| *** openstack has joined #openstack-keystone | 05:42 | |
| *** openstack has joined #openstack-keystone | 05:57 | |
| *** orwell.freenode.net sets mode: +ns | 05:57 | |
| *** orwell.freenode.net sets mode: -o openstack | 05:57 | |
| -orwell.freenode.net- *** Notice -- TS for #openstack-keystone changed from 1466056639 to 1377384024 | 05:57 | |
| *** orwell.freenode.net sets mode: +cgt-s | 05:57 | |
| *** jaosorior has joined #openstack-keystone | 05:57 | |
| *** GB21 has joined #openstack-keystone | 05:57 | |
| *** EinstCrazy has joined #openstack-keystone | 05:57 | |
| *** david-lyle_ has joined #openstack-keystone | 05:57 | |
| *** sheel has joined #openstack-keystone | 05:57 | |
| *** mvk_ has joined #openstack-keystone | 05:57 | |
| *** jefrite has joined #openstack-keystone | 05:57 | |
| *** mkoderer__ has joined #openstack-keystone | 05:57 | |
| *** markvoelker_ has joined #openstack-keystone | 05:57 | |
| *** SpamapS has joined #openstack-keystone | 05:57 | |
| *** mordred has joined #openstack-keystone | 05:57 | |
| *** mdavidson has joined #openstack-keystone | 05:57 | |
| *** _sigmavirus24 has joined #openstack-keystone | 05:57 | |
| *** NikitaKonovalov has joined #openstack-keystone | 05:57 | |
| *** DinaBelova has joined #openstack-keystone | 05:57 | |
| *** freerunner has joined #openstack-keystone | 05:57 | |
| *** htruta` has joined #openstack-keystone | 05:57 | |
| *** bj0rnar- has joined #openstack-keystone | 05:57 | |
| *** bknudson_ has joined #openstack-keystone | 05:57 | |
| *** bapalm has joined #openstack-keystone | 05:57 | |
| *** adam_g has joined #openstack-keystone | 05:57 | |
| *** robcresswell has joined #openstack-keystone | 05:57 | |
| *** BAKfr has joined #openstack-keystone | 05:57 | |
| *** barclaac_ has joined #openstack-keystone | 05:57 | |
| *** raildo-a` has joined #openstack-keystone | 05:57 | |
| *** bigjools has joined #openstack-keystone | 05:57 | |
| *** breton_ has joined #openstack-keystone | 05:57 | |
| *** kragniz has joined #openstack-keystone | 05:57 | |
| *** x58 has joined #openstack-keystone | 05:57 | |
| *** pleia2 has joined #openstack-keystone | 05:57 | |
| *** Daviey_ has joined #openstack-keystone | 05:57 | |
| *** Anticime1 has joined #openstack-keystone | 05:57 | |
| *** boltR_ has joined #openstack-keystone | 05:57 | |
| *** rmstar_ has joined #openstack-keystone | 05:57 | |
| *** patchbot has joined #openstack-keystone | 05:57 | |
| *** haneef_ has joined #openstack-keystone | 05:57 | |
| *** woodburn has joined #openstack-keystone | 05:57 | |
| *** openstackgerrit has joined #openstack-keystone | 05:57 | |
| *** shewless has joined #openstack-keystone | 05:57 | |
| *** afred312 has joined #openstack-keystone | 05:57 | |
| *** ktychkova has joined #openstack-keystone | 05:57 | |
| *** rodrigods has joined #openstack-keystone | 05:57 | |
| *** wasmum has joined #openstack-keystone | 05:57 | |
| *** aloga has joined #openstack-keystone | 05:57 | |
| *** permalac has joined #openstack-keystone | 05:57 | |
| *** orwell.freenode.net sets mode: +v bknudson_ | 05:57 | |
| *** Dinesh_Bhor has joined #openstack-keystone | 05:57 | |
| *** dancn has joined #openstack-keystone | 05:57 | |
| *** zzzeek has joined #openstack-keystone | 05:57 | |
| *** dhellmann has joined #openstack-keystone | 05:57 | |
| *** nkinder has joined #openstack-keystone | 05:57 | |
| *** sileht has joined #openstack-keystone | 05:57 | |
| *** harlowja_ has joined #openstack-keystone | 05:57 | |
| *** lifeless has joined #openstack-keystone | 05:57 | |
| *** elmiko has joined #openstack-keystone | 05:57 | |
| *** alex_xu has joined #openstack-keystone | 05:57 | |
| *** clenimar has joined #openstack-keystone | 05:57 | |
| *** vnogin has joined #openstack-keystone | 05:57 | |
| *** ericksonsantos has joined #openstack-keystone | 05:57 | |
| *** ashokt has joined #openstack-keystone | 05:57 | |
| *** dulek has joined #openstack-keystone | 05:57 | |
| *** opilotte- has joined #openstack-keystone | 05:57 | |
| *** anteaya has joined #openstack-keystone | 05:57 | |
| *** chlong has joined #openstack-keystone | 05:57 | |
| *** hoonetorg has joined #openstack-keystone | 05:57 | |
| *** dobson has joined #openstack-keystone | 05:57 | |
| *** agireud has joined #openstack-keystone | 05:57 | |
| *** jdennis has joined #openstack-keystone | 05:57 | |
| *** amoralej|off has joined #openstack-keystone | 05:57 | |
| *** flaper87 has joined #openstack-keystone | 05:57 | |
| *** iurygregory has joined #openstack-keystone | 05:57 | |
| *** wanghua has joined #openstack-keystone | 05:57 | |
| *** amrith has joined #openstack-keystone | 05:57 | |
| *** gabriel-bezerra has joined #openstack-keystone | 05:57 | |
| *** lunarlamp has joined #openstack-keystone | 05:57 | |
| *** jamielennox has joined #openstack-keystone | 05:57 | |
| *** zigo has joined #openstack-keystone | 05:57 | |
| *** nikhil has joined #openstack-keystone | 05:57 | |
| *** andreykurilin__ has joined #openstack-keystone | 05:57 | |
| *** briancurtin has joined #openstack-keystone | 05:57 | |
| *** DuncanT has joined #openstack-keystone | 05:57 | |
| *** serverascode has joined #openstack-keystone | 05:57 | |
| *** andrewbogott has joined #openstack-keystone | 05:57 | |
| *** ctracey has joined #openstack-keystone | 05:57 | |
| *** clayton has joined #openstack-keystone | 05:57 | |
| *** mgagne has joined #openstack-keystone | 05:57 | |
| *** mtreinish has joined #openstack-keystone | 05:57 | |
| *** timburke has joined #openstack-keystone | 05:57 | |
| *** tpeoples has joined #openstack-keystone | 05:57 | |
| *** chris_hultin has joined #openstack-keystone | 05:57 | |
| *** lmiccini has joined #openstack-keystone | 05:57 | |
| *** orwell.freenode.net sets mode: +v jamielennox | 05:57 | |
| *** d0ugal has joined #openstack-keystone | 05:57 | |
| *** rdo has joined #openstack-keystone | 05:57 | |
| *** boris-42 has joined #openstack-keystone | 05:57 | |
| *** zhiyan has joined #openstack-keystone | 05:57 | |
| *** jraim has joined #openstack-keystone | 05:57 | |
| *** frickler has joined #openstack-keystone | 05:57 | |
| *** martinus__ has joined #openstack-keystone | 05:57 | |
| *** toddnni has joined #openstack-keystone | 05:57 | |
| *** rm_work has joined #openstack-keystone | 05:57 | |
| *** krotscheck has joined #openstack-keystone | 05:57 | |
| *** dgonzalez has joined #openstack-keystone | 05:57 | |
| *** mancdaz has joined #openstack-keystone | 05:57 | |
| *** amakarov has joined #openstack-keystone | 05:57 | |
| *** jistr has joined #openstack-keystone | 05:57 | |
| *** med_ has joined #openstack-keystone | 05:57 | |
| *** cburgess has joined #openstack-keystone | 05:57 | |
| *** nonameentername has joined #openstack-keystone | 05:57 | |
| *** topol has joined #openstack-keystone | 05:57 | |
| *** dmellado has joined #openstack-keystone | 05:57 | |
| *** Tridde has joined #openstack-keystone | 05:57 | |
| *** sudorandom has joined #openstack-keystone | 05:57 | |
| *** briancline has joined #openstack-keystone | 05:57 | |
| *** auggy has joined #openstack-keystone | 05:57 | |
| *** mugsie has joined #openstack-keystone | 05:57 | |
| *** hogepodge has joined #openstack-keystone | 05:57 | |
| *** basilAB has joined #openstack-keystone | 05:57 | |
| *** johnthetubaguy has joined #openstack-keystone | 05:57 | |
| *** samueldmq has joined #openstack-keystone | 05:57 | |
| *** charz_ has joined #openstack-keystone | 05:57 | |
| *** bradjones has joined #openstack-keystone | 05:57 | |
| *** tonyb has joined #openstack-keystone | 05:57 | |
| *** BrAsS_mOnKeY has joined #openstack-keystone | 05:57 | |
| *** crinkle has joined #openstack-keystone | 05:57 | |
| *** tlbr has joined #openstack-keystone | 05:57 | |
| *** afazekas has joined #openstack-keystone | 05:57 | |
| *** notmorgan has joined #openstack-keystone | 05:57 | |
| *** xek has joined #openstack-keystone | 05:57 | |
| *** david_cu has joined #openstack-keystone | 05:57 | |
| *** dims has joined #openstack-keystone | 05:57 | |
| *** dtroyer has joined #openstack-keystone | 05:57 | |
| *** henrynash has joined #openstack-keystone | 05:57 | |
| *** d34dh0r53 has joined #openstack-keystone | 05:57 | |
| *** knikolla has joined #openstack-keystone | 05:57 | |
| *** _fortis has joined #openstack-keystone | 05:57 | |
| *** akscram has joined #openstack-keystone | 05:57 | |
| *** orwell.freenode.net sets mode: +vvv topol samueldmq henrynash | 05:57 | |
| *** baffle has joined #openstack-keystone | 05:57 | |
| *** ianw has joined #openstack-keystone | 05:57 | |
| *** rha has joined #openstack-keystone | 05:57 | |
| *** buhman has joined #openstack-keystone | 05:57 | |
| *** hockeynut has joined #openstack-keystone | 05:57 | |
| *** jlk has joined #openstack-keystone | 05:57 | |
| *** BlackDex has joined #openstack-keystone | 05:57 | |
