*** markvoelker has joined #openstack-keystone | 00:46 | |
*** markvoelker has quit IRC | 00:51 | |
*** markvoelker has joined #openstack-keystone | 01:47 | |
*** markvoelker has quit IRC | 01:51 | |
*** david-lyle has joined #openstack-keystone | 02:35 | |
*** david-lyle has quit IRC | 02:39 | |
*** markvoelker has joined #openstack-keystone | 02:48 | |
*** markvoelker has quit IRC | 02:52 | |
*** stingaci has joined #openstack-keystone | 03:01 | |
*** stingaci has quit IRC | 03:05 | |
*** links has joined #openstack-keystone | 03:36 | |
*** markvoelker has joined #openstack-keystone | 03:48 | |
*** markvoelker has quit IRC | 03:53 | |
*** g2 is now known as trump | 04:22 | |
*** trump is now known as trump1 | 04:23 | |
*** trump1 is now known as trumpinanus | 04:28 | |
*** trumpinanus is now known as g22 | 04:31 | |
*** david-lyle has joined #openstack-keystone | 04:36 | |
*** david-lyle has quit IRC | 04:41 | |
*** sheel has joined #openstack-keystone | 04:43 | |
*** markvoelker has joined #openstack-keystone | 04:49 | |
*** markvoelker has quit IRC | 04:53 | |
openstackgerrit | Merged openstack/keystone: Federated authentication via ECP functional tests https://review.openstack.org/324769 | 05:00 |
---|---|---|
openstackgerrit | Steve Martinelli proposed openstack/keystone: Fix import ordering in tempest plugins https://review.openstack.org/413244 | 05:02 |
*** gus has quit IRC | 05:05 | |
*** guoshan has joined #openstack-keystone | 05:07 | |
*** udesale has joined #openstack-keystone | 05:36 | |
*** markvoelker has joined #openstack-keystone | 05:50 | |
*** markvoelker has quit IRC | 05:54 | |
*** Dinesh_Bhor has joined #openstack-keystone | 06:11 | |
*** stingaci has joined #openstack-keystone | 07:03 | |
*** stingaci has quit IRC | 07:08 | |
*** pcaruana has joined #openstack-keystone | 07:23 | |
*** rcernin has joined #openstack-keystone | 07:37 | |
*** martinus__ has joined #openstack-keystone | 07:37 | |
*** rcernin has quit IRC | 07:39 | |
*** rcernin has joined #openstack-keystone | 07:41 | |
*** rcernin has quit IRC | 07:51 | |
*** rcernin has joined #openstack-keystone | 07:52 | |
*** guoshan has quit IRC | 08:08 | |
*** guoshan has joined #openstack-keystone | 08:09 | |
*** xek has joined #openstack-keystone | 08:40 | |
*** zzzeek has quit IRC | 09:00 | |
*** zzzeek has joined #openstack-keystone | 09:00 | |
*** haplo37 has quit IRC | 09:10 | |
*** d0ugal has joined #openstack-keystone | 09:14 | |
*** haplo37_ has joined #openstack-keystone | 09:14 | |
*** guoshan has quit IRC | 09:20 | |
*** guoshan has joined #openstack-keystone | 09:20 | |
*** guoshan has quit IRC | 09:28 | |
*** guoshan has joined #openstack-keystone | 09:34 | |
*** d0ugal has quit IRC | 10:06 | |
*** mvk has joined #openstack-keystone | 10:08 | |
*** JoeStack has joined #openstack-keystone | 10:12 | |
JoeStack | I try to use the OpenStack CLI remotely on my local terminal. I've installed the python-openstackclient 2.3 and I've written and sourced some environment variables. I can use "nova list" but I cannot use any "openstack service <foo>" requesting the keystone API. When I use some debugging flags with that command, I always see the private keystone URL in the last CURL command instead of the public URL. Anyone any idea to guide me on t | 10:23 |
openstackgerrit | Sami Makki proposed openstack/oslo.policy: Remove dead code and use default value of argparse. https://review.openstack.org/411986 | 10:23 |
