*** mpjetta has quit IRC | 00:04 | |
*** thorst has joined #openstack-keystone | 00:12 | |
*** thorst has quit IRC | 00:19 | |
*** raildo has quit IRC | 00:20 | |
*** gyee has quit IRC | 00:32 | |
*** ediardo has quit IRC | 00:37 | |
*** zhurong has joined #openstack-keystone | 00:44 | |
*** MasterOfBugs has quit IRC | 00:49 | |
*** pramodrj07 has quit IRC | 00:49 | |
*** thorst has joined #openstack-keystone | 00:50 | |
*** mriedem has left #openstack-keystone | 00:50 | |
*** masber has joined #openstack-keystone | 00:55 | |
*** thorst has quit IRC | 01:01 | |
*** shuyingya has joined #openstack-keystone | 01:19 | |
*** raildo has joined #openstack-keystone | 01:39 | |
*** raildo has quit IRC | 01:42 | |
*** thorst has joined #openstack-keystone | 01:49 | |
*** rcernin has joined #openstack-keystone | 02:20 | |
*** thorst has joined #openstack-keystone | 02:21 | |
*** rcernin has quit IRC | 02:26 | |
*** rcernin has joined #openstack-keystone | 02:26 | |
*** Aurelgad1o has joined #openstack-keystone | 02:36 | |
*** Aurelgadjo has quit IRC | 02:39 | |
*** thorst has quit IRC | 02:39 | |
*** lucasxu has joined #openstack-keystone | 03:01 | |
*** lucasxu has quit IRC | 03:09 | |
*** nicolasbock has quit IRC | 03:12 | |
*** links has joined #openstack-keystone | 03:36 | |
*** agrebennikov has quit IRC | 03:40 | |
*** lamt has joined #openstack-keystone | 03:53 | |
*** zhurong has quit IRC | 03:57 | |
*** jamielennox is now known as jamielennox|away | 04:01 | |
*** zhurong has joined #openstack-keystone | 04:17 | |
*** rcernin has quit IRC | 04:29 | |
*** jamielennox|away is now known as jamielennox | 04:29 | |
*** thorst has joined #openstack-keystone | 04:36 | |
*** thorst has quit IRC | 04:41 | |
openstackgerrit | Tin Lam proposed openstack/keystonemiddleware master: Replace pycrypto with cryptography https://review.openstack.org/451941 | 04:46 |
---|---|---|
*** pramodrj07 has joined #openstack-keystone | 05:05 | |
*** MasterOfBugs has joined #openstack-keystone | 05:05 | |
*** davechen has joined #openstack-keystone | 05:08 | |
*** lucasxu has joined #openstack-keystone | 05:19 | |
*** lucasxu has quit IRC | 05:20 | |
*** rcernin has joined #openstack-keystone | 05:37 | |
*** richm has quit IRC | 05:43 | |
openstackgerrit | Tin Lam proposed openstack/keystonemiddleware master: Replace pycrypto with cryptography https://review.openstack.org/451941 | 05:58 |
*** jaosorior_away is now known as jaosorior | 06:18 | |
*** lamt has quit IRC | 06:22 | |
*** lamt has joined #openstack-keystone | 06:32 | |
*** zzzeek has quit IRC | 06:41 | |
openstackgerrit | Merged openstack/oslo.policy master: Optimize the link address https://review.openstack.org/455001 | 06:44 |
*** shuyingya has quit IRC | 06:45 | |
*** shuyingya has joined #openstack-keystone | 06:46 | |
*** voelzmo has joined #openstack-keystone | 06:50 | |
*** jamielennox is now known as jamielennox|away | 06:52 | |
*** faizy has joined #openstack-keystone | 06:55 | |
*** belmoreira has joined #openstack-keystone | 06:56 | |
*** adriant has quit IRC | 06:58 | |
*** zzzeek has joined #openstack-keystone | 06:59 | |
*** pcaruana has joined #openstack-keystone | 07:01 | |
*** rcernin has quit IRC | 07:01 | |
*** rcernin has joined #openstack-keystone | 07:01 | |
*** pramodrj07 has quit IRC | 07:02 | |
*** MasterOfBugs has quit IRC | 07:02 | |
*** pramodrj07 has joined #openstack-keystone | 07:03 | |
*** MasterOfBugs has joined #openstack-keystone | 07:03 | |
*** PramodJ has joined #openstack-keystone | 07:04 | |
*** MasterOfBugs has quit IRC | 07:05 | |
*** pramodrj07 has quit IRC | 07:05 | |
*** MasterOfBugs has