*** felipemonteiro has quit IRC | 00:25 | |
vishakha | cmurphy: :) | 00:36 |
---|---|---|
openstackgerrit | Gage Hugo proposed openstack/keystone master: Organize project tag api-ref by route https://review.openstack.org/606874 | 01:41 |
*** markvoelker has joined #openstack-keystone | 02:40 | |
*** markvoelker has quit IRC | 02:45 | |
*** markvoelker has joined #openstack-keystone | 02:50 | |
*** Dinesh_Bhor has joined #openstack-keystone | 03:31 | |
*** pooja_jadhav has joined #openstack-keystone | 03:55 | |
*** Dinesh_Bhor has quit IRC | 03:56 | |
*** pcaruana has joined #openstack-keystone | 04:06 | |
*** shyamb has joined #openstack-keystone | 04:15 | |
*** pcaruana has quit IRC | 04:23 | |
*** shyamb has quit IRC | 04:45 | |
*** shyamb has joined #openstack-keystone | 05:07 | |
*** huaxia has joined #openstack-keystone | 05:11 | |
*** Dinesh_Bhor has joined #openstack-keystone | 05:29 | |
*** jaosorior has joined #openstack-keystone | 05:37 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Purge soft-deleted trusts https://review.openstack.org/604970 | 05:39 |
*** shyamb has quit IRC | 05:42 | |
*** shyamb has joined #openstack-keystone | 05:45 | |
*** pcaruana has joined #openstack-keystone | 05:51 | |
*** shyamb has quit IRC | 06:07 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Adresses LDAP case-sensitive issue https://review.openstack.org/603345 | 06:09 |
*** shyamb has joined #openstack-keystone | 06:09 | |
*** huaxia has quit IRC | 06:31 | |
*** markvoelker has quit IRC | 06:33 | |
*** markvoelker has joined #openstack-keystone | 06:34 | |
*** markvoelker has quit IRC | 06:38 | |
*** shyamb has quit IRC | 06:51 | |
*** shyamb has joined #openstack-keystone | 06:55 | |
*** sapd1 has quit IRC | 07:26 | |
*** Emine has joined #openstack-keystone | 07:29 | |
*** Dinesh_Bhor has quit IRC | 07:33 | |
*** markvoelker has joined #openstack-keystone | 07:34 | |
*** Dinesh_Bhor has joined #openstack-keystone | 07:35 | |
*** shyamb has quit IRC | 07:38 | |
*** Dinesh_Bhor has quit IRC | 07:44 | |
*** zigo has joined #openstack-keystone | 07:46 | |
*** d0ugal has joined #openstack-keystone | 07:52 | |
*** sapd1 has joined #openstack-keystone | 08:17 | |
*** pooja-jadhav has joined #openstack-keystone | 08:38 | |
*** pooja_jadhav has quit IRC | 08:40 | |
*** shyamb has joined #openstack-keystone | 08:41 | |
*** pooja_jadhav has joined #openstack-keystone | 08:44 | |
*** pooja-jadhav has quit IRC | 08:44 | |
*** pooja-jadhav has joined #openstack-keystone | 08:44 | |
*** shyamb has quit IRC | 08:45 | |
*** shyamb has joined #openstack-keystone | 08:45 | |
*** pooja_jadhav has quit IRC | 08:46 | |
*** pooja_jadhav has joined #openstack-keystone | 08:49 | |
*** pooja-jadhav has quit IRC | 08:52 | |
*** Dinesh_Bhor has joined #openstack-keystone | 08:57 | |
*** Dinesh_Bhor has quit IRC | 09:05 | |
*** sapd1_ has joined #openstack-keystone | 09:06 | |
*** sapd1 has quit IRC | 09:06 | |
*** Dinesh_Bhor has joined #openstack-keystone | 09:06 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remaining cases of MappingEngineTester https://review.openstack.org/606912 | 09:10 |
*** Dinesh_Bhor has quit IRC | 09:22 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Purge soft-deleted trusts https://review.openstack.org/604970 | 09:26 |
*** shyamb has quit IRC | 09:30 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Purge soft-deleted trusts https://review.openstack.org/604970 | 09:33 |
*** shyamb has joined #openstack-keystone | 09:37 | |
*** Dinesh_Bhor has joined #openstack-keystone | 09:53 | |
*** felipemonteiro has joined #openstack-keystone | 09:53 | |
*** shyamb has quit IRC | 10:22 | |
*** shyamb has joined #openstack-keystone | 10:35 | |
*** shyamb has quit IRC | 10:42 | |
*** Dinesh_Bhor has quit IRC | 10:49 | |
*** dave-mccowan has joined #openstack-keystone | 10:57 | |
*** shyamb has joined #openstack-keystone | 10:59 | |
*** jaosorior has quit IRC | 11:27 | |
*** felipemonteiro has quit IRC | 11:34 | |
*** phillu has joined #openstack-keystone | 11:54 | |
*** markvoelker has quit IRC | 11:56 | |
*** raildo has joined #openstack-keystone | 12:02 | |
*** jaosorior has joined #openstack-keystone | 12:10 | |
*** dave-mccowan has quit IRC | 12:22 | |
*** Emine has quit IRC | 12:38 | |
*** krypto has joined #openstack-keystone | 12:38 | |
*** lbragstad has joined #openstack-keystone | 12:39 | |
*** ChanServ sets mode: +o lbragstad | 12:39 | |
krypto | hi all i have newton release of openstack with domain based AD configured.For enabling 2 FA does it require re configuring keystone or can the change be integrated with out re configuration | 12:40 |