Anticimex | happy federated new years | 10:48 |
Anticimex | is it ever possible with federated login to set/get the domain part of a user? | 10:49 |
Anticimex | we're running keystone liberty with federation and have a horizon plugin that depends on domainnames | 10:50 |
Anticimex | do the shadow user features include the domain setting? | 10:50 |
*** guoshan has quit IRC | 10:51 | |
*** udesale has quit IRC | 11:01 | |
*** haplo37_ has quit IRC | 11:02 | |
*** haplo37_ has joined #openstack-keystone | 11:05 | |
*** guoshan has joined #openstack-keystone | 11:12 | |
*** guoshan has quit IRC | 11:57 | |
*** guoshan has joined #openstack-keystone | 12:04 | |
*** asettle has joined #openstack-keystone | 12:07 | |
openstackgerrit | Sami Makki proposed openstack/oslo.policy: Remove dead code and use default value of argparse. https://review.openstack.org/416040 | 12:14 |
*** asettle has quit IRC | 12:17 | |
*** asettle has joined #openstack-keystone | 12:21 | |
*** guoshan has quit IRC | 12:32 | |
*** catintheroof has joined #openstack-keystone | 12:40 | |
samueldmq | morning, happy new year keystoners | 12:50 |
*** markvoelker has joined #openstack-keystone | 12:55 | |
*** guoshan has joined #openstack-keystone | 13:00 | |
*** markvoelker has quit IRC | 13:00 | |
*** pcaruana has quit IRC | 13:00 | |
*** pcaruana has joined #openstack-keystone | 13:04 | |
*** oomichi has quit IRC | 13:07 | |
*** oomichi has joined #openstack-keystone | 13:08 | |
*** oomichi has quit IRC | 13:13 | |
*** oomichi has joined #openstack-keystone | 13:14 | |
*** oomichi has quit IRC | 13:19 | |
*** oomichi has joined #openstack-keystone | 13:20 | |
*** oomichi has quit IRC | 13:22 | |
*** oomichi has joined #openstack-keystone | 13:25 | |
*** oomichi has quit IRC | 13:27 | |
*** oomichi has joined #openstack-keystone | 13:30 | |
*** david-lyle has joined #openstack-keystone | 13:43 | |
*** david-lyle has quit IRC | 13:47 | |
*** markvoelker has joined #openstack-keystone | 13:56 | |
*** markvoelker has quit IRC | 14:00 | |
dstanek | good morning | 14:07 |
*** links has quit IRC | 14:09 | |
*** rcernin has quit IRC | 14:09 | |
*** rcernin has joined #openstack-keystone | 14:11 | |
dstanek | JoeStack: are you using the private URL in the environment vars? | 14:21 |
dstanek | Anticimex: our domain support with federation is pretty weak right now and probably doesn't exist in Liberty | 14:22 |
openstackgerrit | Merged openstack/keystone: Fix cloud_admin rule and ensure only project tokens can be cloud admin https://review.openstack.org/411563 | 14:24 |
Anticimex | dstanek: ack | 14:27 |
Anticimex | i'm close to figuring out how to patch our code now | 14:28 |
Anticimex | we want to use the project's domain (we were using the users domain and that's a nogo it seems with federated), so fix is depending on whether a project scoped token as available in horizon (mitaka) shows the project's domain | 14:29 |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Just a test with python3.5 https://review.openstack.org/412500 | 14:33 |
*** markvoelker has joined #openstack-keystone | 14:57 | |
*** catinthe_ has joined #openstack-keystone | 15:00 | |
*** markvoelker has quit IRC | 15:01 | |
*** catintheroof has quit IRC | 15:04 | |
*** asettle has quit IRC | 15:06 | |
Anticimex | seems the openstack_auth token carried in the horizon middleware request.session object doesn't have directly what i need; domain = {id: None, name: None} , user_domain_id = Federated. | 15:09 |
