kfox1111_ | bknudson: dolphm: thanks. | 00:03 |
---|---|---|
*** markvoelker has quit IRC | 00:06 | |
*** richm has quit IRC | 00:07 | |
*** ctina has joined #openstack-keystone | 00:08 | |
*** chrisshattuck has quit IRC | 00:09 | |
*** jasonsb has quit IRC | 00:11 | |
*** jasonsb has joined #openstack-keystone | 00:11 | |
*** ctina has quit IRC | 00:13 | |
*** su_zhang has quit IRC | 00:24 | |
*** EinstCrazy has quit IRC | 00:25 | |
*** jerrygb has joined #openstack-keystone | 00:31 | |
*** jerrygb has quit IRC | 00:32 | |
*** erhudy has quit IRC | 00:39 | |
*** roxanaghe has quit IRC | 00:41 | |
openstackgerrit | David Stanek proposed openstack/keystone: Use unit.new_service_ref() consistently https://review.openstack.org/238283 | 00:41 |
openstackgerrit | David Stanek proposed openstack/keystone: Use unit.new_endpoint_ref consistently https://review.openstack.org/237758 | 00:41 |
openstackgerrit | David Stanek proposed openstack/keystone: Use unit.new_region_ref() consistently https://review.openstack.org/238302 | 00:41 |
samueldmq | dstanek: that's nice :) ^ | 00:45 |
dstanek | samueldmq: wasn't me - i just had to rebase it because i have work on top of it | 00:45 |
*** markvoelker has joined #openstack-keystone | 00:47 | |
*** sileht has quit IRC | 00:48 | |
openstackgerrit | Hidekazu Nakamura proposed openstack/keystone: Update development environment set up doc https://review.openstack.org/223020 | 00:48 |
samueldmq | dstanek: yep, I saw that's from Sean Perry :) | 00:50 |
andrewbogott | ayoung: now that I have things working with v3, I’m trying to follow your earlier suggestion of making my policy.json support a universal observer. | 00:53 |
andrewbogott | Which, for the short term, means creating a user who can list the instances in projects without having a role in that project. | 00:54 |
andrewbogott | Do you still think that’s possible, or did I fail to state what I was doing adequately before? | 00:54 |
*** gyee has quit IRC | 00:59 | |
*** spandhe has quit IRC | 01:00 | |
*** EinstCrazy has joined #openstack-keystone | 01:01 | |
*** hrou has joined #openstack-keystone | 01:07 | |
*** jmccrory has quit IRC | 01:09 | |
*** boris-42 has joined #openstack-keystone | 01:13 | |
*** jmccrory has joined #openstack-keystone | 01:13 | |
*** jmccrory has quit IRC | 01:14 | |
*** spandhe has joined #openstack-keystone | 01:16 | |
kfox1111_ | is there any drawback to running keystone without a rabbit? | 01:17 |
kfox1111_ | its just used for notifications, right? | 01:17 |
jamielennox | the fox gets bored | 01:18 |
jamielennox | :D | 01:18 |
jamielennox | sorry, weird day | 01:18 |
kfox1111_ | :) | 01:18 |
jamielennox | yup, just notifications | 01:19 |
kfox1111_ | and the notifications are just advisory, nothing really relies apon them today? | 01:19 |
jamielennox | umm, i'd check ceilometer | 01:19 |
jamielennox | but afaik no | 01:19 |
kfox1111_ | k. thx. | 01:20 |
jamielennox | no one is actually doing cleanup | 01:20 |
kfox1111_ | going to setup one keystone to rule them all (multi region) | 01:20 |
kfox1111_ | and just double checking. | 01:20 |
*** mylu has joined #openstack-keystone | 01:21 | |
*** davechen1 has joined #openstack-keystone | 01:22 | |
*** lhcheng has quit IRC | 01:26 | |
*** mylu has quit IRC | 01:34 | |
*** mylu has joined #openstack-keystone | 01:35 | |
notmorgan | ayoung: i am against a "config" option to change the behavior | 01:39 |
notmorgan | ayoung: that really is not solving a clear use-case nor providing good interoperability | 01:39 |
jamielennox | launchpad is missing a "what was that bug i commented on yesterday" style view | 01:39 |
*** mylu has quit IRC | 01:39 | |
notmorgan | ayoung: so either we change "disabled" or we do a new "state" if this is something to be considered | 01:40 |
*** josecastroleon has quit IRC | 01:40 | |
notmorgan | more config options to change behavior is a bad idea. | 01:40 |
notmorgan | imo | 01:40 |
*** roxanaghe has joined #openstack-keystone | 01:41 | |
*** su_zhang has joined #openstack-keystone | 01:43 | |
*** roxanaghe has quit IRC | 01:46 | |
*** dims has joined #openstack-keystone | 01:49 | |
jamielennox | love a good: msg: exception: Code should never reach here | 01:50 |
jamielennox | super helpful | 01:50 |
openstackgerrit | Dave Chen proposed openstack/keystonemiddleware: Deprecate class AuthTokenPlugin properly https://review.openstack.org/220509 | 01:52 |
*** jasonsb has quit IRC | 02:02 | |
*** jmccrory has joined #openstack-keystone | 02:08 | |
*** mylu has joined #openstack-keystone | 02:11 | |
*** su_zhang has quit IRC | 02:11 | |
*** mylu has quit IRC | 02:20 | |
*** mylu has joined #openstack-keystone | 02:21 | |
*** mylu has quit IRC | 02:23 | |
*** mylu has joined #openstack-keystone | 02:25 | |
dolphm | jamielennox: that's like a git blame | kickme | 02:32 |
jamielennox | it's via ansible modules, i'm not even sure where it's coming from | 02:33 |
dolphm | jamielennox: not openstack-ansible, i hope? | 02:34 |
jamielennox | i don't think so | 02:34 |
jamielennox | no it seems to happen when doing keystone_user without a tenant= | 02:34 |
jamielennox | i guess noone thought of that as something you might do | 02:35 |
jamielennox | ditching the whole lot and doing it with commands to openstackclient | 02:35 |
*** GB21 has joined #openstack-keystone | 02:35 | |
*** spandhe has quit IRC | 02:35 | |
jamielennox | dolphm: i didn't see anywhere openstack-ansible-modules let you do anything v3? is that a possibility or just not done via module | 02:36 |
dolphm | jamielennox: like? i'm pretty sure openstack-ansible does everything with v3 | 02:39 |
jamielennox | dolphm: i'm doing my own playbooks, just want to use the helpers so was only looking at https://github.com/openstack-ansible/openstack-ansible-modules | 02:39 |
*** roxanaghe has joined #openstack-keystone | 02:43 | |
*** lhcheng has joined #openstack-keystone | 02:45 | |
*** ChanServ sets mode: +v lhcheng | 02:45 | |
*** btully has quit IRC | 02:45 | |
*** zqfan_afk has quit IRC | 02:46 | |
*** tellesnobrega is now known as tellesnobrega_af | 02:46 | |
*** tellesnobrega_af is now known as tellesnobrega | 02:46 | |
*** roxanaghe has quit IRC | 02:48 | |
*** lhcheng has quit IRC | 02:59 | |
*** tobe has joined #openstack-keystone | 03:27 | |
*** jasonsb has joined #openstack-keystone | 03:27 | |
*** mylu_ has joined #openstack-keystone | 03:29 | |
*** mylu has quit IRC | 03:33 | |
*** mylu_ has quit IRC | 03:33 | |
*** mylu has joined #openstack-keystone | 03:34 | |
*** jasonsb has quit IRC | 03:34 | |
*** mylu has quit IRC | 03:38 | |
*** yangyapeng has joined #openstack-keystone | 03:39 | |
*** roxanaghe has joined #openstack-keystone | 03:45 | |
*** btully has joined #openstack-keystone | 03:46 | |
*** roxanaghe has quit IRC | 03:50 | |
*** btully has quit IRC | 03:51 | |
*** markvoelker has quit IRC | 03:54 | |
*** tellesnobrega is now known as tellesnobrega_af | 03:56 | |
*** tellesnobrega_af is now known as tellesnobrega | 03:57 | |
*** r-daneel has quit IRC | 03:58 | |
*** zqfan_afk has joined #openstack-keystone | 03:58 | |
*** spandhe has joined #openstack-keystone | 04:01 | |
*** flwang has quit IRC | 04:03 | |
openstackgerrit | Jamie Lennox proposed openstack/keystone: Exclude old Shibboleth options from docs https://review.openstack.org/241863 | 04:05 |
