*** itisha has quit IRC | 00:00 | |
*** guoshan has joined #openstack-keystone | 00:05 | |
*** code-R_ has quit IRC | 00:18 | |
*** code-R has joined #openstack-keystone | 00:18 | |
*** markvoelker has joined #openstack-keystone | 00:28 | |
*** code-R_ has joined #openstack-keystone | 00:38 | |
*** code-R has quit IRC | 00:38 | |
*** edmondsw has joined #openstack-keystone | 00:54 | |
*** guoshan has quit IRC | 00:57 | |
*** code-R_ has quit IRC | 01:01 | |
*** code-R has joined #openstack-keystone | 01:11 | |
*** code-R has quit IRC | 01:11 | |
*** guoshan has joined #openstack-keystone | 01:24 | |
*** RA_ has joined #openstack-keystone | 01:26 | |
*** RA_ is now known as RossKrumbeck | 01:29 | |
*** RossKrumbeck is now known as rkrum | 01:35 | |
*** rkrum has quit IRC | 01:40 | |
*** rkrum has joined #openstack-keystone | 01:40 | |
*** EinstCrazy has joined #openstack-keystone | 01:41 | |
*** davechen has joined #openstack-keystone | 01:59 | |
*** hoonetorg has quit IRC | 02:20 | |
*** julim has joined #openstack-keystone | 02:36 | |
*** markvoelker has quit IRC | 02:36 | |
*** zhugaoxiao has quit IRC | 02:57 | |
*** chlong has quit IRC | 03:25 | |
*** julim has quit IRC | 03:28 | |
*** zhugaoxiao has joined #openstack-keystone | 03:36 | |
*** ayoung has quit IRC | 03:39 | |
*** dave-mccowan has quit IRC | 03:47 | |
*** sdake has joined #openstack-keystone | 03:58 | |
openstackgerrit | Anh Tran proposed openstack/keystone: api-ref: Correcting V3 Services APIs https://review.openstack.org/351598 | 04:03 |
---|---|---|
openstackgerrit | Anh Tran proposed openstack/keystone: api-ref: Correcting V3 Services APIs https://review.openstack.org/351598 | 04:06 |
*** roxanaghe has joined #openstack-keystone | 04:08 | |
*** dikonoor has joined #openstack-keystone | 04:14 | |
*** guoshan has quit IRC | 04:14 | |
*** jaosorior has joined #openstack-keystone | 04:14 | |
*** guoshan has joined #openstack-keystone | 04:14 | |
*** guoshan has quit IRC | 04:19 | |
*** korean101 has quit IRC | 04:25 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/351988 | 04:31 |
*** markvoelker has joined #openstack-keystone | 04:37 | |
*** tonytan4ever has quit IRC | 04:39 | |
*** markvoelker has quit IRC | 04:42 | |
*** guoshan has joined #openstack-keystone | 04:50 | |
*** guoshan has quit IRC | 04:56 | |
*** roxanaghe has quit IRC | 05:03 | |
*** pcaruana has quit IRC | 05:03 | |
*** roxanaghe has joined #openstack-keystone | 05:03 | |
*** roxanaghe has quit IRC | 05:04 | |
*** roxanaghe has joined #openstack-keystone | 05:04 | |
*** roxanaghe has quit IRC | 05:05 | |
*** roxanaghe has joined #openstack-keystone | 05:05 | |
*** roxanaghe has quit IRC | 05:06 | |
*** roxanaghe has joined #openstack-keystone | 05:06 | |
*** roxanaghe has quit IRC | 05:06 | |
*** guoshan has joined #openstack-keystone | 05:44 | |
*** guoshan has quit IRC | 05:49 | |
*** adriant has quit IRC | 05:57 | |
*** chlong has joined #openstack-keystone | 05:59 | |
*** roxanaghe has joined #openstack-keystone | 06:02 | |
*** roxanaghe has quit IRC | 06:06 | |
*** dkehn_ has quit IRC | 06:10 | |
*** code-R has joined #openstack-keystone | 06:12 | |
*** code-R_ has joined #openstack-keystone | 06:12 | |
*** code-R has quit IRC | 06:16 | |
*** guoshan has joined #openstack-keystone | 06:21 | |
openstackgerrit | Anh Tran proposed openstack/keystone: api-ref: Correcting V3 Endpoints APIs https://review.openstack.org/351600 | 06:23 |
*** dkehn_ has joined #openstack-keystone | 06:29 | |
*** sdake has quit IRC | 06:38 | |
*** markvoelker has joined #openstack-keystone | 06:38 | |
*** pcaruana has joined #openstack-keystone | 06:38 | |
*** rcernin has joined #openstack-keystone | 06:41 | |
*** markvoelker has quit IRC | 06:42 | |
*** maestropandy has joined #openstack-keystone | 06:48 | |
*** tesseract- has joined #openstack-keystone | 06:53 | |
*** code-R_ has quit IRC | 07:01 | |
*** code-R has joined #openstack-keystone | 07:01 | |
*** jpena|off is now known as jpena | 07:11 | |
*** roxanaghe has joined #openstack-keystone | 07:12 | |
*** dkehn_ has quit IRC | 07:14 | |
*** roxanaghe has quit IRC | 07:17 | |
*** rkrum has quit IRC | 07:23 | |
*** permalac has joined #openstack-keystone | 07:24 | |
*** maestropandy has quit IRC | 07:25 | |
*** zouyapeng has joined #openstack-keystone | 07:27 | |
*** danpawlik has joined #openstack-keystone | 07:43 | |
*** code-R has quit IRC | 07:48 | |
openstackgerrit | Anh Tran proposed openstack/keystone: api-ref: Correcting V3 Domain config APIs https://review.openstack.org/352260 | 07:52 |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:00 | |
openstackgerrit | Anh Tran proposed openstack/keystone: api-ref: Correcting V3 Domain config APIs https://review.openstack.org/352260 | 08:05 |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Testing latest u-c https://review.openstack.org/318435 | 08:10 |
*** roxanaghe has joined #openstack-keystone | 08:13 | |
*** roxanaghe has quit IRC | 08:18 | |
*** amoralej|off is now known as amoralej | 08:20 | |
-openstackstatus- NOTICE: Gerrit is going to be restarted | 08:38 | |
*** dikonoor has quit IRC | 08:45 | |
*** jistr|mtg is now known as jistr | 08:50 | |
*** eileen has joined #openstack-keystone | 08:56 | |
eileen | hi,all | 08:56 |
*** roxanaghe has joined #openstack-keystone | 09:00 | |
*** roxanaghe has quit IRC | 09:05 | |
*** daemontool has joined #openstack-keystone | 09:14 | |
*** pnavarro has joined #openstack-keystone | 09:22 | |
*** mvk has joined #openstack-keystone | 09:24 | |
*** mvk_ has joined #openstack-keystone | 09:27 | |
*** daemontool has quit IRC | 09:31 | |
openstackgerrit | Anh Tran proposed openstack/keystone: api-ref: Correcting V3 Authentication APIs https://review.openstack.org/352291 | 09:32 |
*** mvk_ has quit IRC | 09:38 | |
openstackgerrit | Kseniya Tychkova proposed openstack/oslo.policy: Refactoring of Enforcer class https://review.openstack.org/346002 | 09:39 |
