Wednesday, 2016-07-20

*** dan_nguyen has quit IRC00:07
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Lockout requirements  https://review.openstack.org/34007400:08
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Adds password_expires_at to API docs  https://review.openstack.org/33631800:12
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Adds password_expires_at to API docs  https://review.openstack.org/33631800:13
*** sdake_ has quit IRC00:28
*** code-R has joined #openstack-keystone00:34
*** spzala has quit IRC00:35
*** code-R_ has joined #openstack-keystone00:35
*** spzala has joined #openstack-keystone00:35
*** tqtran has quit IRC00:37
*** code-R has quit IRC00:38
*** spzala has quit IRC00:40
*** spzala has joined #openstack-keystone00:44
*** dan_nguyen has joined #openstack-keystone01:03
*** wangqun has joined #openstack-keystone01:04
*** iurygregory_ has joined #openstack-keystone01:32
*** haplo37_ has joined #openstack-keystone01:34
*** harlowja has joined #openstack-keystone01:37
*** EinstCrazy has joined #openstack-keystone01:41
*** davechen has joined #openstack-keystone01:43
*** wangqun has quit IRC01:46
*** dan_nguyen has left #openstack-keystone01:49
*** dan_nguyen has joined #openstack-keystone01:49
*** dan_nguyen has left #openstack-keystone01:49
*** ravelar159 has joined #openstack-keystone02:02
*** simondodsley has quit IRC02:03
*** wangqun has joined #openstack-keystone02:04
*** ravelar159 has quit IRC02:10
*** spzala has quit IRC02:10
*** wangqun has quit IRC02:13
*** ravelar159 has joined #openstack-keystone02:15
*** jed56 has quit IRC02:15
*** wangqun has joined #openstack-keystone02:25
*** ravelar159 has quit IRC02:26
*** wangqun has quit IRC02:37
*** iurygregory_ has quit IRC02:45
openstackgerritAndrew Liu proposed openstack/keystone: Added cache for id mapping manager  https://review.openstack.org/32882003:00
*** spzala has joined #openstack-keystone03:01
*** spzala has quit IRC03:06
*** wangqun has joined #openstack-keystone03:07
*** kevinbenton has quit IRC03:07
*** browne has quit IRC03:09
*** kevinbenton has joined #openstack-keystone03:11
*** vkmc has quit IRC03:15
*** richm has quit IRC03:19
*** fawadkhaliq has joined #openstack-keystone03:20
*** vkmc has joined #openstack-keystone03:21
*** EinstCrazy has quit IRC03:22
*** EinstCrazy has joined #openstack-keystone03:22
*** adu has quit IRC03:26
*** jaosorior has joined #openstack-keystone03:29
*** julim has quit IRC03:32
*** chrisshattuck has joined #openstack-keystone03:32
*** fawadkhaliq has quit IRC03:34
*** henrynash has quit IRC03:38
*** henrynash has joined #openstack-keystone03:39
*** ChanServ sets mode: +v henrynash03:39
*** woodster_ has quit IRC03:39
openstackgerritSwapnil Kulkarni (coolsvap) proposed openstack/keystone: [WIP] Testing latest u-c  https://review.openstack.org/31843503:44
*** david-lyle has joined #openstack-keystone03:49
*** charz has quit IRC03:50
*** charz has joined #openstack-keystone03:51
*** davechen has quit IRC03:57
*** spzala has joined #openstack-keystone04:02
*** spzala has quit IRC04:07
*** fawadkhaliq has joined #openstack-keystone04:16
*** david-lyle_ has joined #openstack-keystone04:19
*** david-lyle has quit IRC04:19
*** fawadkhaliq has quit IRC04:20
*** lamt has quit IRC04:21
*** yarkot- has quit IRC04:25
*** david-lyle_ has quit IRC04:26
*** itisha has joined #openstack-keystone04:36
*** yarkot1 has joined #openstack-keystone04:40
*** samueldmq has joined #openstack-keystone04:44
*** chrisshattuck has quit IRC04:44
*** samueldmq has quit IRC04:44
*** code-R has joined #openstack-keystone04:45
*** code-R_ has quit IRC04:45
*** d0ugal has quit IRC04:46
*** d0ugal has joined #openstack-keystone04:47
*** spzala has joined #openstack-keystone05:00
*** jed56 has joined #openstack-keystone05:00
*** spzala has quit IRC05:06
openstackgerritRon De Rose proposed openstack/keystone: PCI-DSS Lockout requirements  https://review.openstack.org/34007405:21
*** rcernin has quit IRC05:44
*** haplo37_ has quit IRC05:52
*** davechen has joined #openstack-keystone05:54
*** d0ugal has quit IRC05:58
*** spzala has joined #openstack-keystone06:02
*** spzala has quit IRC06:07
*** rcernin has joined #openstack-keystone06:07
*** code-R has quit IRC06:09
*** TxGVNN has joined #openstack-keystone06:22
*** alex_xu has quit IRC06:25
*** afazekas is now known as afazekas|dentist06:27
*** alex_xu has joined #openstack-keystone06:27
*** jerrygb has quit IRC06:29
*** wangqun has quit IRC06:30
*** roxanaghe has joined #openstack-keystone06:32
*** roxanaghe has quit IRC06:37
*** d0ugal has joined #openstack-keystone06:41
*** tesseract- has joined #openstack-keystone06:50
*** d0ugal has quit IRC06:51
*** belmoreira has joined #openstack-keystone07:01
*** rdo has quit IRC07:05
*** d0ugal has joined #openstack-keystone07:07
*** rdo has joined #openstack-keystone07:13
*** jed56 has quit IRC07:25
*** jerrygb has joined #openstack-keystone07:30
*** jerrygb has quit IRC07:35
openstackgerritDave Chen proposed openstack/keystone: Fix the errors in params in api-ref for V3 region  https://review.openstack.org/34325007:45
