*** Guest5314 is now known as med_ | 00:29 | |
*** med_ has quit IRC | 00:29 | |
*** med_ has joined #openstack-keystone | 00:29 | |
*** gsilvis has joined #openstack-keystone | 00:35 | |
samueldmq | dstanek: you still around ? | 00:35 |
---|---|---|
*** fangzhou has joined #openstack-keystone | 00:35 | |
samueldmq | dstanek: how far are you on getting CacheControl on ksclient? | 00:36 |
*** _cjones_ has quit IRC | 00:52 | |
*** topol has joined #openstack-keystone | 00:54 | |
*** ChanServ sets mode: +v topol | 00:54 | |
*** stevemar has joined #openstack-keystone | 00:55 | |
*** ChanServ sets mode: +v stevemar | 00:55 | |
*** spandhe_ has joined #openstack-keystone | 00:56 | |
*** geoffarnold has quit IRC | 00:57 | |
*** spandhe has quit IRC | 00:57 | |
*** spandhe_ is now known as spandhe | 00:57 | |
*** stevemar has quit IRC | 00:58 | |
*** topol has quit IRC | 00:59 | |
*** jdandrea has quit IRC | 01:02 | |
openstackgerrit | Brant Knudson proposed openstack/python-keystoneclient: oslo-incubator apiclient.exceptions to keystoneclient.exceptions https://review.openstack.org/209302 | 01:06 |
*** jasonsb_ has quit IRC | 01:08 | |
*** david-lyle has joined #openstack-keystone | 01:19 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Split plugin loading https://review.openstack.org/190594 | 01:20 |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Remove auth/ directory https://review.openstack.org/209304 | 01:20 |
*** ajayaggarwal_ has joined #openstack-keystone | 01:21 | |
ajayaggarwal_ | I am new to openstack. I have been reading about federation support in keystone. But its not clear to me how the openstack command line clients make use of federated ids. | 01:23 |
morganfainberg | dstanek: dude... http://uwsgi-docs.readthedocs.org/en/latest/Embed.html#step-3-embedding-flask-itself /impressed | 01:25 |
*** davechen has joined #openstack-keystone | 01:26 | |
*** zzzeek has joined #openstack-keystone | 01:27 | |
*** dank_ is now known as dan | 01:31 | |
*** spandhe has quit IRC | 01:31 | |
*** tqtran-afk has quit IRC | 01:34 | |
*** fangzhou has quit IRC | 01:37 | |
*** ajayaggarwal_ has left #openstack-keystone | 01:38 | |
openstackgerrit | Merged openstack/keystone-specs: Include groups in federated scoped tokens https://review.openstack.org/207159 | 01:40 |
*** mylu has joined #openstack-keystone | 01:40 | |
dstanek | morganfainberg: uwsgi is pretty awesome | 01:44 |
morganfainberg | dstanek: i just proposed it to g-r | 01:44 |
morganfainberg | dstanek: and thinking devstack using emperor mode | 01:44 |
morganfainberg | kindof win | 01:44 |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Move AccessInfo objects into own module https://review.openstack.org/209311 | 01:47 |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Split plugin loading https://review.openstack.org/190594 | 01:47 |
*** zzzeek has quit IRC | 01:50 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Move AccessInfo objects into own module https://review.openstack.org/209311 | 01:52 |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Make missingproperty private https://review.openstack.org/209317 | 01:58 |
*** lhcheng has quit IRC | 02:01 | |
*** dims has quit IRC | 02:04 | |
*** lhcheng has joined #openstack-keystone | 02:12 | |
*** ChanServ sets mode: +v lhcheng | 02:12 | |
*** mylu has quit IRC | 02:12 | |
*** lhcheng has quit IRC | 02:12 | |
*** lhcheng has joined #openstack-keystone | 02:13 | |
*** ChanServ sets mode: +v lhcheng | 02:13 | |
*** mylu has joined #openstack-keystone | 02:15 | |
openstackgerrit | Dave Chen proposed openstack/keystone: Cleanup tearDown in unit tests https://review.openstack.org/207753 | 02:19 |
*** mylu has quit IRC | 02:29 | |
*** mylu has joined #openstack-keystone | 02:29 | |
*** lhcheng has quit IRC | 02:32 | |
*** mylu has quit IRC | 02:33 | |
*** gyee has quit IRC | 02:35 | |
*** hakimo_ has joined #openstack-keystone | 02:52 | |
*** hakimo has quit IRC | 02:54 | |
*** piyanai has joined #openstack-keystone | 03:04 | |
*** btully has quit IRC | 03:04 | |
*** mylu has joined #openstack-keystone | 03:06 | |
*** jasonsb has joined #openstack-keystone | 03:12 | |
openstackgerrit | Dan Nguyen proposed openstack/keystone: Allow Domain Admin to get domain details https://review.openstack.org/208082 | 03:13 |
