*** hrou has joined #openstack-keystone | 00:00 | |
*** openstack has joined #openstack-keystone | 00:03 | |
*** tsymanczyk has joined #openstack-keystone | 00:04 | |
*** markvoelker has quit IRC | 00:04 | |
*** TheIntern has quit IRC | 00:07 | |
*** boris-42 has quit IRC | 00:12 | |
*** stevemar has joined #openstack-keystone | 00:23 | |
*** ChanServ sets mode: +v stevemar | 00:23 | |
*** hogepodge has joined #openstack-keystone | 00:25 | |
*** spandhe has joined #openstack-keystone | 00:26 | |
*** ankita_wagh has quit IRC | 00:29 | |
*** spandhe_ has joined #openstack-keystone | 00:29 | |
*** spandhe has quit IRC | 00:31 | |
*** spandhe_ is now known as spandhe | 00:31 | |
*** woodster_ has quit IRC | 00:32 | |
*** stevemar has quit IRC | 00:32 | |
*** btully has quit IRC | 00:35 | |
*** shaleh has quit IRC | 00:36 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 00:37 | |
*** zzzeek has joined #openstack-keystone | 00:43 | |
*** scorpio-xiatian has joined #openstack-keystone | 00:53 | |
*** rm_work is now known as rm_work|away | 01:00 | |
*** zzzeek has quit IRC | 01:08 | |
jiaxi | Please help me to review my patch set. visit https://review.openstack.org/#/c/200512/ | 01:09 |
---|---|---|
*** jasonsb has quit IRC | 01:11 | |
*** _cjones_ has quit IRC | 01:12 | |
openstackgerrit | Jamie Lennox proposed openstack/python-keystoneclient-kerberos: Disable optional authentication for plugin https://review.openstack.org/188329 | 01:12 |
openstackgerrit | Jamie Lennox proposed openstack/python-keystoneclient-kerberos: Federated Kerberos plugin https://review.openstack.org/173558 | 01:12 |
*** woodster_ has joined #openstack-keystone | 01:25 | |
jiaxi | <jiaxi> Please help me to review my patch set. visit https://review.openstack.org/#/c/200512/ | 01:32 |
*** afazekas has quit IRC | 01:34 | |
*** jdandrea has quit IRC | 01:46 | |
*** tobe_ has joined #openstack-keystone | 01:49 | |
*** ankita_wagh has joined #openstack-keystone | 01:51 | |
*** ankita_wagh has quit IRC | 01:52 | |
*** ankita_wagh has joined #openstack-keystone | 01:53 | |
*** lhcheng has joined #openstack-keystone | 01:57 | |
*** ChanServ sets mode: +v lhcheng | 01:57 | |
miguelgrinberg | marekd rodrigods: do you guys have an example openrc file for openstack client that does the ECP auth flow? | 02:02 |
*** amakarov has joined #openstack-keystone | 02:11 | |
*** piyanai has joined #openstack-keystone | 02:19 | |
*** richm has quit IRC | 02:20 | |
*** ayoung has joined #openstack-keystone | 02:27 | |
*** ChanServ sets mode: +v ayoung | 02:27 | |
*** dims_ has quit IRC | 02:31 | |
bigjools | miguelgrinberg: IIRC you need to add --os-auth-type v3unscopedsaml --os-identity-provider-url=<ecp endpoint> --os-identity-provider <idp in keystone> | 02:35 |
*** chlong-afk has quit IRC | 02:37 | |
*** lhcheng has quit IRC | 02:37 | |
*** chenhong has joined #openstack-keystone | 02:39 | |
*** chlong has joined #openstack-keystone | 02:42 | |
*** stevemar has joined #openstack-keystone | 02:44 | |
*** ChanServ sets mode: +v stevemar | 02:44 | |
bigjools | can the same project be part of more than one domain? | 02:44 |
*** ayoung has quit IRC | 02:45 | |
*** ankita_wagh has quit IRC | 02:47 | |
*** stevemar has quit IRC | 02:49 | |
*** hakimo has joined #openstack-keystone | 02:53 | |
*** hakimo_ has quit IRC | 02:55 | |
*** piyanai has quit IRC | 02:55 | |
nigelb | wah! hi bigjools :) | 02:58 |
bigjools | hey nigelb | 02:58 |
*** hakimo_ has joined #openstack-keystone | 03:10 | |
*** hakimo has quit IRC | 03:10 | |
*** boris-42 has joined #openstack-keystone | 03:14 | |
*** Kennan has quit IRC | 03:20 | |
*** Kennan has joined #openstack-keystone | 03:20 | |
openstackgerrit | jiaxi proposed openstack/keystone: when creating a group without specifying a domain should return 400 https://review.openstack.org/201511 | 03:25 |
*** hakimo has joined #openstack-keystone | 03:27 | |
*** hakimo_ has quit IRC | 03:27 | |
jiaxi | Please help me to review my patch set. visit https://review.openstack.org/#/c/200512/ | 03:28 |
*** woodster_ has quit IRC | 03:32 | |
*** dims_ has joined #openstack-keystone | 03:32 | |
*** dims_ has quit IRC | 03:37 | |
*** hakimo_ has joined #openstack-keystone | 03:44 | |
*** hakimo has quit IRC | 03:44 | |
*** stevemar has joined #openstack-keystone | 03:46 | |
*** ChanServ sets mode: +v stevemar | 03:46 | |
*** geoffarnold has joined #openstack-keystone | 04:00 | |
*** scorpio-xiatian has quit IRC | 04:01 | |
*** hakimo has joined #openstack-keystone | 04:01 | |
*** hakimo_ has quit IRC | 04:01 | |
*** amakarov has quit IRC | 04:05 | |
*** geoffarnold has quit IRC | 04:09 | |
*** hakimo_ has joined #openstack-keystone | 04:18 | |
*** hakimo has quit IRC | 04:18 | |
*** fangzhou has quit IRC | 04:22 | |
*** jasonsb has joined #openstack-keystone | 04:28 | |
*** thedodd has joined #openstack-keystone | 04:33 | |
*** tobe_ has quit IRC | 04:53 | |
*** flwang has quit IRC | 05:00 | |
*** stevemar_ has joined #openstack-keystone | 05:04 | |
*** ChanServ sets mode: +v stevemar_ | 05:04 | |
*** ParsectiX has joined #openstack-keystone | 05:05 | |
*** stevemar has quit IRC | 05:07 | |
*** telemonster has quit IRC | 05:08 | |
*** telemonster has joined #openstack-keystone | 05:08 | |
*** blewis has joined #openstack-keystone | 05:10 | |
*** blewis` has joined #openstack-keystone | 05:12 | |
*** ankita_wagh has joined #openstack-keystone | 05:14 | |
*** blewis has quit IRC | 05:15 | |
*** browne has quit IRC | 05:16 | |
*** thedodd has quit IRC | 05:17 | |
*** ParsectiX has quit IRC | 05:18 | |
*** dguerri` is now known as dguerri | 05:19 | |
*** boris-42_ has joined #openstack-keystone | 05:20 | |
*** diazjf1 has joined #openstack-keystone | 05:21 | |
*** browne has joined #openstack-keystone | 05:21 | |
*** Daviey_ has joined #openstack-keystone | 05:22 | |
*** samuel-dmq has joined #openstack-keystone | 05:23 | |
*** boris-42 has quit IRC | 05:23 | |
*** Protux has quit IRC | 05:23 | |
*** mancdaz has quit IRC | 05:23 | |
*** Daviey has quit IRC | 05:23 | |
*** samueldmq has quit IRC | 05:23 | |
*** Protux has joined #openstack-keystone | 05:24 | |
*** boris-42_ is now known as boris-42 | 05:24 | |
*** mancdaz has joined #openstack-keystone | 05:24 | |
*** chenhong1 has joined #openstack-keystone | 05:27 | |
*** browne has quit IRC | 05:27 | |
*** chenhong has quit IRC | 05:28 | |
*** markvoelker has joined #openstack-keystone | 05:41 | |
*** markvoelker_ has joined #openstack-keystone | 05:44 | |
*** markvoelker has quit IRC | 05:45 | |
*** tobe_ has joined #openstack-keystone | 05:46 | |
*** hrou has quit IRC | 05:52 | |
jiaxi | Please help me to review my patch set. visit https://review.openstack.org/#/c/200512/ | 05:53 |
*** spandhe has quit IRC | 06:00 | |
*** dims_ has joined #openstack-keystone | 06:00 | |
*** stevemar_ has quit IRC | 06:03 | |
*** stevemar has joined #openstack-keystone | 06:04 | |
*** ChanServ sets mode: +v stevemar | 06:04 | |
*** spandhe has joined #openstack-keystone | 06:04 | |
*** stevemar_ has joined #openstack-keystone | 06:06 | |
*** ChanServ sets mode: +v stevemar_ | 06:06 | |
*** dims_ has quit IRC | 06:06 | |
*** ParsectiX has joined #openstack-keystone | 06:07 | |
*** ig0r_ has joined #openstack-keystone | 06:08 | |
*** stevemar has quit IRC | 06:09 | |
ParsectiX | Good Morning :) | 06:09 |
*** stevemar_ has quit IRC | 06:10 | |
*** tobe_ has quit IRC | 06:16 | |
openstackgerrit | David Stanek proposed openstack/keystone: Moves keystone.hacking into keystone.tests https://review.openstack.org/202895 | 06:26 |
*** tobe_ has joined #openstack-keystone | 06:31 | |
*** dguerri is now known as dguerri` | 06:40 | |
*** jaosorior has joined #openstack-keystone | 06:43 | |
*** ig0r_ has quit IRC | 06:45 | |
*** ig0r_ has joined #openstack-keystone | 06:50 | |
*** belmoreira has joined #openstack-keystone | 06:51 | |
*** ankita_wagh has quit IRC | 07:05 | |
*** ankita_wagh has joined #openstack-keystone | 07:05 | |
*** afazekas has joined #openstack-keystone | 07:06 | |
*** bradjones has quit IRC | 07:08 | |
*** bradjones has joined #openstack-keystone | 07:11 | |
*** bradjones has quit IRC | 07:11 | |
*** bradjones has joined #openstack-keystone | 07:11 | |
*** boris-42 has quit IRC | 07:12 | |
*** Pawel__ has joined #openstack-keystone | 07:23 | |
*** fhubik has joined #openstack-keystone | 07:34 | |
*** fhubik has quit IRC | 07:46 | |
*** fhubik has joined #openstack-keystone | 07:48 | |
*** dims_ has joined #openstack-keystone | 07:49 | |
*** dims_ has quit IRC | 07:56 | |
*** ankita_wagh has quit IRC | 08:00 | |
*** rm_work|away is now known as rm_work | 08:04 | |
*** fhubik is now known as fhubik_afk | 08:07 | |
*** jistr has joined #openstack-keystone | 08:15 | |
jiaxi | Please help me to review my patch set. visit https://review.openstack.org/#/c/200512/ | 08:19 |
*** chenhong has joined #openstack-keystone | 08:22 | |
openstackgerrit | jiaxi proposed openstack/keystone: Invalid URLs are not suppressed when creating endpoint https://review.openstack.org/200512 | 08:23 |
