*** dave-mccowan has joined #openstack-keystone | 00:17 | |
*** guoshan has joined #openstack-keystone | 00:41 | |
*** hoangcx has joined #openstack-keystone | 00:41 | |
morgan_ | mfisch: yep | 00:44 |
---|---|---|
*** guoshan has quit IRC | 00:45 | |
*** catintheroof has quit IRC | 00:47 | |
*** catintheroof has joined #openstack-keystone | 00:48 | |
*** gyee has quit IRC | 00:48 | |
*** catintheroof has quit IRC | 00:52 | |
*** woodster_ has quit IRC | 00:56 | |
*** chris_hultin is now known as chris_hultin|AWA | 00:58 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Test revocation race conditions https://review.openstack.org/227995 | 01:01 |
*** agrebennikov has quit IRC | 01:03 | |
openstackgerrit | Eric Brown proposed openstack/keystone: Remove reference to future removal of saml https://review.openstack.org/397456 | 01:06 |
stevemar | mfisch: i'm around now, still needed? | 01:06 |
stevemar | dstanek: you around? | 01:07 |
*** guoshan has joined #openstack-keystone | 01:21 | |
*** diazjf has joined #openstack-keystone | 01:21 | |
*** diazjf has quit IRC | 01:23 | |
*** davechen_afk is now known as davechen | 01:31 | |
stevemar | SO CLOSE to <100 open changes in keystone repo | 01:36 |
stevemar | ah well | 01:36 |
stevemar | cleaned up a fair bit anyway | 01:36 |
* stevemar goes to pick up sushi | 01:36 | |
*** dave-mccowan has quit IRC | 01:45 | |
*** zhangjl has joined #openstack-keystone | 01:48 | |
*** markvoelker has quit IRC | 01:50 | |
*** kfox1111 is now known as kfox1111_away | 01:51 | |
*** annp has joined #openstack-keystone | 01:56 | |
*** markvoelker has joined #openstack-keystone | 02:19 | |
*** mnaser has quit IRC | 02:24 | |
*** mnaser has joined #openstack-keystone | 02:24 | |
*** namnh has joined #openstack-keystone | 02:37 | |
*** namnh has quit IRC | 02:40 | |
*** namnh has joined #openstack-keystone | 02:40 | |
openstackgerrit | David Stanek proposed openstack/keystone: Deprecate the AdminTokenAuthMiddleware https://review.openstack.org/305287 | 02:42 |
*** tqtran has quit IRC | 02:48 | |
*** links has joined #openstack-keystone | 02:49 | |
*** hoangcx has quit IRC | 03:00 | |
*** nkinder has joined #openstack-keystone | 03:01 | |
*** hoangcx has joined #openstack-keystone | 03:02 | |
*** david_cu has joined #openstack-keystone | 03:02 | |
*** namnh has quit IRC | 03:04 | |
*** jamielennox is now known as jamielennox|away | 03:07 | |
*** GB21 has joined #openstack-keystone | 03:08 | |
*** GB21 has quit IRC | 03:19 | |
*** jamielennox|away is now known as jamielennox | 03:21 | |
*** udesale has joined #openstack-keystone | 03:42 | |
*** g2` has quit IRC | 03:50 | |
*** nicolasbock has quit IRC | 03:54 | |
*** guoshan has quit IRC | 03:54 | |
*** nkinder has quit IRC | 03:56 | |
*** BrAsS_mOnKeY has joined #openstack-keystone | 03:56 | |
*** BrAsS_mOnKeY has quit IRC | 04:11 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone: cache_on_issue default to true https://review.openstack.org/383333 | 04:13 |
*** jamielennox is now known as jamielennox|away | 04:15 | |
*** jamielennox|away is now known as jamielennox | 04:17 | |
openstackgerrit | Cao Xuan Hoang proposed openstack/keystoneauth: Using assertIsNotNone() instead of assertNotEqual(None) https://review.openstack.org/397521 | 04:38 |
*** jamielennox is now known as jamielennox|away | 04:40 | |
*** r1chardj0n3s is now known as r1chardj0n3s_afk | 04:40 | |
*** guoshan has joined #openstack-keystone | 04:45 | |
*** guoshan has quit IRC | 04:49 | |
*** jamielennox|away is now known as jamielennox | 05:03 | |
*** khamtamtun has joined #openstack-keystone | 05:04 | |
*** khamtamtun has quit IRC | 05:21 | |
jamielennox | breton: can you have another look at https://review.openstack.org/#/c/382098/8, i think the current way is correct and we need to move on this | 05:23 |
*** adriant has quit IRC | 05:29 | |
openstackgerrit | Jamie Lennox proposed openstack/keystone: Allow fetching an expired token https://review.openstack.org/382098 | 05:29 |
jamielennox | breton: no you're right - still not sure why but in practice it works | 05:31 |
*** guoshan has joined #openstack-keystone | 05:39 | |
*** guoshan has quit IRC | 05:44 | |
*** tqtran has joined #openstack-keystone | 05:48 | |
*** tqtran has quit IRC | 05:52 | |
jamielennox | ptg rooms are sold out already? that's crazy | 05:54 |
