| *** imacdonn has quit IRC | 00:00 | |
| *** imacdonn has joined #openstack-keystone | 00:01 | |
| *** ileixe has joined #openstack-keystone | 00:52 | |
| *** gyee has quit IRC | 01:33 | |
| *** Dinesh_Bhor has joined #openstack-keystone | 01:48 | |
| *** whoami-rajat has joined #openstack-keystone | 02:11 | |
| *** dims has quit IRC | 02:38 | |
| *** dims has joined #openstack-keystone | 02:55 | |
| *** ileixe has quit IRC | 04:38 | |
| *** lbragstad has quit IRC | 05:16 | |
| *** ileixe has joined #openstack-keystone | 05:18 | |
| *** shyamb has joined #openstack-keystone | 05:30 | |
| openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add openstack_groups to assertion https://review.openstack.org/588211 | 06:23 |
|---|---|---|
| *** shyamb has quit IRC | 06:31 | |
| *** zzzeek has quit IRC | 06:33 | |
| *** zzzeek has joined #openstack-keystone | 06:37 | |
| openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Replace 'tenant_id' with 'project_id' https://review.openstack.org/631706 | 07:04 |
| openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Replace 'tenant_id' with 'project_id' https://review.openstack.org/631706 | 07:07 |
| *** markvoelker has joined #openstack-keystone | 07:26 | |
| *** takamatsu has joined #openstack-keystone | 07:46 | |
| *** shyamb has joined #openstack-keystone | 07:59 | |
| *** markvoelker has quit IRC | 07:59 | |
| *** tkajinam has quit IRC | 08:14 | |
| *** shyam89 has joined #openstack-keystone | 08:37 | |
| *** shyamb has quit IRC | 08:40 | |
| *** shyam89 has quit IRC | 08:42 | |
| *** Dinesh_Bhor has quit IRC | 08:44 | |
| *** Dinesh_Bhor has joined #openstack-keystone | 08:44 | |
| *** awalende has joined #openstack-keystone | 08:45 | |
| *** shyamb has joined #openstack-keystone | 08:46 | |
| *** markvoelker has joined #openstack-keystone | 08:56 | |
| *** shyamb has quit IRC | 09:05 | |
| *** shyamb has joined #openstack-keystone | 09:09 | |
| *** markvoelker has quit IRC | 09:29 | |
| *** awalende has quit IRC | 09:39 | |
| openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add openstack_groups to assertion https://review.openstack.org/588211 | 09:40 |
| openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add openstack_groups to assertion https://review.openstack.org/588211 | 09:52 |
| *** shyamb has quit IRC | 09:58 | |
| *** xek_ has joined #openstack-keystone | 09:59 | |
| *** shyamb has joined #openstack-keystone | 10:08 | |
| openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Test case for bad type user in assertion https://review.openstack.org/634193 | 10:09 |
| *** shyamb has quit IRC | 10:25 | |
| *** shyamb has joined #openstack-keystone | 10:25 | |
| *** markvoelker has joined #openstack-keystone | 10:26 | |
| *** jistr is now known as jistr|chat | 10:31 | |
| *** shyamb has quit IRC | 10:40 | |
| *** shyamb has joined #openstack-keystone | 10:43 | |
| *** Dinesh_Bhor has quit IRC | 10:54 | |
| *** shyamb has quit IRC | 10:55 | |
| *** markvoelker has quit IRC | 10:59 | |
| *** jistr|chat is now known as jistr | 11:05 | |
| *** shyamb has joined #openstack-keystone | 11:08 | |
| *** yan0s has joined #openstack-keystone | 11:16 | |
| *** sapd1_ has quit IRC | 11:18 | |
| *** ileixe has quit IRC | 11:20 | |
| *** mchlumsky has quit IRC | 11:33 | |
| *** mchlumsky has joined #openstack-keystone | 11:35 | |
| *** shyamb has quit IRC | 11:40 | |
| *** awalende has joined #openstack-keystone | 11:40 | |
| *** shyamb has joined #openstack-keystone | 11:41 | |
| *** awalende has quit IRC | 11:44 | |
| *** markvoelker has joined #openstack-keystone | 11:57 | |
| *** shyamb has quit IRC | 12:02 | |
| *** shyamb has joined #openstack-keystone | 12:03 | |
| *** shyamb has quit IRC | 12:14 | |
| *** markvoelker has quit IRC | 12:29 | |
| *** shyamb has joined #openstack-keystone | 12:34 | |
| *** erus1 has quit IRC | 13:01 | |
| *** shyamb has quit IRC | 13:16 | |
| *** jistr is now known as jistr|call | 13:25 | |
| *** markvoelker has joined #openstack-keystone | 13:26 | |
| *** jistr|call is now known as jistr | 13:31 | |
| *** shyamb has joined #openstack-keystone | 13:36 | |
| *** xek_ has quit IRC | 13:45 | |
| *** xek_ has joined #openstack-keystone | 13:45 | |
| *** pcaruana has quit IRC | 13:52 | |
| *** takamatsu has quit IRC | 13:54 | |
| *** lbragstad has joined #openstack-keystone | 13:57 | |
