*** openstackgerrit has joined #openstack-keystone | 00:00 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Purge soft-deleted trusts https://review.openstack.org/604970 | 00:00 |
---|---|---|
*** felipemonteiro has joined #openstack-keystone | 00:22 | |
openstackgerrit | Gage Hugo proposed openstack/keystone master: DNM - Expose get domain enforcement issue https://review.openstack.org/605560 | 00:41 |
gagehugo | lbragstad ^ | 00:42 |
gagehugo | From last friday: http://eavesdrop.openstack.org/irclogs/%23openstack-keystone/%23openstack-keystone.2018-09-21.log.html#t2018-09-21T18:37:20 | 00:42 |
gagehugo | I recreated the issue trevormc had I believe | 00:42 |
*** felipemonteiro has quit IRC | 00:51 | |
*** Emine has quit IRC | 00:55 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Fixing wrong url of keystone-specs https://review.openstack.org/605561 | 01:05 |
*** Dinesh_Bhor has joined #openstack-keystone | 01:11 | |
ayoung | jamielennox, ! As I live and breathe! | 01:17 |
*** aning has quit IRC | 01:18 | |
ayoung | kmalloc, that is why I wrote https://review.openstack.org/#/c/165908/ originally | 01:18 |
*** aojea has joined #openstack-keystone | 01:23 | |
*** aojea has quit IRC | 01:27 | |
*** Dinesh_Bhor has quit IRC | 01:31 | |
*** Dinesh_Bhor has joined #openstack-keystone | 01:37 | |
openstackgerrit | Merged openstack/keystone master: Fix command to verify role removal in docs https://review.openstack.org/605509 | 02:00 |
*** Dinesh_Bhor has quit IRC | 02:22 | |
*** Dinesh_Bhor has joined #openstack-keystone | 02:26 | |
openstackgerrit | ayoung proposed openstack/keystone-specs master: Federated Query APIs https://review.openstack.org/313604 | 02:36 |
*** imacdonn has quit IRC | 02:50 | |
*** markvoelker has joined #openstack-keystone | 02:50 | |
*** imacdonn has joined #openstack-keystone | 02:51 | |
*** felipemonteiro has joined #openstack-keystone | 03:15 | |
*** rcernin_ has quit IRC | 03:42 | |
*** rcernin has joined #openstack-keystone | 03:43 | |
*** dave-mccowan has quit IRC | 03:46 | |
*** ayoung has quit IRC | 03:50 | |
*** sapd1 has quit IRC | 03:55 | |
*** sapd1 has joined #openstack-keystone | 04:00 | |
*** blake has quit IRC | 04:04 | |
*** blake has joined #openstack-keystone | 04:06 | |
*** blake has quit IRC | 04:11 | |
*** felipemonteiro has quit IRC | 04:16 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Removes unnecessary utf-8 encoding https://review.openstack.org/605582 | 04:24 |
*** blake has joined #openstack-keystone | 04:36 | |
*** shyamb has joined #openstack-keystone | 04:48 | |
openstackgerrit | Merged openstack/keystone master: Comment out un-runnable tests https://review.openstack.org/603459 | 04:52 |
openstackgerrit | Vishakha Agarwal proposed openstack/python-keystoneclient master: create() call in v3.regions.py is wrong https://review.openstack.org/594921 | 04:59 |
*** blake has quit IRC | 05:06 | |
*** bnemec has quit IRC | 05:39 | |
*** shyamb has quit IRC | 06:11 | |
*** shyamb has joined #openstack-keystone | 06:19 | |
*** Dinesh_Bhor has quit IRC | 06:24 | |
*** shyamb has quit IRC | 06:25 | |
*** pcaruana has joined #openstack-keystone | 06:33 | |
*** shyamb has joined #openstack-keystone | 06:36 | |
*** Dinesh_Bhor has joined #openstack-keystone | 06:43 | |
*** shyamb has quit IRC | 07:11 | |
*** rcernin has quit IRC | 07:12 | |
*** shyamb has joined #openstack-keystone | 07:52 | |
openstackgerrit | wangxiyuan proposed openstack/keystone-specs master: Add domain level limit support https://review.openstack.org/599491 | 08:12 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Adding test case for MappingEngineTester https://review.openstack.org/603539 | 08:15 |