*** jaosorior has joined #openstack-keystone | 06:07 | |
*** khamtamtun has joined #openstack-keystone | 06:17 | |
*** guoshan has joined #openstack-keystone | 06:22 | |
*** khamtamtun has quit IRC | 06:35 | |
*** jaosorior has quit IRC | 06:40 | |
*** jaosorior has joined #openstack-keystone | 06:40 | |
*** richm has quit IRC | 06:41 | |
*** nk2527 has quit IRC | 06:42 | |
*** khamtamtun has joined #openstack-keystone | 06:48 | |
*** rcernin has quit IRC | 07:23 | |
*** tobberyd_ has joined #openstack-keystone | 07:31 | |
*** belmoreira has joined #openstack-keystone | 07:33 | |
*** BrAsS_mOnKeY has joined #openstack-keystone | 07:38 | |
morgan_ | jamielennox: wtf... really? | 07:53 |
* morgan_ rolls eyes. | 07:53 | |
morgan_ | oookay, guess if i am going i'll have to do the ol' not-the-conference^wPTG-hotel | 07:54 |
openstackgerrit | Merged openstack/keystone: Remove reference to future removal of saml https://review.openstack.org/397456 | 07:58 |
*** pcaruana has joined #openstack-keystone | 08:22 | |
*** amoralej|off is now known as amoralej | 08:22 | |
jamielennox | morgan_: no, i think i made a mistake | 08:32 |
jamielennox | if i didn't include saturday before i could get a room | 08:32 |
morgan_ | ah | 08:32 |
jamielennox | but corp rate at the hilton around the block is better so going to do that instead | 08:32 |
breton | the ptg hotel says the rum is USD 185.00 /night | 08:36 |
breton | and hilton on the booking is ~120 | 08:36 |
*** jpich has joined #openstack-keystone | 08:40 | |
jamielennox | lol, my "corp discounted rate" was still 160 | 08:44 |
jamielennox | but it's not the first time i've found the "special rate" to be higher than just getting it from the website | 08:45 |
*** markvoelker has quit IRC | 08:49 | |
*** jaosorior is now known as jaosorior_lunch | 08:52 | |
*** zzzeek has quit IRC | 09:00 | |
*** zzzeek has joined #openstack-keystone | 09:00 | |
*** tobberyd_ has quit IRC | 09:08 | |
*** mvk has quit IRC | 09:13 | |
*** pnavarro has joined #openstack-keystone | 09:14 | |
*** mvk has joined #openstack-keystone | 09:15 | |
*** openstackgerrit has quit IRC | 09:18 | |
*** openstackgerrit has joined #openstack-keystone | 09:18 | |
*** clsacramento has joined #openstack-keystone | 09:21 | |
*** jperry has joined #openstack-keystone | 09:21 | |
*** jaosorior_lunch is now known as jaosorior | 09:42 | |
*** udesale has quit IRC | 09:45 | |
*** markvoelker has joined #openstack-keystone | 09:49 | |
*** markvoelker has quit IRC | 09:55 | |
*** udesale has joined #openstack-keystone | 09:56 | |
*** hoangcx has quit IRC | 10:06 | |
*** asettle has joined #openstack-keystone | 10:22 | |
*** khamtamtun has quit IRC | 10:39 | |
*** deep_1 has joined #openstack-keystone | 10:51 | |
*** guoshan has quit IRC | 10:52 | |
*** udesale has quit IRC | 10:53 | |
deep_1 | Is there any way to use credentials from ldap for swift and s3 ? I want to avoid openstack credential create for every user from ldap ? | 10:54 |
breton | deep_1: no, because credentials are encrypted by keystone and they are far from users. But it might be a nice feature if you describe your usecase, probably on the openstack-dev mailing list or at our meeting today. | 10:59 |
*** khamtamtun has joined #openstack-keystone | 11:01 | |
*** richm has joined #openstack-keystone | 11:11 | |
*** zhangjl has left #openstack-keystone | 11:14 | |
*** mvk has quit IRC | 11:16 | |
*** guoshan has joined #openstack-keystone | 11:21 | |
*** guoshan has quit IRC | 11:26 | |
*** deep_1 has quit IRC | 11:39 | |
*** nicolasbock has joined #openstack-keystone | 11:42 | |
*** links has quit IRC | 11:43 | |
*** mvk has joined #openstack-keystone | 11:47 | |
*** markvoelker has joined #openstack-keystone | 11:51 | |
*** rodrigods has quit IRC | 11:51 | |
*** rodrigods has joined #openstack-keystone | 11:51 | |
*** iurygregory has joined #openstack-keystone | 11:54 | |
*** markvoelker has quit IRC | 11:55 | |
*** annp has quit IRC | 12:08 | |
*** guoshan has joined #openstack-keystone | 12:16 | |
*** guoshan has quit IRC | 12:20 | |
*** nkinder has joined #openstack-keystone | 12:25 | |
*** catintheroof has joined #openstack-keystone | 12:28 | |
*** nkinder has quit IRC | 12:31 | |
*** deep_1 has joined #openstack-keystone | 12:44 | |
*** dave-mccowan has joined #openstack-keystone | 13:03 | |
*** toabctl has joined #openstack-keystone | 13:07 | |
toabctl | is there a way to tell keystone to use --config-dir with the apache wsgi deployment? | 13:08 |
