*** links has joined #openstack-keystone | 00:23 | |
*** namnh has joined #openstack-keystone | 00:55 | |
*** dave-mccowan has quit IRC | 01:05 | |
*** dave-mccowan has joined #openstack-keystone | 01:12 | |
*** gvrangan has joined #openstack-keystone | 01:15 | |
*** daidv has joined #openstack-keystone | 01:41 | |
daidv | lbragstad, hi, I have gone out the office when you ping me :D | 01:43 |
---|---|---|
*** gvrangan has quit IRC | 01:49 | |
*** wes_dillingham has quit IRC | 01:49 | |
*** gus has quit IRC | 01:50 | |
*** itlinux has joined #openstack-keystone | 01:51 | |
*** AlexeyAbashkin has joined #openstack-keystone | 01:51 | |
*** gus has joined #openstack-keystone | 01:51 | |
*** gyee has quit IRC | 01:52 | |
*** dikonoor has joined #openstack-keystone | 01:55 | |
*** AlexeyAbashkin has quit IRC | 01:55 | |
*** dikonoor has quit IRC | 02:01 | |
*** spectr has quit IRC | 02:03 | |
*** spectr has joined #openstack-keystone | 02:05 | |
*** prashkre_ has joined #openstack-keystone | 02:08 | |
*** aselius has quit IRC | 02:18 | |
*** itlinux has quit IRC | 02:29 | |
*** masuberu has quit IRC | 02:34 | |
openstackgerrit | Merged openstack/keystone master: Partially clarify federation auth plugins https://review.openstack.org/513960 | 02:41 |
*** itlinux has joined #openstack-keystone | 02:45 | |
*** itlinux has quit IRC | 02:48 | |
*** prashkre_ has quit IRC | 02:49 | |
*** prashkre_ has joined #openstack-keystone | 02:49 | |
*** AlexeyAbashkin has joined #openstack-keystone | 02:51 | |
*** itlinux has joined #openstack-keystone | 02:53 | |
*** masber has joined #openstack-keystone | 02:55 | |
*** AlexeyAbashkin has quit IRC | 02:55 | |
*** masber has quit IRC | 02:57 | |
*** masber has joined #openstack-keystone | 02:57 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf master: Updated from global requirements https://review.openstack.org/470137 | 03:09 |
*** dave-mccowan has quit IRC | 03:10 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf master: Updated from global requirements https://review.openstack.org/470137 | 03:11 |
*** annp has joined #openstack-keystone | 03:14 | |
*** masber has quit IRC | 03:19 | |
*** nicolasbock has quit IRC | 03:22 | |
*** itlinux has quit IRC | 03:22 | |
*** dikonoor has joined #openstack-keystone | 03:25 | |
*** thorst has joined #openstack-keystone | 03:35 | |
*** prashkre_ has quit IRC | 03:36 | |
*** thorst has quit IRC | 03:41 | |
*** AlexeyAbashkin has joined #openstack-keystone | 03:51 | |
*** AlexeyAbashkin has quit IRC | 03:55 | |
*** masber has joined #openstack-keystone | 04:02 | |
*** masber has quit IRC | 04:04 | |
*** masber has joined #openstack-keystone | 04:04 | |
*** markvoelker has quit IRC | 04:23 | |
*** prashkre has joined #openstack-keystone | 04:35 | |
*** rmcallis has quit IRC | 04:41 | |
*** rmcallis has joined #openstack-keystone | 04:44 | |
*** prashkre has quit IRC | 04:50 | |
*** dikonoor has quit IRC | 04:51 | |
*** markvoelker has joined #openstack-keystone | 04:55 | |
*** markvoelker has quit IRC | 05:24 | |
*** markvoelker has joined #openstack-keystone | 05:24 | |
*** markvoelker has quit IRC | 05:28 | |
*** gvrangan has joined #openstack-keystone | 05:30 | |
*** thorst has joined #openstack-keystone | 05:37 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/pycadf master: Updated from