*** openstack has joined #openstack-keystone | 05:42 | |
*** openstack has joined #openstack-keystone | 05:57 | |
*** orwell.freenode.net sets mode: +ns | 05:57 | |
*** orwell.freenode.net sets mode: -o openstack | 05:57 | |
-orwell.freenode.net- *** Notice -- TS for #openstack-keystone changed from 1466056639 to 1377384024 | 05:57 | |
*** orwell.freenode.net sets mode: +cgt-s | 05:57 | |
*** jaosorior has joined #openstack-keystone | 05:57 | |
*** GB21 has joined #openstack-keystone | 05:57 | |
*** EinstCrazy has joined #openstack-keystone | 05:57 | |
*** david-lyle_ has joined #openstack-keystone | 05:57 | |
*** sheel has joined #openstack-keystone | 05:57 | |
*** mvk_ has joined #openstack-keystone | 05:57 | |
*** jefrite has joined #openstack-keystone | 05:57 | |
*** mkoderer__ has joined #openstack-keystone | 05:57 | |
*** markvoelker_ has joined #openstack-keystone | 05:57 | |
*** SpamapS has joined #openstack-keystone | 05:57 | |
*** mordred has joined #openstack-keystone | 05:57 | |
*** mdavidson has joined #openstack-keystone | 05:57 | |
*** _sigmavirus24 has joined #openstack-keystone | 05:57 | |
*** NikitaKonovalov has joined #openstack-keystone | 05:57 | |
*** DinaBelova has joined #openstack-keystone | 05:57 | |
*** freerunner has joined #openstack-keystone | 05:57 | |
*** htruta` has joined #openstack-keystone | 05:57 | |
*** bj0rnar- has joined #openstack-keystone | 05:57 | |
*** bknudson_ has joined #openstack-keystone | 05:57 | |
*** bapalm has joined #openstack-keystone | 05:57 | |
*** adam_g has joined #openstack-keystone | 05:57 | |
*** robcresswell has joined #openstack-keystone | 05:57 | |
*** BAKfr has joined #openstack-keystone | 05:57 | |
*** barclaac_ has joined #openstack-keystone | 05:57 | |
*** raildo-a` has joined #openstack-keystone | 05:57 | |
*** bigjools has joined #openstack-keystone | 05:57 | |
*** breton_ has joined #openstack-keystone | 05:57 | |
*** kragniz has joined #openstack-keystone | 05:57 | |
*** x58 has joined #openstack-keystone | 05:57 | |
*** pleia2 has joined #openstack-keystone | 05:57 | |
*** Daviey_ has joined #openstack-keystone | 05:57 | |
*** Anticime1 has joined #openstack-keystone | 05:57 | |
*** boltR_ has joined #openstack-keystone | 05:57 | |
*** rmstar_ has joined #openstack-keystone | 05:57 | |
*** patchbot has joined #openstack-keystone | 05:57 | |
*** haneef_ has joined #openstack-keystone | 05:57 | |
*** woodburn has joined #openstack-keystone | 05:57 | |
*** openstackgerrit has joined #openstack-keystone | 05:57 | |
*** shewless has joined #openstack-keystone | 05:57 | |
*** afred312 has joined #openstack-keystone | 05:57 | |
*** ktychkova has joined #openstack-keystone | 05:57 | |
*** rodrigods has joined #openstack-keystone | 05:57 | |
*** wasmum has joined #openstack-keystone | 05:57 | |
*** aloga has joined #openstack-keystone | 05:57 | |
*** permalac has joined #openstack-keystone | 05:57 | |
*** orwell.freenode.net sets mode: +v bknudson_ | 05:57 | |
*** Dinesh_Bhor has joined #openstack-keystone | 05:57 | |
*** dancn has joined #openstack-keystone | 05:57 | |
*** zzzeek has joined #openstack-keystone | 05:57 | |
*** dhellmann has joined #openstack-keystone | 05:57 | |
*** nkinder has joined #openstack-keystone | 05:57 | |
*** sileht has joined #openstack-keystone | 05:57 | |
*** harlowja_ has joined #openstack-keystone | 05:57 | |
*** lifeless has joined #openstack-keystone | 05:57 | |
*** elmiko has joined #openstack-keystone | 05:57 | |
*** alex_xu has joined #openstack-keystone | 05:57 | |
*** clenimar has joined #openstack-keystone | 05:57 | |
*** vnogin has joined #openstack-keystone | 05:57 | |
*** ericksonsantos has joined #openstack-keystone | 05:57 | |
*** ashokt has joined #openstack-keystone | 05:57 | |
*** dulek has joined #openstack-keystone | 05:57 | |
*** opilotte- has joined #openstack-keystone | 05:57 | |
*** anteaya has joined #openstack-keystone | 05:57 | |
*** chlong has joined #openstack-keystone | 05:57 | |
*** hoonetorg has joined #openstack-keystone | 05:57 | |
*** dobson has joined #openstack-keystone | 05:57 | |
*** agireud has joined #openstack-keystone | 05:57 | |
*** jdennis has joined #openstack-keystone | 05:57 | |
*** amoralej|off has joined #openstack-keystone | 05:57 | |
*** flaper87 has joined #openstack-keystone | 05:57 | |
*** iurygregory has joined #openstack-keystone | 05:57 | |
*** wanghua has joined #openstack-keystone | 05:57 | |
*** amrith has joined #openstack-keystone | 05:57 | |
*** gabriel-bezerra has joined #openstack-keystone | 05:57 | |
*** lunarlamp has joined #openstack-keystone | 05:57 | |
*** jamielennox has joined #openstack-keystone | 05:57 | |
*** zigo has joined #openstack-keystone | 05:57 | |
*** nikhil has joined #openstack-keystone | 05:57 | |
*** andreykurilin__ has joined #openstack-keystone | 05:57 | |
*** briancurtin has joined #openstack-keystone | 05:57 | |
*** DuncanT has joined #openstack-keystone | 05:57 | |
*** serverascode has joined #openstack-keystone | 05:57 | |
*** andrewbogott has joined #openstack-keystone | 05:57 | |
*** ctracey has joined #openstack-keystone | 05:57 | |
*** clayton has joined #openstack-keystone | 05:57 | |
*** mgagne has joined #openstack-keystone | 05:57 | |
*** mtreinish has joined #openstack-keystone | 05:57 | |
*** timburke has joined #openstack-keystone | 05:57 | |
*** tpeoples has joined #openstack-keystone | 05:57 | |
*** chris_hultin has joined #openstack-keystone | 05:57 | |
*** lmiccini has joined #openstack-keystone | 05:57 | |
*** orwell.freenode.net sets mode: +v jamielennox | 05:57 | |
*** d0ugal has joined #openstack-keystone | 05:57 | |
*** rdo has joined #openstack-keystone | 05:57 | |
*** boris-42 has joined #openstack-keystone | 05:57 | |
*** zhiyan has joined #openstack-keystone | 05:57 | |
*** jraim has joined #openstack-keystone | 05:57 | |
*** frickler has joined #openstack-keystone | 05:57 | |
*** martinus__ has joined #openstack-keystone | 05:57 | |
*** toddnni has joined #openstack-keystone | 05:57 | |
*** rm_work has joined #openstack-keystone | 05:57 | |
*** krotscheck has joined #openstack-keystone | 05:57 | |
*** dgonzalez has joined #openstack-keystone | 05:57 | |
*** mancdaz has joined #openstack-keystone | 05:57 | |
*** amakarov has joined #openstack-keystone | 05:57 | |
*** jistr has joined #openstack-keystone | 05:57 | |
*** med_ has joined #openstack-keystone | 05:57 | |
*** cburgess has joined #openstack-keystone | 05:57 | |
*** nonameentername has joined #openstack-keystone | 05:57 | |
*** topol has joined #openstack-keystone | 05:57 | |
*** dmellado has joined #openstack-keystone | 05:57 | |
*** Tridde has joined #openstack-keystone | 05:57 | |
*** sudorandom has joined #openstack-keystone | 05:57 | |
*** briancline has joined #openstack-keystone | 05:57 | |
*** auggy has joined #openstack-keystone | 05:57 | |
*** mugsie has joined #openstack-keystone | 05:57 | |
*** hogepodge has joined #openstack-keystone | 05:57 | |
*** basilAB has joined #openstack-keystone | 05:57 | |
*** johnthetubaguy has joined #openstack-keystone | 05:57 | |
*** samueldmq has joined #openstack-keystone | 05:57 | |
*** charz_ has joined #openstack-keystone | 05:57 | |
*** bradjones has joined #openstack-keystone | 05:57 | |
*** tonyb has joined #openstack-keystone | 05:57 | |
*** BrAsS_mOnKeY has joined #openstack-keystone | 05:57 | |
*** crinkle has joined #openstack-keystone | 05:57 | |
*** tlbr has joined #openstack-keystone | 05:57 | |
*** afazekas has joined #openstack-keystone | 05:57 | |
*** notmorgan has joined #openstack-keystone | 05:57 | |
*** xek has joined #openstack-keystone | 05:57 | |
*** david_cu has joined #openstack-keystone | 05:57 | |
*** dims has joined #openstack-keystone | 05:57 | |
*** dtroyer has joined #openstack-keystone | 05:57 | |
*** henrynash has joined #openstack-keystone | 05:57 | |
*** d34dh0r53 has joined #openstack-keystone | 05:57 | |
*** knikolla has joined #openstack-keystone | 05:57 | |
*** _fortis has joined #openstack-keystone | 05:57 | |
*** akscram has joined #openstack-keystone | 05:57 | |
*** orwell.freenode.net sets mode: +vvv topol samueldmq henrynash | 05:57 | |
*** baffle has joined #openstack-keystone | 05:57 | |
*** ianw has joined #openstack-keystone | 05:57 | |
*** rha has joined #openstack-keystone | 05:57 | |
*** buhman has joined #openstack-keystone | 05:57 | |
*** hockeynut has joined #openstack-keystone | 05:57 | |
*** jlk has joined #openstack-keystone | 05:57 | |
*** BlackDex has joined #openstack-keystone | 05:57 | |
*** mhu has joined #openstack-keystone | 05:57 | |
*** brad[] has joined #openstack-keystone | 05:57 | |
*** hugokuo has joined #openstack-keystone | 05:57 | |
*** dolphm has joined #openstack-keystone | 05:57 | |
*** hughsaunders has joined #openstack-keystone | 05:57 | |
*** stian_ has joined #openstack-keystone | 05:57 | |
*** gus has joined #openstack-keystone | 05:57 | |
*** eglute has joined #openstack-keystone | 05:57 | |
*** mjb has joined #openstack-keystone | 05:57 | |
*** dutsmoc has joined #openstack-keystone | 05:57 | |
*** odyssey4me has joined #openstack-keystone | 05:57 | |
*** lbragstad has joined #openstack-keystone | 05:57 | |
*** dstanek has joined #openstack-keystone | 05:57 | |
*** jhesketh has joined #openstack-keystone | 05:57 | |
*** skoude_ has joined #openstack-keystone | 05:57 | |
*** Dave has joined #openstack-keystone | 05:57 | |
*** darrenc has joined #openstack-keystone | 05:57 | |
*** yarkot has joined #openstack-keystone | 05:57 | |
*** Nakato has joined #openstack-keystone | 05:57 | |
*** sshen_ has joined #openstack-keystone | 05:57 | |
*** kfox1111 has joined #openstack-keystone | 05:57 | |
*** Kimmo__ has joined #openstack-keystone | 05:57 | |
*** evrardjp has joined #openstack-keystone | 05:57 | |
*** yarkot1 has joined #openstack-keystone | 05:57 | |
*** vkmc has joined #openstack-keystone | 05:57 | |
*** kevinbenton has joined #openstack-keystone | 05:57 | |
*** gsilvis has joined #openstack-keystone | 05:57 | |
*** zeus has joined #openstack-keystone | 05:57 | |
*** ekarlso has joined #openstack-keystone | 05:57 | |
*** stevemar has joined #openstack-keystone | 05:57 | |
*** tsufiev has joined #openstack-keystone | 05:57 | |
*** jidar has joined #openstack-keystone | 05:57 | |
*** mnaser has joined #openstack-keystone | 05:57 | |
*** trey has joined #openstack-keystone | 05:57 | |
*** rvba has joined #openstack-keystone | 05:57 | |
*** andreaf has joined #openstack-keystone | 05:57 | |
*** fungi has joined #openstack-keystone | 05:57 | |
*** jlvillal has joined #openstack-keystone | 05:57 | |
*** orwell.freenode.net sets mode: +ovo dolphm dstanek stevemar | 05:57 | |
*** ChanServ has joined #openstack-keystone | 05:57 | |
*** notmyname has joined #openstack-keystone | 05:57 | |
*** redrobot has joined #openstack-keystone | 05:57 | |
*** EmilienM has joined #openstack-keystone | 05:57 | |
*** orwell.freenode.net sets mode: +o ChanServ | 05:57 | |
*** orwell.freenode.net sets mode: +bbbb *!bjornar_@* bjornar!*@* bjornar__!*@* *!awrbgh@197.123.75.191 | 05:57 | |
*** orwell.freenode.net sets mode: +qq uvirtbot!*@* uvirbot!*@* | 05:57 | |
*** orwell.freenode.net changes topic to "Newton Deadlines: http://releases.openstack.org/newton/schedule.html | Midcycle (July 20-22, San Jose, CA) wiki https://wiki.openstack.org/wiki/Sprints/KeystoneNewtonSprint | Meeting Etherpad https://etherpad.openstack.org/p/keystone-weekly-meeting" | 05:57 | |
*** alex_xu has quit IRC | 06:03 | |
*** alex_xu has joined #openstack-keystone | 06:06 | |
openstackgerrit | Jamie Lennox proposed openstack/keystone-specs: Reservations (a working title) https://review.openstack.org/330329 | 06:12 |
---|---|---|
*** yolanda has joined #openstack-keystone | 06:18 | |
jamielennox | stevemar: still here? | 06:19 |
*** yolanda has quit IRC | 06:21 | |
*** yolanda has joined #openstack-keystone | 06:24 | |
*** rcernin has joined #openstack-keystone | 06:24 | |
*** EinstCrazy has quit IRC | 06:28 | |
*** EinstCrazy has joined #openstack-keystone | 06:29 | |
*** EinstCrazy has quit IRC | 06:30 | |
*** EinstCrazy has joined #openstack-keystone | 06:30 | |
*** EinstCrazy has quit IRC | 06:41 | |
*** EinstCrazy has joined #openstack-keystone | 06:45 | |
*** afazekas is now known as afazekas|dentist | 06:52 | |
openstackgerrit | Jamie Lennox proposed openstack/keystone-specs: Reservations (a working title) https://review.openstack.org/330329 | 06:58 |
jamielennox | @channel: please read ^ | 06:58 |
*** markvoelker_ has quit IRC | 07:01 | |
*** markvoelker has joined #openstack-keystone | 07:01 | |
*** amoralej|off is now known as amoralej | 07:05 | |
*** tesseract has joined #openstack-keystone | 07:09 | |
*** jamielennox is now known as jamielennox|away | 07:12 | |
*** jed56 has joined #openstack-keystone | 07:16 | |
*** pcaruana has joined #openstack-keystone | 07:17 | |
*** permalac has quit IRC | 07:19 | |
*** zengchen has joined #openstack-keystone | 07:23 | |
*** roxanaghe has joined #openstack-keystone | 07:27 | |
zengchen | Hi guys, please give me a help. how to get the nova or cinder's endpoint in my service if the catalog in the token is empty? i see the policy for 'list_endpoits' is admin, but i am not the admin. thanks. | 07:28 |
*** GB21 has quit IRC | 07:31 | |
*** roxanaghe has quit IRC | 07:32 | |
*** nisha_ has joined #openstack-keystone | 07:37 | |
*** ebarrera has joined #openstack-keystone | 07:42 | |
*** henrynash_ has joined #openstack-keystone | 07:44 | |
*** ChanServ sets mode: +v henrynash_ | 07:44 | |
notmorgan | jamielennox|away: interesting | 07:52 |
*** jinquan has joined #openstack-keystone | 07:59 | |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:00 | |
*** pnavarro has joined #openstack-keystone | 08:07 | |
*** jaosorior has quit IRC | 08:07 | |
*** jaosorior has joined #openstack-keystone | 08:08 | |
*** permalac has joined #openstack-keystone | 08:09 | |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 08:10 |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 08:10 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Disable inactive users requirements https://review.openstack.org/328447 | 08:20 |
*** GB21 has joined #openstack-keystone | 08:32 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Disable inactive users requirements https://review.openstack.org/328447 | 08:39 |
*** jamie_h has joined #openstack-keystone | 08:43 | |
*** nisha_ has quit IRC | 08:53 | |
*** nisha_ has joined #openstack-keystone | 08:53 | |
*** roxanaghe has joined #openstack-keystone | 09:00 | |
*** dmk0202 has joined #openstack-keystone | 09:02 | |
*** roxanaghe has quit IRC | 09:06 | |
openstackgerrit | Merged openstack/keystone: Move TestAuth unscoped token tests to TokenAPITests https://review.openstack.org/329589 | 09:10 |
*** mkoderer__ has quit IRC | 09:28 | |
*** TxGVNN has joined #openstack-keystone | 09:32 | |
*** TxGVNN has quit IRC | 09:37 | |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 10:10 |
*** zqfan has joined #openstack-keystone | 10:10 | |
*** jamielennox|away is now known as jamielennox | 10:15 | |
*** mvk_ has quit IRC | 10:26 | |
*** sdake has joined #openstack-keystone | 10:40 | |
*** sdake_ has joined #openstack-keystone | 10:42 | |
*** rakhmerov has joined #openstack-keystone | 10:44 | |
*** sdake has quit IRC | 10:45 | |
*** gnuoy has joined #openstack-keystone | 10:46 | |
*** mvk_ has joined #openstack-keystone | 10:53 | |
*** GB21 has quit IRC | 10:53 | |
*** nisha__ has joined #openstack-keystone | 10:54 | |
*** nisha_ has quit IRC | 10:57 | |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: WIP - oidc: fix OpenID Connect authorization code grant_type https://review.openstack.org/330006 | 10:58 |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: oidc: move scope into _OidcBase https://review.openstack.org/330463 | 10:58 |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: WIP - oidc: add discovery document support https://review.openstack.org/330464 | 10:58 |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: oidc: remove grant_type argument https://review.openstack.org/330465 | 10:58 |
*** roxanaghe has joined #openstack-keystone | 11:02 | |
*** roxanaghe has quit IRC | 11:07 | |
*** sdake_ has quit IRC | 11:10 | |
openstackgerrit | Mikhail Nikolaenko proposed openstack/keystone: Validate impersonation in trust redelegation https://review.openstack.org/330045 | 11:26 |
*** jed56 has quit IRC | 11:34 | |
*** jed56 has joined #openstack-keystone | 11:34 | |
*** ddieterly has joined #openstack-keystone | 11:47 | |
*** GB21 has joined #openstack-keystone | 11:48 | |
*** amoralej is now known as amoralej|lunch | 11:58 | |
*** roxanaghe has joined #openstack-keystone | 12:03 | |
*** sdake has joined #openstack-keystone | 12:05 | |
samueldmq | jamielennox: auth_token.__init__ imported opts, and opts needed auth_token._opts. when evaluating auth_token._opts, it passes by auth_token.__init__ again | 12:05 |
