*** spzala has quit IRC | 00:04 | |
openstackgerrit | Merged openstack/keystoneauth: Correctly report available for ADFS plugin https://review.openstack.org/349224 | 00:04 |
---|---|---|
*** r-daneel has quit IRC | 00:11 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone: Skip middleware request processing for admin token https://review.openstack.org/344496 | 00:14 |
*** spzala has joined #openstack-keystone | 00:17 | |
*** adriant has joined #openstack-keystone | 00:18 | |
*** doug-fish has quit IRC | 00:29 | |
stevemar | notmorgan: i can only imagine how dhellmann must feel when he still gets oslo questions :) | 00:35 |
stevemar | notmorgan: privilege of being ptl i suppose :P | 00:35 |
stevemar | you did too good of a job :P | 00:35 |
*** ravelar159 has quit IRC | 00:37 | |
*** michauds has quit IRC | 00:39 | |
*** jamielennox is now known as jamielennox|away | 00:49 | |
*** code-R has joined #openstack-keystone | 00:58 | |
*** code-R_ has joined #openstack-keystone | 01:00 | |
*** gyee has quit IRC | 01:02 | |
*** jamielennox|away is now known as jamielennox | 01:03 | |
*** code-R has quit IRC | 01:03 | |
*** spzala has quit IRC | 01:05 | |
*** spzala has joined #openstack-keystone | 01:07 | |
*** KevinE has quit IRC | 01:09 | |
*** KevinE has joined #openstack-keystone | 01:10 | |
*** KevinE has joined #openstack-keystone | 01:10 | |
*** spzala has quit IRC | 01:11 | |
*** sdake has quit IRC | 01:14 | |
*** KevinE has quit IRC | 01:15 | |
*** spedione|AWAY is now known as spedione | 01:23 | |
*** iurygregory_ has joined #openstack-keystone | 01:28 | |
*** spedione is now known as spedione|AWAY | 01:30 | |
*** EinstCrazy has joined #openstack-keystone | 01:31 | |
*** NanKe has joined #openstack-keystone | 01:32 | |
*** jhesketh has quit IRC | 01:51 | |
*** jhesketh has joined #openstack-keystone | 01:51 | |
*** EinstCrazy has quit IRC | 01:53 | |
*** davechen has joined #openstack-keystone | 01:55 | |
openstackgerrit | Merged openstack/keystone: Added postgresql libs to developer docs https://review.openstack.org/349688 | 01:57 |
*** EinstCrazy has joined #openstack-keystone | 01:58 | |
*** diazjf has joined #openstack-keystone | 02:13 | |
stevemar | jamielennox: last one i'm gonna bug you about: https://bugs.launchpad.net/keystonemiddleware/+bug/1605355 | 02:15 |
openstack | Launchpad bug 1605355 in keystonemiddleware "TypeError: string indices must be integers" [Undecided,New] | 02:15 |
stevemar | then i'm done | 02:15 |
stevemar | i've been looking at bugs for about 10 hours | 02:15 |
jamielennox | stevemar: oh, i have that open to look futher into, i havent seen it elsewhere or otherwise reproduced it | 02:16 |
jamielennox | the traceback doesn't really tell me where things are coming from | 02:16 |
jamielennox | i mean it seems like it could be a problme | 02:18 |
jamielennox | but off the top of my head i've no idea why | 02:18 |
jamielennox | brb | 02:18 |
*** markvoelker has joined #openstack-keystone | 02:25 | |
*** jamielennox is now known as jamielennox|away | 02:28 | |
*** amitkqed has quit IRC | 02:30 | |
*** EinstCrazy has quit IRC | 02:30 | |
*** markvoelker_ has joined #openstack-keystone | 02:30 | |
*** markvoelker has quit IRC | 02:30 | |
*** amitkqed has joined #openstack-keystone | 02:30 | |
*** EinstCrazy has joined #openstack-keystone | 02:30 | |
*** lamt_ has quit IRC | 02:31 | |
*** spzala has joined #openstack-keystone | 02:37 | |
stevemar | i feel breton will make another remark about me spamming his inbox :P | 02:40 |
*** jamielennox|away is now known as jamielennox | 02:42 | |
*** spzala has quit IRC | 02:43 | |
*** spzala has joined #openstack-keystone | 03:02 | |
*** dikonoor has joined #openstack-keystone | 03:06 | |
*** spzala has quit IRC | 03:07 | |
*** iurygregory_ has quit IRC | 03:19 | |
*** diazjf has quit IRC | 03:33 | |
*** dkehn_ has quit IRC | 03:46 | |
*** bill_az has quit IRC | 03:46 | |
*** dave-mccowan has quit IRC | 03:52 | |
*** EinstCrazy has quit IRC | 03:53 | |
openstackgerrit | Merged openstack/keystone: Add schema validation to create service in v2 https://review.openstack.org/346962 | 03:56 |
*** dkehn_ has joined #openstack-keystone | 04:00 | |
*** dan_nguyen has joined #openstack-keystone | 04:00 | |
*** davechen has quit IRC | 04:13 | |
*** markvoelker_ has quit IRC | 04:15 | |
*** julim has quit IRC | 04:19 | |
*** itisha has quit IRC | 04:20 | |
*** KevinE has joined #openstack-keystone | 04:29 | |
*** gagehugo_ has quit IRC | 04:34 | |
*** crinkle has quit IRC | 04:35 | |
*** crinkle has joined #openstack-keystone | 04:35 | |
*** links has joined #openstack-keystone | 04:36 | |
*** roxanagh_ has joined #openstack-keystone | 04:45 | |
*** EinstCrazy has joined #openstack-keystone | 04:49 | |
*** dan_nguyen has quit IRC | 04:54 | |
*** spzala has joined #openstack-keystone | 05:02 | |
*** spzala has quit IRC | 05:07 | |
*** markvoelker has joined #openstack-keystone | 05:10 | |
*** code-R has joined #openstack-keystone | 05:16 | |
*** code-R_ has quit IRC | 05:16 | |
*** markvoelker has quit IRC | 05:16 | |
*** jaosorior has joined #openstack-keystone | 05:19 | |
*** code-R_ has joined #openstack-keystone | 05:21 | |
*** code-R has quit IRC | 05:25 | |
*** barclaac has quit IRC | 05:28 | |
*** barclaac has joined #openstack-keystone | 05:28 | |
*** richm has quit IRC | 05:40 | |
*** roxanagh_ has quit IRC | 05:42 | |
*** zouyapeng has quit IRC | 05:42 | |
*** davechen has joined #openstack-keystone | 05:51 | |
*** maestropandy has joined #openstack-keystone | 05:53 | |
*** adriant has quit IRC | 05:58 | |
*** spzala has joined #openstack-keystone | 06:03 | |
*** EinstCrazy has quit IRC | 06:06 | |
*** markvoelker has joined #openstack-keystone | 06:06 | |
*** spzala has quit IRC | 06:07 | |
*** code-R_ has quit IRC | 06:09 | |
*** EinstCrazy has joined #openstack-keystone | 06:13 | |
*** markvoelker has quit IRC | 06:13 | |
*** code-R has joined #openstack-keystone | 06:16 | |
*** code-R_ has joined #openstack-keystone | 06:29 | |
*** code-R has quit IRC | 06:32 | |
*** EinstCrazy has quit IRC | 06:35 | |
*** EinstCrazy has joined #openstack-keystone | 06:38 | |
*** roxanagh_ has joined #openstack-keystone | 06:39 | |
*** NanKe has quit IRC | 06:39 | |
breton | indeed | 06:39 |
*** tesseract- has joined #openstack-keystone | 06:43 | |
*** roxanagh_ has quit IRC | 06:44 | |
*** KevinE has quit IRC | 06:46 | |
*** code-R has joined #openstack-keystone | 06:47 | |
*** code-R_ has quit IRC | 06:47 | |
*** belmoreira has joined #openstack-keystone | 06:50 | |
*** EinstCrazy has quit IRC | 06:56 | |
openstackgerrit | Alvaro Lopez Garcia proposed openstack/keystoneauth: Improve authentication plugins documentation https://review.openstack.org/349423 | 06:58 |
