| *** dave-mccowan has joined #openstack-keystone | 00:08 | |
| *** dave-mccowan has quit IRC | 00:13 | |
| *** markvoelker has joined #openstack-keystone | 00:19 | |
| *** markvoelker has quit IRC | 00:31 | |
| *** ileixe has joined #openstack-keystone | 00:51 | |
| *** markvoelker has joined #openstack-keystone | 01:09 | |
| openstackgerrit | wangxiyuan proposed openstack/keystone master: Clean up the create_arguments_apply methods https://review.openstack.org/627617 | 01:38 |
|---|---|---|
| *** markvoelker has quit IRC | 01:45 | |
| *** erus_ has joined #openstack-keystone | 01:59 | |
| *** mhen has quit IRC | 02:52 | |
| *** mhen has joined #openstack-keystone | 03:00 | |
| openstackgerrit | wangxiyuan proposed openstack/keystone master: Expose receipt_setup and receipt_rotate command https://review.openstack.org/630574 | 03:08 |
| *** markvoelker has joined #openstack-keystone | 03:18 | |
| *** whoami-rajat has joined #openstack-keystone | 03:30 | |
| *** markvoelker has quit IRC | 03:34 | |
| *** markvoelker has joined #openstack-keystone | 03:34 | |
| *** markvoelker has quit IRC | 03:39 | |
| *** markvoelker has joined #openstack-keystone | 03:48 | |
| *** markvoelker has quit IRC | 03:54 | |
| *** markvoelker has joined #openstack-keystone | 03:55 | |
| openstackgerrit | Merged openstack/keystone master: Do not use self in classmethod https://review.openstack.org/629415 | 03:59 |
| openstackgerrit | Merged openstack/keystone master: Update doc for token_setup and token_rotate https://review.openstack.org/629168 | 04:00 |
| *** shyamb has joined #openstack-keystone | 04:19 | |
| *** shyamb has quit IRC | 04:22 | |
| *** erus_ has quit IRC | 05:36 | |
| *** markvoelker has quit IRC | 05:39 | |
| *** erus has quit IRC | 06:02 | |
| *** erus has joined #openstack-keystone | 06:07 | |
| *** markvoelker has joined #openstack-keystone | 06:12 | |
| openstackgerrit | wangxiyuan proposed openstack/keystone master: Expose receipt_setup and receipt_rotate command https://review.openstack.org/630574 | 06:36 |
| *** ileixe has quit IRC | 07:09 | |
| *** pcaruana has joined #openstack-keystone | 07:11 | |
| *** sapd1 has quit IRC | 07:29 | |
| *** sapd1 has joined #openstack-keystone | 07:29 | |
| *** markvoelker has quit IRC | 07:58 | |
| *** markvoelker has joined #openstack-keystone | 08:03 | |
| *** markvoelker has quit IRC | 08:10 | |
| *** sapd1 has quit IRC | 08:15 | |
| *** sapd1 has joined #openstack-keystone | 08:16 | |
| *** markvoelker has joined #openstack-keystone | 08:29 | |
| *** markvoelker has quit IRC | 08:30 | |
| *** markvoelker has joined #openstack-keystone | 08:32 | |
| *** markvoelker has quit IRC | 08:33 | |
| *** markvoelker has joined #openstack-keystone | 08:35 | |
| *** usr2033 has joined #openstack-keystone | 08:39 | |
| usr2033 | hi, does keystone triggers other services when a project is deleted? If so when/in which version it is started? I have an orphened resource problem | 08:41 |
| wxy-xiyuan | usr2033: no, keystone doesn't support it yet. | 09:00 |
| wxy-xiyuan | usr2033: It's under discussion. https://etherpad.openstack.org/p/community-goal-project-deletion Perhaps it'll be landed in T IMO. | 09:02 |
| *** markvoelker has quit IRC | 09:52 | |
| *** awalende has joined #openstack-keystone | 10:20 | |
| *** yan0s has joined #openstack-keystone | 10:35 | |
| usr2033 | wxy-xiyuan: thank you. | 10:58 |
| *** erus has quit IRC | 10:58 | |
| *** erus has joined #openstack-keystone | 11:00 | |
