*** chrisshattuck has quit IRC | 00:01 | |
*** hdd has quit IRC | 00:05 | |
*** samueldmq has joined #openstack-keystone | 00:05 | |
*** dims__ has quit IRC | 00:16 | |
*** dims__ has joined #openstack-keystone | 00:57 | |
*** dims__ has quit IRC | 01:28 | |
*** lhcheng_ has quit IRC | 01:49 | |
*** lhcheng has joined #openstack-keystone | 01:49 | |
*** hdd has joined #openstack-keystone | 02:05 | |
*** chrisshattuck has joined #openstack-keystone | 02:06 | |
*** chrisshattuck has quit IRC | 02:06 | |
*** chrisshattuck has joined #openstack-keystone | 02:07 | |
*** lhcheng has quit IRC | 02:18 | |
*** dims__ has joined #openstack-keystone | 02:28 | |
*** lhcheng has joined #openstack-keystone | 02:29 | |
*** dims__ has quit IRC | 02:33 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Improve creation of expected role assignments https://review.openstack.org/144544 | 02:55 |
---|---|---|
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Improve List Role Assignment Tests https://review.openstack.org/137021 | 02:55 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Refactor role assignment assertions https://review.openstack.org/144543 | 02:55 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Fixes 'OS-INHERIT:inherited_to' info in tests https://review.openstack.org/144542 | 02:55 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Refactor check of targets and actors on RoleV3 https://review.openstack.org/144702 | 02:55 |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: Check for invalid filtering on v3/role_assignments https://review.openstack.org/144703 | 02:55 |
*** erkules has joined #openstack-keystone | 02:58 | |
*** erkules_ has quit IRC | 03:00 | |
*** samueldmq has quit IRC | 03:03 | |
*** lhcheng has quit IRC | 03:05 | |
*** lhcheng has joined #openstack-keystone | 03:06 | |
*** dims__ has joined #openstack-keystone | 03:07 | |
*** lhcheng has quit IRC | 03:10 | |
*** stevemar has quit IRC | 03:27 | |
*** lhcheng has joined #openstack-keystone | 03:32 | |
*** timcline has joined #openstack-keystone | 03:43 | |
*** timcline has quit IRC | 03:43 | |
*** timcline has joined #openstack-keystone | 03:44 | |
*** timcline has quit IRC | 03:45 | |
*** dims__ has quit IRC | 03:56 | |
*** chrisshattuck has quit IRC | 03:57 | |
*** chrisshattuck has joined #openstack-keystone | 03:58 | |
*** rm_work is now known as rm_work|away | 04:02 | |
*** hdd has quit IRC | 04:27 | |
*** dims__ has joined #openstack-keystone | 04:34 | |
*** wpf has quit IRC | 04:36 | |
*** wpf has joined #openstack-keystone | 04:41 | |
*** dims__ has quit IRC | 04:43 | |
*** lhcheng has quit IRC | 04:58 | |
*** rm_work|away is now known as rm_work | 04:59 | |
*** lhcheng has joined #openstack-keystone | 05:04 | |
*** jimbaker has quit IRC | 05:14 | |
*** lhcheng has quit IRC | 05:25 | |
*** stevemar has joined #openstack-keystone | 05:40 | |
*** ChanServ sets mode: +v stevemar | 05:40 | |
*** dims__ has joined #openstack-keystone | 05:44 | |
*** dims__ has quit IRC | 05:49 | |
*** LinstatSDR has joined #openstack-keystone | 06:03 | |
*** LinstatSDR has quit IRC | 06:09 | |
*** hdd has joined #openstack-keystone | 06:26 | |
*** lhcheng has joined #openstack-keystone | 06:26 | |
*** lhcheng has quit IRC | 06:31 | |
*** hdd has quit IRC | 07:00 | |
*** lhcheng has joined #openstack-keystone | 07:41 | |
*** chrisshattuck has quit IRC | 07:53 | |
*** lhcheng has quit IRC | 08:03 | |
openstackgerrit | Abhishek Kekane proposed openstack/keystone: Eventlet green threads not released back to pool https://review.openstack.org/130824 | 08:05 |
*** lhcheng has joined #openstack-keystone | 08:17 | |
*** lhcheng has joined #openstack-keystone | 08:17 | |
*** f13o has joined #openstack-keystone | 08:21 | |
*** lhcheng has quit IRC | 08:31 | |
*** stevemar has quit IRC | 08:43 | |
*** NAND_ has joined #openstack-keystone | 09:11 | |
*** andreaf has joined #openstack-keystone | 10:20 | |
NAND_ | Hey guys, wanted to ask if anyone knows about any problems that may occur during keystone upgrade (juno -> kilo) | 10:24 |