*** blewis` has quit IRC | 08:23 | |
*** chenhong1 has quit IRC | 08:24 | |
*** fhubik_afk is now known as fhubik | 08:28 | |
*** rletrocquer has joined #openstack-keystone | 08:29 | |
*** blewis has joined #openstack-keystone | 08:31 | |
*** kashyap has left #openstack-keystone | 08:32 | |
*** pnavarro has joined #openstack-keystone | 08:39 | |
*** markvoelker_ has quit IRC | 08:42 | |
*** spandhe has quit IRC | 08:43 | |
*** mhu has quit IRC | 08:53 | |
*** mhu has joined #openstack-keystone | 08:56 | |
*** markvoelker has joined #openstack-keystone | 08:57 | |
*** fhubik is now known as fhubik_afk | 09:00 | |
*** ParsectiX has quit IRC | 09:00 | |
*** e0ne has joined #openstack-keystone | 09:01 | |
*** markvoelker has quit IRC | 09:02 | |
*** fhubik_afk is now known as fhubik | 09:04 | |
*** ParsectiX has joined #openstack-keystone | 09:05 | |
*** aix has joined #openstack-keystone | 09:07 | |
*** markvoelker has joined #openstack-keystone | 09:12 | |
*** Daviey_ is now known as Daviey | 09:14 | |
*** dims_ has joined #openstack-keystone | 09:15 | |
*** markvoelker has quit IRC | 09:17 | |
*** dims_ has quit IRC | 09:20 | |
*** tobe_ has quit IRC | 09:25 | |
*** blewis` has joined #openstack-keystone | 09:25 | |
*** markvoelker has joined #openstack-keystone | 09:26 | |
*** blewis has quit IRC | 09:29 | |
*** markvoelker has quit IRC | 09:31 | |
*** Kennan2 has joined #openstack-keystone | 09:33 | |
*** Kennan has quit IRC | 09:33 | |
*** marzif_ has joined #openstack-keystone | 09:39 | |
*** markvoelker has joined #openstack-keystone | 09:41 | |
*** david8hu has quit IRC | 09:43 | |
*** david8hu has joined #openstack-keystone | 09:43 | |
*** markvoelker has quit IRC | 09:45 | |
*** fhubik is now known as fhubik_afk | 09:52 | |
*** piyanai has joined #openstack-keystone | 09:55 | |
*** markvoelker has joined #openstack-keystone | 09:55 | |
*** markvoelker has quit IRC | 10:00 | |
*** dims_ has joined #openstack-keystone | 10:05 | |
*** ParsectiX has quit IRC | 10:05 | |
*** ParsectiX has joined #openstack-keystone | 10:06 | |
*** markvoelker has joined #openstack-keystone | 10:07 | |
*** markvoelker has quit IRC | 10:12 | |
*** btully has joined #openstack-keystone | 10:14 | |
*** ParsectiX has quit IRC | 10:15 | |
*** rm_work is now known as rm_work|away | 10:19 | |
*** btully has quit IRC | 10:19 | |
*** markvoelker has joined #openstack-keystone | 10:22 | |
*** openstackgerrit has quit IRC | 10:31 | |
*** markvoelker has quit IRC | 10:32 | |
*** openstackgerrit has joined #openstack-keystone | 10:32 | |
*** fhubik_afk is now known as fhubik | 10:33 | |
*** ParsectiX has joined #openstack-keystone | 10:35 | |
*** jaosorior has quit IRC | 10:36 | |
*** markvoelker has joined #openstack-keystone | 10:37 | |
*** chenhong1 has joined #openstack-keystone | 10:37 | |
*** chenhong has quit IRC | 10:38 | |
*** lsmola has joined #openstack-keystone | 10:40 | |
*** aix has quit IRC | 10:41 | |
*** chenhong1 has quit IRC | 10:42 | |
*** markvoelker has quit IRC | 10:42 | |
*** aix has joined #openstack-keystone | 10:45 | |
openstackgerrit | Alexey Miroshkin proposed openstack/keystone: Implement backend filtering on membership queries https://review.openstack.org/179758 | 10:51 |
*** markvoelker has joined #openstack-keystone | 10:51 | |
*** markvoelker has quit IRC | 10:56 | |
*** dims_ has quit IRC | 11:06 | |
*** markvoelker has joined #openstack-keystone | 11:06 | |
*** markvoelker has quit IRC | 11:11 | |
*** piyanai has quit IRC | 11:19 | |
*** fhubik has quit IRC | 11:19 | |
*** markvoelker has joined #openstack-keystone | 11:19 | |
*** piyanai has joined #openstack-keystone | 11:20 | |
*** piyanai has quit IRC | 11:22 | |
*** markvoelker has quit IRC | 11:24 | |
*** pnavarro is now known as pnavarro|lunch | 11:29 | |
*** markvoelker has joined #openstack-keystone | 11:32 | |
*** alex_xu is now known as alexus | 11:34 | |
*** markvoelker has quit IRC | 11:44 | |
*** amakarov has joined #openstack-keystone | 11:45 | |
*** josecastroleon has joined #openstack-keystone | 11:51 | |
marekd | miguelgrinberg: there is no OSC wrapper around k2k | 11:53 |
marekd | i can share my script with you if you need it. | 11:53 |
*** markvoelker has joined #openstack-keystone | 11:55 | |
jiaxi | Please help me to review my patch set. visit https://review.openstack.org/#/c/200512/ | 11:55 |
*** bdossant has joined #openstack-keystone | 11:59 | |
*** markvoelker has quit IRC | 12:00 | |
*** pnavarro|lunch has quit IRC | 12:09 | |
*** markvoelker has joined #openstack-keystone | 12:09 | |
*** markvoelker has quit IRC | 12:13 | |
*** markvoelker has joined #openstack-keystone | 12:16 | |
*** markvoelker has quit IRC | 12:21 | |
*** lsmola has quit IRC | 12:21 | |
*** amakarov has quit IRC | 12:21 | |
*** lsmola has joined #openstack-keystone | 12:23 | |
*** jasonsb has quit IRC | 12:23 | |
*** edmondsw has joined #openstack-keystone | 12:23 | |
*** markvoelker has joined #openstack-keystone | 12:24 | |
odyssey4me | marekd I have some bad news :/ | 12:24 |
odyssey4me | it seems that I've uncovered some sort of bug | 12:24 |
*** dims_ has joined #openstack-keystone | 12:25 | |
*** stevemar has joined #openstack-keystone | 12:25 | |
*** ChanServ sets mode: +v stevemar | 12:25 | |
odyssey4me | I have a perfectly working SP setup that works against TestShib. With exactly the same configuration other than switching from http to https, I get a valid auth but keystone thinks that the user has no access to projects. | 12:26 |
*** stevemar has quit IRC | 12:29 | |
*** markvoelker has quit IRC | 12:32 | |
*** stevephone has joined #openstack-keystone | 12:35 | |
*** stevephone has quit IRC | 12:37 | |
*** markvoelker has joined #openstack-keystone | 12:39 | |
*** piyanai has joined #openstack-keystone | 12:40 | |
*** piyanai has quit IRC | 12:40 | |
*** jiaxi has quit IRC | 12:43 | |
*** markvoelker has quit IRC | 12:43 | |
*** woodster_ has joined #openstack-keystone | 12:46 | |
*** piyanai has joined #openstack-keystone | 12:51 | |
*** amakarov has joined #openstack-keystone | 12:52 | |
*** markvoelker has joined #openstack-keystone | 12:53 | |
*** dims_ has quit IRC | 12:54 | |
*** piyanai has quit IRC | 12:55 | |
*** markvoelker has quit IRC | 12:58 | |
*** browne has joined #openstack-keystone | 13:00 | |
*** piyanai has joined #openstack-keystone | 13:00 | |
*** jasonsb has joined #openstack-keystone | 13:00 | |
*** piyanai has quit IRC | 13:00 | |
*** samuel-dmq has quit IRC | 13:04 | |
*** samueldmq has joined #openstack-keystone | 13:04 | |
*** markvoelker has joined #openstack-keystone | 13:05 | |
*** piyanai has joined #openstack-keystone | 13:06 | |
*** markvoelker_ has joined #openstack-keystone | 13:07 | |
marekd | odyssey4me: can you introduce me a little bit more? | 13:07 |
odyssey4me | marekd so I have a test setup which was configured to work with TestShib without SSL. | 13:08 |
odyssey4me | The keystone configs, mappings, etc are all there and were tested to be in a working state. | 13:08 |
*** markvoelker has quit IRC | 13:09 | |
*** diegoadolfo has joined #openstack-keystone | 13:10 | |
odyssey4me | I then set keystone's public endpoint to be https, implemented the certificate, configured shibboleth2.xml to be aware of the changes (entityID, etc), reconfigured horizon to use the updated endpoint, etc | 13:10 |
odyssey4me | I verified that the metadata showed all URL's in the content to be via https and verified that it was accessible via https | 13:11 |
odyssey4me | I submitted the updated metadata to TestShib, then tried a login via WebSSO. | 13:11 |
odyssey4me | I get a valid session to TestShib, WebSSO let's me through, but keystone thinks I have access to no projects. | 13:12 |
odyssey4me | whereas when I tested it without SSL I had access to a project. | 13:12 |
*** rdo has quit IRC | 13:13 | |
*** lhcheng has joined #openstack-keystone | 13:14 | |
*** ChanServ sets mode: +v lhcheng | 13:14 | |
marekd | odyssey4me: did you update metdatafile (same name) or updated another one? | 13:14 |
marekd | odyssey4me: i suspect this might be something with repeated metadata file etc. | 13:14 |
odyssey4me | marekd same name gave other errors, so I uploaded with a new name | 13:15 |
*** rdo has joined #openstack-keystone | 13:15 | |
odyssey4me | the error I'm seeing is exactly the same error I saw with my ADFS IdP - I decided to check the setup against TestShib to validate whether the issue was specific to ADFS or not | 13:15 |
*** jsavak has joined #openstack-keystone | 13:16 | |
marekd | odyssey4me: so you claim that switching between http and https has some impliations on keystone tokens? | 13:17 |
odyssey4me | what makes no sense to me is that shibboleth has a valid session, but keystone seems to do something funky afterwards | 13:17 |
odyssey4me | marekd it would seem that the protocol has an effect on the token somehow, yes - it looks to me like it never goes beyond a scoped token | 13:18 |
marekd | odyssey4me: while switching from https->http did you restart shibd too? | 13:19 |
marekd | odyssey4me: you can try that. | 13:19 |
*** Kiall has quit IRC | 13:20 | |
odyssey4me | marekd yep, I did - in fact I've done both a fresh build and a conversion back and forth | 13:20 |
*** stevemar has joined #openstack-keystone | 13:20 | |
*** ChanServ sets mode: +v stevemar | 13:20 | |
*** hrou has joined #openstack-keystone | 13:21 | |
marekd | odyssey4me: to me it looks more like a shib problem, not rally keystone... | 13:21 |