openstackgerritDave Chen proposed openstack/keystone: Fix the errors in params in api-ref for V3 user  https://review.openstack.org/34208907:45
*** d0ugal has quit IRC07:46
*** jhova has quit IRC07:47
openstackgerritDave Chen proposed openstack/keystone: Fix the errors in params in api-ref for V3 user  https://review.openstack.org/34208907:55
*** zzzeek has quit IRC08:00
*** zzzeek has joined #openstack-keystone08:00
openstackgerritAlvaro Lopez Garcia proposed openstack/keystoneauth: oidc: implement client_credentials grant type  https://review.openstack.org/34462608:00
openstackgerritAlvaro Lopez Garcia proposed openstack/keystoneauth: oidc: add missing 'OidcAccessToken' to __all__  https://review.openstack.org/34462808:03
*** d0ugal has joined #openstack-keystone08:04
*** spzala has joined #openstack-keystone08:04
*** d0ugal has quit IRC08:04
*** d0ugal has joined #openstack-keystone08:04
*** spzala has quit IRC08:08
*** EinstCra_ has joined #openstack-keystone08:08
*** code-R has joined #openstack-keystone08:10
*** EinstCrazy has quit IRC08:11
*** code-R has quit IRC08:15
*** pnavarro has joined #openstack-keystone08:16
*** roxanaghe has joined #openstack-keystone08:21
*** roxanaghe has quit IRC08:25
*** jerrygb has joined #openstack-keystone08:31
*** EinstCrazy has joined #openstack-keystone08:33
*** jerrygb has quit IRC08:35
*** EinstCra_ has quit IRC08:36
*** davechen has quit IRC08:46
*** fawadkhaliq has joined #openstack-keystone08:47
*** davechen has joined #openstack-keystone08:47
*** fawadkhaliq has quit IRC08:47
*** fawadkhaliq has joined #openstack-keystone08:48
*** fawadkhaliq has quit IRC08:48
*** fawadkhaliq has joined #openstack-keystone08:50
*** fawadkhaliq has quit IRC08:52
*** fawadkhaliq has joined #openstack-keystone08:52
*** fawadkhaliq has quit IRC08:56
*** jaosorior has quit IRC08:58
*** jaosorior has joined #openstack-keystone08:58
*** jaosorior is now known as jaosorior_lunch09:00
*** spzala has joined #openstack-keystone09:04
*** spzala has quit IRC09:09
*** aastha has quit IRC09:19
*** sdake has joined #openstack-keystone09:21
openstackgerritDave Chen proposed openstack/keystone: Fix the V2 API for enabling a user  https://review.openstack.org/34405709:21
*** sdake has quit IRC09:23
*** mvk has quit IRC09:27
*** davechen has left #openstack-keystone09:31
*** jerrygb has joined #openstack-keystone09:32
*** jerrygb has quit IRC09:36
*** TxGVNN has quit IRC09:57
*** spzala has joined #openstack-keystone10:05
*** roxanaghe has joined #openstack-keystone10:09
*** spzala has quit IRC10:10
*** roxanaghe has quit IRC10:14
*** sdake has joined #openstack-keystone10:14
*** sdake_ has joined #openstack-keystone10:17
*** jaosorior_lunch is now known as jaosorior10:19
*** sdake has quit IRC10:19
*** sdake_ has quit IRC10:22
*** sdake has joined #openstack-keystone10:25
*** d0ugal has quit IRC10:31
*** jerrygb has joined #openstack-keystone10:33
*** TxGVNN has joined #openstack-keystone10:37
*** sdake has quit IRC10:38
*** jerrygb has quit IRC10:39
*** raildo has joined #openstack-keystone10:40
*** TxGVNN has quit IRC10:41
*** sdake has joined #openstack-keystone10:42
*** Murali has joined #openstack-keystone10:44
*** mvk has joined #openstack-keystone10:44
MuraliHi Could some body help to come over this error http://pastebin.ubuntu.com/20160084/10:45
MuraliI am using mitaka and I am seeing this when i try tacker10:45
raildoMurali, BadRequest: Expecting to find domain in project, sounds like you didn't setted properly the os_env, or the token are not scoped correctly10:49
MuraliRaildo: I am able launch vm suceessfully10:54
MuraliI see this error when I use tacker command10:54
raildoMurali, which version of keystoneclient are you using?10:57
MuraliRaildo Its keystone v311:00
Muraliin mitaka11:00
raildoMurali, nice, so can you do an echo in $OS_PROJECT_ID and $OS_PROJECT_NAME? and verify if at least on of this have some value?11:03
*** spzala has joined #openstack-keystone11:06
*** spzala has quit IRC11:11
*** sdake has quit IRC11:12
openstackgerritMerged openstack/keystone: Clean up api-ref for domains  https://review.openstack.org/34394411:18
openstackgerritYatin Kumbhare proposed openstack/keystonemiddleware: Add Python 3.5 classifier  https://review.openstack.org/34106611:21
