*** sdake_ has joined #openstack-keystone | 00:02 | |
*** jrist has quit IRC | 00:16 | |
*** ayoung has joined #openstack-keystone | 00:20 | |
*** ChanServ sets mode: +v ayoung | 00:20 | |
*** jrist has joined #openstack-keystone | 00:21 | |
*** agrebennikov has joined #openstack-keystone | 00:22 | |
*** david-lyle has quit IRC | 00:25 | |
*** david-lyle has joined #openstack-keystone | 00:26 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password strength requirements https://review.openstack.org/320586 | 00:29 |
---|---|---|
*** david-lyle has quit IRC | 00:30 | |
*** raddaoui has quit IRC | 00:37 | |
*** dan_nguyen has quit IRC | 00:39 | |
*** markvoelker has joined #openstack-keystone | 00:40 | |
*** tqtran has quit IRC | 00:46 | |
*** edtubill has joined #openstack-keystone | 00:52 | |
*** dan_nguyen has joined #openstack-keystone | 01:05 | |
*** dan_nguyen has quit IRC | 01:08 | |
*** browne has quit IRC | 01:10 | |
*** spandhe has left #openstack-keystone | 01:17 | |
*** adu has quit IRC | 01:23 | |
*** rderose has quit IRC | 01:25 | |
*** clenimar has quit IRC | 01:29 | |
*** adu has joined #openstack-keystone | 01:29 | |
*** EinstCrazy has joined #openstack-keystone | 01:29 | |
*** clenimar has joined #openstack-keystone | 01:30 | |
openstackgerrit | Merged openstack/keystone: Update man page for Newton release https://review.openstack.org/324891 | 01:38 |
*** dan_nguyen has joined #openstack-keystone | 01:41 | |
*** clenimar has quit IRC | 01:46 | |
*** woodster_ has quit IRC | 01:48 | |
*** KarthikB has joined #openstack-keystone | 01:49 | |
*** lhcheng has joined #openstack-keystone | 01:51 | |
*** ChanServ sets mode: +v lhcheng | 01:51 | |
*** roxanaghe has joined #openstack-keystone | 01:54 | |
*** frontrunner has quit IRC | 01:55 | |
*** edtubill has quit IRC | 01:56 | |
*** sheel has joined #openstack-keystone | 01:57 | |
*** roxanaghe has quit IRC | 01:58 | |
*** edtubill has joined #openstack-keystone | 02:00 | |
*** edtubill has quit IRC | 02:04 | |
*** clenimar has joined #openstack-keystone | 02:05 | |
*** pushkaru has joined #openstack-keystone | 02:08 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Refactor to allow for service provider caching https://review.openstack.org/298748 | 02:11 |
lbragstad | bknudson ^ that's rebased and passing tests locally - let me know if that speeds up your test results | 02:12 |
*** browne has joined #openstack-keystone | 02:13 | |
bknudson | lbragstad: I'll have to try running the tests on master. | 02:14 |
lbragstad | cool | 02:16 |
*** frontrunner has joined #openstack-keystone | 02:19 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/324829 | 02:21 |
*** agrebennikov has quit IRC | 02:26 | |
stevemar | theres a cinder v3? https://github.com/openstack/python-cinderclient/tree/master/cinderclient/v3 | 02:27 |
bknudson | they're copying us. | 02:29 |
*** pushkaru has quit IRC | 02:36 | |
*** gyee has quit IRC | 02:36 | |
*** KarthikB_ has joined #openstack-keystone | 02:46 | |
*** KarthikB has quit IRC | 02:49 | |
*** r-daneel has quit IRC | 02:53 | |
openstackgerrit | Merged openstack/keystoneauth: Updated from global requirements https://review.openstack.org/324830 | 02:58 |
notmorgan | bknudson: shhh | 03:00 |
notmorgan | :P | 03:00 |
*** KarthikB_ has quit IRC | 03:13 | |
*** richm has quit IRC | 03:23 | |
*** frontrunner has quit IRC | 03:28 | |
*** timonwong has joined #openstack-keystone | 03:30 | |
*** jamielennox is now known as jamielennox|away | 03:39 | |
stevemar | notmorgan: bknudson didn't even know it was a thing yet | 03:40 |
stevemar | kinda upset they didn't put the v3 commands in osc | 03:40 |
stevemar | notmorgan: bknudson got a minute for https://review.openstack.org/#/c/274400/ ? | 03:41 |
patchbot | stevemar: patch 274400 - keystonemiddleware - Use extras for oslo.messaging dependency | 03:41 |
*** diazjf has joined #openstack-keystone | 03:42 | |
*** markvoelker has quit IRC | 03:44 | |
*** dan_nguyen has quit IRC | 03:48 | |
*** adu has quit IRC | 03:52 | |
*** roxanaghe has joined #openstack-keystone | 03:55 | |
*** roxanaghe has quit IRC | 04:00 | |
*** ebalduf_ has joined #openstack-keystone | 04:09 | |
notmorgan | stevemar: post dinner | 04:13 |
notmorgan | will look | 04:14 |
stevemar | notmorgan: i forget how late you eat | 04:14 |
notmorgan | stevemar: also in seattle was havong dribks with jill earlier | 04:14 |
notmorgan | dry aged ribeye omg | 04:14 |
*** abhishekk has left #openstack-keystone | 04:16 | |
*** ayoung has quit IRC | 04:20 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Refactor to allow for service provider caching https://review.openstack.org/298748 | 04:20 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Refactor revoke_model to remove circular dependency https://review.openstack.org/325033 | 04:20 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Cache service providers https://review.openstack.org/298748 | 04:21 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Cache service providers on token validation https://review.openstack.org/298748 | 04:21 |
stevemar | lbragstad: yay | 04:23 |
stevemar | lbragstad: yay for breaking it up | 04:23 |
lbragstad | stevemar yeah - makes sense | 04:23 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Cache service providers on token validation https://review.openstack.org/298748 | 04:36 |
*** links has joined #openstack-keystone | 04:38 | |
*** markvoelker has joined #openstack-keystone | 04:44 | |
*** dave-mccowan has quit IRC | 04:47 | |
*** markvoelker has quit IRC | 04:49 | |
*** iurygregory_ has quit IRC | 04:53 | |
*** roxanaghe has joined #openstack-keystone | 04:56 | |
*** rcernin has joined #openstack-keystone | 04:58 | |
*** roxanaghe has quit IRC | 05:01 | |
*** ebalduf_ has quit IRC | 05:01 | |
*** timonwong has quit IRC | 05:01 | |
*** rcernin has quit IRC | 05:04 | |
*** adu has joined #openstack-keystone | 05:05 | |
*** diazjf has quit IRC | 05:08 | |
*** GB21 has joined #openstack-keystone | 05:30 | |
*** EinstCrazy has quit IRC | 05:41 | |
*** EinstCrazy has joined #openstack-keystone | 05:43 | |
*** rcernin has joined #openstack-keystone | 05:46 | |
*** EinstCra_ has joined #openstack-keystone | 05:47 | |
*** adu has quit IRC | 05:47 | |
*** EinstCrazy has quit IRC | 05:50 | |
*** adu has joined #openstack-keystone | 05:54 | |
*** lhcheng has quit IRC | 05:56 | |
*** agrebennikov has joined #openstack-keystone | 06:00 | |
*** agrebennikov has quit IRC | 06:06 | |
*** openstackgerrit has quit IRC | 06:17 | |
*** openstackgerrit has joined #openstack-keystone | 06:17 | |
*** agrebennikov has joined #openstack-keystone | 