marekd | odyssey4me: anyways, then it doesn't find a vali project what does it say in logS? | 13:21 |
*** Kiall has joined #openstack-keystone | 13:21 | |
odyssey4me | let me get a fresh set of logs quickly | 13:22 |
*** jecarey has joined #openstack-keystone | 13:24 | |
*** stevemar has quit IRC | 13:25 | |
odyssey4me | marekd keystone log: http://paste.openstack.org/show/4CAyxMVchwDfRPUyUZmJ/ | 13:26 |
odyssey4me | marekd: shibd log: http://paste.openstack.org/show/Nk2DjgnCvvz5Cdcbtf6P/ | 13:28 |
marekd | odyssey4me: looking | 13:29 |
odyssey4me | marekd the metadata is here if you'd like to inspect it: https://test1.pigeonbrawl.net:5000/Shibboleth.sso/Metadata | 13:29 |
*** kodoku has joined #openstack-keystone | 13:30 | |
*** topol has joined #openstack-keystone | 13:32 | |
*** ChanServ sets mode: +v topol | 13:32 | |
*** markvoelker_ has quit IRC | 13:34 | |
*** dguerri` has quit IRC | 13:37 | |
*** jiaxi has joined #openstack-keystone | 13:37 | |
*** kodoku has quit IRC | 13:38 | |
*** anteaya has quit IRC | 13:38 | |
*** dguerri` has joined #openstack-keystone | 13:40 | |
*** dguerri` is now known as dguerri | 13:41 | |
*** dguerri has joined #openstack-keystone | 13:41 | |
*** zzzeek has joined #openstack-keystone | 13:41 | |
*** anteaya has joined #openstack-keystone | 13:42 | |
*** pnavarro|lunch has joined #openstack-keystone | 13:43 | |
*** hakimo has joined #openstack-keystone | 13:43 | |
*** hakimo_ has quit IRC | 13:43 | |
*** stevemar has joined #openstack-keystone | 13:44 | |
*** ChanServ sets mode: +v stevemar | 13:44 | |
marekd | odyssey4me: "2015-07-17 13:24:26.421 2435 DEBUG keystone.middleware.core [-] Auth token not in the request header. Will not build auth context. process_request /usr/local/lib/python2.7/dist-packages/keystone/middleware/core.py:200" | 13:44 |
marekd | odyssey4me: i still think it's a matter of shibboleth not evicting sessions/cookies. | 13:45 |
*** dims_ has joined #openstack-keystone | 13:45 | |
marekd | and it's super strange for me that it doesn't do that after killing shibd daemon. | 13:45 |
breton | gyee: | 13:46 |
jiaxi | Please spare some minutes in reviewing my patch set https://review.openstack.org/#/c/200512/ | 13:46 |
jiaxi | thank you in advance | 13:46 |
odyssey4me | marekd an issue on the SP or the IDP? | 13:47 |
marekd | SP | 13:47 |
marekd | i think | 13:47 |
*** Guest9887 has quit IRC | 13:48 | |
marekd | morganfainberg: where should bugs against ksa-saml2 (or any ksa-* project) be filed? lanuchpad/bugs/keystonauth-saml2 or lanuchpad/bugs/keystoneauth ? | 13:48 |
*** stevemar has quit IRC | 13:48 | |
odyssey4me | marekd ok, perhaps a cookie is interfering here even though I'm doing a private browsing session - let me flush and try again | 13:49 |
*** markvoelker has joined #openstack-keystone | 13:49 | |
morganfainberg | marekd: we should have an LP page, but we haven't been using it yet | 13:49 |
*** jaosorior has joined #openstack-keystone | 13:49 | |
morganfainberg | https://launchpad.net/keystoneauth | 13:49 |
*** blewis has joined #openstack-keystone | 13:49 | |
*** blewis is now known as Guest62465 | 13:49 | |
marekd | ok, so ksa subprojects are still handled by https://launchpad.net/keystoneauth . | 13:49 |
*** raildo1 is now known as raildo | 13:51 | |
*** stevemar has joined #openstack-keystone | 13:51 | |
*** ChanServ sets mode: +v stevemar | 13:51 | |
openstackgerrit | Marek Denis proposed openstack/keystoneauth-saml2: Depend on keystoneauth https://review.openstack.org/186854 | 13:52 |
*** stevemar_ has joined #openstack-keystone | 13:52 | |
*** ChanServ sets mode: +v stevemar_ | 13:52 | |
openstackgerrit | Marek Denis proposed openstack/keystoneauth-saml2: Standardize federated auth token scoping https://review.openstack.org/177227 | 13:53 |
marekd | lhcheng: ^^ | 13:53 |
*** markvoelker has quit IRC | 13:54 | |
*** stevemar has quit IRC | 13:55 | |
*** pnavarro|lunch is now known as pnavarro | 13:56 | |
*** jdandrea has joined #openstack-keystone | 13:56 | |
lhcheng | marekd: looking | 13:56 |
odyssey4me | marekd fresh, whole new browser and the same result | 13:57 |
*** stevemar_ has quit IRC | 13:57 | |
*** stevemar has joined #openstack-keystone | 13:58 | |
*** ChanServ sets mode: +v stevemar | 13:58 | |
*** ayoung has joined #openstack-keystone | 13:58 | |
*** ChanServ sets mode: +v ayoung | 13:58 | |
*** markvoelker has joined #openstack-keystone | 13:59 | |
marekd | morganfainberg: odyssey4me wait, so you switched from https to http some time ago and you still have some problems with that? you are not being redirected to a IdP and the cookie is somewhere there? | 13:59 |
marekd | morganfainberg: sorry | 14:00 |
*** gyee has joined #openstack-keystone | 14:00 | |
*** ChanServ sets mode: +v gyee | 14:00 | |
odyssey4me | marekd no - let me clarify - I took a working http setup and converted it to serve via https and now while the auth works, keystone doesn't seem to allow an unscoped token | 14:00 |
odyssey4me | marekd I also did a fresh build immediately with an https setup, and had the same results | 14:01 |
marekd | odyssey4me: and chance to try it myself? | 14:02 |
marekd | odyssey4me: is this server available from the internet ? | 14:02 |
odyssey4me | marekd yep, you can test directly to https://test1.pigeonbrawl.net | 14:02 |
lhcheng | ayoung: https://review.openstack.org/#/c/202224/ | 14:02 |
marekd | odyssey4me: let me try then. | 14:03 |
odyssey4me | marekd I can put your ssh key on the server too to look around if you like. | 14:03 |
marekd | odyssey4me: what's idp name you configured? | 14:04 |
marekd | in keystone | 14:05 |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:06 | |
samueldmq | ayoung: ping - do you have any news on the dynamic policy ? I'd like to figure out the next step I can do in the next weeks :) | 14:07 |
*** markvoelker has quit IRC | 14:07 | |
odyssey4me | testshib-idp: https://idp.testshib.org/idp/shibboleth | 14:09 |
odyssey4me | marekd ^ | 14:09 |
ayoung | samueldmq, 1 sec | 14:09 |
samueldmq | ayoung: sure sir | 14:09 |
*** cinerama has quit IRC | 14:09 | |
jiaxi | Would you spare some minutes in reviewing my patch set https://review.openstack.org/#/c/200512/ ? | 14:09 |
*** jecarey has quit IRC | 14:09 | |
*** jecarey has joined #openstack-keystone | 14:10 | |
*** hakimo has quit IRC | 14:11 | |
*** hakimo_ has joined #openstack-keystone | 14:11 | |
*** ParsectiX has quit IRC | 14:12 | |
*** rdo has quit IRC | 14:13 | |
*** markvoelker has joined #openstack-keystone | 14:14 | |
*** fangzhou has joined #openstack-keystone | 14:14 | |
marekd | odyssey4me: no no, idp name you added to keystone | 14:15 |
marekd | i want to try link: keystone:5000/v3/OS-FEDERATION/identity_providers/{idp}/protocols/{saml2}/auth | 14:15 |
marekd | and need idp name :-) | 14:16 |
odyssey4me | marekd: testshib-idp | 14:17 |
*** markvoelker has quit IRC | 14:18 | |
marekd | odyssey4me: https://test1.pigeonbrawl.net:5000/v3/OS-FEDERATION/identity_providers/testship-idp/protocols/saml2/auth gives me 404 | 14:19 |
marekd | http 404 "Cannot find Identity Provider testshib-idp" | 14:20 |
marekd | to be more specific | 14:20 |
odyssey4me | marekd odd, it redirects me straight to testshib | 14:20 |
marekd | the link i just pasted? | 14:20 |
odyssey4me | yep | 14:20 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Cleanup logging in federation/idp.py https://review.openstack.org/203047 | 14:20 |
marekd | odyssey4me: apparently you were not copy psting my link as i made typo :P | 14:21 |
odyssey4me | marekd heh, I see that - this is the only idp so it'll redirect any auth request to it :p | 14:21 |
*** csoukup has joined #openstack-keystone | 14:22 | |
marekd | odyssey4me: so i got unscoped token | 14:22 |
marekd | odyssey4me: i closed, opened by browser in private mode and had to auth again. | 14:23 |
odyssey4me | marekd sounds like my experience so far | 14:23 |
*** mylu has joined #openstack-keystone | 14:24 | |
lhcheng | marekd: added comment to https://review.openstack.org/#/c/186854/ (missed a spot) | 14:24 |
*** mestery has quit IRC | 14:25 | |
rodrigods | marekd, stevemar ping... https://review.openstack.org/#/c/192438/ without this, the K2K plugin won't work =( | 14:28 |
*** markvoelker has joined #openstack-keystone | 14:28 | |
marekd | rodrigods: i will take a look later, ok ? | 14:31 |
rodrigods | marekd, ok, thx | 14:31 |
rodrigods | just to make sure it is in your review list :) | 14:32 |
*** rdo has joined #openstack-keystone | 14:32 | |
*** Kennan2 has quit IRC | 14:32 | |
*** markvoelker has quit IRC | 14:33 | |
openstackgerrit | Marek Denis proposed openstack/keystoneauth-saml2: Depend on keystoneauth https://review.openstack.org/186854 | 14:33 |
*** Kennan has joined #openstack-keystone | 14:33 | |
marekd | lhcheng: again | 14:33 |
marekd | rodrigods: it's starred :P | 14:36 |