| *** Dinesh_Bhor has joined #openstack-keystone | 11:08 | |
| *** mvkr has quit IRC | 11:26 | |
| *** raildo has joined #openstack-keystone | 11:53 | |
| *** mvkr has joined #openstack-keystone | 11:56 | |
| *** awalende has quit IRC | 12:00 | |
| *** markvoelker has joined #openstack-keystone | 12:01 | |
| *** awalende has joined #openstack-keystone | 12:03 | |
| *** awalende has quit IRC | 12:08 | |
| *** mvkr has quit IRC | 12:10 | |
| *** mvkr has joined #openstack-keystone | 12:10 | |
| *** awalende has joined #openstack-keystone | 12:27 | |
| *** Dinesh_Bhor has quit IRC | 12:45 | |
| *** awalende has quit IRC | 12:55 | |
| *** needssleep is now known as TheJulia | 13:02 | |
| *** awalende has joined #openstack-keystone | 13:03 | |
| *** dave-mccowan has joined #openstack-keystone | 13:14 | |
| *** erus_ has joined #openstack-keystone | 13:54 | |
| *** mchlumsky has joined #openstack-keystone | 14:16 | |
| *** beekneemech is now known as bnemec | 14:19 | |
| *** lbragstad has joined #openstack-keystone | 14:19 | |
| *** ChanServ sets mode: +o lbragstad | 14:19 | |
| *** aojea has joined #openstack-keystone | 14:19 | |
| *** awalende has quit IRC | 14:20 | |
| *** markvoelker has quit IRC | 14:31 | |
| *** markvoelker has joined #openstack-keystone | 14:34 | |
| lbragstad | o/ | 14:36 |
| *** aojea has quit IRC | 14:41 | |
| *** usr2033 has quit IRC | 14:55 | |
| *** erus_ has quit IRC | 15:08 | |
| openstackgerrit | Corey Bryant proposed openstack/keystone master: PY3: switch to using unicode text values https://review.openstack.org/611190 | 15:10 |
| *** xek has joined #openstack-keystone | 15:15 | |
| *** markvoelker has quit IRC | 15:20 | |
| *** markvoelker has joined #openstack-keystone | 15:20 | |
| *** markvoelker has quit IRC | 15:20 | |
| knikolla | o/ | 15:38 |
| lbragstad | how goes it knikolla? | 15:39 |
| gagehugo | o/ | 15:58 |
| yan0s | Hi all, | 15:59 |
| yan0s | is it possible to create a resource in openstack cli as admin | 15:59 |
| yan0s | but for a different user as owner? | 15:59 |
| yan0s | eq. a private network | 16:00 |
| yan0s | is it just a matter of creating the private network on a project in which the other user has rights to access? | 16:02 |
| lbragstad | yan0s, you could try doing it with a trust scoped tokne | 16:05 |
| lbragstad | or building a trust between the user and the admin with impersonation on | 16:05 |
| knikolla | lbragstad: good, how're you? | 16:08 |
| lbragstad | halfway through my first coffee - so i can't complain ;) | 16:11 |
| knikolla | i'm trying to cut down on those, or switching to decaf. | 16:14 |
| lbragstad | that's not a bad idea... | 16:15 |
| lbragstad | i might have to do that, eventually | 16:16 |
| *** pcaruana has quit IRC | 16:20 | |
| yan0s | lbragstad: thanks, I will read more about that | 16:26 |
| *** yan0s has quit IRC | 17:11 | |
| *** pcaruana has joined #openstack-keystone | 17:15 | |
| *** itlinux has joined #openstack-keystone | 17:33 | |
| *** mvkr has quit IRC | 17:41 | |
| *** erus_ has joined #openstack-keystone | 17:59 | |
| erus_ | hi! | 18:23 |
| *** itlinux_ has joined #openstack-keystone | 18:26 | |
| *** dave-mccowan has quit IRC | 18:26 | |
| *** itlinux_ has quit IRC | 18:28 | |
| *** itlinux has quit IRC | 18:29 | |
| *** dave-mccowan has joined #openstack-keystone | 18:33 | |
| *** mvkr has joined #openstack-keystone | 18:56 | |
| *** pcaruana has quit IRC | 19:08 | |
| *** erus_ has quit IRC | 19:34 | |
| *** erus has quit IRC | 19:43 | |