joined #openstack-keystone | 07:05 | |
*** tesseract has joined #openstack-keystone | 07:12 | |
*** shuyingy_ has joined #openstack-keystone | 07:26 | |
*** shuyingya has quit IRC | 07:30 | |
*** lamt has quit IRC | 07:32 | |
*** aojea has quit IRC | 07:43 | |
*** Aqsa has joined #openstack-keystone | 07:51 | |
*** aojea has joined #openstack-keystone | 07:51 | |
*** MasterOfBugs has quit IRC | 07:59 | |
*** PramodJ has quit IRC | 07:59 | |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:00 | |
*** shuyingy_ has quit IRC | 08:15 | |
*** shuyingya has joined #openstack-keystone | 08:16 | |
*** shuyingy_ has joined #openstack-keystone | 08:23 | |
*** aojea has quit IRC | 08:25 | |
*** shuyingya has quit IRC | 08:27 | |
*** aojea has joined #openstack-keystone | 08:32 | |
*** Shunli has joined #openstack-keystone | 08:35 | |
*** thorst has joined #openstack-keystone | 08:41 | |
*** belmoreira has quit IRC | 08:46 | |
*** belmoreira has joined #openstack-keystone | 08:47 | |
-openstackstatus- NOTICE: zuul was restarted due to an unrecoverable disconnect from gerrit. If your change is missing a CI result and isn't listed in the pipelines on http://status.openstack.org/zuul/ , please recheck | 08:51 | |
*** belmoreira has quit IRC | 08:56 | |
*** shuyingy_ has quit IRC | 08:56 | |
*** shuyingya has joined #openstack-keystone | 08:58 | |
*** aojea has quit IRC | 08:58 | |
*** thorst has quit IRC | 08:59 | |
*** aojea has joined #openstack-keystone | 09:01 | |
*** shuyingy_ has joined #openstack-keystone | 09:04 | |
*** shuyingya has quit IRC | 09:07 | |
*** rocky has quit IRC | 09:07 | |
*** rocky has joined #openstack-keystone | 09:10 | |
*** jaosorior has quit IRC | 09:26 | |
*** shuyingy_ has quit IRC | 09:27 | |
*** shuyingya has joined #openstack-keystone | 09:27 | |
*** jaosorior has joined #openstack-keystone | 09:30 | |
*** henrynash has joined #openstack-keystone | 09:37 | |
*** mvk has joined #openstack-keystone | 09:38 | |
*** aojea has quit IRC | 09:51 | |
*** aojea has joined #openstack-keystone | 10:14 | |
*** richm has joined #openstack-keystone | 10:15 | |
*** zhurong has quit IRC | 10:17 | |
*** rocky is now known as xuhaigang | 10:19 | |
*** nicolasbock has joined #openstack-keystone | 10:28 | |
*** henrynash has quit IRC | 10:33 | |
*** zhurong has joined #openstack-keystone | 10:45 | |
*** thorst has joined #openstack-keystone | 10:56 | |
*** erlon has joined #openstack-keystone | 11:01 | |
*** thorst has quit IRC | 11:01 | |
*** aojea has quit IRC | 11:18 | |
*** raildo has joined #openstack-keystone | 11:18 | |
*** jamielennox|away is now known as jamielennox | 11:18 | |
*** ayoung has quit IRC | 11:20 | |
*** ayoung has joined #openstack-keystone | 11:25 | |
*** namnh has joined #openstack-keystone | 11:39 | |
*** Shunli has quit IRC | 11:39 | |
namnh | hi everyone. | 11:41 |
*** Shunli has joined #openstack-keystone | 11:41 | |
namnh | I am confguring keyston high avalibility. are there anyone have experience with this. can I ask a question | 11:42 |
namnh | davechen, hi dave. are you free? | 11:44 |
breton | just ask away | 11:51 |
breton | someone will probably answer | 11:51 |
namnh | I want to build three keyston with high availibilty using haproxy. | 11:52 |
namnh | But I am using fernet to authentic. but I see that keystone don't write to DB. | 11:53 |
namnh | it stores its local | 11:53 |
*** thorst has joined #openstack-keystone | 11:53 | |
namnh | so if I want to use keystone HA. I have to use token to authentic | 11:54 |
namnh | is that right? | 11:54 |
namnh | breton, | 11:54 |
namnh | s/availibilty/availability | 11:55 |
