Friday, 2015-07-24

*** hrou has joined #openstack-keystone00:08
*** chlong has joined #openstack-keystone00:11
*** zzzeek has joined #openstack-keystone00:12
*** jiaxi has quit IRC00:24
*** stevemar has joined #openstack-keystone00:28
*** ChanServ sets mode: +v stevemar00:28
*** david-lyle has quit IRC00:40
*** stevemar has quit IRC00:43
*** jaosorior has quit IRC00:46
*** sigmavirus24_awa is now known as sigmavirus2400:47
openstackgerritMerged openstack/keystone: Fix test_exception.py for py34  https://review.openstack.org/20480700:49
openstackgerritMerged openstack/keystone: test_base64utils works with py34  https://review.openstack.org/20385300:52
openstackgerritMerged openstack/keystone: Fix s3.core for py34  https://review.openstack.org/20480400:52
ayoungflwang, you don't need to put the role in the other policy files;  they will ignore it if it is not set.00:53
*** browne has joined #openstack-keystone00:55
*** _cjones_ has quit IRC01:05
*** ankita_wagh has quit IRC01:06
*** gordc has quit IRC01:07
*** topol has quit IRC01:11
openstackgerritIan Cordasco proposed openstack/python-keystoneclient: Set reasonable defaults for TCP Keep-Alive  https://review.openstack.org/20474101:14
*** topol has joined #openstack-keystone01:16
*** ChanServ sets mode: +v topol01:16
*** Kennan has quit IRC01:17
openstackgerritIan Cordasco proposed openstack/keystoneauth: Set reasonable defaults for TCP Keep-Alive  https://review.openstack.org/20527601:18
*** topol has quit IRC01:19
*** dims has joined #openstack-keystone01:20
*** davechen has joined #openstack-keystone01:23
*** Kennan has joined #openstack-keystone01:24
*** jiaxi has joined #openstack-keystone01:25
*** markvoelker has joined #openstack-keystone01:25
flwangayoung: cool, i will give it a try, thanks a lot01:26
jiaxiHello,everyone01:26
*** jsavak has joined #openstack-keystone01:27
jiaxiPlease help me review my patch set https://review.openstack.org/#/c/204952/01:28
ayoungjiaxi, did you end up resubmitting that iwth a differen change ID?01:32
ayoungI thought there were reviews on the earlier version?01:32
*** fangzhou has quit IRC01:32
*** telemons1er is now known as telemonster01:33
*** jdandrea has quit IRC01:34
*** jiaxi has quit IRC01:34
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecations  https://review.openstack.org/19151101:34
*** jsavak has quit IRC01:36
dramakriayoung: ping.. can you please re-look at this one - https://review.openstack.org/#/c/190863/ ? You had +2ed it yday. Just removed the comments in one of the code files as suggested by henrynash. Thanks!01:40
ayoungdramakri, done01:41
dramakriayoung: thanks a lot!!01:41
*** topol has joined #openstack-keystone01:42
*** ChanServ sets mode: +v topol01:42
*** jiaxi has joined #openstack-keystone01:44
jiaxiayoung: Yes01:44
ayoungjiaxi, use the old commit id, please01:44
jiaxiayoung: I run into git merge trouble. So submit in a new changeID01:44
jiaxiayoung: commit id ????? Change ID ???01:45
jiaxiayoung: Why01:45
*** topol has quit IRC01:47
jiaxiayoung: are you here01:55
*** lhcheng has quit IRC01:55
*** zzzeek has quit IRC01:57
bigjoolsayoung: hey, are you involved at all with https://review.openstack.org/#/c/159910 ?01:57
*** bknudson has quit IRC01:58
jiaxihttps://review.openstack.org/#/c/204952/02:01
*** jiaxi has quit IRC02:04
*** sigmavirus24 is now known as sigmavirus24_awa02:05
*** jiaxi has joined #openstack-keystone02:06
*** dramakri has quit IRC02:09
*** dramakri has joined #openstack-keystone02:09
*** gyee has quit IRC02:17
*** henrynash_ has joined #openstack-keystone02:18
*** ChanServ sets mode: +v henrynash_02:18
*** chenhong has joined #openstack-keystone02:20
*** henrynash has quit IRC02:20
*** henrynash_ is now known as henrynash02:20
*** spandhe has quit IRC02:22
*** jiaxi has quit IRC02:23
*** btully has quit IRC02:27
*** dims has quit IRC02:27
*** ankita_wagh has joined #openstack-keystone02:30
*** lhcheng has joined #openstack-keystone02:31
*** ChanServ sets mode: +v lhcheng02:31
*** dramakri has quit IRC02:46
*** kiran-r has joined #openstack-keystone02:47
*** hakimo_ has joined #openstack-keystone02:52
ayoungbigjools, nope02:53
*** hakimo has quit IRC02:54
*** bradjones has quit IRC02:59
openstackgerritDave Chen proposed openstack/keystone: test_backend_sql work with python34  https://review.openstack.org/20535202:59
openstackgerritjiaxi proposed openstack/keystone: Suppressing the request when creating endpoint with invalid urls  https://review.openstack.org/20051203:00
*** woodster_ has quit IRC03:02
*** bradjones has joined #openstack-keystone03:02
*** bradjones has quit IRC03:02
*** bradjones has joined #openstack-keystone03:02
*** kiran-r has quit IRC03:04
*** dramakri has joined #openstack-keystone03:05
*** piyanai has quit IRC03:08
openstackgerritayoung proposed openstack/keystone: Revoke Events in list  https://review.openstack.org/20526603:15
*** david-lyle has joined #openstack-keystone03:17
*** jiaxi has joined #openstack-keystone03:17
jiaxiayoung:03:17
ayoungjiaxi, if you do03:18
jiaxiayoung: https://review.openstack.org/#/c/200512/03:18
jiaxiayoung: Done03:18
ayoungjiaxi, cool,  thanks03:18
jiaxiayoung: It's my duty.03:18
jiaxiayoung: Please help review my patch set https://review.openstack.org/#/c/200512/03:19
ayoungjiaxi, define "suppresed" in this case?03:19
jiaxiayoung: what do you mean ?03:19
ayoungsuppressed  is not the right word...not your fault I see in the origianl bug report.03:19
ayounginvalid urls should be "rejected" not suppresed03:20
jiaxiayoung: ok03:20
ayoungjiaxi, I'm going to edit your commit comment.  PLease do:  git review -d 200512 before making any further changes  so you pick it up03:20
*** richm has quit IRC03:21
jiaxiayoung: Look forward to your edit.03:21
openstackgerritayoung proposed openstack/keystone: Reject create endpoint with invalid urls  https://review.openstack.org/20051203:21
ayoungjiaxi, you should test this fix agains the openstack common CLI for V3 endpoints03:22
openstackgerritMerged openstack/keystone: Add missing "raise" when throwing exception.  https://review.openstack.org/19941403:22
jiaxiayoung: This bug is about v203:24
openstackgerritMerged openstack/keystone: Imported Translations from Transifex  https://review.openstack.org/20490303:24
jiaxiayoung: It I add v3, the other cores may not agree with us.03:24
ayoungjiaxi, test it on both.03:25
ayoungI bet it fixes the bug on V3 as well, which you can test using the common CLI03:25
ayoungjiaxi, anyway, you missed what I said before about iterating...see my comment about what I meant.03:25
jiaxiayoung: 100% fix the bug on v303:25
ayoungotherwise, looks good03:25
jiaxiayoung: Thank you, I will fix v3 , too.  I hope the cores agree with us.03:27
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements  https://review.openstack.org/20493703:31
openstackgerritOpenStack Proposal Bot proposed openstack/keystonemiddleware: Updated from global requirements  https://review.openstack.org/19725403:31
jiaxiayoung :03:34
jiaxiayoung:  why you assined my bug to you ????????????????03:34
ayoungjiaxi, I didn't03:34
jiaxiayoung: The bug is mine https://bugs.launchpad.net/keystone/+bug/147103403:34
openstackLaunchpad bug 1471034 in Keystone "invalid URLs are not suppressed" [Low,In progress] - Assigned to Adam Young (ayoung)03:34
jiaxiayoung: Look by yoursele03:35
*** miguelgrinberg has quit IRC03:35
jiaxiayoung: Look by yourself.  I don't think it's reasonable and good03:35
ayoungjiaxi, guessing that launchpad did that automatically when I edited the commit.  Braindead03:36
*** hightall has joined #openstack-keystone03:36
ayoungjiaxi, assigned back to you03:36
jiaxiayoung: I can't03:36
jiaxiayoung: have no permission03:36
ayoungjiaxi, I just did03:36
ayoungjiaxi, refresh.  I changed the bug name, too03:37
*** hightall has quit IRC03:37
jiaxiayoung: Thank you .03:37
*** markvoelker has quit IRC03:38
jiaxiayoung: I'm sorry to mistake you. Some time ago, a core assigne my bug to him. so I doubt.03:38
ayoung没必要道歉03:39
*** hightall has joined #openstack-keystone03:39
*** hightall has quit IRC03:40
dstanekjiaxi: that how a lot of our tooling works. last person to make certain changes gets it assigned to them03:41
