| *** jamesmcarthur has quit IRC | 00:00 | |
| *** jamesmcarthur has joined #openstack-keystone | 00:00 | |
| *** jamesmcarthur has quit IRC | 00:43 | |
| *** jamesmcarthur has joined #openstack-keystone | 00:44 | |
| *** jamesmcarthur has quit IRC | 00:49 | |
| *** jamesmcarthur has joined #openstack-keystone | 00:53 | |
| *** jamesmcarthur has quit IRC | 01:15 | |
| *** jamesmcarthur has joined #openstack-keystone | 01:43 | |
| *** markvoelker has joined #openstack-keystone | 02:29 | |
| *** rcernin has quit IRC | 02:45 | |
| *** rcernin has joined #openstack-keystone | 02:47 | |
| *** jamesmcarthur has quit IRC | 03:21 | |
| *** jamesmcarthur has joined #openstack-keystone | 03:22 | |
| *** jamesmcarthur has quit IRC | 03:27 | |
| *** jamesmcarthur has joined #openstack-keystone | 03:39 | |
| *** jamesmcarthur has quit IRC | 03:58 | |
| *** jamesmcarthur has joined #openstack-keystone | 03:59 | |
| *** jamesmcarthur has quit IRC | 04:04 | |
| *** jamesmcarthur has joined #openstack-keystone | 04:07 | |
| *** jamesmcarthur has quit IRC | 04:40 | |
| *** jamesmcarthur has joined #openstack-keystone | 05:07 | |
| *** jamesmcarthur has quit IRC | 05:14 | |
| *** brtknr has quit IRC | 05:17 | |
| *** brtknr has joined #openstack-keystone | 05:19 | |
| *** whoami-rajat has joined #openstack-keystone | 05:22 | |
| *** jaosorior has joined #openstack-keystone | 05:26 | |
| *** jamesmcarthur has joined #openstack-keystone | 05:40 | |
| *** jamesmcarthur has quit IRC | 05:44 | |
| *** jamesmcarthur has joined #openstack-keystone | 06:20 | |
| *** jamesmcarthur has quit IRC | 06:25 | |
| openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add openstack_groups to assertion https://review.opendev.org/588211 | 06:59 |
|---|---|---|
| *** tesseract has joined #openstack-keystone | 07:08 | |
| *** rcernin has quit IRC | 07:11 | |
| *** jamesmcarthur has joined #openstack-keystone | 07:21 | |
| *** jamesmcarthur has quit IRC | 07:25 | |
| *** pcaruana has joined #openstack-keystone | 07:31 | |
| *** dancn has joined #openstack-keystone | 07:46 | |
| *** jamesmcarthur has joined #openstack-keystone | 07:57 | |
| *** jaosorior has quit IRC | 07:59 | |
| *** jamesmcarthur has quit IRC | 08:02 | |
| *** ivve has joined #openstack-keystone | 08:15 | |
| *** tkajinam has quit IRC | 08:30 | |
| *** brtknr has quit IRC | 08:33 | |
| *** brtknr has joined #openstack-keystone | 08:35 | |
| *** jaosorior has joined #openstack-keystone | 08:46 | |
| *** tesseract has quit IRC | 08:58 | |
| *** jamesmcarthur has joined #openstack-keystone | 08:59 | |
| *** jamesmcarthur has quit IRC | 09:03 | |
| *** stingrayza_ is now known as stingrayza | 09:10 | |
| *** trident has quit IRC | 09:16 | |
| *** trident has joined #openstack-keystone | 09:17 | |
| *** tesseract has joined #openstack-keystone | 09:20 | |
| *** baffle has quit IRC | 09:22 | |
| *** altlogbot_2 has quit IRC | 09:24 | |
| *** altlogbot_2 has joined #openstack-keystone | 09:25 | |
| *** baffle has joined #openstack-keystone | 09:30 | |
| *** jamesmcarthur has joined #openstack-keystone | 09:38 | |
| *** jamesmcarthur has quit IRC | 09:43 | |
| *** jaosorior has quit IRC | 10:23 | |
| *** brtknr has quit IRC | 10:30 | |
| *** brtknr has joined #openstack-keystone | 10:32 | |
| *** brtknr has quit IRC | 10:34 | |
| *** brtknr has joined #openstack-keystone | 10:35 | |
| *** brtknr has quit IRC | 10:36 | |
| *** jawad_axd has joined #openstack-keystone | 10:38 | |
| *** jamesmcarthur has joined #openstack-keystone | 10:39 | |
| *** jamesmcarthur has quit IRC | 10:44 | |
| *** brtknr has joined #openstack-keystone | 10:45 | |
| *** brtknr has quit IRC | 11:04 | |
| *** brtknr has joined #openstack-keystone | 11:05 | |
| *** brtknr has quit IRC | 11:06 | |
| *** brtknr has joined #openstack-keystone | 11:06 | |
| *** brtknr has quit IRC | 11:07 | |
| openstackgerrit | Dmitry Tantsur proposed openstack/keystoneauth master: Allow requesting fixed retry delay instead of exponential https://review.opendev.org/672930 | 11:07 |
| *** brtknr has joined #openstack-keystone | 11:08 | |
| *** jamesmcarthur has joined #openstack-keystone | 11:11 | |
| *** jamesmcarthur has quit IRC | 11:16 | |
