*** edmondsw has joined #openstack-keystone | 01:13 | |
*** edmondsw has quit IRC | 01:18 | |
*** annp has joined #openstack-keystone | 01:55 | |
*** gongysh has joined #openstack-keystone | 02:12 | |
*** edmondsw has joined #openstack-keystone | 03:02 | |
*** gongysh has quit IRC | 03:04 | |
*** edmondsw has quit IRC | 03:06 | |
*** jmlowe has quit IRC | 03:10 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Strict two level limit model https://review.openstack.org/557696 | 03:20 |
---|---|---|
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add project_id filter for listing limit https://review.openstack.org/579330 | 03:20 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add show hierarchy filter https://review.openstack.org/579331 | 03:20 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: [WIP]Update project depth check https://review.openstack.org/580258 | 03:20 |
*** zzzeek has quit IRC | 04:40 | |
*** zzzeek has joined #openstack-keystone | 04:43 | |
*** edmondsw has joined #openstack-keystone | 04:51 | |
*** edmondsw has quit IRC | 04:55 | |
*** zzzeek has quit IRC | 05:10 | |
*** zzzeek has joined #openstack-keystone | 05:11 | |
*** sonuk has joined #openstack-keystone | 05:36 | |
*** sonuk_ has quit IRC | 05:38 | |
*** nicolasbock has joined #openstack-keystone | 05:49 | |
*** martinus__ has joined #openstack-keystone | 05:50 | |
*** josecastroleon has joined #openstack-keystone | 06:10 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Strict two level limit model https://review.openstack.org/557696 | 06:55 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add project_id filter for listing limit https://review.openstack.org/579330 | 06:55 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add show hierarchy filter https://review.openstack.org/579331 | 06:55 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Update project depth check https://review.openstack.org/580258 | 06:55 |
*** ispp has joined #openstack-keystone | 07:09 | |
*** ispp has quit IRC | 07:20 | |
*** peereb has joined #openstack-keystone | 07:22 | |
*** kashyap has left #openstack-keystone | 07:22 | |
*** ispp has joined #openstack-keystone | 07:26 | |
openstackgerrit | Adrian Turjak proposed openstack/keystone master: Implement auth receipts spec https://review.openstack.org/572286 | 07:27 |
*** amoralej|off is now known as amoralej | 07:29 | |
*** ispp has quit IRC | 07:39 | |
*** rcernin has quit IRC | 07:54 | |
*** ispp has joined #openstack-keystone | 08:00 | |
*** apdibbo has joined #openstack-keystone | 08:19 | |
*** tosky has joined #openstack-keystone | 08:27 | |
*** edmondsw has joined #openstack-keystone | 08:28 | |
*** edmondsw has quit IRC | 08:32 | |
*** ispp has quit IRC | 08:55 | |
openstackgerrit | Adrian Turjak proposed openstack/keystone master: Implement auth receipts spec https://review.openstack.org/572286 | 09:14 |
openstackgerrit | Adrian Turjak proposed openstack/keystone master: Implement auth receipts spec https://review.openstack.org/572286 | 09:22 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: [WIP]Add project hierarchical tree check when Keystone start https://review.openstack.org/580331 | 09:33 |
*** ispp has joined #openstack-keystone | 09:50 | |
*** vishakha has quit IRC | 10:03 | |
*** vishakha has joined #openstack-keystone | 10:17 | |
*** annp has quit IRC | 10:25 | |
*** annp has joined #openstack-keystone | 10:26 | |
*** annp has quit IRC | 10:38 | |
*** annp has joined #openstack-keystone | 10:49 | |
*** annp has quit IRC | 10:54 | |
*** amoralej is now known as amoralej|lunch | 11:04 | |
*** edmondsw has joined #openstack-keystone | 11:29 | |
*** lifeless has quit IRC | 11:45 | |
*** gongysh has joined #openstack-keystone | 11:53 | |
*** edmondsw has quit IRC | 12:07 | |
*** edmondsw has joined #openstack-keystone | 12:13 | |
*** edmondsw_ has joined #openstack-keystone | 12:16 | |
*** edmondsw has quit IRC | 12:19 | |
*** jmlowe has joined #openstack-keystone | 12:28 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add project hierarchical tree check when Keystone start https://review.openstack.org/580331 | 12:30 |
*** vishakha has quit IRC | 12:31 | |
*** raildo has joined #openstack-keystone | 12:32 | |
knikolla | o/ | 12:44 |
