 has quit IRC | 03:47 | |
ayoung | nkinder, https://review.openstack.org/#/c/129951/ merged. It twice got caught in a server migration issue, dropping it from Zuul. | 03:57 |
nkinder | ayoung: yep, I saw the notification | 04:00 |
nkinder | ayoung: nice to see that finally go through | 04:00 |
ayoung | nkinder, I think we need to get more reviewers on the other puppet-keystone patches | 04:00 |
ayoung | also, Matt has an LDAP patch that is in merge conflict and has been sitting since August | 04:01 |
ayoung | want me to grab that? | 04:01 |
ayoung | er, Rich...not Matt | 04:02 |
ayoung | https://review.openstack.org/#/c/76002/ nkinder this one | 04:02 |
*** samuelms_ has joined #openstack-keystone | 04:06 | |
*** samuelms has quit IRC | 04:09 | |
openstackgerrit | ayoung proposed openstack/keystone: better handling for empty/None ldap values https://review.openstack.org/76002 | 04:13 |
*** tellesnobrega_ has quit IRC | 04:27 | |
*** oomichi_ has joined #openstack-keystone | 04:30 | |
openstackgerrit | Jamie Lennox proposed openstack/keystonemiddleware: Turn our auth plugin into a token interface https://review.openstack.org/137268 | 04:31 |
*** zzzeek has quit IRC | 04:37 | |
*** stevemar has quit IRC | 04:39 | |
openstackgerrit | Jamie Lennox proposed openstack/python-keystoneclient: Fix importing config module and classmethod params https://review.openstack.org/133866 | 04:49 |
*** _cjones_ has joined #openstack-keystone | 04:59 | |
*** _cjones_ has quit IRC | 05:04 | |
*** kobtea has joined #openstack-keystone | 05:12 | |
*** kobtea has quit IRC | 05:17 | |
*** ajayaa has joined #openstack-keystone | 05:21 | |
*** amakarov_away has quit IRC | 05:31 | |
*** amakarov_away has joined #openstack-keystone | 05:31 | |
*** Shohei has quit IRC | 05:35 | |
*** Shohei has joined #openstack-keystone | 05:36 | |
*** Shohei has quit IRC | 05:36 | |
*** Shohei has joined #openstack-keystone | 05:37 | |
openstackgerrit | Merged openstack/python-keystoneclient: Sync oslo-incubator to 1fc3cd47 https://review.openstack.org/130959 | 05:46 |
*** _cjones_ has joined #openstack-keystone | 05:56 | |
*** stevemar has joined #openstack-keystone | 06:03 | |
*** ChanServ sets mode: +v stevemar | 06:03 | |
stevemar | bump | 06:05 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Imported Translations from Transifex https://review.openstack.org/136243 | 06:07 |
*** k4n0 has joined #openstack-keystone | 06:26 | |
*** ukalifon1 has joined #openstack-keystone | 06:37 | |
*** _cjones_ has quit IRC | 06:40 | |
*** jamielennox is now known as jamielennox|away | 06:50 | |
*** ekarlso- has quit IRC | 06:54 | |
*** ekarlso- has joined #openstack-keystone | 06:54 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: New stuff https://review.openstack.org/137540 | 07:40 |
ekarlso- | stevemar: ^ not the best title i've seen :P | 07:41 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Add support for listing public idps https://review.openstack.org/137540 | 07:42 |
*** ukalifon1 has quit IRC | 07:47 | |
openstackgerrit | Marcos FermÃn Lobo proposed openstack/keystone: Implement group related methods for LDAP backend https://review.openstack.org/102244 | 07:47 |
*** stevemar has quit IRC | 07:56 | |
*** henrynash has quit IRC | 07:59 | |
*** henrynash has joined #openstack-keystone | 08:10 | |
*** ChanServ sets mode: +v henrynash | 08:10 | |
*** afazekas has joined #openstack-keystone | 08:19 | |
*** oomichi_ has quit IRC | 08:24 | |
*** kobtea has joined #openstack-keystone | 08:49 | |
*** mzbik has joined #openstack-keystone | 08:52 | |
mzbik | Anyone alive here? | 08:54 |
*** kobtea has quit IRC | 08:54 | |
mzbik | How can I pass filter like this (&(cn={0})(objectClass=groupOfUniqueNames)) in keystone with LDAP? | 08:55 |
