*** d0ugal_ has quit IRC | 00:10 | |
*** panbalag has joined #openstack-keystone | 00:14 | |
*** d0ugal_ has joined #openstack-keystone | 00:24 | |
*** lbragstad has joined #openstack-keystone | 00:34 | |
*** ChanServ sets mode: +o lbragstad | 00:34 | |
*** dims has quit IRC | 00:42 | |
*** lbragstad has quit IRC | 00:49 | |
*** edmondsw has joined #openstack-keystone | 00:56 | |
*** fiddletwix has quit IRC | 00:57 | |
*** fiddletwix has joined #openstack-keystone | 00:57 | |
*** lbragstad has joined #openstack-keystone | 00:59 | |
*** ChanServ sets mode: +o lbragstad | 00:59 | |
*** chenyb4 has joined #openstack-keystone | 01:07 | |
*** d0ugal__ has joined #openstack-keystone | 01:08 | |
*** d0ugal_ has quit IRC | 01:11 | |
*** d0ugal has joined #openstack-keystone | 01:14 | |
*** lbragstad has quit IRC | 01:14 | |
*** d0ugal__ has quit IRC | 01:16 | |
*** edmondsw has quit IRC | 01:33 | |
*** edmondsw has joined #openstack-keystone | 01:33 | |
*** edmondsw has quit IRC | 01:38 | |
*** masuberu has joined #openstack-keystone | 01:54 | |
*** masber has quit IRC | 01:58 | |
*** masber has joined #openstack-keystone | 02:00 | |
*** masuberu has quit IRC | 02:01 | |
*** gongysh has joined #openstack-keystone | 02:06 | |
*** masber has quit IRC | 02:13 | |
*** panbalag has quit IRC | 02:21 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Update IdP sql model https://review.openstack.org/559676 | 02:35 |
---|---|---|
*** edmondsw has joined #openstack-keystone | 02:48 | |
*** edmondsw has quit IRC | 02:52 | |
*** sonuk has joined #openstack-keystone | 03:18 | |
*** dklyle has quit IRC | 03:18 | |
*** lbragstad has joined #openstack-keystone | 03:48 | |
*** ChanServ sets mode: +o lbragstad | 03:48 | |
*** masber has joined #openstack-keystone | 03:49 | |
*** ayoung has quit IRC | 03:50 | |
*** bhagyashris has joined #openstack-keystone | 04:19 | |
*** edmondsw has joined #openstack-keystone | 04:36 | |
*** edmondsw has quit IRC | 04:40 | |
cmurphy | lbragstad: I don't think we really need a forum session for app creds, I don't think there's much to discuss on the direction | 04:41 |
lbragstad | cmurphy: ack - just wanted to double check | 04:42 |
*** gongysh has quit IRC | 05:09 | |
*** gongysh has joined #openstack-keystone | 05:12 | |
*** gongysh has quit IRC | 05:24 | |
*** d0ugal has quit IRC | 05:27 | |
*** d0ugal has joined #openstack-keystone | 05:29 | |
*** gongysh has joined #openstack-keystone | 05:45 | |
*** mvk has quit IRC | 06:10 | |
*** mvk has joined #openstack-keystone | 06:10 | |
*** Horrorcat has left #openstack-keystone | 06:15 | |
*** edmondsw has joined #openstack-keystone | 06:24 | |
*** edmondsw has quit IRC | 06:28 | |
*** rcernin has quit IRC | 06:56 | |
*** pcaruana has joined #openstack-keystone | 07:13 | |
*** tesseract has joined #openstack-keystone | 07:21 | |
*** tesseract has quit IRC | 07:33 | |
*** tesseract has joined #openstack-keystone | 07:35 | |
*** threestrands has quit IRC | 07:47 | |
*** itlinux has joined #openstack-keystone | 07:47 | |
*** evrardjp has joined #openstack-keystone | 07:55 | |
*** pcichy has joined #openstack-keystone | 07:55 | |
*** AlexeyAbashkin has joined #openstack-keystone | 07:58 | |
*** sonuk_ has joined #openstack-keystone | 07:58 | |
*** itlinux_ has joined #openstack-keystone | 08:02 | |
*** sonuk has quit IRC | 08:02 | |
*** itlinux has quit IRC | 08:04 | |
*** itlinux_ has quit IRC | 08:06 | |
*** jaosorior has joined #openstack-keystone | 08:10 | |
