*** stingaci has quit IRC | 00:08 | |
*** stingaci has joined #openstack-keystone | 00:09 | |
*** stingaci has quit IRC | 00:36 | |
*** thorst has joined #openstack-keystone | 00:45 | |
*** tovin07 has joined #openstack-keystone | 00:48 | |
*** thorst has quit IRC | 00:50 | |
*** Nakato has quit IRC | 01:14 | |
*** thorst has joined #openstack-keystone | 01:21 | |
*** thorst has quit IRC | 01:22 | |
*** liujiong has joined #openstack-keystone | 01:27 | |
*** jamielennox is now known as jamielennox|away | 01:33 | |
*** jamielennox|away is now known as jamielennox | 01:44 | |
*** namnh has joined #openstack-keystone | 01:44 | |
*** thorst has joined #openstack-keystone | 01:47 | |
*** Nakato has joined #openstack-keystone | 01:56 | |
*** thorst has joined #openstack-keystone | 02:18 | |
*** nicolasbock has quit IRC | 02:21 | |
*** thorst has quit IRC | 02:36 | |
*** Guest76746 is now known as med_ | 02:37 | |
*** med_ has joined #openstack-keystone | 02:38 | |
*** Shunli has joined #openstack-keystone | 03:07 | |
*** aojea has joined #openstack-keystone | 03:14 | |
*** aojea has quit IRC | 03:18 | |
*** jaugustine has joined #openstack-keystone | 03:29 | |
*** thorst has joined #openstack-keystone | 03:33 | |
*** dikonoor has joined #openstack-keystone | 03:36 | |
*** dave-mccowan has quit IRC | 03:37 | |
*** thorst has quit IRC | 03:37 | |
*** prashkre has joined #openstack-keystone | 03:49 | |
*** jaugustine has quit IRC | 03:54 | |
*** jaugustine has joined #openstack-keystone | 03:59 | |
*** Dinesh_Bhor has joined #openstack-keystone | 04:06 | |
*** jaugustine has quit IRC | 04:26 | |
*** dikonoor has quit IRC | 04:32 | |
*** thorst has joined #openstack-keystone | 04:34 | |
*** thorst has quit IRC | 04:38 | |
*** dikonoor has joined #openstack-keystone | 04:43 | |
*** oomichi has quit IRC | 04:46 | |
*** aojea has joined #openstack-keystone | 05:07 | |
*** thorst has joined #openstack-keystone | 05:34 | |
*** thorst has quit IRC | 05:39 | |
*** dikonoor has quit IRC | 05:43 | |
*** aojea has quit IRC | 05:45 | |
*** aojea has joined #openstack-keystone | 05:47 | |
*** dikonoor has joined #openstack-keystone | 05:51 | |
*** aojea has quit IRC | 05:52 | |
*** adriant has quit IRC | 06:08 | |
*** Dinesh_Bhor has quit IRC | 06:13 | |
*** liujiong has quit IRC | 06:27 | |
*** Dinesh_Bhor has joined #openstack-keystone | 06:27 | |
*** thorst has joined #openstack-keystone | 06:35 | |
*** thorst has quit IRC | 06:39 | |
*** aojea has joined #openstack-keystone | 06:48 | |
*** yangyapeng has joined #openstack-keystone | 06:52 | |
yangyapeng | hello GUys, Install OpenStack in Devstack have a error, keystone did not start | 06:53 |
---|---|---|
*** voelzmo has joined #openstack-keystone | 06:53 | |
*** aojea has quit IRC | 06:54 | |
*** voelzmo has quit IRC | 07:02 | |
*** voelzmo has joined #openstack-keystone | 07:12 | |
*** pcaruana has joined #openstack-keystone | 07:24 | |
*** jaosorior has joined #openstack-keystone | 07:33 | |
*** thorst has joined #openstack-keystone | 07:37 | |
*** rcernin has joined #openstack-keystone | 07:43 | |
*** d0ugal has joined #openstack-keystone | 07:50 | |
*** d0ugal has quit IRC | 07:50 | |
*** d0ugal has joined #openstack-keystone | 07:50 | |
*** Aqsa has joined #openstack-keystone | 07:52 | |
*** thorst has quit IRC | 07:56 | |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:00 | |
*** rcernin has quit IRC | 08:23 | |
*** evrardjp has joined #openstack-keystone | 08:41 | |
*** aojea has joined #openstack-keystone | 08:50 | |
*** aojea has quit IRC | 08:55 | |
*** dikonoor has quit IRC | 08:55 | |
*** dikonoor has joined #openstack-keystone | 09:21 | |
*** dikonoor has quit IRC | 09:32 | |
*** Shunli has quit IRC | 09:42 | |
*** thorst has joined #openstack-keystone | 09:53 | |
*** mvk has quit IRC | 09:54 | |
*** masber has quit IRC | 09:54 | |
*** thorst has quit IRC | 09:57 | |
*** nicolasbock has joined #openstack-keystone | 10:06 | |
*** aojea has joined #openstack-keystone | 10:14 | |
*** aloga has quit IRC | 10:21 | |
*** aloga has joined #openstack-keystone | 10:21 | |
*** yangyapeng has quit IRC | 10:22 | |
*** mvk has joined #openstack-keystone | 10:23 | |
*** dikonoor has joined #openstack-keystone | 10:42 | |
*** thorst has joined #openstack-keystone | 10:53 | |
openstackgerrit | Aqsa Malik proposed openstack/keystone master: Fix mapping_purge failure https://review.openstack.org/408304 | 10:58 |
*** thorst has quit IRC | 10:58 | |
*** raildo has joined #openstack-keystone | 11:09 | |
*** dave-mccowan has joined #openstack-keystone | 11:09 | |
*** dikonoor has quit IRC | 11:11 | |
*** zhugaoxiao has quit IRC | 11:13 | |
*** zhurong has joined #openstack-keystone | 11:17 | |
*** zhugaoxiao has joined #openstack-keystone | 11:17 | |
*** dikonoor has joined #openstack-keystone | 11:29 | |
*** zhugaoxiao has quit IRC | 11:34 | |
*** zhugaoxiao has joined #openstack-keystone | 11:35 | |
*** thorst has joined #openstack-keystone | 11:42 | |
*** prashkre has quit IRC | 12:03 | |
*** namnh has quit IRC | 12:05 | |
*** lamt has quit IRC | 12:18 | |
*** slunkad has joined #openstack-keystone | 12:24 | |
*** edmondsw has joined #openstack-keystone | 12:26 | |
*** catintheroof has joined #openstack-keystone | 12:37 | |
*** stingaci has joined #openstack-keystone | 12:37 | |
*** zhurong has quit IRC | 12:39 | |
*** stingaci has quit IRC | 12:42 | |
*** lamt has joined #openstack-keystone | 13:01 | |
*** kencjohnston has quit IRC | 13:02 | |
*** jerrygb has joined #openstack-keystone | 13:02 | |
*** prashkre has joined #openstack-keystone | 13:14 | |
*** jdwidari has joined #openstack-keystone | 13:41 | |
*** erhudy has joined #openstack-keystone | 13:44 | |
*** d0ugal_ has joined #openstack-keystone | 13:45 | |
*** d0ugal has quit IRC | 13:48 | |
*** d0ugal_ has quit IRC | 13:55 | |
*** d0ugal has joined #openstack-keystone | 13:58 | |
*** d0ugal has quit IRC | 14:01 | |
*** d0ugal has joined #openstack-keystone | 14:32 | |
*** g0d355__ has joined #openstack-keystone | 14:34 | |
openstackgerrit | Gage Hugo proposed openstack/keystonemiddleware master: Added "warning-is-error" sphinx check for docs https://review.openstack.org/439819 | 14:52 |
openstackgerrit | Gage Hugo proposed openstack/python-keystoneclient master: Remove pbr warnerrors in favor of sphinx check https://review.openstack.org/441468 | 14:56 |
*** richm has joined #openstack-keystone | 15:00 | |
*** adrian_otto has joined #openstack-keystone | 15:01 | |
*** phalmos has joined #openstack-keystone | 15:08 | |
*** sjain has joined #openstack-keystone | 15:11 | |
ayoung | knikolla, did you see my comments about the default/wildcard values in the pattern match? | 15:13 |