*** hightall has joined #openstack-keystone03:41
ayoungdstanek, to make sure it is not too convenient to make a change.03:41
dstanekayoung: it's a little strange for sure, but in practice it doesn't matter much03:43
jiaxiayoung: It' great that  you can use chinese.  But my chinese input method is broken.  Ubuntu is a shit.,03:43
dstanekayoung: although, i'm not fond of getting all of the extra emails from launchpad because i update a patch03:43
*** hightall has quit IRC03:44
jiaxidstanek: Hello, david. I'm going to fix v3 as well in my patch set.  Is that okay ?03:44
jiaxidstanek: Do you agree with me ? Because use the same logic can fix v3.03:44
dstanekjiaxi: i think only v3 *needs* to be fixed. v2 is nice, but i don't care much about it.03:46
ayoungit can't urt...V2 will be around for a while, but I agree, V3 is the important one03:46
ayoungjiaxi, I cheated on the chinese03:47
ayounghttps://translate.google.com/#zh-CN/en/%E6%B2%A1%E5%BF%85%E8%A6%81%E9%81%93%E6%AD%8903:47
jiaxijiaxi, Good , what os do you use ?  mac os ? or Ubuntu ?03:47
ayounghttp://adam.younglogic.com/2012/11/why-i-work-at-red-hat/  jiaxi see if you can guess based on that03:48
dstanekayoung: arch?03:49
ayoungslackware03:49
jiaxiSo geek.03:50
dstanekayoung: i've mostly moved over from ubuntu to fedora :-)  been pretty happy so far03:50
dstanekthe move to dnf has been a little bit of a pain03:50
ayoungdstanek, glad to hear it.03:50
ayoungthe dnf thing ius a little emotional for some people, too.  The guy that wrote yum was killed while biking...he was well liked03:51
ayounghttp://www.wral.com/bicyclist-killed-in-durham-hit-and-run/12639104/03:51
dstanekwow. i had no idea.03:51
ayoungyeah...it was pretty sad.03:52
jiaxidstanek: david. In morning, I was thinking about use fedora instead of ubuntu. ubuntu is a shit.  On night, I will use fedora.03:52
ayoungI didn;t know him personally, but many of my coworkers did03:52
dstanekmy pain has been more elementary. i have to remember to install yum-utils before i can use ansible because i'm too lazy to roll and image with it or to fix ansible03:52
ayoungI thougjht all the yum stuff worked fine, it just complains at you....03:53
ayoungmust be a command line alias, but different at the python levle?03:53
ayounglevel03:53
dstanekthe command line complains, but ansible imports yum and does stuff, so you need to yum shim03:53
dstanekjiaxi: you'll probably be happy. i find that ubuntu is moving toward being the Windows of the linux world and i'm just not the target audience anymore03:54
ayoungI must have had it installed already....getting to like Ansible...now if I could just find a nightly build of RHEL + RH OS that I can automated the install .  Last one ...just somehwo breaks syslog03:54
jiaxidstanek: pretty right. It's same with me.03:55
*** markvoelker has joined #openstack-keystone04:03
*** markvoelker has quit IRC04:08
*** spandhe has joined #openstack-keystone04:17
*** btully has joined #openstack-keystone04:17
*** spandhe_ has joined #openstack-keystone04:19
*** spandhe has quit IRC04:21
*** spandhe_ is now known as spandhe04:21
*** htruta_ has quit IRC04:30
*** henrynash has quit IRC04:36
*** jsavak has joined #openstack-keystone04:36
*** ankita_wagh has quit IRC04:36
*** henrynash has joined #openstack-keystone04:37
*** ChanServ sets mode: +v henrynash04:37
*** ankita_wagh has joined #openstack-keystone04:37
*** hightall has joined #openstack-keystone04:39
*** jsavak has quit IRC04:41
*** lhcheng has quit IRC04:53
*** markvoelker has joined #openstack-keystone05:04
*** henrynash has quit IRC05:05
*** henrynash has joined #openstack-keystone05:07
*** ChanServ sets mode: +v henrynash05:07
*** markvoelker has quit IRC05:09
*** ankita_wagh has quit IRC05:11
*** ankita_wagh has joined #openstack-keystone05:12
dramakrihenrynash: ping.. removed the comments as per your suggestion. Please take a look at it - https://review.openstack.org/#/c/190863/ ? Thanks!05:18
*** belmoreira has joined #openstack-keystone05:18
*** chenhong1 has joined #openstack-keystone05:41
*** chenhong has quit IRC05:43
*** ajayaa has joined #openstack-keystone05:44
*** hrou has quit IRC05:47
*** kiran-r has joined #openstack-keystone05:51
*** kiran-r has quit IRC05:52
*** spandhe has quit IRC05:54
*** spandhe has joined #openstack-keystone06:00
*** ajayaa has quit IRC06:00
*** belmoreira has quit IRC06:08
*** ParsectiX has joined #openstack-keystone06:13
*** ajayaa has joined #openstack-keystone06:23
*** dramakri has left #openstack-keystone06:28
*** lhcheng has joined #openstack-keystone06:41
*** ChanServ sets mode: +v lhcheng06:41
*** lhcheng has quit IRC06:46
*** ankita_wagh has quit IRC06:55
*** belmoreira has joined #openstack-keystone06:55
*** jiaxi has quit IRC06:57
*** markvoelker has joined #openstack-keystone07:05
*** spandhe has quit IRC07:08
*** pcaruana has joined #openstack-keystone07:10
*** markvoelker has quit IRC07:10
*** belmoreira has quit IRC07:12
*** pcaruana is now known as centos07:13
*** centos is now known as Guest5973007:13
*** Guest59730 is now known as pcaruana07:13
*** browne has quit IRC07:18
*** rletrocquer has joined #openstack-keystone07:22
*** ankita_wagh has joined #openstack-keystone07:30
openstackgerritYusuke Hayashi proposed openstack/keystone: Missing logging tag _LI  https://review.openstack.org/20541307:31
*** pnavarro has joined #openstack-keystone07:31
*** chlong has quit IRC07:33
openstackgerritYusuke Hayashi proposed openstack/keystone: Missing logging tag _LI  https://review.openstack.org/20541307:39
*** jaosorior has joined #openstack-keystone07:44
openstackgerritjiaxi proposed openstack/keystone: Reject create endpoint with invalid urls  https://review.openstack.org/20051207:47
*** ankita_wagh has quit IRC07:49
*** mkoderer has joined #openstack-keystone07:50
*** henrynash has quit IRC07:51
*** fhubik has joined #openstack-keystone07:56
*** btully has quit IRC07:56
*** jistr has joined #openstack-keystone08:04
*** jiaxi has joined #openstack-keystone08:10
*** jiaxi has quit IRC08:17
*** henrynash has joined #openstack-keystone08:17
*** ChanServ sets mode: +v henrynash08:17
*** belmoreira has joined #openstack-keystone08:18
*** jsheeren has joined #openstack-keystone08:19
*** pnavarro has quit IRC08:25
*** fhubik has quit IRC08:29
*** lhcheng has joined #openstack-keystone08:30
*** ChanServ sets mode: +v lhcheng08:30
*** lhcheng has quit IRC08:35
*** aix has joined #openstack-keystone08:38
*** belmoreira has quit IRC08:44
*** pnavarro has joined #openstack-keystone08:47
*** jsheeren has quit IRC08:49
openstackgerritAndrey Pavlov proposed openstack/keystonemiddleware: Adding parse of protocol v4 of AWS auth to ec2_token  https://review.openstack.org/20544008:49
*** markvoelker has joined #openstack-keystone08:51
*** lhcheng has joined #openstack-keystone08:55
*** ChanServ sets mode: +v lhcheng08:55
*** markvoelker has quit IRC08:56
*** davechen has left #openstack-keystone08:59
*** lhcheng has quit IRC08:59
*** fhubik has joined #openstack-keystone09:00
*** marzif has joined #openstack-keystone09:02
*** btully has joined #openstack-keystone09:03
openstackgerritMarek Denis proposed openstack/keystoneauth-saml2: Depend on keystoneauth  https://review.openstack.org/18685409:04
openstackgerritAtsushi SAKAI proposed openstack/keystone: Fix four typos and Add one space on keystone document  https://review.openstack.org/20545209:05
*** btully has quit IRC09:08
*** marzif has quit IRC09:08
*** marzif has joined #openstack-keystone09:09
*** marzif has quit IRC09:11
*** marzif has joined #openstack-keystone09:12
*** afazekas has quit IRC09:20
*** _afazekas has quit IRC09:20
*** hightall has quit IRC09:20
*** lsmola has quit IRC09:21
*** __afazekas has joined #openstack-keystone09:23
*** afazekas has joined #openstack-keystone09:25
*** dguerri` is now known as dguerri09:42
*** e0ne has joined #openstack-keystone09:42
openstackgerritAndrey Pavlov proposed openstack/keystonemiddleware: Adding parse of protocol v4 of AWS auth to ec2_token  https://review.openstack.org/20544009:48