*** edmondsw has joined #openstack-keystone | 08:13 | |
*** edmondsw has quit IRC | 08:17 | |
*** gongysh has quit IRC | 08:22 | |
*** gongysh has joined #openstack-keystone | 08:25 | |
*** h3yduck has joined #openstack-keystone | 08:27 | |
h3yduck | hey folks, We are trying to configure an environment where users log in via SAML2 and get their group names in 'niifEduPersonAttendedCourse' attribute, which is an array of course names in the SAML response. It works well when there are groups already for all course names. However we cannot create all groups, only some of them unfortunately. Therefore authentication fails if someone logs in with a course name assigned that has no corresponding | 08:31 |
h3yduck | group in OpenStack yet. A working solution for us would be if Keystone would create the group if it didn't exist yet or if Keystone would map the authentication to already existing groups only, ignoring unexistent ones. Here is our mapping: https://pastebin.com/0rumqE0t. Could you guys suggest a solution for this? | 08:31 |
*** gongysh has quit IRC | 08:40 | |
*** gongysh has joined #openstack-keystone | 08:43 | |
hugokuo | morning | 08:52 |
*** itlinux has joined #openstack-keystone | 08:53 | |
hugokuo | is there a way to limit user to authenticate via v2 API of a specific? | 08:53 |
hugokuo | specific project(tenant) | 08:53 |
hugokuo | thx | 08:53 |
*** itlinux has quit IRC | 08:54 | |
*** itlinux has joined #openstack-keystone | 08:57 | |
*** itlinux has quit IRC | 09:28 | |
*** wxy has quit IRC | 09:30 | |
*** bhagyashris has quit IRC | 09:34 | |
*** gongysh has quit IRC | 09:51 | |
openstackgerrit | Dai Hanada proposed openstack/keystone master: Fix keystone-manage mapping_purge with --type option https://review.openstack.org/554397 | 09:58 |
*** wxy has joined #openstack-keystone | 09:58 | |
*** bhagyashris has joined #openstack-keystone | 10:19 | |
*** nicolasbock has joined #openstack-keystone | 10:33 | |
*** chenyb4 has quit IRC | 10:36 | |
*** nicolasbock has quit IRC | 10:39 | |
*** pooja_jadhav has joined #openstack-keystone | 10:49 | |
openstackgerrit | Merged openstack/python-keystoneclient master: add lower-constraints job https://review.openstack.org/556142 | 10:50 |
*** itlinux has joined #openstack-keystone | 11:16 | |
*** nicolasbock has joined #openstack-keystone | 11:17 | |
*** dave-mcc_ has joined #openstack-keystone | 11:58 | |
*** markvoelker has joined #openstack-keystone | 11:59 | |
*** dave-mccowan has quit IRC | 12:01 | |
*** raildo has joined #openstack-keystone | 12:04 | |
*** doxa has joined #openstack-keystone | 12:04 | |
*** mvk has quit IRC | 12:05 | |
doxa | Good day ! Can anyone help me with a OpenStack TOTP Horizon/Keystone pluggin? | 12:05 |
*** d0ugal_ has joined #openstack-keystone | 12:13 | |
*** h3yduck has quit IRC | 12:15 | |
*** d0ugal has quit IRC | 12:15 | |
*** edmondsw has joined #openstack-keystone | 12:21 | |
*** prashkre has joined #openstack-keystone | 12:25 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Update IdP sql model https://review.openstack.org/559676 | 12:26 |
*** dims has joined #openstack-keystone | 12:30 | |
*** panbalag has joined #openstack-keystone | 12:36 | |
*** panbalag has left #openstack-keystone | 12:38 | |
*** sonuk_ has quit IRC | 12:44 | |
*** itlinux has quit IRC | 12:46 | |
*** mvk has joined #openstack-keystone | 12:49 | |
*** chenyb4 has joined #openstack-keystone | 12:51 | |
*** chenyb4 has quit IRC | 12:56 | |
*** dklyle has joined #openstack-keystone | 13:00 | |
*** dklyle has quit IRC | 13:09 | |
lbragstad | hugokuo: I don't think there is with v2.0 | 13:12 |