knikolla | ayoung: yes, working on that now. the wildcard verb case is easy. i'm unsure about the wildcard path. the routes library provides a syntax for wildcards https://routes.readthedocs.io/en/latest/setting_up.html#wildcard-routes | 15:14 |
ayoung | knikolla, good catch | 15:15 |
ayoung | knikolla, also, do you know how to get devstack setup to be able to test this? I can help with that | 15:15 |
*** sjain has quit IRC | 15:16 | |
knikolla | ayoung: where is ksm installed in devstack? | 15:17 |
ayoung | knikolla, so, what you want to do is treat ksm and the other libraries as global installs | 15:17 |
knikolla | ayoung: if it's in site-packages it's just pip install -e . and restarting apache | 15:17 |
ayoung | knikolla, so, yeah, /usr/libwhatever/python27/sit-packages | 15:17 |
ayoung | you can do su and then python setup.py install in the respective directories | 15:18 |
ayoung | there is even an option to symlink to the source code directory, but I'd have to dig to remember | 15:18 |
openstackgerrit | Kristi Nikolla proposed openstack/keystonemiddleware master: WIP - Role check in middleware https://review.openstack.org/458931 | 15:19 |
knikolla | ayoung: this fixes some of your comments ^^ i still need to plug in the cache though | 15:19 |
ayoung | knikolla, right now I'm not expanded the implied roles on the server side. We can either build that into the middleware, or we need to modify the server to expand. | 15:29 |
*** david-lyle has joined #openstack-keystone | 15:29 | |
ayoung | oh, with | 15:29 |
ayoung | wait | 15:29 |
ayoung | for now, we can expand the implied roles in the token validation. Good enough for round one | 15:29 |
knikolla | ayoung: elaborate on that | 15:38 |
ayoung | knikolla, I was thinking that your code need to call and expand the implied roles, but that is already handled | 15:38 |
ayoung | when you validate the token, the keystone server is capable of doing that | 15:39 |
ayoung | it is a config option that needs to be set, but that is enough for now | 15:39 |
knikolla | ayoung: i see | 15:39 |
ayoung | the other option is to expand the implied roles in the routes, either on the server side or in the middleware, but not a first iteration problem | 15:39 |
*** zhurong has joined #openstack-keystone | 15:42 | |
knikolla | ayoung: ack | 15:45 |
*** zhurong has quit IRC | 15:57 | |
*** Aqsa has quit IRC | 16:00 | |
*** gyee has joined #openstack-keystone | 16:00 | |
*** voelzmo has quit IRC | 16:02 | |
*** zhurong has joined #openstack-keystone | 16:02 | |
*** dikonoor has quit IRC | 16:03 | |
*** zhurong has quit IRC | 16:07 | |
*** sjain has joined #openstack-keystone | 16:14 | |
sjain | Hi, I'm a new contributor, I made my first contribution here, https://review.openstack.org/#/c/450038/ | 16:14 |
sjain | Can anyone please review the changes | 16:14 |
*** jerrygb has quit IRC | 16:16 | |
*** dikonoor has joined #openstack-keystone | 16:29 | |
*** gyee has quit IRC | 16:32 | |
SamYaple | /win 6 | 16:33 |
*** jerrygb has joined #openstack-keystone | 16:33 | |
*** mvk has quit IRC | 16:39 | |
*** gyee has joined #openstack-keystone | 16:42 | |
*** sjain has quit IRC | 16:54 | |
*** jaosorior is now known as jaosorior_away | 16:59 | |
knikolla | ayoung: if there is no rule match. what should be the default behavior? | 17:02 |
ayoung | knikolla, if the role check is enabled and there is no rule match, denuy | 17:02 |
