*** imacdonn has quit IRC | 01:15 | |
*** imacdonn has joined #openstack-keystone | 01:16 | |
openstackgerrit | Tao Li proposed openstack/keystone master: Use uuidutils instead of uuid.uuid4() https://review.openstack.org/603542 | 01:25 |
---|---|---|
openstackgerrit | wangxiyuan proposed openstack/keystone master: Update log translation hacking check https://review.openstack.org/604245 | 01:47 |
*** Dinesh_Bhor has joined #openstack-keystone | 01:50 | |
*** errr has quit IRC | 02:12 | |
*** Dinesh_Bhor has quit IRC | 02:26 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Mapped Groups don't exist breaks WebSSO https://review.openstack.org/597992 | 02:28 |
*** errr has joined #openstack-keystone | 02:37 | |
*** Dinesh_Bhor has joined #openstack-keystone | 02:38 | |
*** hoonetorg has quit IRC | 02:48 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Mapped Groups don't exist breaks WebSSO https://review.openstack.org/597992 | 02:52 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Mapped Groups don't exist breaks WebSSO https://review.openstack.org/597992 | 02:54 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Mapped Groups don't exist breaks WebSSO https://review.openstack.org/597992 | 02:57 |
*** hoonetorg has joined #openstack-keystone | 03:02 | |
*** rodrigods has quit IRC | 03:02 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Update log translation hacking check https://review.openstack.org/604245 | 03:03 |
*** jmccrory has quit IRC | 03:32 | |
*** jmccrory has joined #openstack-keystone | 03:37 | |
*** jamielennox has quit IRC | 03:37 | |
*** jamielennox has joined #openstack-keystone | 03:38 | |
*** rcernin has quit IRC | 03:48 | |
*** rcernin has joined #openstack-keystone | 03:49 | |
*** edmondsw has quit IRC | 03:56 | |
*** Dinesh_Bhor has quit IRC | 03:58 | |
*** jhesketh_ has joined #openstack-keystone | 04:32 | |
*** Dinesh_Bhor has joined #openstack-keystone | 04:34 | |
*** d34dh0r53 has quit IRC | 04:34 | |
*** d34dh0r53 has joined #openstack-keystone | 04:34 | |
*** jhesketh has quit IRC | 04:36 | |
kmalloc | adriant: part of the default roles and documented rules in code, we can make changes so admin_or_owner can be changed. | 05:08 |
adriant | kmalloc: oh yeah, it's just going to take time, and require a shift in mindset | 05:08 |
kmalloc | yep. | 05:10 |
adriant | because until we do shift away from the idea of "any role on a project" being the standard, RBAC is pretty limited. Although with the way the policy in code is now will make it somewhat easier for operators to do such changes themselves | 05:11 |
*** Dinesh_Bhor has quit IRC | 05:12 | |
adriant | but yeah, it will take time. And in the meantime, we'll play with our own deployment's policy and see what works :) | 05:13 |
*** Dinesh_Bhor has joined #openstack-keystone | 05:16 | |
*** jhesketh_ is now known as jhesketh | 05:25 | |
openstackgerrit | Vishakha Agarwal proposed openstack/python-keystoneclient master: create() call in v3.regions.py is wrong https://review.openstack.org/594921 | 05:33 |
*** shyamb has joined #openstack-keystone | 05:51 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/oslo.policy master: POC: Add Open Policy Agent driver https://review.openstack.org/604038 | 05:54 |
openstackgerrit | Tao Li proposed openstack/keystone master: Use uuidutils instead of uuid.uuid4() https://review.openstack.org/603542 | 05:58 |