*** tellesnobrega is now known as tellesnobrega_af | 04:08 | |
*** mylu has joined #openstack-keystone | 04:09 | |
*** links has joined #openstack-keystone | 04:26 | |
*** su_zhang has joined #openstack-keystone | 04:36 | |
*** jasonsb has joined #openstack-keystone | 04:38 | |
*** sileht has joined #openstack-keystone | 04:45 | |
marekd | jamielennox: yes it does. | 04:51 |
jamielennox | marekd: i'm almost there | 04:51 |
marekd | good luck | 04:52 |
jamielennox | marekd: there's a lot of difference between shib and mellon | 04:52 |
jamielennox | even just in expectation | 04:52 |
marekd | jamielennox: why do you prefer mellon ? | 04:53 |
jamielennox | marekd: not necessarily a preference, just shib isn't shipped on rhel | 04:54 |
jamielennox | interesting how they differ is all | 04:54 |
jamielennox | shib very much tries to be it's own application that happens to be launched by apache | 04:54 |
jamielennox | mellon is a more traditional apache auth module that does what it's told and is configured via apache conf | 04:55 |
*** markvoelker has joined #openstack-keystone | 04:55 | |
marekd | jamielennox: you mean because there is a shibd and mod_shib ? | 04:55 |
jamielennox | marekd: can you launch shibd seperate to mod_shib? | 04:55 |
jamielennox | everything is happening via apache atm | 04:55 |
marekd | jamielennox: not sure if I can but AFAIR arch is that there is a shibd daemon that does the work. | 04:56 |
marekd | jamielennox: in fact it would be good if I could | 04:56 |
jamielennox | yea, | 04:56 |
jamielennox | and there is an /etc/init.d/shibd as well | 04:56 |
marekd | jamielennox: why should I limit myself to Apache only? | 04:56 |
jamielennox | /etc/init.d feels ancient after using systemd for a while | 04:56 |
marekd | all this Apache stuff and static config files is just big lol | 04:56 |
jamielennox | yea, it's just how i've done it - i'm seeing some reasons you did things certain ways that shib supports better | 04:57 |
marekd | if you have a system with systemd you will still have /etc/init.d/shibd ? | 04:58 |
marekd | jamielennox: i often think saml and anything OSS that implements it doesn't really keep up with todays technology... | 04:59 |
marekd | seriously. | 04:59 |
marekd | and requirements for scalability and all this stuff. | 04:59 |
jamielennox | marekd: i don't know, currently i've only got access to a ubuntu vm so i'm having to learn shib | 04:59 |
jamielennox | and remember all the quirks between the two | 04:59 |
marekd | jamielennox: so you are configuring shibd to work with testshib or mellon ? | 05:00 |
*** markvoelker has quit IRC | 05:00 | |
jamielennox | shibd with testshib | 05:00 |
jamielennox | i tried to point mellon at it and it just doesn't work | 05:00 |
jamielennox | the configuration that shibd/testshib are exchanging is not just saml metadata | 05:00 |
marekd | jamielennox: it should be. | 05:01 |
marekd | what do you mean not just saml metadata? | 05:01 |
jamielennox | marekd: underlying it should be, but the config they are doing with each other expects shib config | 05:01 |
jamielennox | ie dynamic fetching of metadata | 05:01 |
jamielennox | umm | 05:01 |
jamielennox | the testshib registration config | 05:01 |
marekd | jamielennox: hm, it should be a SP metadata | 05:02 |
jamielennox | it was just painful to try and get it working with mellon | 05:02 |
*** su_zhang has quit IRC | 05:02 | |
marekd | jamielennox: why are saml2 plugins not listed here ? https://review.openstack.org/#/c/238549/8/setup.cfg | 05:03 |
marekd | jamielennox: because they are experimental or whatever? | 05:03 |
jamielennox | marekd: i've imported them as private because a) i want to fix them up a bit b) they don't work | 05:04 |
jamielennox | i get some problem with passing args to __init__ failure when i try to load them | 05:04 |
jamielennox | so i'm importing them as private until that can all be fixed | 05:04 |
marekd | jamielennox: what's not working? | 05:05 |
marekd | jamielennox: so there was that thing with lazy importer | 05:05 |
marekd | jamielennox: which got eventually removed | 05:05 |
jamielennox | i'm not sure, it was just telling me that the options weren't being passed to __init__ correctly | 05:06 |
jamielennox | i wanted to import as is for now and fix in place | 05:06 |
marekd | jamielennox: is it going to work somehow with OSC without entrypoints? | 05:06 |
jamielennox | marekd: no it will need the entry points | 05:06 |
jamielennox | but i want to get it working first | 05:07 |
marekd | jamielennox: short term (make fixes to the patch) or make requests_saml2 ? | 05:07 |
jamielennox | marekd: short term i want to get it in and get it working, fairly short term i want to refactor the ECP bit into a requests plugin, longer term i want to put that requests plugin in an upstream repo | 05:08 |
jamielennox | the requests plugin can always live in our repo for a wihle | 05:08 |
marekd | jamielennox: yes. | 05:09 |
marekd | what was the change required to make it work as a requests_plugin ? | 05:09 |
marekd | workaround on 30x redirects ? | 05:09 |
jamielennox | marekd: there's a fair bit of restructuring. you can look at the requests docs for how their auth plugins work, or look at like requests-kerberos to see how they handle plugins | 05:10 |
jamielennox | they didn't show a lot, i found another plugin that had lots more detail to it just on github somewhere, i've forgotten the name | 05:10 |
jamielennox | but you can search for examples | 05:10 |
jamielennox | marekd: does shib fail if you don't use ssl? | 05:10 |
jamielennox | Status: urn:oasis:names:tc:SAML:2.0:status:Responder | 05:10 |
jamielennox | Message: Unable to encrypt assertion | 05:10 |
marekd | shib-keygen -y <num of years> | 05:11 |
marekd | did you call it? | 05:11 |
marekd | it shouldn't fail if you configure it with http | 05:11 |
jamielennox | yea | 05:11 |
marekd | need to check logs then | 05:15 |
jamielennox | marekd: there's no keys in the metadata i provide to testshib | 05:15 |
jamielennox | is that right? | 05:15 |
marekd | jamielennox: no. | 05:18 |
marekd | jamielennox: hm, rerun shib-keygen, maybe restart shibd and apache | 05:18 |
marekd | and see if the key is there | 05:18 |
jamielennox | oh, i think maybe i've got the permissions set up wrong | 05:18 |
marekd | (in the metadata) | 05:18 |
jamielennox | i've got the key owned by keystone | 05:18 |
marekd | ah | 05:18 |
marekd | so it's probably there | 05:19 |
marekd | i suggest opening another terminal and tail -f /var/log/shibboleth/* | 05:19 |
marekd | or whatever the dir was | 05:19 |
jamielennox | marekd: yea - i just found that folder, i was wondering why there was nothing in the apache logs | 05:19 |
marekd | :-) | 05:20 |
marekd | apache logs also have some shib related stuff. | 05:20 |