*** spandhe has joined #openstack-keystone | 03:22 | |
*** doug-fish has joined #openstack-keystone | 03:24 | |
*** mylu has quit IRC | 03:24 | |
*** mylu has joined #openstack-keystone | 03:24 | |
*** spandhe_ has joined #openstack-keystone | 03:25 | |
*** spandhe has quit IRC | 03:27 | |
*** spandhe_ is now known as spandhe | 03:27 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Limit subtree and parents queries https://review.openstack.org/209132 | 03:37 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Honor domain operations in project table https://review.openstack.org/143763 | 03:37 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Restrict inherited role assignments to subdomains https://review.openstack.org/164180 | 03:37 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Change project name constraints https://review.openstack.org/158372 | 03:37 |
*** Nakato has quit IRC | 03:38 | |
*** Nakato has joined #openstack-keystone | 03:40 | |
*** hrou has quit IRC | 03:50 | |
*** topol has joined #openstack-keystone | 03:51 | |
*** ChanServ sets mode: +v topol | 03:51 | |
*** mylu has quit IRC | 03:51 | |
*** stevemar has joined #openstack-keystone | 03:55 | |
*** ChanServ sets mode: +v stevemar | 03:55 | |
*** stevemar has quit IRC | 03:58 | |
*** kafka_ has joined #openstack-keystone | 04:03 | |
*** geoffarnold has joined #openstack-keystone | 04:04 | |
*** geoffarnold has quit IRC | 04:06 | |
kafka_ | curl -s -X GET 127.0.0.1:35357/v3/users?inotexist=dd842 -H 'Content-Type: application/json' -H 'Accept: application/json' -H 'X-Auth-Token: 229cf704ae0e4ad2b55e1ee07aa2bc6c'|python -mjson.tool | 04:08 |
*** geoffarnold has joined #openstack-keystone | 04:09 | |
kafka_ | query paramter is a not exist property, and GET return all , is that valid? | 04:09 |
*** geoffarnold has quit IRC | 04:16 | |
*** stevemar has joined #openstack-keystone | 04:29 | |
*** ChanServ sets mode: +v stevemar | 04:29 | |
*** fifieldt has joined #openstack-keystone | 04:32 | |
*** pcaruana has quit IRC | 04:59 | |
*** piyanai has quit IRC | 05:06 | |
*** davechen has quit IRC | 05:11 | |
*** davechen has joined #openstack-keystone | 05:11 | |
morganfainberg | marekd, stevemar, dstanek: https://github.com/nginx-shib/nginx-http-shibboleth | 05:12 |
stevemar | morganfainberg: ola | 05:12 |
morganfainberg | trying to start the work to document other webserver and wsgi implementation options | 05:13 |
morganfainberg | stevemar: isn't is crazy late there and a holiday or something | 05:13 |
stevemar | morganfainberg: yes and yes | 05:13 |
stevemar | morganfainberg: i'm back on the clock tomorrow | 05:14 |
* morganfainberg nods | 05:14 | |
morganfainberg | tomorrow i'll be camped in the coffee shop again | 05:14 |
morganfainberg | then on a plane | 05:14 |
morganfainberg | and then jetlagged. | 05:14 |
stevemar | morganfainberg: coming or going? | 05:15 |
*** davechen1 has joined #openstack-keystone | 05:19 | |
*** topol has quit IRC | 05:20 | |
*** davechen has quit IRC | 05:22 | |
openstackgerrit | Merged openstack/keystone-specs: List credentials by type https://review.openstack.org/209228 | 05:22 |
morganfainberg | Headed home. | 05:24 |
*** davechen has joined #openstack-keystone | 05:26 | |
*** davechen1 has quit IRC | 05:27 | |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Remove auth/ directory https://review.openstack.org/209304 | 05:32 |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Split plugin loading https://review.openstack.org/190594 | 05:32 |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Remove oslo_config from auth plugin loading https://review.openstack.org/209348 | 05:32 |
openstackgerrit | Jamie Lennox proposed openstack/keystoneauth: Move session loading into loading module https://review.openstack.org/209349 | 05:32 |
openstackgerrit | Raildo Mascena de Sousa Filho proposed openstack/keystone: List credentials by type https://review.openstack.org/208620 | 05:48 |
openstackgerrit | Raildo Mascena de Sousa Filho proposed openstack/keystone: List credentials by type https://review.openstack.org/208620 | 06:01 |
