| *** mvkr has joined #openstack-keystone | 00:12 | |
| openstackgerrit | Ian Wienand proposed openstack/keystoneauth master: Fair semaphore fixes https://review.openstack.org/616717 | 00:16 |
|---|---|---|
| *** gyee has quit IRC | 00:16 | |
| *** pcaruana has quit IRC | 00:25 | |
| openstackgerrit | Monty Taylor proposed openstack/keystoneauth master: Add support for client-side rate limiting https://review.openstack.org/605043 | 00:27 |
| *** Dinesh_Bhor has joined #openstack-keystone | 01:03 | |
| *** Dinesh_Bhor has quit IRC | 01:25 | |
| *** Dinesh_Bhor has joined #openstack-keystone | 01:31 | |
| openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Update more info of vhost file https://review.openstack.org/616457 | 01:49 |
| openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remove deprecated "bind" in token https://review.openstack.org/613891 | 01:53 |
| *** jrist has quit IRC | 02:30 | |
| *** jrist has joined #openstack-keystone | 02:43 | |
| openstackgerrit | 98k proposed openstack/ldappool master: Add python 3.6 unit test job https://review.openstack.org/616739 | 02:54 |
| *** Dinesh_Bhor has quit IRC | 03:17 | |
| *** Dinesh_Bhor has joined #openstack-keystone | 03:20 | |
| *** aojea has joined #openstack-keystone | 03:24 | |
| *** aojea has quit IRC | 03:29 | |
| openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Update api-ref for set registered limits. https://review.openstack.org/616755 | 03:37 |
| openstackgerrit | Merged openstack/keystone master: Replace usage of get_legacy_facade() with get_engine() https://review.openstack.org/615749 | 03:46 |
| openstackgerrit | Merged openstack/keystone master: Change __all__ list to tuple https://review.openstack.org/616364 | 03:47 |
| *** Dinesh_Bhor has quit IRC | 04:08 | |
| *** Dinesh_Bhor has joined #openstack-keystone | 04:40 | |
| *** openstackstatus has quit IRC | 04:59 | |
| *** openstack has joined #openstack-keystone | 07:07 | |
| *** ChanServ sets mode: +o openstack | 07:07 | |
| *** pcaruana has joined #openstack-keystone | 07:21 | |
| *** ebukha has quit IRC | 07:54 | |
| *** trident has quit IRC | 08:12 | |
| *** trident has joined #openstack-keystone | 08:14 | |
| mbuil | vishakha: are you trying to deploy K2K federation? | 08:51 |
| cmurphy | vishakha: yes that's helpful, that says Unauthorized: User 099285cabca64ca68037d15f765536aa has no access to project 8d5c2f4c615941cc8f7a8969b3618445 | 08:57 |
| cmurphy | which wasn't showing up in the logs yesterday | 08:57 |
| cmurphy | vishakha: double check that the group you created for federated users has a role assignment on that project | 08:58 |
| vishakha | cmurphy: Yes I also saw that error. Let me check once again | 08:58 |
| vishakha | mbuil: Yes | 08:59 |
| mbuil | cmurphy: When doing K2K federation, why we don‘t need shibboleth in the IdP side. Does keystone already include code to handle SAML2 in IdP? | 09:00 |
| cmurphy | mbuil: yes it does http://git.openstack.org/cgit/openstack/keystone/tree/keystone/federation/idp.py | 09:01 |
| mbuil | cmurphy: ah ok thanks. Is anyone trying to do the same for SP? Is Shibboleth going to disappear from the picture? | 09:03 |
| cmurphy | mbuil: it's in the backlog http://specs.openstack.org/openstack/keystone-specs/specs/keystone/backlog/native-saml.html | 09:03 |
| mbuil | cmurphy: thanks!! | 09:03 |
| cmurphy | possibly one of my outreachy interns might be able to start work on it in the next few months | 09:04 |
| cmurphy | mbuil: what's your interest in getting rid of the shibboleth sp? | 09:05 |
| mbuil | cmurphy: I was just curious, no reason :) | 09:06 |
| cmurphy | :) | 09:06 |
| vishakha | cmurphy: I got the token after giving admin role to group in thar project | 09:11 |
| vishakha | s/thar/that | 09:11 |
| cmurphy | vishakha: awesome | 09:12 |
| *** Emine has joined #openstack-keystone | 09:18 | |
| cmurphy | vishakha: so check again if it works in horizon, if it doesn't you can turn up the debug logging in logging -> handlers -> console -> level in horizon's local_settings.py which might give more information | 09:20 |
| vishakha | cmurphy: Now I can use this token on SP to create instances right? | 09:20 |
