*** guoshan has quit IRC | 00:02 | |
*** LiYuenan has joined #openstack-keystone | 00:03 | |
*** jerrygb has quit IRC | 00:17 | |
*** haplo37_ has quit IRC | 00:22 | |
*** haplo37_ has joined #openstack-keystone | 00:24 | |
*** PsionTheory has joined #openstack-keystone | 00:33 | |
*** guoshan has joined #openstack-keystone | 00:58 | |
*** guoshan has quit IRC | 01:02 | |
*** guoshan has joined #openstack-keystone | 01:03 | |
*** guoshan has quit IRC | 01:13 | |
*** guoshan has joined #openstack-keystone | 01:14 | |
stevemar | jamielennox: ah, nice comment | 01:38 |
---|---|---|
*** anushkrishnamurt has joined #openstack-keystone | 02:00 | |
*** markvoelker has joined #openstack-keystone | 02:17 | |
*** PsionTheory has quit IRC | 02:30 | |
openstackgerrit | ayoung proposed openstack/keystone-specs: Token Verify Role Check https://review.openstack.org/391624 | 02:37 |
ayoung | stevemar, jamielennox, ^^ interested to see what you think of that. TLDR; add the role check into the token validation call | 02:37 |
*** anushkrishnamurt has quit IRC | 02:40 | |
*** jdennis1 has joined #openstack-keystone | 03:07 | |
*** jdennis has quit IRC | 03:07 | |
guoshan | hi all, are there any api to query tokens expire time? | 03:09 |
guoshan | the exact time for each token expire time, not the config token expire time | 03:10 |
*** jerrygb has joined #openstack-keystone | 03:33 | |
*** jerrygb has quit IRC | 03:37 | |
*** guoshan has quit IRC | 04:24 | |
*** jerrygb has joined #openstack-keystone | 04:37 | |
*** guoshan has joined #openstack-keystone | 04:38 | |
*** guoshan has quit IRC | 04:47 | |
*** guoshan has joined #openstack-keystone | 04:47 | |
*** links has joined #openstack-keystone | 04:48 | |
*** jerrygb has quit IRC | 05:04 | |
*** Nakato has quit IRC | 05:07 | |
*** kiran-r has quit IRC | 05:07 | |
*** Nakato has joined #openstack-keystone | 05:10 | |
openstackgerrit | Xu Ao proposed openstack/oslo.policy: Fix a code logic while doing cyclical reference check to the policy https://review.openstack.org/391370 | 05:32 |
*** guoshan has quit IRC | 05:32 | |
breton | aaand he quit | 05:56 |
*** hoangcx has joined #openstack-keystone | 06:01 | |
*** hoangcx has quit IRC | 06:02 | |
*** hoangcx has joined #openstack-keystone | 06:03 | |
*** guoshan has joined #openstack-keystone | 06:08 | |
*** guoshan_ has joined #openstack-keystone | 06:13 | |
*** guoshan has quit IRC | 06:14 | |
*** guoshan_ has quit IRC | 06:37 | |
*** belmoreira has joined #openstack-keystone | 06:59 | |
*** jerrygb has joined #openstack-keystone | 07:02 | |
*** kiran-r has joined #openstack-keystone | 07:08 | |
*** jerrygb has quit IRC | 07:08 | |
*** kiran-r has quit IRC | 07:09 | |
*** kiran-r has joined #openstack-keystone | 07:09 | |
*** kiran-r has quit IRC | 07:09 | |
*** tesseract has joined #openstack-keystone | 07:11 | |
*** tesseract is now known as Guest58324 | 07:11 | |
*** jaosorior has joined #openstack-keystone | 07:11 | |
*** agrebennikov has joined #openstack-keystone | 07:14 | |
*** agrebennikov has quit IRC | 07:19 | |
*** guoshan has joined #openstack-keystone | 07:37 | |
*** guoshan has quit IRC | 07:42 | |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:00 | |
*** guoshan has joined #openstack-keystone | 08:09 | |
*** beddari has quit IRC | 08:28 | |
*** guoshan has quit IRC | 08:49 | |
*** guoshan has joined #openstack-keystone | 08:49 | |
*** haplo37_ has quit IRC | 09:19 | |
*** haplo37_ has joined #openstack-keystone | 09:21 | |
*** TonyXu has joined #openstack-keystone | 09:31 | |
*** pjm6 has joined #openstack-keystone | 09:42 | |
*** jaosorior has quit IRC | 09:47 | |
*** jaosorior has joined #openstack-keystone | 09:48 | |
*** pjm6 has quit IRC | 10:07 | |
*** pjm6 has joined #openstack-keystone | 10:08 | |
*** LiYuenan has quit IRC | 10:12 | |
*** guoshan has quit IRC | 10:16 | |
*** hoangcx has quit IRC | 10:19 | |
*** rvba has quit IRC | 10:40 | |
*** rvba has joined #openstack-keystone | 10:43 | |
*** rvba has quit IRC | 10:44 | |
*** rvba has joined #openstack-keystone | 10:44 | |
*** TonyXu has quit IRC | 10:50 | |
*** nicolasbock has joined #openstack-keystone | 10:54 | |
*** jerrygb has joined #openstack-keystone | 10:57 | |
*** clayton has quit IRC | 11:10 | |
*** rvba has quit IRC | 11:12 | |
*** clayton has joined #openstack-keystone | 11:12 | |
*** anushkrishnamurt has joined #openstack-keystone | 11:14 | |
*** guoshan has joined #openstack-keystone | 11:17 | |
*** rvba has joined #openstack-keystone | 11:18 | |
*** rvba has quit IRC | 11:18 | |
*** rvba has joined #openstack-keystone | 11:18 | |
*** guoshan has quit IRC | 11:21 | |
*** anushkrishnamurt has quit IRC | 11:36 | |
*** chlong has joined #openstack-keystone | 11:41 | |
*** jerrygb has quit IRC | 12:01 | |
*** clayton has quit IRC | 12:06 | |
*** clayton has joined #openstack-keystone | 12:07 | |
*** ayoung has quit IRC | 12:28 | |
stevemar | o/ | 12:35 |
*** links has quit IRC | 12:50 | |
stevemar | {"url": "http://docs-beta.openstack.org/developer/keystone/federation/federation.html", "status": 404, "referer": "http://docs-beta.openstack.org/developer/keystone/federation/federated_identity.html"}, | 12:51 |
stevemar | {"url": "http://docs-beta.openstack.org/developer/keystone/nogoodresource", "status": 404, "referer": "http://docs-beta.openstack.org/developer/keystone/developing_drivers.html"}, | 12:51 |
stevemar | dead links! | 12:51 |
*** dave-mccowan has joined #openstack-keystone | 12:53 | |
*** jerrygb has joined #openstack-keystone | 13:03 | |
*** jerrygb has quit IRC | 13:07 | |
*** jerrygb has joined #openstack-keystone | 13:11 | |
*** jerrygb has quit IRC | 13:11 | |
*** edmondsw has joined #openstack-keystone | 13:12 | |
dstanek | stevemar: :-( | 13:20 |
lbragstad | morning! | 13:21 |
*** amoralej is now known as amoralej|lunch | 13:22 | |
knikolla | o/ | 13:26 |
dstanek | morning | 13:27 |
*** jperry has joined #openstack-keystone | 13:30 | |
*** jperry has quit IRC | 13:30 | |
*** jperry has joined #openstack-keystone | 13:31 | |
openstackgerrit | Merged openstack/keystone: Pass a request to controllers instead of a context https://review.openstack.org/391609 | 13:38 |
*** nicolasbock has quit IRC | 13:40 | |
*** richm has joined #openstack-keystone | 13:41 | |
*** nicolasbock has joined #openstack-keystone | 13:43 | |
*** ayoung has joined #openstack-keystone | 13:56 | |
*** ChanServ sets mode: +v ayoung | 13:56 | |
*** afred312 has quit IRC | 14:00 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone: Add structure for Devstack plugin https://review.openstack.org/391400 | 14:03 |
stevemar | morning amigos | 14:06 |
lbragstad | stevemar yo | 14:06 |
ayoung | lbragstad, you were sorely missed last week | 14:06 |
ayoung | as was dstanek and bknudson | 14:07 |
lbragstad | ayoung :) i look forward to notes | 14:07 |
ayoung | lbragstad, had a summit epiphany, Thursday night, too late to discuss with the other cores, as I flew on Thursday... | 14:07 |
ayoung | https://review.openstack.org/#/c/391624/ | 14:07 |
stevemar | lbragstad: i'll try and get some stuff posted this week | 14:08 |