mzbik | exact question is: how to pass argument to that cn={0}? | 08:56 |
*** jistr has joined #openstack-keystone | 09:10 | |
*** nellysmitt has joined #openstack-keystone | 09:14 | |
*** xiaozhi_ has joined #openstack-keystone | 09:29 | |
*** _cjones_ has joined #openstack-keystone | 09:41 | |
*** _cjones_ has quit IRC | 09:45 | |
*** tellesnobrega_ has joined #openstack-keystone | 10:15 | |
*** henrynash has quit IRC | 10:24 | |
*** tellesnobrega_ has quit IRC | 10:31 | |
*** tellesnobrega_ has joined #openstack-keystone | 10:35 | |
samuelms_ | morning | 10:36 |
*** samuelms_ is now known as samuelms | 10:36 | |
samuelms | mzbik, hi | 10:36 |
samuelms | mzbik, what do you'd like to do? filter users when calling list_users API? | 10:36 |
*** aix has joined #openstack-keystone | 10:37 | |
*** tellesnobrega_ has quit IRC | 10:52 | |
*** NM has joined #openstack-keystone | 10:52 | |
*** fifieldt has quit IRC | 10:59 | |
*** henrynash has joined #openstack-keystone | 11:08 | |
*** ChanServ sets mode: +v henrynash | 11:08 | |
mzbik | samuelms, rather I wanted to filter group name when listing groups | 11:13 |
mzbik | I have huge LDAP | 11:13 |
mzbik | I wanted to use /v3/groups?name=MyGroup&domain_id=123456 to filter only MyGroup | 11:14 |
mzbik | but | 11:14 |
mzbik | in LDAP for that domain there are thousands of groups | 11:14 |
mzbik | it too much for keystone (size exeeced) | 11:15 |
mzbik | and I cant use page_size | 11:15 |
mzbik | so I thout I could use that kind of filter to filter only one group without fetching all groups from LDAP | 11:17 |
*** NM has quit IRC | 11:30 | |
*** NM has joined #openstack-keystone | 11:30 | |
*** xiaozhi_ has quit IRC | 11:38 | |
openstackgerrit | Boris Bobrov proposed openstack/python-keystoneclient: Add self-installation to venv deployment https://review.openstack.org/137613 | 11:42 |
*** henrynash has quit IRC | 11:48 | |
*** aix has quit IRC | 11:55 | |
samuelms | mzbik, why are you passing domain_id on your request? /v3/groups?name=MyGroup&domain_id=123456 | 11:58 |
samuelms | mzbik, one you have a token for that domain, you just need to query /v3/groups?name=MyGroup | 11:59 |
mzbik | samuelms, im affraid you are wrong | 12:00 |
mzbik | it is obligatory if you have multibackend in keystone | 12:00 |
mzbik | https://bugs.launchpad.net/keystone/+bug/1387379 | 12:00 |
uvirtbot | Launchpad bug 1387379 in keystone "No documentation on the fact that List users/groups require a domain to be specified in multi domain configuration" [Medium,In progress] | 12:00 |
mzbik | "if domain-specific drivers are enabled then, as indicated above, you must specify a domain_id as par of the a GET /users or GET /groups call." | 12:01 |
samuelms | mzbik, so you're using this? | 12:03 |
samuelms | mzbik, you have multiple ldap connected instead of a single one as you said .. | 12:03 |
rodrigods | mzbik, you need to specify only if you don't have the domain_id in your token | 12:04 |
*** diegows has joined #openstack-keystone | 12:04 | |
mzbik | rodrigods, I have but it does not work, anyways clue is a bit different ;) | 12:05 |
*** diegows has quit IRC | 12:14 | |
mzbik | samuelms, yes I have SQL backend for service users and LDAP for rest of users cause I have read-only LDAP and cannot change it. | 12:20 |
*** k4n0 has quit IRC | 12:26 | |
samuelms | mzbik, ok .. I think ayoung is a good person to help you out .. he understand better how ldap things are implemented | 12:29 |
mzbik | ayoung, ping | 12:30 |
marekd | mzbik: ^^ so you are now doomed :P | 12:30 |
mzbik | Am I? :( | 12:30 |
mzbik | erm... ayound is Adam Young? | 12:30 |
marekd | yep | 12:30 |
mzbik | yes... Im doomed | 12:31 |
mzbik | :P | 12:31 |
samuelms | haha | 12:31 |
*** KanagarajM has quit IRC | 12:37 | |
openstackgerrit | Andre Aranha proposed openstack/keystone-specs: Modify the policy file https://review.openstack.org/135408 | 12:53 |