*** EinstCrazy has joined #openstack-keystone | 07:00 | |
*** markvoelker has joined #openstack-keystone | 07:02 | |
*** spzala has joined #openstack-keystone | 07:04 | |
*** jpena|off is now known as jpena | 07:07 | |
*** markvoelker has quit IRC | 07:08 | |
*** spzala has quit IRC | 07:08 | |
*** EinstCrazy has quit IRC | 07:13 | |
*** EinstCrazy has joined #openstack-keystone | 07:16 | |
*** EinstCrazy has quit IRC | 07:30 | |
*** EinstCrazy has joined #openstack-keystone | 07:32 | |
*** EinstCrazy has quit IRC | 07:34 | |
*** EinstCrazy has joined #openstack-keystone | 07:35 | |
*** pnavarro has joined #openstack-keystone | 07:37 | |
*** EinstCrazy has quit IRC | 07:47 | |
*** EinstCrazy has joined #openstack-keystone | 07:49 | |
*** markvoelker has joined #openstack-keystone | 07:58 | |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:00 | |
*** markvoelker has quit IRC | 08:04 | |
*** spzala has joined #openstack-keystone | 08:04 | |
*** tangchen_ has quit IRC | 08:08 | |
*** spzala has quit IRC | 08:09 | |
*** aastha has quit IRC | 08:09 | |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 08:10 |
*** jamielennox is now known as jamielennox|away | 08:10 | |
*** jaosorior has quit IRC | 08:11 | |
*** jaosorior has joined #openstack-keystone | 08:12 | |
*** marekd2 has joined #openstack-keystone | 08:14 | |
*** nk2527 has quit IRC | 08:17 | |
*** mfisch has quit IRC | 08:17 | |
*** jaosorior_ has joined #openstack-keystone | 08:18 | |
*** sileht has quit IRC | 08:19 | |
*** clenimar has quit IRC | 08:19 | |
*** DuncanT has quit IRC | 08:19 | |
*** DuncanT has joined #openstack-keystone | 08:20 | |
*** tangchen_ has joined #openstack-keystone | 08:20 | |
*** jaosorior has quit IRC | 08:21 | |
*** sileht has joined #openstack-keystone | 08:21 | |
*** fungi has quit IRC | 08:22 | |
*** mfisch has joined #openstack-keystone | 08:22 | |
*** mfisch has quit IRC | 08:22 | |
*** mfisch has joined #openstack-keystone | 08:22 | |
*** clenimar has joined #openstack-keystone | 08:23 | |
*** TxGVNN has joined #openstack-keystone | 08:23 | |
*** fungi has joined #openstack-keystone | 08:24 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add the migration phase status table https://review.openstack.org/349703 | 08:24 |
*** links has quit IRC | 08:26 | |
*** aloga has quit IRC | 08:28 | |
*** code-R has quit IRC | 08:28 | |
*** aloga has joined #openstack-keystone | 08:28 | |
*** danpawlik has joined #openstack-keystone | 08:29 | |
*** nk2527 has joined #openstack-keystone | 08:30 | |
*** links has joined #openstack-keystone | 08:41 | |
*** daemontool_ has joined #openstack-keystone | 08:51 | |
*** markvoelker has joined #openstack-keystone | 08:54 | |
*** daemontool__ has quit IRC | 08:54 | |
*** EinstCrazy has quit IRC | 08:59 | |
*** markvoelker has quit IRC | 09:00 | |
*** EinstCrazy has joined #openstack-keystone | 09:02 | |
*** EinstCrazy has quit IRC | 09:03 | |
*** EinstCrazy has joined #openstack-keystone | 09:03 | |
*** EinstCrazy has quit IRC | 09:04 | |
*** EinstCrazy has joined #openstack-keystone | 09:04 | |
*** EinstCra_ has joined #openstack-keystone | 09:05 | |
*** EinstCra_ has quit IRC | 09:05 | |
*** spzala has joined #openstack-keystone | 09:05 | |
*** EinstCrazy has quit IRC | 09:05 | |
*** EinstCra_ has joined #openstack-keystone | 09:06 | |
*** EinstCra_ has quit IRC | 09:07 | |
*** EinstCr__ has joined #openstack-keystone | 09:09 | |
*** spzala has quit IRC | 09:10 | |
*** EinstCr__ has quit IRC | 09:10 | |
*** EinstCrazy has joined #openstack-keystone | 09:11 | |
*** davechen has left #openstack-keystone | 09:11 | |
*** EinstCrazy has quit IRC | 09:12 | |
*** EinstCrazy has joined #openstack-keystone | 09:12 | |
*** EinstCrazy has quit IRC | 09:13 | |
*** EinstCra_ has joined #openstack-keystone | 09:15 | |
*** EinstCr__ has joined #openstack-keystone | 09:16 | |
*** EinstCr__ has quit IRC | 09:16 | |
*** jaosorior_ is now known as jaosorior | 09:16 | |
*** EinstCrazy has joined #openstack-keystone | 09:16 | |
*** EinstCra_ has quit IRC | 09:17 | |
*** EinstCra_ has joined #openstack-keystone | 09:17 | |
*** EinstCrazy has quit IRC | 09:17 | |
*** EinstCra_ has quit IRC | 09:17 | |
*** EinstCrazy has joined #openstack-keystone | 09:18 | |
*** EinstCrazy has quit IRC | 09:19 | |
*** EinstCrazy has joined #openstack-keystone | 09:19 | |
*** EinstCrazy has quit IRC | 09:19 | |
*** EinstCrazy has joined #openstack-keystone | 09:20 | |
*** EinstCrazy has quit IRC | 09:21 | |
*** EinstCrazy has joined #openstack-keystone | 09:21 | |
*** pnavarro has quit IRC | 09:21 | |
*** mvk has quit IRC | 09:21 | |
*** EinstCrazy has quit IRC | 09:21 | |
*** EinstCrazy has joined #openstack-keystone | 09:23 | |
*** EinstCrazy has quit IRC | 09:23 | |
*** EinstCrazy has joined #openstack-keystone | 09:24 | |
*** EinstCrazy has quit IRC | 09:24 | |
*** EinstCrazy has joined #openstack-keystone | 09:26 | |
*** EinstCrazy has quit IRC | 09:26 | |
*** EinstCrazy has joined #openstack-keystone | 09:27 | |
*** EinstCrazy has quit IRC | 09:27 | |
*** EinstCrazy has joined #openstack-keystone | 09:27 | |
*** links has quit IRC | 09:28 | |
*** TxGVNN has quit IRC | 09:29 | |
*** EinstCra_ has joined #openstack-keystone | 09:30 | |
*** EinstCra_ has quit IRC | 09:32 | |
*** EinstCrazy has quit IRC | 09:32 | |
*** EinstCrazy has joined #openstack-keystone | 09:33 | |
*** EinstCrazy has quit IRC | 09:33 | |
*** EinstCrazy has joined #openstack-keystone | 09:36 | |
*** links has joined #openstack-keystone | 09:40 | |
*** mvk has joined #openstack-keystone | 09:48 | |
*** markvoelker has joined #openstack-keystone | 09:49 | |
*** markvoelker has quit IRC | 09:56 | |
*** EinstCrazy has quit IRC | 09:58 | |
*** EinstCrazy has joined #openstack-keystone | 10:00 | |
*** spzala has joined #openstack-keystone | 10:06 | |
*** richm has joined #openstack-keystone | 10:08 | |
*** spzala has quit IRC | 10:11 | |
*** EinstCrazy has quit IRC | 10:25 | |
*** EinstCrazy has joined #openstack-keystone | 10:25 | |
*** EinstCrazy has quit IRC | 10:30 | |
*** ntpttr- has quit IRC | 10:30 | |
*** EinstCrazy has joined #openstack-keystone | 10:32 | |
*** rodrigods has quit IRC | 10:36 | |
*** rodrigods has joined #openstack-keystone | 10:36 | |
*** ntpttr- has joined #openstack-keystone | 10:39 | |
*** tangchen_ has quit IRC | 10:42 | |
*** EinstCrazy has quit IRC | 10:44 | |
*** tangchen_ has joined #openstack-keystone | 10:44 | |
*** markvoelker has joined #openstack-keystone | 10:45 | |
*** EinstCrazy has joined #openstack-keystone | 10:45 | |
*** EinstCrazy has quit IRC | 10:45 | |
*** EinstCra_ has joined #openstack-keystone | 10:47 | |
*** EinstCra_ has quit IRC | 10:48 | |
*** EinstCrazy has joined #openstack-keystone | 10:49 | |
*** EinstCrazy has quit IRC | 10:49 | |
*** markvoelker has quit IRC | 10:51 | |
*** EinstCrazy has joined #openstack-keystone | 10:52 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Remove unused config sample https://review.openstack.org/349933 | 10:53 |
openstackgerrit | henry-nash proposed openstack/keystone: WIP Add support for rolling upgrades to keystone-manage https://review.openstack.org/349716 | 11:00 |