lbragstad | hugokuo: oh - actually i think i misunderstood you question | 13:13 |
lbragstad | hugokuo: are you trying to limit a user to only being able to authenticate via v2.0? | 13:14 |
*** fabian_ has joined #openstack-keystone | 13:26 | |
*** jroll has quit IRC | 13:26 | |
*** jroll has joined #openstack-keystone | 13:27 | |
*** superdan is now known as dansmith | 13:35 | |
*** pcichy has quit IRC | 13:39 | |
*** pcichy has joined #openstack-keystone | 13:39 | |
*** d0ugal_ has quit IRC | 13:40 | |
*** d0ugal has joined #openstack-keystone | 13:41 | |
*** d0ugal has quit IRC | 13:41 | |
*** d0ugal has joined #openstack-keystone | 13:41 | |
*** pcichy has quit IRC | 13:45 | |
*** pcichy has joined #openstack-keystone | 13:46 | |
*** bhagyashris has quit IRC | 13:48 | |
*** jmlowe_ has quit IRC | 13:49 | |
*** bhagyashris has joined #openstack-keystone | 13:49 | |
*** pcichy has quit IRC | 13:50 | |
*** pcichy has joined #openstack-keystone | 13:50 | |
*** pooja-jadhav has joined #openstack-keystone | 13:51 | |
*** pooja_jadhav has quit IRC | 13:52 | |
*** gongysh has joined #openstack-keystone | 13:53 | |
*** jmlowe has joined #openstack-keystone | 13:54 | |
*** r-daneel has quit IRC | 13:57 | |
*** fabian_ has quit IRC | 13:57 | |
*** ayoung has joined #openstack-keystone | 14:03 | |
kmalloc | doxa in what way do you need help? | 14:13 |
kmalloc | doxa: we might be able to help, but lets start with a bit more context in what you need :) | 14:13 |
*** jmlowe has quit IRC | 14:13 | |
*** felipemonteiro has joined #openstack-keystone | 14:15 | |
*** jmlowe has joined #openstack-keystone | 14:17 | |
*** spilla has joined #openstack-keystone | 14:17 | |
*** jmlowe has quit IRC | 14:32 | |
gagehugo | o/ | 14:50 |
*** mugsie has quit IRC | 14:53 | |
*** mugsie has joined #openstack-keystone | 14:53 | |
*** mugsie has quit IRC | 14:53 | |
*** mugsie has joined #openstack-keystone | 14:53 | |
*** jmlowe has joined #openstack-keystone | 14:56 | |
*** fabian_ has joined #openstack-keystone | 14:56 | |
*** felipemonteiro_ has joined #openstack-keystone | 14:59 | |
lbragstad | o/ | 15:00 |
hrybacki | o/ | 15:02 |
*** felipemonteiro has quit IRC | 15:02 | |
ayoung | lbragstad, I rebased the CLI patch on top of one that runs pep8 clean | 15:02 |
hrybacki | lbragstad: I think default-roles spec is looking solid | 15:02 |
ayoung | https://review.openstack.org/#/c/560132/ | 15:02 |
*** r-daneel has joined #openstack-keystone | 15:03 | |
lbragstad | ayoung: oh - thanks | 15:03 |
lbragstad | hrybacki: yeah - i think so too | 15:03 |
lbragstad | i think ayoung just had a couple comments left | 15:03 |
ayoung | looking.... | 15:03 |
hrybacki | lbragstad: I think I got those addressed as well | 15:04 |
ayoung | Deltas look good | 15:04 |
hrybacki | woo | 15:05 |
lbragstad | oh - i'm an iteration behind | 15:05 |
lbragstad | i'll have a look | 15:05 |
ayoung | I can only +1, but I've done that. | 15:05 |
lbragstad | cool - thanks | 15:06 |
lbragstad | i'm in the same boat | 15:06 |
*** pcaruana has quit IRC | 15:09 | |
*** prashkre has quit IRC | 15:24 | |
*** prashkre has joined #openstack-keystone | 15:25 | |
*** jistr is now known as jistr|mtg | 15:33 | |
*** fabian_ has quit IRC | 15:35 | |
*** felipemonteiro_ has quit IRC | 15:40 | |
*** mgagne_ is now known as mgagne | 15:50 | |
*** fiddletwix has quit IRC | 15:51 | |
*** fiddletwix has joined #openstack-keystone | 15:51 | |
ayoung | lbragstad, how would I go about fixing the formatting on this page? | 15:58 |