*** rkrum has joined #openstack-keystone | 09:46 | |
openstackgerrit | Anh Tran proposed openstack/keystone: api-ref: Correcting parameters of Policies APIs https://review.openstack.org/351636 | 10:04 |
rdo | yo - having a problem with Horizon and keystone domains... I can get a domain scoped token from Keystone, and have configured Horizon for v3, but when I try and login it keeps redirecting me to the login page, never proceeds to the dashboard, any ideas? thanks! | 10:13 |
*** guoshan has quit IRC | 10:21 | |
*** EinstCrazy has quit IRC | 10:24 | |
*** amakarov_away is now known as amakarov | 10:37 | |
*** rkrum has quit IRC | 10:38 | |
*** eileen has quit IRC | 10:39 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/351988 | 10:42 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/352322 | 10:42 |
*** dkehn has joined #openstack-keystone | 10:48 | |
*** maestropandy has joined #openstack-keystone | 10:57 | |
*** maestropandy has quit IRC | 11:01 | |
openstackgerrit | Boris Bobrov proposed openstack/keystoneauth: Add 308 to the list of redirect statuses https://review.openstack.org/352346 | 11:02 |
*** guoshan has joined #openstack-keystone | 11:02 | |
openstackgerrit | Boris Bobrov proposed openstack/keystoneauth: Add 308 to the list of redirect statuses https://review.openstack.org/352346 | 11:02 |
*** maestropandy has joined #openstack-keystone | 11:04 | |
*** maestropandy has left #openstack-keystone | 11:05 | |
*** pcaruana has quit IRC | 11:06 | |
*** pcaruana has joined #openstack-keystone | 11:07 | |
*** sdake has joined #openstack-keystone | 11:08 | |
*** sdake has quit IRC | 11:08 | |
*** sdake has joined #openstack-keystone | 11:08 | |
*** permalac has quit IRC | 11:09 | |
*** thiagolib has joined #openstack-keystone | 11:17 | |
*** jaosorior has quit IRC | 11:27 | |
*** jaosorior has joined #openstack-keystone | 11:28 | |
*** maestropandy1 has joined #openstack-keystone | 11:28 | |
*** rodrigods has quit IRC | 11:33 | |
*** rodrigods has joined #openstack-keystone | 11:33 | |
*** sdake has quit IRC | 11:36 | |
*** sdake has joined #openstack-keystone | 11:39 | |
*** pauloewerton has joined #openstack-keystone | 11:39 | |
*** sdake has quit IRC | 11:41 | |
*** gordc has joined #openstack-keystone | 11:43 | |
*** sdake has joined #openstack-keystone | 11:43 | |
*** markvoelker has joined #openstack-keystone | 11:45 | |
*** raildo has joined #openstack-keystone | 11:56 | |
*** jpena is now known as jpena|lunch | 11:58 | |
*** amoralej is now known as amoralej|off | 12:02 | |
*** amoralej|off is now known as amoralej|lunch | 12:03 | |
*** davechen has quit IRC | 12:04 | |
*** maestropandy1 has quit IRC | 12:09 | |
*** guoshan has quit IRC | 12:12 | |
openstackgerrit | yuyafei proposed openstack/python-keystoneclient: Add __ne__ built-in function https://review.openstack.org/337435 | 12:12 |
*** guoshan has joined #openstack-keystone | 12:28 | |
*** rkrum has joined #openstack-keystone | 12:31 | |
*** rkrum has left #openstack-keystone | 12:31 | |
*** maestropandy has joined #openstack-keystone | 12:33 | |
*** maestropandy has left #openstack-keystone | 12:34 | |
*** zouyapeng has quit IRC | 12:42 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add contract migrations to keystone-manage https://review.openstack.org/349939 | 12:51 |
*** dave-mccowan has joined #openstack-keystone | 12:52 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add the migration phase status table https://review.openstack.org/349703 | 12:57 |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for rolling upgrades to keystone-manage https://review.openstack.org/349716 | 13:09 |
openstackgerrit | henry-nash proposed openstack/keystone: Add contract migrations to keystone-manage https://review.openstack.org/349939 | 13:10 |
*** dkehn has quit IRC | 13:11 | |
*** tonytan4ever has joined #openstack-keystone | 13:12 | |
*** jpena|lunch is now known as jpena | 13:17 | |
*** maestropandy1 has joined #openstack-keystone | 13:18 | |
*** dkehn_ has joined #openstack-keystone | 13:24 | |
*** julim has joined #openstack-keystone | 13:33 | |
amakarov | bknudson, good day! Can you please look at https://review.openstack.org/#/c/352343/ | 13:33 |
patchbot | amakarov: patch 352343 - keystoneauth - add status code 308 to _REDIRECT_STATUSES | 13:33 |
amakarov | it's a quick fix | 13:33 |
*** ayoung has joined #openstack-keystone | 13:34 | |
*** ChanServ sets mode: +v ayoung | 13:34 | |
*** ayoung has quit IRC | 13:37 | |
*** amoralej|lunch is now known as amoralej | 13:37 | |
*** ayoung has joined #openstack-keystone | 13:43 | |
*** ChanServ sets mode: +v ayoung | 13:43 | |
*** guoshan has quit IRC | 13:50 | |
*** guoshan has joined #openstack-keystone | 13:55 | |
*** iurygregory has joined #openstack-keystone | 13:56 | |
*** richm has joined #openstack-keystone | 13:57 | |
bknudson | amakarov: if it's important then there should be a unit test. | 14:01 |
*** roxanaghe has joined #openstack-keystone | 14:02 | |
amakarov | bknudson, ack | 14:02 |
*** ezpz has joined #openstack-keystone | 14:02 | |
*** roxanaghe has quit IRC | 14:06 | |
*** EinstCrazy has joined #openstack-keystone | 14:07 | |
openstackgerrit | Alexander Ignatyev proposed openstack/keystone: Support new osprofiler API https://review.openstack.org/341401 | 14:08 |
*** ravelar has joined #openstack-keystone | 14:09 | |
*** spzala has joined #openstack-keystone | 14:10 | |
*** woodster_ has joined #openstack-keystone | 14:11 | |
*** maestropandy1 has quit IRC | 14:12 | |
*** spzala has quit IRC | 14:15 | |
*** spzala has joined #openstack-keystone | 14:15 | |
*** code-R has joined #openstack-keystone | 14:16 | |
*** spzala has quit IRC | 14:16 | |
*** spzala has joined #openstack-keystone | 14:16 | |
*** jaugustine_ is now known as jaugustine | 14:18 | |
*** maestropandy1 has joined #openstack-keystone | 14:20 | |
*** maestropandy1 has left #openstack-keystone | 14:20 | |
*** code-R_ has joined #openstack-keystone | 14:20 | |
*** maestropandy has joined #openstack-keystone | 14:21 | |
*** permalac has joined #openstack-keystone | 14:21 | |
*** maestropandy has left #openstack-keystone | 14:21 | |
*** code-R has quit IRC | 14:23 | |
*** slberger has joined #openstack-keystone | 14:24 | |
*** EinstCrazy has quit IRC | 14:26 | |
openstackgerrit | Alexander Makarov proposed openstack/keystoneauth: add status code 308 to _REDIRECT_STATUSES https://review.openstack.org/352343 | 14:27 |
