Monday, 2019-01-07

*** erus has quit IRC00:35
*** erus has joined #openstack-keystone00:40
openstackgerritMerged openstack/keystone master: Bring SP/IdP URLs closer to style guide guidance  https://review.openstack.org/62784301:35
openstackgerritMerged openstack/keystone master: Fix nits in code blocks in federation guide  https://review.openstack.org/62784401:35
openstackgerritMerged openstack/keystone master: Use samltest.id as an example sandbox IdP  https://review.openstack.org/62784501:35
openstackgerritMerged openstack/keystone master: Update federation SP prerequisites section  https://review.openstack.org/62784601:36
*** ileixe has joined #openstack-keystone02:14
*** shyamb has joined #openstack-keystone02:37
*** whoami-rajat has joined #openstack-keystone02:52
*** mhen has quit IRC03:01
wxy-xiyuanlbragstad: I'll take a look. :)03:01
*** mhen has joined #openstack-keystone03:02
*** shyamb has quit IRC03:15
*** shyamb has joined #openstack-keystone03:16
openstackgerritMerged openstack/keystone master: Remove duplicate RBAC logging from enforcer  https://review.openstack.org/62479904:04
openstackgerritMerged openstack/keystone master: Add prerequisites section to keystone-to-keystone  https://review.openstack.org/62784704:04
*** shyamb has quit IRC04:18
*** shyamb has joined #openstack-keystone04:21
*** shyamb has quit IRC04:30
*** ileixe has quit IRC04:57
*** ileixe has joined #openstack-keystone05:03
*** shyamb has joined #openstack-keystone05:39
*** shyamb has quit IRC05:48
*** shyamb has joined #openstack-keystone06:05
*** rcernin has quit IRC06:56
*** ileixe has quit IRC07:31
*** shyamb has quit IRC07:50
*** ileixe has joined #openstack-keystone07:51
*** yan0s has joined #openstack-keystone07:56
*** pcaruana has joined #openstack-keystone08:14
*** pcaruana has quit IRC08:24
*** xek has joined #openstack-keystone08:39
*** pcaruana has joined #openstack-keystone08:46
*** shyamb has joined #openstack-keystone08:53
*** shyamb has quit IRC09:14
*** shyamb has joined #openstack-keystone09:16
*** shyamb has quit IRC09:44
*** shyamb has joined #openstack-keystone09:44
*** jaosorior has joined #openstack-keystone10:03
*** shyamb has quit IRC10:48
*** pcaruana has quit IRC11:11
*** pcaruana has joined #openstack-keystone11:16
openstackgerritVishakha Agarwal proposed openstack/keystone master: Add openstack_groups to assertion  https://review.openstack.org/58821111:20
*** ileixe has quit IRC11:23
*** vishakha has joined #openstack-keystone11:31
*** tobias-urdin is now known as tobias-urdin_afk11:34
*** shyamb has joined #openstack-keystone11:35
*** raildo has joined #openstack-keystone11:51
*** tobias-urdin_afk is now known as tobias-urdin11:59
*** zigo has quit IRC12:31
*** ygk_12345 has joined #openstack-keystone12:38
ygk_12345HI all12:50
ygk_12345I need some help with AD integration of keystone12:51
ygk_12345i have already integrated it as a separate domain apart from the default domain12:51
ygk_12345but when I list the users , it is throwing this error12:51
ygk_12345Number of User/Group entities returned by LDAP exceeded size limit. Contact your LDAP administrator. (HTTP 500) (Request-ID:12:51
ygk_12345how to solve this ?12:53
ygk_12345 I am using rocky12:53
*** shyamb has quit IRC12:59
*** jhesketh has quit IRC13:05
ygk_12345is anyone around ?13:06
*** jhesketh has joined #openstack-keystone13:06
*** shyamb has joined #openstack-keystone13:06
cmurphyygk_12345: that error is due to the way your ldap server is configured, the number of results it can return is limited so it throws an error instead13:12
cmurphya workaround is to set page_size in keystone.conf so that keystone requests fewer results at a time13:13
ygk_12345cmurphy:  where to modify ?13:21
cmurphyygk_12345: in keystone.conf in the [ldap] section https://docs.openstack.org/keystone/latest/admin/integrate-with-ldap.html#identity-ldap-server-set-up13:22
ygk_12345cmurphy: can I increase the page_size from 0 to how much ?13:23
cmurphyygk_12345: however much you want, something below your AD server's size limit13:24
ygk_12345cmurphy: in OSA install, where should I restart the keystone service after makinh changes in the keystone container ?13:31
cmurphyygk_12345: you'd have to ask the OSA people that13:31
ygk_12345cmurphy: ok thank you13:31
cmurphyyou're welcome13:31
*** dave-mccowan has joined #openstack-keystone13:32
ygk_12345cmurphy: when I list the projects using openstack project list from the AD domain, it is returning empty list13:48
ygk_12345cmurphy: but it is returning user list well13:48
cmurphyygk_12345: projects are not read from AD, they are always read from keystone's sql database, so if you haven't created any projects in that domain then it won't return any13:49
ygk_12345cmurphy: i want to convert the existing AD users into projects in keystone. HOw do I do that ?13:57
*** vishakha has quit IRC13:58
cmurphyygk_12345: you can't do that, users are not projects14:00
