Tuesday, 2022-05-31

*** dviroel is now known as dviroel|out00:04
opendevreviewYusuke Niimi proposed openstack/keystone master: OAuth2.0 Client Credentials Grant Flow Support  https://review.opendev.org/c/openstack/keystone/+/83073908:18
opendevreviewYusuke Niimi proposed openstack/keystoneauth master: OAuth2.0 Client Credentials Grant Flow Support  https://review.opendev.org/c/openstack/keystoneauth/+/83073408:38
opendevreviewHiromu Asahina proposed openstack/keystone-specs master: OAuth 2.0 Mutual-TLS Support  https://review.opendev.org/c/openstack/keystone-specs/+/84376510:04
opendevreviewHiromu Asahina proposed openstack/keystone-specs master: OAuth 2.0 Mutual-TLS Support  https://review.opendev.org/c/openstack/keystone-specs/+/84376510:14
opendevreviewYusuke Niimi proposed openstack/keystoneauth master: OAuth2.0 Client Credentials Grant Flow Support  https://review.opendev.org/c/openstack/keystoneauth/+/83073410:43
*** dviroel|out is now known as dviroel11:29
opendevreviewYusuke Niimi proposed openstack/keystone master: OAuth2.0 Client Credentials Grant Flow Support  https://review.opendev.org/c/openstack/keystone/+/83073911:53
opendevreviewYusuke Niimi proposed openstack/keystone master: OAuth2.0 Client Credentials Grant Flow Support  https://review.opendev.org/c/openstack/keystone/+/83073912:31
*** whoami-rajat__ is now known as whoami-rajat13:42
knikollai have a scheduling conflict with today's meeting, but i will be reading back the logs as soon as i'm done later today. 14:47
opendevreviewHiromu Asahina proposed openstack/keystone-specs master: OAuth 2.0 Mutual-TLS Support  https://review.opendev.org/c/openstack/keystone-specs/+/84376514:59
d34dh0r53knikolla: ack, thank you15:00
d34dh0r53#startmeeting keystone15:00
opendevmeetMeeting started Tue May 31 15:00:28 2022 UTC and is due to finish in 60 minutes.  The chair is d34dh0r53. Information about MeetBot at http://wiki.debian.org/MeetBot.15:00
opendevmeetUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.15:00
opendevmeetThe meeting name has been set to 'keystone'15:00
d34dh0r53#topic Roll Call15:00
d34dh0r53courtesy ping for admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, knikolla, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek15:01
d34dh0r53#topic Review past meeting work items15:01
d34dh0r53#link https://meetings.opendev.org/meetings/keystone_weekly_meeting/2022/keystone_weekly_meeting.2022-05-24-15.04.html15:02
d34dh0r53I had an action item to discuss with dmendiza[m] the meeting during the summit.15:03
d34dh0r53I was not able to connect with Doug, so we'll have to talk about it in Berlin.  We'll update you here about the status of the meeting15:03
d34dh0r53#action d34dh0r53 talk to dmendiza[m] about next weeks meeting15:04
d34dh0r53#topic Specifications15:04
d34dh0r53OAuth 2.015:04
h-asahinao/15:04
d34dh0r53#link https://review.opendev.org/q/topic:bp%252Foauth2-client-credentials-ext15:04
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-specs/+/84376515:05
h-asahinaZuul is still in progress...15:05
d34dh0r53h-asahina: I see you submitted the additional specification for Mutual-TLS support15:05
h-asahinayes and I've just fixed tox which failed building recently15:06
h-asahinaAlso, I've submitted the bug report regarding this problem of tox15:06
h-asahinaI'll submit the patch to fix it separately later.15:07
d34dh0r53h-asahina: excellent, thank you15:07
h-asahina:) 15:07
h-asahinaI'd like to explain the contents of the spec now. is it ok?15:07
d34dh0r53h-asahina: yes, that is fine15:08
h-asahinathanks15:08
h-asahinaI'll briefly explain the background of this spec as we have changed the contents from the BP.15:08
