*** spartakos has quit IRC | 00:30 | |
stewie925 | kmalloc: thank you | 00:32 |
---|---|---|
*** rcernin has quit IRC | 00:50 | |
*** rcernin has joined #openstack-keystone | 00:51 | |
*** gyee has quit IRC | 00:53 | |
*** stewie925 has quit IRC | 01:15 | |
*** chaconpiza has quit IRC | 01:19 | |
openstackgerrit | Monty Taylor proposed openstack/keystoneauth master: Add support for ironic single-version responses https://review.openstack.org/595980 | 01:30 |
wxy-xiyuan | lbragstad: cool. I'll take a look. Thanks. | 01:31 |
lbragstad | wxy-xiyuan no problem | 01:31 |
*** lbragstad has quit IRC | 01:43 | |
*** lbragstad has joined #openstack-keystone | 01:45 | |
*** ChanServ sets mode: +o lbragstad | 01:45 | |
*** sapd1_ has joined #openstack-keystone | 02:03 | |
*** sapd1 has quit IRC | 02:07 | |
*** lbragstad has quit IRC | 02:09 | |
*** sapd1_ has quit IRC | 02:09 | |
*** spartakos has joined #openstack-keystone | 02:10 | |
*** sapd1 has joined #openstack-keystone | 02:13 | |
*** nicolasbock has quit IRC | 02:18 | |
openstackgerrit | wangxiyuan proposed openstack/keystonemiddleware master: No need to compare CONF content https://review.openstack.org/599936 | 02:34 |
errr | Im setting up federtion using mod_auth_mellon, and in my idp Im not sure what value to use for "Signle Sign On URL". When using shibboleth it is: https://mysite.com:5000/Shibboleth.sso/SAML2/POST but whenusing mod_auth_mellon I dont know what to use.. Any ideas? | 03:25 |
errr | my idp is okta is that matters/helps | 03:26 |
*** spartakos has quit IRC | 03:35 | |
openstackgerrit | Monty Taylor proposed openstack/keystoneauth master: Add support for ironic single-version responses https://review.openstack.org/595980 | 03:50 |
*** markvoelker has joined #openstack-keystone | 04:06 | |
*** markvoelker has quit IRC | 04:11 | |
*** ykarel|away has joined #openstack-keystone | 04:17 | |
*** dave-mccowan has quit IRC | 04:36 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: WIP - Convert domains api to flask https://review.openstack.org/597350 | 04:36 |
*** ducnv has quit IRC | 04:42 | |
*** ducnv has joined #openstack-keystone | 04:42 | |
*** shyamb has joined #openstack-keystone | 04:45 | |
*** markvoelker has joined #openstack-keystone | 05:07 | |
openstackgerrit | Deepak Mourya proposed openstack/keystone master: Added support for a ``description`` attribute for Identity Roles https://review.openstack.org/484348 | 05:09 |
deepak_mourya_ | cmurphy: Hi, I have updated your comments in https://review.openstack.org/#/c/484348/16 you can review this. | 05:12 |
*** ykarel|away is now known as ykarel | 05:18 | |
*** shyamb has quit IRC | 05:25 | |
*** ykarel has quit IRC | 05:26 | |
*** shyamb has joined #openstack-keystone | 05:36 | |
*** ykarel has joined #openstack-keystone | 05:45 | |
*** ducnv has left #openstack-keystone | 06:10 | |
*** pcaruana has joined #openstack-keystone | 06:25 | |
*** shyam89 has joined #openstack-keystone | 06:37 | |
*** shyamb has quit IRC | 06:41 | |
*** markvoelker has quit IRC | 06:45 | |
*** rcernin has quit IRC | 07:00 | |
openstackgerrit | wangxiyuan proposed openstack/oslo.limit master: Add opts file https://review.openstack.org/586760 | 07:00 |
openstackgerrit | wangxiyuan proposed openstack/oslo.limit master: Add limit check func https://review.openstack.org/596520 | 07:00 |
*** chaconpiza has joined #openstack-keystone | 07:04 | |
*** Emine has joined #openstack-keystone | 07:06 | |
openstackgerrit | wangxiyuan proposed openstack/oslo.limit master: Add limit check func https://review.openstack.org/596520 | 07:13 |