cmurphyygk_12345: https://docs.openstack.org/keystone/latest/admin/identity-concepts.html14:00
cmurphyygk_12345: you can manually create the projects you want with `openstack project create`14:01
ygk_12345cmurphy: ok14:01
*** whoami-rajat has quit IRC14:01
*** irclogbot_1 has quit IRC14:14
lbragstado/14:16
cmurphy\o14:16
openstackgerritColleen Murphy proposed openstack/keystone master: [WIP] Add API for /v3/allowed-requests  https://review.openstack.org/62852414:16
openstackgerritColleen Murphy proposed openstack/keystone master: [WIP] Add manager support for app cred capabilities  https://review.openstack.org/62819314:16
openstackgerritColleen Murphy proposed openstack/keystone master: [WIP] Add API changes for app cred capabilities  https://review.openstack.org/62816814:16
*** xek has quit IRC14:27
*** xek has joined #openstack-keystone14:28
*** shyamb has quit IRC14:28
*** needsleep is now known as TheJulia14:36
bnemeclbragstad: Go Bison!14:39
*** irclogbot_1 has joined #openstack-keystone14:39
lbragstadinoright?14:40
lbragstad7 national championships in 8 years14:40
*** ygk_12345 has quit IRC14:41
*** jdennis has joined #openstack-keystone14:42
bnemecI'm sad I missed the game. Family Christmas this weekend and my brother is a cord cutter.14:43
bnemecAnd I have an adorable two year old niece who gets all my attention when I'm there. :-)14:44
lbragstadwell - that's understandable ;)14:46
*** irclogbot_1 has quit IRC15:01
*** irclogbot_1 has joined #openstack-keystone15:10
*** sapd1_ has joined #openstack-keystone15:14
*** evrardjp has joined #openstack-keystone15:15
*** sapd1 has quit IRC15:16
evrardjphello... I saw an email on the ML that was not tagged keystone but is more or less linked to keystone: An issue in openstack CLI... Just saying :) http://lists.openstack.org/pipermail/openstack-discuss/2019-January/001409.html15:17
*** openstackgerrit has quit IRC15:22
*** mchlumsky has joined #openstack-keystone15:23
*** mchlumsky has quit IRC15:35
*** mchlumsky has joined #openstack-keystone15:36
lbragstadevrardjp interesting - thanks for the ping15:54
*** openstackgerrit has joined #openstack-keystone15:57
openstackgerritColleen Murphy proposed openstack/keystone master: Enhance authn sections in federation guide  https://review.openstack.org/62796615:57
openstackgerritColleen Murphy proposed openstack/keystone master: Clean up keystone-to-keystone section  https://review.openstack.org/62796815:57
openstackgerritColleen Murphy proposed openstack/keystone master: Reorganize guide on configuring a keystone SP  https://review.openstack.org/62797215:57
openstackgerritColleen Murphy proposed openstack/keystone master: Add section on configuring protected auth paths  https://review.openstack.org/62797515:57
openstackgerritColleen Murphy proposed openstack/keystone master: Consolidate WebSSO guide into SP instructions  https://review.openstack.org/62797615:57
openstackgerritColleen Murphy proposed openstack/keystone master: Enhance the shibboleth guide  https://review.openstack.org/62798215:57
openstackgerritColleen Murphy proposed openstack/keystone master: Enhance the mellon guide  https://review.openstack.org/62799315:57
openstackgerritColleen Murphy proposed openstack/keystone master: Enhance the openidc guide  https://review.openstack.org/62803715:57
bnemecColleen is going to annexed by the docs team if she spends any more time there. :-)15:59
* cmurphy hides16:00
*** mchlumsky has quit IRC16:01
bnemec*get annexed16:02
bnemecPer Muphry's Law, there would naturally be a typo in any comment about writing.16:02
cmurphy;)16:02
*** bnemec is now known as stackymcstackfac16:04
*** stackymcstackfac is now known as bnemec16:05
evrardjpbnemec: you ddi good there16:07
bnemecevrardjp: :-)16:08
bnemecI'm also giving myself points for not making the really obvious joke based on someone's last name.16:09
bnemecI expect she's already heard them all. ;-)16:09
evrardjpbnemec: I thought it was included in the sentence too. I took it as part of the joke at least:p16:09
cmurphyi generally assume every time murphy's law comes up it's a joke at my expense :P16:10
evrardjpcmurphy: isn't that proving the law in itself?16:10
bnemecThere _are_ other names for that law that I could have used, it's true.16:10
bnemecAlthough this one might have been more applicable here: 'Umhoefer's or Umhöfer's rule: "Articles on writing are themselves badly written."'16:13
bnemecSince I wasn't actually grammar nitpicking for a change. :-)16:13
* bnemec carefully sidesteps the wikipedia rabbit hole and closes the window16:14
cmurphythat's a healthy choice16:15
evrardjp:)16:16
*** pcaruana has quit IRC16:21
*** erus has quit IRC16:24
*** erus has joined #openstack-keystone16:25
*** whoami-rajat has joined #openstack-keystone16:28
*** imacdonn has joined #openstack-keystone16:51
*** yan0s has quit IRC17:15
*** markvoelker has joined #openstack-keystone17:33
*** markvoelker has quit IRC17:34
openstackgerritMerged openstack/keystone master: correct the description on domain re-enable  https://review.openstack.org/62870517:35