*** rodrigods has quit IRC11:26
MuraliRaildo: echo $OS_PROJECT_NAME having admin11:33
*** jerrygb has joined #openstack-keystone11:35
bretonMurali: what about echo $OS_PROJECT_DOMAIN_NAME and echo $OS_PROJECT_DOMAIN_ID ?11:35
MuraliBreton: echo $OS_PROJECT_DOMAIN_NAME having default11:36
bretonMurali: for some reason this variable is not passed to keystoneclient11:39
*** jerrygb has quit IRC11:39
bretonalso, the log is from tacker service, right? So maybe something is misconfigured in tacker itself?11:40
MuraliBreton: I am facing this error only when I ran "tacker vim-register --config-file config.yaml --description ""sdfsdfs"11:41
bretoni have no idea how tacker is configured11:41
MuraliHere config.yaml should include the contents of adminrc looks like11:41
MuraliLet me try to add the adminrc content to config.yaml and try11:42
*** itisha has quit IRC11:50
*** d0ugal has joined #openstack-keystone12:03
*** anush_ has joined #openstack-keystone12:04
*** anush_ has quit IRC12:06
*** spzala has joined #openstack-keystone12:07
*** jed56 has joined #openstack-keystone12:10
*** spzala has quit IRC12:12
*** rodrigods has joined #openstack-keystone12:12
*** markvoelker_ has quit IRC12:18
*** markvoelker has joined #openstack-keystone12:23
*** dikonoor has joined #openstack-keystone12:30
dikonoorhenrynash: Hi Henry. I have a query on fernet token. Who would be the right person to ask ?12:31
*** julim has joined #openstack-keystone12:31
dikonoorit's about ferner rotation. I have a cron job that runs every few hours (3 hours for eg.) that calls keystone-manage fernet_token and rotates the keys.12:32
dikonoorThe format of the cron job looks something like this >> 0 */3 * * * meaning run every 3 hours..12:33
dikonoorand I'd assume that most people might use something similar in their environments12:34
dikonoorbut the problem with the above is that the cron job does not actually run every 3 hours. It runs in multiples of 3..So if I enable the cronjob at 8am, it runs at 9am, 12pm, 3pm and so on..12:35
dikonoormeaning the period the fernet keys are going to be around is lesser than the period we want it to be (for eg. lesser than the token expiration period)12:36
*** jerrygb has joined #openstack-keystone12:36
dikonoorbknudson_: probably henrynash is away..anyone who can answer the above12:36
dikonoorso the question is how do ppl generally automatically rotate their fernet keys..If they use cron , then wouldn;t they run into the above (or do they use some other format?)12:38
*** jojden has quit IRC12:39
dikonoordolphm: anyone around..perhaps everyone is having breakfast. I'll wait..12:39
*** gordc has joined #openstack-keystone12:39
*** jerrygb has quit IRC12:41
*** pauloewerton has joined #openstack-keystone12:44
*** jsavak has joined #openstack-keystone12:56
*** TxGVNN has joined #openstack-keystone13:00
*** edmondsw has joined #openstack-keystone13:00
*** henrynash has quit IRC13:03
*** richm has joined #openstack-keystone13:04
*** spzala has joined #openstack-keystone13:08
*** spzala has quit IRC13:12
*** d0ugal has quit IRC13:14
*** sdake has joined #openstack-keystone13:21
*** spzala has joined #openstack-keystone13:31
*** jerrygb has joined #openstack-keystone13:37
*** code-R has joined #openstack-keystone13:37
*** code-R_ has joined #openstack-keystone13:41
*** jerrygb has quit IRC13:41
*** d0ugal has joined #openstack-keystone13:43
*** code-R has quit IRC13:43
*** roxanaghe has joined #openstack-keystone13:45
*** rdo has quit IRC13:48
*** roxanaghe has quit IRC13:49
*** itisha has joined #openstack-keystone13:49
*** rdo has joined #openstack-keystone13:50
*** spzala has quit IRC13:51
openstackgerritMerged openstack/keystone: Run AuthTokenTests against fernet and uuid  https://review.openstack.org/34381213:51
*** jerrygb has joined #openstack-keystone13:53
*** tonytan4ever has joined #openstack-keystone13:58
bretondikonoor: rotate less often13:59
bretondikonoor: once a day will be fine13:59
*** ddieterly has joined #openstack-keystone14:02
*** sdake_ has joined #openstack-keystone14:02
*** roxanaghe has joined #openstack-keystone14:02
bretondikonoor: also, for situation described (8am and then 9am, with token expiration equal to 1 hour) use more keys. It is configurable in keystone.conf14:03
*** sdake has quit IRC14:03
*** sdake has joined #openstack-keystone14:05
bretondikonoor: [fernet_tokens]max_active_keys14:05
dikonoorbreton: yeah..that makes sense14:06
*** roxanaghe has quit IRC14:06
dikonoorbreton: (I have been using token_expiration period / rotation frequewncy) + 2 to decide on the max_active_keys14:06
*** jaugustine has joined #openstack-keystone14:07
*** sdake_ has quit IRC14:07
*** ddieterly has quit IRC14:07
*** ddieterly has joined #openstack-keystone14:08
dikonoorbreton: increasing the key count by 1 should solve the problem associated with what I was talking14:08