ayoung | deny | 17:02 |
knikolla | ayoung: ack | 17:03 |
*** adrian_otto1 has joined #openstack-keystone | 17:06 | |
*** zhugaoxiao has quit IRC | 17:06 | |
*** zhugaoxiao has joined #openstack-keystone | 17:07 | |
knikolla | ayoung: should we treat /bla and /bla/ the same? | 17:08 |
*** adrian_otto has quit IRC | 17:09 | |
*** jdennis1 has joined #openstack-keystone | 17:15 | |
*** jdennis has quit IRC | 17:17 | |
ayoung | knikolla, lets go with whatever routes does by default | 17:17 |
ayoung | not try to add out own logic | 17:18 |
*** mvk has joined #openstack-keystone | 17:18 | |
knikolla | ayoung: I think our APIs treat them as the same | 17:19 |
knikolla | ayoung: routes treats them differently | 17:19 |
ayoung | knikolla, go with routes | 17:19 |
*** Aqsa has joined #openstack-keystone | 17:22 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystonemiddleware master: WIP - Role check in middleware https://review.openstack.org/458931 | 17:22 |
*** adrian_otto1 has quit IRC | 17:23 | |
knikolla | ayoung: added some unit tests and the role_check option ^^ | 17:24 |
knikolla | will start real testing after lunch | 17:24 |
*** dikonoor has quit IRC | 17:41 | |
*** eandersson has joined #openstack-keystone | 17:54 | |
*** chlong has joined #openstack-keystone | 17:59 | |
*** catintheroof has quit IRC | 18:01 | |
*** ducttape_ has joined #openstack-keystone | 18:02 | |
*** ducttape_ has quit IRC | 18:04 | |
*** ducttape_ has joined #openstack-keystone | 18:22 | |
Yash_ | Hi people | 18:25 |
Yash_ | I am facing this error : You are not authorized to perform the requested action: identity:create_domain. (HTTP 403) when trying to do any adminstrative task | 18:25 |
Yash_ | Can anyone help me with this? | 18:26 |
*** stingaci has joined #openstack-keystone | 18:34 | |
*** catintheroof has joined #openstack-keystone | 18:38 | |
edmondsw | Yash_ did you check your /etc/keystone/policy.json file? | 18:56 |
edmondsw | look for "identity:create_domain" there | 18:56 |
edmondsw | it will tell you who is allowed to do that | 18:56 |
edmondsw | lbragstad or anyone... What's the best way to recover from "ValueError: Fernet key must be 32 url-safe base64-encoded bytes" | 18:58 |
edmondsw | Someone is reporting this on a system where the disk had filled up, and I'm thinking maybe that interfered with the key rotation cron job | 18:58 |
lbragstad | edmondsw ohhh | 18:58 |
* lbragstad goes to find a bug reoprt | 18:58 | |
lbragstad | edmondsw is this what you're seeing? https://bugs.launchpad.net/keystone/+bug/1642457 | 19:00 |
openstack | Launchpad bug 1642457 in OpenStack Identity (keystone) "Fernet rotate doesn't prevent rotation when disk is full" [Low,Fix released] - Assigned to John Lin (johnlinp) | 19:00 |
edmondsw | lbragstad yeah, probably | 19:01 |
lbragstad | that landed in ocata | 19:01 |
edmondsw | lbragstad so once it's happened, what would suggest to fix the system? | 19:02 |
edmondsw | patching keystone-manage will prevent it from happening again, but won't get the 500 to go away... | 19:03 |
lbragstad | edmondsw i'd probably start looking at all the fernet keys and figure out if the oldest ones could be removed | 19:03 |
edmondsw | sound like the problem is with the staged key, though | 19:03 |
edmondsw | can't just remove that, since you have to have a staged key, right? | 19:03 |