*** kobtea has joined #openstack-keystone | 12:55 | |
*** f13o_f13o has joined #openstack-keystone | 12:55 | |
*** f13o_f13o has quit IRC | 12:55 | |
*** kobtea has quit IRC | 12:59 | |
*** aix has joined #openstack-keystone | 13:06 | |
*** dims has joined #openstack-keystone | 13:20 | |
*** dims_ has joined #openstack-keystone | 13:24 | |
*** dims has quit IRC | 13:27 | |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Comparision of database models and migrations. https://review.openstack.org/80630 | 13:37 |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Fix index name the assignment.actor_id table. https://review.openstack.org/137637 | 13:37 |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Add primary key to the endpoint_group id column. https://review.openstack.org/137638 | 13:37 |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Add index to the revocation_event.revoked_at. https://review.openstack.org/137639 | 13:37 |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Migrate_repo init version helper https://review.openstack.org/137640 | 13:37 |
openstackgerrit | Ilya Pekelny proposed openstack/keystone: Use metadata.create_all() to fill a test database https://review.openstack.org/93558 | 13:37 |
*** jaosorior has joined #openstack-keystone | 13:39 | |
*** gordc has joined #openstack-keystone | 13:49 | |
ajayaa | Hi. How does other openstack components check for project's existence in keystone, where project_id is used in the url. | 13:58 |
ayoung | mzbik, it is thanksgiving here, and I am really not supposed to be doing work.... | 13:59 |
ayoung | I think you can filter on groups | 13:59 |
mzbik | ayoung, I will try to ping you after holidays then | 14:01 |
*** mzbik has quit IRC | 14:09 | |
*** NM1 has joined #openstack-keystone | 14:29 | |
*** NM has quit IRC | 14:31 | |
*** ukalifon1 has joined #openstack-keystone | 14:39 | |
*** _cjones_ has joined #openstack-keystone | 15:00 | |
*** dims has joined #openstack-keystone | 15:05 | |
*** dims_ has quit IRC | 15:09 | |
*** stevemar has joined #openstack-keystone | 15:09 | |
*** ChanServ sets mode: +v stevemar | 15:09 | |
*** r-daneel has joined #openstack-keystone | 15:10 | |
*** jdennis has joined #openstack-keystone | 15:23 | |
*** NM1 has quit IRC | 15:28 | |
marekd | stevemar: if you make an apache configuration with <Location /v3/OS-FEDERATION/identity_providers/*/...> you would need to *again* implement Discover service, something you want to do for Horizon already... | 15:29 |
marekd | stevemar: so, you 'd go to horizon, choose idp of your choice, get redirected to Keystone, go again to similar page where you choose a IdP of your choice. | 15:29 |
marekd | stevemar: hi, btw :-) | 15:31 |
stevemar | marekd, hello as well :) | 15:32 |
marekd | maybe the the alternative is to implement one endpoint, v3/OS-FEDERATION/websso | 15:33 |
marekd | where a user is redirected always | 15:33 |
*** NM has joined #openstack-keystone | 15:33 | |
marekd | then, he actually gets to the DS | 15:33 |
marekd | which is completely separate from Keystone | 15:34 |
marekd | user authenticates | 15:34 |
marekd | gets back to /websso endpoint | 15:34 |
marekd | and the right mapping is choosed basing on IdP identifier squeezed into saml assertion | 15:34 |
marekd | then, we would need to add entityId in the identity_provider objects, instead of is_public | 15:35 |
marekd | like here: https://github.com/cernops/keystone/commit/66dabd94b4ad32abca171cef9192210fec289235 | 15:37 |
marekd | you know what i mean? | 15:41 |
