*** jamesmcarthur has joined #openstack-keystone | 00:35 | |
*** gyee has quit IRC | 00:44 | |
*** jamesmcarthur has quit IRC | 00:51 | |
*** jamesmcarthur has joined #openstack-keystone | 00:52 | |
*** jamesmcarthur has quit IRC | 00:57 | |
*** gagehugo has joined #openstack-keystone | 01:19 | |
*** jamesmcarthur has joined #openstack-keystone | 01:22 | |
*** jamesmcarthur has quit IRC | 01:23 | |
*** jamesmcarthur has joined #openstack-keystone | 01:23 | |
*** jamesmcarthur has quit IRC | 01:55 | |
*** jamesmcarthur has joined #openstack-keystone | 02:00 | |
*** jamesmcarthur has quit IRC | 02:31 | |
*** jamesmcarthur has joined #openstack-keystone | 02:43 | |
*** jamesmcarthur has quit IRC | 02:49 | |
*** jamesmcarthur has joined #openstack-keystone | 02:53 | |
*** jamesmcarthur has quit IRC | 03:07 | |
*** jamesmcarthur has joined #openstack-keystone | 03:31 | |
*** jamesmcarthur has quit IRC | 03:58 | |
*** gagehugo has quit IRC | 05:03 | |
*** gagehugo has joined #openstack-keystone | 05:03 | |
*** vishakha has joined #openstack-keystone | 05:20 | |
*** Abhishek has joined #openstack-keystone | 05:24 | |
Abhishek | Hi.. reg MFA functionality in keystone.. once a user is MFA enabled, 'openstack token issue' command returns a 401, which is as expected.. i was wondering what if the MFA enabled user wants to generate a token from this command instead of REST API.. there is no optional argument in this command to pass the totp & no environment variable which I can set in openrc for totp.. this means 'openstack token issue' command is not designed to work | 05:28 |
---|---|---|
Abhishek | with MFA users.. | 05:28 |
Abhishek | is my above understanding right or there is a way 'openstack token issue' command can be user to generate token for MFA users? | 05:29 |
*** rcernin has quit IRC | 05:33 | |
*** rcernin has joined #openstack-keystone | 05:33 | |
*** evrardjp has quit IRC | 05:34 | |
*** evrardjp has joined #openstack-keystone | 05:35 | |
vishakha | Abhishek: I have updated a patch https://review.opendev.org/#/c/697444/ so that you can create user with the options. Also you can update the MFA user with the other arguments | 05:57 |
*** abdysn has joined #openstack-keystone | 06:03 | |
*** kozhukalov has joined #openstack-keystone | 06:07 | |
Abhishek | vishakha: my query was something else.. no matter how the user options are set (api, cli etc), can a user who is mfa enabled (generate token by say password & totp) get his token by running 'openstack token issue' command? | 06:10 |
Abhishek | there is no option provided in 'openstack token issue' command to enter the totp | 06:10 |
vishakha | Abhishek: You can set the password and top while creating a user only. we dont pass anything to openstack token issue | 06:12 |
Abhishek | vishakha: password can be set while creating a user.. not totp as it changes every 30 seconds.. so, as far as i understand , openstack doesn't support generation of token for a mfa user using 'openstack token issue' | 06:16 |
*** rcernin has quit IRC | 06:24 | |
*** lbragstad has quit IRC | 06:26 | |
vishakha | Abhishek: yes not from openstack token issue. You can make an API request https://docs.openstack.org/keystone/latest/admin/auth-totp.html#tokens | 06:39 |
Abhishek | vishakha: yes.. isn't this some sort of bug/enhancement that can be done.. coz 'openstack token issue' command should provide token no matter what the auth mechanism be.. can a option be added to this command, something like --totp <passcode> after which token is generated for mfa enabled users also | 06:42 |
vishakha | Abhishek: You can add this as bug. I can bring this topic in weekly meeting and will update over the bug. or team can have a look at it | 06:49 |
vishakha | cmurphy gagehugo knikolla ^^ | 06:50 |
Abhishek | vishakha: sure | 06:52 |