*** shyamb has quit IRC | 06:01 | |
*** shyamb has joined #openstack-keystone | 06:02 | |
*** shyamb has quit IRC | 06:13 | |
*** shyamb has joined #openstack-keystone | 06:14 | |
*** shyamb has quit IRC | 06:21 | |
*** shyamb has joined #openstack-keystone | 06:22 | |
*** shyamb has quit IRC | 06:38 | |
*** belmoreira has joined #openstack-keystone | 06:42 | |
*** shyamb has joined #openstack-keystone | 06:58 | |
*** rcernin has quit IRC | 07:02 | |
*** shyamb has quit IRC | 07:13 | |
*** shyamb has joined #openstack-keystone | 07:13 | |
*** shyamb has quit IRC | 07:20 | |
*** shyamb has joined #openstack-keystone | 07:20 | |
*** mattgo has joined #openstack-keystone | 07:23 | |
*** shyamb has quit IRC | 07:39 | |
*** dims has quit IRC | 08:11 | |
*** dims has joined #openstack-keystone | 08:12 | |
*** shyamb has joined #openstack-keystone | 08:13 | |
*** belmoreira has quit IRC | 08:37 | |
*** Dinesh_Bhor has quit IRC | 08:37 | |
*** shyamb has quit IRC | 08:41 | |
*** Emine has joined #openstack-keystone | 08:45 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Adding test case for MappingEngineTester https://review.openstack.org/603539 | 08:45 |
*** belmoreira has joined #openstack-keystone | 08:46 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Adding test case for MappingEngineTester https://review.openstack.org/603539 | 08:55 |
*** Dinesh_Bhor has joined #openstack-keystone | 08:55 | |
*** sapd1 has quit IRC | 09:00 | |
*** sapd1_ has joined #openstack-keystone | 09:01 | |
*** shyamb has joined #openstack-keystone | 09:08 | |
*** hoonetorg has quit IRC | 09:08 | |
*** Emine has quit IRC | 09:09 | |
*** jaosorior is now known as jaosorior_lunch | 09:09 | |
*** Dinesh_Bhor has quit IRC | 09:16 | |
*** Emine has joined #openstack-keystone | 09:21 | |
*** hoonetorg has joined #openstack-keystone | 09:25 | |
*** shyamb has quit IRC | 09:40 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Adresses LDAP case-sensitive issue https://review.openstack.org/603345 | 09:55 |
*** Dinesh_Bhor has joined #openstack-keystone | 09:56 | |
*** shyamb has joined #openstack-keystone | 10:03 | |
*** Dinesh_Bhor has quit IRC | 10:20 | |
*** shyamb has quit IRC | 10:32 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Adresses LDAP case-sensitive issue https://review.openstack.org/603345 | 10:32 |
*** shyamb has joined #openstack-keystone | 10:33 | |
*** shyamb has quit IRC | 10:42 | |
*** Emine has quit IRC | 10:44 | |
*** shyamb has joined #openstack-keystone | 11:22 | |
*** jaosorior_lunch is now known as jaosorior | 12:11 | |
*** raildo has joined #openstack-keystone | 12:16 | |
*** shyamb has quit IRC | 12:29 | |
cmurphy | any ptg recaps I should include in the update email? kmalloc knikolla gagehugo hrybacki | 12:39 |
knikolla | cmurphy: nothing from me. You and Lance do an amazing job every time :) | 12:53 |
lbragstad | o/ | 13:02 |
*** trevormc has joined #openstack-keystone | 13:07 | |
lbragstad | awesome summary cmurphy | 13:20 |
lbragstad | i just noticed you published it | 13:20 |
*** jistr is now known as jistr|call | 13:31 | |
*** belmoreira has quit IRC | 13:33 | |
openstackgerrit | ayoung proposed openstack/keystone master: Comment out un-runnable tests https://review.openstack.org/603459 | 13:35 |
*** felipemonteiro has joined #openstack-keystone | 13:43 | |
johnthetubaguy | lbragstad: this is the unified limits spec in Nova I promised: https://review.openstack.org/#/c/602201 Not finished, but has a lot of detail in there now (probably too much) | 13:44 |
lbragstad | johnthetubaguy awesome - thanks! | 13:49 |
*** dansmith is now known as SteelyDan | 13:50 | |
*** felipemonteiro has quit IRC | 13:56 | |
*** openstackgerrit has quit IRC | 14:07 | |
*** mchlumsky has quit IRC | 14:09 | |
*** mchlumsky has joined #openstack-keystone | 14:18 | |
*** lbragstad is now known as elbragstad | 14:24 | |
kmalloc | hrybacki: o/ | 14:33 |
raildo | kmalloc, Harry is ofline-ish today, helping a friend to get in their house after the Hurricane Florence in the NC coast | 14:35 |
raildo | but he is responding emails :) | 14:35 |
kmalloc | raildo: yeah, not surprised | 14:35 |
raildo | knikolla, gagehugo hey guys, do you have some time to review this patch? https://review.openstack.org/#/c/597992/ John and me already take a look on it, and we think that it's in a good shape right now | 14:37 |
