dstanek | stevemar: how close is that hotel to the venue? | 00:02 |
---|---|---|
*** edtubill has joined #openstack-keystone | 00:05 | |
*** aratus has quit IRC | 00:06 | |
*** rcernin has joined #openstack-keystone | 00:17 | |
*** ddieterly has joined #openstack-keystone | 00:17 | |
*** sdake has quit IRC | 00:18 | |
*** rcernin has quit IRC | 00:22 | |
*** rk4n has quit IRC | 00:22 | |
*** rk4n has joined #openstack-keystone | 00:22 | |
*** browne has quit IRC | 00:28 | |
*** david-lyle has quit IRC | 00:32 | |
*** tqtran has quit IRC | 00:33 | |
*** edtubill has quit IRC | 00:34 | |
*** ddieterly has quit IRC | 00:35 | |
*** edtubill has joined #openstack-keystone | 00:45 | |
*** edtubill has quit IRC | 00:46 | |
*** rcernin has joined #openstack-keystone | 00:48 | |
*** roxanagh_ has joined #openstack-keystone | 00:49 | |
*** adrian_otto has quit IRC | 00:49 | |
*** roxanagh_ has quit IRC | 00:53 | |
*** rcernin has quit IRC | 00:53 | |
*** roxanaghe has quit IRC | 00:55 | |
notmorgan | lbragstad: https://review.openstack.org/#/c/273218/3 would be good to extract some basic data from the test run | 00:57 |
patchbot | notmorgan: patch 273218 - keystone - exception sensitive cache/audit changes | 00:57 |
notmorgan | lbragstad: for performance... also it reported twice | 00:57 |
lbragstad | notmorgan yeah - that was my bad... i had the scheduler running in two different places | 00:57 |
notmorgan | lbragstad: also pasteraw mangles the color coding | 00:57 |
lbragstad | notmorgan it does... i've added an issue to remove the dependency on pasteraw | 00:58 |
notmorgan | is there a rule against putting the output for both of those into the actual message? | 00:58 |
notmorgan | slash comment | 00:58 |
notmorgan | also i think you want to post the data as CI data like jenkins does / 3rd party CI does. | 00:59 |
*** ddieterly has joined #openstack-keystone | 00:59 | |
lbragstad | notmorgan no - there is no rule. | 00:59 |
lbragstad | i just put the results in paste and left a link | 00:59 |
notmorgan | for the log/runtime so it shows in the "jenkins check" area | 00:59 |
lbragstad | i agree that it would be much better for the bot to actually determine the performance increase and leave a comment like "performance difference between master and patchset at <some-percentage>" | 01:00 |
notmorgan | lbragstad: so my comments are: post basic data in the comment, and post like jenkins does so it shows as a CI user | 01:00 |
notmorgan | and for an external link only 1 link with all the data, comparison at the top | 01:00 |
notmorgan | not two outputs, if you can avoid it. | 01:00 |
* notmorgan is aiming for usability here. | 01:00 | |
lbragstad | agreed | 01:00 |
lbragstad | https://github.com/lbragstad/keystone-performance/issues/5 | 01:00 |
notmorgan | https://github.com/lbragstad/keystone-performance/issues/10 | 01:02 |
notmorgan | just added that one | 01:02 |
lbragstad | notmorgan sweet | 01:03 |
lbragstad | notmorgan as in a pass fail type output? | 01:03 |
notmorgan | it should show in a similar manner | 01:03 |
lbragstad | notmorgan what do we determine as pass/fail for performance tests? | 01:03 |
notmorgan | i *bet* you could make it show something (text-y) that says "performance difference <seconds> => <seconds> | 01:03 |
lbragstad | or maybe a certain percentage? | 01:04 |
notmorgan | if you look at the infra ci https://review.openstack.org/#/c/329376/ | 01:04 |
patchbot | notmorgan: patch 329376 - openstack-infra/project-config - Add jobs for Monasca-Analytics | 01:04 |
lbragstad | "performance degraded >5%, fail" | 01:04 |
notmorgan | Jenkins XML output has changed. in 7m 57s (non-voting) | 01:04 |
*** rk4n has quit IRC | 01:04 | |
notmorgan | not a success/failure | 01:04 |
notmorgan | maybe just a "Time (Patch): XXX, Time (POST): XXX"? | 01:05 |
*** rk4n has joined #openstack-keystone | 01:05 | |
notmorgan | and have the link be to the full logs | 01:05 |
notmorgan | (eventually pretty graphs too, but that is way down the line) | 01:05 |
*** rcernin has joined #openstack-keystone | 01:06 | |
lbragstad | i have that documented here too - https://github.com/lbragstad/keystone-performance/issues/8 | 01:06 |
notmorgan | right. i am thinking just the raw output published | 01:07 |
notmorgan | long term actual trends for merged patches would be fantastic | 01:07 |
lbragstad | ok - that makes sense | 01:07 |
lbragstad | agreed... that would be awesome | 01:07 |
notmorgan | trigger on a merge event | 01:07 |
notmorgan | and run performance for the long-term thing, and store based on a SHA | 01:07 |
notmorgan | and then trending | 01:07 |
lbragstad | we could even map that | 01:08 |
lbragstad | back to keystone inception | 01:08 |
lbragstad | just looping through each keystone sha back several releases and deploying with that sha | 01:08 |
*** rk4n has quit IRC | 01:09 | |
lbragstad | er - how ever many releases OSA would go back | 01:09 |
*** rk4n has joined #openstack-keystone | 01:10 | |
*** rcernin has quit IRC | 01:10 | |
*** rk4n has quit IRC | 01:11 | |
*** dan_nguyen has quit IRC | 01:11 | |
*** ddieterly has quit IRC | 01:15 | |
*** rk4n has joined #openstack-keystone | 01:16 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 01:20 |
notmorgan | lbragstad: ++ | 01:25 |
*** sdake has joined #openstack-keystone | 01:28 | |
*** tqtran has joined #openstack-keystone | 01:30 | |
*** sdake has quit IRC | 01:32 | |
*** tqtran has quit IRC | 01:34 | |
*** rk4n has quit IRC | 01:35 | |
*** BjoernT has joined #openstack-keystone | 01:37 | |
*** raddaoui has quit IRC | 01:37 | |
*** EinstCrazy has joined #openstack-keystone | 01:38 | |
*** BjoernT has quit IRC | 01:43 | |
*** links has joined #openstack-keystone | 01:54 | |
*** jrist has quit IRC | 01:56 | |
*** ddieterly has joined #openstack-keystone | 01:57 | |
*** ddieterly is now known as ddieterly[away] | 01:57 | |
*** ddieterly[away] is now known as ddieterly | 01:57 | |
*** jrist has joined #openstack-keystone | 02:03 | |
*** ddieterly has quit IRC | 02:12 | |
*** browne has joined #openstack-keystone | 02:16 | |
*** ddieterly has joined #openstack-keystone | 02:20 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 02:21 |
*** nkinder has quit IRC | 02:23 | |
*** nkinder has joined #openstack-keystone | 02:23 | |
*** EinstCrazy has quit IRC | 02:25 | |
*** EinstCrazy has joined #openstack-keystone | 02:28 | |
*** jinquan has joined #openstack-keystone | 02:29 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 02:29 |
*** EinstCrazy has quit IRC | 02:29 | |
*** EinstCrazy has joined #openstack-keystone | 02:31 | |
*** EinstCrazy has quit IRC | 02:33 | |
*** ddieterly has quit IRC | 02:35 | |
*** ddieterly has joined #openstack-keystone | 02:35 | |
*** ddieterly has quit IRC | 02:35 | |
*** rderose has quit IRC | 02:36 | |
*** EinstCra_ has joined #openstack-keystone | 02:36 | |
*** julim has joined #openstack-keystone | 02:38 | |
*** EinstCra_ has quit IRC | 02:42 | |
*** EinstCrazy has joined #openstack-keystone | 02:43 | |
*** browne has quit IRC | 02:48 | |
*** roxanaghe has joined #openstack-keystone | 02:50 | |
*** roxanaghe has quit IRC | 02:55 | |
*** links has quit IRC | 02:56 | |
*** gyee has quit IRC | 02:59 | |
*** iurygregory_ has quit IRC | 03:05 | |
*** richm has quit IRC | 03:11 | |
*** tqtran has joined #openstack-keystone | 03:31 | |
*** sheel has joined #openstack-keystone | 03:34 | |
*** tqtran has quit IRC | 03:36 | |
*** EinstCrazy has quit IRC | 03:47 | |
*** EinstCrazy has joined #openstack-keystone | 03:47 | |
*** EinstCrazy has quit IRC | 03:55 | |
*** julim has quit IRC | 04:04 | |
*** links has joined #openstack-keystone | 04:05 | |
*** david-lyle has joined #openstack-keystone | 04:06 | |
*** GB21 has joined #openstack-keystone | 04:13 | |
openstackgerrit | Merged openstack/keystone: Add cache invalidation for service providers https://review.openstack.org/325417 | 04:27 |