| *** brtknr has quit IRC | 11:20 | |
| *** brtknr has joined #openstack-keystone | 11:21 | |
| *** brtknr has quit IRC | 11:22 | |
| *** brtknr has joined #openstack-keystone | 11:23 | |
| *** brtknr has quit IRC | 11:23 | |
| *** brtknr has joined #openstack-keystone | 11:24 | |
| *** brtknr has quit IRC | 11:24 | |
| *** brtknr has joined #openstack-keystone | 11:25 | |
| *** jamesmcarthur has joined #openstack-keystone | 11:27 | |
| *** dancn has quit IRC | 11:27 | |
| vishakha | cmorpheus: Could you help for #link https://review.opendev.org/#/c/669331/ shade support for app creds. Facing issue while assigning the user.id value in base_path #link ]https://www.paste.org/99742 | 11:30 |
| *** jaosorior has joined #openstack-keystone | 11:34 | |
| *** kplant has joined #openstack-keystone | 11:36 | |
| *** jamesmcarthur has quit IRC | 11:36 | |
| *** jamesmcarthur has joined #openstack-keystone | 11:37 | |
| mordred | vishakha: left of a comment on what I Think it is | 11:51 |
| *** raildo has joined #openstack-keystone | 11:55 | |
| *** jamesmcarthur has quit IRC | 12:05 | |
| *** raildo_ has joined #openstack-keystone | 12:06 | |
| *** raildo has quit IRC | 12:07 | |
| *** dancn has joined #openstack-keystone | 12:09 | |
| *** mvkr has quit IRC | 12:22 | |
| *** raildo_ has quit IRC | 12:27 | |
| *** raildo has joined #openstack-keystone | 12:27 | |
| *** ivve has quit IRC | 12:34 | |
| *** jamesmcarthur has joined #openstack-keystone | 12:49 | |
| *** jroll has quit IRC | 13:07 | |
| *** jawad_axd has quit IRC | 13:08 | |
| *** jroll has joined #openstack-keystone | 13:08 | |
| *** ivve has joined #openstack-keystone | 13:11 | |
| *** jmlowe has joined #openstack-keystone | 13:13 | |
| *** ivve has quit IRC | 13:16 | |
| *** mvkr has joined #openstack-keystone | 13:20 | |
| jdennis | kplant, cmorpheus: I've been on vacation and just got back, I see you're having some problems with mellon, I got lost in the earlier discussions, if are still having problems or a specific question ping me. | 13:21 |
| kplant | jdennis: i was ultimately able to get it working with keycloak as an idp | 13:23 |
| kplant | i had to change in https://docs.openstack.org/keystone/latest/admin/federation/mellon.html: MellonEndPointPath to MellonEndpointPath /v3/OS-FEDERATION/identity_providers/keycloak/protocols/saml2/auth/mellon | 13:24 |
| kplant | that matched what the mellon script populated in the metadata.xml | 13:24 |
| jdennis | kplant: The mellon metdatadata and the MellonEndpointPath *must* be in sync, this is discussed here in the user guide: https://github.com/Uninett/mod_auth_mellon/blob/master/doc/user_guide/mellon_user_guide.adoc#105-incorrect-mellonendpointpath | 13:29 |
| kplant | right, that's why i had to change it | 13:31 |
| jdennis | kplant, cmorpheus: the upstream version of the Mellon User Guide has all sorts of useful information including debugging tips, I see Colleen pointed you to a version of the doc in my private area, but that's old, use this upstream version instead: https://github.com/Uninett/mod_auth_mellon/blob/master/doc/user_guide/mellon_user_guide.adoc | 13:31 |
| jdennis | kplant: glad you got it working | 13:32 |
| kplant | yeah the mellon documentation was super helpful | 13:32 |
| kplant | thank you | 13:32 |
| jdennis | kplant: sometimes turning on the "diagnostics" logging in mellon can be a real help as well. | 13:33 |
| *** mvkr has quit IRC | 13:34 | |
| *** whoami-rajat has quit IRC | 13:42 | |
| *** cmorpheus is now known as cmurphy | 13:46 | |
| *** mvkr has joined #openstack-keystone | 13:47 | |
| cmurphy | thanks jdennis | 13:48 |
| cmurphy | vishakha: i can try to help later today | 13:48 |
| *** dklyle has quit IRC | 14:00 | |
| *** dklyle has joined #openstack-keystone | 14:00 | |
| *** dancn has quit IRC | 14:03 | |
| *** jmlowe has quit IRC | 14:08 | |
| *** dancn has joined #openstack-keystone | 14:11 | |
| kplant | cmurphy: i'm running through configuring mellon avain with /v3/mellon as the endpoint and just supplying that to the script instead, that should be much cleaner if it works | 14:20 |
| kplant | again* | 14:21 |
| *** ivve has joined #openstack-keystone | 14:55 | |