*** EinstCrazy has quit IRC | 11:03 | |
*** EinstCrazy has joined #openstack-keystone | 11:03 | |
*** samueldmq has joined #openstack-keystone | 11:05 | |
*** ChanServ sets mode: +v samueldmq | 11:05 | |
samueldmq | morning | 11:05 |
*** spzala has joined #openstack-keystone | 11:07 | |
*** EinstCrazy has quit IRC | 11:09 | |
*** EinstCrazy has joined #openstack-keystone | 11:09 | |
*** spzala has quit IRC | 11:11 | |
openstackgerrit | henry-nash proposed openstack/keystone: WIP - Add contract migrations to keystone-manage https://review.openstack.org/349939 | 11:19 |
*** EinstCrazy has quit IRC | 11:26 | |
*** sdake has joined #openstack-keystone | 11:27 | |
*** sdake_ has joined #openstack-keystone | 11:30 | |
openstackgerrit | Li Wei proposed openstack/oslo.policy: Delete H803 in flake8 ignore https://review.openstack.org/349943 | 11:31 |
*** sdake has quit IRC | 11:31 | |
openstackgerrit | Li Wei proposed openstack/oslo.policy: Delete H803 in flake8 ignore https://review.openstack.org/349943 | 11:35 |
*** markvoelker has joined #openstack-keystone | 11:39 | |
*** markvoelker_ has joined #openstack-keystone | 11:44 | |
*** markvoelker has quit IRC | 11:44 | |
*** Jehane has joined #openstack-keystone | 11:46 | |
Jehane | hi | 11:47 |
Jehane | I have some trouble with setting up ldap authentication with keystone | 11:50 |
Jehane | either my "local authentication" is working (admin account et services users) or my ldap authentication is working (but no openstack admin or services ) | 11:50 |
Jehane | is there a way to have both working at the same time ? | 11:51 |
*** sdake_ is now known as sdake | 11:51 | |
*** jpena is now known as jpena|lunch | 12:04 | |
rodrigods | Jehane, yes, by using domain specific backends: http://docs.openstack.org/developer/keystone/configuration.html#domain-specific-drivers | 12:12 |
Jehane | rodrigods: thanks | 12:12 |
Jehane | an other question, will it do a lot of ldap query or is it reasonable ? it's to know if I need to setup a dedicated slave | 12:14 |
*** gordc has joined #openstack-keystone | 12:19 | |
dstanek | Jehane: i think that is subjective. you should probably do a little testing and see what you think | 12:30 |
*** pauloewerton has joined #openstack-keystone | 12:33 | |
*** ccard has joined #openstack-keystone | 12:36 | |
*** samueldmq has quit IRC | 12:38 | |
openstackgerrit | lilintan proposed openstack/keystoneauth: Don't include openstack/common in flake8 exclude list https://review.openstack.org/349978 | 12:39 |
*** adriant has joined #openstack-keystone | 12:44 | |
lbragstad | o/ | 12:44 |
Jehane | dstanek: ok I will do that | 12:47 |
*** adriant is now known as adriant_is_away | 12:47 | |
*** links has quit IRC | 12:48 | |
*** ddieterly has joined #openstack-keystone | 12:49 | |
*** ddieterly has quit IRC | 12:51 | |
*** samueldmq has joined #openstack-keystone | 12:53 | |
*** ChanServ sets mode: +v samueldmq | 12:53 | |
*** maestropandy has left #openstack-keystone | 12:53 | |
openstackgerrit | lilintan proposed openstack/keystone: Don't include openstack/common in flake8 exclude list https://review.openstack.org/349988 | 12:58 |
*** jpena|lunch is now known as jpena | 13:00 | |
*** hwcomcn has joined #openstack-keystone | 13:01 | |
*** hwcomcn has quit IRC | 13:01 | |
*** jsavak has joined #openstack-keystone | 13:01 | |
*** hwcomcn has joined #openstack-keystone | 13:02 | |
*** Raildo has joined #openstack-keystone | 13:02 | |
*** spzala has joined #openstack-keystone | 13:09 | |
*** clenimar has quit IRC | 13:09 | |
*** ericksonsantos has quit IRC | 13:09 | |
*** pauloewerton has quit IRC | 13:09 | |
*** iurygregory has quit IRC | 13:09 | |
*** samueldmq has quit IRC | 13:10 | |
*** clenimar has joined #openstack-keystone | 13:10 | |
*** iurygregory has joined #openstack-keystone | 13:11 | |
*** ericksonsantos has joined #openstack-keystone | 13:12 | |
*** pauloewerton has joined #openstack-keystone | 13:12 | |
*** spzala has quit IRC | 13:13 | |
*** spzala has joined #openstack-keystone | 13:15 | |
*** links has joined #openstack-keystone | 13:21 | |
*** markvoelker_ has quit IRC | 13:23 | |
*** julim has joined #openstack-keystone | 13:26 | |
*** julim has quit IRC | 13:26 | |
*** julim has joined #openstack-keystone | 13:33 | |
*** ddieterly has joined #openstack-keystone | 13:36 | |
*** narengan has joined #openstack-keystone | 13:39 | |
*** thiagolib has joined #openstack-keystone | 13:40 | |
*** itisha has joined #openstack-keystone | 13:46 | |
*** code-R has joined #openstack-keystone | 13:49 | |
*** code-R_ has joined #openstack-keystone | 13:52 | |
*** thumpba has quit IRC | 13:52 | |
*** adrian_otto has joined #openstack-keystone | 13:53 | |
*** thumpba has joined #openstack-keystone | 13:53 | |
*** code-R has quit IRC | 13:54 | |
*** spedione|AWAY is now known as spedione | 13:56 | |
*** thumpba has quit IRC | 13:57 | |
*** code-R_ has quit IRC | 14:00 | |
*** code-R has joined #openstack-keystone | 14:01 | |
*** code-R has quit IRC | 14:02 | |
*** code-R has joined #openstack-keystone | 14:02 | |
*** markvoelker has joined #openstack-keystone | 14:02 | |
*** bill_az has joined #openstack-keystone | 14:02 | |
*** adrian_otto has quit IRC | 14:04 | |
*** ametts has joined #openstack-keystone | 14:04 | |
*** spedione is now known as spedione|AWAY | 14:06 | |
*** spedione|AWAY is now known as spedione | 14:11 | |
*** links has quit IRC | 14:12 | |
*** edmondsw has joined #openstack-keystone | 14:13 | |
*** dave-mccowan has joined #openstack-keystone | 14:14 | |
*** tonytan4ever has joined #openstack-keystone | 14:17 | |
*** richm has quit IRC | 14:19 | |
*** samueldmq has joined #openstack-keystone | 14:23 | |
*** ChanServ sets mode: +v samueldmq | 14:23 | |
openstackgerrit | Merged openstack/keystone: Add token feature support matrix to documentation https://review.openstack.org/316118 | 14:27 |
*** jsavak has quit IRC | 14:32 | |
dstanek | henrynash: you around? | 14:34 |
stevemar | lbragstad: thanks for hitting up sdagues mailing list request | 14:37 |
lbragstad | stevemar no worries | 14:38 |
lbragstad | stevemar I need to take a step back from the revocation/caching stuff for a half a day (i've been fried on it all weekend) | 14:38 |
lbragstad | stevemar I'm going to go back and review rderose's PCI reviews, then I should be able to get around to sdague's email | 14:39 |
*** ravelar159 has joined #openstack-keystone | 14:40 | |
Jehane | I got some questions about domain creation. I already have an admin user and various services users (created by packstack) | 14:41 |
Jehane | what happen to them when I create the default domain | 14:41 |
Jehane | ? | 14:41 |
Jehane | Are they put into it automatically ? | 14:41 |
*** adriant_is_away has quit IRC | 14:42 | |
rderose | lbragstad: :) | 14:43 |
rderose | lbragstad: hold off on lockout, doing some more testing on that one | 14:43 |
rodrigods | Jehane, the default domain is created automatically, you don't need to create it ( even using packstack). As such, all those users are in the default domain | 14:44 |
