*** itlinux has quit IRC | 00:01 | |
*** superdan is now known as dansmith | 00:08 | |
*** mylu has joined #openstack-keystone | 00:12 | |
*** sdake has quit IRC | 00:24 | |
*** itlinux has joined #openstack-keystone | 00:25 | |
*** itlinux has quit IRC | 00:28 | |
*** spzala has joined #openstack-keystone | 00:28 | |
*** sdake has joined #openstack-keystone | 00:29 | |
*** mylu has quit IRC | 00:34 | |
*** roxanaghe has quit IRC | 00:39 | |
*** mylu has joined #openstack-keystone | 00:46 | |
*** EinstCrazy has joined #openstack-keystone | 01:19 | |
*** jbell8 has quit IRC | 01:22 | |
*** mylu has quit IRC | 01:25 | |
*** mylu has joined #openstack-keystone | 01:27 | |
*** itlinux has joined #openstack-keystone | 01:27 | |
*** spzala has quit IRC | 01:29 | |
*** itlinux has quit IRC | 01:36 | |
*** sdake has quit IRC | 01:36 | |
*** itlinux has joined #openstack-keystone | 01:37 | |
*** itlinux has quit IRC | 01:40 | |
*** EinstCra_ has joined #openstack-keystone | 01:48 | |
*** EinstCrazy has quit IRC | 01:50 | |
*** EinstCrazy has joined #openstack-keystone | 02:00 | |
*** EinstCra_ has quit IRC | 02:03 | |
*** furface has quit IRC | 02:06 | |
*** itlinux has joined #openstack-keystone | 02:12 | |
*** itlinux has quit IRC | 02:13 | |
*** itlinux has joined #openstack-keystone | 02:17 | |
*** itlinux has quit IRC | 02:21 | |
*** spzala has joined #openstack-keystone | 02:29 | |
*** itlinux has joined #openstack-keystone | 02:29 | |
*** itlinux has quit IRC | 02:31 | |
*** spzala has quit IRC | 02:35 | |
*** furface has joined #openstack-keystone | 02:43 | |
*** dan_nguyen has joined #openstack-keystone | 02:44 | |
*** itlinux has joined #openstack-keystone | 03:17 | |
*** mylu has quit IRC | 03:26 | |
*** dave-mccowan has quit IRC | 03:27 | |
*** jbell8 has joined #openstack-keystone | 03:28 | |
*** spzala has joined #openstack-keystone | 03:31 | |
*** itlinux has quit IRC | 03:34 | |
*** spzala has quit IRC | 03:37 | |
*** mylu has joined #openstack-keystone | 03:45 | |
*** jbell8 has quit IRC | 03:45 | |
*** furface has quit IRC | 04:01 | |
*** links has joined #openstack-keystone | 04:03 | |
*** roxanaghe has joined #openstack-keystone | 04:25 | |
*** spzala has joined #openstack-keystone | 04:33 | |
*** roxanaghe has quit IRC | 04:38 | |
*** spzala has quit IRC | 04:38 | |
*** dan_nguyen has quit IRC | 04:47 | |
*** dan_nguyen has joined #openstack-keystone | 04:47 | |
*** roxanaghe has joined #openstack-keystone | 04:51 | |
*** mylu has quit IRC | 04:53 | |
*** real56 has joined #openstack-keystone | 04:53 | |
*** dan_nguyen has quit IRC | 04:57 | |
*** EinstCra_ has joined #openstack-keystone | 04:57 | |
*** EinstCrazy has quit IRC | 04:59 | |
*** furface has joined #openstack-keystone | 05:04 | |
*** real56 has quit IRC | 05:05 | |
*** _fortis has joined #openstack-keystone | 05:17 | |
*** sdake has joined #openstack-keystone | 05:29 | |
*** spzala has joined #openstack-keystone | 05:34 | |
*** sdake has quit IRC | 05:38 | |
*** spzala has quit IRC | 05:38 | |
*** roxanaghe has quit IRC | 05:39 | |
*** roxanaghe has joined #openstack-keystone | 05:41 | |
*** sdake has joined #openstack-keystone | 05:41 | |
*** roxanaghe has quit IRC | 05:45 | |
*** GB21 has joined #openstack-keystone | 05:51 | |
*** LZ has joined #openstack-keystone | 05:52 | |
*** sdake has quit IRC | 05:55 | |
*** pcaruana has quit IRC | 06:02 | |
*** jaosorior has joined #openstack-keystone | 06:06 | |
*** jaosorior has quit IRC | 06:07 | |
*** jaosorior has joined #openstack-keystone | 06:08 | |
*** mvk_ has joined #openstack-keystone | 06:09 | |
*** mvk has quit IRC | 06:12 | |
*** openstackgerrit has quit IRC | 06:17 | |
*** openstackgerrit_ is now known as openstackgerrit | 06:17 | |
*** openstackgerrit_ has joined #openstack-keystone | 06:18 | |
*** openstackgerrit_ is now known as openstackgerrit | 06:18 | |
*** openstackgerrit_ has joined #openstack-keystone | 06:19 | |
*** rcernin has joined #openstack-keystone | 06:20 | |
*** spzala has joined #openstack-keystone | 06:34 | |
*** spzala has quit IRC | 06:39 | |
*** roxanaghe has joined #openstack-keystone | 06:42 | |
*** roxanaghe has quit IRC | 06:47 | |
*** spzala has joined #openstack-keystone | 07:35 | |
*** jbell8 has joined #openstack-keystone | 07:38 | |
*** jbell8 has quit IRC | 07:39 | |
*** spzala has quit IRC | 07:40 | |
*** Nirupama has joined #openstack-keystone | 07:42 | |
*** GB21 has quit IRC | 07:45 | |
*** daemontool has joined #openstack-keystone | 07:50 | |
*** tesseract has joined #openstack-keystone | 07:50 | |
*** tesseract is now known as Guest9441 | 07:51 | |
*** GB21 has joined #openstack-keystone | 08:25 | |
*** roxanaghe has joined #openstack-keystone | 08:30 | |
*** roxanaghe has quit IRC | 08:34 | |
*** spzala has joined #openstack-keystone | 08:36 | |
*** permalac has joined #openstack-keystone | 08:40 | |
*** spzala has quit IRC | 08:41 | |
*** daemontool has quit IRC | 08:55 | |
*** bjornar has joined #openstack-keystone | 08:56 | |
*** sheel has joined #openstack-keystone | 08:59 | |
*** LZ has quit IRC | 09:01 | |
*** henrynash has quit IRC | 09:02 | |
*** daemontool has joined #openstack-keystone | 09:04 | |
*** permalac has quit IRC | 09:05 | |
*** permalac has joined #openstack-keystone | 09:05 | |
*** LZ has joined #openstack-keystone | 09:12 | |
*** naresht has joined #openstack-keystone | 09:12 | |
*** mvk_ has quit IRC | 09:19 | |
naresht | Identity API version 2 will support federation ? | 09:20 |
