*** pgbridge has quit IRC | 00:00 | |
stevemar | gyee: nah, its a stat holiday | 00:01 |
---|---|---|
*** rderose has joined #openstack-keystone | 00:01 | |
*** c_soukup has quit IRC | 00:02 | |
*** fawadkhaliq has quit IRC | 00:07 | |
*** fawadkhaliq has joined #openstack-keystone | 00:07 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: WIP - Drop EPHEMERAL user type https://review.openstack.org/296639 | 00:13 |
*** rderose has quit IRC | 00:14 | |
*** rdo has quit IRC | 00:17 | |
*** sdake_ has joined #openstack-keystone | 00:20 | |
*** roxanaghe has quit IRC | 00:22 | |
*** sdake has quit IRC | 00:22 | |
*** arunkant_ has quit IRC | 00:26 | |
knikolla | http://lists.openstack.org/pipermail/openstack-dev/2016-March/090422.html | 00:29 |
knikolla | results are out | 00:29 |
*** shoutm has quit IRC | 00:34 | |
*** shoutm has joined #openstack-keystone | 00:36 | |
*** fawadkhaliq has quit IRC | 00:38 | |
*** fawadkhaliq has joined #openstack-keystone | 00:39 | |
*** sheel has joined #openstack-keystone | 00:40 | |
ayoung | stevemar, Congrats! | 00:44 |
*** flaper87 has quit IRC | 00:45 | |
*** flaper87 has joined #openstack-keystone | 00:46 | |
*** fawadkhaliq has quit IRC | 00:47 | |
*** fawadkhaliq has joined #openstack-keystone | 00:48 | |
*** knikolla has quit IRC | 00:50 | |
*** timcline has joined #openstack-keystone | 00:51 | |
*** fawadkhaliq has quit IRC | 00:54 | |
samueldmq | stevemar: thanks for the update; same here :) | 00:54 |
samueldmq | stevemar: enjoy this long weekend | 00:54 |
*** timcline has quit IRC | 00:55 | |
*** shoutm_ has joined #openstack-keystone | 00:55 | |
*** shoutm has quit IRC | 00:55 | |
*** lhcheng_ has joined #openstack-keystone | 00:57 | |
*** lhcheng has quit IRC | 01:00 | |
*** jorge_munoz has quit IRC | 01:04 | |
*** EinstCrazy has joined #openstack-keystone | 01:05 | |
*** EinstCrazy has quit IRC | 01:07 | |
*** EinstCrazy has joined #openstack-keystone | 01:09 | |
*** pushkaru has quit IRC | 01:16 | |
*** agrebennikov has quit IRC | 01:23 | |
*** sdake_ has quit IRC | 01:27 | |
*** fawadkhaliq has joined #openstack-keystone | 01:29 | |
*** dan_nguyen has quit IRC | 01:47 | |
*** timcline has joined #openstack-keystone | 01:52 | |
*** lhcheng_ has quit IRC | 01:52 | |
*** timcline has quit IRC | 01:56 | |
*** itlinux_ has joined #openstack-keystone | 02:06 | |
*** itlinux has quit IRC | 02:06 | |
*** woodster_ has quit IRC | 02:07 | |
*** edmondsw has quit IRC | 02:22 | |
*** lhcheng has joined #openstack-keystone | 02:41 | |
*** ChanServ sets mode: +v lhcheng | 02:41 | |
*** timcline has joined #openstack-keystone | 02:53 | |
*** gyee has quit IRC | 02:53 | |
*** timcline has quit IRC | 02:54 | |
*** timcline has joined #openstack-keystone | 02:54 | |
*** sheel has quit IRC | 02:57 | |
*** timcline has quit IRC | 02:59 | |
*** fawadkhaliq has quit IRC | 03:03 | |
*** sdake has joined #openstack-keystone | 03:07 | |
openstackgerrit | Anh Tran proposed openstack/keystone: Removing redundant words https://review.openstack.org/297499 | 03:09 |
*** dave-mccowan has quit IRC | 03:10 | |
*** chlong has quit IRC | 03:12 | |
*** harlowja_at_home has quit IRC | 03:12 | |
*** harlowja_at_home has joined #openstack-keystone | 03:12 | |
*** dave-mccowan has joined #openstack-keystone | 03:13 | |
*** fawadkhaliq has joined #openstack-keystone | 03:14 | |
*** chlong has joined #openstack-keystone | 03:14 | |
*** pgreg has joined #openstack-keystone | 03:15 | |
*** shoutm_ has quit IRC | 03:18 | |
*** shoutm has joined #openstack-keystone | 03:18 | |
*** dave-mccowan has quit IRC | 03:20 | |
*** roxanaghe has joined #openstack-keystone | 03:25 | |
*** roxanaghe has quit IRC | 03:40 | |
*** roxanaghe has joined #openstack-keystone | 03:41 | |
*** jasonsb has joined #openstack-keystone | 03:42 | |
*** timcline has joined #openstack-keystone | 03:55 | |
*** timcline has quit IRC | 04:00 | |
*** links has joined #openstack-keystone | 04:01 | |
*** jasonsb has quit IRC | 04:04 | |
*** EinstCra_ has joined #openstack-keystone | 04:05 | |
*** EinstCrazy has quit IRC | 04:06 | |
*** jasonsb has joined #openstack-keystone | 04:26 | |
*** david_cu has quit IRC | 04:34 | |
*** jasonsb_ has joined #openstack-keystone | 04:50 | |
*** jasonsb has quit IRC | 04:50 | |
*** timcline has joined #openstack-keystone | 04:56 | |
*** timcline has quit IRC | 05:00 | |
*** spandhe has joined #openstack-keystone | 05:05 | |
*** shoutm_ has joined #openstack-keystone | 05:06 | |
*** shoutm has quit IRC | 05:08 | |
*** wasmum has joined #openstack-keystone | 05:11 | |
openstackgerrit | Merged openstack/keystone: Removing redundant words https://review.openstack.org/297499 | 05:14 |