*** piyanai has quit IRC | 14:36 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Move constants out of federation.core https://review.openstack.org/200706 | 14:39 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Federation API provides method to evaluate rules https://review.openstack.org/196308 | 14:39 |
*** TheIntern has joined #openstack-keystone | 14:40 | |
*** mgarza_ has joined #openstack-keystone | 14:43 | |
*** fangzhou has quit IRC | 14:45 | |
*** fangzhou has joined #openstack-keystone | 14:46 | |
*** markvoelker has joined #openstack-keystone | 14:50 | |
*** diegoadolfo__ has joined #openstack-keystone | 14:51 | |
*** diegoadolfo__ has quit IRC | 14:51 | |
*** diegoadolfo has quit IRC | 14:52 | |
*** gyee has quit IRC | 14:53 | |
*** piyanai has joined #openstack-keystone | 14:54 | |
*** markvoelker has quit IRC | 14:57 | |
*** rdo has quit IRC | 14:57 | |
*** markvoelker_ has joined #openstack-keystone | 14:57 | |
*** markvoelker_ has quit IRC | 14:57 | |
*** markvoelker has joined #openstack-keystone | 14:57 | |
*** mestery has joined #openstack-keystone | 14:58 | |
dstanek | jiaxi: please be patient. there are lots of patches that we are working on and most of us are currently traveling | 14:59 |
*** rdo has joined #openstack-keystone | 14:59 | |
dstanek | morganfainberg: http://paste.openstack.org/show/383928/ | 15:02 |
*** bknudson has joined #openstack-keystone | 15:03 | |
*** ChanServ sets mode: +v bknudson | 15:03 | |
*** gyee has joined #openstack-keystone | 15:03 | |
*** ChanServ sets mode: +v gyee | 15:03 | |
samueldmq | dstanek: what is that ? that's scaring, looks like the check isn't working properly | 15:04 |
*** jsavak has quit IRC | 15:05 | |
morganfainberg | dstanek: /me cries | 15:05 |
morganfainberg | dstanek: yeah we need to *not* do that anymore :P | 15:05 |
dstanek | morganfainberg: i haven;t actually check to see if they are all valid | 15:05 |
dstanek | samueldmq: what do you mean? | 15:05 |
morganfainberg | dstanek: the oauth1 is | 15:06 |
morganfainberg | i just looked | 15:07 |
morganfainberg | thye *probably* all are | 15:07 |
*** jsavak has joined #openstack-keystone | 15:07 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Clean up notifications type checking https://review.openstack.org/200733 | 15:07 |
*** blewis` has quit IRC | 15:10 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Remove unnecessary check from notifications.py https://review.openstack.org/203069 | 15:12 |
*** Pawel__ has quit IRC | 15:13 | |
anteaya | morganfainberg: if you want to support the multinode work, sdague is looking for reviews on this patch: https://review.openstack.org/#/c/199091/12 | 15:18 |
*** shaleh has joined #openstack-keystone | 15:19 | |
*** roxanaghe has joined #openstack-keystone | 15:21 | |
morganfainberg | anteaya: cool | 15:21 |
anteaya | :) | 15:22 |
*** jecarey has quit IRC | 15:23 | |
*** fangzhou has quit IRC | 15:23 | |
marekd | roxanaghe: hello | 15:23 |
stevemar | roxanaghe: http://specs.openstack.org/openstack/keystone-specs/specs/liberty/functional-testing.html << spec | 15:23 |
stevemar | roxanaghe: https://review.openstack.org/#/c/151310/8 << first patch | 15:23 |
stevemar | roxanaghe: the gate changes we would have to make: https://github.com/openstack-infra/project-config/blob/master/jenkins/jobs/keystone.yaml | 15:24 |
stevemar | roxanaghe: https://github.com/openstack-infra/project-config/blob/master/jenkins/jobs/osc.yaml | 15:25 |
marekd | odyssey4me: sorry, i am doing 5 things at the same itme. | 15:26 |
marekd | time | 15:26 |
odyssey4me | marekd no problem, I realise that you're pressed for time | 15:26 |
*** rdo has quit IRC | 15:27 | |
*** cinerama has joined #openstack-keystone | 15:27 | |
*** rdo has joined #openstack-keystone | 15:27 | |
stevemar | roxanaghe: http://www.ibm.com/developerworks/cloud/library/cl-ldap-keystone/ | 15:28 |
roxanaghe | stevemar, thanks | 15:28 |
*** janonymous_ has joined #openstack-keystone | 15:28 | |
miguelgrinberg | marekd: so this script to wrap openstack client that you mentioned just does the ECP workflow and then sets env vars for endpoint and token for openstack client to use? | 15:31 |
samueldmq | dstanek: I meant that paste, why does it say 'Undesirable "else" block found' when actually it has found a for block? | 15:32 |
marekd | miguelgrinberg: it's not for wrapping osc, it's for wrapping k2k auth plugin | 15:33 |
samueldmq | dstanek: or are those codes using that for/else python construct? | 15:33 |
dstanek | samueldmq: that's my new check :-) no for-else and while-else | 15:33 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone: Do not remove expired revocation events on "get" https://review.openstack.org/203085 | 15:33 |
samueldmq | dstanek: great, I think a message telling 'Undesirable "for-else" block found' though | 15:34 |
samueldmq | dstanek: instead of just telling 'else block'; but that's up to you to decide :) | 15:34 |
morganfainberg | mfisch: what is your gerrit user? | 15:34 |
morganfainberg | mfisch: want to tag you on a fix | 15:35 |
morganfainberg | for review | 15:35 |
morganfainberg | mfisch, dolphm: re: revocation events - https://review.openstack.org/#/c/203085/ | 15:35 |
morganfainberg | and fixing for DB churn-y things | 15:35 |
morganfainberg | in short - don't prune on get, prune on revocation issuance | 15:36 |
morganfainberg | ayoung: https://review.openstack.org/#/c/203085/ | 15:37 |
*** mylu has quit IRC | 15:38 | |
*** mylu has joined #openstack-keystone | 15:39 | |
*** gyee has quit IRC | 15:41 | |
ayoung | https://review.openstack.org/#/c/203085/1 | 15:42 |
ayoung | bknudson, ^^ | 15:42 |
*** mylu has quit IRC | 15:42 | |
*** belmoreira has quit IRC | 15:43 | |
*** mylu has joined #openstack-keystone | 15:45 | |
*** mylu has quit IRC | 15:47 | |
*** mylu has joined #openstack-keystone | 15:48 | |
*** chlong has quit IRC | 15:49 | |
*** raildo_ has joined #openstack-keystone | 15:49 | |
*** btully has joined #openstack-keystone | 15:50 | |
*** gyee has joined #openstack-keystone | 15:50 | |
*** ChanServ sets mode: +v gyee | 15:50 | |
*** ankita_wagh has joined #openstack-keystone | 15:51 | |
*** bdossant has quit IRC | 15:53 | |
*** jsavak has quit IRC | 15:54 | |
*** jsavak has joined #openstack-keystone | 15:55 | |
*** raildo_ has quit IRC | 15:58 | |
*** afazekas has quit IRC | 15:58 | |
*** tsymanczyk has quit IRC | 15:59 | |
*** mestery has quit IRC | 16:01 | |
*** mestery has joined #openstack-keystone | 16:01 | |
marekd | odyssey4me: can you give me project_id that federated user should be albe to use ? | 16:02 |
odyssey4me | marekd sure, hold a minute | 16:02 |
odyssey4me | marekd: c0cde3fd864045ce97f384614f7e317d | 16:02 |
*** eglute has quit IRC | 16:04 | |
openstackgerrit | Brant Knudson proposed openstack/keystonemiddleware: Use marker for py3 test requirements https://review.openstack.org/203107 | 16:04 |
*** eglute has joined #openstack-keystone | 16:05 | |
marekd | odyssey4me: ok, i might miss something but..i can get unscoped and scoped token via CLI | 16:05 |
marekd | odyssey4me: was it something you had problems with ? | 16:06 |
openstackgerrit | Brant Knudson proposed openstack/keystonemiddleware: Use marker for py3 test requirements https://review.openstack.org/203107 | 16:06 |
odyssey4me | marekd ok, then the issue must be somewhere in the websso - when you try to use horizon it kicks out saying that it can't find any projects the user can access | 16:06 |
marekd | lhcheng: ^^ | 16:07 |
* marekd lhcheng to the rescue | 16:07 | |
*** ankita_wagh has quit IRC | 16:10 | |
lhcheng | odyssey4me: when you restarted apache, you got kicked out? | 16:12 |
*** Kiall has quit IRC | 16:12 | |
*** Kiall has joined #openstack-keystone | 16:13 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/202282 | 16:13 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/197254 | 16:13 |
lhcheng | odyssey4me: if horizon is using in-memory session backend, restarting apache would cause all users to have invalid session | 16:14 |
*** rm_work|away is now known as rm_work | 16:14 | |
odyssey4me | lhcheng no, you can try it yourself: hit https://test1.pigeonbrawl.net - use the testshib login method (federated via saml2) | 16:15 |
odyssey4me | it'll kick you back, saying that the use has no access to any projects. | 16:15 |
odyssey4me | when using websso without ssl on the keystone endpoint, it works fine - you get in and have access to projects. | 16:16 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/203137 | 16:17 |
odyssey4me | lhcheng: Login failed: Unable to retrieve authorized projects. | 16:18 |
openstackgerrit | David Stanek proposed openstack/keystone: Adds a base class for functional tests https://review.openstack.org/203142 | 16:18 |
odyssey4me | lhcheng: but marekd has confirmed that retrieving a scope and unscoped token works just fine | 16:18 |
marekd | lhcheng: yep | 16:18 |
dstanek | samueldmq: those are the loops that contain the construct | 16:18 |
lhcheng | odyssey4me: did you update the keystone conf too | 16:19 |
*** geoffarnold has joined #openstack-keystone | 16:19 | |
lhcheng | odyssey4me: [federation] trusted_dashboard = https://test1.pigeonbrawl.net.. > | 16:19 |
odyssey4me | lhcheng: two entries | 16:20 |
odyssey4me | [federation] | 16:20 |
odyssey4me | remote_id_attribute = Shib-Identity-Provider | 16:20 |
odyssey4me | trusted_dashboard = https://104.130.5.125/auth/websso/ | 16:20 |