*** jaosorior has joined #openstack-keystone | 11:08 | |
*** dims__ has joined #openstack-keystone | 11:10 | |
*** dims__ has quit IRC | 11:15 | |
*** lhcheng has joined #openstack-keystone | 11:31 | |
*** samueldmq has joined #openstack-keystone | 11:32 | |
*** lhcheng has quit IRC | 11:36 | |
*** rm_work is now known as rm_work|away | 11:36 | |
*** samueldmq has quit IRC | 12:24 | |
*** jimbaker has joined #openstack-keystone | 12:36 | |
*** jimbaker has quit IRC | 12:36 | |
*** jimbaker has joined #openstack-keystone | 12:36 | |
*** therve` is now known as therve | 12:46 | |
*** NAND_ has quit IRC | 12:46 | |
*** samueldmq has joined #openstack-keystone | 13:20 | |
*** samueldmq has quit IRC | 13:40 | |
*** LinstatSDR has joined #openstack-keystone | 13:53 | |
*** dims__ has joined #openstack-keystone | 13:56 | |
openstackgerrit | Merged openstack/keystone: Remove extra V3 version router https://review.openstack.org/118522 | 14:08 |
*** LinstatSDR has quit IRC | 14:12 | |
*** pradip_vedams has joined #openstack-keystone | 14:15 | |
pradip_vedams | hi every one | 14:16 |
pradip_vedams | i am getting problem with keystone services | 14:16 |
pradip_vedams | i had submit the bug | 14:16 |
pradip_vedams | https://bugs.launchpad.net/keystone/+bug/1407090 | 14:16 |
uvirtbot | Launchpad bug 1407090 in keystone "Unable to start keystone service on Docker container" [Undecided,New] | 14:16 |
pradip_vedams | can anybody have any idea about how to setup keystone on docker container | 14:17 |
lbragstad | pradip_vedams: there was some stuff in Devstack for running services in docker containers but I'm not sure where that is at now. I want to say that it was ripped out last March? | 14:19 |
lbragstad | pradip_vedams: I've tried it a few times, but I end up getting stuck on issues with docker | 14:19 |
lbragstad | pradip_vedams: you could try using https://github.com/ewindisch/dockenstack | 14:20 |
*** dims__ has quit IRC | 14:28 | |
*** colettecello is now known as gothicmindfood | 14:44 | |
*** junhongl has quit IRC | 15:06 | |
*** junhongl has joined #openstack-keystone | 15:06 | |
*** dims__ has joined #openstack-keystone | 15:13 | |
*** pradip_vedams has quit IRC | 15:23 | |
*** dims__ has quit IRC | 15:29 | |
*** f13o has quit IRC | 15:31 | |
*** jungleboyj has joined #openstack-keystone | 15:34 | |
lbragstad | https://review.openstack.org/#/c/144669/ is an easy one for any other cores around | 16:12 |
*** BMDan has joined #openstack-keystone | 16:13 | |
BMDan | I've looked around, but I've been unable to find it: anyone know if there's a blueprint for RFC 3602 support in Keystone? It's the extended password change operation, which would allow us to offload password validation onto LDAP (right now, since we just push a hashed password in, there's no way to e.g. check that the minimum password length is satisfied). | 16:14 |
*** chrisshattuck has joined #openstack-keystone | 16:15 | |
*** thedodd has joined #openstack-keystone | 16:23 | |
*** afazekas has joined #openstack-keystone | 16:24 | |
lbragstad | BMDan: I don't believe so, | 16:24 |
lbragstad | BMDan: that sounds like it'd be a specific auth plugin type/operation | 16:25 |
*** dims__ has joined #openstack-keystone | 16:30 | |
*** samueldmq has joined #openstack-keystone | 16:32 | |
*** dims__ has quit IRC | 16:34 | |
*** stevemar has joined #openstack-keystone | 16:42 | |
*** ChanServ sets mode: +v stevemar | 16:42 | |
*** _cjones_ has joined #openstack-keystone | 16:43 | |
*** samueldmq has quit IRC | 16:44 | |
bknudson | BMDan: https://tools.ietf.org/html/rfc3602 ? | 16:46 |
bknudson | nobody should be using LDAP directly with Keystone... that's what federation is for. | 16:46 |