*** fhubik is now known as fhubik_afk09:50
*** fhubik_afk is now known as fhubik09:51
*** jiaxi has joined #openstack-keystone10:01
*** e0ne_ has joined #openstack-keystone10:02
*** e0ne has quit IRC10:03
*** fhubik is now known as fhubik_afk10:05
*** henrynash has quit IRC10:08
*** henrynash has joined #openstack-keystone10:13
*** ChanServ sets mode: +v henrynash10:13
openstackgerritAtsushi SAKAI proposed openstack/keystone: Fix four typos and Add one space on keystone document  https://review.openstack.org/20545210:17
*** dims has joined #openstack-keystone10:36
*** chenhong1 has quit IRC10:43
*** marzif has quit IRC10:45
*** henrynash has quit IRC10:46
*** marzif has joined #openstack-keystone10:46
*** piyanai has joined #openstack-keystone10:50
*** markvoelker has joined #openstack-keystone10:52
*** fhubik_afk is now known as fhubik10:56
*** markvoelker has quit IRC10:57
*** openstackgerrit has quit IRC11:01
*** openstackgerrit has joined #openstack-keystone11:02
*** yottatsa has joined #openstack-keystone11:14
*** pnavarro has quit IRC11:16
*** pnavarro has joined #openstack-keystone11:21
*** henrynash has joined #openstack-keystone11:39
*** ChanServ sets mode: +v henrynash11:39
*** henrynash has quit IRC11:42
samueldmqayoung: morning11:42
samueldmqayoung: see https://etherpad.openstack.org/p/centralized-policy-delivery-operators again11:42
samueldmqayoung: I improved it, I think that is too clear now that it is a step of the dynamic policies11:42
*** jagter has joined #openstack-keystone11:45
*** jiaxi has quit IRC11:53
*** fhubik is now known as fhubik_afk12:08
openstackgerritSamuel de Medeiros Queiroz proposed openstack/keystone-specs: Centralized Policies Fetch and Cache  https://review.openstack.org/13465512:09
samueldmqdolphm: expanded the performance and security impact sections ^12:09
*** ayoung has quit IRC12:10
*** jaosorior has quit IRC12:11
*** jaosorior has joined #openstack-keystone12:11
*** eandersson has joined #openstack-keystone12:14
*** raildo has joined #openstack-keystone12:14
*** cloudull_zzz is now known as cloudnull12:16
*** wasmum has quit IRC12:20
marekdsamueldmq: i think the Dynamic/Centralized Policy was supposed to be optional, right?12:20
*** e0ne_ is now known as e0ne12:20
samueldmqmarekd: hey, yes, there will be a config switch in the middleware to whether fetch the centralized policy or not12:21
marekdsamueldmq: i commented on the review.12:23
eanderssonHey. I am getting the following error in Horizon/liberty with domain-tokens.12:23
eandersson> The resource could not be found. (https://keystone:5000/users/<id>/projects)12:23
eanderssonI was just wondering if this is a valid request in Kilo :p12:23
marekdeandersson: did doc say anything about deprecation ?12:24
*** markvoelker has joined #openstack-keystone12:25
eanderssonI haven't found anything at least. :D12:25
eanderssonI am trying to figure out if this is a misconfiguration, bug or well incomaptibility.12:26
*** fhubik_afk is now known as fhubik12:27
eanderssonI'll have to set it up in a local dev environment and see if I can find out what it is trying to do I guess12:27
*** amakarov_away is now known as amakarov12:29
openstackgerritSamuel de Medeiros Queiroz proposed openstack/keystone-specs: Centralized Policies Fetch and Cache  https://review.openstack.org/13465512:30
samueldmqmarekd: ^ done12:30
*** piyanai has quit IRC12:34
*** jsavak has joined #openstack-keystone12:36
*** rletrocquer has quit IRC12:37
*** rletrocquer has joined #openstack-keystone12:37
*** jiaxi has joined #openstack-keystone12:41
jiaxihello.everyone12:43
dstanekjiaxi: hi12:46
*** bknudson has joined #openstack-keystone12:48
*** ChanServ sets mode: +v bknudson12:48
marekdsamueldmq: thanks12:48
samueldmqmarekd: np12:48
samueldmqsome reviews are just .. so funny12:48
marekd?12:48
samueldmqa review from stevemar in one of the specs : 'this spec doesn't make me want to rage quit keystone-spec, so it's a good thing.'12:48
samueldmqhehe I was looking at it now :)12:49
dstaneksamueldmq: at least you're aiming high12:49
marekdi like steve's sense oh humour12:49
samueldmqdstanek: :)12:49
samueldmqmarekd: yes12:49
jiaxidstanek: https://review.openstack.org/#/c/200512/  My patch looks much better now12:49
jiaxidstanek: but no one look...12:50
dstanekjiaxi: nice12:50
samueldmqand another ... dolphm's review on my patch yesterday : "WTF kind of use case is this?"12:50
samueldmqhehehe12:50
dstaneksamueldmq: that actually made me laugh out load when i read that12:50
samueldmqdstanek: me too ahah12:51
dstanekjiaxi: yes, sometimes it takes a while. according to next-review i have 208 reviews to reviews and i'm also trying to get some coding done12:52
samueldmqdstanek: I took his comment as something funny, and not as he was hating my text at all :p12:52
*** dims has quit IRC12:52
marekdsamueldmq: that was not his intention :P12:53
*** dims has joined #openstack-keystone12:53
samueldmqanyway I like when there is space for improvements12:53
samueldmqif I am learning I am happy, I apply this to everything I am doing :)12:54
marekd...12:54
samueldmqmarekd: I am not judging that comment, I am just saying something in general :p12:54
marekdneither do i!12:55
samueldmqmarekd: sure I know :)12:55
samueldmqmarekd: btw the second spec that needs love is the on in keystone side (https://review.openstack.org/#/c/197980/)12:58
*** jdandrea has joined #openstack-keystone12:59
samueldmqmarekd: I think that middleware one is almost ready :)12:59
samueldmqmarekd: were you at the midcycle ? did you see the demo?12:59
yottatsajiaxi, (slow)hi13:00
samueldmqdstanek: basically we changed from 'dynamic policies delivery' to somehting like 'centralized policies distribution'13:01
openstackgerritDavid Stanek proposed openstack/python-keystoneclient: No keystone Endpoint now gives a valid Error Message  https://review.openstack.org/15526013:01
samueldmqdstanek: the bp name refers to the former, should I create another bp with the latter and update specs ? (to be more consistent)13:01
samueldmqdstanek: it currently is 'dynamic-policies-delivery', and I don't think it's possible to update the bp url, for ex13:02
dstaneksamueldmq: i don't care as much about the bp since that is really for tracking purposes. the spec is the design doc and wording there matters13:03
*** wasmum has joined #openstack-keystone13:03
samueldmqdstanek: makes sense, I will update just the bp title/description, thanks13:03
*** jsavak has quit IRC13:03
*** jsavak has joined #openstack-keystone13:04
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecations  https://review.openstack.org/19151113:06
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Deprecations fixture support calling deprecated function  https://review.openstack.org/20552413:06
*** hockeynut has quit IRC13:09
*** browne has joined #openstack-keystone13:12
marekdsamueldmq: yes, i was, yes i did see it13:12
openstackgerritAndrey Pavlov proposed openstack/keystonemiddleware: Adding parse of protocol v4 of AWS auth to ec2_token  https://review.openstack.org/20544013:12
marekdsamueldmq: let me read it later, ok ?13:14
marekdi need to do sth else right now.13:14
jiaxiayoung:  are you here13:15
*** hockeynut has joined #openstack-keystone13:15
*** hockeynut has quit IRC13:15
samueldmqmarekd: sure sir, take your time :)13:16
*** petertr7_away is now known as petertr713:17
*** hockeynut_afk has quit IRC13:24
*** richm has joined #openstack-keystone13:24
*** hrou has joined #openstack-keystone13:25
*** jistr is now known as jistr|mtg13:29
openstackgerritMerged openstack/keystone: Fix four typos and Add one space on keystone document  https://review.openstack.org/20545213:31
*** tristanC has quit IRC13:31
*** tristanC has joined #openstack-keystone13:32
*** fhubik has quit IRC13:32
*** hockeynut has joined #openstack-keystone13:32
*** fhubik has joined #openstack-keystone13:32
jiaxihttps://review.openstack.org/#/c/200512/13:33
*** geoffarnold has joined #openstack-keystone13:33
*** petertr7 is now known as petertr7_away13:34
jiaxiyottatsa:  help me to review my patch set https://review.openstack.org/#/c/200512/13:34
jiaxiyottatsa: You are so kind.13:35
*** petertr7_away is now known as petertr713:35
*** woodster_ has joined #openstack-keystone13:36
*** geoffarnold has quit IRC13:37
*** gordc has joined #openstack-keystone13:41
*** ayoung has joined #openstack-keystone13:42
*** ChanServ sets mode: +v ayoung13:42
*** ajayaa has quit IRC13:47
marekdlbragstad:ok, i need your playbooks to quickly deploy keystone env.13:50