| *** erus has joined #openstack-keystone | 19:44 | |
| *** itlinux has joined #openstack-keystone | 19:51 | |
| *** erus_ has joined #openstack-keystone | 19:53 | |
| *** itlinux has quit IRC | 20:04 | |
| openstackgerrit | Corey Bryant proposed openstack/keystone master: PY3: switch to using unicode text values https://review.openstack.org/611190 | 20:24 |
| *** whoami-rajat has quit IRC | 20:40 | |
| erus_ | hello, are someone available? :) knikolla? o/ | 20:43 |
| knikolla | erus_: o/ i'm here | 21:00 |
| *** bzhao__ has quit IRC | 21:11 | |
| *** jroll has quit IRC | 21:11 | |
| *** jroll has joined #openstack-keystone | 21:12 | |
| *** trident has quit IRC | 21:13 | |
| *** trident has joined #openstack-keystone | 21:16 | |
| erus_ | hi knikolla how are you? | 21:17 |
| erus_ | I broke everything with the authentication :D | 21:18 |
| erus_ | so good! | 21:18 |
| erus_ | the last thing that I had was duplicate PVs :P | 21:18 |
| erus_ | don't know how I got there | 21:20 |
| erus_ | I set up everything from scratch and now I am trying mellon | 21:21 |
| erus_ | we'll see | 21:21 |
| *** xek has quit IRC | 21:28 | |
| *** _KaszpiR_ has left #openstack-keystone | 21:48 | |
| *** imacdonn has quit IRC | 22:06 | |
| *** imacdonn has joined #openstack-keystone | 22:06 | |
| erus_ | well I got stuck haha let me know if you are available :D | 22:09 |
| erus_ | I'm having 2 differents errors when trying to run openstack token issue | 22:11 |
| erus_ | the first one: __init__() got an unexpected keyword argument 'user_domain_id' | 22:11 |
| erus_ | the second: SSL exception connecting to https://sp.keystone.test.org/idendity/v3/OS-FEDERATION/identity_providers/samlidp/protocols/saml2/auth: HTTPSConnectionPool(host='sp.keystone.test.org', port=443): Max retries exceeded with url: /idendity/v3/OS-FEDERATION/identity_providers/samlidp/protocols/saml2/auth (Caused by SSLError(SSLError("bad handshake: Error([('SSL routines', 'ssl3_get_record', | 22:11 |
| erus_ | 'wrong version number')],)",),)) | 22:12 |
| erus_ | knikolla don't remember your timezone :) | 22:12 |
| erus_ | I'll be here for maybe 3-4 hours | 22:12 |
| knikolla | erus: walking home now, give me about 20 minutes and I’ll be back to help. I’m on EST. | 22:13 |
| erus_ | knikolla ok thanks :D | 22:14 |
| knikolla | erus_: alright, let’s look into this :) | 22:27 |
| erus_ | hi hi | 22:27 |
| erus_ | :D | 22:27 |
| erus_ | well | 22:27 |
| erus_ | with shibboleth as I said I broke everything | 22:28 |
| erus_ | so I started from scratch | 22:28 |
| erus_ | and tried to set up mellon | 22:28 |
| erus_ | and did everything following the docs, but when doing the env variable export and then tring to run openstack token issue I got that errors | 22:29 |
| erus_ | trying* | 22:29 |
| knikolla | You’re trying keystone to keystone federation? | 22:30 |
| knikolla | Or federating with samltest | 22:30 |
| erus_ | with samltest | 22:30 |
| erus_ | using mellon instead of shib | 22:31 |
| erus_ | because with shib I had to downgrade libcurl :/ | 22:31 |
| *** rcernin has joined #openstack-keystone | 22:31 | |
| erus_ | have* | 22:31 |
| knikolla | erus_: can you paste the environment variables that you exported into paste.openstack.org and send me a link | 22:32 |
| knikolla | Clear out anything sensitive | 22:33 |
| knikolla | As that link will be public. | 22:33 |
| erus_ | ok, do you have a pad? | 22:33 |
| erus_ | maybe could work too | 22:33 |
| knikolla | You mean etherpad? | 22:35 |