*** roxanaghe has joined #openstack-keystone | 05:20 | |
jamielennox | hmm, no this is an identity provider error being returne d | 05:24 |
jamielennox | aha! | 05:25 |
jamielennox | ok, i'm in | 05:27 |
jamielennox | marekd: thanks | 05:27 |
*** roxanaghe has quit IRC | 05:41 | |
*** spandhe has quit IRC | 05:42 | |
*** fawadkhaliq has quit IRC | 05:43 | |
marekd | congrats | 05:44 |
*** fawadkhaliq has joined #openstack-keystone | 05:44 | |
jamielennox | this gives me at least something to test the saml plugins against again | 05:45 |
*** btully has joined #openstack-keystone | 05:45 | |
davechen1 | jamielennox: maybe the note could be kept there - https://review.openstack.org/#/c/241863 | 05:53 |
*** jaosorior has joined #openstack-keystone | 05:53 | |
davechen1 | jamielennox: i might be more clear why we do config as that under apache. | 05:54 |
davechen1 | s/i/it | 05:55 |
*** boris-42 has quit IRC | 05:58 | |
*** fangzhou has quit IRC | 05:59 | |
*** roxanaghe has joined #openstack-keystone | 06:03 | |
*** akanksha_ has quit IRC | 06:08 | |
openstackgerrit | Hidekazu Nakamura proposed openstack/keystone: Update development environment set up doc https://review.openstack.org/223020 | 06:08 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Imported Translations from Zanata https://review.openstack.org/238789 | 06:13 |
*** mylu has quit IRC | 06:21 | |
*** sileht has quit IRC | 06:25 | |
*** fangzhou has joined #openstack-keystone | 06:27 | |
*** fangzhou has quit IRC | 06:32 | |
*** sileht has joined #openstack-keystone | 06:42 | |
*** spandhe has joined #openstack-keystone | 06:47 | |
*** henrynash has joined #openstack-keystone | 06:49 | |
*** ChanServ sets mode: +v henrynash | 06:49 | |
*** henrynash has quit IRC | 06:55 | |
*** roxanaghe has quit IRC | 06:55 | |
*** heha37 has joined #openstack-keystone | 06:56 | |
*** markvoelker has joined #openstack-keystone | 06:56 | |
*** hrou has quit IRC | 06:57 | |
*** markvoelker has quit IRC | 07:01 | |
*** heha37 has quit IRC | 07:02 | |
*** heha37 has joined #openstack-keystone | 07:04 | |
*** josecastroleon has joined #openstack-keystone | 07:06 | |
*** fawadkhaliq has quit IRC | 07:14 | |
*** sileht has quit IRC | 07:15 | |
*** wanghua has quit IRC | 07:20 | |
*** lsmola has joined #openstack-keystone | 07:20 | |
*** wanghua has joined #openstack-keystone | 07:20 | |
*** fawadkhaliq has joined #openstack-keystone | 07:29 | |
*** fawadkhaliq has quit IRC | 07:36 | |
*** fawadkhaliq has joined #openstack-keystone | 07:36 | |
*** e0ne has joined #openstack-keystone | 07:51 | |
*** jvarlamova has quit IRC | 07:53 | |
*** zigo has quit IRC | 07:53 | |
*** jamielennox is now known as jamielennox|away | 07:54 | |
*** jamielennox|away is now known as jamielennox | 07:54 | |
*** zigo has joined #openstack-keystone | 07:56 | |
*** jamielennox is now known as jamielennox|away | 07:57 | |
*** sileht has joined #openstack-keystone | 07:59 | |
*** e0ne has quit IRC | 08:00 | |
*** ntt has joined #openstack-keystone | 08:02 | |
ntt | Hi, I'm using kilo release of keystone and I'd like to use ssl, someone can help me? | 08:03 |
*** e0ne has joined #openstack-keystone | 08:04 | |
*** btully has quit IRC | 08:07 | |
*** shaleh has quit IRC | 08:07 | |
marekd | ntt: Hi, where is the problem? | 08:08 |
ntt | which section of keystone.conf should I use for ssl? | 08:09 |
ntt | I'm using keystone with apache | 08:09 |
ntt | and I have a wsgi-keystone.conf in the apache config dir | 08:09 |
ntt | Should I just configure ssl in the apache config file or I have to modify some section in keystone.conf? | 08:10 |
*** jvarlamova has joined #openstack-keystone | 08:13 | |
*** fawadkhaliq has quit IRC | 08:15 | |
*** fawadkhaliq has joined #openstack-keystone | 08:15 | |
*** openstackgerrit has quit IRC | 08:16 | |
*** openstackgerrit has joined #openstack-keystone | 08:17 | |
marekd | ntt: just configure ssl in apache | 08:17 |
marekd | and make sure you use https instead of http. | 08:17 |
marekd | apache will handle ssl stuff. | 08:18 |
*** josecastroleon has quit IRC | 08:20 | |
*** fawadk has joined #openstack-keystone | 08:26 | |
openstackgerrit | Marek Denis proposed openstack/keystone: Federation Identity Provider functional tests https://review.openstack.org/203258 | 08:29 |
*** fawadkhaliq has quit IRC | 08:29 | |
openstackgerrit | Marek Denis proposed openstack/keystone: Functional tests for federation mapping CRUD https://review.openstack.org/231574 | 08:31 |
openstackgerrit | Marek Denis proposed openstack/keystone: Functional tests for federation protocols CRUD https://review.openstack.org/233733 | 08:31 |
*** gildub has quit IRC | 08:31 | |
*** openstack has joined #openstack-keystone | 08:33 | |
*** e0ne has quit IRC | 08:33 | |
*** e0ne has joined #openstack-keystone | 08:34 | |
ntt | marekd: thanks... It seems to work. | 08:41 |
*** e0ne has quit IRC | 08:45 | |
*** davechen1 has left #openstack-keystone | 08:45 | |
*** EinstCrazy has quit IRC | 08:45 | |
*** spandhe has quit IRC | 08:45 | |
*** e0ne has joined #openstack-keystone | 08:46 | |
*** e0ne has quit IRC | 08:48 | |
*** EinstCrazy has joined #openstack-keystone | 08:50 | |
*** fhubik has joined #openstack-keystone | 08:51 | |
*** fhubik is now known as fhubik_brb | 08:52 | |
*** jaosorior has quit IRC | 08:53 | |
*** markvoelker has joined #openstack-keystone | 08:57 | |
*** Nirupama has quit IRC | 08:57 | |
*** spandhe has joined #openstack-keystone | 08:57 | |
*** josecastroleon has joined #openstack-keystone | 09:00 | |
*** markvoelker has quit IRC | 09:01 | |
*** gildub has joined #openstack-keystone | 09:06 | |
*** jaosorior has joined #openstack-keystone | 09:09 | |
*** browne has quit IRC | 09:09 | |
*** jistr has joined #openstack-keystone | 09:24 | |
*** urulama has quit IRC | 09:24 | |
*** urulama has joined #openstack-keystone | 09:25 | |
marekd | ntt: coolio :-) | 09:25 |
openstackgerrit | Marek Denis proposed openstack/keystone: Functional tests for federation protocols CRUD https://review.openstack.org/233733 | 09:26 |
ntt | marekd: next step is ssl with swift..... It seems more difficult because I have to use stud, pound or similar. Have you some advise? | 09:27 |
marekd | what's stud or pound ? | 09:27 |
ntt | https://github.com/bumptech/stud | 09:28 |
ntt | I'd like to have an ssl endpoint for swift proxy | 09:28 |
marekd | so try without proxy dfor now | 09:29 |
marekd | and make sure it works correctly with ssl | 09:29 |
marekd | i'd start with a simplified use case | 09:29 |
ntt | I'm using swift without ssl and it works well. With ssl, it seems that swift-proxy doesn't support ssl, so I have to use stud. Right? | 09:30 |
marekd | i don't know whether swift-proxy supports ssl or not | 09:31 |
marekd | i suggest asking swift guys. | 09:31 |
ntt | ok | 09:31 |
ntt | thanks | 09:31 |
marekd | yw | 09:31 |