| cmurphy | vishakha: yes | 09:21 |
| vishakha | cmurphy: I moved to SP Horizon through drop down and I tried to list volumes, But n side its showing unable to retrieve volume list | 09:22 |
| cmurphy | vishakha: hmm well if the SP dropdown worked then that sounds like keystone is working at least :) | 09:24 |
| vishakha | cmurphy: yes it is :) | 09:24 |
| vishakha | cmurphy: thank you | 09:24 |
| cmurphy | you're welcome | 09:24 |
| cmurphy | vishakha: are you going to be in Berlin next week? | 09:25 |
| vishakha | cmurphy: No . My session wasn't selected. | 09:25 |
| cmurphy | vishakha: ah too bad :( | 09:26 |
| vishakha | cmurphy: Have a safe travel | 09:27 |
| cmurphy | thanks :) | 09:27 |
| *** Dinesh_Bhor has quit IRC | 09:34 | |
| *** Dinesh_Bhor has joined #openstack-keystone | 09:57 | |
| *** Dinesh_Bhor has quit IRC | 10:01 | |
| openstackgerrit | Merged openstack/keystone master: Remove deprecated "bind" in token https://review.openstack.org/613891 | 11:21 |
| *** raildo has joined #openstack-keystone | 11:22 | |
| *** ebukha has joined #openstack-keystone | 12:23 | |
| openstackgerrit | Juan Antonio Osorio Robles proposed openstack/oslo.policy master: WIP: Create OPA check https://review.openstack.org/614224 | 12:36 |
| openstackgerrit | Juan Antonio Osorio Robles proposed openstack/oslo.policy master: Create OPA check https://review.openstack.org/614224 | 12:38 |
| honza | What is morgan fainberg's irc nick? does he usually hang out here? | 12:59 |
| honza | hm, github says he's in seattle so it might be too early still | 13:02 |
| cmurphy | honza: his nick is kmalloc and yes it's a little early for him right now | 13:03 |
| honza | cmurphy: perfect, thanks | 13:06 |
| *** Dinesh_Bhor has joined #openstack-keystone | 13:18 | |
| *** ebukha has quit IRC | 13:24 | |
| *** Dinesh_Bhor has quit IRC | 13:34 | |
| *** ebukha has joined #openstack-keystone | 13:41 | |
| *** aojea_ has joined #openstack-keystone | 14:01 | |
| *** Emine has quit IRC | 14:11 | |
| lbragstad | o/ | 14:26 |
| cmurphy | \o | 14:28 |
| mbuil | cmurphy: I have the K2K federation working in CLI but I still get problems with horizon. When switching to "mysp" in Horizon, I see these logs in IdP's keystone_access.log: https://hastebin.com/kesecakozu.bash apparently, everything seems correct and Horizon(?) gets the SAML Response, or? | 14:34 |
| cmurphy | mbuil: I don't see anything wrong there, what's the error you're seeing in horizon? | 14:38 |
| openstackgerrit | Merged openstack/keystone master: Add a test for idp and federated user cascade deleting https://review.openstack.org/591946 | 14:41 |
| mbuil | Error: "Switching to Keystone Provider mysp has failed. Service provider authentication failed. An error occurred authenticating. Please try again layer." | 14:41 |
| cmurphy | mbuil: do the keystone logs on the SP have anything? | 14:42 |
| mbuil | cmurphy ^. I can't see anything happening in the logs of the SP... how is the flow? Once Horizon gets the SAML Response, it should contact the SP's keystone? | 14:42 |
| lbragstad | looks like keystone's operator feedback is at the same time as https://www.openstack.org/summit/berlin-2018/summit-schedule/events/22785/change-of-ownership-of-resources | 14:44 |
| cmurphy | mbuil: yeah the horizon server should contact the keystone SP directly | 14:47 |
| mbuil | cmurphy: ok, thanks. I think it is a connectivity issue | 14:47 |
| *** aojea_ has quit IRC | 14:49 | |
| cmurphy | lbragstad: sadness, I was planning on going to that | 14:52 |
| cmurphy | lbragstad: the resource deletion one is on a different day though, I think that's more relevant to us | 14:52 |
| lbragstad | yeah... we might have to divide and conquer | 14:52 |
| lbragstad | i have the other one on my schedule for sure | 14:52 |
| honza | kmalloc: hey, i noticed you worked on the flaskification of the keystone server --- i was hoping you could help me with a bug; i'm getting a 500 error on OPTIONS when requesting a new token | 14:55 |
| honza | kmalloc: here is the bug report, note especially the one comment before last https://bugs.launchpad.net/tripleo/+bug/1801778 | 14:56 |
