*** odyssey4me has quit IRC | 00:10 | |
*** odyssey4me has joined #openstack-keystone | 00:10 | |
*** germs has joined #openstack-keystone | 00:11 | |
*** germs has quit IRC | 00:11 | |
*** germs has joined #openstack-keystone | 00:11 | |
*** itlinux has joined #openstack-keystone | 00:12 | |
*** germs has quit IRC | 00:15 | |
*** AlexeyAbashkin has joined #openstack-keystone | 00:18 | |
*** AlexeyAbashkin has quit IRC | 00:22 | |
*** r-daneel has quit IRC | 00:31 | |
openstackgerrit | Adrian Turjak proposed openstack/keystone-specs master: Add spec for MFA auth receipts https://review.openstack.org/553670 | 00:37 |
---|---|---|
*** felipemonteiro_ has joined #openstack-keystone | 00:52 | |
*** felipemonteiro__ has joined #openstack-keystone | 00:54 | |
*** felipemonteiro_ has quit IRC | 00:58 | |
*** harlowja has quit IRC | 01:07 | |
*** AlexeyAbashkin has joined #openstack-keystone | 01:18 | |
*** AlexeyAbashkin has quit IRC | 01:22 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Limit description support https://review.openstack.org/553132 | 01:25 |
*** felipemonteiro_ has joined #openstack-keystone | 01:32 | |
*** felipemonteiro__ has quit IRC | 01:32 | |
*** wes_dillingham has quit IRC | 01:35 | |
lbragstad | wxy: thanks for the comments on https://review.openstack.org/#/c/554320/ | 01:54 |
*** dangtrinhnt has joined #openstack-keystone | 01:54 | |
wxy | lbragstad: thanks for your spec proposal. :) | 01:55 |
lbragstad | yeah - no problem | 01:56 |
lbragstad | you're doing the hard work :) | 01:56 |
lbragstad | i wanted to update that spec today, but i ran out of time | 01:57 |
wxy | lbragstad: it doesn't matter. I spent most time on yaml catalog, limit things and some glance stuff these few days. I have to pay attention on token refactor next. | 02:00 |
lbragstad | yeah.. i have to pick that back up... | 02:01 |
lbragstad | the tests actually pass, but pep8 fails due to the complexity of some of the logic | 02:01 |
*** panbalag has quit IRC | 02:12 | |
*** AlexeyAbashkin has joined #openstack-keystone | 02:18 | |
*** AlexeyAbashkin has quit IRC | 02:23 | |
*** dangtrinhnt has quit IRC | 02:35 | |
*** zhurong has joined #openstack-keystone | 02:40 | |
*** felipemonteiro_ has quit IRC | 02:55 | |
*** dave-mccowan has quit IRC | 03:16 | |
*** zhurong has quit IRC | 03:44 | |
*** links has joined #openstack-keystone | 04:00 | |
*** links has quit IRC | 04:00 | |
*** harlowja has joined #openstack-keystone | 04:39 | |
*** harlowja has quit IRC | 04:56 | |
*** rybridges has quit IRC | 05:30 | |
*** rybridges has joined #openstack-keystone | 05:43 | |
*** rybridges has quit IRC | 05:51 | |
*** rybridges has joined #openstack-keystone | 06:04 | |
*** masuberu has quit IRC | 06:04 | |
*** zhurong has joined #openstack-keystone | 06:04 | |
*** rybridges has quit IRC | 06:09 | |
*** germs has joined #openstack-keystone | 06:13 | |
*** germs has quit IRC | 06:13 | |
*** germs has joined #openstack-keystone | 06:13 | |
*** germs has quit IRC | 06:18 | |
*** rybridges has joined #openstack-keystone | 06:23 | |
*** masber has joined #openstack-keystone | 06:31 | |
*** gus has quit IRC | 06:34 | |
*** gus has joined #openstack-keystone | 06:36 | |
*** pcichy has joined #openstack-keystone | 06:44 | |
*** wxy_ has quit IRC | 06:51 | |
*** gongysh has joined #openstack-keystone | 06:55 | |
*** aojea has joined #openstack-keystone | 06:57 | |
*** jaosorior has quit IRC | 07:05 | |
*** masber has quit IRC | 07:05 | |
*** masber has joined #openstack-keystone | 07:06 | |
*** aojea has quit IRC | 07:13 | |
*** aojea has joined #openstack-keystone | 07:14 | |
*** rcernin has quit IRC | 07:21 | |
*** voelzmo has joined #openstack-keystone | 07:21 | |
*** aojea has quit IRC | 07:28 | |
*** martinus__ has joined #openstack-keystone | 07:37 | |
*** jaosorior