*** ukalifon1 has quit IRC | 15:59 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone-specs: Trust redelegation documentation https://review.openstack.org/131541 | 16:23 |
*** stevemar has quit IRC | 16:27 | |
*** _cjones_ has quit IRC | 16:28 | |
*** kobtea has joined #openstack-keystone | 16:32 | |
*** jaosorior has quit IRC | 16:33 | |
*** kobtea has quit IRC | 16:37 | |
*** _cjones_ has joined #openstack-keystone | 16:37 | |
*** afazekas has quit IRC | 16:46 | |
*** nellysmitt has quit IRC | 16:46 | |
*** jdennis has quit IRC | 17:29 | |
*** nellysmitt has joined #openstack-keystone | 17:31 | |
*** ajayaa has quit IRC | 17:43 | |
*** jistr has quit IRC | 17:50 | |
*** diegows has joined #openstack-keystone | 17:52 | |
*** mzbik has joined #openstack-keystone | 17:52 | |
*** _cjones_ has quit IRC | 18:04 | |
openstackgerrit | Sergey Kraynev proposed openstack/python-keystoneclient: Using correct keyword for region in v3 https://review.openstack.org/118383 | 18:19 |
*** _cjones_ has joined #openstack-keystone | 18:31 | |
*** jaosorior has joined #openstack-keystone | 18:44 | |
*** svasheka has quit IRC | 18:51 | |
*** svasheka has joined #openstack-keystone | 18:51 | |
*** stevemar has joined #openstack-keystone | 18:58 | |
*** ChanServ sets mode: +v stevemar | 18:58 | |
*** henrynash has joined #openstack-keystone | 19:05 | |
*** ChanServ sets mode: +v henrynash | 19:05 | |
*** aix has quit IRC | 19:15 | |
*** dims has quit IRC | 19:27 | |
openstackgerrit | Andre Aranha proposed openstack/keystone: Modify the policy v3 sample https://review.openstack.org/123509 | 19:33 |
openstackgerrit | Andre Aranha proposed openstack/keystone-specs: Modify the policy file https://review.openstack.org/135408 | 19:41 |
*** afaranha has left #openstack-keystone | 20:01 | |
*** nellysmitt has quit IRC | 20:02 | |
*** _cjones_ has quit IRC | 20:08 | |
*** afaranha has joined #openstack-keystone | 20:09 | |
*** kobtea has joined #openstack-keystone | 20:10 | |
*** mzbik has quit IRC | 20:11 | |
*** kobtea has quit IRC | 20:15 | |
*** dims has joined #openstack-keystone | 20:27 | |
*** mzbik has joined #openstack-keystone | 20:31 | |
*** _cjones_ has joined #openstack-keystone | 20:34 | |
*** mzbik_ has joined #openstack-keystone | 20:45 | |
*** mzbik has quit IRC | 20:49 | |
*** dims has quit IRC | 21:02 | |
samuelms | henrynash, which one sounds better: '_list_applicable_assignments_TO_user_and_project' or '_list_applicable_assignments_FOR_user_and_project'? | 21:08 |
samuelms | henrynash, applicable should be direct + indirect assignments (from expansion) | 21:09 |
samuelms | does anyone know which one sounds better ? | 21:10 |
samuelms | I meant, which one is correct ? if both, then which one sounds better :p | 21:10 |
*** mzbik_ has quit IRC | 21:12 | |
*** NM has quit IRC | 21:12 | |
*** dims has joined #openstack-keystone | 21:14 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/136616 | 21:42 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/135965 | 21:43 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/134794 | 21:48 |
*** dims has quit IRC | 21:49 | |
*** nellysmitt has joined #openstack-keystone | 22:03 | |
*** nellysmitt has quit IRC | 22:07 | |
*** samuelms_ has joined #openstack-keystone | 22:17 | |
*** stevemar has quit IRC | 22:27 | |
*** stevemar has joined #openstack-keystone | 22:29 | |
*** ChanServ sets mode: +v stevemar | 22:29 | |
*** lhcheng has joined #openstack-keystone | 22:40 | |
*** stevemar has quit IRC | 22:54 | |
*** gordc has quit IRC | 23:01 | |
*** jamielennox|away is now known as jamielennox | 23:19 | |
*** tellesnobrega_ has joined #openstack-keystone | 23:21 | |
*** diegows has quit IRC | 23:21 | |
*** jaosorior has quit IRC | 23:23 | |
*** oomichi has joined #openstack-keystone | 23:43 | |
*** dims has joined #openstack-keystone | 23:46 | |
*** kobtea has joined #openstack-keystone | 23:47 | |
*** kobtea has quit IRC | 23:52 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!