*** ddieterly is now known as ddieterly[away] | 12:05 | |
*** henrynash_ has quit IRC | 12:06 | |
*** nisha__ is now known as nisha_ | 12:07 | |
*** roxanaghe has quit IRC | 12:08 | |
*** GB21 has quit IRC | 12:15 | |
*** GB21 has joined #openstack-keystone | 12:17 | |
*** rcernin has quit IRC | 12:24 | |
*** nisha_ has quit IRC | 12:25 | |
*** nisha_ has joined #openstack-keystone | 12:25 | |
*** lamt has joined #openstack-keystone | 12:31 | |
*** ddieterly has joined #openstack-keystone | 12:32 | |
stevemar | o/ | 12:33 |
stevemar | morning folks | 12:33 |
*** pauloewerton has joined #openstack-keystone | 12:35 | |
*** rcernin has joined #openstack-keystone | 12:39 | |
samueldmq | stevemar: o/ | 12:39 |
*** julim has joined #openstack-keystone | 12:39 | |
*** mwheckmann has joined #openstack-keystone | 12:40 | |
*** ddieterly is now known as ddieterly[away] | 12:41 | |
*** ddieterly[away] has quit IRC | 12:41 | |
*** edmondsw has joined #openstack-keystone | 12:45 | |
*** rodrigods has quit IRC | 12:46 | |
*** rodrigods has joined #openstack-keystone | 12:46 | |
*** elmiko has left #openstack-keystone | 12:52 | |
*** GB21 has quit IRC | 12:53 | |
*** rcernin has quit IRC | 12:54 | |
*** nisha__ has joined #openstack-keystone | 12:55 | |
*** jsavak has joined #openstack-keystone | 12:55 | |
*** nisha_ has quit IRC | 12:57 | |
aloga | stevemar: hi there | 13:02 |
*** roxanaghe has joined #openstack-keystone | 13:04 | |
*** amoralej|lunch is now known as amoralej | 13:05 | |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Add domain functional tests https://review.openstack.org/329598 | 13:06 |
*** rcernin has joined #openstack-keystone | 13:07 | |
openstackgerrit | Merged openstack/keystone: Update driver versioning documentation https://review.openstack.org/330118 | 13:08 |
*** roxanaghe has quit IRC | 13:08 | |
*** pnavarro has quit IRC | 13:09 | |
*** nisha_ has joined #openstack-keystone | 13:14 | |
*** nisha_ has quit IRC | 13:14 | |
openstackgerrit | Rodrigo Duarte proposed openstack/keystone: Fix some nits in integration tests https://review.openstack.org/330537 | 13:16 |
*** EinstCrazy has quit IRC | 13:20 | |
*** EinstCrazy has joined #openstack-keystone | 13:21 | |
*** EinstCrazy has quit IRC | 13:26 | |
*** raildo-a` is now known as raildo | 13:27 | |
*** frontrunner has joined #openstack-keystone | 13:30 | |
*** roxanaghe has joined #openstack-keystone | 13:32 | |
*** roxanaghe has quit IRC | 13:32 | |
*** roxanaghe has joined #openstack-keystone | 13:33 | |
*** roxanaghe has quit IRC | 13:33 | |
*** ddieterly has joined #openstack-keystone | 13:40 | |
stevemar | aloga: good morning (or good evening for you) | 13:41 |
*** ddieterly is now known as ddieterly[away] | 13:44 | |
*** _sigmavirus24 is now known as sigmavirus24 | 13:46 | |
*** sigmavirus24 has joined #openstack-keystone | 13:46 | |
*** rderose has joined #openstack-keystone | 13:47 | |
rderose | henrynash: are you there? | 13:48 |
*** ddieterly[away] is now known as ddieterly | 13:49 | |
shewless | Hi. Does anyone here know if there is an easy way to query an Identity provider for a list of attributes that it provides? I have a working SP connected to testshib but I'm having trouble determining what attributes are available to me. | 13:50 |
*** adrian_otto has joined #openstack-keystone | 13:52 | |
*** adrian_otto has quit IRC | 13:54 | |
rodrigods | shewless, as a Service Provider: https://www.testshib.org/test.html | 13:55 |
shewless | rodrigods: thanks! I've been there.. and I've tried accessing https://yourhost.org/Shibboleth.sso/Session but I think it only shows me the attributes I've already requested (not all available). | 13:56 |
*** richm has joined #openstack-keystone | 13:58 | |
*** jaugustine has joined #openstack-keystone | 14:00 | |
*** jaugustine has quit IRC | 14:00 | |
*** jaugustine has joined #openstack-keystone | 14:01 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: WIP/DNM Unified delegation assignment driver https://review.openstack.org/291318 | 14:01 |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Delegation parent discovery function https://review.openstack.org/330573 | 14:01 |
*** woodster_ has joined #openstack-keystone | 14:01 | |
*** rderose_ has joined #openstack-keystone | 14:05 | |
*** sheel has quit IRC | 14:05 | |
shewless | rodrigods: I confirmed that the Session page only shows me what I ask for in /etc/shibboleth/attribute-map.xml. I'd like to find a "username" of such field (without the email part) but I dont' know what's available on the IDP side | 14:06 |
*** nisha__ is now known as nisha_ | 14:08 | |
*** rderose has quit IRC | 14:08 | |
*** jaugustine has quit IRC | 14:16 | |
*** daemontool has joined #openstack-keystone | 14:19 | |
*** lucas___ has joined #openstack-keystone | 14:23 | |
stevemar | biab, dental app | 14:23 |
*** jistr is now known as jistr|mtg | 14:28 | |
*** ayoung has joined #openstack-keystone | 14:30 | |
*** ChanServ sets mode: +v ayoung | 14:30 | |
*** sheel has joined #openstack-keystone | 14:30 | |
*** jorge_munoz has joined #openstack-keystone | 14:31 | |
*** edtubill has joined #openstack-keystone | 14:32 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 14:33 |
*** adrian_otto has joined #openstack-keystone | 14:34 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 14:35 |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 14:36 |
*** jaugustine has joined #openstack-keystone | 14:37 | |
*** adrian_otto has quit IRC | 14:38 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 14:40 |
*** pcaruana has quit IRC | 14:41 | |
*** henrynash_ has joined #openstack-keystone | 14:42 | |
*** ChanServ sets mode: +v henrynash_ | 14:42 | |
henrynash | redrose: hi | 14:42 |
henrynash | rderose: hi | 14:43 |
*** gordc has joined #openstack-keystone | 14:45 | |
*** adrian_otto has joined #openstack-keystone | 14:46 | |
*** timcline has joined #openstack-keystone | 14:46 | |
*** timcline has quit IRC | 14:46 | |
notmorgan | o/ | 14:46 |
*** timcline has joined #openstack-keystone | 14:47 | |
*** roxanaghe has joined #openstack-keystone | 14:47 | |
*** jaosorior has quit IRC | 14:49 | |
*** roxanaghe has quit IRC | 14:52 | |
*** sdake has quit IRC | 14:54 | |
*** nisha__ has joined #openstack-keystone | 14:54 | |
lbragstad | rderose_ ^ | 14:54 |
rderose_ | lbragstad: yes | 14:55 |
lbragstad | rderose_ henrynash was looking for you | 14:55 |
rderose_ | ah, thx | 14:55 |
henrynash | lbragstad:….only ‘cause he was looking for me :-) | 14:55 |
lbragstad | rderose_ also, it doesn't look like much changed with https://review.openstack.org/#/c/314284/84 except addressing henrynash's comment on patchset 80? | 14:55 |
patchbot | lbragstad: patch 314284 - keystone - PCI-DSS Password SQL model changes | 14:55 |
rderose_ | henrynash: hi, had a question regarding your comment on disable active users | 14:56 |
rderose_ | henrynash: but see you've responded, let me read your latest comment | 14:57 |
*** nisha_ has quit IRC | 14:57 | |
henrynash | rederose_: sure…Ok, yes - I should ahve explained my concern in more detail….I may just be misunderstanding what you intended | 14:57 |
*** EinstCrazy has joined #openstack-keystone | 14:58 | |
notmorgan | lbragstad: patchset 80... and not becsuse of back/forth/bikeshedding | 14:58 |
notmorgan | lbragstad: rderose_ is trying to get the alltime-patchset-count-for-a-review-in-keystone award | 14:58 |
lbragstad | notmorgan he's getting close :) | 14:59 |
*** sdake has joined #openstack-keystone | 14:59 | |
rderose_ | henrynash: no, I think you are understanding my intent. hmm... | 14:59 |
rderose_ | henrynash: maybe migrated_at would be better... not sure I like that, but see your point regarding created_at | 15:00 |
*** david-lyle_ is now known as david-lyle | 15:00 | |
rderose_ | henrynash: thx | 15:00 |
rderose_ | notmorgan: hahah, yeah | 15:01 |
henrynash | rederose_: ok | 15:01 |
rderose_ | notmorgan: what's the record? | 15:01 |
notmorgan | rderose_: 80-something... but like 120 if you include the followup patch for trusts :P | 15:02 |
notmorgan | rderose_: since it landed: code, tests in two patches | 15:02 |
notmorgan | otherwise i think stevemar holds the record | 15:02 |
rderose_ | notmorgan: cool, I'll aim for that :) | 15:02 |
henrynash | rderose_: I guess I would also say, that the reult of this approach, hwoever, would be you haev this field in the DB that is effectively olny used for a temporary period….seems wasteful (although downright terrible) | 15:02 |
*** walharthi has joined #openstack-keystone | 15:03 | |
*** pushkaru has joined #openstack-keystone | 15:03 | |
rderose_ | henrynash: yeah, maybe... | 15:03 |