| *** ChanServ sets mode: +o lbragstad | 13:57 | |
| *** markvoelker has quit IRC | 13:58 | |
| *** pcaruana has joined #openstack-keystone | 14:02 | |
| brtknr | ubuntu@devstack-master:/opt/stack$ openstack trust create demo service-user --project demo --role member | 14:03 |
| brtknr | You are not authorized to perform the requested action: identity:create_trust. (HTTP 403) (Request-ID: req-6d767713-0ae2-46ac-9c8d-ddedb5148cbf) | 14:03 |
| brtknr | ubuntu@devstack-master:/opt/stack$ openstack trust create demo service-user --project demo --role member | 14:03 |
| brtknr | You are not authorized to perform the requested action: identity:create_trust. (HTTP 403) (Request-ID: req-6d767713-0ae2-46ac-9c8d-ddedb5148cbf) | 14:03 |
| brtknr | Is anyone able to help me debug why I cant create trust as non-admin user | 14:03 |
| *** shyamb has quit IRC | 14:17 | |
| *** dave-mccowan has joined #openstack-keystone | 14:18 | |
| *** dave-mccowan has quit IRC | 14:41 | |
| yan0s | "identity:create_trust": "user_id:%(trust.trustor_user_id)s", | 14:45 |
| yan0s | brtknr: this is the default policy for creating trust in keystone policy.json | 14:46 |
| yan0s | brtknr: not sure how to translate it | 14:47 |
| yan0s | brtknr: but setting it to : "identity:create_trust": "", | 14:48 |
| yan0s | brtknr: should allow everyone to create trusts regardless of their role | 14:48 |
| brtknr | yan0s: is there any downside to allowing this? | 14:49 |
| yan0s | also you may need to restart apache2 service to apply the rule | 14:49 |
| yan0s | not sure about downsides.. | 14:50 |
| brtknr | yan0s: what does "user_id:%(trust.trustor_user_id)s" even mean? | 14:52 |
| brtknr | who is currently allowed to create trust? | 14:52 |
| brtknr | i mean, who is it currently allowing to create trust? | 14:52 |
| cmurphy | don't disable the create_trust policy, that would allow anyone to create trusts for anyone | 14:53 |
| cmurphy | the default policy is supposed to only allow a user to create a trust for themselves | 14:53 |
| cmurphy | but the client has a strange issue with names because looking up a user by name requires admin privileges | 14:53 |
| yan0s | brtknr: I don't know what this means, if someone can explain this I would be very interested to know too | 14:54 |
| cmurphy | so it returns a confusing forbidden error | 14:54 |
| cmurphy | the way around it is to use user IDs and not names | 14:54 |
| yan0s | cmurphy: can you explain the "user_id" and "%(trust.trustor_user_id)s" parts of the filter? | 14:55 |
| yan0s | cmurphy: I really need to be able to know what filters I can use in the policy files | 14:56 |
| *** markvoelker has joined #openstack-keystone | 14:56 | |
| cmurphy | yan0s: it looks at the token payload for user_id and matches the value to the trustor_user_id value in the trust body | 14:57 |
| yan0s | cmurphy: what is the trust body? | 14:58 |
| brtknr | cmurphy: great! that finally worked, using id istead of username | 14:58 |
| cmurphy | yan0s: the json you use to create the trust | 14:58 |
| openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Replace 'tenant_id' with 'project_id' https://review.openstack.org/631706 | 14:58 |
| cmurphy | brtknr: great | 14:58 |
| brtknr | so the trustor gives control of their account to the trustee correct? | 14:59 |
| brtknr | what is impersonation? | 14:59 |
| cmurphy | no not of their account, just their role on the project | 14:59 |
| *** mvkr has quit IRC | 15:00 | |
| yan0s | cmurphy: so all the variables I can use in a filter exist in the token payload? | 15:00 |
| brtknr | cmurphy: oops thats what i meant | 15:00 |
| brtknr | cmurphy: what is the difference between having impersonation on and off, its not very well documented afaics | 15:01 |
| cmurphy | impersonation i think means that it will use the trustor's name/id for things so for auditing it looks like they themselves were acting, nonimpersonation means the other user has permission to do things but they're stilling their own name | 15:01 |
| cmurphy | i think, i'm a little fuzzy on that part | 15:01 |
| brtknr | --impersonate Tokens generated from the trust will represent | 15:01 |
| brtknr | <trustor> (defaults to False) | 15:01 |
| brtknr | as opposed to represting someone else? | 15:02 |
| cmurphy | yan0s: i think so yes | 15:02 |
| cmurphy | brtknr: yes as opposed to representing the trustee | 15:02 |