global requirements https://review.openstack.org/470137 | 05:41 |
*** thorst has quit IRC | 05:41 | |
*** gvrangan_odl has joined #openstack-keystone | 06:01 | |
*** gvrangan has quit IRC | 06:01 | |
*** AlexeyAbashkin has joined #openstack-keystone | 06:03 | |
*** prashkre has joined #openstack-keystone | 06:04 | |
*** AlexeyAbashkin has quit IRC | 06:19 | |
*** josecastroleon has quit IRC | 06:19 | |
*** zhangjl has quit IRC | 06:28 | |
*** zhangjl has joined #openstack-keystone | 06:28 | |
*** josecastroleon has joined #openstack-keystone | 06:36 | |
*** josecastroleon has quit IRC | 06:37 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystonemiddleware master: Imported Translations from Zanata https://review.openstack.org/514529 | 06:39 |
openstackgerrit | Abhishek Sharma M proposed openstack/keystonemiddleware master: Changed LOG type from warning to debug https://review.openstack.org/515291 | 06:40 |
*** josecastroleon has joined #openstack-keystone | 06:55 | |
*** josecastroleon has quit IRC | 07:03 | |
*** rcernin has quit IRC | 07:04 | |
*** josecastroleon has joined #openstack-keystone | 07:07 | |
*** tesseract has joined #openstack-keystone | 07:09 | |
*** markvoelker has joined #openstack-keystone | 07:25 | |
openstackgerrit | Merged openstack/oslo.policy master: Imported Translations from Zanata https://review.openstack.org/514946 | 07:30 |
*** gvrangan_odl has quit IRC | 07:34 | |
*** gvrangan has joined #openstack-keystone | 07:45 | |
*** ioggstream has joined #openstack-keystone | 07:45 | |
*** zhangjl has quit IRC | 07:56 | |
*** zhangjl has joined #openstack-keystone | 07:57 | |
*** markvoelker has quit IRC | 07:59 | |
*** AlexeyAbashkin has joined #openstack-keystone | 08:03 | |
*** namnh has quit IRC | 08:04 | |
*** namnh has joined #openstack-keystone | 08:04 | |
openstackgerrit | Shan Guo proposed openstack/keystone master: Remove v2 token value model https://review.openstack.org/514554 | 08:09 |
openstackgerrit | Shan Guo proposed openstack/keystone master: Remove simple cert support https://review.openstack.org/515309 | 08:18 |
*** david-lyle has quit IRC | 08:24 | |
*** david-lyle has joined #openstack-keystone | 08:25 | |
*** d0ugal has quit IRC | 08:32 | |
*** d0ugal_ has joined #openstack-keystone | 08:32 | |
*** d0ugal_ has quit IRC | 08:33 | |
*** d0ugal has joined #openstack-keystone | 08:33 | |
*** d0ugal has quit IRC | 08:33 | |
*** d0ugal has joined #openstack-keystone | 08:33 | |
*** rmcallis has quit IRC | 08:39 | |
*** rmcallis has joined #openstack-keystone | 08:44 | |
*** gvrangan has quit IRC | 08:46 | |
*** gvrangan has joined #openstack-keystone | 08:47 | |
*** markvoelker has joined #openstack-keystone | 08:57 | |
*** Suramya has joined #openstack-keystone | 08:59 | |
*** AlexeyAbashkin has quit IRC | 09:02 | |
*** AlexeyAbashkin has joined #openstack-keystone | 09:06 | |
*** namnh has quit IRC | 09:24 | |
*** namnh has joined #openstack-keystone | 09:24 | |
*** david-lyle has quit IRC | 09:26 | |
*** dklyle has joined #openstack-keystone | 09:26 | |
*** markvoelker has quit IRC | 09:29 | |
openstackgerrit | Stephen Finucane proposed openstack/oslo.policy master: generator: Reimplement wrapping of 'description' https://review.openstack.org/485646 | 09:30 |