*** ravelar159 has joined #openstack-keystone14:14
*** gagehugo has joined #openstack-keystone14:16
*** spzala has joined #openstack-keystone14:20
*** spzala_ has joined #openstack-keystone14:21
*** spzala has quit IRC14:24
*** phalmos has joined #openstack-keystone14:27
*** phalmos_ has joined #openstack-keystone14:28
openstackgerritDave Chen proposed openstack/keystone: Fix the errors in params in api-ref for V3 region  https://review.openstack.org/34325014:30
openstackgerritDave Chen proposed openstack/keystone: Fix the errors in params in api-ref for V3 user  https://review.openstack.org/34208914:30
*** julim has quit IRC14:32
*** phalmos has quit IRC14:32
*** dave-mccowan has joined #openstack-keystone14:33
*** d0ugal has quit IRC14:33
*** jsavak has quit IRC14:37
*** jhova has joined #openstack-keystone14:37
*** tonytan_brb has joined #openstack-keystone14:38
*** jistr is now known as jistr|mtg14:39
openstackgerritSwapnil Kulkarni (coolsvap) proposed openstack/keystone: [WIP] Testing latest u-c  https://review.openstack.org/31843514:39
*** d0ugal has joined #openstack-keystone14:40
*** tonytan4ever has quit IRC14:40
*** ravelar has joined #openstack-keystone14:41
*** slberger has joined #openstack-keystone14:43
*** jaugustine has quit IRC14:43
*** dikonoor has quit IRC14:44
*** anushkrishnamurt has joined #openstack-keystone14:47
*** jhova has quit IRC14:48
*** jsavak has joined #openstack-keystone14:48
*** anushkrishnamurt has quit IRC14:53
*** jed56 has quit IRC14:55
*** jaosorior has quit IRC14:57
*** amrith has left #openstack-keystone14:58
*** jaugustine has joined #openstack-keystone15:00
*** KevinE has joined #openstack-keystone15:01
*** jhova has joined #openstack-keystone15:02
*** haplo37_ has joined #openstack-keystone15:04
*** rcernin has quit IRC15:09
*** rcernin has joined #openstack-keystone15:12
*** chrisshattuck has joined #openstack-keystone15:15
*** belmoreira has quit IRC15:18
*** spzala_ has quit IRC15:21
*** rcernin has quit IRC15:22
*** tesseract- has quit IRC15:25
*** woodburn has joined #openstack-keystone15:26
*** sdake has quit IRC15:26
*** spzala has joined #openstack-keystone15:27
*** code-R_ has quit IRC15:28
*** code-R has joined #openstack-keystone15:28
*** dave-mccowan has quit IRC15:29
*** sdake has joined #openstack-keystone15:29
*** krotscheck is now known as krotscheck_dcm15:30
*** spzala has quit IRC15:31
*** lucas__ has joined #openstack-keystone15:38
*** spzala has joined #openstack-keystone15:38
*** woodburn has quit IRC15:39
*** mvk has quit IRC15:40
*** jhova has quit IRC15:41
*** jed56 has joined #openstack-keystone15:41
*** dave-mccowan has joined #openstack-keystone15:42
*** chrisshattuck has quit IRC15:43
*** spzala has quit IRC15:43
*** slberger has quit IRC15:46
*** daemontool has joined #openstack-keystone15:46
*** ravelar has quit IRC15:48
*** ravelar_159 has joined #openstack-keystone15:48
*** jistr|mtg is now known as jistr15:48
*** ravelar159 has quit IRC15:49
*** spzala has joined #openstack-keystone15:50
*** lamt has joined #openstack-keystone15:50
*** code-R_ has joined #openstack-keystone15:51
*** harlowja has quit IRC15:52
*** code-R has quit IRC15:54
*** spzala has quit IRC15:55
*** lucas__ has quit IRC15:57
*** slberger has joined #openstack-keystone15:59
*** ravelar_159 has quit IRC16:01
*** roxanaghe has joined #openstack-keystone16:02
*** ravelar159 has joined #openstack-keystone16:07
*** d0ugal has quit IRC16:07
*** BjoernT has joined #openstack-keystone16:08
*** spzala has joined #openstack-keystone16:09
*** roxanaghe has quit IRC16:11
openstackgerritMerged openstack/keystone: Handle Py35 fix of ast.node.col_offset bug  https://review.openstack.org/33795216:14
openstackgerritMerged openstack/keystone: Add Python 3.5 classifier  https://review.openstack.org/34390616:14
*** spzala has quit IRC16:14
openstackgerrithenry-nash proposed openstack/keystone: Fix up the api-ref request/response parameters for projects  https://review.openstack.org/34334016:16
*** roxanaghe has joined #openstack-keystone16:17
*** roxanaghe has quit IRC16:18
*** roxanaghe has joined #openstack-keystone16:18
*** david-lyle has joined #openstack-keystone16:19
lbragstadlink to the sprint etherpad: https://etherpad.openstack.org/p/keystone-newton-midcycle16:20
openstackgerrithenry-nash proposed openstack/keystone-specs: Support nested domains to provide additional project namespaces  https://review.openstack.org/33294016:21
*** ravelar159 has quit IRC16:21
*** spzala has joined #openstack-keystone16:21
openstackgerrithenry-nash proposed openstack/keystone-specs: Gate inherited assignments from parent  https://review.openstack.org/33436416:21