*** EinstCra_ has quit IRC | 05:30 | |
*** roxanaghe has quit IRC | 05:32 | |
*** EinstCrazy has joined #openstack-keystone | 05:33 | |
*** roxanaghe has joined #openstack-keystone | 05:36 | |
*** links has quit IRC | 05:43 | |
*** roxanaghe has quit IRC | 05:47 | |
*** spandhe has quit IRC | 05:50 | |
*** sdake has quit IRC | 05:50 | |
*** timcline has joined #openstack-keystone | 05:57 | |
*** spandhe has joined #openstack-keystone | 05:58 | |
*** timcline has quit IRC | 06:01 | |
*** spandhe has quit IRC | 06:03 | |
*** timcline has joined #openstack-keystone | 06:23 | |
*** shoutm_ has quit IRC | 06:26 | |
*** shoutm has joined #openstack-keystone | 06:27 | |
*** timcline has quit IRC | 06:27 | |
*** lhcheng has quit IRC | 06:30 | |
*** EinstCrazy has quit IRC | 06:44 | |
*** chlong has quit IRC | 06:45 | |
*** EinstCrazy has joined #openstack-keystone | 06:48 | |
*** e0ne has joined #openstack-keystone | 07:06 | |
*** henrynash has joined #openstack-keystone | 07:08 | |
*** ChanServ sets mode: +v henrynash | 07:08 | |
*** rk4n has joined #openstack-keystone | 07:08 | |
*** spandhe has joined #openstack-keystone | 07:10 | |
*** rk4n has quit IRC | 07:11 | |
*** EinstCrazy has quit IRC | 07:12 | |
*** rk4n has joined #openstack-keystone | 07:12 | |
*** e0ne has quit IRC | 07:15 | |
*** rk4n has quit IRC | 07:17 | |
*** fawadkhaliq has quit IRC | 07:17 | |
*** EinstCrazy has joined #openstack-keystone | 07:21 | |
*** timcline has joined #openstack-keystone | 07:24 | |
*** rk4n has joined #openstack-keystone | 07:25 | |
*** timcline has quit IRC | 07:28 | |
*** shoutm_ has joined #openstack-keystone | 07:29 | |
*** shoutm has quit IRC | 07:30 | |
*** spandhe has quit IRC | 07:36 | |
*** pcaruana has joined #openstack-keystone | 07:38 | |
*** nisha has joined #openstack-keystone | 07:43 | |
*** kyen has joined #openstack-keystone | 07:44 | |
*** rk4n has quit IRC | 07:51 | |
*** rk4n has joined #openstack-keystone | 07:56 | |
*** rk4n has quit IRC | 08:00 | |
*** nisha has quit IRC | 08:06 | |
*** lhcheng has joined #openstack-keystone | 08:19 | |
*** ChanServ sets mode: +v lhcheng | 08:19 | |
*** lhcheng has quit IRC | 08:24 | |
*** EinstCrazy has quit IRC | 08:24 | |
*** timcline has joined #openstack-keystone | 08:25 | |
*** timcline has quit IRC | 08:29 | |
*** shoutm_ has quit IRC | 08:34 | |
*** EinstCrazy has joined #openstack-keystone | 08:34 | |
*** sheel has joined #openstack-keystone | 08:38 | |
*** openstackstatus has joined #openstack-keystone | 09:08 | |
*** ChanServ sets mode: +v openstackstatus | 09:08 | |
*** EinstCra_ has joined #openstack-keystone | 09:16 | |
*** EinstCrazy has quit IRC | 09:17 | |
*** EinstCrazy has joined #openstack-keystone | 09:18 | |
*** EinstCra_ has quit IRC | 09:19 | |
*** real56 has joined #openstack-keystone | 09:20 | |
*** EinstCrazy has quit IRC | 09:20 | |
*** EinstCrazy has joined #openstack-keystone | 09:21 | |
*** daemontool has joined #openstack-keystone | 09:22 | |
*** EinstCrazy has quit IRC | 09:23 | |
*** EinstCr__ has joined #openstack-keystone | 09:23 | |
*** EinstCrazy has joined #openstack-keystone | 09:24 | |
*** real56 has joined #openstack-keystone | 09:25 | |
*** Einst____ has joined #openstack-keystone | 09:26 | |
*** timcline has joined #openstack-keystone | 09:26 | |
*** EinstCr__ has quit IRC | 09:27 | |
*** EinstCrazy has quit IRC | 09:29 | |
*** timcline has quit IRC | 09:30 | |
*** real56_ has joined #openstack-keystone | 09:36 | |
*** real56 has quit IRC | 09:39 | |
*** real56_ is now known as real56 | 09:39 | |
*** kyen has quit IRC | 09:40 | |
*** kfox1111 has quit IRC | 09:44 | |
*** kfox1111 has joined #openstack-keystone | 09:44 | |
*** xek has quit IRC | 09:48 | |
*** xek has joined #openstack-keystone | 09:49 | |
*** EinstCrazy has joined #openstack-keystone | 09:56 | |
*** Einst____ has quit IRC | 09:59 | |
*** e0ne has joined #openstack-keystone | 10:11 | |
*** jed56 has quit IRC | 10:13 | |
*** EinstCrazy has quit IRC | 10:14 | |
*** timcline has joined #openstack-keystone | 10:26 | |
*** timcline has quit IRC | 10:30 | |
*** lhcheng