Monday, 2022-08-08

*** marlinc is now known as Guest747100:18
*** osmanlicilegi is now known as Guest748500:18
*** lbragstad8 is now known as lbragstad04:48
*** tobias-urdin5 is now known as tobias-urdin06:03
mkarpiarzHi all! With Keysone using LDAP as the identity provider, where are assignments between users and resources (for example quotas) stored?09:07
mkarpiarzI understand that LDAP users exist in LDAP and not the SQL database so other tables can't simply refer to them by a key, right?09:09
mkarpiarzAlso, I know quotas are project specific so I'd also like to know where and how LDAP organisation-to-resources are stored.09:11
tv1I have a question regarding federation;09:40
*** tv1 is now known as Kvisle09:40
KvisleI am integrating with multiple KeyCloak-instances using SAML.  I'm using mod_auth_mellon to absorb the saml-part.09:42
KvisleThis works great for a single identity provider, but I can't really see how I can do this with a second identity provider without adding a new protocol (named acme_saml2 or so) ... Because of the websso-endpoint that only includes the protocol-endpoint without the identity-provider-endpoint.09:42
Kvisleerh; Because of the websso-endpoint only including protocol, not identity-provider. Example: <Location "/v3/auth/OS-FEDERATION/websso/saml2">09:42
KvisleI have found that I can create a custom protocol that does saml (acme_saml2), but I need to register an entry point -- which I have successfully done by editing /usr/lib/python3.9/site-packages/keystone-21.0.0-py3.9.egg-info/entry_points.txt ... however, that would be reverted when I upgrade the package, so I am assuming I am doing something wrong09:44
KvisleCan anyone here point me in the right direction? What am I missing/doing wrong?09:44
*** dviroel_ is now known as dviroel11:38
opendevreviewGrzegorz Grasza proposed openstack/keystone master: Add an option to randomize LDAP urls list  https://review.opendev.org/c/openstack/keystone/+/82108612:34
*** dasm|off is now known as dasm13:31
*** dviroel is now known as dviroel|lunch15:29
*** dviroel|lunch is now known as dviroel16:38
*** dviroel is now known as dviroel|out21:22
*** dasm is now known as dasm|off22:03

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!