ayoung | https://specs.openstack.org/openstack/keystone-specs/specs/backlog/implied-roles.html | 15:58 |
ayoung | is that really in backlog? | 15:58 |
lbragstad | yeah - it probably needs to be cleaned up | 15:59 |
ayoung | its not | 15:59 |
ayoung | there is nothing in backlog | 15:59 |
ayoung | in git anywya | 15:59 |
lbragstad | hmm | 16:00 |
ayoung | its in mitaka | 16:00 |
lbragstad | looks like it is https://github.com/openstack/keystone-specs/tree/master/specs/keystone/backlog | 16:00 |
ayoung | https://specs.openstack.org/openstack/keystone-specs/specs/keystone/mitaka/implied-roles.html | 16:00 |
ayoung | and it formats nicely there | 16:00 |
lbragstad | hmm | 16:00 |
lbragstad | that might be due to how we do docs now? | 16:01 |
lbragstad | s/do/build/ | 16:01 |
ayoung | ah, ok I'm submitting a review to dro p it from backlog | 16:01 |
lbragstad | ayoung: it's not in the backlog in master, though | 16:01 |
lbragstad | at least i don't see it here - https://github.com/openstack/keystone-specs/tree/master/specs/keystone/backlog | 16:02 |
ayoung | you are right | 16:02 |
lbragstad | i bet we moved it out of backlog when we targetted it to mitaka | 16:02 |
ayoung | right | 16:03 |
*** gongysh has quit IRC | 16:03 | |
ayoung | I just found the old one when doing a web search | 16:03 |
lbragstad | ah | 16:03 |
ayoung | this is not critical, as I know where the good one is, just took me til now to realize that\ | 16:03 |
*** jistr|mtg is now known as jistr | 16:03 | |
ayoung | looks like someting needs to clean out the old files, probably left behind from old build/publishing | 16:04 |
lbragstad | possibly | 16:05 |
* lbragstad runs to grab lunch | 16:09 | |
*** gyee has joined #openstack-keystone | 16:13 | |
*** lbragstad has quit IRC | 16:24 | |
*** jmlowe has quit IRC | 16:28 | |
*** jrist has quit IRC | 16:39 | |
hugokuo | lbragstad re: "are you trying to limit a user to only being able to authenticate via v2.0?" The opposite, can an user or group of users in a tenant only auth via v3.0? | 16:44 |
openstackgerrit | Merged openstack/oslo.policy master: set default python to python3 https://review.openstack.org/561324 | 16:45 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: WIP - Add LDAP-backed functional testing gate https://review.openstack.org/558940 | 16:50 |
*** jdennis has quit IRC | 16:54 | |
*** jrist has joined #openstack-keystone | 17:01 | |
*** jdennis has joined #openstack-keystone | 17:10 | |
*** mvk has quit IRC | 17:13 | |
kmalloc | hugokuo: not possible to block v2/v3 for specific groups of users short of disabling v2 | 17:15 |
kmalloc | hugokuo: globally that is. | 17:15 |
kmalloc | hugokuo: from a design perspective, v3 (non-default domain) users were not intended to auth via v2, but... there were bugs and we couldn't change the behavior. The solution was to move away from v2 (As we have) and v3 only | 17:16 |
*** AlexeyAbashkin has quit IRC | 17:17 | |
hugokuo | kmalloc: so Queens release would be the best option since the v2 was removed entirely since Q release | 17:17 |
kmalloc | you can disable v2 before that, but everything in queens is sure to work without v2 | 17:18 |
hugokuo | kk | 17:18 |
hugokuo | got it | 17:18 |
kmalloc | iirc, pike was well tested with v2 removed. | 17:18 |
kmalloc | prior to Pike, you might run into weird bugs. | 17:18 |