has joined #openstack-keystone | 10:32 | |
*** ChanServ sets mode: +v lhcheng | 10:32 | |
*** lhcheng has quit IRC | 10:37 | |
*** lmiccini has quit IRC | 10:39 | |
*** lmiccini has joined #openstack-keystone | 10:40 | |
*** rk4n has joined #openstack-keystone | 11:02 | |
*** rk4n has quit IRC | 11:03 | |
*** rk4n_ has joined #openstack-keystone | 11:03 | |
*** wanghua has quit IRC | 11:24 | |
*** timcline has joined #openstack-keystone | 11:27 | |
*** timcline has quit IRC | 11:31 | |
*** jsavak has joined #openstack-keystone | 11:32 | |
*** pgreg has quit IRC | 11:32 | |
*** jsavak has quit IRC | 11:52 | |
*** pgreg has joined #openstack-keystone | 12:06 | |
fundcor | It seems that gunicorn reads just the part of config that is under # sign (cmd is listed later). But it doesn't seem to read other config (uwsgi and apache2 mod_wsgi do it automatically it seems): ~/keystone/venv/bin/gunicorn --paste /etc/keystone/keystone-paste.ini --paste /etc/keystone/keystone.conf --paste /etc/keystone/test2.ini#admin_service --bind 10.10.10.10:8001 --log-level debug --access-logfile - | 12:13 |
fundcor | as you can see additional --paste sections doesn't affect anything at all. How can I make gunicorn to read all the configs without hardcoding it in wsgi script? | 12:14 |
*** timcline has joined #openstack-keystone | 12:28 | |
morgan | fundcor: unfortunately, this is not something we have spent a lot of time on. If you figure it out, I recommend making a blog post/contributing documentation. | 12:32 |
*** timcline has quit IRC | 12:32 | |
morgan | fundcor: i do remember gunicorn had issues with configs not working right. it may require hard-coding, it may require other things, it also may be unsupportable. | 12:33 |
*** david-lyle has quit IRC | 12:45 | |
*** flaper87 has quit IRC | 12:46 | |
*** flaper87 has joined #openstack-keystone | 12:46 | |
*** jsavak has joined #openstack-keystone | 12:47 | |
*** jed56 has joined #openstack-keystone | 12:47 | |
*** henrynash has quit IRC | 13:01 | |
dstanek | fundcor: why would you pass your keystone.conf on the command-line to gunicor? | 13:01 |
*** jsavak has quit IRC | 13:07 | |
*** ninag has joined #openstack-keystone | 13:09 | |
*** jsavak has joined #openstack-keystone | 13:10 | |
*** edmondsw has joined #openstack-keystone | 13:10 | |
*** jsavak has quit IRC | 13:15 | |
*** jsavak has joined #openstack-keystone | 13:16 | |
*** edmondsw has quit IRC | 13:16 | |
*** edmondsw has joined #openstack-keystone | 13:21 | |
*** timcline has joined #openstack-keystone | 13:28 | |
*** pgreg has quit IRC | 13:29 | |
*** timcline has quit IRC | 13:33 | |
*** jaugustine has joined #openstack-keystone | 13:35 | |
dstanek | ok, i'll officially stumped by oslo_config... might be time to call it a day already :-( | 13:44 |
*** ayoung has quit IRC | 13:44 | |
*** pushkaru has joined #openstack-keystone | 13:48 | |
*** kyen has joined #openstack-keystone | 13:53 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:03 | |
*** knikolla has joined #openstack-keystone | 14:04 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Use ldap3 for DN comparison https://review.openstack.org/260721 | 14:17 |
*** spzala has joined #openstack-keystone | 14:18 | |
*** knikolla has quit IRC | 14:19 | |
*** nisha has joined #openstack-keystone | 14:20 | |
*** edmondsw has quit IRC | 14:22 | |
*** c_soukup has joined #openstack-keystone | 14:22 | |
*** ayoung has joined #openstack-keystone | 14:26 | |
*** ChanServ sets mode: +v ayoung | 14:26 | |
*** henrynash has joined #openstack-keystone | 14:29 | |
*** ChanServ sets mode: +v henrynash | 14:29 | |
*** timcline has joined #openstack-keystone | 14:29 | |
*** slberger has joined #openstack-keystone | 14:31 | |
*** timcline has quit IRC | 14:34 | |
*** edmondsw has joined #openstack-keystone | 14:37 | |
*** sdake has joined #openstack-keystone | 14:41 | |
*** knikolla has joined #openstack-keystone | 14:43 | |
*** diazjf has joined #openstack-keystone | 14:44 | |
*** dan_nguyen has joined #openstack-keystone | 14:45 | |
*** timcline has joined #openstack-keystone | 14:46 | |
*** diazjf1 has joined #openstack-keystone | 14:49 | |
*** jorge_munoz has joined #openstack-keystone | 14:51 | |
*** diazjf has quit IRC | 14:52 | |
*** nisha has quit IRC | 14:53 | |
*** c_soukup has quit IRC | 15:12 | |
*** nisha has joined #openstack-keystone | 15:17 | |
*** pumarani__ has joined #openstack-keystone | 15:19 | |
*** pushkaru has quit IRC | 15:21 | |
*** diazjf1 has quit IRC | 15:24 | |
*** diazjf has joined #openstack-keystone | 15:24 | |
*** spzala has quit IRC | 15:27 | |
mfisch | dolphm: lbragstad G+ for our call today? | 15:29 |