*** AlexeyAbashkin has quit IRC | 09:37 | |
*** thorst has joined #openstack-keystone | 09:39 | |
*** thorst has quit IRC | 09:43 | |
*** AlexeyAbashkin has joined #openstack-keystone | 09:46 | |
*** gvrangan has quit IRC | 09:46 | |
*** gvrangan has joined #openstack-keystone | 09:46 | |
*** AlexeyAbashkin has quit IRC | 09:53 | |
openstackgerrit | Shan Guo proposed openstack/keystone master: Remove simple cert support https://review.openstack.org/515309 | 09:53 |
openstackgerrit | Shan Guo proposed openstack/keystone master: Remove simple cert support https://review.openstack.org/515309 | 09:56 |
*** sambetts|afk is now known as sambetts | 10:09 | |
*** masber has quit IRC | 10:09 | |
*** namnh has quit IRC | 10:16 | |
*** markvoelker has joined #openstack-keystone | 10:26 | |
*** gmann is now known as gmann_afk | 10:29 | |
*** nicolasbock has joined #openstack-keystone | 10:54 | |
*** markvoelker has quit IRC | 10:59 | |
*** nicolasbock has quit IRC | 11:06 | |
*** AlexeyAbashkin has joined #openstack-keystone | 11:07 | |
*** zhangjl has quit IRC | 11:08 | |
*** zhangjl has joined #openstack-keystone | 11:10 | |
*** zhangjl has quit IRC | 11:18 | |
*** nicolasbock has joined #openstack-keystone | 11:20 | |
*** masber has joined #openstack-keystone | 11:22 | |
*** zhangjl has joined #openstack-keystone | 11:26 | |
*** zhangjl has quit IRC | 11:32 | |
*** links has quit IRC | 11:36 | |
*** akrzos has quit IRC | 11:38 | |
*** zhangjl has joined #openstack-keystone | 11:42 | |
*** akrzos has joined #openstack-keystone | 11:42 | |
*** annp has quit IRC | 11:46 | |
*** zhangjl has quit IRC | 11:50 | |
*** edmondsw has joined #openstack-keystone | 11:50 | |
*** dave-mccowan has joined #openstack-keystone | 11:51 | |
*** zhangjl has joined #openstack-keystone | 11:52 | |
*** markvoelker has joined #openstack-keystone | 11:57 | |
*** magicboiz has quit IRC | 11:57 | |
*** thorst has joined #openstack-keystone | 12:01 | |
*** zhangjl has quit IRC | 12:03 | |
*** zhangjl has joined #openstack-keystone | 12:04 | |
*** raildo has joined #openstack-keystone | 12:10 | |
*** wes_dillingham has joined #openstack-keystone | 12:11 | |
*** markvoelker has quit IRC | 12:29 | |
*** panbalag has joined #openstack-keystone | 12:32 | |
*** panbalag has left #openstack-keystone | 12:32 | |
*** markvoelker has joined #openstack-keystone | 12:40 | |
*** zhangjl has quit IRC | 12:50 | |
*** zhangjl has joined #openstack-keystone | 12:51 | |
*** mvk has quit IRC | 12:52 | |
*** gvrangan has quit IRC | 13:14 | |
*** jaosorior has quit IRC | 13:16 | |
*** sbezverk has joined #openstack-keystone | 13:20 | |
*** ayoung has quit IRC | 13:22 | |
openstackgerrit | prashkre proposed openstack/keystone master: Filter users/groups in ldap with whitespaces https://review.openstack.org/515409 | 13:28 |
*** mvk has joined #openstack-keystone | 13:32 | |
*** spzala has joined #openstack-keystone | 13:35 | |
*** magicboiz has joined #openstack-keystone | 13:48 | |
*** jaosorior has joined #openstack-keystone | 13:53 | |
*** spzala has quit IRC | 13:54 | |
*** McClymontS has joined #openstack-keystone | 13:59 | |
*** spzala has joined #openstack-keystone | 14:06 | |
*** rcernin has joined #openstack-keystone | 14:08 | |
prashkre | lbragstad: Hi! Gud morning. | 14:08 |
prashkre | lbragstad: Could you please review on https://review.openstack.org/#/c/514885/ | 14:08 |
knikolla | o/ | 14:10 |