---|---|---|
naresht | I am new to Openstack | 09:20 |
*** gsilvis has quit IRC | 09:23 | |
*** gsilvis has joined #openstack-keystone | 09:23 | |
marekd | naresht: hi, no, it won't | 09:26 |
marekd | in general Identity API v2 is slowly going to be removed so I'd consider switching to V3 | 09:26 |
*** henrynash has joined #openstack-keystone | 09:26 | |
*** ChanServ sets mode: +v henrynash | 09:26 | |
*** permalac has quit IRC | 09:26 | |
naresht | Thank you +marekd | 09:28 |
naresht | How to update to V3 from V2 | 09:29 |
marekd | naresht: well, you probably have V3 already enabled (depending on version of OpenStack you have). | 09:29 |
marekd | naresht: now, just make your clients start speaing v3 | 09:29 |
*** rk4n has joined #openstack-keystone | 09:32 | |
*** spzala has joined #openstack-keystone | 09:37 | |
*** spzala has quit IRC | 09:41 | |
naresht | I'm trying Keysonte as an IdP. following this link http://blog.rodrigods.com/it-is-time-to-play-with-keystone-to-keystone-federation-in-kilo/. We are getting below errors http://paste.openstack.org/show/491230/. How can I generate certs ?. Could you please help me ? | 09:45 |
*** mvk_ has joined #openstack-keystone | 09:51 | |
*** chaitu has joined #openstack-keystone | 09:52 | |
*** e0ne has joined #openstack-keystone | 09:52 | |
marekd | naresht: i recommend also reading this: http://docs.openstack.org/developer/keystone/configure_federation.html#keystone-as-an-identity-provider-idp | 09:53 |
marekd | naresht: see if /etc/keystone/ssl/certs/ has .pem files | 09:53 |
marekd | if so you should be good to use them. | 09:53 |
*** rk4n has quit IRC | 10:01 | |
*** rk4n has joined #openstack-keystone | 10:02 | |
naresht | +marekd; I'm sorry. We didn't find any .pem files and I need to create them. How could I do ? | 10:07 |
marekd | http://docs.openstack.org/developer/keystone/configuration.html#certificates-for-pki | 10:08 |
*** GB21 has quit IRC | 10:12 | |
*** jaosorior has quit IRC | 10:15 | |
*** jaosorior has joined #openstack-keystone | 10:15 | |
*** roxanaghe has joined #openstack-keystone | 10:18 | |
*** roxanaghe has quit IRC | 10:22 | |
*** EinstCra_ has quit IRC | 10:27 | |
*** naresht has quit IRC | 10:31 | |
*** agrebennikov has joined #openstack-keystone | 10:32 | |
*** agrebennikov has quit IRC | 10:37 | |
*** spzala has joined #openstack-keystone | 10:37 | |
*** spzala has quit IRC | 10:42 | |
*** LZ has quit IRC | 10:43 | |
*** LZ has joined #openstack-keystone | 10:43 | |
*** tellesnobrega is now known as tellesnobrega_af | 10:46 | |
*** tellesnobrega_af is now known as tellesnobrega | 10:49 | |
*** dims has joined #openstack-keystone | 10:49 | |
*** naresht has joined #openstack-keystone | 10:50 | |
naresht | +marekd; Thanks. We generated those .pem files. Now I'm getting error http://paste.openstack.org/show/491236/. Could you please look at it once ? | 10:50 |
*** henrynash has quit IRC | 10:53 | |
openstackgerrit | Konstantin Maximov proposed openstack/keystone: Add test for domains list filtering and limiting https://review.openstack.org/207456 | 11:12 |
*** GB21 has joined #openstack-keystone | 11:19 | |
*** tellesnobrega is now known as tellesnobrega_af | 11:20 | |
*** tellesnobrega_af is now known as tellesnobrega | 11:21 | |
*** edmondsw has joined #openstack-keystone | 11:27 | |
*** spzala has joined #openstack-keystone | 11:38 | |
*** spzala has quit IRC | 11:43 | |
*** dave-mccowan has joined #openstack-keystone | 11:47 | |
*** gordc has joined #openstack-keystone | 11:47 | |
*** spzala has joined #openstack-keystone | 11:53 | |
*** trown|PTO is now known as trown | 12:01 | |
*** roxanaghe has joined #openstack-keystone | 12:06 | |
*** rodrigods has quit IRC | 12:10 | |
*** roxanaghe has quit IRC | 12:10 | |
*** rodrigods has joined #openstack-keystone | 12:10 | |
*** pauloewerton has joined #openstack-keystone | 12:24 | |
*** henrynash has joined #openstack-keystone | 12:25 | |
*** ChanServ sets mode: +v henrynash | 12:25 | |
*** henrynash has quit IRC | 12:26 | |
*** nisha has joined #openstack-keystone | 12:29 | |
*** EinstCrazy has joined #openstack-keystone | 12:30 | |
nisha | Hi all :) | 12:31 |
*** GB21 has quit IRC | 12:31 | |
*** woodster_ has joined #openstack-keystone | 12:34 | |
breton | o/ | 12:34 |
*** LZ has quit IRC | 12:34 | |
*** mvk_ has quit IRC | 12:34 | |
*** mvk has joined #openstack-keystone | 12:35 | |
*** raildo-afk is now known as raildo | 12:35 | |
*** akanksha_ has joined #openstack-keystone | 12:40 | |
*** doug-fis_ has joined #openstack-keystone | 12:47 | |
naresht | When I do this "keystone-manage saml_idp_metadata > /etc/keystone/keystone_idp_metadata.xml" I'm getting below error "IOError: Cannot open certificate /etc/keystone/ssl/certs/signing_cert_req.pem. Reason: Strange beginning of PEM file". Could you please help me here ? | 12:48 |
marekd | naresht: make a copy of the pem file | 12:48 |
marekd | and remove the text | 12:48 |
marekd | naresht: what's the structure of your certificate? | 12:48 |
marekd | it's lots of text and public key there? | 12:49 |