Jehane | rodrigods: ok, thanks | 14:45 |
Jehane | so I just need to switch to the v3 api and add my custom domain to user multi-domain auth ? | 14:45 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Use %()d for integer substitution https://review.openstack.org/350069 | 14:46 |
lbragstad | rderose https://review.openstack.org/#/c/328339/43 looks good to me - I pushed ^ to address dstanek's comment | 14:46 |
patchbot | lbragstad: patch 328339 - keystone - PCI-DSS Password history requirements | 14:46 |
*** slberger has joined #openstack-keystone | 14:46 | |
*** ddieterly is now known as ddieterly[away] | 14:47 | |
bknudson | something kind of strange -- identity.sql.Identity authenticate() calls self._get_user to get the user. | 14:50 |
bknudson | but of course, the driver doesn't have any caching for the user info | 14:51 |
*** hwcomcn has quit IRC | 14:51 | |
bknudson | because all the caching is done at the manager level. | 14:51 |
bknudson | and I'm guessing we can't put MEMOIZE on identity manager authenticate() | 14:52 |
bknudson | so should be able to improve authenticate performance by getting the user from the cache. | 14:52 |
*** michauds has joined #openstack-keystone | 14:53 | |
*** ddieterly[away] is now known as ddieterly | 14:53 | |
*** jsavak has joined #openstack-keystone | 14:54 | |
*** diazjf has joined #openstack-keystone | 14:54 | |
*** ddieterly has quit IRC | 14:55 | |
*** samueldmq has quit IRC | 14:57 | |
bknudson | has anybody used any profiling tools against keystone? | 14:59 |
*** ddieterly has joined #openstack-keystone | 15:00 | |
*** jsavak has quit IRC | 15:04 | |
*** jsavak has joined #openstack-keystone | 15:05 | |
*** richm has joined #openstack-keystone | 15:05 | |
*** samueldmq has joined #openstack-keystone | 15:09 | |
*** ChanServ sets mode: +v samueldmq | 15:09 | |
*** nkinder has quit IRC | 15:16 | |
*** nkinder has joined #openstack-keystone | 15:17 | |
*** belmoreira has quit IRC | 15:21 | |
openstackgerrit | Merged openstack/oslo.policy: Delete H803 in flake8 ignore https://review.openstack.org/349943 | 15:24 |
*** code-R has quit IRC | 15:26 | |
*** diazjf has quit IRC | 15:28 | |
*** thumpba has joined #openstack-keystone | 15:32 | |
lbragstad | bknudson i've followed dolphm's approach documented here a couple times - http://dolphm.com/performance-profiling-openstack-services-with-repoze-profile/ | 15:32 |
*** thumpba has quit IRC | 15:32 | |
*** thumpba has joined #openstack-keystone | 15:33 | |
bknudson | lbragstad: neat, will take a look. | 15:36 |
openstackgerrit | Merged openstack/keystoneauth: Don't include openstack/common in flake8 exclude list https://review.openstack.org/349978 | 15:37 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Move Mapping API to its own file https://review.openstack.org/350117 | 15:39 |
*** pnavarro has joined #openstack-keystone | 15:39 | |
*** code-R has joined #openstack-keystone | 15:41 | |
*** dave-mcc_ has joined #openstack-keystone | 15:43 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Introduce read-only mode for the database https://review.openstack.org/349700 | 15:43 |
*** dave-mccowan has quit IRC | 15:44 | |
*** diazjf has joined #openstack-keystone | 15:44 | |
*** lamt_ has joined #openstack-keystone | 15:46 | |
*** lamt_ has quit IRC | 15:47 | |
*** lamt_ has joined #openstack-keystone | 15:47 | |
*** aastha has joined #openstack-keystone | 15:50 | |
*** danpawlik has quit IRC | 15:50 | |
*** jaosorior has quit IRC | 15:52 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Move Mapping API to its own file https://review.openstack.org/350117 | 15:52 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Move Service Provider API to its own file https://review.openstack.org/350128 | 15:53 |
*** jaosorior has joined #openstack-keystone | 15:54 | |
*** brancal has joined #openstack-keystone | 15:58 | |
*** adrian_otto has joined #openstack-keystone | 16:01 | |
*** gokrokve has joined #openstack-keystone | 16:02 | |
*** tangchen_ has quit IRC | 16:02 | |
*** jsavak has quit IRC | 16:03 | |
slberger | Does anyone know if there is an open bug report for the issue with tempest and keystone using fernet tokens? | 16:03 |
bknudson | lbragstad: ^ ? | 16:04 |
bknudson | We have a proposed change to devstack, but there's no bug for it: https://review.openstack.org/#/c/258650/ | 16:04 |
lbragstad | slberger the timing issue? | 16:04 |
patchbot | bknudson: patch 258650 - keystone - [WIP]Make fernet default token provider | 16:04 |
dolphm | slberger: what issue? | 16:04 |
*** jsavak has joined #openstack-keystone | 16:04 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Move Service Provider API to its own file https://review.openstack.org/350128 | 16:04 |
bknudson | oh, that change is for keystone and not devstack. | 16:05 |
bknudson | the devstack change was merged and then reverted... | 16:05 |
slberger | lbragstad dolphm Someone had told me that tempest has issues or doesn't work with a keystone installation that uses fernet | 16:05 |
*** code-R_ has joined #openstack-keystone | 16:06 | |
bknudson | Here's the devstack change: https://review.openstack.org/#/c/319489/ | 16:06 |
patchbot | bknudson: patch 319489 - openstack-dev/devstack - Switch fernet back as the default token provider | 16:06 |
bknudson | https://bugs.launchpad.net/keystone/+bug/1578866 | 16:06 |
openstack | Launchpad bug 1578866 in OpenStack Identity (keystone) "Race condition between token validation and revocation API causes intermittent gate failures." [High,Fix released] - Assigned to Lance Bragstad (lbragstad) | 16:06 |
dolphm | slberger: definitely - we've had a couple of different problems with tempest on the topic | 16:06 |
bknudson | https://bugs.launchpad.net/keystone/+bug/1577558 | 16:06 |
openstack | Launchpad bug 1577558 in OpenStack Identity (keystone) mitaka "[OSSA 2016-008] v2.0 fernet tokens audit ids are inconsistent (CVE-2016-4911)" [High,Fix released] | 16:06 |
bknudson | both of those bugs are fix released. | 16:06 |
*** jaosorior has quit IRC | 16:06 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Move List Projects and Domains API to its own file https://review.openstack.org/350143 | 16:07 |
bknudson | Here's the keystone change to make fernet the default: https://review.openstack.org/#/c/345688/5 | 16:07 |
patchbot | bknudson: patch 345688 - keystone - Switch fernet to be the default token provider. | 16:08 |
*** ddieterly has quit IRC | 16:08 | |
lbragstad | https://review.openstack.org/#/c/345688/5 still uncovered some issues that we are tracking with https://bugs.launchpad.net/keystone/+bug/1607553 | 16:09 |
openstack | Launchpad bug 1607553 in OpenStack Identity (keystone) "Revocation event caching is broken across processes" [High,New] | 16:09 |
patchbot | lbragstad: patch 345688 - keystone - Switch fernet to be the default token provider. | 16:09 |