*** jawad_axd has joined #openstack-keystone | 07:47 | |
*** tesseract has joined #openstack-keystone | 07:53 | |
*** dancn has joined #openstack-keystone | 07:57 | |
*** tkajinam has quit IRC | 08:02 | |
*** Abhishek has quit IRC | 08:09 | |
*** stingrayza has quit IRC | 08:53 | |
*** xek__ has joined #openstack-keystone | 09:43 | |
*** dmellado has quit IRC | 09:59 | |
*** stingrayza has joined #openstack-keystone | 10:43 | |
*** shyamb has joined #openstack-keystone | 10:56 | |
*** kozhukalov has quit IRC | 11:17 | |
*** kozhukalov has joined #openstack-keystone | 11:21 | |
*** kozhukalov has quit IRC | 11:35 | |
*** kozhukalov has joined #openstack-keystone | 11:35 | |
*** kozhukalov has quit IRC | 11:43 | |
*** ivve has joined #openstack-keystone | 11:53 | |
*** gagehugo has quit IRC | 12:19 | |
*** gagehugo has joined #openstack-keystone | 12:20 | |
*** shyamb has quit IRC | 12:33 | |
*** jamesmcarthur has joined #openstack-keystone | 12:36 | |
*** kozhukalov has joined #openstack-keystone | 12:39 | |
*** shyamb has joined #openstack-keystone | 12:40 | |
*** kplant has joined #openstack-keystone | 12:54 | |
*** shyamb has quit IRC | 12:56 | |
*** jamesmcarthur has quit IRC | 13:00 | |
*** jamesmcarthur has joined #openstack-keystone | 13:00 | |
*** dmellado has joined #openstack-keystone | 13:05 | |
*** shyamb has joined #openstack-keystone | 13:05 | |
*** jamesmcarthur has quit IRC | 13:06 | |
*** jamesmcarthur has joined #openstack-keystone | 13:10 | |
*** shyamb has quit IRC | 13:16 | |
kplant | would anyone mind giving me a hand with the openstack cli authenticating via openid-connect? i've got some of my config and outputs here: http://paste.openstack.org/show/Ok1chRmNxjBj5i8vKh5H/ | 13:22 |
kplant | websso is working, just having some trouble with the cli | 13:22 |
*** jamesmcarthur has quit IRC | 13:32 | |
*** jamesmcarthur has joined #openstack-keystone | 13:32 | |
*** gshippey has joined #openstack-keystone | 13:43 | |
*** waverider has joined #openstack-keystone | 13:44 | |
*** jamesmcarthur has quit IRC | 13:47 | |
*** jamesmcarthur_ has joined #openstack-keystone | 13:47 | |
cmurphy | Abhishek: vishakha please see https://docs.openstack.org/keystoneauth/latest/authentication-plugins.html#multi-factor-with-v3-identity-plugins for MFA with the CLI - at least with keystoneauth it should be possible to use the v3multifactor auth method and pass all the auth credentials at once, if it doesn't already work with openstackclient it should only need minor tweaking (cc adriant) | 13:51 |
cmurphy | kplant: using the cli with oidc is tricky, the best example is https://osticket.massopen.cloud/kb/faq.php?id=16 but a lot depends on how your idp is configured, knikolla may be able to help more | 13:53 |
*** lbragstad has joined #openstack-keystone | 13:59 | |
kplant | thanks. i'll try to make my rc look more like the example | 14:03 |
kplant | did you see anything blatantly wrong with the keystone side of my config? | 14:03 |
*** jawad_axd has quit IRC | 14:04 | |
*** dancn has quit IRC | 14:09 | |
*** dancn has joined #openstack-keystone | 14:10 | |
cmurphy | kplant: i don't see anything wrong but i'm not the best person to ask | 14:26 |
*** jamesmcarthur_ has quit IRC | 14:35 | |
*** jamesmcarthur has joined #openstack-keystone | 14:40 | |
*** jamesmcarthur has quit IRC | 14:48 | |
*** abdysn has quit IRC | 14:54 | |
*** gyee has joined #openstack-keystone | 15:21 | |
*** dancn has quit IRC | 15:22 | |
*** jamesmcarthur has joined #openstack-keystone | 15:38 | |
vishakha | cmurphy: I added a test case for openstack_groups https://review.opendev.org/#/c/704271/. I can see that openstack_groups is added to the assertion https://review.opendev.org/#/c/588211/45/keystone/federation/idp.py L245 which we can see in | 16:21 |
vishakha | https://21b1134b494fcbb80a11-30f2d4bfe90ac8b488e5b54b3e170d95.ssl.cf1.rackcdn.com/704271/11/check/keystone-dsvm-py3-functional-federation-opensuse15-k2k/06630d0/controller/logs/screen-keystone.txt | 16:21 |
vishakha | 4:09 | 16:21 |
vishakha | Feb 21 13:38:27.532996 opensuse-15-ovh-gra1-0014732249 | 16:21 |
vishakha | BUt the Environment Variables fetched from flask params doen;t contain openstack groups https://github.com/openstack/keystone/blob/04316beecc0d20290fb36e7791eb3050953c1011/keystone/federation/utils.py#L430 | 16:21 |
vishakha | Due to which assertion_data passed to SP doens't have openstack_groups in it. | 16:22 |
cmurphy | vishakha: did you add openstack_groups to attribute-map.xml in the devstack plugin? | 16:24 |
cmurphy | https://opendev.org/openstack/keystone/src/branch/master/devstack/files/federation/attribute-map.xml#L10-L14 | 16:25 |
*** tesseract has quit IRC | 16:27 | |
vishakha | cmurphy: I think I missed it. Thanks a lot | 16:29 |
vishakha | cmurphy: Also if you can take a look at https://review.opendev.org/#/c/697444/. I think its good to go | 16:37 |