06:20 | |
*** lmiccini has quit IRC | 06:29 | |
*** lmiccini has joined #openstack-keystone | 06:32 | |
*** harlowja has quit IRC | 06:35 | |
*** agrebennikov has quit IRC | 06:35 | |
*** adu has quit IRC | 06:37 | |
*** browne has quit IRC | 06:37 | |
*** markvoelker has joined #openstack-keystone | 06:45 | |
*** agrebennikov has joined #openstack-keystone | 06:52 | |
*** EinstCra_ has quit IRC | 06:54 | |
*** EinstCrazy has joined #openstack-keystone | 06:54 | |
*** roxanaghe has joined #openstack-keystone | 06:57 | |
*** markvoelker has quit IRC | 06:58 | |
*** EinstCrazy has quit IRC | 06:58 | |
*** EinstCrazy has joined #openstack-keystone | 06:58 | |
*** roxanaghe has quit IRC | 07:01 | |
*** openstackgerrit has quit IRC | 07:03 | |
*** openstackgerrit has joined #openstack-keystone | 07:03 | |
*** EinstCrazy has quit IRC | 07:08 | |
*** EinstCrazy has joined #openstack-keystone | 07:08 | |
*** mou has joined #openstack-keystone | 07:09 | |
openstackgerrit | Ryosuke Mizuno proposed openstack/keystone: Add validation rules for create token https://review.openstack.org/325086 | 07:11 |
*** agrebennikov has quit IRC | 07:15 | |
*** jistr is now known as jistr|mtg | 07:22 | |
*** EinstCrazy has quit IRC | 07:22 | |
*** EinstCrazy has joined #openstack-keystone | 07:23 | |
*** EinstCra_ has joined #openstack-keystone | 07:27 | |
*** EinstCrazy has quit IRC | 07:27 | |
*** EinstCra_ has quit IRC | 07:32 | |
*** EinstCrazy has joined #openstack-keystone | 07:33 | |
*** clenimar has quit IRC | 07:39 | |
*** lhcheng has joined #openstack-keystone | 07:44 | |
*** ChanServ sets mode: +v lhcheng | 07:44 | |
*** lhcheng has quit IRC | 07:49 | |
*** roxanaghe has joined #openstack-keystone | 07:50 | |
*** EinstCrazy has quit IRC | 07:51 | |
*** roxanaghe has quit IRC | 07:53 | |
*** nikhil has quit IRC | 07:58 | |
*** jed56 has quit IRC | 07:58 | |
*** tpeoples has quit IRC | 07:58 | |
*** auggy has quit IRC | 07:58 | |
*** zzzeek has quit IRC | 08:00 | |
*** EinstCrazy has joined #openstack-keystone | 08:01 | |
*** zzzeek has joined #openstack-keystone | 08:01 | |
*** henrynash has joined #openstack-keystone | 08:02 | |
*** ChanServ sets mode: +v henrynash | 08:02 | |
*** sdake_ has quit IRC | 08:03 | |
*** TxGVNN has joined #openstack-keystone | 08:03 | |
*** TxGVNN has quit IRC | 08:05 | |
*** daemontool has joined #openstack-keystone | 08:06 | |
*** permalac has joined #openstack-keystone | 08:08 | |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 08:10 |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 08:10 |
*** fesp has joined #openstack-keystone | 08:10 | |
*** pnavarro has joined #openstack-keystone | 08:11 | |
*** fesp has quit IRC | 08:16 | |
openstackgerrit | henry-nash proposed openstack/keystone-specs: Relax the project name uniqueness constraints https://review.openstack.org/310048 | 08:25 |
*** rdo has joined #openstack-keystone | 08:35 | |
*** mou1 has joined #openstack-keystone | 08:36 | |
*** BrAsS_mO- has joined #openstack-keystone | 08:38 | |
*** briancli1e has joined #openstack-keystone | 08:38 | |
*** daemontool has quit IRC | 08:38 | |
*** johnthetubaguy has quit IRC | 08:39 | |
*** bradjones has quit IRC | 08:39 | |
*** mou has quit IRC | 08:39 | |
*** briancline has quit IRC | 08:39 | |
*** amakarov_away has quit IRC | 08:39 | |
*** arunkant has quit IRC | 08:39 | |
*** BrAsS_mOnKeY has quit IRC | 08:39 | |
*** tonyb has quit IRC | 08:39 | |
*** jdennis has quit IRC | 08:39 | |
*** tonyb has joined #openstack-keystone | 08:39 | |
*** johnthetubaguy has joined #openstack-keystone | 08:39 | |
*** jdennis1 has joined #openstack-keystone | 08:39 | |
*** bradjones has joined #openstack-keystone | 08:39 | |
*** bradjones has quit IRC | 08:39 | |
*** bradjones has joined #openstack-keystone | 08:39 | |
*** amakarov_away has joined #openstack-keystone | 08:40 | |
hugokuo | Hi guys, I'm testing Keystone PKI with Swift. But keep get 401. Here's the verbose logs from authtoken middleware. https://gist.github.com/HugoKuo/2b619a5c20147f8e83cf9b7d79e867ba | 08:40 |
*** arunkant has joined #openstack-keystone | 08:41 | |
hugokuo | The swift-proxy service user is root. it suppose not the permission problem of the signing directory from my understanding. | 08:41 |
hugokuo | Keystone middleware version - 1.5.0.3-5~trusty | 08:42 |
*** jistr|mtg is now known as jistr | 08:43 | |
openstackgerrit | henry-nash proposed openstack/keystone-specs: Support hierarchical project naming https://review.openstack.org/318605 | 08:44 |
*** jaosorior has joined #openstack-keystone | 08:51 | |
*** roxanaghe has joined #openstack-keystone | 08:51 | |
hugokuo | and where can I find the milestone of Keystone Middleware ? | 08:53 |
*** samueldmq has joined #openstack-keystone | 08:55 | |
*** ChanServ sets mode: +v samueldmq | 08:55 | |
*** roxanaghe has quit IRC | 08:56 | |
*** EinstCrazy has quit IRC | 09:03 | |
*** rk4n has joined #openstack-keystone | 09:03 | |
*** EinstCrazy has joined #openstack-keystone | 09:05 | |
*** tpeoples has joined #openstack-keystone | 09:08 | |
*** jed56 has joined #openstack-keystone | 09:11 | |
*** auggy has joined #openstack-keystone | 09:12 | |
*** rk4n has quit IRC | 09:14 | |
*** nikhil_ has joined #openstack-keystone | 09:17 | |
*** nikhil_ is now known as Guest27231 | 09:17 | |
*** jaosorior has quit IRC | 09:21 | |
*** fhubik has joined #openstack-keystone | 09:25 | |
*** jaosorior has joined #openstack-keystone | 09:26 | |
*** rcernin is now known as rcernin|lunch | 09:31 | |
-openstackstatus- NOTICE: CI is experiencing issues with test logs, all jobs are currently UNSTABLE as a result. No need to recheck until this is fixed! Thanks for your patience. | 09:37 | |
*** pcaruana has joined #openstack-keystone | 09:44 | |
*** roxanaghe has joined #openstack-keystone | 09:52 | |
*** roxanaghe has quit IRC | 09:56 | |
*** charz_ has joined #openstack-keystone | 09:59 | |
*** frickler has quit IRC | 10:01 | |
*** hogepodge has quit IRC | 10:01 | |
*** charz has quit IRC | 10:01 | |
*** jed56 has quit IRC | 10:02 | |
*** auggy has quit IRC | 10:02 | |
*** tpeoples has quit IRC | 10:02 | |
*** Guest27231 has quit IRC | 10:02 | |
*** frickler has joined #openstack-keystone | 10:03 | |
*** mvk_ has joined #openstack-keystone | 10:05 | |
*** mvk has quit IRC | 10:07 | |
-openstackstatus- NOTICE: CI is experiencing issues with test logs, all jobs are currently UNSTABLE as a result. No need to recheck until this is fixed! Thanks for your patience. | 10:08 | |