*** vishakha has joined #openstack-keystone | 12:46 | |
*** jmlowe has quit IRC | 12:51 | |
*** gongysh has quit IRC | 12:53 | |
*** vishakha has quit IRC | 12:55 | |
*** jmlowe has joined #openstack-keystone | 13:00 | |
*** vishakha has joined #openstack-keystone | 13:08 | |
*** amoralej|lunch is now known as amoralej | 13:28 | |
*** rmascena has joined #openstack-keystone | 13:57 | |
*** raildo has quit IRC | 13:59 | |
*** ispp has quit IRC | 14:08 | |
*** ispp has joined #openstack-keystone | 14:09 | |
*** rmascena is now known as raildo | 14:11 | |
*** rmascena has joined #openstack-keystone | 14:13 | |
*** raildo has quit IRC | 14:16 | |
*** rmascena is now known as raildo | 14:24 | |
gagehugo | o/ | 14:25 |
*** mriedem has joined #openstack-keystone | 14:36 | |
mriedem | riddle me this, | 14:36 |
mriedem | we're debating in #openstack-placement that keystone project/user ids have to be uuids or not | 14:36 |
mriedem | i didn't think they had to be uuids | 14:37 |
*** itlinux has quit IRC | 14:40 | |
ayoung | Anyone interested in co-presenting at the Summit? I have an idea for a talk. Tentatice title "Pushing Keystone over the Edge" on dealing with the multi-site issues | 14:43 |
ayoung | mriedem, define "have to" | 14:43 |
ayoung | I made them work as DNs back in early LDAP days, but that is yucky | 14:44 |
ayoung | we assign UUIDs or things that look like them to Federated Ids that come in | 14:44 |
ayoung | I wanted them to be sha256 hashes, which are longer | 14:44 |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Copy shibboleth logs in v3 functional jobs https://review.openstack.org/580401 | 14:45 |
*** sonuk has quit IRC | 14:46 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone-tempest-plugin master: Keystone to Keystone tests https://review.openstack.org/580041 | 14:46 |
mriedem | ayoung: is it safe to assume that project and user ids in openstack are UUIDs | 14:51 |
mriedem | or can they be other things based on how the deployment is configured | 14:51 |
mriedem | because a few years ago sdague asserted they don't have to be uuids and some deployments didn't make them uuids | 14:51 |
mriedem | or they encoded domain-specific things in the project id for some deployments | 14:51 |
*** ayoung has quit IRC | 14:52 | |
*** testovich has quit IRC | 14:52 | |
knikolla | mriedem: for projects, unless they are using their own custom made driver, yes. for users, not. ldap users don't have UUIDs. | 14:55 |
knikolla | bf97c38af9e3a2db2f63190683180b138c57f393a2ebea70287698e1fc427072 | demo | 14:56 |
*** ayoung has joined #openstack-keystone | 15:03 | |
mriedem | knikolla: ack thanks | 15:04 |
openstackgerrit | Kristi Nikolla proposed openstack/keystonemiddleware master: Document endpoint interface and region behavior https://review.openstack.org/505396 | 15:13 |
openstackgerrit | Kristi Nikolla proposed openstack/keystonemiddleware master: Document endpoint interface and region behavior https://review.openstack.org/505396 | 15:13 |
*** fiddletwix has quit IRC | 15:15 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Only upload SP metadata to testshib.org if IDP id is testshib https://review.openstack.org/545471 | 15:18 |
*** peereb has quit IRC | 15:22 | |
*** itlinux has joined #openstack-keystone | 15:25 | |
*** martinus__ has quit IRC | 15:30 | |
*** gyee has joined #openstack-keystone | 15:31 | |
apdibbo | Hi, I am having an issue with Keystone and LDAP, is anyone around who could give me a few pointers? When active directory users are authenticating through keystone we are getting a 504 timeout. tracing through the logs it looks like it is authenticating against ldap but the clients receive a "ConnectFailure: Unable to establish connection to https://openstack.nubes.rl.ac.uk:5000/v3/auth/tokens: ('Connection aborted.', | 15:41 |
apdibbo | BadStatusLine("''",))" | 15:41 |
*** dtruong has joined #openstack-keystone | 15:55 | |
*** jmlowe has quit IRC | 16:01 | |
*** mriedem has left #openstack-keystone | 16:20 | |
*** apdibbo_ has joined #openstack-keystone | 16:30 | |
*** ispp has quit IRC | 16:32 | |
*** apdibbo has quit IRC | 16:33 | |
*** apdibbo_ has quit IRC | 16:35 | |
openstackgerrit | Stephen Finucane proposed openstack/keystone master: Replace support matrix ext with common library https://review.openstack.org/527808 | 16:38 |
*** s10 has joined #openstack-keystone | 16:56 | |
*** amoralej is now known as amoralej|off | 17:03 | |
*** s10 has quit IRC | 17:05 | |
*** jmlowe has joined #openstack-keystone | 17:44 | |
*** pcichy has quit IRC | 18:11 | |
*** nicodemus_ has joined #openstack-keystone | 18:12 | |
nicodemus_ | Hello! | 18:13 |