*** larsks|alt is now known as larsks | 16:50 | |
*** samueldmq has joined #openstack-keystone | 16:55 | |
*** stevemar has quit IRC | 17:03 | |
*** stevemar has joined #openstack-keystone | 17:03 | |
*** ChanServ sets mode: +v stevemar | 17:03 | |
*** dims__ has joined #openstack-keystone | 17:07 | |
*** dims__ has quit IRC | 17:07 | |
*** LinstatSDR has joined #openstack-keystone | 17:12 | |
*** rwsu has joined #openstack-keystone | 17:23 | |
*** samueldmq has quit IRC | 17:27 | |
*** jdennis has joined #openstack-keystone | 17:36 | |
*** afaranha has joined #openstack-keystone | 17:37 | |
*** dims__ has joined #openstack-keystone | 17:38 | |
*** dims__ has quit IRC | 17:43 | |
*** LinstatSDR has quit IRC | 17:51 | |
*** harlowja_away is now known as harlowja | 18:11 | |
openstackgerrit | Merged openstack/keystone: Update the keystone.conf sample https://review.openstack.org/144669 | 18:13 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/python-keystoneclient-federation: Updated from global requirements https://review.openstack.org/144785 | 18:21 |
*** hdd has joined #openstack-keystone | 18:25 | |
BMDan | bknudson: Sorry, 3062*, not 3602. As to federation: I'm using [identity] driver=keystone.identity.backends.ldap.Identity | 18:25 |
BMDan | Am I taking the wrong approach? | 18:26 |
*** afaranha_ has joined #openstack-keystone | 18:29 | |
*** afaranha has quit IRC | 18:30 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Add positive test case for content types https://review.openstack.org/130591 | 18:31 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Tests assert 200 on POST operations instead of 201 https://review.openstack.org/142440 | 18:31 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Expose bug in token revocation for projects https://review.openstack.org/142099 | 18:32 |
BMDan | (While I wait for a reply…) I'm going to see how far I can get with adding rfc3062 support to keystone.identity.backends.ldap.Identity, as it just seems generally useful. | 18:37 |
*** afaranha__ has joined #openstack-keystone | 18:38 | |
*** afaranha_ has quit IRC | 18:39 | |
*** tellesnobrega has quit IRC | 18:42 | |
*** samuelms has quit IRC | 18:43 | |
BMDan | bknudson: Specifically, I followed (mostly) http://docs.openstack.org/admin-guide-cloud/content/configuring-keystone-for-ldap-backend.html | 18:48 |
*** afaranha__ has quit IRC | 18:50 | |
bknudson | BMDan: my opinion is that it's the wrong approach. Eventually all that code should be going away in favor of federation | 18:50 |
bknudson | and if you're using LDAP with keystone it should be in read-only mode. make updates to ldap using your ldap tools. | 18:52 |
*** rwsu has quit IRC | 18:55 | |
*** rwsu has joined #openstack-keystone | 18:55 | |
*** radez_g0` is now known as radez | 18:56 | |
*** dims__ has joined #openstack-keystone | 19:06 | |
*** tellesnobrega has joined #openstack-keystone | 19:07 | |
*** samuelms has joined #openstack-keystone | 19:08 | |
BMDan | bknudson: I'm in Icehouse due to a need for LTS (this is a security-audited deployment, so I can't chase head). I don't foresee the needed bits of Federation being backported, do you? As to changing passwords—fair enough, I could do it with an external tool, instead, but why not take advantage of a single interface, since I've already got it? 3062 is also more secure, if only because it enables stronger hash options and (at least on 3 | 19:13 |
*** dims__ has quit IRC | 19:13 | |
BMDan | At the risk of creating an XY problem for myself, though, here's the whole story: I've got a VPN server and my OpenStack. I need both of them to share a password DB, and I need to enforce the use of strong passwords. If there's a better overall approach to this, I'm open to it! | 19:14 |
bknudson | BMDan: federation will not be backported... openstack policy is to not backport features (only bugs). | 19:19 |
BMDan | bknudson: Unintentional humor? ;) | 19:22 |
BMDan | But, yes, figured. So, that means I get to hoe the lonely row on my own, I guess. S'ok, it doesn't strike me as being that hard, based on what I've seen thus far. | 19:23 |
BMDan | I'll push my changes back up towards the tree, keeping in mind they're unlikely to be applied, just in case someone else finds themselves in my same bind. :) | 19:24 |
BMDan | ["bind": no pun intended] | 19:24 |
*** lhcheng has joined #openstack-keystone | 19:27 | |
*** lhcheng_ has joined #openstack-keystone | 19:30 | |
bknudson | BMDan: are extended operations supported by python ldpa? | 19:32 |
bknudson | ldap | 19:32 |