lbragstad | stable review if anyone is interested - https://review.openstack.org/#/c/514885/1 | 14:12 |
lbragstad | cc kmalloc stevemar ^ | 14:12 |
lbragstad | knikolla: prashkre o/ | 14:12 |
lbragstad | prashkre: viewed | 14:12 |
lbragstad | reviewed* | 14:12 |
*** dklyle has quit IRC | 14:15 | |
*** catintheroof has joined #openstack-keystone | 14:17 | |
*** jmlowe has joined #openstack-keystone | 14:18 | |
prashkre | lbragstad:thank you. | 14:21 |
lbragstad | prashkre: thanks for the ping | 14:26 |
*** spilla has joined #openstack-keystone | 14:34 | |
*** prashkre has quit IRC | 14:47 | |
*** david-lyle has joined #openstack-keystone | 14:48 | |
*** McClymontS has quit IRC | 15:01 | |
*** spectr has quit IRC | 15:02 | |
*** jaosorior has quit IRC | 15:02 | |
*** rcernin has quit IRC | 15:04 | |
*** josecastroleon has quit IRC | 15:18 | |
*** catintheroof has quit IRC | 15:20 | |
*** catintheroof has joined #openstack-keystone | 15:20 | |
*** catintheroof has quit IRC | 15:25 | |
*** jdwidari has joined #openstack-keystone | 15:29 | |
*** jdwidari has quit IRC | 15:29 | |
*** AlexeyAbashkin has quit IRC | 15:29 | |
*** jdwidari has joined #openstack-keystone | 15:31 | |
*** mvk has quit IRC | 15:39 | |
*** itlinux has joined #openstack-keystone | 15:39 | |
*** gyee has joined #openstack-keystone | 15:43 | |
*** Suramya has quit IRC | 15:47 | |
kmalloc | Will look soon | 15:47 |
*** jdwidari has left #openstack-keystone | 15:49 | |
*** catintheroof has joined #openstack-keystone | 15:51 | |
*** catintheroof has quit IRC | 15:55 | |
*** catintheroof has joined #openstack-keystone | 16:01 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Consolidate V2Controller functionality https://review.openstack.org/514814 | 16:03 |
stevemar | lbragstad: +1 | 16:33 |
lbragstad | stevemar: i don't think it's urgent, i'll wait for kmalloc to review | 16:34 |
*** magicboiz has quit IRC | 16:37 | |
kmalloc | do do do... | 16:42 |
*** AlexeyAbashkin has joined #openstack-keystone | 16:53 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Ensure listing projects always returns tags https://review.openstack.org/515468 | 16:53 |
*** mvk has joined #openstack-keystone | 16:54 | |
*** AlexeyAbashkin has quit IRC | 16:57 | |
*** sambetts is now known as sambetts|afk | 16:58 | |
*** panbalag has joined #openstack-keystone | 17:10 | |
*** panbalag has quit IRC | 17:12 | |
*** prashkre has joined #openstack-keystone | 17:18 | |
*** raildo has quit IRC | 17:19 | |
*** tesseract has quit IRC | 17:45 | |
*** raildo has joined #openstack-keystone | 17:46 | |
*** AlexeyAbashkin has joined #openstack-keystone | 17:48 | |
*** AlexeyAbashkin has quit IRC | 17:52 | |
*** ioggstream has quit IRC | 17:59 | |
*** phalmos has joined #openstack-keystone | 18:10 | |
*** catintheroof has quit IRC | 18:13 | |
*** phalmos has quit IRC | 18:14 | |
*** AlexeyAbashkin has joined #openstack-keystone | 18:30 | |
*** AlexeyAbashkin has quit IRC | 18:34 | |
*** spilla has quit IRC | 18:43 | |
itlinux | hello all.. I have a question since I configured fernet and LDAP. I can see all users but cannot see any groups.. this is a test env but the POC env with UUID can see the groups and the users from the LDAP same config.. just fernet diff.. it says invalid token.. uhm!! | 18:47 |