h-asahinaActually, we have to change our contents for Zed release as our priority has been changed.15:09
h-asahinaAs I explained before, I came from OpenStack Tacker project that try to make Virtual Network Function Manager supporint the famous standard in that area called ETSI NFV SOL.15:10
h-asahinaand that's why we need to meet the latest standard15:10
h-asahinaIn the latest SOL013, which define the common API specification for NFV components (including VNFM), forces the components to use OAuth2.0 mutual TLS, i.e., RFC8705.15:11
h-asahinahttps://datatracker.ietf.org/doc/html/rfc870515:12
h-asahinaTo meets this requirement, we'd like to implement RFC8705 to Keystone, KeystoneMiddleware and keystoneauth.15:12
h-asahinaChanges to do it includes the contents of BP but also includes several new parts like adding APIs.15:13
h-asahinaSo, I'd like to hear the feasibility of this proposal from Keystone core.15:13
h-asahinaI note that this changes will not reduce the security level by the way.15:14
h-asahinaCould you tell me your opinion?15:15
d34dh0r53h-asahina: The specification you've provided looks good, but I am not qualified to fully give an opinion at this time.15:17
d34dh0r53h-asahina: I will bring this up as an item for discussion with dmendiza[m] and knikolla at the Summit next week.  Are you going to be there?15:17
h-asahinaunfortunately, I'm not15:18
d34dh0r53h-asahina: ok15:19
d34dh0r53#action d34dh0r53 dmendiza[m] knikolla review meeting logs and discuss https://review.opendev.org/c/openstack/keystone-specs/+/843765/4/specs/keystone/zed/support-oauth2-mtls.rst15:20
h-asahinaso, plese give me comments on the spec. I'll check and reply it.15:20
d34dh0r53h-asahina: yes, we will and hopefully time will permit us to hold the weekly meeting so we can discuss further15:21
h-asahinagood15:21
d34dh0r53thank you h-asahina!15:21
d34dh0r53moving on to Secure RBAC15:21
h-asahinathank you too!15:21
d34dh0r53#link https://governance.openstack.org/tc/goals/selected/consistent-and-secure-rbac.html#z-release-timeline_15:21
d34dh0r53I don't have any updates for Secure RBAC15:22
*** dviroel is now known as dviroel|lunch15:22
d34dh0r53next up: Gate inherited assignments from parent (bbobrov)15:23
d34dh0r53#link https://review.opendev.org/c/openstack/keystone-specs/+/33436415:23
d34dh0r53we will review this at the summit as well as it's been updated recently15:25
d34dh0r53bbobrov: do you have anything you'd like to add?15:25
d34dh0r53#action d34dh0r53 dmendiza[m] knikolla review https://review.opendev.org/c/openstack/keystone-specs/+/33436415:26
d34dh0r53#topic public discussion15:27
d34dh0r53I need to ask dmendiza[m] about bandit and building from git15:28
d34dh0r53#action d34dh0r53 ask dmendiza[m] about this bandit line in the agenda15:28
d34dh0r53anything else?15:28
d34dh0r53ok, moving on15:29
opendevreviewAlexandre arents proposed openstack/keystone master: Federation: add support for projects_json assertion  https://review.opendev.org/c/openstack/keystone/+/84409815:29
d34dh0r53#topic bug review15:30
d34dh0r53#link https://bugs.launchpad.net/keystone/?orderby=-id&start=015:30
d34dh0r53looks like one new keystone bug: https://bugs.launchpad.net/keystone/+bug/197638715:30
d34dh0r53this was from h-asahina and a fix is forthcoming15:30
h-asahinayes15:31
d34dh0r53#link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=015:31
d34dh0r53no new python-keystoneclient bugs15:31
d34dh0r53#link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=015:31
d34dh0r53no new keystoneauth bugs15:31
d34dh0r53#link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=015:32
d34dh0r53no new keystomemiddleware bugs15:32