*** spandhe has quit IRC | 09:36 | |
*** hidekazu has quit IRC | 09:42 | |
*** e0ne has joined #openstack-keystone | 09:53 | |
*** markvoelker has joined #openstack-keystone | 09:57 | |
*** browne has joined #openstack-keystone | 09:58 | |
*** jamielennox|away is now known as jamielennox | 10:01 | |
*** markvoelker has quit IRC | 10:02 | |
*** browne has quit IRC | 10:03 | |
*** heha37 has quit IRC | 10:06 | |
*** fhubik_brb is now known as fhubik | 10:06 | |
*** fawadk has quit IRC | 10:10 | |
*** yangyapeng has quit IRC | 10:14 | |
*** EinstCrazy has quit IRC | 10:20 | |
*** fhubik is now known as fhubik_brb | 10:24 | |
*** pnavarro has joined #openstack-keystone | 10:28 | |
*** GB21 has quit IRC | 10:37 | |
*** GB21 has joined #openstack-keystone | 10:38 | |
*** fhubik_brb is now known as fhubik | 10:38 | |
*** Nirupama has joined #openstack-keystone | 10:39 | |
*** henrynash has joined #openstack-keystone | 10:41 | |
*** ChanServ sets mode: +v henrynash | 10:41 | |
*** gildub has quit IRC | 10:43 | |
*** lhcheng has joined #openstack-keystone | 10:45 | |
*** ChanServ sets mode: +v lhcheng | 10:45 | |
*** EinstCrazy has joined #openstack-keystone | 10:48 | |
*** Nirupama has quit IRC | 10:49 | |
*** fhubik is now known as fhubik_brb | 10:58 | |
*** fhubik_brb is now known as fhubik | 10:58 | |
*** jerrygb has joined #openstack-keystone | 10:58 | |
*** henrynash has quit IRC | 10:59 | |
*** urulama has quit IRC | 11:00 | |
*** urulama has joined #openstack-keystone | 11:01 | |
*** fhubik is now known as fhubik_brb | 11:03 | |
*** fhubik_brb is now known as fhubik | 11:10 | |
*** tellesnobrega_af is now known as tellesnobrega | 11:11 | |
*** markvoelker has joined #openstack-keystone | 11:13 | |
samueldmq | morning all | 11:15 |
*** markvoelker has quit IRC | 11:18 | |
*** ajaya has joined #openstack-keystone | 11:18 | |
*** akanksha_ has joined #openstack-keystone | 11:30 | |
*** ajaya has quit IRC | 11:35 | |
*** josecastroleon has quit IRC | 11:36 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Constraint to prevent duplicates endpoints https://review.openstack.org/134095 | 11:43 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Change endpoint.url column type to String https://review.openstack.org/241748 | 11:43 |
*** ajaya has joined #openstack-keystone | 11:48 | |
*** GB21 has quit IRC | 11:56 | |
*** ajaya has quit IRC | 12:01 | |
*** pnavarro_ has joined #openstack-keystone | 12:08 | |
*** pnavarro has quit IRC | 12:10 | |
*** jerrygb has quit IRC | 12:10 | |
*** raildo-afk is now known as raildo | 12:15 | |
openstackgerrit | Merged openstack/keystone: Get user role without project id is not implemented https://review.openstack.org/237658 | 12:16 |
*** fhubik is now known as fhubik_brb | 12:18 | |
*** dims_ has joined #openstack-keystone | 12:22 | |
*** dims has quit IRC | 12:25 | |
*** sileht has quit IRC | 12:28 | |
*** josecastroleon has joined #openstack-keystone | 12:33 | |
*** topol has joined #openstack-keystone | 12:35 | |
*** ChanServ sets mode: +v topol | 12:35 | |
*** pgreg has joined #openstack-keystone | 12:37 | |
*** topol has quit IRC | 12:38 | |
*** sileht has joined #openstack-keystone | 12:39 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone-specs: Unified delegation spec https://review.openstack.org/189816 | 12:40 |
openstackgerrit | Alexander Makarov proposed openstack/keystone-specs: Unified delegation spec https://review.openstack.org/189816 | 12:40 |
*** fhubik_brb is now known as fhubik | 12:41 | |
*** daemontool has quit IRC | 12:49 | |
*** lhcheng has quit IRC | 12:51 | |
*** jistr has quit IRC | 12:52 | |
*** su_zhang has joined #openstack-keystone | 12:59 | |
*** woodster_ has joined #openstack-keystone | 13:02 | |
*** tobe has quit IRC | 13:03 | |
*** jamielennox is now known as jamielennox|away | 13:08 | |
*** tobe has joined #openstack-keystone | 13:10 | |
*** jistr has joined #openstack-keystone | 13:11 | |
*** jerrygb has joined #openstack-keystone | 13:11 | |
*** gb21 has joined #openstack-keystone | 13:12 | |
*** gordc has joined #openstack-keystone | 13:14 | |
*** markvoelker has joined #openstack-keystone | 13:14 | |
*** tobe has quit IRC | 13:14 | |
*** pnavarro_ has quit IRC | 13:14 | |
*** gb21 has quit IRC | 13:14 | |
*** tobe has joined #openstack-keystone | 13:14 | |
*** GB21 has joined #openstack-keystone | 13:15 | |
*** jerrygb has quit IRC | 13:16 | |
*** fhubik is now known as fhubik_brb | 13:17 | |
*** markvoelker_ has joined #openstack-keystone | 13:18 | |
*** markvoelker has quit IRC | 13:18 | |
*** tobe has quit IRC | 13:19 | |
*** GB21 has quit IRC | 13:19 | |
*** tobe has joined #openstack-keystone | 13:20 | |
*** jsavak has joined #openstack-keystone | 13:22 | |
*** tobe has quit IRC | 13:25 | |
*** sweetJeebus has joined #openstack-keystone | 13:25 | |
sweetJeebus | good morning y'all | 13:27 |
*** pnavarro_ has joined #openstack-keystone | 13:28 | |
*** topol has joined #openstack-keystone | 13:30 | |
*** ChanServ sets mode: +v topol | 13:30 | |
sweetJeebus | I was hoping someone could help point me at some info. I've been digging around for details on converting a v2 api keystone installation to v3. I'm not finding much that is current, so perhaps I'm just not looking in the right place? What I do find is some instructions on manually manipulating the db entries to s/v2/v3/ in the service lists. That sort of thing. Is this still the most current way of making the change? | 13:31 |
*** NM has quit IRC | 13:33 | |
*** edmondsw has joined #openstack-keystone | 13:34 | |
*** hrou has joined #openstack-keystone | 13:34 | |
*** topol has quit IRC | 13:40 | |
*** fhubik_brb is now known as fhubik | 13:42 | |
*** topol has joined #openstack-keystone | 13:43 | |
*** ChanServ sets mode: +v topol | 13:43 | |
*** topol has quit IRC | 13:43 | |
*** topol has joined #openstack-keystone | 13:43 | |
*** ChanServ sets mode: +v topol | 13:43 | |
*** topol has quit IRC | 13:43 | |
*** c_soukup has joined #openstack-keystone | 13:45 | |
*** sweetJeebus has quit IRC | 13:45 | |
*** ajaya has joined #openstack-keystone | 13:52 | |
*** richm has joined #openstack-keystone | 13:55 | |
samueldmq | htruta: raildo ping - about change #241748, what's wrong with making a TEXT type unique ? | 13:56 |
*** jaosorior has quit IRC | 13:57 | |
htruta | samueldmq: dave chen explains it here: https://review.openstack.org/#/c/134095/3/keystone/catalog/backends/sql.py | 13:57 |
*** jaosorior has joined #openstack-keystone | 13:58 | |
raildo | htruta: ++ | 13:58 |
*** c_soukup has quit IRC | 13:58 | |
*** daemontool has joined #openstack-keystone | 13:59 | |
*** links has quit IRC | 14:01 | |
samueldmq | htruta: raildo nice. could (service_id, region_id, interface) be enough for that constraint ? | 14:02 |
raildo | lbragstad: told for us in a previous patch that we really need add url in the constraint | 14:03 |
samueldmq | htruta: raildo: it would even be more accurate imo, because an endpoint shouldn't be able to have 2 url's for the same interface | 14:03 |
raildo | samueldmq: let me found the comment | 14:03 |
*** jerrygb has joined #openstack-keystone | 14:04 | |
samueldmq | raildo: yes, please :) | 14:04 |
raildo | samueldmq: https://review.openstack.org/#/c/134095/6/keystone/catalog/backends/sql.py | 14:05 |