*** lhcheng has quit IRC | 19:32 | |
BMDan | bknudson: Yes: http://www.python-ldap.org/doc/html/ldap.html#ldap.LDAPObject.passwd | 19:41 |
bknudson | BMDan: ok, should be easy | 19:42 |
BMDan | bknudson: Yeah, for you. I'm not very good at Python; I'm an old, grizzled C veteran. I like my programs undocumented and my pointer math endian-dependent. ;) | 19:47 |
BMDan | But I'll push this up somewhere when I'm done so you more-talented folk can mock me until it's half-decent. :) | 19:47 |
*** hdd has quit IRC | 19:50 | |
*** jdandrea has quit IRC | 20:01 | |
*** jaosorior has quit IRC | 20:03 | |
*** zzzeek has joined #openstack-keystone | 20:10 | |
*** dims__ has joined #openstack-keystone | 20:14 | |
*** dims__ has quit IRC | 20:18 | |
*** dims__ has joined #openstack-keystone | 20:18 | |
*** EmilienM is now known as EmilienM|afk | 20:24 | |
*** thedodd has quit IRC | 20:24 | |
*** harlowja is now known as harlowja_away | 20:28 | |
*** _cjones_ has quit IRC | 20:29 | |
*** andreaf has quit IRC | 20:35 | |
*** andreaf has joined #openstack-keystone | 20:36 | |
*** dims__ has quit IRC | 20:36 | |
*** andreaf has quit IRC | 20:40 | |
*** andreaf has joined #openstack-keystone | 20:41 | |
*** _cjones_ has joined #openstack-keystone | 20:44 | |
*** andreaf has quit IRC | 20:48 | |
*** zzzeek has quit IRC | 20:48 | |
*** andreaf has joined #openstack-keystone | 20:48 | |
*** zzzeek has joined #openstack-keystone | 20:48 | |
*** EmilienM|afk is now known as EmilienM | 20:52 | |
*** LinstatSDR has joined #openstack-keystone | 21:01 | |
*** andreaf has quit IRC | 21:04 | |
*** andreaf has joined #openstack-keystone | 21:05 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: switch from sample_config.sh to oslo-config-generator https://review.openstack.org/113905 | 21:05 |
*** dims_ has joined #openstack-keystone | 21:06 | |
*** andreaf has quit IRC | 21:11 | |
*** andreaf has joined #openstack-keystone | 21:12 | |
*** fifieldt has quit IRC | 21:19 | |
*** fifieldt_ has joined #openstack-keystone | 21:19 | |
*** andreaf has quit IRC | 21:24 | |
*** andreaf has joined #openstack-keystone | 21:24 | |
*** LinstatSDR has quit IRC | 21:41 | |
*** lhcheng_ has quit IRC | 21:44 | |
*** hdd has joined #openstack-keystone | 21:48 | |
*** zzzeek has quit IRC | 21:51 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Remove test PYTHONHASHSEED setting https://review.openstack.org/136593 | 21:58 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Correct XMLEquals matcher for ordering https://review.openstack.org/138918 | 21:58 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Correct test_auth_unscoped_token_project for result ordering https://review.openstack.org/138919 | 21:58 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Correct test_get_v3_catalog test for result ordering https://review.openstack.org/138920 | 21:58 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Correct catalog response checker for result ordering https://review.openstack.org/138921 | 21:58 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Correct a v3 auth test for result ordering https://review.openstack.org/138922 | 21:58 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Correct version tests for result ordering https://review.openstack.org/138923 | 21:58 |
*** andreaf has quit IRC | 22:04 | |
*** andreaf has joined #openstack-keystone | 22:05 | |
*** dims_ has quit IRC | 22:05 | |
*** dims__ has joined #openstack-keystone | 22:09 | |
*** stevemar has quit IRC | 22:17 | |
*** dims__ has quit IRC | 22:31 | |
*** hdd has quit IRC | 22:39 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Tests fail only on deprecation warnings from keystone https://review.openstack.org/144810 | 22:43 |
*** dims__ has joined #openstack-keystone | 22:57 | |
*** dims__ has quit IRC | 23:05 | |
*** BMDan has quit IRC | 23:07 | |
*** rwsu has quit IRC | 23:07 | |
*** rwsu has joined #openstack-keystone | 23:18 | |
*** chrisshattuck has quit IRC | 23:23 | |
*** stevemar has joined #openstack-keystone | 23:50 | |
*** ChanServ sets mode: +v stevemar | 23:50 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!