*** dims has quit IRC | 00:04 | |
*** dims has joined #openstack-keystone | 00:22 | |
*** bknudson has joined #openstack-keystone | 00:43 | |
*** ChanServ sets mode: +v bknudson | 00:43 | |
*** redrobot has quit IRC | 00:59 | |
*** amauryme` has quit IRC | 01:01 | |
*** mordred has quit IRC | 01:01 | |
*** tellesnobrega has quit IRC | 01:01 | |
*** navid_ has quit IRC | 01:01 | |
*** amaurymedeiros has joined #openstack-keystone | 01:05 | |
*** amaurymedeiros has quit IRC | 01:05 | |
*** amaurymedeiros has joined #openstack-keystone | 01:05 | |
*** redrobot has joined #openstack-keystone | 01:06 | |
*** mordred has joined #openstack-keystone | 01:06 | |
*** redrobot is now known as Guest48074 | 01:06 | |
*** stevemar has quit IRC | 01:07 | |
*** navid_ has joined #openstack-keystone | 01:14 | |
*** tellesnobrega has joined #openstack-keystone | 01:15 | |
*** alexsyip has quit IRC | 01:25 | |
*** lhcheng has quit IRC | 01:31 | |
*** devlaps1 has quit IRC | 01:35 | |
*** tqtran_ has quit IRC | 01:37 | |
ayoung | Is there anyone here? I need to brag about something? morganfainberg ? | 01:41 |
---|---|---|
morganfainberg | brag away | 01:42 |
ayoung | morganfainberg, OK so you know how I was working on Federation with SSSD? It works with WebSSO, no code changes required | 01:43 |
morganfainberg | nice | 01:44 |
ayoung | morganfainberg, yeah, and it gives us a path to get rid of LDAP identity | 01:44 |
ayoung | morganfainberg, I think I can make it work on the Keystone side with Basic Auth | 01:44 |
ayoung | If we really wanted to | 01:45 |
morganfainberg | ayoung, so if you saw my PTL email... | 01:45 |
morganfainberg | and read it | 01:45 |
ayoung | but the short of it is that this is how we can move forward | 01:45 |
ayoung | too much white space | 01:45 |
morganfainberg | my hope is we can eventually punt all the backends into their own namespaces/repos | 01:45 |
*** erkules_ has joined #openstack-keystone | 01:45 | |
morganfainberg | with stable ABIs | 01:45 |
morganfainberg | meaning SSSD, LDAP, etc all become "whatever you want to install" | 01:45 |
morganfainberg | meaning... if someone loves LDAP Identity we can make them core on it/have it's own core team | 01:46 |
morganfainberg | that can do craaaaaaazy things to optimise it | 01:46 |
morganfainberg | w/o impacting other things | 01:46 |
ayoung | SSSD required only the Federation code. It Is all on the Apache server. It is even less.... | 01:46 |
morganfainberg | ayoung, so it's a conf. doc | 01:46 |
morganfainberg | but you see what i'm driving at | 01:46 |
ayoung | yep | 01:46 |
morganfainberg | make keystone the framework to manage identity to OpenStack | 01:47 |
ayoung | morganfainberg, I'm particaularly please by this little hack. IN order to \figure out what suyb urls need to be rprotected by kerberos... | 01:47 |
*** erkules has quit IRC | 01:47 | |
ayoung | <location ~ "kerberos" > | 01:47 |
ayoung | AuthType Kerberos | 01:47 |
morganfainberg | how the identity gets into keystone becomes a question for the deployer. the functional test suite is then keystone's core testing, and should work against any backend | 01:47 |
ayoung | ... | 01:47 |
morganfainberg | :) | 01:47 |
ayoung | I'm pretty sure I can make this work with X509 the exact same way, too | 01:48 |
openstackgerrit | Merged openstack/keystone: Update sample config file https://review.openstack.org/170165 | 01:48 |
ayoung | So...we should de-emphasize going to /auth/token to get an unscoped token, and instead use the federation urls for that. | 01:48 |