*** guoshan has joined #openstack-keystone | 13:10 | |
*** nk2527 has joined #openstack-keystone | 13:10 | |
*** guoshan has quit IRC | 13:14 | |
rodrigods | stevemar, ayoung https://review.openstack.org/#/c/397735/1 | 13:15 |
rodrigods | dstanek, ^ | 13:15 |
*** khamtamtun has quit IRC | 13:16 | |
*** lamt has joined #openstack-keystone | 13:16 | |
*** nkinder has joined #openstack-keystone | 13:16 | |
*** lamt has quit IRC | 13:16 | |
stevemar | rodrigods: i thought there was a race condition in the ksc tests? | 13:16 |
rodrigods | stevemar, did you see it again? | 13:17 |
stevemar | hmm | 13:17 |
rodrigods | stevemar, it is non-voting anyway | 13:17 |
stevemar | yeah | 13:17 |
stevemar | does that mean we remove them from ksc gate? | 13:17 |
*** lamt has joined #openstack-keystone | 13:17 | |
rodrigods | stevemar, nope | 13:18 |
*** edmondsw has joined #openstack-keystone | 13:18 | |
openstackgerrit | Ron De Rose proposed openstack/keystone-specs: Extend user API to support federated attributes https://review.openstack.org/397410 | 13:20 |
rodrigods | stevemar, regarding tests, what do you think we propose to have a LDAP gate job as the project for the outreachy student? | 13:20 |
breton | or to gsoc student if we get accepted to gsoc | 13:23 |
*** lamt has quit IRC | 13:24 | |
rodrigods | breton, we have a student for outreachy's next round | 13:24 |
rodrigods | breton, her project is exactly about keystone tests scenarios and infra :) | 13:25 |
*** markvoelker has joined #openstack-keystone | 13:28 | |
*** jdennis has joined #openstack-keystone | 13:30 | |
*** asettle is now known as her-royalness | 13:32 | |
*** spligak has joined #openstack-keystone | 13:34 | |
stevemar | dolphm: can you look at https://bugs.launchpad.net/keystone/+bug/1498556 when you get a chance, you filed it a long time ago and its vague in what it'll take to close the bug | 13:39 |
openstack | Launchpad bug 1498556 in keystoneauth "Reasonable assumptions concerning domain references" [Medium,Triaged] | 13:39 |
dolphm | stevemar: sure | 13:39 |
stevemar | rodrigods: up to you, i was going to start looking at the ldap stuff soon | 13:39 |
stevemar | i wasn't going to create a job | 13:39 |
dolphm | stevemar: how on earth is this vague?! :P | 13:40 |
rodrigods | stevemar, creating the job is enough work i guess - assuming the ldap stuff is ready on devstack | 13:40 |
rodrigods | stevemar, if it needs some fixes, would be nice to have before the project starts :) and is something me and raildo can help out | 13:41 |
dolphm | stevemar: you're talking about the bug where i wrote a short novel about how we should offer a better user experience across the board, yes? | 13:41 |
openstackgerrit | Steve Martinelli proposed openstack/keystone: Reduce revoke events for disabled domains and projects. https://review.openstack.org/253273 | 13:42 |
rodrigods | dolphm, that bug looks like a spec | 13:44 |
rodrigods | a well written spec, btw | 13:44 |
dolphm | i tried to document the way that the default domain was intended to be used - for many users, it's a reasonable assumption. what we have instead is an overly complicated user experience because we have too many options, and as jamie pointed out, we have yet another option to try to make the user experience of having too many options better. | 13:46 |
dolphm | stevemar: ^ | 13:46 |
toabctl | stevemar, any idea how to use --config-dir with the apache wsgi deployment? | 13:47 |
*** crinkle_ has joined #openstack-keystone | 13:48 | |
*** crinkle has quit IRC | 13:49 | |
*** jdennis has quit IRC | 13:52 | |
*** jperry has quit IRC | 13:53 | |
*** her-royalness is now known as asettle | 13:57 | |
*** crinkle_ is now known as crinkle | 13:58 | |
*** khamtamtun has joined #openstack-keystone | 13:58 | |
*** jdennis has joined #openstack-keystone | 13:59 | |
*** udesale has joined #openstack-keystone | 14:00 | |
*** guoshan has joined #openstack-keystone | 14:04 | |
stevemar | jlk: was there something you specifically wanted documented for the healthcheck middleware addition? the bug https://bugs.launchpad.net/keystone/+bug/1640616 was created cause you used DocImpact in the commit message | 14:06 |