*** jamielennox|away is now known as jamielennox16:23
*** dikonoor has joined #openstack-keystone16:25
*** dikonoor has quit IRC16:25
*** spzala has quit IRC16:26
openstackgerritSamuel de Medeiros Queiroz proposed openstack/keystone: DO NOT MERGE: Remove cache from revoke subsystem  https://review.openstack.org/34387516:26
*** samueldmq has joined #openstack-keystone16:27
*** spzala has joined #openstack-keystone16:28
*** jsavak has quit IRC16:28
*** jsavak has joined #openstack-keystone16:29
*** ddieterly is now known as ddieterly[away]16:37
openstackgerritMikhail Nikolaenko proposed openstack/keystone: Retry revocation on MySQL deadlock  https://review.openstack.org/34492416:37
*** ayoung has joined #openstack-keystone16:38
*** ChanServ sets mode: +v ayoung16:38
ayoungjdennis1, at the Keystone Midcycle16:39
ayoungvideo has not been enabled...16:39
*** harlowja has joined #openstack-keystone16:40
*** ddieterly[away] is now known as ddieterly16:40
*** phalmos_ has quit IRC16:42
*** david-lyle has quit IRC16:42
*** daemontool_ has joined #openstack-keystone16:42
*** karthikb has joined #openstack-keystone16:43
*** code-R_ has quit IRC16:45
*** daemontool has quit IRC16:45
*** d0ugal has joined #openstack-keystone16:47
*** jsavak has quit IRC16:49
*** spzala has quit IRC16:50
*** edmondsw has quit IRC16:51
*** edmondsw has joined #openstack-keystone16:52
*** phalmos has joined #openstack-keystone16:52
*** daemontool_ has quit IRC16:53
*** ddieterly has quit IRC16:55
*** jsavak has joined #openstack-keystone17:03
*** ddieterly has joined #openstack-keystone17:03
*** code-R has joined #openstack-keystone17:04
*** sdake has quit IRC17:07
*** ddieterly has quit IRC17:08
*** ddieterly has joined #openstack-keystone17:10
*** sdake has joined #openstack-keystone17:11
*** ravelar159 has joined #openstack-keystone17:12
*** zzzeek has quit IRC17:13
*** sdake has quit IRC17:16
*** spzala has joined #openstack-keystone17:17
openstackgerritMonty Taylor proposed openstack/keystoneauth: Add tests for YamlJsonSerializer  https://review.openstack.org/34494317:17
*** spzala has quit IRC17:17
*** spzala has joined #openstack-keystone17:17
*** gagehugo has quit IRC17:17
*** ddieterly has quit IRC17:21
*** ravelar159 has quit IRC17:23
mordredstevemar: ^^ added tests :)17:23
*** pcaruana has quit IRC17:27
lbragstaddolphm example of a migration that fails until data is migrated - https://github.com/openstack/nova/blob/master/nova/db/sqlalchemy/migrate_repo/versions/330_enforce_mitaka_online_migrations.py#L1917:29
lbragstaddolphm  another example - https://github.com/openstack/nova/blob/master/nova/db/sqlalchemy/migrate_repo/versions/267_instance_uuid_non_nullable.py#L51-L5717:32
dolphmlbragstad: so they have validation before running migrations, that's cool17:33
dolphmlbragstad: but how are they exposing the --force-complete type behavior to operators?17:33
lbragstadtrying to find the nova-manage command that finishes the data migration17:33
lbragstaddolphm https://github.com/openstack/nova/blob/bae1d9cc21dd2dc9559b10cc1650045e6bcbeaf5/nova/cmd/manage.py#L81117:34
*** TxGVNN has quit IRC17:34
*** code-R has quit IRC17:36
*** dave-mccowan has quit IRC17:37
*** zzzeek has joined #openstack-keystone17:37
*** dan_nguyen has joined #openstack-keystone17:39
*** hoonetorg has quit IRC17:40
*** code-R has joined #openstack-keystone17:40
*** phalmos has quit IRC17:47
*** timcline has joined #openstack-keystone17:47
*** timcline_ has joined #openstack-keystone17:49
*** timcline has quit IRC17:52
*** gagehugo has joined #openstack-keystone17:52
*** hoonetorg has joined #openstack-keystone17:54
*** gordc has quit IRC17:56
*** dave-mccowan has joined #openstack-keystone17:57
*** michauds has joined #openstack-keystone18:01
notmorganhope everyone is enjoying their time at the midcycle so far18:03
samueldmqnotmorgan: o/18:04
*** tqtran has joined #openstack-keystone18:05
*** woodster_ has joined #openstack-keystone18:12
*** harlowja has quit IRC18:19
openstackgerritMerged openstack/keystonemiddleware: Add Python 3.5 classifier  https://review.openstack.org/34106618:20
*** gordc has joined #openstack-keystone18:22
*** tonytan_brb is now known as tonytan4ever18:22
*** phalmos has joined #openstack-keystone18:29
samueldmq#success Keystone now supports Python 3.5 (see https://review.openstack.org/341066)18:31
openstackstatussamueldmq: Added success to Success page18:31