htruta | samueldmq: in the bug description someone also says that the ideal constraint contains url | 14:05 |
htruta | we can have more than one url to an endpoint | 14:06 |
samueldmq | htruta: for the same interface ? | 14:06 |
*** NM has joined #openstack-keystone | 14:06 | |
* samueldmq is looking lbragstad's comment in there | 14:07 | |
*** ninag has joined #openstack-keystone | 14:08 | |
*** david-lyle has joined #openstack-keystone | 14:08 | |
htruta | samueldmq: maybe it was discussed here in irc, look at the bug page discussion too | 14:10 |
samueldmq | htruta: raildo: k will look, thanks | 14:12 |
*** gordc has quit IRC | 14:15 | |
*** daemontool has quit IRC | 14:15 | |
*** daemontool has joined #openstack-keystone | 14:16 | |
*** topol has joined #openstack-keystone | 14:17 | |
*** ChanServ sets mode: +v topol | 14:17 | |
*** topol has quit IRC | 14:23 | |
*** jaosorior has quit IRC | 14:26 | |
*** thiagop has joined #openstack-keystone | 14:26 | |
*** jaosorior has joined #openstack-keystone | 14:26 | |
*** dims has joined #openstack-keystone | 14:40 | |
*** miguelgrinberg has quit IRC | 14:41 | |
*** dims_ has quit IRC | 14:43 | |
*** ajaya has quit IRC | 14:44 | |
*** _elmiko has quit IRC | 14:44 | |
*** rha has quit IRC | 14:44 | |
*** GB21 has joined #openstack-keystone | 14:45 | |
*** _elmiko has joined #openstack-keystone | 14:45 | |
*** tjcocozz has quit IRC | 14:46 | |
*** petertr7_away is now known as petertr7 | 14:46 | |
*** ajaya has joined #openstack-keystone | 14:47 | |
*** miguelgrinberg has joined #openstack-keystone | 14:47 | |
*** tjcocozz has joined #openstack-keystone | 14:47 | |
*** iurygregory has quit IRC | 14:48 | |
*** rha has joined #openstack-keystone | 14:48 | |
*** iurygregory has joined #openstack-keystone | 14:49 | |
*** dims has quit IRC | 14:53 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs: Add even more clarity to scope docs https://review.openstack.org/229949 | 14:57 |
lbragstad | dstanek mind revisiting https://review.openstack.org/#/c/215212/ and https://review.openstack.org/#/c/215715/ when you get a chance? I think you're comments were addressed. | 15:00 |
*** tonytan4ever has joined #openstack-keystone | 15:04 | |
dstanek | lbragstad: sure | 15:05 |
*** david-lyle has quit IRC | 15:06 | |
*** btully has joined #openstack-keystone | 15:10 | |
*** pumaranikar has joined #openstack-keystone | 15:12 | |
*** GB21 has quit IRC | 15:15 | |
lbragstad | dstanek thanks! | 15:16 |
lbragstad | bknudson should we not worry about backporting this to kilo? https://review.openstack.org/#/c/236083/ | 15:19 |
lbragstad | bknudson do you think we need to? | 15:19 |
bknudson | lbragstad: if there's nothing that depends on it then there's no reason to backport it. | 15:19 |
lbragstad | bknudson makes sense, it's just a rename anyway | 15:20 |
bknudson | I thought it was proposed as a backport because it made a fix easier to backport? | 15:20 |
lbragstad | bknudson I'm double checking that now | 15:21 |
lbragstad | bknudson working through that chain | 15:21 |
lbragstad | bknudson what other review were you referencing in your comment here - https://review.openstack.org/#/c/221799/ ? | 15:23 |
bknudson | must have been related to "backport proposed - https://review.openstack.org/#/c/236071/" | 15:24 |
*** doug-fish has joined #openstack-keystone | 15:24 | |
*** markvoelker has joined #openstack-keystone | 15:30 | |
*** markvoelker_ has quit IRC | 15:31 | |
*** NM has quit IRC | 15:31 | |
*** NM has joined #openstack-keystone | 15:34 | |
*** phalmos has joined #openstack-keystone | 15:35 | |
*** markvoelker_ has joined #openstack-keystone | 15:35 | |
lbragstad | bknudson done - https://review.openstack.org/#/c/221799/2 | 15:35 |
openstackgerrit | Tom Cocozzello proposed openstack/keystonemiddleware: Define entry points for filter factories for Paste Deployment https://review.openstack.org/233839 | 15:36 |
*** GB21 has joined #openstack-keystone | 15:36 | |
bknudson | lbragstad: still lots of conflicts | 15:36 |
bknudson | why so many conflicts? | 15:36 |
bknudson | are we adding tons of new features to fernet tokens? | 15:37 |
*** markvoelker has quit IRC | 15:37 | |
*** c_soukup has joined #openstack-keystone | 15:44 | |
*** fhubik has quit IRC | 15:45 | |
*** urulama has quit IRC | 15:46 | |
*** urulama has joined #openstack-keystone | 15:46 | |
*** GB21 has quit IRC | 15:47 | |
*** ayoung_ has joined #openstack-keystone | 15:49 | |
dhellmann | bknudson : do we still need to block these keystone libs in liberty? https://review.openstack.org/#/c/235923/ | 15:50 |
*** c_soukup has quit IRC | 15:51 | |
bknudson | dhellmann: those releases still contain bad requirements, and we don't want packagers to use them so I think they should be blocked. | 15:52 |
*** jistr is now known as jistr|afkmtg | 15:53 | |
*** GB21 has joined #openstack-keystone | 15:55 | |
*** chrisshattuck has joined #openstack-keystone | 15:55 | |
*** pumaranikar has quit IRC | 15:55 | |
*** pumaranikar has joined #openstack-keystone | 15:55 | |
*** topol has joined #openstack-keystone | 16:02 | |
*** ChanServ sets mode: +v topol | 16:02 | |
*** pumaranikar has quit IRC | 16:04 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Deprecate the pki and pkiz token providers. https://review.openstack.org/241389 | 16:06 |
*** pumaranikar has joined #openstack-keystone | 16:08 | |
lbragstad | bknudson no, i don't think we did, i think it was just a big sequence of fixes? | 16:10 |
*** ayoung_ has quit IRC | 16:11 | |
bknudson | lbragstad: then there shouldn't be conflicts when backporting | 16:11 |
*** chrisshattuck has quit IRC | 16:11 | |
*** jerrygb has quit IRC | 16:13 | |
*** jerrygb has joined #openstack-keystone | 16:15 | |
*** browne has joined #openstack-keystone | 16:19 | |
*** urulama has quit IRC | 16:22 | |
*** urulama has joined #openstack-keystone | 16:23 | |
lbragstad | dolphm ayoung for the conversion from mysql `datetime` to `int`, we determined that we wouldn't need a spec, right? | 16:24 |
ayoung | lbragstad, I never think we need a spec | 16:24 |
ayoung | specs are dumb | 16:24 |
dolphm | lbragstad: i don't think so - don't we already have an open bug? | 16:25 |
ayoung | lbragstad, so...it does not change the API. Right? | 16:25 |
ayoung | We are going to change the DB column and the mechanism for comparison. | 16:25 |
ayoung | embedding the sub-second section in the token body should be a non-user-visible change | 16:26 |
ayoung | I think we are OK without a spec, and just used the bug report. | 16:26 |
lbragstad | ayoung the api responses will come back with sub-second precision, but that will happen when we have the change to fernet land | 16:26 |
*** c_soukup has joined #openstack-keystone | 16:26 | |
ayoung | that is still inside the token spec, though, as the UUID and PKI tokens do that now, right? | 16:26 |
lbragstad | right | 16:29 |
dolphm | lbragstad: pretty sure the v3 doc mandates subsecond precision everywhere, unless you document an exception. does the revoke API document it otherwise? | 16:29 |
lbragstad | dolphm yep, you're right. | 16:29 |