*** lbragstad has quit IRC | 12:40 | |
*** mchlumsky has joined #openstack-keystone | 12:45 | |
kmalloc | krypto: the 2fa built into Keystone or a 2fa built into AD. | 12:47 |
kmalloc | The keystone version is very rough around the edges still. We expect to enhance it and make it more usable this cycle | 12:48 |
kmalloc | (so stien and after) | 12:48 |
cmurphy | krypto: if you're wanting to use TOTP as the 2nd auth factor you need to add totp to [auth]/methods in keystone.conf, i think all other changes can be done via the API but there is pretty much 0 documentation on it | 12:49 |
kmalloc | cmurphy: ++ | 12:49 |
kmalloc | krypto: and I don't think keystoneauth (and therefore horizon or any tool) can use 2fa easily | 12:50 |
kmalloc | So, it would require direct auth via rest calls not leaning on the current tool chains. | 12:51 |
*** shyamb has quit IRC | 12:51 | |
krypto | Thanks Kmalloc for the reply. For now there is no 2FA integrated with AD/keystone .On already running system will it be possible to make the changes without reconfiguring keystone ..lets say if AD will be integrated with 2FA and not keystoen | 12:51 |
kmalloc | If AD is handling the 2fa, and it works like many tools, pin+token in lieu of password, no change to keystone is needed. | 12:52 |
*** Emine has joined #openstack-keystone | 12:52 | |
kmalloc | AD or a tool directly integrated with AD* | 12:53 |
kmalloc | If it works like Google's 2fa (or security FIDO[2]) with a separate page/prompt for the token, keystone does not have the workflow for that unless it is done in a WebSSO (using something like ADFS for SAML) model | 12:54 |
*** jroll has quit IRC | 12:54 | |
kmalloc | s/security/security key/ | 12:55 |
*** jroll has joined #openstack-keystone | 12:55 | |
*** Emine has quit IRC | 12:59 | |
*** krypto has quit IRC | 13:00 | |
*** shyamb has joined #openstack-keystone | 13:10 | |
openstackgerrit | ayoung proposed openstack/keystone master: LDAP attribute names non-case-sensitive https://review.openstack.org/603345 | 13:11 |
*** shyamb has quit IRC | 13:17 | |
*** Emine has joined #openstack-keystone | 13:17 | |
*** dave-mccowan has joined #openstack-keystone | 13:21 | |
kmalloc | o.O. | 13:27 |
kmalloc | We treat attr names as.case sensitive... Ugh | 13:27 |
*** krypto has joined #openstack-keystone | 13:29 | |
krypto | Thanks kmalloc :) | 13:29 |
*** ayoung has joined #openstack-keystone | 13:34 | |
*** mchlumsky has quit IRC | 13:37 | |
openstackgerrit | ayoung proposed openstack/keystone master: Allow an explicit_domain_id parameter when creating a domain https://review.openstack.org/605235 | 13:38 |
openstackgerrit | ayoung proposed openstack/keystone master: Replace UUID with id_generator for Federated users https://review.openstack.org/605169 | 13:38 |
*** mchlumsky has joined #openstack-keystone | 13:39 | |
*** dklyle has joined #openstack-keystone | 13:47 | |
*** jaosorior has quit IRC | 13:48 | |
*** markvoelker has joined #openstack-keystone | 14:09 | |
*** markvoelker has quit IRC | 14:15 | |
*** markvoelker has joined #openstack-keystone | 14:17 | |
*** beekneemech is now known as bnemec | 14:21 | |
*** itlinux has quit IRC | 14:25 | |
*** markvoelker has quit IRC | 14:26 | |
*** cfriesen has joined #openstack-keystone | 14:57 | |
*** kukacz_ is now known as kukacz | 14:59 | |
*** krypto has quit IRC | 15:16 | |
*** krypto has joined #openstack-keystone | 15:18 | |
*** itlinux has joined #openstack-keystone | 15:21 | |
*** krypto has quit IRC | 15:22 | |
*** pcaruana has quit IRC | 15:30 | |
openstackgerrit | ayoung proposed openstack/keystone master: LDAP attribute names non-case-sensitive https://review.openstack.org/603345 | 15:31 |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: LDAP attribute names non-case-sensitive https://review.openstack.org/603345 | 15:35 |