henrynash | rderose_: your objection to setting last_auth_at to now() on migration is, I assume, that it is a little misleading? (Even through the audit even on auth is the notifcation that gets sent….peopel shouldn’t really be using these DB fields for audit purposes) | 15:04 |
henrynash | redrose_: (typo in my early messge… I meanst to say “although not downright terrible”..freudian slip! | 15:05 |
*** ebarrera has quit IRC | 15:06 | |
rderose_ | henrynash: well, my intent is to only set last_auth_at to now when authentication happens | 15:06 |
henrynash | rderose_: which in general is exactly right, of course, it’s all about how we handle this period between migation and next auth | 15:07 |
rderose_ | henrynash: exactly | 15:07 |
henrynash | rderose_: however, we know last_auth_at can only tend towards correctness for the user population as a whole (i.e. a value of None just means “I don’t know when/if this person last authenticated, but I know it is not since you migrated to Newton”) | 15:11 |
*** jistr|mtg is now known as jistr | 15:19 | |
*** aratus has joined #openstack-keystone | 15:24 | |
shewless | okay I see I was missing in the log it mentions which oids are available but skipped. | 15:33 |
shewless | but my problem now is I'm trying to ask for an attribute specifically and it's still being "skipped". <Attribute name="urn:mace:dir:attribute-def:manager" id="manager"/>. I know this isn't a "SP/IDP" board but I'm hoping you can help me . | 15:34 |
*** openstackgerrit has quit IRC | 15:34 | |
*** openstackgerrit has joined #openstack-keystone | 15:34 | |
*** adrian_otto has quit IRC | 15:34 | |
*** raddaoui has joined #openstack-keystone | 15:36 | |
*** jaugustine has quit IRC | 15:37 | |
*** adrian_otto has joined #openstack-keystone | 15:44 | |
*** nkinder has quit IRC | 15:47 | |
*** aratus has quit IRC | 15:47 | |
*** roxanaghe has joined #openstack-keystone | 15:48 | |
*** ddieterly is now known as ddieterly[away] | 15:51 | |
*** ddieterly[away] is now known as ddieterly | 15:51 | |
*** aratus has joined #openstack-keystone | 15:52 | |
*** roxanaghe has quit IRC | 15:53 | |
*** EinstCrazy has quit IRC | 15:53 | |
*** belmoreira has joined #openstack-keystone | 15:56 | |
shewless | I couldn't get the manager one to work but I was able to get all of the other skipped ones to work. Now I've mapped the "name" field to "sn" - but I still get a 404 error | 15:58 |
shewless | here is my mapping file: http://paste.ubuntu.com/17400397/ | 15:58 |
*** nkinder has joined #openstack-keystone | 15:58 | |
*** tesseract has quit IRC | 16:00 | |
*** lucas___ has quit IRC | 16:00 | |
*** lucas___ has joined #openstack-keystone | 16:01 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: WIP/DNM Unified delegation assignment driver https://review.openstack.org/291318 | 16:03 |
*** gyee has joined #openstack-keystone | 16:06 | |
*** ChanServ sets mode: +v gyee | 16:06 | |
*** lucas___ has quit IRC | 16:06 | |
*** BjoernT has joined #openstack-keystone | 16:06 | |
shewless | If I only have 1 identity provider do I need to set the remote id using a command like this: openstack identity provider set --remote-id <remote-id> <idp-id> | 16:08 |
shewless | or is it enough to specify it in my metadata only? | 16:09 |
shewless | dstanek: any chance you are around? I'm close to getting federation to work but I'm stuck. I get a "page not found" error for v3/auth/OS-FEDERATION/websso/saml2 | 16:10 |
shewless | I see that I'm getting attributes from the IDP (testshib) but I'm not sure why the page not found error is occuring | 16:10 |
*** roxanaghe has joined #openstack-keystone | 16:10 | |
*** roxanaghe has quit IRC | 16:10 | |
shewless | what is responsible for ensuring that v3/auth/OS-FEDERATION/websso/saml2 is available? | 16:11 |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Delegation parent discovery function https://review.openstack.org/330573 | 16:11 |
openstackgerrit | Alexander Makarov proposed openstack/keystone: WIP/DNM Unified delegation assignment driver https://review.openstack.org/291318 | 16:13 |
*** permalac has quit IRC | 16:15 | |
*** timcline_ has joined #openstack-keystone | 16:15 | |
stevemar | notmorgan: rderose_ the record is held by ayoung for revoke events :) | 16:17 |
stevemar | i come in second | 16:17 |
openstackgerrit | henry-nash proposed openstack/keystone: WIP - Add framework for supporting microversions https://review.openstack.org/330674 | 16:17 |
*** timcline has quit IRC | 16:19 | |
*** sdake has quit IRC | 16:20 | |
*** timcline_ has quit IRC | 16:21 | |
*** bunting has joined #openstack-keystone | 16:21 | |
*** timcline has joined #openstack-keystone | 16:21 | |
*** bunting has left #openstack-keystone | 16:22 | |
gyee | henrynash, a question for ya on DSR | 16:23 |
henrynash | gyee: shot | 16:23 |
henrynash | shoot even | 16:23 |
gyee | can both prior and implied role be in the same domain? | 16:24 |
*** jsavak has quit IRC | 16:24 | |
shewless | anyone? I'm really stuck on this part | 16:24 |
gyee | I am guessing yes | 16:24 |
henrynash | gyee: you mean can one dsr imply another drs? | 16:24 |
henrynash | (dsr) | 16:25 |
gyee | henrynash, yes | 16:25 |
henrynash | gyee: yes, as far as I know | 16:25 |
gyee | with the vanilla policy.json this is allowed, but not policy.v3 | 16:25 |
gyee | so this is a bug then | 16:26 |
*** bunting has joined #openstack-keystone | 16:26 | |
gyee | henrynash, I will file a bug to earn more karma points :-) | 16:26 |
henrynash | gyee: you be rackin’ up, bro | 16:27 |
*** jsavak has joined #openstack-keystone | 16:27 | |
gyee | shewless, you are trying to setup WebSSO? | 16:28 |
dstanek | shewless: is that url configured to go to keystone and is the 404 an apache error or keystone one? | 16:28 |
*** sdake has joined #openstack-keystone | 16:28 | |
*** ddieterly is now known as ddieterly[away] | 16:29 | |
shewless | gyee: yes, dstanek: I have configured that URL in apache but I'm not sure what you mean about keystone. The 404 is an apache error | 16:29 |
henrynash | jamielennox: hi | 16:29 |
bunting | Hi, would someone be able to tell me the current state of service tokens? I heard they were being deprecated? | 16:30 |
shewless | dstanek: here is what I have in my apache config: http://paste.ubuntu.com/17402076 | 16:32 |
*** lucas___ has joined #openstack-keystone | 16:33 | |
gyee | shewless, what does your /etc/apache2/sites-enabled/keystone.conf looks like? | 16:34 |
*** david-lyle has quit IRC | 16:35 | |
shewless | gyee: I'm on Mitaka and have wsgi-keystone-public.conf.. is that what you're after? | 16:35 |
gyee | shewless, yes | 16:35 |
gyee | can you pastebin it? | 16:35 |
*** dan_nguyen has joined #openstack-keystone | 16:35 | |
shewless | gyee, dstanek: the whole file: http://paste.ubuntu.com/17402290 | 16:36 |
*** lucas___ has quit IRC | 16:38 | |
gyee | shewless, you have /v3/auth/FEDERATION there, but you are trying to access /v3/FEDERATION | 16:38 |
gyee | so there's a mismatch somewhere | 16:38 |
gyee | may want to check your horizon local_settings.py | 16:39 |
gyee | bunting, I haven't heard of that rumor | 16:40 |
openstackgerrit | henry-nash proposed openstack/keystone: WIP - Add framework for supporting microversions https://review.openstack.org/330674 | 16:40 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Use upper-constraints for cover job https://review.openstack.org/330691 | 16:41 |
*** lucas___ has joined #openstack-keystone | 16:41 | |
shewless | gyee: not sure what you mean. The error I'm getting is: Not found: /v3/auth/OS-FEDERATION/websso/saml2 and in apache I have <Location ~ "/v3/auth/OS-FEDERATION/websso/saml2"> | 16:42 |
*** dmk0202 has quit IRC | 16:42 | |
*** lucas___ has quit IRC | 16:44 | |
*** lucas___ has joined #openstack-keystone | 16:44 | |
shewless | gyee: what would I check in local_settings.py? OPENSTACK_KEYSTONE_URL? or something else? | 16:47 |
gyee | shewless, you see the request in apache access log? | 16:47 |
shewless | gyee: in the apache2/error.log I see this: [Thu Jun 16 16:48:51.944406 2016] [wsgi:error] [pid 17849:tid 140076990158592] Not Found: /v3/auth/OS-FEDERATION/websso/saml2 | 16:49 |
*** david-lyle has joined #openstack-keystone | 16:50 | |
*** ebarrera has joined #openstack-keystone | 16:50 | |
shewless | gyee: in the apache2/access.log I see this: 192.168.216.117 - "" [16/Jun/2016:16:48:51 +0000] "GET /v3/auth/OS-FEDERATION/websso/saml2?origin=https://mycloud.foo.com/auth/websso/ HTTP/1.1" 404 5616 "https://idp.testshib.org/idp/profile/SAML2/Redirect/SSO" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.84 Safari/537.36" | 16:51 |
