*** jamesmcarthur has quit IRC | 00:00 | |
*** jamesmcarthur has joined #openstack-keystone | 00:00 | |
*** jamesmcarthur has quit IRC | 00:43 | |
*** jamesmcarthur has joined #openstack-keystone | 00:44 | |
*** jamesmcarthur has quit IRC | 00:49 | |
*** jamesmcarthur has joined #openstack-keystone | 00:53 | |
*** jamesmcarthur has quit IRC | 01:15 | |
*** jamesmcarthur has joined #openstack-keystone | 01:43 | |
*** markvoelker has joined #openstack-keystone | 02:29 | |
*** rcernin has quit IRC | 02:45 | |
*** rcernin has joined #openstack-keystone | 02:47 | |
*** jamesmcarthur has quit IRC | 03:21 | |
*** jamesmcarthur has joined #openstack-keystone | 03:22 | |
*** jamesmcarthur has quit IRC | 03:27 | |
*** jamesmcarthur has joined #openstack-keystone | 03:39 | |
*** jamesmcarthur has quit IRC | 03:58 | |
*** jamesmcarthur has joined #openstack-keystone | 03:59 | |
*** jamesmcarthur has quit IRC | 04:04 | |
*** jamesmcarthur has joined #openstack-keystone | 04:07 | |
*** jamesmcarthur has quit IRC | 04:40 | |
*** jamesmcarthur has joined #openstack-keystone | 05:07 | |
*** jamesmcarthur has quit IRC | 05:14 | |
*** brtknr has quit IRC | 05:17 | |
*** brtknr has joined #openstack-keystone | 05:19 | |
*** whoami-rajat has joined #openstack-keystone | 05:22 | |
*** jaosorior has joined #openstack-keystone | 05:26 | |
*** jamesmcarthur has joined #openstack-keystone | 05:40 | |
*** jamesmcarthur has quit IRC | 05:44 | |
*** jamesmcarthur has joined #openstack-keystone | 06:20 | |
*** jamesmcarthur has quit IRC | 06:25 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add openstack_groups to assertion https://review.opendev.org/588211 | 06:59 |
---|---|---|
*** tesseract has joined #openstack-keystone | 07:08 | |
*** rcernin has quit IRC | 07:11 | |
*** jamesmcarthur has joined #openstack-keystone | 07:21 | |
*** jamesmcarthur has quit IRC | 07:25 | |
*** pcaruana has joined #openstack-keystone | 07:31 | |
*** dancn has joined #openstack-keystone | 07:46 | |
*** jamesmcarthur has joined #openstack-keystone | 07:57 | |
*** jaosorior has quit IRC | 07:59 | |
*** jamesmcarthur has quit IRC | 08:02 | |
*** ivve has joined #openstack-keystone | 08:15 | |
*** tkajinam has quit IRC | 08:30 | |
*** brtknr has quit IRC | 08:33 | |
*** brtknr has joined #openstack-keystone | 08:35 | |
*** jaosorior has joined #openstack-keystone | 08:46 | |
*** tesseract has quit IRC | 08:58 | |
*** jamesmcarthur has joined #openstack-keystone | 08:59 | |
*** jamesmcarthur has quit IRC | 09:03 | |
*** stingrayza_ is now known as stingrayza | 09:10 | |
*** trident has quit IRC | 09:16 | |
*** trident has joined #openstack-keystone | 09:17 | |
*** tesseract has joined #openstack-keystone | 09:20 | |
*** baffle has quit IRC | 09:22 | |
*** altlogbot_2 has quit IRC | 09:24 | |
*** altlogbot_2 has joined #openstack-keystone | 09:25 | |
*** baffle has joined #openstack-keystone | 09:30 | |
*** jamesmcarthur has joined #openstack-keystone | 09:38 | |
*** jamesmcarthur has quit IRC | 09:43 | |
*** jaosorior has quit IRC | 10:23 | |
*** brtknr has quit IRC | 10:30 | |
*** brtknr has joined #openstack-keystone | 10:32 | |
*** brtknr has quit IRC | 10:34 | |
*** brtknr has joined #openstack-keystone | 10:35 | |
*** brtknr has quit IRC | 10:36 | |
*** jawad_axd has joined #openstack-keystone | 10:38 | |
*** jamesmcarthur has joined #openstack-keystone | 10:39 | |
*** jamesmcarthur has quit IRC | 10:44 | |
*** brtknr has joined #openstack-keystone | 10:45 | |
*** brtknr has quit IRC | 11:04 | |
*** brtknr has joined #openstack-keystone | 11:05 | |
*** brtknr has quit IRC | 11:06 | |
*** brtknr has joined #openstack-keystone | 11:06 | |
*** brtknr has quit IRC | 11:07 | |
openstackgerrit | Dmitry Tantsur proposed openstack/keystoneauth master: Allow requesting fixed retry delay instead of exponential https://review.opendev.org/672930 | 11:07 |
