*** r-daneel has joined #openstack-keystone | 00:05 | |
*** r-daneel has quit IRC | 00:05 | |
*** fiddletwix has joined #openstack-keystone | 00:07 | |
*** eschwartz is now known as anyone | 00:39 | |
*** chenyb4 has joined #openstack-keystone | 00:51 | |
*** harlowja has quit IRC | 01:16 | |
*** AlexeyAbashkin has joined #openstack-keystone | 01:39 | |
*** AlexeyAbashkin has quit IRC | 01:43 | |
*** panbalag has joined #openstack-keystone | 01:56 | |
*** panbalag has left #openstack-keystone | 01:56 | |
*** nicolasbock has quit IRC | 02:06 | |
*** jmlowe_ has quit IRC | 02:15 | |
*** oikiki has joined #openstack-keystone | 02:28 | |
*** dklyle has joined #openstack-keystone | 02:31 | |
*** jmlowe has joined #openstack-keystone | 02:41 | |
*** oikiki has quit IRC | 02:44 | |
*** dave-mccowan has quit IRC | 03:02 | |
*** sonuk has joined #openstack-keystone | 03:19 | |
*** prashkre_ has quit IRC | 03:25 | |
*** harlowja has joined #openstack-keystone | 03:43 | |
*** chenyb4 has quit IRC | 03:47 | |
*** chenyb4 has joined #openstack-keystone | 03:48 | |
*** harlowja has quit IRC | 04:12 | |
*** gyee has quit IRC | 04:20 | |
*** pcaruana has joined #openstack-keystone | 05:05 | |
*** pcichy has joined #openstack-keystone | 05:11 | |
*** pcaruana has quit IRC | 05:19 | |
*** zhurong has joined #openstack-keystone | 05:36 | |
*** oikiki has joined #openstack-keystone | 05:37 | |
*** oikiki has quit IRC | 06:06 | |
*** oikiki has joined #openstack-keystone | 06:10 | |
*** gmann has quit IRC | 06:21 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Invalidate the shadow user cache when deleting a user https://review.openstack.org/561908 | 06:29 |
---|---|---|
*** jmlowe_ has joined #openstack-keystone | 06:31 | |
*** dklyle has quit IRC | 06:32 | |
*** dklyle has joined #openstack-keystone | 06:32 | |
*** jmlowe has quit IRC | 06:33 | |
*** yikun_ has joined #openstack-keystone | 06:34 | |
*** yikun has quit IRC | 06:36 | |
*** ildikov has joined #openstack-keystone | 06:43 | |
*** mordred has quit IRC | 06:45 | |
*** links has joined #openstack-keystone | 06:46 | |
*** dklyle has quit IRC | 06:47 | |
*** oikiki has quit IRC | 06:48 | |
*** mordred has joined #openstack-keystone | 06:49 | |
*** pcaruana has joined #openstack-keystone | 06:50 | |
*** rcernin has quit IRC | 07:00 | |
*** zigo has quit IRC | 07:11 | |
*** gmann has joined #openstack-keystone | 07:13 | |
*** zigo has joined #openstack-keystone | 07:14 | |
*** oikiki has joined #openstack-keystone | 07:14 | |
*** sonuk_ has joined #openstack-keystone | 07:22 | |
*** sonuk has quit IRC | 07:25 | |
*** sonuk has joined #openstack-keystone | 07:28 | |
*** links has quit IRC | 07:29 | |
*** tesseract has joined #openstack-keystone | 07:29 | |
*** sonuk_ has quit IRC | 07:29 | |
*** AlexeyAbashkin has joined #openstack-keystone | 07:30 | |
*** zhurong has quit IRC | 07:30 | |
*** oikiki has quit IRC | 07:31 | |
*** pooja-jadhav has quit IRC | 07:43 | |
*** links has joined #openstack-keystone | 07:47 | |
*** yikun__ has joined #openstack-keystone | 07:48 | |
*** yikun_ has quit IRC | 07:51 | |
*** links has quit IRC | 07:52 | |
*** mugsie has quit IRC | 08:09 | |
*** mugsie has joined #openstack-keystone | 08:21 | |
*** mugsie has quit IRC | 08:21 | |
*** mugsie has joined #openstack-keystone | 08:21 | |
*** pcichy has quit IRC | 08:30 | |
*** zhurong has joined #openstack-keystone | 08:39 | |
*** links has joined #openstack-keystone | 08:48 | |
*** pooja_jadhav has joined #openstack-keystone | 08:50 | |
*** yikun__ has quit IRC | 09:02 | |
*** yikun__ has joined #openstack-keystone | 09:03 | |
*** annp has quit IRC | 09:04 | |
*** annp has joined #openstack-keystone | 09:05 | |
*** HW_Peter has quit IRC | 09:13 | |
*** itlinux has joined #openstack-keystone | 09:40 | |
itlinux | hello keystone guys, I have a question, I have a Ctl which is in London, using AD, but the login is slow since the AD is located in CZ zone. Any tips | 09:41 |
*** yikun_ has joined #openstack-keystone | 09:42 | |
*** yikun__ has quit IRC | 09:45 | |
*** itlinux has quit IRC | 09:49 | |
*** bhagyashris is now known as neha_alhat | 09:51 | |
*** neha_alhat is now known as bhagyashris | 09:52 | |
*** zhurong has quit IRC | 09:57 | |
*** itlinux has joined #openstack-keystone | 10:01 | |
*** chenyb4 has quit IRC | 10:17 | |
*** pcaruana has quit IRC | 10:27 | |
*** nicolasbock has joined #openstack-keystone | 10:31 | |
*** mvk has quit IRC | 11:08 | |
*** sonuk has quit IRC | 11:31 | |
*** sonuk has joined #openstack-keystone | 11:31 | |
*** bhagyashris has quit IRC | 11:32 | |
*** itlinux has quit IRC | 11:34 | |
*** gmann has quit IRC | 11:51 | |
*** itlinux has joined #openstack-keystone | 11:58 | |
*** raildo has joined #openstack-keystone | 12:01 | |
*** pcichy has joined #openstack-keystone | 12:10 | |
*** anyone is now known as eschwartz | 12:12 | |
*** sonuk has quit IRC | 12:14 | |
*** gmann has joined #openstack-keystone | 12:15 | |
*** edmondsw has joined #openstack-keystone | 12:15 | |
*** pcaruana has joined #openstack-keystone | 12:19 | |
*** mvk has joined #openstack-keystone | 12:20 | |
*** panbalag has joined #openstack-keystone | 12:30 | |
*** Alexey_Abashkin has joined #openstack-keystone | 12:31 | |
*** AlexeyAbashkin has quit IRC | 12:33 | |
*** Alexey_Abashkin is now known as AlexeyAbashkin | 12:33 | |
*** jmlowe has joined #openstack-keystone | 12:35 | |
*** jmlowe_ has quit IRC | 12:35 | |
*** itlinux has quit IRC | 12:51 | |
*** bhagyashris has joined #openstack-keystone | 12:52 | |
*** dave-mccowan has joined #openstack-keystone | 13:07 | |
lbragstad | gagehugo: good question | 13:07 |
lbragstad | pending the decision we make about encryption, i was just going to look into using whatever is already in gr | 13:07 |
*** dave-mccowan has quit IRC | 13:11 | |
*** pcichy has quit IRC | 13:13 | |
*** dave-mccowan has joined #openstack-keystone | 13:17 | |
openstackgerrit | melissaml proposed openstack/keystone master: Update auth_uri option to www_authenticate_uri https://review.openstack.org/562279 | 13:29 |
*** germs has joined #openstack-keystone | 13:31 | |
*** germs has quit IRC | 13:31 | |
*** germs has joined #openstack-keystone | 13:31 | |
*** itlinux has joined #openstack-keystone | 13:32 | |
*** fabian_ has joined #openstack-keystone | 13:33 | |
openstackgerrit | Russell Tweed proposed openstack/keystone master: Add prerequisite package note to Keystone install guide https://review.openstack.org/552568 | 13:37 |
*** itlinux has quit IRC | 13:40 | |
*** fabian_ is now known as chenyb4 | 13:46 | |
*** pcichy has joined #openstack-keystone | 13:48 | |
lbragstad | hrybacki: http://lists.openstack.org/pipermail/openstack-dev/2018-April/129474.html | 13:49 |
hrybacki | nice. thank you lbragstad :) | 13:51 |
hrybacki | strange that it isn't really clear how/where that vote happens | 13:51 |