*** doug-fish has quit IRC | 12:50 | |
marekd | naresht: it should be only key with ------BEGIN CERTIFICATE----- and -----END CERTIFICATE----- | 12:51 |
amakarov | naresht, I'm recalling I've ran into something similar too - look for another certificate file in that folder | 12:56 |
*** real56 has joined #openstack-keystone | 12:58 | |
naresht | amakarov: I have got two files which are "signing_cert_req.pem" "signing_key.pem" | 12:58 |
* amakarov looking through old presentations and stuff... | 12:59 | |
naresht | both are in same format what +marekd specified. | 12:59 |
*** ninag has joined #openstack-keystone | 13:00 | |
*** richm has joined #openstack-keystone | 13:08 | |
amakarov | naresht, here, catch! http://blog.rodrigods.com/it-is-time-to-play-with-keystone-to-keystone-federation-in-kilo/ | 13:09 |
amakarov | I've noticed that path to certificated differs from keystone default, but rodrigods'es recipe worked for me | 13:10 |
*** ametts has joined #openstack-keystone | 13:21 | |
naresht | We have followed rodrigods'es recipe... but not worked for me. | 13:24 |
naresht | is there anything like ownership permissions | 13:24 |
amakarov | naresht, are you using devstack? | 13:25 |
naresht | Yes | 13:26 |
*** real56 has quit IRC | 13:28 | |
*** links has quit IRC | 13:28 | |
naresht | amakarov: yes | 13:28 |
*** permalac has joined #openstack-keystone | 13:34 | |
*** dims_ has joined #openstack-keystone | 13:34 | |
amakarov | naresht, have you noticed this config line? certfile=/etc/keystone/ssl/certs/ca.pem | 13:35 |
*** dims has quit IRC | 13:36 | |
naresht | amakarov; yes i have same path but file name is different | 13:37 |
*** henrynash has joined #openstack-keystone | 13:37 | |
*** ChanServ sets mode: +v henrynash | 13:37 | |
amakarov | naresht, yes, and I remember that ca.pem works fine and the default one - does not | 13:38 |
naresht | amakarov: Here is my saml section http://paste.openstack.org/show/491267/ | 13:38 |
amakarov | naresht, yep, exact my problem :) Don't you have ca.pem in that folder? | 13:40 |
*** vint_bra has joined #openstack-keystone | 13:40 | |
amakarov | If you have - use ca.pem | 13:40 |
naresht | No I don't have | 13:41 |
amakarov | naresht, for some reason these pem files are not compatible | 13:41 |
naresht | How to generate that file | 13:41 |
amakarov | rodrigods, ^^ | 13:41 |
*** nisha has quit IRC | 13:43 | |
amakarov | naresht, this is the question to answer - I haven't look that deep - I've just had that files | 13:43 |
amakarov | rodrigods, where have you got /etc/keystone/ssl/certs/ca.pem for K2K fedefation? | 13:45 |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:51 | |
*** naresht has quit IRC | 13:52 | |
*** roxanaghe has joined #openstack-keystone | 13:54 | |
*** dave-mccowan has quit IRC | 13:55 | |
*** BigWillie has joined #openstack-keystone | 13:55 | |
*** real56 has joined #openstack-keystone | 13:56 | |
*** sdake has joined #openstack-keystone | 13:58 | |
*** roxanaghe has quit IRC | 13:58 | |
*** pcaruana has joined #openstack-keystone | 14:05 | |
openstackgerrit | Raildo Mascena proposed openstack/keystonemiddleware: Handling is_domain token attribute from keystone https://review.openstack.org/198076 | 14:09 |
*** jaosorior has quit IRC | 14:10 | |
*** jaosorior has joined #openstack-keystone | 14:11 | |
*** dave-mccowan has joined #openstack-keystone | 14:12 | |
*** spzala has quit IRC | 14:12 | |
*** boris-42 has joined #openstack-keystone | 14:12 | |
*** knikolla has joined #openstack-keystone | 14:12 | |
*** Ephur has joined #openstack-keystone | 14:18 | |
*** alejandrito has joined #openstack-keystone | 14:18 | |
*** slberger has joined #openstack-keystone | 14:27 | |
*** itlinux has joined #openstack-keystone | 14:27 | |
*** Nirupama has quit IRC | 14:28 | |
rodrigods | amakarov, hi... was afk | 14:31 |
rodrigods | generated via keystone-manager iirc | 14:31 |
*** csoukup has joined #openstack-keystone | 14:31 | |
*** bjornar has quit IRC | 14:34 | |
*** nisha has joined #openstack-keystone | 14:34 | |
zigo | Guys, it looks like keystone missed decorator in its requirements.txt | 14:35 |
zigo | See: http://paste.openstack.org/show/491274/ | 14:35 |
stevemar | zigo that looks like it is coming from `migrate` ? | 14:36 |
stevemar | which comes from oslo.db ? | 14:37 |
zigo | stevemar: So, it should be added to the python-migrate package as depends: ? | 14:37 |
* zigo checks | 14:37 | |
*** jorge_munoz has joined #openstack-keystone | 14:37 | |
stevemar | zigo: thats how i would understand it | 14:37 |
zigo | Ok, I'll fix that one there then. | 14:37 |
zigo | Hum... I have it there already... | 14:38 |
zigo | I don't get it. | 14:38 |
rodrigods | stevemar, any hints about the import issue here https://review.openstack.org/#/c/294201/ ? | 14:38 |
patchbot | rodrigods: patch 294201 - keystone - Add conflict validation for idp update | 14:38 |
stevemar | https://github.com/openstack/oslo.db/blob/master/requirements.txt#L13 | 14:38 |
zigo | Oh, I think I know. | 14:38 |
zigo | It happens only in my Trusty port. | 14:39 |
stevemar | zigo: hmm yeah, it is there: https://github.com/openstack/sqlalchemy-migrate/blob/fe3e08ae0b70cd94b0105a87919977ce506fe49b/requirements.txt#L10 | 14:39 |
stevemar | ah | 14:39 |