odyssey4me | trusted_dashboard = https://test1.pigeonbrawl.net/auth/websso/ | 16:20 |
samueldmq | dstanek: yes, but what I meant is: you saying an unexpected for-else or while-else construct was found could be better than just telling an else statement was found | 16:20 |
odyssey4me | lhcheng I just removed the first one to test, same result | 16:21 |
dstanek | samueldmq: so just a msg change? i don't think i can easily get the line of the else, but i'll look at that later | 16:21 |
samueldmq | dstanek: just to be more specific. in fact, that's just a suggestion on the message, I like the fact you're creating those checks :) | 16:21 |
*** TheIntern has quit IRC | 16:22 | |
dstanek | samueldmq: unfortunately i did this a 2am when i couldn't sleep so it can probably be done better | 16:22 |
samueldmq | dstanek: even if you can't get to the line of the else, just saying for-else or while-else could be more specific :) | 16:22 |
dstanek | samueldmq: i'd love the ^ to point to the else | 16:22 |
samueldmq | dstanek: yeah could be better :) | 16:22 |
*** _cjones_ has joined #openstack-keystone | 16:23 | |
*** eglute has quit IRC | 16:23 | |
*** eglute has joined #openstack-keystone | 16:24 | |
samueldmq | ayoung: you around ? | 16:24 |
samueldmq | ayoung: still need to talk to you to figure out the next steps, let me know when you have some minutes :) | 16:25 |
*** jaosorior has quit IRC | 16:26 | |
lhcheng | odyssey4me: looking at the horizon code, it fails at the point when it tries to use the federated unscoped token to get list of projects. | 16:29 |
odyssey4me | lhcheng notes that I did hit https://bugs.launchpad.net/horizon/+bug/1452232 but have applied the patch | 16:30 |
openstack | Launchpad bug 1452232 in OpenStack Dashboard (Horizon) ""NameError: global name '_' is not defined" on keystone authorization error" [Medium,Confirmed] - Assigned to Doug Fish (drfish) | 16:30 |
*** jistr has quit IRC | 16:31 | |
lhcheng | odyssey4me: would you be able to test the federated token to call the list projects api? | 16:32 |
lhcheng | odyssey4me: yup, you got passed that bug | 16:32 |
*** eglute has quit IRC | 16:33 | |
*** eglute has joined #openstack-keystone | 16:34 | |
*** dims_ has quit IRC | 16:37 | |
*** piyanai has quit IRC | 16:38 | |
lhcheng | odyssey4me: curious, what session backend do you use for horizon? | 16:38 |
odyssey4me | lhcheng memcache for the cache backend, and cached_db for the session engine | 16:40 |
odyssey4me | ie django.core.cache.backends.memcached.MemcachedCache and django.contrib.sessions.backends.cached_db | 16:41 |
lhcheng | odyssey4me: cool, that should be fine | 16:41 |
odyssey4me | lhcheng it may be pertinent to note that this environment's also using uuid tokens | 16:42 |
odyssey4me | but I think you figured that out already :p | 16:42 |
*** stevemar has quit IRC | 16:42 | |
lhcheng | odyssey4me: yup, uuid token should be fine | 16:43 |
*** stevemar has joined #openstack-keystone | 16:43 | |
*** ChanServ sets mode: +v stevemar | 16:43 | |
*** topol has quit IRC | 16:43 | |
*** BrAsS_mOnKeY has quit IRC | 16:45 | |
*** ankita_wagh has joined #openstack-keystone | 16:45 | |
lhcheng | odyssey4me: might need to turn on debug on horizon, to see the response return by keystone when the federated token was used to get the list of projects | 16:46 |
*** gyee has quit IRC | 16:46 | |
lhcheng | do you see error in keystone? | 16:46 |
lhcheng | odyssey4me: heading out for lunch, brb | 16:47 |
*** amakarov has quit IRC | 16:47 | |
*** tsymanczyk has joined #openstack-keystone | 16:47 | |
odyssey4me | lhcheng debug's already on ;) | 16:47 |
lhcheng | does it show the api request made to keystone? | 16:48 |
*** stevemar has quit IRC | 16:48 | |
odyssey4me | lhcheng no error in keystone, but we've learned that keystone swallows exceptions too well - so I may need to add more debugging statements to work through it | 16:48 |
*** roxanaghe has quit IRC | 16:48 | |
*** fangzhou has joined #openstack-keystone | 16:49 | |
odyssey4me | lhcheng this is an earlier log - I can get a fresh one if you like: http://paste.openstack.org/show/4CAyxMVchwDfRPUyUZmJ/ | 16:50 |
odyssey4me | enjoy lunch! | 16:50 |
*** diazjf1 has left #openstack-keystone | 16:51 | |
*** sigmavirus24 has quit IRC | 16:52 | |
*** sigmavirus24 has joined #openstack-keystone | 16:52 | |
*** browne has quit IRC | 16:54 | |
*** mylu has quit IRC | 16:54 | |
*** stevemar has joined #openstack-keystone | 16:55 | |
*** ChanServ sets mode: +v stevemar | 16:55 | |
*** stevemar_ has joined #openstack-keystone | 16:56 | |
*** ChanServ sets mode: +v stevemar_ | 16:56 | |
*** Ephur has joined #openstack-keystone | 16:57 | |
openstackgerrit | Merged openstack/keystone: Log xmlsec1 output if it fails https://review.openstack.org/202477 | 16:57 |
*** sigmavirus24 has quit IRC | 16:57 | |
*** stevema__ has joined #openstack-keystone | 16:58 | |
*** ChanServ sets mode: +v stevema__ | 16:58 | |
*** piyanai has joined #openstack-keystone | 16:58 | |
*** mylu has joined #openstack-keystone | 16:58 | |
*** ankita_w_ has joined #openstack-keystone | 16:59 | |
*** ankita_w_ has quit IRC | 17:00 | |
*** stevemar has quit IRC | 17:00 | |
*** sigmavirus24 has joined #openstack-keystone | 17:00 | |
*** ankita_w_ has joined #openstack-keystone | 17:00 | |
*** stevemar_ has quit IRC | 17:01 | |
*** ankita_wagh has quit IRC | 17:02 | |
*** stevema__ has quit IRC | 17:02 | |
*** tsymanczyk has quit IRC | 17:02 | |
*** BrAsS_mOnKeY has joined #openstack-keystone | 17:04 | |
*** BrAsS_mOnKeY has quit IRC | 17:06 | |
*** tsymanczyk has joined #openstack-keystone | 17:07 | |
*** mylu has quit IRC | 17:10 | |
*** spandhe has joined #openstack-keystone | 17:12 | |
*** piyanai has quit IRC | 17:14 | |
*** mylu has joined #openstack-keystone | 17:15 | |
*** jasonsb has quit IRC | 17:17 | |
*** jasonsb has joined #openstack-keystone | 17:17 | |
*** mylu has quit IRC | 17:19 | |
*** mylu has joined #openstack-keystone | 17:21 | |
*** piyanai has joined #openstack-keystone | 17:22 | |
*** jasonsb has quit IRC | 17:22 | |
*** harlowja has quit IRC | 17:26 | |
*** harlowja has joined #openstack-keystone | 17:26 | |
*** mylu has quit IRC | 17:27 | |
*** mylu has joined #openstack-keystone | 17:27 | |
*** piyanai has quit IRC | 17:27 | |
*** mylu has quit IRC | 17:28 | |
*** mylu has joined #openstack-keystone | 17:30 | |
dhellmann | hey, folks, where is keystoneauth-saml2 on launchpad? | 17:31 |
dhellmann | morganfainberg: ^^ | 17:31 |
*** ankita_wagh has joined #openstack-keystone | 17:32 | |
morganfainberg | dhellmann: uhmmmmmmmmm. Needs to be made i think | 17:32 |
*** ankita_w_ has quit IRC | 17:32 | |
dhellmann | morganfainberg: ah, that explains why I can't import its release history :-) | 17:34 |
dhellmann | no worries, I'll just ignore it for now | 17:34 |
*** mestery has quit IRC | 17:35 | |
morganfainberg | Yeah. I dont thibk it was ever released either. | 17:35 |
dhellmann | cool, we can deal with it when you're ready for a release | 17:35 |
dhellmann | I'm just working on importing the release history into the releases repo | 17:35 |
*** eglute has quit IRC | 17:35 | |
*** eglute has joined #openstack-keystone | 17:36 | |
*** mestery has joined #openstack-keystone | 17:36 | |
*** pnavarro has quit IRC | 17:41 | |
*** e0ne has quit IRC | 17:44 | |
*** boris-42 has joined #openstack-keystone | 17:44 | |
*** mylu has quit IRC | 17:47 | |
*** jasonsb has joined #openstack-keystone | 17:52 | |
*** browne has joined #openstack-keystone | 17:52 | |
*** mylu has joined #openstack-keystone | 17:56 | |
*** piyanai has joined #openstack-keystone | 18:00 | |
*** mylu has quit IRC | 18:01 | |
*** mylu has joined #openstack-keystone | 18:02 | |
*** ankita_wagh has quit IRC | 18:02 | |
*** ankita_wagh has joined #openstack-keystone | 18:02 | |
*** Kennan2 has joined #openstack-keystone | 18:04 | |
*** Kennan has quit IRC | 18:05 | |
*** tqtran has joined #openstack-keystone | 18:08 | |
*** mestery has quit IRC | 18:10 | |
*** btully has quit IRC | 18:11 | |
*** piyanai has quit IRC | 18:14 | |
*** TheIntern has joined #openstack-keystone | 18:19 | |
*** amakarov has joined #openstack-keystone | 18:24 | |
*** piyanai has joined #openstack-keystone | 18:28 | |
*** e0ne has joined #openstack-keystone | 18:29 | |
*** mestery has joined #openstack-keystone | 18:31 | |
*** roxanaghe has joined #openstack-keystone | 18:31 | |
*** jsavak has quit IRC | 18:31 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Add is_domain field in Project Table https://review.openstack.org/157427 | 18:31 |
*** jsavak has joined #openstack-keystone | 18:32 | |
*** markvoelker has quit IRC | 18:32 | |
lhcheng | odyssey4me: don't horizon log show the rest api made to keystone? | 18:38 |
lhcheng | odyssey4me: if debug is enabled, you should see the REST api made to /OS-FEDERATION/projects | 18:39 |
openstackgerrit | henry-nash proposed openstack/keystone-specs: Move inherited assignments to core, and support new inheritance rules https://review.openstack.org/200434 | 18:42 |
morganfainberg | Testing | 18:43 |
odyssey4me | lhcheng let me check | 18:43 |
*** gordc has joined #openstack-keystone | 18:47 | |
marekd | roxanaghe: can you link the patch here? | 18:47 |