nicodemus_ | I'm trying to configure Keystone as a SP using a third-party IdP | 18:13 |
nicodemus_ | but when horizon redirects to the OS-FEDERATION url, keystone logs tht it's "missing entity ID from environment" | 18:15 |
nicodemus_ | I'm having trouble understanding exactly how to tell keystone the ID of the entity I want to use... has anyone had such issue? | 18:16 |
*** s10 has joined #openstack-keystone | 18:16 | |
cmurphy | nicodemus_: that error could have a lot of different causes but the gist is that horizon is trying to redirect to a keystone federation endpoint but it's failing to go through the apache saml mod which means it's failing to set the right headers in the apache request | 18:26 |
cmurphy | the first thing to check is that remote_id_attribute is set correctly in keystone.conf | 18:26 |
cmurphy | the next thing is to look at the <Location ..> directives in the vhost and make sure they're correct | 18:27 |
cmurphy | and then also check that the OPENSTACK_KEYSTONE_URL in horizon's local_settings.py is correct | 18:27 |
nicodemus_ | cmurphy: so when horizon does the redirect to keystone, the request should contain a specific header telling keystone which identity-provider to use? Is that correct? | 18:34 |
cmurphy | nicodemus_: not exactly, when horizon does the redirect to keystone it should be redirecting to one of the paths protected by <Location ...> directives in the apache vhost, and the apache mod will set the needed headers before passing it on to keystone | 18:36 |
*** pcichy has joined #openstack-keystone | 18:36 | |
nicodemus_ | I see. I've configured the remote_id_attribute in keystone.conf as per https://docs.openstack.org/keystone/pike/advanced-topics/federation/federated_identity.html (I'm using mellon, so the attribute is set to MELLON_IDP) | 18:37 |
nicodemus_ | but it's unclear the effect that variable would have | 18:39 |
cmurphy | that setting just tells keystone how to process the data that apache is passing to it | 18:42 |
cmurphy | if you're using mellon then you should have some pieces in your keystone vhost that look something like this http://paste.openstack.org/show/725136/ | 18:43 |
cmurphy | but the paths need to match the routes you're actually using, for example you may or may not have your keystone using a /identity endpoint and you need to make sure the idp and protocol parts of the path match what you configured | 18:44 |
nicodemus_ | I see... so the <Location ...> stanza shouldn't have the MellonSPPrivateKeyFile directives? Those I've configured in the <Location /v3> section | 18:47 |
cmurphy | nicodemus_: no those are correct to have there, for example this has worked for me in the past http://paste.openstack.org/show/725137/ | 18:49 |
cmurphy | sorry i just clipped it out because that's usually not the tricky part | 18:49 |
nicodemus_ | thanks cmurphy ! That's quite helpful | 18:55 |
nicodemus_ | much obliged | 18:55 |
cmurphy | you're welcome, hope you work it out | 18:55 |
*** Chealion has quit IRC | 19:21 | |
*** Chealion has joined #openstack-keystone | 19:24 | |
nicodemus_ | cmurphy: let me ask you yet another question (that might be obvious) | 19:29 |
nicodemus_ | in the last paste, there's a <Location...> that goes on the vhost conf on keystone, and another <Location...> that goes on the horizon vhost? | 19:30 |
cmurphy | nicodemus_: no, sorry that comment is misleading, they're all for keystone | 19:31 |
nicodemus_ | oh, ok | 19:32 |
nicodemus_ | so horizon simply does a redirect, and all the mellon magic happens in keystone | 19:32 |
nicodemus_ | do you by any chance know which header would mellon include in the header? I'm trying to validate if mellon is in fact doing something or not | 19:33 |
cmurphy | nicodemus_: I think it will literally be 'MELLON_IDP', and if it's working properly you should be able to see it in the keystone debug logs | 19:36 |
nicodemus_ | Got it. Thanks again !! | 19:37 |
cmurphy | np | 19:37 |
*** lifeless has joined #openstack-keystone | 19:39 | |
*** jmlowe has quit IRC | 19:40 | |
*** jmlowe has joined #openstack-keystone | 19:59 | |
*** pcichy has quit IRC | 20:05 | |
*** aojea_ has joined #openstack-keystone | 20:19 | |
*** dmellado has quit IRC | 20:28 | |
*** mchlumsky has quit IRC | 20:36 | |
*** raildo has quit IRC | 20:40 | |
*** aojea_ has quit IRC | 20:56 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Copy shibboleth logs in v3 functional jobs https://review.openstack.org/580401 | 20:59 |
*** jmlowe has quit IRC | 20:59 | |
*** jmlowe has joined #openstack-keystone | 21:00 | |
*** aojea has joined #openstack-keystone | 21:01 | |
nicodemus_ | cmurphy: I'm making progress! But still have another doubt regarding the traffic flow | 21:06 |