| *** mhu has joined #openstack-keystone | 05:57 | |
| *** brad[] has joined #openstack-keystone | 05:57 | |
| *** hugokuo has joined #openstack-keystone | 05:57 | |
| *** dolphm has joined #openstack-keystone | 05:57 | |
| *** hughsaunders has joined #openstack-keystone | 05:57 | |
| *** stian_ has joined #openstack-keystone | 05:57 | |
| *** gus has joined #openstack-keystone | 05:57 | |
| *** eglute has joined #openstack-keystone | 05:57 | |
| *** mjb has joined #openstack-keystone | 05:57 | |
| *** dutsmoc has joined #openstack-keystone | 05:57 | |
| *** odyssey4me has joined #openstack-keystone | 05:57 | |
| *** lbragstad has joined #openstack-keystone | 05:57 | |
| *** dstanek has joined #openstack-keystone | 05:57 | |
| *** jhesketh has joined #openstack-keystone | 05:57 | |
| *** skoude_ has joined #openstack-keystone | 05:57 | |
| *** Dave has joined #openstack-keystone | 05:57 | |
| *** darrenc has joined #openstack-keystone | 05:57 | |
| *** yarkot has joined #openstack-keystone | 05:57 | |
| *** Nakato has joined #openstack-keystone | 05:57 | |
| *** sshen_ has joined #openstack-keystone | 05:57 | |
| *** kfox1111 has joined #openstack-keystone | 05:57 | |
| *** Kimmo__ has joined #openstack-keystone | 05:57 | |
| *** evrardjp has joined #openstack-keystone | 05:57 | |
| *** yarkot1 has joined #openstack-keystone | 05:57 | |
| *** vkmc has joined #openstack-keystone | 05:57 | |
| *** kevinbenton has joined #openstack-keystone | 05:57 | |
| *** gsilvis has joined #openstack-keystone | 05:57 | |
| *** zeus has joined #openstack-keystone | 05:57 | |
| *** ekarlso has joined #openstack-keystone | 05:57 | |
| *** stevemar has joined #openstack-keystone | 05:57 | |
| *** tsufiev has joined #openstack-keystone | 05:57 | |
| *** jidar has joined #openstack-keystone | 05:57 | |
| *** mnaser has joined #openstack-keystone | 05:57 | |
| *** trey has joined #openstack-keystone | 05:57 | |
| *** rvba has joined #openstack-keystone | 05:57 | |
| *** andreaf has joined #openstack-keystone | 05:57 | |
| *** fungi has joined #openstack-keystone | 05:57 | |
| *** jlvillal has joined #openstack-keystone | 05:57 | |
| *** orwell.freenode.net sets mode: +ovo dolphm dstanek stevemar | 05:57 | |
| *** ChanServ has joined #openstack-keystone | 05:57 | |
| *** notmyname has joined #openstack-keystone | 05:57 | |
| *** redrobot has joined #openstack-keystone | 05:57 | |
| *** EmilienM has joined #openstack-keystone | 05:57 | |
| *** orwell.freenode.net sets mode: +o ChanServ | 05:57 | |
| *** orwell.freenode.net sets mode: +bbbb *!bjornar_@* bjornar!*@* bjornar__!*@* *!awrbgh@197.123.75.191 | 05:57 | |
| *** orwell.freenode.net sets mode: +qq uvirtbot!*@* uvirbot!*@* | 05:57 | |
| *** orwell.freenode.net changes topic to "Newton Deadlines: http://releases.openstack.org/newton/schedule.html | Midcycle (July 20-22, San Jose, CA) wiki https://wiki.openstack.org/wiki/Sprints/KeystoneNewtonSprint | Meeting Etherpad https://etherpad.openstack.org/p/keystone-weekly-meeting" | 05:57 | |
| *** alex_xu has quit IRC | 06:03 | |
| *** alex_xu has joined #openstack-keystone | 06:06 | |
| openstackgerrit | Jamie Lennox proposed openstack/keystone-specs: Reservations (a working title) https://review.openstack.org/330329 | 06:12 |
|---|---|---|
| *** yolanda has joined #openstack-keystone | 06:18 | |
| jamielennox | stevemar: still here? | 06:19 |
| *** yolanda has quit IRC | 06:21 | |
| *** yolanda has joined #openstack-keystone | 06:24 | |
| *** rcernin has joined #openstack-keystone | 06:24 | |
| *** EinstCrazy has quit IRC | 06:28 | |
| *** EinstCrazy has joined #openstack-keystone | 06:29 | |
| *** EinstCrazy has quit IRC | 06:30 | |
| *** EinstCrazy has joined #openstack-keystone | 06:30 | |
| *** EinstCrazy has quit IRC | 06:41 | |
| *** EinstCrazy has joined #openstack-keystone | 06:45 | |
| *** afazekas is now known as afazekas|dentist | 06:52 | |
| openstackgerrit | Jamie Lennox proposed openstack/keystone-specs: Reservations (a working title) https://review.openstack.org/330329 | 06:58 |
| jamielennox | @channel: please read ^ | 06:58 |
| *** markvoelker_ has quit IRC | 07:01 | |
| *** markvoelker has joined #openstack-keystone | 07:01 | |
| *** amoralej|off is now known as amoralej | 07:05 | |
| *** tesseract has joined #openstack-keystone | 07:09 | |
| *** jamielennox is now known as jamielennox|away | 07:12 | |
| *** jed56 has joined #openstack-keystone | 07:16 | |
| *** pcaruana has joined #openstack-keystone | 07:17 | |
| *** permalac has quit IRC | 07:19 | |
| *** zengchen has joined #openstack-keystone | 07:23 | |
| *** roxanaghe has joined #openstack-keystone | 07:27 | |
| zengchen | Hi guys, please give me a help. how to get the nova or cinder's endpoint in my service if the catalog in the token is empty? i see the policy for 'list_endpoits' is admin, but i am not the admin. thanks. | 07:28 |
| *** GB21 has quit IRC | 07:31 | |
| *** roxanaghe has quit IRC | 07:32 | |
| *** nisha_ has joined #openstack-keystone | 07:37 | |
| *** ebarrera has joined #openstack-keystone | 07:42 | |
| *** henrynash_ has joined #openstack-keystone | 07:44 | |
| *** ChanServ sets mode: +v henrynash_ | 07:44 | |
| notmorgan | jamielennox|away: interesting | 07:52 |
| *** jinquan has joined #openstack-keystone | 07:59 | |
| *** zzzeek has quit IRC | 08:00 | |
| *** zzzeek has joined #openstack-keystone | 08:00 | |
| *** pnavarro has joined #openstack-keystone | 08:07 | |
| *** jaosorior has quit IRC | 08:07 | |
| *** jaosorior has joined #openstack-keystone | 08:08 | |
| *** permalac has joined #openstack-keystone | 08:09 | |
| openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 08:10 |
| openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 08:10 |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Disable inactive users requirements https://review.openstack.org/328447 | 08:20 |
| *** GB21 has joined #openstack-keystone | 08:32 | |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Disable inactive users requirements https://review.openstack.org/328447 | 08:39 |
| *** jamie_h has joined #openstack-keystone | 08:43 | |
| *** nisha_ has quit IRC | 08:53 | |
| *** nisha_ has joined #openstack-keystone | 08:53 | |
| *** roxanaghe has joined #openstack-keystone | 09:00 | |
| *** dmk0202 has joined #openstack-keystone | 09:02 | |
| *** roxanaghe has quit IRC | 09:06 | |
| openstackgerrit | Merged openstack/keystone: Move TestAuth unscoped token tests to TokenAPITests https://review.openstack.org/329589 | 09:10 |
| *** mkoderer__ has quit IRC | 09:28 | |
| *** TxGVNN has joined #openstack-keystone | 09:32 | |
| *** TxGVNN has quit IRC | 09:37 | |
| openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 10:10 |
| *** zqfan has joined #openstack-keystone | 10:10 | |
| *** jamielennox|away is now known as jamielennox | 10:15 | |
| *** mvk_ has quit IRC | 10:26 | |
| *** sdake has joined #openstack-keystone | 10:40 | |
| *** sdake_ has joined #openstack-keystone | 10:42 | |
| *** rakhmerov has joined #openstack-keystone | 10:44 | |
| *** sdake has quit IRC | 10:45 | |
| *** gnuoy has joined #openstack-keystone | 10:46 | |
| *** mvk_ has joined #openstack-keystone | 10:53 | |
| *** GB21 has quit IRC | 10:53 | |
| *** nisha__ has joined #openstack-keystone | 10:54 | |
| *** nisha_ has quit IRC | 10:57 | |
| openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: WIP - oidc: fix OpenID Connect authorization code grant_type https://review.openstack.org/330006 | 10:58 |
| openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: oidc: move scope into _OidcBase https://review.openstack.org/330463 | 10:58 |
| openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: WIP - oidc: add discovery document support https://review.openstack.org/330464 | 10:58 |
| openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: oidc: remove grant_type argument https://review.openstack.org/330465 | 10:58 |
| *** roxanaghe has joined #openstack-keystone | 11:02 | |
| *** roxanaghe has quit IRC | 11:07 | |
| *** sdake_ has quit IRC | 11:10 | |
| openstackgerrit | Mikhail Nikolaenko proposed openstack/keystone: Validate impersonation in trust redelegation https://review.openstack.org/330045 | 11:26 |
| *** jed56 has quit IRC | 11:34 | |
| *** jed56 has joined #openstack-keystone | 11:34 | |
| *** ddieterly has joined #openstack-keystone | 11:47 | |
| *** GB21 has joined #openstack-keystone | 11:48 | |
| *** amoralej is now known as amoralej|lunch | 11:58 | |
| *** roxanaghe has joined #openstack-keystone | 12:03 | |
| *** sdake has joined #openstack-keystone | 12:05 | |
| samueldmq | jamielennox: auth_token.__init__ imported opts, and opts needed auth_token._opts. when evaluating auth_token._opts, it passes by auth_token.__init__ again | 12:05 |
| *** ddieterly is now known as ddieterly[away] | 12:05 | |