*** david-lyle has joined #openstack-keystone | 15:34 | |
*** agrebennikov has joined #openstack-keystone | 15:34 | |
*** spzala has joined #openstack-keystone | 15:34 | |
*** agrebennikov has quit IRC | 15:37 | |
*** agrebennikov has joined #openstack-keystone | 15:37 | |
*** nisha has quit IRC | 15:38 | |
*** david-lyle_ has joined #openstack-keystone | 15:38 | |
*** spzala has quit IRC | 15:38 | |
*** david-lyle has quit IRC | 15:38 | |
*** woodster_ has joined #openstack-keystone | 15:39 | |
*** henrynash has quit IRC | 15:39 | |
*** david-lyle_ is now known as david-lyle | 15:39 | |
*** pnavarro has joined #openstack-keystone | 15:41 | |
*** spzala has joined #openstack-keystone | 15:44 | |
*** jdennis has quit IRC | 15:47 | |
*** spzala has quit IRC | 15:49 | |
*** spzala has joined #openstack-keystone | 15:50 | |
breton | in k2k there are attributes like openstack_user_domain or openstack_project in the SAML attribute. What is it for? Afaik we cannot set project dynamically in the mapping, can we? | 15:54 |
*** ebalduf has joined #openstack-keystone | 15:54 | |
*** spzala has quit IRC | 15:55 | |
*** gyee has joined #openstack-keystone | 15:55 | |
*** ChanServ sets mode: +v gyee | 15:55 | |
breton | *what are they for? | 15:55 |
*** spzala has joined #openstack-keystone | 15:56 | |
*** roxanaghe has joined #openstack-keystone | 15:57 | |
*** gmmaha has joined #openstack-keystone | 16:00 | |
gmmaha | Hi, i had a quick question.. I have an openstack multinode deployment and it fails with create new projects with the error "Error: Could not find defualt role "_member_" in Keystone | 16:01 |
*** spzala has quit IRC | 16:01 | |
gmmaha | i found a bug https://bugs.launchpad.net/devstack/+bug/1421616 but it seems its an issue with devstack and not openstack itself.. | 16:01 |
openstack | Launchpad bug 1421616 in devstack "Cannot create project using Horizon - Could not find default role "_member_"" [Undecided,Fix released] - Assigned to Attila Fazekas (afazekas) | 16:01 |
gmmaha | i also found that _member_ role doesnt exist in my isntalltion. http://paste.openstack.org/show/491910/ | 16:02 |
*** rderose has joined #openstack-keystone | 16:02 | |
gmmaha | shouldnt the _member_ role be created by default? Do I have to create it manually | 16:02 |
*** spzala has joined #openstack-keystone | 16:02 | |
gmmaha | i believe this is upstream master code thats being deployed | 16:02 |
*** rk4n_ has quit IRC | 16:06 | |
*** spzala has quit IRC | 16:06 | |
breton | yes, you need to create it | 16:09 |
*** pcaruana has quit IRC | 16:11 | |
*** spzala has joined #openstack-keystone | 16:11 | |
*** roxanaghe has quit IRC | 16:15 | |
*** spzala has quit IRC | 16:16 | |
gmmaha | breton: ohh.. i always thought that when keystone gets instantiated, both admin and _member_ get created by default.. | 16:17 |
*** spzala has joined #openstack-keystone | 16:17 | |
gmmaha | did that change in the recent past or do i just have my know-how wrong. | 16:17 |
*** roxanaghe has joined #openstack-keystone | 16:18 | |
breton | gmmaha: i think the latter :) | 16:20 |
gmmaha | breton: :) thanks for clarifying | 16:20 |
gmmaha | breton: then maybe a small bug is in order? With user admin, when i try to create a new project/user it fails with _member_ role not available.. | 16:22 |
*** spzala has quit IRC | 16:22 | |
gmmaha | maybe we should need it or if thts a need, maybe we create.. | 16:22 |
gmmaha | Just easier user exprience.. sorry if this has already been discussed | 16:22 |
*** roxanaghe has quit IRC | 16:22 | |
*** spzala has joined #openstack-keystone | 16:23 | |
*** roxanaghe has joined #openstack-keystone | 16:24 | |
*** spzala has quit IRC | 16:28 | |
*** spzala has joined #openstack-keystone | 16:29 | |
*** jdennis has joined #openstack-keystone | 16:29 | |
*** spzala has quit IRC | 16:33 | |
*** mylu has joined #openstack-keystone | 16:33 | |
*** spzala has joined #openstack-keystone | 16:35 | |
*** spzala has quit IRC | 16:39 | |
SamYaple | question. can a user belong to multiple domains? if so how-to-do? I thought this was the case but cannot figure it out | 16:40 |