ayoung | Ideally the Federation URL would be the Auth URL, and that idea of the mini service catalog in the unscoped token would then point the user at /v3/auth instead | 01:49 |
ayoung | I'll get a demo of this up on the Younglogic site. | 01:50 |
*** harlowja is now known as harlowja_away | 01:52 | |
*** markvoelker has quit IRC | 02:01 | |
*** markvoelker has joined #openstack-keystone | 02:03 | |
*** davechen has joined #openstack-keystone | 02:18 | |
*** spandhe has quit IRC | 02:32 | |
morganfainberg | ayoung, this could use a quick prodding: https://review.openstack.org/#/c/165962/ | 03:04 |
openstackgerrit | Merged openstack/keystone: Fix errors in ec2 signature logic checking https://review.openstack.org/143772 | 03:07 |
ayoung | done | 03:09 |
*** alexsyip has joined #openstack-keystone | 03:32 | |
*** tqtran has joined #openstack-keystone | 03:40 | |
*** links has joined #openstack-keystone | 03:45 | |
*** zzzeek has joined #openstack-keystone | 03:46 | |
*** stevemar has joined #openstack-keystone | 03:46 | |
*** ChanServ sets mode: +v stevemar | 03:46 | |
*** chlong has joined #openstack-keystone | 03:48 | |
*** chlong has quit IRC | 03:49 | |
*** rushiagr_away is now known as rushiagr | 03:58 | |
openstackgerrit | Merged openstack/keystone: Fix setting default log levels https://review.openstack.org/165962 | 04:04 |
*** tqtran has quit IRC | 04:05 | |
*** Guest7019 has joined #openstack-keystone | 04:17 | |
*** Guest7019 is now known as wanghong | 04:19 | |
*** wanghong has quit IRC | 04:29 | |
*** devlaps has joined #openstack-keystone | 04:42 | |
*** briancurtin has quit IRC | 04:46 | |
*** dougwig has quit IRC | 04:46 | |
*** zhiyan has quit IRC | 04:46 | |
*** ctracey has quit IRC | 04:46 | |
*** zhiyan has joined #openstack-keystone | 04:47 | |
*** briancurtin has joined #openstack-keystone | 04:47 | |
*** dougwig has joined #openstack-keystone | 04:48 | |
*** ctracey has joined #openstack-keystone | 04:49 | |
*** Administrator has joined #openstack-keystone | 05:07 | |
*** Administrator is now known as Guest89150 | 05:07 | |
*** Guest89150 is now known as wanghong | 05:07 | |
*** henrynash has joined #openstack-keystone | 05:10 | |
*** ChanServ sets mode: +v henrynash | 05:10 | |
*** zzzeek has quit IRC | 05:11 | |
henrynash | stevemar, dstanek, morganfainberg: I took over https://review.openstack.org/#/c/138113/ and added a fix for it in https://review.openstack.org/#/c/170022/ (the fix is super simple)…. | 05:12 |
stevemar | classic henrynash, taking over things | 05:12 |
henrynash | stevemar: a core’s gotta do, what a core’s gotto do… | 05:13 |
stevemar | excamined is a funny word | 05:13 |
henrynash | i didn’t wriet that bit! Hmmm, yes, there ar a few typos in that commit message! | 05:14 |
henrynash | can fix that if required | 05:14 |
stevemar | henrynash, tweak the commit msg of the second patch, it was copy/pasta | 05:14 |
henrynash | will do | 05:14 |
openstackgerrit | henry-nash proposed openstack/keystone: Fix multiple SQL backend usage validation error https://review.openstack.org/170022 | 05:15 |
henrynash | done | 05:15 |
stevemar | that is some convoluted testing yo | 05:17 |
stevemar | 3 mocks in a row, you aren't playing | 05:17 |
henrynash | stevemar: yep, agreed…..can’t take credit, Bogun wrotoe that…clearly a master mocker | 05:18 |
*** rushiagr is now known as rushiagr_away | 05:20 | |
openstackgerrit | henry-nash proposed openstack/keystone: Expose multiple SQL backend usage validation error https://review.openstack.org/138113 | 05:26 |
stevemar | henrynash, gah, we should have made _assert_no_more_than_one_sql_driver return a boolean :P | 05:27 |
stevemar | tracking _any_sql is a pain | 05:27 |