*** diazjf has joined #openstack-keystone | 04:28 | |
*** diazjf has quit IRC | 04:29 | |
*** henrynash_ has quit IRC | 04:42 | |
*** EinstCra_ has joined #openstack-keystone | 04:44 | |
*** roxanaghe has joined #openstack-keystone | 04:51 | |
*** roxanaghe has quit IRC | 04:54 | |
*** roxanaghe has joined #openstack-keystone | 04:55 | |
*** jaosorior has joined #openstack-keystone | 05:04 | |
*** GB21 has quit IRC | 05:05 | |
*** kursad_ has joined #openstack-keystone | 05:17 | |
kursad_ | Hi, we face some problem while enabling federation in keystone using saml. Is there any one to help us? | 05:22 |
kursad_ | The final error that we get is the following: Could not map user while setting ephemeral user identity. Either mapping rules must specify user id/name or REMOTE_USER environment variable must be set | 05:22 |
*** EinstCra_ has quit IRC | 05:36 | |
*** EinstCrazy has joined #openstack-keystone | 05:36 | |
*** GB21 has joined #openstack-keystone | 05:37 | |
*** EinstCrazy has quit IRC | 05:45 | |
*** EinstCrazy has joined #openstack-keystone | 05:45 | |
*** yolanda has joined #openstack-keystone | 06:13 | |
*** yolanda_ has joined #openstack-keystone | 06:13 | |
*** roxanaghe has quit IRC | 06:14 | |
*** yolanda_ has quit IRC | 06:14 | |
*** openstackgerrit has quit IRC | 06:18 | |
*** openstackgerrit has joined #openstack-keystone | 06:18 | |
*** rcernin has joined #openstack-keystone | 06:29 | |
*** EinstCrazy has quit IRC | 06:50 | |
*** EinstCrazy has joined #openstack-keystone | 06:50 | |
*** belmoreira has joined #openstack-keystone | 06:51 | |
*** GB21 has quit IRC | 06:53 | |
*** EinstCrazy has quit IRC | 06:55 | |
*** EinstCrazy has joined #openstack-keystone | 06:58 | |
*** amoralej|off is now known as amoralej | 06:59 | |
*** tesseract has joined #openstack-keystone | 07:03 | |
*** rcernin has quit IRC | 07:04 | |
*** rcernin has joined #openstack-keystone | 07:04 | |
*** GB21 has joined #openstack-keystone | 07:05 | |
*** EinstCrazy has quit IRC | 07:10 | |
*** EinstCrazy has joined #openstack-keystone | 07:13 | |
*** EinstCrazy has quit IRC | 07:16 | |
*** EinstCrazy has joined #openstack-keystone | 07:17 | |
*** dhellmann has quit IRC | 07:20 | |
*** dhellmann has joined #openstack-keystone | 07:20 | |
*** danpawlik has joined #openstack-keystone | 07:25 | |
*** GB21 has quit IRC | 07:30 | |
*** openstackgerrit has quit IRC | 07:33 | |
*** openstackgerrit has joined #openstack-keystone | 07:33 | |
*** EinstCrazy has quit IRC | 07:36 | |
*** EinstCrazy has joined #openstack-keystone | 07:37 | |
*** links has quit IRC | 07:39 | |
*** EinstCrazy has quit IRC | 07:52 | |
*** EinstCrazy has joined #openstack-keystone | 07:52 | |
*** jaosorior is now known as jaosorior_brb | 07:53 | |
*** links has joined #openstack-keystone | 07:56 | |
*** EinstCrazy has quit IRC | 07:57 | |
*** zzzeek has quit IRC | 08:00 | |
*** EinstCrazy has joined #openstack-keystone | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:03 | |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 08:10 |
openstackgerrit | Andrew Liu proposed openstack/keystone: Added cache for sql id mapping driver https://review.openstack.org/328820 | 08:14 |
*** dmk0202 has joined #openstack-keystone | 08:22 | |
*** GB21 has joined #openstack-keystone | 08:24 | |
*** henrynash_ has joined #openstack-keystone | 08:40 | |
*** ChanServ sets mode: +v henrynash_ | 08:40 | |
*** jaosorior_brb has quit IRC | 08:40 | |
*** jaosorior_brb has joined #openstack-keystone | 08:40 | |
*** jaosorior_brb is now known as jaosorior | 08:41 | |
*** henrynash_ has quit IRC | 08:45 | |
*** tqtran has joined #openstack-keystone | 08:45 | |
*** rk4n has joined #openstack-keystone | 08:46 | |
*** EinstCrazy has quit IRC | 08:47 | |
*** EinstCrazy has joined #openstack-keystone | 08:48 | |
*** henrynash_ has joined #openstack-keystone | 08:48 | |
*** ChanServ sets mode: +v henrynash_ | 08:48 | |
*** tqtran has quit IRC | 08:50 | |
*** EinstCrazy has quit IRC | 08:50 | |
*** EinstCrazy has joined #openstack-keystone | 08:50 | |
*** TxGVNN has joined #openstack-keystone | 08:54 | |
*** jaosorior has quit IRC | 08:57 | |
*** nisha_ has joined #openstack-keystone | 08:58 | |
*** TxGVNN has quit IRC | 09:07 | |
*** mvk_ has quit IRC | 09:11 | |
*** jaosorior has joined #openstack-keystone | 09:21 | |
*** EinstCrazy has quit IRC | 09:23 | |
*** EinstCrazy has joined #openstack-keystone | 09:23 | |
*** dancn has quit IRC | 09:27 | |
*** dancn has joined #openstack-keystone | 09:27 | |
*** EinstCrazy has quit IRC | 09:28 | |
*** EinstCrazy has joined #openstack-keystone | 09:30 | |
*** Dinesh_Bhor has joined #openstack-keystone | 09:30 | |
*** GB21 has quit IRC | 09:33 | |
*** TxGVNN has joined #openstack-keystone | 09:37 | |
*** EinstCrazy has quit IRC | 09:38 | |
*** nisha_ has quit IRC | 09:38 | |
*** EinstCrazy has joined #openstack-keystone | 09:39 | |
*** nisha_ has joined #openstack-keystone | 09:39 | |
*** TxGVNN has quit IRC | 09:43 | |
*** EinstCrazy has quit IRC | 09:44 | |
*** mvk_ has joined #openstack-keystone | 09:45 | |
*** rk4n has quit IRC | 09:48 | |
*** rk4n has joined #openstack-keystone | 09:51 | |
*** rk4n has quit IRC | 09:51 | |
*** rk4n has joined #openstack-keystone | 09:52 | |
*** EinstCrazy has joined #openstack-keystone | 09:57 | |
*** EinstCrazy has quit IRC | 09:58 | |
*** EinstCrazy has joined #openstack-keystone | 09:58 | |
*** permalac has joined #openstack-keystone | 09:58 | |
odyssey4me | lbragstad back to icehouse in various forms... back to juno/kilo only for this particular repo but only kilo will work to deploy just keystone easily | 09:59 |
*** GB21 has joined #openstack-keystone | 10:01 | |
*** jinquan has left #openstack-keystone | 10:03 | |
openstackgerrit | Liam Young proposed openstack/keystone: Correct domain_id and name constraint dropping https://review.openstack.org/329855 | 10:07 |
openstackgerrit | Andrew Liu proposed openstack/keystone: Added named argument to response test functions https://review.openstack.org/328907 | 10:08 |
*** henrynash_ has quit IRC | 10:11 | |
*** rk4n has quit IRC | 10:14 | |
*** GB21 has quit IRC | 10:23 | |
*** nisha_ has quit IRC | 10:32 | |
*** nisha_ has joined #openstack-keystone | 10:32 | |
*** henrynash_ has joined #openstack-keystone | 10:33 | |
*** ChanServ sets mode: +v henrynash_ | 10:33 | |
*** jefrite has joined #openstack-keystone | 10:34 | |
*** GB21 has joined #openstack-keystone | 10:48 | |
Dinesh_Bhor | dolphm: Hi, Could you please take a look at it ? https://bugs.launchpad.net/keystone/+bug/1534473 | 10:49 |
openstack | Launchpad bug 1534473 in OpenStack Identity (keystone) "openstack service create allows duplicate names" [Undecided,Confirmed] - Assigned to Kanika Singh (kanikasingh-1490) | 10:49 |