Anticimex | which i guess makes sense | 15:09 |
*** guoshan has quit IRC | 15:14 | |
*** links has joined #openstack-keystone | 15:16 | |
*** catintheroof has joined #openstack-keystone | 15:19 | |
*** catinthe_ has quit IRC | 15:23 | |
*** catinthe_ has joined #openstack-keystone | 15:30 | |
*** catintheroof has quit IRC | 15:31 | |
JoeStack | dstanek: I'm using the public URL in the environment vars. | 15:32 |
*** links has quit IRC | 15:44 | |
*** david-lyle has joined #openstack-keystone | 15:45 | |
*** david-lyle has quit IRC | 15:49 | |
*** nolwenn has joined #openstack-keystone | 15:49 | |
*** mvk has quit IRC | 15:50 | |
*** markvoelker has joined #openstack-keystone | 15:58 | |
dstanek | JoeStack: v2 or v3? | 15:59 |
nolwenn | hello, I just upgrade keystone in mitaka, and since I have a problem with autoscaling. When I send a signal with the scale up / scale down urls, I get "AWS authentication failure". Do you see where it comes from? | 16:00 |
*** markvoelker has quit IRC | 16:02 | |
JoeStack | dstanek: v2 | 16:05 |
*** sheel has quit IRC | 16:07 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements https://review.openstack.org/415965 | 16:10 |
*** asettle has joined #openstack-keystone | 16:13 | |
*** rcernin has quit IRC | 16:16 | |
dstanek | JoeStack: v2 limits the things that can be done on the public endpoint. are you able to use v3 instead? | 16:35 |
dstanek | nolwenn: i'm not sure if that has anything to do with keystone. have you looked in the keystone logs? | 16:37 |
nolwenn | dstanek : yes, I have {"name":"keystone.common.wsgi","request_id":"req-08b69ec1-459a-445b-afb9-1b9f94b78fcd","user_identity":"- - - - -","instance":"","message":"Authorization failed. The request you have made requires authentication} | 16:38 |
*** rcernin has joined #openstack-keystone | 16:39 | |
dstanek | nolwenn: where are you getting that AWS message from? | 16:39 |
nolwenn | dstanek : from heat-cfn-api | 16:40 |
nolwenn | dstanek : heat-cfn-api_1 | {"name":"heat.api.aws.ec2token","instance":"","message":"AWS authentication failure."} | 16:44 |
*** dave-mccowan has joined #openstack-keystone | 16:53 | |
dstanek | nolwenn: i'm guessing that something is wrong with the token being used. do you have debug logging on? | 16:54 |
*** catintheroof has joined #openstack-keystone | 16:56 | |
*** markvoelker has joined #openstack-keystone | 16:58 | |
*** catinthe_ has quit IRC | 17:00 | |
*** markvoelker has quit IRC | 17:03 | |
nolwenn | dstanek : It is during recovery of the token from ec2 credentials i think | 17:05 |
dstanek | nolwenn: if you have debugging on you may be more information about why the token is being rejected or even if a token is being provided | 17:07 |
nolwenn | i have already debugging, but not more information | 17:09 |
dstanek | nolwenn: there is no debug entries in the keystone log near that time? | 17:15 |
nolwenn | dstanek: just {"name":"keystone.common.wsgi","request_id":"req-9fbf1447-fe42-40ae-b5b5-a3e4cef66f39","user_identity":"- - - - -","instance":"","message":"Authorization failed. The request you have made requires authentication. from 172.18.0.10"} | 17:18 |
nolwenn | dstanek : I don't know if this is a good track but check_signature in https://github.com/openstack/keystone/blob/stable/mitaka/keystone/contrib/ec2/controllers.py#L58 return false | 17:28 |