marekddo you have some sort of newbie intro ?13:50
openstackgerritSamuel de Medeiros Queiroz proposed openstack/keystone-specs: Centralized Policies Distribution Mechanism  https://review.openstack.org/19798013:50
openstackgerritSamuel de Medeiros Queiroz proposed openstack/keystone-specs: Centralized Policies Fetch and Cache  https://review.openstack.org/13465513:51
samueldmqayoung: did you have a chance to take a look at the email message?13:53
samueldmqayoung: I am asking because I will have to leave in a bit and will only be back later today13:53
samueldmqayoung: so if you think it is good enough I could send it already :)13:54
*** edmondsw has joined #openstack-keystone13:56
bretonDoes13:57
bretonSam Leong13:57
bretonah, dammit.13:58
breton*Does Sam Leong hang out here?13:58
bretonI don't see his nickname on the launchpad page13:58
*** henrynash has joined #openstack-keystone13:58
*** ChanServ sets mode: +v henrynash13:58
*** piyanai has joined #openstack-keystone14:00
*** topol has joined #openstack-keystone14:01
*** ChanServ sets mode: +v topol14:01
samueldmqayoung: specs updated.. I am leaving for a bit, will be back this afternoon14:01
jiaxiayoung:  are you here14:03
*** btully has joined #openstack-keystone14:03
*** ParsectiX has quit IRC14:04
*** browne has quit IRC14:05
*** mylu has joined #openstack-keystone14:06
*** r-daneel has joined #openstack-keystone14:11
*** jistr|mtg is now known as jistr14:12
*** henrynash has quit IRC14:14
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecations  https://review.openstack.org/19151114:18
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for AccessInfo region_name parameter  https://review.openstack.org/20554714:18
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for AccessInfo scoped property  https://review.openstack.org/20554814:18
*** jecarey has joined #openstack-keystone14:19
jiaxihttps://review.openstack.org/#/c/200512/14:20
*** jaosorior has quit IRC14:21
*** sigmavirus24_awa is now known as sigmavirus2414:23
ayoungjiaxi, sort of.  What's up?14:24
jiaxiayoung: https://review.openstack.org/#/c/200512/   my patch set always failure  because of tempest , tempest is broken..  recheck for many times14:26
openstackgerritVladimir Eremin proposed openstack/keystone: Replace 401 to 404 when token is invalid  https://review.openstack.org/20555414:26
openstackgerritMerged openstack/keystone: add federation docs for mod_auth_mellon  https://review.openstack.org/19808314:27
*** browne has joined #openstack-keystone14:27
ayoungjiaxi, looks good.  +2 from me14:28
ayoungjiaxi, maybe tempest is setting invalid URLs.  Take a look at the failures....I don;t think that to be the case ,but...wouldn't it be cool if you caught that?14:28
jiaxiayoung: Thank you. You are so nice.14:29
jiaxiayoung: I will check the log.14:29
ayoung不用谢我14:29
yottatsajiaxi, looking on 20051214:32
jiaxiyottatsa: what do you mean ?14:32
jiaxiyottatsa: look my patch set ? which part ?14:33
yottatsajiaxi, yup14:33
jiaxiyottatsa: which part ?  I have look it for so many time.14:33
*** stevemar has joined #openstack-keystone14:34
*** ChanServ sets mode: +v stevemar14:34
*** geoffarnold has joined #openstack-keystone14:35
*** topol has quit IRC14:35
*** henrynash has joined #openstack-keystone14:36
*** ChanServ sets mode: +v henrynash14:36
*** jiaxi has quit IRC14:40
*** hockeynut_afk has joined #openstack-keystone14:42
larsksIs the change from keystone.token.backends to keystone.token.persistence.backends between Juno and Kilo documented somewhere?14:43
stevemarlarsks: probably in the release notes14:44
*** marzif has quit IRC14:44
larsksI don't recall seeing deprecation warnings in Juno, so I am susprised to see this go away in Kilo like that.14:45
stevemarhey ayoung, i think i remember you asking about oslo.policy adoption, it's going well: https://bugs.launchpad.net/nova/+bug/145894514:45
openstackLaunchpad bug 1458945 in Cinder "Use graduated oslo.policy instead of oslo-incubator code" [Medium,In progress] - Assigned to Ivan Kolodyazhny (e0ne)14:45
*** marzif has joined #openstack-keystone14:45
ayoungstevemar, I'm too depressed about the rest of policy to cheer.14:45
larsksstevemar: There doesn't appear to be any mention of the change in the keystone source itself. Which release notes were you referring to?14:45
larsksAh, releasenotes/kilo on the wiki, maybe...14:46
stevemarlarsks: https://wiki.openstack.org/wiki/ReleaseNotes/Kilo#Upgrade_Notes_514:46
larsksYeah, finding my way there.14:46
stevemarlarsks: we rarely remove without deprecation...14:46
larsksstevemar: I know, that's why I was surprised!14:46
*** henrynash has quit IRC14:47
rodrigodshenrynash, ping... we are discussing patches "consistency". In the first patch of the Reseller chain we can create a is_domain Project that won't be actually a domain that follow all rules. Is that ok?14:47
*** tellesnobrega has quit IRC14:47
ayounglarsks, yeah, they couldn't be bothered with fixing PKI, so they rolled back to UUID and wrote fernet instead14:47
*** tellesnobrega has joined #openstack-keystone14:47
stevemarlarsks: the message was in the juno code: https://github.com/openstack/keystone/blob/stable/juno/keystone/token/core.py#L36-L4014:47
stevemarlarsks: are you upgrading from icehouse or earlier?14:48
larsksstevemar: Guess I am just blind, or I get so used to seeing deprecation warnings that they fade from awareness.14:48
larsksThanks!14:48
ayoungoh...that.14:48
stevemarit's actually this one: https://github.com/openstack/keystone/blob/stable/juno/keystone/token/core.py#L104-L10814:48
*** hockeynut_afk has quit IRC14:48
*** tellesnobrega has quit IRC14:48
stevemarlarsks: possible14:48
*** tellesnobrega has joined #openstack-keystone14:49
*** hockeynut_afk has joined #openstack-keystone14:49
stevemarayoung: not bad though... just magnetoDB, magnum, nova and cinder, that need to use oslo.policy14:50
*** ajayaa has joined #openstack-keystone14:51
*** petertr7 is now known as petertr7_away14:51
*** ajayaggarwal has joined #openstack-keystone14:52
*** petertr7_away is now known as petertr714:53
*** geoffarnold has quit IRC14:54
*** tellesnobrega has quit IRC14:56
*** tellesnobrega has joined #openstack-keystone14:56
*** tellesnobrega has quit IRC14:57
*** zzzeek has joined #openstack-keystone14:58
*** tellesnobrega has joined #openstack-keystone14:59
*** mylu has quit IRC15:00
*** pnavarro has quit IRC15:03
*** mylu has joined #openstack-keystone15:07
morganfainbergayoung: is jamielennox on vacation?15:10
*** piyanai has quit IRC15:11
*** piyanai has joined #openstack-keystone15:11
*** pnavarro has joined #openstack-keystone15:16
*** arunkant has quit IRC15:17
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecations  https://review.openstack.org/19151115:17
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Stop using deprecated AccessInfo.auth_url  https://review.openstack.org/20558115:17
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for AccessInfo auth_url property  https://review.openstack.org/20558215:17
*** geoffarnold has joined #openstack-keystone15:18
*** piyanai has quit IRC15:19
*** piyanai has joined #openstack-keystone15:20
*** piyanai has quit IRC15:20
dstaneki was hoping to find an easy way using sphinx/docutils to parse docstrings. looks like it will be harder than i thought15:21
morganfainberg:(15:22
morganfainbergdstanek: that's unfortunate15:22
dstanekmorganfainberg: all i want is param types and return types :-(  i'll have to try again later15:23
*** piyanai has joined #openstack-keystone15:23
marekdHm, when nova wants to validate a token it calls GET keystone:5000/v3/auth/tokens ?15:23
*** mylu has quit IRC15:24
*** mylu has joined #openstack-keystone15:24
marekdlbragstad: i need your help :-)15:26
*** piyanai has quit IRC15:26
dolphmlbragstad: he's on vacation15:27
dolphmmarekd: ^15:27
marekddolphm: ok15:27
marekddolphm: maybe you've got a minute ?15:27
dolphmmarekd: he returns home monday morning, not sure if he'll be on monday or tuesday15:27
dolphmmarekd: sure15:27