*** jerrygb has joined #openstack-keystone | 14:08 | |
ayoung | Lets do the role check for policy as part of the token validation. | 14:08 |
lbragstad | isn't that what we do with validation already? | 14:09 |
lbragstad | we validate a token and the service applies the roles in the policy to the roles in the token validation response | 14:09 |
lbragstad | stevemar awesome - i can't wait to read them | 14:10 |
lbragstad | stevemar i spend last week overhauling http://keystone-performance.lbragstad.com/ | 14:10 |
ayoung | lbragstad, nah, no role validation is done inside the Keystone server, only later | 14:10 |
ayoung | and the only role that is checked now is Admin...except for Keystone with service users | 14:11 |
*** amoralej|lunch is now known as amoralej | 14:11 | |
lbragstad | ayoung if we wanted to move the policy check into the token validation path within keystone wouldn't that mean keystone would need all the policy information for every service? | 14:12 |
ayoung | lbragstad, nope | 14:12 |
ayoung | lbragstad, we leave the existing check in place | 14:13 |
ayoung | we only doi the Role check in keystone | 14:13 |
ayoung | it is the split I was talking about before: | 14:13 |
ayoung | scope check is hard coded | 14:13 |
ayoung | role check is dynamic, and in middleware | 14:13 |
ayoung | by moving it to the Keystone server, we don't have to deal with distribution or caching of the policy files | 14:13 |
ayoung | Role check is addtional to, and prior to, default policy check | 14:14 |
ayoung | but both are still needed | 14:14 |
*** chris_hultin|AWA is now known as chris_hultin | 14:14 | |
lbragstad | ayoung by role check do you mean ensuring the user has a role on the project? | 14:15 |
stevemar | lbragstad: nice | 14:15 |
ayoung | lbragstad, more like ensureing that the role in the token matches the role required for the API, but yes | 14:15 |
stevemar | lbragstad: the bot came up as well as the bug reports you automated, and one suggestion was to keep a running tally | 14:15 |
stevemar | graph it out so we can see the results over time, or something like that | 14:16 |
lbragstad | ayoung so keystone needs to have the policy in order to do that, right? | 14:16 |
stevemar | snapshots in data don't help as much as seeing the overall picture | 14:16 |
lbragstad | stevemar yep - that's what i started doing https://github.com/lbragstad/keystone-performance/tree/master/results | 14:16 |
ayoung | lbragstad, sort of. It needs some policy, but it can be much simpler than the existing policy files | 14:16 |
ayoung | the example I put in the spec it | 14:16 |
lbragstad | stevemar so far i'm keep all data from all runs in source control | 14:16 |
ayoung | GET /v3/users/{user_id}/projects : role:Reader | 14:16 |
stevemar | lbragstad: yep, i saw that :) | 14:16 |
lbragstad | stevemar if people want to graph it differently, they have all the data to do it | 14:17 |
ayoung | So policy check is on Verb and a pattern match of the URL, much like the routes.Mapper does in Keystone | 14:17 |
ayoung | Excuse me, let me be explicit and say the RBAC check | 14:17 |
*** edtubill has joined #openstack-keystone | 14:17 | |
ayoung | we still will have the policy check executed in the code like this: | 14:17 |
ayoung | http://git.openstack.org/cgit/openstack/keystone/tree/etc/policy.json#n45 | 14:18 |
openstackgerrit | Boris Bobrov proposed openstack/keystone: Fix broken links in the docs https://review.openstack.org/391851 | 14:18 |
ayoung | but instead of "admin_required" we make it more forgiving, something that lets an appropriately scoped user in as well. | 14:19 |
