*** aojea has joined #openstack-keystone | 00:22 | |
openstackgerrit | Merged openstack/keystone master: Drop the compatibility password column https://review.openstack.org/613513 | 00:36 |
---|---|---|
*** raildo has quit IRC | 00:49 | |
openstackgerrit | ayoung proposed openstack/keystone-specs master: WIP Scale Out https://review.openstack.org/618609 | 00:49 |
*** aojea has quit IRC | 00:54 | |
openstackgerrit | Merged openstack/keystoneauth master: Add py36 tox environment https://review.openstack.org/615845 | 00:58 |
*** gyee has quit IRC | 01:39 | |
*** aojea has joined #openstack-keystone | 01:43 | |
*** erus has joined #openstack-keystone | 02:06 | |
*** aojea has quit IRC | 02:15 | |
openstackgerrit | zhouxinyong proposed openstack/keystoneauth master: Replacing the HTTP protocal with HTTPS in using-sessions.rst. https://review.openstack.org/617811 | 02:52 |
*** aojea has joined #openstack-keystone | 03:09 | |
*** erus has quit IRC | 03:33 | |
*** aojea has quit IRC | 03:42 | |
*** aojea has joined #openstack-keystone | 04:34 | |
*** aojea has quit IRC | 05:06 | |
*** aojea has joined #openstack-keystone | 05:58 | |
*** aojea has quit IRC | 06:32 | |
*** aojea has joined #openstack-keystone | 07:26 | |
*** aojea has quit IRC | 07:54 | |
*** aojea has joined #openstack-keystone | 08:22 | |
*** aojea has quit IRC | 08:56 | |
*** aojea has joined #openstack-keystone | 09:52 | |
*** aojea has quit IRC | 10:15 | |
adriant | kmalloc: potentially not a great idea, but jotting it down just in case. For the JWT public key sharing, can't we still provide it via a keystone API, but have keystonemiddleware cache it? if it encounters something it can't decrypt, or some timer has been hit, go back and ask for new keys. Restart of service also reloads cached keys, so you can fo | 10:23 |
adriant | rce an update if needed. | 10:23 |
adriant | Makes distribution/rotation a little easier while still limiting the extra API calls KSM has to do. | 10:24 |
adriant | First ever request after a key refresh may take a little longer, but that model doesn't have too many downsides, and if there is a worry about bogus values causing extra calls back to keystone to check keys we can potentially rate limit that based on a deployer configured setting (e.g. smallest amount of time between rotations). | 10:28 |
*** jistr has quit IRC | 10:30 | |
*** jistr has joined #openstack-keystone | 10:31 | |
*** aojea has joined #openstack-keystone | 10:40 | |
adriant | right now KSM doesn't need any constant attention from deployers, so ideally if we can maintain that model (configure it once, and mostly forget) then that's a benefit. Becuase if a shift to JWT means now also having to manage keys in KSM... people will probably stick with fernet unless JWT gives them a lot of advantages. Having KSM auto-handle reg | 10:41 |
adriant | ardless of token type means easier adoption as well. | 10:41 |
*** aojea has quit IRC | 12:21 | |
*** erus has joined #openstack-keystone | 12:36 | |
*** aojea has joined #openstack-keystone | 12:50 | |
*** aojea has quit IRC | 13:01 | |
*** aojea has joined #openstack-keystone | 13:42 | |
*** aojea has quit IRC | 14:14 | |
*** aojea has joined #openstack-keystone | 15:01 | |
*** aojea has quit IRC | 15:28 | |
*** erus has quit IRC | 15:46 | |
*** aojea has joined #openstack-keystone | 16:13 | |
*** aojea has quit IRC | 16:26 | |
*** aojea has joined #openstack-keystone | 16:27 | |
*** hoonetorg has quit IRC | 16:30 | |
*** aojea has quit IRC | 16:31 | |
*** hoonetorg has joined #openstack-keystone | 16:42 | |
*** sapd1 has joined #openstack-keystone | 17:02 | |
*** imacdonn has quit IRC | 17:16 | |
*** imacdonn has joined #openstack-keystone | 17:16 | |
*** aojea has joined #openstack-keystone | 18:04 | |
*** sapd1 has quit IRC | 18:54 | |
*** aojea has quit IRC | 19:19 | |
*** aojea_ has joined #openstack-keystone | 19:19 | |
*** aojea_ has quit IRC | 20:01 | |
*** aojea has joined #openstack-keystone | 20:01 | |
*** aojea has quit IRC | 20:06 | |
*** trident has quit IRC | 20:19 | |
*** trident has joined #openstack-keystone | 20:20 | |
*** aojea has joined #openstack-keystone | 20:42 | |
*** aojea has quit IRC | 20:48 | |
*** aojea has joined #openstack-keystone | 20:57 | |
*** shrasool has joined #openstack-keystone | 21:04 | |
*** shrasool has quit IRC | 21:11 | |
*** shrasool has joined #openstack-keystone | 21:52 | |
*** aojea has quit IRC | 22:23 | |
*** aojea has joined #openstack-keystone | 23:06 | |
*** aojea has quit IRC | 23:16 | |
*** aojea has joined #openstack-keystone | 23:16 | |
*** shrasool has quit IRC | 23:28 | |
*** aojea has quit IRC | 23:48 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!