d34dh0r53#link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=015:32
d34dh0r53no new pycadf bugs15:32
d34dh0r53#link https://bugs.launchpad.net/ldappool/+bugs?orderby=-id&start=015:33
d34dh0r53and, no new ldappool bugs15:33
d34dh0r53#topic open floor15:33
d34dh0r53Does anyone have anything else for this week?15:33
d34dh0r53Reminder than the OpenInfra Summit is next week in Berlin, I'm looking forward to meeting and seeing those who can make it15:34
d34dh0r53Another reminder that we'll be having another reviewathon at 15:00 UTC this Friday.  Please let me know if you'd like to be included and I can send you the invite.15:35
d34dh0r53Thanks everyone!15:38
d34dh0r53#endmeeting15:38
opendevmeetMeeting ended Tue May 31 15:38:20 2022 UTC.  Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4)15:38
opendevmeetMinutes:        https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-05-31-15.00.html15:38
opendevmeetMinutes (text): https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-05-31-15.00.txt15:38
opendevmeetLog:            https://meetings.opendev.org/meetings/keystone/2022/keystone.2022-05-31-15.00.log.html15:38
alistarleHello, in order to enhance a little bit the mapping in the federation system, we propose a patch to allow specify a JSON of project/role, coming directly from the IdP (like we do for the groups by example): https://review.opendev.org/c/openstack/keystone/+/84409815:43
alistarled34dh0r53 you seem to know well the federation, do you have any clue about this patch ?15:44
d34dh0r53alistarle: I can look :)15:45
aarentsd34dh0r53: thanks for having a look, FYI the change in mapped.py is mainly a move of the inner function because we reach the pep8 complex founction'15:48
opendevreviewHiromu Asahina proposed openstack/keystone-specs master: [WIP] Fix document build  https://review.opendev.org/c/openstack/keystone-specs/+/84410015:49
d34dh0r53aarents: ack, I was wondering about that15:49
opendevreviewHiromu Asahina proposed openstack/keystone-specs master: [WIP] Fix document build  https://review.opendev.org/c/openstack/keystone-specs/+/84410016:21
*** dviroel|lunch is now known as dviroel16:24
opendevreviewHiromu Asahina proposed openstack/keystone-specs master: [WIP] Fix document build  https://review.opendev.org/c/openstack/keystone-specs/+/84410017:00
opendevreviewHiromu Asahina proposed openstack/keystone-specs master: Disable auto-discovery for setuptools  https://review.opendev.org/c/openstack/keystone-specs/+/83990917:04
opendevreviewHiromu Asahina proposed openstack/keystone-specs master: Update python testing template to latest version  https://review.opendev.org/c/openstack/keystone-specs/+/83994517:04
opendevreviewHiromu Asahina proposed openstack/keystone-specs master: OAuth 2.0 Mutual-TLS Support  https://review.opendev.org/c/openstack/keystone-specs/+/84376517:04
opendevreviewPedro Henrique Pereira Martins proposed openstack/keystoneauth master: Add OTP to v3OIDCpassword plugin  https://review.opendev.org/c/openstack/keystoneauth/+/69734817:31
opendevreviewPedro Henrique Pereira Martins proposed openstack/keystoneauth master: Add OTP to v3OIDCpassword plugin  https://review.opendev.org/c/openstack/keystoneauth/+/69734817:32
*** dviroel is now known as dviroel|afk20:25
opendevreviewGhanshyam proposed openstack/keystone-tempest-plugin master: Add stable/yoga jobs on master gate  https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/83807021:24
opendevreviewGhanshyam proposed openstack/keystone-tempest-plugin master: Update stable branches jobs on master gate  https://review.opendev.org/c/openstack/keystone-tempest-plugin/+/83807023:50

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!