*** ChanServ changes topic to "CI is experiencing issues with test logs, all jobs are currently UNSTABLE as a result. No need to recheck until this is fixed! Thanks for your patience." | 10:08 | |
*** mvk_ has quit IRC | 10:12 | |
*** mvk_ has joined #openstack-keystone | 10:13 | |
*** jaosorior has quit IRC | 10:16 | |
*** samueldmq has quit IRC | 10:16 | |
*** rdo has quit IRC | 10:16 | |
*** permalac has quit IRC | 10:16 | |
*** henrynash has quit IRC | 10:16 | |
*** GB21 has quit IRC | 10:16 | |
*** henrynash_ is now known as henrynash | 10:16 | |
*** rcernin|lunch is now known as rcernin | 10:20 | |
*** Trident has quit IRC | 10:24 | |
*** ChanServ sets mode: +v henrynash | 10:24 | |
*** nisha has joined #openstack-keystone | 10:26 | |
*** nisha has quit IRC | 10:27 | |
*** EinstCrazy has quit IRC | 10:30 | |
*** tpeoples has joined #openstack-keystone | 10:32 | |
*** jaosorior has joined #openstack-keystone | 10:34 | |
*** jed56 has joined #openstack-keystone | 10:35 | |
*** auggy has joined #openstack-keystone | 10:36 | |
*** Guest27231 has joined #openstack-keystone | 10:41 | |
*** Trident has joined #openstack-keystone | 10:43 | |
*** permalac has joined #openstack-keystone | 10:45 | |
*** hogepodge has joined #openstack-keystone | 10:49 | |
*** samueldmq has joined #openstack-keystone | 10:49 | |
*** rdo has joined #openstack-keystone | 10:49 | |
*** orwell.freenode.net sets mode: +v samueldmq | 10:49 | |
*** orwell.freenode.net changes topic to "Newton Deadlines: http://releases.openstack.org/newton/schedule.html | Keystone Midcycle RSVP: http://goo.gl/forms/NfFMpJe6MSCXSNhr2 (Hosted By Cicso, July 20-22, 170 W Tasman Dr, San Jose, CA 95134) | Keystone Midcycle wiki https://wiki.openstack.org/wiki/Sprints/KeystoneNewtonSprint" | 10:49 | |
*** ChanServ changes topic to "CI is experiencing issues with test logs, all jobs are currently UNSTABLE as a result. No need to recheck until this is fixed! Thanks for your patience." | 10:49 | |
*** roxanaghe has joined #openstack-keystone | 10:53 | |
*** GB21 has joined #openstack-keystone | 10:53 | |
*** markvoelker has joined #openstack-keystone | 10:55 | |
*** roxanaghe has quit IRC | 10:57 | |
*** amakarov_away is now known as amakarov | 10:58 | |
*** markvoelker has quit IRC | 11:00 | |
*** raildo-afk is now known as raildo | 11:02 | |
*** GB21 has quit IRC | 11:19 | |
*** gordc has joined #openstack-keystone | 11:29 | |
*** tesseract has joined #openstack-keystone | 11:33 | |
*** d0ugal has quit IRC | 11:34 | |
*** gordc has quit IRC | 11:39 | |
*** gordc has joined #openstack-keystone | 11:40 | |
-openstackstatus- NOTICE: CI is experiencing issues with test logs, all jobs are currently UNSTABLE as a result. No need to recheck until this is fixed! Thanks for your patience. | 11:41 | |
*** gordc has quit IRC | 11:43 | |
*** pcaruana has quit IRC | 11:45 | |
*** roxanaghe has joined #openstack-keystone | 11:54 | |
*** gordc has joined #openstack-keystone | 11:55 | |
*** roxanaghe has quit IRC | 11:59 | |
*** GB21 has joined #openstack-keystone | 11:59 | |
openstackgerrit | Mikhail Nikolaenko proposed openstack/keystone-specs: WIP - Alternative policy enforcement https://review.openstack.org/323791 | 12:05 |
openstackgerrit | Mikhail Nikolaenko proposed openstack/keystone-specs: WIP - Alternative policy enforcement https://review.openstack.org/323791 | 12:09 |
*** GB21 has quit IRC | 12:10 | |
*** markvoelker has joined #openstack-keystone | 12:11 | |
*** markvoelker has quit IRC | 12:15 | |
*** markvoelker has joined #openstack-keystone | 12:16 | |
*** daemontool has joined #openstack-keystone | 12:16 | |
*** frontrunner has joined #openstack-keystone | 12:25 | |
*** julim has joined #openstack-keystone | 12:36 | |
*** EinstCrazy has joined #openstack-keystone | 12:37 | |
*** iurygregory has quit IRC | 12:42 | |
*** dave-mccowan has joined #openstack-keystone | 12:44 | |
*** clenimar has joined #openstack-keystone | 12:47 | |
*** iurygregory has joined #openstack-keystone | 12:47 | |
*** sdake has joined #openstack-keystone | 12:49 | |
*** daemontool has quit IRC | 12:50 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Sample commit to demonstrate dev workflow at SBRC https://review.openstack.org/325272 | 12:50 |
*** clenimar has quit IRC | 12:54 | |
*** roxanaghe has joined #openstack-keystone | 12:54 | |
*** d0ugal has joined #openstack-keystone | 12:55 | |
*** EinstCrazy has quit IRC | 12:56 | |
*** tonytan4ever has quit IRC | 12:56 | |
*** mvk_ has quit IRC | 12:57 | |
*** roxanaghe has quit IRC | 12:59 | |
*** rodrigods has quit IRC | 12:59 | |
*** rodrigods has joined #openstack-keystone | 12:59 | |
*** EinstCrazy has joined #openstack-keystone | 13:02 | |
*** richm has joined #openstack-keystone | 13:04 | |
*** spzala has joined #openstack-keystone | 13:11 | |
*** zqfan has quit IRC | 13:13 | |
*** rderose has joined #openstack-keystone | 13:15 | |
*** daemontool has joined #openstack-keystone | 13:16 | |
*** TxGVNN has joined #openstack-keystone | 13:21 | |
*** tonytan4ever has joined #openstack-keystone | 13:26 | |
*** aurelien__ has joined #openstack-keystone | 13:28 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Add failed auth attempts logic to meet PCI-DSS https://review.openstack.org/324029 | 13:30 |
*** tonytan4ever has quit IRC | 13:31 | |
*** KarthikB has joined #openstack-keystone | 13:38 | |
*** KarthikB_ has joined #openstack-keystone | 13:40 | |
*** edmondsw has joined #openstack-keystone | 13:41 | |
*** KarthikB has quit IRC | 13:43 | |
*** pushkaru has joined #openstack-keystone | 13:43 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Test revocation race conditions https://review.openstack.org/227995 | 13:44 |
*** Guest27231 has quit IRC | 13:45 | |
*** Guest27231 has joined #openstack-keystone | 13:46 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone-specs: Fixes the versions in Federation API Spec https://review.openstack.org/325304 | 13:47 |
openstackgerrit | Dolph Mathews proposed openstack/keystone: PEP257: Ignore D203 because it was deprecated https://review.openstack.org/325305 | 13:48 |
*** Guest27231 is now known as nikhil | 13:48 | |
openstackgerrit | Dolph Mathews proposed openstack/keystonemiddleware: PEP257: Ignore D203 because it was deprecated https://review.openstack.org/325306 | 13:50 |
*** ametts has joined #openstack-keystone | 13:52 | |
openstackgerrit | Dolph Mathews proposed openstack/keystoneauth: PEP257: Ignore D203 because it was deprecated https://review.openstack.org/325307 | 13:52 |
knikolla | morning! o/ | 13:53 |
openstackgerrit | Dolph Mathews proposed openstack/python-keystoneclient: PEP257: Ignore D203 because it was deprecated https://review.openstack.org/325309 | 13:53 |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone-specs: Fix versions blocks in Federation API Spec https://review.openstack.org/325304 | 13:53 |