*** jamielennox is now known as jamielennox|away | 12:05 | |
*** edmondsw has joined #openstack-keystone | 12:11 | |
*** faizy has quit IRC | 12:11 | |
*** nicolasbock has quit IRC | 12:19 | |
breton | namnh: a token means that a user has authenticated, with username+password or somehow else. Fernet is one of backends for tokens. HA works for all our backends, if configured correctly. | 12:19 |
openstackgerrit | ayoung proposed openstack/keystone master: Route based RBAC Management Interface https://review.openstack.org/401808 | 12:20 |
namnh | breton, I am reading this doc: https://docs.openstack.org/admin-guide/identity-fernet-token-faq.html | 12:20 |
*** chlong has quit IRC | 12:21 | |
*** lamt has joined #openstack-keystone | 12:21 | |
*** lamt has quit IRC | 12:22 | |
namnh | breton, I think all keystone nodes have to a same content at the /etc/keystone/credential-keys forder and the /etc/keystone/fernet-keys forder | 12:22 |
namnh | breton, is that right? | 12:22 |
breton | namnh: yes, that's right | 12:22 |
*** lamt has joined #openstack-keystone | 12:23 | |
*** lamt has quit IRC | 12:23 | |
namnh | breton, thanks, I am testing | 12:24 |
*** nicolasbock has joined #openstack-keystone | 12:25 | |
namnh | breton, it's ok. thanks for your time :) | 12:31 |
*** shuyingya has quit IRC | 12:35 | |
*** Shunli has quit IRC | 12:35 | |
*** Shunli has joined #openstack-keystone | 12:36 | |
*** shuyingya has joined #openstack-keystone | 12:36 | |
*** stradling has joined #openstack-keystone | 12:40 | |
*** shuyingya has quit IRC | 12:40 | |
*** Daviey has joined #openstack-keystone | 12:56 | |
*** Shunli has quit IRC | 13:00 | |
*** shuyingya has joined #openstack-keystone | 13:04 | |
*** shuyingya has quit IRC | 13:08 | |
*** rajpatel has joined #openstack-keystone | 13:27 | |
*** links has quit IRC | 13:29 | |
*** chlong has joined #openstack-keystone | 13:35 | |
lbragstad | redrobot dstanek looks like lamt fixed the padding issues we were seeing yesterday - https://gist.github.com/lbragstad/0c5c831d11684f8c7def7a6c553e1c40 | 13:40 |
lbragstad | i tested ^ that and it works | 13:40 |
*** Dinesh_Bhor has quit IRC | 13:41 | |
lbragstad | redrobot dstanek specifically this diff - https://gist.github.com/lbragstad/0c5c831d11684f8c7def7a6c553e1c40/revisions#diff-067f591dd676d7de57dc19ef083dcf24 | 13:41 |
*** Dinesh_Bhor has joined #openstack-keystone | 13:43 | |
*** catintheroof has joined #openstack-keystone | 13:44 | |
*** catintheroof has quit IRC | 13:45 | |
*** catintheroof has joined #openstack-keystone | 13:45 | |
*** ma9_ has joined #openstack-keystone | 13:49 | |
*** catintheroof has quit IRC | 13:50 | |
*** catintheroof has joined #openstack-keystone | 13:51 | |
dstanek | lbragstad: nice | 13:56 |
ayoung | knikolla, updated the patch with the new names and paths. I realize the Bulk API is untested. That is now called ServiceRoutes (better than Access Rules, I think) | 13:57 |
ayoung | Can you update keystoneclient accordingly? | 13:57 |
*** zhurong has quit IRC | 13:57 | |
knikolla | ayoung: sure. will do. | 13:58 |
lbragstad | dstanek yeah - so i think the padding there looks correct, but I'm testing it a little more locally | 13:59 |
*** lamt has joined #openstack-keystone | 14:00 | |
lbragstad | dstanek the padding looks right to me here - http://cdn.pasteraw.com/ap4r1atddreccq87bd09zeh8i568fi | 14:00 |
lbragstad | lamt nice work on the new crypto patch | 14:01 |
lamt | lbragstad o/ Thanks. I used the recommended PKCS7 padding, and ran a few tests last night - it looked okay. | 14:02 |
lbragstad | lamt i see that, i'm tinkering with it locally, but everything seems to be consistent with what redrobot was suggesting afaict | 14:03 |