| *** henrynash_ has quit IRC | 12:06 | |
| *** nisha__ is now known as nisha_ | 12:07 | |
| *** roxanaghe has quit IRC | 12:08 | |
| *** GB21 has quit IRC | 12:15 | |
| *** GB21 has joined #openstack-keystone | 12:17 | |
| *** rcernin has quit IRC | 12:24 | |
| *** nisha_ has quit IRC | 12:25 | |
| *** nisha_ has joined #openstack-keystone | 12:25 | |
| *** lamt has joined #openstack-keystone | 12:31 | |
| *** ddieterly has joined #openstack-keystone | 12:32 | |
| stevemar | o/ | 12:33 |
| stevemar | morning folks | 12:33 |
| *** pauloewerton has joined #openstack-keystone | 12:35 | |
| *** rcernin has joined #openstack-keystone | 12:39 | |
| samueldmq | stevemar: o/ | 12:39 |
| *** julim has joined #openstack-keystone | 12:39 | |
| *** mwheckmann has joined #openstack-keystone | 12:40 | |
| *** ddieterly is now known as ddieterly[away] | 12:41 | |
| *** ddieterly[away] has quit IRC | 12:41 | |
| *** edmondsw has joined #openstack-keystone | 12:45 | |
| *** rodrigods has quit IRC | 12:46 | |
| *** rodrigods has joined #openstack-keystone | 12:46 | |
| *** elmiko has left #openstack-keystone | 12:52 | |
| *** GB21 has quit IRC | 12:53 | |
| *** rcernin has quit IRC | 12:54 | |
| *** nisha__ has joined #openstack-keystone | 12:55 | |
| *** jsavak has joined #openstack-keystone | 12:55 | |
| *** nisha_ has quit IRC | 12:57 | |
| aloga | stevemar: hi there | 13:02 |
| *** roxanaghe has joined #openstack-keystone | 13:04 | |
| *** amoralej|lunch is now known as amoralej | 13:05 | |
| openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Add domain functional tests https://review.openstack.org/329598 | 13:06 |
| *** rcernin has joined #openstack-keystone | 13:07 | |
| openstackgerrit | Merged openstack/keystone: Update driver versioning documentation https://review.openstack.org/330118 | 13:08 |
| *** roxanaghe has quit IRC | 13:08 | |
| *** pnavarro has quit IRC | 13:09 | |
| *** nisha_ has joined #openstack-keystone | 13:14 | |
| *** nisha_ has quit IRC | 13:14 | |
| openstackgerrit | Rodrigo Duarte proposed openstack/keystone: Fix some nits in integration tests https://review.openstack.org/330537 | 13:16 |
| *** EinstCrazy has quit IRC | 13:20 | |
| *** EinstCrazy has joined #openstack-keystone | 13:21 | |
| *** EinstCrazy has quit IRC | 13:26 | |
| *** raildo-a` is now known as raildo | 13:27 | |
| *** frontrunner has joined #openstack-keystone | 13:30 | |
| *** roxanaghe has joined #openstack-keystone | 13:32 | |
| *** roxanaghe has quit IRC | 13:32 | |
| *** roxanaghe has joined #openstack-keystone | 13:33 | |
| *** roxanaghe has quit IRC | 13:33 | |
| *** ddieterly has joined #openstack-keystone | 13:40 | |
| stevemar | aloga: good morning (or good evening for you) | 13:41 |
| *** ddieterly is now known as ddieterly[away] | 13:44 | |
| *** _sigmavirus24 is now known as sigmavirus24 | 13:46 | |
| *** sigmavirus24 has joined #openstack-keystone | 13:46 | |
| *** rderose has joined #openstack-keystone | 13:47 | |
| rderose | henrynash: are you there? | 13:48 |
| *** ddieterly[away] is now known as ddieterly | 13:49 | |
| shewless | Hi. Does anyone here know if there is an easy way to query an Identity provider for a list of attributes that it provides? I have a working SP connected to testshib but I'm having trouble determining what attributes are available to me. | 13:50 |
| *** adrian_otto has joined #openstack-keystone | 13:52 | |
| *** adrian_otto has quit IRC | 13:54 | |
| rodrigods | shewless, as a Service Provider: https://www.testshib.org/test.html | 13:55 |
| shewless | rodrigods: thanks! I've been there.. and I've tried accessing https://yourhost.org/Shibboleth.sso/Session but I think it only shows me the attributes I've already requested (not all available). | 13:56 |
| *** richm has joined #openstack-keystone | 13:58 | |
| *** jaugustine has joined #openstack-keystone | 14:00 | |
| *** jaugustine has quit IRC | 14:00 | |
| *** jaugustine has joined #openstack-keystone | 14:01 | |
| openstackgerrit | Alexander Makarov proposed openstack/keystone: WIP/DNM Unified delegation assignment driver https://review.openstack.org/291318 | 14:01 |
| openstackgerrit | Alexander Makarov proposed openstack/keystone: Delegation parent discovery function https://review.openstack.org/330573 | 14:01 |
| *** woodster_ has joined #openstack-keystone | 14:01 | |
| *** rderose_ has joined #openstack-keystone | 14:05 | |
| *** sheel has quit IRC | 14:05 | |
| shewless | rodrigods: I confirmed that the Session page only shows me what I ask for in /etc/shibboleth/attribute-map.xml. I'd like to find a "username" of such field (without the email part) but I dont' know what's available on the IDP side | 14:06 |
| *** nisha__ is now known as nisha_ | 14:08 | |
| *** rderose has quit IRC | 14:08 | |
| *** jaugustine has quit IRC | 14:16 | |
| *** daemontool has joined #openstack-keystone | 14:19 | |
| *** lucas___ has joined #openstack-keystone | 14:23 | |
| stevemar | biab, dental app | 14:23 |
| *** jistr is now known as jistr|mtg | 14:28 | |
| *** ayoung has joined #openstack-keystone | 14:30 | |
| *** ChanServ sets mode: +v ayoung | 14:30 | |
| *** sheel has joined #openstack-keystone | 14:30 | |
| *** jorge_munoz has joined #openstack-keystone | 14:31 | |
| *** edtubill has joined #openstack-keystone | 14:32 | |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 14:33 |
| *** adrian_otto has joined #openstack-keystone | 14:34 | |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 14:35 |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 14:36 |
| *** jaugustine has joined #openstack-keystone | 14:37 | |
| *** adrian_otto has quit IRC | 14:38 | |
| openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Password SQL model changes https://review.openstack.org/314284 | 14:40 |
| *** pcaruana has quit IRC | 14:41 | |
| *** henrynash_ has joined #openstack-keystone | 14:42 | |
| *** ChanServ sets mode: +v henrynash_ | 14:42 | |
| henrynash | redrose: hi | 14:42 |
| henrynash | rderose: hi | 14:43 |
| *** gordc has joined #openstack-keystone | 14:45 | |
| *** adrian_otto has joined #openstack-keystone | 14:46 | |
| *** timcline has joined #openstack-keystone | 14:46 | |
| *** timcline has quit IRC | 14:46 | |
| notmorgan | o/ | 14:46 |
| *** timcline has joined #openstack-keystone | 14:47 | |
| *** roxanaghe has joined #openstack-keystone | 14:47 | |
| *** jaosorior has quit IRC | 14:49 | |
| *** roxanaghe has quit IRC | 14:52 | |
| *** sdake has quit IRC | 14:54 | |
| *** nisha__ has joined #openstack-keystone | 14:54 | |
| lbragstad | rderose_ ^ | 14:54 |
| rderose_ | lbragstad: yes | 14:55 |
| lbragstad | rderose_ henrynash was looking for you | 14:55 |
| rderose_ | ah, thx | 14:55 |
| henrynash | lbragstad:….only ‘cause he was looking for me :-) | 14:55 |
| lbragstad | rderose_ also, it doesn't look like much changed with https://review.openstack.org/#/c/314284/84 except addressing henrynash's comment on patchset 80? | 14:55 |
| patchbot | lbragstad: patch 314284 - keystone - PCI-DSS Password SQL model changes | 14:55 |
| rderose_ | henrynash: hi, had a question regarding your comment on disable active users | 14:56 |
| rderose_ | henrynash: but see you've responded, let me read your latest comment | 14:57 |
| *** nisha_ has quit IRC | 14:57 | |
| henrynash | rederose_: sure…Ok, yes - I should ahve explained my concern in more detail….I may just be misunderstanding what you intended | 14:57 |
| *** EinstCrazy has joined #openstack-keystone | 14:58 | |
| notmorgan | lbragstad: patchset 80... and not becsuse of back/forth/bikeshedding | 14:58 |
| notmorgan | lbragstad: rderose_ is trying to get the alltime-patchset-count-for-a-review-in-keystone award | 14:58 |
| lbragstad | notmorgan he's getting close :) | 14:59 |
| *** sdake has joined #openstack-keystone | 14:59 | |
| rderose_ | henrynash: no, I think you are understanding my intent. hmm... | 14:59 |
| rderose_ | henrynash: maybe migrated_at would be better... not sure I like that, but see your point regarding created_at | 15:00 |
| *** david-lyle_ is now known as david-lyle | 15:00 | |
| rderose_ | henrynash: thx | 15:00 |
| rderose_ | notmorgan: hahah, yeah | 15:01 |
| henrynash | rederose_: ok | 15:01 |
| rderose_ | notmorgan: what's the record? | 15:01 |
| notmorgan | rderose_: 80-something... but like 120 if you include the followup patch for trusts :P | 15:02 |
| notmorgan | rderose_: since it landed: code, tests in two patches | 15:02 |
| notmorgan | otherwise i think stevemar holds the record | 15:02 |
| rderose_ | notmorgan: cool, I'll aim for that :) | 15:02 |
| henrynash | rderose_: I guess I would also say, that the reult of this approach, hwoever, would be you haev this field in the DB that is effectively olny used for a temporary period….seems wasteful (although downright terrible) | 15:02 |
