*** itlinux has joined #openstack-keystone | 00:11 | |
*** whoami-rajat has quit IRC | 00:21 | |
*** erus has quit IRC | 00:34 | |
openstackgerrit | Merged openstack/keystone-tempest-plugin master: Clean up the auto generated domain https://review.openstack.org/579063 | 00:48 |
---|---|---|
*** imacdonn has quit IRC | 01:20 | |
*** whoami-rajat has joined #openstack-keystone | 01:21 | |
openstackgerrit | Merged openstack/oslo.policy master: Fixes is_admin type from StrOpt to BoolOpt. https://review.openstack.org/628207 | 01:32 |
*** lifeless_ has joined #openstack-keystone | 01:55 | |
*** erus has joined #openstack-keystone | 01:55 | |
*** tridde has joined #openstack-keystone | 01:57 | |
*** erus has quit IRC | 01:57 | |
*** erus has joined #openstack-keystone | 01:58 | |
*** dklyle has quit IRC | 02:00 | |
*** lifeless has quit IRC | 02:00 | |
*** larsks has quit IRC | 02:00 | |
*** errr has quit IRC | 02:00 | |
*** trident has quit IRC | 02:00 | |
*** jrist has quit IRC | 02:00 | |
*** larsks has joined #openstack-keystone | 02:00 | |
*** openstackgerrit has quit IRC | 02:02 | |
*** dims has quit IRC | 02:02 | |
*** dims has joined #openstack-keystone | 02:05 | |
*** errr has joined #openstack-keystone | 02:07 | |
*** Dinesh_Bhor has joined #openstack-keystone | 02:27 | |
*** mhen has quit IRC | 02:49 | |
*** tridde is now known as trident | 03:06 | |
*** Dinesh_Bhor has quit IRC | 03:29 | |
*** Dinesh_Bhor has joined #openstack-keystone | 03:35 | |
*** shyamb has joined #openstack-keystone | 03:41 | |
*** tkajinam__ has joined #openstack-keystone | 04:58 | |
*** shyamb has quit IRC | 04:58 | |
*** shyamb has joined #openstack-keystone | 04:59 | |
*** tkajinam_ has quit IRC | 05:00 | |
*** shyamb has quit IRC | 05:01 | |
*** shyamb has joined #openstack-keystone | 05:01 | |
*** shyam89 has joined #openstack-keystone | 05:49 | |
*** shyamb has quit IRC | 05:51 | |
*** aojea has joined #openstack-keystone | 06:22 | |
*** aojea has quit IRC | 06:23 | |
*** jaosorior has joined #openstack-keystone | 06:33 | |
*** Dinesh_Bhor has quit IRC | 06:35 | |
*** Dinesh_Bhor has joined #openstack-keystone | 07:22 | |
*** pcaruana has joined #openstack-keystone | 07:25 | |
*** shyam89 has quit IRC | 07:39 | |
*** shyamb has joined #openstack-keystone | 07:39 | |
*** pcaruana has quit IRC | 07:55 | |
*** pcaruana has joined #openstack-keystone | 07:55 | |
*** yan0s has joined #openstack-keystone | 08:08 | |
*** shyamb has quit IRC | 08:10 | |
*** openstackgerrit has joined #openstack-keystone | 08:14 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement system reader for role_assignments https://review.openstack.org/609210 | 08:14 |
*** Dinesh_Bhor has quit IRC | 08:17 | |
*** tkajinam__ has quit IRC | 08:18 | |
*** Dinesh_Bhor has joined #openstack-keystone | 08:25 | |
*** Dinesh_Bhor has quit IRC | 08:34 | |
*** yan0s has quit IRC | 08:45 | |
*** yan0s has joined #openstack-keystone | 08:46 | |
*** Dinesh_Bhor has joined #openstack-keystone | 08:47 | |
*** shyamb has joined #openstack-keystone | 09:03 | |
*** Dinesh_Bhor has quit IRC | 09:17 | |
*** xek has joined #openstack-keystone | 09:28 | |
*** shyamb has quit IRC | 09:34 | |
*** erus has quit IRC | 09:38 | |
*** erus has joined #openstack-keystone | 09:41 | |
*** mvkr has joined #openstack-keystone | 09:41 | |
*** shyamb has joined #openstack-keystone | 09:42 | |
*** erus has quit IRC | 09:47 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement system reader