Dinesh_Bhor | Can someone help me with the above bug ? | 10:54 |
Dinesh_Bhor | is keystone allowing to create services with duplicate names purposely ? | 10:54 |
*** rk4n has joined #openstack-keystone | 10:55 | |
*** dave-mccowan has quit IRC | 11:04 | |
*** EinstCrazy has quit IRC | 11:07 | |
*** EinstCrazy has joined #openstack-keystone | 11:07 | |
*** rk4n has quit IRC | 11:08 | |
*** dave-mccowan has joined #openstack-keystone | 11:20 | |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Add domain functional tests https://review.openstack.org/329598 | 11:22 |
*** henrynash_ has quit IRC | 11:23 | |
*** henrynash_ has joined #openstack-keystone | 11:25 | |
*** ChanServ sets mode: +v henrynash_ | 11:25 | |
*** belmoreira has quit IRC | 11:33 | |
*** rk4n has joined #openstack-keystone | 11:38 | |
*** nisha__ has joined #openstack-keystone | 11:39 | |
*** nisha_ has quit IRC | 11:43 | |
*** rk4n has quit IRC | 11:43 | |
*** rk4n has joined #openstack-keystone | 11:44 | |
*** ddieterly has joined #openstack-keystone | 11:45 | |
*** dave-mccowan has quit IRC | 11:47 | |
*** henrynash_ has quit IRC | 11:50 | |
*** aloga has quit IRC | 11:53 | |
*** aloga has joined #openstack-keystone | 11:53 | |
*** ddieterly is now known as ddieterly[away] | 12:08 | |
*** pauloewerton has joined #openstack-keystone | 12:12 | |
*** daemontool has joined #openstack-keystone | 12:16 | |
*** GB21 has quit IRC | 12:24 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 12:25 |
*** raildo-afk is now known as raildo | 12:26 | |
*** ddieterly[away] is now known as ddieterly | 12:27 | |
*** frontrunner has joined #openstack-keystone | 12:31 | |
*** ddieterly has quit IRC | 12:35 | |
*** nisha__ is now known as nisha_ | 12:42 | |
*** edmondsw has joined #openstack-keystone | 12:43 | |
*** tqtran has joined #openstack-keystone | 12:47 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password history requirements https://review.openstack.org/328339 | 12:50 |
*** tqtran has quit IRC | 12:51 | |
*** jsavak has joined #openstack-keystone | 12:51 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 12:55 |
*** rderose has joined #openstack-keystone | 12:58 | |
*** julim has joined #openstack-keystone | 12:59 | |
dstanek | Dinesh_Bhor: what about it? | 12:59 |
*** woodster_ has joined #openstack-keystone | 13:02 | |
*** afred312 has quit IRC | 13:02 | |
openstackgerrit | David Stanek proposed openstack/python-keystoneclient: WIP: Response objects from Manager methods https://review.openstack.org/329913 | 13:04 |
dstanek | dolphm: ^ | 13:13 |
*** rcernin has quit IRC | 13:14 | |
*** ddieterly has joined #openstack-keystone | 13:16 | |
*** amoralej is now known as amoralej|lunch | 13:16 | |
*** richm has joined #openstack-keystone | 13:16 | |
*** wasmum has joined #openstack-keystone | 13:22 | |
*** nisha_ has quit IRC | 13:24 | |
*** afred312 has joined #openstack-keystone | 13:28 | |
Dinesh_Bhor | dstanek: Keystone allows to create services with duplicate names. is it done purposely ? | 13:28 |
*** rcernin has joined #openstack-keystone | 13:28 | |
Dinesh_Bhor | for both v2.0 and v3 it is allowing. | 13:29 |
*** sdake has joined #openstack-keystone | 13:29 | |
*** ebarrera has joined #openstack-keystone | 13:29 | |
ebarrera | Hi all | 13:30 |
dstanek | Dinesh_Bhor: i don't know if we meant to allow it, but from what i see we do | 13:30 |
dstanek | hi ebarrera | 13:31 |
*** lamt has quit IRC | 13:31 | |
ebarrera | I'm trying to configure keystone v3 domains but not with too much luck. Once I switch to domain admin I'm not able to create a project. | 13:32 |
ayoung | ebarrera, which policy file? | 13:33 |
ebarrera | this domain admin as role admin for the domain but anyway it says I'm not authorized (using the cli) it is the v3sample.json | 13:33 |
Dinesh_Bhor | dstanek: so do we need to fix this issue ? | 13:34 |
ayoung | ebarrera, paste the config file you are using,. with passwords removed, please | 13:35 |
ayoung | ebarrera, the keystone rc file, that is | 13:35 |
dstanek | Dinesh_Bhor: probably? it looks like someone took ownership of that bug a few weeks ago and is presumably working on it | 13:35 |
ebarrera | ayoung, http://pastebin.com/d0B85aps | 13:37 |
ayoung | ebarrera, you need to set OS_DOMAIN_NAME to get a domain scoped token | 13:38 |
ayoung | unset OS_DOMAIN_NAME is messing you up | 13:38 |
*** ddieterly is now known as ddieterly[away] | 13:39 | |
ayoung | export OS_DOMAIN_NAME=default I think | 13:39 |
Dinesh_Bhor | dstanek: yes..because from openstackclient if we try to delete or show any service with duplicate names it is giving problem, so if this issue is fixed in keystone both problems will be solved. | 13:39 |
dstanek | Dinesh_Bhor: if you are interested in fixing then i would say you should ask in the bug if it's currently being worked on | 13:40 |
*** sdake_ has joined #openstack-keystone | 13:42 | |
Dinesh_Bhor | dstanek: ok , Thank you for your help | 13:42 |
dstanek | Dinesh_Bhor: np | 13:42 |
ebarrera | ayoung, it doesn't work neither... I removed the unset and I changed to export OS_DOMAIN_NAME=default instead of my_domain . Why default and not my_domain ? It still doesn't after reloadinv env vars | 13:43 |
ayoung | whatever your domain is | 13:43 |
ebarrera | ok, It already was there | 13:43 |
ebarrera | its the last line... probably hidden | 13:43 |
ebarrera | ayoung, ^ | 13:43 |
*** sdake has quit IRC | 13:45 | |
*** ddieterly[away] is now known as ddieterly | 13:46 | |
dstanek | ebarrera: also did you check the logs to see that it was policy that failed and not something else? | 13:46 |
*** rodrigods has quit IRC | 13:47 | |
*** rodrigods has joined #openstack-keystone | 13:48 | |
*** henrynash_ has joined #openstack-keystone | 13:48 | |
*** ChanServ sets mode: +v henrynash_ | 13:48 | |
stevemar | morning keystoners | 13:50 |
henrynash_ | mornin’ | 13:50 |
ayoung | ebarrera, next step is openstack --debug token issue | 13:50 |
ayoung | look at the response to see what roles are in the token validation response | 13:50 |
dstanek | morning stevemar | 13:50 |
ebarrera | dstanek, yes... it fails on identity:create_project ... There is also another fail in the logs... It also fail on list_domains that it's extrange | 13:51 |
ayoung | stevemar, I took over my last manager job (10 years ago) about 2 months before my first son was born.... | 13:52 |
dstanek | ebarrera: k, i mentioned that because we have other checks (not policy related) that bail with a not authorized error | 13:52 |
ebarrera | dstanek, http://pastebin.com/Jk8A9uKu here you can find the logs | 13:52 |
ayoung | 'roles': [u'admin'], 'domain_id': u'2e25369784564c508fdb51903ce98368', | 13:53 |
ayoung | that should be sufficient | 13:53 |
ayoung | the rule is | 13:53 |
ebarrera | u'2e25369784564c508fdb51903ce98368', is the id om my domain | 13:53 |
dstanek | ebarrera: does your user (and token) have the admin role on that domain? | 13:53 |
ebarrera | my_domain | 13:53 |
*** rcernin has quit IRC | 13:54 | |
ebarrera | dstanek, yes, they have... | 13:54 |
ayoung | assuming u'2e25369784564c508fdb51903ce98368', is the domain name for u'domain_id': u'my_domain', | 13:54 |
ayoung | which it is not | 13:54 |
dstanek | also noticed "Could not find domain: my_domain" in the log | 13:54 |
