*** dave-mccowan has joined #openstack-keystone | 00:08 | |
*** dave-mccowan has quit IRC | 00:13 | |
*** markvoelker has joined #openstack-keystone | 00:19 | |
*** markvoelker has quit IRC | 00:31 | |
*** ileixe has joined #openstack-keystone | 00:51 | |
*** markvoelker has joined #openstack-keystone | 01:09 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Clean up the create_arguments_apply methods https://review.openstack.org/627617 | 01:38 |
---|---|---|
*** markvoelker has quit IRC | 01:45 | |
*** erus_ has joined #openstack-keystone | 01:59 | |
*** mhen has quit IRC | 02:52 | |
*** mhen has joined #openstack-keystone | 03:00 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Expose receipt_setup and receipt_rotate command https://review.openstack.org/630574 | 03:08 |
*** markvoelker has joined #openstack-keystone | 03:18 | |
*** whoami-rajat has joined #openstack-keystone | 03:30 | |
*** markvoelker has quit IRC | 03:34 | |
*** markvoelker has joined #openstack-keystone | 03:34 | |
*** markvoelker has quit IRC | 03:39 | |
*** markvoelker has joined #openstack-keystone | 03:48 | |
*** markvoelker has quit IRC | 03:54 | |
*** markvoelker has joined #openstack-keystone | 03:55 | |
openstackgerrit | Merged openstack/keystone master: Do not use self in classmethod https://review.openstack.org/629415 | 03:59 |
openstackgerrit | Merged openstack/keystone master: Update doc for token_setup and token_rotate https://review.openstack.org/629168 | 04:00 |
*** shyamb has joined #openstack-keystone | 04:19 | |
*** shyamb has quit IRC | 04:22 | |
*** erus_ has quit IRC | 05:36 | |
*** markvoelker has quit IRC | 05:39 | |
*** erus has quit IRC | 06:02 | |
*** erus has joined #openstack-keystone | 06:07 | |
*** markvoelker has joined #openstack-keystone | 06:12 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Expose receipt_setup and receipt_rotate command https://review.openstack.org/630574 | 06:36 |
*** ileixe has quit IRC | 07:09 | |
*** pcaruana has joined #openstack-keystone | 07:11 | |
*** sapd1 has quit IRC | 07:29 | |
*** sapd1 has joined #openstack-keystone | 07:29 | |
*** markvoelker has quit IRC | 07:58 | |
*** markvoelker has joined #openstack-keystone | 08:03 | |
*** markvoelker has quit IRC | 08:10 | |
*** sapd1 has quit IRC | 08:15 | |
*** sapd1 has joined #openstack-keystone | 08:16 | |
*** markvoelker has joined #openstack-keystone | 08:29 | |
*** markvoelker has quit IRC | 08:30 | |
*** markvoelker has joined #openstack-keystone | 08:32 | |
*** markvoelker has quit IRC | 08:33 | |
*** markvoelker has joined #openstack-keystone | 08:35 | |
*** usr2033 has joined #openstack-keystone | 08:39 | |
usr2033 | hi, does keystone triggers other services when a project is deleted? If so when/in which version it is started? I have an orphened resource problem | 08:41 |
wxy-xiyuan | usr2033: no, keystone doesn't support it yet. | 09:00 |
wxy-xiyuan | usr2033: It's under discussion. https://etherpad.openstack.org/p/community-goal-project-deletion Perhaps it'll be landed in T IMO. | 09:02 |
*** markvoelker has quit IRC | 09:52 | |
*** awalende has joined #openstack-keystone | 10:20 | |
*** yan0s has joined #openstack-keystone | 10:35 | |
usr2033 | wxy-xiyuan: thank you. | 10:58 |