breton | morganfainberg: ping | 18:49 |
morganfainberg | pong | 18:49 |
*** fangzhou has quit IRC | 18:49 | |
breton | morganfainberg: what does keystone/common/sql/migrate_repo/versions/050_fk_consistent_indexes.py do? | 18:49 |
breton | is it relevant now? | 18:50 |
morganfainberg | it's an index rename | 18:50 |
morganfainberg | just to make things consistent | 18:50 |
morganfainberg | breton: if it's not being collapsed, it is relevant | 18:51 |
morganfainberg | but it's mostly historical | 18:51 |
morganfainberg | afaict | 18:51 |
breton | it is collapsed | 18:51 |
breton | it's between i an j | 18:51 |
morganfainberg | as long as the indexs in the collapse match the result | 18:51 |
morganfainberg | from that, you're good | 18:51 |
morganfainberg | should be the defaults that was cleaning up a badly named/renamed table i think | 18:51 |
roxanaghe | marekd, sure: https://review.openstack.org/#/c/180769/ | 18:52 |
morganfainberg | breton: see the https://github.com/openstack/keystone/commit/ba6705a731f8a80f9d01e88ae3425a93d70e4688 | 18:52 |
breton | the indexes are set only for mysql and only in migration. Original models were not changed in that commit | 18:52 |
odyssey4me | lhcheng odd, those debug lines should be in the error log for the vhost, right? | 18:52 |
breton | yep, https://review.openstack.org/#/c/84444/ | 18:52 |
morganfainberg | breton: yeah bad rename where indexes no longer matched | 18:53 |
lhcheng | odyssey4me: yup | 18:53 |
breton | ok, so I won't include it in the squashed migration | 18:53 |
lhcheng | odyssey4me: did you set this to DEBUG too: https://github.com/openstack/horizon/blob/master/openstack_dashboard/local/local_settings.py.example#L391 ? | 18:53 |
morganfainberg | breton: yeah just include the correct indexes ;) | 18:54 |
*** henrynash has joined #openstack-keystone | 18:54 | |
*** ChanServ sets mode: +v henrynash | 18:54 | |
odyssey4me | lhcheng something isn't right, I'm only getting this output: http://paste.openstack.org/show/LhttHGFn6WC6BNqXplQx/ | 18:57 |
*** mylu has quit IRC | 18:58 | |
*** mylu has joined #openstack-keystone | 18:58 | |
lhcheng | odyssey4me: that looks like the apache log file | 18:59 |
*** TheIntern has quit IRC | 18:59 | |
lhcheng | odyssey4me: horizon have its own logfile, configured in your apache conf | 19:00 |
*** bknudson has quit IRC | 19:00 | |
odyssey4me | lhcheng that's the log file specified in the vhost: ErrorLog /var/log/horizon/horizon-error.log | 19:00 |
*** gyee has joined #openstack-keystone | 19:00 | |
*** ChanServ sets mode: +v gyee | 19:00 | |
odyssey4me | lhcheng with LogLevel debug | 19:01 |
*** mylu has quit IRC | 19:02 | |
odyssey4me | ah, hang on - other loggers are disabled - hang on a sec | 19:02 |
*** TheIntern has joined #openstack-keystone | 19:02 | |
*** mylu has joined #openstack-keystone | 19:03 | |
*** stevemar has joined #openstack-keystone | 19:03 | |
*** ChanServ sets mode: +v stevemar | 19:03 | |
*** fangzhou has joined #openstack-keystone | 19:03 | |
htruta | henrynash: ping | 19:05 |
henrynash | htruta: hi | 19:05 |
odyssey4me | lhcheng there we go: http://paste.openstack.org/show/7LIzjZ09I8bRoVuOl7as/ | 19:05 |
htruta | regarding your comment, I disagree that is_domain=true projects must have the parent_id as domain_id | 19:06 |
htruta | if I see that, I'd think that B's users are in its domain (A) | 19:06 |
htruta | using the example in the review | 19:06 |
htruta | to see B in the list, I think the correct way would be GET /projects?parent_id=A | 19:07 |
henrynash | htruta: I’m probably being dumb, but I don’t see that | 19:07 |
henrynash | htruta: the users in B, will have a domain_id=project_id of B | 19:08 |
henrynash | htruta: so I won’t see the as being owned by A | 19:08 |
htruta | the morganfainberg statement was "Projects acting as a domain are owned by the parent domain, not by their own domain" | 19:09 |
htruta | conceptually speaking, what difference does this owning make? | 19:09 |
henrynash | htruta: so if I say “what domain is B in?” what’s the answre? | 19:10 |
htruta | henrynash: I see that they're still owned by the parent, even though the domain_id is its own | 19:10 |
htruta | I guess B is a domain. | 19:10 |
lhcheng | odyssey4me: horizon is making call "http://test1.pigeonbrawl.net:5000/v3/OS-FEDERATION/projects" | 19:10 |
htruta | is the answer | 19:10 |
henrynash | htruta: hmmm, I’d have said it’s in domain A | 19:11 |
lhcheng | odyssey4me: the keystone endpoint is not the https version | 19:11 |
htruta | I don't think it is | 19:11 |
lhcheng | odyssey4me: what's the endpoint in your keystone service catalog? | 19:11 |
henrynash | htruta: :-) | 19:11 |
htruta | henrynash: there is nothing from is_domain A that B uses | 19:11 |
htruta | do you get my point? | 19:11 |
*** stevemar has quit IRC | 19:12 | |
odyssey4me | lhcheng hmm, I see two endpoints - one http and one https - let me fix that | 19:12 |
*** btully has joined #openstack-keystone | 19:13 | |
*** stevemar has joined #openstack-keystone | 19:13 | |
*** ChanServ sets mode: +v stevemar | 19:13 | |
henrynash | htruta: so when I want to control, by policy, if someone can create create a domain “below A”, I haev to wrote a different rule than for projects? (i.e. one that uses parent_id not domain_id ?) | 19:13 |
henrynash | brb | 19:13 |
odyssey4me | lhcheng so the publis endpoint is https, the others are http - it looks like it's redirecting | 19:14 |
htruta | henrynash: I think so. That's something I was discussing this week with rodrigods and raildo | 19:14 |
*** blewis has joined #openstack-keystone | 19:15 | |
*** stevemar_ has joined #openstack-keystone | 19:15 | |
*** ChanServ sets mode: +v stevemar_ | 19:15 | |
odyssey4me | lhcheng OPENSTACK_ENDPOINT_TYPE = 'publicURL' but it seems that keystone is referring the client to the internal endpoint | 19:16 |
*** blewis` has joined #openstack-keystone | 19:17 | |
*** mylu has quit IRC | 19:17 | |
*** btully has quit IRC | 19:17 | |
*** stevemar has quit IRC | 19:17 | |
henrynash | back | 19:17 |
raildo | henrynash: htruta I think that the parent_id is responsable to reflect the hierarchy information. Not the domain_id, so i think that doesn't make sense use the domain_id to point a parent domain. | 19:17 |
lhcheng | odyssey4me: oops, that call actually uses the setting in local_settings.py OPENSTACK_KEYSTONE_URL | 19:18 |
*** dims_ has joined #openstack-keystone | 19:18 | |
lhcheng | odyssey4me: can you try updating that too | 19:18 |
henrynash | sorry, brb (again!!!) | 19:18 |
raildo | henrynash: np :P | 19:18 |
odyssey4me | lhcheng that's already set: OPENSTACK_KEYSTONE_URL = "https://test1.pigeonbrawl.net:5000/v3" | 19:19 |
*** afazekas has joined #openstack-keystone | 19:19 | |
*** ankita_wagh has quit IRC | 19:19 | |
*** stevemar_ has quit IRC | 19:20 | |
*** ankita_wagh has joined #openstack-keystone | 19:20 | |
*** blewis has quit IRC | 19:20 | |
*** mylu has joined #openstack-keystone | 19:21 | |
*** mylu has quit IRC | 19:23 | |
*** edmondsw has quit IRC | 19:24 | |
*** stevemar has joined #openstack-keystone | 19:24 | |
*** ChanServ sets mode: +v stevemar | 19:24 | |
*** mylu has joined #openstack-keystone | 19:25 | |
henrynash | back (again, again) | 19:25 |
henrynash | raildo: so i guess I’m struggling with why we would treat a project acting as a domain different than a regaulr project….what’s the advantage of doing it differently (in terms of what domain_id is set to) | 19:26 |
henrynash | ? | 19:26 |
*** mylu has quit IRC | 19:28 | |
*** flwang has joined #openstack-keystone | 19:28 | |
*** mylu has joined #openstack-keystone | 19:29 | |
*** dims__ has joined #openstack-keystone | 19:30 | |
lhcheng | odyssey4me: if I make the call to "http://test1.pigeonbrawl.net:5000/v3/OS-FEDERATION/projects" it doesn't return anything | 19:31 |
lhcheng | odyssey4me: but I make the same call to https, it works fine | 19:31 |
lhcheng | odyssey4me: I'm using curl | 19:31 |
odyssey4me | lhcheng yep, that does seem to be the issue - I tested the curl from the debug as well | 19:31 |
lhcheng | odyssey4me: so I think we just need to figure out why horizon is using the http endpoint | 19:31 |
raildo | henrynash: i don't see benefits in treat a project acting as a domain different than a project... but the idea with reseller is exactly work with it as a project and domain | 19:32 |
odyssey4me | lhcheng agreed - or why keystone is insisting on sending it to the internal endpoint | 19:32 |
raildo | henrynash: hum... I don't know, I have to think more about it | 19:33 |
htruta | henrynash, raildo: we treat it different because it is different... it is also a domain | 19:33 |
*** dims_ has quit IRC | 19:34 | |
htruta | the is_domain=True subproject won't have anything domain specific of the parent | 19:34 |
henrynash | raildo: I guess a question to ask…what would break in the code you have written if we did set domain_id of B to the project_id of A | 19:34 |
lhcheng | odyssey4me: looking at the code, it might pull up the keystone endpoint from here | 19:34 |
lhcheng | odyssey4me: https://github.com/openstack/django_openstack_auth/blob/master/openstack_auth/views.py#L136-L137 | 19:34 |