henrynash | stevemar: guilty | 05:27 |
henrynash | stevemar: although there are others that prefer the exception raiseing to be done out-of-band (i.e. in things liek _assert…) | 05:28 |
openstackgerrit | henry-nash proposed openstack/keystone: Fix multiple SQL backend usage validation error https://review.openstack.org/170022 | 05:28 |
stevemar | henrynash, that's true, we do that in bits of federation code | 05:29 |
stevemar | henrynash, the follow-on patch looks good | 05:29 |
morganfainberg | stevemar, i mock your mocking so it's a mock of a mocking mock? | 05:33 |
morganfainberg | henrynash, isn't it... either stupidly early or stupidly late where you are? | 05:34 |
henrynash | I’m actually in France, so it’s only vaguely stupidly early | 05:34 |
morganfainberg | henrynash, OH | 05:35 |
morganfainberg | wait... | 05:35 |
morganfainberg | you're not on vacation are you? | 05:35 |
morganfainberg | cause... | 05:35 |
openstackgerrit | henry-nash proposed openstack/keystone: Fix multiple SQL backend usage validation error https://review.openstack.org/170022 | 05:36 |
henrynash | well, it’s a public holiday today (well in the UK it is)… | 05:37 |
stevemar | for us too :D | 05:37 |
morganfainberg | hol...i...day? | 05:37 |
henrynash | ha ha | 05:38 |
morganfainberg | stevemar, i'm going to check out for the evening. we need to hit the bugs hard tomorrow. | 05:38 |
morganfainberg | ayoung, commented on https://review.openstack.org/#/c/169045/ +2 as it is, but didn't want to approve until you / others saw the comment | 05:46 |
stevemar | morganfainberg, i'm off tomorrow :) | 05:48 |
morganfainberg | stevemar, crap | 05:48 |
morganfainberg | stevemar, :( | 05:48 |
morganfainberg | stevemar, have a good day off or something then | 05:48 |
morganfainberg | ;) | 05:48 |
stevemar | i would normally lurk and help out, but i actually have plans for most of the day | 05:48 |
stevemar | evening should be okay | 05:48 |
*** topol has quit IRC | 05:59 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Imported Translations from Transifex https://review.openstack.org/170354 | 06:03 |
*** spandhe has joined #openstack-keystone | 06:05 | |
*** alexsyip has quit IRC | 06:26 | |
*** ParsectiX has joined #openstack-keystone | 06:27 | |
*** markvoelker has quit IRC | 06:29 | |
*** rushiagr_away is now known as rushiagr | 06:29 | |
*** henrynash has quit IRC | 06:29 | |
*** lhcheng has joined #openstack-keystone | 06:33 | |
*** spandhe has quit IRC | 06:42 | |
*** davechen1 has joined #openstack-keystone | 06:59 | |
openstackgerrit | Merged openstack/keystone: Cleanup use of .driver https://review.openstack.org/166542 | 06:59 |
*** markvoelker has joined #openstack-keystone | 06:59 | |
*** davechen has quit IRC | 07:01 | |
*** henrynash has joined #openstack-keystone | 07:02 | |
*** ChanServ sets mode: +v henrynash | 07:02 | |
breton | what kind of bugs? | 07:02 |
stevemar | breton, the bugs here: https://launchpad.net/keystone/+milestone/kilo-rc1 | 07:03 |
*** markvoelker has quit IRC | 07:04 | |
*** ajayaa has joined #openstack-keystone | 07:10 | |
*** ParsectiX has quit IRC | 07:11 | |
*** henrynash has quit IRC | 07:18 | |
*** stevemar has quit IRC | 07:18 | |
*** jistr has joined #openstack-keystone | 07:29 | |
*** ParsectiX has joined #openstack-keystone | 07:32 | |
openstackgerrit | Merged openstack/keystone: Exposes bug in Federation list projects endpoint https://review.openstack.org/158163 | 07:41 |
openstackgerrit | Merged openstack/keystone: Fixes bug in Federation list projects endpoint https://review.openstack.org/169113 | 07:41 |
