| *** ivve has quit IRC | 01:23 | |
| *** markvoelker has joined #openstack-keystone | 01:40 | |
| *** markvoelker has quit IRC | 01:45 | |
| *** markvoelker has joined #openstack-keystone | 01:50 | |
| *** markvoelker has quit IRC | 02:00 | |
| *** markvoelker has joined #openstack-keystone | 02:01 | |
| *** markvoelker has quit IRC | 02:05 | |
| *** jamesmcarthur has joined #openstack-keystone | 02:06 | |
| *** Dinesh_Bhor has quit IRC | 02:10 | |
| *** rcernin has quit IRC | 02:10 | |
| *** jamesmcarthur has quit IRC | 03:02 | |
| *** jamesmcarthur has joined #openstack-keystone | 03:03 | |
| *** jamesmcarthur has quit IRC | 03:03 | |
| *** jamesmcarthur has joined #openstack-keystone | 03:03 | |
| *** jamesmcarthur has quit IRC | 03:05 | |
| *** jamesmcarthur has joined #openstack-keystone | 03:06 | |
| *** jamesmcarthur has quit IRC | 03:11 | |
| *** Dinesh_Bhor has joined #openstack-keystone | 03:32 | |
| *** jamesmcarthur has joined #openstack-keystone | 03:36 | |
| *** jamesmcarthur has quit IRC | 03:42 | |
| *** jamesmcarthur has joined #openstack-keystone | 04:16 | |
| *** jamesmcarthur has quit IRC | 04:20 | |
| *** jawad_axd has joined #openstack-keystone | 04:44 | |
| *** jamesmcarthur has joined #openstack-keystone | 04:48 | |
| *** jamesmcarthur has quit IRC | 04:53 | |
| *** jawad_axd has quit IRC | 04:59 | |
| *** jamesmcarthur has joined #openstack-keystone | 05:49 | |
| *** jamesmcarthur has quit IRC | 05:54 | |
| *** jamesmcarthur has joined #openstack-keystone | 06:10 | |
| *** jawad_axd has joined #openstack-keystone | 06:12 | |
| openstackgerrit | zhangboye proposed openstack/keystone master: Stop testing python2.7 https://review.opendev.org/691595 | 06:13 |
|---|---|---|
| *** jawad_ax_ has joined #openstack-keystone | 06:14 | |
| openstackgerrit | haixin proposed openstack/ldappool master: Drop python2.7 support https://review.opendev.org/691597 | 06:15 |
| *** jawad_axd has quit IRC | 06:17 | |
| *** jawad_ax_ has quit IRC | 06:19 | |
| *** jawad_axd has joined #openstack-keystone | 06:20 | |
| *** Luzi has joined #openstack-keystone | 06:22 | |
| *** jawad_axd has quit IRC | 06:25 | |
| *** jawad_axd has joined #openstack-keystone | 06:25 | |
| *** jawad_axd has quit IRC | 06:29 | |
| *** jawad_axd has joined #openstack-keystone | 06:30 | |
| *** mloza has quit IRC | 06:30 | |
| *** jamesmcarthur has quit IRC | 06:44 | |
| *** dancn has joined #openstack-keystone | 06:49 | |
| *** jmlowe has quit IRC | 06:52 | |
| *** jmlowe has joined #openstack-keystone | 06:55 | |
| *** markvoelker has joined #openstack-keystone | 07:08 | |
| *** markvoelker has quit IRC | 07:12 | |
| *** jawad_axd has quit IRC | 07:39 | |
| *** jawad_axd has joined #openstack-keystone | 07:39 | |
| *** jamesmcarthur has joined #openstack-keystone | 07:47 | |
| *** jamesmcarthur has quit IRC | 07:51 | |
| *** tkajinam has quit IRC | 08:04 | |
| *** lifeless has joined #openstack-keystone | 08:05 | |
| *** tesseract has joined #openstack-keystone | 08:13 | |
| *** ivve has joined #openstack-keystone | 08:48 | |
| *** jamesmcarthur has joined #openstack-keystone | 08:48 | |
| *** jamesmcarthur has quit IRC | 08:53 | |
| *** trident has quit IRC | 09:01 | |
| *** markvoelker has joined #openstack-keystone | 09:08 | |
| *** trident has joined #openstack-keystone | 09:08 | |
| *** markvoelker has quit IRC | 09:13 | |
| *** jamesmcarthur has joined #openstack-keystone | 09:24 | |
| *** yankcrime has joined #openstack-keystone | 09:26 | |
| *** jamesmcarthur has quit IRC | 09:28 | |
| *** dancn has quit IRC | 09:34 | |
| *** dancn has joined #openstack-keystone | 09:40 | |
| *** dswebb has quit IRC | 09:47 | |
| *** dustinc is now known as dustinc_pto | 10:07 | |