*** m3m0 has joined #openstack-keystone | 13:52 | |
m3m0 | Hello, Is it possible to query projects (tenants) directly from my ldap domain? openstack project list --domain ldap? | 13:52 |
m3m0 | my ldap.conf looks like this http://paste.openstack.org/show/719473/ | 13:54 |
*** itlinux has joined #openstack-keystone | 13:54 | |
m3m0 | and I do have a test cn (tenant) in my backend, but keystone does not show anything | 13:54 |
m3m0 | and I don't even see a query in my ldap logs when I query projects | 13:55 |
lbragstad | m3m0: python-openstackclient does pass some of that information along to keystone | 14:03 |
lbragstad | is there a specific query you're looking to make? | 14:03 |
lbragstad | hrybacki: i thought so too, but i might not be looking in the right place | 14:03 |
m3m0 | lbragstad: yes, to retrieve the list of projects in my backend, so far I can only retreive users | 14:04 |
lbragstad | m3m0: the resource backend, which is responsible for projects doesn't back to ldap | 14:05 |
lbragstad | it used to, but i don't think that is the case anymore | 14:06 |
hrybacki | \_0_/ | 14:06 |
*** pcichy has quit IRC | 14:07 | |
lbragstad | m3m0: https://docs.openstack.org/keystone/latest/configuration/config-options.html#resource | 14:07 |
m3m0 | mmm so, no longer the option to have a centralized way to manage projects, users and roles is possible? I have to inject the projects directly to keystone? | 14:08 |
lbragstad | m3m0: you can create projects in sql and manage role assignments in keystone for users in ldap | 14:10 |
m3m0 | no no, my projects, roles and users are in ldap | 14:10 |
m3m0 | I can query the users, but not the projects | 14:10 |
lbragstad | right | 14:10 |
m3m0 | well in fairness, the roles are not there yet, still working on the projects | 14:11 |
*** panbalag has left #openstack-keystone | 14:11 | |
*** dave-mccowan has quit IRC | 14:13 | |
*** dklyle has joined #openstack-keystone | 14:15 | |
*** chenyb4 has quit IRC | 14:15 | |
lbragstad | found this - http://lists.openstack.org/pipermail/openstack-dev/2015-January/055459.html | 14:15 |
*** itlinux has quit IRC | 14:15 | |
m3m0 | lbragstad: thanks let me take a look | 14:19 |
lbragstad | m3m0: there is a bunch of context in there that might help | 14:19 |
lbragstad | kmalloc: originally wrote it | 14:19 |
*** itlinux has joined #openstack-keystone | 14:19 | |
*** spilla has joined #openstack-keystone | 14:20 | |
m3m0 | lbragstad: it makes sense, then I will find a workaround on our side, maybe a cron job that add/remove projects into the sql backend | 14:22 |
lbragstad | yeha | 14:22 |
lbragstad | assignments might be a bit easier to manage if you use ldap groups and sql groups | 14:22 |
lbragstad | then just have the assignment on the sql groups | 14:22 |
m3m0 | lbragstad: but as far as I know you cannot combine users intro groups from different backends, is it the same behaviour for assignments? | 14:23 |
m3m0 | into* | 14:24 |
lbragstad | if you have a group, it can hold users from which ever domain you like | 14:24 |
m3m0 | aaa that's perfect, thanks a lot :) | 14:25 |
lbragstad | so if you have multiple ldaps backed to keystone, using domain specific configurations for each, you should be able to give them role assignments on projects throughout the deployment | 14:25 |
lbragstad | or you can keep them totally isolated within the domain you set up for them | 14:25 |