stevemar | ayoung: whos the red hat packager / maintainer for openstack bits? | 14:19 |
ayoung | Keystone ones are actually the worst, as they are mostly domain scoped operations. But take role assignments | 14:19 |
dstanek | ayoung: i have to say that i was nice not having to travel :-) | 14:19 |
*** briancurtin has quit IRC | 14:19 | |
ayoung | stevemar, varies. But I have a say in the keystone* ones | 14:20 |
ayoung | dstanek, travel does get tough. See you in Feb in ATL, though | 14:20 |
ayoung | I hope... | 14:20 |
ayoung | stevemar, which package in particular? | 14:20 |
stevemar | ayoung: centos packaging bug reported on the keystone queue: https://bugs.launchpad.net/keystone/+bug/1637850 | 14:20 |
openstack | Launchpad bug 1637850 in OpenStack Identity (keystone) "newton openstack-keystone service not created on Centos7" [Undecided,New] | 14:20 |
ayoung | stevemar, not-a-bug | 14:21 |
dstanek | ayoung: i'm assuming so yes | 14:21 |
ayoung | dstanek, well, I might have a conflict. My wife has a seminar to give, and we both can't travel at the same time.... | 14:21 |
*** d0ugal has joined #openstack-keystone | 14:22 | |
*** briancurtin has joined #openstack-keystone | 14:22 | |
ayoung | stevemar, updated. | 14:23 |
ayoung | are we still having the team meeting tomorrow? I assume yes, but want to make sure | 14:31 |
dstanek | ayoung: that's unfortunate | 14:32 |
ayoung | dstanek, I think I'm clear. I think she is going the following week | 14:32 |
ayoung | Feb 20-24, 2017 is the PTG, and I thin hers is later | 14:33 |
*** jamielennox is now known as jamielennox|away | 14:34 | |
lbragstad | rderose ping? | 14:37 |
lbragstad | rderose curious if you or ravelar have seen https://bugs.launchpad.net/keystone/+bug/1634746 | 14:38 |
openstack | Launchpad bug 1524030 in OpenStack Identity (keystone) "duplicate for #1634746 Reduce revocation events for performance improvement" [Medium,In progress] - Assigned to Ron De Rose (ronald-de-rose) | 14:38 |
ayoung | lbragstad, I just had a thought. We could do the whole thing with implied roles, and drop the RBAC config files. Hmmmm | 14:48 |
*** ravelar has joined #openstack-keystone | 14:53 | |
lbragstad | ayoung how so? | 15:04 |
*** jerrygb has quit IRC | 15:07 | |
*** jerrygb has joined #openstack-keystone | 15:08 | |
ayoung | lbragstad, say the rule was: | 15:09 |
ayoung | er, the role was the URL pattern | 15:09 |
ayoung | hmmm...need a way to make a single string with both the Verb and the pattern | 15:10 |
ayoung | and then we could assign someone exactly that pattern as an assignment, or delegate via trust | 15:10 |
ayoung | so...we create role "GET identity /v3/users" | 15:10 |
ayoung | and Member implies "GET identity /v3/users" | 15:11 |
ayoung | so if you have the top level role, you get the lower level role | 15:11 |
ayoung | instead of having a rule that is "GET identity /v3/users" : role:Member | 15:11 |
ayoung | it would all be via the inference rules. | 15:12 |
lbragstad | hmm | 15:13 |
*** nkinder has joined #openstack-keystone | 15:19 | |
*** guoshan has joined #openstack-keystone | 15:20 | |
ayoung | stevemar, dstanek can I get a go-ahead on https://review.openstack.org/#/c/389783/ | 15:24 |
ayoung | I'm trying to figure out why the backport test failed, but it seems spurious | 15:24 |
*** guoshan has quit IRC | 15:25 | |
*** hyakuhei has quit IRC | 15:25 | |
*** hyakuhei has joined #openstack-keystone | 15:25 | |
*** hyakuhei has quit IRC | 15:25 | |
*** hyakuhei has joined #openstack-keystone | 15:25 | |
dstanek | ayoung: looking | 15:26 |