*** jsavak has quit IRC | 16:40 | |
breton | gmmaha: maybe | 16:41 |
*** jsavak has joined #openstack-keystone | 16:41 | |
breton | gmmaha: it won't hurt after all | 16:41 |
breton | SamYaple: no, user cannot belong to multiple domains. Why would you want that? | 16:42 |
breton | SamYaple: you can assign user roles on mulitple domains though | 16:42 |
SamYaple | breton: its not _that_ crazy. one user admining multiple domains where domains are seperate companies (multi-tenant cloud) | 16:43 |
SamYaple | so if i assign roles for other domains to one user that should allow this, yes? | 16:43 |
gmmaha | breton: thanks.. let me file a bug | 16:43 |
SamYaple | i remeber being able to do this, just not hte details of how | 16:43 |
SamYaple | roles sound like the answer | 16:44 |
breton | SamYaple: well, assign him roles. it doesn't mean that the user can control the domain by being in it | 16:44 |
SamYaple | breton: in this case its a bit more... not so cool. basically the goal is to have horizon view look like one project or another. so lets see if roles can solve that | 16:46 |
SamYaple | one domain or another* | 16:46 |
gmmaha | breton: commented on an existing bug.. https://bugs.launchpad.net/devstack/+bug/1421616 | 16:51 |
openstack | Launchpad bug 1421616 in devstack "Cannot create project using Horizon - Could not find default role "_member_"" [Undecided,Fix released] - Assigned to Attila Fazekas (afazekas) | 16:51 |
gmmaha | thanks for the help | 16:51 |
*** mylu has quit IRC | 16:51 | |
*** edmondsw has quit IRC | 16:52 | |
*** mylu has joined #openstack-keystone | 16:55 | |
*** jsavak has quit IRC | 16:57 | |
*** henrynash has joined #openstack-keystone | 16:58 | |
*** ChanServ sets mode: +v henrynash | 16:58 | |
openstackgerrit | Alexander Makarov proposed openstack/keystoneauth: Examples for migration from keystoneclient https://review.openstack.org/297764 | 16:58 |
*** rderose has quit IRC | 17:01 | |
*** rderose has joined #openstack-keystone | 17:06 | |
*** jorge_munoz has quit IRC | 17:09 | |
openstackgerrit | Tom Cocozzello proposed openstack/keystone: Allow Python 3 testing for `test_fernet_provider` https://review.openstack.org/297768 | 17:15 |
*** sigmavirus24 is now known as sigmavirus24_awa | 17:15 | |
*** timcline has quit IRC | 17:17 | |
*** timcline has joined #openstack-keystone | 17:18 | |
*** e0ne has quit IRC | 17:19 | |
*** timcline has quit IRC | 17:22 | |
*** jdennis has quit IRC | 17:32 | |
*** jsavak has joined #openstack-keystone | 17:44 | |
*** ayoung has quit IRC | 17:47 | |
*** jsavak has quit IRC | 17:48 | |
*** timcline has joined #openstack-keystone | 17:48 | |
*** jsavak has joined #openstack-keystone | 17:49 | |
*** timcline has quit IRC | 17:51 | |
*** timcline has joined #openstack-keystone | 17:51 | |
*** rderose has quit IRC | 17:52 | |
*** spzala has joined #openstack-keystone | 17:53 | |
*** rk4n has joined #openstack-keystone | 17:55 | |
*** spandhe has joined #openstack-keystone | 18:04 | |
*** jasonsb_ has quit IRC | 18:06 | |
*** sdake_ has joined #openstack-keystone | 18:07 | |
*** sdake has quit IRC | 18:08 | |
*** jorge_munoz has joined #openstack-keystone | 18:11 | |
*** daemontool has quit IRC | 18:12 | |
*** kyen has quit IRC | 18:14 | |
*** edmondsw has joined #openstack-keystone | 18:15 | |
*** pumarani__ has quit IRC | 18:15 | |
*** pushkaru has joined #openstack-keystone | 18:15 | |
dstanek | gmmaha: so the fix to devstack didn't actually work in all cases? | 18:18 |
gmmaha | dstanek: not sure about devstack.. my setup is a multinode openstack install and i ran into the same issue | 18:19 |
gmmaha | Just thought creating a new bug for the smae issue wasnt the best.. so added my comments to it | 18:20 |
*** pushkaru has quit IRC | 18:25 | |
dstanek | gmmaha: ah, i see. i think the resolution of that bug was that keystone isn't creating _member_ and that the deployment software should be doing it | 18:29 |
gmmaha | dstanek: but then if its an requirement that it needs to be created, why not just have it created by default? | 18:30 |
gmmaha | sorry just curious to understand the rationale behind needing that but not creating by default | 18:30 |