for role_assignments https://review.openstack.org/609210 | 09:49 |
*** erus has joined #openstack-keystone | 09:53 | |
*** annp_ has quit IRC | 09:59 | |
*** erus has quit IRC | 09:59 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Replace 'tenant_id' with 'project_id' https://review.openstack.org/631706 | 10:00 |
*** erus has joined #openstack-keystone | 10:08 | |
*** erus has quit IRC | 10:15 | |
*** erus has joined #openstack-keystone | 10:23 | |
*** shyamb has quit IRC | 10:58 | |
*** shyamb has joined #openstack-keystone | 11:16 | |
openstackgerrit | Mike Chen proposed openstack/keystone master: Fix wrong urls https://review.openstack.org/631779 | 11:28 |
*** odyssey4me has joined #openstack-keystone | 11:30 | |
*** shyamb has quit IRC | 11:42 | |
*** shyamb has joined #openstack-keystone | 11:42 | |
*** shyamb has quit IRC | 11:52 | |
*** shyamb has joined #openstack-keystone | 11:53 | |
*** erus has quit IRC | 11:58 | |
*** shyamb has quit IRC | 11:58 | |
*** erus has joined #openstack-keystone | 12:00 | |
*** shyamb has joined #openstack-keystone | 12:05 | |
*** ignaziocassano1 has joined #openstack-keystone | 12:27 | |
ignaziocassano1 | hello | 12:27 |
ignaziocassano1 | anyone can help mi on trust scoped token ? | 12:28 |
ignaziocassano1 | anyone can help me on trust scoped token ? | 12:28 |
ignaziocassano1 | please ! | 12:28 |
*** shyamb has quit IRC | 12:32 | |
*** erus has quit IRC | 12:32 | |
*** erus has joined #openstack-keystone | 12:33 | |
ignaziocassano1 | ou are not authorized to perform the requested action: Using trust-scoped token to create another token. Create a new trust-scoped token instead. (HTTP 403) | 12:33 |
ignaziocassano1 | When a trust scoped token is passed to cinder client to take a snapshot, I expect the client use the token to authenticate and perform the operation which cinder client does. However cinder volume service invokes novaclient as part of cinder nfs backend snapshot operation and novaclient tries to re-authenticate. Since keystone does not allow re-authentication using trust based tokens, cinder snapshot operation fails. | 12:35 |
*** erus has quit IRC | 12:40 | |
*** TheJulia is now known as needssleep | 12:42 | |
*** erus has joined #openstack-keystone | 12:46 | |
*** erus has quit IRC | 12:53 | |
*** erus has joined #openstack-keystone | 13:01 | |
*** erus_ has joined #openstack-keystone | 13:08 | |
*** erus has quit IRC | 13:13 | |
*** erus has joined #openstack-keystone | 13:16 | |
*** erus has quit IRC | 13:23 | |
*** erus has joined #openstack-keystone | 13:31 | |
*** erus has quit IRC | 13:37 | |
*** erus has joined #openstack-keystone | 13:46 | |
*** xek has quit IRC | 13:47 | |
*** xek has joined #openstack-keystone | 13:48 | |
*** erus has quit IRC | 13:53 | |
*** erus has joined #openstack-keystone | 14:01 | |
lbragstad | ignaziocassano1 i assume you don't have that issue if you try taking the snapshot with a project-scoped token? | 14:04 |
*** erus has quit IRC | 14:07 | |
ignaziocassano1 | Yes I did not have problems with project-scoped | 14:08 |
ignaziocassano1 | I am using trilio backup software. Trilio support said there are issues with trust-scoped tokens | 14:10 |
*** imus has joined #openstack-keystone | 14:11 | |
ignaziocassano1 | They use trust-scoped tokens | 14:12 |
ignaziocassano1 | So, I am asking this is unsupported and or buk in keystone or they should modify their code | 14:13 |