*** gyee has joined #openstack-keystone17:45
openstackgerritMerged openstack/keystone master: Enhance authn sections in federation guide  https://review.openstack.org/62796617:55
openstackgerritMerged openstack/keystone master: Clean up keystone-to-keystone section  https://review.openstack.org/62796817:55
openstackgerritBrian Rosmaita proposed openstack/oslo.policy master: Fix sample config value when set_defaults is used  https://review.openstack.org/62329218:11
openstackgerritLance Bragstad proposed openstack/keystone master: Implement system reader role for projects  https://review.openstack.org/62421518:11
openstackgerritLance Bragstad proposed openstack/keystone master: Implement system member role project test coverage  https://review.openstack.org/62421618:11
lbragstadbiab18:13
*** jmlowe has quit IRC18:32
gyeelbragstad, so looks like for users, unlike domains and projects, disabling a user will permanently invalid the token. Doesn't matter whether the user is re-enable immediately.18:34
*** jmlowe has joined #openstack-keystone18:50
*** jmlowe has quit IRC18:58
*** jmlowe has joined #openstack-keystone18:59
*** itlinux has joined #openstack-keystone19:15
lbragstadgyee ack19:16
lbragstadgyee do you think that behavior with users should be the same as with domains and projects?19:16
gyeelbragstad: from consistency perspective, yes19:34
gyeebut the notion of "user" has always been different from other resources19:37
*** whoami-rajat has quit IRC19:58
*** jmlowe has quit IRC20:01
*** jmlowe has joined #openstack-keystone20:03
lbragstadgyee right20:05
lbragstadi guess right now we expect re-enabled users to reauthenticate20:06
lbragstadbut that same expectation is optional for projects and domains20:07
gyeelbragstad, yeah, I don't have a strong argument for one way or the other. So as long as we are properly doc the expected behavior I guess we're fine.20:12
lbragstadyeah - that works for me20:12
lbragstadnice find though20:13
lbragstaddepending on what stance you have, we could one of two things20:13
lbragstad1.) open a bug saying that we should remove the revocation event that is persisted when a user is disabled20:13
lbragstad2.) doc the behavior that re-authentication is required when a user is re-enabled20:14
gyeeI'd go for 2) for now20:16
gyeeI've got a feeling that 1) may open up a can of worms :-)20:16
gyeenot sure if this behavior was by design as part of PCI DSS20:17
gyeethough I can't seem to find anything on it20:18
lbragstadi have a feeling it is left over cruft from revocation events20:21
gyeeyeah could be20:30
lbragstadthat's an area of code that could probably be simplified20:31
gyeelbragstad: how about lets do 2) in short term, and 1) in longer term?20:37
*** jmlowe has quit IRC20:42
lbragstadgyee works for me20:59
openstackgerritLance Bragstad proposed openstack/keystone master: Implement system admin role in project API  https://review.openstack.org/62421720:59
cmurphyI didn't think users could be disabled?20:59
lbragstadthey can be21:00
lbragstadhttps://git.openstack.org/cgit/openstack/keystone/tree/keystone/identity/core.py#n96821:00
lbragstadgroups can't be though21:01
gyeewe can do 'openstack user set --disable user'21:01
*** raildo has quit IRC21:03
*** xek has quit IRC21:11
*** jmlowe has joined #openstack-keystone21:27
lbragstadi don't think there is an actual reason why groups can't be disabled though...21:39
*** bnemec has quit IRC21:58
*** bnemec has joined #openstack-keystone22:02
*** erus has quit IRC22:10
*** erus has joined #openstack-keystone22:16
*** ianw_pto is now known as ianw22:26
openstackgerritMerged openstack/keystone master: Reorganize guide on configuring a keystone SP  https://review.openstack.org/62797222:26
openstackgerritMerged openstack/keystone master: Add section on configuring protected auth paths  https://review.openstack.org/62797522:26
openstackgerritLance Bragstad proposed openstack/keystone master: Implement domain reader functionality for projects  https://review.openstack.org/62421822:35
*** itlinux has quit IRC22:37
*** erus has quit IRC22:43
*** erus has joined #openstack-keystone22:44
openstackgerritLance Bragstad proposed openstack/keystone master: Implement domain reader functionality for projects  https://review.openstack.org/62421822:44
openstackgerritLance Bragstad proposed openstack/keystone master: Implement domain member functionality for projects  https://review.openstack.org/62421922:44
*** rcernin has joined #openstack-keystone22:45
-openstackstatus- NOTICE: The Etherpad service at https://etherpad.openstack.org/ has been offline since 23:22 UTC due to a hypervisor issue in our service provider, but should hopefully return to service shortly.23:49
*** dave-mccowan has quit IRC23:56
*** erus is now known as eRus23:59

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!