amakarov | bknudson, ^ | 14:27 |
*** EinstCrazy has joined #openstack-keystone | 14:28 | |
*** narengan has joined #openstack-keystone | 14:29 | |
*** narengan has quit IRC | 14:30 | |
*** HenryG has joined #openstack-keystone | 14:33 | |
*** amoralej is now known as amoralej|brb | 14:34 | |
*** roxanaghe has joined #openstack-keystone | 14:37 | |
*** markvoelker has quit IRC | 14:41 | |
*** guoshan has quit IRC | 14:53 | |
*** markvoelker has joined #openstack-keystone | 14:54 | |
*** eeiden has left #openstack-keystone | 14:55 | |
*** jaosorior has quit IRC | 14:56 | |
*** pnavarro has quit IRC | 14:57 | |
*** narengan has joined #openstack-keystone | 14:59 | |
*** kragniz has quit IRC | 15:00 | |
*** ravelar has quit IRC | 15:02 | |
*** KevinE has joined #openstack-keystone | 15:04 | |
*** KevinE has joined #openstack-keystone | 15:05 | |
*** amoralej|brb is now known as amoralej | 15:07 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for rolling upgrades to keystone-manage https://review.openstack.org/349716 | 15:12 |
openstackgerrit | henry-nash proposed openstack/keystone: Add contract migrations to keystone-manage https://review.openstack.org/349939 | 15:12 |
*** ravelar has joined #openstack-keystone | 15:22 | |
*** EinstCrazy has quit IRC | 15:34 | |
*** EinstCrazy has joined #openstack-keystone | 15:35 | |
*** code-R_ has quit IRC | 15:37 | |
*** pgbridge has joined #openstack-keystone | 15:38 | |
*** woodburn has joined #openstack-keystone | 15:43 | |
*** edmondsw has quit IRC | 15:50 | |
*** michauds has joined #openstack-keystone | 15:57 | |
*** haplo37__ has joined #openstack-keystone | 16:00 | |
*** rcernin has quit IRC | 16:01 | |
*** Nissmed has joined #openstack-keystone | 16:02 | |
*** narengan1 has joined #openstack-keystone | 16:02 | |
Nissmed | hello, someone can help me ! I want to know ho i can display the consol with php opencloud 'openstack' | 16:03 |
*** narengan has quit IRC | 16:06 | |
*** EinstCrazy has quit IRC | 16:09 | |
*** dikonoor has joined #openstack-keystone | 16:11 | |
*** pcaruana has quit IRC | 16:11 | |
*** permalac has quit IRC | 16:12 | |
*** adrian_otto has joined #openstack-keystone | 16:12 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone-specs: Simplify manage-migration spec by introducing read-only mode https://review.openstack.org/351798 | 16:15 |
stevemar | of course, the one time i book with delta.... | 16:19 |
*** code-R has joined #openstack-keystone | 16:22 | |
*** code-R_ has joined #openstack-keystone | 16:23 | |
*** slberger has quit IRC | 16:24 | |
lbragstad | amakarov ping! | 16:24 |
amakarov | lbragstad, o/ | 16:24 |
lbragstad | amakarov do you mind if we abandon https://review.openstack.org/#/c/324029/ since https://review.openstack.org/#/c/340074/ merged? | 16:25 |
patchbot | lbragstad: patch 324029 - keystone - Add failed auth attempts logic to meet PCI-DSS | 16:25 |
patchbot | lbragstad: patch 340074 - keystone - PCI-DSS Lockout requirements (MERGED) | 16:25 |
amakarov | lbragstad, do I have a choice? )) | 16:25 |
lbragstad | amakarov ha - I was just making sure there wasn't something else in there that needed to be done? | 16:26 |
lbragstad | amakarov I was looking through the last review PCI patches and I saw that one still open | 16:26 |
*** code-R has quit IRC | 16:26 | |
amakarov | lbragstad, Ron did that his way and I support that - 1 man doing 1 feature | 16:26 |
lbragstad | amakarov cool | 16:27 |
amakarov | lbragstad, of course abandon that | 16:27 |
lbragstad | amakarov sounds good - thanks for confirming :) | 16:27 |
amakarov | lbragstad, and since you are here: https://review.openstack.org/#/c/309146/ | 16:27 |
patchbot | amakarov: patch 309146 - keystone - Pre-cache new tokens | 16:27 |
amakarov | do you performance test bot enables caching for tests? | 16:28 |
amakarov | lbragstad, and where can I find it :) | 16:28 |
stevemar | amakarov: https://github.com/lbragstad/keystone-performance | 16:28 |
*** catintheroof has joined #openstack-keystone | 16:28 | |
*** doug-fish has joined #openstack-keystone | 16:29 | |
lbragstad | amakarov we use totally upstream openstack-ansible to standup keystone | 16:29 |
*** david-lyle_ has joined #openstack-keystone | 16:29 | |
lbragstad | amakarov which is all here - https://github.com/openstack/openstack-ansible-os_keystone | 16:30 |
amakarov | lbragstad, the thing is: was my patch tested with caching enabled or not? It's value depends on it | 16:30 |
lbragstad | amakarov token caching? | 16:31 |
lbragstad | i believe so | 16:31 |
*** slberger has joined #openstack-keystone | 16:31 | |
lbragstad | caching is enabled by default in keystone I think | 16:32 |
*** david-lyle has quit IRC | 16:33 | |
amakarov | lbragstad, if I test it on vanilla devstack - will I have the same keystone settings? | 16:33 |
lbragstad | amakarov nope - probably not | 16:33 |
Nissmed | hello, someone can help please ! I want to know ho i can display the consol with php opencloud 'openstack' | 16:33 |
lbragstad | devstack and openstack-ansible are both opinioned deployment tools for openstack | 16:33 |
*** gyee has joined #openstack-keystone | 16:33 | |
*** tonytan4ever has quit IRC | 16:34 | |
amakarov | lbragstad, so I need an env deployed with openstack-ansible? | 16:34 |
lbragstad | amakarov yeah - you could | 16:34 |