openstackgerrit | Merged openstack/keystone: Imported Translations from Transifex https://review.openstack.org/170354 | 07:52 |
openstackgerrit | Victor Sergeyev proposed openstack/keystone: Fix index name the assignment.actor_id table. https://review.openstack.org/137637 | 07:57 |
*** ajayaa has quit IRC | 07:59 | |
*** markvoelker has joined #openstack-keystone | 08:00 | |
*** dims has quit IRC | 08:03 | |
*** rushiagr is now known as rushiagr_away | 08:04 | |
*** markvoelker has quit IRC | 08:05 | |
*** lhcheng is now known as lhcheng_afk | 08:07 | |
*** ajayaa has joined #openstack-keystone | 08:11 | |
*** Bsony has joined #openstack-keystone | 08:12 | |
*** lhcheng_afk has quit IRC | 08:27 | |
*** markvoelker has joined #openstack-keystone | 09:01 | |
*** markvoelker has quit IRC | 09:05 | |
*** rushiagr_away is now known as rushiagr | 09:09 | |
*** devlaps has quit IRC | 09:19 | |
zigo | morganfainberg: Hey, I just wrote a bit of text on how to do Debian builds, if you want to have a look: http://openstack.alioth.debian.org/ | 09:22 |
zigo | The first paragraph is for you guys (upstream) who want to test building with Debian. | 09:22 |
*** wanghong has quit IRC | 09:32 | |
*** rushiagr is now known as rushiagr_away | 09:43 | |
*** rushiagr_away is now known as rushiagr | 09:58 | |
*** davechen1 has quit IRC | 09:59 | |
*** markvoelker has joined #openstack-keystone | 10:02 | |
*** toddnni has quit IRC | 10:05 | |
*** toddnni has joined #openstack-keystone | 10:05 | |
*** lhcheng_afk has joined #openstack-keystone | 10:05 | |
*** markvoelker has quit IRC | 10:06 | |
*** dims has joined #openstack-keystone | 10:12 | |
*** dims has quit IRC | 10:13 | |
*** toddnni_ has joined #openstack-keystone | 10:17 | |
*** lhcheng__ has joined #openstack-keystone | 10:19 | |
*** dims has joined #openstack-keystone | 10:19 | |
*** toddnni has quit IRC | 10:20 | |
*** toddnni_ is now known as toddnni | 10:20 | |
*** lhcheng_afk has quit IRC | 10:21 | |
*** lhcheng__ has quit IRC | 10:52 | |
*** markvoelker has joined #openstack-keystone | 11:02 | |
*** toddnni_ has joined #openstack-keystone | 11:06 | |
*** markvoelker has quit IRC | 11:07 | |
*** toddnni has quit IRC | 11:09 | |
*** toddnni_ is now known as toddnni | 11:09 | |
*** amakarov_away is now known as amakarov | 11:20 | |
*** aix has joined #openstack-keystone | 11:20 | |
*** toddnni has quit IRC | 11:23 | |
*** toddnni has joined #openstack-keystone | 11:25 | |
*** markvoelker has joined #openstack-keystone | 12:03 | |
*** markvoelker has quit IRC | 12:08 | |
*** erkules_ is now known as erkules | 12:19 | |
*** erkules has joined #openstack-keystone | 12:19 | |
*** adam_g is now known as adam_g_out | 12:20 | |
*** markvoelker has joined #openstack-keystone | 12:21 | |
*** fhubik_meeting has joined #openstack-keystone | 12:27 | |
*** fhubik_meeting is now known as fhubik_afk | 12:27 | |
*** jistr_ has joined #openstack-keystone | 12:27 | |
*** lsmola_ has joined #openstack-keystone | 12:27 | |
*** fhubik_lunch has quit IRC | 12:29 | |
*** jistr has quit IRC | 12:30 | |
*** lsmola has quit IRC | 12:31 | |
*** fhubik_lunch has joined #openstack-keystone | 12:31 | |
*** jistr has joined #openstack-keystone | 12:31 | |
*** fhubik_afk has quit IRC | 12:31 | |
*** lsmola_ has quit IRC | 12:32 | |
*** jistr_ has quit IRC | 12:32 | |
*** lsmola_ has joined #openstack-keystone | 12:44 | |
*** davechen has joined #openstack-keystone | 12:57 | |
*** bknudson has quit IRC | 13:00 | |
*** dims has quit IRC | 13:01 | |
*** dims has joined #openstack-keystone | 13:02 | |
*** davechen has quit IRC | 13:03 | |
*** ayoung has quit IRC | 13:24 | |
*** bknudson has