lbragstad | lamt you know this means whenever i have a crypto question, i'm asking you first :) | 14:03 |
lamt | lbragstad lol. I was trying to remove the padding per the convo with redrobot, but it appears all that padding logic was already in the caching logic. Changing it will definitely break upgradeability. | 14:05 |
lbragstad | lamt yeah - from what i could tell, that's how we were suppose to use it | 14:06 |
lbragstad | lamt the pycrypto bits seemed to be padding accoring to PKCS#7 but the cryptography bits in the test script wasn't - which is where the inconsistency was | 14:07 |
lamt | yup. Was converting the code to use the padder/unpadder instead of the old six.int2byte() logic and still keep everything consistent. | 14:09 |
*** lucasxu has joined #openstack-keystone | 14:11 | |
lbragstad | lamt the six.int2byte() stuff if how we encrypted in ksm before, right? | 14:12 |
lamt | yes, it was used to pad the data | 14:13 |
lbragstad | lamt yeah - that's what it looks like | 14:13 |
lbragstad | in the crypto implementation before your patch | 14:13 |
lbragstad | lamt we could roll that script you wrote into a test, actually | 14:14 |
lbragstad | never mind | 14:15 |
lamt | yeah, it was using cipher.encrypt(data + six.int2byte(padding) * padding) and then result[:-1 * six.byte2int([result[-1]])] to get rid of that padding during decrypt | 14:15 |
lbragstad | the whole point of this is to *not* be dependent on pycrypto and moving that to a test would still require us to have it | 14:15 |
*** agrebennikov has joined #openstack-keystone | 14:15 | |
*** aojea has joined #openstack-keystone | 14:18 | |
lbragstad | lamt sweet, looks good to me | 14:21 |
lbragstad | lamt i'll let dstanek and redrobot give it a peak if they want https://review.openstack.org/#/c/451941/6 | 14:22 |
lamt | lbragstad thanks | 14:22 |
*** aojea has quit IRC | 14:23 | |
*** mpjetta has joined #openstack-keystone | 14:24 | |
*** aojea has joined #openstack-keystone | 14:28 | |
dstanek | lbragstad: sure | 14:28 |
namnh | breton, currenlty, I have three keystone HA nodes. In your option what number should we put with max_active_keys option? | 14:32 |
*** aojea has quit IRC | 14:32 | |
dstanek | namnh: it depends on a lot a factors. the default is good in most cases. how often do you want to rotate and how long does it take to propagate keys out to all of your nodes? | 14:39 |
namnh | dstanek, thanks for your reply, actually, i dont have much experience with keystone. I am trying to configure high availability for openstack including keystone | 14:41 |
namnh | dstanek, I am configuring three keystone nodes running active/active | 14:41 |
*** chris_hultin|AWA is now known as chris_hultin | 14:42 | |
namnh | dstanek, there is a problem when I start third keystone. there is a log like this: | 14:42 |
namnh | dstanek, http://paste.openstack.org/show/606459/ | 14:43 |
dstanek | namnh: are all of your nodes using the same keys in the key repository? | 14:45 |
dstanek | lbragstad: lamt: i noted a problem with that review | 14:45 |
namnh | dstanek, yes. I did it | 14:45 |
dstanek | namnh: hmmm...that invalid user token is very strange then | 14:47 |
dstanek | namnh: how are you syncing keys? | 14:47 |
namnh | dstanek, two keystone nodes run at the same time. But when I start third keystone node then there will be the error | 14:48 |
namnh | dstanek, I copied from one to others | 14:48 |
dstanek | something about that one is different | 14:49 |
namnh | no. all of them is the same | 14:49 |
namnh | I already compared them. there is no problem | 14:49 |