openstackgerrit | Richard Avelar proposed openstack/keystone: Remove unused statements in matches https://review.openstack.org/387548 | 15:32 |
*** pkoraca has quit IRC | 15:36 | |
*** pkoraca has joined #openstack-keystone | 15:36 | |
*** woodburn has quit IRC | 15:40 | |
stevemar | ayoung: +W | 15:51 |
ayoung | +W? | 15:51 |
stevemar | ayoung: workflow | 15:52 |
ayoung | Ah. Cool | 15:52 |
stevemar | someone want to approve https://review.openstack.org/#/c/391400/ ? | 15:52 |
ayoung | +TYVM | 15:52 |
ayoung | stevemar, looking | 15:53 |
ayoung | stevemar, +W to use your term | 15:55 |
stevemar | :) | 15:55 |
*** browne has joined #openstack-keystone | 15:55 | |
*** aloga_ has joined #openstack-keystone | 15:56 | |
ayoung | knikolla, +A on your patch. And that is the first patch I've +Aedthat, in the past would grant ATC access to the summit that will no longer do so :( | 15:56 |
*** Guest58324 has quit IRC | 15:56 | |
*** woodburn has joined #openstack-keystone | 15:57 | |
*** AlexeyAbashkin has quit IRC | 16:13 | |
*** AlexeyAbashkin has joined #openstack-keystone | 16:15 | |
*** guoshan has joined #openstack-keystone | 16:21 | |
*** kfox1111_ is now known as kfox1111 | 16:23 | |
*** guoshan has quit IRC | 16:25 | |
openstackgerrit | Merged openstack/keystone: Create default role as a part of bootstrap https://review.openstack.org/389783 | 16:27 |
*** links has joined #openstack-keystone | 16:32 | |
*** chlong has quit IRC | 16:32 | |
*** lamt has joined #openstack-keystone | 16:40 | |
openstackgerrit | Merged openstack/keystone: Add structure for Devstack plugin https://review.openstack.org/391400 | 16:40 |
*** links has quit IRC | 16:42 | |
*** ravelar has quit IRC | 16:46 | |
*** richm has quit IRC | 16:47 | |
*** david-lyle has joined #openstack-keystone | 16:51 | |
knikolla | ayoung, thanks for the +A :) | 16:53 |
*** d0ugal has quit IRC | 16:54 | |
*** ravelar has joined #openstack-keystone | 16:55 | |
*** d0ugal has joined #openstack-keystone | 16:58 | |
*** d0ugal has quit IRC | 16:58 | |
*** d0ugal has joined #openstack-keystone | 16:58 | |
*** belmoreira has quit IRC | 16:58 | |
*** jaosorior has quit IRC | 16:59 | |
*** mvk has quit IRC | 17:01 | |
*** gyee has joined #openstack-keystone | 17:05 | |
*** aloga_ has quit IRC | 17:06 | |
*** edtubill has quit IRC | 17:11 | |
openstackgerrit | Gage Hugo proposed openstack/keystone: WIP: remove LDAP write support https://review.openstack.org/374482 | 17:11 |
stevemar | back in a few hours :( | 17:22 |
stevemar | hold down the fort keystoners! | 17:22 |
*** richm has joined #openstack-keystone | 17:23 | |
*** gyee has quit IRC | 17:38 | |
*** dave-mccowan has quit IRC | 17:49 | |
samueldmq | hey keystoners :) | 17:53 |
*** lamt has quit IRC | 17:55 | |
samueldmq | lbragstad: stevemar: dstanek: are we holding on anything specific for patch 345688 ? | 17:55 |
lbragstad | samueldmq yeah - it's dependent on https://review.openstack.org/#/c/376526/6 | 17:56 |
samueldmq | (other than the depends-on patch on devstack?) | 17:56 |
lbragstad | samueldmq nope - that's the only dependency | 17:57 |
samueldmq | lbragstad: 345688 has a depends-on (in the commit message) to https://review.openstack.org/#/c/367052/ (devstack patch) | 17:58 |
lbragstad | samueldmq yep | 17:58 |
lbragstad | so the devstack patch has to merge first | 17:58 |
lbragstad | before we can merge the release note | 17:58 |
lbragstad | once that merges we can approve the switch | 17:58 |
samueldmq | lbragstad: gotcha | 17:59 |