zigo | Yup, because keystone doesn't require a version high enough of migrate in my package. | 14:39 |
stevemar | zigo: gotcha! | 14:39 |
stevemar | zigo: time to bump it :) | 14:39 |
stevemar | rodrigods: it's opened in one of my chrome tabs, just haven't gotten to it yet | 14:39 |
stevemar | rodrigods: i'm moving slow this morning | 14:40 |
rodrigods | stevemar, np, i'm just not understanding why i can't import keystone.common there | 14:40 |
rodrigods | you can take a look when you have a moment | 14:40 |
rodrigods | thanks | 14:40 |
dstanek | rodrigods: imports are hard :-) | 14:41 |
zigo | stevemar: Yup, did so. | 14:41 |
rodrigods | dstanek, i'm getting to same the conclusion too :) | 14:41 |
dstanek | rodrigods: at first glance it appears that you introduced a import loop | 14:41 |
zigo | Though I catched it because -migrate 0.10.0 failed to build in my Trusty Jenkins, which I didn't catch. | 14:42 |
rodrigods | dstanek, hmm | 14:42 |
stevemar | rodrigods: dstanek hmmm http://logs.openstack.org/01/294201/2/check/gate-keystone-python27/70fb02c/console.html.gz#_2016-03-18_18_54_25_311 | 14:43 |
stevemar | rodrigods: i still don't understand why the legacy drivers would fail? you aren't changing the signature | 14:44 |
rodrigods | stevemar, it fails because the test expects a 409 | 14:45 |
rodrigods | and a 500 is returned | 14:45 |
*** bjornar has joined #openstack-keystone | 14:46 | |
*** timcline has joined #openstack-keystone | 14:53 | |
*** links has joined #openstack-keystone | 14:54 | |
*** tellesnobrega is now known as tellesnobrega_af | 14:55 | |
*** spzala has joined #openstack-keystone | 14:57 | |
*** spzala has quit IRC | 14:57 | |
*** spzala has joined #openstack-keystone | 14:57 | |
*** links has quit IRC | 15:02 | |
stevemar | rodrigods: i'll pull it down and see what i can do | 15:03 |
*** raorn has quit IRC | 15:04 | |
*** BAKfr has quit IRC | 15:09 | |
dstanek | rodrigods: any luck on your import problem? | 15:10 |
*** tellesnobrega_af is now known as tellesnobrega | 15:11 | |
*** tellesnobrega is now known as tellesnobrega_af | 15:12 | |
*** henrynash has quit IRC | 15:12 | |
dstanek | clear | 15:14 |
dstanek | lol | 15:14 |
*** fesp has joined #openstack-keystone | 15:16 | |
dstanek | rodrigods: let me pull down the patch real quick... | 15:17 |
*** EinstCrazy has quit IRC | 15:18 | |
dstanek | rodrigods: solved: http://paste.openstack.org/show/491291/ | 15:18 |
*** BAKfr has joined #openstack-keystone | 15:18 | |
dstanek | you'll have to figure out a different way organize some of the code so that there is no circular import | 15:18 |
*** real56 has quit IRC | 15:20 | |
*** real56 has joined #openstack-keystone | 15:21 | |
*** EinstCrazy has joined #openstack-keystone | 15:26 | |
*** EinstCrazy has quit IRC | 15:33 | |
*** roxanaghe has joined #openstack-keystone | 15:42 | |
*** nisha has quit IRC | 15:43 | |
*** alejandrito has quit IRC | 15:47 | |
*** roxanaghe has quit IRC | 15:47 | |
*** real56 has quit IRC | 15:47 | |
rodrigods | dstanek, sorry, was afk | 15:48 |
rodrigods | stevemar, dstanek got it... will try here | 15:49 |
*** alejandrito has joined #openstack-keystone | 15:49 | |
*** nisha has joined #openstack-keystone | 15:49 | |
openstackgerrit | Konstantin Maximov proposed openstack/keystone: Add test for domains list filtering and limiting https://review.openstack.org/207456 | 15:49 |
*** mylu has joined #openstack-keystone | 15:49 | |
*** fesp has quit IRC | 15:50 | |
stevemar | dstanek: clear | 15:52 |
dstanek | stevemar: done | 15:53 |
*** bjornar has quit IRC | 15:56 | |
*** alejandrito has quit IRC | 15:57 | |
*** rderose has joined #openstack-keystone | 15:58 | |
*** alejandrito has joined #openstack-keystone | 15:59 | |
*** rcernin has quit IRC | 15:59 | |
*** daemontool has quit IRC | 16:00 | |
*** henrynash has joined #openstack-keystone | 16:01 | |
*** ChanServ sets mode: +v henrynash | 16:01 | |
*** browne has joined #openstack-keystone | 16:01 | |
*** mylu has quit IRC | 16:09 | |
*** daemontool has joined #openstack-keystone | 16:10 | |
*** jorge_munoz has quit IRC | 16:14 | |
*** real56 has joined #openstack-keystone | 16:15 | |
*** dan_nguyen has joined #openstack-keystone | 16:18 | |
*** roxanaghe has joined #openstack-keystone | 16:18 | |
stevemar | is anyone else getting disconnected a lot? | 16:19 |
rodrigods | stevemar, fine here, i'm connected to cameron.freenode | 16:21 |
*** itlinux has quit IRC | 16:22 | |
*** pcaruana has quit IRC | 16:25 | |
*** spzala has quit IRC | 16:25 | |
*** mylu has joined #openstack-keystone | 16:26 | |
*** Guest9441 has quit IRC | 16:30 | |
*** tqtran-afk has joined #openstack-keystone | 16:31 | |
*** spzala has joined #openstack-keystone | 16:32 | |
*** aginwala has joined #openstack-keystone | 16:32 | |
*** rderose has quit IRC | 16:34 | |
*** spzala has quit IRC | 16:36 | |
*** sdake_ has joined #openstack-keystone | 16:38 | |
*** sdake has quit IRC | 16:41 | |
*** spzala has joined #openstack-keystone | 16:47 | |
*** rderose has joined #openstack-keystone | 16:47 | |
*** agireud has quit IRC | 16:49 | |
*** aginwala has quit IRC | 16:49 | |
*** lhcheng has joined #openstack-keystone | 16:50 | |
*** ChanServ sets mode: +v lhcheng | 16:50 | |
*** aginwala has joined #openstack-keystone | 16:50 | |
*** daemontool has quit IRC | 16:51 | |
*** spzala has quit IRC | 16:51 | |
*** agireud has joined #openstack-keystone | 16:52 | |
*** aginwala has quit IRC | 16:54 | |
*** aginwala has joined #openstack-keystone | 16:55 | |
*** spzala has joined #openstack-keystone | 16:57 | |
*** rderose has quit IRC | 16:57 | |
morgan | stevemar: i haven't had an issue | 16:57 |