*** pauloewerton has joined #openstack-keystone | 13:55 | |
*** sheel has quit IRC | 13:55 | |
*** roxanaghe has joined #openstack-keystone | 13:55 | |
*** timcline has joined #openstack-keystone | 13:59 | |
*** roxanaghe has quit IRC | 13:59 | |
*** ChanServ changes topic to "Newton Deadlines: http://releases.openstack.org/newton/schedule.html | Keystone Midcycle RSVP: http://goo.gl/forms/NfFMpJe6MSCXSNhr2 (Hosted By Cicso, July 20-22, 170 W Tasman Dr, San Jose, CA 95134) | Keystone Midcycle wiki https://wiki.openstack.org/wiki/Sprints/KeystoneNewtonSprint" | 13:59 | |
-openstackstatus- NOTICE: Cleanup from earlier block storage disruption on static.openstack.org has been repaired, and any jobs which reported an "UNSTABLE" result or linked to missing logs between 08:00-14:00 UTC can be retriggered by leaving a "recheck" comment. | 14:00 | |
*** ayoung has joined #openstack-keystone | 14:00 | |
*** ChanServ sets mode: +v ayoung | 14:00 | |
*** pushkaru has quit IRC | 14:05 | |
*** KarthikB_ has quit IRC | 14:06 | |
openstackgerrit | Dolph Mathews proposed openstack/keystonemiddleware: Improve documentation for auth_uri https://review.openstack.org/310290 | 14:10 |
*** EinstCrazy has quit IRC | 14:11 | |
SamYaple | hey everyone. is this all of the identity API calls? http://developer.openstack.org/api-ref-identity-v3.html | 14:12 |
openstackgerrit | Merged openstack/keystone: Config settings to support PCI-DSS https://review.openstack.org/314679 | 14:13 |
SamYaple | the call /auth/domains and /auth/projects appear to be undocumented, and i dont see them listed there, though i can confirm they work correctly | 14:13 |
*** KarthikB has joined #openstack-keystone | 14:13 | |
*** EinstCrazy has joined #openstack-keystone | 14:14 | |
SamYaple | notmorgan: per our conversation yesterday im not sure a new api is needed since those provide enough information to parse in my opinion | 14:14 |
samueldmq | SamYaple: you may find updated docs at https://specs.openstack.org/openstack/keystone-specs/ | 14:15 |
samueldmq | https://specs.openstack.org/openstack/keystone-specs/#v3-api and https://specs.openstack.org/openstack/keystone-specs/#v2-0-api | 14:15 |
*** EinstCrazy has quit IRC | 14:15 | |
SamYaple | samueldmq: it is indeed listed there, but is that really the only place its "documented"? | 14:16 |
SamYaple | it references http://docs.openstack.org/api/openstack-identity/3/rel/auth_domains which is a dead link | 14:16 |
*** clenimar has joined #openstack-keystone | 14:18 | |
*** KarthikB has quit IRC | 14:19 | |
*** KarthikB has joined #openstack-keystone | 14:19 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:22 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone-specs: Complete RBAC in keystone https://review.openstack.org/325326 | 14:23 |
*** KarthikB has quit IRC | 14:24 | |
*** r-daneel has joined #openstack-keystone | 14:25 | |
breton | knikolla: hi! | 14:30 |
breton | so i tried the plugin | 14:30 |
*** KarthikB has joined #openstack-keystone | 14:30 | |
breton | and tried to modify it a little bit so that it could work with websso | 14:31 |
*** KarthikB_ has joined #openstack-keystone | 14:31 | |
breton | in fact, all changes i made was adding a new <LocationMatch /identity/v3/auth/OS-FEDERATION/websso/saml2> and changing list of trusted dashboards | 14:32 |
breton | and i am always getting "The request you have made requires authentication" | 14:32 |
breton | even after i have authenticated at the idp | 14:32 |
knikolla | breton: hmmm, did you point it to the right port? | 14:33 |
knikolla | breton: i think i've enabled mod_shib only for 5000 | 14:33 |
breton | knikolla: no ports at all. Keystone is not on /identity/. | 14:33 |
breton | i have changed that part and keystone redirects me to the idp | 14:34 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/325336 | 14:34 |
breton | *is now on | 14:34 |
breton | but after idp redirects me back, i get this | 14:34 |
breton | i think that it might have something to do with the mapping | 14:34 |
breton | or with REMOTE_USER | 14:34 |
*** KarthikB has quit IRC | 14:35 | |
*** KarthikB_ has quit IRC | 14:35 | |
knikolla | breton: it might, i've only really tested the setup with k2k. i'll give it a try with websso | 14:36 |
knikolla | what did you use as the idp? | 14:36 |
breton | knikolla: okta.com | 14:36 |
*** links has quit IRC | 14:36 | |
breton | knikolla: also, i was quite surprised to see REMOTE_USER in the config because of note on http://docs.openstack.org/security-guide/identity/federated-keystone.html (ctrl-f there for REMOTE_USER) | 14:36 |
knikolla | breton: it very well might be the issue, i'll scan through the docs and see what i'm doing differently | 14:38 |
knikolla | breton: thanks for trying it out. :) | 14:38 |
*** tonytan4ever has joined #openstack-keystone | 14:38 | |
*** lucas___ has joined #openstack-keystone | 14:42 | |
*** rcernin has quit IRC | 14:46 | |
*** mou1 has quit IRC | 14:46 | |
*** clenimar has quit IRC | 14:50 | |
*** pushkaru has joined #openstack-keystone | 14:50 | |
*** jaosorior has quit IRC | 14:52 | |
*** raddaoui has joined #openstack-keystone | 14:52 | |
*** raildo is now known as raildo-afk | 14:53 | |
*** KarthikB has joined #openstack-keystone | 14:55 | |
*** roxanaghe has joined #openstack-keystone | 14:56 | |
*** adu has joined #openstack-keystone | 14:58 | |
*** roxanaghe has quit IRC | 15:00 | |
breton | knikolla: oooh, i see what the problems is | 15:01 |
breton | knikolla: *problem | 15:01 |
breton | with "enable_service federation-sp" the mapping expects that k2k is in use | 15:02 |
knikolla | breton: riiiiight. mapping expects openstack_user attribute | 15:02 |
knikolla | breton: good find! | 15:03 |
knikolla | breton: we can have an ENV variable and set it for either k2k or federation and load the correct mapping | 15:04 |
knikolla | FEDERATION_MAPPING=k2k / generic (or something more specific) | 15:05 |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Bootstrap: enable and reset password for existing users https://review.openstack.org/325352 | 15:05 |
*** dan_nguyen has joined #openstack-keystone | 15:06 | |
breton | knikolla: yep, sounds good. Also i am wondering if we can have a variable to provide a path to the mapping. | 15:06 |
breton | as an alternative to k2k/generic | 15:06 |
knikolla | breton: that sounds good. k2k/generic/directly specify the path | 15:08 |
knikolla | breton: once you have a working mapping, can you please update the review with a new patchset? | 15:09 |