ayoung | ebarrera, what command line are you calling to create the project? | 13:55 |
ebarrera | openstack project create --domain my_domain my_domain_project1 | 13:55 |
openstackgerrit | Merged openstack/keystone-specs: Drop Support for Driver Versioning https://review.openstack.org/324081 | 13:55 |
*** amoralej|lunch is now known as amoralej | 13:56 | |
ebarrera | dstanek, true... | 13:56 |
*** links has quit IRC | 13:56 | |
ebarrera | dstanek, but a domain admin as no right to list the domains | 13:57 |
ebarrera | dstanek, only cloud_admin | 13:57 |
*** jed56 has quit IRC | 14:01 | |
*** jed56 has joined #openstack-keystone | 14:01 | |
dolphm | stevemar: when would the next openstackclient release be? | 14:01 |
ebarrera | ayoung, what do you mean with "which it is not" ? | 14:02 |
ebarrera | | 2e25369784564c508fdb51903ce98368 | my_domain | | 14:03 |
dstanek | ebarrera: line 26 of your paste http://pastebin.com/Jk8A9uKu | 14:05 |
dstanek | ebarrera: also line 41 | 14:06 |
ebarrera | dstanek, do you mean that there is writen the domain name instead the domain_id ? | 14:07 |
ayoung | ebarrera, sorry...company all hands Openstack meeting now...hard to multiplex | 14:09 |
*** rcernin has joined #openstack-keystone | 14:09 | |
ayoung | ebarrera, yes, it looks like the domain_id is set to the domain_name | 14:10 |
ayoung | ebarrera, --domain my_domain should be looking up the domainname, but it is not | 14:10 |
ayoung | that might be abug | 14:10 |
ayoung | try | 14:10 |
ayoung | openstack project create --domain 2e25369784564c508fdb51903ce98368 my_domain_project1 | 14:10 |
ebarrera | ok | 14:10 |
*** ddieterly is now known as ddieterly[away] | 14:11 | |
ebarrera | ayoung, lol!!!!!!!!!! it worked | 14:11 |
ebarrera | ayoung++ | 14:11 |
ayoung | ebarrera, the "id vs name" battle in Openstack is lingering | 14:11 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password history requirements https://review.openstack.org/328339 | 14:14 |
stevemar | dolphm: we have a few things to clean up, but should be before newton-2 | 14:15 |
stevemar | before newton-2 ends | 14:15 |
*** jaugustine has joined #openstack-keystone | 14:16 | |
*** jaugustine has quit IRC | 14:17 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 14:18 |
*** rcernin has quit IRC | 14:18 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:18 | |
*** raddaoui has joined #openstack-keystone | 14:18 | |
*** ddieterly[away] is now known as ddieterly | 14:19 | |
stevemar | dolphm: you could hit up dtroyer for details | 14:20 |
stevemar | dolphm: itching to try things out with federated users? :) | 14:20 |
dolphm | stevemar: no, i want to see this fixed https://bugs.launchpad.net/python-openstackclient/+bug/1592062 | 14:21 |
openstack | Launchpad bug 1592062 in python-openstackclient "An OS_PROJECT_* value is unnecessarily demanded, even if the user has a default project" [Undecided,New] | 14:21 |
dolphm | stevemar: it's sort of a blocker when people don't know their project ID / name because they've never had to use it before | 14:22 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 14:23 |
stevemar | dolphm: oh, that wasn't on our list of things to fix for this upcoming release | 14:23 |
*** jrist has quit IRC | 14:23 | |
*** lucas___ has joined #openstack-keystone | 14:24 | |
stevemar | dolphm: blah... | 14:25 |
openstackgerrit | Liam Young proposed openstack/keystone: Correct domain_id and name constraint dropping https://review.openstack.org/329855 | 14:26 |
*** nisha_ has joined #openstack-keystone | 14:28 | |
*** pushkaru has joined #openstack-keystone | 14:29 | |
dolphm | stevemar: it looks like it's doing a scope check on the options before it authenticates? and instead it should do that same check but after it's got a token | 14:29 |
stevemar | dolphm: right, we actually have a patch up to refactor that bit: https://review.openstack.org/#/c/318201/ | 14:30 |
patchbot | stevemar: patch 318201 - python-openstackclient - Refactor check_valid_auth_options function | 14:30 |
dolphm | stevemar: should i test to see if that will fix this issue? | 14:31 |
stevemar | dolphm: the "required_scope" is true by default, and overridden in certain commands where no scope is possible, like getting a token or a catalog (like you reported in the bug) | 14:31 |
stevemar | dolphm: AFAICT it won't | 14:31 |
*** rcernin has joined #openstack-keystone | 14:31 | |
stevemar | dolphm: you can certainly try | 14:31 |
*** catintheroof has joined #openstack-keystone | 14:32 | |
stevemar | dolphm: but the refactor is just getting the opts from the auth plugin and if the plugin requires a project_id/name/etc... then it'll ask for one | 14:32 |
aloga | stevemar: do you have a second for https://bugs.launchpad.net/keystoneauth/+bug/1583961 ? | 14:32 |
openstack | Launchpad bug 1583961 in keystoneauth "OpenID Connect support for authorization code seems to be incomplete" [Undecided,New] - Assigned to Alvaro Lopez (aloga) | 14:32 |
stevemar | aloga: for you, i have a minute | 14:33 |
stevemar | :) | 14:33 |
aloga | stevemar: thanks :) | 14:33 |
*** jorge_munoz has joined #openstack-keystone | 14:33 | |
dolphm | stevemar: it actually does fix it! | 14:33 |
aloga | I've been working a bit on the OIDC support, as you know, the problem comes with the authZ code grant_type | 14:33 |
dolphm | stevemar: wait, no it doesn't | 14:33 |
dolphm | stevemar: sorry, lol. | 14:34 |
aloga | the authorization code, AFAIK, is a single use code | 14:34 |
*** jefrite has quit IRC | 14:34 | |
*** jsavak has quit IRC | 14:34 | |
stevemar | dolphm: :) | 14:34 |
aloga | so the user cannot provide with it, but the client needs to get the code from the autorization_endpoint, then use the code with the token_endpoint to obtain the access_token, then get the keystone token | 14:34 |
aloga | s/provide with/provide/ | 14:34 |
*** jsavak has joined #openstack-keystone | 14:35 | |
dolphm | stevemar: i'll look into a fix though. i suspect the answer IS to refactor that function - and separate authN checks (pre authentication) from authZ checks (post authentication) | 14:35 |
aloga | so, it is needed an additional step (the one that gets the token) | 14:35 |
stevemar | dolphm: likely, please comment on the patch regardless and cite the bug | 14:35 |
dolphm | stevemar: the fact that the required_scope argument is there sort of illustrates that the function is overloaded on behaviors / usage | 14:35 |
stevemar | dolphm: totes | 14:35 |
stevemar | aloga: let me look at my oidc notes, i forget which one is authz code | 14:36 |
aloga | however, the authorization_endpoint may redirect the user to a login page (as google does), where the user enter his credentials and eventually authorize the client | 14:36 |
*** jrist has joined #openstack-keystone | 14:37 | |
aloga | stevemar: sure :) | 14:37 |
aloga | stevemar: here it is nicely explained https://developers.google.com/identity/protocols/OpenIDConnect#server-flow | 14:40 |
stevemar | aloga: haha, on there now | 14:40 |
*** danpawlik has left #openstack-keystone | 14:40 | |
knikolla | o/ | 14:41 |
stevemar | knikolla: o/ | 14:42 |
aloga | stevemar: the tricky part is that the user needs to authenticate with the idp | 14:42 |
aloga | stevemar: therefore, a browser is needed | 14:42 |