*** Dinesh_Bhor has quit IRC | 08:16 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Adding test case for MappingEngineTester https://review.openstack.org/603539 | 08:21 |
*** nick_kar_ has quit IRC | 08:52 | |
*** nick_kar has joined #openstack-keystone | 08:53 | |
*** Dinesh_Bhor has joined #openstack-keystone | 08:55 | |
*** a-pugachev has joined #openstack-keystone | 09:01 | |
*** shyamb has quit IRC | 09:16 | |
*** shyamb has joined #openstack-keystone | 09:24 | |
*** Emine has joined #openstack-keystone | 09:24 | |
*** Dinesh_Bhor has quit IRC | 09:29 | |
*** shyamb has quit IRC | 09:57 | |
*** shyamb has joined #openstack-keystone | 09:57 | |
*** Dinesh_Bhor has joined #openstack-keystone | 10:04 | |
openstackgerrit | Merged openstack/keystone master: Convert legacy functional jobs to Zuul-v3-native https://review.openstack.org/602452 | 10:15 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Adding test case for MappingEngineTester https://review.openstack.org/603539 | 10:21 |
*** Dinesh_Bhor has quit IRC | 10:29 | |
*** shyamb has quit IRC | 10:56 | |
*** shyamb has joined #openstack-keystone | 10:58 | |
cmurphy | knikolla: jdennis I reported the k2k/mellon problem here https://bugs.launchpad.net/keystone/+bug/1794726 | 11:00 |
openstack | Launchpad bug 1794726 in OpenStack Identity (keystone) "Keystone as a SAML IdP does not work when mod_auth_mellon is used as the SP" [Undecided,New] | 11:00 |
cmurphy | hrybacki: i put a bunch of things in https://trello.com/c/sNGFeeAP/81-federation-improvements | 11:01 |
*** felipemonteiro has joined #openstack-keystone | 11:30 | |
knikolla | cmurphy: awesome. Shouldn’t be a hard fix :) | 11:39 |
hrybacki | Thanks cmurphy :) | 11:50 |
*** pcaruana has quit IRC | 11:50 | |
*** felipemonteiro has quit IRC | 12:04 | |
*** shyamb has quit IRC | 12:13 | |
*** shyamb has joined #openstack-keystone | 12:14 | |
*** pcaruana has joined #openstack-keystone | 12:39 | |
*** shyam89 has joined #openstack-keystone | 12:50 | |
*** shyamb has quit IRC | 12:52 | |
*** shyam89 has quit IRC | 12:55 | |
*** raildo has joined #openstack-keystone | 13:01 | |
lbragstad | gagehugo nice - thanks | 13:09 |
*** bnemec has joined #openstack-keystone | 13:18 | |
gagehugo | o/ | 13:41 |
*** mbeierl has joined #openstack-keystone | 13:47 | |
*** itlinux has quit IRC | 13:59 | |
*** jistr is now known as jistr|call | 14:31 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Fix broken link to Stein roadmap https://review.openstack.org/605761 | 14:44 |
*** evrardjp has quit IRC | 14:45 | |
*** evrardjp has joined #openstack-keystone | 14:47 | |
*** itlinux has joined #openstack-keystone | 14:58 | |
*** evrardjp has quit IRC | 14:58 | |
lbragstad | nice test gagehugo https://review.openstack.org/#/c/605560/1 | 15:02 |
lbragstad | i think that was actually relevant to what we were talking about last night | 15:02 |
lbragstad | lol thanks for the sanity check jamielennox ;) | 15:03 |
gagehugo | lbragstad ah | 15:06 |
gagehugo | I'm wondering if domains isn't building the enforcement target correctly | 15:07 |
lbragstad | you mean the policy check? | 15:09 |
lbragstad | or the policy check string? | 15:09 |
gagehugo | policy check | 15:10 |
lbragstad | yeah... | 15:11 |
gagehugo | because you should be able to access the domain if you are admin or your project domain id = domain id | 15:11 |
lbragstad | i'm going to rework https://review.openstack.org/#/c/605539/ today | 15:11 |
lbragstad | which should hopefully make it easier to figure out why the bug you're proposing a test for exists | 15:12 |
gagehugo | ok cool | 15:14 |
gagehugo | and I was able to access it once I gave the user "admin" | 15:14 |