*** aurelien__ has quit IRC | 15:10 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Bootstrap: enable and reset password for existing users https://review.openstack.org/325352 | 15:11 |
*** KarthikB has quit IRC | 15:11 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Add failed auth attempts logic to meet PCI-DSS https://review.openstack.org/324029 | 15:11 |
breton | knikolla: i will. But it will probably be on the weekend or on Monday. | 15:12 |
knikolla | breton: sounds good, i'll update the patchset today with the logic to handle the new variable and then you can just upload the mapping.json for generic. | 15:13 |
*** dan_nguyen has quit IRC | 15:16 | |
dolphm | notmorgan: small amendment for bootstrap https://bugs.launchpad.net/keystone/+bug/1588860 | 15:17 |
openstack | Launchpad bug 1588860 in OpenStack Identity (keystone) mitaka "keystone-manage bootstrap cannot recover admin account" [Medium,In progress] - Assigned to Dolph Mathews (dolph) | 15:17 |
*** r-daneel has quit IRC | 15:18 | |
*** KarthikB has joined #openstack-keystone | 15:18 | |
*** pnavarro has quit IRC | 15:20 | |
notmorgan | dolphm: "recover" admin account? oh reset password? | 15:21 |
*** TxGVNN has quit IRC | 15:21 | |
*** KarthikB has quit IRC | 15:22 | |
*** apj has joined #openstack-keystone | 15:23 | |
dolphm | notmorgan: and enabled | 15:23 |
notmorgan | dolphm: added a comment, maybe we want a separate command? | 15:24 |
*** KarthikB has joined #openstack-keystone | 15:24 | |
notmorgan | dolphm: bootstrap is very narrow in what kind of user/placement of user it acts | 15:24 |
notmorgan | and requires a specific set of roles etc | 15:24 |
notmorgan | dolphm: but i'd be ok with adding it to bootstrap, just thinking about the use-case | 15:25 |
*** dan_nguyen has joined #openstack-keystone | 15:25 | |
dolphm | notmorgan: in this case, i imagine it being included in openstack ansible, for example, and called as part of the keystone role. i'd expect it to be idempotent and act as a recovery mechanism to steam roll over any silly manual changes that broke the operator | 15:27 |
*** woodster_ has joined #openstack-keystone | 15:27 | |
notmorgan | dolphm: hm. like i said, i'm good with it either way | 15:28 |
*** KarthikB has quit IRC | 15:28 | |
knikolla | dolphm: in the case of pci-dss not allowing to use the same password would it just skip the checks? | 15:30 |
notmorgan | knikolla: this would need to go around pci-dss. | 15:30 |
*** josecastroleon has quit IRC | 15:30 | |
*** KarthikB has joined #openstack-keystone | 15:30 | |
dolphm | knikolla: it's calling the administrative password reset API, not the self-service password change API... so yes, i'd expect it to circumvent password history checks | 15:31 |
notmorgan | knikolla: it is an adminstrative task. which even in pci land, can set password directly to an old value | 15:31 |
*** rcernin has joined #openstack-keystone | 15:31 | |
notmorgan | dolphm: ++ | 15:31 |
knikolla | dolphm: notmorgan: sounds good. just wanted to clarify. | 15:32 |
notmorgan | dolphm: so, minor complaint... but should be easy to fix | 15:33 |
notmorgan | will add comment | 15:33 |
dolphm | notmorgan: ack | 15:33 |
*** KarthikB has quit IRC | 15:34 | |
notmorgan | dolphm: oh wait nvm | 15:34 |
notmorgan | dolphm: i misread it. :P | 15:34 |
*** KarthikB has joined #openstack-keystone | 15:34 | |
*** ninag has joined #openstack-keystone | 15:34 | |
notmorgan | dolphm: yeah i'm fine with this as is. | 15:34 |
dolphm | notmorgan: sweet | 15:35 |
*** ninag has quit IRC | 15:35 | |
notmorgan | dolphm: +2 | 15:36 |
*** d0ugal has quit IRC | 15:39 | |
*** rcernin has quit IRC | 15:39 | |
stevemar | dolphm: when would the user's enabled field ever be not true if we're updating it to true? | 15:41 |
stevemar | line 227 | 15:42 |
*** KevinE has joined #openstack-keystone | 15:42 | |
*** KevinE has quit IRC | 15:42 | |
*** dan_nguyen has quit IRC | 15:43 | |
odyssey4me | stevemar sometimes people do stupid things, like lose their passwords or disable the admin user | 15:43 |
*** KevinE has joined #openstack-keystone | 15:43 | |
odyssey4me | things go wrong, and without the token back-end available there has to be some way of rectifying it without digging into the db | 15:44 |
stevemar | odyssey4me: oh i get the use case, just wondering how line 227 would ever be anything but true: https://review.openstack.org/#/c/325352/3/keystone/cmd/cli.py | 15:44 |
patchbot | stevemar: patch 325352 - keystone - Bootstrap: enable and reset password for existing ... | 15:44 |
*** KevinE has quit IRC | 15:44 | |
odyssey4me | I suppose it could be prudent to actually have an extra CLI flag or something that informs bootstrap to steam-roll over all the bootstrapped items... so that the endpoint, user, role, etc can all be steamrolled to get the admin back to a point that they can fix everything else? | 15:45 |
*** KevinE has joined #openstack-keystone | 15:45 | |
dolphm | stevemar: i could make that a bit more clear, but that's the OLD user reference, not the just-updated one | 15:45 |
stevemar | dolphm: oh wow, yeah | 15:46 |
dolphm | stevemar: i actually had was_enabled = user['enabled'] on ~L216 in a previous patch | 15:46 |
stevemar | dolphm: toss a comment in and i'll +2/+A :P | 15:46 |
dolphm | stevemar: comment or was_enabled? | 15:46 |
stevemar | dolphm: you decide | 15:46 |
dolphm | stevemar: both it is | 15:47 |
stevemar | i like both | 15:47 |
stevemar | :) | 15:47 |
*** josecastroleon has joined #openstack-keystone | 15:47 | |
*** apj has quit IRC | 15:47 | |
*** KarthikB has quit IRC | 15:48 | |
*** KarthikB has joined #openstack-keystone | 15:48 | |
stevemar | lbragstad: dolphm do we want to backport https://review.openstack.org/#/c/325033/1 and it's follow on? | 15:48 |
patchbot | stevemar: patch 325033 - keystone - Refactor revoke_model to remove circular dependency | 15:48 |
stevemar | henrynash: bknudson ^ | 15:49 |
bknudson | why backport it? | 15:49 |
stevemar | for all the performance ? | 15:49 |
bknudson | I don't know what the performance effect is. | 15:49 |
*** henrynash_ has joined #openstack-keystone | 15:49 | |
*** ChanServ sets mode: +v henrynash_ | 15:49 | |
bknudson | we don't do any performance testing | 15:49 |
stevemar | bknudson: oh the follow on has the perf improvement | 15:49 |
bknudson | I thought using caching would improve performance on liberty but it actually made the performance worse | 15:50 |
stevemar | bknudson: maybe rally should finally be part of the gate :P | 15:50 |
stevemar | =\ | 15:50 |
bknudson | rally is useless if it's run on virtual machines in different environments. | 15:50 |