openstackgerrit | wangxiyuan proposed openstack/oslo.limit master: Add limit check func https://review.openstack.org/596520 | 07:25 |
openstackgerrit | wangxiyuan proposed openstack/oslo.limit master: Make callback required https://review.openstack.org/600357 | 07:25 |
cmurphy | errr: which value are you trying to set exactly? is this in keystone.conf or in the apache vhost? | 07:29 |
*** hoonetorg has quit IRC | 07:34 | |
*** pcaruana has quit IRC | 07:36 | |
*** shyam89 has quit IRC | 07:38 | |
*** markvoelker has joined #openstack-keystone | 07:43 | |
*** hoonetorg has joined #openstack-keystone | 07:47 | |
*** pcaruana has joined #openstack-keystone | 07:48 | |
*** shyamb has joined #openstack-keystone | 07:58 | |
*** david-lyle has quit IRC | 08:14 | |
*** shyamb has quit IRC | 08:14 | |
*** dklyle has joined #openstack-keystone | 08:15 | |
*** jamiec has quit IRC | 08:30 | |
*** jamiec has joined #openstack-keystone | 08:33 | |
*** shyamb has joined #openstack-keystone | 08:34 | |
*** d0ugal has joined #openstack-keystone | 08:49 | |
*** hwoarang_ has joined #openstack-keystone | 09:11 | |
*** hwoarang has quit IRC | 09:15 | |
*** shyamb has quit IRC | 09:22 | |
*** hwoarang_ is now known as hwoarang | 09:23 | |
openstackgerrit | wangxiyuan proposed openstack/oslo.limit master: Add limit check func https://review.openstack.org/596520 | 09:34 |
openstackgerrit | wangxiyuan proposed openstack/oslo.limit master: Make callback required https://review.openstack.org/600357 | 09:34 |
*** shyamb has joined #openstack-keystone | 09:38 | |
*** shyam89 has joined #openstack-keystone | 09:46 | |
*** shyamb has quit IRC | 09:50 | |
*** d0ugal has quit IRC | 09:51 | |
*** shyam89 has quit IRC | 09:56 | |
*** shyamb has joined #openstack-keystone | 09:56 | |
*** d0ugal has joined #openstack-keystone | 10:01 | |
*** shyamb has quit IRC | 10:03 | |
*** shyamb has joined #openstack-keystone | 10:03 | |
*** d0ugal has quit IRC | 10:14 | |
*** d0ugal has joined #openstack-keystone | 10:22 | |
*** nicolasbock has joined #openstack-keystone | 10:31 | |
*** shyamb has quit IRC | 10:43 | |
*** shyamb has joined #openstack-keystone | 10:54 | |
*** Emine has quit IRC | 11:23 | |
*** Emine has joined #openstack-keystone | 11:25 | |
*** shyamb has quit IRC | 11:57 | |
*** shyamb has joined #openstack-keystone | 12:05 | |
*** markvoelker has quit IRC | 12:22 | |
*** shyamb has quit IRC | 12:24 | |
*** shyamb has joined #openstack-keystone | 12:24 | |
*** ykarel is now known as ykarel|away | 12:41 | |
*** ykarel|away has quit IRC | 12:47 | |
*** lbragstad has joined #openstack-keystone | 12:54 | |
*** ChanServ sets mode: +o lbragstad | 12:54 | |
*** raildo has joined #openstack-keystone | 12:54 | |
*** lbragstad has quit IRC | 13:09 | |
*** lbragstad has joined #openstack-keystone | 13:15 | |
*** ChanServ sets mode: +o lbragstad | 13:15 | |
*** mchlumsky has joined #openstack-keystone | 13:32 | |
*** shyamb has quit IRC | 13:35 | |
*** d0ugal has quit IRC | 14:05 | |
*** d0ugal has joined #openstack-keystone | 14:09 | |
lbragstad | ildikov i'm updating https://etherpad.openstack.org/p/keystone-stein-ptg with room details, for tuesday should i put Ballroom A on our etherpad? | 14:29 |
lbragstad | i assume that's where we'll plan to discuss keystone-related edge topics | 14:29 |
knikolla | o/ | 14:31 |
lbragstad | what's the consensus for getting a room on wednesday? | 14:34 |
lbragstad | right now we don't have one, but our schedule is loosely defined | 14:34 |
lbragstad | and it's tentatively going to be a day for hacking | 14:35 |