*** code-R has quit IRC | 16:09 | |
lbragstad | looks like there are still some issues with revocation event caching | 16:09 |
*** nishaYadav has joined #openstack-keystone | 16:15 | |
*** tangchen_ has joined #openstack-keystone | 16:16 | |
*** gokrokve has quit IRC | 16:17 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Move Federation Auth API to its own file https://review.openstack.org/350151 | 16:18 |
*** dikonoor has quit IRC | 16:19 | |
*** browne has joined #openstack-keystone | 16:25 | |
*** krotscheck is now known as krot_sickleave | 16:27 | |
*** marekd2 has quit IRC | 16:28 | |
*** marekd2 has joined #openstack-keystone | 16:28 | |
*** marekd2 has quit IRC | 16:33 | |
*** martinus- has quit IRC | 16:34 | |
*** dikonoor has joined #openstack-keystone | 16:36 | |
openstackgerrit | Gage Hugo proposed openstack/keystone: Add schema validation to create user v2 https://review.openstack.org/348531 | 16:37 |
*** dikonoor has quit IRC | 16:42 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Move Assertion API to its own file https://review.openstack.org/350158 | 16:43 |
openstackgerrit | Gage Hugo proposed openstack/keystone: Add schema validation to update user v2 https://review.openstack.org/345022 | 16:43 |
samueldmq | stevemar: ^ the remaining ones ( in the move of fed docs ) | 16:43 |
*** thumpba has quit IRC | 16:44 | |
*** diazjf has quit IRC | 16:49 | |
*** tesseract- has quit IRC | 16:51 | |
stevemar | samueldmq: thanks boss | 16:55 |
*** KevinE has joined #openstack-keystone | 16:55 | |
samueldmq | stevemar: sure sir | 16:57 |
*** chlong has quit IRC | 16:58 | |
*** jpena is now known as jpena|off | 16:59 | |
*** adrian_otto has quit IRC | 17:01 | |
*** julim has quit IRC | 17:02 | |
*** mvk has quit IRC | 17:06 | |
*** julim has joined #openstack-keystone | 17:06 | |
*** jsavak has quit IRC | 17:08 | |
*** jsavak has joined #openstack-keystone | 17:08 | |
*** chlong has joined #openstack-keystone | 17:12 | |
*** ametts has quit IRC | 17:12 | |
*** samueldmq has quit IRC | 17:12 | |
*** thumpba has joined #openstack-keystone | 17:13 | |
*** ametts has joined #openstack-keystone | 17:13 | |
*** crinkle has quit IRC | 17:17 | |
*** thumpba_ has joined #openstack-keystone | 17:23 | |
*** narengan has quit IRC | 17:23 | |
*** thumpba has quit IRC | 17:25 | |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Improve docs for v3 ec2 https://review.openstack.org/350173 | 17:27 |
*** jsavak has quit IRC | 17:27 | |
*** code-R_ has quit IRC | 17:28 | |
*** jsavak has joined #openstack-keystone | 17:28 | |
*** tqtran has joined #openstack-keystone | 17:31 | |
*** maestropandy has joined #openstack-keystone | 17:36 | |
*** Gorian_ has joined #openstack-keystone | 17:37 | |
*** code-R has joined #openstack-keystone | 17:38 | |
*** maestropandy has left #openstack-keystone | 17:43 | |
stevemar | so much on the meeting agenda again :O | 17:44 |
*** adriant has joined #openstack-keystone | 17:45 | |
*** narengan has joined #openstack-keystone | 17:46 | |
*** narengan1 has joined #openstack-keystone | 17:47 | |
*** narengan has quit IRC | 17:51 | |
lbragstad | stevemar lots to talk about :) | 17:54 |
*** narengan1 has quit IRC | 17:57 | |
*** mvk has joined #openstack-keystone | 17:58 | |
* notmorgan escapes meetings. | 17:58 | |
* stevemar waves bye to notmorgan | 17:59 | |
breton | notmorgan: wat | 17:59 |
breton | notmorgan: we need you there! | 17:59 |
*** crinkle has joined #openstack-keystone | 18:00 | |
notmorgan | nope, you all can handle it w/o me :) | 18:00 |
notmorgan | i have faith in the keystone team | 18:00 |
*** jamielennox|away is now known as jamielennox | 18:01 | |
*** amakarov has quit IRC | 18:04 | |
*** amakarov has joined #openstack-keystone | 18:04 | |
*** amakarov has quit IRC | 18:04 | |
*** alexander__ has joined #openstack-keystone | 18:05 | |
*** adrian_otto has joined #openstack-keystone | 18:09 | |
*** itisha has quit IRC | 18:10 | |
*** daemontool_ has quit IRC | 18:12 | |
*** diazjf has joined #openstack-keystone | 18:23 | |
*** brancal has quit IRC | 18:23 | |
*** jrist has quit IRC | 18:27 | |
*** jrist has joined #openstack-keystone | 18:28 | |
*** julim has quit IRC | 18:29 | |
*** jrist has quit IRC | 18:30 | |
*** julim has joined #openstack-keystone | 18:31 | |
openstackgerrit | Jamie Lennox proposed openstack/keystone: Move audit initiator creation to request https://review.openstack.org/342658 | 18:34 |
openstackgerrit | Merged openstack/keystone: Fix python{3,}-all-dev depends in deb based https://review.openstack.org/341010 | 18:36 |
*** marekd2 has joined #openstack-keystone | 18:44 | |
dstanek | henrynash: if this is correct then i don't see why #4 and #5 are dirfferent steps http://paste.openstack.org/show/545718/ | 18:48 |
*** brancal has joined #openstack-keystone | 18:49 | |
*** marekd2 has quit IRC | 18:49 | |
openstackgerrit | Merged openstack/keystone-specs: Add rolling upgrade steps to keystone-manage https://review.openstack.org/337680 | 18:49 |
*** aastha has quit IRC | 18:49 | |
henrynash | dstanek: so we only read the database flag at startup, so they'll be some nodes that have seen the new flag,some that haven't | 18:51 |
dstanek | henrynash: ah, it looked like you would be managing the state in the DB itself. so you have to run the manage commands on every node? | 18:52 |
henrynash | dstanek: no....but I was persuaded that we don't want to check the DB flag on every access...so only check on reboot | 18:53 |
henrynash | i orgigionally had 4 and 5 as one step, but xek pointed out the problem | 18:54 |
dstanek | henrynash: in #2 why not write to both columns then? | 18:54 |
jamielennox | henrynash: steve just +Aed that but i had a comment or two | 18:55 |
*** Raildo has quit IRC | 18:55 | |
jamielennox | henrynash: why do we need that migration tsatus flag ? | 18:55 |
*** maestropandy1 has joined #openstack-keystone | 18:58 | |
henrynash | dstanek: I'll try and go through this again, add addendum write up and see if we can simplify.... | 18:58 |
*** maestropandy1 has left #openstack-keystone | 18:59 | |
dstanek | i think stevemar is trigger happy | 18:59 |
stevemar | dstanek: just being courteous to our infra team | 18:59 |
dstanek | :-) | 18:59 |
stevemar | :) | 18:59 |
lbragstad | gotta refill coffee | 18:59 |
stevemar | adriant: so ... | 19:00 |
henrynash | dstanek: but I've been through it a few times and come back to this solution | 19:00 |
dstanek | henrynash: cool. i just don't see the extra step. new code can automatically write the both columns and then needs something to tell it to start reading there too | 19:00 |
jamielennox | which is my question - why do we need the status flag instead of the two migration counters we already have | 19:01 |
*** Raildo has joined #openstack-keystone | 19:01 | |
stevemar | adriant: maybe trying to get MFA in time for N is a bit risky. let's keep fine tuning the spec and hopefully it'll land in O | 19:01 |
