*** jamesmcarthur has quit IRC | 00:15 | |
*** tkajinam has joined #openstack-keystone | 00:16 | |
*** jamesmcarthur has joined #openstack-keystone | 00:29 | |
*** jamesmcarthur has quit IRC | 00:44 | |
*** jamesmcarthur has joined #openstack-keystone | 01:01 | |
*** jamesmcarthur has quit IRC | 01:13 | |
*** aloga has quit IRC | 01:24 | |
*** Dinesh_Bhor has quit IRC | 02:10 | |
openstackgerrit | Arthur Dayne proposed openstack/keystone master: Stop testing Python 2 https://review.opendev.org/688601 | 02:59 |
---|---|---|
openstackgerrit | Arthur Dayne proposed openstack/keystone master: Stop testing Python 2 https://review.opendev.org/688601 | 03:30 |
*** dave-mccowan has quit IRC | 04:02 | |
*** vishalmanchanda has joined #openstack-keystone | 04:42 | |
openstackgerrit | Merged openstack/keystone master: Remove group deletion for non-sql driver when removing domains. https://review.opendev.org/688939 | 04:51 |
*** ileixe has quit IRC | 05:56 | |
*** ivve has joined #openstack-keystone | 05:57 | |
*** ileixe has joined #openstack-keystone | 05:59 | |
*** jawad_axd has quit IRC | 06:05 | |
*** ivve has quit IRC | 06:15 | |
*** jawad_axd has joined #openstack-keystone | 06:36 | |
openstackgerrit | Arthur Dayne proposed openstack/keystone master: Stop testing Python 2 https://review.opendev.org/688601 | 06:38 |
*** pcaruana has joined #openstack-keystone | 07:09 | |
*** Luzi has joined #openstack-keystone | 07:22 | |
*** jawad_axd has quit IRC | 07:32 | |
*** jawad_axd has joined #openstack-keystone | 07:42 | |
*** dancn has joined #openstack-keystone | 07:54 | |
*** tkajinam has quit IRC | 08:03 | |
*** prometheanfire has quit IRC | 08:35 | |
*** prometheanfire has joined #openstack-keystone | 08:37 | |
openstackgerrit | Arthur Dayne proposed openstack/keystone master: Stop testing Python 2 https://review.opendev.org/688601 | 08:40 |
*** ivve has joined #openstack-keystone | 08:53 | |
*** vesper has joined #openstack-keystone | 09:08 | |
*** vesper11 has quit IRC | 09:09 | |
*** trident has quit IRC | 09:26 | |
*** trident has joined #openstack-keystone | 09:34 | |
*** tesseract has joined #openstack-keystone | 09:38 | |
*** aloga has joined #openstack-keystone | 10:22 | |
*** rcernin has quit IRC | 10:27 | |
*** pcaruana has quit IRC | 10:35 | |
*** dswebb has joined #openstack-keystone | 10:39 | |
*** baffle has quit IRC | 10:44 | |
*** openstackstatus has quit IRC | 10:44 | |
*** kimamisa has joined #openstack-keystone | 10:45 | |
*** kimamisa has quit IRC | 10:55 | |
*** baffle has joined #openstack-keystone | 11:04 | |
dswebb | hi, can anyone tell me where the redirect URL for mellon from /v3/auth/OS-FEDERATION/identity_providers/MYIDP/protocols/saml2/websso gets created? for some reason it keeps redirecting me to a http:// address and I've only got keystone listening on https | 11:36 |
dswebb | all of the references in my sp.xml and idp.xml are referencing https addresses | 11:38 |
*** kimamisa has joined #openstack-keystone | 11:40 | |
*** raildo has joined #openstack-keystone | 11:44 | |
*** pcaruana has joined #openstack-keystone | 12:00 | |
*** jawad_axd has quit IRC | 12:24 | |
*** jawad_axd has joined #openstack-keystone | 12:24 | |
*** jawad_axd has quit IRC | 12:25 | |
*** markvoelker has quit IRC | 12:25 | |
*** markvoelker has joined #openstack-keystone | 12:25 | |
*** jawad_axd has joined #openstack-keystone | 12:26 | |
*** jawad_ax_ has joined #openstack-keystone | 12:28 | |
*** jawad_axd has quit IRC | 12:31 | |
*** jawad_ax_ has quit IRC | 12:33 | |
*** jmlowe has quit IRC | 12:36 | |
*** mvkr has quit IRC | 12:38 | |
*** jawad_axd has joined #openstack-keystone | 12:51 | |
*** jawad_axd has quit IRC | 12:53 | |
*** jawad_ax_ has joined #openstack-keystone | 12:53 | |
*** jawad_axd has joined #openstack-keystone | 12:54 | |
*** jawad_ax_ has quit IRC | 12:57 | |
*** jawad_axd has quit IRC | 13:00 | |
*** jawad_axd has joined #openstack-keystone | 13:01 | |
*** jawad_axd has quit IRC | 13:01 | |
*** jawad_axd has joined #openstack-keystone | 13:02 | |
*** jmlowe has joined #openstack-keystone | 13:12 | |
*** mvkr has joined #openstack-keystone | 13:12 | |
*** xek has joined #openstack-keystone | 13:13 | |
openstackgerrit | Pedro Henrique Pereira Martins proposed openstack/keystoneauth master: Fixes OIDC authentication with multiple IdPs https://review.opendev.org/692140 | 13:33 |