openstack | Launchpad bug 1640616 in OpenStack Identity (keystone) " Add healthcheck middleware to pipelines" [Undecided,New] | 14:06 |
*** guoshan has quit IRC | 14:08 | |
*** jperry has joined #openstack-keystone | 14:10 | |
openstackgerrit | David Stanek proposed openstack/keystone: Force SQLite to properly deal with foreign keys https://review.openstack.org/126030 | 14:12 |
dstanek | stevemar: just saw your message from last night | 14:13 |
*** pcaruana has quit IRC | 14:13 | |
*** BrAsS_mOnKeY has quit IRC | 14:16 | |
*** nkinder has quit IRC | 14:16 | |
*** khamtamtun has quit IRC | 14:16 | |
*** nkinder has joined #openstack-keystone | 14:18 | |
*** chris_hultin|AWA is now known as chris_hultin | 14:18 | |
*** BrAsS_mOnKeY has joined #openstack-keystone | 14:22 | |
*** chris_hultin is now known as chris_hultin|AWA | 14:24 | |
openstackgerrit | Merged openstack/keystone: Limits config fixture usage to where it's needed https://review.openstack.org/266399 | 14:25 |
*** BrAsS_mOnKeY has quit IRC | 14:26 | |
*** chris_hultin|AWA is now known as chris_hultin | 14:26 | |
*** BrAsS_mOnKeY has joined #openstack-keystone | 14:27 | |
*** BrAsS_mOnKeY has quit IRC | 14:29 | |
*** BrAsS_mOnKeY has joined #openstack-keystone | 14:30 | |
*** BrAsS_mOnKeY has quit IRC | 14:32 | |
*** jdennis has quit IRC | 14:36 | |
*** jaosorior has quit IRC | 14:36 | |
openstackgerrit | Ron De Rose proposed openstack/keystone-specs: Extend user API to support federated attributes https://review.openstack.org/397410 | 14:41 |
openstackgerrit | Ron De Rose proposed openstack/keystone-specs: Extend user API to support federated attributes https://review.openstack.org/397410 | 14:43 |
*** amoralej is now known as amoralej|lunch | 14:43 | |
*** khamtamtun has joined #openstack-keystone | 14:45 | |
*** BrAsS_mOnKeY has joined #openstack-keystone | 14:49 | |
*** khamtamtun has quit IRC | 14:50 | |
*** tqtran has joined #openstack-keystone | 14:53 | |
*** udesale has quit IRC | 14:54 | |
*** lamt has joined #openstack-keystone | 14:55 | |
*** tqtran has quit IRC | 14:57 | |
*** BrAsS_mOnKeY is now known as g2 | 14:57 | |
*** guoshan has joined #openstack-keystone | 14:58 | |
*** guoshan has quit IRC | 15:02 | |
*** edtubill has joined #openstack-keystone | 15:03 | |
stevemar | lbragstad: can you weigh in on https://bugs.launchpad.net/keystone/+bug/1597077 | 15:17 |
openstack | Launchpad bug 1597077 in OpenStack Identity (keystone) "Mitaka token 'expires' padding differs between POST and GET/HEAD on Fernet tokens" [Medium,Triaged] | 15:17 |
lbragstad | stevemar sure | 15:18 |
ayoung | rodrigods, for somereason, I cannot even +1 that patch | 15:19 |
stevemar | rderose: lbragstad: which of you is following ravelar's work closely? | 15:22 |
stevemar | samueldmq: update https://bugs.launchpad.net/keystone/+bug/1402339 please | 15:25 |
openstack | Launchpad bug 1402339 in OpenStack Identity (keystone) "Status code from HEAD requests must be consistent" [Low,Triaged] | 15:25 |
*** woodburn has joined #openstack-keystone | 15:25 | |
*** jaugustine has joined #openstack-keystone | 15:26 | |
rderose | stevemar: I have been trying to, why? | 15:26 |
rderose | stevemar: especially around the revocation stuff | 15:26 |
*** agrebennikov has joined #openstack-keystone | 15:30 | |
knikolla | o/ | 15:30 |
stevemar | rderose: look at https://bugs.launchpad.net/keystone/+bug/1268751 please | 15:34 |
openstack | Launchpad bug 1268751 in OpenStack Identity (keystone) "Potential token revocation abuse via group membership" [Low,Triaged] | 15:34 |
stevemar | its an old one that may be resolved now | 15:34 |
*** jaugustine has quit IRC | 15:42 | |
*** deep_1 has quit IRC | 15:42 | |
*** adrian_otto has joined #openstack-keystone | 15:43 | |
*** jdennis has joined #openstack-keystone | 15:46 | |
*** openstackgerrit has quit IRC | 15:48 | |
*** openstackgerrit has joined #openstack-keystone | 15:48 | |
*** amoralej|lunch is now known as amoralej | 15:48 | |
*** guoshan has joined #openstack-keystone | 15:52 | |
* breton sighs | 15:56 | |
*** guoshan has quit IRC | 15:57 | |
breton | has the request id chaining ever been implemented? | 15:57 |
breton | dims: maybe you know | 15:57 |