marekddolphm: no worries, doens't needto be Lance specifically15:28
marekdso, when any service wants to validate a token  it hits keystone:5000/v3/auth/tokens15:29
marekddolphm: is that right?15:29
dolphmmarekd: :5000 or :35357 in the case of v315:29
*** piyanai has joined #openstack-keystone15:29
dolphmmarekd: if it was v2, it'd have to hit GET :35357/v2.0/tokens15:29
marekdyeah, i am talking v3 only15:30
marekdan fernet15:30
dolphmGET :35357/v2.0/tokens/{token_id} *15:30
dolphmmarekd: ack, then GET /v3/auth/tokens + X-Subject-Token15:30
marekdso it comes to calling auth.controllers.Auth.validate_token()15:30
marekdanyway, i am trying to get to the spot where actually a token format is distinguished and fernet code is being executed...15:31
*** diazjf has joined #openstack-keystone15:31
*** fhubik has quit IRC15:31
marekdcause clearly the fernet token must be disassembled15:31
dolphmmarekd: yep15:32
*** mylu has quit IRC15:32
marekddolphm: can you point me to that function/method ?15:33
dolphmmarekd: are you referring to the fernet token format being handled, or the payload inside the fernet token being handled?15:35
marekddolphm: payload.15:35
*** topol has joined #openstack-keystone15:36
*** ChanServ sets mode: +v topol15:36
marekddolphm: well, in fact i wanted to say where anything that touches fernet starts...15:36
*** ankita_wagh has joined #openstack-keystone15:36
dolphmmarekd: https://github.com/openstack/keystone/blob/master/keystone/token/providers/fernet/token_formatters.py#L174-L17615:36
marekdfor instance i am using a fernet token with my nova, that fails on token validation, and added rpdb breakpoint in the disassembling method and this seems to not even get there.15:37
dolphmmarekd: the first method there calls cryptography.io do validate the fernet token and return the messagepacked payload15:37
dolphmmarekd: oh, well you might not be hitting the breakpoint if there's caching taking place somewhere15:38
marekdit's simple devstack, i even restarted apache and can see keystone logs that keystone is doing some work.15:38
*** piyanai has quit IRC15:38
dolphmmarekd: devstack runs memcached, iirc15:39
dolphmmarekd: the caching could be in auth_token in front of nova, even15:39
marekddolphm: i figured, but i generated another token too .15:39
dolphmmarekd: if you set a breakpoint on L174 there, you should hit it for a fresh token15:39
marekdtoken_formatters.py ?15:40
*** topol has quit IRC15:40
*** gyee has joined #openstack-keystone15:41
*** ChanServ sets mode: +v gyee15:41
*** piyanai has joined #openstack-keystone15:41
*** david-lyle has quit IRC15:44
*** pnavarro has quit IRC15:46
*** ayoung has quit IRC15:48
marekddolphm: ok, i hit the breakpoints.15:48
marekdthanks15:48
*** topol has joined #openstack-keystone15:51
*** ChanServ sets mode: +v topol15:51
dolphmmarekd: was it caching, or were you setting a breakpoint in the wrong spot?15:54
*** bitblt has joined #openstack-keystone15:56
marekd.pyc file i think.15:57
*** ajayaggarwal has left #openstack-keystone15:58
marekdi thoroughly cleaned all .pyc, pyo files, restarted apache and it worked.15:58
*** mylu has joined #openstack-keystone15:59
*** yottatsa has quit IRC16:01
*** yottatsa has joined #openstack-keystone16:03
*** marzif has quit IRC16:05
yottatsamarekd, look at https://review.openstack.org/20555416:05
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecations  https://review.openstack.org/19151116:05
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for AccessInfo auth_url property  https://review.openstack.org/20558216:05
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Stop using deprecated AccessInfo.auth_url and management_url  https://review.openstack.org/20558116:05
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for AccessInfo management_url property  https://review.openstack.org/20560216:05
*** marzif has joined #openstack-keystone16:06
*** kiran-r has joined #openstack-keystone16:06
marekdyottatsa: thanks.16:06
*** mylu has quit IRC16:07
*** mylu has joined #openstack-keystone16:07
yottatsamarekd, here the place where token_provider_api is used for validation https://github.com/openstack/keystone/blob/master/keystone/token/controllers.py#L44816:08
yottatsathere is fernet implementation https://github.com/openstack/keystone/blob/master/keystone/token/providers/fernet/core.py#L15216:09
yottatsathere is uuid implementation https://github.com/openstack/keystone/blob/master/keystone/token/providers/common.py#L67916:09
yottatsadolphm, https://review.openstack.org//205130 I've done with bugfix16:11
yottatsaplease take a look16:11
*** tsymanczyk has quit IRC16:12
dolphmyottatsa: already am!16:14
dolphmyottatsa: looks great, but i have a nit i'm writing a rather detailed explanation for - give me one minute16:14
dolphmyottatsa: posted https://review.openstack.org/#/c/205554/16:16
*** _cjones_ has joined #openstack-keystone16:16
*** _cjones_ has quit IRC16:17
*** _cjones_ has joined #openstack-keystone16:17
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecations  https://review.openstack.org/19151116:17
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecations for modules  https://review.openstack.org/20561016:17
dolphmyottatsa: also, when you go to update https://review.openstack.org/#/c/205130/ with the final, approved patch from master ... i recommend using "git review -X 205554" to produce the patch, which will include the "cherry-picked from commit <sha>" in the commit message, which the stable maintenance team and other folks downstream seem to really appreciate16:17
*** geoffarn_ has joined #openstack-keystone16:17
*** geoffarnold has quit IRC16:18
*** geoffarn_ has quit IRC16:18
dolphmyottatsa: thanks for doing the backport though! if i don't do the cherry picking myself, then that means i can +2 it :)16:18
*** jecarey has quit IRC16:19
*** geoffarnold has joined #openstack-keystone16:19
*** tsymancz1k has joined #openstack-keystone16:19
*** dguerri is now known as dguerri`16:20
*** david-lyle has joined #openstack-keystone16:20
openstackgerritVladimir Eremin proposed openstack/keystone: Replace 401 to 404 when token is invalid  https://review.openstack.org/20555416:20
yottatsadolphm, thank you for explanation!16:20
dolphmyottatsa: +2!16:22
yottatsathanks dolphm!16:22
dolphmyottatsa: are you running openstack at yandex?16:22
yottatsayup16:22
yottatsaabout 2500 nodes setup16:22
dolphmyottatsa: nice! is it a production environment?16:23
yottatsadolphm I'm afraid I can't speak on behalf of Yandex, PR department doesn't like it16:25
*** petertr7 is now known as petertr7_away16:25
dolphmyottatsa: i'm just interested in what you're doing with fernet :)16:27
dolphmyottatsa: but, understood!16:27
*** piyanai has quit IRC16:28
yottatsadolphm, we have some business critical tasks in the cloud (like automatic fuctional testing), so API stability and performance is very important for our deployment16:30
*** diazjf has quit IRC16:31
yottatsafernet tokens allow us to dramatically reduce token issue and token validation time16:32
bretonyottatsa: 2500 physical nodes or 2500 vms?16:32
yottatsait's mainly because we don't need to store tokens in keystone.token table16:32
yottatsabreton, 2500 physical nodes, about 100k cores16:33
*** diazjf has joined #openstack-keystone16:34
*** gyee has quit IRC16:34
*** Protux has quit IRC16:37
*** browne has quit IRC16:37
*** piyanai has joined #openstack-keystone16:37
*** Protux has joined #openstack-keystone16:37
*** tellesnobrega has quit IRC16:37
*** geoffarnold has quit IRC16:38
*** tellesnobrega has joined #openstack-keystone16:38
*** geoffarnold has joined #openstack-keystone16:38
*** gyee has joined #openstack-keystone16:40
*** ChanServ sets mode: +v gyee16:40
*** arunkant has joined #openstack-keystone16:43
*** lhcheng has joined #openstack-keystone16:46
*** ChanServ sets mode: +v lhcheng16:46
*** nkinder has joined #openstack-keystone16:48
*** snapdey has joined #openstack-keystone16:54
*** stevemar has quit IRC16:55
*** ayoung has joined #openstack-keystone16:55
*** ChanServ sets mode: +v ayoung16:55
*** piyanai has quit IRC16:57
*** kiran-r has quit IRC16:58
*** ankita_wagh has quit IRC16:58
*** geoffarn_ has joined #openstack-keystone16:59
*** piyanai has joined #openstack-keystone17:00
*** yottatsa has quit IRC17:00
bretongyee: hey!17:00