*** tonytan4ever has joined #openstack-keystone | 16:34 | |
amakarov | lbragstad, thank you for directions | 16:36 |
lbragstad | amakarov i believe the openstack-ansible folks have some good documentation on deploying | 16:37 |
prometheanfire | :D | 16:37 |
*** tonytan_brb has joined #openstack-keystone | 16:37 | |
lbragstad | amakarov absolutely! | 16:37 |
lbragstad | amakarov my performance stuff setups a local keystone deployment | 16:37 |
lbragstad | using the keystone role | 16:37 |
lbragstad | amakarov speaking of openstack-ansible, meet prometheanfire :) | 16:37 |
prometheanfire | lol, I mostly do rpc-o but close enough | 16:38 |
*** tonytan4ever has quit IRC | 16:38 | |
*** esp has joined #openstack-keystone | 16:38 | |
amakarov | lbragstad, you mean that smiling man above? ) | 16:38 |
amakarov | prometheanfire, hi! | 16:38 |
prometheanfire | laughing man, sure | 16:38 |
amakarov | can you please point me a row that specifies that token caching is enabled? | 16:39 |
prometheanfire | in master? | 16:40 |
*** roxanaghe has quit IRC | 16:40 | |
*** roxanaghe has joined #openstack-keystone | 16:41 | |
amakarov | prometheanfire, I want to find out why my shiny-brilliant-performance-boosting patch has next to no effect https://review.openstack.org/#/c/309146/ :) | 16:41 |
patchbot | amakarov: patch 309146 - keystone - Pre-cache new tokens | 16:41 |
amakarov | prometheanfire, so I try to figure out the setup of performance testing env | 16:42 |
prometheanfire | you want to set up a test env to make sure your patch works? | 16:42 |
amakarov | prometheanfire, yes | 16:43 |
*** Nissmed has left #openstack-keystone | 16:43 | |
prometheanfire | easiest way is to set up an AIO | 16:43 |
amakarov | prometheanfire, and right now I'm deploying devstack for that | 16:43 |
amakarov | AIO? | 16:43 |
prometheanfire | all in one | 16:44 |
prometheanfire | https://developer.rackspace.com/blog/life-without-devstack-openstack-development-with-osa/ | 16:44 |
amakarov | okay... so devstack... | 16:44 |
*** jpena is now known as jpena|off | 16:44 | |
prometheanfire | basically | 16:44 |
prometheanfire | I don't think anyone has made updated docs for our split out stuff | 16:44 |
amakarov | prometheanfire, it's sooo slow ( | 16:44 |
prometheanfire | OSA is better in my experience at least | 16:45 |
amakarov | prometheanfire, is there any "step-by-step OSA for dummies" available? | 16:46 |
prometheanfire | http://docs.openstack.org/developer/openstack-ansible/ | 16:46 |
prometheanfire | the newton section most likely | 16:47 |
*** amoralej is now known as amoralej|off | 16:47 | |
*** code-R has joined #openstack-keystone | 16:47 | |
*** code-R_ has quit IRC | 16:48 | |
*** tesseract- has quit IRC | 16:57 | |
*** amakarov has quit IRC | 17:00 | |
*** browne has joined #openstack-keystone | 17:03 | |
*** amakarov has joined #openstack-keystone | 17:03 | |
*** sdake_ has joined #openstack-keystone | 17:13 | |
*** sdake has quit IRC | 17:15 | |
*** daemontool has joined #openstack-keystone | 17:16 | |
*** narengan1 has quit IRC | 17:23 | |
*** diazjf has joined #openstack-keystone | 17:23 | |
henrynash | dolphm: hi...I added your RO upgrade proposal to tomorrow's agenda....so we have a slot if we need one | 17:24 |
*** edmondsw has joined #openstack-keystone | 17:28 | |
*** ezpz has quit IRC | 17:36 | |
*** nishaYadav has joined #openstack-keystone | 17:37 | |
* nishaYadav o/ | 17:37 | |
*** dikonoor has quit IRC | 17:37 | |
openstackgerrit | Merged openstack/keystonemiddleware: Updated from global requirements https://review.openstack.org/352322 | 17:39 |
*** diazjf has quit IRC | 17:41 | |
*** code-R has quit IRC | 17:41 | |
*** Nakato has quit IRC | 17:41 | |
*** david-lyle_ has quit IRC | 17:42 | |
*** Nakato has joined #openstack-keystone | 17:42 | |
*** Gorian_ has joined #openstack-keystone | 17:43 | |
ayoung | stevemar, notmorgan, Ever test Federation code behind HA Proxy? | 17:45 |
*** david-lyle has joined #openstack-keystone | 17:45 | |
ayoung | jdennis, BTW, does it make sense that mod_auth_mellon should check the Destination against its copy of the metadata instead of against a host URL it builds? | 17:47 |
notmorgan | ayoung: nope. | 17:48 |
ayoung | notmorgan, I know you were doing a lot with HA proxy. We've hit a bit of a speedbump here. | 17:48 |
ayoung | notmorgan, it seems that HA proxy likes things that start with https, but apache is doing things with http. If they are in headers, HA proxy can translate, but SAML puts things into the body of the messages that also need to be confirmed | 17:49 |
ayoung | I've got the problems limited down to http vs https | 17:50 |
*** dikonoor has joined #openstack-keystone | 17:50 | |
notmorgan | ayoung: haven't even tried. | 17:50 |
ayoung | notmorgan, ok...we'll get it | 17:50 |
notmorgan | the simplest solution might be to avoid that all together and TLS haproxy->apache | 17:51 |
notmorgan | i know it costs more cpu to do so | 17:51 |
jdennis | ayoung: I'm not sure I understand your question, it has to use the URL's in the metadata, that is the trusted piece of information | 17:51 |
ayoung | notmorgan, that is one thing we are considering | 17:52 |
ayoung | jdennis, but that is not what it is checking | 17:52 |
notmorgan | but it *is* the simplest. | 17:52 |
ayoung | it is doing | 17:52 |
ayoung | url = am_reconstruct_url(r); | 17:52 |
openstackgerrit | Eric Brown proposed openstack/keystone: Removal of deprecated direct driver loading https://review.openstack.org/350815 | 17:52 |
ayoung | notmorgan, yes, for us, but might not be a viable solution for everyone. It means you are encryting for local traffic, too which may be more expense than people want. But, yeah, that was my first thought, and probably what I will go with. | 17:53 |
jdennis | ayoung: sorry, not being clear, in this case the destination is set from the SP metadata by the IdP, SAML requires the endpoint the message was received on matches that, so am_reconstruct_url should (in theory) be the endpoint the message was received on | 17:54 |