ignaziocassano1 | So, I am asking this is unsupported and or bugs in keystone or they should modify their code | 14:13 |
ignaziocassano1 | they got the error posted here http://paste.openstack.org/show/742944/ | 14:15 |
ignaziocassano1 | lbragstad, can you read the above post ? | 14:16 |
*** erus has joined #openstack-keystone | 14:16 | |
*** erus has quit IRC | 14:22 | |
ignaziocassano1 | the code returning the error is here: https://github.com/openstack/cinder/blob/master/cinder/volume/drivers/remotefs.py#L1476 | 14:25 |
lbragstad | ignaziocassano1 have you tried using application credentials? | 14:30 |
lbragstad | based on your email and scrollback here, it sounds like it would work for what you're trying to do | 14:30 |
lbragstad | ignaziocassano1 https://docs.openstack.org/keystone/latest/user/application_credentials.html | 14:31 |
*** erus has joined #openstack-keystone | 14:31 | |
ignaziocassano1 | No, I have not. I could suggest it to developers. | 14:34 |
lbragstad | i'd suggest trying that, as opposed to trusts | 14:34 |
ignaziocassano1 | But do you think trust-scoped is not supported ? | 14:35 |
lbragstad | they're supported, it just might be the wrong application for it | 14:35 |
lbragstad | we developed application credentials as a way for developers to give authorization to software | 14:35 |
ignaziocassano1 | OK. | 14:35 |
ignaziocassano1 | I will suggest | 14:35 |
ignaziocassano1 | thanks | 14:35 |
lbragstad | yep | 14:35 |
lbragstad | they were implemented in Queens | 14:36 |
*** erus has quit IRC | 14:38 | |
*** mchlumsky has joined #openstack-keystone | 14:45 | |
*** erus has joined #openstack-keystone | 14:47 | |
*** erus has quit IRC | 14:54 | |
ayoung | Is the trust token issue a filed bug? | 14:56 |
lbragstad | which issue ayoung ? | 14:56 |
ayoung | Trust scoped tokens were written under a state of paranoia that lifted when Dolph left the project. | 14:56 |
ayoung | Using a trust scoped token to get another token is rightly denied | 14:57 |
ayoung | why would Nova be trying to do that, and not just reuse the token instead? | 14:57 |
ayoung | I get that App Scoped creds don't have that limitation, but that is actually a security hole | 14:57 |
ayoung | and this is why I wanted to implement app creds via trusts, so we didn;t have a proliferation of security and code issues. | 14:58 |
ayoung | we should have modified the trust code to support app creds instead of reimplementing | 14:58 |
ayoung | the only difference betweenb a trust and an app cred should be that an app cred gets its own password. | 14:59 |
ignaziocassano1 | Wrong application or keystone bug ? | 15:01 |
*** erus has joined #openstack-keystone | 15:01 | |
lbragstad | ayoung what's the security hole in application credentials? | 15:03 |
lbragstad | i'm not sure i'm 100% following | 15:03 |
ayoung | lbragstad, using an app scoped token to get another token | 15:03 |
ayoung | either it provides 0 value or it is a security hole | 15:03 |
lbragstad | how so? | 15:04 |
ayoung | what does the second token have that the first token does not? Different roles? Different expiry? | 15:04 |
lbragstad | a different expiry would be the main thing | 15:04 |
ayoung | I'm sure it is not being paranoid and dropping roles (and I know it cannot) | 15:04 |
ayoung | there is a reason we did not allow that | 15:04 |
ayoung | Go ask Russell Bryant, because back before he was Nova PTL was when we had the discussion | 15:05 |
ayoung | when a token is used to get a new token, it should have no longer an expiry than the original token. I think that is still in effect | 15:06 |