*** mylu has quit IRC17:01
*** roxanaghe has joined #openstack-keystone17:02
bretongyee: are there any plans to make changes to ksm and ksc for X.509 support?17:02
*** geoffarnold has quit IRC17:03
*** mylu has joined #openstack-keystone17:03
*** ajayaa has quit IRC17:04
*** dims is now known as dimsum__17:04
*** petertr7_away is now known as petertr717:04
*** yottatsa has joined #openstack-keystone17:06
*** tqtran has joined #openstack-keystone17:07
*** tsymancz1k has quit IRC17:08
*** spandhe has joined #openstack-keystone17:08
*** snapdey has quit IRC17:09
*** snapdey has joined #openstack-keystone17:12
*** piyanai has quit IRC17:12
yottatsaPromise I've done https://blueprints.launchpad.net/keystone/+spec/keystone-slaveification on Monday17:13
*** petertr7 is now known as petertr7_away17:14
*** ankita_wagh has joined #openstack-keystone17:17
*** piyanai has joined #openstack-keystone17:19
*** geoffarnold has joined #openstack-keystone17:19
*** piyanai has quit IRC17:20
*** geoffarn_ has quit IRC17:23
*** piyanai has joined #openstack-keystone17:23
*** diazjf has left #openstack-keystone17:27
*** browne has joined #openstack-keystone17:30
*** petertr7_away is now known as petertr717:32
ayoungdolphm, samueldmq, https://review.openstack.org/#/c/205629/  . let's use that spec as the grounds for further discussion on how to get past the global admin issues.17:32
*** TheIntern has joined #openstack-keystone17:32
*** piyanai has quit IRC17:35
gyeebreton, yes, I think jamielennox have most of the plumbing done already17:36
gyeeit would be trivial to make it support x.509 since the feature is landed17:36
*** yottatsa has quit IRC17:36
*** deep has joined #openstack-keystone17:38
openstackgerritRodrigo Duarte proposed openstack/keystone: Add is_domain field in Project Table  https://review.openstack.org/15742717:38
bretongyee: he did it in both ksm and ksc? Is there a patch to review?17:38
gyeeayoung, for the endpoint constraint patch, I'll remove the py3 stuff once bknudson's patches are landed17:38
deepHello17:38
*** ankita_wagh has quit IRC17:39
gyeebreton, its just another auth plugin so it should work for both ksc and ksm17:39
deepresponse = self._adapter.request(path, method, **kwargs)17:39
ayounggyee, works for me17:40
ayounggyee, is that the last issue?17:40
gyeeayoung, yes, because test-requirements-py3 was holding up jenkins17:40
bretongyee: is the plugin implemented?17:41
gyeebreton, not yet, but should be fairly trivial17:41
ayounggyee, added you to https://review.openstack.org/#/c/205629/  as I think you might be interested17:42
deepin the keystone middleware auth_token, i am trying to understand the code, in _identity.py line 247 response = self._adapter.request(path, method, **kwargs), i am not able to understand where does this request goes and where to look for the code for _adapter.request. I am trying to debug the issue where proxy server is not able to download revoked token from keystone running on ssl17:42
gyeeayoung, amend brother!17:42
ayoungI think you mean Amen.17:42
gyeeyes17:42
gyeemy bad17:42
*** piyanai has joined #openstack-keystone17:43
gyeeI was mixing git commands with English17:43
ayoungAme is from the Hebrew "We Speak" meaning to affirm.  To amend....I wonder if those are related words...interesting17:43
gyeeindeed17:43
bhendersonI all, anyone recommend a docker container for keystone?17:44
raildogyee: sometimes I do this, with english and my own language :P17:44
bretongyee: ok. You won't mind me implementing it, will you?17:44
gyeebreton, go for it17:44
gyeebreton, all we need is a plugin which will convey the scope in the request headers17:45
*** rletrocquer has quit IRC17:45
gyeeeverything else should already be taken care off by the SSL connection itself17:45
ayounggyee, so...they are actually not related words at all. A-M-N  is the root word for "faithful"  and "Mend"  is the Latin root word for fault or error...pretty much the opposite.  Neat17:46
gyeeraildo, at least your language is closer to english :)17:46
gyeeayoung, good to know :)17:46
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements  https://review.openstack.org/20493717:47
*** petertr7 is now known as petertr7_away17:48
*** petertr7_away is now known as petertr717:48
*** geoffarnold has quit IRC17:48
deepin the keystone middleware auth_token, i am trying to understand the code, in _identity.py line 247 response = self._adapter.request(path, method, **kwargs), i am not able to understand where does this request goes and where to look for the code for _adapter.request. I am trying to debug the issue where proxy server is not able to download revoked token from keystone running on ssl17:48
*** geoffarnold has joined #openstack-keystone17:48
gyeeayoung, ya think we can automate gerrit to strip extra white spaces off instead of having them in red?17:49
lhchenggyee: question on setting up tokenless auth in devstack..17:49
openstackgerritRodrigo Duarte proposed openstack/keystone: Add is_domain field in Project Table  https://review.openstack.org/15742717:49
lhchenggyee: updating the apache conf and keystone.conf atm17:49
ayounggyee, that would be stellar17:49
ayoungdo I have some?  I thought tox would have failed17:49
gyeeayoung, line 8617:49
lhchenggyee: http://paste.openstack.org/show/405384/ is the value of "trusted_issuer" correct?17:49
* ayoung has been 86ed!17:49
gyeeheh17:50
gyeelhcheng, looking17:50
ayounggyee, thanks...fixed17:51
lhchenggyee: so I set the SSLCACertificatePath to the same value as  SSLCertificateFile.. to make the self-signed cert work17:51
gyeelhcheng, yes, that should work17:51
lhchenggyee:  for the truster_issuer value, does having the spaces there okay?17:52
gyeelet me 2x check the code17:53
dstanekbhenderson: i have not used one, but i don't see why it wouldn't work17:53
bhendersondstanek: the couple I've tried seem to have lots of other dependencies, but I'm also new to keystone and I don't really know what deps it has17:54
*** stevemar has joined #openstack-keystone17:54
*** ChanServ sets mode: +v stevemar17:54
bhendersonthanks17:54
*** e0ne has quit IRC17:54
gyeelhcheng, space should be fine17:55
*** stevemar has quit IRC17:57
*** e0ne has joined #openstack-keystone17:57
*** e0ne has quit IRC17:58
lhchenggyee: cool, will bug you more later as I go along setting it up today. :)17:58
*** marzif has quit IRC17:58
*** ankita_wagh has joined #openstack-keystone17:58
*** belmoreira has joined #openstack-keystone17:58
*** stevemar has joined #openstack-keystone18:00
*** ChanServ sets mode: +v stevemar18:00
*** stevemar has quit IRC18:01
*** stevemar has joined #openstack-keystone18:01
*** ChanServ sets mode: +v stevemar18:01
*** stevemar has quit IRC18:03
*** TheIntern has quit IRC18:03
*** piyanai has quit IRC18:04
*** stevemar has joined #openstack-keystone18:04
*** ChanServ sets mode: +v stevemar18:04
*** stevemar has quit IRC18:04
*** stevemar has joined #openstack-keystone18:04
*** ChanServ sets mode: +v stevemar18:04
*** stevemar has quit IRC18:05
ayounghey gyee you in a jacket  and tie now?  http://www.theregister.co.uk/2015/07/24/hp_dress_code?mt=143776088398518:05
*** stevemar has joined #openstack-keystone18:05
*** ChanServ sets mode: +v stevemar18:05
*** stevemar has quit IRC18:06
*** belmoreira has quit IRC18:06
gyeeayoung, hah, I only wear jacket and tie to either wedding or funeral18:06
*** geoffarn_ has joined #openstack-keystone18:07
morganfainbergayoung: ahaha. I sure didnt see that memo- sooooo tshirt it is next week! :P18:07
*** geoffarnold has quit IRC18:08
morganfainberggyee: hey jacket and tie can be cool elsewhere too... Just not all the time.18:08
gyeemorganfainberg, elsewhere? like getting me free beer? :)18:08
morganfainberggyee: like "cause i feel like weirding put people today" :)18:09
gyeehahah18:09
morganfainbergIf it wasnt so bloody warm i might do the 3-peice suit for this trip to sunnyvale. :P18:10
morganfainbergJust to really make people go "wtf"18:10
gyeeyou do that18:10
*** TheIntern has joined #openstack-keystone18:10
gyeereaction would be priceless18:10