| *** adriant has quit IRC | 10:23 | |
| *** jamesmcarthur has joined #openstack-keystone | 10:24 | |
| *** jaosorior has joined #openstack-keystone | 10:25 | |
| *** adriant has joined #openstack-keystone | 10:25 | |
| *** adriant has quit IRC | 10:27 | |
| *** jamesmcarthur has quit IRC | 10:29 | |
| *** dancn has quit IRC | 10:35 | |
| *** jaosorior has quit IRC | 10:36 | |
| *** dancn has joined #openstack-keystone | 10:40 | |
| *** dancn has quit IRC | 10:53 | |
| *** dancn has joined #openstack-keystone | 10:59 | |
| *** jamesmcarthur has joined #openstack-keystone | 11:25 | |
| *** jamesmcarthur has quit IRC | 11:30 | |
| *** jaosorior has joined #openstack-keystone | 11:34 | |
| *** dave-mccowan has joined #openstack-keystone | 11:57 | |
| *** markvoelker has joined #openstack-keystone | 12:06 | |
| *** jamesmcarthur has joined #openstack-keystone | 12:11 | |
| *** jaosorior has quit IRC | 12:26 | |
| *** jamesmcarthur has quit IRC | 12:29 | |
| *** jmlowe has quit IRC | 12:46 | |
| *** jamesmcarthur has joined #openstack-keystone | 12:46 | |
| *** jmlowe has joined #openstack-keystone | 13:02 | |
| *** dklyle has quit IRC | 13:12 | |
| *** prometheanfire has quit IRC | 13:18 | |
| *** prometheanfire has joined #openstack-keystone | 13:20 | |
| *** raildo has joined #openstack-keystone | 13:24 | |
| *** jaosorior has joined #openstack-keystone | 13:33 | |
| *** dancn has quit IRC | 13:51 | |
| *** dancn has joined #openstack-keystone | 13:56 | |
| *** mloza has joined #openstack-keystone | 14:01 | |
| *** jamesmcarthur has quit IRC | 14:06 | |
| *** dklyle has joined #openstack-keystone | 14:07 | |
| *** jdwidari has joined #openstack-keystone | 14:19 | |
| *** kimamisa has joined #openstack-keystone | 14:21 | |
| *** jamesmcarthur has joined #openstack-keystone | 14:28 | |
| *** jamesmcarthur has quit IRC | 14:34 | |
| *** Luzi has quit IRC | 14:41 | |
| *** jamesmcarthur has joined #openstack-keystone | 14:42 | |
| *** jawad_axd has quit IRC | 14:51 | |
| *** dklyle has quit IRC | 14:58 | |
| *** dklyle has joined #openstack-keystone | 14:59 | |
| *** markvoelker has quit IRC | 15:12 | |
| *** markvoelker has joined #openstack-keystone | 15:19 | |
| *** markvoelker has quit IRC | 15:19 | |
| *** markvoelker has joined #openstack-keystone | 15:19 | |
| *** markvoelker has quit IRC | 15:24 | |
| *** memo_ has joined #openstack-keystone | 15:25 | |
| *** gyee has joined #openstack-keystone | 15:25 | |
| *** memo_ has quit IRC | 15:30 | |
| *** memo_ has joined #openstack-keystone | 15:32 | |
| *** markvoelker has joined #openstack-keystone | 15:39 | |
| *** jmlowe has quit IRC | 15:48 | |
| *** tellesnobrega has joined #openstack-keystone | 15:49 | |
| tellesnobrega | lbragstad, hey, have you seen this error Conflict project: (pymysql.err.IntegrityError) (1062, u"Duplicate entry 'default-admin' for key 'ixu_project_name_domain_id'" while deploying openstack with tripleo standalone? | 15:50 |
| *** ivve has quit IRC | 16:04 | |
| *** jaosorior has quit IRC | 16:33 | |
| *** jamesmcarthur has quit IRC | 16:49 | |
| *** kimamisa has quit IRC | 16:49 | |
| mloza | I have "identity:list_role_assignments": "rule:admin_or_owner" and "identity:list_role_assignments_for_tree": "rule:admin_or_owner" in policy.yaml and a user member role still keep getting "You are not authorized to perform the requested action: identity:list_role_assignments." | 16:50 |
| cmurphy | mloza: a user with a member role isn't an admin and not an owner of any role assignments so that rule doesn't apply | 16:58 |
| cmurphy | lbragstad: fyi https://bugs.launchpad.net/keystone/+bug/1850087 | 16:58 |
| openstack | Launchpad bug 1850087 in OpenStack Identity (keystone) "keystone: token replaced at auth_context middleware" [Undecided,New] | 16:58 |