has joined #openstack-keystone | 07:44 | |
*** AlexeyAbashkin has joined #openstack-keystone | 07:55 | |
*** jmlowe has quit IRC | 07:57 | |
*** aojea_ has joined #openstack-keystone | 08:20 | |
*** aojea_ has quit IRC | 08:25 | |
*** tesseract has joined #openstack-keystone | 08:31 | |
*** brad[] has quit IRC | 08:34 | |
*** masber has quit IRC | 08:40 | |
*** Supun has joined #openstack-keystone | 08:46 | |
*** tesseract has quit IRC | 08:51 | |
*** tesseract has joined #openstack-keystone | 08:52 | |
*** tesseract has quit IRC | 08:54 | |
*** tesseract has joined #openstack-keystone | 08:57 | |
*** zhurong has quit IRC | 09:04 | |
*** zhurong has joined #openstack-keystone | 09:13 | |
*** masber has joined #openstack-keystone | 09:20 | |
openstackgerrit | Jens Harbott (frickler) proposed openstack/keystoneauth master: Be more helpful when version discovery fails https://review.openstack.org/554044 | 09:21 |
*** gongysh has quit IRC | 09:30 | |
*** Supun has quit IRC | 09:33 | |
*** voelzmo has quit IRC | 09:54 | |
*** voelzmo has joined #openstack-keystone | 09:55 | |
*** voelzmo has quit IRC | 09:55 | |
*** voelzmo has joined #openstack-keystone | 09:56 | |
*** voelzmo has quit IRC | 10:00 | |
openstackgerrit | yangweiwei proposed openstack/keystone master: Fix user email in federated shadow users https://review.openstack.org/549723 | 10:05 |
*** aojea_ has joined #openstack-keystone | 10:08 | |
*** aojea_ has quit IRC | 10:14 | |
*** sapd_ has quit IRC | 10:38 | |
*** sapd has joined #openstack-keystone | 10:39 | |
*** zhurong has quit IRC | 10:55 | |
*** voelzmo has joined #openstack-keystone | 11:04 | |
*** gyankum has joined #openstack-keystone | 11:10 | |
*** wes_dillingham has joined #openstack-keystone | 11:14 | |
*** pcichy has quit IRC | 11:27 | |
*** voelzmo has quit IRC | 11:32 | |
*** MeltedLux has quit IRC | 11:41 | |
*** wes_dillingham has quit IRC | 11:55 | |
*** aojea_ has joined #openstack-keystone | 11:57 | |
*** aojea_ has quit IRC | 12:01 | |
*** odyssey4me has quit IRC | 12:03 | |
*** odyssey4me has joined #openstack-keystone | 12:03 | |
*** jmlowe has joined #openstack-keystone | 12:08 | |
*** wes_dillingham has joined #openstack-keystone | 12:09 | |
*** raildo has joined #openstack-keystone | 12:12 | |
*** raildo has quit IRC | 12:14 | |
*** raildo has joined #openstack-keystone | 12:24 | |
*** edmondsw has joined #openstack-keystone | 12:40 | |
*** panbalag has joined #openstack-keystone | 12:50 | |
*** felipemonteiro_ has joined #openstack-keystone | 13:01 | |
*** felipemonteiro__ has joined #openstack-keystone | 13:02 | |
*** germs has joined #openstack-keystone | 13:04 | |
*** germs has quit IRC | 13:04 | |
*** germs has joined #openstack-keystone | 13:04 | |
*** felipemonteiro_ has quit IRC | 13:06 | |
*** panbalag has left #openstack-keystone | 13:06 | |
*** panbalag has joined #openstack-keystone | 13:31 | |
*** mvk has quit IRC | 13:31 | |
*** brad[] has joined #openstack-keystone | 13:38 | |
*** jdennis has quit IRC | 13:39 | |
*** jdennis has joined #openstack-keystone | 13:39 | |
*** dklyle has joined #openstack-keystone | 13:44 | |
*** david-lyle has quit IRC | 13:44 | |
*** mvk has joined #openstack-keystone | 13:47 | |
*** aojea_ has joined #openstack-keystone | 13:50 | |
*** aojea_ has quit IRC | 13:53 | |
*** aojea_ has joined #openstack-keystone | 13:54 | |
*** idlemind has joined #openstack-keystone | 13:54 | |
*** itlinux has quit IRC | 14:16 | |
*** itlinux has joined #openstack-keystone | 14:17 | |
*** aojea_ has quit IRC | 14:18 | |
*** itlinux has quit IRC | 14:22 | |
knikolla | o/ | 14:23 |
*** r-daneel has joined #openstack-keystone | 14:25 | |
lbragstad | o/ | 14:26 |
lbragstad | some good discussion in -tc this morning | 14:26 |
SamYaple | "zuul people" lol | 14:26 |