gagehugo | so it's likely the target.domain.id issue | 15:15 |
lbragstad | oh - yeah.. | 15:16 |
lbragstad | that could be, too | 15:16 |
lbragstad | which would be a problem with how we're building target data? | 15:16 |
gagehugo | potentially yeah | 15:20 |
gagehugo | or the domainresource isn't building a target correctly | 15:20 |
lbragstad | right | 15:22 |
lbragstad | specifically the domain resource | 15:22 |
gagehugo | yup | 15:23 |
*** dave-mccowan has joined #openstack-keystone | 15:42 | |
*** jistr|call is now known as jistr | 15:46 | |
*** gyee has joined #openstack-keystone | 15:53 | |
*** gyee has quit IRC | 15:54 | |
*** gyee has joined #openstack-keystone | 15:57 | |
*** dave-mccowan has quit IRC | 16:08 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Pass context objects to policy enforcement https://review.openstack.org/605539 | 16:11 |
lbragstad | gagehugo fixed ^ | 16:11 |
lbragstad | well - using the context objects directly that is | 16:11 |
lbragstad | we no longer deal with building creds dictionaries prior to calling oslo.policy | 16:11 |
gagehugo | cool | 16:12 |
lbragstad | kmalloc might be interested in that, too | 16:14 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Pass context objects to policy enforcement https://review.openstack.org/605539 | 16:18 |
*** raildo_ has joined #openstack-keystone | 16:19 | |
*** raildo has quit IRC | 16:22 | |
*** a-pugachev has quit IRC | 16:34 | |
kmalloc | o/ | 16:46 |
kmalloc | here now | 16:46 |
kmalloc | another dr. appt this morning | 16:47 |
kmalloc | tomorrow i'm prob. out most of the day | 16:47 |
lbragstad | ack | 16:48 |
lbragstad | thanks kmalloc | 16:48 |
*** Emine has quit IRC | 17:21 | |
*** aning has joined #openstack-keystone | 17:32 | |
aning | cmurphy: an update on the Horizon issue with WEBSSO I had a few days ago ... the issue is that when I login in the Idp, I got a error page. | 17:34 |
*** Emine has joined #openstack-keystone | 17:34 | |
aning | cmurphy: it turns out there is a mismatch between the SP's metadata and the URL the SP asks the Idp to send the SAML Response to | 17:36 |
aning | cmurphy: This is the AssertionConsumerService in the metadata, it uses Domain Name as the Location. | 17:37 |
aning | cmurphy: but the URL Horizon generated and send to Idp for the returned SAML Response is in IP address, so they don't match. | 17:37 |
cmurphy | aning: that's configured by the OPENSTACK_KEYSTONE_URL setting in horizon's local_settings.py, you can change horizon to use the domain name instead of the IP address | 17:38 |
aning | cmurphy: as a quick test I manually changed the metadata to be my SP's IP address, uploaded again, and Horizon works flowless. | 17:38 |
aning | cmurphy: great. | 17:39 |
cmurphy | aning: btw I reported the other horizon problem you were seeing here https://bugs.launchpad.net/horizon/+bug/1794710 in case you want to track it or mark "also affects me" | 17:40 |
openstack | Launchpad bug 1794710 in OpenStack Dashboard (Horizon) "WebSSO initial redirect 404s" [Undecided,New] | 17:40 |
aning | cmurphy: Thx | 17:40 |
aning | cmurphy: but that's only seen in master, not in Rocky. | 17:41 |
cmurphy | aning: right | 17:41 |
*** mvkr has quit IRC | 17:42 | |
aning | cmurphy: another piece of information in case it's helpful for others, is that ECP can be enabled like this: | 17:43 |
aning | cmurphy: <SSO entityID="https://idp.testshib.org/idp/shibboleth" ECP="true"> | 17:43 |
aning | cmurphy: with this both WEBSSO and ECP work, at least in Rocky. | 17:43 |
cmurphy | aning: ++ | 17:43 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system reader role in domains API https://review.openstack.org/605485 | 17:47 |