| lbragstad | hmmm | 17:00 |
| lbragstad | are there specific steps to reproduce? | 17:00 |
| cmurphy | i have no other information | 17:01 |
| mloza | cmurphy: can I do it like this "identity:list_role_assignments": "role:admin and role:member"? | 17:04 |
| *** markvoelker has quit IRC | 17:04 | |
| cmurphy | mloza: are you trying to allow regular users to list all role assignments, or just check their own role assignments? | 17:08 |
| mloza | allow regular users to list all role assignments | 17:08 |
| cmurphy | mloza: why? | 17:08 |
| mloza | cmurphy: I want to give a ability to a user to list the members who are in the project | 17:12 |
| mloza | It seems `openstack role assigment list --project` is the only way to list the members of a project | 17:13 |
| *** dancn has quit IRC | 17:14 | |
| mloza | and without admin privileges, a user can't list other members who are in the project | 17:14 |
| cmurphy | mloza: identity:list_role_assignments allows users to list all users and groups in all projects and all domains | 17:16 |
| cmurphy | mloza: you could use identity:list_role_assignments_for_tree, then your rule should use "or" instead of "and" otherwise users would still need the admin role | 17:16 |
| cmurphy | identity:list_role_assignments is also only for system or domain scope, _for_tree will work with project scope | 17:17 |
| cmurphy | the rule should actually be what's listed in https://docs.openstack.org/keystone/latest/configuration/policy.html under identity:list_role_assignments_for_tree but with role:admin changed to role:member | 17:20 |
| lbragstad | tellesnobrega i have not seen that - but i haven't tried recently | 17:25 |
| *** markvoelker has joined #openstack-keystone | 17:27 | |
| *** pcaruana has joined #openstack-keystone | 17:31 | |
| *** jmlowe has joined #openstack-keystone | 17:32 | |
| mloza | cmurphy: I changed what is listed in defaults of keystone policy.yaml but still the user is unauthorized list assignments | 17:38 |
| mloza | (keystone)[root@c2ostack01a /]# cat /etc/keystone/policy.yaml | 17:38 |
| mloza | "identity:list_role_assignments_for_tree": "role:admin or role:member" | 17:38 |
| mloza | (keystone)[root@c2ostack01a /]# | 17:38 |
| mloza | I have stable/stein env | 17:39 |
| *** jaosorior has joined #openstack-keystone | 17:40 | |
| cmurphy | mloza: you need to include the project_id:%(target.project.id)s part like in the link i gave | 17:42 |
| *** ivve has joined #openstack-keystone | 17:45 | |
| openstackgerrit | Pedro Henrique Pereira Martins proposed openstack/keystone master: Stop adding entry in local_user while updating ephemerals https://review.opendev.org/687990 | 17:51 |
| mloza | "identity:list_role_assignments_for_tree": "(role:admin and project_id:%(target.project.id)s) or (role:member and project_id:%(target.project.id)s)" | 17:57 |
| mloza | still won't let me list assigments | 17:57 |
| *** bnemec has quit IRC | 18:01 | |
| *** bnemec has joined #openstack-keystone | 18:02 | |
| mloza | keystone==15.0.1.dev16 | 18:08 |
| *** dklyle has quit IRC | 18:08 | |
| *** david-lyle has joined #openstack-keystone | 18:08 | |
| *** ebbex has joined #openstack-keystone | 18:24 | |
| *** jawad_axd has joined #openstack-keystone | 18:25 | |
| *** jawad_axd has quit IRC | 18:30 | |
| *** pcaruana has quit IRC | 18:30 | |
| *** pcaruana has joined #openstack-keystone | 18:31 | |
| *** tesseract has quit IRC | 18:31 | |
| *** vishalmanchanda has joined #openstack-keystone | 18:33 | |
| *** jmlowe has quit IRC | 18:36 | |
| *** jmlowe has joined #openstack-keystone | 18:39 | |
| *** jawad_axd has joined #openstack-keystone | 18:46 | |
| *** jawad_axd has quit IRC | 18:50 | |