*** dancn has joined #openstack-keystone | 16:38 | |
cmurphy | vishakha: will do | 16:38 |
vishakha | cmurphy: :) | 16:38 |
*** waverider has quit IRC | 16:40 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add openstack_groups to assertion https://review.opendev.org/588211 | 16:45 |
*** jamesmcarthur has quit IRC | 16:45 | |
*** renich has joined #openstack-keystone | 16:46 | |
*** jamesmcarthur has joined #openstack-keystone | 16:46 | |
*** jmlowe has quit IRC | 16:54 | |
*** renich_ has joined #openstack-keystone | 16:58 | |
*** renich has quit IRC | 16:59 | |
*** shyamb has joined #openstack-keystone | 17:17 | |
*** shyamb has quit IRC | 17:17 | |
*** evrardjp has quit IRC | 17:35 | |
*** evrardjp has joined #openstack-keystone | 17:35 | |
*** jmlowe has joined #openstack-keystone | 18:01 | |
*** jmlowe has quit IRC | 18:05 | |
*** jmlowe has joined #openstack-keystone | 18:05 | |
*** kplant has quit IRC | 18:24 | |
*** jmlowe has quit IRC | 18:27 | |
*** jmlowe has joined #openstack-keystone | 18:30 | |
*** dancn has quit IRC | 18:32 | |
*** jamesmcarthur has quit IRC | 18:33 | |
*** jamesmcarthur has joined #openstack-keystone | 18:33 | |
*** jmlowe has quit IRC | 18:34 | |
*** jmlowe has joined #openstack-keystone | 18:35 | |
*** jmlowe has quit IRC | 18:36 | |
*** jmlowe has joined #openstack-keystone | 18:56 | |
*** jmlowe has quit IRC | 18:59 | |
*** kplant has joined #openstack-keystone | 19:06 | |
-openstackstatus- NOTICE: Memory pressure on zuul.opendev.org is causing connection timeouts resulting in POST_FAILURE and RETRY_LIMIT results for some jobs since around 06:00 UTC today; we will be restarting the scheduler shortly to relieve the problem, and will follow up with another notice once running changes are reenqueued. | 19:11 | |
*** jamesmcarthur has quit IRC | 19:12 | |
*** jmlowe has joined #openstack-keystone | 19:31 | |
*** jamesmcarthur has joined #openstack-keystone | 19:40 | |
-openstackstatus- NOTICE: The scheduler for zuul.opendev.org has been restarted; any changes which were in queues at the time of the restart have been reenqueued automatically, but any changes whose jobs failed with a RETRY_LIMIT, POST_FAILURE or NODE_FAILURE build result in the past 14 hours should be manually rechecked for fresh results | 19:44 | |
*** gyee has quit IRC | 19:49 | |
*** gyee has joined #openstack-keystone | 19:49 | |
*** jmlowe has quit IRC | 20:07 | |
*** kozhukalov has quit IRC | 20:27 | |
*** kozhukalov has joined #openstack-keystone | 20:28 | |
*** jmlowe has joined #openstack-keystone | 20:30 | |
kplant | ~. | 20:46 |
*** kplant has quit IRC | 20:46 | |
*** jamesmcarthur has quit IRC | 20:54 | |
*** joshualyle has joined #openstack-keystone | 21:03 | |
*** joshualyle has quit IRC | 21:05 | |
*** kozhukalov has quit IRC | 21:08 | |
*** kozhukalov has joined #openstack-keystone | 21:40 | |
*** rcernin has joined #openstack-keystone | 21:44 | |
*** xek__ has quit IRC | 21:53 | |
*** jamesmcarthur has joined #openstack-keystone | 21:54 | |
*** jamesmcarthur has quit IRC | 22:08 | |
*** jamesmcarthur has joined #openstack-keystone | 22:11 | |
*** joshualyle has joined #openstack-keystone | 22:20 | |
*** joshualyle has quit IRC | 22:25 | |
*** jawad_axd has joined #openstack-keystone | 22:38 | |
*** jawad_axd has quit IRC | 22:43 | |
adriant | vishakha, cmurphy: yeah the work to get MFA support into the openstackclient never happened. I think I talked briefly with mordred about it, but I didn't have the time to chase after it. | 22:45 |
adriant | I'm going to try and get the horizon part done potentially this cycle but the horizon auth code is a weird nightmare | 22:45 |
mordred | adriant: I keep meaning to dig in to horizon and start replacing stuff with sdk/ksa | 22:46 |
mordred | adriant: ENOTIME | 22:46 |
*** jamesmcarthur has quit IRC | 22:49 | |
*** tkajinam has joined #openstack-keystone | 22:51 | |
*** tkajinam has quit IRC | 22:51 | |
*** tkajinam has joined #openstack-keystone | 22:51 | |
*** ivve has quit IRC | 22:57 | |
*** jamesmcarthur has joined #openstack-keystone | 23:25 | |
*** kozhukalov has quit IRC | 23:35 | |
*** jawad_axd has joined #openstack-keystone | 23:40 | |
*** jawad_axd has quit IRC | 23:45 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!