*** jdennis has quit IRC | 16:51 | |
gyee | shewless, arrrg | 16:52 |
gyee | the <location> should be inside <VirtualHost> | 16:52 |
shewless | gyee: Just that one locatoin? (not the other LocationMatch stuff)? | 16:52 |
gyee | all of them | 16:53 |
shewless | gyee: I will try that. I was using dstanek's example.. maybe I misread it: http://paste.openstack.org/show/508990/ | 16:53 |
*** nisha__ has quit IRC | 16:54 | |
gyee | I think that example is incorrect | 16:54 |
*** ddieterly[away] is now known as ddieterly | 16:54 | |
*** nisha__ has joined #openstack-keystone | 16:54 | |
*** amakarov has quit IRC | 16:55 | |
shewless | gyee: I'm getting an error now about not finding this page: https://mycloud.foo.com/Shibboleth.sso/SAML2/POST. I wonder if I have to re-upload my metadata? | 16:56 |
ayoung | stevemar, I actually claim it for Trusts. You have to include the dolphm patch for the tests there, and the two together were well over 120 revisions | 16:56 |
*** amakarov has joined #openstack-keystone | 16:57 | |
gyee | shewless, which IdP are you testing with? ADFS? | 17:00 |
*** belmoreira has quit IRC | 17:00 | |
shewless | gyee: testshib right now.. adfs in the future. So... this section has to be outside the virtualhost block: <Location /Shibboleth.sso> SetHandler shib </Location> | 17:01 |
shewless | gyee: If I put everything inside the virtualhost EXCEPT the <Location /Shibboleth.sso> stuff I end up with the same error (Not Found: /v3/auth/OS-FEDERATION/websso/saml2) | 17:05 |
shewless | gyee: If I put the /Shiboleth.sso inside the virtualhost I can't even generate metadata.. | 17:05 |
*** mvk_ has quit IRC | 17:06 | |
ayoung | gyee, I took your Anchor Certmonger helper and started a repo. is this OK? https://github.com/admiyo/anchor-certmonger-helper | 17:06 |
ayoung | Added a readme, and put in an Apache license header | 17:07 |
*** daemontool has quit IRC | 17:08 | |
shewless | gyee: Is there any other place that I need to "enable" or specify /v3/auth/OS-FEDERATION/websso/saml2 for that page to be available? | 17:08 |
gyee | ayoung, go for it, thanks man | 17:08 |
ayoung | gyee, cool | 17:09 |
shewless | gyee: my trusted_dashboard is trusted_dashboard = https://mycloud.foo.com/auth/websso - is that correct? | 17:09 |
gyee | shewless, that's fine, if you are using devstack, I think it should be /dashboard/auth/websso | 17:11 |
ayoung | shewless, no | 17:11 |
gyee | but we haven't get to that step yet | 17:11 |
ayoung | https://mycloud.foo.com/auth/websso not necess | 17:11 |
ayoung | should be your Horizon server | 17:11 |
*** roxanaghe has joined #openstack-keystone | 17:11 | |
ayoung | shewless, I think /websso is Keystone | 17:12 |
gyee | ayoung, that's the Horizon callback url | 17:12 |
gyee | s/callback/redirect back/ | 17:12 |
ayoung | gyee, trusted desktop is the one that initially started to convo, | 17:12 |
ayoung | I used... | 17:12 |
* ayoung still looking | 17:14 | |
ayoung | gyee, can't find it. Anyway, I think that is too low | 17:15 |
ayoung | I think it can be just the Horizon server, and Horizon should be https://mycloud.foo.com/ or https://mycloud.foo.com/desktop or maybe even https://mycloud.foo.com/auth | 17:15 |
ayoung | the websso might mess things up | 17:15 |
shewless | gyee, ayoung: not using devstack.. so so what is responsible for providing the /v3/auth/OS-FEDERATION/websso/saml2 page? Aside from apache I don't have that config anywhere | 17:15 |
gyee | shewless, /v3/auth/OS-FEDERATION/websso/saml2 is a Keystone endpoint | 17:16 |
*** roxanaghe has quit IRC | 17:16 | |
gyee | protected by Shibboleth | 17:16 |
ayoung | I totally lied | 17:16 |
ayoung | trusted_dashboard = https://openstack.ayoung.rhsso.oslab.test/dashboard/auth/websso/ | 17:16 |
shewless | gyee: is it possible a mapping problem could cause this? | 17:17 |
ayoung | shewless, so qwhen you set up Federation, you have to make 3 keystone calls | 17:17 |
ayoung | those create the Sub URL: | 17:17 |
gyee | shewless <Location /Shiboleth.sso> should also be inside <VirtualHost> | 17:17 |
ayoung | /v3/auth/OS-FEDERATION/<idp> | 17:17 |
ayoung | and | 17:17 |
ayoung | /v3/auth/OS-FEDERATION/<idp>/protocol | 17:17 |
ayoung | er /v3/auth/OS-FEDERATION/<idp>/<protocol> | 17:17 |
ayoung | shewless, Yout can test it by hitting it with curl | 17:18 |
ayoung | 404 means it does not exist, 401 means it works OK | 17:18 |
shewless | gyee: If I do that I cannot access https://mycloud.foo.com/Shibboleth.sso/Metadata. I should be able to right? | 17:18 |
*** roxanaghe has joined #openstack-keystone | 17:18 | |
shewless | ayoung what's the curl line? | 17:18 |
gyee | https://mycloud.foo.com:5000/Shibboleth.sso/Metadata | 17:19 |
*** javis has joined #openstack-keystone | 17:19 | |
ayoung | shewless so for me it was curl https://ipa.ayoung.rhsso.oslab.test/auth/realms/openstack/protocol/saml | 17:19 |
ayoung | nope | 17:19 |
ayoung | curl -g -i -X GET https://openstack.ayoung.rhsso.oslab.test:5000/v3/OS-FEDERATION/identity_providers/rhsso/protocols/saml2/auth | 17:19 |
ayoung | that is for ECP | 17:20 |
ayoung | try variations on that | 17:20 |
ayoung | https://openstack.ayoung.rhsso.oslab.test:5000/v3/OS-FEDERATION/identity_providers/rhsso is my IdP. so for you... | 17:21 |
*** rcernin has quit IRC | 17:21 | |
shewless | gyee: in that case I guess I should upload my new metadata then | 17:23 |
*** browne has joined #openstack-keystone | 17:23 | |
shewless | gyee: if I do that https doesn't work anymore.. should I add SSL stuff do my virtualhost *.5000? | 17:23 |
*** ddieterly is now known as ddieterly[away] | 17:24 | |
gyee | shewless, sorry, you can leave that one outside | 17:24 |
gyee | now back to the 404 | 17:24 |
javis | can someone point me in the direction of the required binary dependencies when install keystone from source? | 17:25 |
shewless | gyee: okay back to the 404 | 17:25 |
ayoung | javis, look in packstack | 17:26 |
gyee | shewless, lets start with your Horizon local_settings.py | 17:26 |
ayoung | javis, let me try that again | 17:26 |
ayoung | javis, look in devstack | 17:26 |
gyee | shewless, what does your OPENSTACK_KEYSTONE_URL set to? | 17:27 |
*** boltR_ has quit IRC | 17:27 | |
shewless | gyee: http://paste.ubuntu.com/17404514 | 17:28 |
ayoung | javis, for debs http://git.openstack.org/cgit/openstack-dev/devstack/tree/files/debs | 17:28 |
ayoung | http://git.openstack.org/cgit/openstack-dev/devstack/tree/files/debs/keystone | 17:28 |
ayoung | for RPMs | 17:28 |
shewless | gyee: OPENSTACK_KEYSTONE_URL = "http://%s:5000/v3" % OPENSTACK_HOST | 17:28 |
javis | ayoung: yea I saw that, oh thanks. debs are fine | 17:28 |
ayoung | http://git.openstack.org/cgit/openstack-dev/devstack/tree/files/rpms/keystone | 17:28 |
ayoung | javis, another approach is to install the keystone debs, get the dependencies installed, then uninstall keystone | 17:29 |
gyee | shewless, and your <location> block is inside <VirtualHost *:5000>? | 17:30 |
gyee | shewless, <Location ~ "/v3/auth/OS-FEDERATION/websso/saml2"> I mean | 17:31 |
*** tqtran has joined #openstack-keystone | 17:31 | |
shewless | gyee: here is what I did.. I moved everything inside except the shiboleth.sso part: http://paste.ubuntu.com/17404645 | 17:31 |
openstackgerrit | henry-nash proposed openstack/keystone: Pass request back into wsgi render_reponse https://review.openstack.org/330720 | 17:32 |
gyee | shewless, and what error are you getting now? | 17:33 |
javis | ayoung, ahh I see. I will try using bindep with an other-requirements.txt file. | 17:33 |
ayoung | javis, what are you trying to do? | 17:33 |
shewless | gyee: same as beforev [Thu Jun 16 17:36:10.407472 2016] [wsgi:error] [pid 28789:tid 139944201254656] Not Found: /v3/auth/OS-FEDERATION/websso/saml2 | 17:36 |
*** nisha_ has joined #openstack-keystone | 17:36 | |
openstackgerrit | henry-nash proposed openstack/keystone: WIP - Add framework for supporting microversions https://review.openstack.org/330674 | 17:36 |
gyee | shewless, did you restart Apache? | 17:38 |
javis | ayoung, setting up keystone on a docker container. I know there is kolla but was going the manual route for kicks | 17:38 |
*** nisha__ has quit IRC | 17:38 | |
shewless | gyee: many times. along with shibd. but hmm.. I changed the OPENSTACK_HOST line.. because it was my "internal hostname" and not the name I'm hitting.. I think that got me a different error (401) | 17:39 |