*** asettle has joined #openstack-keystone | 18:00 | |
samueldmq | lbragstad: it is expected that the upgrade Newton -> Ocata is not backwards compat for role creation, right ? | 18:02 |
samueldmq | lbragstad: I remember we had a discussion about it in the past (apparently we had broken a gate), just can't remember the decision | 18:02 |
lbragstad | samueldmq for role creation? | 18:02 |
samueldmq | my bad, token creation | 18:02 |
samueldmq | lbragstad: | 18:02 |
lbragstad | samueldmq token creation is backwards incompatible you mean? | 18:03 |
samueldmq | lbragstad: yes, in the defaults, because of the config change | 18:03 |
lbragstad | it should be compatible if a deployer wants to keep using UUID, they can, but they just have to explicitly say it | 18:03 |
lbragstad | in that case, tokens created using newton should be validatable against Ocata | 18:04 |
samueldmq | lbragstad: sounds fair. the behavior is very well documented in the release notes. | 18:04 |
lbragstad | samueldmq yeah - that's what we're aiming for | 18:04 |
samueldmq | lbragstad: ++ | 18:05 |
*** haplo37_ has quit IRC | 18:08 | |
*** haplo37_ has joined #openstack-keystone | 18:10 | |
*** Zer0Byte__ has joined #openstack-keystone | 18:18 | |
*** dave-mccowan has joined #openstack-keystone | 18:19 | |
*** edtubill has joined #openstack-keystone | 18:29 | |
*** kiran-r has joined #openstack-keystone | 18:30 | |
ayoung | stevemar, a + from you on the bootstrap backport would be much appreciated: https://review.openstack.org/#/c/391678/ | 18:34 |
*** lamt has joined #openstack-keystone | 18:35 | |
ayoung | Disregard | 18:35 |
ayoung | thanks | 18:35 |
*** kiran-r has quit IRC | 18:40 | |
*** edtubill has quit IRC | 18:40 | |
stevemar | ayoung: poke dolphm i suppose | 18:46 |
ayoung | stevemar, sure, or other stable maints. I just didn't see your + at first, and wanted to say that other keystoners had looked at it. THanks | 18:47 |
stevemar | ayoung: rgr | 18:47 |
*** asettle has quit IRC | 18:47 | |
ayoung | stevemar, BTW, I think we should call the Keystone Turtle Mascot 'Stoney' | 18:47 |
stevemar | i like that! | 18:47 |
*** asettle has joined #openstack-keystone | 18:48 | |
*** asettle has quit IRC | 18:48 | |
*** asettle has joined #openstack-keystone | 18:48 | |
*** edtubill has joined #openstack-keystone | 18:49 | |
stevemar | lbragstad: poke https://review.openstack.org/#/c/391069/1 | 18:51 |
*** artmr has joined #openstack-keystone | 18:51 | |
*** asettle has quit IRC | 18:52 | |
*** asettle has joined #openstack-keystone | 18:52 | |
*** kiran-r has joined #openstack-keystone | 18:53 | |
lbragstad | stevemar nice - done | 18:56 |
*** bezilla has joined #openstack-keystone | 19:01 | |
lbragstad | stevemar do we have an outlook on the removal of pki and pkiz? | 19:01 |
stevemar | lbragstad: it needs a rebase :\ https://review.openstack.org/#/c/374479/ | 19:01 |
stevemar | lbragstad: it got all messy cause of the whole PKI being used to get revocation lists business | 19:02 |
lbragstad | ah | 19:03 |
stevemar | lbragstad: feel free to pick it up? | 19:07 |
stevemar | lbragstad: i know breton picked it up at one point | 19:07 |
openstackgerrit | ayoung proposed openstack/keystone: Support AD Nested groups https://review.openstack.org/389316 | 19:26 |
ayoung | What do we need to do to kill PKI? | 19:26 |
*** kiran-r has quit IRC | 19:31 | |
*** ayoung has quit IRC | 19:35 | |
openstackgerrit | Merged openstack/keystone: Clarifying on the remove of `build_auth_context` middleware https://review.openstack.org/391069 | 19:37 |