| erus_ | http://paste.openstack.org/show/742360/ | 22:36 |
| erus_ | yes etherpad or another one that you use | 22:37 |
| knikolla | So, you have a devstack installation, right? | 22:37 |
| erus_ | yes | 22:39 |
| knikolla | Where is it running on? | 22:39 |
| erus_ | ubuntu 18.04 | 22:39 |
| knikolla | Is it a vm on your machine, a vm on a cloud? | 22:39 |
| erus_ | a vm on my machine | 22:39 |
| knikolla | Does it have a desktop environment? | 22:40 |
| erus_ | no | 22:40 |
| knikolla | You’re running the commands from your machine or the vm? | 22:40 |
| erus_ | I access through ssh to the vm | 22:40 |
| knikolla | Ok, cool. | 22:41 |
| knikolla | So in that case, change auth_url to be localhost | 22:41 |
| knikolla | Because it’s not really sp.keystone.test.org | 22:41 |
| erus_ | yes I have doubt with it, do you want to see my configs? | 22:42 |
| erus_ | well I'll try localhost first | 22:42 |
| erus_ | export OS_AUTH_URL = localhost/identity/v3 or just localhost? | 22:43 |
| knikolla | http://localhost/identity/v3 | 22:43 |
| erus_ | ok thanks I'll try that | 22:43 |
| erus_ | Internal Server Error (HTTP 500) | 22:44 |
| knikolla | Do it with `--debug` | 22:44 |
| knikolla | To see at which step it fails | 22:44 |
| knikolla | There’s going to be a loooot of text | 22:44 |
| knikolla | If you can’t make sense of it just do another paste.openstack.org and I’ll look into it. | 22:45 |
| erus_ | yes it's a lot of text haha | 22:47 |
| *** itlinux has joined #openstack-keystone | 22:47 | |
| erus_ | http://paste.openstack.org/show/742362/ | 22:47 |
| knikolla | Can you look into the keystone logs? | 22:49 |
| erus_ | there is nothing | 22:50 |
| erus_ | the last log was | 22:50 |
| erus_ | Jan 14 19:20:49 u-stack devstack@keystone.service[9084]: [pid: 9087|app: 0|req: 19/38] 192.168.122.141 () {60 vars in 1301 bytes} [Mon Jan 14 19:20:49 2019] GET /identity/v3/users/c227eb56457644d0a781f2ff06414f8e/projects => generated 1027 bytes in 52 msecs (HTTP/1.1 200) 5 headers in 178 bytes (1 switches on core 0) | 22:50 |
| erus_ | 30 minutes ago | 22:50 |
| knikolla | But we just got a 500, there must be a 500 error in there. | 22:51 |
| erus_ | but it's not | 22:53 |
| erus_ | I'm running journalctl -f -a --unit devstack@keystone | 22:53 |
| knikolla | Try the call again while you have a separate tab on journalctl | 22:58 |
| *** mchlumsky has quit IRC | 23:03 | |
| erus_ | I already did that | 23:04 |
| knikolla | Hmm... then look in the apache logs | 23:04 |
| erus_ | The request you have made requires authentication. (HTTP 401) (Request-ID: req-e28abffd-3adb-4181-8719-65dab2df5945) | 23:06 |
| erus_ | I change some settings and now says that | 23:06 |
| knikolla | Leave the settings how they were | 23:07 |
| knikolla | And look at the apache logs | 23:07 |
| knikolla | There might be some misconfiguration with apache mellon | 23:07 |
| knikolla | And the call not going to keystone at all, hence there being nothing in the keystone logs | 23:07 |
| erus_ | Jan 14 19:20:17 u-stack apachectl[11382]: AH00558: apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.1.1. Set the 'ServerName' directive globally to suppress this message that was the last log when I run openstack token issue | 23:08 |
| knikolla | That wouldn’t cause it. | 23:08 |
| erus_ | I had apache and keystone logso open at the same time | 23:08 |
| erus_ | the change that I made was that I wasn't declared <VirtualHost> tag in keyston.conf vhost | 23:09 |
