*** vishalmanchanda has joined #openstack-keystone | 00:05 | |
*** jamesmcarthur has joined #openstack-keystone | 00:11 | |
*** jamesmcarthur has quit IRC | 00:19 | |
*** jamesmcarthur has joined #openstack-keystone | 00:21 | |
*** jamesmcarthur has quit IRC | 00:26 | |
*** jamesmcarthur has joined #openstack-keystone | 00:44 | |
*** jamesmcarthur has quit IRC | 01:08 | |
*** jamesmcarthur has joined #openstack-keystone | 01:12 | |
*** jamesmcarthur has quit IRC | 01:24 | |
*** jamesmcarthur has joined #openstack-keystone | 01:24 | |
*** jamesmcarthur has quit IRC | 02:06 | |
*** jamesmcarthur has joined #openstack-keystone | 02:07 | |
*** vishalmanchanda has quit IRC | 03:05 | |
*** jamesmcarthur has quit IRC | 03:21 | |
*** vishalmanchanda has joined #openstack-keystone | 03:31 | |
*** lbragstad_ has joined #openstack-keystone | 03:54 | |
*** rcernin has quit IRC | 04:04 | |
*** rcernin has joined #openstack-keystone | 04:04 | |
*** dave-mccowan has quit IRC | 04:40 | |
*** lbragstad_ has quit IRC | 05:34 | |
*** evrardjp has quit IRC | 05:35 | |
*** evrardjp has joined #openstack-keystone | 05:35 | |
*** shyamb has joined #openstack-keystone | 05:59 | |
*** ccstone has quit IRC | 06:23 | |
*** ccstone has joined #openstack-keystone | 06:24 | |
*** abdysn has joined #openstack-keystone | 06:26 | |
*** shyamb has quit IRC | 06:37 | |
*** shyamb has joined #openstack-keystone | 06:58 | |
*** dancn has joined #openstack-keystone | 07:06 | |
*** shyam89 has joined #openstack-keystone | 07:10 | |
*** shyamb has quit IRC | 07:12 | |
*** shyamb has joined #openstack-keystone | 07:40 | |
*** shyam89 has quit IRC | 07:42 | |
*** xek_ has joined #openstack-keystone | 07:57 | |
*** tkajinam has quit IRC | 08:08 | |
*** tesseract has joined #openstack-keystone | 08:11 | |
*** shyamb has quit IRC | 09:10 | |
*** shyamb has joined #openstack-keystone | 09:14 | |
*** ygk_12345 has joined #openstack-keystone | 09:23 | |
*** ygk_12345 has left #openstack-keystone | 09:24 | |
*** shyamb has quit IRC | 09:32 | |
*** bengates has joined #openstack-keystone | 10:20 | |
*** bengates has quit IRC | 10:20 | |
*** bengates has joined #openstack-keystone | 10:21 | |
*** kplant has joined #openstack-keystone | 11:11 | |
*** tkajinam has joined #openstack-keystone | 11:15 | |
*** jamesmcarthur has joined #openstack-keystone | 11:19 | |
*** jamesmcarthur has quit IRC | 11:24 | |
*** Luzi has joined #openstack-keystone | 11:37 | |
*** bengates has quit IRC | 12:04 | |
*** raildo has joined #openstack-keystone | 12:07 | |
*** raildo has quit IRC | 12:19 | |
*** raildo has joined #openstack-keystone | 12:20 | |
*** jamesmcarthur has joined #openstack-keystone | 12:21 | |
*** jamesmcarthur has quit IRC | 12:36 | |
*** bengates has joined #openstack-keystone | 12:51 | |
*** xek_ is now known as xek | 13:01 | |
*** lbragstad_ has joined #openstack-keystone | 13:01 | |
*** kplant has quit IRC | 13:07 | |
*** kplant has joined #openstack-keystone | 13:12 | |
*** lbragstad_ is now known as lbragstad | 13:12 | |
*** lbragstad has quit IRC | 13:13 | |
*** lbragstad has joined #openstack-keystone | 13:16 | |
*** dave-mccowan has joined #openstack-keystone | 14:04 | |
*** abdysn has quit IRC | 14:13 | |
*** Luzi has quit IRC | 14:32 | |
*** jamesmcarthur has joined #openstack-keystone | 14:39 | |
*** jamesmcarthur has quit IRC | 14:46 | |
*** jamesmcarthur has joined #openstack-keystone | 14:54 | |
*** jamesmcarthur has quit IRC | 14:56 | |
*** jamesmcarthur has joined #openstack-keystone | 14:56 | |
*** ayoung has joined #openstack-keystone | 14:57 | |
*** tkajinam has quit IRC | 15:17 | |
rm_work | apologies, I know I bring this up like every couple of months without really making any progress, but ... | 15:18 |
---|---|---|
rm_work | what is the current state of x509-based keystone auth? | 15:18 |
rm_work | is it still "conceptually something that we'd like to support" or is it in-progress or semi-implemented? | 15:18 |
rm_work | there's docs about it as if it already exists? | 15:22 |
rm_work | https://docs.openstack.org/keystone/pike/advanced-topics/configure_tokenless_x509.html | 15:22 |
*** gyee has joined #openstack-keystone | 15:43 | |
cmurphy | fyi meeting is in 1:10 not in 10 minutes | 15:52 |
cmurphy | rm_work: it's a thing that works, you would configure it the same way you would configure federation https://docs.openstack.org/keystone/latest/admin/federation/federated_identity.html but use mod_ssl with this apache config https://docs.openstack.org/keystone/latest/admin/external-authentication.html#x-509-example | 15:53 |
rm_work | cool, thanks | 15:53 |
rm_work | (for confirming) | 15:54 |
cmurphy | tokenless auth using x509 is a thing but it's really just for service to service communication https://docs.openstack.org/keystone/latest/admin/configure_tokenless_x509.html | 15:54 |
rm_work | hmm k | 15:54 |
cmurphy | rm_work: btw you make me sad by linking the pike docs :P | 15:54 |