stevemar | ayoung went offline :( | 19:39 |
lbragstad | I was just about to start responding, too | 19:39 |
lbragstad | ayo<tab><tab><tab> | 19:39 |
openstackgerrit | Jesse Keating proposed openstack/keystone: Add healthcheck middleware to pipelines https://review.openstack.org/387731 | 19:39 |
knikolla | hard to find a review not previously reviewed by stevemar :P | 19:45 |
*** amoralej is now known as amoralej|off | 19:46 | |
openstackgerrit | Merged openstack/keystone: Don't deprecate the LDAP property which is still needed https://review.openstack.org/391077 | 19:48 |
stevemar | knikolla: i am the eye of sauron! | 19:48 |
stevemar | breton: you may want to check your email :) | 19:49 |
*** edtubill has quit IRC | 19:50 | |
*** edtubill has joined #openstack-keystone | 19:51 | |
knikolla | stevemar, can I assume only ubuntu for now for the Devstack plugin, shibboleth is a pain on anything else :( | 19:53 |
stevemar | knikolla: lets start with that then | 19:53 |
knikolla | stevemar, roger. i'll have an initial review that federated with testshib to ensure that the steps are correct. Then a subsequent patch will install a real idp and i'll switch from testshib to that. | 19:55 |
stevemar | sounds promising | 19:56 |
stevemar | i'll start poking at the ldap stuff, dtroyer showed me a few things to look at and some suggestions | 19:56 |
*** edtubill has quit IRC | 19:58 | |
lbragstad | was there an outcome regarding horizon revoking a token after a user switches projects and how that effects long running operations? | 20:03 |
robcresswell | lbragstad: We've removed the token revocation from master | 20:04 |
robcresswell | lbragstad: There is a patch to remove from stable too. | 20:04 |
*** ravelar has quit IRC | 20:04 | |
lbragstad | robcresswell ah - so now if I switch projects in horizon my token won't be revoked, right? | 20:05 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Add api-ref /auth/tokens/OS-PKI/revoked (v3) https://review.openstack.org/390904 | 20:05 |
stevemar | lbragstad: this should be ready https://review.openstack.org/#/c/390904/3 | 20:05 |
robcresswell | lbragstad: Right :) | 20:06 |
lbragstad | robcresswell awesome! | 20:07 |
*** dave-mccowan has quit IRC | 20:15 | |
*** guoshan has joined #openstack-keystone | 20:24 | |
*** kiran-r has joined #openstack-keystone | 20:24 | |
openstackgerrit | Samuel Pilla proposed openstack/keystone: Document v2 Revoked Token Route https://review.openstack.org/390913 | 20:25 |
*** ayoung has joined #openstack-keystone | 20:26 | |
*** ChanServ sets mode: +v ayoung | 20:26 | |
openstackgerrit | Samuel Pilla proposed openstack/keystone: Document v2 Revoked Token Route https://review.openstack.org/390913 | 20:26 |
*** guoshan has quit IRC | 20:28 | |
*** mvk has joined #openstack-keystone | 20:31 | |
*** aloga_ has joined #openstack-keystone | 20:31 | |
*** d0ugal has quit IRC | 20:40 | |
*** d0ugal has joined #openstack-keystone | 20:42 | |
*** dave-mccowan has joined #openstack-keystone | 20:45 | |
*** lamt has quit IRC | 20:47 | |
*** jerrygb__ has joined #openstack-keystone | 20:48 | |
*** jerrygb has quit IRC | 20:49 | |
*** jerrygb__ has quit IRC | 20:52 | |
breton | lbragstad: there is a serie of action items on removing PKI | 20:57 |
breton | lbragstad: morgan had a great plan in that review | 20:57 |
breton | stevemar: cool! I'll do my best. | 20:58 |
*** chris_hultin is now known as chris_hultin|AWA | 21:01 | |
lbragstad | is morgan_ around? | 21:02 |