*** erus has quit IRC | 10:58 | |
*** erus has joined #openstack-keystone | 11:00 | |
*** Dinesh_Bhor has joined #openstack-keystone | 11:08 | |
*** mvkr has quit IRC | 11:26 | |
*** raildo has joined #openstack-keystone | 11:53 | |
*** mvkr has joined #openstack-keystone | 11:56 | |
*** awalende has quit IRC | 12:00 | |
*** markvoelker has joined #openstack-keystone | 12:01 | |
*** awalende has joined #openstack-keystone | 12:03 | |
*** awalende has quit IRC | 12:08 | |
*** mvkr has quit IRC | 12:10 | |
*** mvkr has joined #openstack-keystone | 12:10 | |
*** awalende has joined #openstack-keystone | 12:27 | |
*** Dinesh_Bhor has quit IRC | 12:45 | |
*** awalende has quit IRC | 12:55 | |
*** needssleep is now known as TheJulia | 13:02 | |
*** awalende has joined #openstack-keystone | 13:03 | |
*** dave-mccowan has joined #openstack-keystone | 13:14 | |
*** erus_ has joined #openstack-keystone | 13:54 | |
*** mchlumsky has joined #openstack-keystone | 14:16 | |
*** beekneemech is now known as bnemec | 14:19 | |
*** lbragstad has joined #openstack-keystone | 14:19 | |
*** ChanServ sets mode: +o lbragstad | 14:19 | |
*** aojea has joined #openstack-keystone | 14:19 | |
*** awalende has quit IRC | 14:20 | |
*** markvoelker has quit IRC | 14:31 | |
*** markvoelker has joined #openstack-keystone | 14:34 | |
lbragstad | o/ | 14:36 |
*** aojea has quit IRC | 14:41 | |
*** usr2033 has quit IRC | 14:55 | |
*** erus_ has quit IRC | 15:08 | |
openstackgerrit | Corey Bryant proposed openstack/keystone master: PY3: switch to using unicode text values https://review.openstack.org/611190 | 15:10 |
*** xek has joined #openstack-keystone | 15:15 | |
*** markvoelker has quit IRC | 15:20 | |
*** markvoelker has joined #openstack-keystone | 15:20 | |
*** markvoelker has quit IRC | 15:20 | |
knikolla | o/ | 15:38 |
lbragstad | how goes it knikolla? | 15:39 |
gagehugo | o/ | 15:58 |
yan0s | Hi all, | 15:59 |
yan0s | is it possible to create a resource in openstack cli as admin | 15:59 |
yan0s | but for a different user as owner? | 15:59 |
yan0s | eq. a private network | 16:00 |
yan0s | is it just a matter of creating the private network on a project in which the other user has rights to access? | 16:02 |
lbragstad | yan0s, you could try doing it with a trust scoped tokne | 16:05 |
lbragstad | or building a trust between the user and the admin with impersonation on | 16:05 |
knikolla | lbragstad: good, how're you? | 16:08 |
lbragstad | halfway through my first coffee - so i can't complain ;) | 16:11 |
knikolla | i'm trying to cut down on those, or switching to decaf. | 16:14 |
lbragstad | that's not a bad idea... | 16:15 |
lbragstad | i might have to do that, eventually | 16:16 |
*** pcaruana has quit IRC | 16:20 | |
yan0s | lbragstad: thanks, I will read more about that | 16:26 |
*** yan0s has quit IRC | 17:11 | |
*** pcaruana has joined #openstack-keystone | 17:15 | |
*** itlinux has joined #openstack-keystone | 17:33 | |
*** mvkr has quit IRC | 17:41 | |
*** erus_ has joined #openstack-keystone | 17:59 | |
erus_ | hi! | 18:23 |
*** itlinux_ has joined #openstack-keystone | 18:26 | |
*** dave-mccowan has quit IRC | 18:26 | |
*** itlinux_ has quit IRC | 18:28 | |
*** itlinux has quit IRC | 18:29 | |
*** dave-mccowan has joined #openstack-keystone | 18:33 | |
*** mvkr has joined #openstack-keystone | 18:56 | |
*** pcaruana has quit IRC | 19:08 | |
*** erus_ has quit IRC | 19:34 | |
*** erus has quit IRC | 19:43 | |
*** erus has joined #openstack-keystone | 19:44 | |
*** itlinux has joined #openstack-keystone | 19:51 | |
*** erus_ has joined #openstack-keystone | 19:53 | |
*** itlinux has quit IRC | 20:04 | |
openstackgerrit | Corey Bryant proposed openstack/keystone master: PY3: switch to using unicode text values https://review.openstack.org/611190 | 20:24 |