*** brtknr has joined #openstack-keystone | 11:08 | |
*** jamesmcarthur has joined #openstack-keystone | 11:11 | |
*** jamesmcarthur has quit IRC | 11:16 | |
*** brtknr has quit IRC | 11:20 | |
*** brtknr has joined #openstack-keystone | 11:21 | |
*** brtknr has quit IRC | 11:22 | |
*** brtknr has joined #openstack-keystone | 11:23 | |
*** brtknr has quit IRC | 11:23 | |
*** brtknr has joined #openstack-keystone | 11:24 | |
*** brtknr has quit IRC | 11:24 | |
*** brtknr has joined #openstack-keystone | 11:25 | |
*** jamesmcarthur has joined #openstack-keystone | 11:27 | |
*** dancn has quit IRC | 11:27 | |
vishakha | cmorpheus: Could you help for #link https://review.opendev.org/#/c/669331/ shade support for app creds. Facing issue while assigning the user.id value in base_path #link ]https://www.paste.org/99742 | 11:30 |
*** jaosorior has joined #openstack-keystone | 11:34 | |
*** kplant has joined #openstack-keystone | 11:36 | |
*** jamesmcarthur has quit IRC | 11:36 | |
*** jamesmcarthur has joined #openstack-keystone | 11:37 | |
mordred | vishakha: left of a comment on what I Think it is | 11:51 |
*** raildo has joined #openstack-keystone | 11:55 | |
*** jamesmcarthur has quit IRC | 12:05 | |
*** raildo_ has joined #openstack-keystone | 12:06 | |
*** raildo has quit IRC | 12:07 | |
*** dancn has joined #openstack-keystone | 12:09 | |
*** mvkr has quit IRC | 12:22 | |
*** raildo_ has quit IRC | 12:27 | |
*** raildo has joined #openstack-keystone | 12:27 | |
*** ivve has quit IRC | 12:34 | |
*** jamesmcarthur has joined #openstack-keystone | 12:49 | |
*** jroll has quit IRC | 13:07 | |
*** jawad_axd has quit IRC | 13:08 | |
*** jroll has joined #openstack-keystone | 13:08 | |
*** ivve has joined #openstack-keystone | 13:11 | |
*** jmlowe has joined #openstack-keystone | 13:13 | |
*** ivve has quit IRC | 13:16 | |
*** mvkr has joined #openstack-keystone | 13:20 | |
jdennis | kplant, cmorpheus: I've been on vacation and just got back, I see you're having some problems with mellon, I got lost in the earlier discussions, if are still having problems or a specific question ping me. | 13:21 |
kplant | jdennis: i was ultimately able to get it working with keycloak as an idp | 13:23 |
kplant | i had to change in https://docs.openstack.org/keystone/latest/admin/federation/mellon.html: MellonEndPointPath to MellonEndpointPath /v3/OS-FEDERATION/identity_providers/keycloak/protocols/saml2/auth/mellon | 13:24 |
kplant | that matched what the mellon script populated in the metadata.xml | 13:24 |
jdennis | kplant: The mellon metdatadata and the MellonEndpointPath *must* be in sync, this is discussed here in the user guide: https://github.com/Uninett/mod_auth_mellon/blob/master/doc/user_guide/mellon_user_guide.adoc#105-incorrect-mellonendpointpath | 13:29 |
kplant | right, that's why i had to change it | 13:31 |
jdennis | kplant, cmorpheus: the upstream version of the Mellon User Guide has all sorts of useful information including debugging tips, I see Colleen pointed you to a version of the doc in my private area, but that's old, use this upstream version instead: https://github.com/Uninett/mod_auth_mellon/blob/master/doc/user_guide/mellon_user_guide.adoc | 13:31 |
jdennis | kplant: glad you got it working | 13:32 |
kplant | yeah the mellon documentation was super helpful | 13:32 |
kplant | thank you | 13:32 |
jdennis | kplant: sometimes turning on the "diagnostics" logging in mellon can be a real help as well. | 13:33 |
*** mvkr has quit IRC | 13:34 | |
*** whoami-rajat has quit IRC | 13:42 | |
*** cmorpheus is now known as cmurphy | 13:46 | |
*** mvkr has joined #openstack-keystone | 13:47 | |
cmurphy | thanks jdennis | 13:48 |
cmurphy | vishakha: i can try to help later today | 13:48 |
*** dklyle has quit IRC | 14:00 | |
*** dklyle has joined #openstack-keystone | 14:00 | |
*** dancn has quit IRC | 14:03 | |
*** jmlowe has quit IRC | 14:08 | |
*** dancn has joined #openstack-keystone | 14:11 | |
kplant | cmurphy: i'm running through configuring mellon avain with /v3/mellon as the endpoint and just supplying that to the script instead, that should be much cleaner if it works | 14:20 |
kplant | again* | 14:21 |