*** dave-mccowan has joined #openstack-keystone | 13:59 | |
*** jaosorior has joined #openstack-keystone | 14:21 | |
*** jamesmcarthur has joined #openstack-keystone | 14:24 | |
*** jamesmcarthur has quit IRC | 14:31 | |
*** dasp has quit IRC | 14:32 | |
*** dasp has joined #openstack-keystone | 14:42 | |
*** kimamisa has quit IRC | 14:50 | |
coreycb | hi, there's a regression in keystone stable/queens that I have a patch revert up for: https://bugs.launchpad.net/bugs/1850634 | 14:56 |
openstack | Launchpad bug 1850634 in keystone (Ubuntu Bionic) "queens regresion: _dn_to_id() not using utf8_encode/decode" [High,Triaged] - Assigned to Corey Bryant (corey.bryant) | 14:56 |
*** xek_ has joined #openstack-keystone | 15:03 | |
*** xek has quit IRC | 15:05 | |
*** jaosorior has quit IRC | 15:06 | |
*** jawad_axd has quit IRC | 15:19 | |
*** gyee has joined #openstack-keystone | 15:24 | |
*** Luzi has quit IRC | 15:25 | |
cmurphy | coreycb: do you know if it's safe for rocky? | 15:26 |
cmurphy | looks like yes | 15:27 |
coreycb | cmurphy: yes rocky is ok | 15:27 |
coreycb | cmurphy: to be honest my tests that go through that path don't behave any differently with or without that code so I'm slightly confused | 15:28 |
cmurphy | coreycb: how did you notice the bug then? | 15:29 |
*** jamesmcarthur has joined #openstack-keystone | 15:29 | |
coreycb | cmurphy: just looking at the code | 15:29 |
coreycb | cmurphy: this should help | 15:35 |
*** kimamisa has joined #openstack-keystone | 15:36 | |
coreycb | here's the relevant code in the stable/rocky backport (note it regressed the if path which was fixed with a follow on patch) | 15:36 |
coreycb | https://review.opendev.org/#/c/672351/2/keystone/identity/backends/ldap/common.py | 15:36 |
coreycb | here's the same patch to stable/queens (note it didn't regress the if path but still received the follow on patch) | 15:37 |
coreycb | https://review.opendev.org/#/c/674030/2/keystone/identity/backends/ldap/common.py | 15:37 |
*** kimamisa has quit IRC | 15:38 | |
cmurphy | got it | 15:38 |
*** jmlowe has quit IRC | 15:41 | |
*** jamesmcarthur has quit IRC | 15:41 | |
*** jaosorior has joined #openstack-keystone | 15:51 | |
*** ivve has quit IRC | 16:10 | |
*** jamesmcarthur has joined #openstack-keystone | 16:18 | |
*** jamesmcarthur has quit IRC | 16:22 | |
*** jamesmcarthur has joined #openstack-keystone | 16:22 | |
*** fozboz has joined #openstack-keystone | 16:25 | |
*** mvkr has quit IRC | 16:31 | |
*** jawad_axd has joined #openstack-keystone | 16:44 | |
*** jawad_axd has quit IRC | 16:49 | |
*** openstackstatus has joined #openstack-keystone | 17:03 | |
*** ChanServ sets mode: +v openstackstatus | 17:03 | |
*** dancn has quit IRC | 17:04 | |
*** jmlowe has joined #openstack-keystone | 17:05 | |
*** mvkr has joined #openstack-keystone | 17:21 | |
*** xek_ has quit IRC | 17:29 | |
*** jamesmcarthur has quit IRC | 17:38 | |
*** jamesmcarthur has joined #openstack-keystone | 17:39 | |
*** kimamisa has joined #openstack-keystone | 17:42 | |
*** jamesmcarthur has quit IRC | 17:44 | |
*** jamesmcarthur has joined #openstack-keystone | 17:51 | |
*** jamesmcarthur has quit IRC | 17:58 | |
*** jamesmcarthur has joined #openstack-keystone | 18:00 | |
*** jamesmcarthur has quit IRC | 18:05 | |
*** pcaruana has quit IRC | 18:10 | |
*** stingrayza has quit IRC | 18:12 | |
*** jamesmcarthur has joined #openstack-keystone | 18:13 | |
*** jamesmcarthur has quit IRC | 18:15 | |
*** jamesmcarthur has joined #openstack-keystone | 18:16 | |
dswebb | bah, forced a rewrite of the location in haproxy and then keystone complains: "Invalid Destination on Response. Should be 'http://openstack-keystone:5000/v3/OS-FEDERATION/identity_providers/MYIDP/protocols/saml2/auth/mellon/postResponse" | 18:17 |