*** Raildo has quit IRC | 19:01 | |
jamielennox | don't the migration counters provide a max and minimum of what columns we need to support | 19:01 |
stevemar | adriant: i get the impression that folks are stretched thin and can't provide enough review time for this subject | 19:01 |
jamielennox | (obviously not exactly max/min as they are independant counters) | 19:02 |
adriant | stevemar: not a problem, was expecting as much. Code was mainly being worked on to try some ideas out. | 19:02 |
henrynash | jamielennox: because we can't use sqlalchemy migration control for on-the-fly data migration or tidy-up, since you need to re-run them multiple times potentially (e.g. only want to for mirgation 100 rows at a time) | 19:02 |
dstanek | henrynash: jamielennox: hmmmm....maybe because of the stop writing to old columns | 19:02 |
stevemar | adriant: glad to have you working on the code and spec. FWIW i think it's great and should be in, but i'm only 1 vote ;) | 19:02 |
henrynash | jamielennox: we use alchemy migrate repos for the actual scheme changes (expacnd and contract) | 19:02 |
adriant | stevemar: I'll also write and test an edit of v2 for MFA, but the worry is how to make the totp part optional | 19:03 |
rodrigods | adriant, know the feeling of having stuff postponed and even with that, it landed with some fundamental problems | 19:03 |
rodrigods | aka HMT | 19:03 |
jamielennox | henrynash: so rerunning is an odd problem i'm not sure about - i wasn't thinking we'd suppot that | 19:03 |
*** diazjf1 has joined #openstack-keystone | 19:03 | |
henrynash | jamielennix: (and in Newton for data migration sicne that is part of expand), but with on-the-fly migrations there is no data migration in teh exapnd phase | 19:03 |
stevemar | rodrigods: that's back on the agenda for next week ;) | 19:03 |
rodrigods | stevemar, fair enough :) | 19:04 |
* rodrigods will hide in the corner | 19:04 | |
henrynash | jamielennox: the request from teh midcycle was to support the standard phases (even if we don't need them yet)... | 19:04 |
jamielennox | henrynash: do we support that case? expand and migrate seperate | 19:04 |
dstanek | henrynash: ok, i think that's what i was missing. step #2 can start writing to both. then you need to tell it to start reading from new. ...then you need to tell it to not update or read old | 19:04 |
*** julim has quit IRC | 19:04 | |
*** diazjf has quit IRC | 19:05 | |
*** jsavak has quit IRC | 19:05 | |
jamielennox | i wasn't thinking of that, however i'm still not sure why the max/min counters don't tell the code what columns to write | 19:05 |
henrynash | dstanek: yes step 2 *could* write to both, althogh I'm not sure it gains you much...but yes, the key is to know when to start reading from both | 19:06 |
bknudson | is keystone going to query a table on every operation? If so that's going to slow things considerably | 19:06 |
*** julim has joined #openstack-keystone | 19:06 | |
*** jsavak has joined #openstack-keystone | 19:06 | |
henrynash | bknudson: no | 19:07 |
*** fifieldt has quit IRC | 19:07 | |
*** samueldmq has joined #openstack-keystone | 19:07 | |
rodrigods | stevemar, think bknudson has a point on requiring features to have tempest tests (in keystone's plugin or in tempest itself) | 19:07 |
henrynash | bknudson: that's why we have the extra phases, to allow us only to read on startup | 19:07 |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Improve docs for v3 ec2 https://review.openstack.org/350173 | 19:07 |
bknudson | ok, so it's just like the config file. | 19:07 |
bknudson | but keystone-manage can write to it | 19:07 |
bknudson | works for me. | 19:08 |
henrynash | bknudson: actually a database status row | 19:08 |
henrynash | blnudson: but same princple | 19:08 |
henrynash | bknudson: yep | 19:08 |
bknudson | henrynash: doesn't tab completion work for you? | 19:08 |
henrynash | no! | 19:08 |
henrynash | bugger! | 19:08 |
henrynash | bknudson: must get the working! | 19:08 |
bknudson | henrynash: your fingers will wear out. | 19:09 |
henrynash | all teh time I'd have saved if I took the time to fix it | 19:09 |
bknudson | or we need shorter nicks. | 19:09 |
henrynash | bknudson: we each grab a letter? I'll take 'h' | 19:10 |
rodrigods | lol | 19:10 |
bknudson | that should work. | 19:10 |
bknudson | we'll be getting a lot of notifications. | 19:10 |
*** KevinE has quit IRC | 19:12 | |
*** nishaYadav has quit IRC | 19:13 | |
*** narengan has joined #openstack-keystone | 19:13 | |
*** samueldmq has quit IRC | 19:15 | |
*** samuel_ has joined #openstack-keystone | 19:17 | |
*** samuel_ has quit IRC | 19:17 | |
*** nishaYadav has joined #openstack-keystone | 19:17 | |
*** nishaYadav is now known as Guest53941 | 19:17 | |
*** samueldmq has joined #openstack-keystone | 19:17 | |
*** ChanServ sets mode: +v samueldmq | 19:17 | |
*** fifieldt has joined #openstack-keystone | 19:18 | |
*** maestropandy has joined #openstack-keystone | 19:19 | |
*** maestropandy has left #openstack-keystone | 19:19 | |
breton | guyses | 19:23 |
breton | i think i've mixed something up with trusts validation | 19:23 |
breton | but not only me! | 19:23 |
breton | lbragstad: i can validate trust-scoped fernet tokens in v2.0 too! | 19:23 |
*** narengan has quit IRC | 19:24 | |
*** KevinE has joined #openstack-keystone | 19:28 | |
*** roxanaghe has quit IRC | 19:30 | |
*** narengan has joined #openstack-keystone | 19:32 | |
*** maestropandy1 has joined #openstack-keystone | 19:33 | |
*** maestropandy1 has left #openstack-keystone | 19:33 | |
*** adriant has quit IRC | 19:33 | |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Add ec2 functional tests https://review.openstack.org/350245 | 19:34 |
*** jsavak has quit IRC | 19:36 | |
*** jsavak has joined #openstack-keystone | 19:37 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Lockout requirements https://review.openstack.org/340074 | 19:41 |
*** maestropandy has joined #openstack-keystone | 19:42 | |
*** maestropandy has left #openstack-keystone | 19:47 | |
stevemar | breton: trusts amirite | 19:49 |
stevemar | breton: what did you find? | 19:49 |
*** aastha has joined #openstack-keystone | 19:50 | |
*** diazjf1 has quit IRC | 19:50 | |
*** code-R has quit IRC | 19:56 | |
*** jrist has joined #openstack-keystone | 19:58 | |
*** diazjf has joined #openstack-keystone | 19:59 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Minimum password age requirements https://review.openstack.org/343314 | 20:00 |
*** julim has quit IRC | 20:04 | |
openstackgerrit | Eric Brown proposed openstack/keystone: Improve domain configuration API docs https://review.openstack.org/348591 | 20:05 |
*** Guest53941 has quit IRC | 20:09 | |
*** brancal has quit IRC | 20:14 | |
*** roxanaghe has joined #openstack-keystone | 20:18 | |
*** KevinE has quit IRC | 20:18 | |
*** adrian_otto has quit IRC | 20:26 | |
*** itisha has joined #openstack-keystone | 20:33 | |
*** openstackgerrit_ has joined #openstack-keystone | 20:35 | |
*** daemontool has joined #openstack-keystone | 20:35 | |
*** openstackgerrit_ has quit IRC | 20:36 | |
*** daemontool has quit IRC | 20:42 | |
*** ametts has quit IRC | 20:44 | |
*** tonytan4ever has quit IRC | 20:46 | |
openstackgerrit | Ron De Rose proposed openstack/keystone: PCI-DSS Minimum password age requirements https://review.openstack.org/343314 | 20:51 |