dims | breton : don't think it was ever done fully (with tests( | 15:58 |
*** dave-mccowan has quit IRC | 15:59 | |
breton | dims: was there a cross-project spec, bp or anything else to track? | 15:59 |
*** phalmos has joined #openstack-keystone | 15:59 | |
*** diazjf has joined #openstack-keystone | 16:00 | |
*** nicolasbock has quit IRC | 16:01 | |
*** pcaruana has joined #openstack-keystone | 16:02 | |
*** nicolasbock has joined #openstack-keystone | 16:05 | |
openstackgerrit | Tin Lam proposed openstack/keystone: Enable CADF notification format by default https://review.openstack.org/397339 | 16:07 |
*** g2 has quit IRC | 16:10 | |
*** phalmos has quit IRC | 16:10 | |
*** BrAsS_mOnKeY has joined #openstack-keystone | 16:10 | |
rodrigods | breton, is it the thing that appears in the logs? | 16:16 |
dims | breton : https://github.com/openstack/openstack-specs/blob/master/specs/return-request-id.rst | 16:17 |
*** BrAsS_mOnKeY is now known as g2 | 16:17 | |
openstackgerrit | Gage Hugo proposed openstack/keystone: WIP - Add reason to notification payload https://review.openstack.org/396752 | 16:18 |
*** dave-mccowan has joined #openstack-keystone | 16:18 | |
* breton sighs at https://bugs.launchpad.net/python-openstacksdk/+bug/1465817 | 16:20 | |
openstack | Launchpad bug 1465817 in OpenStack SDK "Provide method to get latest request id" [Medium,Confirmed] | 16:20 |
stevemar | lbragstad: got another bug for you to look at: https://bugs.launchpad.net/keystone/+bug/1433311 | 16:20 |
openstack | Launchpad bug 1433311 in OpenStack Identity (keystone) "Fernet tokens don't support token bind" [Wishlist,Triaged] | 16:20 |
stevemar | breton: it's a mess | 16:20 |
briancurtin | can we just not do that? look in the logs | 16:22 |
*** belmoreira has quit IRC | 16:22 | |
*** jaugustine has joined #openstack-keystone | 16:23 | |
*** kfox1111_away is now known as kfox1111 | 16:28 | |
openstackgerrit | Johannes Grassler proposed openstack/keystone-specs: Added trust-scope-extensions https://review.openstack.org/396331 | 16:28 |
openstackgerrit | Johannes Grassler proposed openstack/keystone-specs: Added spec on standalone trusts https://review.openstack.org/396634 | 16:29 |
stevemar | briancurtin: turns out it was broken in keystoneclient for a year and no one noticed | 16:39 |
stevemar | briancurtin: now we're trying to remove it, and determining if fixing it is a good option | 16:40 |
stevemar | morgan_: ehrm, do you have a minute to look at a betamax failure? http://logs.openstack.org/21/397521/1/check/gate-keystoneauth-python34/33fde2f/testr_results.html.gz | 16:41 |
*** guoshan has joined #openstack-keystone | 16:46 | |
*** diazjf has quit IRC | 16:46 | |
*** chrisplo has joined #openstack-keystone | 16:48 | |
*** guoshan has quit IRC | 16:50 | |
*** tqtran has joined #openstack-keystone | 16:52 | |
*** phalmos has joined #openstack-keystone | 16:56 | |
*** pnavarro has quit IRC | 16:58 | |
*** spzala has joined #openstack-keystone | 16:59 | |
*** kbaikov has joined #openstack-keystone | 16:59 | |
*** phalmos_ has joined #openstack-keystone | 17:00 | |
*** haplo37_ has quit IRC | 17:03 | |
*** phalmos has quit IRC | 17:03 | |
*** diazjf has joined #openstack-keystone | 17:05 | |
*** browne has joined #openstack-keystone | 17:13 | |
*** adrian_otto has quit IRC | 17:15 | |
*** diazjf has quit IRC | 17:16 | |
jlk | stevemar: I misunderstood the docimpact flag. I documented it in the review request. | 17:23 |
*** diazjf has joined #openstack-keystone | 17:24 | |
*** adrian_otto has joined #openstack-keystone | 17:27 | |
*** arunkant has joined #openstack-keystone | 17:32 | |
*** mvk has quit IRC | 17:38 | |
*** guoshan has joined #openstack-keystone | 17:40 | |
*** haplo37 has joined #openstack-keystone | 17:44 | |
*** guoshan has quit IRC | 17:45 | |
*** jpich has quit IRC | 17:51 | |
openstackgerrit | David Stanek proposed openstack/keystone-specs: Add spec for native SAML2 https://review.openstack.org/397860 | 17:52 |
*** diazjf has quit IRC | 17:59 | |
*** edtubill has quit IRC | 17:59 | |
*** henrynash has joined #openstack-keystone | 18:03 | |
*** ChanServ sets mode: +v henrynash | 18:03 | |
edmondsw | can anyone think of a good reason that test_create_trust_without_project_id uses an unscoped token? Seems totally wrong to me | 18:06 |