| openstack | Launchpad bug 1801778 in tripleo "Keystone circular reference on OPTIONS" [High,Triaged] | 14:56 |
| honza | kmalloc: any and all pointers would be much appreciated | 14:56 |
| *** aojea_ has joined #openstack-keystone | 14:58 | |
| *** lbragstad has quit IRC | 15:02 | |
| *** lbragstad has joined #openstack-keystone | 15:03 | |
| *** ChanServ sets mode: +o lbragstad | 15:03 | |
| *** Emine has joined #openstack-keystone | 15:31 | |
| kmalloc | lbragstad: change of ownership is easy imo. Services are allowed to do so if they want. Keystone does not allow rehoming resources. | 15:39 |
| kmalloc | Because moving projects is bad news with inheritance | 15:39 |
| kmalloc | Of roles. | 15:39 |
| lbragstad | yeah - i was more or less just curious to be in the room | 15:40 |
| lbragstad | i like being a fly on the wall | 15:40 |
| kmalloc | honza: there is an error in keystone somewhere. The 500 is because rbac enforcement isn't called when that error happens. Request processing is probably a red herring in this case. | 15:40 |
| kmalloc | A side effect, not the root cause. | 15:41 |
| kmalloc | It also means whatever issue is occuring was never tested in keystone, so it realistically is broken due to lack of direct testing on merges. | 15:42 |
| honza | kmalloc: any tips on finding the root cause? dig through logs some more? with the new flask stuff, do we need to change the way we do cors requests? | 15:42 |
| kmalloc | I'll have to go look when I am more awake | 15:43 |
| honza | kmalloc: thanks | 15:43 |
| kmalloc | I just woke up 1m ago | 15:43 |
| honza | kmalloc: https://media.giphy.com/media/DrJm6F9poo4aA/giphy.gif | 15:44 |
| kmalloc | Yup | 15:50 |
| *** bnemec is now known as beekneemech | 15:53 | |
| mbuil | cmurphy: I fixed the connectivity problem and now I see "You are not authorized to access this page" when switching to mysp | 15:54 |
| cmurphy | mbuil: as in it doesn't let you switch, or as in after you've switched some page elements aren't accessible? | 15:55 |
| mbuil | cmurphy: it does not allow to switch. I mean, I did what is shown at the bottom of http://www.gazlene.net/demystifying-keystone-federation.html#Keystone%20to%20Keystone and now it shows mysp instead of Local Keystone. Hoever, that message appears and then a "Log in" | 15:59 |
| *** jistr is now known as jistr|call | 16:00 | |
| cmurphy | mbuil: like this? http://www.gazlene.net/horizon.png | 16:08 |
| mbuil | cmurphy: exactly that | 16:08 |
| cmurphy | mbuil: do you have a full openstack running on the service provider? nova glance etc? or just keystone? | 16:09 |
| mbuil | cmurphy: everything | 16:09 |
| cmurphy | i think that's normal if you're just running keystone and you don't have an admin role | 16:09 |
| cmurphy | not sure about that then | 16:10 |
| cmurphy | might still be a permission issue | 16:10 |
| mbuil | cmurphy: Ok. I need to fix my networking issues permanently first. I did a hack and it does not work always :P. Then, I'll investigate further | 16:11 |
| *** ayoung has joined #openstack-keystone | 16:12 | |
| *** lbragstad has quit IRC | 16:14 | |
| *** lbragstad has joined #openstack-keystone | 16:15 | |
| *** ChanServ sets mode: +o lbragstad | 16:15 | |
| *** jistr|call is now known as jistr | 16:17 | |
| *** imacdonn has quit IRC | 16:18 | |
| *** aojea_ has quit IRC | 16:20 | |
| *** aojea_ has joined #openstack-keystone | 16:21 | |
| *** etp has quit IRC | 16:21 | |
| *** gyee has joined #openstack-keystone | 16:22 | |
| openstackgerrit | Colleen Murphy proposed openstack/keystone master: [WIP] Add introduction section to federation docs https://review.openstack.org/615384 | 16:23 |
| *** etp has joined #openstack-keystone | 16:27 | |
| *** markvoelker has quit IRC | 17:30 | |
| *** imacdonn has joined #openstack-keystone | 17:32 | |
| ayoung | cmurphy, kmalloc lbragstad knikolla gagehugo can we fast track Catalog for Unscoped tokens through? https://review.openstack.org/#/c/607346/ It was originally approved, but then retracted. This just reinstates it. jamielennox was not around to drive it on home when he wrote it. | 17:36 |
| *** ebukha has quit IRC | 17:44 | |