notmorgan | ayoung: not always. you could run a VHOST just for ssl for HAproxy and have a non-TLS vhost for everything else. | 17:54 |
gyee | ayoung, are you hitting the famouse 'BindException' with request url mismatch? | 17:54 |
ayoung | jdennis, so, I am looking to see if, instead of am_reconstruct_url we could pull the AssertionConsumerService Localtion value | 17:55 |
ayoung | gyee, not quite | 17:55 |
*** sdake has joined #openstack-keystone | 17:55 | |
gyee | we hit that one last year, when ssl is terminated at ha proxy | 17:55 |
jdennis | ayoung: no, absolutely not | 17:55 |
ayoung | gyee, we are getting something similary, which is essentailly a string mismatch. The host is OK, it is the https versus http that is messing us up right now | 17:55 |
jdennis | ayoung: that is bypassing the security check | 17:55 |
ayoung | jdennis, why, if it is the local version of the metadata? | 17:56 |
ayoung | it is parsed out of the file. | 17:56 |
gyee | yeah, problem is request URL is signed as part of relay state | 17:56 |
gyee | and signature is being validated at the apache instance | 17:56 |
jdennis | ayoung: no, it's not coming from the local copy on the SP, it's coming from the metadata loaded into the IdP | 17:56 |
gyee | request URL is point to the VIP | 17:56 |
ayoung | jdennis, so, that is not what I am suggesting | 17:56 |
ayoung | there is code that reads and stores it in cfg->sp_metadata_file | 17:57 |
ayoung | it is read from the file system | 17:57 |
*** sdake_ has quit IRC | 17:57 | |
jdennis | ayoung: no, that is not implementing the SAML requirement | 17:57 |
*** diazjf has joined #openstack-keystone | 17:57 | |
*** ravelar has quit IRC | 17:58 | |
ayoung | jdennis, I've not read the requirment, but I assume it is along the lines of "verify that the destination value passed in is the one that you expect" | 17:59 |
ayoung | and the "one that you expect" as defined by mod_auth_mellon today is not the same as what you need if there is a proxy | 17:59 |
jdennis | ayoung: the IdP says "I intend this message to go here (e.g. destination)", the SP must confirm the message was actually received at that endpoint, e.g. what is in the request | 18:00 |
*** code-R has joined #openstack-keystone | 18:00 | |
ayoung | jdennis, right, and the sp needs to determine "hey, what is my name" in order to confirm that. mellon is being to Apache based in answering that. | 18:00 |
jdennis | ayoung: there is a difference between "what you expect" and "what it actually is" | 18:01 |
ayoung | I could see it be a mellon config option "MellonSPUrL" | 18:01 |
ayoung | When I deposit a check to be cashed, I put it in an envelope that is addressed to BofA, not to the Actual name of the Teller behind the window. | 18:02 |
jdennis | ayoung: there isn't one "MellonSPUrl", there are many, all are in the SP metadata | 18:02 |
*** julim has quit IRC | 18:04 | |
jdennis | ayoung: there is no point in trying to reinvent the SAML specification, it's very clear on the requirements and until proven otherwise I believe Mellon is enforcing the requirement | 18:04 |
ayoung | jdennis, so why is it a problem if mod_auth_mellon reads those values out of its local config as opposed to regenerating it from what Apache thinks it is? | 18:05 |
*** doug-fish has quit IRC | 18:05 | |
*** dikonoor has quit IRC | 18:05 | |
ayoung | the spec can't say "you have to call ap_reconstruct_url" it has to be more generic than that | 18:05 |
*** julim has joined #openstack-keystone | 18:05 | |
jdennis | ayoung: because it's the difference between what is expected (what is in some copy of the metadata) and what is actually received | 18:07 |
jdennis | ayoung: it's akin to man-in-the-middle checks | 18:08 |
*** ravelar has joined #openstack-keystone | 18:09 | |
ayoung | jdennis, but in this case, mod_auth_mellon would be confirming that the value it got back matches what it expects. It just is a different definition of how to determine what it expects. | 18:09 |
*** daemontool has quit IRC | 18:10 | |
ayoung | <import namespace="urn:oasis:names:tc:SAML:2.0:assertion" | 18:10 |
ayoung | schemaLocation="saml-schema-assertion-2.0.xsd"/> | 18:10 |
ayoung | <import namespace="http://www.w3.org/2000/09/xmldsig#" | 18:10 |
ayoung | schemaLocation="http://www.w3.org/TR/2002/REC-xmldsig-core- | 18:10 |
ayoung | 20020212/xmldsig-core-schema.xsd"/> | 18:10 |
ayoung | <annotation> | 18:10 |
ayoung | <documentation> | 18:10 |
ayoung | Document identifier: saml-schema-protocol-2.0 | 18:10 |
ayoung | Location: http://docs.oasis-open.org/security/saml/v2.0/ | 18:10 |
ayoung | Revision history: | 18:10 |
ayoung | V1.0 (November, 2002): | 18:10 |
ayoung | Initial Standard Schema. | 18:10 |
ayoung | V1.1 (September, 2003): | 18:10 |
ayoung | Updates within the same V1.0 namespace. | 18:10 |
ayoung | V2.0 (March, 2005): | 18:10 |
ayoung | New protocol schema based in a SAML V2.0 namespace. | 18:10 |
ayoung | </documentation> | 18:10 |
ayoung | </annotation> | 18:10 |
ayoung | ... | 18:10 |
ayoung | </schema> | 18:10 |
ayoung | 3.2 | 18:10 |
ayoung | Requests | 18:10 |
ayoung | and Responses | 18:11 |
ayoung | The following secti | 18:11 |
ayoung | ons define the SAML constru | 18:11 |
ayoung | cts and basic | 18:11 |
ayoung | require | 18:11 |
ayoung | ments that underlie all of the request | 18:11 |
ayoung | and respon | 18:11 |
ayoung | se messages used in SAML protocols. | 18:11 |
ayoung | 3.2.1 | 18:11 |
ayoung | Complex T | 18:11 |
ayoung | ype Request | 18:11 |
ayoung | AbstractT | 18:11 |
ayoung | ype | 18:11 |
ayoung | All SAML requests are of types that are derived from the abstract | 18:11 |
ayoung | Request | 18:11 |
ayoung | AbstractType | 18:11 |
ayoung | complex type. | 18:11 |
ayoung | This type defines common attributes and elements that are associated | 18:11 |