gyeeI am sure there will be a lot of "wtf's Morgan smoking lately" stares18:11
ayoungmorganfainberg, you don't count./  GIven your druthers, you;'d look like the people in the Piston booth on a daily basis18:12
morganfainbergNah.18:12
morganfainbergToo much work cleaning those clothes.18:12
*** eandersson has quit IRC18:12
ayoung"It was Colonel Fainberg, in the meeting room, with a cheese-grater"18:12
morganfainbergNewp. No thanks.18:13
ayoungmorganfainberg, I'm trying to focus things down from Dynamic policy to just solving 968696;  https://review.openstack.org/#/c/205629/18:13
ayoungmaybe that will be a small-enough-to-be-understood amount18:14
*** jistr has quit IRC18:14
gyeeidea for tokyo, handing out t-shits with just 968696 on them18:14
gyeet-shirts18:15
ayoungI think you might have been right the first time18:15
*** stevemar has joined #openstack-keystone18:16
*** ChanServ sets mode: +v stevemar18:16
gyeeheh18:16
*** ankita_w_ has joined #openstack-keystone18:18
*** ankita_wagh has quit IRC18:18
morganfainbergI ... Nope so not going to ask ...18:18
*** tsymancz1k has joined #openstack-keystone18:20
gyeemorganfainberg, plan on spending a few hours in the Huntington Library and Getty Museum next week18:21
ayounggyee, T-Shirt would cost $25.  Want one?18:21
gyee$25?!!!18:21
*** snapdey has quit IRC18:22
gyeefrom customlink?18:22
ayounggyee, yep18:23
ayoungcustomink, not link18:23
gyeeayoung, yet, lets do this18:24
*** snapdey has joined #openstack-keystone18:24
*** gordc has quit IRC18:25
*** tqtran has quit IRC18:26
odyssey4medstanek dolphm marekd what review was that fernet token patch for federated scoped tokens again?18:26
odyssey4meI'd like to give it a try18:26
morganfainberggyee: huntington is nice. Check out the gardens too.18:28
morganfainbergThe huntington is walking distance (ok a long walk) from my house.18:28
*** gordc has joined #openstack-keystone18:29
*** snapdey has quit IRC18:29
*** snapdey has joined #openstack-keystone18:32
*** mylu has quit IRC18:34
*** jistr has joined #openstack-keystone18:35
*** mylu has joined #openstack-keystone18:35
*** snapdey has quit IRC18:35
*** piyanai has joined #openstack-keystone18:35
*** jistr is now known as jistr|afk18:35
dstanekodyssey4me: this one? https://review.openstack.org/#/c/202176/18:36
odyssey4medstanek yeah, thanks - I actually had just found it18:37
odyssey4meit looks like it still needs another revision18:37
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements  https://review.openstack.org/20493718:38
*** ankita_w_ has quit IRC18:41
*** ankita_wagh has joined #openstack-keystone18:41
openstackgerritAlexander Makarov proposed openstack/keystone-specs: Unified delegation spec  https://review.openstack.org/18981618:41
*** stevemar has quit IRC18:42
*** iamjarvo has joined #openstack-keystone18:42
*** stevemar has joined #openstack-keystone18:42
*** ChanServ sets mode: +v stevemar18:42
*** topol has quit IRC18:43
openstackgerritAlexey Miroshkin proposed openstack/keystone: Assign different values to public and admin ports  https://review.openstack.org/20566718:43
*** snapdey has joined #openstack-keystone18:43
*** stevemar has quit IRC18:47
*** TheIntern has quit IRC18:47
*** mylu has quit IRC18:49
*** mylu has joined #openstack-keystone18:51
*** pnavarro has joined #openstack-keystone18:55
lhchenggyee: in the doc https://review.openstack.org/#/c/156870/43/doc/source/configure_tokenless_x509.rst18:55
lhchenggyee: should "SSLCACertificatePath /etc/apache2/ssl/cacert.crt" point to a directory?18:55
lhchenggyee: I get an error after restarting apache: "SSLCACertificatePath: directory '/opt/stack/data/CA/int-ca/devstack-cert.crt' does not exist"18:56
gyeethat's weird18:58
gyeefile perms set correctly?18:58
*** stevemar has joined #openstack-keystone18:59
*** ChanServ sets mode: +v stevemar18:59
*** gyee has quit IRC18:59
*** snapdey has quit IRC19:00
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecations  https://review.openstack.org/19151119:00
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for BaseIdentityPlugin username, password, token_id properties  https://review.openstack.org/20567619:00
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for BaseIdentityPlugin trust_id property  https://review.openstack.org/20567719:00
*** snapdey has joined #openstack-keystone19:00
lhchenggyee: I think so, this is the same cert used by devstack for ssl.  permission is 64419:01
*** ankita_wagh has quit IRC19:01
*** ankita_wagh has joined #openstack-keystone19:02
openstackgerritRodrigo Duarte proposed openstack/keystone: Add is_domain field in Project Table  https://review.openstack.org/15742719:10
openstackgerritRodrigo Duarte proposed openstack/keystone: Change project name constraints  https://review.openstack.org/15837219:10
*** tsymancz1k has quit IRC19:12
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecations  https://review.openstack.org/19151119:16
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Stop using Manager.api  https://review.openstack.org/20568119:16
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for Manager.api  https://review.openstack.org/20568219:16
*** EmilienM is now known as EmilienM|brb19:18
*** bitblt has quit IRC19:22
*** mylu has quit IRC19:22
*** mylu has joined #openstack-keystone19:25
*** mylu has quit IRC19:27
*** mylu has joined #openstack-keystone19:28
*** geoffarn_ has quit IRC19:29
*** geoffarnold has joined #openstack-keystone19:30
*** piyanai has quit IRC19:34
*** deep has quit IRC19:37
*** piyanai has joined #openstack-keystone19:38
*** topol has joined #openstack-keystone19:38
*** ChanServ sets mode: +v topol19:38
*** TheIntern has joined #openstack-keystone19:40
*** mylu has quit IRC19:41
*** ankita_wagh has quit IRC19:43
*** mylu has joined #openstack-keystone19:44
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecations  https://review.openstack.org/19151119:46
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for client.HTTPClient  https://review.openstack.org/20568719:46
*** ankita_wagh has joined #openstack-keystone19:46
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for is_ans1_token  https://review.openstack.org/20568819:46
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for Dicover.available_versions()  https://review.openstack.org/20568919:46
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for Dicover.raw_version_data unstable parameter  https://review.openstack.org/20569019:46
openstackgerritAndrey Pavlov proposed openstack/keystonemiddleware: Adding parse of protocol v4 of AWS auth to ec2_token  https://review.openstack.org/20544019:54
*** topol has quit IRC19:55
*** piyanai has quit IRC19:56
*** EmilienM|brb is now known as EmilienM19:59
*** piyanai has joined #openstack-keystone19:59
*** henrynash has joined #openstack-keystone20:01
*** ChanServ sets mode: +v henrynash20:01
*** geoffarnold has quit IRC20:01
*** hrou has quit IRC20:05
*** hrou has joined #openstack-keystone20:05
*** tsymancz1k has joined #openstack-keystone20:11
samueldmqayoung: you around ?20:16
samueldmqayoung: morganfainberg did you take a look at the message I am planning to send to the operators list?20:18
ayoungsamueldmq, I'm not very round, but starting to get soft in the belly20:18
*** snapdey has quit IRC20:18
raildohenrynash: ping, the link for the reseller session https://www.openstack.org/summit/tokyo-2015/vote-for-speakers/presentation/633820:19
raildolet's vote :D20:19
samueldmqayoung: not sure I got what you mean ...20:19
ayoungsamueldmq, I've looked at it, started editing it, stopped, moved over to global admin stuff, and moved back.  I'm not quite sure what to tell you;  I thjink it is the right idea, but not sure how to communicate it.20:20
ayoungrodrigods, you need a photo up, man20:20
samueldmqayoung: so you think I am addressing the feature the wrong way in that message?20:20
raildoayoung: ++20:21
samueldmqayoung: feel free to make any edits on it if you think we could improve that20:21
*** snapdey has joined #openstack-keystone20:21
ayoungsamueldmq, so, the reason we want the "fetch frrom Keystone" is so we can do all sorts of better management in the future20:21
ayoungrow level editingm, etc20:21