| kmalloc | honza: i'm looking now, so, this indicates we have somehow failed in our circular reference checking, but more importantly i need to exempt that check from enforcement/change where enforcement occurs for that to ensure that our hard-check ensuring ALL apis are enforced doesn't get trigggered. | 17:55 |
| kmalloc | honza: i bet i can have something proposed to fix that today. | 17:55 |
| honza | kmalloc: wonderful news, thank you for checking so quickly | 18:18 |
| honza | jrist: ^ | 18:18 |
| jrist | oh yeay | 18:20 |
| jrist | good work finding a bug honza | 18:20 |
| jrist | :) | 18:20 |
| jrist | kmalloc++ | 18:21 |
| kmalloc | jrist: it really is something we weren't testing clearly | 18:29 |
| kmalloc | and you are creating a bad set of roles | 18:29 |
| kmalloc | somehow | 18:29 |
| kmalloc | but we also are raising an exception before we run enforcement, so it wasn't marked as an enforced API | 18:29 |
| kmalloc | this is a good thing for us, means there is no way to accidently have an unenforced api call, it must be enforced or it raises a 500 (as it should) | 18:30 |
| kmalloc | drastic improvement to previous keystones | 18:30 |
| kmalloc | honza: so... out of curoisity did OPTIONS actually ever work before flask? | 18:39 |
| kmalloc | honza: for keystone? | 18:39 |
| kmalloc | i'm inclined to say it never really did. | 18:39 |
| kmalloc | it just didn't error. | 18:39 |
| *** bigdogstl has joined #openstack-keystone | 18:50 | |
| honza | kmalloc: it worked great before | 18:59 |
| honza | kmalloc: i mean, i was able to authenticate against keystone using cors in the browser | 19:01 |
| honza | kmalloc: no errors | 19:01 |
| *** bigdogstl has quit IRC | 19:08 | |
| *** bigdogstl has joined #openstack-keystone | 19:12 | |
| *** zigo has quit IRC | 19:25 | |
| *** bigdogstl has quit IRC | 19:26 | |
| *** bigdogstl has joined #openstack-keystone | 19:30 | |
| kmalloc | yeah | 19:33 |
| kmalloc | figured no errors but not giving useful information | 19:33 |
| *** bigdogstl has quit IRC | 19:35 | |
| *** Emine has quit IRC | 19:48 | |
| *** bigdogstl has joined #openstack-keystone | 19:53 | |
| *** bigdogstl has quit IRC | 19:57 | |
| *** bigdogstl has joined #openstack-keystone | 20:59 | |
| * lbragstad heads to the airport and puts some John Denver on the stereo | 21:08 | |
| lbragstad | safe travels, all | 21:08 |
| *** lbragstad has quit IRC | 21:08 | |
| *** bigdogstl has quit IRC | 21:09 | |
| *** bigdogstl has joined #openstack-keystone | 21:13 | |
| *** bigdogstl has quit IRC | 21:18 | |
| *** raildo has quit IRC | 22:00 | |
| *** bigdogstl has joined #openstack-keystone | 22:51 | |
| *** bigdogstl has quit IRC | 23:03 | |
| *** bigdogstl has joined #openstack-keystone | 23:05 | |
| *** erus has quit IRC | 23:08 | |
| *** bigdogstl has quit IRC | 23:10 | |
| *** erus has joined #openstack-keystone | 23:11 | |
| *** bigdogstl has joined #openstack-keystone | 23:11 | |
| *** erus has quit IRC | 23:17 | |
| openstackgerrit | Merged openstack/keystone master: Update more info of vhost file https://review.openstack.org/616457 | 23:18 |
| openstackgerrit | Merged openstack/keystone master: Emit CADF notifications on authentication for invalid users https://review.openstack.org/613455 | 23:18 |
| openstackgerrit | Merged openstack/keystone master: Remove unused lower constraints https://review.openstack.org/615750 | 23:20 |
| openstackgerrit | Merged openstack/keystone master: Provide a Location on HTTP 300 https://review.openstack.org/613633 | 23:20 |
| *** erus has joined #openstack-keystone | 23:22 | |
| *** bigdogstl has quit IRC | 23:24 | |
| *** bigdogstl has joined #openstack-keystone | 23:27 | |
| *** erus has quit IRC | 23:29 | |
| *** bigdogstl has quit IRC | 23:32 | |
| *** erus has joined #openstack-keystone | 23:37 | |
| *** bigdogstl has joined #openstack-keystone | 23:43 | |
| *** erus has quit IRC | 23:43 | |
| *** erus has joined #openstack-keystone | 23:52 | |
| *** aojea_ has quit IRC | 23:52 | |
| *** bigdogstl has quit IRC | 23:54 | |
| *** erus has quit IRC | 23:59 | |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!