*** mchlumsky has quit IRC | 14:40 | |
*** mchlumsky has joined #openstack-keystone | 14:41 | |
cmurphy | kmalloc: do you think you could write up a proposal for outreachy on the flask test_client and subsystem reorg ideas? i can volunteer to mentor if you don't want to | 14:41 |
cmurphy | s/a proposal/proposals | 14:41 |
kmalloc | Sure. But it won't be until 1st week of October probably. | 14:42 |
cmurphy | okay, the deadline is oct 9 | 14:42 |
*** nick_kar has quit IRC | 14:43 | |
kmalloc | Yeah I can have it by then | 14:50 |
cmurphy | o7 | 14:50 |
kmalloc | It prob will be oct 3 or 4 | 14:50 |
kmalloc | But def. doable by the 9th | 14:50 |
kmalloc | Since I want to take my birthday off work :P | 14:51 |
cmurphy | :D | 14:51 |
gagehugo | o/ | 14:53 |
knikolla | raildo: o/, reviewed and left a question | 15:09 |
*** jistr|call is now known as jistr | 15:11 | |
*** bnemec is now known as beekneemech | 15:21 | |
raildo | knikolla, thank you sir! | 15:21 |
*** openstackgerrit has joined #openstack-keystone | 15:52 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Repropose JWT specification for Stein https://review.openstack.org/541903 | 15:52 |
*** felipemonteiro has joined #openstack-keystone | 16:25 | |
*** felipemonteiro has quit IRC | 16:30 | |
*** felipemonteiro has joined #openstack-keystone | 16:30 | |
*** mattgo has quit IRC | 16:41 | |
*** gyee has joined #openstack-keystone | 17:01 | |
*** nicolasbock_ has joined #openstack-keystone | 17:03 | |
*** sonuk has quit IRC | 17:05 | |
*** spsurya has quit IRC | 17:05 | |
*** etp has quit IRC | 17:41 | |
*** etp has joined #openstack-keystone | 17:44 | |
*** etp has quit IRC | 17:55 | |
*** etp has joined #openstack-keystone | 17:56 | |
*** nicolasbock_ has quit IRC | 18:12 | |
*** felipemonteiro has quit IRC | 18:24 | |
trevormc | hi all, I have a policy question :) I'm trying to hit the TARGET_DOMAIN portion of the get_domain policy so that I can move this test in tempest https://review.openstack.org/#/c/525244/, but it appears it is not possible http://paste.openstack.org/show/730556/ can someone describe what kind of setup I need to show the default domain with a non-admin user? | 18:37 |
trevormc | here is the policy for reference https://github.com/openstack/keystone/blob/582cab391a10714a4ec8bab1a6cce9b49867f8d4/keystone/common/policies/domain.py#L20 | 18:38 |
elbragstad | this one specifically? https://github.com/openstack/keystone/blob/582cab391a10714a4ec8bab1a6cce9b49867f8d4/keystone/common/policies/base.py#L21-L23 | 18:42 |
trevormc | Yes! | 18:42 |
elbragstad | it doesn't look like the target attr information is getting passed into policy check function | 18:45 |
*** trevormc_ has joined #openstack-keystone | 18:47 | |
trevormc_ | sorry i got disconnected :( | 18:47 |
elbragstad | actually - gagehugo just modified a bunch of code in the area | 18:47 |
elbragstad | https://github.com/openstack/keystone/commit/296f20f0a7e26784b6414ddbe12e0218087a9f51 | 18:47 |
elbragstad | are you using master? | 18:47 |
*** felipemonteiro has joined #openstack-keystone | 18:48 | |
trevormc_ | yes i have the changes as of Monday this week. | 18:48 |
trevormc_ | commit: c96c7fd03b7afab033bcb31465390f46e56089c5 | 18:48 |
*** felipemonteiro has quit IRC | 18:49 | |
elbragstad | cool - https://git.openstack.org/cgit/openstack/keystone/commit/keystone?id=c96c7fd03b7afab033bcb31465390f46e56089c5 | 18:49 |
*** trevormc has quit IRC | 18:49 | |
*** felipemonteiro has joined #openstack-keystone | 18:49 | |
elbragstad | so you're actually hitting this https://github.com/openstack/keystone/blob/ba459352d8d2b54807a591312bc0b65aa1498b86/keystone/api/domains.py#L78 | 18:50 |
elbragstad | that call is what's protecting the get_domain API | 18:51 |
elbragstad | with policy | 18:51 |
elbragstad | and it doesn't look like it's passing in any sort of target informatino | 18:51 |
elbragstad | information* | 18:51 |
elbragstad | which is an option argument to that method - https://github.com/openstack/keystone/blob/master/keystone/common/rbac_enforcer/enforcer.py#L246-L248 | 18:52 |