| *** walharthi has joined #openstack-keystone | 15:03 | |
| *** pushkaru has joined #openstack-keystone | 15:03 | |
| rderose_ | henrynash: yeah, maybe... | 15:03 |
| henrynash | rderose_: your objection to setting last_auth_at to now() on migration is, I assume, that it is a little misleading? (Even through the audit even on auth is the notifcation that gets sent….peopel shouldn’t really be using these DB fields for audit purposes) | 15:04 |
| henrynash | redrose_: (typo in my early messge… I meanst to say “although not downright terrible”..freudian slip! | 15:05 |
| *** ebarrera has quit IRC | 15:06 | |
| rderose_ | henrynash: well, my intent is to only set last_auth_at to now when authentication happens | 15:06 |
| henrynash | rderose_: which in general is exactly right, of course, it’s all about how we handle this period between migation and next auth | 15:07 |
| rderose_ | henrynash: exactly | 15:07 |
| henrynash | rderose_: however, we know last_auth_at can only tend towards correctness for the user population as a whole (i.e. a value of None just means “I don’t know when/if this person last authenticated, but I know it is not since you migrated to Newton”) | 15:11 |
| *** jistr|mtg is now known as jistr | 15:19 | |
| *** aratus has joined #openstack-keystone | 15:24 | |
| shewless | okay I see I was missing in the log it mentions which oids are available but skipped. | 15:33 |
| shewless | but my problem now is I'm trying to ask for an attribute specifically and it's still being "skipped". <Attribute name="urn:mace:dir:attribute-def:manager" id="manager"/>. I know this isn't a "SP/IDP" board but I'm hoping you can help me . | 15:34 |
| *** openstackgerrit has quit IRC | 15:34 | |
| *** openstackgerrit has joined #openstack-keystone | 15:34 | |
| *** adrian_otto has quit IRC | 15:34 | |
| *** raddaoui has joined #openstack-keystone | 15:36 | |
| *** jaugustine has quit IRC | 15:37 | |
| *** adrian_otto has joined #openstack-keystone | 15:44 | |
| *** nkinder has quit IRC | 15:47 | |
| *** aratus has quit IRC | 15:47 | |
| *** roxanaghe has joined #openstack-keystone | 15:48 | |
| *** ddieterly is now known as ddieterly[away] | 15:51 | |
| *** ddieterly[away] is now known as ddieterly | 15:51 | |
| *** aratus has joined #openstack-keystone | 15:52 | |
| *** roxanaghe has quit IRC | 15:53 | |
| *** EinstCrazy has quit IRC | 15:53 | |
| *** belmoreira has joined #openstack-keystone | 15:56 | |
| shewless | I couldn't get the manager one to work but I was able to get all of the other skipped ones to work. Now I've mapped the "name" field to "sn" - but I still get a 404 error | 15:58 |
| shewless | here is my mapping file: http://paste.ubuntu.com/17400397/ | 15:58 |
| *** nkinder has joined #openstack-keystone | 15:58 | |
| *** tesseract has quit IRC | 16:00 | |
| *** lucas___ has quit IRC | 16:00 | |
| *** lucas___ has joined #openstack-keystone | 16:01 | |
| openstackgerrit | Alexander Makarov proposed openstack/keystone: WIP/DNM Unified delegation assignment driver https://review.openstack.org/291318 | 16:03 |
| *** gyee has joined #openstack-keystone | 16:06 | |
| *** ChanServ sets mode: +v gyee | 16:06 | |
| *** lucas___ has quit IRC | 16:06 | |
| *** BjoernT has joined #openstack-keystone | 16:06 | |
| shewless | If I only have 1 identity provider do I need to set the remote id using a command like this: openstack identity provider set --remote-id <remote-id> <idp-id> | 16:08 |
| shewless | or is it enough to specify it in my metadata only? | 16:09 |
| shewless | dstanek: any chance you are around? I'm close to getting federation to work but I'm stuck. I get a "page not found" error for v3/auth/OS-FEDERATION/websso/saml2 | 16:10 |
| shewless | I see that I'm getting attributes from the IDP (testshib) but I'm not sure why the page not found error is occuring | 16:10 |
| *** roxanaghe has joined #openstack-keystone | 16:10 | |
| *** roxanaghe has quit IRC | 16:10 | |
| shewless | what is responsible for ensuring that v3/auth/OS-FEDERATION/websso/saml2 is available? | 16:11 |
| openstackgerrit | Alexander Makarov proposed openstack/keystone: Delegation parent discovery function https://review.openstack.org/330573 | 16:11 |
| openstackgerrit | Alexander Makarov proposed openstack/keystone: WIP/DNM Unified delegation assignment driver https://review.openstack.org/291318 | 16:13 |
| *** permalac has quit IRC | 16:15 | |
| *** timcline_ has joined #openstack-keystone | 16:15 | |
| stevemar | notmorgan: rderose_ the record is held by ayoung for revoke events :) | 16:17 |
| stevemar | i come in second | 16:17 |
| openstackgerrit | henry-nash proposed openstack/keystone: WIP - Add framework for supporting microversions https://review.openstack.org/330674 | 16:17 |
| *** timcline has quit IRC | 16:19 | |
| *** sdake has quit IRC | 16:20 | |
| *** timcline_ has quit IRC | 16:21 | |
| *** bunting has joined #openstack-keystone | 16:21 | |
| *** timcline has joined #openstack-keystone | 16:21 | |
| *** bunting has left #openstack-keystone | 16:22 | |
| gyee | henrynash, a question for ya on DSR | 16:23 |
| henrynash | gyee: shot | 16:23 |
| henrynash | shoot even | 16:23 |
| gyee | can both prior and implied role be in the same domain? | 16:24 |
| *** jsavak has quit IRC | 16:24 | |
| shewless | anyone? I'm really stuck on this part | 16:24 |
| gyee | I am guessing yes | 16:24 |
| henrynash | gyee: you mean can one dsr imply another drs? | 16:24 |
| henrynash | (dsr) | 16:25 |
| gyee | henrynash, yes | 16:25 |
| henrynash | gyee: yes, as far as I know | 16:25 |
| gyee | with the vanilla policy.json this is allowed, but not policy.v3 | 16:25 |
| gyee | so this is a bug then | 16:26 |
| *** bunting has joined #openstack-keystone | 16:26 | |
| gyee | henrynash, I will file a bug to earn more karma points :-) | 16:26 |
| henrynash | gyee: you be rackin’ up, bro | 16:27 |
| *** jsavak has joined #openstack-keystone | 16:27 | |
| gyee | shewless, you are trying to setup WebSSO? | 16:28 |
| dstanek | shewless: is that url configured to go to keystone and is the 404 an apache error or keystone one? | 16:28 |
| *** sdake has joined #openstack-keystone | 16:28 | |
| *** ddieterly is now known as ddieterly[away] | 16:29 | |
| shewless | gyee: yes, dstanek: I have configured that URL in apache but I'm not sure what you mean about keystone. The 404 is an apache error | 16:29 |
| henrynash | jamielennox: hi | 16:29 |
| bunting | Hi, would someone be able to tell me the current state of service tokens? I heard they were being deprecated? | 16:30 |
| shewless | dstanek: here is what I have in my apache config: http://paste.ubuntu.com/17402076 | 16:32 |
| *** lucas___ has joined #openstack-keystone | 16:33 | |
| gyee | shewless, what does your /etc/apache2/sites-enabled/keystone.conf looks like? | 16:34 |
| *** david-lyle has quit IRC | 16:35 | |
| shewless | gyee: I'm on Mitaka and have wsgi-keystone-public.conf.. is that what you're after? | 16:35 |
| gyee | shewless, yes | 16:35 |
| gyee | can you pastebin it? | 16:35 |
| *** dan_nguyen has joined #openstack-keystone | 16:35 | |
| shewless | gyee, dstanek: the whole file: http://paste.ubuntu.com/17402290 | 16:36 |
| *** lucas___ has quit IRC | 16:38 | |
| gyee | shewless, you have /v3/auth/FEDERATION there, but you are trying to access /v3/FEDERATION | 16:38 |
| gyee | so there's a mismatch somewhere | 16:38 |
| gyee | may want to check your horizon local_settings.py | 16:39 |
| gyee | bunting, I haven't heard of that rumor | 16:40 |
| openstackgerrit | henry-nash proposed openstack/keystone: WIP - Add framework for supporting microversions https://review.openstack.org/330674 | 16:40 |
| openstackgerrit | Brant Knudson proposed openstack/keystone: Use upper-constraints for cover job https://review.openstack.org/330691 | 16:41 |
| *** lucas___ has joined #openstack-keystone | 16:41 | |
| shewless | gyee: not sure what you mean. The error I'm getting is: Not found: /v3/auth/OS-FEDERATION/websso/saml2 and in apache I have <Location ~ "/v3/auth/OS-FEDERATION/websso/saml2"> | 16:42 |
| *** dmk0202 has quit IRC | 16:42 | |
| *** lucas___ has quit IRC | 16:44 | |
| *** lucas___ has joined #openstack-keystone | 16:44 | |
| shewless | gyee: what would I check in local_settings.py? OPENSTACK_KEYSTONE_URL? or something else? | 16:47 |
| gyee | shewless, you see the request in apache access log? | 16:47 |
| shewless | gyee: in the apache2/error.log I see this: [Thu Jun 16 16:48:51.944406 2016] [wsgi:error] [pid 17849:tid 140076990158592] Not Found: /v3/auth/OS-FEDERATION/websso/saml2 | 16:49 |
| *** david-lyle has joined #openstack-keystone | 16:50 | |
| *** ebarrera has joined #openstack-keystone | 16:50 | |