*** mvk_ has joined #openstack-keystone | 17:39 | |
shewless | gyee: yup.. now I get: {"error": {"message": "The request you have made requires authentication.", "code": 401, "title": "Unauthorized"}} | 17:39 |
lbragstad | getting a run in over lunch quick - biab | 17:39 |
shewless | gyee: is that better or worse? | 17:39 |
gyee | shewless, that's better | 17:40 |
shewless | gyee: hurray! looking at keystone logs now | 17:40 |
gyee | now Keystone should send you to the IdP to authenticate | 17:40 |
openstackgerrit | Merged openstack/keystone: Move project scoped tests to TokenAPITests https://review.openstack.org/330116 | 17:40 |
shewless | gyee: http://foo.sandvine.com/auth/websso/ is not a trusted dashboard host | 17:41 |
shewless | gyee: I notice that there is no https for some reason.. do you know why that would be? | 17:42 |
shewless | gyee: Just FYI even before I was already authenitcating against the IdP | 17:42 |
shewless | gyee: and I was able to get attributes | 17:42 |
gyee | shewless, change it to /dashboard/auth/websso | 17:42 |
openstackgerrit | Merged openstack/keystone: Move project scoped catalog tests to TokenAPITests https://review.openstack.org/330161 | 17:42 |
shewless | gyee: I think it's because I put in https:// instead of http:// | 17:43 |
gyee | shewless, yes, it must march the original Horizon URL | 17:43 |
shewless | gyee: but the original horizon URL is https: | 17:43 |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: WIP - oidc: fix OpenID Connect authorization code grant_type https://review.openstack.org/330006 | 17:44 |
gyee | shewless, I think you miss /dashboard in the path | 17:44 |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: WIP - oidc: add discovery document support https://review.openstack.org/330464 | 17:44 |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: oidc: remove grant_type argument https://review.openstack.org/330465 | 17:44 |
shewless | gyee: I don't see anything referencing the dashboard part.. I'll try it though | 17:44 |
gyee | shewless, if in doubt, 2x check your /etc/apache2/sites-enabled/horizon | 17:45 |
shewless | gyee: would that be 000-default in Mitaka (there is no horizon file) | 17:46 |
shewless | gyee: I changed it to https://mycloud.foo.com/dashboard/auth/websso | 17:47 |
openstackgerrit | Merged openstack/keystone: Move more project scoped behavior tests to TokenAPITests https://review.openstack.org/330162 | 17:48 |
shewless | gyee: but I get the same error: https://mycloud.foo.com/auth/websso/ is not a trusted dashboard host | 17:48 |
openstackgerrit | Merged openstack/keystone: Consolidate domain token tests into TokenAPITests https://review.openstack.org/330163 | 17:48 |
shewless | gyee: I think the problem is that the port 5000 stuff is http and the other stuff is https.. | 17:49 |
gyee | this has nothing to do with port 5000 | 17:50 |
gyee | this is horizon url | 17:50 |
gyee | is your Horizon HTTP or HTTPS? | 17:51 |
gyee | shewless, what's in your /etc/apache2/sites-enabled/ | 17:51 |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: WIP - oidc: remove grant_type argument https://review.openstack.org/330465 | 17:52 |
shewless | gyee: My horizon that I'm accessing it https (https://mycloud.foo.com). Here is in sites-enabled: 000-default.conf wsgi-keystone-internal.conf wsgi-keystone-public.conf | 17:52 |
openstackgerrit | Merged openstack/keystone: Move negative domain scope test to TokenAPITests https://review.openstack.org/330215 | 17:54 |
shewless | gyee: does it make sense that I need a trailing slash on this line? trusted_dashboard = https://mycloud.foo.com/auth/websso/ | 17:54 |
gyee | shewless, grep 'origin=' keystone.log | 17:54 |
openstackgerrit | Merged openstack/keystone: Move unscoped token test to TokenAPITests https://review.openstack.org/330216 | 17:55 |
shewless | gyee: that seems to get rid of my trusted dashboard problem | 17:55 |
openstackgerrit | Merged openstack/keystone: Move negative token tests to TokenAPITests https://review.openstack.org/330217 | 17:55 |
gyee | yes,, the trailing slash matters | 17:55 |
gyee | shewless, it has to match exactly what's in the 'origin' query param | 17:55 |
gyee | shewless, can you do a 'grep 'origin=' keystone.log'? | 17:56 |
gyee | I want to see what's coming in | 17:56 |
shewless | gyee: GET http://mycloud.foo.com:5000/v3/auth/OS-FEDERATION/websso/saml2?origin=https://mycloud.foo.com/auth/websso/ | 17:56 |
shewless | gyee: so I think that trailing '/' is what was missing.. now I get this error: | 17:57 |
shewless | {"error": {"message": "Could not find Identity Provider: https://idp.testshib.org/idp/shibboleth", "code": 404, "title": "Not Found"}} | 17:57 |
shewless | gyee: thjat's after I login to the idp | 17:58 |
*** rderose_ has quit IRC | 17:59 | |
gyee | shewless, now its getting into your IdP meta file | 17:59 |
shewless | gyee: that's cool. Why the 404 error? That page exists if I browse to it | 18:00 |
*** jsavak has quit IRC | 18:03 | |
*** amoralej is now known as amoralej|off | 18:04 | |
*** ebalduf has joined #openstack-keystone | 18:06 | |
*** jsavak has joined #openstack-keystone | 18:06 | |
gyee | shewless, that error coming from Keystone or Horizon? | 18:07 |
*** rcernin has joined #openstack-keystone | 18:07 | |
shewless | gyee: that message is in /var/log/apache2/keystone-public.log... so I guess keystone | 18:08 |
shewless | gyee: the weird part to me is that I can view this: https://mycloud.foo.com/Shibboleth.sso/Session and it'll tell me all the attributes of the user I've logged in as.. | 18:08 |
shewless | gyee: I've been able to to that for awihle though | 18:08 |
gyee | shewless, in your keystone.conf, what does remote_id_attribute set to? | 18:10 |
gyee | that attribute in your saml2 should map to the IdP you created in Keystone | 18:10 |
shewless | gyee: remote_id_attribute = Shib-Identity-Provider | 18:10 |
gyee | Keystone use that to lookup the IdP | 18:11 |
shewless | gyee: hmm. where do I put that in keystone? | 18:11 |
shewless | gyee: like openstack identity provider show "provider_name" | 18:12 |
shewless | gyee: the --remote_ids field? I've left that blank up until now.. that's bad isn't it? | 18:12 |
gyee | yes --remote_ids field | 18:13 |
*** jaugustine has joined #openstack-keystone | 18:13 | |
shewless | gyee: so should it be https://idp.testshib.org/idp/shibboleth or Shib-Identity-Provider | 18:14 |
gyee | set your remote_ids to "https://idp.testshib.org/idp/shibboleth" | 18:14 |
shewless | gyee: SUCCESS!!!!!!!! | 18:15 |
gyee | nice | 18:15 |
gyee | shewless, I have to dash to a meeting, good luck the rest of the way | 18:16 |
shewless | gyee, dstanek, ayoung: thank you so much! that was a battle | 18:16 |
shewless | gyee: thanks.. still have a lot to do.. | 18:16 |
*** aratus has quit IRC | 18:17 | |
ayoung | shewless, working on making it less painful in the future, albeing not for Shib, but other | 18:19 |
shewless | ayoung: I would choose other to avoid that pain :) | 18:19 |
shewless | so.. my user name is some crazy hash string.. I'm guessing I need to update my mapping file to make that clearer? | 18:20 |
ayoung | shewless, I have ansible playbooks I am working on for Red Hat SSO, based on Keycloak, and and older one for Ipsilon | 18:21 |
shewless | ayoung: that's cool. I'll actually be putting my stuff into a playbook as well | 18:22 |
*** aratus has joined #openstack-keystone | 18:22 | |
ayoung | they are not perfect. I just realized that they assume mod_auth_mellon has already been installed | 18:22 |
ayoung | cuz, we do that early on | 18:22 |
ayoung | but that should be in the playbook. | 18:22 |
ayoung | er, the role | 18:22 |
ayoung | https://github.com/admiyo/rippowam/tree/master/roles/rhsso | 18:22 |
ayoung | for rhsso | 18:23 |
shewless | ayoung: I'll have a look. thanks | 18:23 |
ayoung | https://github.com/admiyo/rippowam/tree/master/roles/keycloak-saml-idp is the KEystone side of it for Keycloak | 18:23 |
shewless | ayoung: do you know how I would get the top right login name to be the "Name" and not the "ID" ? | 18:23 |
ayoung | https://github.com/admiyo/rippowam/tree/master/roles/rhsso-saml-idp | 18:23 |
ayoung | shewless, fix the bug assigned to me? | 18:23 |
shewless | ayoung: lol.. | 18:23 |
ayoung | shewless, https://bugs.launchpad.net/keystone/+bug/1590426 | 18:24 |
openstack | Launchpad bug 1590426 in OpenStack Identity (keystone) "Keystone Federated Identity assertion name not included in token" [Undecided,New] - Assigned to Adam Young (ayoung) | 18:24 |
shewless | ayoung: so no workaround? | 18:24 |