*** diazjf has quit IRC | 20:52 | |
*** marekd2 has joined #openstack-keystone | 20:55 | |
*** notmyname has quit IRC | 20:55 | |
lbragstad | breton ? | 20:59 |
lbragstad | breton I'm working on a patch now to make uuid and fernet behave the same when it comes to trusts validation and v2.0 | 20:59 |
lbragstad | breton i'm running tests now | 20:59 |
*** marekd2 has quit IRC | 21:00 | |
*** thumpba_ has quit IRC | 21:01 | |
breton | lbragstad: how do they differ? | 21:02 |
*** diazjf has joined #openstack-keystone | 21:02 | |
lbragstad | breton after doing a pile of digging | 21:02 |
lbragstad | breton I think something got changed in the refactor I did a while back to make fernet use the same path as uuid | 21:03 |
lbragstad | breton according to the original code, you should get a 403 Forbidden when trying to get a new scoped token with a trust scoped token | 21:03 |
lbragstad | Fernet wasn't honoring that | 21:03 |
breton | lbragstad: ok. should i be able to validate trust-scoped token now with fernet in 2.0? | 21:05 |
lbragstad | breton yep - i'm almost done. | 21:05 |
breton | lbragstad: no, i mean with master | 21:05 |
lbragstad | breton you shouldn't be https://github.com/openstack/keystone/blob/7a160c258917afb4194ec7c19a90ddec051c1e9c/keystone/token/providers/common.py#L83-L86 | 21:06 |
*** narengan1 has joined #openstack-keystone | 21:18 | |
*** narengan1 has quit IRC | 21:18 | |
mfisch | stevemar: we're also hitting this bug in M | 21:18 |
mfisch | https://bugs.launchpad.net/keystone/+bug/1600393 | 21:18 |
openstack | Launchpad bug 1600393 in OpenStack Identity (keystone) "AttributeError: 'list' object has no attribute 'items'" [High,New] | 21:18 |
mfisch | digging into logs today showed its happening occassionally | 21:18 |
browne | mfisch: oh good. i'm not crazy then | 21:19 |
browne | we had to completely turn off the cache | 21:19 |
stevemar | mfisch: damn, was hoping browne was crazy | 21:19 |
mfisch | we're running a container built off mitaka yesterday | 21:19 |
*** code-R has joined #openstack-keystone | 21:19 | |
mfisch | browne: middleware cache or keystone cache? | 21:19 |
browne | lol | 21:19 |
browne | the global cache keystone setting | 21:20 |
breton | lbragstad: http://paste.openstack.org/show/545754/ the script | 21:20 |
*** pauloewerton has quit IRC | 21:20 | |
mfisch | browne: and it goes away? | 21:20 |
*** narengan has quit IRC | 21:20 | |
browne | mfisch: we use stable/mitaka keystone with eventlet, memcache, fernet | 21:20 |
mfisch | memcache fernet + docker/uwsgi | 21:20 |
browne | mfisch: yep, it goes away. performance probably sucks now | 21:21 |
mfisch | good thing mitaka is only in the lab | 21:21 |
*** diazjf has quit IRC | 21:21 | |
jamielennox | mfisch: do you have any ideas where that's coming from yet? | 21:21 |
breton | lbragstad: "checking v3 token on v2" | 21:21 |
mfisch | someone is making a v3 API call, unsure who | 21:21 |
jamielennox | mfisch: i haven't gone a long way but i haven't been able to reproduce | 21:21 |
breton | lbragstad: fails with 401 | 21:22 |
browne | mfisch: keep in mind that oslo.cache also has a bug in mitaka, you also have to set the driver to the cache no-op driver otherwise it doesn't really turn off | 21:22 |
mfisch | we see calls from Swift | 21:22 |
mfisch | browne: have a link? | 21:22 |
mfisch | and also monasca | 21:22 |
lbragstad | breton hmm - strange because we have this in the tests... https://github.com/openstack/keystone/blob/7a160c258917afb4194ec7c19a90ddec051c1e9c/keystone/token/providers/common.py#L83-L86 | 21:22 |
mfisch | jamielennox: its weird | 21:23 |
mfisch | it looks like the cache gets in a weird state | 21:23 |
*** vinsh has joined #openstack-keystone | 21:24 | |
breton | lbragstad: the same behavior on uuid | 21:24 |
browne | mfisch: https://review.openstack.org/#/c/304688/ | 21:24 |
patchbot | browne: patch 304688 - oslo.cache - If caching is globally disabled force dogpile to u... (MERGED) | 21:24 |
breton | lbragstad: so now fernet behaves the same way as uuid | 21:24 |
jamielennox | yea, once its in cache it's really hard to figure out because it may be the result of a code update | 21:24 |
lbragstad | breton with what? | 21:25 |
breton | lbragstad: with trusts | 21:25 |
browne | mfisch: jamielennox from what i observed, it seemed somehow related to v2 and v3 mixed with invalid caching. seemed like many times it would get v2 data for a v3 request and vice versa. i know i saw a v3 token with a v2 service catalog | 21:27 |
lbragstad | breton i mean with master? | 21:27 |
vinsh | breton: ACK. following for mfisch. He stepped out for the day. | 21:27 |
breton | lbragstad: that's with master | 21:28 |
jamielennox | browne: yuk | 21:28 |
*** diazjf has joined #openstack-keystone | 21:28 | |
lbragstad | breton that's confusing because the code specifically says to raise a 401 | 21:28 |
lbragstad | when validation trust scoped tokens against v2.0 | 21:28 |
browne | btw, our deployment is also two keystones using ha-proxy to load-balance if that matters | 21:28 |
vinsh | Same. haproxy here | 21:29 |
lbragstad | breton how does this pass? https://github.com/openstack/keystone/blob/7a160c258917afb4194ec7c19a90ddec051c1e9c/keystone/tests/unit/test_v3_auth.py#L1190 | 21:30 |
*** code-R_ has joined #openstack-keystone | 21:31 | |
breton | lbragstad: it takes v3 token and tries to validate it on v2.0 | 21:33 |
breton | lbragstad: it fails for me too | 21:33 |
*** code-R has quit IRC | 21:33 | |
lbragstad | breton so we *do* have a bug | 21:34 |
*** pnavarro has quit IRC | 21:34 | |
breton | checking v2 token on v2 | 21:36 |
breton | 200 | 21:36 |
breton | checking v2 token on v3 | 21:36 |
breton | 200 | 21:36 |
breton | checking v3 token on v2 | 21:36 |
breton | 401 | 21:36 |
breton | checking v3 token on v3 | 21:36 |
breton | 200 | 21:36 |
breton | that's fernet | 21:36 |
breton | the same happens with uuid on master | 21:36 |
breton | is it a bug? | 21:36 |
lbragstad | breton I thought the original bug was that you couldn't validate a trust-scoped token on v2.0 period? | 21:37 |
breton | lbragstad: it seems that i was wrong on that one and that i actually can | 21:38 |
lbragstad | breton that's so weird - because we apparently have tests that explicitly test that we shouldn't be able to do that | 21:39 |
breton | lbragstad: for example? and what is "that"? | 21:39 |
lbragstad | https://github.com/openstack/keystone/blob/7a160c258917afb4194ec7c19a90ddec051c1e9c/keystone/tests/unit/test_v3_auth.py#L1190 | 21:39 |
lbragstad | which you were able to duplicate | 21:40 |
*** diazjf has quit IRC | 21:40 | |
breton | test_v2_validate_trust_scoped_token == "checking v3 token on v2" | 21:40 |