lbragstad | just skimmed the scroll back | 14:27 |
*** felipemonteiro__ has quit IRC | 14:47 | |
*** aojea_ has joined #openstack-keystone | 14:47 | |
*** dave-mccowan has joined #openstack-keystone | 14:47 | |
*** felipemonteiro__ has joined #openstack-keystone | 14:47 | |
*** germs has quit IRC | 14:51 | |
*** gyankum has quit IRC | 14:51 | |
*** aojea_ has quit IRC | 14:51 | |
*** felipemonteiro_ has joined #openstack-keystone | 14:52 | |
*** germs has joined #openstack-keystone | 14:52 | |
*** felipemonteiro__ has quit IRC | 14:55 | |
gagehugo | o/ | 14:58 |
*** felipemonteiro__ has joined #openstack-keystone | 15:07 | |
*** Drankis has joined #openstack-keystone | 15:10 | |
*** felipemonteiro_ has quit IRC | 15:11 | |
lbragstad | reminder that the policy meeting will be starting in ~8 minutes | 15:52 |
*** Drankis has quit IRC | 15:52 | |
* cmurphy going to miss it | 15:56 | |
lbragstad | ack | 15:58 |
lbragstad | we have a pretty light agenda... | 15:58 |
*** itlinux has joined #openstack-keystone | 16:07 | |
*** itlinux has quit IRC | 16:15 | |
lbragstad | dims: ping | 16:16 |
dims | pong @lbragstad | 16:16 |
lbragstad | qq on the oslo.policy spec for additional attributes - https://review.openstack.org/#/c/552045/1/specs/rocky/consistent-policy-attributes.rst | 16:17 |
lbragstad | maybe i should have started this conversation in -oslo? | 16:17 |
dims | ++ lbragstad | 16:18 |
lbragstad | ok - moving there | 16:18 |
*** masber has quit IRC | 16:27 | |
*** AlexeyAbashkin has quit IRC | 16:29 | |
*** aojea_ has joined #openstack-keystone | 16:32 | |
*** aojea_ has quit IRC | 16:36 | |
*** gyee has joined #openstack-keystone | 16:38 | |
*** itlinux has joined #openstack-keystone | 16:50 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove references to v2.0 from external developer doc https://review.openstack.org/554690 | 16:58 |
*** bradjones has quit IRC | 17:03 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Fix tags and tags-any filter interaction https://review.openstack.org/553108 | 17:04 |
*** felipemonteiro__ has quit IRC | 17:11 | |
*** felipemonteiro__ has joined #openstack-keystone | 17:11 | |
*** jmlowe has quit IRC | 17:37 | |
*** NobodyCam has quit IRC | 17:37 | |
*** r-daneel has quit IRC | 17:37 | |
*** r-daneel has joined #openstack-keystone | 17:37 | |
*** gus has quit IRC | 17:38 | |
*** gmann_ has quit IRC | 17:38 | |
*** NobodyCam has joined #openstack-keystone | 17:39 | |
*** andreaf has quit IRC | 17:39 | |
*** gus has joined #openstack-keystone | 17:39 | |
*** andreaf_ has joined #openstack-keystone | 17:39 | |
*** gmann_ has joined #openstack-keystone | 17:40 | |
*** felipemonteiro_ has joined #openstack-keystone | 17:40 | |
*** andreaf_ is now known as andreaf | 17:41 | |
*** felipemonteiro__ has quit IRC | 17:41 | |
*** spilla has joined #openstack-keystone | 17:44 | |
*** Drankis has joined #openstack-keystone | 17:47 | |
*** panbalag has quit IRC | 17:49 | |
openstackgerrit | ayoung proposed openstack/keystone-specs master: Add whitelist-extension-for-app-creds https://review.openstack.org/396331 | 17:54 |
*** felipemonteiro__ has joined #openstack-keystone | 18:02 | |
*** AlexeyAbashkin has joined #openstack-keystone | 18:03 | |
*** felipemonteiro_ has quit IRC | 18:06 | |
*** jmlowe has joined #openstack-keystone | 18:15 | |
*** aojea_ has joined #openstack-keystone | 18:20 | |
*** AlexeyAbashkin has quit IRC | 18:21 | |
*** EmilienM is now known as mimi | 18:21 | |
*** mimi is now known as EmilienM | 18:21 | |
*** NM has joined #openstack-keystone | 18:23 | |
*** harlowja has joined #openstack-keystone | 18:24 | |
*** aojea_ has quit IRC | 18:25 | |
*** jmlowe has quit IRC | 18:36 | |
lbragstad | kmalloc: not sure how busy you are today, but i'm wondering if we could step through https://review.openstack.org/#/c/545450/ | 18:42 |