| shewless | gyee: in the apache2/access.log I see this: 192.168.216.117 - "" [16/Jun/2016:16:48:51 +0000] "GET /v3/auth/OS-FEDERATION/websso/saml2?origin=https://mycloud.foo.com/auth/websso/ HTTP/1.1" 404 5616 "https://idp.testshib.org/idp/profile/SAML2/Redirect/SSO" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.84 Safari/537.36" | 16:51 |
| *** jdennis has quit IRC | 16:51 | |
| gyee | shewless, arrrg | 16:52 |
| gyee | the <location> should be inside <VirtualHost> | 16:52 |
| shewless | gyee: Just that one locatoin? (not the other LocationMatch stuff)? | 16:52 |
| gyee | all of them | 16:53 |
| shewless | gyee: I will try that. I was using dstanek's example.. maybe I misread it: http://paste.openstack.org/show/508990/ | 16:53 |
| *** nisha__ has quit IRC | 16:54 | |
| gyee | I think that example is incorrect | 16:54 |
| *** ddieterly[away] is now known as ddieterly | 16:54 | |
| *** nisha__ has joined #openstack-keystone | 16:54 | |
| *** amakarov has quit IRC | 16:55 | |
| shewless | gyee: I'm getting an error now about not finding this page: https://mycloud.foo.com/Shibboleth.sso/SAML2/POST. I wonder if I have to re-upload my metadata? | 16:56 |
| ayoung | stevemar, I actually claim it for Trusts. You have to include the dolphm patch for the tests there, and the two together were well over 120 revisions | 16:56 |
| *** amakarov has joined #openstack-keystone | 16:57 | |
| gyee | shewless, which IdP are you testing with? ADFS? | 17:00 |
| *** belmoreira has quit IRC | 17:00 | |
| shewless | gyee: testshib right now.. adfs in the future. So... this section has to be outside the virtualhost block: <Location /Shibboleth.sso> SetHandler shib </Location> | 17:01 |
| shewless | gyee: If I put everything inside the virtualhost EXCEPT the <Location /Shibboleth.sso> stuff I end up with the same error (Not Found: /v3/auth/OS-FEDERATION/websso/saml2) | 17:05 |
| shewless | gyee: If I put the /Shiboleth.sso inside the virtualhost I can't even generate metadata.. | 17:05 |
| *** mvk_ has quit IRC | 17:06 | |
| ayoung | gyee, I took your Anchor Certmonger helper and started a repo. is this OK? https://github.com/admiyo/anchor-certmonger-helper | 17:06 |
| ayoung | Added a readme, and put in an Apache license header | 17:07 |
| *** daemontool has quit IRC | 17:08 | |
| shewless | gyee: Is there any other place that I need to "enable" or specify /v3/auth/OS-FEDERATION/websso/saml2 for that page to be available? | 17:08 |
| gyee | ayoung, go for it, thanks man | 17:08 |
| ayoung | gyee, cool | 17:09 |
| shewless | gyee: my trusted_dashboard is trusted_dashboard = https://mycloud.foo.com/auth/websso - is that correct? | 17:09 |
| gyee | shewless, that's fine, if you are using devstack, I think it should be /dashboard/auth/websso | 17:11 |
| ayoung | shewless, no | 17:11 |
| gyee | but we haven't get to that step yet | 17:11 |
| ayoung | https://mycloud.foo.com/auth/websso not necess | 17:11 |
| ayoung | should be your Horizon server | 17:11 |
| *** roxanaghe has joined #openstack-keystone | 17:11 | |
| ayoung | shewless, I think /websso is Keystone | 17:12 |
| gyee | ayoung, that's the Horizon callback url | 17:12 |
| gyee | s/callback/redirect back/ | 17:12 |
| ayoung | gyee, trusted desktop is the one that initially started to convo, | 17:12 |
| ayoung | I used... | 17:12 |
| * ayoung still looking | 17:14 | |
| ayoung | gyee, can't find it. Anyway, I think that is too low | 17:15 |
| ayoung | I think it can be just the Horizon server, and Horizon should be https://mycloud.foo.com/ or https://mycloud.foo.com/desktop or maybe even https://mycloud.foo.com/auth | 17:15 |
| ayoung | the websso might mess things up | 17:15 |
| shewless | gyee, ayoung: not using devstack.. so so what is responsible for providing the /v3/auth/OS-FEDERATION/websso/saml2 page? Aside from apache I don't have that config anywhere | 17:15 |
| gyee | shewless, /v3/auth/OS-FEDERATION/websso/saml2 is a Keystone endpoint | 17:16 |
| *** roxanaghe has quit IRC | 17:16 | |
| gyee | protected by Shibboleth | 17:16 |
| ayoung | I totally lied | 17:16 |
| ayoung | trusted_dashboard = https://openstack.ayoung.rhsso.oslab.test/dashboard/auth/websso/ | 17:16 |
| shewless | gyee: is it possible a mapping problem could cause this? | 17:17 |
| ayoung | shewless, so qwhen you set up Federation, you have to make 3 keystone calls | 17:17 |
| ayoung | those create the Sub URL: | 17:17 |
| gyee | shewless <Location /Shiboleth.sso> should also be inside <VirtualHost> | 17:17 |
| ayoung | /v3/auth/OS-FEDERATION/<idp> | 17:17 |
| ayoung | and | 17:17 |
| ayoung | /v3/auth/OS-FEDERATION/<idp>/protocol | 17:17 |
| ayoung | er /v3/auth/OS-FEDERATION/<idp>/<protocol> | 17:17 |
| ayoung | shewless, Yout can test it by hitting it with curl | 17:18 |
| ayoung | 404 means it does not exist, 401 means it works OK | 17:18 |
| shewless | gyee: If I do that I cannot access https://mycloud.foo.com/Shibboleth.sso/Metadata. I should be able to right? | 17:18 |
| *** roxanaghe has joined #openstack-keystone | 17:18 | |
| shewless | ayoung what's the curl line? | 17:18 |
| gyee | https://mycloud.foo.com:5000/Shibboleth.sso/Metadata | 17:19 |
| *** javis has joined #openstack-keystone | 17:19 | |
| ayoung | shewless so for me it was curl https://ipa.ayoung.rhsso.oslab.test/auth/realms/openstack/protocol/saml | 17:19 |
| ayoung | nope | 17:19 |
| ayoung | curl -g -i -X GET https://openstack.ayoung.rhsso.oslab.test:5000/v3/OS-FEDERATION/identity_providers/rhsso/protocols/saml2/auth | 17:19 |
| ayoung | that is for ECP | 17:20 |
| ayoung | try variations on that | 17:20 |
| ayoung | https://openstack.ayoung.rhsso.oslab.test:5000/v3/OS-FEDERATION/identity_providers/rhsso is my IdP. so for you... | 17:21 |
| *** rcernin has quit IRC | 17:21 | |
| shewless | gyee: in that case I guess I should upload my new metadata then | 17:23 |
| *** browne has joined #openstack-keystone | 17:23 | |
| shewless | gyee: if I do that https doesn't work anymore.. should I add SSL stuff do my virtualhost *.5000? | 17:23 |
| *** ddieterly is now known as ddieterly[away] | 17:24 | |
| gyee | shewless, sorry, you can leave that one outside | 17:24 |
| gyee | now back to the 404 | 17:24 |
| javis | can someone point me in the direction of the required binary dependencies when install keystone from source? | 17:25 |
| shewless | gyee: okay back to the 404 | 17:25 |
| ayoung | javis, look in packstack | 17:26 |
| gyee | shewless, lets start with your Horizon local_settings.py | 17:26 |
| ayoung | javis, let me try that again | 17:26 |
| ayoung | javis, look in devstack | 17:26 |
| gyee | shewless, what does your OPENSTACK_KEYSTONE_URL set to? | 17:27 |
| *** boltR_ has quit IRC | 17:27 | |
| shewless | gyee: http://paste.ubuntu.com/17404514 | 17:28 |
| ayoung | javis, for debs http://git.openstack.org/cgit/openstack-dev/devstack/tree/files/debs | 17:28 |
| ayoung | http://git.openstack.org/cgit/openstack-dev/devstack/tree/files/debs/keystone | 17:28 |
| ayoung | for RPMs | 17:28 |
| shewless | gyee: OPENSTACK_KEYSTONE_URL = "http://%s:5000/v3" % OPENSTACK_HOST | 17:28 |
| javis | ayoung: yea I saw that, oh thanks. debs are fine | 17:28 |
| ayoung | http://git.openstack.org/cgit/openstack-dev/devstack/tree/files/rpms/keystone | 17:28 |
| ayoung | javis, another approach is to install the keystone debs, get the dependencies installed, then uninstall keystone | 17:29 |
| gyee | shewless, and your <location> block is inside <VirtualHost *:5000>? | 17:30 |
| gyee | shewless, <Location ~ "/v3/auth/OS-FEDERATION/websso/saml2"> I mean | 17:31 |
| *** tqtran has joined #openstack-keystone | 17:31 | |
| shewless | gyee: here is what I did.. I moved everything inside except the shiboleth.sso part: http://paste.ubuntu.com/17404645 | 17:31 |
| openstackgerrit | henry-nash proposed openstack/keystone: Pass request back into wsgi render_reponse https://review.openstack.org/330720 | 17:32 |
| gyee | shewless, and what error are you getting now? | 17:33 |
| javis | ayoung, ahh I see. I will try using bindep with an other-requirements.txt file. | 17:33 |
| ayoung | javis, what are you trying to do? | 17:33 |
| shewless | gyee: same as beforev [Thu Jun 16 17:36:10.407472 2016] [wsgi:error] [pid 28789:tid 139944201254656] Not Found: /v3/auth/OS-FEDERATION/websso/saml2 | 17:36 |
| *** nisha_ has joined #openstack-keystone | 17:36 | |
| openstackgerrit | henry-nash proposed openstack/keystone: WIP - Add framework for supporting microversions https://review.openstack.org/330674 | 17:36 |
| gyee | shewless, did you restart Apache? | 17:38 |
| javis | ayoung, setting up keystone on a docker container. I know there is kolla but was going the manual route for kicks | 17:38 |
| *** nisha__ has quit IRC | 17:38 | |
| shewless | gyee: many times. along with shibd. but hmm.. I changed the OPENSTACK_HOST line.. because it was my "internal hostname" and not the name I'm hitting.. I think that got me a different error (401) | 17:39 |