joined #openstack-keystone | 13:30 | |
*** ChanServ sets mode: +v bknudson | 13:30 | |
*** openstackgerrit has quit IRC | 13:36 | |
*** openstackgerrit has joined #openstack-keystone | 13:36 | |
*** davechen has joined #openstack-keystone | 13:37 | |
*** davechen has quit IRC | 13:38 | |
*** joesavak has joined #openstack-keystone | 13:39 | |
*** rushiagr is now known as rushiagr_away | 13:41 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:43 | |
openstackgerrit | Merged openstack/oslo.policy: Lists for Generic Checks https://review.openstack.org/169045 | 13:49 |
*** joesavak has quit IRC | 13:56 | |
*** ajayaa has quit IRC | 14:03 | |
*** edmondsw has joined #openstack-keystone | 14:12 | |
*** rushiagr_away is now known as rushiagr | 14:28 | |
*** topol has joined #openstack-keystone | 14:30 | |
*** ChanServ sets mode: +v topol | 14:30 | |
*** carlosmarin has joined #openstack-keystone | 14:31 | |
*** links has quit IRC | 14:33 | |
*** iamjarvo has joined #openstack-keystone | 14:33 | |
*** iamjarvo has quit IRC | 14:33 | |
*** iamjarvo has joined #openstack-keystone | 14:34 | |
*** openstackgerrit has quit IRC | 14:39 | |
*** openstackgerrit has joined #openstack-keystone | 14:39 | |
*** eezhova has quit IRC | 14:41 | |
*** henrynash has joined #openstack-keystone | 14:50 | |
*** ChanServ sets mode: +v henrynash | 14:50 | |
*** jdandrea has joined #openstack-keystone | 14:59 | |
*** thedodd has joined #openstack-keystone | 15:07 | |
*** EmilienM is now known as EmilienM|afk | 15:07 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Group role revocation invalidates all user tokens https://review.openstack.org/141854 | 15:17 |
*** zzzeek has joined #openstack-keystone | 15:23 | |
jdandrea | Reality check Q: Given only a keystone token (based on a project/username/password), is there a way to verify a given role assignment (like admin)? | 15:24 |
bknudson | jdandrea: validate the token and it'll give you the roles. | 15:24 |
jdandrea | bknudson: Tx! So I can use tokens.validate and pass in the token. Wonderful. | 15:26 |
*** links has joined #openstack-keystone | 15:27 | |
*** EmilienM|afk is now known as EmilienM | 15:39 | |
*** rushiagr is now known as rushiagr_away | 15:40 | |
*** ParsectiX has quit IRC | 15:41 | |
*** packet has joined #openstack-keystone | 15:44 | |
*** dims is now known as dimsum__ | 15:44 | |
*** rushiagr_away is now known as rushiagr | 15:51 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Failing bandit test - DO NOT MERGE https://review.openstack.org/170547 | 15:51 |
*** jistr has quit IRC | 15:53 | |
*** jistr has joined #openstack-keystone | 15:53 | |
jdandrea | bknudson: I tried to access validate() but I'm not finding it. Must be pilot error. It's in the docs. http://paste.openstack.org/show/198147/ | 15:58 |
bknudson | jdandrea: I think it's pretty recent... what version of python-keystoneclient? | 15:59 |
bknudson | jdandrea: here's the change that added validate token to v3: https://review.openstack.org/#/c/142147/ | 16:00 |
jdandrea | bknudson: Thank you! I will check. I bet I have a version from December. | 16:01 |
jdandrea | bknudson: Odd. The blueprint shows up as "New." This lands in kilo, yes? | 16:06 |
bknudson | jdandrea: the blueprint is to get auth_token middleware to use the keystoneclient, and that won't be done in kilo. | 16:07 |
jdandrea | Ah. Ok. I'm trying to find the blueprint that shows where this lands. | 16:07 |
jdandrea | (the validate) | 16:07 |
jdandrea | Or maybe there isn't one. | 16:07 |
jdandrea | Although, wait, clients aren't tied to releases. | 16:08 |
jdandrea | So it should be there now. :) | 16:08 |