kmalloc | sure | 18:42 |
kmalloc | bluejeans/hangout? | 18:43 |
lbragstad | either or | 18:43 |
kmalloc | https://bluejeans.com/5606719471 | 18:44 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Make tags filter match subset rather than exact https://review.openstack.org/553108 | 18:44 |
lbragstad | in case anyone else is interested in walking through a way forward with https://review.openstack.org/#/c/545450/ | 18:45 |
*** jmlowe has joined #openstack-keystone | 18:46 | |
*** raildo has quit IRC | 18:52 | |
*** jmlowe has quit IRC | 18:57 | |
* gagehugo is stuck in a meeting | 19:04 | |
*** jmlowe has joined #openstack-keystone | 19:06 | |
*** mvk has quit IRC | 19:09 | |
*** felipemonteiro__ has quit IRC | 19:13 | |
*** felipemonteiro__ has joined #openstack-keystone | 19:13 | |
*** AlexeyAbashkin has joined #openstack-keystone | 19:17 | |
*** oikiki has joined #openstack-keystone | 19:18 | |
*** AlexeyAbashkin has quit IRC | 19:21 | |
*** jaosorior has quit IRC | 19:23 | |
SamYaple | im hitting "Invalid domain name (MYDOMAIN) found in config file name" where MYDOMAIN is all caps | 19:28 |
SamYaple | but when i create the domain `openstack domain create MYDOMAIN` it and restart keystone it works | 19:29 |
SamYaple | anyone seen that? | 19:29 |
*** panbalag has joined #openstack-keystone | 19:35 | |
*** panbalag has left #openstack-keystone | 19:35 | |
*** tesseract has quit IRC | 19:38 | |
*** jaosorior has joined #openstack-keystone | 19:44 | |
SamYaple | ah looking through the commit history itappears that is intentional behaviour to require a restart of keystone | 19:47 |
*** anyone is now known as eschwartz | 19:48 | |
openstackgerrit | Merged openstack/python-keystoneclient master: Updated from global requirements https://review.openstack.org/549565 | 19:58 |
*** aojea has joined #openstack-keystone | 20:08 | |
*** aojea has quit IRC | 20:14 | |
*** Krenair has quit IRC | 20:14 | |
*** Krenair has joined #openstack-keystone | 20:18 | |
*** AlexeyAbashkin has joined #openstack-keystone | 20:18 | |
*** wes_dillingham has quit IRC | 20:21 | |
*** AlexeyAbashkin has quit IRC | 20:22 | |
*** Krenair has quit IRC | 20:22 | |
*** Krenair has joined #openstack-keystone | 20:30 | |
*** jaosorior_ has joined #openstack-keystone | 20:33 | |
*** jaosorior has quit IRC | 20:37 | |
*** Krenair has quit IRC | 20:41 | |
adriant | lbragstad, kmalloc: Totally unrelated to receipts, I am curious though if key rotation of 15mins is something anyone would do? Doesn't that mean your tokens at last between 30-15mins? Or can you make fernet use X number of old keys for decryption, but only ever have 15mins worth of time when a key is used for generation? | 20:42 |
*** Krenair has joined #openstack-keystone | 20:42 | |
kmalloc | doubtful | 20:43 |
lbragstad | adriant: it depends on the number of max_active_keys in the repository | 20:49 |
*** aojea has joined #openstack-keystone | 20:49 | |
lbragstad | you can rotate every 15 minutes and have max_active_keys set to 40 - which means you tokens will be around for 10 hours before being invalidated because the key is missing | 20:50 |
lbragstad | your* | 20:50 |
*** Krenair has quit IRC | 20:54 | |
adriant | lbragstad: thanks, had a feeling that was the case but it's been too long since I looked at that properly | 20:55 |
*** jmlowe has quit IRC | 20:56 | |
*** Krenair has joined #openstack-keystone | 21:02 | |
*** Krenair has joined #openstack-keystone | 21:10 | |
adriant | lbragstad: what's the recommended key rotation period? | 21:13 |
*** raildo has joined #openstack-keystone | 21:15 | |
*** AlexeyAbashkin has joined #openstack-keystone | 21:17 | |
*** AlexeyAbashkin has quit IRC | 21:21 | |
*** jmlowe has joined #openstack-keystone | 21:21 | |
lbragstad | adriant: that totally depends on your deployments security model | 21:25 |