breton | and it failes for me | 21:40 |
lbragstad | https://github.com/openstack/keystone/blob/7a160c258917afb4194ec7c19a90ddec051c1e9c/keystone/tests/unit/test_auth.py#L1333 | 21:40 |
lbragstad | breton yep | 21:41 |
breton | ok, i stopped understanding :) | 21:41 |
breton | test_v2_validate_trust_scoped_token checks that 401 is returned, and my test shows that 401 is returned indeed | 21:42 |
lbragstad | yep - so that is consistent | 21:42 |
*** diazjf has joined #openstack-keystone | 21:43 | |
breton | test_delete_trust_revokes_token is ... weird. | 21:43 |
lbragstad | breton yeah | 21:43 |
lbragstad | breton I want to rewrite that test because it's hardcoded to assert against a persistent token backend | 21:44 |
*** tonytan4ever has joined #openstack-keystone | 21:47 | |
*** tonytan4ever has quit IRC | 21:52 | |
*** markvoelker has quit IRC | 21:54 | |
*** diazjf has quit IRC | 22:10 | |
harlowja | soooo quick question, well probably not quick | 22:13 |
harlowja | if we have a IDP (SSO) that we use internally (called okta) and that is SAML compliant, then it should be pretty easy to plug keystone into using that (to act as the identiyy provider?) | 22:14 |
*** jsavak has quit IRC | 22:17 | |
*** edmondsw has quit IRC | 22:17 | |
lbragstad | breton i think https://github.com/openstack/keystone/blob/7a160c258917afb4194ec7c19a90ddec051c1e9c/keystone/tests/unit/test_v3_auth.py#L1190 raises an exception because the trustee isn't in the default domain | 22:18 |
*** jsavak has joined #openstack-keystone | 22:20 | |
lbragstad | breton https://github.com/openstack/keystone/blob/master/keystone/token/providers/common.py#L703 | 22:21 |
*** gordc has quit IRC | 22:22 | |
*** jsavak has quit IRC | 22:23 | |
openstackgerrit | Eric Brown proposed openstack/keystone: Bump API version number and date https://review.openstack.org/350289 | 22:28 |
stevemar | browne: you're the only one that remembers to bump that | 22:37 |
stevemar | harlowja: "pretty easy" is relative | 22:38 |
stevemar | :) | 22:38 |
harlowja | stevemar sure ;) | 22:38 |
*** sdake has quit IRC | 22:40 | |
stevemar | harlowja: just a heads up though, setting up SSO is pretty do-able, but CLI stuff will be flakey until osc 3.0.0 | 22:40 |
harlowja | kk | 22:40 |
harlowja | makes sense | 22:40 |
openstackgerrit | Merged openstack/keystoneauth: Improve authentication plugins documentation https://review.openstack.org/349423 | 22:43 |
*** ravelar159 has quit IRC | 22:45 | |
*** david-lyle has quit IRC | 22:50 | |
*** david-lyle has joined #openstack-keystone | 22:51 | |
*** michauds has quit IRC | 22:52 | |
*** spzala has quit IRC | 22:56 | |
browne | stevemar: haha, just stumbled onto that version by accident and happened to remember the other 3.7 change | 22:56 |
*** spzala has joined #openstack-keystone | 22:57 | |
browne | anyone here the maintainer of keystone's launchpad page (https://launchpad.net/keystone)? | 22:59 |
stevemar | browne: i could try | 22:59 |
stevemar | whats up | 22:59 |
browne | i noticed the Downloads link is out-dated. still version 8 | 22:59 |
browne | liberty, not mitaka | 22:59 |
breton | harlowja: yes | 23:00 |
*** slberger has left #openstack-keystone | 23:00 | |
breton | harlowja: i configured keystone for okta and it worked great | 23:00 |
harlowja | cool | 23:01 |
breton | harlowja: the only issue is that they don't have ecp | 23:01 |
harlowja | whats ecp? | 23:01 |
*** spzala has quit IRC | 23:01 | |
breton | harlowja: so you won't be able to use federation with cli | 23:01 |
jmlowe | harlowja: isn't that the thingy that lets you get redirected to auth then redirect back? | 23:02 |
*** code-R_ has quit IRC | 23:02 | |
harlowja | prob something like that :-P | 23:02 |
breton | yes, kinda that | 23:02 |
*** dave-mcc_ has quit IRC | 23:02 | |
breton | but for cli | 23:03 |
*** spedione is now known as spedione|AWAY | 23:03 | |
*** julim has joined #openstack-keystone | 23:03 | |
breton | also in Okta you'll have to create custom attributes for users | 23:03 |
breton | (or i haven't figured out how to use standard) | 23:04 |
harlowja | cool, where u at breton ? | 23:04 |
harlowja | might be interesting to chat if u in the bay area :) | 23:05 |
*** vinsh has quit IRC | 23:05 | |
*** ravelar159 has joined #openstack-keystone | 23:05 | |
breton | harlowja: i am in Moscow, Russia | 23:05 |
harlowja | oh durn | 23:06 |
harlowja | ha | 23:06 |
harlowja | u should move, ha | 23:06 |
breton | i'd love to :) | 23:06 |
stevemar | browne: no idea how to update it, just tried for 10 minutes | 23:07 |
stevemar | i gave up | 23:07 |
*** marekd2 has joined #openstack-keystone | 23:07 | |
browne | stevemar: oh well, np | 23:07 |
stevemar | harlowja: you'd have to fight dims if you steal away breton | 23:08 |
harlowja | lol | 23:08 |
*** spzala has joined #openstack-keystone | 23:11 | |
*** marekd2 has quit IRC | 23:12 | |
*** ravelar159 has quit IRC | 23:12 | |
*** sdake has joined #openstack-keystone | 23:15 | |
*** ravelar159 has joined #openstack-keystone | 23:16 | |
*** sdake_ has joined #openstack-keystone | 23:17 | |
rodrigods | stevemar, harlowja did a lot of testing this week for federation | 23:19 |
rodrigods | but some stuff in rodrigods.com, again | 23:19 |
rodrigods | put* | 23:19 |
*** sdake has quit IRC | 23:20 | |
*** sdake_ is now known as sdake | 23:21 | |
*** ravelar159 has quit IRC | 23:21 | |
stevemar | rodrigods: good, we need more testing of it :) | 23:21 |
rodrigods | stevemar, seems to work pretty well | 23:21 |
stevemar | maybe harlowja can create some nifty automation for it like he does with *literally everything* | 23:21 |
rodrigods | only the ecp stuff in osc is a bit wonky | 23:22 |
rodrigods | stevemar, maybe we can have https://review.openstack.org/#/c/324769/ landing in O | 23:22 |
patchbot | rodrigods: patch 324769 - keystone - WIP: Federated authentication via ECP functional t... | 23:22 |
stevemar | rodrigods: that can land at any time | 23:34 |
rodrigods | stevemar, needs the devstack plugin | 23:35 |
* breton ducks | 23:35 | |
breton | devstack plugin is almost ready too btw | 23:36 |
rodrigods | breton, ++ | 23:36 |
breton | i plan to tackle it this week | 23:36 |
rodrigods | breton, what time is it in russia? | 23:36 |
rodrigods | is already late in Brazil | 23:36 |
breton | rodrigods: 02:36 am | 23:37 |
rodrigods | breton, long day in the office? heh | 23:37 |
breton | rodrigods: 40+% of time i am keystoning from home :p | 23:37 |
rodrigods | breton, ++ | 23:39 |
*** sigmavirus is now known as sigmavirus_away | 23:41 | |
*** bill_az has quit IRC | 23:44 | |
*** Gorian_ has quit IRC | 23:47 | |
*** ravelar159 has joined #openstack-keystone | 23:51 | |
*** roxanaghe has quit IRC | 23:52 | |
*** code-R has joined #openstack-keystone | 23:55 | |
*** code-R_ has joined #openstack-keystone | 23:57 | |
*** ravelar159 has quit IRC | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!