*** mkoderer__ has joined #openstack-keystone | 18:24 | |
ayoung | shewless, workaround involves editing python files... | 18:24 |
ayoung | does that count>? | 18:24 |
*** ddieterly[away] has quit IRC | 18:24 | |
shewless | ayoung: yes if there isn't too much to modify! | 18:24 |
ayoung | heh | 18:24 |
ayoung | I have not yet looked at it | 18:24 |
ayoung | its in the token, and that is as far as I got | 18:25 |
shewless | ayoung: lol okay I'll put up with what it is for now | 18:25 |
*** gyee has quit IRC | 18:25 | |
shewless | ayoung: I want each user to have their own project assigned to them. Do you know if there is a "project" field in the mapping file? | 18:26 |
ayoung | shewless, heh | 18:26 |
*** dan_nguyen has quit IRC | 18:26 | |
ayoung | dolphm, is working on an autoprovisioning spec even as we speak | 18:26 |
shewless | ayoung: cool. for now I'm okay if I create the project ahead of time.. I just need to map it correctly | 18:26 |
ayoung | shewless, nah, you still need a role assignment | 18:27 |
shewless | ayoung: that's okay. It's the same for ldap. When we have new users join the company I can run 2 command to assign their role and create a project | 18:27 |
*** ddieterly has joined #openstack-keystone | 18:30 | |
shewless | ayoung: I bet I'd have to create a unique group for every user and have a role associated with each group with a default project. Is that right? | 18:34 |
ayoung | shewless, today? Yep | 18:34 |
ayoung | you can use the "empty blacklist" approach though so you don;'t need to have each in the mapping | 18:34 |
shewless | ayoung: oh? that sounds interesting. How do I do that? | 18:35 |
ayoung | have each user be their own group, create the group in the SQL backend | 18:35 |
ayoung | shewless, so instead of https://github.com/admiyo/rippowam/blob/master/roles/keyfed/files/mapping_ipsilon_saml2.json#L30 | 18:36 |
shewless | ayoung: right.. then the mapping would be group "name" : {1} | 18:36 |
ayoung | do "blacklist": [] | 18:36 |
shewless | ayoung: okay. .can I just remove the whitelist/blacklist completely from the mapping? | 18:37 |
ayoung | you can map the remote "type": "MELLON_NAME_ID" to "local": [{ | 18:37 |
ayoung | "groups": "{0}", | 18:37 |
ayoung | nahm, you need one or the other | 18:37 |
*** aratus has quit IRC | 18:39 | |
*** rderose has joined #openstack-keystone | 18:39 | |
*** pushkaru has quit IRC | 18:40 | |
*** tonytan4ever has joined #openstack-keystone | 18:43 | |
*** dmk0202 has joined #openstack-keystone | 18:44 | |
*** dmk0202 has quit IRC | 18:45 | |
*** ebarrera has quit IRC | 18:46 | |
*** amit213 has joined #openstack-keystone | 18:51 | |
mwheckmann | hello. Wondering if anyone saw the thread I started in openstack-operators ML: http://lists.openstack.org/pipermail/openstack-operators/2016-June/010694.html | 18:53 |
mwheckmann | actually, ayoung noticed it, but the Operator community doesn't really have much to say about it, so I'm turning to the dev community. | 18:54 |
*** nisha__ has joined #openstack-keystone | 18:54 | |
mwheckmann | Is there anyway to do what I'm trying to achieve? Or do I have to wait for https://review.openstack.org/#/c/324055/2/specs/keystone/newton/shadow-mapping.rst ? | 18:55 |
patchbot | mwheckmann: patch 324055 - keystone-specs - Mapping shadow users into projects and roles | 18:55 |
*** nisha_ has quit IRC | 18:57 | |
mwheckmann | The main blocker for me is that all users who come in from federation are thrown into the special "Federated" domain | 18:58 |
*** yolanda has quit IRC | 19:00 | |
*** rderose_ has joined #openstack-keystone | 19:01 | |
*** rderose has quit IRC | 19:05 | |
*** jsavak has quit IRC | 19:05 | |
lbragstad | here is a refactor review if anyone is interested - https://review.openstack.org/#/c/330218/1 | 19:08 |
patchbot | lbragstad: patch 330218 - keystone - Move cross domain/group/project auth tests | 19:08 |
lbragstad | once that lands i'm going to rebase and fix all the merge conflicts on the dependent patches | 19:08 |
*** ebalduf has quit IRC | 19:09 | |
*** jdennis has joined #openstack-keystone | 19:12 | |
*** roxanagh_ has joined #openstack-keystone | 19:13 | |
*** roxanagh_ has quit IRC | 19:17 | |
*** aratus has joined #openstack-keystone | 19:25 | |
lbragstad | i'm going to perform some updates to the performance job | 19:27 |
*** rderose_ has quit IRC | 19:27 | |
lbragstad | patches in review with 'check performance' will be logged and the jobs will be run later | 19:27 |
*** nisha__ is now known as nisha_ | 19:32 | |
*** rderose has joined #openstack-keystone | 19:32 | |
*** aratus has quit IRC | 19:38 | |
*** jdennis has quit IRC | 19:39 | |
*** dmk0202 has joined #openstack-keystone | 19:40 | |
*** dmk0202 has quit IRC | 19:43 | |
*** aratus has joined #openstack-keystone | 19:47 | |
*** djc_ has joined #openstack-keystone | 19:49 | |
djc_ | why is the default keystone token expiration set to 24 hours? what are the ramifications of increasing beyond 24 hours? | 19:49 |
*** jsavak has joined #openstack-keystone | 19:55 | |
*** ebalduf has joined #openstack-keystone | 20:01 | |
*** rderose has quit IRC | 20:02 | |
*** rderose_ has joined #openstack-keystone | 20:02 | |
*** dan_nguyen has joined #openstack-keystone | 20:02 | |
*** lucas___ has quit IRC | 20:04 | |
*** sheel has quit IRC | 20:05 | |
browne | djc_: default token timeout is 1 hour (3600 seconds) | 20:08 |
djc_ | browne: is the default 1 hour for security purposes? | 20:10 |
browne | yes, because the tokens are bearer tokens. the longer the expiration, the more time someone can use the token if stolen | 20:11 |
djc_ | browne: we are using swift and keystone. does the 1 hour expiration time pose a problem for transfers longer than 1 hour? | 20:12 |
notmyname | no | 20:12 |
* notmyname lurks in here too | 20:12 | |
browne | djc_: not if swift properly acquires a new token when its expired | 20:12 |
*** djc_ has quit IRC | 20:13 | |
browne | i think most projects use keystonemiddleware which handles this | 20:13 |
notmyname | the token is validated near the start of the request. so if it's validated and then data is transferred for the next 2 hours, that's ok. no need to re-auth in the middle, because that's the same request | 20:14 |
*** ddieterly is now known as ddieterly[away] | 20:14 | |
browne | oh ok | 20:14 |
*** ayoung has quit IRC | 20:18 | |
*** openstackstatus has joined #openstack-keystone | 20:19 | |
*** ChanServ sets mode: +v openstackstatus | 20:19 | |
*** tonytan4ever has quit IRC | 20:19 | |
*** dmk0202 has joined #openstack-keystone | 20:23 | |
*** gyee has joined #openstack-keystone | 20:24 | |
*** ChanServ sets mode: +v gyee | 20:24 | |
*** henrynash_ has quit IRC | 20:29 | |
*** jsavak has quit IRC | 20:31 | |
*** jsavak has joined #openstack-keystone | 20:32 | |
shewless | hey guys. I think I'm hitting a weird bug in with my federation setup. When I first try and "connect" via horizon I see an error apache error: Not Found: /v3/auth/OS-FEDERATION/websso/saml2. But when I try and connect subsequently it works as expected. | 20:32 |
shewless | I can reproduce this on all browsers or after I restart apache2 | 20:32 |
*** mwheckmann has quit IRC | 20:32 | |
*** nisha_ has quit IRC | 20:32 | |
shewless | IE when I restart apache I will always get a "page not found" error the first time I try to connect with each browser.. and then subsequent attempts to connect work perfectly | 20:33 |
*** ddieterly[away] is now known as ddieterly | 20:44 | |
*** dan_nguyen has quit IRC | 20:48 | |
*** aratus has quit IRC | 20:49 | |
*** aratus has joined #openstack-keystone | 20:50 | |
*** jaugustine has quit IRC | 20:52 | |
*** jamie_h has quit IRC | 20:57 | |
*** aratus has quit IRC | 21:03 | |
*** aratus has joined #openstack-keystone | 21:10 | |
*** roxanagh_ has joined #openstack-keystone | 21:14 | |
*** pauloewerton has quit IRC | 21:15 | |
openstackgerrit | Merged openstack/keystone: Move cross domain/group/project auth tests https://review.openstack.org/330218 | 21:16 |
openstackgerrit | Merged openstack/keystone: Use request object in auth plugins https://review.openstack.org/330290 | 21:17 |
*** roxanagh_ has quit IRC | 21:18 | |
adrian_otto | I'm trying to debug a trust configuration issue, and I'm not able to figure out how to list identity domains. I don't see them in Horizon, and I cant find them in the "openstack" client either. | 21:23 |
adrian_otto | where should I be looking for that? | 21:23 |
lbragstad | adrian_otto it looks like osc has domains as it's own subcommand - http://docs.openstack.org/developer/python-openstackclient/command-objects/domain.html | 21:30 |
