Friday, 2017-12-08

*** gmann_afk is now known as gmann00:01
*** threestrands has joined #openstack-keystone00:01
*** itlinux has joined #openstack-keystone00:03
*** rcernin has quit IRC00:25
*** rcernin has joined #openstack-keystone00:25
*** seniorcrepe has joined #openstack-keystone01:00
*** gyee has quit IRC01:01
seniorcrepeCorrect me if I am wrong.. but fernet keys are 128bit AES?01:02
*** david-lyle has joined #openstack-keystone01:18
*** seniorcrepe has quit IRC01:18
*** Dinesh_Bhor has joined #openstack-keystone01:28
*** david-lyle has quit IRC01:36
lbragstadseniorcrepe yes - they consist of a 128 AES encryption key and a SHA256 HMAC signing key02:02
lbragstadhttps://cryptography.io/en/latest/fernet/#implementation02:02
*** harlowja has quit IRC02:03
*** annp has joined #openstack-keystone02:26
*** namnh has joined #openstack-keystone02:38
*** aselius has quit IRC02:42
*** zhurong has joined #openstack-keystone02:47
*** Dinesh_Bhor has quit IRC03:25
*** dave-mccowan has quit IRC03:26
openstackgerritwangxiyuan proposed openstack/keystone-specs master: Limits API  https://review.openstack.org/45570903:29
openstackgerritwangxiyuan proposed openstack/keystone master: Add schema check for authorize request token  https://review.openstack.org/52629603:37
*** links has joined #openstack-keystone03:42
openstackgerritwangxiyuan proposed openstack/keystone master: Deprecate member_role_id and member_role_name  https://review.openstack.org/52246103:46
openstackgerritwangxiyuan proposed openstack/keystone master: Remove useless function  https://review.openstack.org/52626203:46
openstackgerritwangxiyuan proposed openstack/keystone master: Remove useless function  https://review.openstack.org/52626203:51
openstackgerritwangxiyuan proposed openstack/keystone master: Remove useless function  https://review.openstack.org/52626203:54
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types for user policies  https://review.openstack.org/52620304:03
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types for policy policies  https://review.openstack.org/52619704:03
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to ec2 policies  https://review.openstack.org/52619104:04
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to credential policies  https://review.openstack.org/52618904:04
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to oauth policies  https://review.openstack.org/52618404:04
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to trust policies  https://review.openstack.org/52617604:04
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to token revocation policies  https://review.openstack.org/52617504:04
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to token policies  https://review.openstack.org/52617404:04
*** aojea has joined #openstack-keystone04:04
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to domain policies  https://review.openstack.org/52570504:04
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to role policies  https://review.openstack.org/52617104:04
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to implied role policies  https://review.openstack.org/52619304:04
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to service policies  https://review.openstack.org/52569604:05
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to project policies  https://review.openstack.org/52615904:05
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to endpoint policies  https://review.openstack.org/52569504:05
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to endpoint group policies  https://review.openstack.org/52570004:05
*** Dinesh_Bhor has joined #openstack-keystone04:06
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to identity provider policies  https://review.openstack.org/52614504:06
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to protocol policies  https://review.openstack.org/52616104:06
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to project endpoint policies  https://review.openstack.org/52616004:07
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types for revoke event policies  https://review.openstack.org/52619804:07
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to region policies  https://review.openstack.org/52569804:08
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to service provider policies  https://review.openstack.org/52617304:08