*** tellesnobrega_af is now known as tellesnobrega | 16:59 | |
*** aginwala has quit IRC | 17:00 | |
*** spzala has quit IRC | 17:02 | |
*** timcline has quit IRC | 17:02 | |
*** timcline has joined #openstack-keystone | 17:03 | |
*** daemontool has joined #openstack-keystone | 17:03 | |
*** spzala has joined #openstack-keystone | 17:03 | |
*** aginwala has joined #openstack-keystone | 17:03 | |
*** aginwala has quit IRC | 17:03 | |
*** aginwala has joined #openstack-keystone | 17:04 | |
*** tqtran-afk is now known as tqtran | 17:06 | |
*** timcline has quit IRC | 17:07 | |
*** spzala has quit IRC | 17:08 | |
*** spzala has joined #openstack-keystone | 17:09 | |
*** trown is now known as trown|lunch | 17:11 | |
*** CaioBrentano has joined #openstack-keystone | 17:13 | |
*** spzala has quit IRC | 17:13 | |
*** mylu has quit IRC | 17:14 | |
*** mylu has joined #openstack-keystone | 17:14 | |
*** spzala has joined #openstack-keystone | 17:15 | |
*** yarkot1 has quit IRC | 17:18 | |
*** spzala has quit IRC | 17:19 | |
*** doug-fis_ has quit IRC | 17:20 | |
*** spzala has joined #openstack-keystone | 17:20 | |
*** doug-fish has joined #openstack-keystone | 17:21 | |
*** e0ne has quit IRC | 17:21 | |
*** yarkot has joined #openstack-keystone | 17:23 | |
*** nisha has quit IRC | 17:25 | |
*** spzala has quit IRC | 17:25 | |
*** doug-fish has quit IRC | 17:25 | |
*** agireud has quit IRC | 17:26 | |
*** spzala has joined #openstack-keystone | 17:26 | |
*** agireud has joined #openstack-keystone | 17:28 | |
*** chlong|wfh has quit IRC | 17:28 | |
*** aginwala has quit IRC | 17:29 | |
*** agireud has quit IRC | 17:29 | |
*** agireud has joined #openstack-keystone | 17:31 | |
*** spzala has quit IRC | 17:31 | |
*** aginwala has joined #openstack-keystone | 17:32 | |
*** mvk has quit IRC | 17:32 | |
*** jasonsb has quit IRC | 17:36 | |
*** aginwala has quit IRC | 17:38 | |
*** aginwala has joined #openstack-keystone | 17:38 | |
*** aginwala has quit IRC | 17:39 | |
*** aginwala has joined #openstack-keystone | 17:40 | |
*** sdake_ has quit IRC | 17:40 | |
*** chlong|wfh has joined #openstack-keystone | 17:42 | |
*** real56 has quit IRC | 17:44 | |
*** spzala has joined #openstack-keystone | 17:44 | |
*** real56 has joined #openstack-keystone | 17:44 | |
*** spzala has quit IRC | 17:47 | |
*** spzala has joined #openstack-keystone | 17:48 | |
*** real56 has quit IRC | 17:48 | |
*** real56 has joined #openstack-keystone | 17:48 | |
*** Ephur has quit IRC | 17:48 | |
*** Ephur has joined #openstack-keystone | 17:50 | |
*** doug-fish has joined #openstack-keystone | 17:50 | |
*** timcline has joined #openstack-keystone | 17:51 | |
*** doug-fish has quit IRC | 17:52 | |
*** doug-fish has joined #openstack-keystone | 17:52 | |
*** jaosorior has quit IRC | 17:53 | |
*** tellesnobrega is now known as tellesnobrega_af | 17:54 | |
*** tellesnobrega_af is now known as tellesnobrega | 17:54 | |
*** nisha has joined #openstack-keystone | 17:59 | |
*** mvk has joined #openstack-keystone | 18:07 | |
*** Ephur has quit IRC | 18:07 | |
*** nehap has joined #openstack-keystone | 18:08 | |
*** itlinux has joined #openstack-keystone | 18:09 | |
*** tellesnobrega is now known as tellesnobrega_af | 18:10 | |
*** aginwala has quit IRC | 18:10 | |
*** sdake has joined #openstack-keystone | 18:13 | |
nehap | Hi ayoung | 18:13 |
ayoung | nehap, with you in a moment | 18:14 |
*** tellesnobrega_af is now known as tellesnobrega | 18:14 | |
*** mvk_ has joined #openstack-keystone | 18:16 | |
*** aginwala has joined #openstack-keystone | 18:17 | |
*** mvk has quit IRC | 18:20 | |
*** trown|lunch is now known as trown | 18:27 | |
*** rderose has joined #openstack-keystone | 18:29 | |
*** nisha_ has joined #openstack-keystone | 18:33 | |
*** aginwala has quit IRC | 18:34 | |
*** nisha has quit IRC | 18:35 | |
*** real56 has quit IRC | 18:41 | |
*** real56 has joined #openstack-keystone | 18:41 | |
*** rderose has quit IRC | 18:44 | |
*** pnavarro has joined #openstack-keystone | 18:46 | |
*** aginwala has joined #openstack-keystone | 18:49 | |
*** aginwala has quit IRC | 18:50 | |
*** mvk has joined #openstack-keystone | 18:50 | |
*** aginwala has joined #openstack-keystone | 18:50 | |
*** mvk_ has quit IRC | 18:53 | |
*** e0ne has joined #openstack-keystone | 18:55 | |
*** aginwala has quit IRC | 18:56 | |
*** pushkaru has joined #openstack-keystone | 18:57 | |
*** nehap has quit IRC | 19:01 | |
*** timcline has quit IRC | 19:08 | |
*** timcline has joined #openstack-keystone | 19:09 | |
*** dave-mccowan has quit IRC | 19:10 | |
*** timcline has quit IRC | 19:14 | |
*** rderose has joined #openstack-keystone | 19:14 | |
*** roxanaghe has quit IRC | 19:18 | |
*** pnavarro has quit IRC | 19:27 | |
*** gordc has quit IRC | 19:28 | |
*** slberger1 has joined #openstack-keystone | 19:28 | |
*** aginwala has joined #openstack-keystone | 19:29 | |
*** rderose has quit IRC | 19:30 | |
*** timcline has joined #openstack-keystone | 19:30 | |
*** slberger has quit IRC | 19:31 | |
*** mylu has quit IRC | 19:31 | |
*** mylu has joined #openstack-keystone | 19:33 | |
*** dave-mccowan has joined #openstack-keystone | 19:36 | |
*** spandhe has joined #openstack-keystone | 19:38 | |
*** nisha__ has joined #openstack-keystone | 19:46 | |
*** rk4n has quit IRC | 19:48 | |
*** nisha_ has quit IRC | 19:48 | |
openstackgerrit | Raildo Mascena proposed openstack/keystone: [WIP]Make fernet default token provider https://review.openstack.org/258650 | 19:50 |