dolphm | stevemar: thoughts? http://cdn.pasteraw.com/ulc3q3wfjratn6h0mfryl5vqbfsw6p | 15:50 |
stevemar | dolphm: ++ | 15:51 |
bknudson | but if somebody could set up a testing environment for performance that would be useful. We'll likely have one at some point. | 15:51 |
dolphm | bknudson: we've had one before, no one really cared | 15:51 |
dolphm | bknudson: we had a dedicated bare metal box running benchmarks every couple hours | 15:52 |
bknudson | dolphm: did it report on changes? | 15:52 |
bknudson | like post to gerrit | 15:52 |
*** lucas___ has quit IRC | 15:53 | |
dolphm | bknudson: no, it only tested master and showed performance variation of master over time | 15:53 |
*** KarthikB has quit IRC | 15:53 | |
dolphm | if someone wants to build a voting job, i'd run it on bare metal again | 15:53 |
bknudson | it would be interesting to see. | 15:54 |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Bootstrap: enable and reset password for existing users https://review.openstack.org/325352 | 15:54 |
bknudson | Do we need a job for it? I think you'd just post reviews like a normal user. | 15:54 |
*** KarthikB has joined #openstack-keystone | 15:54 | |
dolphm | stevemar: notmorgan: revised with better comments https://review.openstack.org/#/c/325352/ | 15:55 |
patchbot | dolphm: patch 325352 - keystone - Bootstrap: enable and reset password for existing ... | 15:55 |
*** lucas___ has joined #openstack-keystone | 15:55 | |
dolphm | bknudson: well something has to poll / listen to gerrit, queue up work, run tests, maintain state across runs, and vote appropriately | 15:56 |
notmorgan | dolphm: nit picking... can we not change the password if the password hasn't changed? | 15:56 |
*** lucas___ has quit IRC | 15:56 | |
*** lucas___ has joined #openstack-keystone | 15:56 | |
dolphm | notmorgan: how do we know what the user's current password is? | 15:56 |
*** roxanaghe has joined #openstack-keystone | 15:56 | |
notmorgan | dolphm: run the password through the crypt mechanism and compare the strings | 15:56 |
notmorgan | dolphm: we have deep internal access with bootstrap | 15:57 |
notmorgan | (in theory) | 15:57 |
notmorgan | maybe not worth it. | 15:57 |
openstackgerrit | Merged openstack/keystone: Refactor revoke_model to remove circular dependency https://review.openstack.org/325033 | 15:57 |
dolphm | notmorgan: you'll get a different salt | 15:58 |
dolphm | notmorgan: assuming you mean compare hashed strings | 15:58 |
notmorgan | dolphm: not if you're doing it as though you're authing. | 15:58 |
notmorgan | dolphm: but meh, total nitpicking it's fine as is. | 15:59 |
dolphm | notmorgan: would you just attempt to actually auth then? | 15:59 |
*** KarthikB has quit IRC | 15:59 | |
notmorgan | dolphm: could do that. | 15:59 |
dolphm | notmorgan: try: auth(); except: reset_password() + enable() | 15:59 |
notmorgan | dolphm: yeah, but like i said, not super important | 15:59 |
notmorgan | can be an addon if you feel up to it | 15:59 |
notmorgan | +2 as it sits imo | 15:59 |
dolphm | notmorgan: i was a little averse to calling auth() in bootstrap, only because i figured the logs & auditing would be weird | 15:59 |
*** KarthikB has joined #openstack-keystone | 15:59 | |
*** agrebennikov has joined #openstack-keystone | 16:00 | |
*** lucas___ has quit IRC | 16:01 | |
*** lucas___ has joined #openstack-keystone | 16:02 | |
*** fhubik has quit IRC | 16:04 | |
*** fhubik_brb has joined #openstack-keystone | 16:04 | |
*** fhubik_brb has quit IRC | 16:04 | |
*** clenimar has joined #openstack-keystone | 16:04 | |
*** lucas___ has quit IRC | 16:07 | |
stevemar | dolphm: they would be | 16:09 |
openstackgerrit | Merged openstack/keystone: Cache service providers on token validation https://review.openstack.org/298748 | 16:09 |
notmorgan | uhh | 16:10 |
notmorgan | lbragstad: ^ that patch is going to cause weird behavior | 16:10 |
lbragstad | notmorgan ? | 16:11 |
notmorgan | lbragstad: you are providing zero invalidations | 16:11 |
lbragstad | notmorgan btw i'm kicking off a devstack run to performance test it | 16:11 |
*** diazjf has joined #openstack-keystone | 16:11 | |
notmorgan | lbragstad: as in.. updates/changes/etc will NOT reflect changes | 16:11 |
notmorgan | lbragstad: that was the point of my -1. | 16:11 |
lbragstad | notmorgan true | 16:12 |
notmorgan | and it just got merged | 16:12 |
notmorgan | i'd revert it tbh | 16:12 |
notmorgan | or hurry up and get an invalidation in | 16:12 |
bknudson | lbragstad: I've been running my perf for validation tests on https://review.openstack.org/#/c/298748/ ... looks like there's some improvement. | 16:12 |
patchbot | bknudson: patch 298748 - keystone - Cache service providers on token validation (MERGED) | 16:12 |
bknudson | hard to tell though the perf test env isn't that consistent and the improvement is small. | 16:13 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone: Revert "Cache service providers on token validation" https://review.openstack.org/325391 | 16:13 |
notmorgan | lbragstad: ^ pick which way to approach this, but we're def. not testing this correctly either. | 16:14 |
notmorgan | lbragstad: i'll let you pick if revert or add another CR is the path you choose, but i'd like to see something proposed today if we're keeping it merged in. | 16:16 |
*** frontrunner has quit IRC | 16:17 | |
lbragstad | notmorgan yeah.. working on it now | 16:17 |
*** josecastroleon has quit IRC | 16:17 | |
*** woodburn has joined #openstack-keystone | 16:17 | |
*** dan_nguyen has joined #openstack-keystone | 16:17 | |
notmorgan | lbragstad: feel free to abandon that revert once your thing is proposed :) | 16:17 |
stevemar | dolphm: did you want to comment on https://review.openstack.org/#/c/325305/1 before i push it through? | 16:17 |
patchbot | stevemar: patch 325305 - keystone - PEP257: Ignore D203 because it was deprecated | 16:17 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/325336 | 16:18 |
*** woodburn has left #openstack-keystone | 16:19 | |
stevemar | who the pci option stuff was merged :O | 16:19 |
stevemar | i should really review that.. | 16:19 |
*** tesseract has quit IRC | 16:19 | |
dolphm | stevemar: done | 16:19 |
stevemar | rderose: why was lockout_duration given a non-zero default? | 16:20 |
stevemar | thanks dolphm | 16:20 |
dolphm | stevemar: https://review.openstack.org/#/q/Icc048b947acea8f655d00540c221123b906e7545,n,z | 16:21 |
rderose | stevemar: because it is only used if lockout is turned on | 16:21 |
rderose | stevemar: so if lockout is turned on, I think we should have a default duration | 16:21 |
stevemar | rderose: neato | 16:21 |