*** dan_nguyen has quit IRC18:32
*** dan_nguyen has joined #openstack-keystone18:34
*** rakhmerov has quit IRC18:38
*** tsufiev has quit IRC18:39
*** ravelar159 has joined #openstack-keystone18:39
*** roxanaghe has quit IRC18:46
*** karthikb has quit IRC18:46
*** Gorian_ has joined #openstack-keystone18:47
*** Gorian_ has quit IRC18:47
*** Gorian_ has joined #openstack-keystone18:48
*** pcaruana has joined #openstack-keystone18:48
*** ravelar_159 has joined #openstack-keystone18:49
*** ravelar159 has quit IRC18:50
*** ravelar_159 has quit IRC18:51
*** Gorian_ has quit IRC18:51
*** Gorian_ has joined #openstack-keystone18:51
*** Gorian_ has quit IRC18:52
*** Gorian_ has joined #openstack-keystone18:52
*** pnavarro has quit IRC19:07
*** dan_nguyen has quit IRC19:07
*** phalmos has quit IRC19:07
*** amakarov has joined #openstack-keystone19:09
*** tqtran is now known as tqtran-afk19:10
*** roxanaghe has joined #openstack-keystone19:13
*** harlowja has joined #openstack-keystone19:19
*** ravelar159 has joined #openstack-keystone19:19
*** jsavak has quit IRC19:31
*** jsavak has joined #openstack-keystone19:32
*** harlowja has quit IRC19:36
*** haneef_ has quit IRC19:36
*** ravelar159 has quit IRC19:37
*** ravelar159 has joined #openstack-keystone19:38
*** sdake has joined #openstack-keystone19:38
*** rakhmerov has joined #openstack-keystone19:41
*** dan_nguyen has joined #openstack-keystone19:44
*** tsufiev has joined #openstack-keystone19:46
*** sdake has quit IRC19:47
*** raildo has quit IRC19:51
*** dan_nguyen has quit IRC19:59
*** anushkrishnamurt has joined #openstack-keystone20:00
*** dan_nguyen has joined #openstack-keystone20:00
*** jsavak has quit IRC20:01
*** jsavak has joined #openstack-keystone20:01
*** julim has joined #openstack-keystone20:02
openstackgerritGage Hugo proposed openstack/keystone: Add schema validation to create_user in v2  https://review.openstack.org/34502220:04
openstackgerritMerged openstack/oslo.policy: Adds debug logging for policy file validation  https://review.openstack.org/34144620:07
openstackgerritAlex Xu proposed openstack/oslo.policy: Add note about not all APIs support policy enforcement by user_id  https://review.openstack.org/32564520:11
openstackgerrithenry-nash proposed openstack/keystone: Fix up the api-ref request/response parameters for projects  https://review.openstack.org/34334020:12
*** spzala has quit IRC20:17
*** spzala has joined #openstack-keystone20:18
ayoungamakarov, do you wantus to try and set up audio?20:20
amakarovayoung: good idea, what are the options?20:20
ayoungamakarov, talking to our hosts here to find out.  Would a dial in number work for you?20:21
*** spzala has quit IRC20:22
*** spzala has joined #openstack-keystone20:22
amakarovayoung: not sure it's a good idea considering local providers prices )) Hangout maybe?20:22
jamielennoxamakarov: i've found in the past for me that hangouts dialer lets you call for free into the US20:25
jamielennoxi'm not sure where hangouts dialer is available though20:26
amakarovjamielennox: yes, hangout works fine20:26
jamielennoxhangouts dialer is a seperate thing that lets you make phone calls20:26
jamielennoxand it's free within US and for making US calls from outside20:27
ayoungamakarov, probably be webex20:30
amakarovayoung: ok20:30
openstackgerritMerged openstack/keystone: Cleanup trusts controller  https://review.openstack.org/34196920:33
*** ravelar159 has quit IRC20:35
openstackgerritMerged openstack/keystone: Remove get_user_id in trust controller  https://review.openstack.org/34197020:35
amakarovayoung, jamielennox: /me awaiting instructions :)20:43
*** jaugustine has quit IRC20:43
ayoungamakarov, we're waiting for an answer from hosts20:45
amakarovack20:45
*** dan_nguyen has quit IRC20:46
*** dan_nguyen has joined #openstack-keystone20:47
ayoungamakarov, not looking too good20:47
amakarovayoung: sent you an invitation to hangout - let's thy if it allow an outsider into Mirantis :P20:51
amakarov*try20:51
*** pcaruana has quit IRC20:53
ayoungamakarov, what account did you send it to?20:55
amakarovayoung@redhat.com20:55
ayoungamakarov, ah...ok, I have two accounts..let me check that20:55
*** code-R has quit IRC20:56
*** jerrygb has quit IRC20:56
*** anushkrishnamurt has quit IRC20:59
*** gyee has joined #openstack-keystone21:00
*** ChanServ sets mode: +v gyee21:00
*** jerrygb has joined #openstack-keystone21:02
ayoungamakarov, try adam.m.young@gmail.com21:03
*** jsavak has quit IRC21:05
*** jdennis has joined #openstack-keystone21:05
*** gordc has quit IRC21:05
*** jdennis1 has quit IRC21:08
*** arunkant has quit IRC21:13
*** ebalduf has joined #openstack-keystone21:16
samueldmqnotmorgan: ping - you around ?21:22
*** tqtran-afk is now known as tqtran21:22
*** gyee has quit IRC21:22
samueldmqnotmorgan: I am getting keystone gates working again with fernet enabled with https://review.openstack.org/#/c/343875/21:23