*** dims_ is now known as dims | 18:05 | |
*** jistr has quit IRC | 18:47 | |
*** jistr has joined #openstack-keystone | 18:49 | |
*** jistr has quit IRC | 19:08 | |
*** jistr has joined #openstack-keystone | 19:08 | |
*** itlinux has quit IRC | 19:09 | |
lbragstad | gagehugo is there a bug open for https://review.openstack.org/#/c/605560/1/keystone/tests/unit/test_v3_resource.py yet? | 19:15 |
*** jistr has quit IRC | 19:23 | |
lbragstad | gagehugo i can't seem to find one - https://bugs.launchpad.net/keystone/+bug/1794864 | 19:24 |
openstack | Launchpad bug 1794864 in OpenStack Identity (keystone) "Calling GET /v3/domains/{domain_id} with a project-scoped or domain-scoped token fails" [Medium,Triaged] | 19:24 |
lbragstad | so i opened that ^ | 19:24 |
*** jistr has joined #openstack-keystone | 19:26 | |
*** jistr has quit IRC | 19:28 | |
*** jistr has joined #openstack-keystone | 19:29 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Pass context objects to policy enforcement https://review.openstack.org/605539 | 19:33 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system reader role in domains API https://review.openstack.org/605485 | 19:33 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system member role in domains API https://review.openstack.org/605849 | 19:33 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement system admin role in domains API https://review.openstack.org/605850 | 19:33 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Allow domain users to access the GET domain API https://review.openstack.org/605851 | 19:33 |
* lbragstad steps away for a late lunch | 19:34 | |
*** jistr has quit IRC | 19:34 | |
*** jistr has joined #openstack-keystone | 19:37 | |
*** jistr has quit IRC | 19:39 | |
*** jistr has joined #openstack-keystone | 19:49 | |
*** pcaruana has quit IRC | 19:54 | |
*** aojea has joined #openstack-keystone | 19:57 | |
openstackgerrit | Merged openstack/keystone-specs master: Fix broken link to Stein roadmap https://review.openstack.org/605761 | 20:03 |
*** Nel1x has joined #openstack-keystone | 20:04 | |
gagehugo | lbragstad no I hadn't opened one yet, thanks | 20:12 |
lbragstad | np | 20:15 |
*** Emine has quit IRC | 20:27 | |
*** Emine has joined #openstack-keystone | 20:28 | |
*** aojea has quit IRC | 20:32 | |
*** aojea has joined #openstack-keystone | 20:33 | |
*** cfriesen has joined #openstack-keystone | 20:42 | |
cfriesen | odd question...if I run "openstack user list" should I see the service users? | 20:42 |
lbragstad | yeah - the only thing that distinguishes a user from a "service" user is the name | 20:50 |
lbragstad | keystone doesn't treat them any different | 20:51 |
*** rmascena__ has joined #openstack-keystone | 20:57 | |
*** raildo_ has quit IRC | 21:00 | |
kmalloc | lbragstad: this needs stable eyes: https://review.openstack.org/#/c/601882/ | 21:15 |
lbragstad | kmalloc ack | 21:22 |
*** mchlumsky has quit IRC | 21:37 | |
*** felipemonteiro has joined #openstack-keystone | 21:43 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Allow project users to retrieve domains https://review.openstack.org/605871 | 22:06 |
lbragstad | gagehugo fix for the domain issue ^ | 22:06 |
lbragstad | with project users | 22:06 |
gagehugo | nice | 22:07 |
*** mvkr has joined #openstack-keystone | 22:13 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove domain policies from policy.v3cloudsample.json https://review.openstack.org/605876 | 22:28 |
*** rcernin has joined #openstack-keystone | 22:29 | |
*** aojea has quit IRC | 22:38 | |
*** felipemonteiro has quit IRC | 23:55 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!