*** csoukup has joined #openstack-keystone | 18:32 | |
*** jorge_munoz has quit IRC | 18:33 | |
*** mylu has quit IRC | 18:33 | |
*** ayoung has joined #openstack-keystone | 18:34 | |
*** ChanServ sets mode: +v ayoung | 18:34 | |
*** mylu has joined #openstack-keystone | 18:36 | |
*** rk4n has quit IRC | 18:39 | |
*** rk4n has joined #openstack-keystone | 18:39 | |
*** jdennis has joined #openstack-keystone | 18:45 | |
*** jdennis has quit IRC | 18:47 | |
morgan | dstanek: _member_ was only used for migration purposes. New deployments shouldn't need it iirc. | 18:47 |
morgan | Unless outside software used it. / configs. Which case the deployment could create it. | 18:47 |
morgan | gmmaha: ^cc | 18:48 |
dstanek | morgan: yes, i believe that it what we discussed | 18:48 |
morgan | dstanek: so, SoCal is dry. :P | 18:48 |
gmmaha | morgan: aah .. | 18:49 |
gmmaha | this setup of mine is deploying master openstack using kolla.. | 18:49 |
gmmaha | so i am curious why i am running into the issue where i cannot create new projects/users from the admin account | 18:49 |
*** roxanaghe has quit IRC | 18:52 | |
*** jdennis has joined #openstack-keystone | 18:54 | |
*** sdake_ is now known as sdake | 18:56 | |
knikolla | should this be moved out of backlog and into ongoing? https://specs.openstack.org/openstack/keystone-specs/specs/backlog/ldap3.html | 19:01 |
*** jed56 has quit IRC | 19:03 | |
*** mylu has quit IRC | 19:03 | |
*** real56 has quit IRC | 19:06 | |
stevemar | lbragstad: hey, is dolphm around? | 19:14 |
lbragstad | stevemar nope he is on vacation today | 19:14 |
stevemar | lbragstad: ah okay | 19:14 |
stevemar | lbragstad: i wanted to talk mfa, can you can about that instead of him :P | 19:15 |
lbragstad | stevemar depends on the questions :0 | 19:15 |
lbragstad | what's up? | 19:15 |
stevemar | lbragstad: any plans for newton for MFA? | 19:15 |
stevemar | lbragstad: not just TOTP | 19:15 |
lbragstad | stevemar yeah - to the best of my knowledge I thought the plan was to make all auth plugins in keystone aware of the their authentication factor | 19:16 |
lbragstad | and then expose that through the API | 19:16 |
lbragstad | then subsequent work to oslo.policy could enforce operations to have a minimum number of authentication factors | 19:17 |
lbragstad | but the next step, now that totp is implemented, would be to make all the authentication plugins aware of what kind of authentication factor they represent | 19:17 |
stevemar | lbragstad: that last part sounds stretchy | 19:17 |
lbragstad | I thought that was up-to-bat for N | 19:17 |
lbragstad | stevemar I wouldn't expect the oslo.policy stuff to land until o | 19:18 |
stevemar | lbragstad: y'all have notes on this stuff? | 19:18 |
lbragstad | stevemar yeah it was written up in a spec somewhere | 19:18 |
stevemar | lbragstad: wouldn't it also depends on where the user comes from? | 19:18 |
stevemar | lbragstad: oh right, we broke up the spec into 4 pieces didn't we | 19:19 |
stevemar | i forgot about that | 19:19 |
lbragstad | stevemar yeah - the entire MFA idea is strung across several specs | 19:19 |
stevemar | right right | 19:19 |
lbragstad | stevemar these were my notes on it https://review.openstack.org/#/c/272287/5/specs/backlog/multifactor-authentication.rst | 19:19 |
patchbot | lbragstad: patch 272287 - keystone-specs - Add spec for multifactor authentication | 19:19 |
*** e0ne has joined #openstack-keystone | 19:20 | |
lbragstad | stevemar that spec only details exposing the factors through the API | 19:20 |
lbragstad | stevemar how we want to "enforce" multifactor after that is still a discussion worth having | 19:20 |
lbragstad | because there are probably a few different ways we could do that | 19:21 |
lbragstad | enforcing in oslo.policy is just one of them | 19:21 |
lbragstad | which is the example in the spec at line #85 | 19:22 |
lbragstad | stevemar is that a topic we want to put on the discussion board for the summit | 19:25 |
lbragstad | ? | 19:25 |
dstanek | lbragstad: i think it would a good idea | 19:26 |
lbragstad | I'd definitely want to hear what the oslo folks think about enforcing it in oslo.policy | 19:26 |
*** spzala has quit IRC | 19:27 | |
stevemar | lbragstad: you betcha | 19:32 |
*** spzala has joined #openstack-keystone | 19:35 | |
stevemar | lbragstad: so i'm wondering how much support for 'mfa' we can state now, given that totp is merged | 19:35 |
stevemar | we need client and auth support | 19:35 |
stevemar | but there's nothing that actually uses it now? could i enable totp with horizon now? | 19:36 |