morgan_ | stevemar: i do once the metting is done | 18:08 |
*** jperry has quit IRC | 18:09 | |
*** asettle has quit IRC | 18:10 | |
*** spilla has joined #openstack-keystone | 18:11 | |
edmondsw | oh, nm | 18:11 |
edmondsw | better question... does it really make sense to try to get a scoped token from an unscoped trust? | 18:29 |
*** guoshan has joined #openstack-keystone | 18:34 | |
*** harlowja has quit IRC | 18:38 | |
*** guoshan has quit IRC | 18:38 | |
*** amoralej is now known as amoralej|off | 18:40 | |
openstackgerrit | Kam Nasim proposed openstack/keystone: Network conn timeout on Identity LDAP backend https://review.openstack.org/390948 | 18:40 |
openstackgerrit | Ron De Rose proposed openstack/keystone-specs: Extend user API to support federated attributes https://review.openstack.org/397410 | 18:40 |
*** knikolla has left #openstack-keystone | 18:49 | |
*** gyee has joined #openstack-keystone | 18:54 | |
*** spzala has quit IRC | 19:00 | |
morgan_ | stevemar: eeeuuuwww on that betamax failure | 19:01 |
*** rcernin has joined #openstack-keystone | 19:02 | |
ayoung | morgan_, lbragstad on the RBAC spec I proposed...would it make more sense to push for code that can be run inside of middleware based on fetching the URL pattern matching info from Keystone? It means that all the caching we now do will still work | 19:02 |
morgan_ | ayoung: let me re-read that sentence | 19:03 |
morgan_ | i see words... but strung together like that... my brain isn't parsing it | 19:03 |
morgan_ | ok still not making sense | 19:03 |
jamielennox | stevemar, breton: can you guys give https://review.openstack.org/#/c/382098/ another pass? would like to merge that soon | 19:03 |
morgan_ | care to re-phrase that? | 19:03 |
morgan_ | jamielennox: why are you coding an option for the expired window? | 19:05 |
jamielennox | morgan_: why not? | 19:05 |
morgan_ | jamielennox: it would seem like the requestor should be able to enforce how long expired it wants | 19:05 |
morgan_ | i just don't see a benefit to a hard-limit in this case enforced in keystone | 19:05 |
jamielennox | i would think you have to have some server side enforcement | 19:05 |
morgan_ | the requestor knows the token is expired already | 19:05 |
morgan_ | it specifically asked and can examine the expiry | 19:06 |
jamielennox | amongst other things you still need to purge uuid tokens | 19:06 |
*** harlowja has joined #openstack-keystone | 19:06 | |
morgan_ | for uuid i would just make it an option on the purge | 19:06 |
jamielennox | not really, i think mostly this will be auth_token wanting to know | 19:06 |
morgan_ | right.. so, auth token would (imo) check the expiry | 19:06 |
morgan_ | it's the requestor in this case | 19:06 |
morgan_ | not keystone. | 19:07 |
morgan_ | and the enforcement would be <this task allows expired tokens> | 19:07 |
morgan_ | not really a rejection from auth token or keystone | 19:07 |
morgan_ | jamielennox: if that makes sense? | 19:07 |
jamielennox | i mean i can put something liek that into policy enforcement, but i'm not sure wouldn't sue it | 19:08 |
morgan_ | so step me through how auth token gates this when you need to enforce below auth token | 19:09 |
morgan_ | this seems to work like delay auth decision | 19:09 |
morgan_ | but conditionally | 19:09 |
morgan_ | how does auth token know if this action is allowed to use an expired token? how does it know what the epxiry extension should be? | 19:09 |
jamielennox | so in my current thinking i don't see any reason to provide that, i'm just saying i can | 19:10 |
jamielennox | why would an action not allow an expired token? | 19:10 |
jamielennox | i wasn't thinking of letting this be a controlled thing, this should just work for everyone | 19:11 |
stevemar | jamielennox: will do | 19:11 |
stevemar | morgan_: thats 2 or 3 betamax failures now :( | 19:12 |
morgan_ | jamielennox: so... we just ignore expiry for <window> for every action | 19:12 |
morgan_ | why don't we just make expiry longer then | 19:12 |
jamielennox | because you can only get the expiry with a service token | 19:13 |
jamielennox | it's only extended after the token enters the system | 19:13 |
morgan_ | euuuw | 19:13 |
jamielennox | is that enlightenment or disgust? | 19:14 |
morgan_ | so i'll then reiterate: why do we have a fixed window? | 19:14 |