| *** joshualyle has quit IRC | 15:06 | |
| *** jamesmcarthur has quit IRC | 15:16 | |
| *** jamesmcarthur_ has joined #openstack-keystone | 15:16 | |
| *** gyee has joined #openstack-keystone | 15:39 | |
| *** mvkr has quit IRC | 16:01 | |
| *** vishwanathj has quit IRC | 16:02 | |
| *** dancn has quit IRC | 16:09 | |
| *** vishwanathj has joined #openstack-keystone | 16:19 | |
| *** ivve has quit IRC | 16:21 | |
| *** joshualyle has joined #openstack-keystone | 16:26 | |
| *** tesseract has quit IRC | 16:28 | |
| *** joshualyle has quit IRC | 16:30 | |
| *** ivve has joined #openstack-keystone | 16:52 | |
| *** ivve has quit IRC | 16:59 | |
| *** xek has quit IRC | 17:07 | |
| *** xek has joined #openstack-keystone | 17:08 | |
| *** vishwanathj has quit IRC | 17:21 | |
| *** jamesmcarthur_ has quit IRC | 17:24 | |
| *** dancn has joined #openstack-keystone | 17:35 | |
| *** vishwanathj has joined #openstack-keystone | 17:39 | |
| *** whoami-rajat has joined #openstack-keystone | 17:39 | |
| *** dancn has quit IRC | 17:40 | |
| *** jdwidari has joined #openstack-keystone | 17:42 | |
| *** trident has quit IRC | 17:47 | |
| *** dancn has joined #openstack-keystone | 17:47 | |
| *** trident has joined #openstack-keystone | 17:51 | |
| *** jamesmcarthur has joined #openstack-keystone | 18:12 | |
| kplant | is there a way to set the relay_state_prefix for an SP? trying to work around the bug here: https://bugs.launchpad.net/keystone/+bug/1794726 | 18:27 |
| openstack | Launchpad bug 1794726 in OpenStack Identity (keystone) "Keystone as a SAML IdP does not work when mod_auth_mellon is used as the SP" [Medium,Triaged] | 18:27 |
| kplant | i can see relate_state_prefix as 'ss:mem:' but can't figure out how to change it | 18:27 |
| cmurphy | kplant: that bug should have been fixed in at least some versions of the mellon package, i hadn't closed it because i hadn't verified where it was fixed | 18:31 |
| kplant | i'm running into the same exact behavior detailed in that bug | 18:32 |
| kplant | am on centos though, so the version of mellon might be ancient | 18:32 |
| *** dancn has quit IRC | 18:32 | |
| *** joshualyle has joined #openstack-keystone | 18:49 | |
| *** jamesmcarthur has quit IRC | 18:52 | |
| *** jamesmcarthur has joined #openstack-keystone | 19:04 | |
| knikolla | cmurphy: the part of the bug which has been fixed is the way that mellon interprets the signed xml | 19:14 |
| knikolla | afaik the relay-state part still applies | 19:15 |
| kplant | knikolla: do you know what the relay prefix should be? i've tried http://nameofsp but still not working | 19:16 |
| kplant | i'm just hand editing it in mariadb | 19:16 |
| knikolla | i only remember what i wrote in the bug comment | 19:18 |
| knikolla | it's been a while | 19:18 |
| kplant | i think i'm going to have to deal with rebuilding kolla containers to use shibboleth instead, mellon is way too hacky for production | 19:22 |
| *** kplant has quit IRC | 19:42 | |
| *** jamesmcarthur has quit IRC | 19:54 | |
| *** jmlowe has joined #openstack-keystone | 19:57 | |
| *** jamesmcarthur has joined #openstack-keystone | 19:58 | |
| *** vishwanathj has quit IRC | 19:58 | |
| *** jamesmcarthur has quit IRC | 20:03 | |
| *** vishwanathj has joined #openstack-keystone | 20:06 | |
| *** jmlowe has quit IRC | 20:14 | |
| *** jamesmcarthur has joined #openstack-keystone | 20:25 | |
| *** jamesmcarthur has quit IRC | 20:31 | |
| *** kplant has joined #openstack-keystone | 20:37 | |
| *** whoami-rajat has quit IRC | 20:39 | |
| *** xek has quit IRC | 20:43 | |
| *** trident has quit IRC | 20:49 | |
| *** trident has joined #openstack-keystone | 20:52 | |
| *** jamesmcarthur has joined #openstack-keystone | 20:59 | |
| *** jamesmcarthur has quit IRC | 21:03 | |
| *** jdwidari has quit IRC | 21:29 | |
| *** jamesmcarthur has joined #openstack-keystone | 21:39 | |
| *** jamesmcarthur has quit IRC | 21:40 | |
| *** jamesmcarthur_ has joined #openstack-keystone | 21:40 | |
| *** mvkr has joined #openstack-keystone | 22:06 | |
| *** tkajinam has joined #openstack-keystone | 22:54 | |
| *** rcernin has joined #openstack-keystone | 23:02 | |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!