*** whoami-rajat has quit IRC | 20:40 | |
erus_ | hello, are someone available? :) knikolla? o/ | 20:43 |
knikolla | erus_: o/ i'm here | 21:00 |
*** bzhao__ has quit IRC | 21:11 | |
*** jroll has quit IRC | 21:11 | |
*** jroll has joined #openstack-keystone | 21:12 | |
*** trident has quit IRC | 21:13 | |
*** trident has joined #openstack-keystone | 21:16 | |
erus_ | hi knikolla how are you? | 21:17 |
erus_ | I broke everything with the authentication :D | 21:18 |
erus_ | so good! | 21:18 |
erus_ | the last thing that I had was duplicate PVs :P | 21:18 |
erus_ | don't know how I got there | 21:20 |
erus_ | I set up everything from scratch and now I am trying mellon | 21:21 |
erus_ | we'll see | 21:21 |
*** xek has quit IRC | 21:28 | |
*** _KaszpiR_ has left #openstack-keystone | 21:48 | |
*** imacdonn has quit IRC | 22:06 | |
*** imacdonn has joined #openstack-keystone | 22:06 | |
erus_ | well I got stuck haha let me know if you are available :D | 22:09 |
erus_ | I'm having 2 differents errors when trying to run openstack token issue | 22:11 |
erus_ | the first one: __init__() got an unexpected keyword argument 'user_domain_id' | 22:11 |
erus_ | the second: SSL exception connecting to https://sp.keystone.test.org/idendity/v3/OS-FEDERATION/identity_providers/samlidp/protocols/saml2/auth: HTTPSConnectionPool(host='sp.keystone.test.org', port=443): Max retries exceeded with url: /idendity/v3/OS-FEDERATION/identity_providers/samlidp/protocols/saml2/auth (Caused by SSLError(SSLError("bad handshake: Error([('SSL routines', 'ssl3_get_record', | 22:11 |
erus_ | 'wrong version number')],)",),)) | 22:12 |
erus_ | knikolla don't remember your timezone :) | 22:12 |
erus_ | I'll be here for maybe 3-4 hours | 22:12 |
knikolla | erus: walking home now, give me about 20 minutes and I’ll be back to help. I’m on EST. | 22:13 |
erus_ | knikolla ok thanks :D | 22:14 |
knikolla | erus_: alright, let’s look into this :) | 22:27 |
erus_ | hi hi | 22:27 |
erus_ | :D | 22:27 |
erus_ | well | 22:27 |
erus_ | with shibboleth as I said I broke everything | 22:28 |
erus_ | so I started from scratch | 22:28 |
erus_ | and tried to set up mellon | 22:28 |
erus_ | and did everything following the docs, but when doing the env variable export and then tring to run openstack token issue I got that errors | 22:29 |
erus_ | trying* | 22:29 |
knikolla | You’re trying keystone to keystone federation? | 22:30 |
knikolla | Or federating with samltest | 22:30 |
erus_ | with samltest | 22:30 |
erus_ | using mellon instead of shib | 22:31 |
erus_ | because with shib I had to downgrade libcurl :/ | 22:31 |
*** rcernin has joined #openstack-keystone | 22:31 | |
erus_ | have* | 22:31 |
knikolla | erus_: can you paste the environment variables that you exported into paste.openstack.org and send me a link | 22:32 |
knikolla | Clear out anything sensitive | 22:33 |
knikolla | As that link will be public. | 22:33 |
erus_ | ok, do you have a pad? | 22:33 |
erus_ | maybe could work too | 22:33 |
knikolla | You mean etherpad? | 22:35 |
