15:00:24 #startmeeting keystone 15:00:24 Meeting started Wed Jun 18 15:00:24 2025 UTC and is due to finish in 60 minutes. The chair is gtema. Information about MeetBot at http://wiki.debian.org/MeetBot. 15:00:24 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 15:00:24 The meeting name has been set to 'keystone' 15:00:32 Reminder: This meeting takes place under the OpenInfra Foundation Code of Conduct 15:00:39 #link https://openinfra.dev/legal/code-of-conduct 15:00:48 #topic roll call 15:00:56 admiyo, bbobrov, crisloma, d34dh0r53, dpar, dstanek, hrybacki, lbragstad, lwanderley, kmalloc, rodrigods, samueldmq, ruan_he, wxy, sonuk, vishakha, Ajay, rafaelwe, xek, gmann, zaitcev, reqa, dmendiza[m], dmendiza, mharley, jph, gtema, cardoe, deydra 15:01:01 o/ 15:01:53 special ping for dmendiza 15:02:42 looks we are alone Greg 15:02:46 :) 15:02:54 #topic review past meeting work items 15:03:03 #link https://meetings.opendev.org/meetings/keystone/2025/keystone.2025-06-11-15.12.html 15:03:19 dmendiza: wanted to update S-RBAC topic 15:03:37 I see it is not done 15:04:32 na well, ... 15:04:35 #topic liaison updates 15:04:43 there is nothing from me 15:05:01 no updates from me either 15:05:26 ack, then we jump into 15:05:28 #topic specification 15:05:37 #topic oauth2 15:06:03 I do not think there are any changes, so not going to post all the links yet again 15:06:24 #topic openapi 15:06:54 changes that I posted last week are now merged. Will take a look at going further with split of request/responses 15:07:14 #topis secure rbac 15:07:26 I have myself just updated 2024.1 to 2025.2 15:07:32 I mean in the agenda 15:08:21 I see we set enforce_new_defaults in some federation tests 15:09:44 and also I see enforce_new_defaults is default to True in oslo.policy 15:10:16 with that I am actually wondering - is there anything to do wrt that? 15:12:08 i am from NetApp. we have customer who is looking for SAML based authentication between Cinder and Netapp filer through data-plane connection. Are there any existing workflows where Cinder is using keystone for SAML auth with backed storage? 15:12:11 ok, without Doug I am not willing to drop the item from agenda, but at the same time I believe there is actually nothing to do since we do not flip the defaults on the Keystone side 15:13:22 jayaanand_ - not sure. From Keystone side we have no clue what Cinder is doing and how 15:14:13 on the other side Dave Wilde (d34dh0r53) mentined recently that in RH 10 mod_shiboleth is going to be dropped so in general future of SAML is under the axe 15:15:37 on the other side I hardly believe Cinder NetApp may have any SAML communication since it requires browser. So it is not usable for the server-side flows from my knowledge 15:16:09 anyway, 15:16:12 #topic open discussion 15:16:34 Hi, I posted a patch that needs review 15:16:48 yes, I have seen that 15:16:53 #link https://review.opendev.org/c/openstack/keystone/+/951792 15:17:13 problem is that we have no CI and nobody having practical experience with AD so far 15:17:32 so reviewing this is not easy 15:17:54 well, it is easy, but ensuring it is correct is not 15:18:45 #action review https://review.opendev.org/c/openstack/keystone/+/951792 on friday during reviewaton 15:19:40 anything else for open discussion? 15:19:46 I see, thanks 15:20:29 #topic bug review 15:20:31 Please at least check if the changes are acceptable for you because it kind og goes against the design of the classes there 15:20:58 as recorded, we would try to check it on friday in regular review meeting 15:21:37 #link https://bugs.launchpad.net/keystone/?orderby=-id&start=0 15:21:55 no new bugs in Keystone (huray) 15:22:06 #link https://bugs.launchpad.net/python-keystoneclient/?orderby=-id&start=0 15:22:16 nothing in python-keystoneclient either 15:22:41 #link https://bugs.launchpad.net/keystoneauth/+bugs?orderby=-id&start=0 15:22:49 nothing new in keystoneauth 15:23:15 #link https://bugs.launchpad.net/keystonemiddleware/+bugs?orderby=-id&start=0 15:23:17 nothing new 15:23:42 #link https://bugs.launchpad.net/pycadf/+bugs?orderby=-id&start=0 15:23:47 nothing in pycadf 15:24:02 that would be it for bugs 15:24:04 #topic conclusion 15:24:19 last chance to raise anything 15:24:49 #action discuss with missing folks on Friday during reviewaton abount CFP for forum and Project Update 15:25:29 Does not look like there is anything else 15:25:36 With that - thanks folks 15:25:43 #endmeeting