bknudson | jdandrea: you can check the git logs for it, git log <tag> | 16:08 |
jdandrea | tx *getting my sea legs* | 16:08 |
*** iamjarvo has quit IRC | 16:11 | |
*** lhcheng_afk has joined #openstack-keystone | 16:16 | |
*** carlosmarin has quit IRC | 16:17 | |
*** lhcheng_afk is now known as lhcheng | 16:17 | |
*** jistr has quit IRC | 16:17 | |
*** devlaps has joined #openstack-keystone | 16:20 | |
*** thedodd has quit IRC | 16:21 | |
*** alexsyip has joined #openstack-keystone | 16:24 | |
*** thedodd has joined #openstack-keystone | 16:27 | |
*** carlosmarin has joined #openstack-keystone | 16:30 | |
openstackgerrit | Brant Knudson proposed openstack/keystone: Import fernet providers only if used in keystone-manage https://review.openstack.org/162476 | 16:32 |
*** stevemar has joined #openstack-keystone | 16:34 | |
*** ChanServ sets mode: +v stevemar | 16:34 | |
*** SlickNik has left #openstack-keystone | 16:37 | |
*** stevemar has quit IRC | 16:38 | |
morganfainberg | Mornin. | 16:44 |
*** henrynash has quit IRC | 16:53 | |
*** spandhe has joined #openstack-keystone | 16:54 | |
*** ParsectiX has joined #openstack-keystone | 16:55 | |
*** ParsectiX has quit IRC | 17:01 | |
*** ParsectiX has joined #openstack-keystone | 17:02 | |
*** ParsectiX has quit IRC | 17:02 | |
*** ParsectiX has joined #openstack-keystone | 17:02 | |
*** harlowja_away is now known as harlowja | 17:02 | |
*** raildo has joined #openstack-keystone | 17:03 | |
*** henrynash has joined #openstack-keystone | 17:06 | |
*** ChanServ sets mode: +v henrynash | 17:06 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 17:07 | |
raildo | dstanek: ping, Do you have some time to see the discussion here: https://review.openstack.org/#/c/159944/24/keystone/resource/controllers.py | 17:09 |
openstackgerrit | Brant Knudson proposed openstack/keystone: Update testing docs https://review.openstack.org/161553 | 17:10 |
*** hogepodge has quit IRC | 17:12 | |
*** hogepodge has joined #openstack-keystone | 17:14 | |
*** devlaps has quit IRC | 17:21 | |
*** devlaps has joined #openstack-keystone | 17:22 | |
*** amakarov is now known as amakarov_away | 17:26 | |
*** links has quit IRC | 17:27 | |
*** david-lyle has quit IRC | 17:29 | |
*** iamjarvo has joined #openstack-keystone | 17:30 | |
morganfainberg | rodrigods: raildo: please fast-track proposing reseller to the liberty cycle. I sent an email to the ml about the expectation when proposing a spec to liberty that was accepted for kilo. | 17:32 |
bknudson | example failing bandit: http://logs.openstack.org/47/170547/1/experimental/gate-keystone-tox-bandit/d054186/console.html | 17:32 |
morganfainberg | rodrigods: raildo this is so we can do the sub-core concept jogo was describing | 17:32 |
*** ajayaa has joined #openstack-keystone | 17:33 | |
morganfainberg | bknudson: it isn't clear to me why it failed there. | 17:34 |
bknudson | http://logs.openstack.org/47/170547/1/experimental/gate-keystone-tox-bandit/d054186/console.html#_2015-04-03_16_10_23_056 | 17:34 |
bknudson | the code is calling subrpocess.Popen with shell=True. | 17:34 |
morganfainberg | bknudson: I see it now. | 17:35 |
morganfainberg | Was a mobile device issue. Bad line wrap. | 17:35 |
bknudson | I didn't think about mobile device UX. | 17:36 |
morganfainberg | Don't. | 17:36 |
morganfainberg | I do recommend clearly saying xxx following is a list of failures. | 17:37 |
morganfainberg | Not just "results" | 17:37 |
morganfainberg | But the mobile ux is an edge case not worth catering to here. | 17:37 |
bknudson | I also asked about how to get rid of the escape codes in the output. | 17:38 |