*** gyee has joined #openstack-keystone | 21:05 | |
*** jamielennox|away is now known as jamielennox | 21:06 | |
*** lamt has joined #openstack-keystone | 21:07 | |
openstackgerrit | Jesse Keating proposed openstack/keystone: Add healthcheck middleware to pipelines https://review.openstack.org/387731 | 21:07 |
*** openstackgerrit has quit IRC | 21:18 | |
*** openstackgerrit has joined #openstack-keystone | 21:18 | |
*** guoshan has joined #openstack-keystone | 21:24 | |
*** guoshan has quit IRC | 21:29 | |
*** edtubill has joined #openstack-keystone | 21:32 | |
*** dave-mccowan has quit IRC | 21:38 | |
stevemar | gagehugo: is samuel pilla on irc? | 21:38 |
stevemar | gagehugo: not sure why he -W'ed https://review.openstack.org/#/c/390913/ | 21:38 |
*** adriant has joined #openstack-keystone | 21:42 | |
lamt | @stevemar : I think he -W'ed because it has the same selector as the v3 patch | 21:44 |
stevemar | lamt: eh, just add a v2 and call it a day | 21:45 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Document v2 Revoked Token Route https://review.openstack.org/390913 | 21:45 |
stevemar | there we go | 21:45 |
lamt | stevemar : thanks, this should be fixed: https://bugs.launchpad.net/openstack-doc-tools/+bug/1583623 so it doesn't conflict as much in the docs | 21:46 |
openstack | Launchpad bug 1583623 in openstack-doc-tools "os-api-ref: duplicate labels for selectors" [Undecided,New] | 21:46 |
*** richm has quit IRC | 21:47 | |
*** aloga_ has quit IRC | 21:48 | |
stevemar | lamt: let's not wait around for it :) | 21:48 |
*** jerrygb has joined #openstack-keystone | 21:59 | |
openstackgerrit | Merged openstack/keystone: Add api-ref /auth/tokens/OS-PKI/revoked (v3) https://review.openstack.org/390904 | 22:01 |
*** jerrygb has quit IRC | 22:04 | |
*** chlong has joined #openstack-keystone | 22:08 | |
stevemar | lbragstad: want to punt this one through? https://review.openstack.org/#/c/385028/ | 22:09 |
*** jperry has quit IRC | 22:19 | |
*** agrebennikov has joined #openstack-keystone | 22:21 | |
*** agrebennikov has quit IRC | 22:22 | |
*** agrebennikov has joined #openstack-keystone | 22:23 | |
*** agrebennikov has quit IRC | 22:23 | |
lbragstad | stevemar yeah i can review it | 22:23 |
*** agrebennikov has joined #openstack-keystone | 22:25 | |
*** guoshan has joined #openstack-keystone | 22:25 | |
*** lamt has quit IRC | 22:27 | |
*** gyee has quit IRC | 22:28 | |
*** agrebennikov has quit IRC | 22:29 | |
*** guoshan has quit IRC | 22:30 | |
stevemar | thanks lbragstad | 22:33 |
*** edmondsw has quit IRC | 22:39 | |
gagehugo | stevemar: yeah what lamt said | 22:41 |
*** jerrygb has joined #openstack-keystone | 22:42 | |
*** jerrygb_ has joined #openstack-keystone | 22:45 | |
*** edtubill has quit IRC | 22:48 | |
*** jerrygb has quit IRC | 22:48 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone-specs: Add reason to notifications for PCI-DSS events https://review.openstack.org/381302 | 22:58 |
openstackgerrit | Steve Martinelli proposed openstack/keystone-specs: Target Fernet key store to Ocata https://review.openstack.org/363065 | 23:00 |
openstackgerrit | Merged openstack/keystone-specs: Target Fernet key store to Ocata https://review.openstack.org/363065 | 23:05 |
*** asettle has quit IRC | 23:11 | |
*** nicolasbock has quit IRC | 23:13 | |
*** artmr has quit IRC | 23:13 | |
*** guoshan has joined #openstack-keystone | 23:26 | |
*** ianw has quit IRC | 23:30 | |
*** guoshan has quit IRC | 23:30 | |
*** browne has quit IRC | 23:36 | |
*** kiran-r has quit IRC | 23:41 | |
*** ianw has joined #openstack-keystone | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!