stevemar | dolphm: yeah, just approved them all | 16:21 |
stevemar | dolphm: didn't know you could have the same change-id across projects | 16:22 |
stevemar | TIL | 16:22 |
rderose | stevemar: you can review this one: https://review.openstack.org/#/c/320156/ :) | 16:22 |
patchbot | rderose: patch 320156 - keystone - PCI-DSS Change password requirements | 16:22 |
openstackgerrit | Merged openstack/keystone-specs: Fix versions blocks in Federation API Spec https://review.openstack.org/325304 | 16:23 |
dolphm | stevemar: they only have to be unique per branch per project | 16:23 |
*** lucas___ has joined #openstack-keystone | 16:24 | |
bknudson | if you have the same change-id then you can't use depends-on | 16:25 |
*** lucas___ has quit IRC | 16:26 | |
*** lucas___ has joined #openstack-keystone | 16:26 | |
*** lhcheng has joined #openstack-keystone | 16:29 | |
*** ChanServ sets mode: +v lhcheng | 16:29 | |
*** frontrunner has joined #openstack-keystone | 16:30 | |
*** sheel has joined #openstack-keystone | 16:30 | |
*** rcernin has joined #openstack-keystone | 16:31 | |
*** clenimar has quit IRC | 16:32 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password strength requirements https://review.openstack.org/320586 | 16:33 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password strength requirements https://review.openstack.org/320586 | 16:39 |
*** r-daneel has joined #openstack-keystone | 16:42 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password strength requirements https://review.openstack.org/320586 | 16:47 |
*** KarthikB has quit IRC | 16:53 | |
*** tonytan4ever has quit IRC | 16:53 | |
*** harlowja has joined #openstack-keystone | 16:55 | |
*** nkinder has quit IRC | 16:56 | |
*** nkinder has joined #openstack-keystone | 16:56 | |
*** KarthikB has joined #openstack-keystone | 16:59 | |
*** lucas___ has quit IRC | 17:00 | |
*** KarthikB has quit IRC | 17:04 | |
*** KarthikB has joined #openstack-keystone | 17:06 | |
notmorgan | bknudson: ++ | 17:09 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add cache invalidation for service providers https://review.openstack.org/325417 | 17:09 |
lbragstad | notmorgan ^ | 17:09 |
*** KarthikB has quit IRC | 17:11 | |
*** KarthikB has joined #openstack-keystone | 17:12 | |
notmorgan | lbragstad: inline comment, you're close | 17:13 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add cache invalidation for service providers https://review.openstack.org/325417 | 17:15 |
lbragstad | notmorgan done - i'm going to get a run in over lunch. feel free to tag team that patch if anyone else has comments while i'm out | 17:16 |
notmorgan | lbragstad: i have some other things i need to jump on today but ill keep poking at it as i can | 17:16 |
*** KarthikB has quit IRC | 17:17 | |
*** KarthikB has joined #openstack-keystone | 17:18 | |
*** KarthikB has quit IRC | 17:23 | |
*** KarthikB has joined #openstack-keystone | 17:25 | |
*** lhcheng has quit IRC | 17:25 | |
*** lhcheng has joined #openstack-keystone | 17:25 | |
*** ChanServ sets mode: +v lhcheng | 17:25 | |
openstackgerrit | Merged openstack/keystonemiddleware: PEP257: Ignore D203 because it was deprecated https://review.openstack.org/325306 | 17:26 |
*** spzala has quit IRC | 17:27 | |
*** spzala has joined #openstack-keystone | 17:27 | |
*** KarthikB has quit IRC | 17:29 | |
openstackgerrit | Merged openstack/python-keystoneclient: PEP257: Ignore D203 because it was deprecated https://review.openstack.org/325309 | 17:31 |
*** KarthikB has joined #openstack-keystone | 17:31 | |
*** spzala has quit IRC | 17:32 | |
*** notmorgan is now known as morgan | 17:32 | |
*** devananda is now known as deva | 17:32 | |
*** deva is now known as devananda | 17:33 | |
openstackgerrit | Merged openstack/keystone: PEP257: Ignore D203 because it was deprecated https://review.openstack.org/325305 | 17:33 |
*** devananda is now known as deva | 17:34 | |
*** deva is now known as devananda | 17:34 | |
*** spzala has joined #openstack-keystone | 17:35 | |
*** KarthikB has quit IRC | 17:36 | |
openstackgerrit | Merged openstack/keystoneauth: PEP257: Ignore D203 because it was deprecated https://review.openstack.org/325307 | 17:37 |
*** KarthikB has joined #openstack-keystone | 17:39 | |
*** tonytan4ever has joined #openstack-keystone | 17:42 | |
*** KarthikB has quit IRC | 17:43 | |
*** daemontool has quit IRC | 17:44 | |
*** josecastroleon has joined #openstack-keystone | 17:45 | |
*** KarthikB has joined #openstack-keystone | 17:45 | |
*** SamYaple has quit IRC | 17:49 | |
*** morgan is now known as notmorgan | 17:50 | |
*** pnavarro has joined #openstack-keystone | 17:56 | |
*** pushkaru has quit IRC | 17:58 | |
*** permalac has quit IRC | 17:58 | |
*** yolanda has quit IRC | 17:59 | |
*** spzala has quit IRC | 18:02 | |
*** spzala has joined #openstack-keystone | 18:03 | |
*** pushkaru has joined #openstack-keystone | 18:03 | |
*** tqtran has joined #openstack-keystone | 18:06 | |
notmorgan | bknudson, stevemar: uhm... does v2 auth (in keystone/keystonemiddlewarE) pass down "default" as the domain_id explicitly in the auth context? | 18:06 |
* notmorgan is looking and not seeing it. | 18:06 | |
notmorgan | cause... if not... we have an issue we need to address for oslo_policy consumption | 18:07 |
*** spzala has quit IRC | 18:07 | |
bknudson | why would auth token middleware ever present v2 info to the application? | 18:08 |
bknudson | unless you configured auth_token to use v2 to validate | 18:08 |
notmorgan | bknudson: right. when auth_token passes the headers down, does it set "default" as the domain for a v2 token being received? | 18:11 |
notmorgan | bknudson: project_domain_id, etc. | 18:11 |
bknudson | I'd have to try it out (and I don't have time) | 18:12 |
notmorgan | bknudson: thats fine, i just figured i'd ask if you knew off the top of your head | 18:12 |
notmorgan | bknudson: because if we don't, it means consumption of project_name in oslo_policy is potentially very broken. | 18:13 |
bknudson | if it didn't get the domain id back from keystone and didn't pass it on to the application in the headers then that would be a bug | 18:13 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/324829 | 18:13 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystoneauth: Updated from global requirements https://review.openstack.org/325452 | 18:13 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/324831 | 18:13 |
notmorgan | bknudson: yeah, i know we don't populate domain info in v2 tokens though. so i just don't know the base behavior. i'll try it out | 18:13 |
bknudson | shouldn't matter what's in the token since it's validated using ve3 | 18:14 |