nicodemus_ | I'm being redirected to the SAML host for login, but after using valid credentials there's a "bad request" page waiting for me. | 21:07 |
nicodemus_ | Once the SAML host receives the credencials, it is supposed to do a callback to horizon, or to keystone? | 21:07 |
cmurphy | nicodemus_: i have a diagram for you http://www.gazlene.net/demystifying-keystone-federation.html#websso-with-keystone-and-horizon | 21:11 |
cmurphy | it should call back to keystone at that point | 21:11 |
nicodemus_ | Wonderful! Many thanks !! | 21:11 |
cmurphy | is the bad request coming from keystone? or horizon? or the idp? | 21:11 |
nicodemus_ | It's clear | 21:11 |
nicodemus_ | it comes from keystone | 21:12 |
cmurphy | if you turn on insecure_debug = true in keystone.conf it should give you a clear error message of what went wrong | 21:12 |
nicodemus_ | I see that I have an encrypted SAML response, but when it's POSTed to keystone on an URL that ends with 'auth/mellon/postResponse' I get the 400 error - bad request. Perhaps Keystone isn't able to decrypt the response? | 21:16 |
cmurphy | it should be able to decrypt it because exchanging the service provider's public key with the identity provider is part of uploading its metadata | 21:19 |
nicodemus_ | Perhaps if the user that configures the IdP didn't configure my metadata properly, I should expect a 400 error | 21:20 |
nicodemus_ | (I didn't mention that I'm not configuring the IdP) | 21:20 |
cmurphy | you might try setting it up with testshib.org and if you can get that working then you can compare to your idp | 21:22 |
cmurphy | the regular apache logs might have more information on mellon-specific errors if the keystone logs don't have anything | 21:23 |
nicodemus_ | certanly, there's an error in the apache logs | 21:23 |
nicodemus_ | http://paste.openstack.org/show/725149/ | 21:24 |
*** itlinux has quit IRC | 21:24 | |
cmurphy | hmm I've never seen that one, but https://github.com/UNINETT/mod_auth_mellon/issues/112 seems to indicate that something might be wrong in the MellonIdPMetadataFile file | 21:27 |
nicodemus_ | Looks like it | 21:27 |
nicodemus_ | Do you know if the 'MellonIdP' value in the apache vhost for keystone should be the entityID from the metadata of the IdP? | 21:30 |
cmurphy | I don't think so, I just use "IDP". From the docs I think it's setting the name of the header, as in MELLON_IDP | 21:34 |
cmurphy | it's the name of the header that will have the entityID as its value | 21:34 |
*** rcernin has joined #openstack-keystone | 22:00 | |
*** nicolasbock has quit IRC | 22:17 | |
adriant | cmurphy: you still about? | 22:17 |
*** aojea has quit IRC | 22:23 | |
*** nicodemus_ has quit IRC | 22:30 | |
*** aojea_ has joined #openstack-keystone | 22:39 | |
*** edmondsw_ has quit IRC | 22:40 | |
*** edmondsw has joined #openstack-keystone | 22:41 | |
*** edmondsw has quit IRC | 22:45 | |
*** aojea_ has quit IRC | 22:55 | |
*** rcernin has quit IRC | 22:58 | |
*** rcernin has joined #openstack-keystone | 23:01 | |
*** tosky has quit IRC | 23:01 | |
* kmalloc tries to vacation... keeps looking at code | 23:03 | |
adriant | kmalloc: I was home sick yesterday... still followed up on code review | 23:07 |
adriant | Trying to keep away from work when stuff is a little time sensitive is hard, and also work/life balance is a thing so many people suck at! | 23:09 |
*** aojea has joined #openstack-keystone | 23:16 | |
*** aojea has quit IRC | 23:21 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Flesh out and add testing for flask_RESTful scaffolding https://review.openstack.org/578190 | 23:40 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Make keystone.server.flask more interesting for importing https://review.openstack.org/579928 | 23:40 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Fix keystone.common.rbac_enforcer.__init__.py exporting https://review.openstack.org/579930 | 23:40 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Do not use flask.g imported as g https://review.openstack.org/579985 | 23:40 |
*** aojea has joined #openstack-keystone | 23:46 | |
*** aojea has quit IRC | 23:50 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!