patchbotsamueldmq: patch 343875 - keystone - DO NOT MERGE: Remove cache from revoke subsystem21:23
*** pauloewerton has quit IRC21:26
*** gyee has joined #openstack-keystone21:26
*** ChanServ sets mode: +v gyee21:26
*** haplo37_ has quit IRC21:27
*** jerrygb has quit IRC21:32
*** timcline_ has quit IRC21:37
notmorgansamueldmq: hmm?21:40
samueldmqnotmorgan: so our caching for revoke seems to be broken21:40
notmorganwhat is broken.21:41
*** iurygregory_ has joined #openstack-keystone21:41
*** darrenc is now known as darrenc_afk21:41
samueldmqnotmorgan: maybe dogpile region.invalidate() is broken, OR it's our custom _RevokeEventHandler21:41
notmorganremoving the cache without documentation as to why is silly.21:41
samueldmqnotmorgan: I don't know what exactly, but by removing the revoke region (what my patch above did), keystone gates with fernet in devstack work agian21:42
notmorgani mean, honestly do what you need.21:42
notmorgani wont block -1 or -2 it21:42
openstackgerritMonty Taylor proposed openstack/keystoneauth: Add tests for YamlJsonSerializer  https://review.openstack.org/34494321:42
lbragstadthat kinda sounds like an issue with revocation cache invalidation?21:42
notmorganprobably21:42
mordrednotmorgan: ^^ amazingly enough, adding tests actually found a bug21:43
mordrednotmorgan: when is the last time _that_ happened21:43
notmorganmordred: hah this is why i like tests21:43
notmorganmordred: yesterday? it's not all that uncommon21:43
notmorgan:P21:43
samueldmqmordred: yay cool :)21:43
* notmorgan stops being snarky21:43
mordredsamueldmq: :)21:43
* mordred hands notmorgan a snark stick21:43
notmorganOOOOOOOOOH21:43
* notmorgan waves snark stick around widly, watchout someone's eye is going to be poked out21:44
*** markvoelker has quit IRC21:45
notmorganoh not supposed to be unicodE?21:45
* notmorgan scratches head.21:45
notmorganoh is that because it becomes a u'' ? mordred ^ with default=unicode?21:46
*** code-R has joined #openstack-keystone21:47
mordrednotmorgan: yah. but also, hten I read what default=unicode does, and I don't think we want it anyway21:47
notmorganok21:47
notmorganwfm21:47
openstackgerritJamie Lennox proposed openstack/keystone: Move audit initiator creation to request  https://review.openstack.org/34265821:50
*** josdotso has joined #openstack-keystone21:51
josdotsoQ: Is it possible for a common user (e.g. jdoe) to choose between two auth methods (e.g. MySQL traditional and SSO)?  In this way, a user could access the cloud on CLI without OIDC yet the same user could use OIDC at Horizon.21:52
josdotso(same user)21:52
josdotsoKeystone password becomes like an API key21:53
josdotso(external IDP)21:53
notmorganjosdotso: as an FYI most of the keystone fokls are at the midcycle right now, so you might have a delayed response.21:54
josdotsoThanks notmorgan.  That's helpful.21:54
notmorganjosdotso: i'd ask stevemar and dolphm about this, they will be able to fill you in on the modern-state-of-federation-and-local-user-y-things21:54
openstackgerritGage Hugo proposed openstack/keystone: Add schema validation to create/update user in v2  https://review.openstack.org/34502221:54
openstackgerritLance Bragstad proposed openstack/keystone: Use freezegun to increment clock in test_v3_assignment  https://review.openstack.org/34386021:55
josdotsoOk cool.  I'll take a note to ask them in email if it doesn't get answered here.  Thanks!21:55
openstackgerritLance Bragstad proposed openstack/keystone: Refactor TestAuthExternalDomain to not inherit tests  https://review.openstack.org/34388621:55
openstackgerritLance Bragstad proposed openstack/keystone: Don't run TokenCacheInvalidation with Fernet  https://review.openstack.org/34393221:56
openstackgerritLance Bragstad proposed openstack/keystone: Run AuthWithToken against all token providers  https://review.openstack.org/34393521:56
*** code-R_ has joined #openstack-keystone21:57
*** code-R has quit IRC22:00
18VAA56T6stevemar: want to push this in (before something else chanegs underneath it again): https://review.openstack.org/#/c/343340/22:06
patchbot18VAA56T6: patch 343340 - keystone - Fix up the api-ref request/response parameters for...22:06
*** mvk has joined #openstack-keystone22:09
*** harlowja has joined #openstack-keystone22:11
*** harlowja has quit IRC22:11
dolphmjosdotso: today - not through the API, but part of our roadmap for the shadow users effort in mitaka & newton is to add "account linking"22:15
josdotsodolphm: Awesome.  Thanks!  yeah I found the wiki page on shadow users, so cool22:16
dolphmjosdotso: the reality is that you could modify the local user ID for either your federated_user or your local_user to point to the same (shadow) user ID, and you'll have two authentication methods for the same user. we just need to expose that process to the API.22:16