bknudson | v3 | 18:14 |
notmorgan | right. | 18:14 |
notmorgan | bknudson: ok cool. | 18:14 |
notmorgan | i'm good with that answer | 18:14 |
*** josecastroleon has quit IRC | 18:15 | |
*** amakarov is now known as amakarov_away | 18:17 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/oslo.policy: Updated from global requirements https://review.openstack.org/325466 | 18:18 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf: Updated from global requirements https://review.openstack.org/324851 | 18:18 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements https://review.openstack.org/324856 | 18:18 |
*** SamYaple has joined #openstack-keystone | 18:30 | |
*** jed56 has quit IRC | 18:35 | |
*** KarthikB has quit IRC | 18:44 | |
*** sheel has quit IRC | 18:45 | |
*** henrynash_ has quit IRC | 18:48 | |
*** spzala has joined #openstack-keystone | 18:53 | |
*** adu has quit IRC | 18:55 | |
*** mfisch has quit IRC | 19:06 | |
*** mvk_ has joined #openstack-keystone | 19:08 | |
bknudson | what do you think about deprecating using v2 for validation in auth_token ? | 19:13 |
bknudson | notmorgan ^ (since we were just talking about auth_token) | 19:13 |
notmorgan | bknudson: 100% | 19:14 |
notmorgan | bknudson: :) | 19:14 |
bknudson | ok. I had it on my list already. | 19:14 |
notmorgan | i think we are almost all there except perhaps ironic in devstack (still uses some v2-things) | 19:14 |
notmorgan | :) | 19:14 |
*** amakarov_away has quit IRC | 19:16 | |
*** ametts has quit IRC | 19:22 | |
*** yolanda has joined #openstack-keystone | 19:27 | |
openstackgerrit | Merged openstack/keystone: Bootstrap: enable and reset password for existing users https://review.openstack.org/325352 | 19:31 |
*** adu has joined #openstack-keystone | 19:36 | |
bknudson | if I can use a token to validate itself why does auth_token need a user at all? | 19:37 |
bknudson | just validate the token by using the token. | 19:37 |
bknudson | also, we could improve keystone so that if the x-subject-token is the same as x-auth-token then just validate. | 19:38 |
bknudson | validate once | 19:38 |
*** roxanaghe has quit IRC | 19:39 | |
*** spzala has quit IRC | 19:40 | |
openstackgerrit | Merged openstack/keystone: Move stray notification options into config module https://review.openstack.org/324880 | 19:43 |
openstackgerrit | Merged openstack/keystone: Updating sample configuration file https://review.openstack.org/325336 | 19:44 |
*** pushkaru has quit IRC | 19:47 | |
*** amrith is now known as _amrith_ | 19:49 | |
-openstackstatus- NOTICE: The infrastructure team is taking Gerrit offline for maintenance this afternoon, beginning shortly after 20:00 UTC. We aim to have it back online around 00:00 UTC. | 19:59 | |
*** adu has quit IRC | 20:01 | |
*** _amrith_ is now known as amrith | 20:04 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updating sample configuration file https://review.openstack.org/325505 | 20:06 |
*** spzala has joined #openstack-keystone | 20:07 | |
*** spzala has quit IRC | 20:08 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/324829 | 20:09 |
-openstackstatus- NOTICE: Gerrit is offline for maintenance until 00:00 UTC | 20:09 | |
*** ChanServ changes topic to "Gerrit is offline for maintenance until 00:00 UTC" | 20:09 | |
*** rcernin has quit IRC | 20:15 | |
*** gyee has joined #openstack-keystone | 20:16 | |
*** ChanServ sets mode: +v gyee | 20:16 | |
*** KevinE has quit IRC | 20:29 | |
*** frontrunner has quit IRC | 20:32 | |
*** roxanaghe has joined #openstack-keystone | 20:33 | |
*** roxanaghe has quit IRC | 20:40 | |
*** roxanaghe has joined #openstack-keystone | 20:40 | |
*** tonytan4ever has quit IRC | 20:41 | |
*** diazjf has quit IRC | 20:42 | |
*** julim has quit IRC | 20:44 | |
*** ayoung has quit IRC | 20:44 | |
*** iurygregory has quit IRC | 20:48 | |
*** timcline_ has joined #openstack-keystone | 20:48 | |
*** timcline has quit IRC | 20:51 | |
*** ebalduf has joined #openstack-keystone | 20:54 | |
bknudson | for some reason uwsgi using threads gives terrible parallel performance... processes works better | 20:56 |
*** edtubill has joined #openstack-keystone | 21:09 | |
*** pauloewerton has quit IRC | 21:09 | |
*** ebalduf has quit IRC | 21:10 | |
*** amrith is now known as _amrith_ | 21:15 | |
*** harlowja has quit IRC | 21:20 | |
breton | bknudson: because of GIL maybe? | 21:27 |
*** _amrith_ is now known as amrith | 21:27 | |
*** timcline_ has quit IRC | 21:28 | |
*** daemontool has joined #openstack-keystone | 21:31 | |
notmorgan | bknudson: iirc you see the same thing with mod_wsgi | 21:31 |
notmorgan | bknudson: using "threads" over more processes | 21:31 |
breton | notmorgan: right | 21:36 |
*** edtubill has quit IRC | 21:37 | |
*** ThomasHsiao has joined #openstack-keystone | 21:51 | |
*** dave-mccowan has quit IRC | 21:54 | |
*** yolanda has quit IRC | 21:57 | |
*** dan_nguyen has quit IRC | 22:00 | |
*** dan_nguyen has joined #openstack-keystone | 22:09 | |
*** gordc has quit IRC | 22:15 | |
*** daemontool has quit IRC | 22:26 | |
*** markvoelker has quit IRC | 22:31 | |
*** henrynash_ has joined #openstack-keystone | 22:36 | |
*** ChanServ sets mode: +v henrynash_ | 22:36 | |
*** henrynash_ has quit IRC | 22:36 | |
*** edmondsw has quit IRC | 22:41 | |
*** lhcheng has quit IRC | 22:47 | |
*** harlowja has joined #openstack-keystone | 22:51 | |
*** rderose has quit IRC | 22:55 | |
*** rderose has joined #openstack-keystone | 22:57 | |
*** jrist has quit IRC | 23:01 | |
*** jrist has joined #openstack-keystone | 23:02 | |
*** r-daneel has quit IRC | 23:04 | |
*** rderose has quit IRC | 23:05 | |
*** mvk_ has quit IRC | 23:06 | |
*** harlowja has quit IRC | 23:10 | |
*** harlowja has joined #openstack-keystone | 23:10 | |
*** henrynash_ has joined #openstack-keystone | 23:15 | |
*** ChanServ sets mode: +v henrynash_ | 23:15 | |
*** dan_nguyen has quit IRC | 23:15 | |
*** adu has joined #openstack-keystone | 23:16 | |
*** adu has quit IRC | 23:32 | |
*** lhcheng has joined #openstack-keystone | 23:34 | |
*** ChanServ sets mode: +v lhcheng | 23:34 | |
*** henrynash_ has quit IRC | 23:37 | |
*** gyee has quit IRC | 23:43 | |
*** roxanaghe has quit IRC | 23:49 | |
*** lhcheng_ has joined #openstack-keystone | 23:50 | |
*** johnthetubaguy has quit IRC | 23:53 | |
*** johnthetubaguy has joined #openstack-keystone | 23:53 | |
*** lhcheng has quit IRC | 23:53 | |
*** henrynash_ has joined #openstack-keystone | 23:54 | |
*** ChanServ sets mode: +v henrynash_ | 23:54 | |
*** basilAB has quit IRC | 23:55 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!