*** edtubill has joined #openstack-keystone | 14:42 | |
*** phalmos has joined #openstack-keystone | 14:43 | |
*** henrynash_ has quit IRC | 14:43 | |
aloga | stevemar: but noy only that, we need a listening HTTP endpoint where the callback will be redirected | 14:43 |
aloga | stevemar: so that we can obtain the access code | 14:43 |
*** gagehugo has joined #openstack-keystone | 14:45 | |
*** anush__ has joined #openstack-keystone | 14:45 | |
stevemar | aloga: right, i had to go to https://accounts.google.com/o/oauth2/auth?scope=email%20profile&redirect_uri=urn:ietf:wg:oauth:2.0:oob&response_type=code&client_id=809841518623-rc1718nrf70tkvv44pddicuam4n7deqq.apps.googleusercontent.com to get an access code | 14:47 |
stevemar | aloga: so that pin is only good for an hour or so, right? | 14:48 |
aloga | stevemar: I don't know about the duration, but this should be a single-use code | 14:48 |
*** gordc has joined #openstack-keystone | 14:50 | |
stevemar | aloga: hmm, to get the authz code, the client id is secret are needed | 14:51 |
stevemar | shouldn't the exchange to get the authz code be handled by mod_auth_openidc ? | 14:51 |
*** phalmos has quit IRC | 14:52 | |
aloga | stevemar: yes, the exchange works with mod_auth_openidc, but that would work only with websso, right? | 14:54 |
aloga | not using openstackclient + keystoneauth | 14:54 |
*** phalmos has joined #openstack-keystone | 14:55 | |
stevemar | aloga: oh you're saying that after every osc command, the user will need to supply a new authz code? | 14:57 |
aloga | yes | 14:57 |
*** amakarov_away is now known as amakarov | 14:57 | |
stevemar | since the session is terminated | 14:57 |
stevemar | lol | 14:57 |
aloga | stevemar: I have some code working | 14:58 |
stevemar | okay, i get the problem now, that's pretty funny | 14:58 |
aloga | where I fire up a browser so that the user authenticates | 14:58 |
aloga | but the problem is that if you do 100 operations, you get 100 brand new tabs :) | 14:58 |
stevemar | aloga: hehe | 14:58 |
*** jsavak has quit IRC | 14:58 | |
*** tonytan4ever has joined #openstack-keystone | 14:58 | |
stevemar | aloga: gce has something similar | 14:58 |
amakarov | notmorgan, please review this CR: https://review.openstack.org/#/c/325242/ - it's a bug fix in oslo.cache | 14:59 |
patchbot | amakarov: patch 325242 - oslo.cache - Handle empty memcache pool corner case | 14:59 |
*** jsavak has joined #openstack-keystone | 14:59 | |
*** timcline has joined #openstack-keystone | 14:59 | |
stevemar | aloga: marekdenis was emailing me about this a few weeks ago | 15:01 |
stevemar | aloga: refer to 3:39 at https://www.youtube.com/watch?v=gxZvofAvgHQ | 15:04 |
*** afred312_ has joined #openstack-keystone | 15:04 | |
aloga | stevemar: I guess that they get the access_token | 15:05 |
aloga | stevemar: then they are reusing it | 15:05 |
aloga | stevemar: that's perfectly feasible | 15:05 |
*** afred312 has quit IRC | 15:05 | |
stevemar | aloga: yeah, i think it's saved somewhere and they keep reusing it | 15:05 |
aloga | stevemar: but we need to store the access_token somewhere | 15:05 |
stevemar | right, and we can't do that in the session, cause the process is terminated! :O | 15:06 |
aloga | stevemar: oauth2client/tools.py: webbrowser.open(authorize_url, new=1, autoraise=True) | 15:06 |
aloga | v3/oidc.py: webbrowser.open(url) | 15:06 |
aloga | so, I'm doing the same thing \o/ | 15:06 |
*** catintheroof has quit IRC | 15:08 | |
*** sdake_ has quit IRC | 15:08 | |
*** sdake has joined #openstack-keystone | 15:10 | |
aloga | stevemar: I have to leave, thanks for your input | 15:11 |
stevemar | aloga: i'm trying to find out where they store the authz code | 15:11 |
stevemar | aloga: storing in $HOME/.openstack/tmp_file is always a good option | 15:11 |
*** kursad_ has quit IRC | 15:11 | |
*** sdake has quit IRC | 15:11 | |
stevemar | i'm wondering if that's a security concern though... | 15:12 |
aloga | stevemar: I will submit the code that I have right now to see if it makes sense or not (assuming that we manage to store the credential somewhere) | 15:14 |
stevemar | aloga: do it up | 15:14 |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: WIP: fix OpenID Connect authorization code grant_type https://review.openstack.org/330006 | 15:15 |
*** jaugustine has joined #openstack-keystone | 15:15 | |
aloga | stevemar: there you are :) | 15:15 |
aloga | stevemar: see you, thanks for your help! | 15:15 |
stevemar | aloga: thank *you* for all your patches recently :) | 15:15 |
aloga | stevemar: you're welcome, it's a pleasure :) | 15:16 |
*** ktychkova has quit IRC | 15:18 | |
*** EinstCrazy has quit IRC | 15:19 | |
*** dan_nguyen has joined #openstack-keystone | 15:20 | |
*** phalmos has quit IRC | 15:21 | |
*** ebarrera has quit IRC | 15:21 | |
*** diazjf has joined #openstack-keystone | 15:21 | |
*** anush__ has quit IRC | 15:24 | |
*** tonytan4ever has quit IRC | 15:24 | |
*** phalmos has joined #openstack-keystone | 15:25 | |
openstackgerrit | Steve Martinelli proposed openstack/keystoneauth: Use SAML2 requests plugin https://review.openstack.org/255056 | 15:25 |
*** sheel has quit IRC | 15:25 | |
*** ktychkova has joined #openstack-keystone | 15:26 | |
*** pushkaru has quit IRC | 15:26 | |
*** jaugustine has quit IRC | 15:26 | |
*** pushkaru has joined #openstack-keystone | 15:26 | |
*** browne has joined #openstack-keystone | 15:27 | |
*** ktychkova has quit IRC | 15:30 | |
*** pushkaru has quit IRC | 15:31 | |
*** ktychkova has joined #openstack-keystone | 15:31 | |
*** dan_nguyen has left #openstack-keystone | 15:32 | |
*** anush__ has joined #openstack-keystone | 15:32 | |
*** jaugustine has joined #openstack-keystone | 15:34 | |
*** rk4n has quit IRC | 15:34 | |
*** anush__ has quit IRC | 15:37 | |
*** ddieterly is now known as ddieterly[away] | 15:39 | |
ayoung | stevemar, do we have docs on how to tune the logging for different subsections to troubleshoot keystone? | 15:45 |
stevemar | ayoung: hmm? subsections? for more logging/tuning i normally flip some of these values: https://github.com/openstack/keystone/blob/master/etc/keystone.conf.sample#L190 | 15:46 |
ayoung | stevemar, yep, but we know what we are doing...I was wondering if we have a doc that says "here is how and why" but I can start one. | 15:47 |
stevemar | ayoung: oh, i get what you mean, i thought you were asking me. tribal knowledge ftw! | 15:48 |
amakarov | ayoung, good day! Quick question: can a delegation issued for a group (not for user) be redelegated? | 15:49 |
*** ddieterly[away] is now known as ddieterly | 15:49 | |
*** aratus has joined #openstack-keystone | 15:50 | |
*** pcaruana has quit IRC | 15:50 | |
ayoung | stevemar, I'm specifically looking for LDAP debugging techniques. We don;'t have an LDAP entry in that line. Can one be added ? | 15:51 |
*** roxanaghe has joined #openstack-keystone | 15:51 | |
ayoung | Those are for the external libraries mostly, right? amqp=WARN,amqplib=WARN,boto=WARN,qpid=WARN,sqlalchemy=WARN,suds=INFO,oslo.messaging=INFO,iso8601=WARN,requests.packages.urllib3.connectionpool=WARN,urllib3.connectionpool=WARN,websocket=WARN,requests.packages.urllib3.util.retry=WARN,urllib3.util.retry=WARN,keystonemiddleware=WARN,routes.middleware=WARN,stevedore=WARN,taskflow=WARN | 15:51 |