adriant | lbragstad: and I guess the volume of traffic you expect | 21:26 |
adriant | well, volume of token requests | 21:26 |
lbragstad | adriant: https://www.youtube.com/watch?v=702SRZHdNW8&feature=youtu.be&t=12m5s | 21:30 |
lbragstad | we worked that into a presentation because we get that question quite a bit | 21:30 |
*** felipemonteiro_ has joined #openstack-keystone | 21:32 | |
*** NM has quit IRC | 21:33 | |
adriant | lbragstad: huh, I have actually seen that video, I'm just having a slow brain day it seems. | 21:35 |
adriant | thanks! | 21:35 |
lbragstad | adriant: yep - anytime! | 21:35 |
*** felipemonteiro__ has quit IRC | 21:35 | |
openstackgerrit | Merged openstack/keystone master: Mark the implied role API as stable https://review.openstack.org/550611 | 21:42 |
*** Krenair has quit IRC | 21:43 | |
*** itlinux has quit IRC | 21:51 | |
*** Krenair_ has joined #openstack-keystone | 21:53 | |
*** spilla has quit IRC | 21:55 | |
*** pcaruana has quit IRC | 21:55 | |
openstackgerrit | Adrian Turjak proposed openstack/keystone-specs master: Add spec for MFA auth receipts https://review.openstack.org/553670 | 21:56 |
*** Krenair_ has quit IRC | 21:57 | |
*** Krenair_ has joined #openstack-keystone | 22:00 | |
*** martinus__ has quit IRC | 22:12 | |
*** raildo has quit IRC | 22:15 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Add functional testing gate https://review.openstack.org/531014 | 22:18 |
*** rcernin has joined #openstack-keystone | 22:25 | |
*** threestrands has joined #openstack-keystone | 22:29 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: WIP: rewrite keystone https://review.openstack.org/545450 | 22:29 |
*** felipemonteiro_ has quit IRC | 22:29 | |
lbragstad | kmalloc: reworked ^ | 22:29 |
*** felipemonteiro_ has joined #openstack-keystone | 22:29 | |
lbragstad | for some reason it's failing 4 python 3.5 tests... | 22:30 |
*** threestrands has quit IRC | 22:30 | |
*** threestrands has joined #openstack-keystone | 22:30 | |
*** threestrands has quit IRC | 22:30 | |
*** threestrands has joined #openstack-keystone | 22:30 | |
*** Krenair_ has quit IRC | 22:31 | |
*** Krenair has joined #openstack-keystone | 22:34 | |
*** d0ugal has quit IRC | 22:34 | |
*** d0ugal has joined #openstack-keystone | 22:37 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Add functional testing gate https://review.openstack.org/531014 | 22:43 |
*** aojea has quit IRC | 22:54 | |
*** aojea has joined #openstack-keystone | 22:54 | |
*** aojea has quit IRC | 22:55 | |
*** aojea has joined #openstack-keystone | 22:55 | |
*** aojea has quit IRC | 22:55 | |
*** masber has joined #openstack-keystone | 23:04 | |
*** raildo has joined #openstack-keystone | 23:06 | |
*** edmondsw has quit IRC | 23:07 | |
*** oikiki has quit IRC | 23:16 | |
*** itlinux has joined #openstack-keystone | 23:20 | |
*** oikiki has joined #openstack-keystone | 23:23 | |
*** Krenair has quit IRC | 23:28 | |
*** r-daneel has quit IRC | 23:30 | |
*** Krenair has joined #openstack-keystone | 23:38 | |
*** felipemonteiro_ has quit IRC | 23:41 | |
*** Krenair has quit IRC | 23:43 | |
*** gyee has quit IRC | 23:45 | |
*** Krenair has joined #openstack-keystone | 23:52 | |
*** wes_dillingham has joined #openstack-keystone | 23:53 | |
kmalloc | lbragstad: check to make sure the issued_at is the same as the fernet timestamp? | 23:57 |
kmalloc | lbragstad: we might need that returned from mint? | 23:58 |
kmalloc | oh! you did that | 23:58 |
openstackgerrit | Merged openstack/keystone master: Add logging for xmlsec1 installation https://review.openstack.org/553592 | 23:58 |
kmalloc | nvm | 23:58 |
*** Krenair has quit IRC | 23:58 | |
kmalloc | braaaaaaaaain... i has none atm | 23:58 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!