*** ivve has joined #openstack-keystone | 14:55 | |
*** joshualyle has quit IRC | 15:06 | |
*** jamesmcarthur has quit IRC | 15:16 | |
*** jamesmcarthur_ has joined #openstack-keystone | 15:16 | |
*** gyee has joined #openstack-keystone | 15:39 | |
*** mvkr has quit IRC | 16:01 | |
*** vishwanathj has quit IRC | 16:02 | |
*** dancn has quit IRC | 16:09 | |
*** vishwanathj has joined #openstack-keystone | 16:19 | |
*** ivve has quit IRC | 16:21 | |
*** joshualyle has joined #openstack-keystone | 16:26 | |
*** tesseract has quit IRC | 16:28 | |
*** joshualyle has quit IRC | 16:30 | |
*** ivve has joined #openstack-keystone | 16:52 | |
*** ivve has quit IRC | 16:59 | |
*** xek has quit IRC | 17:07 | |
*** xek has joined #openstack-keystone | 17:08 | |
*** vishwanathj has quit IRC | 17:21 | |
*** jamesmcarthur_ has quit IRC | 17:24 | |
*** dancn has joined #openstack-keystone | 17:35 | |
*** vishwanathj has joined #openstack-keystone | 17:39 | |
*** whoami-rajat has joined #openstack-keystone | 17:39 | |
*** dancn has quit IRC | 17:40 | |
*** jdwidari has joined #openstack-keystone | 17:42 | |
*** trident has quit IRC | 17:47 | |
*** dancn has joined #openstack-keystone | 17:47 | |
*** trident has joined #openstack-keystone | 17:51 | |
*** jamesmcarthur has joined #openstack-keystone | 18:12 | |
kplant | is there a way to set the relay_state_prefix for an SP? trying to work around the bug here: https://bugs.launchpad.net/keystone/+bug/1794726 | 18:27 |
openstack | Launchpad bug 1794726 in OpenStack Identity (keystone) "Keystone as a SAML IdP does not work when mod_auth_mellon is used as the SP" [Medium,Triaged] | 18:27 |
kplant | i can see relate_state_prefix as 'ss:mem:' but can't figure out how to change it | 18:27 |
cmurphy | kplant: that bug should have been fixed in at least some versions of the mellon package, i hadn't closed it because i hadn't verified where it was fixed | 18:31 |
kplant | i'm running into the same exact behavior detailed in that bug | 18:32 |
kplant | am on centos though, so the version of mellon might be ancient | 18:32 |
*** dancn has quit IRC | 18:32 | |
*** joshualyle has joined #openstack-keystone | 18:49 | |
*** jamesmcarthur has quit IRC | 18:52 | |
*** jamesmcarthur has joined #openstack-keystone | 19:04 | |
knikolla | cmurphy: the part of the bug which has been fixed is the way that mellon interprets the signed xml | 19:14 |
knikolla | afaik the relay-state part still applies | 19:15 |
kplant | knikolla: do you know what the relay prefix should be? i've tried http://nameofsp but still not working | 19:16 |
kplant | i'm just hand editing it in mariadb | 19:16 |
knikolla | i only remember what i wrote in the bug comment | 19:18 |
knikolla | it's been a while | 19:18 |
kplant | i think i'm going to have to deal with rebuilding kolla containers to use shibboleth instead, mellon is way too hacky for production | 19:22 |
*** kplant has quit IRC | 19:42 | |
*** jamesmcarthur has quit IRC | 19:54 | |
*** jmlowe has joined #openstack-keystone | 19:57 | |
*** jamesmcarthur has joined #openstack-keystone | 19:58 | |
*** vishwanathj has quit IRC | 19:58 | |
*** jamesmcarthur has quit IRC | 20:03 | |
*** vishwanathj has joined #openstack-keystone | 20:06 | |
*** jmlowe has quit IRC | 20:14 | |
*** jamesmcarthur has joined #openstack-keystone | 20:25 | |
*** jamesmcarthur has quit IRC | 20:31 | |
*** kplant has joined #openstack-keystone | 20:37 | |
*** whoami-rajat has quit IRC | 20:39 | |
*** xek has quit IRC | 20:43 | |
*** trident has quit IRC | 20:49 | |
*** trident has joined #openstack-keystone | 20:52 | |
*** jamesmcarthur has joined #openstack-keystone | 20:59 | |
*** jamesmcarthur has quit IRC | 21:03 | |
*** jdwidari has quit IRC | 21:29 | |
*** jamesmcarthur has joined #openstack-keystone | 21:39 | |
*** jamesmcarthur has quit IRC | 21:40 | |
*** jamesmcarthur_ has joined #openstack-keystone | 21:40 | |
*** mvkr has joined #openstack-keystone | 22:06 | |
*** tkajinam has joined #openstack-keystone | 22:54 | |
*** rcernin has joined #openstack-keystone | 23:02 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!