lbragstad | should we jump the gun and schedule a room, or play it by ear? | 14:35 |
knikolla | lbragstad: if there's empty rooms, might as well schedule one. and if we don't use it we can post on IRC and advertise it as a free use space for other teams | 14:39 |
lbragstad | true | 14:40 |
lbragstad | i'll see if a smaller room is available and schedule it later today if possible | 14:40 |
lbragstad | otherwise i do remember there being open tables close to the room we were in last time (lobby upstairs) | 14:40 |
lbragstad | that seemed pretty quiet | 14:40 |
gagehugo | o/ | 14:48 |
*** d0ugal has quit IRC | 14:50 | |
*** d0ugal has joined #openstack-keystone | 14:52 | |
kmalloc | knikolla: ++ | 14:52 |
ildikov | lbragstad: yes, for Tuesday Ballroom A should work well | 14:54 |
ildikov | lbragstad: I think it's also easier from overall logistics perspective | 14:55 |
*** itlinux has quit IRC | 14:56 | |
lbragstad | ildikov awesome - i've updated our schedule to reflect that | 15:02 |
*** gyee has joined #openstack-keystone | 15:11 | |
*** r-daneel has quit IRC | 15:17 | |
*** d0ugal has quit IRC | 15:21 | |
*** spartakos has joined #openstack-keystone | 15:24 | |
*** d0ugal has joined #openstack-keystone | 15:34 | |
*** pcaruana has quit IRC | 15:42 | |
*** r-daneel has joined #openstack-keystone | 15:44 | |
*** r-daneel has quit IRC | 15:45 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: WIP - Convert domains api to flask https://review.openstack.org/597350 | 15:46 |
*** itlinux has joined #openstack-keystone | 15:54 | |
cmurphy | fyi i'm traveling tomorrow so i won't send out the update email, seems like not much happened this week to report on anyway | 16:01 |
*** pcaruana has joined #openstack-keystone | 16:01 | |
knikolla | cmurphy: safe travels! | 16:02 |
cmurphy | knikolla: ty, you as well | 16:02 |
knikolla | ty :) | 16:02 |
*** itlinux_ has joined #openstack-keystone | 16:08 | |
*** itlinux has quit IRC | 16:12 | |
*** itlinux_ has quit IRC | 16:33 | |
errr | cmurphy: Its on the IDP side of things. Im using okta and Im trying to set values for the app, and you get a screen like this: https://camo.githubusercontent.com/b870027fa31de46d28007a9131d5cc96588c454d/68747470733a2f2f692e696d6775722e636f6d2f766137535937622e706e67 | 16:39 |
errr | cmurphy: Those are the values that work for using shibboleth, but I need to move to mod_auth_mellon and I do not know what those values should be for mod_auth_mellon | 16:39 |
*** ykarel|away has joined #openstack-keystone | 16:42 | |
errr | cmurphy: this is the setup doc for mellon Im using: https://docs.openstack.org/keystone/pike/advanced-topics/federation/mellon.html | 16:43 |
lbragstad | FYI - we have Longs Peak booked for wednesday morning | 16:49 |
lbragstad | if we decide we need more time on wednesday afternoon, we can see what there is for availability | 16:49 |
cmurphy | errr: in the SP metadata there should be a HTTP-POST binding, I think that's the value it's looking for | 16:55 |
errr | where do I get that? | 16:56 |
cmurphy | errr: i'm not familiar with okta but usually you would just hand it the whole metadata file and it would figure it out | 16:56 |
cmurphy | errr: it's the file you set with MellonSPMetadataFile on the SP | 16:57 |
cmurphy | mellon comes with a script to generate it | 16:57 |
cmurphy | i'm not sure if it serves it on some endpoint by default | 16:57 |
errr | ok. | 16:57 |
cmurphy | looks like just <endpoint>/metadata according to https://github.com/Uninett/mod_auth_mellon#service-provider-metadata | 16:58 |