cmurphy | ayoung: ^ | 15:35 |
ayoung | gah | 15:38 |
ayoung | cmurphy, you fixed the nit, too, didn't you? | 15:38 |
ayoung | Heh | 15:39 |
ayoung | Slugworth! | 15:39 |
ayoung | cmurphy, I'll rebase on yours | 15:39 |
cmurphy | ayoung: i thought you fixed the nit, i didn't overwrite that | 15:39 |
ayoung | AH | 15:40 |
ayoung | cmurphy, I see...I thought we were in a race condition here, but you got my change. THanks | 15:40 |
cmurphy | yep | 15:40 |
ayoung | TYVM | 15:40 |
cmurphy | yavw | 15:41 |
ayoung | kmalloc, https://review.openstack.org/#/c/606195/1 makes all of knikolla 's Federated tests pass. Once that merges, lets make those tests voting | 15:46 |
kmalloc | ayoung: only if we aren't leaning on testshib | 15:51 |
kmalloc | ayoung: we can't make test-shib based testing voting | 15:51 |
ayoung | kmalloc, ah, ok, so we need to spin up our own SSO before we can make it voting? | 15:52 |
kmalloc | ayoung: yep | 15:52 |
kmalloc | ayoung: otherwise 100% needs to be voting | 15:52 |
kmalloc | no question | 15:52 |
ayoung | hrybacki, I think ^^ is a task for you | 15:52 |
knikolla | o/ | 15:53 |
ayoung | knikolla, you working on that? | 15:54 |
kmalloc | I also need to spin up a functional docker document | 15:54 |
kmalloc | And make my docker-unit test more dynamic | 15:55 |
knikolla | i have a patch for k2k testing which i need to polish one of these weeks | 15:55 |
knikolla | but i'm not working on setting up a different idp atm | 15:55 |
kmalloc | I'll get the docker-test/docker-functional rolled into our official docs | 15:55 |
kmalloc | If we have a docker-functional folks can run locally, I can expand for federation functional as well (once we have a standip an idp) bit. | 15:56 |
kmalloc | But first. | 15:56 |
kmalloc | Coffee | 15:56 |
kmalloc | cmurphy: tag me in if you need coverage on stuff while lbragstad is busy. I'm keeping an extra eye on pings (will do the same if I'm swamped) | 15:57 |
*** dave-mccowan has quit IRC | 15:58 | |
cmurphy | kmalloc: cool, btw i'll plan on chairing the meeting tomorrow | 16:00 |
kmalloc | cmurphy: perfectr | 16:00 |
ayoung | kmalloc, knikolla what are we going to run in Docker? | 16:01 |
kmalloc | cmurphy: we can swap week to week as needed depending on how long till lbragstad sneaks back online :) | 16:01 |
cmurphy | kmalloc: sounds good | 16:01 |
kmalloc | ayoung: i run all my unit tests run in docker, i will work to spin up a docker-functional and docker-function-idp mechanism for our tests locally | 16:01 |
ayoung | ah, cool | 16:02 |
kmalloc | i have a lot to do this week in catchup from last | 16:02 |
ayoung | kmalloc, I was thinking that, for our purposes, an IdM instance and Ipsilon would still be the way to go | 16:02 |
kmalloc | 6 doctor appointments in 7 days was a lot. | 16:02 |
cmurphy | zuul can easily do multinode tests if we want to go that route for separate idp | 16:02 |
ayoung | WebSSO is too much of a different app | 16:02 |
kmalloc | cmurphy: right. i was thinking strictly for local stuff, replicate the use of loci | 16:03 |
*** aojea has joined #openstack-keystone | 16:03 | |
kmalloc | cmurphy: and have a command that spins up an idp, configures, and runs functional | 16:03 |
kmalloc | cmurphy: for gate ++ multi node is probably the easiest | 16:03 |
kmalloc | my new tkl mechanical keyboard will be here in 2 days | 16:04 |
kmalloc | will make it easier to work between this computer and the workstation (ugh, i wish synergy would run under wayland... but nope, not until next year) | 16:05 |
gagehugo | o/ | 16:11 |
spotz | Hey all quick Pike logs question - Student is seeing UserWarning: Invalid uuid: RegionOne. in his logs when doing an Ubuntu installation based on the docs. Concern not a concern and if it is would you like a bug? | 16:14 |
*** aojea has quit IRC | 16:15 | |
cmurphy | spotz: if it's just in the logs and not causing user-facing errors that is probably fine, python-openstackclient does things like that because it doesn't know if you've given it a resource ID or name and so it first tries to treat it as an ID and then tries it as a name | 16:25 |