ayoung | otherwise, any service out there could bypass the expiration by constantly getting a new token. | 15:06 |
*** erus_ has quit IRC | 15:06 | |
*** erus_ has joined #openstack-keystone | 15:07 | |
*** erus has quit IRC | 15:08 | |
ayoung | This is why I was pushing for a unified delegation model back when Alex M was on the project. To have one view of what it means, and a maximum set of potential features. Each of the mechanisms might shut off features, like App creds could say "we won't allow impersonation" | 15:08 |
lbragstad | ah - yeah.. nevermind expiration is carried forward | 15:08 |
ayoung | so then why token-to-token? My guess is provides nothing | 15:09 |
ayoung | so, no security hole, but we could totally just ease up on that rule for trusts, too | 15:10 |
lbragstad | i'd be curious to know why the rescoping is happening, then | 15:11 |
lbragstad | https://git.openstack.org/cgit/openstack/keystone/tree/keystone/token/provider.py#n242 (expired at code) | 15:11 |
ayoung | when you request and app scoped token, it explicitly states the roles you get, right? No way to request a smaller set of roles? | 15:11 |
*** ignaziocassano1 has quit IRC | 15:12 | |
*** erus has joined #openstack-keystone | 15:16 | |
lbragstad | ayoung not yet | 15:17 |
lbragstad | ayoung actually - i lied | 15:17 |
lbragstad | you can request a smaller set | 15:17 |
lbragstad | https://docs.openstack.org/keystone/latest/user/application_credentials.html#managing-application-credentials | 15:17 |
*** xek has quit IRC | 15:23 | |
*** erus has quit IRC | 15:23 | |
*** xek has joined #openstack-keystone | 15:23 | |
*** erus has joined #openstack-keystone | 15:31 | |
*** erus has quit IRC | 15:37 | |
*** erus has joined #openstack-keystone | 15:46 | |
*** dklyle has joined #openstack-keystone | 15:47 | |
*** erus has quit IRC | 15:53 | |
*** itlinux has quit IRC | 15:58 | |
*** pcaruana has quit IRC | 16:00 | |
*** erus has joined #openstack-keystone | 16:01 | |
*** erus has quit IRC | 16:07 | |
*** erus has joined #openstack-keystone | 16:16 | |
*** sayalilunkad has quit IRC | 16:21 | |
*** erus has quit IRC | 16:22 | |
*** erus_ has quit IRC | 16:22 | |
*** erus_ has joined #openstack-keystone | 16:23 | |
*** sayalilunkad has joined #openstack-keystone | 16:30 | |
*** sayalilunkad has quit IRC | 16:30 | |
*** erus has joined #openstack-keystone | 16:31 | |
*** erus has quit IRC | 16:37 | |
*** yan0s has quit IRC | 16:42 | |
*** erus has joined #openstack-keystone | 16:46 | |
*** erus has quit IRC | 16:52 | |
*** lbragstad is now known as elbragstad | 16:58 | |
*** erus has joined #openstack-keystone | 17:01 | |
*** itlinux has joined #openstack-keystone | 17:02 | |
*** erus has quit IRC | 17:07 | |
*** NM has joined #openstack-keystone | 17:08 | |
*** erus has joined #openstack-keystone | 17:16 | |
*** erus has quit IRC | 17:22 | |
*** itlinux has quit IRC | 17:28 | |
*** itlinux has joined #openstack-keystone | 17:28 | |
*** itlinux has quit IRC | 17:29 | |
*** erus has joined #openstack-keystone | 17:31 | |
*** itlinux has joined #openstack-keystone | 17:34 | |
*** erus has quit IRC | 17:39 | |
*** erus has joined #openstack-keystone | 17:46 | |
*** erus has quit IRC | 17:52 | |
*** erus has joined #openstack-keystone | 18:02 | |
*** erus has quit IRC | 18:08 | |
*** aojea has joined #openstack-keystone | 18:09 | |
*** jaosorior has quit IRC | 18:13 | |
*** aojea