dolphmcc- rderose22:16
josdotsodolphm: So today it's possible via MySQL calls, but not using the API?22:17
openstackgerritLance Bragstad proposed openstack/keystone: refactor: inherit AuthWithRemoteUser for other providers  https://review.openstack.org/34507522:17
dolphmjosdotso: should be!22:17
josdotsodophm: Excellent.  Thanks again22:18
rderosejosdotso: what's the link for the wiki on shadow users?22:18
dolphmjosdotso: we designed the SQL schema to accomidate the use case. if there are any caveats to doing it "manually" today, rderose would know22:18
josdotsohttps://specs.openstack.org/openstack/keystone-specs/specs/mitaka/shadow-users.html  (okay so not wiki)22:18
rderosejosdotso: if you do account linking via sql, it should work22:18
rderosejosdotso: ah, the spec22:19
josdotsorderose: Nice22:19
josdotsoIf backing system is LDAP, could the account linking be done there?22:19
josdotsovia LDAP protocol22:20
rderosejosdotso: shadowing ldap is being done in Newton22:20
rderosejosdotso: there is a new nonlocal_user table that will be used to map LDAP22:20
josdotsoOkay, so it's users in MySQL + SSO == shadow possible today.... and users in LDAP + SSO == shadow possible later (in Newton)?22:21
rderosejosdotso: correct22:21
josdotsoPerfect.. Thansk22:21
josdotso*Thanks22:21
rderosejosdotso: np22:21
*** darrenc_afk is now known as darrenc22:24
*** ebalduf has quit IRC22:30
*** josdotso has quit IRC22:31
*** slberger has left #openstack-keystone22:32
*** jerrygb has joined #openstack-keystone22:33
stevemar18VAA56T6: you need a more obvious username :P22:33
18VAA56T6I know…us brits are now undercover22:34
18VAA56T6.22:34
18VAA56T6damn bouncer22:35
stevemarthanks dolphm for answering ^22:35
stevemar18VAA56T6: oh nash?22:35
18VAA56T6guilty22:36
*** amakarov has quit IRC22:37
*** KevinE has quit IRC22:38
*** jerrygb has quit IRC22:39
openstackgerritDolph Mathews proposed openstack/keystone: Increase the default token lifespan  https://review.openstack.org/34508322:44
*** markvoelker has joined #openstack-keystone22:45
*** itisha has quit IRC22:50
*** markvoelker has quit IRC22:50
*** spzala has quit IRC22:51
*** markvoelker has joined #openstack-keystone22:51
*** spzala has joined #openstack-keystone22:51
*** catintheroof has joined #openstack-keystone22:52
*** spzala has quit IRC22:56
*** harlowja has joined #openstack-keystone23:00
*** harlowja has quit IRC23:03
*** michauds has quit IRC23:03
openstackgerritLance Bragstad proposed openstack/keystone: refactor: make TestAuthKerberos test pki/pkiz/uuid  https://review.openstack.org/34508923:05
openstackgerritLance Bragstad proposed openstack/keystone: Only run TestAuthExternalDefaultDomain uuid/pki/pkiz  https://review.openstack.org/34509023:05
openstackgerritLance Bragstad proposed openstack/keystone: refactor: make TestAuthExternalDefaultDomain test uuid/pki/pkiz  https://review.openstack.org/34509023:06
*** harlowja has joined #openstack-keystone23:07
*** harlowja has quit IRC23:12
openstackgerritDolph Mathews proposed openstack/keystone: Return expired tokens within a grace period  https://review.openstack.org/34509223:15
*** BjoernT has quit IRC23:16
openstackgerritMerged openstack/keystonemiddleware: Remove the _is_v2 and _is_v3 helpers  https://review.openstack.org/33868623:18
dstanekls23:19
*** timcline has joined #openstack-keystone23:20
samueldmqdstanek: api-ref CONTRIBUTING.rst examples keystone keystone_tempest_plugin other-requirements.txt releasenotes setup.py tox.ini23:22
*** arunkant has joined #openstack-keystone23:23
*** timcline has quit IRC23:24
stevemarsamueldmq: lol23:28
openstackgerritMerged openstack/keystoneauth: oidc: add missing 'OidcAccessToken' to __all__  https://review.openstack.org/34462823:29
*** Gorian_ has quit IRC23:33
openstackgerritLance Bragstad proposed openstack/keystone: refactor: make TestFetchRevocationList test uuid  https://review.openstack.org/34509923:34
*** roxanaghe has quit IRC23:35
*** jerrygb has joined #openstack-keystone23:35
*** ayoung has quit IRC23:39
*** jerrygb has quit IRC23:41
18VAA56T6cc23:44
18VAA56T6test23:47
18VAA56T6hello23:49
18VAA56T6test23:49
breton18VAA56T6: test passed23:49
18VAA56T6tahnks23:49
stevemar^_^23:49
stevemar-_-23:50
bretonhow's the weather in San Jose?23:50
stevemarbreton: chilly at night23:51
openstackgerritGage Hugo proposed openstack/keystone: Add schema validation to create/update user  https://review.openstack.org/34502223:53
openstackgerritLance Bragstad proposed openstack/keystone: Use freezegun in OSRevokeTests  https://review.openstack.org/34510423:57

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!