| *** mvk_ has joined #openstack-keystone | 17:39 | |
| shewless | gyee: yup.. now I get: {"error": {"message": "The request you have made requires authentication.", "code": 401, "title": "Unauthorized"}} | 17:39 |
| lbragstad | getting a run in over lunch quick - biab | 17:39 |
| shewless | gyee: is that better or worse? | 17:39 |
| gyee | shewless, that's better | 17:40 |
| shewless | gyee: hurray! looking at keystone logs now | 17:40 |
| gyee | now Keystone should send you to the IdP to authenticate | 17:40 |
| openstackgerrit | Merged openstack/keystone: Move project scoped tests to TokenAPITests https://review.openstack.org/330116 | 17:40 |
| shewless | gyee: http://foo.sandvine.com/auth/websso/ is not a trusted dashboard host | 17:41 |
| shewless | gyee: I notice that there is no https for some reason.. do you know why that would be? | 17:42 |
| shewless | gyee: Just FYI even before I was already authenitcating against the IdP | 17:42 |
| shewless | gyee: and I was able to get attributes | 17:42 |
| gyee | shewless, change it to /dashboard/auth/websso | 17:42 |
| openstackgerrit | Merged openstack/keystone: Move project scoped catalog tests to TokenAPITests https://review.openstack.org/330161 | 17:42 |
| shewless | gyee: I think it's because I put in https:// instead of http:// | 17:43 |
| gyee | shewless, yes, it must march the original Horizon URL | 17:43 |
| shewless | gyee: but the original horizon URL is https: | 17:43 |
| openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: WIP - oidc: fix OpenID Connect authorization code grant_type https://review.openstack.org/330006 | 17:44 |
| gyee | shewless, I think you miss /dashboard in the path | 17:44 |
| openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: WIP - oidc: add discovery document support https://review.openstack.org/330464 | 17:44 |
| openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: oidc: remove grant_type argument https://review.openstack.org/330465 | 17:44 |
| shewless | gyee: I don't see anything referencing the dashboard part.. I'll try it though | 17:44 |
| gyee | shewless, if in doubt, 2x check your /etc/apache2/sites-enabled/horizon | 17:45 |
| shewless | gyee: would that be 000-default in Mitaka (there is no horizon file) | 17:46 |
| shewless | gyee: I changed it to https://mycloud.foo.com/dashboard/auth/websso | 17:47 |
| openstackgerrit | Merged openstack/keystone: Move more project scoped behavior tests to TokenAPITests https://review.openstack.org/330162 | 17:48 |
| shewless | gyee: but I get the same error: https://mycloud.foo.com/auth/websso/ is not a trusted dashboard host | 17:48 |
| openstackgerrit | Merged openstack/keystone: Consolidate domain token tests into TokenAPITests https://review.openstack.org/330163 | 17:48 |
| shewless | gyee: I think the problem is that the port 5000 stuff is http and the other stuff is https.. | 17:49 |
| gyee | this has nothing to do with port 5000 | 17:50 |
| gyee | this is horizon url | 17:50 |
| gyee | is your Horizon HTTP or HTTPS? | 17:51 |
| gyee | shewless, what's in your /etc/apache2/sites-enabled/ | 17:51 |
| openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: WIP - oidc: remove grant_type argument https://review.openstack.org/330465 | 17:52 |
| shewless | gyee: My horizon that I'm accessing it https (https://mycloud.foo.com). Here is in sites-enabled: 000-default.conf wsgi-keystone-internal.conf wsgi-keystone-public.conf | 17:52 |
| openstackgerrit | Merged openstack/keystone: Move negative domain scope test to TokenAPITests https://review.openstack.org/330215 | 17:54 |
| shewless | gyee: does it make sense that I need a trailing slash on this line? trusted_dashboard = https://mycloud.foo.com/auth/websso/ | 17:54 |
| gyee | shewless, grep 'origin=' keystone.log | 17:54 |
| openstackgerrit | Merged openstack/keystone: Move unscoped token test to TokenAPITests https://review.openstack.org/330216 | 17:55 |
| shewless | gyee: that seems to get rid of my trusted dashboard problem | 17:55 |
| openstackgerrit | Merged openstack/keystone: Move negative token tests to TokenAPITests https://review.openstack.org/330217 | 17:55 |
| gyee | yes,, the trailing slash matters | 17:55 |
| gyee | shewless, it has to match exactly what's in the 'origin' query param | 17:55 |
| gyee | shewless, can you do a 'grep 'origin=' keystone.log'? | 17:56 |
| gyee | I want to see what's coming in | 17:56 |
| shewless | gyee: GET http://mycloud.foo.com:5000/v3/auth/OS-FEDERATION/websso/saml2?origin=https://mycloud.foo.com/auth/websso/ | 17:56 |
| shewless | gyee: so I think that trailing '/' is what was missing.. now I get this error: | 17:57 |
| shewless | {"error": {"message": "Could not find Identity Provider: https://idp.testshib.org/idp/shibboleth", "code": 404, "title": "Not Found"}} | 17:57 |
| shewless | gyee: thjat's after I login to the idp | 17:58 |
| *** rderose_ has quit IRC | 17:59 | |
| gyee | shewless, now its getting into your IdP meta file | 17:59 |
| shewless | gyee: that's cool. Why the 404 error? That page exists if I browse to it | 18:00 |
| *** jsavak has quit IRC | 18:03 | |
| *** amoralej is now known as amoralej|off | 18:04 | |
| *** ebalduf has joined #openstack-keystone | 18:06 | |
| *** jsavak has joined #openstack-keystone | 18:06 | |
| gyee | shewless, that error coming from Keystone or Horizon? | 18:07 |
| *** rcernin has joined #openstack-keystone | 18:07 | |
| shewless | gyee: that message is in /var/log/apache2/keystone-public.log... so I guess keystone | 18:08 |
| shewless | gyee: the weird part to me is that I can view this: https://mycloud.foo.com/Shibboleth.sso/Session and it'll tell me all the attributes of the user I've logged in as.. | 18:08 |
| shewless | gyee: I've been able to to that for awihle though | 18:08 |
| gyee | shewless, in your keystone.conf, what does remote_id_attribute set to? | 18:10 |
| gyee | that attribute in your saml2 should map to the IdP you created in Keystone | 18:10 |
| shewless | gyee: remote_id_attribute = Shib-Identity-Provider | 18:10 |
| gyee | Keystone use that to lookup the IdP | 18:11 |
| shewless | gyee: hmm. where do I put that in keystone? | 18:11 |
| shewless | gyee: like openstack identity provider show "provider_name" | 18:12 |
| shewless | gyee: the --remote_ids field? I've left that blank up until now.. that's bad isn't it? | 18:12 |
| gyee | yes --remote_ids field | 18:13 |
| *** jaugustine has joined #openstack-keystone | 18:13 | |
| shewless | gyee: so should it be https://idp.testshib.org/idp/shibboleth or Shib-Identity-Provider | 18:14 |
| gyee | set your remote_ids to "https://idp.testshib.org/idp/shibboleth" | 18:14 |
| shewless | gyee: SUCCESS!!!!!!!! | 18:15 |
| gyee | nice | 18:15 |
| gyee | shewless, I have to dash to a meeting, good luck the rest of the way | 18:16 |
| shewless | gyee, dstanek, ayoung: thank you so much! that was a battle | 18:16 |
| shewless | gyee: thanks.. still have a lot to do.. | 18:16 |
| *** aratus has quit IRC | 18:17 | |
| ayoung | shewless, working on making it less painful in the future, albeing not for Shib, but other | 18:19 |
| shewless | ayoung: I would choose other to avoid that pain :) | 18:19 |
| shewless | so.. my user name is some crazy hash string.. I'm guessing I need to update my mapping file to make that clearer? | 18:20 |
| ayoung | shewless, I have ansible playbooks I am working on for Red Hat SSO, based on Keycloak, and and older one for Ipsilon | 18:21 |
| shewless | ayoung: that's cool. I'll actually be putting my stuff into a playbook as well | 18:22 |
| *** aratus has joined #openstack-keystone | 18:22 | |
| ayoung | they are not perfect. I just realized that they assume mod_auth_mellon has already been installed | 18:22 |
| ayoung | cuz, we do that early on | 18:22 |
| ayoung | but that should be in the playbook. | 18:22 |
| ayoung | er, the role | 18:22 |
| ayoung | https://github.com/admiyo/rippowam/tree/master/roles/rhsso | 18:22 |
| ayoung | for rhsso | 18:23 |
| shewless | ayoung: I'll have a look. thanks | 18:23 |
| ayoung | https://github.com/admiyo/rippowam/tree/master/roles/keycloak-saml-idp is the KEystone side of it for Keycloak | 18:23 |
| shewless | ayoung: do you know how I would get the top right login name to be the "Name" and not the "ID" ? | 18:23 |
| ayoung | https://github.com/admiyo/rippowam/tree/master/roles/rhsso-saml-idp | 18:23 |
| ayoung | shewless, fix the bug assigned to me? | 18:23 |
| shewless | ayoung: lol.. | 18:23 |
| ayoung | shewless, https://bugs.launchpad.net/keystone/+bug/1590426 | 18:24 |
| openstack | Launchpad bug 1590426 in OpenStack Identity (keystone) "Keystone Federated Identity assertion name not included in token" [Undecided,New] - Assigned to Adam Young (ayoung) | 18:24 |
| shewless | ayoung: so no workaround? | 18:24 |