jamielennox | o/ | 21:31 |
lbragstad | jamielennox o/ | 21:31 |
adrian_otto | thanks lbragstad. Looks like my osc client is older, because it's not in there. | 21:32 |
adrian_otto | 2.6.0 | 21:32 |
lbragstad | adrian_otto ah ha - that could be why | 21:33 |
*** aratus has quit IRC | 21:34 | |
*** rcernin has quit IRC | 21:36 | |
*** dmk0202 has quit IRC | 21:38 | |
*** aratus has joined #openstack-keystone | 21:41 | |
jamielennox | notmorgan: interesting like good? | 21:43 |
*** woodster_ has quit IRC | 21:48 | |
*** adrian_otto has quit IRC | 21:50 | |
*** dan_nguyen has joined #openstack-keystone | 21:53 | |
*** jsavak has quit IRC | 21:53 | |
*** jsavak has joined #openstack-keystone | 21:53 | |
tqtran | hello, i have a question regarding how sso_callback_template.html how is keystone hosting this file? | 21:57 |
tqtran | stevemar: ^-- since i know you did some work on this way back | 21:58 |
jamielennox | tqtran: from memory it's not hosted by default, you need to stick it in your apache conf in the appropriate place | 22:00 |
jamielennox | but it has been a little while | 22:00 |
*** dmk0202 has joined #openstack-keystone | 22:04 | |
*** browne has quit IRC | 22:04 | |
*** BjoernT has quit IRC | 22:04 | |
*** sigmavirus24 is now known as sigmavirus24_ | 22:05 | |
*** timcline has quit IRC | 22:07 | |
*** ayoung has joined #openstack-keystone | 22:07 | |
*** ChanServ sets mode: +v ayoung | 22:07 | |
*** timcline has joined #openstack-keystone | 22:08 | |
*** edtubill has quit IRC | 22:09 | |
dstanek | tqtran: jamielennox: actually keystone serves this from the federation controller | 22:10 |
jamielennox | dstanek: oh? then i will shut back up again :p | 22:11 |
dstanek | jamielennox: http://git.openstack.org/cgit/openstack/keystone/tree/keystone/federation/controllers.py#n338 | 22:11 |
*** timcline has quit IRC | 22:12 | |
dstanek | i've been looking at federation waaaaay too much | 22:13 |
dstanek | bknudson_: so what do you think of the response object approach to request_id in keystone client? | 22:16 |
bknudson_ | dstanek: I don't know what that means | 22:16 |
dstanek | https://review.openstack.org/#/c/329913 - you mentioned it in a review | 22:17 |
dstanek | tqtran: does that answer your question | 22:17 |
*** javis has quit IRC | 22:18 | |
bknudson_ | dstanek: so you have to use .data to get the data? | 22:18 |
bknudson_ | not a fan just because I don't think that's how any other client library implemented this. | 22:19 |
dstanek | bknudson_: yes | 22:19 |
dstanek | bknudson_: i just don't want to jump off the bridge because everyone else is doing it | 22:19 |
dstanek | client libs are harder to change | 22:19 |
*** walharthi has quit IRC | 22:21 | |
dstanek | bknudson_: what do you think would be the right way to do this if we were doing greenfield development | 22:22 |
bknudson_ | just think of osc - it has to work with all these libraries and keystone is going to be totally different | 22:22 |
bknudson_ | I believe the session object has a way to register a callback so I'd have applications do that so they can opt in to getting the request ID | 22:23 |
bknudson_ | also it would be totally async | 22:23 |
*** ebalduf has quit IRC | 22:23 | |
bknudson_ | and generated dynamically | 22:23 |
bknudson_ | and unicorns would dance | 22:24 |
dstanek | :-) so magic | 22:24 |
bknudson_ | so it would be similar to your proposal but be a callback instead of changing the return value | 22:25 |
*** jsavak has quit IRC | 22:26 | |
bknudson_ | the callback would provide more info like the URL that was requested... maybe some timing info? | 22:26 |
dstanek | i think that would be much better than what was proposed | 22:26 |
dstanek | bknudson_: right, that's the kind of stuff that i would put in the response object | 22:27 |
openstackgerrit | Jamie Lennox proposed openstack/keystone: Use http_proxy_to_wsgi from oslo.middleware https://review.openstack.org/327418 | 22:27 |
bknudson_ | dstanek: http://docs.python-requests.org/en/master/user/advanced/#event-hooks | 22:28 |
bknudson_ | might not need any changes to keystoneclient to use this | 22:29 |
*** ddieterly is now known as ddieterly[away] | 22:32 | |
dstanek | bknudson_: you wouldn't with that | 22:32 |
*** ddieterly[away] has quit IRC | 22:32 | |
*** darrenc is now known as darren_afk | 22:34 | |
lbragstad | keystone performance review if anyone has feedback https://github.com/lbragstad/keystone-performance/pull/11 | 22:36 |
tqtran | dstanek: yep, thanks for the lead. zaqar is trying to do something similar for their subscription confirmation page | 22:36 |
bknudson_ | lbragstad: just put it in gerrit already! | 22:36 |
lbragstad | bknudson_ soon! | 22:37 |
jamielennox | ayoung: so your ipa.younglogic.net - what's an ECP protected target i can test it with? | 22:37 |
bknudson_ | lbragstad: doesn't need to clean up? | 22:38 |
lbragstad | bknudson_ nope - it's in a container that gets deleted when the performance results are done | 22:39 |
*** dmk0202 has quit IRC | 22:39 | |
dstanek | lbragstad: does that do a run before and a run after the commit it's testing? | 22:43 |
lbragstad | nope it does it only in the set up | 22:43 |
lbragstad | so it standup keystone, populates it with garbage, | 22:43 |
lbragstad | run benchmarks on master | 22:44 |
lbragstad | then runs benchmarks on the patch | 22:44 |
*** darren_afk is now known as darrenc | 22:55 | |
*** gordc has quit IRC | 22:55 | |
*** browne has joined #openstack-keystone | 22:57 | |
*** ayoung has quit IRC | 23:07 | |
*** edmondsw has quit IRC | 23:07 | |
*** browne has quit IRC | 23:10 | |
*** rderose has joined #openstack-keystone | 23:13 | |
*** rderose_ has quit IRC | 23:15 | |
*** roxanagh_ has joined #openstack-keystone | 23:15 | |
*** raddaoui has quit IRC | 23:17 | |
*** adrian_otto has joined #openstack-keystone | 23:19 | |
*** roxanagh_ has quit IRC | 23:20 | |
*** rderose has quit IRC | 23:22 | |
*** roxanaghe has quit IRC | 23:23 | |
*** aratus has quit IRC | 23:26 | |
dstanek | lbragstad: i was thinking that in addition to those two links it puts in there that it could show the before/after in a single txt file | 23:29 |
*** aratus has joined #openstack-keystone | 23:30 | |
dstanek | sorry shewless; got busy on a call and didn't realize that you responded. were you able to get what you needed from the others? | 23:32 |
*** iurygregory_ has joined #openstack-keystone | 23:34 | |
*** aratus has quit IRC | 23:35 | |
*** aratus has joined #openstack-keystone | 23:38 | |
*** chlong has quit IRC | 23:42 | |
openstackgerrit | Jamie Lennox proposed openstack/keystone: Use request.params instead of context['query_string'] https://review.openstack.org/330822 | 23:42 |
*** sshen_ has quit IRC | 23:43 | |
openstackgerrit | Jamie Lennox proposed openstack/keystone: Use http_proxy_to_wsgi from oslo.middleware https://review.openstack.org/327418 | 23:44 |
*** ayoung has joined #openstack-keystone | 23:44 | |
*** ChanServ sets mode: +v ayoung | 23:44 | |
*** rderose has joined #openstack-keystone | 23:45 | |
*** sshen has joined #openstack-keystone | 23:48 | |
*** jdennis has joined #openstack-keystone | 23:51 | |
lbragstad | dstanek yeah - I have an issue open to simplify all of that | 23:53 |
lbragstad | dstanek https://github.com/lbragstad/keystone-performance/issues/5 | 23:53 |
*** rderose has quit IRC | 23:54 | |
ayoung | jamielennox, there is a good chance that the Rippowam deploy will fail on upgrade. if it does, I'll reinstall the IPA server | 23:54 |
jamielennox | ayoung: i won't need it for long, if you've got something that i can test against for the next few hours that will be enough | 23:55 |
jamielennox | ayoung: also did you see my reservations spec? | 23:55 |
ayoung | jamielennox, everything else is inside the RH firewall | 23:55 |
ayoung | jamielennox, packstack is broken right now | 23:57 |
*** sdake has quit IRC | 23:57 | |
ayoung | wait...but this should not be | 23:57 |
ayoung | butno, I don't have anything set up. jamielennox want to throw some app up to hit? Can even do a Keystone instance if you have an easy way to set it up[ | 23:58 |
jamielennox | ayoung: i regret to say i'd need to read all the docs again - but the app is as simple as pretty print the environ | 23:58 |
ayoung | we had one of those, I thought. | 23:59 |
jamielennox | i had a test script that rippowam used to deploy and comment out | 23:59 |
jamielennox | i don't know how you've deployed your public instance | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!