*** AlexeyAbashkin has joined #openstack-keystone | 18:47 | |
lbragstad | itlinux: what steps did you take? | 18:49 |
itlinux | well I am looking at the logs now.. it says cannot find domain.. but I can do openstack user list --domain domainname.com | 18:50 |
itlinux | and that works.. | 18:50 |
itlinux | uhm! | 18:50 |
*** catintheroof has joined #openstack-keystone | 18:51 | |
itlinux | intresting .. still says cannot find domain but from the undercloud I can see the list of users.. | 18:51 |
itlinux | uhm!! | 18:51 |
lbragstad | i'm not sure what the expected behavior is | 18:51 |
lbragstad | can you describe what you're trying to do? | 18:52 |
*** AlexeyAbashkin has quit IRC | 18:52 | |
lbragstad | with steps/ | 18:52 |
itlinux | simple tripleo deployment configured with LDAP then add the admin into that domain.com | 18:52 |
itlinux | then openstack user list --domain domain.com works.. | 18:52 |
itlinux | openstack group list --domain domain.com does not | 18:53 |
itlinux | well it's empty response.. | 18:53 |
itlinux | and the logs are giving me domain not found.. | 18:53 |
itlinux | but the openstack domain list shows the domain | 18:53 |
lbragstad | and the groups are defined in LDAP, right? | 18:54 |
lbragstad | you have nothing persisted locally in SQL | 18:54 |
itlinux | yes I have the same config on a diff locaton and I can see the groups.. | 18:54 |
itlinux | nothing in my sql.. I just created one and that shows up fine in my local default domain | 18:54 |
*** catintheroof has quit IRC | 18:56 | |
lbragstad | so you have two deployments, right? | 18:56 |
lbragstad | both should have the same exact configuration? | 18:56 |
itlinux | uhm... I see that I have 2 directories in /etc/keystone/credential-keys and the other fernet-keys | 18:57 |
lbragstad | and you're able to list groups for domain.com in the one that uses UUID just fine? | 18:57 |
itlinux | yes two deployments.. | 18:57 |
itlinux | yes correct lbragstad: | 18:57 |
lbragstad | ok - can you try switching your `keystone.conf [token] provider = fernet` in that deployment and try again? | 18:57 |
itlinux | so I wonder why I the logs are showing cannot find any domains.. | 18:57 |
*** prashkre has quit IRC | 18:58 | |
*** prashkre_ has joined #openstack-keystone | 18:58 | |
lbragstad | and make sure you run `keystone-manage fernet_setup`? | 18:58 |
itlinux | let me check the one with UUID cannot change it.. but the other is ok.. let me try | 18:58 |
itlinux | yes I have 3 controllers.. so I will do it on all three.. | 18:58 |
lbragstad | i just want to make sure it's not some ldap configuration issue | 18:58 |
itlinux | one sec.. | 18:58 |
itlinux | provider = fernet this is on the servers now.. | 19:00 |
*** lbragstad changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/5F0h9Hoe/keystone" | 19:00 | |
itlinux | well I cannot touch the other env. for now.. | 19:00 |
lbragstad | ok - it sounds like an issue with mapping groups from ldap in to keystone on the deployment that is using fernet (the token provider shouldn't be preventing that in anyway ) | 19:01 |
itlinux | yes that's what it sounds like uhm! | 19:01 |
lbragstad | there are a bunch of configuration options for ldap and groups - https://github.com/openstack/keystone/blob/master/keystone/conf/ldap.py#L257-L335 | 19:02 |
lbragstad | those are the same in each deployment? | 19:03 |