erus_ | http://paste.openstack.org/show/742360/ | 22:36 |
erus_ | yes etherpad or another one that you use | 22:37 |
knikolla | So, you have a devstack installation, right? | 22:37 |
erus_ | yes | 22:39 |
knikolla | Where is it running on? | 22:39 |
erus_ | ubuntu 18.04 | 22:39 |
knikolla | Is it a vm on your machine, a vm on a cloud? | 22:39 |
erus_ | a vm on my machine | 22:39 |
knikolla | Does it have a desktop environment? | 22:40 |
erus_ | no | 22:40 |
knikolla | You’re running the commands from your machine or the vm? | 22:40 |
erus_ | I access through ssh to the vm | 22:40 |
knikolla | Ok, cool. | 22:41 |
knikolla | So in that case, change auth_url to be localhost | 22:41 |
knikolla | Because it’s not really sp.keystone.test.org | 22:41 |
erus_ | yes I have doubt with it, do you want to see my configs? | 22:42 |
erus_ | well I'll try localhost first | 22:42 |
erus_ | export OS_AUTH_URL = localhost/identity/v3 or just localhost? | 22:43 |
knikolla | http://localhost/identity/v3 | 22:43 |
erus_ | ok thanks I'll try that | 22:43 |
erus_ | Internal Server Error (HTTP 500) | 22:44 |
knikolla | Do it with `--debug` | 22:44 |
knikolla | To see at which step it fails | 22:44 |
knikolla | There’s going to be a loooot of text | 22:44 |
knikolla | If you can’t make sense of it just do another paste.openstack.org and I’ll look into it. | 22:45 |
erus_ | yes it's a lot of text haha | 22:47 |
*** itlinux has joined #openstack-keystone | 22:47 | |
erus_ | http://paste.openstack.org/show/742362/ | 22:47 |
knikolla | Can you look into the keystone logs? | 22:49 |
erus_ | there is nothing | 22:50 |
erus_ | the last log was | 22:50 |
erus_ | Jan 14 19:20:49 u-stack devstack@keystone.service[9084]: [pid: 9087|app: 0|req: 19/38] 192.168.122.141 () {60 vars in 1301 bytes} [Mon Jan 14 19:20:49 2019] GET /identity/v3/users/c227eb56457644d0a781f2ff06414f8e/projects => generated 1027 bytes in 52 msecs (HTTP/1.1 200) 5 headers in 178 bytes (1 switches on core 0) | 22:50 |
erus_ | 30 minutes ago | 22:50 |
knikolla | But we just got a 500, there must be a 500 error in there. | 22:51 |
erus_ | but it's not | 22:53 |
erus_ | I'm running journalctl -f -a --unit devstack@keystone | 22:53 |
knikolla | Try the call again while you have a separate tab on journalctl | 22:58 |
*** mchlumsky has quit IRC | 23:03 | |
erus_ | I already did that | 23:04 |
knikolla | Hmm... then look in the apache logs | 23:04 |
erus_ | The request you have made requires authentication. (HTTP 401) (Request-ID: req-e28abffd-3adb-4181-8719-65dab2df5945) | 23:06 |
erus_ | I change some settings and now says that | 23:06 |
knikolla | Leave the settings how they were | 23:07 |
knikolla | And look at the apache logs | 23:07 |
knikolla | There might be some misconfiguration with apache mellon | 23:07 |
knikolla | And the call not going to keystone at all, hence there being nothing in the keystone logs | 23:07 |
erus_ | Jan 14 19:20:17 u-stack apachectl[11382]: AH00558: apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.1.1. Set the 'ServerName' directive globally to suppress this message that was the last log when I run openstack token issue | 23:08 |
knikolla | That wouldn’t cause it. | 23:08 |
erus_ | I had apache and keystone logso open at the same time | 23:08 |
erus_ | the change that I made was that I wasn't declared <VirtualHost> tag in keyston.conf vhost | 23:09 |