ayoung | with all SAML request | 18:11 |
ayoung | s: | 18:11 |
ayoung | Note: | 18:11 |
ayoung | The | 18:11 |
ayoung | < | 18:11 |
ayoung | RespondWith | 18:11 |
ayoung | > | 18:11 |
ayoung | element has been removed from | 18:11 |
ayoung | RequestAbstractType | 18:11 |
ayoung | for V2.0 of SAML. | 18:11 |
ayoung | ID | 18:12 |
ayoung | [Requi | 18:12 |
ayoung | red] | 18:12 |
ayoung | An identifier for the request. It is of type | 18:12 |
ayoung | xs: | 18:12 |
ayoung | ID | 18:12 |
ayoung | and MUST follow the requi | 18:12 |
ayoung | rements specified | 18:12 |
ayoung | in Section | 18:12 |
ayoung | 1.3.4 | 18:12 |
ayoung | for identifier uniqueness. The values of the | 18:12 |
ayoung | ID | 18:12 |
ayoung | attribute in a request | 18:12 |
ayoung | and the | 18:12 |
ayoung | InResponseTo | 18:12 |
ayoung | attribute in the corresponding | 18:12 |
ayoung | respon | 18:12 |
ayoung | se MUST match. | 18:12 |
ayoung | Version | 18:12 |
ayoung | [Requi | 18:12 |
ayoung | red] | 18:12 |
ayoung | The version of this request. | 18:12 |
ayoung | The identifier for the version of SAML defined in this specification is "2.0". | 18:12 |
ayoung | SAML versioning is d | 18:12 |
ayoung | iscussed in Section | 18:12 |
ayoung | 4 | 18:12 |
ayoung | . | 18:12 |
ayoung | IssueInstant | 18:12 |
ayoung | [Requi | 18:13 |
ayoung | red] | 18:13 |
ayoung | The time instant of issue of the request. | 18:13 |
jdennis | ayoung: what did you paste into chat? It's long and coming through in slow tiny snippets | 18:13 |
ayoung | The time value is encoded in | 18:13 |
ayoung | UTC, as described in | 18:13 |
ayoung | Section | 18:13 |
ayoung | 1.3.3 | 18:13 |
ayoung | . | 18:13 |
ayoung | Destination | 18:13 |
ayoung | [Optional] | 18:13 |
*** doug-fish has joined #openstack-keystone | 18:13 | |
ayoung | A URI reference indicating the add | 18:13 |
ayoung | ress to which this request has been sent. | 18:13 |
ayoung | This is useful to prevent | 18:13 |
ayoung | malicious | 18:13 |
ayoung | forwarding of request | 18:13 |
ayoung | s to unintende | 18:13 |
ayoung | d recipients, a protection that is requi | 18:13 |
ayoung | red by some | 18:13 |
ayoung | protocol | 18:13 |
ayoung | bindings. If it is present, | 18:13 |
ayoung | the actual recipient M | 18:13 |
ayoung | Ah Sorry | 18:13 |
ayoung | Sorry to the whole room for that misclick...was not supposed to be in this window | 18:13 |
ayoung | jdennis, anyway, I was looking at the spec: https://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf | 18:13 |
ayoung | and what it says can be read if you read up in my crapflood about 10 lines to where it starts Destination | 18:13 |
ayoung | jdennis, I did not mean to paste that in to chat. It came from a PDF I was looking at and accidentally highlighted | 18:13 |
ayoung | jdennis, I was reading https://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf | 18:13 |
openstackgerrit | Merged openstack/keystone: remove test utilities related to adding extensions https://review.openstack.org/351979 | 18:14 |
jdennis | ayoung: yes, I know what it says, I've reread over the weekend and again this morning | 18:14 |
ayoung | jdennis, I'll defer to you, but I do not see how reading the value from a config file could lead to a MITM attack. | 18:15 |
ayoung | Now, I would agree that if it used the metadata as send in the SAML handshake across the wire, that would be untrustworthy | 18:15 |
*** adrian_otto has quit IRC | 18:16 | |
jdennis | ayoung: "the Destination XML attribute in the root SAML element of the protocol message MUST contain the URL to which the sender has instructed the user agent to deliver the message. The recipient MUST then verify that the value matches the location at which the message has been received." | 18:17 |
jdennis | ayoung: it's the last 4 words here that are the issue, Mellon is verifying where it was received | 18:18 |
SamYaple | /kick ayoung spam | 18:18 |
jdennis | that is where the reconstruct_url is coming into play based off Apache's request rec | 18:18 |
jdennis | k | 18:19 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/351988 | 18:20 |
*** doug-fish has quit IRC | 18:20 | |
ayoung | SamYaple, sorry | 18:22 |
ayoung | SamYaple, it was a bad compibantion of clicking in the wrong window and PDF forcing through newlines | 18:22 |
ayoung | SamYaple, coupled by the fact that I had highlighted more than I really wanted...it ended up very ugly | 18:23 |
ayoung | jdennis, I see no problem with mod_auth_mellon reading its copy of the metadata file for the url to confirm. It is a local config file at that point. | 18:24 |
ayoung | jdennis, anyway, gotta go pick up my son...Summer schedule only for one more week after this... | 18:25 |
SamYaple | ayoung: it gets me too. two paste buffers and i dont always paste the correct one | 18:26 |
*** ayoung has quit IRC | 18:27 | |
*** Ephur has quit IRC | 18:40 | |
*** ravelar has quit IRC | 18:43 | |
notmorgan | i... | 18:43 |
notmorgan | wow | 18:43 |
* stevemar waves at notmorgan: | 18:45 | |
notmorgan | i came back to ayoung's misclick :P | 18:45 |