dstanek | there has to be something different. so now we have to figure out what | 14:50 |
dstanek | namnh: can you do a cksum of that directory's contents and check permissions | 14:51 |
*** catintheroof has quit IRC | 14:52 | |
*** catintheroof has joined #openstack-keystone | 14:52 | |
namnh | please wait a moment. | 14:57 |
*** mtreinish has quit IRC | 14:57 | |
*** mtreinish has joined #openstack-keystone | 14:58 | |
namnh | dstanek, here is the result: http://paste.openstack.org/show/606462/ | 14:58 |
namnh | dstanek, there are no any difference | 14:59 |
*** henrynash has joined #openstack-keystone | 14:59 | |
*** voelzmo has quit IRC | 15:01 | |
namnh | one thing, I feel strange. when I run only two keystone nodes, the bug will not occur. But with three keystones, it occurs | 15:03 |
*** Yada has joined #openstack-keystone | 15:03 | |
namnh | dstanek, so I believe that it's related to fernet or something in keystone, that I don't know. | 15:04 |
*** bigjools_ has joined #openstack-keystone | 15:05 | |
ayoung | knikolla, I'm adding an additional column to the table: body_key. We should be able to treat path+body_key as a composite for matching. The compound name should be ok, as it does not show up in the indices etc | 15:08 |
ayoung | the rules for matching when body_key are not None is going to be fun | 15:08 |
ayoung | is not None.... | 15:08 |
ayoung | are going to be fun | 15:09 |
ayoung | Subject verb agreement be hard | 15:09 |
*** afazekas_ has joined #openstack-keystone | 15:09 | |
*** dutsmoc has joined #openstack-keystone | 15:09 | |
*** melwitt_ has joined #openstack-keystone | 15:09 | |
*** dstanek_ has joined #openstack-keystone | 15:09 | |
*** lbragstad_ has joined #openstack-keystone | 15:09 | |
*** zigo_ has joined #openstack-keystone | 15:09 | |
*** EmilienM_ has joined #openstack-keystone | 15:09 | |
*** spotz_ has joined #openstack-keystone | 15:09 | |
*** dtroyer_zz has joined #openstack-keystone | 15:09 | |
*** pcaruana has quit IRC | 15:10 | |
*** kencjohnston_ has joined #openstack-keystone | 15:10 | |
*** dtroyer has quit IRC | 15:10 | |
*** lbragstad has quit IRC | 15:10 | |
*** melwitt has quit IRC | 15:10 | |
*** mordred has quit IRC | 15:10 | |
*** kencjohnston has quit IRC | 15:10 | |
*** stevemar has quit IRC | 15:10 | |
*** dstanek has quit IRC | 15:10 | |
*** EmilienM has quit IRC | 15:10 | |
*** chris_hultin has quit IRC | 15:10 | |
*** afazekas has quit IRC | 15:10 | |
*** spotz has quit IRC | 15:10 | |
*** zigo has quit IRC | 15:10 | |
*** dstanek_ is now known as dstanek | 15:10 | |
*** mordred1 has joined #openstack-keystone | 15:10 | |
knikolla | ayoung: hmm.. true | 15:11 |
*** EmilienM_ is now known as 17WAAOC7S | 15:11 | |
*** chris_hultin|AWA has joined #openstack-keystone | 15:11 | |
ayoung | knikolla, OK, let me try to get them down here: | 15:11 |
*** 21WAAA2JF has joined #openstack-keystone | 15:11 | |
*** chris_hultin|AWA is now known as chris_hultin | 15:11 | |
*** stevemar has joined #openstack-keystone | 15:11 | |
ayoung | for a given VERB+PATH...we'll shortcut that by calling it an API...for a given API, if there is no body_key, then the global rules take precedence | 15:12 |
*** zigo_ is now known as zigo | 15:12 | |
ayoung | if there is a body_key, attempt to match it against the body | 15:12 |
ayoung | if there is a match, then the role in that match gets added to the set of required roles needed to call the API | 15:12 |
*** zigo is now known as Guest52586 | 15:12 | |
ayoung | if there are multiple matches, all the set of roles are required | 15:13 |
ayoung | or...we can treat that as an error | 15:13 |