henrynash | (assuming A is a project acting as a domain) | 19:34 |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Additional Fernet test coverage https://review.openstack.org/192739 | 19:36 |
htruta | henrynash: I suppose It breaks a lot of things | 19:36 |
henrynash | htruta: really?? | 19:36 |
htruta | but surely would need to look further | 19:36 |
lhcheng | odyssey4me: perhaps keystone set the http_referrer when posting to horizon | 19:37 |
odyssey4me | lhcheng that is possible - keystone's SSL is being handled by a load balancer | 19:37 |
odyssey4me | so it only knows about this from the catalogue | 19:37 |
htruta | henrynash: considering we move with that idea of yours, who'd be the domain_id of a root is_domain project? None of itself? | 19:38 |
*** jsavak has quit IRC | 19:38 | |
htruta | henrynash: /s/of/or | 19:38 |
marekd | odyssey4me: uh oh | 19:38 |
*** jsavak has joined #openstack-keystone | 19:38 | |
henrynash | htruta: I guess that’s a good question, and my initial reaction is None | 19:38 |
marekd | odyssey4me: is standard http handled by a lb ? | 19:39 |
htruta | henrynash: I think it does not make any sense | 19:39 |
odyssey4me | marekd yes, both are handled by the same lb - just the public one has ssl offloading involved | 19:39 |
*** mylu has quit IRC | 19:39 | |
marekd | what's ssl offloading ? | 19:39 |
*** mylu has joined #openstack-keystone | 19:40 | |
*** ankita_wagh has quit IRC | 19:40 | |
henrynash | htruta: well, a domain object today has an ID, but not a domain_id… | 19:40 |
odyssey4me | marekd when a specialised load balancer (like an F5, or haproxy in this case) handles the SSL encryption on behalf of the back-end http service | 19:40 |
odyssey4me | so it's like a reverse proxy | 19:40 |
htruta | henrynash: but the domain_id is its own id | 19:41 |
htruta | and if it is a project and a domain, I think it can share the same id and domain_id | 19:41 |
henrynash | htruta: yep, which is the project ID in our new representation | 19:42 |
lhcheng | odyssey4me: you can try commenting out the code on https://github.com/openstack/django_openstack_auth/blob/master/openstack_auth/views.py#L136-L137 | 19:42 |
lhcheng | odyssey4me: set auth_url=None | 19:43 |
lhcheng | just to see if things would work | 19:43 |
*** TheIntern has quit IRC | 19:43 | |
henrynash | htruta: here’s another way of saying this. We could (conceptually) remove domain_id from all projects….and calculate it on-the-fly from a projects position in the hierarcy…and that works wether the project is acting as a domain or not….so if storing the domain_id is just saving us working it out, then (again) why is it different for the two types of project | 19:44 |
*** jsavak has quit IRC | 19:44 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Move cli.py into keystone.cmd https://review.openstack.org/203224 | 19:45 |
*** mylu has quit IRC | 19:45 | |
*** jsavak has joined #openstack-keystone | 19:45 | |
odyssey4me | lhcheng nope, doesn't work - it still gets referred to the internal endpoint | 19:46 |
odyssey4me | lhcheng REQ: curl -g -i -X GET https://test1.pigeonbrawl.net:5000/v3 -H "Accept: application/json" -H "User-Agent: python-keystoneclient" | 19:46 |
odyssey4me | lhcheng RESP BODY: {"version": {"status": "stable", "updated": "2015-03-30T00:00:00Z", "media-types": [{"base": "application/json", "type": "application/vnd.openstack.identity-v3+json"}], "id": "v3.4", "links": [{"href": "http://test1.pigeonbrawl.net:5000/v3/", "rel": "self"}]}} | 19:47 |
*** rm_work has quit IRC | 19:47 | |
odyssey4me | it really does persist :/ | 19:47 |
*** blewis` has quit IRC | 19:47 | |
*** ig0r_ has quit IRC | 19:47 | |
htruta | henrynash: that is a good question | 19:47 |
*** rm_work has joined #openstack-keystone | 19:48 | |
htruta | henrynash: but I still say that a domain is not part of another domain. it is isolated. but the is_domain is just a child of it | 19:48 |
htruta | B does not belong to A | 19:48 |
htruta | B is a child of A | 19:48 |
lhcheng | odyssey4me: isn't " https://test1.pigeonbrawl.net:5000/v3 " the external endpoint? | 19:49 |
odyssey4me | lhcheng yes | 19:49 |
odyssey4me | it's the public endpoint in the catalog, and the configured endpoint for horizon to use | 19:49 |
odyssey4me | so horizon requests from the right endpoint, but keystone responds with the wrong href | 19:50 |
lhcheng | odyssey4me: if the auth_url was set to None, horizon will fallback to OPENSTACK_KEYSTONE_URL (configured in the settings) | 19:50 |
odyssey4me | lhcheng horizon always seems to be behaving initially, but keystone seems to be responding with referrals to other endpoints | 19:50 |
*** mylu has joined #openstack-keystone | 19:51 | |
henrynash | htruta: I wonder if this is just semantics…..can you point me at somthing that would be harder to do (or not work at all) if we used my model? | 19:51 |
htruta | henrynash: let me think | 19:51 |
lhcheng | odyssey4me: do you still get the same error? | 19:51 |
odyssey4me | lhcheng yes - the error is most likely due to the empty response from keystone | 19:52 |
lhcheng | odyssey4me: don't the GET /OS-federation/projects work now? | 19:52 |
odyssey4me | lhcheng nope | 19:52 |
*** piyanai has quit IRC | 19:53 | |
*** jecarey has joined #openstack-keystone | 19:53 | |
*** gyee has quit IRC | 19:57 | |
openstackgerrit | Boris Bobrov proposed openstack/keystone: Migrations squash https://review.openstack.org/203229 | 19:58 |
*** amakarov has quit IRC | 20:00 | |
*** jsavak has quit IRC | 20:04 | |
breton | +41, -475 | 20:04 |
dolphm | lbragstad: was there a change to move fernet provider's issue_v3_token() method somewhere else? | 20:04 |
*** c_soukup has joined #openstack-keystone | 20:05 | |
raildo | henrynash: I think that you won this time haha I don't see any issue | 20:07 |
henrynash | raildo: well, let’s mull on it overnight | 20:07 |
raildo | henrynash: ok | 20:07 |
htruta | henrynash: I don't see issue, either. just see it conceptually wrong | 20:07 |
htruta | just like I said, I don't see B in A | 20:07 |
htruta | I see B child of A | 20:08 |
*** csoukup has quit IRC | 20:08 | |
*** geoffarnold has quit IRC | 20:09 | |
henrynash | htruta: understand….it probably is a conceptual thing but I see it the other way :-) | 20:09 |
raildo | henrynash: what you're saying is that I do GET projects/?domain=A.id, project B will be returned, right? | 20:09 |
henrynash | raildo: yes | 20:10 |
stevemar | marekd: how are things there? | 20:10 |
*** piyanai has joined #openstack-keystone | 20:10 | |
lhcheng | who's the expert on Session object next to jamielennox? | 20:10 |
raildo | henrynash: great | 20:10 |
henrynash | lhcheng: there’s sessions object sitting next to jamielennox? | 20:10 |
stevemar | henrynash: hes a new contributor | 20:11 |
henrynash | lhcheng: sorry, couldn’t resist | 20:11 |
lhcheng | henrynash: lol | 20:11 |
henrynash | lhcheng: it’s like the old joke: “what’s on TV”, answer: a bunch of flowers in a vase | 20:11 |
stevemar | henrynash: whats going on there? are things winding down? | 20:11 |
lhcheng | he's going to do all the ksc work for jamie | 20:12 |
henrynash | stevemar: yes, I think our brains are fried | 20:12 |
lhcheng | henrynash: hah | 20:12 |
stevemar | henrynash: is the building still shaking? | 20:12 |
henrynash | stevemar: I think that has stopped | 20:12 |
stevemar | marekd: are you alive? | 20:12 |
henrynash | stevemar: the T-Rex only ate 4 of us | 20:13 |
stevemar | henrynash: um... depending on who the trex ate, my reply will be yay or nay | 20:13 |
stevemar | that morganfainberg guy.... | 20:14 |
*** TheIntern has joined #openstack-keystone | 20:14 | |
henrynash | stevemar: tis the promised land for all PTLs | 20:14 |
stevemar | so thats where dolphm went | 20:15 |
*** stevemar has quit IRC | 20:16 | |
*** jsavak has joined #openstack-keystone | 20:17 | |
dolphm | was stevemar not at the midcycle? | 20:17 |
lhcheng | odyssey4me: I think KSC is trying to be smart and uses discovery to figure out the keystone endpoint instead of the auth_url passed to it. | 20:18 |
lhcheng | odyssey4me: what's the value of "public_endpoint" in your keystone conf? | 20:18 |
odyssey4me | lhcheng: not value set, so it's the default | 20:21 |
*** ankita_wagh has joined #openstack-keystone | 20:22 | |
odyssey4me | hmm, it seems that may be an appropriate setting to use | 20:22 |
lhcheng | odyssey4me: yup | 20:22 |
*** henrynash has quit IRC | 20:23 | |
odyssey4me | lhcheng yes! that's it :) | 20:29 |
*** stevemar has joined #openstack-keystone | 20:29 | |
*** ChanServ sets mode: +v stevemar | 20:29 | |
odyssey4me | alright, now one more issue to resolve - for some reason the first time I auth it redirects to keystone's service URL instead of back to horizon | 20:29 |
odyssey4me | if I, through the same session, try again - then it works | 20:29 |
lhcheng | odyssey4me: did you set the port too on the public_endpoint? | 20:30 |
odyssey4me | lhcheng yep, public_endpoint = https://test1.pigeonbrawl.net:5000 works, except that the redirect is wrong on the first auth attempt | 20:31 |
marekd | stevemar: i am alive! | 20:32 |
*** dims__ has quit IRC | 20:34 | |
morganfainberg | Lol | 20:34 |