rm_work | lol just what came up in google :D | 15:54 |
cmurphy | i know T.T | 15:54 |
*** vishalmanchanda has quit IRC | 16:05 | |
*** lbragstad has quit IRC | 16:07 | |
*** bengates has quit IRC | 16:08 | |
*** lbragstad has joined #openstack-keystone | 16:08 | |
*** trident has quit IRC | 16:34 | |
*** trident has joined #openstack-keystone | 16:36 | |
cmurphy | meeting in about 9 minutes in #openstack-meeting-alt | 16:51 |
cmurphy | meeting now in #openstack-meeting-alt | 17:01 |
*** tesseract has quit IRC | 17:07 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Correcting api-ref for users https://review.opendev.org/710734 | 17:13 |
*** jamesmcarthur has quit IRC | 17:20 | |
*** jamesmcarthur has joined #openstack-keystone | 17:27 | |
*** evrardjp has quit IRC | 17:35 | |
*** evrardjp has joined #openstack-keystone | 17:35 | |
*** jamesmcarthur has quit IRC | 17:43 | |
*** jamesmcarthur has joined #openstack-keystone | 17:56 | |
*** NM has joined #openstack-keystone | 17:57 | |
*** trident has quit IRC | 18:08 | |
*** trident has joined #openstack-keystone | 18:17 | |
*** mugsie has quit IRC | 19:23 | |
*** mugsie has joined #openstack-keystone | 19:26 | |
*** jamesmcarthur has quit IRC | 19:30 | |
*** openstackgerrit has quit IRC | 19:32 | |
*** kplant has quit IRC | 19:47 | |
raildo | cmurphy, hey, how things are going? have a few minutes to talk about a possible backport request? | 19:50 |
raildo | cmurphy, I was trying to backport this cadf auditing to credentials on https://github.com/openstack/keystone/commit/579cc19857048a8710a9f173c602f51a2fcabba1 but at some moment I saw that this change depends on this bigger change which includes this caching for credentials https://github.com/openstack/keystone/commit/479a2a0afaeb505c371ee97a1f2fbc1b11e3cef1 | 19:52 |
raildo | cmurphy, for this second change it creates some config options for caching, which I'm not sure if it's a valid action for backporting | 19:52 |
*** lbragstad_ has joined #openstack-keystone | 19:55 | |
*** lbragstad has quit IRC | 19:58 | |
cmurphy | raildo: i don't think the caching can be backported, can the cherry-pick be modified so it doesn't depend on the caching? | 19:58 |
cmurphy | raildo: is `AttributeError: 'function' object has no attribute 'invalidate'` the issue? i think just remove the invalidate if it's not applicable in that branch | 19:59 |
raildo | cmurphy, that's would be my second approach, I didn't evaluate it entirely but doesn't sound something easy to do | 19:59 |
raildo | cmurphy, well, it's a bit more than that... for example the caching patch added some calls like delete credentials, which would be great to have it backported as well | 20:00 |
raildo | cmurphy, I'll work a little bit more on that patch to solve the tests issues and see if that backport makes sense without the caching credentials stuff | 20:01 |
raildo | cmurphy, and I can poke you later to evaluate if it will makes sense to have it backported | 20:01 |
cmurphy | raildo: :thumbsup: | 20:01 |
*** NM has quit IRC | 20:02 | |
*** NM has joined #openstack-keystone | 20:05 | |
*** jamesmcarthur has joined #openstack-keystone | 20:17 | |
*** openstackstatus has joined #openstack-keystone | 20:19 | |
*** ChanServ sets mode: +v openstackstatus | 20:19 | |
*** NM has quit IRC | 20:20 | |
*** dave-mccowan has quit IRC | 20:27 | |
*** joshualyle has joined #openstack-keystone | 20:32 | |
*** NM has joined #openstack-keystone | 20:36 | |
*** joshualyle has quit IRC | 20:36 | |
*** NM has quit IRC | 20:41 | |
*** dancn has quit IRC | 20:45 | |
*** rcernin has quit IRC | 20:53 | |
*** xek has quit IRC | 21:07 | |
*** lbragstad_ has quit IRC | 21:11 | |
*** jamesmcarthur has quit IRC | 21:28 | |
*** jamesmcarthur has joined #openstack-keystone | 21:28 | |
*** openstackgerrit has joined #openstack-keystone | 21:33 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: Document the "immutable" resource option https://review.opendev.org/712182 | 21:33 |
openstackgerrit | Merged openstack/keystone master: NIT: Fix spelling https://review.opendev.org/711583 | 21:33 |
*** jamesmcarthur has quit IRC | 21:44 | |
*** jamesmcarthur has joined #openstack-keystone | 21:45 | |
*** jamesmcarthur has quit IRC | 21:53 | |
*** jamesmcarthur has joined #openstack-keystone | 22:05 | |
*** jamesmcarthur has quit IRC | 22:10 | |
*** evrardjp has quit IRC | 22:17 | |
*** evrardjp has joined #openstack-keystone | 22:18 | |
*** evrardjp has quit IRC | 22:31 | |
*** evrardjp has joined #openstack-keystone | 22:33 | |
*** tkajinam has joined #openstack-keystone | 22:53 | |
*** lbragstad_ has joined #openstack-keystone | 23:00 | |
*** lbragstad_ has quit IRC | 23:25 | |
*** rcernin has joined #openstack-keystone | 23:26 | |
*** lbragstad_ has joined #openstack-keystone | 23:38 | |
*** renich has joined #openstack-keystone | 23:38 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!