*** m3m0 has quit IRC | 14:49 | |
*** felipemonteiro has joined #openstack-keystone | 14:54 | |
*** mchlumsky has quit IRC | 15:05 | |
*** mchlumsky has joined #openstack-keystone | 15:08 | |
*** itlinux has quit IRC | 15:31 | |
*** dklyle has quit IRC | 15:38 | |
*** links has quit IRC | 15:55 | |
*** itlinux has joined #openstack-keystone | 15:58 | |
*** harlowja has joined #openstack-keystone | 16:06 | |
*** r-daneel has joined #openstack-keystone | 16:07 | |
*** r-daneel has quit IRC | 16:08 | |
*** AlexeyAbashkin has quit IRC | 16:23 | |
*** gyee has joined #openstack-keystone | 16:30 | |
*** szaher has quit IRC | 16:53 | |
*** szaher has joined #openstack-keystone | 17:04 | |
*** gyee has quit IRC | 17:12 | |
openstackgerrit | Merged openstack/keystone master: Add prerequisite package note to Keystone install guide https://review.openstack.org/552568 | 17:18 |
*** spilla has quit IRC | 17:22 | |
kmalloc | lbragstad: ++ | 17:23 |
*** mvk has quit IRC | 17:25 | |
*** spilla has joined #openstack-keystone | 17:27 | |
*** raildo has quit IRC | 17:28 | |
openstackgerrit | Merged openstack/pycadf master: Updated from global requirements https://review.openstack.org/551615 | 17:34 |
*** raildo has joined #openstack-keystone | 17:37 | |
*** harlowja has quit IRC | 17:44 | |
*** AlexeyAbashkin has joined #openstack-keystone | 17:46 | |
*** itlinux has quit IRC | 17:48 | |
*** AlexeyAbashkin has quit IRC | 17:51 | |
*** mvk has joined #openstack-keystone | 17:52 | |
*** itlinux has joined #openstack-keystone | 17:54 | |
*** oikiki has joined #openstack-keystone | 17:57 | |
*** raildo has quit IRC | 17:58 | |
*** dave-mccowan has joined #openstack-keystone | 17:59 | |
*** spilla has quit IRC | 18:08 | |
*** raildo has joined #openstack-keystone | 18:10 | |
*** pcaruana has quit IRC | 18:12 | |
*** spilla has joined #openstack-keystone | 18:13 | |
*** harlowja has joined #openstack-keystone | 18:18 | |
*** harlowja_ has joined #openstack-keystone | 18:23 | |
*** harlowja has quit IRC | 18:24 | |
*** itlinux has quit IRC | 18:35 | |
*** itlinux has joined #openstack-keystone | 18:40 | |
*** felipemonteiro_ has joined #openstack-keystone | 19:01 | |
*** raildo has quit IRC | 19:05 | |
*** felipemonteiro has quit IRC | 19:05 | |
*** spilla has quit IRC | 19:08 | |
*** pcaruana has joined #openstack-keystone | 19:13 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Allow blocking users from self-service password change https://review.openstack.org/559438 | 19:15 |
*** tesseract has quit IRC | 19:15 | |
*** felipemonteiro__ has joined #openstack-keystone | 19:16 | |
*** raildo has joined #openstack-keystone | 19:17 | |
*** felipemonteiro_ has quit IRC | 19:20 | |
*** pcaruana has quit IRC | 19:20 | |
kmalloc | mordred: re https://review.openstack.org/#/c/462218/4 -- i think.... that changes behavior (possibly) for a given catalog | 19:26 |
kmalloc | mordred: and we will need it to be opt-in for the new filtering. | 19:26 |
kmalloc | mordred: but i wanted to confirm/make sure I am not missing some key bit here instead of scoring it incorrectly | 19:26 |
kmalloc | mordred: but I *really* like the direction and that we're leaning on an external set of aliases | 19:27 |