stevemar | (just talking aloud) | 19:36 |
*** lhcheng has joined #openstack-keystone | 19:36 | |
*** spzala has quit IRC | 19:38 | |
*** spzala has joined #openstack-keystone | 19:38 | |
openstackgerrit | Alexander Makarov proposed openstack/keystoneauth: Examples for migration from keystoneclient https://review.openstack.org/297764 | 19:41 |
*** gyee has quit IRC | 19:42 | |
*** e0ne has quit IRC | 19:44 | |
*** e0ne has joined #openstack-keystone | 19:46 | |
dstanek | stevemar: did the client support not merge? | 19:52 |
*** mylu has joined #openstack-keystone | 20:00 | |
openstackgerrit | Tom Cocozzello proposed openstack/keystone: WIP Allow Python 3 testing for `test_fernet_provider` https://review.openstack.org/297768 | 20:01 |
dstanek | tjcocozz: take a look at https://review.openstack.org/#/c/207526 and see if any of that stuff still needs to be done | 20:05 |
dstanek | tjcocozz: i'm going to abandon it in favor of your review | 20:07 |
tjcocozz | dstanek, preasure is on. haha can you give the low down on what bug you were hitting? | 20:08 |
*** pushkaru has joined #openstack-keystone | 20:08 | |
*** spzala has quit IRC | 20:09 | |
tjcocozz | dstanek, thanks for the heads up i will take a look! | 20:10 |
dstanek | tjcocozz: no bug. the the that concerns me about you patch is that i want to make sure that the source of the data is the same type and not just type check in order to make the tests pass | 20:10 |
tjcocozz | dstanek, that is my exact concern. Which is why they are wip. I am getting different results when running these test: https://review.openstack.org/#/c/294797/ then the tests in the patch above | 20:12 |
patchbot | tjcocozz: patch 294797 - keystone - Run federation tests under Python 3 | 20:12 |
*** spzala has joined #openstack-keystone | 20:13 | |
*** sdake_ has joined #openstack-keystone | 20:14 | |
*** e0ne has quit IRC | 20:14 | |
*** tqtran has joined #openstack-keystone | 20:14 | |
tjcocozz | dstanek, i am going to add more tests. I am assuming the tests are trying to test the correct functionality, i couldn't find anyother way of working around the problem i was facing when i was hitting bytes then to type check. do you have a different sudgestion? or are you saying in production i probably won't be hitting it as bytes? | 20:15 |
*** sdake has quit IRC | 20:17 | |
*** jorge_munoz has joined #openstack-keystone | 20:18 | |
*** spzala has quit IRC | 20:18 | |
tjcocozz | dstanek, lets talk more on monday. have a good weekend :) | 20:19 |
*** rdo has joined #openstack-keystone | 20:19 | |
dstanek | tjcocozz: i'll be on vacation Monday! | 20:20 |
dstanek | tjcocozz: i'm wondering if the data itself needs to be different. why is it bytes when it gets to that point? | 20:21 |
*** spzala has joined #openstack-keystone | 20:21 | |
dstanek | tjcocozz: maybe something can be done to always make it bytes? | 20:21 |
dstanek | on the other hand, i haven't looked into your patch other than a quick glance so that may be the best place for it | 20:21 |
*** roxanaghe has joined #openstack-keystone | 20:22 | |
*** spzala has quit IRC | 20:26 | |
*** spzala has joined #openstack-keystone | 20:27 | |
*** spzala has quit IRC | 20:31 | |
*** spzala has joined #openstack-keystone | 20:33 | |
*** jaugustine has quit IRC | 20:34 | |
*** spzala has quit IRC | 20:37 | |
*** spzala has joined #openstack-keystone | 20:38 | |
*** spzala has quit IRC | 20:43 | |
*** ebalduf has quit IRC | 20:43 | |
*** spzala has joined #openstack-keystone | 20:47 | |
*** spzala has quit IRC | 20:47 | |
*** spzala has joined #openstack-keystone | 20:48 | |
*** spzala has quit IRC | 20:49 | |
*** spzala has joined #openstack-keystone | 20:52 | |
*** spzala has quit IRC | 20:56 | |
*** dan_nguyen has quit IRC | 21:01 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone: WIP - ldap3 Identity Driver https://review.openstack.org/296090 | 21:05 |
*** david-lyle_ has joined #openstack-keystone | 21:08 | |
*** david-lyle has quit IRC | 21:08 | |
*** david-lyle has joined #openstack-keystone | 21:13 | |
*** pushkaru has quit IRC | 21:14 | |
*** pumarani__ has joined #openstack-keystone | 21:14 | |
*** david-lyle_ has quit IRC | 21:14 | |
*** spzala has joined #openstack-keystone | 21:15 | |
stevemar | dstanek: i didn't think so? | 21:17 |
stevemar | dstanek: nope: https://review.openstack.org/#/c/281086/ | 21:19 |