ayoung | kindof prefer the first | 15:13 |
*** rcernin has quit IRC | 15:13 | |
ayoung | if there are no matches, then (and only then) apply the rule for the API without the body_key value | 15:14 |
*** lbragstad_ is now known as lbragstad | 15:14 | |
*** ChanServ sets mode: +o lbragstad | 15:14 | |
ayoung | another way to say it "there must always be at least one rule that applies. Look first at the most specific. If there are multiple, apply them all. Then then progress to the most general." | 15:15 |
*** lamt has quit IRC | 15:15 | |
ayoung | knikolla, I think that is the way to go. | 15:15 |
*** ngupta has joined #openstack-keystone | 15:15 | |
knikolla | ayoung: i like the apply them all. | 15:16 |
ayoung | most specific is verb+api+body_path | 15:16 |
ayoung | next is probably api+body_path (no verb) | 15:16 |
ayoung | after that er | 15:16 |
ayoung | let me try that again | 15:16 |
*** ngupta has quit IRC | 15:16 | |
ayoung | most specific is verb+path+body_key | 15:17 |
ayoung | next is path+body_key (no verb) | 15:17 |
ayoung | next is verb+path(no body_key) | 15:17 |
ayoung | next is path (no verb or body_key) | 15:17 |
ayoung | last is the catchall rule for the service | 15:18 |
knikolla | ayoung: +1 | 15:19 |
ayoung | knikolla, I'll update the spec with that. | 15:19 |
ayoung | or make it a second spec. I think that makes more sense | 15:19 |
*** lamt has joined #openstack-keystone | 15:24 | |
*** ma9_1 has joined #openstack-keystone | 15:25 | |
*** ma9_ has quit IRC | 15:25 | |
*** namnh has quit IRC | 15:26 | |
*** catintheroof has quit IRC | 15:27 | |
*** catintheroof has joined #openstack-keystone | 15:27 | |
*** catintheroof has quit IRC | 15:27 | |
*** aojea has joined #openstack-keystone | 15:28 | |
*** aojea has quit IRC | 15:33 | |
*** dutsmoc has quit IRC | 15:34 | |
*** ma9_ has joined #openstack-keystone | 15:34 | |
*** comstud has joined #openstack-keystone | 15:34 | |
*** ma9_1 has quit IRC | 15:36 | |
*** ma9_ has quit IRC | 15:40 | |
*** stradling has quit IRC | 15:42 | |
*** mordred1 is now known as mordred | 15:46 | |
*** ma9_ has joined #openstack-keystone | 15:50 | |
*** ma9_ has left #openstack-keystone | 15:50 | |
*** ngupta has joined #openstack-keystone | 16:01 | |
*** stradling has joined #openstack-keystone | 16:07 | |
openstackgerrit | ayoung proposed openstack/keystone master: Expand the route tables to include a body key https://review.openstack.org/456692 | 16:10 |
*** thorst has quit IRC | 16:23 | |
*** stradling has quit IRC | 16:24 | |
*** thorst has joined #openstack-keystone | 16:25 | |
*** stradling has joined #openstack-keystone | 16:25 | |
*** henrynash has quit IRC | 16:27 | |
*** openstack has joined #openstack-keystone | 16:32 | |
*** d0ugal has joined #openstack-keystone | 16:32 | |
*** jistr has joined #openstack-keystone | 16:32 | |
*** openstackstatus has joined #openstack-keystone | 16:34 | |
*** ChanServ sets mode: +v openstackstatus | 16:34 | |
*** erlon has quit IRC | 16:35 | |
*** tesseract has joined #openstack-keystone | 16:35 | |
*** catintheroof has joined #openstack-keystone | 16:36 | |
*** dolphm has quit IRC | 16:38 | |
*** shuyingya has joined #openstack-keystone | 16:41 | |
*** melwitt_ is now known as melwitt | 16:43 | |
*** catintheroof has quit IRC | 16:44 | |
*** jaosorior has quit IRC | 16:44 | |
*** shuyingya has quit IRC | 16:45 | |
samueldmq | hi keystone | 16:46 |
samueldmq | lbragstad: I will work on https://review.openstack.org/#/c/182658/ today | 16:47 |