*** maxabidi has joined #openstack-keystone | 19:58 | |
ayoung | raildo, did you work around the test issues? | 19:59 |
*** gordc has joined #openstack-keystone | 20:10 | |
*** e0ne has quit IRC | 20:17 | |
*** pcaruana has joined #openstack-keystone | 20:21 | |
*** alejandrito has quit IRC | 20:25 | |
*** jrist has quit IRC | 20:26 | |
*** jrist has joined #openstack-keystone | 20:27 | |
*** aginwala has quit IRC | 20:29 | |
*** roxanaghe has joined #openstack-keystone | 20:31 | |
*** alejandrito has joined #openstack-keystone | 20:31 | |
*** aginwala has joined #openstack-keystone | 20:33 | |
raildo | ayoung: yes, I fix a couple of tests related to assignments and with the last rebase | 20:38 |
ayoung | raildo, how are we looking? Is it close to running, or do we still have significant work left? | 20:38 |
raildo | ayoung: we have a couple os tests related to trust that I don't know how to handle, and I'm working in the others tests, I think that we are close to running | 20:39 |
raildo | ayoung: I'll come in the next days to discuss with you and lbragstad about it | 20:39 |
ayoung | raildo, that works. | 20:40 |
knikolla | ayoung, I'd like to help with this https://etherpad.openstack.org/p/Keystone-LDAP-Cleanup | 20:42 |
ayoung | knikolla, excellent | 20:43 |
ayoung | knikolla, can you deploy Devstack with LDAP in it yet? | 20:43 |
knikolla | ayoung, yeah. It's already running. | 20:43 |
ayoung | Excellent. | 20:43 |
ayoung | knikolla, OK, so we have 3 main tasks | 20:44 |
ayoung | one is to convert over to the ldap3 library | 20:44 |
ayoung | care to give that a try? | 20:44 |
knikolla | ayoung, sounds good. | 20:44 |
ayoung | knikolla, so that can start by editing the tox requirements and pulling in the ldap3 library. | 20:46 |
ayoung | dstanek, youi played some with LDAP3. Is it a drop in replacement for the python-ldap? Does it work for 2 as well as 3? | 20:46 |
*** akanksha_ has quit IRC | 20:47 | |
ayoung | knikolla, keep notes about what you are doing posted on the etherpad so other people can see, too. | 20:47 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Add conflict validation for idp update https://review.openstack.org/294201 | 20:49 |
knikolla | ayoung, sure. | 20:49 |
ayoung | knikolla, please break things, then record how you break them | 20:50 |
ayoung | knikolla, the LDAP code is nasty. | 20:50 |
morgan | ayoung: ldap3 is not a drop in replacement | 20:50 |
ayoung | It could stand a bit of refactoring | 20:50 |
ayoung | morgan, does it at least also support ldap2? | 20:50 |
ayoung | er | 20:50 |
ayoung | python2? | 20:50 |
morgan | yep | 20:50 |
morgan | it's pure python | 20:50 |
*** maxabidi has quit IRC | 20:51 | |
morgan | as well | 20:51 |
*** BigWillie has quit IRC | 20:51 | |
morgan | but it is totally different semantics to write code around it, hence the idea to do http://specs.openstack.org/openstack/keystone-specs/specs/backlog/ldap3.html | 20:51 |
morgan | ayoung: a new driver that is ldap3 specific vs. trying to refactor/retrofit the current code | 20:51 |
knikolla | morgan, i like the idea of a new driver | 20:52 |
morgan | ayoung: ldap3 is much more pythonic as well, it uses dicts rather than listsof tuples | 20:52 |
ayoung | knikolla, excellent. | 20:52 |
morgan | bascially nothing will be needed in keystone.common for the ldap3 driver | 20:53 |
ayoung | OK...this is a better approach. I can see that now. | 20:53 |
morgan | it can be 100% isolated in keystone.identity.backends.ldap3 | 20:53 |
morgan | :) | 20:53 |
ayoung | morgan, do we inherit anything from the common config? | 20:53 |
morgan | ayoung: perhaps. didn't evaluate that | 20:53 |
morgan | ayoung: it may be worth new options in [ldap3] block | 20:54 |
ayoung | I think we do...its mostly the fields needed to talk to the remote server | 20:54 |
ayoung | lets try not. | 20:54 |
ayoung | if all we have to do is tell people to change their driver, it will be much nicer | 20:54 |
morgan | ayoung: but that part i figured was more implementation detail | 20:54 |
morgan | you'll likely need to make some changes to options add one or remove a couple | 20:54 |
ayoung | OK...that gets us both goals | 20:54 |
morgan | but that shouldn't be the end of the world | 20:54 |
morgan | but there should be zero ldap3 code in keystone.common | 20:55 |
ayoung | I doubt it. Those values are for "here is the LDAP query" to execute, and should be orthoganal to the code layout | 20:55 |
ayoung | we might want to deprecate most of them | 20:55 |
ayoung | but the ones we use should be the ones from that file | 20:55 |
morgan | when assignment was killed many ldap options were killed | 20:55 |