*** ayoung has joined #openstack-keystone | 19:29 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: [Do Not Merge] Adding debugging task https://review.openstack.org/561751 | 19:36 |
*** felipemonteiro__ has quit IRC | 19:39 | |
*** felipemonteiro__ has joined #openstack-keystone | 19:40 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove the sample .conf file https://review.openstack.org/521249 | 19:40 |
*** spilla has joined #openstack-keystone | 19:40 | |
lbragstad | odyssey4me: d34dh0r53 ^ that should pass this time | 19:40 |
lbragstad | i'm done mucking around with the tests | 19:40 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove the sample .conf file https://review.openstack.org/521249 | 19:41 |
*** ayoung has quit IRC | 19:50 | |
*** oikiki has quit IRC | 19:52 | |
*** blake has joined #openstack-keystone | 19:58 | |
*** oikiki has joined #openstack-keystone | 20:08 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Add LDAP user-backed functional testing gate https://review.openstack.org/558940 | 20:14 |
*** blake has quit IRC | 20:20 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Handle LDAP Server Down in Pool https://review.openstack.org/560724 | 20:26 |
openstackgerrit | Merged openstack/keystoneauth master: Fix W503 line-break-before-binary-operator https://review.openstack.org/561259 | 20:42 |
*** sonuk has joined #openstack-keystone | 20:43 | |
*** oikiki has quit IRC | 20:45 | |
*** dmellado has quit IRC | 20:45 | |
*** blake has joined #openstack-keystone | 20:52 | |
openstackgerrit | Merged openstack/keystone master: Fix json schema nullable to add None to ENUM https://review.openstack.org/561348 | 20:55 |
*** oikiki has joined #openstack-keystone | 20:56 | |
*** blake has quit IRC | 20:57 | |
*** dave-mccowan has quit IRC | 20:59 | |
*** spilla has quit IRC | 20:59 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Update keystone functional tests https://review.openstack.org/560129 | 21:04 |
*** eandersson has quit IRC | 21:10 | |
*** eandersson has joined #openstack-keystone | 21:13 | |
*** spilla has joined #openstack-keystone | 21:19 | |
*** sonuk has quit IRC | 21:27 | |
*** mchlumsky has quit IRC | 21:32 | |
*** timburke_ is now known as timburke | 21:33 | |
*** oikiki has quit IRC | 21:43 | |
*** tobberydberg has quit IRC | 21:43 | |
*** oikiki has joined #openstack-keystone | 21:45 | |
*** tobberydberg has joined #openstack-keystone | 21:51 | |
*** oikiki has quit IRC | 22:05 | |
*** felipemonteiro_ has joined #openstack-keystone | 22:06 | |
*** afred312 has joined #openstack-keystone | 22:09 | |
*** felipemonteiro__ has quit IRC | 22:10 | |
kmalloc | lbragstad: can you +1 the backports for ENUM fix | 22:11 |
kmalloc | lbragstad: then i feel ok pushing them through | 22:11 |
*** afred312 has quit IRC | 22:19 | |
*** blake has joined #openstack-keystone | 22:21 | |
*** blake has quit IRC | 22:21 | |
*** felipemonteiro_ has quit IRC | 22:29 | |
*** felipemonteiro_ has joined #openstack-keystone | 22:29 | |
*** rcernin has joined #openstack-keystone | 22:31 | |
*** itlinux has quit IRC | 22:32 | |
*** edmondsw has quit IRC | 22:41 | |
*** mvk has quit IRC | 22:44 | |
*** AlexeyAbashkin has joined #openstack-keystone | 22:45 | |
*** mvk has joined #openstack-keystone | 22:49 | |
*** AlexeyAbashkin has quit IRC | 22:50 | |
*** raildo has quit IRC | 23:11 | |
*** andreaf has quit IRC | 23:18 | |
*** andreaf has joined #openstack-keystone | 23:18 | |
*** vegarl has quit IRC | 23:20 | |
*** vegarl has joined #openstack-keystone | 23:20 | |
*** spilla has quit IRC | 23:27 | |
*** felipemonteiro_ has quit IRC | 23:35 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!