*** jrist has quit IRC | 15:52 | |
*** dmk0202 has quit IRC | 15:52 | |
*** rcernin has quit IRC | 15:53 | |
stevemar | ayoung: correct, we could add pyldap in there | 15:53 |
ayoung | for the future | 15:53 |
*** tesseract has quit IRC | 15:55 | |
ayoung | stevemar, would keystone.common.ldap=DEBUG work? | 15:55 |
*** tonytan4ever has joined #openstack-keystone | 15:56 | |
*** ma9 has joined #openstack-keystone | 16:02 | |
*** afred312 has joined #openstack-keystone | 16:03 | |
*** jsavak has quit IRC | 16:04 | |
*** jsavak has joined #openstack-keystone | 16:04 | |
ma9 | Hi, I would like to configure Keystone and Swift in such a way: users can log into a host via SSH, with SSHKeys or with Password. Kerberos can be enables, but Kerberos does not generate a token if SSH Keys are used so it does not help in this case. Once the user is in, I would like to grant him the rights to push files into Swift, without the need to authenticate again or type his password. How can I do it with Keystone? We nee | 16:04 |
nisha_ | stevemar, how should reply back in the review itself, in the patch I submitted | 16:04 |
*** afred312_ has quit IRC | 16:04 | |
nisha_ | stevemar, when I use the reply option at top, it adds me too as one of the reviewers | 16:05 |
*** sdake has joined #openstack-keystone | 16:05 | |
*** shewless has quit IRC | 16:09 | |
*** krotscheck is now known as krotscheck_dcm | 16:09 | |
*** jsavak has quit IRC | 16:09 | |
*** jsavak has joined #openstack-keystone | 16:10 | |
*** aratus has quit IRC | 16:10 | |
*** lucas___ has quit IRC | 16:11 | |
*** lucas has joined #openstack-keystone | 16:12 | |
raildo | nisha_: and this is the correct way :) | 16:12 |
raildo | nisha_: just review with 0 and add a comment | 16:13 |
nisha_ | oh, alright | 16:13 |
nisha_ | raildo, thanks | 16:13 |
raildo | nisha_: yw | 16:13 |
*** shaleh has joined #openstack-keystone | 16:13 | |
*** henrynash_ has joined #openstack-keystone | 16:13 | |
*** ChanServ sets mode: +v henrynash_ | 16:13 | |
*** aratus has joined #openstack-keystone | 16:14 | |
*** tonytan4ever has quit IRC | 16:14 | |
*** lucas has quit IRC | 16:14 | |
*** lucas has joined #openstack-keystone | 16:14 | |
nisha_ | raildo, one more thing, If I want to add an inline comment, then it is getting saved as a draft | 16:15 |
nisha_ | raildo, how can i post it? | 16:15 |
*** ddieterly is now known as ddieterly[away] | 16:16 | |
raildo | nisha_: when you review, gerrit will post the inline comments. | 16:16 |
nisha_ | oh, thanks again :) | 16:16 |
raildo | nisha_: every draft comment will be a public comment | 16:16 |
shaleh | nisha_: welcome to the chaos :-) | 16:16 |
nisha_ | raildo, that's nice | 16:16 |
openstackgerrit | Mikhail Nikolaenko proposed openstack/keystone: Validate impersonation in trust redelegation https://review.openstack.org/330045 | 16:17 |
raildo | nisha_: btw, I suggest take a look on gertty :D https://github.com/openstack/gertty | 16:17 |
*** rderose has quit IRC | 16:17 | |
*** rderose has joined #openstack-keystone | 16:18 | |
nisha_ | raildo, on it :D | 16:18 |
*** lucas has quit IRC | 16:18 | |
*** tonytan4ever has joined #openstack-keystone | 16:19 | |
*** phalmos has quit IRC | 16:19 | |
*** EinstCrazy has joined #openstack-keystone | 16:20 | |
*** jaosorior has quit IRC | 16:20 | |
*** phalmos has joined #openstack-keystone | 16:20 | |
*** ddieterly[away] is now known as ddieterly | 16:21 | |
*** timcline has quit IRC | 16:21 | |
*** timcline has joined #openstack-keystone | 16:21 | |
*** Guest5 has joined #openstack-keystone | 16:22 | |
*** lucas has joined #openstack-keystone | 16:22 | |
*** Guest5 has left #openstack-keystone | 16:24 | |
*** EinstCrazy has quit IRC | 16:25 | |
*** tonytan4ever has quit IRC | 16:26 | |
*** lucas has quit IRC | 16:26 | |
*** timcline has quit IRC | 16:26 | |
*** henrynash_ has quit IRC | 16:27 | |
*** nisha_ has quit IRC | 16:28 | |
*** henrynash_ has joined #openstack-keystone | 16:31 | |
*** ChanServ sets mode: +v henrynash_ | 16:31 | |
*** nisha_ has joined #openstack-keystone | 16:31 | |
*** jaugustine has quit IRC | 16:31 | |
dolphm | stevemar: https://review.openstack.org/#/c/330057/ | 16:31 |
patchbot | dolphm: patch 330057 - python-openstackclient - Do not prompt for scope options with default scope... | 16:31 |
*** sdake has quit IRC | 16:42 | |
*** shaleh is now known as shaleh|away | 16:43 | |
*** yolanda has quit IRC | 16:46 | |
*** ddieterly is now known as ddieterly[away] | 16:47 | |
*** lucas has joined #openstack-keystone | 16:51 | |
*** lucas has quit IRC | 16:52 | |
*** lucas___ has joined #openstack-keystone | 16:52 | |
*** browne has quit IRC | 16:53 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password history requirements https://review.openstack.org/328339 | 16:53 |
*** lucas has joined #openstack-keystone | 16:54 | |
*** lucas___ has quit IRC | 16:54 | |
*** lucas___ has joined #openstack-keystone | 16:55 | |
*** lucas has quit IRC | 16:55 | |
*** lucas has joined #openstack-keystone | 16:57 | |
*** sheel has joined #openstack-keystone | 16:58 | |
*** lucas has quit IRC | 16:58 | |
*** lucas has joined #openstack-keystone | 16:59 | |
*** lucas___ has quit IRC | 16:59 | |
*** woodster_ has quit IRC | 16:59 | |
*** woodster_ has joined #openstack-keystone | 17:00 | |
*** ma9 has quit IRC | 17:01 | |
*** timcline has joined #openstack-keystone | 17:04 | |
*** lucas has quit IRC | 17:04 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password history requirements https://review.openstack.org/328339 | 17:07 |
notmorgan | dolphm: i like py3 so much more than py2.7 | 17:08 |
notmorgan | dolphm: it's... fantastic | 17:08 |
*** mvk_ has quit IRC | 17:08 | |
*** ddieterly[away] is now known as ddieterly | 17:08 | |
dolphm | notmorgan: super random but ++ lol | 17:09 |
notmorgan | dolphm: i've been doing a lot of py3 conversion work and also enjoyed pycon recently | 17:09 |
notmorgan | dolphm: i wish we could drop py2 from keystone :P | 17:09 |
dolphm | someday! | 17:10 |
*** lucas has joined #openstack-keystone | 17:10 | |
notmorgan | dolphm: hehe. actually reminds me i need to reach out to sean (python-memcached person) and fnish the import into gerrit | 17:10 |
*** amoralej is now known as amoralej|off | 17:10 | |
*** lucas___ has joined #openstack-keystone | 17:11 | |
*** lucas___ has quit IRC | 17:12 | |
*** luca_____ has joined #openstack-keystone | 17:12 | |
*** lucas has quit IRC | 17:14 | |
*** luca_____ has quit IRC | 17:15 | |
*** lucas has joined #openstack-keystone | 17:15 | |
*** jsavak has quit IRC | 17:16 | |
*** jsavak has joined #openstack-keystone | 17:16 | |
*** tonytan4ever has joined #openstack-keystone | 17:17 | |
*** lucas___ has joined #openstack-keystone | 17:19 | |
*** lucas has quit IRC | 17:19 | |
*** lucas has joined #openstack-keystone | 17:20 | |
*** pcaruana has joined #openstack-keystone | 17:21 | |
*** henrynash_ has quit IRC | 17:22 | |
*** luca_____ has joined #openstack-keystone | 17:23 | |
*** lucas___ has quit IRC | 17:23 | |
*** lucas has quit IRC | 17:24 | |
*** luca_____ has quit IRC | 17:26 | |
*** lucas has joined #openstack-keystone | 17:26 | |
*** afred312 has quit IRC | 17:29 | |
*** tqtran has joined #openstack-keystone | 17:31 | |
*** jaugustine has joined #openstack-keystone | 17:32 | |
*** jsavak has quit IRC | 17:32 | |
*** jaugustine has quit IRC | 17:33 | |
*** jaugustine has joined #openstack-keystone | 17:34 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Move project scoped tests to TokenAPITests https://review.openstack.org/330116 | 17:35 |
*** tqtran has quit IRC | 17:35 | |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Add domain functional tests https://review.openstack.org/329598 | 17:37 |
*** roxanaghe has quit IRC | 17:41 | |
*** ddieterly is now known as ddieterly[away] | 17:41 | |
*** roxanaghe has joined #openstack-keystone | 17:42 | |
*** nisha_ has quit IRC | 17:42 | |
*** jaugustine has quit IRC | 17:42 | |
*** jsavak has joined #openstack-keystone | 17:45 | |
*** henrynash_ has joined #openstack-keystone | 17:45 | |
*** ChanServ sets mode: +v henrynash_ | 17:45 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: Update driver versioning documentation https://review.openstack.org/330118 | 17:47 |
openstackgerrit | Ron De Rose proposed openstack/keystone: Update driver versioning documentation https://review.openstack.org/330118 | 17:47 |