* morgan_ wants ramen today | 19:14 | |
jamielennox | because it seems like a bad idea to let these live forever, i don't want 2 week old tokens coming back | 19:15 |
jamielennox | its a problem for fernet key rotation | 19:15 |
jamielennox | and a problem for uuid token storage | 19:15 |
morgan_ | uuid token storage i view as a non-issue | 19:16 |
*** edtubill has joined #openstack-keystone | 19:16 | |
morgan_ | that is easy to address with the purge options | 19:16 |
morgan_ | if the token has been purged... call it a day | 19:16 |
morgan_ | much the same with fernet key rotation | 19:17 |
morgan_ | i mean, is this something we should really make configurable? | 19:17 |
morgan_ | or would a fixed value of say 86400s be sufficient? | 19:17 |
jamielennox | morgan_: i have no idea what that number should be | 19:17 |
jamielennox | i understand reducing the config options | 19:18 |
jamielennox | but i really don't know what that number will settle out as | 19:18 |
morgan_ | i would start with 86400 (1 day0 | 19:18 |
morgan_ | i worry about too many configs and knobs to turn | 19:18 |
morgan_ | options that shouldn't be tuned shouldn't be options. This feels like one of those cases | 19:19 |
morgan_ | jamielennox: ftr, i wont block it because of an option (or even -1 it) | 19:20 |
morgan_ | just making sure we're not adding an option for the sake of making it tunable | 19:20 |
jamielennox | yea, i understand the desire, maybe this is just history but it seems like the sort of thing you owuld tune | 19:21 |
morgan_ | i think the general token expiry is something we've tuned historically | 19:22 |
*** spzala has joined #openstack-keystone | 19:22 | |
morgan_ | but i'm not sure i would expect this value to be tuned. | 19:23 |
*** spzala has quit IRC | 19:23 | |
morgan_ | we want it to be generous and to cover almost all cases in any deployment | 19:23 |
*** spzala has joined #openstack-keystone | 19:23 | |
morgan_ | but not overly generous (e.g your 2 week example) | 19:23 |
stevemar | lbragstad: anything interesting in the meeting? | 19:28 |
lbragstad | stevemar nope - went pretty smooth, we visited about project properties a lot | 19:28 |
*** guoshan has joined #openstack-keystone | 19:28 | |
stevemar | ah | 19:28 |
stevemar | a contentious one | 19:29 |
lbragstad | very :/ | 19:29 |
lbragstad | stevemar i suppose we'll try and cover the rest next week? | 19:29 |
*** guoshan has quit IRC | 19:33 | |
*** diazjf has joined #openstack-keystone | 19:34 | |
*** kbaikov has quit IRC | 19:37 | |
*** kbaikov has joined #openstack-keystone | 19:37 | |
mfisch | stevemar: rderose you guys wnat to talk about the PCI stuff in a few min? | 19:39 |
stevemar | mfisch: sure thing amigo | 19:40 |
*** kbaikov has quit IRC | 19:40 | |
stevemar | lbragstad: we don't need to talk about ALL the specs | 19:40 |
lbragstad | stevemar ok | 19:40 |
stevemar | i am hoping people comment on the reviews | 19:40 |
*** kbaikov has joined #openstack-keystone | 19:40 | |
stevemar | so we are not restricted to hour long segments once per week :) | 19:40 |
lbragstad | stevemar good to know, i wasn't sure if we wanted to do a group review or not | 19:40 |
mfisch | stevemar: whenever Mr Rose is avail | 19:41 |
*** kbaikov has quit IRC | 19:41 | |
mfisch | I have 2 pieces of feedback | 19:41 |
*** phalmos_ has quit IRC | 19:41 | |
mfisch | stevemar: rolled Newton into my lab today | 19:44 |
mfisch | smooth as butta | 19:44 |
morgan_ | stevemar: the betamax thing is weird. | 19:45 |
*** knikolla has joined #openstack-keystone | 19:45 | |
*** knikolla has quit IRC | 19:45 | |
*** knikolla has joined #openstack-keystone | 19:46 | |
stevemar | lbragstad: i kind of expect all the cores to see each spec proposed to ocata at least once | 19:49 |
stevemar | whether or not i'm delusional, we'll find out | 19:49 |
stevemar | mfisch: okay, we can wait for ron, i'm cleaning up an osc patch now anyway | 19:50 |
stevemar | he's probably just on lunch | 19:50 |
mfisch | ok | 19:50 |
jlk | Quick question, project quotas, are those stored in Keystone, or are they stored in individual project databases? | 19:59 |
mfisch | individual projects | 19:59 |
mfisch | jlk: ^ | 20:00 |
jlk | thanks | 20:00 |
mfisch | jlk: cross-region quota mgmt is a real pain | 20:02 |
jlk | I can imagine. | 20:02 |