edmondsw | so somehow need to put a valid key in that file | 19:03 |
edmondsw | suggestion on how to create a valid key myself? | 19:04 |
lbragstad | you could generate a key manually | 19:04 |
lbragstad | yeah - i can get you an exmaple | 19:04 |
edmondsw | tx | 19:04 |
lbragstad | edmondsw per the pyca/cryptography docs - http://cdn.pasteraw.com/57kpixuj8d2e36ny082t0kzvc8od5sr | 19:05 |
lbragstad | https://github.com/pyca/cryptography | 19:05 |
edmondsw | lbragstad tx! | 19:06 |
lbragstad | you could patch that into the staged key manually to fix it | 19:06 |
lbragstad | then go about the key distribution like you normally would | 19:06 |
lbragstad | edmondsw np! | 19:06 |
Aqsa | cmurphy: Thanks for all the pointers in the unit test! | 19:40 |
*** jerrygb has quit IRC | 19:42 | |
cmurphy | Aqsa: glad I could help :) | 19:43 |
*** prashkre has quit IRC | 19:49 | |
*** ducttape_ has quit IRC | 19:56 | |
*** Yash_ has quit IRC | 20:01 | |
*** pcaruana has quit IRC | 20:01 | |
*** harlowja has quit IRC | 20:03 | |
*** raildo has quit IRC | 20:04 | |
*** MasterOfBugs has joined #openstack-keystone | 20:08 | |
*** jamielennox is now known as jamielennox|away | 20:13 | |
*** jerrygb has joined #openstack-keystone | 20:17 | |
*** jamielennox|away is now known as jamielennox | 20:20 | |
*** jerrygb has quit IRC | 20:21 | |
*** Aqsa has quit IRC | 20:33 | |
*** ducttape_ has joined #openstack-keystone | 20:56 | |
*** harlowja has joined #openstack-keystone | 20:59 | |
*** thorst has quit IRC | 21:01 | |
*** adrian_otto has joined #openstack-keystone | 21:02 | |
*** ducttape_ has quit IRC | 21:05 | |
*** ducttape_ has joined #openstack-keystone | 21:05 | |
*** ducttape_ has quit IRC | 21:10 | |
*** ducttape_ has joined #openstack-keystone | 21:14 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: WIP - Routes API Ref https://review.openstack.org/458983 | 21:15 |
*** catintheroof has quit IRC | 21:15 | |
*** ducttape_ has quit IRC | 21:16 | |
*** adrian_otto has quit IRC | 21:19 | |
*** ducttape_ has joined #openstack-keystone | 21:20 | |
*** adrian_otto has joined #openstack-keystone | 21:20 | |
*** aojea has quit IRC | 21:26 | |
openstackgerrit | Gage Hugo proposed openstack/python-keystoneclient master: Remove pbr warnerrors in favor of sphinx check https://review.openstack.org/441468 | 21:28 |
openstackgerrit | Gage Hugo proposed openstack/keystonemiddleware master: Added "warning-is-error" sphinx check for docs https://review.openstack.org/439819 | 21:31 |
*** jamiec has quit IRC | 21:35 | |
*** jamiec has joined #openstack-keystone | 21:38 | |
*** thorst has joined #openstack-keystone | 21:41 | |
*** thorst has quit IRC | 21:46 | |
*** jlk has joined #openstack-keystone | 22:21 | |
*** phalmos has quit IRC | 22:30 | |
*** adrian_otto has quit IRC | 22:52 | |
*** ducttap__ has joined #openstack-keystone | 23:19 | |
*** ducttape_ has quit IRC | 23:19 | |
*** jlk has left #openstack-keystone | 23:21 | |
*** hyakuhei has quit IRC | 23:22 | |
*** hyakuhei has joined #openstack-keystone | 23:28 | |
*** ducttap__ has quit IRC | 23:29 | |
*** dave-mccowan has quit IRC | 23:30 | |
*** spotz_ has quit IRC | 23:34 | |
*** lamt has quit IRC | 23:36 | |
*** spotz_ has joined #openstack-keystone | 23:56 | |
*** spotz_ has quit IRC | 23:58 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!