morganfainberg | That would be nice too | 17:38 |
morganfainberg | Overall I like bandit. | 17:40 |
*** tqtran has joined #openstack-keystone | 17:40 | |
bknudson | I'll feel safer having it. | 17:41 |
*** ajayaa has quit IRC | 17:41 | |
bknudson | plus, if it's good enough we can skip our own static analysis. | 17:41 |
bknudson | the static analysis we do doesn't fit into a CI pipeline... too many false positives and no filtering | 17:41 |
jdandrea | bknudson: That did it - validate works from the client library now! Thanks. | 17:45 |
bknudson | jdandrea: great! | 17:45 |
*** bknudson has quit IRC | 17:48 | |
raildo | morganfainberg: ok, I'll do that, thanks! | 18:01 |
*** ajayaa has joined #openstack-keystone | 18:04 | |
*** ajayaa has quit IRC | 18:06 | |
*** aix has quit IRC | 18:13 | |
raildo | morganfainberg: sorry but I don't find this email in the ml. Do you have sent this today? | 18:15 |
morganfainberg | raildo. http://lists.openstack.org/pipermail/openstack-dev/2015-March/059565.html | 18:16 |
jdandrea | In this excerpt from validate(), should is_admin be 1.0 (meaning true)? http://paste.openstack.org/show/198168/ | 18:16 |
raildo | morganfainberg: ow.. thanks :) | 18:18 |
morganfainberg | raildo, happy to point you there. it did get lost in the mess of some craziness in k3/moving towards rc | 18:19 |
*** jeffDeville has joined #openstack-keystone | 18:23 | |
jeffDeville | All - Is there a recommended way (in Juno) to create access tokens that are revocable, but do not automatically expire? Scenario: We would like to use standard, expiring tokens for web access, but would like to have API tokens that can be set and forgotten (for automated jobs). We don't want to have to reuse the same credentials the user signed in with, because we don't want users to have to u | 18:27 |
jeffDeville | pdate all of their scripts every time they have to change their password. Any pointers on how we'd go about this? | 18:27 |
morganfainberg | jeffDeville, i believe EC2 credentials work like that | 18:37 |
morganfainberg | jeffDeville, longer term we are working on suopporting X509 as an auth mechanism, but it didn't land in Kilo [and isn't in Juno]. you could probably write an auth system that uses X509 certs for juno | 18:39 |
morganfainberg | jeffDeville, but i think saying "go write code to solve this" isn't the answer you're looking for here. | 18:40 |
edmondsw | jeffDeville, if it's a question of having to update a lot of things, just have all those things lookup the user/pwd from the same place, and you only have on place to edit | 18:40 |
*** aix has joined #openstack-keystone | 18:41 | |
jeffDeville | @morganfainberg - Thanks, it is true I was hoping for a: Just make this setting tweak, but it's hardly the biggest disappointment of my life. :-) We'll live | 18:42 |
morganfainberg | jeffDeville, like i said, i think you can do it with the EC2 token auth in keystone | 18:43 |
morganfainberg | jeffDeville, but in Liberty! (ok a long ways out) we should be able to use x509 auth for a couple things in keystone (at least) | 18:43 |
morganfainberg | jeffDeville, at least that is the plan | 18:43 |
morganfainberg | jeffDeville, another alternative is use something that issues SAML and federation in keystone (or OpenId in Kilo+) | 18:44 |
morganfainberg | jeffDeville, all not "great" options to solve what you're trying to accomplish | 18:44 |
jeffDeville | @morganfainberg: Sorry, googling "EC2 token keystone"... | 18:58 |