*** aojea has quit IRC04:08
openstackgerritDai Dang Van proposed openstack/keystone master: Add scope_types to policy association policies  https://review.openstack.org/52619504:09
*** Dinesh_Bhor has quit IRC04:19
*** Dinesh_Bhor has joined #openstack-keystone04:19
*** zhurong has quit IRC04:26
*** sticker has quit IRC05:03
*** rcernin has quit IRC05:11
*** threestrands has quit IRC05:24
*** harlowja has joined #openstack-keystone05:37
*** threestrands has joined #openstack-keystone05:39
*** threestrands has quit IRC05:39
*** threestrands has joined #openstack-keystone05:39
*** zhurong has joined #openstack-keystone05:40
*** rcernin has joined #openstack-keystone06:11
*** swain has joined #openstack-keystone06:12
*** harlowja has quit IRC06:14
*** threestrands has quit IRC06:28
*** Shunli has joined #openstack-keystone06:39
*** zhurong has quit IRC06:47
-openstackstatus- NOTICE: Due to some unforseen Zuul issues the gate is under very high load and extremely unstable at the moment. This is likely to persist until PST morning07:03
*** ChanServ changes topic to "Due to some unforseen Zuul issues the gate is under very high load and extremely unstable at the moment. This is likely to persist until PST morning"07:03
*** amito has quit IRC07:06
*** kencjohnston has quit IRC07:08
*** odyssey4me has quit IRC07:08
*** melwitt has quit IRC07:08
*** cmurphy has quit IRC07:08
*** cmurphy has joined #openstack-keystone07:09
*** melwitt has joined #openstack-keystone07:10
*** melwitt is now known as Guest905407:11
*** odyssey4me has joined #openstack-keystone07:12
*** kencjohnston has joined #openstack-keystone07:13
*** bhagyashri_s has joined #openstack-keystone07:28
*** david-lyle has joined #openstack-keystone07:52
*** zhurong has joined #openstack-keystone08:16
*** aojea has joined #openstack-keystone08:20
*** aojea has quit IRC08:20
*** aojea has joined #openstack-keystone08:20
*** tesseract has joined #openstack-keystone08:20
*** swain has quit IRC08:22
*** sapd__ has joined #openstack-keystone08:31
*** sapd_ has quit IRC08:31
*** aojea has quit IRC08:33
openstackgerritMehdi Abaakouk (sileht) proposed openstack/keystonemiddleware master: Add missing python-memcached requirements  https://review.openstack.org/52662408:34
openstackgerritMehdi Abaakouk (sileht) proposed openstack/keystonemiddleware master: Revert "Use oslo_cache in auth_token middleware"  https://review.openstack.org/52662808:44
openstackgerritMehdi Abaakouk (sileht) proposed openstack/keystonemiddleware master: cfg.CONF must not be used directly  https://review.openstack.org/52663108:59
*** itlinux has quit IRC09:01
*** amito has joined #openstack-keystone09:06
*** sapd__ has quit IRC09:11
*** sapd has joined #openstack-keystone09:12
*** sapd_ has joined #openstack-keystone09:22
*** sapd has quit IRC09:22
*** Shunli has quit IRC09:29
*** Dinesh_Bhor has quit IRC09:37
*** gmann is now known as gmann_afk09:48
*** annp has quit IRC10:07
*** namnh has quit IRC10:19
*** daidv has quit IRC10:38
*** zhurong has quit IRC10:40
*** hoonetorg has quit IRC10:44
*** hoonetorg has joined #openstack-keystone10:46
*** openstackgerrit has quit IRC11:17
*** links has quit IRC11:28
*** links has joined #openstack-keystone11:41
*** dave-mccowan has joined #openstack-keystone11:45
*** tesseract has quit IRC11:50
*** tesseract has joined #openstack-keystone11:51
*** raildo has joined #openstack-keystone12:00
*** efried is now known as fried_rice12:29
*** jaosorior has quit IRC13:12
*** jaosorior has joined #openstack-keystone13:13
*** aojea has joined #openstack-keystone13:33
*** aojea has quit IRC13:37
*** markvoelker has quit IRC13:40
*** markvoelker has joined #openstack-keystone13:43
*** panbalag has joined #openstack-keystone13:45
*** panbalag has left #openstack-keystone13:45
*** tesseract has quit IRC13:47
*** tesseract has joined #openstack-keystone13:50
*** crepe has joined #openstack-keystone13:55
crepeHopped off last night so I apologize if this was answered.. I read in the docs that keystone uses aes256 with fernet, but it looks like fernet only supports 128?13:55
cmurphycrepe: lbragstad responded just after you left http://eavesdrop.openstack.org/irclogs/%23openstack-keystone/%23openstack-keystone.2017-12-08.log.html#t2017-12-08T02:02:5613:58
crepeThanks!13:58
cmurphyno problem13:59