lbragstad | dolphm i meant the return of sub-second precision that isn't .000000Z | 16:30 |
lbragstad | so, no | 16:30 |
lbragstad | no api changes | 16:30 |
dolphm | lbragstad: ++ agree | 16:30 |
lbragstad | this is the only bug that I could find related to it - https://bugs.launchpad.net/keystone/+bug/1459790 | 16:30 |
openstack | Launchpad bug 1459790 in OpenStack Identity (keystone) kilo "With fernet tokens, validate token loses the ms on 'expires' value " [Medium,Fix released] - Assigned to Dolph Mathews (dolph) | 16:30 |
lbragstad | and that is closed | 16:30 |
lbragstad | or 'Fix Released' | 16:31 |
*** jerrygb has quit IRC | 16:31 | |
*** jerrygb has joined #openstack-keystone | 16:31 | |
lbragstad | so, should we open a new bug that is specific to supporting accurate sub-second precision in fernet's creation timestamp? | 16:31 |
dolphm | lbragstad: that's with regard to a different timestamp though | 16:31 |
lbragstad | correct | 16:31 |
lbragstad | i think we should open a new bug | 16:31 |
dolphm | lbragstad: but you're not concerned about the creation timestamp, right? you're concerned about the revocation event timestamp | 16:32 |
lbragstad | yes | 16:32 |
lbragstad | well.. yes, having subsecond support in sql will get us part of the way there. | 16:32 |
lbragstad | the other half would be getting sub-second accuracy in fernet's creation timestamp | 16:33 |
lbragstad | so, a new bug specific to getting sub-second accuracy in sql | 16:33 |
lbragstad | and a bug specific to getting sub-second accuracy in fernet's creation timestamp | 16:33 |
dolphm | lbragstad: agree. i was handling that bit as part of the "tempest is failing" bug, but more specific bugs would make sense at this point i think | 16:33 |
lbragstad | dolphm makes sense, i'll create both of those then | 16:34 |
dolphm | lbragstad: this might be a migration worth backporting, too | 16:34 |
dolphm | lbragstad: which i think would be a first for us | 16:34 |
lbragstad | dolphm the 'tempest is failing' bug should be closed out (temporarily) by https://review.openstack.org/#/c/231191/ | 16:35 |
dolphm | lbragstad: ooh, right | 16:35 |
dolphm | lbragstad: then yes, we definitely need new bugs to work against | 16:35 |
lbragstad | dolphm yep, i have odyssey4me on the schedule for the next keystone meeting to get operator feedback | 16:35 |
dolphm | because we have at least 2 more related changes to keystone | 16:35 |
dolphm | lbragstad: on? | 16:35 |
lbragstad | dolphm the migration from datetime to int | 16:36 |
lbragstad | we were talking about it a bit at the summit and he was interested | 16:36 |
*** chrisshattuck has joined #openstack-keystone | 16:36 | |
dolphm | marekd: when are we going to support defederation? i just like the word and i think we should support that word | 16:36 |
dolphm | lbragstad: cool | 16:37 |
*** phalmos has quit IRC | 16:46 | |
lbragstad | dolphm sub-second accuracy support for sql - https://bugs.launchpad.net/keystone/+bug/1513538 | 16:46 |
openstack | Launchpad bug 1513538 in OpenStack Identity (keystone) "Remove SQL's datetime format inplace of integer timestamps" [Undecided,New] | 16:46 |
lbragstad | sub-second accuracy support for fernet's creation timestamp - https://bugs.launchpad.net/keystone/+bug/1513541 | 16:46 |
openstack | Launchpad bug 1513541 in OpenStack Identity (keystone) "Support sub-second accuracy in Fernet's creation timestamp" [Undecided,New] | 16:46 |
*** phalmos has joined #openstack-keystone | 16:47 | |
openstackgerrit | Darren Shaw proposed openstack/keystone: Correct description in Keystone key_terms https://review.openstack.org/242155 | 16:48 |
dolphm | lbragstad: amended description with a citation | 16:49 |
*** arunkant_ has joined #openstack-keystone | 16:49 | |
*** wanghua_ has joined #openstack-keystone | 16:50 | |
lbragstad | dolphm thanks | 16:50 |
*** jgriffith has joined #openstack-keystone | 16:51 | |
*** jgriffith is now known as Guest88047 | 16:51 | |
*** odyssey4me_ has joined #openstack-keystone | 16:51 | |
*** toddnni_ has joined #openstack-keystone | 16:51 | |
*** haneef_ has joined #openstack-keystone | 16:51 | |
*** alex_xu_ has joined #openstack-keystone | 16:51 | |
*** su_zhang has quit IRC | 16:52 | |
*** _hrou_ has joined #openstack-keystone | 16:52 | |
*** thiagop_ has joined #openstack-keystone | 16:52 | |
*** wanghua has quit IRC | 16:52 | |
*** jaosorior_ has joined #openstack-keystone | 16:52 | |
*** Daviey_ has joined #openstack-keystone | 16:54 | |
*** gb21_ has joined #openstack-keystone | 16:54 | |
*** hrou has quit IRC | 16:54 | |
*** ktychkova_ has joined #openstack-keystone | 16:56 | |
*** jsavak has quit IRC | 16:58 | |
*** e0ne has quit IRC | 16:58 | |
*** Alexander has joined #openstack-keystone | 16:59 | |
*** jbell8 has joined #openstack-keystone | 16:59 | |
*** Alexander is now known as Guest9218 | 17:00 | |
*** esp_ has joined #openstack-keystone | 17:00 | |
*** dhellmann_ has joined #openstack-keystone | 17:00 | |
*** tsufiev_ has joined #openstack-keystone | 17:00 | |
*** tsufiev has quit IRC | 17:00 | |
*** arif-ali_ has joined #openstack-keystone | 17:00 | |
*** cburgess_ has joined #openstack-keystone | 17:00 | |
*** chrissha_ has joined #openstack-keystone | 17:01 | |
*** chrissha_ has quit IRC | 17:01 | |
*** Guest9218 has quit IRC | 17:01 | |
*** sirushti_ has joined #openstack-keystone | 17:01 | |
*** chrissha_ has joined #openstack-keystone | 17:02 | |
*** lsmola has quit IRC | 17:02 | |
*** pushkaru has joined #openstack-keystone | 17:02 | |
*** pumaranikar has quit IRC | 17:02 | |
*** jsavak has joined #openstack-keystone | 17:03 | |
*** chrisshattuck has quit IRC | 17:04 | |
*** GB21 has quit IRC | 17:04 | |
*** jaosorior has quit IRC | 17:04 | |
*** thiagop has quit IRC | 17:04 | |
*** ericksonsantos has quit IRC | 17:04 | |
*** alex_xu has quit IRC | 17:04 | |
*** Guest90242 has quit IRC | 17:04 | |
*** ktychkova has quit IRC | 17:04 | |
*** haneef has quit IRC | 17:04 | |
*** dhellmann has quit IRC | 17:04 | |
*** amakarov has quit IRC | 17:04 | |
*** arif-ali has quit IRC | 17:04 | |
*** andrewbogott has quit IRC | 17:04 | |
*** toddnni has quit IRC | 17:04 | |
*** odyssey4me has quit IRC | 17:04 | |
*** cburgess has quit IRC | 17:04 | |
*** svasheka has quit IRC | 17:04 | |
*** Daviey has quit IRC | 17:04 | |
*** esp has quit IRC | 17:04 | |
*** sirushti has quit IRC | 17:04 | |
*** sirushti_ is now known as sirushti | 17:04 | |
*** arif-ali_ is now known as arif-ali | 17:04 | |
*** toddnni_ is now known as toddnni | 17:04 | |
*** svasheka has joined #openstack-keystone | 17:05 | |
*** dhellmann_ is now known as dhellmann | 17:05 | |
*** mylu has joined #openstack-keystone | 17:05 | |
*** ericksonsantos has joined #openstack-keystone | 17:05 | |
*** agireud has quit IRC | 17:05 | |
*** amakarov has joined #openstack-keystone | 17:05 | |
*** agireud has joined #openstack-keystone | 17:07 | |
*** mylu has quit IRC | 17:11 | |
*** josecastroleon has quit IRC | 17:13 | |
*** andrewbogott has joined #openstack-keystone | 17:13 | |
*** jistr|afkmtg is now known as jistr | 17:14 | |
*** andrewbogott has quit IRC | 17:14 | |
*** andrewbogott has joined #openstack-keystone | 17:14 | |
*** arunkant_ has quit IRC | 17:16 | |
*** arunkant_ has joined #openstack-keystone | 17:19 | |
*** mylu has joined #openstack-keystone | 17:32 | |
*** e0ne has joined #openstack-keystone | 17:41 | |
ayoung | So...I was looking in to supporting Basic_Auth as a Federation mechanism. Apache mod_authn_dbd is not there, yet, as it only supports sha1, not sha512. And that would still not give us the group list. Does it make sense to create a custom middleware/filter that could go in front of OS-FEDERATION that could handle basic-auth? And, if so, how do we make sure it does not get triggered by the non-Basic_auth paths in ap | 17:42 |