*** jaosorior has quit IRC | 17:00 | |
*** jaosorior has joined #openstack-keystone | 17:01 | |
*** itlinux has joined #openstack-keystone | 17:03 | |
*** imacdonn has quit IRC | 17:05 | |
*** imacdonn has joined #openstack-keystone | 17:05 | |
*** spartakos has quit IRC | 17:11 | |
*** r-daneel has joined #openstack-keystone | 17:11 | |
*** ChanServ sets mode: -rf | 17:16 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: WIP - Convert domains api to flask https://review.openstack.org/597350 | 17:21 |
*** pcaruana has quit IRC | 17:27 | |
*** ykarel|away has quit IRC | 17:30 | |
*** spartakos has joined #openstack-keystone | 17:35 | |
*** links has joined #openstack-keystone | 17:38 | |
*** links has quit IRC | 17:38 | |
openstackgerrit | Lance Bragstad proposed openstack/keystonemiddleware master: Remove tox_install.sh https://review.openstack.org/599003 | 17:39 |
*** mvenesio has joined #openstack-keystone | 17:40 | |
openstackgerrit | Lance Bragstad proposed openstack/oslo.limit master: Render API reference documentation https://review.openstack.org/600264 | 17:44 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.limit master: Add a conceptual overview to docs https://review.openstack.org/600265 | 17:44 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.limit master: Allow ProjectClaims to support multiple resources https://review.openstack.org/600266 | 17:44 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.limit master: Add a conceptual overview to docs https://review.openstack.org/600265 | 17:45 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.limit master: Allow ProjectClaims to support multiple resources https://review.openstack.org/600266 | 17:45 |
openstackgerrit | Lance Bragstad proposed openstack/oslo.limit master: Rename callback to usage_callback https://review.openstack.org/600491 | 17:59 |
lbragstad | ^ some relatively mild oslo.limit reviews if folks are interesting in having a look | 18:02 |
*** pcaruana has joined #openstack-keystone | 18:02 | |
*** links has joined #openstack-keystone | 18:02 | |
errr | cmurphy: I found that file you are talking about. Looks like I generated it wrong. Thanks for your help. | 18:04 |
*** openstackgerrit has quit IRC | 18:05 | |
cmurphy | errr: yw | 18:06 |
errr | I think it would be great to do a little web series on setting up federation using shib and mellon and doing it with a couple of platforms, like openstack-ansible, and like tripleo and devstack. The use some free IDPs to show how to go from basic keystone auth to functional federation. | 18:07 |
errr | Would anyone be interested in doing that with me? We put it up on youtube, and get the examples worked up into the keystone docs. | 18:08 |
errr | Cover some of the advanced mapping stuff.. basiclly take our time do it really nice like so the content doesnt have to be crammed into the timespan of an openstack talk.. | 18:09 |
*** mvenesio has quit IRC | 18:10 | |
*** mvenesio has joined #openstack-keystone | 18:11 | |
*** links has quit IRC | 18:11 | |
*** spartakos has quit IRC | 18:15 | |
*** melwitt is now known as melwitt_awaysick | 18:18 | |
*** jaosorior has quit IRC | 18:27 | |
*** timburke has joined #openstack-keystone | 18:29 | |
knikolla | errr: sure, i'd be interested in helping out. | 18:33 |
errr | awesome :D | 18:33 |
lbragstad | errr that's a great idea | 18:44 |
lbragstad | kmalloc do you want to take a peak at https://review.openstack.org/#/c/598990/ | 18:52 |
kmalloc | looking | 18:56 |
kmalloc | lbragstad: easy +2/+A | 18:56 |
lbragstad | also - we have mess going on with various keystone repositories and pushing through dhellmann's changes for python 3 | 18:57 |