*** narengan has joined #openstack-keystone | 18:47 | |
*** tsufiev_ has joined #openstack-keystone | 18:49 | |
*** tsufiev has quit IRC | 18:49 | |
*** Anticime1 has joined #openstack-keystone | 18:50 | |
*** mtreinish_ has joined #openstack-keystone | 18:50 | |
*** Kimmo___ has joined #openstack-keystone | 18:50 | |
*** rderose_ has joined #openstack-keystone | 18:50 | |
*** gsilvis_ has joined #openstack-keystone | 18:50 | |
*** sto_ has joined #openstack-keystone | 18:50 | |
*** ianw_ has joined #openstack-keystone | 18:50 | |
*** dancn` has joined #openstack-keystone | 18:50 | |
*** mfisch` has joined #openstack-keystone | 18:50 | |
*** ntpttr has quit IRC | 18:50 | |
*** mfisch has quit IRC | 18:50 | |
*** ianw has quit IRC | 18:50 | |
*** mtreinish has quit IRC | 18:50 | |
*** Dave has quit IRC | 18:50 | |
*** Anticimex has quit IRC | 18:50 | |
*** sto has quit IRC | 18:50 | |
*** nikhil has quit IRC | 18:50 | |
*** rderose has quit IRC | 18:50 | |
*** david_cu has quit IRC | 18:50 | |
*** dancn has quit IRC | 18:50 | |
*** gsilvis has quit IRC | 18:50 | |
*** henrynash has quit IRC | 18:50 | |
*** Kimmo__ has quit IRC | 18:50 | |
*** ntpttr- has joined #openstack-keystone | 18:50 | |
*** Dave__ has joined #openstack-keystone | 18:50 | |
*** mtreinish_ is now known as mtreinish | 18:50 | |
*** ianw_ is now known as ianw | 18:50 | |
*** henrynash has joined #openstack-keystone | 18:50 | |
*** gsilvis_ is now known as gsilvis | 18:51 | |
*** nikhil has joined #openstack-keystone | 18:52 | |
*** code-R has quit IRC | 18:56 | |
*** code-R has joined #openstack-keystone | 18:59 | |
prometheanfire | stevemar: dolphm said you are doing it wrong | 19:00 |
prometheanfire | kthnx | 19:00 |
prometheanfire | s/\./_/ | 19:00 |
*** roxanaghe has quit IRC | 19:04 | |
*** fifieldt has quit IRC | 19:07 | |
*** narengan has quit IRC | 19:10 | |
*** fifieldt has joined #openstack-keystone | 19:17 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/python-keystoneclient: Remove deprecated 'data' credential argument https://review.openstack.org/352567 | 19:20 |
*** narengan has joined #openstack-keystone | 19:20 | |
samueldmq | stevemar: dolphm: this ^ removes something that was supposed to be removed in ksc 2.0.0 | 19:20 |
samueldmq | I created a bug for tracking it, as I was not sure a blueprint or something else was needed | 19:20 |
*** Ephur has joined #openstack-keystone | 19:22 | |
*** diazjf1 has joined #openstack-keystone | 19:31 | |
*** diazjf has quit IRC | 19:35 | |
*** edmondsw has quit IRC | 19:42 | |
*** jistr has quit IRC | 19:44 | |
bknudson | why aren't reviews adequate for tracking? | 19:46 |
*** nikhil has quit IRC | 19:47 | |
*** nikhil has joined #openstack-keystone | 19:47 | |
*** tsufiev_ is now known as tsufiev | 19:47 | |
*** jistr has joined #openstack-keystone | 19:48 | |
samueldmq | bknudson: they are. but for release notes we need a bug/bp afaik | 19:50 |
bknudson | I disagree that a bug is needed for release notes. | 19:51 |
bknudson | or a blueprint | 19:51 |
samueldmq | ok I may be wrong then | 19:51 |
samueldmq | I will remove the bug | 19:52 |
bknudson | I just don't want to see people wasting their time maintaining bug reports. | 19:53 |
*** jistr has quit IRC | 19:53 | |
bknudson | We need to publicize problems. That's what bugs are for. | 19:53 |
samueldmq | bknudson: that makes sense | 19:53 |
*** itisha has joined #openstack-keystone | 19:56 | |
*** jistr has joined #openstack-keystone | 19:56 | |
*** adrian_otto has joined #openstack-keystone | 19:57 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/python-keystoneclient: Remove deprecated 'data' credential argument https://review.openstack.org/352567 | 19:58 |
samueldmq | bknudson: ^ thanks | 19:58 |
*** roxanaghe has joined #openstack-keystone | 20:06 | |
bknudson | back to thinking about the caching problem -- what if we put the original key in the value. Then the code could check the original key matched the given key. | 20:09 |
openstackgerrit | Harini proposed openstack/keystone: EndpointPolicy driver doesn't inherit interface https://review.openstack.org/352586 | 20:14 |
*** narengan1 has joined #openstack-keystone | 20:16 | |
*** tonytan_brb has quit IRC | 20:16 | |
*** narengan has quit IRC | 20:19 | |
*** spzala has quit IRC | 20:25 | |
*** spzala has joined #openstack-keystone | 20:27 | |
*** tqtran has joined #openstack-keystone | 20:29 | |
*** edtubill has joined #openstack-keystone | 20:31 | |
*** sdake has quit IRC | 20:33 | |
*** gyee has quit IRC | 20:46 | |
*** gyee has joined #openstack-keystone | 20:47 | |
*** edmondsw has joined #openstack-keystone | 20:51 | |
*** diazjf1 has quit IRC | 20:55 | |
*** ayoung has joined #openstack-keystone | 20:55 | |
*** ChanServ sets mode: +v ayoung | 20:55 | |
*** raildo has quit IRC | 21:03 | |
*** pauloewerton has quit IRC | 21:06 | |
*** ravelar has joined #openstack-keystone | 21:07 | |
*** haplo37__ has quit IRC | 21:08 | |
*** pnavarro has joined #openstack-keystone | 21:10 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Add basic upgrade documentation https://review.openstack.org/350341 | 21:12 |
*** tonytan4ever has joined #openstack-keystone | 21:17 | |
*** asettle has joined #openstack-keystone | 21:21 | |
*** julim has quit IRC | 21:21 | |
asettle | dstanek lbragstad dolphm - pinging you all in one channel is easier. I'm going through the docs, and I might require config files for certain sections that I cannot find immediately on the federated identity site. | 21:21 |
asettle | Can you guys help me source? | 21:21 |
dolphm | asettle: absolutely | 21:22 |
dolphm | cc- rderose_ ravelar | 21:22 |
*** tonytan4ever has quit IRC | 21:22 | |
*** ravelar has quit IRC | 21:23 | |
dstanek | asettle: shore | 21:23 |
asettle | Cool. So, running through the docs as is. I'm looking at enabling federation within keystone. Step 1: "run keystone under apache" - can I have the command for this. Step 2: "configure apache to user a federation capable authentication method" - configuration file please, and Step 3: "configure federation in keystone" - configuration info for this one too please | 21:23 |
*** haplo37__ has joined #openstack-keystone | 21:23 | |
*** adriant has joined #openstack-keystone | 21:24 | |
dolphm | asettle: there's no command - it's referring to configuring apache with a mod_wsgi virtual host(s) for keystone | 21:24 |
asettle | Ah I see. Makes sense. Cool. As long as "Run keystone under apache" makes sense on its own, happy to move on. | 21:25 |
dolphm | asettle: so, http://docs.openstack.org/mitaka/install-guide-obs/keystone-install.html.wsgi | 21:25 |
asettle | That 404'd me | 21:26 |
dolphm | asettle: whoops http://docs.openstack.org/mitaka/install-guide-obs/keystone-install.html | 21:26 |