patchbot | stevemar: patch 281086 - keystoneauth - Support TOTP auth plugin | 21:19 |
*** jorge_munoz has quit IRC | 21:19 | |
*** spzala has quit IRC | 21:20 | |
*** dan_nguyen has joined #openstack-keystone | 21:26 | |
*** timcline has quit IRC | 21:33 | |
*** jsavak has quit IRC | 21:34 | |
*** sdake has joined #openstack-keystone | 21:41 | |
*** sdake_ has quit IRC | 21:44 | |
*** roxanaghe has quit IRC | 21:44 | |
*** roxanaghe has joined #openstack-keystone | 21:47 | |
*** slberger has left #openstack-keystone | 21:55 | |
*** mylu has quit IRC | 21:59 | |
*** lhcheng has quit IRC | 22:02 | |
*** ninag has quit IRC | 22:03 | |
*** lhcheng has joined #openstack-keystone | 22:08 | |
*** agrebennikov has quit IRC | 22:13 | |
openstackgerrit | Merged openstack/keystone: Simplify repetitive unequal checks https://review.openstack.org/281305 | 22:20 |
*** markvoelker has quit IRC | 22:21 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Correct _populate_default_domain in tests https://review.openstack.org/297879 | 22:27 |
*** dan_nguyen has quit IRC | 22:27 | |
*** fawadkhaliq has joined #openstack-keystone | 22:33 | |
dstanek | stevemar: that's unfortunate | 22:36 |
*** sheel has quit IRC | 22:37 | |
*** dan_nguyen has joined #openstack-keystone | 22:41 | |
*** pumarani__ has quit IRC | 22:42 | |
stevemar | dstanek: no time like the present for another review! | 22:43 |
dstanek | stevemar: that's what i was thinking | 22:44 |
*** sdake_ has joined #openstack-keystone | 22:44 | |
*** diazjf has quit IRC | 22:45 | |
stevemar | dstanek: i'm still not clear on how we're going to enable mfa for folks | 22:45 |
dstanek | stevemar: what do you mean? | 22:46 |
stevemar | dstanek: i guess the shadowed user will have another attribute (mfa-enabled) that they can enable in settings... | 22:46 |
dstanek | stevemar: ah i see what you mean. in my test deployment any user was allowed to use mfa | 22:46 |
stevemar | dstanek: i guess, if i'm a deployer, how can i take advantage of totp today | 22:46 |
stevemar | maybe i should re-read the spec :) | 22:47 |
*** sdake has quit IRC | 22:47 | |
dstanek | stevemar: you just enable the totp auth method | 22:48 |
dstanek | if you just take your existing keystone deployment and add a shared secret for the user, they could use google authenticator to get a token from keystone | 22:49 |
stevemar | dstanek: right, that's just logging in once (with your google authenticator) and you get your token | 22:50 |
stevemar | theres no multi-login / mfa yet | 22:50 |
stevemar | *yet* | 22:51 |
stevemar | i feel awful today, i should just stop while i'm ahead | 22:52 |
*** fawadkhaliq has quit IRC | 22:53 | |
*** mylu has joined #openstack-keystone | 22:54 | |
*** pushkaru has joined #openstack-keystone | 22:56 | |
*** fawadkhaliq has joined #openstack-keystone | 22:56 | |
*** mylu has quit IRC | 22:59 | |
*** pushkaru has quit IRC | 23:01 | |
*** pushkaru has joined #openstack-keystone | 23:02 | |
*** fawadkhaliq has quit IRC | 23:05 | |
*** agrebennikov has joined #openstack-keystone | 23:06 | |
*** csoukup has quit IRC | 23:06 | |
*** browne has quit IRC | 23:07 | |
*** mylu has joined #openstack-keystone | 23:12 | |
*** fawadkhaliq has joined #openstack-keystone | 23:12 | |
*** fawadkhaliq has quit IRC | 23:12 | |
*** fawadkhaliq has joined #openstack-keystone | 23:13 | |
*** lhcheng has quit IRC | 23:14 | |
*** knikolla has quit IRC | 23:18 | |
*** markvoelker has joined #openstack-keystone | 23:21 | |
*** spandhe has quit IRC | 23:21 | |
*** lhcheng has joined #openstack-keystone | 23:24 | |
*** lhcheng has quit IRC | 23:24 | |
*** dhellmann has quit IRC | 23:24 | |
*** lhcheng has joined #openstack-keystone | 23:24 | |
*** pushkaru has quit IRC | 23:25 | |
*** fawadkhaliq has quit IRC | 23:26 | |
*** markvoelker has quit IRC | 23:26 | |
*** fawadkhaliq has joined #openstack-keystone | 23:26 | |
*** rderose has joined #openstack-keystone | 23:30 | |
*** lhcheng has quit IRC | 23:34 | |
dstanek | stevemar: yeah, mfa in on the roadmap for N i think | 23:40 |
*** fawadkhaliq has quit IRC | 23:41 | |
*** fawadkhaliq has joined #openstack-keystone | 23:41 | |
*** edmondsw has quit IRC | 23:45 | |
*** fawadkhaliq has quit IRC | 23:47 | |
*** fawadkhaliq has joined #openstack-keystone | 23:47 | |
*** hockeynut has quit IRC | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!