| *** openstackgerrit has quit IRC | 18:50 | |
| *** mordred has quit IRC | 18:52 | |
| *** jawad_axd has joined #openstack-keystone | 19:06 | |
| *** jawad_axd has quit IRC | 19:11 | |
| *** david-lyle is now known as dklyle | 19:29 | |
| *** openstackgerrit has joined #openstack-keystone | 19:32 | |
| openstackgerrit | Merged openstack/oslo.policy master: Modernize policy checker https://review.opendev.org/682783 | 19:32 |
| *** zaneb has joined #openstack-keystone | 19:52 | |
| zaneb | lbragstad: thanks for the review on https://review.opendev.org/691181 - I have a question for you about https://bugs.launchpad.net/oslo.policy/+bug/1742569 when you have a moment | 19:53 |
| openstack | Launchpad bug 1742569 in oslo.policy "Including deprecated policy names in sample file" [Undecided,Fix released] - Assigned to Lance Bragstad (lbragstad) | 19:53 |
| *** dswebb has joined #openstack-keystone | 19:56 | |
| bnemec | Oh, that was added for Horizon. TIL. | 19:57 |
| dswebb | hi, hopefully quick question. I think I've run into the limitations of openid for federated auth (namely I can't get the cli to work for the life of me which I think relates to: https://bugs.launchpad.net/keystone/+bug/1815971). Does SAML2 suffer the same problems? | 19:58 |
| openstack | Launchpad bug 1815971 in OpenStack Identity (keystone) "RFE: Improved OpenID Connect Support" [Wishlist,In progress] - Assigned to Alvaro Lopez (aloga) | 19:58 |
| zaneb | bnemec: I'm glad someone else found it as inexplicable as I did ;) | 20:01 |
| *** pcaruana has quit IRC | 20:02 | |
| *** jawad_axd has joined #openstack-keystone | 20:08 | |
| *** jawad_axd has quit IRC | 20:13 | |
| cmurphy | dswebb: saml2 should work just fine with the cli, you just need to ensure ECP is enabled on your service provider https://docs.openstack.org/keystone/latest/admin/federation/configure_federation.html#use-the-cli-to-authenticate-with-a-saml2-0-identity-provider | 20:32 |
| dswebb | I'm using keycloak as my IdP so it should support ECP out of the box based on 1 minutes googling, cheers! | 20:35 |
| *** mordred has joined #openstack-keystone | 20:43 | |
| *** jmlowe has quit IRC | 20:43 | |
| *** jdwidari has quit IRC | 20:44 | |
| *** jamesmcarthur has joined #openstack-keystone | 20:47 | |
| *** kimamisa has joined #openstack-keystone | 20:49 | |
| *** vishalmanchanda has quit IRC | 21:02 | |
| *** jaosorior has quit IRC | 21:19 | |
| *** jaosorior has joined #openstack-keystone | 21:20 | |
| *** raildo has quit IRC | 21:22 | |
| *** kimamisa has quit IRC | 21:26 | |
| *** jmlowe has joined #openstack-keystone | 21:27 | |
| *** kimamisa has joined #openstack-keystone | 21:41 | |
| *** markvoelker has quit IRC | 21:45 | |
| *** dswebb has quit IRC | 21:54 | |
| *** adriant has joined #openstack-keystone | 21:57 | |
| *** jamesmcarthur has quit IRC | 22:28 | |
| *** jawad_axd has joined #openstack-keystone | 22:36 | |
| *** jaosorior has quit IRC | 22:38 | |
| *** jawad_axd has quit IRC | 22:40 | |
| openstackgerrit | Colleen Murphy proposed openstack/keystone master: Refresh "how can I help?" doc https://review.opendev.org/691769 | 22:48 |
| *** kimamisa has quit IRC | 22:52 | |
| *** rcernin has joined #openstack-keystone | 22:58 | |
| *** tkajinam has joined #openstack-keystone | 23:00 | |
| *** markvoelker has joined #openstack-keystone | 23:01 | |
| *** markvoelker has quit IRC | 23:06 | |
| *** mvkr has joined #openstack-keystone | 23:13 | |
| *** adriant has quit IRC | 23:25 | |
| *** adriant has joined #openstack-keystone | 23:25 | |
| *** prometheanfire has quit IRC | 23:50 | |
| *** prometheanfire has joined #openstack-keystone | 23:50 | |
| *** gyee has quit IRC | 23:57 | |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!