asettle | "Configure the apache HTTP server" ? | 21:27 |
dolphm | asettle: oh, yes, i meant to link straight to that section | 21:27 |
asettle | All good :) found it. It'll be easy cause then I can link it up. | 21:27 |
dolphm | asettle: step 2, that's sort of a big step. it's literally install something like shibboleth (libapache2-mod-shib2), configure your apache virtual host to be protected by shib, and setup shib itself | 21:29 |
dolphm | asettle: which is mostly covered here http://docs.openstack.org/developer/keystone/federation/shibboleth.html | 21:29 |
asettle | Okay, cool :) | 21:30 |
dolphm | asettle: and you'd have to follow all of shib's docs https://wiki.shibboleth.net/confluence/display/SHIB2/Installation | 21:30 |
dstanek | lbragstad: whoa, no worky worky | 21:31 |
lbragstad | dstanek did you try set_time_override()? | 21:32 |
asettle | dolphm: why would I have to follow them all? | 21:32 |
dolphm | asettle: i just mean the step implies "setup shibboleth itself, and setup apache to utilize shibboleth" | 21:32 |
asettle | Oh deary. Okay. This is getting web-like. I see :p | 21:32 |
asettle | Is the wiki the best source of install information here? | 21:32 |
dolphm | asettle: yeah, and shibboleth is just one example | 21:32 |
dolphm | asettle: shibboleth's wiki? | 21:33 |
asettle | dolphm: yis | 21:33 |
asettle | So this is all for 'configuring apache to use a federatin capable authentication method' | 21:33 |
asettle | Okay, might have to classify it as one example. Could you name some other examples I could list/ | 21:33 |
asettle | ? * | 21:33 |
dolphm | asettle: it's the best documentation i've found for it | 21:34 |
asettle | Cool :) thank you. | 21:34 |
dolphm | asettle: mod_auth_melon is the other, slightly less popular one in our world https://github.com/UNINETT/mod_auth_mellon | 21:34 |
asettle | Thank you :) | 21:35 |
asettle | Would it be fair to say 'we recommend' shibboleth? | 21:35 |
*** tonytan4ever has joined #openstack-keystone | 21:35 | |
asettle | dolphm: ^ | 21:36 |
openstackgerrit | Nisha Yadav proposed openstack/python-keystoneclient: Add credential functional tests https://review.openstack.org/348557 | 21:39 |
nishaYadav | samueldmq, ^ | 21:39 |
samueldmq | nishaYadav: looking | 21:40 |
nishaYadav | samueldmq, thanks :) | 21:40 |
dolphm | asettle: probably, for now? cc- dstanek | 21:40 |
dstanek | asettle: dolphm: i think so. that's the one most people seem to be using and familiar with | 21:43 |
*** catintheroof has quit IRC | 21:43 | |
dolphm | dstanek: when are we going to be able to recommend pure python? | 21:43 |
asettle | Cool :) cheers. | 21:43 |
dstanek | dolphm: would we ever do that? | 21:44 |
dolphm | dstanek: if it's easier to deploy and operate, why not? | 21:44 |
*** diazjf has joined #openstack-keystone | 21:44 | |
*** pnavarro has quit IRC | 21:45 | |
*** prometheanfire has left #openstack-keystone | 21:46 | |
asettle | Okay, dolphm and dstanek on that third point, "configure federation in keystone" ? | 21:47 |
*** diazjf has quit IRC | 21:48 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Add rolling upgrade documentation https://review.openstack.org/350793 | 21:48 |
*** spzala has quit IRC | 21:49 | |
*** diazjf has joined #openstack-keystone | 21:49 | |
dstanek | asettle: ? | 21:56 |
asettle | Sorry, I'll recontext. | 21:57 |
asettle | Step 3: "configure federation in keystone" - configuration info for this one. It relates to the enabling federation section | 21:58 |
*** narengan1 has quit IRC | 21:58 | |
*** diazjf has quit IRC | 22:00 | |
*** slberger has left #openstack-keystone | 22:00 | |
*** diazjf has joined #openstack-keystone | 22:01 | |
stevemar | dolphm: did you get promoetheanfire all settled? | 22:02 |
*** edtubill has quit IRC | 22:06 | |
asettle | lbragstad: what is this meant to mean? "What do you ean by federation?" | 22:07 |
asettle | Oh wait, nvm, that is obviously 'mean' | 22:07 |
dstanek | asettle: if you told me to use federation i would assume you are just being mean | 22:08 |
asettle | Hhahaha it's not that bad, be nice to old fedo | 22:08 |
dstanek | asettle: http://docs.openstack.org/developer/keystone/federation/federated_identity.html is almost entirely about configuring keystone federation. the extra apache bits, the new apache plugin, and some other stuf | 22:09 |
asettle | dstanek: yah that's where I"m basing my information from | 22:09 |
asettle | But I'm attempting to flesh out some of your steps to ensure that it is applicable for openstack-docs | 22:09 |
asettle | Hence, asking for the config info | 22:10 |
dstanek | asettle: i can get something together for you | 22:12 |
asettle | dstanek: would love it :) thank you. | 22:12 |
*** nisha_ has joined #openstack-keystone | 22:18 | |
*** julim has joined #openstack-keystone | 22:19 | |
*** nishaYadav has quit IRC | 22:20 | |
*** ChanServ sets mode: +v henrynash | 22:21 | |
*** haplo37__ has quit IRC | 22:32 | |
*** gordc has quit IRC | 22:34 | |
*** chlong has quit IRC | 22:35 | |
*** michauds has quit IRC | 22:37 | |
*** asettle has quit IRC | 22:38 | |
*** nisha_ is now known as nishaYadav | 22:42 | |
*** code-R has quit IRC | 22:44 | |
*** code-R has joined #openstack-keystone | 22:44 | |
*** nishaYadav has quit IRC | 22:46 | |
*** diazjf has quit IRC | 22:52 | |
*** code-R has quit IRC | 23:12 | |
*** roxanaghe has quit IRC | 23:18 | |
*** roxanaghe has joined #openstack-keystone | 23:30 | |
*** roxanaghe has quit IRC | 23:31 | |
*** rkrum has joined #openstack-keystone | 23:32 | |
*** markvoelker has quit IRC | 23:39 | |
*** Gorian_ has quit IRC | 23:41 | |
*** richm has quit IRC | 23:43 | |
*** code-R has joined #openstack-keystone | 23:55 | |
*** sdake has joined #openstack-keystone | 23:56 | |
*** esp has quit IRC | 23:56 | |
*** code-R_ has joined #openstack-keystone | 23:57 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!