| *** mkoderer__ has joined #openstack-keystone | 18:24 | |
| ayoung | shewless, workaround involves editing python files... | 18:24 |
| ayoung | does that count>? | 18:24 |
| *** ddieterly[away] has quit IRC | 18:24 | |
| shewless | ayoung: yes if there isn't too much to modify! | 18:24 |
| ayoung | heh | 18:24 |
| ayoung | I have not yet looked at it | 18:24 |
| ayoung | its in the token, and that is as far as I got | 18:25 |
| shewless | ayoung: lol okay I'll put up with what it is for now | 18:25 |
| *** gyee has quit IRC | 18:25 | |
| shewless | ayoung: I want each user to have their own project assigned to them. Do you know if there is a "project" field in the mapping file? | 18:26 |
| ayoung | shewless, heh | 18:26 |
| *** dan_nguyen has quit IRC | 18:26 | |
| ayoung | dolphm, is working on an autoprovisioning spec even as we speak | 18:26 |
| shewless | ayoung: cool. for now I'm okay if I create the project ahead of time.. I just need to map it correctly | 18:26 |
| ayoung | shewless, nah, you still need a role assignment | 18:27 |
| shewless | ayoung: that's okay. It's the same for ldap. When we have new users join the company I can run 2 command to assign their role and create a project | 18:27 |
| *** ddieterly has joined #openstack-keystone | 18:30 | |
| shewless | ayoung: I bet I'd have to create a unique group for every user and have a role associated with each group with a default project. Is that right? | 18:34 |
| ayoung | shewless, today? Yep | 18:34 |
| ayoung | you can use the "empty blacklist" approach though so you don;'t need to have each in the mapping | 18:34 |
| shewless | ayoung: oh? that sounds interesting. How do I do that? | 18:35 |
| ayoung | have each user be their own group, create the group in the SQL backend | 18:35 |
| ayoung | shewless, so instead of https://github.com/admiyo/rippowam/blob/master/roles/keyfed/files/mapping_ipsilon_saml2.json#L30 | 18:36 |
| shewless | ayoung: right.. then the mapping would be group "name" : {1} | 18:36 |
| ayoung | do "blacklist": [] | 18:36 |
| shewless | ayoung: okay. .can I just remove the whitelist/blacklist completely from the mapping? | 18:37 |
| ayoung | you can map the remote "type": "MELLON_NAME_ID" to "local": [{ | 18:37 |
| ayoung | "groups": "{0}", | 18:37 |
| ayoung | nahm, you need one or the other | 18:37 |
| *** aratus has quit IRC | 18:39 | |
| *** rderose has joined #openstack-keystone | 18:39 | |
| *** pushkaru has quit IRC | 18:40 | |
| *** tonytan4ever has joined #openstack-keystone | 18:43 | |
| *** dmk0202 has joined #openstack-keystone | 18:44 | |
| *** dmk0202 has quit IRC | 18:45 | |
| *** ebarrera has quit IRC | 18:46 | |
| *** amit213 has joined #openstack-keystone | 18:51 | |
| mwheckmann | hello. Wondering if anyone saw the thread I started in openstack-operators ML: http://lists.openstack.org/pipermail/openstack-operators/2016-June/010694.html | 18:53 |
| mwheckmann | actually, ayoung noticed it, but the Operator community doesn't really have much to say about it, so I'm turning to the dev community. | 18:54 |
| *** nisha__ has joined #openstack-keystone | 18:54 | |
| mwheckmann | Is there anyway to do what I'm trying to achieve? Or do I have to wait for https://review.openstack.org/#/c/324055/2/specs/keystone/newton/shadow-mapping.rst ? | 18:55 |
| patchbot | mwheckmann: patch 324055 - keystone-specs - Mapping shadow users into projects and roles | 18:55 |
| *** nisha_ has quit IRC | 18:57 | |
| mwheckmann | The main blocker for me is that all users who come in from federation are thrown into the special "Federated" domain | 18:58 |
| *** yolanda has quit IRC | 19:00 | |
| *** rderose_ has joined #openstack-keystone | 19:01 | |
| *** rderose has quit IRC | 19:05 | |
| *** jsavak has quit IRC | 19:05 | |
| lbragstad | here is a refactor review if anyone is interested - https://review.openstack.org/#/c/330218/1 | 19:08 |
| patchbot | lbragstad: patch 330218 - keystone - Move cross domain/group/project auth tests | 19:08 |
| lbragstad | once that lands i'm going to rebase and fix all the merge conflicts on the dependent patches | 19:08 |
| *** ebalduf has quit IRC | 19:09 | |
| *** jdennis has joined #openstack-keystone | 19:12 | |
| *** roxanagh_ has joined #openstack-keystone | 19:13 | |
| *** roxanagh_ has quit IRC | 19:17 | |
| *** aratus has joined #openstack-keystone | 19:25 | |
| lbragstad | i'm going to perform some updates to the performance job | 19:27 |
| *** rderose_ has quit IRC | 19:27 | |
| lbragstad | patches in review with 'check performance' will be logged and the jobs will be run later | 19:27 |
| *** nisha__ is now known as nisha_ | 19:32 | |
| *** rderose has joined #openstack-keystone | 19:32 | |
| *** aratus has quit IRC | 19:38 | |
| *** jdennis has quit IRC | 19:39 | |
| *** dmk0202 has joined #openstack-keystone | 19:40 | |
| *** dmk0202 has quit IRC | 19:43 | |
| *** aratus has joined #openstack-keystone | 19:47 | |
| *** djc_ has joined #openstack-keystone | 19:49 | |
| djc_ | why is the default keystone token expiration set to 24 hours? what are the ramifications of increasing beyond 24 hours? | 19:49 |
| *** jsavak has joined #openstack-keystone | 19:55 | |
| *** ebalduf has joined #openstack-keystone | 20:01 | |
| *** rderose has quit IRC | 20:02 | |
| *** rderose_ has joined #openstack-keystone | 20:02 | |
| *** dan_nguyen has joined #openstack-keystone | 20:02 | |
| *** lucas___ has quit IRC | 20:04 | |
| *** sheel has quit IRC | 20:05 | |
| browne | djc_: default token timeout is 1 hour (3600 seconds) | 20:08 |
| djc_ | browne: is the default 1 hour for security purposes? | 20:10 |
| browne | yes, because the tokens are bearer tokens. the longer the expiration, the more time someone can use the token if stolen | 20:11 |
| djc_ | browne: we are using swift and keystone. does the 1 hour expiration time pose a problem for transfers longer than 1 hour? | 20:12 |
| notmyname | no | 20:12 |
| * notmyname lurks in here too | 20:12 | |
| browne | djc_: not if swift properly acquires a new token when its expired | 20:12 |
| *** djc_ has quit IRC | 20:13 | |
| browne | i think most projects use keystonemiddleware which handles this | 20:13 |
| notmyname | the token is validated near the start of the request. so if it's validated and then data is transferred for the next 2 hours, that's ok. no need to re-auth in the middle, because that's the same request | 20:14 |
| *** ddieterly is now known as ddieterly[away] | 20:14 | |
| browne | oh ok | 20:14 |
| *** ayoung has quit IRC | 20:18 | |
| *** openstackstatus has joined #openstack-keystone | 20:19 | |
| *** ChanServ sets mode: +v openstackstatus | 20:19 | |
| *** tonytan4ever has quit IRC | 20:19 | |
| *** dmk0202 has joined #openstack-keystone | 20:23 | |
| *** gyee has joined #openstack-keystone | 20:24 | |
| *** ChanServ sets mode: +v gyee | 20:24 | |
| *** henrynash_ has quit IRC | 20:29 | |
| *** jsavak has quit IRC | 20:31 | |
| *** jsavak has joined #openstack-keystone | 20:32 | |
| shewless | hey guys. I think I'm hitting a weird bug in with my federation setup. When I first try and "connect" via horizon I see an error apache error: Not Found: /v3/auth/OS-FEDERATION/websso/saml2. But when I try and connect subsequently it works as expected. | 20:32 |
| shewless | I can reproduce this on all browsers or after I restart apache2 | 20:32 |
| *** mwheckmann has quit IRC | 20:32 | |
| *** nisha_ has quit IRC | 20:32 | |
| shewless | IE when I restart apache I will always get a "page not found" error the first time I try to connect with each browser.. and then subsequent attempts to connect work perfectly | 20:33 |
| *** ddieterly[away] is now known as ddieterly | 20:44 | |
| *** dan_nguyen has quit IRC | 20:48 | |
| *** aratus has quit IRC | 20:49 | |
| *** aratus has joined #openstack-keystone | 20:50 | |
| *** jaugustine has quit IRC | 20:52 | |
| *** jamie_h has quit IRC | 20:57 | |
| *** aratus has quit IRC | 21:03 | |
| *** aratus has joined #openstack-keystone | 21:10 | |
| *** roxanagh_ has joined #openstack-keystone | 21:14 | |
| *** pauloewerton has quit IRC | 21:15 | |
| openstackgerrit | Merged openstack/keystone: Move cross domain/group/project auth tests https://review.openstack.org/330218 | 21:16 |
| openstackgerrit | Merged openstack/keystone: Use request object in auth plugins https://review.openstack.org/330290 | 21:17 |
| *** roxanagh_ has quit IRC | 21:18 | |
| adrian_otto | I'm trying to debug a trust configuration issue, and I'm not able to figure out how to list identity domains. I don't see them in Horizon, and I cant find them in the "openstack" client either. | 21:23 |
| adrian_otto | where should I be looking for that? | 21:23 |
| lbragstad | adrian_otto it looks like osc has domains as it's own subcommand - http://docs.openstack.org/developer/python-openstackclient/command-objects/domain.html | 21:30 |