has quit IRC | 18:14 | |
*** erus has joined #openstack-keystone | 18:16 | |
*** erus has quit IRC | 18:23 | |
*** erus has joined #openstack-keystone | 18:31 | |
*** hemna is now known as hemnaaway | 18:35 | |
*** erus has quit IRC | 18:37 | |
*** erus has joined #openstack-keystone | 18:46 | |
*** erus has quit IRC | 18:52 | |
*** erus has joined #openstack-keystone | 19:05 | |
*** erus has quit IRC | 19:11 | |
*** erus has joined #openstack-keystone | 19:16 | |
*** erus has quit IRC | 19:23 | |
*** erus has joined #openstack-keystone | 19:33 | |
*** erus has quit IRC | 19:39 | |
*** erus has joined #openstack-keystone | 19:46 | |
*** erus has quit IRC | 19:53 | |
*** imacdonn has joined #openstack-keystone | 19:53 | |
*** NM has quit IRC | 20:01 | |
*** erus has joined #openstack-keystone | 20:01 | |
*** erus has quit IRC | 20:09 | |
*** erus has joined #openstack-keystone | 20:17 | |
*** erus has quit IRC | 20:23 | |
*** whoami-rajat has quit IRC | 20:30 | |
*** erus has joined #openstack-keystone | 20:31 | |
*** NM has joined #openstack-keystone | 20:32 | |
*** erus has quit IRC | 20:37 | |
*** erus_ has quit IRC | 20:46 | |
*** erus has joined #openstack-keystone | 20:46 | |
*** erus_ has joined #openstack-keystone | 20:46 | |
*** erus has quit IRC | 20:52 | |
*** erus_ has quit IRC | 20:52 | |
*** erus_ has joined #openstack-keystone | 20:53 | |
*** erus has joined #openstack-keystone | 21:01 | |
*** erus has quit IRC | 21:08 | |
*** erus has joined #openstack-keystone | 21:16 | |
*** erus has quit IRC | 21:23 | |
*** erus has joined #openstack-keystone | 21:31 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Update inaccurate details in JWS specification https://review.openstack.org/631887 | 21:33 |
*** erus has quit IRC | 21:38 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Update inaccurate details in JWS specification https://review.openstack.org/631887 | 21:46 |
*** erus has joined #openstack-keystone | 21:47 | |
*** itlinux has quit IRC | 21:49 | |
*** erus has quit IRC | 21:53 | |
*** erus has joined #openstack-keystone | 22:01 | |
*** erus has quit IRC | 22:08 | |
*** erus has joined #openstack-keystone | 22:16 | |
*** erus has quit IRC | 22:23 | |
*** xek has quit IRC | 22:25 | |
*** erus has joined #openstack-keystone | 22:31 | |
*** jistr has quit IRC | 22:32 | |
*** erus_ has quit IRC | 22:32 | |
*** erus_ has joined #openstack-keystone | 22:33 | |
*** jistr has joined #openstack-keystone | 22:33 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add configuration options for JWT provider https://review.openstack.org/628676 | 22:35 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add keystone-manage jws_setup functionality https://review.openstack.org/615315 | 22:35 |
*** erus has quit IRC | 22:37 | |
*** erus has joined #openstack-keystone | 22:46 | |
*** jistr has quit IRC | 22:49 | |
*** jistr has joined #openstack-keystone | 22:50 | |
*** erus has quit IRC | 22:52 | |
*** erus has joined #openstack-keystone | 23:01 | |
*** erus has quit IRC | 23:08 | |
*** erus has joined #openstack-keystone | 23:16 | |
*** mchlumsky has quit IRC | 23:21 | |
*** erus has quit IRC | 23:23 | |
*** erus has joined #openstack-keystone | 23:31 | |
*** erus has quit IRC | 23:35 | |
*** erus has joined #openstack-keystone | 23:37 | |
*** erus has quit IRC | 23:49 | |
*** erus has joined #openstack-keystone | 23:50 | |
*** erus has quit IRC | 23:57 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!