ayoung | ok... knikolla you got enough to get started? | 20:55 |
morgan | the read/write options will be deprecated | 20:55 |
morgan | since ldap3 will be read only | 20:55 |
ayoung | morgan, I was thinking all the "tree" options, too | 20:55 |
morgan | ayoung: likely | 20:56 |
ayoung | make it so there is only one way to specify the objects you are looking for, etc | 20:56 |
knikolla | ayoung, yes. | 20:56 |
*** alejandrito has quit IRC | 20:57 | |
ayoung | knikolla, try supporting just the config options in here: http://adam.younglogic.com/2014/08/getting-service-users-out-of-ldap/ | 20:57 |
ayoung | Hmmm | 20:57 |
ayoung | actually, let me see if I have a better set... | 20:57 |
rodrigods | stevemar, thanks! was working on it just right now | 20:58 |
rodrigods | heh | 20:58 |
* ayoung goes to get stevemar 's keystone O'Reilly book,... | 20:58 | |
*** alejandrito has joined #openstack-keystone | 20:58 | |
ayoung | knikolla, yeah, we still need the tree_dn way of querying. Start by supporting the config options in http://adam.younglogic.com/2014/08/getting-service-users-out-of-ldap/ but we will need to put in a few more, for AD support, as an example. | 21:01 |
*** timcline has quit IRC | 21:01 | |
knikolla | ayoung, ok, good! I'll do that. | 21:02 |
knikolla | ayoung, once I get something basic I'll propose a WIP change. What topic should that be on? | 21:03 |
*** raildo is now known as raildo-afk | 21:03 | |
*** raildo-afk is now known as raildo | 21:06 | |
ayoung | knikolla, ldap3 | 21:06 |
*** rk4n has joined #openstack-keystone | 21:08 | |
*** aginwala has quit IRC | 21:09 | |
*** pauloewerton has quit IRC | 21:13 | |
dstanek | morgan: i actually started a wrapper around ldap3 to highlight the differences | 21:14 |
*** trown is now known as trown|outtypewww | 21:16 | |
morgan | dstanek: I know the ldap3 folks are planning a drop in compat modulr | 21:18 |
*** rk4n has quit IRC | 21:18 | |
morgan | You might be able to contribute to that. But last I saw it had zero develop memt on it and a big "TODO" | 21:18 |
knikolla | ayoung, morgan. Would the new ldap3 driver be sync or async? | 21:22 |
*** pnavarro has joined #openstack-keystone | 21:22 | |
ayoung | sync knikolla | 21:22 |
morgan | knikolla: uhmmmmmmm... *shrug* go with what ayoung says | 21:22 |
ayoung | morgan, async means threads. This is Python.... | 21:23 |
ayoung | we shall await your reply | 21:23 |
morgan | ayoung: like i said... go with what you said. | 21:23 |
ayoung | knikolla, does ldap3 claim to have decend async support, or are you just talking from an LDAP perspective? | 21:24 |
*** aginwala has joined #openstack-keystone | 21:25 | |
knikolla | ayoung, http://ldap3.readthedocs.org/tutorial.html#accessing-an-ldap-server | 21:25 |
knikolla | according to this guide, ldap3 support async | 21:25 |
ayoung | SORRY This page does not exist yet. | 21:26 |
knikolla | ayoung, http://ldap3.readthedocs.org/tutorial.html | 21:26 |
ayoung | weeeeeird | 21:26 |
knikolla | ayoung, scroll to "Accessing an LDAP server" | 21:27 |
knikolla | looks like inpage links don't work *shrugs* | 21:27 |
ayoung | knikolla, ah, right, so a very thin wrapper around the LDAP protocol. So, I am not certain that we could even do async | 21:27 |
dstanek | knikolla: i don't think we should do async | 21:28 |
dstanek | ayoung: basically the calls would return a message id for a request and then we'd have to ask at some later point what the status was for the operation | 21:28 |
ayoung | dstanek, Oh, I know we *should not* do it. I was wondering if we even *could* do it. I guess, in theory we could, but I am not certain that it would actually work in python | 21:28 |
ayoung | dstanek, it is so eventlet like | 21:29 |
ayoung | "never block" for IO | 21:29 |
dstanek | ayoung: python has great async IO support; we don't have the necessary infrastructure for it | 21:29 |
*** doug-fish has quit IRC | 21:29 | |
ayoung | dstanek, "infrastructure" meaning what? | 21:30 |
dstanek | ayoung: kinda like eventlet, but we would control the event loop | 21:30 |
knikolla | dstanek, ayoung. even with async support it wouldn't have much benefit. We wouldn't be doing anything else with the thread while waiting. | 21:30 |
dstanek | knikolla: exactly. | 21:30 |
dstanek | if we were making a multiplexed app then we would see some benefit, but that's very far off from our design | 21:31 |
*** doug-fish has joined #openstack-keystone | 21:32 | |
ayoung | knikolla, still, that was a good question. Please capture this discussion on the Etherpad. | 21:34 |
*** doug-fis_ has joined #openstack-keystone | 21:34 | |
*** doug-fish has quit IRC | 21:36 | |
knikolla | ayoung, done. | 21:38 |
*** doug-fis_ has quit IRC | 21:38 | |
*** pnavarro_ has joined #openstack-keystone | 21:39 | |
*** sdake_ has joined #openstack-keystone | 21:39 | |
*** pnavarro has quit IRC | 21:40 | |
*** fawadkhaliq has joined #openstack-keystone | 21:41 | |
*** sdake has quit IRC | 21:41 | |
*** nisha__ has quit IRC | 21:44 | |
*** aginwala has quit IRC | 21:45 | |
*** nisha__ has joined #openstack-keystone | 21:45 | |
*** raildo is now known as raildo-afk | 21:47 | |
*** doug-fish has joined #openstack-keystone | 21:51 | |
*** aginwala has joined #openstack-keystone | 21:52 | |
*** doug-fish has quit IRC | 21:55 | |
*** doug-fish has joined #openstack-keystone | 21:55 | |
mfisch | stevemar: which team owns the requirements repo? | 21:57 |