*** mvk_ has joined #openstack-keystone | 17:49 | |
stevemar | dolphm: danke | 17:56 |
stevemar | ayoung: that should work, did it? | 17:56 |
ayoung | stevemar, no idea. I told someone else to try it | 17:57 |
ayoung | I'm in the middle of a redeploy | 17:57 |
ayoung | installer churn is the best | 17:57 |
stevemar | raildo: thanks for answering nisha's question :) | 17:57 |
stevemar | ah | 17:57 |
raildo | stevemar: np :) | 17:58 |
*** daemontool has quit IRC | 17:59 | |
dolphm | stevemar: the patch i uploaded works, yes. just revised it with a release note | 18:00 |
*** jsavak has quit IRC | 18:03 | |
samueldmq | raildo: thanks for helping nisha | 18:04 |
notmorgan | dolphm, stevemar: interesting read - http://blog.blindspotsecurity.com/2016/06/advisory-http-header-injection-in.html | 18:04 |
*** tonytan4ever has quit IRC | 18:04 | |
*** adrian_otto has joined #openstack-keystone | 18:05 | |
raildo | samueldmq: just doing our job here :D | 18:05 |
samueldmq | :) | 18:06 |
raildo | samueldmq: a long time ago in a galaxy far far away, it was us asking for help here :P | 18:06 |
dolphm | notmorgan: the redirect attack is pretty scary | 18:07 |
notmorgan | dolphm: right? | 18:07 |
stevemar | raildo: ++ for paying it forward | 18:10 |
*** mwheckmann has joined #openstack-keystone | 18:11 | |
*** tqtran has joined #openstack-keystone | 18:13 | |
*** tonytan4ever has joined #openstack-keystone | 18:16 | |
*** browne has joined #openstack-keystone | 18:17 | |
*** aratus has quit IRC | 18:18 | |
stevemar | dolphm: thanks for the patch! | 18:18 |
*** tonytan4ever has quit IRC | 18:19 | |
*** adrian_otto has quit IRC | 18:20 | |
*** EinstCrazy has joined #openstack-keystone | 18:22 | |
*** adrian_otto has joined #openstack-keystone | 18:25 | |
*** aratus has joined #openstack-keystone | 18:26 | |
*** EinstCrazy has quit IRC | 18:27 | |
*** pnavarro has joined #openstack-keystone | 18:29 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 18:31 |
notmorgan | dolphm: btw, who do i send an email to at Rax to say more good things about lbragstad ? | 18:33 |
notmorgan | dolphm: :P | 18:33 |
stevemar | dolphm: ++ | 18:33 |
stevemar | ken savich? | 18:33 |
dolphm | notmorgan: chris laco! | 18:34 |
notmorgan | stevemar: dude. GPG-ssh is awesome. | 18:34 |
notmorgan | stevemar: just sayin' | 18:34 |
notmorgan | dolphm: oh.. that means i need to talk to claco... nvm :P [j/k] | 18:34 |
stevemar | dolphm: oh i can twitter that | 18:34 |
lbragstad | lol | 18:35 |
notmorgan | stevemar: exactly :) | 18:35 |
dolphm | stevemar: ++ | 18:35 |
lbragstad | claco and i hold one-on-ones via twitter | 18:35 |
lbragstad | it's the perfect tool, meetings in 140 characters or less | 18:35 |
notmorgan | lbragstad: as long as you don't use DMs ... cause those are like 10k letters | 18:36 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password history requirements https://review.openstack.org/328339 | 18:37 |
notmorgan | stevemar: lol i just saw your tweet | 18:37 |
notmorgan | almost the same as mine | 18:37 |
*** jaugustine has joined #openstack-keystone | 18:39 | |
stevemar | :) | 18:42 |
*** ddieterly[away] has quit IRC | 18:43 | |
*** jaugustine is now known as jaugustine_ | 18:44 | |
*** ddieterly has joined #openstack-keystone | 18:44 | |
*** jaosorior has joined #openstack-keystone | 18:44 | |
*** jaugustine_ is now known as jaugustine | 18:44 | |
*** jed56 has quit IRC | 18:45 | |
*** aratus has quit IRC | 18:49 | |
*** jaugustine has quit IRC | 18:54 | |
*** henrynash_ has quit IRC | 18:54 | |
*** henrynash_ has joined #openstack-keystone | 18:58 | |
*** ChanServ sets mode: +v henrynash_ | 18:58 | |
notmorgan | stevemar: omg real office chair > couch and hurting back. | 18:59 |
stevemar | notmorgan: i use my dining room table and chair | 19:01 |
notmorgan | stevemar: i was doing that for a bit, but sinc ei'm setting up a real desk... | 19:01 |
notmorgan | i bought a real office chair | 19:01 |
notmorgan | it was the low end herman miller mirra2, but it's so muhc more comfortable than the dining room chair. | 19:01 |
notmorgan | i figure i sit in the chair enough i should get one i know is comfortable | 19:02 |
samueldmq | raildo: yes, it's important to pay it forward in the community | 19:02 |
bknudson | I got an aeron for the house. | 19:02 |
notmorgan | bknudson: yeah i looked at the aeron, but i didn't want to spend $500 more than i already did | 19:02 |
bknudson | couple years ago now | 19:02 |
*** jsavak has joined #openstack-keystone | 19:02 | |
bknudson | should last forever | 19:03 |
notmorgan | bknudson: and i know the mirra works for me, so went with the less pricy option. had i not used a mirra before, i'd have sprung for the aeron | 19:03 |
* lbragstad is rocking whatever was on sale at costco | 19:03 | |
notmorgan | bknudson: no question. and with a 12yr warranty... yeah it better last damn near forever ;) | 19:03 |
notmorgan | bknudson: but hermann miller chairs are pretty darn awesome | 19:04 |
*** diazjf has left #openstack-keystone | 19:05 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Move project scoped catalog tests to TokenAPITests https://review.openstack.org/330161 | 19:05 |
*** sheel has quit IRC | 19:05 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Move more project scoped behavior tests to TokenAPITests https://review.openstack.org/330162 | 19:05 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Consolidate domain token tests into TokenAPITests https://review.openstack.org/330163 | 19:05 |
*** afred312 has joined #openstack-keystone | 19:05 | |
*** mkrcmari__ has joined #openstack-keystone | 19:08 | |
*** tonytan4ever has joined #openstack-keystone | 19:09 | |
*** mvk_ has quit IRC | 19:11 | |
*** tonytan4ever has quit IRC | 19:14 | |
*** timcline has quit IRC | 19:25 | |
*** timcline has joined #openstack-keystone | 19:26 | |
*** timcline has quit IRC | 19:28 | |
*** timcline has joined #openstack-keystone | 19:28 | |
*** timcline_ has joined #openstack-keystone | 19:29 | |
*** timcline_ has quit IRC | 19:29 | |
*** timcline has quit IRC | 19:30 | |
*** timcline has joined #openstack-keystone | 19:30 | |
*** deberon has joined #openstack-keystone | 19:31 | |
*** ddieterly has quit IRC | 19:31 | |
deberon | Does anyone know of any documentation on getting an API v2 endpoint in mitaka? | 19:32 |