*** lhcheng has quit IRC | 18:59 | |
*** lhcheng has joined #openstack-keystone | 18:59 | |
*** devlaps has quit IRC | 19:05 | |
*** devlaps has joined #openstack-keystone | 19:05 | |
*** henrynash has quit IRC | 19:10 | |
*** jeffDeville has quit IRC | 19:17 | |
*** jeffDeville has joined #openstack-keystone | 19:17 | |
openstackgerrit | Merged openstack/keystone: Import fernet providers only if used in keystone-manage https://review.openstack.org/162476 | 19:18 |
*** jeffDeville has quit IRC | 19:22 | |
*** jeffDeville has joined #openstack-keystone | 19:22 | |
*** jeffDeville has quit IRC | 19:24 | |
*** mitz has quit IRC | 19:28 | |
*** david-lyle has joined #openstack-keystone | 19:33 | |
*** mitz has joined #openstack-keystone | 19:37 | |
*** adrian_otto has joined #openstack-keystone | 19:39 | |
*** zzzeek has quit IRC | 19:47 | |
*** zzzeek has joined #openstack-keystone | 19:48 | |
*** raildo has quit IRC | 19:50 | |
*** krtaylor has quit IRC | 19:51 | |
*** krtaylor has joined #openstack-keystone | 19:52 | |
openstackgerrit | Nathan Kinder proposed openstack/keystone: Allow identity provider to be created with remote_ids set to None https://review.openstack.org/170597 | 19:56 |
nkinder | morganfainberg: we're going to want to fix that for Kilo ^^^ | 19:56 |
nkinder | morganfainberg: the multiple remote_ids introduced a regression, which pops up using OSC | 19:57 |
morganfainberg | nkinder: ++ | 19:58 |
*** devlaps has quit IRC | 20:01 | |
*** devlaps has joined #openstack-keystone | 20:01 | |
*** mattfarina has quit IRC | 20:02 | |
morganfainberg | nkinder: rc1 bug | 20:03 |
*** topol has quit IRC | 20:30 | |
*** toddnni has quit IRC | 20:33 | |
*** toddnni has joined #openstack-keystone | 20:33 | |
*** aix has quit IRC | 20:47 | |
*** packet has quit IRC | 20:48 | |
*** harlowja has quit IRC | 20:53 | |
*** david-lyle has quit IRC | 20:55 | |
*** samueldmq_ has joined #openstack-keystone | 21:24 | |
*** edmondsw has quit IRC | 21:53 | |
*** iamjarvo has quit IRC | 21:56 | |
*** samueldmq_ has quit IRC | 21:57 | |
*** henrynash has joined #openstack-keystone | 21:58 | |
*** ChanServ sets mode: +v henrynash | 21:58 | |
*** devlaps has quit IRC | 21:59 | |
*** devlaps has joined #openstack-keystone | 21:59 | |
*** henrynash has quit IRC | 22:02 | |
*** spandhe has quit IRC | 22:03 | |
*** trey has joined #openstack-keystone | 22:12 | |
*** david-lyle has joined #openstack-keystone | 22:12 | |
*** david-lyle_ has joined #openstack-keystone | 22:13 | |
*** Bsony has quit IRC | 22:13 | |
*** spandhe has joined #openstack-keystone | 22:15 | |
*** iamjarvo has joined #openstack-keystone | 22:21 | |
*** iamjarvo has quit IRC | 22:21 | |
*** iamjarvo has joined #openstack-keystone | 22:22 | |
*** iamjarvo has quit IRC | 22:22 | |
*** iamjarvo has joined #openstack-keystone | 22:22 | |
*** lhcheng has quit IRC | 22:31 | |
*** thedodd has quit IRC | 22:32 | |
*** lhcheng has joined #openstack-keystone | 22:33 | |
*** devlaps1 has joined #openstack-keystone | 22:37 | |
*** devlaps has quit IRC | 22:37 | |
*** iamjarvo has quit IRC | 22:38 | |
*** iamjarvo has joined #openstack-keystone | 22:38 | |
*** iamjarvo has quit IRC | 22:39 | |
*** harlowja has joined #openstack-keystone | 22:40 | |
*** zzzeek has quit IRC | 23:06 | |
*** samueldmq_ has joined #openstack-keystone | 23:14 | |
*** carlosmarin has quit IRC | 23:21 | |
*** zzzeek has joined #openstack-keystone | 23:26 | |
*** zzzeek has quit IRC | 23:26 | |
*** Viswanath has joined #openstack-keystone | 23:31 | |
*** rushiagr is now known as rushiagr_away | 23:33 | |
*** alexsyip has quit IRC | 23:39 | |
*** Viswanath has quit IRC | 23:40 | |
*** samueldmq_ has quit IRC | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!