elbragstad | https://github.com/openstack/keystone/blob/master/keystone/common/rbac_enforcer/enforcer.py#L261-L267 | 18:52 |
elbragstad | so.. that method will actually attempt to populate it - https://github.com/openstack/keystone/blob/master/keystone/common/rbac_enforcer/enforcer.py#L340-L341 | 18:53 |
elbragstad | which means target_attr will be a dictionary or reference of the domain... | 18:54 |
trevormc_ | ok so it appears we need to pass the target information so we can check the TARGET_DOMAIN of the token, right? | 18:54 |
elbragstad | either that or we need to rewrite the check here | 18:54 |
elbragstad | https://github.com/openstack/keystone/blob/ba459352d8d2b54807a591312bc0b65aa1498b86/keystone/common/policies/base.py#L23 | 18:54 |
elbragstad | because the check string is written like it's assuming target data to be coming from the token and not the domains API | 18:55 |
elbragstad | if that makes sense? | 18:55 |
elbragstad | but yeah... that policy seems to be inconsistent with the logic in that API... | 18:55 |
elbragstad | cc kmalloc gagehugo ^ | 18:55 |
elbragstad | i guess you could test that by rewriting the policy | 18:56 |
trevormc_ | ok I can do that, i'm not following entirely but I think I have enough to get started. I can follow up with gagehugo if I have questions, we're in the same office :) | 18:58 |
elbragstad | nice :) | 18:58 |
elbragstad | flick a pencil at him for me | 18:58 |
trevormc_ | lol ok. :P | 18:59 |
*** dave-mccowan has quit IRC | 19:03 | |
* gagehugo ducks | 19:03 | |
openstackgerrit | ayoung proposed openstack/keystone master: Comment out un-runnable tests https://review.openstack.org/603459 | 19:06 |
*** felipemonteiro has quit IRC | 19:14 | |
*** dave-mccowan has joined #openstack-keystone | 19:14 | |
knikolla | jdennis: does mod_auth_mellon require both the response and the assertion to be signed? | 19:18 |
jdennis | knikolla: could you define response? | 19:22 |
knikolla | jdennis: <samlp:Response> | 19:23 |
knikolla | which is separate from the <saml:Assertion> signature. | 19:24 |
jdennis | knikolla: response is relative to the party, please be more specific | 19:24 |
knikolla | jdennis: i'm trying to set up keystone as an IdP using ECP. When mellon receives the ECP message it complains that it doesn't have a signature | 19:25 |
knikolla | http://paste.openstack.org/show/jvbKqiFEjdIWY4YstemW/ | 19:25 |
jdennis | knikolla: thanks, that's better, let me check the code ... | 19:27 |
jdennis | knikolla: a quick check of the code implies it does require the assertion to be signed, it would be a huge security risk if assertions were not signed btw. | 19:32 |
knikolla | jdennis: yes, i understand that. the keystone generated assertion does have a signature, i am trying to find out why mellon says it can't find the signature. | 19:34 |
knikolla | assertion for reference http://paste.openstack.org/show/730566/ | 19:34 |
jdennis | knikolla: I'm reviewing the paste ... | 19:38 |
knikolla | thank you | 19:38 |
jdennis | knikolla: I'd have to page in some of my xml signature knowledge but if I'm not mistaken your signature does not point to anything in the message | 19:45 |
jdennis | knikolla: sorry, I misread the xml, forget that :-) | 19:48 |
gagehugo | elbragstad: should get_domain not be checking from the token? | 19:53 |
gagehugo | sorry been pulled in many directions today | 19:53 |
*** felipemonteiro has joined #openstack-keystone | 19:53 | |
jdennis | knikolla: hmm... I don't see an obvious problem. I assume you have the IdP's metadata loaded into mellon, yes/no? | 19:54 |
knikolla | jdennis: yes, the first line here says so http://paste.openstack.org/show/jvbKqiFEjdIWY4YstemW/ | 19:55 |
knikolla | metadata here http://paste.openstack.org/show/730567/ | 19:55 |
knikolla | apache config here http://paste.openstack.org/show/730568/ | 19:56 |
knikolla | was playing around with a few settings (including MellonSignatureMethod) | 19:57 |