hugokuo | nice point. I'll give it a shot tmr. | 17:18 |
hugokuo | I just learned something about the non-default domain user should not be able to auth via v2.0. | 17:19 |
kmalloc | yeah. it's a known bug that, because people relied on it, we couldn't fix. so we just lived with v3 users (non-default domain) working via v2 | 17:20 |
kmalloc | and kept pushing on v2 removal | 17:20 |
*** jdennis has quit IRC | 17:21 | |
*** felipemonteiro has joined #openstack-keystone | 17:21 | |
*** jrist has quit IRC | 17:22 | |
*** spilla has quit IRC | 17:25 | |
openstackgerrit | Pavlo Shchelokovskyy proposed openstack/keystoneauth master: Use defusedxml for XML parsing in SAML https://review.openstack.org/536761 | 17:27 |
*** jrist has joined #openstack-keystone | 17:32 | |
*** jrist has quit IRC | 17:32 | |
*** jrist has joined #openstack-keystone | 17:32 | |
*** r-daneel has quit IRC | 17:34 | |
*** r-daneel has joined #openstack-keystone | 17:35 | |
*** jdennis has joined #openstack-keystone | 17:38 | |
*** jmlowe has joined #openstack-keystone | 17:42 | |
*** lbragstad has joined #openstack-keystone | 17:43 | |
*** ChanServ sets mode: +o lbragstad | 17:43 | |
*** felipemonteiro_ has joined #openstack-keystone | 17:45 | |
*** felipemonteiro has quit IRC | 17:48 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: WIP - Add LDAP-backed functional testing gate https://review.openstack.org/558940 | 17:55 |
*** spilla has joined #openstack-keystone | 17:56 | |
*** jdennis has quit IRC | 18:24 | |
*** tesseract has quit IRC | 18:36 | |
*** jdennis has joined #openstack-keystone | 18:38 | |
*** harlowja has joined #openstack-keystone | 18:40 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: WIP - Add LDAP-backed functional testing gate https://review.openstack.org/558940 | 18:44 |
*** AlexeyAbashkin has joined #openstack-keystone | 18:44 | |
*** AlexeyAbashkin has quit IRC | 18:49 | |
*** AlexeyAbashkin has joined #openstack-keystone | 18:49 | |
*** mvk has joined #openstack-keystone | 18:52 | |
*** jmlowe has quit IRC | 18:58 | |
*** AlexeyAbashkin has quit IRC | 18:59 | |
*** openstackgerrit has quit IRC | 19:05 | |
hrybacki | lbragstad: if you delete a project, should related security groups also be deleted? Or is that an additional step required to be done manually (I think this is right) | 19:07 |
lbragstad | hrybacki: yeah - since keystone doesn't manage security groups we wouldn't be able to handle that case within keystone | 19:07 |
lbragstad | nova would have to consume a notification and clean those things up | 19:08 |
hrybacki | lbragstad: ack, thank you for comfirming :) | 19:08 |
lbragstad | yep | 19:08 |
*** pcichy has quit IRC | 19:15 | |
*** openstackgerrit has joined #openstack-keystone | 19:28 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: WIP - Add LDAP-backed functional testing gate https://review.openstack.org/558940 | 19:28 |
*** edmondsw_ has joined #openstack-keystone | 20:00 | |
*** r-daneel has quit IRC | 20:01 | |
*** edmondsw has quit IRC | 20:03 | |
*** ayoung has quit IRC | 20:04 | |
doxa | kmalloc: I am looking to add totp to openstack. OPenstack has this option since mitaka but not in horizon just keystone. | 20:09 |
doxa | I need graphical interface | 20:09 |
*** r-daneel has joined #openstack-keystone | 20:19 | |
openstackgerrit | Merged openstack/keystone master: Use consistent role schema in token response validation https://review.openstack.org/407587 | 20:28 |