| jamielennox | o/ | 21:31 |
| lbragstad | jamielennox o/ | 21:31 |
| adrian_otto | thanks lbragstad. Looks like my osc client is older, because it's not in there. | 21:32 |
| adrian_otto | 2.6.0 | 21:32 |
| lbragstad | adrian_otto ah ha - that could be why | 21:33 |
| *** aratus has quit IRC | 21:34 | |
| *** rcernin has quit IRC | 21:36 | |
| *** dmk0202 has quit IRC | 21:38 | |
| *** aratus has joined #openstack-keystone | 21:41 | |
| jamielennox | notmorgan: interesting like good? | 21:43 |
| *** woodster_ has quit IRC | 21:48 | |
| *** adrian_otto has quit IRC | 21:50 | |
| *** dan_nguyen has joined #openstack-keystone | 21:53 | |
| *** jsavak has quit IRC | 21:53 | |
| *** jsavak has joined #openstack-keystone | 21:53 | |
| tqtran | hello, i have a question regarding how sso_callback_template.html how is keystone hosting this file? | 21:57 |
| tqtran | stevemar: ^-- since i know you did some work on this way back | 21:58 |
| jamielennox | tqtran: from memory it's not hosted by default, you need to stick it in your apache conf in the appropriate place | 22:00 |
| jamielennox | but it has been a little while | 22:00 |
| *** dmk0202 has joined #openstack-keystone | 22:04 | |
| *** browne has quit IRC | 22:04 | |
| *** BjoernT has quit IRC | 22:04 | |
| *** sigmavirus24 is now known as sigmavirus24_ | 22:05 | |
| *** timcline has quit IRC | 22:07 | |
| *** ayoung has joined #openstack-keystone | 22:07 | |
| *** ChanServ sets mode: +v ayoung | 22:07 | |
| *** timcline has joined #openstack-keystone | 22:08 | |
| *** edtubill has quit IRC | 22:09 | |
| dstanek | tqtran: jamielennox: actually keystone serves this from the federation controller | 22:10 |
| jamielennox | dstanek: oh? then i will shut back up again :p | 22:11 |
| dstanek | jamielennox: http://git.openstack.org/cgit/openstack/keystone/tree/keystone/federation/controllers.py#n338 | 22:11 |
| *** timcline has quit IRC | 22:12 | |
| dstanek | i've been looking at federation waaaaay too much | 22:13 |
| dstanek | bknudson_: so what do you think of the response object approach to request_id in keystone client? | 22:16 |
| bknudson_ | dstanek: I don't know what that means | 22:16 |
| dstanek | https://review.openstack.org/#/c/329913 - you mentioned it in a review | 22:17 |
| dstanek | tqtran: does that answer your question | 22:17 |
| *** javis has quit IRC | 22:18 | |
| bknudson_ | dstanek: so you have to use .data to get the data? | 22:18 |
| bknudson_ | not a fan just because I don't think that's how any other client library implemented this. | 22:19 |
| dstanek | bknudson_: yes | 22:19 |
| dstanek | bknudson_: i just don't want to jump off the bridge because everyone else is doing it | 22:19 |
| dstanek | client libs are harder to change | 22:19 |
| *** walharthi has quit IRC | 22:21 | |
| dstanek | bknudson_: what do you think would be the right way to do this if we were doing greenfield development | 22:22 |
| bknudson_ | just think of osc - it has to work with all these libraries and keystone is going to be totally different | 22:22 |
| bknudson_ | I believe the session object has a way to register a callback so I'd have applications do that so they can opt in to getting the request ID | 22:23 |
| bknudson_ | also it would be totally async | 22:23 |
| *** ebalduf has quit IRC | 22:23 | |
| bknudson_ | and generated dynamically | 22:23 |
| bknudson_ | and unicorns would dance | 22:24 |
| dstanek | :-) so magic | 22:24 |
| bknudson_ | so it would be similar to your proposal but be a callback instead of changing the return value | 22:25 |
| *** jsavak has quit IRC | 22:26 | |
| bknudson_ | the callback would provide more info like the URL that was requested... maybe some timing info? | 22:26 |
| dstanek | i think that would be much better than what was proposed | 22:26 |
| dstanek | bknudson_: right, that's the kind of stuff that i would put in the response object | 22:27 |
| openstackgerrit | Jamie Lennox proposed openstack/keystone: Use http_proxy_to_wsgi from oslo.middleware https://review.openstack.org/327418 | 22:27 |
| bknudson_ | dstanek: http://docs.python-requests.org/en/master/user/advanced/#event-hooks | 22:28 |
| bknudson_ | might not need any changes to keystoneclient to use this | 22:29 |
| *** ddieterly is now known as ddieterly[away] | 22:32 | |
| dstanek | bknudson_: you wouldn't with that | 22:32 |
| *** ddieterly[away] has quit IRC | 22:32 | |
| *** darrenc is now known as darren_afk | 22:34 | |
| lbragstad | keystone performance review if anyone has feedback https://github.com/lbragstad/keystone-performance/pull/11 | 22:36 |
| tqtran | dstanek: yep, thanks for the lead. zaqar is trying to do something similar for their subscription confirmation page | 22:36 |
| bknudson_ | lbragstad: just put it in gerrit already! | 22:36 |
| lbragstad | bknudson_ soon! | 22:37 |
| jamielennox | ayoung: so your ipa.younglogic.net - what's an ECP protected target i can test it with? | 22:37 |
| bknudson_ | lbragstad: doesn't need to clean up? | 22:38 |
| lbragstad | bknudson_ nope - it's in a container that gets deleted when the performance results are done | 22:39 |
| *** dmk0202 has quit IRC | 22:39 | |
| dstanek | lbragstad: does that do a run before and a run after the commit it's testing? | 22:43 |
| lbragstad | nope it does it only in the set up | 22:43 |
| lbragstad | so it standup keystone, populates it with garbage, | 22:43 |
| lbragstad | run benchmarks on master | 22:44 |
| lbragstad | then runs benchmarks on the patch | 22:44 |
| *** darren_afk is now known as darrenc | 22:55 | |
| *** gordc has quit IRC | 22:55 | |
| *** browne has joined #openstack-keystone | 22:57 | |
| *** ayoung has quit IRC | 23:07 | |
| *** edmondsw has quit IRC | 23:07 | |
| *** browne has quit IRC | 23:10 | |
| *** rderose has joined #openstack-keystone | 23:13 | |
| *** rderose_ has quit IRC | 23:15 | |
| *** roxanagh_ has joined #openstack-keystone | 23:15 | |
| *** raddaoui has quit IRC | 23:17 | |
| *** adrian_otto has joined #openstack-keystone | 23:19 | |
| *** roxanagh_ has quit IRC | 23:20 | |
| *** rderose has quit IRC | 23:22 | |
| *** roxanaghe has quit IRC | 23:23 | |
| *** aratus has quit IRC | 23:26 | |
| dstanek | lbragstad: i was thinking that in addition to those two links it puts in there that it could show the before/after in a single txt file | 23:29 |
| *** aratus has joined #openstack-keystone | 23:30 | |
| dstanek | sorry shewless; got busy on a call and didn't realize that you responded. were you able to get what you needed from the others? | 23:32 |
| *** iurygregory_ has joined #openstack-keystone | 23:34 | |
| *** aratus has quit IRC | 23:35 | |
| *** aratus has joined #openstack-keystone | 23:38 | |
| *** chlong has quit IRC | 23:42 | |
| openstackgerrit | Jamie Lennox proposed openstack/keystone: Use request.params instead of context['query_string'] https://review.openstack.org/330822 | 23:42 |
| *** sshen_ has quit IRC | 23:43 | |
| openstackgerrit | Jamie Lennox proposed openstack/keystone: Use http_proxy_to_wsgi from oslo.middleware https://review.openstack.org/327418 | 23:44 |
| *** ayoung has joined #openstack-keystone | 23:44 | |
| *** ChanServ sets mode: +v ayoung | 23:44 | |
| *** rderose has joined #openstack-keystone | 23:45 | |
| *** sshen has joined #openstack-keystone | 23:48 | |
| *** jdennis has joined #openstack-keystone | 23:51 | |
| lbragstad | dstanek yeah - I have an issue open to simplify all of that | 23:53 |
| lbragstad | dstanek https://github.com/lbragstad/keystone-performance/issues/5 | 23:53 |
| *** rderose has quit IRC | 23:54 | |
| ayoung | jamielennox, there is a good chance that the Rippowam deploy will fail on upgrade. if it does, I'll reinstall the IPA server | 23:54 |
| jamielennox | ayoung: i won't need it for long, if you've got something that i can test against for the next few hours that will be enough | 23:55 |
| jamielennox | ayoung: also did you see my reservations spec? | 23:55 |
| ayoung | jamielennox, everything else is inside the RH firewall | 23:55 |
| ayoung | jamielennox, packstack is broken right now | 23:57 |
| *** sdake has quit IRC | 23:57 | |
| ayoung | wait...but this should not be | 23:57 |
| ayoung | butno, I don't have anything set up. jamielennox want to throw some app up to hit? Can even do a Keystone instance if you have an easy way to set it up[ | 23:58 |
| jamielennox | ayoung: i regret to say i'd need to read all the docs again - but the app is as simple as pretty print the environ | 23:58 |
| ayoung | we had one of those, I thought. | 23:59 |
| jamielennox | i had a test script that rippowam used to deploy and comment out | 23:59 |
| jamielennox | i don't know how you've deployed your public instance | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!