*** rk4n has joined #openstack-keystone | 21:57 | |
mfisch | I see commits from lots of folks | 21:57 |
mfisch | I'd like to know when the mitaka branch will show up | 21:58 |
*** real56 has quit IRC | 21:58 | |
morgan | jamielennox, ayoung: if either of you happen to have centos7 image running: https://github.com/morganfainberg/positional/issues/16 a quick check would be good. | 21:58 |
*** real56 has joined #openstack-keystone | 21:58 | |
ayoung | morgan, I do...let me look | 21:59 |
morgan | ayoung: thnx | 21:59 |
ayoung | morgan, uh...hhmmm | 21:59 |
ayoung | what am I looking for? | 21:59 |
*** timcline has joined #openstack-keystone | 21:59 | |
morgan | ayoung: pip install positional | 21:59 |
morgan | failed for that guy on cent7 | 22:00 |
ayoung | morgan, http://fpaste.org/343515/85976561/ | 22:01 |
ayoung | CentOS Linux release 7.2.1511 (Core) | 22:01 |
morgan | hmmm | 22:01 |
morgan | ok | 22:01 |
*** Ephur has joined #openstack-keystone | 22:01 | |
*** sdake_ is now known as sdake | 22:02 | |
*** rk4n has quit IRC | 22:02 | |
*** nisha__ has quit IRC | 22:04 | |
*** knikolla has quit IRC | 22:04 | |
*** pcaruana has quit IRC | 22:06 | |
*** aginwala has quit IRC | 22:07 | |
*** rk4n has joined #openstack-keystone | 22:09 | |
*** pnavarro_ has quit IRC | 22:09 | |
*** aginwala has joined #openstack-keystone | 22:10 | |
*** nisha has joined #openstack-keystone | 22:12 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Switch migration tests to oslo.db DbTestCase https://review.openstack.org/294246 | 22:12 |
*** sdake_ has joined #openstack-keystone | 22:12 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 22:13 | |
jamielennox | morgan: yea, module release doesn't sound like its our fault | 22:15 |
*** sdake has quit IRC | 22:15 | |
*** timcline has quit IRC | 22:17 | |
morgan | jamielennox: yeah. | 22:17 |
*** timcline has joined #openstack-keystone | 22:18 | |
*** aginwala has quit IRC | 22:20 | |
*** csoukup has quit IRC | 22:22 | |
morgan | jamielennox: do you have a pypi user? | 22:22 |
jamielennox | morgan: yep | 22:22 |
morgan | jamielennox: let me give you access to publish positional releases | 22:22 |
jamielennox | pretty sure | 22:22 |
*** aginwala has joined #openstack-keystone | 22:22 | |
morgan | jamielennox: since i am ... busy finding work -- | 22:23 |
jamielennox | morgan: it's just jamielennox | 22:23 |
morgan | jamielennox: ok | 22:24 |
morgan | will add you soon to the owners of the pypi package | 22:24 |
*** mylu has quit IRC | 22:27 | |
morgan | jamielennox: ok added | 22:27 |
jamielennox | yay? | 22:28 |
*** spzala has quit IRC | 22:29 | |
*** nisha has quit IRC | 22:30 | |
*** alejandrito has quit IRC | 22:32 | |
*** ninag has quit IRC | 22:33 | |
*** ninag has joined #openstack-keystone | 22:33 | |
*** zqfan has joined #openstack-keystone | 22:36 | |
*** ninag has quit IRC | 22:38 | |
*** knikolla has joined #openstack-keystone | 22:39 | |
*** slberger1 has left #openstack-keystone | 22:39 | |
*** timcline has quit IRC | 22:53 | |
*** timcline has joined #openstack-keystone | 22:54 | |
*** spzala has joined #openstack-keystone | 22:54 | |
*** aginwala has quit IRC | 22:58 | |
*** timcline has quit IRC | 22:58 | |
*** spzala has quit IRC | 22:59 | |
*** edmondsw has quit IRC | 22:59 | |
*** ametts has quit IRC | 23:00 | |
*** openstackgerrit has quit IRC | 23:03 | |
*** openstackgerrit_ is now known as openstackgerrit | 23:03 | |
*** openstackgerrit has quit IRC | 23:03 | |
*** openstackgerrit_ has joined #openstack-keystone | 23:03 | |
*** boris-42 has quit IRC | 23:04 | |
*** openstackgerrit_ is now known as openstackgerrit | 23:04 | |
*** rk4n has quit IRC | 23:07 | |
*** openstackgerrit_ has joined #openstack-keystone | 23:08 | |
*** dims_ has quit IRC | 23:09 | |
*** dims has joined #openstack-keystone | 23:09 | |
*** lucas_ has joined #openstack-keystone | 23:10 | |
*** mylu has joined #openstack-keystone | 23:11 | |
*** dims has quit IRC | 23:21 | |
*** dims has joined #openstack-keystone | 23:22 | |
*** sdake has joined #openstack-keystone | 23:25 | |
*** sdake_ has quit IRC | 23:26 | |
*** spzala has joined #openstack-keystone | 23:27 | |
*** dims has quit IRC | 23:27 | |
*** dims has joined #openstack-keystone | 23:28 | |
*** dims has quit IRC | 23:33 | |
*** gordc has quit IRC | 23:33 | |
*** fawadkhaliq has quit IRC | 23:35 | |
*** timcline has joined #openstack-keystone | 23:39 | |
*** trown|outtypewww is now known as trown | 23:42 | |
*** timcline has quit IRC | 23:44 | |
*** trown is now known as trown|outtypewww | 23:45 | |
*** fawadkhaliq has joined #openstack-keystone | 23:45 | |
*** aginwala has joined #openstack-keystone | 23:46 | |
*** fawadkhaliq has quit IRC | 23:50 | |
*** fawadkhaliq has joined #openstack-keystone | 23:50 | |
*** pushkaru has quit IRC | 23:50 | |
*** pushkaru has joined #openstack-keystone | 23:51 | |
*** furface has quit IRC | 23:52 | |
*** aginwala has quit IRC | 23:54 | |
*** pushkaru has quit IRC | 23:55 | |
*** lucas_ has quit IRC | 23:56 | |
*** lucas_ has joined #openstack-keystone | 23:57 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!