erus_ | keystone* | 23:10 |
knikolla | Show me the keystone.conf | 23:10 |
knikolla | Just put it in another paste | 23:10 |
erus_ | http://paste.openstack.org/show/742365/ | 23:11 |
erus_ | yep | 23:11 |
erus_ | the only new there is the VirtualHost tag | 23:11 |
erus_ | that config is inside keystone-wsgi-public.conf in sites-available | 23:13 |
knikolla | Did you create the files referenced there? Privatekeyfile, certfile, etc? | 23:14 |
erus_ | yes | 23:14 |
erus_ | I actually create the mellon dir | 23:14 |
erus_ | and run the script and then rename the files | 23:14 |
knikolla | What is the ip of the vm? | 23:14 |
erus_ | 192.168.122.141 | 23:15 |
erus_ | and the endpoint is 192.168.122.141/identity | 23:15 |
knikolla | Can you try to open http://192.168.122.141/identity from your browser in your machine | 23:15 |
knikolla | You should get the version information | 23:16 |
erus_ | yes it give a json | 23:16 |
knikolla | Cool | 23:16 |
erus_ | http://paste.openstack.org/show/742366/ | 23:16 |
knikolla | Now try to access from the browser, http://192.168.122.141/identity/v3/OS-FEDERATION/identity_providers/samlidp/protocols/saml2/auth | 23:16 |
knikolla | Ideally, this should redirect you to samlidp | 23:17 |
knikolla | What we’re encountering is that it’s giving you a 500 | 23:17 |
erus_ | error | 23:17 |
erus_ | code 401 | 23:17 |
erus_ | message "The request you have made requires authentication." | 23:17 |
erus_ | title "Unauthorized" | 23:17 |
knikolla | Remove the virtualhost part, I guess. | 23:17 |
erus_ | yes without the virtualhost it give me a 500 | 23:18 |
knikolla | What is happening is that mellon is not being triggered, hence you’re going to keystone without doing being authenticated through samlidp | 23:18 |
erus_ | I removed the virtualhost part | 23:19 |
knikolla | That is what the <Location> tag does, it Require(s) a valid-user and the AuthType is Mellon | 23:19 |
knikolla | Therefore when you hit that path, Mellon is triggered | 23:19 |
knikolla | Redirecting you to samlidp | 23:20 |
knikolla | Where you authenticate, and then come back | 23:20 |
knikolla | And then keystone lets you in | 23:20 |
erus_ | ok ok | 23:20 |
knikolla | :) | 23:20 |
knikolla | So we need to hunt down what is throwing a 500, and fix that | 23:21 |
knikolla | Restarting apache works? | 23:22 |
erus_ | yep :D | 23:23 |
knikolla | Please remind me what timezone are you in | 23:25 |
erus_ | UTC-3 | 23:25 |
erus_ | xD | 23:25 |
knikolla | What time will you be available tomorrow to continue debugging? | 23:26 |
knikolla | I gotta log off now | 23:26 |
*** raildo has quit IRC | 23:28 | |
erus_ | maybe 9? | 23:30 |
erus_ | I have to go too | 23:30 |
knikolla | am? pm? | 23:30 |
erus_ | am | 23:30 |
knikolla | 9am what timezone? | 23:31 |
erus_ | UTC-3? haha | 23:31 |
erus_ | it's 12 UTC | 23:31 |
knikolla | That makes it 7am here, sure, that works. | 23:32 |
erus_ | ohh haha right, it's ok for you? | 23:32 |
erus_ | I could later if you want :) | 23:32 |
erus_ | if you prefer that | 23:33 |
knikolla | Yeah, I generally try to be awake by that time. | 23:33 |
knikolla | Not always successful, lol | 23:33 |
erus_ | haha I can't awake at that time | 23:34 |
*** erus_ has quit IRC | 23:41 | |
*** markvoelker has joined #openstack-keystone | 23:58 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!