*** stevemar has quit IRC | 20:34 | |
*** flwang has quit IRC | 20:34 | |
*** lsmola has quit IRC | 20:35 | |
*** raildo has quit IRC | 20:35 | |
*** piyanai has quit IRC | 20:36 | |
lhcheng | odyssey4me: that might be on keystone side | 20:37 |
lhcheng | odyssey4me: after that, can you login to horizon now? | 20:38 |
odyssey4me | lhcheng yes, I can - and on the second auth I get redirected to the summary page and the project info shows correctly | 20:38 |
odyssey4me | thank you so much :) | 20:39 |
htruta | henrynash, morganfainberg: are you documenting any decisions of the midcycle? | 20:40 |
htruta | is there an etherpad? | 20:40 |
*** stevemar has joined #openstack-keystone | 20:42 | |
*** ChanServ sets mode: +v stevemar | 20:42 | |
*** mylu has quit IRC | 20:42 | |
*** mylu has joined #openstack-keystone | 20:42 | |
*** e0ne has quit IRC | 20:43 | |
*** piyanai has joined #openstack-keystone | 20:44 | |
*** stevemar has quit IRC | 20:46 | |
*** piyanai has quit IRC | 20:46 | |
*** gordc has quit IRC | 20:47 | |
*** piyanai has joined #openstack-keystone | 20:48 | |
*** piyanai has quit IRC | 20:51 | |
lhcheng | odyssey4me: \o/ | 20:51 |
lhcheng | odyssey4me: glad it finally worked! | 20:52 |
lhcheng | I wonder if there some config issue on the callback of the IdP | 20:52 |
odyssey4me | marekd thanks to lhcheng we've come to the bottom of keystone's behaviour - I was missing the public_endpoint setting to inform keystone that it should advertise itself at the https endpoint :) | 20:52 |
odyssey4me | marekd do you perhaps have a similar reference config for keystone's apache setup for shibboleth? I'm still getting inconsistent redirects when successfully authing to the idp | 20:53 |
*** stevemar has joined #openstack-keystone | 20:53 | |
*** ChanServ sets mode: +v stevemar | 20:53 | |
odyssey4me | lhcheng the idp gets its info from the SP's metadata, and also uses referer info from the SP as I understand it | 20:53 |
*** pnavarro has joined #openstack-keystone | 20:54 | |
lhcheng | odyssey4me: marekd just left, heading to the airport | 20:55 |
*** janonymous_ has quit IRC | 20:55 | |
odyssey4me | :/ | 20:56 |
odyssey4me | anyone else around that knows the mod_shib config well? | 20:57 |
*** mylu has quit IRC | 20:57 | |
*** stevemar has quit IRC | 20:57 | |
*** pnavarro has quit IRC | 20:58 | |
*** edmondsw has joined #openstack-keystone | 20:59 | |
*** stevemar has joined #openstack-keystone | 20:59 | |
*** ChanServ sets mode: +v stevemar | 20:59 | |
*** dims_ has joined #openstack-keystone | 21:00 | |
*** geoffarnold has joined #openstack-keystone | 21:00 | |
*** btully has joined #openstack-keystone | 21:01 | |
*** stevemar has quit IRC | 21:04 | |
*** btully has quit IRC | 21:05 | |
*** jsavak has quit IRC | 21:05 | |
*** jsavak has joined #openstack-keystone | 21:06 | |
*** btully has joined #openstack-keystone | 21:07 | |
*** pnavarro has joined #openstack-keystone | 21:08 | |
lhcheng | odyssey4me: most of the folks are in transit now | 21:09 |
lhcheng | odyssey4me: need to wait til monday | 21:10 |
odyssey4me | lhcheng well, it can wait until next week then :) | 21:10 |
odyssey4me | thank you so much, and to marekd as well :) | 21:10 |
lhcheng | odyssey4me: you're welcome | 21:10 |
lhcheng | :) | 21:10 |
*** jecarey has quit IRC | 21:12 | |
*** htruta has quit IRC | 21:12 | |
*** htruta has joined #openstack-keystone | 21:12 | |
*** jsavak has quit IRC | 21:12 | |
*** dguerri is now known as dguerri` | 21:12 | |
*** ayoung has quit IRC | 21:16 | |
*** roxanaghe has quit IRC | 21:25 | |
*** geoffarnold has quit IRC | 21:26 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Refactor: clean up TokenAPITests https://review.openstack.org/203250 | 21:26 |
*** lhcheng has quit IRC | 21:27 | |
*** fangzhou has quit IRC | 21:41 | |
*** fangzhou has joined #openstack-keystone | 21:45 | |
marekd | odyssey4me: told ya it wasn't bug :P | 21:49 |
*** spandhe has quit IRC | 21:50 | |
*** spandhe has joined #openstack-keystone | 21:50 | |
*** spandhe has quit IRC | 21:50 | |
*** pnavarro has quit IRC | 21:51 | |
*** BrAsS_mOnKeY has joined #openstack-keystone | 21:52 | |
odyssey4me | marekd :) glad that it wasn't and I learned a few gotchas on the way which have been valuable lessons learned | 21:54 |
odyssey4me | I should be able to try the fernet/federation/scoped keystone patch on Monday/Tuesday | 21:54 |
*** c_soukup has quit IRC | 21:58 | |
marekd | odyssey4me: thanks, i will try that too, once i get my office | 22:01 |
openstackgerrit | Marek Denis proposed openstack/keystone: Adds a base class for functional tests https://review.openstack.org/203142 | 22:03 |
openstackgerrit | Marek Denis proposed openstack/keystone: Federation Identity Provider functional tests https://review.openstack.org/203258 | 22:03 |
*** piyanai has joined #openstack-keystone | 22:04 | |
*** stevemar has joined #openstack-keystone | 22:04 | |
*** ChanServ sets mode: +v stevemar | 22:04 | |
*** hrou has quit IRC | 22:07 | |
*** stevemar has quit IRC | 22:13 | |
*** stevemar has joined #openstack-keystone | 22:15 | |
*** ChanServ sets mode: +v stevemar | 22:15 | |
*** fangzhou has quit IRC | 22:15 | |
*** fangzhou has joined #openstack-keystone | 22:16 | |
stevemar | marekd: ping | 22:18 |
*** zzzeek has quit IRC | 22:18 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Create a version package https://review.openstack.org/203262 | 22:19 |
marekd | stevemar: i am here. | 22:19 |
marekd | what's up? | 22:19 |
stevemar | marekd: \o/ | 22:20 |
stevemar | you are alive! | 22:20 |
stevemar | get through security? | 22:20 |
marekd | nope, have some food iwant to eat | 22:20 |
marekd | so i am going to wait a little. | 22:20 |
marekd | food like our hackathon yogurth :P | 22:20 |
*** zzzeek has joined #openstack-keystone | 22:21 | |
*** fangzhou has quit IRC | 22:21 | |
*** stevemar_ has joined #openstack-keystone | 22:22 | |
*** ChanServ sets mode: +v stevemar_ | 22:22 | |
*** stevemar_ has quit IRC | 22:22 | |
*** stevemar_ has joined #openstack-keystone | 22:23 | |
*** ChanServ sets mode: +v stevemar_ | 22:23 | |
stevemar_ | marekd: garbage wifi in the airport | 22:23 |
marekd | stevemar_: don't tell me... | 22:23 |
stevemar_ | marekd: i'm sure you're aware of it | 22:24 |
stevemar_ | marekd: https://review.openstack.org/#/c/203262/ | 22:24 |
*** stevemar has quit IRC | 22:24 | |
marekd | stevemar_: always on watch :-) | 22:25 |
marekd | i meant You :P | 22:25 |
stevemar_ | marekd: i didnt code enough @ BU | 22:26 |
stevemar_ | gotta make up for it at the airport | 22:26 |
*** piyanai has quit IRC | 22:26 | |
marekd | stevemar_: oh, shut up, you are all good. | 22:27 |
stevemar_ | marekd: <3 | 22:27 |
*** flwang has joined #openstack-keystone | 22:27 | |
*** edmondsw has quit IRC | 22:28 | |
marekd | so this changes moves all the files that deal with /v2.0 and /v3 to separate directory, right? | 22:29 |
marekd | stevemar_: ^^ | 22:29 |
breton | looks like it | 22:29 |
*** ankita_w_ has joined #openstack-keystone | 22:30 | |
*** ankita___ has joined #openstack-keystone | 22:31 | |
*** ankit____ has joined #openstack-keystone | 22:32 | |
*** ankita___ has quit IRC | 22:32 | |
stevemar_ | marekd: yes sir! | 22:34 |
*** ankita_wagh has quit IRC | 22:34 | |
stevemar_ | theres a lot of files just hanging out in the top level dir for some reason | 22:34 |
breton | -1 :) | 22:34 |
*** ankita_w_ has quit IRC | 22:35 | |
stevemar_ | breton: thanks for the migration squash :) | 22:35 |
breton | np | 22:35 |
stevemar_ | its on my list of things to review | 22:36 |
*** henrynash has joined #openstack-keystone | 22:38 | |
*** ChanServ sets mode: +v henrynash | 22:38 | |
*** mgarza_ has quit IRC | 22:49 | |
*** fangzhou has joined #openstack-keystone | 22:51 | |
*** mylu has joined #openstack-keystone | 22:54 | |
*** stevemar_ has quit IRC | 22:56 | |
*** flwang has quit IRC | 22:59 | |
*** ankita_wagh has joined #openstack-keystone | 23:00 | |
marekd | stevemar is gone. | 23:01 |
marekd | ? | 23:01 |
*** ankit____ has quit IRC | 23:03 | |
*** hrou has joined #openstack-keystone | 23:05 | |
*** ankita_w_ has joined #openstack-keystone | 23:10 | |
*** mylu has quit IRC | 23:11 | |
*** btully has quit IRC | 23:11 | |
*** fangzhou has quit IRC | 23:12 | |
*** stevemar has joined #openstack-keystone | 23:12 | |
*** ChanServ sets mode: +v stevemar | 23:12 | |
*** ankita_wagh has quit IRC | 23:13 | |
*** fangzhou has joined #openstack-keystone | 23:16 | |
*** flwang has joined #openstack-keystone | 23:17 | |
marekd | i ma about to go offline, the connection is too shabby | 23:30 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Create a version package https://review.openstack.org/203262 | 23:40 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Move cli.py into keystone.cmd https://review.openstack.org/203224 | 23:46 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Create a version package https://review.openstack.org/203262 | 23:47 |
*** ankita_w_ has quit IRC | 23:50 | |
*** henrynash has quit IRC | 23:53 | |
*** stevemar_ has joined #openstack-keystone | 23:58 | |
*** ChanServ sets mode: +v stevemar_ | 23:58 | |
*** tqtran has quit IRC | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!