*** jaosorior has joined #openstack-keystone | 16:54 | |
*** lamt has quit IRC | 17:01 | |
*** Aqsa has quit IRC | 17:03 | |
*** jaosorior has quit IRC | 17:03 | |
*** 21WAAA2JF is now known as EmilienM | 17:05 | |
*** EmilienM has joined #openstack-keystone | 17:05 | |
*** gyee has joined #openstack-keystone | 17:06 | |
*** ngupta has quit IRC | 17:09 | |
*** ngupta has joined #openstack-keystone | 17:11 | |
*** rderose has joined #openstack-keystone | 17:11 | |
ayoung | knikolla, OK, I think the second patch I have posted is enough to get us working toward a proof of concept. | 17:12 |
ayoung | knikolla, I think we need to do the matching logic in keystoneclient, so it can be used by end users eventually, but needs to be able to work with cached data | 17:12 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/python-keystoneclient master: Add support for endpoint group filtering https://review.openstack.org/182658 | 17:15 |
*** raildo has quit IRC | 17:15 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/python-keystoneclient master: Add support for endpoint group filtering https://review.openstack.org/182658 | 17:19 |
samueldmq | lbragstad: ^ | 17:19 |
*** stradling has quit IRC | 17:20 | |
*** aojea has joined #openstack-keystone | 17:32 | |
*** aojea has quit IRC | 17:32 | |
lbragstad | samueldmq awesome - thanks for picking that up, i just noticed it yesterday as I was getting ready to release ksc :) | 17:32 |
*** aojea has joined #openstack-keystone | 17:32 | |
*** raildo has joined #openstack-keystone | 17:32 | |
samueldmq | lbragstad: np, I've rerun the unit tests, hopefully the functional still pass after the changes :-) | 17:33 |
lbragstad | samueldmq perfect | 17:33 |
*** raildo has quit IRC | 17:38 | |
*** raildo has joined #openstack-keystone | 17:38 | |
*** rcernin has joined #openstack-keystone | 17:42 | |
*** stradling has joined #openstack-keystone | 17:47 | |
*** lamt has joined #openstack-keystone | 18:05 | |
*** chlong has quit IRC | 18:07 | |
smccully | Alright, Mr. Clark @hyakuhei -- You do realize that there is no other way to verify the Public Internet then to keep copies of every well known Certificate Authority. I don't know how you think this is bad security, or what possible alternative you would think acceptable | 18:18 |
ayoung | knikolla, I am actually blocked on the client work. Are you actively working on it, or do you mind if I update? | 18:24 |
knikolla | ayoung: haven't started yet, just got back from lunch break. | 18:26 |
knikolla | ayoung: you can go ahead and update if you're working on it. | 18:26 |
*** lamt has quit IRC | 18:27 | |
ayoung | knikolla, OK. I'll update. Should be up shortly | 18:28 |
*** mvk has quit IRC | 18:29 | |
*** Yada has quit IRC | 18:30 | |
*** henrynash has joined #openstack-keystone | 18:32 | |
*** lamt has joined #openstack-keystone | 18:33 | |
openstackgerrit | ayoung proposed openstack/python-keystoneclient master: WIP - Client functions for Routes https://review.openstack.org/452893 | 18:35 |
openstackgerrit | Tin Lam proposed openstack/keystonemiddleware master: Replace pycrypto with cryptography https://review.openstack.org/451941 | 18:35 |
*** aojea has quit IRC | 18:42 | |
*** lucasxu has quit IRC | 18:43 | |
*** rajpatel has quit IRC | 18:44 | |
*** chlong has joined #openstack-keystone | 18:49 | |
*** rajpatel has joined #openstack-keystone | 18:50 | |
*** MasterOfBugs has joined #openstack-keystone | 18:59 | |
*** chlong has quit IRC | 19:02 | |
*** rmascena has joined #openstack-keystone | 19:04 | |
*** raildo has quit IRC | 19:06 | |
*** chris_hultin is now known as chris_hultin|AWA | 19:14 | |
*** rmascena has quit IRC | 19:20 | |
*** voelzmo has joined #openstack-keystone | 19:22 | |
*** voelzmo has quit IRC | 19:26 | |
*** aojea has joined #openstack-keystone | 19:26 | |
*** voelzmo has joined #openstack-keystone | 19:28 | |
*** aojea has quit IRC | 19:29 | |
*** aojea has joined #openstack-keystone | 19:29 | |
*** henrynash has quit IRC | 19:31 | |
*** rmascena has joined #openstack-keystone | 19:34 | |
*** aojea has quit IRC | 19:35 | |
*** ngupta has quit IRC | 19:37 | |
*** ngupta has joined #openstack-keystone | 19:37 | |
*** ravelar has joined #openstack-keystone | 19:48 | |
*** ravelar has quit IRC | 19:50 | |
-openstackstatus- NOTICE: The Gerrit service on http://review.openstack.org is being restarted to address hung remote replication tasks. | 19:51 | |
*** aojea has joined #openstack-keystone | 19:53 | |
*** rajpatel has quit IRC | 19:53 | |
*** raildo has joined #openstack-keystone | 20:02 | |
*** rmascena has quit IRC | 20:02 | |
*** Aqsa has joined #openstack-keystone | 20:14 | |
*** raildo has quit IRC | 20:19 | |
*** voelzmo has quit IRC | 20:20 | |
*** ngupta has quit IRC | 20:23 | |
*** ngupta has joined #openstack-keystone | 20:24 | |
*** ngupta has quit IRC | 20:27 | |
*** ngupta has joined #openstack-keystone | 20:28 | |
*** ediardo has joined #openstack-keystone | 20:37 | |
*** ngupta_ has joined #openstack-keystone | 20:38 | |
*** ngupta has quit IRC | 20:41 | |
*** ngupta_ has quit IRC | 20:43 | |
*** rajpatel has joined #openstack-keystone | 20:45 | |
*** edmondsw has quit IRC | 20:47 | |
*** edmondsw has joined #openstack-keystone | 20:48 | |
*** edmondsw has quit IRC | 20:53 | |
*** thorst has quit IRC | 21:02 | |
*** rajpatel has quit IRC | 21:07 | |
*** mnaser has left #openstack-keystone | 21:10 | |
*** mnaser has joined #openstack-keystone | 21:10 | |
*** chlong has joined #openstack-keystone | 21:17 | |
*** rajpatel has joined #openstack-keystone | 21:21 | |
*** rajpatel has quit IRC | 21:22 | |
*** ngupta has joined #openstack-keystone | 21:32 | |
*** henrynash has joined #openstack-keystone | 21:39 | |
*** chlong has quit IRC | 21:42 | |
*** stradling has quit IRC | 21:46 | |
*** tesseract has quit IRC | 21:47 | |
*** henrynash has quit IRC | 21:51 | |
hyakuhei | smccully you around? | 21:52 |
hyakuhei | Is change 452585 regarding the client side code for PKI, as described here: https://docs.openstack.org/developer/keystoneauth/authentication-plugins.html#tokenless-auth | 21:53 |
*** lamt has quit IRC | 21:55 | |
*** ngupta has quit IRC | 21:58 | |
*** thorst has joined #openstack-keystone | 22:10 | |
smccully | nooo | 22:13 |
smccully | :) | 22:13 |
hyakuhei | Heh | 22:13 |
hyakuhei | Sorry, I was dealing with a big issue earlier but also getting pinged to comment on your change | 22:14 |
hyakuhei | I just dropped a fresh note on there, I should have realised when you mentioned requests but I didn't. My fault. | 22:15 |
*** jamielennox|away is now known as jamielennox | 22:19 | |
hyakuhei | Anyway, was dropping by to apologise for me getting the wrong end of the stick earlier. | 22:19 |
*** thorst has quit IRC | 22:20 | |
*** aojea has quit IRC | 22:26 | |
*** Aqsa has quit IRC | 22:40 | |
*** thorst has joined #openstack-keystone | 22:43 | |
*** thorst has quit IRC | 22:44 | |
*** MasterOfBugs has quit IRC | 23:00 | |
*** thorst has joined #openstack-keystone | 23:15 | |
*** thorst has quit IRC | 23:26 | |
*** thorst has joined #openstack-keystone | 23:41 | |
*** ngupta has joined #openstack-keystone | 23:50 | |
*** edmondsw has joined #openstack-keystone | 23:54 | |
*** shuyingya has joined #openstack-keystone | 23:56 | |
*** edmondsw has quit IRC | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!