*** openstackgerrit has quit IRC | 19:33 | |
*** openstackgerrit has joined #openstack-keystone | 19:33 | |
*** jsavak has quit IRC | 19:34 | |
*** jsavak has joined #openstack-keystone | 19:35 | |
*** sdake has joined #openstack-keystone | 19:36 | |
*** sdake_ has joined #openstack-keystone | 19:40 | |
*** sdake has quit IRC | 19:42 | |
*** jaosorior has quit IRC | 19:57 | |
*** EinstCrazy has joined #openstack-keystone | 19:57 | |
*** henrynash_ has quit IRC | 19:58 | |
*** jaugustine has joined #openstack-keystone | 19:59 | |
*** krotscheck_dcm is now known as krotscheck | 20:00 | |
*** EinstCrazy has quit IRC | 20:02 | |
*** jaugustine has quit IRC | 20:03 | |
*** sdake_ has quit IRC | 20:07 | |
*** sdake has joined #openstack-keystone | 20:07 | |
*** sdake_ has joined #openstack-keystone | 20:11 | |
*** jaugustine has joined #openstack-keystone | 20:11 | |
*** phalmos has quit IRC | 20:11 | |
*** sdake has quit IRC | 20:12 | |
raildo | deberon: v2.0 was deprecated, so anything changes on v2 endpoint api in mitaka, it will be the same doc as other previous releases | 20:14 |
deberon | So if I just follow the libery release docs for setting up the identity endpoint I should be all set? | 20:15 |
raildo | deberon: I think so, if you're using v2.. | 20:17 |
deberon | Is it possible for v3 and v2 to live side by side? | 20:19 |
deberon | We have a couple integration libraries that haven't migrated to the v3 auth url yet. | 20:20 |
raildo | deberon: hum... that a trick question :P I think it's possible with some incompatibilities... | 20:21 |
*** shewless has joined #openstack-keystone | 20:22 | |
deberon | I figured there would be some :). Incompatibilties with system libraries I'm assuming? | 20:22 |
raildo | deberon: i believe so and other thinks like v3 features and api calls, that doesn't work on v2 | 20:24 |
shewless | Hi dstanek: I remember at one point you said a 404 error during SSO may indicate that the mapping file is incorrect? Is that right? | 20:24 |
*** timcline_ has joined #openstack-keystone | 20:24 | |
*** sdake_ has quit IRC | 20:27 | |
*** timcline has quit IRC | 20:28 | |
*** aratus has joined #openstack-keystone | 20:35 | |
*** julim has quit IRC | 20:39 | |
*** aratus has quit IRC | 20:43 | |
ayoung | notmorgan, ldapsearch -Y gssapi -H ldap://ldap.corp.redhat.com -b 'dc=redhat,dc=com' 'cn=Monty Taylor' 'employeeType' | 20:54 |
*** raildo is now known as raildo-afk | 21:01 | |
notmorgan | ayoung: did you not see the twitterstorm? | 21:01 |
notmorgan | :) | 21:01 |
ayoung | notmorgan, I saw the twitterstorm. I've been running that LDAP query for weeks, and it finally returns something | 21:01 |
notmorgan | lol | 21:03 |
*** jsavak has quit IRC | 21:04 | |
*** jsavak has joined #openstack-keystone | 21:05 | |
*** jsavak has quit IRC | 21:05 | |
*** jsavak has joined #openstack-keystone | 21:05 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 21:06 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Move negative domain scope test to TokenAPITests https://review.openstack.org/330215 | 21:07 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Move unscoped token test to TokenAPITests https://review.openstack.org/330216 | 21:07 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Move negative token tests to TokenAPITests https://review.openstack.org/330217 | 21:07 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Move cross domain/group/project auth tests https://review.openstack.org/330218 | 21:07 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Move more project scoped token behavior to TokenAPITests https://review.openstack.org/330219 | 21:07 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Remove test_validate_v2_unscoped_token_with_v3_api https://review.openstack.org/330220 | 21:07 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Refactor test_validate_v2_scoped_token_with_v3_api https://review.openstack.org/330221 | 21:07 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Move external auth and bind test to TokenAPITests https://review.openstack.org/330222 | 21:07 |
*** spandhe has joined #openstack-keystone | 21:08 | |
ayoung | jamielennox, can I assign this to you: https://bugzilla.redhat.com/show_bug.cgi?id=1346886 | 21:09 |
openstack | bugzilla.redhat.com bug 1346886 in python-keystoneclient "Keystone is not properly looking up the domain_id" [Unspecified,Assigned] - Assigned to ayoung | 21:09 |
*** dan_nguyen has joined #openstack-keystone | 21:11 | |
*** pauloewerton has quit IRC | 21:11 | |
*** walharthi has joined #openstack-keystone | 21:14 | |
*** ayoung has left #openstack-keystone | 21:15 | |
*** spandhe has quit IRC | 21:16 | |
*** spandhe has joined #openstack-keystone | 21:16 | |
*** gagehugo has quit IRC | 21:22 | |
*** walharthi has quit IRC | 21:30 | |
*** jaugustine has quit IRC | 21:32 | |
openstackgerrit | Merged openstack/keystone: Add service providers integration tests https://review.openstack.org/303502 | 21:38 |
openstackgerrit | Merged openstack/keystone: Add mapping rules integration tests https://review.openstack.org/305444 | 21:39 |
openstackgerrit | Merged openstack/keystone: Add protocols integration tests https://review.openstack.org/307508 | 21:39 |
*** pnavarro has quit IRC | 21:41 | |
*** aratus has joined #openstack-keystone | 21:42 | |
*** gyee has joined #openstack-keystone | 21:42 | |
*** ChanServ sets mode: +v gyee | 21:42 | |
*** dan_nguyen has quit IRC | 21:49 | |
*** deberon has quit IRC | 21:50 | |
*** aratus has quit IRC | 21:53 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Move last few TestAuth tests to TokenAPITests https://review.openstack.org/330239 | 21:54 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Remove TestAuth https://review.openstack.org/330240 | 21:54 |
*** edtubill has quit IRC | 21:58 | |
*** mwheckmann has quit IRC | 22:02 | |
*** EinstCrazy has joined #openstack-keystone | 22:02 | |
*** jsavak has quit IRC | 22:02 | |
*** openstackgerrit has quit IRC | 22:02 | |
*** aratus has joined #openstack-keystone | 22:04 | |
*** catintheroof has joined #openstack-keystone | 22:04 | |
*** openstackgerrit has joined #openstack-keystone | 22:05 | |
*** EinstCrazy has quit IRC | 22:07 | |
*** timcline_ has quit IRC | 22:08 | |
*** adrian_otto1 has joined #openstack-keystone | 22:20 | |
*** adrian_otto has quit IRC | 22:23 | |
*** roxanaghe has quit IRC | 22:26 | |
*** adrian_otto1 has quit IRC | 22:26 | |
*** adrian_otto has joined #openstack-keystone | 22:27 | |
*** roxanaghe has joined #openstack-keystone | 22:28 | |
*** roxanaghe has quit IRC | 22:30 | |
*** roxanaghe has joined #openstack-keystone | 22:30 | |
*** frontrunner has quit IRC | 22:31 | |
*** aratus has quit IRC | 22:37 | |
*** edmondsw has quit IRC | 22:40 | |
*** catintheroof has quit IRC | 22:41 | |
*** aratus has joined #openstack-keystone | 22:53 | |
*** woodburn has quit IRC | 22:53 | |
*** woodburn has joined #openstack-keystone | 22:55 | |
*** henrynash_ has joined #openstack-keystone | 22:55 | |
*** ChanServ sets mode: +v henrynash_ | 22:55 | |
openstackgerrit | Colleen Murphy proposed openstack/keystoneauth: Fix kerberos available property https://review.openstack.org/330265 | 22:56 |
crinkle | jamielennox: ^ | 22:57 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!