openstackgerrit | David Stanek proposed openstack/keystone: Fixes remaining nits in endpoint_policy tests https://review.openstack.org/397928 | 20:05 |
*** jperry has joined #openstack-keystone | 20:06 | |
*** chris_hultin is now known as chris_hultin|AWA | 20:06 | |
*** diazjf has quit IRC | 20:13 | |
*** chris_hultin|AWA is now known as chris_hultin | 20:19 | |
*** guoshan has joined #openstack-keystone | 20:23 | |
*** gyee has quit IRC | 20:24 | |
*** guoshan has quit IRC | 20:27 | |
*** browne has quit IRC | 20:30 | |
*** spilla has quit IRC | 20:36 | |
breton | my internets died and i missed the meeting :( | 20:44 |
stevemar | breton: good to see your internets is living again | 20:46 |
*** nk2527 has quit IRC | 20:49 | |
*** browne has joined #openstack-keystone | 21:10 | |
*** adrian_otto has quit IRC | 21:13 | |
*** adrian_otto has joined #openstack-keystone | 21:14 | |
*** guoshan has joined #openstack-keystone | 21:17 | |
*** guoshan has quit IRC | 21:21 | |
*** edtubill has quit IRC | 21:26 | |
*** phalmos has joined #openstack-keystone | 21:31 | |
*** diazjf has joined #openstack-keystone | 21:31 | |
*** spzala has quit IRC | 21:32 | |
*** pcaruana has quit IRC | 21:32 | |
*** spzala has joined #openstack-keystone | 21:32 | |
*** spzala has quit IRC | 21:37 | |
*** adriant has joined #openstack-keystone | 21:40 | |
lbragstad | stevemar dolphm responded - | 21:41 |
lbragstad | https://bugs.launchpad.net/keystone/+bug/1597077 | 21:41 |
openstack | Launchpad bug 1597077 in OpenStack Identity (keystone) "Mitaka token 'expires' padding differs between POST and GET/HEAD on Fernet tokens" [Medium,Triaged] | 21:41 |
*** diazjf has quit IRC | 21:42 | |
stevemar | lbragstad: ah so its confirmed | 21:53 |
stevemar | lbragstad: its different between post and get eh | 21:53 |
stevemar | nasty | 21:53 |
lbragstad | yeah | 21:53 |
*** harlowja has quit IRC | 21:55 | |
*** diazjf has joined #openstack-keystone | 21:57 | |
*** jdennis has quit IRC | 22:01 | |
*** nkinder has quit IRC | 22:05 | |
*** jaugustine has quit IRC | 22:07 | |
*** guoshan has joined #openstack-keystone | 22:11 | |
openstackgerrit | Matthew Edmonds proposed openstack/keystone: admin gets is_admin_project by default https://review.openstack.org/311203 | 22:13 |
*** harlowja has joined #openstack-keystone | 22:13 | |
openstackgerrit | Gage Hugo proposed openstack/keystone: Add reason to notification payload for PCI-DSS https://review.openstack.org/396752 | 22:13 |
*** mvk has joined #openstack-keystone | 22:14 | |
*** guoshan has quit IRC | 22:15 | |
*** catinthe_ has joined #openstack-keystone | 22:18 | |
*** catintheroof has quit IRC | 22:21 | |
*** adrian_otto has quit IRC | 22:28 | |
*** khamtamtun has joined #openstack-keystone | 22:29 | |
*** adrian_otto has joined #openstack-keystone | 22:32 | |
*** catintheroof has joined #openstack-keystone | 22:35 | |
*** catinthe_ has quit IRC | 22:36 | |
*** edmondsw has quit IRC | 22:36 | |
*** rcernin has quit IRC | 22:42 | |
*** adrian_otto has quit IRC | 22:45 | |
*** lamt has quit IRC | 22:48 | |
*** khamtamtun has quit IRC | 22:59 | |
*** jperry has quit IRC | 23:00 | |
*** guoshan has joined #openstack-keystone | 23:05 | |
*** guoshan has quit IRC | 23:09 | |
*** chris_hultin is now known as chris_hultin|AWA | 23:11 | |
*** dave-mccowan has quit IRC | 23:12 | |
*** lamt has joined #openstack-keystone | 23:23 | |
rderose | rderose | 23:29 |
rderose | stevemar mfisch: sorry, stuck in meetings all day | 23:32 |
rderose | stevemar mfisch: perhaps we can touch base tomorrow re PCI | 23:33 |
*** diazjf has quit IRC | 23:34 | |
rderose | stevemar: will look at https://bugs.launchpad.net/keystone/+bug/1268751 and try to reproduce. I'll get back to you on this. | 23:36 |
openstack | Launchpad bug 1268751 in OpenStack Identity (keystone) "Potential token revocation abuse via group membership" [Low,Triaged] - Assigned to Ron De Rose (ronald-de-rose) | 23:36 |
*** lamt has quit IRC | 23:41 | |
*** catintheroof has quit IRC | 23:52 | |
*** catintheroof has joined #openstack-keystone | 23:54 | |
*** lamt has joined #openstack-keystone | 23:55 | |
*** catintheroof has quit IRC | 23:58 | |
*** agrebennikov has quit IRC | 23:59 | |
*** guoshan has joined #openstack-keystone | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!