lbragstad | for example https://review.openstack.org/#/c/597685/ | 18:58 |
lbragstad | shows that the stable branch for ksc is hosed | 18:58 |
lbragstad | same with ksm | 18:58 |
lbragstad | (which i have patches up for) | 18:58 |
lbragstad | not sure how to get the ones for ksm working... we have an optional dependency on oslo.messaging that appears to be messing things up | 19:00 |
*** mbuil has quit IRC | 19:04 | |
lbragstad | https://review.openstack.org/#/c/600518/ should fix stable/pike for ksc (hopefully) | 19:04 |
lbragstad | https://review.openstack.org/#/c/600519/ should do the same for stable/ocata | 19:06 |
*** mbuil has joined #openstack-keystone | 19:07 | |
*** openstackgerrit has joined #openstack-keystone | 19:09 | |
openstackgerrit | Merged openstack/python-keystoneclient master: Update reno for stable/rocky https://review.openstack.org/589791 | 19:09 |
*** spartakos has joined #openstack-keystone | 19:30 | |
gagehugo | kmalloc the domains flask is getting closer, getting some 403s on a few of the tests and not sure why atm, currently looking | 19:34 |
*** pcaruana has quit IRC | 19:35 | |
*** Emine has quit IRC | 19:37 | |
*** Emine has joined #openstack-keystone | 19:38 | |
*** nicolasbock has quit IRC | 20:34 | |
openstackgerrit | Merged openstack/keystoneauth master: Remove os-testr from requirements https://review.openstack.org/600004 | 20:38 |
openstackgerrit | Monty Taylor proposed openstack/keystoneauth master: Add support for ironic single-version responses https://review.openstack.org/595980 | 20:49 |
*** raildo has quit IRC | 20:53 | |
*** nicolasbock has joined #openstack-keystone | 20:54 | |
*** dims has quit IRC | 20:55 | |
lbragstad | kmalloc https://review.openstack.org/#/c/600554/ will need a kick once it passes to fix stable/ocata | 21:06 |
*** dims has joined #openstack-keystone | 21:11 | |
lbragstad | FYI - i added another items to the agenda for next wednesday | 21:12 |
lbragstad | i have results from the user survey, i can share them if people want to take a look, but putting it on the agenda in case we want to dig into them face-to-face | 21:13 |
*** mvenesio has quit IRC | 21:18 | |
*** mvenesio has joined #openstack-keystone | 21:19 | |
*** mvenesio has quit IRC | 21:25 | |
kmalloc | lbragstad: ah cool | 21:50 |
kmalloc | gagehugo: nice. | 21:50 |
openstackgerrit | Gage Hugo proposed openstack/keystoneauth master: Revert "Change log hashing to SHA256" https://review.openstack.org/600561 | 22:04 |
gagehugo | bah | 22:05 |
*** dave-mccowan has joined #openstack-keystone | 22:22 | |
lbragstad | Per domain configuration had 79 responses; Enhancing policy had 92 responses; Scaling out to multiple regions had 136 responses; Performance improvements had 144 responses; Federated identity enhancements had 184 responses | 22:26 |
*** rcernin has joined #openstack-keystone | 22:29 | |
*** itlinux has quit IRC | 22:34 | |
gagehugo | interesting | 22:35 |
lbragstad | yeah | 22:38 |
lbragstad | i'll need to dig up the results from older surveys, but i think the gap between the top three and the rest has widened | 22:39 |
lbragstad | federated identity enhancements is still in the lead, by far | 22:40 |
lbragstad | for those interested in viewing the feedback directly https://docs.google.com/spreadsheets/d/1HOIq7U8rgR5SAZDpuL1VdoVALIf1Np3ar1YzATKumd0/edit?usp=sharing | 22:47 |
*** dave-mccowan has quit IRC | 23:01 | |
*** itlinux has joined #openstack-keystone | 23:45 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!