cmurphy | so you'll probably see a failed GET /v3/regions/RegionOne and then a successful GET /v3/regions?name=RegionOne | 16:26 |
spotz | cmurphy: He did reinstall once because he'd made a mistake but says except for that message all is working this time around. | 16:26 |
spotz | But that makes sense, I'll let them know thanks! | 16:26 |
cmurphy | yw | 16:27 |
*** gyee has joined #openstack-keystone | 16:30 | |
kmalloc | spotz: it's a bug in how we handle things in CADF. we need to add special exemption(s) | 16:42 |
kmalloc | we have it in a few places. | 16:42 |
kmalloc | it should have zero impact | 16:42 |
spotz | kmalloc: Thanks, I'm assuming already bugged or would you like me to file one? | 16:42 |
kmalloc | it's not something we have bugged really. it is tough because keystone does things oddly | 16:43 |
kmalloc | it might be a bug already. but i don't think it is | 16:43 |
kmalloc | it is sortof a "known" issue =/ | 16:43 |
spotz | Just let me know:) We do a bit of just fixing and having official bugs for OSA | 16:43 |
kmalloc | yeah. | 16:43 |
kmalloc | feel free to file a bug | 16:44 |
spotz | Ok will do | 16:44 |
kmalloc | but i don't know if/when we can fix it, we made some choices in notifications/details that were in opposition with keystone's api/data/contract | 16:44 |
kmalloc | and it's ... a pain to unwind :P | 16:44 |
kmalloc | cmurphy, ayoung: i think simo covered a lot of what we already covered at the PTG | 16:45 |
kmalloc | cmurphy, ayoung: the biggest take away was the pool of crypto mechs. otherwise i *think* we are all on the same page (for the most part) there on JWT/JOSE/ | 16:45 |
spotz | kmalloc: Yeah it's still works fine so it's more of a visual thing and wishlisty | 16:46 |
ayoung | kmalloc, ++ | 16:46 |
kmalloc | ayoung: this one is painful. so much unwinding to do: https://review.openstack.org/#/c/603461/2 | 16:50 |
kmalloc | ayoung: i think i'm ~20 hrs into converting auth to flask. | 16:51 |
kmalloc | it's a *nightmare* | 16:51 |
kmalloc | i'm tempted to cheat. | 16:51 |
kmalloc | it's the wrong choice and doesn't fix things.. but ugh. | 16:52 |
*** zzzeek_ has joined #openstack-keystone | 16:53 | |
*** dave-mccowan has joined #openstack-keystone | 16:54 | |
*** d0ugal has quit IRC | 16:54 | |
*** aojea has joined #openstack-keystone | 16:55 | |
*** pcaruana has joined #openstack-keystone | 16:56 | |
ayoung | cheat? | 17:30 |
kmalloc | yeah. just hard convert to webob and back to flask | 17:42 |
kmalloc | like i did for transition of federation | 17:43 |
kmalloc | but it wont make anything any easier | 17:43 |
kmalloc | soooooo. | 17:43 |
*** imacdonn has quit IRC | 17:51 | |
*** imacdonn has joined #openstack-keystone | 17:52 | |
*** blake has joined #openstack-keystone | 17:57 | |
*** jmlowe has joined #openstack-keystone | 18:06 | |
*** imacdonn has quit IRC | 18:08 | |
*** markvoelker has joined #openstack-keystone | 18:15 | |
*** imacdonn has joined #openstack-keystone | 18:21 | |
*** markvoelker has quit IRC | 18:24 | |
*** jmlowe has quit IRC | 18:27 | |
*** aojea has quit IRC | 18:32 | |
*** markvoelker has joined #openstack-keystone | 18:32 | |
*** aojea has joined #openstack-keystone | 18:32 | |
*** markvoelker has quit IRC | 18:37 | |
*** jmlowe has joined #openstack-keystone | 18:44 | |
*** blake has quit IRC | 19:04 | |
*** pcaruana has quit IRC | 20:43 | |
*** raildo has quit IRC | 21:00 | |
*** phillu has quit IRC | 21:24 | |
*** itlinux has quit IRC | 21:39 | |
*** aojea has quit IRC | 21:41 | |
openstackgerrit | Merged openstack/keystone master: LDAP attribute names non-case-sensitive https://review.openstack.org/603345 | 21:44 |
*** ianw is now known as ianw_pto | 22:17 | |
*** threestrands has joined #openstack-keystone | 22:41 | |
*** rcernin has joined #openstack-keystone | 22:49 | |
*** gyee has quit IRC | 23:47 | |
kmalloc | ayoung: oooh man. well here we go, down to 8 failing tests... erm 7... | 23:51 |
kmalloc | ayoung: gah. so icky. | 23:51 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: WIP: Convert auth to flask native dispatching https://review.openstack.org/603461 | 23:52 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!