| erus_ | keystone* | 23:10 |
| knikolla | Show me the keystone.conf | 23:10 |
| knikolla | Just put it in another paste | 23:10 |
| erus_ | http://paste.openstack.org/show/742365/ | 23:11 |
| erus_ | yep | 23:11 |
| erus_ | the only new there is the VirtualHost tag | 23:11 |
| erus_ | that config is inside keystone-wsgi-public.conf in sites-available | 23:13 |
| knikolla | Did you create the files referenced there? Privatekeyfile, certfile, etc? | 23:14 |
| erus_ | yes | 23:14 |
| erus_ | I actually create the mellon dir | 23:14 |
| erus_ | and run the script and then rename the files | 23:14 |
| knikolla | What is the ip of the vm? | 23:14 |
| erus_ | 192.168.122.141 | 23:15 |
| erus_ | and the endpoint is 192.168.122.141/identity | 23:15 |
| knikolla | Can you try to open http://192.168.122.141/identity from your browser in your machine | 23:15 |
| knikolla | You should get the version information | 23:16 |
| erus_ | yes it give a json | 23:16 |
| knikolla | Cool | 23:16 |
| erus_ | http://paste.openstack.org/show/742366/ | 23:16 |
| knikolla | Now try to access from the browser, http://192.168.122.141/identity/v3/OS-FEDERATION/identity_providers/samlidp/protocols/saml2/auth | 23:16 |
| knikolla | Ideally, this should redirect you to samlidp | 23:17 |
| knikolla | What we’re encountering is that it’s giving you a 500 | 23:17 |
| erus_ | error | 23:17 |
| erus_ | code 401 | 23:17 |
| erus_ | message "The request you have made requires authentication." | 23:17 |
| erus_ | title "Unauthorized" | 23:17 |
| knikolla | Remove the virtualhost part, I guess. | 23:17 |
| erus_ | yes without the virtualhost it give me a 500 | 23:18 |
| knikolla | What is happening is that mellon is not being triggered, hence you’re going to keystone without doing being authenticated through samlidp | 23:18 |
| erus_ | I removed the virtualhost part | 23:19 |
| knikolla | That is what the <Location> tag does, it Require(s) a valid-user and the AuthType is Mellon | 23:19 |
| knikolla | Therefore when you hit that path, Mellon is triggered | 23:19 |
| knikolla | Redirecting you to samlidp | 23:20 |
| knikolla | Where you authenticate, and then come back | 23:20 |
| knikolla | And then keystone lets you in | 23:20 |
| erus_ | ok ok | 23:20 |
| knikolla | :) | 23:20 |
| knikolla | So we need to hunt down what is throwing a 500, and fix that | 23:21 |
| knikolla | Restarting apache works? | 23:22 |
| erus_ | yep :D | 23:23 |
| knikolla | Please remind me what timezone are you in | 23:25 |
| erus_ | UTC-3 | 23:25 |
| erus_ | xD | 23:25 |
| knikolla | What time will you be available tomorrow to continue debugging? | 23:26 |
| knikolla | I gotta log off now | 23:26 |
| *** raildo has quit IRC | 23:28 | |
| erus_ | maybe 9? | 23:30 |
| erus_ | I have to go too | 23:30 |
| knikolla | am? pm? | 23:30 |
| erus_ | am | 23:30 |
| knikolla | 9am what timezone? | 23:31 |
| erus_ | UTC-3? haha | 23:31 |
| erus_ | it's 12 UTC | 23:31 |
| knikolla | That makes it 7am here, sure, that works. | 23:32 |
| erus_ | ohh haha right, it's ok for you? | 23:32 |
| erus_ | I could later if you want :) | 23:32 |
| erus_ | if you prefer that | 23:33 |
| knikolla | Yeah, I generally try to be awake by that time. | 23:33 |
| knikolla | Not always successful, lol | 23:33 |
| erus_ | haha I can't awake at that time | 23:34 |
| *** erus_ has quit IRC | 23:41 | |
| *** markvoelker has joined #openstack-keystone | 23:58 | |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!