ayoung | ache (short of making sure apache has valid_user-required) | 17:42 |
openstackgerrit | Tom Cocozzello proposed openstack/keystonemiddleware: Define entry points for filter factories for Paste Deployment https://review.openstack.org/233839 | 17:46 |
*** e0ne has quit IRC | 17:51 | |
*** jbell8 has quit IRC | 17:53 | |
*** thiagop_ is now known as thiagop | 17:53 | |
*** jbell8 has joined #openstack-keystone | 17:54 | |
*** e0ne has joined #openstack-keystone | 17:54 | |
*** kfox1111_ is now known as kfox1111 | 17:55 | |
*** mylu has quit IRC | 17:56 | |
*** mylu has joined #openstack-keystone | 17:56 | |
*** e0ne has quit IRC | 17:56 | |
*** jbell8 has quit IRC | 17:58 | |
*** mylu has quit IRC | 17:59 | |
*** mylu has joined #openstack-keystone | 17:59 | |
*** chrissha_ has quit IRC | 18:00 | |
*** chrisshattuck has joined #openstack-keystone | 18:00 | |
*** jistr has quit IRC | 18:00 | |
*** spandhe has joined #openstack-keystone | 18:02 | |
*** chrisshattuck has quit IRC | 18:02 | |
*** pnavarro_ has quit IRC | 18:03 | |
*** jsavak has quit IRC | 18:03 | |
*** jsavak has joined #openstack-keystone | 18:04 | |
*** e0ne has joined #openstack-keystone | 18:04 | |
*** browne has quit IRC | 18:05 | |
*** pgreg has quit IRC | 18:05 | |
openstackgerrit | Merged openstack/keystone-specs: Add even more clarity to scope docs https://review.openstack.org/229949 | 18:06 |
*** mylu has quit IRC | 18:06 | |
*** mylu has joined #openstack-keystone | 18:07 | |
*** mylu has quit IRC | 18:07 | |
*** e0ne has quit IRC | 18:08 | |
*** mylu has joined #openstack-keystone | 18:08 | |
*** daemontool has quit IRC | 18:09 | |
*** mylu has quit IRC | 18:11 | |
*** mylu has joined #openstack-keystone | 18:11 | |
*** gordc has joined #openstack-keystone | 18:13 | |
*** roxanaghe has joined #openstack-keystone | 18:15 | |
*** henrynash has joined #openstack-keystone | 18:16 | |
*** ChanServ sets mode: +v henrynash | 18:16 | |
*** su_zhang has joined #openstack-keystone | 18:20 | |
*** tonytan4ever has quit IRC | 18:23 | |
openstackgerrit | Raildo Mascena de Sousa Filho proposed openstack/keystone: Translation-friendly formatting of msg string https://review.openstack.org/240316 | 18:24 |
*** jbell8 has joined #openstack-keystone | 18:25 | |
*** jsavak has quit IRC | 18:29 | |
*** mylu has quit IRC | 18:31 | |
*** mylu has joined #openstack-keystone | 18:32 | |
*** henrynash has quit IRC | 18:34 | |
*** mylu has quit IRC | 18:36 | |
*** jsavak has joined #openstack-keystone | 18:37 | |
*** petertr7 is now known as petertr7_away | 18:37 | |
*** jasonsb has quit IRC | 18:38 | |
*** doug-fis_ has joined #openstack-keystone | 18:42 | |
*** doug-fish has quit IRC | 18:45 | |
*** rdo has quit IRC | 18:45 | |
*** rdo has joined #openstack-keystone | 18:46 | |
*** tonytan4ever has joined #openstack-keystone | 18:47 | |
*** mylu has joined #openstack-keystone | 18:50 | |
*** browne has joined #openstack-keystone | 18:50 | |
*** mylu has quit IRC | 18:54 | |
*** jbell8 has quit IRC | 18:54 | |
*** jbell8_ has joined #openstack-keystone | 18:54 | |
*** shaleh has joined #openstack-keystone | 18:55 | |
*** jerrygb has quit IRC | 18:57 | |
*** jerrygb has joined #openstack-keystone | 18:58 | |
*** akanksha_ has quit IRC | 18:58 | |
*** ninag has quit IRC | 19:01 | |
*** ninag has joined #openstack-keystone | 19:01 | |
*** jerrygb has quit IRC | 19:03 | |
*** ninag_ has joined #openstack-keystone | 19:03 | |
*** ankita_wagh has joined #openstack-keystone | 19:03 | |
*** ninag has quit IRC | 19:05 | |
*** ninag has joined #openstack-keystone | 19:06 | |
*** ninag_ has quit IRC | 19:07 | |
*** _hrou_ is now known as hrou | 19:19 | |
*** jasonsb has joined #openstack-keystone | 19:24 | |
*** shaleh is now known as shaleh_afk | 19:26 | |
*** fawadkhaliq has joined #openstack-keystone | 19:27 | |
*** ankita_wagh has quit IRC | 19:30 | |
*** ankita_wagh has joined #openstack-keystone | 19:30 | |
*** petertr7_away is now known as petertr7 | 19:34 | |
*** ninag has quit IRC | 19:40 | |
*** ninag has joined #openstack-keystone | 19:40 | |
*** ninag has quit IRC | 19:41 | |
*** ninag has joined #openstack-keystone | 19:41 | |
*** ninag has quit IRC | 19:43 | |
*** ninag has joined #openstack-keystone | 19:44 | |
*** ninag has quit IRC | 19:45 | |
*** ninag has joined #openstack-keystone | 19:46 | |
*** c_soukup has quit IRC | 19:49 | |
*** jerrygb has joined #openstack-keystone | 19:53 | |
*** jsavak has quit IRC | 19:58 | |
*** jsavak has joined #openstack-keystone | 19:58 | |
*** jaosorior_ has quit IRC | 19:58 | |
*** jaosorior has joined #openstack-keystone | 20:00 | |
*** ninag has quit IRC | 20:01 | |
*** ninag has joined #openstack-keystone | 20:02 | |
*** alejandrito has joined #openstack-keystone | 20:02 | |
*** phalmos has quit IRC | 20:04 | |
*** jaosorior has quit IRC | 20:04 | |
*** doug-fis_ is now known as doug-fish | 20:05 | |
*** ninag has quit IRC | 20:06 | |
*** fawadkhaliq has quit IRC | 20:10 | |
*** ninag has joined #openstack-keystone | 20:13 | |
*** ninag has quit IRC | 20:18 | |
*** ninag has joined #openstack-keystone | 20:18 | |
*** dave-mccowan has joined #openstack-keystone | 20:19 | |
*** ninag has quit IRC | 20:20 | |
*** ninag has joined #openstack-keystone | 20:20 | |
*** daemontool has joined #openstack-keystone | 20:22 | |
*** MHeder has joined #openstack-keystone | 20:23 | |
*** ankita_wagh has quit IRC | 20:24 | |
*** ninag has quit IRC | 20:28 | |
*** ninag has joined #openstack-keystone | 20:29 | |
*** ninag has quit IRC | 20:33 | |
*** ninag has joined #openstack-keystone | 20:35 | |
*** ninag_ has joined #openstack-keystone | 20:36 | |
MHeder | FYI: we have done some work on user/project provisioning for SAML+Keystone scenarios. Here is the white paper: http://arxiv.org/abs/1510.04017 | 20:36 |
MHeder | Any comments are welcome | 20:36 |
*** ninag has quit IRC | 20:39 | |
*** flwang has joined #openstack-keystone | 20:39 | |
*** ninag_ has quit IRC | 20:40 | |
samueldmq | MHeder: nice, cc marekd ^ | 20:41 |