*** dklyle has joined #openstack-keystone | 20:28 | |
lbragstad | hrybacki: +1 on the default roles spec | 20:29 |
lbragstad | looks great | 20:29 |
*** raildo has quit IRC | 20:31 | |
*** AlexeyAbashkin has joined #openstack-keystone | 20:41 | |
*** AlexeyAbashkin has quit IRC | 20:45 | |
*** mtreinish has quit IRC | 20:51 | |
*** harlowja has quit IRC | 20:55 | |
*** edmondsw_ has quit IRC | 20:56 | |
*** mtreinish has joined #openstack-keystone | 20:57 | |
*** edmondsw has joined #openstack-keystone | 20:59 | |
*** edmondsw has quit IRC | 21:03 | |
lbragstad | curious if anyone else here has thoughts on this - https://review.openstack.org/#/c/559676/4 and https://bugs.launchpad.net/keystone/+bug/1760843 | 21:14 |
openstack | Launchpad bug 1760843 in OpenStack Identity (keystone) "Identity Provider domain is not unique" [Undecided,In progress] - Assigned to wangxiyuan (wangxiyuan) | 21:14 |
*** spilla has quit IRC | 21:17 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: WIP - Add LDAP-backed functional testing gate https://review.openstack.org/558940 | 21:17 |
*** dklyle has quit IRC | 21:22 | |
*** felipemonteiro_ has quit IRC | 21:23 | |
*** jmlowe has joined #openstack-keystone | 21:36 | |
*** dklyle has joined #openstack-keystone | 21:50 | |
*** rcernin has joined #openstack-keystone | 21:51 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove the sample .conf file https://review.openstack.org/521249 | 21:53 |
kmalloc | doxa: i don't think horizon has that implemented yet. We're working on some changes for Rocky to make it possible. | 22:00 |
*** BlackDex has quit IRC | 22:04 | |
*** BlackDex has joined #openstack-keystone | 22:05 | |
*** david-lyle has joined #openstack-keystone | 22:06 | |
*** dklyle has quit IRC | 22:08 | |
*** david-lyle has quit IRC | 22:11 | |
*** jdennis has quit IRC | 22:15 | |
*** jdennis has joined #openstack-keystone | 22:17 | |
hrybacki | awesome, thanks lbragstad :) | 22:30 |
kmalloc | lbragstad: re-cherry-picked the master ENUM nullable change | 22:32 |
*** panbalag has joined #openstack-keystone | 22:38 | |
*** dklyle has joined #openstack-keystone | 22:40 | |
lbragstad | kmalloc: awesome - thanks | 22:40 |
*** panbalag has left #openstack-keystone | 22:47 | |
*** ayoung has joined #openstack-keystone | 22:48 | |
*** panbalag has joined #openstack-keystone | 22:56 | |
*** dklyle has quit IRC | 22:58 | |
*** dklyle has joined #openstack-keystone | 23:13 | |
*** panbalag has quit IRC | 23:23 | |
openstackgerrit | Tin Lam proposed openstack/keystone master: [Do Not Merge] Adding debugging task https://review.openstack.org/561751 | 23:26 |
*** jaosorior has quit IRC | 23:26 | |
*** jaosorior has joined #openstack-keystone | 23:27 | |
*** r-daneel has quit IRC | 23:29 | |
*** jaosorior has quit IRC | 23:34 | |
*** jaosorior has joined #openstack-keystone | 23:34 | |
*** d0ugal has quit IRC | 23:36 | |
*** dklyle has quit IRC | 23:40 | |
*** jroll has quit IRC | 23:42 | |
*** gyee has quit IRC | 23:43 | |
adriant | kmalloc, lbragstad: Apologies re not any progress/news on auth receipts front. Busy with internal work, but new dev is joining us soon who can take over some of my current stuff while I dedicate 1-2 days a week to upstream work. | 23:45 |
adriant | also doxa: feel free to bug me regarding TOTP! I've looked quite a bit into how to setup MFA stuff in keystone/horizon | 23:46 |
*** d0ugal has joined #openstack-keystone | 23:52 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!