lbragstad | (are both deployments pointing to the same ldap backend?) | 19:03 |
*** prashkre__ has joined #openstack-keystone | 19:04 | |
*** prashkre_ has quit IRC | 19:04 | |
*** catintheroof has joined #openstack-keystone | 19:05 | |
*** catintheroof has quit IRC | 19:09 | |
itlinux | yes ldap backend.. | 19:13 |
itlinux | diff deployments.. | 19:13 |
itlinux | the ldap file is exactly the same.. | 19:13 |
itlinux | so the only diff is fernet and UUID.. | 19:13 |
lbragstad | hm | 19:16 |
itlinux | now I am running this openstack role add --domain b2e1c1f4988c4bd7b904cada5c5b4010 --user admin admin | 19:18 |
itlinux | and it shows.. | 19:18 |
itlinux | the AD.. groups. | 19:18 |
itlinux | intresting.. | 19:18 |
itlinux | let me try the other.. | 19:18 |
itlinux | no luck for the ldap.. but AD worked.. | 19:19 |
itlinux | uhm! | 19:19 |
*** wes_dillingham has quit IRC | 19:19 | |
itlinux | well I will try to remove it and readd it.. after lunch! thanks | 19:21 |
*** catintheroof has joined #openstack-keystone | 19:28 | |
*** jmlowe has quit IRC | 19:31 | |
lbragstad | itlinux: that's strange, so you were missing a role assignment? | 19:32 |
*** ioggstream has joined #openstack-keystone | 19:37 | |
*** harlowja has quit IRC | 19:46 | |
itlinux | no I have added the same command on both domains.. | 19:50 |
lbragstad | and now things work? | 19:52 |
itlinux | no .. will readd and see.. | 19:52 |
itlinux | no luck! crap! | 20:02 |
itlinux | http://paste.openstack.org/show/624748/ | 20:05 |
itlinux | exactly the same but domain.com cannot query groups.. | 20:06 |
*** aselius has joined #openstack-keystone | 20:15 | |
*** McClymontS has joined #openstack-keystone | 20:15 | |
*** McClymontS has quit IRC | 20:17 | |
*** jamielennox has quit IRC | 20:30 | |
*** AlexeyAbashkin has joined #openstack-keystone | 20:31 | |
*** harlowja has joined #openstack-keystone | 20:33 | |
*** jamielennox has joined #openstack-keystone | 20:34 | |
*** AlexeyAbashkin has quit IRC | 20:35 | |
*** AlexeyAbashkin has joined #openstack-keystone | 20:47 | |
*** catintheroof has quit IRC | 20:49 | |
*** thorst has quit IRC | 20:50 | |
*** AlexeyAbashkin has quit IRC | 20:52 | |
*** jamielennox has quit IRC | 20:54 | |
*** jamielennox has joined #openstack-keystone | 20:55 | |
*** ioggstream has quit IRC | 21:00 | |
*** raildo has quit IRC | 21:03 | |
*** prashkre__ has quit IRC | 21:07 | |
*** thorst has joined #openstack-keystone | 22:00 | |
*** thorst has quit IRC | 22:06 | |
*** wes_dillingham has joined #openstack-keystone | 22:11 | |
*** spzala has quit IRC | 22:14 | |
*** spzala has joined #openstack-keystone | 22:15 | |
*** spzala has quit IRC | 22:19 | |
*** spzala has joined #openstack-keystone | 22:31 | |
*** itlinux has quit IRC | 22:39 | |
*** jmlowe has joined #openstack-keystone | 22:39 | |
*** AlexeyAbashkin has joined #openstack-keystone | 22:46 | |
*** AlexeyAbashkin has quit IRC | 22:50 | |
*** AlexeyAbashkin has joined #openstack-keystone | 23:07 | |
*** AlexeyAbashkin has quit IRC | 23:11 | |
*** AlexeyAbashkin has joined #openstack-keystone | 23:27 | |
*** thorst has joined #openstack-keystone | 23:29 | |
*** AlexeyAbashkin has quit IRC | 23:32 | |
*** thorst has quit IRC | 23:43 | |
*** links has joined #openstack-keystone | 23:46 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!