| yan0s | cmurphy: thanks! | 15:02 |
| brtknr | interesting, so its main implication is for auditing | 15:03 |
| brtknr | sounds like the desired behaviour is the default behaviour | 15:03 |
| brtknr | unless the trustee account is ephemeral | 15:03 |
| vishakha | cmurphy: hey, By any chance you have time we can discuss over https://review.openstack.org/#/c/588211/ | 15:06 |
| cmurphy | vishakha: i need to take a closer look at that, not sure what to suggest offhand | 15:09 |
| cmurphy | it's on my list for when I have time | 15:10 |
| vishakha | surr thanks | 15:10 |
| vishakha | Also pl have a look over https://review.openstack.org/#/c/631706/ will not take much time | 15:11 |
| *** mvkr has joined #openstack-keystone | 15:13 | |
| gagehugo | o/ | 15:26 |
| *** markvoelker has quit IRC | 15:29 | |
| brtknr | vishakha: +1 | 15:46 |
| *** jmlowe has quit IRC | 15:49 | |
| *** jmlowe has joined #openstack-keystone | 16:04 | |
| *** yan0s has quit IRC | 16:07 | |
| brtknr | cmurphy: is there a way to delege trust without specifying the --role arg? | 16:26 |
| brtknr | i want to delegate all roles | 16:26 |
| *** markvoelker has joined #openstack-keystone | 16:27 | |
| brtknr | but I dont know what roles I'm assigned to as a non-admin user | 16:27 |
| lbragstad | brtknr as a user, you can validate your token and see the role assignment you have associate to that token | 16:31 |
| brtknr | how? | 16:31 |
| *** imacdonn has quit IRC | 16:31 | |
| brtknr | lbragstad: openstack token issue? | 16:32 |
| lbragstad | brtknr yeah - that will issue you a token | 16:37 |
| lbragstad | if you use openstack token issue --debug, osc will print the actual response and request so you get the entire token body | 16:37 |
| lbragstad | which will contain the roles you have associated to that token | 16:37 |
| *** imus has joined #openstack-keystone | 16:41 | |
| kmalloc | o/ | 16:46 |
| kmalloc | mornin | 16:46 |
| brtknr | lbragstad: excellent! that worked like a treat!! | 16:46 |
| lbragstad | good deal | 16:47 |
| lbragstad | o/ kmalloc | 16:47 |
| *** spsurya has quit IRC | 16:54 | |
| *** markvoelker has quit IRC | 17:00 | |
| *** takamatsu has joined #openstack-keystone | 17:14 | |
| *** gyee has joined #openstack-keystone | 17:19 | |
| *** dave-mccowan has joined #openstack-keystone | 18:25 | |
| *** mvkr has quit IRC | 18:35 | |
| *** markvoelker has joined #openstack-keystone | 19:27 | |
| *** pcaruana has quit IRC | 19:30 | |
| *** sapd1 has joined #openstack-keystone | 19:42 | |
| *** sapd1 has quit IRC | 19:48 | |
| kmalloc | hm. | 19:52 |
| *** markvoelker has quit IRC | 20:00 | |
| *** jmlowe has quit IRC | 20:04 | |
| *** awalende has joined #openstack-keystone | 20:16 | |
| *** awalende has quit IRC | 20:20 | |
| *** jmlowe has joined #openstack-keystone | 20:24 | |
| *** markvoelker has joined #openstack-keystone | 20:57 | |
| *** xek_ has quit IRC | 21:19 | |
| *** xek has joined #openstack-keystone | 21:19 | |
| *** markvoelker has quit IRC | 21:30 | |
| openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add configuration options for JWS provider https://review.openstack.org/628676 | 21:33 |
| openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add keystone-manage create_jws_keypair functionality https://review.openstack.org/615315 | 21:33 |
| openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add test fixture for the JWS key repository https://review.openstack.org/614547 | 21:33 |
| openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add PyJWT as a requirement https://review.openstack.org/614548 | 21:33 |
| openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement JWS token provider https://review.openstack.org/614549 | 21:33 |
| openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add JWS token provider documentation https://review.openstack.org/633831 | 21:33 |
| openstackgerrit | Islam Musleh proposed openstack/keystone master: Converting the API tests to use flask's test_client https://review.openstack.org/630301 | 21:40 |
| *** mchlumsky has quit IRC | 21:51 | |
| *** markvoelker has joined #openstack-keystone | 22:27 | |
| *** erus1 has joined #openstack-keystone | 22:38 | |
| *** markvoelker has quit IRC | 22:41 | |
| *** tkajinam has joined #openstack-keystone | 22:56 | |
| *** whoami-rajat has quit IRC | 23:00 | |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!