Tuesday, 2026-01-20

*** mhen_ is now known as mhen02:48
opendevreviewGrzegorz Grasza proposed openstack/keystone master: Add OpenID Connect CLI authentication examples  https://review.opendev.org/c/openstack/keystone/+/97171411:43
stephenfingtema: I was trying to bump pyOpenSSL but it's being held back by pysaml2 which looks rather unmaintained. Am I imagining things, or was there a plan to remove that functionality from keystone?  https://review.opendev.org/c/openstack/requirements/+/972474/15:45
gtemayes, this is exactly what we were discussing during the PTG. There is no way rather than drop the saml support, but it can not happen without a massive rework of the Keystone which I am doing in Rust. In the near future we would not be able to get rid of saml support and support for exploring rewrite was also not very huge15:47
stephenfinIt seems our usage of pysaml2 is rather small. What about vendoring only what we need?15:47
gtemanot sure it helps. It is a pretty security sensitive component in addition, so a very specific knowledge is expected15:49
gtemabut you are definitely correct - usage is small with only few CSPs relying on it15:49
gtemaand I am working with them on redesigning the stuff15:50
gtemastephenfin: pysaml2 is (from what I understood) being dropped from the newer RH stack meaning it is a technological end and we should rather focus on getting rid of it rather than trying to keep it alive15:52
stephenfinpysaml2 specifically, or SAML in general?15:56
gtemaboth15:56
stephenfinack15:57
gtemaOIDC intends to replace the SAML but there are still few cornercases that are not addressed. Due to that people still use SAML (mostly Enterprises only)15:57
opendevreviewMerged openstack/keystone master: Update hard-coded policy for GET /v3/limits  https://review.opendev.org/c/openstack/keystone/+/97316316:21
opendevreviewIvan Anfimov proposed openstack/keystonemiddleware master: Remove url tags from README  https://review.opendev.org/c/openstack/keystonemiddleware/+/97400020:46
opendevreviewIvan Anfimov proposed openstack/keystonemiddleware master: Remove url tags from README  https://review.opendev.org/c/openstack/keystonemiddleware/+/97400020:47

Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!