*** ChanServ changes topic to "Queens release schedule: https://releases.openstack.org/queens/schedule.html | Meeting agenda: https://etherpad.openstack.org/p/keystone-weekly-meeting | Bugs that need triaging: http://bit.ly/2iJuN1h | Trello: https://trello.com/b/5F0h9Hoe/keystone"13:59
-openstackstatus- NOTICE: The issues have been fixed, Zuul is operating fine again but has a large backlog. You can recheck jobs that failed.13:59
crepeIts more of a curiosity at this point.. but I believe this means that fernet+keystone wouldn't satisfy FIPS requirements. If not FIPS then there are other requirements that it wouldn't satisfy. I guess the alternative would be to use PKI instead of fernet14:00
cmurphywe don't support PKI tokens any more14:01
cmurphycrepe: have a link handy for those specifications?14:01
crepeYea lemme track down something that I can link14:01
cmurphywe're also working on implementing JWT as an alternative token format http://specs.openstack.org/openstack/keystone-specs/specs/keystone/backlog/json-web-tokens.html14:02
lbragstadcrepe: let me know if you find a link, i'd be interested in that14:11
lbragstadcmurphy: that'd be another good reason to do JWT... if JWT is FIPS compliant?14:14
cmurphyI don't know much about fips compliance except that it makes compiling openssl a pita :P14:15
crepeHeh yea FIPS can be a pain. So far I have found this: https://www.iad.gov/iad/customcf/openAttachment.cfm?FilePath=/iad/library/ia-guidance/ia-solutions-for-classified/algorithm-guidance/assets/public/upload/CNSA-Suite-and-Quantum-Computing-FAQ.pdf&WpKes=aF6woL7fQp3dJiaUTzJUSR35PvDWGNkSuyZ38R14:18
crepeReal links are hard to find. Standards for different classification levels now appear to require AES256, but again I am having a hard time finding a good link. The Information Assurance one is probably the best I can find for now14:21
crepeAgain like I said, not a huge deal and at this point more of a curiosity.14:22
cmurphyI'd be interested if there are companies rejecting using openstack/keystone because of non-FIPS compliance, we've certainly been working towards becoming PCI compiant14:24
*** dansmith is now known as superdan14:25
crepeI'd imagine waivers could be / have been granted but it'd be nice to eventually be FIPS/DoD compliant14:26
crepeAlthough that is an ever-moving target14:26
cmurphylbragstad: i finally went through https://review.openstack.org/#/c/455709 top to bottom again and i'm worried it's not fully fleshed out yet :/ feel bad about getting to it so late though :(14:29
*** links has quit IRC14:37
lbragstadcmurphy: i'll read up on your comments14:38
lbragstadcmurphy: in your opinion, what do you think the hierarchy check is on line 407?14:42
cmurphylbragstad: what i meant by "keystone cannot do any hierarchical checks" was wrt the hierarchical quota model, if we don't have the model defined then keystone doesn't have rules to follow when checking the limits in the hierarchy14:48
lbragstadok14:49
lbragstadso - we would allow for limits to be associated to projects (that may or may not be in a hierarchy)14:51
lbragstadand then enabled enforcement of limits based on the hierarchy in a subsequent release?14:51
lbragstad(would that be backwards incompatible?)14:51
lbragstador - would we only allow you to set limits on projects that *aren't* in a hierarchy14:52
*** Guest9054 is now known as melwitt14:52
lbragstadi wish sdague was around14:54
cmurphythat might work14:54
cmurphyi was thinking about the backwards compat issue14:54
lbragstadyeah...14:54
lbragstadthat's going to be tricky14:54
cmurphyand thinking we'd need some kind of discovery mechanism14:54
cmurphybut if we just forbid using it on a project in a hierarchy that might circumvent the problem14:55
lbragstadespecially if people start associating invalid limits to projects in a hierarchy, and then we go and implement proper validation14:55
*** spilla has joined #openstack-keystone14:55
*** rcernin has quit IRC14:55
cmurphysdague is online just not here14:56
lbragstadcmurphy: should we move this to -dev?14:56
lbragstadin hopes of attracting someone from bm/vm14:56
cmurphy++14:56
kmalloclbragstad: responded to your comments on the PRoviderAPIs patch15:23
kmalloctl;dr, yep, only _provides_api attr is needed on the manager(S)15:23
*** samuelbartel has joined #openstack-keystone15:24
kmalloclbragstad: i think it would be backwards incompat if suddenly we checked the hierarchy for quota limit restrictions15:24
kmalloccmurphy: ^ cc15:25
cmurphykmalloc: yeah, my idea was to have some kind of discovery mechanism to get around that but in -dev i think we settled on just forbidding applying limits to child projects15:26