*** stingrayza has joined #openstack-keystone | 18:20 | |
*** jamesmcarthur has quit IRC | 18:23 | |
*** jamesmcarthur has joined #openstack-keystone | 18:24 | |
*** fozboz has quit IRC | 18:27 | |
*** memo_ has quit IRC | 18:30 | |
dswebb | aaaand redhat had the same issue 3 years ago: http://lists.openstack.org/pipermail/openstack-dev/2016-August/101132.html | 18:48 |
dswebb | awesome | 18:48 |
*** jamesmcarthur has quit IRC | 18:58 | |
*** jamesmcarthur has joined #openstack-keystone | 18:58 | |
*** zaneb has quit IRC | 19:00 | |
*** tesseract has quit IRC | 19:03 | |
*** jamesmcarthur has quit IRC | 19:03 | |
*** pcaruana has joined #openstack-keystone | 19:05 | |
*** ivve has joined #openstack-keystone | 19:06 | |
*** jamesmcarthur has joined #openstack-keystone | 19:16 | |
*** jaosorior has quit IRC | 19:21 | |
*** prometheanfire has quit IRC | 19:21 | |
*** prometheanfire has joined #openstack-keystone | 19:21 | |
*** pcaruana has quit IRC | 19:29 | |
*** jawad_axd has joined #openstack-keystone | 19:29 | |
*** stingrayza has quit IRC | 19:31 | |
*** stingrayza has joined #openstack-keystone | 19:33 | |
*** jamesmcarthur has quit IRC | 19:34 | |
*** jawad_axd has quit IRC | 19:34 | |
*** pcaruana has joined #openstack-keystone | 19:39 | |
dswebb | so turns out this is a mellon issue where it inspects the vhost it's in to construct the redirect url, and since I have ssl offload done at haproxy it's detecting keystone as unencrypted hence the http :/ | 19:45 |
*** pcaruana has quit IRC | 20:09 | |
*** jamesmcarthur has joined #openstack-keystone | 20:13 | |
*** stingrayza has quit IRC | 20:17 | |
*** jamesmcarthur has quit IRC | 20:29 | |
*** adriant has quit IRC | 20:31 | |
*** aloga has quit IRC | 20:36 | |
*** stingrayza has joined #openstack-keystone | 20:45 | |
*** jamesmcarthur has joined #openstack-keystone | 20:50 | |
*** markvoelker has quit IRC | 20:55 | |
*** markvoelker has joined #openstack-keystone | 20:55 | |
*** markvoelker has quit IRC | 20:59 | |
*** aloga has joined #openstack-keystone | 20:59 | |
*** jamesmcarthur has quit IRC | 21:00 | |
*** jamesmcarthur has joined #openstack-keystone | 21:07 | |
*** jamesmcarthur_ has joined #openstack-keystone | 21:09 | |
*** vishalmanchanda has quit IRC | 21:10 | |
*** jamesmcarthur has quit IRC | 21:12 | |
*** jamesmcarthur_ has quit IRC | 21:24 | |
*** jamesmcarthur has joined #openstack-keystone | 21:27 | |
*** jamesmcarthur has quit IRC | 21:29 | |
*** jamesmcarthur has joined #openstack-keystone | 21:32 | |
*** jamesmcarthur has quit IRC | 21:44 | |
*** jamesmcarthur has joined #openstack-keystone | 21:44 | |
*** jmccrory has joined #openstack-keystone | 21:46 | |
*** jamesmcarthur has quit IRC | 21:49 | |
*** jamesmcarthur has joined #openstack-keystone | 21:50 | |
*** raildo has quit IRC | 21:53 | |
*** jamesmcarthur has quit IRC | 21:55 | |
*** jamesmcarthur has joined #openstack-keystone | 21:56 | |
*** jamesmcarthur has quit IRC | 22:00 | |
*** jawad_axd has joined #openstack-keystone | 22:13 | |
*** jawad_axd has quit IRC | 22:18 | |
*** adriant has joined #openstack-keystone | 22:51 | |
*** jawad_axd has joined #openstack-keystone | 22:55 | |
*** markvoelker has joined #openstack-keystone | 22:56 | |
*** jawad_axd has quit IRC | 22:59 | |
*** markvoelker has quit IRC | 23:00 | |
*** tkajinam has joined #openstack-keystone | 23:01 | |
*** tkajinam has quit IRC | 23:01 | |
*** tkajinam has joined #openstack-keystone | 23:04 | |
*** jawad_axd has joined #openstack-keystone | 23:16 | |
*** jawad_axd has quit IRC | 23:21 | |
*** ivve has quit IRC | 23:21 | |
*** jawad_axd has joined #openstack-keystone | 23:37 | |
*** jawad_axd has quit IRC | 23:41 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!