elbragstad | gagehugo maybe it should be? | 19:57 |
knikolla | removing or adding it doesn't change the log output | 19:57 |
jdennis | knikolla: if you send me the soap messge (yes I know it's in the paste), and the IdP metadata as attachments in an email to jdennis@redhat.com I'll try to debug it, but probably not until Monday or Tuesday | 19:58 |
jdennis | knikolla: what version of mellon and lasso are you running? | 19:58 |
jdennis | knikolla: MellonSignatureMethod only changes how mellon signs messages, it's independent of validating signatures | 20:00 |
knikolla | mod_auth_mellon-0.13.1-3.el7_5.x86_64, lasso-2.5.1-2.el7.x86_64 | 20:01 |
knikolla | i see | 20:01 |
knikolla | i'll send you an email, thanks a lot. | 20:02 |
jdennis | knikolla: ok great, those are current enough and I'm not aware of any signature bugs in them | 20:02 |
jdennis | knikolla: sometimes lasso reports one error when actually it was a different error that triggered the failure | 20:03 |
knikolla | that doesn't sound fun | 20:04 |
elbragstad | kmalloc you use ipdb, right? do you know if there is a way to make it work with stestr? | 20:05 |
*** felipemonteiro has quit IRC | 20:05 | |
openstackgerrit | Merged openstack/keystone master: Mapped Groups don't exist breaks WebSSO https://review.openstack.org/597992 | 20:32 |
*** trevormc_ has quit IRC | 20:32 | |
elbragstad | knikolla gagehugo vishakha ^ that should probably have a release note | 20:37 |
knikolla | elbragstad: good point | 20:38 |
mbeierl | knikolla: do you know if cmurphy's blog (http://www.gazlene.net/demystifying-keystone-federation.html) will work using keystone as the IdP instead of "http://idp.saml.demo"? | 20:44 |
knikolla | mbeierl: the last section talks about that | 20:46 |
mbeierl | for some reason, I cannot get the metadata from the Keystone idP | 20:48 |
mbeierl | knikolla: I'll keep plugging at it, thanks | 20:49 |
gagehugo | knikolla I can write one real quick unless you are wanting to | 20:52 |
knikolla | gagehugo: go for it | 20:52 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: WIP/DNM Add domain target https://review.openstack.org/604471 | 21:00 |
gagehugo | trevormc_ ^ | 21:01 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Add releasenote for bug fix 1789450 https://review.openstack.org/604475 | 21:09 |
gagehugo | knikolla ^ | 21:09 |
gagehugo | elbragstad ^ | 21:09 |
elbragstad | nice - thanks | 21:09 |
*** raildo has quit IRC | 21:15 | |
*** mchlumsky has quit IRC | 21:30 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Add releasenote for bug fix 1789450 https://review.openstack.org/604475 | 21:34 |
openstackgerrit | Gage Hugo proposed openstack/keystone master: Add releasenote for bug fix 1789450 https://review.openstack.org/604475 | 21:35 |
gagehugo | spelling is hard | 21:35 |
*** felipemonteiro has joined #openstack-keystone | 21:35 | |
elbragstad | thanks gagehugo | 21:45 |
*** felipemonteiro has quit IRC | 21:45 | |
*** felipemonteiro has joined #openstack-keystone | 21:50 | |
*** felipemonteiro has quit IRC | 22:00 | |
*** dave-mccowan has quit IRC | 22:04 | |
*** felipemo_ has joined #openstack-keystone | 22:05 | |
kmalloc | elbragstad: I use pycharm | 22:12 |
kmalloc | elbragstad: and I don't use stestr, I run tests individually if I need to debug | 22:12 |
elbragstad | ack | 22:12 |
elbragstad | i figured out a workaround ;) | 22:12 |
kmalloc | Give me a sec on the other thing (on a phone) | 22:13 |
kmalloc | The policy string bit | 22:13 |
elbragstad | no worries - i'm about burnt out for the day ( i was trying to figure out tempest testing client stuff so that i can implement system scope) | 22:14 |
*** felipemo_ has quit IRC | 22:16 | |
*** mbeierl has quit IRC | 22:50 | |
kmalloc | Ouch | 23:09 |
kmalloc | That is some brain fry. For sure. | 23:09 |
*** jrist has quit IRC | 23:12 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!