kmallocwfm15:27
*** openstackgerrit has joined #openstack-keystone15:28
openstackgerritwangxiyuan proposed openstack/keystone-specs master: Limits API  https://review.openstack.org/45570915:28
cmurphyoh wxy is still awake :)15:28
lbragstadcmurphy: kmalloc we have sdague's attention in -dev :)15:33
lbragstadcc wxy ^15:34
kmallocok i need coffee and food.16:13
*** jaosorior has quit IRC16:13
* kmalloc goes to wake up family members for said coffee and foodz16:13
*** itlinux has joined #openstack-keystone16:14
lbragstadkmalloc: cmurphy think we can re-write the spec to target the "flat" model for queens/16:20
*** MasterOfBugs has joined #openstack-keystone16:22
*** pramodrj07 has joined #openstack-keystone16:22
*** samuelbartel has quit IRC16:24
cmurphylbragstad: I think it can be done, not sure about the timeline :)16:31
lbragstadalright - i'll repropose the specification today16:31
lbragstadi think it will simplify the implementation16:31
*** AlexeyAbashkin has joined #openstack-keystone16:40
*** itlinux has quit IRC16:42
*** itlinux has joined #openstack-keystone16:43
*** AlexeyAbashkin has quit IRC16:44
openstackgerritMerged openstack/keystone master: Updated from global requirements  https://review.openstack.org/52637716:46
cmurphylbragstad: do you think you want to extend the spec deadline? if so i'll add it to my email16:49
lbragstadi think we could just submit a spec freeze exception16:50
lbragstadfor this spec - everything else is pretty set16:50
cmurphy++16:50
*** d0ugal has quit IRC16:52
*** d0ugal has joined #openstack-keystone16:54
*** d0ugal has quit IRC16:54
*** d0ugal has joined #openstack-keystone16:54
*** david-lyle has quit IRC16:57
*** itlinux has quit IRC17:00
*** itlinux has joined #openstack-keystone17:05
*** gyee has joined #openstack-keystone17:14
*** tesseract has quit IRC17:29
*** raildo has quit IRC17:29
*** spilla has quit IRC17:33
*** david-lyle has joined #openstack-keystone17:36
*** fried_rice is now known as fried_rolls17:41
*** raildo has joined #openstack-keystone17:53
openstackgerritLance Bragstad proposed openstack/keystone-specs master: Update unified limits spec to clarify flat-ness  https://review.openstack.org/52674517:57
lbragstadwxy: cmurphy kmalloc ^17:57
*** openstackgerrit has quit IRC18:03
*** crepe has quit IRC18:03
*** panbalag has joined #openstack-keystone18:07
*** raildo has quit IRC18:12
*** raildo has joined #openstack-keystone18:13
*** r-daneel has joined #openstack-keystone18:15
*** david-lyle has quit IRC18:21
*** aselius has joined #openstack-keystone18:33
* lbragstad breaks for lunch18:37
*** panbalag has left #openstack-keystone18:41
*** openstackgerrit has joined #openstack-keystone19:05
openstackgerritLance Bragstad proposed openstack/keystone-specs master: Update unified limits spec to clarify flat-ness  https://review.openstack.org/52674519:06
openstackgerritLance Bragstad proposed openstack/keystone-specs master: Fix line-too-long error  https://review.openstack.org/52675619:07
*** aojea has joined #openstack-keystone19:08
*** pramodrj07 has quit IRC19:13
*** MasterOfBugs has quit IRC19:13
*** aojea has quit IRC19:15
*** harlowja has joined #openstack-keystone19:21
*** raildo has quit IRC19:25
*** MasterOfBugs has joined #openstack-keystone19:27
*** pramodrj07 has joined #openstack-keystone19:27
*** __david has joined #openstack-keystone19:29
*** AlexeyAbashkin has joined #openstack-keystone19:46
__davidI'm trying to setup swift3 ( S3 API compatibility with Openstack Swift) and I'm having issues with the s3_extension function of keystone.  In the staging setup I have, the logs show 404 on POST requests to /v2.0/s3tokens on the Keystone admin service . I believe the POST is coming from the s3token middelware in Swift.19:50
*** fried_rolls is now known as fried_rice19:53
timburke__david: it is. following https://github.com/openstack/swift3/commit/2a48861 you can configure s3token to use v3 keystone with `auth_version = 3`19:53
timburkethat path component used to be hardcoded, so swift3 couldn't use a sane default :-(19:54
*** raildo has joined #openstack-keystone19:55
*** AlexeyAbashkin has quit IRC19:56
*** jmlowe has quit IRC20:04
*** jmlowe has joined #openstack-keystone20:10
__david@timburke - I'm using ver 1.12 of swift3, so I have that commit. My proxy server config has the s3token section with the following20:11
__davidreseller_prefix = AUTH_ delay_auth_decision = False auth_uri = https://keystone-url:35357/ auth_version = 2.0 http_timeout = 10.020:11
timburke__david: right. and i'm guessing it's a v3-only keystone install? i think just changing that "auth_version = 2.0" to be "auth_version = 3" will square you20:13