*** d0ugal has joined #openstack-keystone | 17:40 | |
*** d0ugal has joined #openstack-keystone | 17:40 | |
*** d0ugal has quit IRC | 17:49 | |
*** andrewbogott has quit IRC | 17:51 | |
*** briancurtin has quit IRC | 17:51 | |
*** jraim has quit IRC | 17:52 | |
*** pkoraca has quit IRC | 17:53 | |
*** boris-42 has quit IRC | 17:53 | |
*** nikhil has quit IRC | 17:53 | |
*** samueldmq has quit IRC | 17:54 | |
*** andrewbogott has joined #openstack-keystone | 17:55 | |
JoeStack | dstanek: does it mean still to use the keystone URI/v2.0 and set environment var: OS_IDENTITY_API_VERSION=3? | 17:55 |
*** pkoraca has joined #openstack-keystone | 17:56 | |
*** boris-42 has joined #openstack-keystone | 17:57 | |
*** nikhil has joined #openstack-keystone | 17:57 | |
*** samueldmq has joined #openstack-keystone | 17:57 | |
*** ChanServ sets mode: +v samueldmq | 17:57 | |
*** dave-mccowan has quit IRC | 17:57 | |
*** markvoelker has joined #openstack-keystone | 17:59 | |
*** jraim has joined #openstack-keystone | 18:00 | |
*** markvoelker has quit IRC | 18:04 | |
*** briancurtin has joined #openstack-keystone | 18:07 | |
rodrigods | hey all, happy new year! :) | 18:17 |
*** asettle has quit IRC | 18:28 | |
*** asettle has joined #openstack-keystone | 18:28 | |
*** asettle has quit IRC | 18:33 | |
dstanek | JoeStack: if you switch the identity api version you will be using v3 | 18:49 |
dstanek | rodrigods: happy new year! | 18:49 |
*** dave-mccowan has joined #openstack-keystone | 18:51 | |
*** haplo37_ has quit IRC | 18:51 | |
*** haplo37_ has joined #openstack-keystone | 18:54 | |
*** markvoelker has joined #openstack-keystone | 19:00 | |
*** markvoelker has quit IRC | 19:05 | |
openstackgerrit | Davanum Srinivas (dims) proposed openstack/keystone: [WIP] Just a test with python3.5 https://review.openstack.org/412500 | 19:28 |
*** mvk has joined #openstack-keystone | 19:46 | |
*** dave-mccowan has quit IRC | 19:58 | |
*** pcaruana has quit IRC | 20:00 | |
*** markvoelker has joined #openstack-keystone | 20:01 | |
*** markvoelker has quit IRC | 20:06 | |
*** asettle has joined #openstack-keystone | 20:14 | |
*** asettle has quit IRC | 20:14 | |
*** asettle has joined #openstack-keystone | 20:15 | |
*** asettle has joined #openstack-keystone | 20:15 | |
*** asettle has joined #openstack-keystone | 20:16 | |
*** asettle has joined #openstack-keystone | 20:17 | |
*** david-lyle has joined #openstack-keystone | 20:48 | |
*** david-lyle has quit IRC | 20:52 | |
*** asettle has joined #openstack-keystone | 20:54 | |
*** pcaruana has joined #openstack-keystone | 21:00 | |
*** asettle has quit IRC | 21:01 | |
*** markvoelker has joined #openstack-keystone | 21:01 | |
*** rcernin has quit IRC | 21:02 | |
*** markvoelker has quit IRC | 21:06 | |
*** asettle has joined #openstack-keystone | 21:09 | |
*** asettle has quit IRC | 21:10 | |
*** pcaruana has quit IRC | 21:20 | |
*** pcaruana has joined #openstack-keystone | 21:42 | |
*** markvoelker has joined #openstack-keystone | 22:02 | |
*** markvoelker has quit IRC | 22:07 | |
*** pcaruana has quit IRC | 22:13 | |
jamielennox | Anticimex: what do you need the project_domain_id for? Typically it's sufficient to use the project_id for anything like that | 22:38 |
*** david-lyle has joined #openstack-keystone | 22:49 | |
*** david-lyle has quit IRC | 22:54 | |
*** markvoelker has joined #openstack-keystone | 23:03 | |
*** markvoelker has quit IRC | 23:08 | |
*** JoeStack has left #openstack-keystone | 23:29 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!