ayoungand, the driving reason for that is...what would you say?20:22
samueldmqayoung: yes, and I told that in the mesage, the granular management of rules20:22
samueldmqayoung: that will open the door to: i)  granular manipulation of policy rules20:23
samueldmqayoung: ii) validation of policy rules20:23
ayoungBUT WHY20:23
ayoungsorry20:23
samueldmqayoung: iii) hierarchical roles20:23
ayoungand those are important becasue we want more fine grained delegation.20:23
ayoungand that is for scale.20:23
*** tsymancz1k has quit IRC20:24
ayoungYou need to have the "ADMIN" role for fewer and fewer things.20:24
*** pnavarro has quit IRC20:24
samueldmqayoung: so there is the link to the overview spec (wiki page) already there .. I am not sure how much of details it is necessary to add in there20:25
ayoungright....20:25
samueldmqayoung: otherwise we'll end up with a spec insteade of a email message20:25
ayoungbecause the end goal is so far from the feature we are trying to enable20:25
*** henrynash has quit IRC20:26
samueldmqayoung: I think in the email message that's just a step and is opening the door for other things20:26
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecations  https://review.openstack.org/19151120:26
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for httpclient.request()  https://review.openstack.org/20569920:26
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Fix tests passing user, project, and token  https://review.openstack.org/20570020:26
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for HTTPClient tenant_id, tenant_name parameters  https://review.openstack.org/20570120:27
samueldmqin hte email message I made clear**20:27
samueldmqayoung: get someone else  to read that for you, and ask him/her if that is clear the message we want to pass20:27
samueldmqayoung: we are so involved in the subject that sometimes we aren't the right people to evaluate if we pass/understand the message we are supposed to :)20:28
samueldmqayoung: in additio, if they have quaestions, concerns, they will ask20:29
samueldmqayoung: that's why it's an email thread, not an announcement we're doing :p20:29
*** henrynash has joined #openstack-keystone20:33
*** ChanServ sets mode: +v henrynash20:33
*** amakarov is now known as amakarov_away20:33
*** stevemar has quit IRC20:33
*** henrynash has quit IRC20:34
*** henrynash has joined #openstack-keystone20:34
*** ChanServ sets mode: +v henrynash20:34
*** mylu has quit IRC20:40
*** tsymancz1k has joined #openstack-keystone20:40
*** mylu has joined #openstack-keystone20:42
*** snapdey has quit IRC20:45
*** stevemar has joined #openstack-keystone20:45
*** ChanServ sets mode: +v stevemar20:45
*** mylu has quit IRC20:46
*** mylu has joined #openstack-keystone20:46
*** roxanaghe has quit IRC20:49
*** stevemar has quit IRC20:50
*** gyee has joined #openstack-keystone20:55
*** ChanServ sets mode: +v gyee20:55
*** iamjarvo has quit IRC20:57
*** raildo has quit IRC20:58
*** TheIntern has quit IRC20:59
*** __afazekas has quit IRC21:03
*** iamjarvo has joined #openstack-keystone21:03
*** edmondsw has quit IRC21:06
*** _afazekas has joined #openstack-keystone21:07
*** afazekas has quit IRC21:07
*** afazekas has joined #openstack-keystone21:08
*** snapdey has joined #openstack-keystone21:10
*** ankita_w_ has joined #openstack-keystone21:11
*** petertr7 is now known as petertr7_away21:11
gyeelhcheng, I think the doc is wrong, should be SSLCACertificateFile or SSLCACertificatePath21:11
*** snapdey has quit IRC21:11
*** piyanai has quit IRC21:12
*** ankita_wagh has quit IRC21:14
gyeelhcheng, I'll update the doc21:14
lhchenggyee: cool, that work!21:16
lhcheng*worked21:16
*** e0ne has joined #openstack-keystone21:21
openstackgerritMerged openstack/python-keystoneclient: Deprecations fixture support calling deprecated function  https://review.openstack.org/20552421:22
*** iamjarvo has quit IRC21:25
*** piyanai has joined #openstack-keystone21:27
*** iamjarvo has joined #openstack-keystone21:27
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecations  https://review.openstack.org/19151121:30
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for HTTPClient tenant_id, tenant_name parameters  https://review.openstack.org/20570121:30
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for HTTPClient.tenant_id|name  https://review.openstack.org/20571021:30
openstackgerritBrant Knudson proposed openstack/python-keystoneclient: Proper deprecation for HTTPClient.request methods  https://review.openstack.org/20571121:30
*** gordc has quit IRC21:31
*** snapdey has joined #openstack-keystone21:34
*** iamjarvo has quit IRC21:36
*** roxanaghe has joined #openstack-keystone21:41
*** roxanaghe has quit IRC21:45
*** roxanaghe has joined #openstack-keystone21:47
*** piyanai has quit IRC21:50
*** r-daneel has quit IRC21:53
*** jsavak has quit IRC21:56
*** mylu has quit IRC21:58
*** e0ne has quit IRC22:00
*** snapdey has quit IRC22:27
*** _hrou_ has joined #openstack-keystone22:27
*** snapdey has joined #openstack-keystone22:28
*** hrou has quit IRC22:29
*** hrou has joined #openstack-keystone22:29
*** _hrou_ has quit IRC22:32
*** __afazekas has joined #openstack-keystone22:34
*** afazekas has quit IRC22:35
*** snapdey has quit IRC22:36
*** _afazekas has quit IRC22:36
*** afazekas has joined #openstack-keystone22:36
*** snapdey has joined #openstack-keystone22:43
*** hrou has quit IRC22:47
*** woodster_ has quit IRC22:54
*** jsavak has joined #openstack-keystone22:56
*** jsavak has quit IRC23:01
*** dimsum__ has quit IRC23:02
*** ankita_w_ has quit IRC23:03
*** tsymancz1k has quit IRC23:03
*** dimsum__ has joined #openstack-keystone23:05
*** samleon has joined #openstack-keystone23:08
*** snapdey has quit IRC23:10
*** tsymanczyk has joined #openstack-keystone23:13
*** tsymanczyk is now known as Guest2814523:14
*** markvoelker has quit IRC23:15
*** dguerri` has quit IRC23:27
*** jistr|afk has quit IRC23:29
*** dguerri` has joined #openstack-keystone23:29
*** dguerri` is now known as dguerri23:30
*** dguerri has joined #openstack-keystone23:30
lhchengsamleon, gyee: I am done up to line 168 in the tokenless auth setup: https://review.openstack.org/#/c/156870/43/doc/source/configure_tokenless_x509.rst23:36
lhchengdo I need to make changes in the middleware to test?23:37
*** __afazekas has quit IRC23:37
*** afazekas has quit IRC23:37
gyeeno changes to middleware needed23:39
gyeejust curl should do23:39
*** _afazekas has joined #openstack-keystone23:40
lhchengI tried using "curl -k --cert /opt/stack/data/CA/int-ca/devstack-cert.crt https://10.0.2.15:5000/v3/projects"23:41
lhchenggot an error of "curl: (58) unable to set private key file: '/opt/stack/data/CA/int-ca/cacert.pem' type PEM "23:41
*** zzzeek has quit IRC23:41
gyeecurl --cert <certfile>  --key <keyfile> https://10.0.2.15:5000/v3/projects23:41
lhchengdefinitely something wrong on my curl command23:41
gyeeand --cacert23:42
gyeesince you are using self-signed cert23:42
*** afazekas has joined #openstack-keystone23:42
lhchenghttp://paste.openstack.org/show/405524/23:45
gyee--key should be corresponding to the SSLCertificateKeyFile in your apache mod_ssl23:46
lhchenggyee: fixed, got a new error23:48
lhchenghttp://paste.openstack.org/show/405524/23:48
lhchenggetting close ... :)23:48
gyeethat's the same paste23:49
gyeeyou set the key correctly?23:49
lhchengoops sorry23:50
lhchenghttp://paste.openstack.org/show/405526/23:50
lhchengyeah, key set correctly now23:50
*** nzeer_ has joined #openstack-keystone23:51
*** htruta_ has joined #openstack-keystone23:53
gyeecan you run openssl against it?23:53
*** dguerri has quit IRC23:54
*** wasmum has quit IRC23:54
*** nzeer has quit IRC23:54
gyeeopenssl s_client -CAfile /opt/stack/data/CA/int-ca/devstack-cert.crt -connect 10.0.2.15:500023:54
*** dguerri` has joined #openstack-keystone23:54
*** nzeer_ is now known as nzeer23:54
*** dguerri` is now known as dguerri23:54
*** dguerri has joined #openstack-keystone23:54
*** marzif has joined #openstack-keystone23:55
lhchenghttp://paste.openstack.org/show/405527/23:55
gyeelhcheng, is there a ca cert in /opt/stack/data/CA/int-ca/23:59

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!