__david@timburke it's v2.0 and v3. We only use v2.0 actually.20:14
timburkeoh, weird then... does the keystone wsgi pipeline include s3_extension?20:14
*** sbezverk has joined #openstack-keystone20:14
__davidI think keystone-paste.ini is unchanged from the example in the keystone etc folder. admin composite in keystone-paste.ini maps /v2.0 to admin_api which has the following: pipeline = cors sizelimit http_proxy_to_wsgi osprofiler url_normalize request_id admin_token_auth build_auth_context token_auth json_body ec2_extension s3_extension admin_service20:16
*** david-lyle has joined #openstack-keystone20:16
__davidkeystone is from the newton release and swift is pike, with the 1.12 swift3 release fwiw20:17
*** ChanServ has quit IRC20:17
*** ChanServ has joined #openstack-keystone20:24
*** barjavel.freenode.net sets mode: +o ChanServ20:24
*** sbezverk has quit IRC20:29
__davidDoes anyone know why the word "admin" is in the middle of the URL in this log entry:20:31
__david2017-12-08 20:30:03.752 1385 INFO keystone.common.wsgi [req-e6df7039-d024-4f50-b4c8-e315377ee59b - - - - -] POST https://lax-staging.identity.sohonet.com:35357admin/v2.0/s3tokens20:31
*** sbezverk has joined #openstack-keystone20:31
*** david-lyle has quit IRC20:32
openstackgerritLance Bragstad proposed openstack/keystone-specs master: Update unified limits spec to clarify flat-ness  https://review.openstack.org/52674520:37
*** dgonzalez has left #openstack-keystone20:45
*** itlinux has quit IRC20:55
*** itlinux has joined #openstack-keystone20:59
*** sbezverk has quit IRC21:02
*** kuma has joined #openstack-keystone21:09
*** fried_rice is now known as efried_cya_jan21:12
jdennisworkflow question, I submitted a gerrit review and in the commit message it said "Closes-Bug: xxxx" but the launchpad bug was never updated with the proposed fix, it was suggested to me this might be because there was no # in front of the bug number, the documented workflow does not show using a #, is the missing # causing it to fail linking the review to the bug? BTW the review is https://review.openstack.org/#/c/525744/ and21:13
jdennis the bug is https://bugs.launchpad.net/os-client-config/+bug/163569621:13
openstackLaunchpad bug 1635696 in os-client-config "Having a '{' or '}' in password causes formatting errors" [High,Confirmed] - Assigned to John Dennis (jdennis-a)21:13
lbragstadjdennis: sometimes the underlying infrastructure misses reviews21:15
lbragstadi don't think i could tell you why though21:15
jdennislbragstad: I could add a comment in the bug pointing to the review but that would hid it from the rest of the tool chain I suspect, is there a recommend way to fix this? Or is it a non-issue?21:16
lbragstadhonestly, ^ that's usually what I do21:17
lbragstadi just leave a comment in the bug so that others can find it21:17
jdennislbragstad: thanks, OK21:17
*** david-lyle has joined #openstack-keystone21:24
*** dave-mccowan has quit IRC21:25
*** kuma has quit IRC21:25
*** david-lyle has quit IRC21:29
*** panbalag has joined #openstack-keystone21:34
*** panbalag has quit IRC21:42
*** rcernin has joined #openstack-keystone21:44
*** panbalag has joined #openstack-keystone21:55
*** edmondsw has joined #openstack-keystone21:55
*** edmondsw has quit IRC21:56
*** itlinux has quit IRC22:01
*** rcernin has quit IRC22:03
*** rcernin has joined #openstack-keystone22:03
*** raildo has quit IRC22:07
*** itlinux has joined #openstack-keystone22:17
*** itlinux has quit IRC22:18
*** gmann_afk is now known as gmann22:21
lbragstadgagehugo: FYI - https://review.openstack.org/#/c/526525/122:39
lbragstadwe'll catch the project tags client stuff in queens-322:39
lbragstador whenever it's done, i can roll another python-keystoneclient release.22:39
*** panbalag has left #openstack-keystone22:46
lbragstadstepping away for a bit, have a good weekend all!22:49
openstackgerritJaewoo Park proposed openstack/python-keystoneclient master: Add project tags to keystoneclient  https://review.openstack.org/48122323:02
*** aojea has joined #openstack-keystone23:13
*** aojea has quit IRC23:18
*** markvoelker has quit IRC23:49
*** markvoelker has joined #openstack-keystone23:50
*** markvoelker has quit IRC23:54

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!