*** phalmos has joined #openstack-keystone | 20:42 | |
*** spandhe has quit IRC | 20:45 | |
*** ankita_wagh has joined #openstack-keystone | 20:49 | |
*** phalmos has quit IRC | 20:50 | |
*** phalmos has joined #openstack-keystone | 20:50 | |
*** ajaya has quit IRC | 20:57 | |
*** mylu has joined #openstack-keystone | 20:57 | |
*** mylu has quit IRC | 21:02 | |
*** MHeder has quit IRC | 21:08 | |
*** henrynash has joined #openstack-keystone | 21:08 | |
*** ChanServ sets mode: +v henrynash | 21:08 | |
*** mylu has joined #openstack-keystone | 21:09 | |
*** NM has quit IRC | 21:09 | |
*** mylu has quit IRC | 21:09 | |
*** mylu has joined #openstack-keystone | 21:09 | |
*** mylu has quit IRC | 21:15 | |
*** mylu has joined #openstack-keystone | 21:16 | |
*** flwang has quit IRC | 21:24 | |
*** flwang has joined #openstack-keystone | 21:24 | |
*** jbell8 has joined #openstack-keystone | 21:27 | |
*** jbell8_ has quit IRC | 21:27 | |
*** NM has joined #openstack-keystone | 21:27 | |
*** phalmos has quit IRC | 21:30 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: Limit the number of roles a user can be assigned within a project https://review.openstack.org/239948 | 21:31 |
*** ninag has joined #openstack-keystone | 21:38 | |
*** NM has quit IRC | 21:40 | |
*** thiagop has quit IRC | 21:40 | |
*** NM has joined #openstack-keystone | 21:42 | |
*** mylu has quit IRC | 21:43 | |
*** mylu has joined #openstack-keystone | 21:43 | |
*** mylu_ has joined #openstack-keystone | 21:46 | |
*** pnavarro_ has joined #openstack-keystone | 21:47 | |
*** mylu has quit IRC | 21:48 | |
*** AJaeger has joined #openstack-keystone | 21:49 | |
AJaeger | keystone cores, could you import translations again? Both for stable and liberty, please? These contain metadata changes -removal of an obsolete URL: https://review.openstack.org/238789 and https://review.openstack.org/238790 | 21:49 |
*** su_zhang has quit IRC | 21:50 | |
*** su_zhang has joined #openstack-keystone | 21:51 | |
*** edmondsw has quit IRC | 21:52 | |
*** pnavarro_ has quit IRC | 21:55 | |
openstackgerrit | ayoung proposed openstack/keystone-specs: is_admin_project https://review.openstack.org/242232 | 21:57 |
*** jsavak has quit IRC | 22:00 | |
*** phalmos has joined #openstack-keystone | 22:02 | |
*** AJaeger has quit IRC | 22:07 | |
*** topol has quit IRC | 22:07 | |
*** petertr7 is now known as petertr7_away | 22:07 | |
*** ayoung has quit IRC | 22:08 | |
*** mhu has quit IRC | 22:08 | |
*** lhcheng has joined #openstack-keystone | 22:13 | |
*** ChanServ sets mode: +v lhcheng | 22:13 | |
*** mhu has joined #openstack-keystone | 22:14 | |
*** mylu_ has quit IRC | 22:14 | |
*** su_zhang has quit IRC | 22:16 | |
*** su_zhang has joined #openstack-keystone | 22:16 | |
*** petertr7_away is now known as petertr7 | 22:17 | |
openstackgerrit | Merged openstack/keystone: Correct description in Keystone key_terms https://review.openstack.org/242155 | 22:17 |
*** mylu has joined #openstack-keystone | 22:20 | |
*** daemontool has quit IRC | 22:21 | |
*** urulama has quit IRC | 22:23 | |
*** urulama has joined #openstack-keystone | 22:23 | |
*** jbell8 has quit IRC | 22:27 | |
*** gyee has joined #openstack-keystone | 22:32 | |
*** ChanServ sets mode: +v gyee | 22:32 | |
*** shaleh_afk is now known as shaleh | 22:32 | |
shaleh | while gerrit is nice for hosting the review. the interface is not pleasant for discussing the review | 22:33 |
*** mylu has quit IRC | 22:34 | |
*** mylu has joined #openstack-keystone | 22:34 | |
*** mylu has quit IRC | 22:39 | |
openstackgerrit | Merged openstack/keystone: Add caching to get_catalog https://review.openstack.org/215212 | 22:39 |
*** mylu has joined #openstack-keystone | 22:39 | |
*** petertr7 is now known as petertr7_away | 22:40 | |
*** mylu has quit IRC | 22:40 | |
*** mylu has joined #openstack-keystone | 22:41 | |
*** alejandrito has quit IRC | 22:41 | |
*** jbell8 has joined #openstack-keystone | 22:41 | |
*** jsavak has joined #openstack-keystone | 22:41 | |
*** su_zhang has quit IRC | 22:42 | |
*** mylu has quit IRC | 22:42 | |
*** mylu has joined #openstack-keystone | 22:42 | |
*** su_zhang has joined #openstack-keystone | 22:42 | |
*** simondodsley has quit IRC | 22:44 | |
*** simondodsley has joined #openstack-keystone | 22:45 | |
*** tsymanczyk has quit IRC | 22:45 | |
*** phalmos has quit IRC | 22:48 | |
*** mylu has quit IRC | 22:50 | |
*** tsymanczyk has joined #openstack-keystone | 22:50 | |
*** dgonzalez has quit IRC | 22:51 | |
*** tsymanczyk is now known as Guest24995 | 22:51 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add caching to role assignments https://review.openstack.org/215715 | 22:52 |
*** mylu has joined #openstack-keystone | 22:57 | |
*** su_zhang has quit IRC | 22:57 | |
*** gyee has quit IRC | 22:57 | |
*** urulama has quit IRC | 22:57 | |
*** su_zhang has joined #openstack-keystone | 22:58 | |
*** urulama has joined #openstack-keystone | 22:58 | |
*** jamielennox|away is now known as jamielennox | 22:59 | |
*** jsavak has quit IRC | 23:01 | |
*** mylu has quit IRC | 23:02 | |
samueldmq | lbragstad: one more review there :-) | 23:03 |
*** mylu has joined #openstack-keystone | 23:04 | |
*** dgonzalez has joined #openstack-keystone | 23:04 | |
*** dgonzalez has quit IRC | 23:06 | |
*** dgonzalez has joined #openstack-keystone | 23:07 | |
*** jerrygb has quit IRC | 23:08 | |
*** rmstar has quit IRC | 23:08 | |
*** rmstar has joined #openstack-keystone | 23:08 | |
*** pushkaru has quit IRC | 23:12 | |
*** dgonzalez has quit IRC | 23:12 | |
samueldmq | when is keystone midcycle going to happen ? | 23:12 |
samueldmq | do we have any plans already ? | 23:12 |
*** dgonzalez has joined #openstack-keystone | 23:12 | |
*** gildub has joined #openstack-keystone | 23:16 | |
*** gyee has joined #openstack-keystone | 23:19 | |
*** ChanServ sets mode: +v gyee | 23:19 | |
*** sseago has quit IRC | 23:21 | |
shaleh | re midcycle, April in Austin TX right? | 23:22 |
*** sseago has joined #openstack-keystone | 23:22 | |
*** hrou has quit IRC | 23:25 | |
*** jbell8 has quit IRC | 23:30 | |
*** jerrygb has joined #openstack-keystone | 23:33 | |
*** jbell8 has joined #openstack-keystone | 23:34 | |
*** Guest24995 has quit IRC | 23:36 | |
lhcheng | shaleh: that's the summit :) | 23:36 |
shaleh | lhcheng: ah right | 23:37 |
*** sseago has quit IRC | 23:37 | |
lhcheng | midcycle if its happen, would probably around jan or early feb | 23:37 |
lhcheng | doesn't seem like we have a lot new features going on this cycle (mostly stabilization), not sure if we need a midcycle this time. | 23:39 |
*** jbell8 has quit IRC | 23:40 | |
*** mylu has quit IRC | 23:44 | |
*** mylu has joined #openstack-keystone | 23:44 | |
shaleh | lhcheng: agreed | 23:46 |
*** daemontool has joined #openstack-keystone | 23:46 | |
*** ninag has quit IRC | 23:49 | |
*** mylu has quit IRC | 23:49 | |
*** jerrygb_ has joined #openstack-keystone | 23:49 | |
*** jerrygb has quit IRC | 23:50 | |
openstackgerrit | Sean Perry proposed openstack/keystone: Use unit.new_endpoint_ref consistently https://review.openstack.org/237758 | 23:51 |
*** tonytan4ever has quit IRC | 23:52 | |
*** gordc has quit IRC | 23:56 | |
*** jasonsb_ has joined #openstack-keystone | 23:57 | |
*** mylu has joined #openstack-keystone | 23:57 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!