*** ParsectiX has joined #openstack-keystone | 06:04 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/keystone: Imported Translations from Transifex https://review.openstack.org/208823 | 06:07 |
*** spandhe_ has joined #openstack-keystone | 06:11 | |
*** spandhe has quit IRC | 06:11 | |
*** spandhe_ is now known as spandhe | 06:11 | |
*** topol has joined #openstack-keystone | 06:21 | |
*** ChanServ sets mode: +v topol | 06:21 | |
*** topol has quit IRC | 06:25 | |
stevemar | jamielennox: weird trust issue on the ML | 06:26 |
jamielennox | stevemar: everyone fighting like that - trust is bound to become an issue | 06:27 |
stevemar | jamielennox: hardeeharhar | 06:28 |
stevemar | http://openstack.markmail.org/search/?q=trust#query:trust%20order%3Adate-backward+page:1+mid:xp44mfkgwflaes3u+state:results | 06:28 |
stevemar | the reader is seeing a KSC exception | 06:29 |
jamielennox | yea, that was terrible | 06:30 |
jamielennox | ah - damn, i saw this one land in the inbox but i was at conference | 06:31 |
jamielennox | i thought i marked it somehow | 06:31 |
*** henrynash has joined #openstack-keystone | 06:31 | |
*** ChanServ sets mode: +v henrynash | 06:31 | |
stevemar | is it the common session? | 06:32 |
*** yottatsa has joined #openstack-keystone | 06:32 | |
jamielennox | stevemar: bah - turns out marking something as todo on my phone moves it to a completely app specific folder and so i never see it again | 06:32 |
stevemar | \o/ | 06:32 |
stevemar | productivity++ | 06:32 |
* stevemar thinks its the common session | 06:33 | |
*** spandhe has quit IRC | 06:33 | |
*** browne has quit IRC | 06:34 | |
jamielennox | stevemar: hmm, it looks ok | 06:34 |
stevemar | replied with that anyway | 06:35 |
*** marzif_ has quit IRC | 06:35 | |
stevemar | i only have 1 meeting tomorrow! oh joy! | 06:35 |
stevemar | jamielennox: poke around it if you can, otherwise no biggie | 06:36 |
stevemar | i'm out for now, see ya! | 06:36 |
jamielennox | stevemar: seeya | 06:36 |
*** pcaruana has joined #openstack-keystone | 06:36 | |
*** stevemar has quit IRC | 06:40 | |
*** stevemar has joined #openstack-keystone | 06:41 | |
*** ChanServ sets mode: +v stevemar | 06:41 | |
*** vivekd has joined #openstack-keystone | 06:41 | |
*** davechen has quit IRC | 06:41 | |
*** davechen has joined #openstack-keystone | 06:42 | |
*** stevemar has quit IRC | 06:43 | |
*** davechen1 has joined #openstack-keystone | 06:45 | |
*** davechen has quit IRC | 06:47 | |
*** davechen has joined #openstack-keystone | 06:50 | |
*** davechen1 has quit IRC | 06:53 | |
*** davechen1 has joined #openstack-keystone | 06:58 | |
breton | kafka_: yes afaik | 07:00 |
breton | morning, keystone | 07:00 |
marekd | hey | 07:00 |
*** davechen has quit IRC | 07:00 | |
*** afazekas has joined #openstack-keystone | 07:02 | |
*** davechen has joined #openstack-keystone | 07:08 | |
*** kafka_ has quit IRC | 07:09 | |
*** davechen1 has quit IRC | 07:11 | |
*** marzif_ has joined #openstack-keystone | 07:13 | |
*** davechen1 has joined #openstack-keystone | 07:14 | |
*** vince_ has joined #openstack-keystone | 07:15 | |
*** marzif__ has joined #openstack-keystone | 07:16 | |
*** davechen has quit IRC | 07:16 | |
*** marzif_ has quit IRC | 07:18 | |
*** lhcheng has joined #openstack-keystone | 07:22 | |
*** ChanServ sets mode: +v lhcheng | 07:22 | |
*** navid__ has joined #openstack-keystone | 07:23 | |
*** davechen has joined #openstack-keystone | 07:26 | |
*** lsmola has joined #openstack-keystone | 07:29 | |
*** davechen1 has quit IRC | 07:29 | |
*** browne has joined #openstack-keystone | 07:30 | |
marekd | morganfainberg: wow | 07:32 |
morganfainberg | marekd: :) | 07:33 |
marekd | morganfainberg: it was ofc re: ngix-shib thing :-) | 07:33 |
morganfainberg | Yep | 07:33 |
*** browne has quit IRC | 07:40 | |
*** jiaxi has joined #openstack-keystone | 07:43 | |
jiaxi | Hi, davechen | 07:43 |
jiaxi | davechen: Hi | 07:43 |
jiaxi | There are many place in unittest use 'self.resource_api.create_domain' | 07:44 |
*** josecastroleon has quit IRC | 07:44 | |
jiaxi | Where is the domain created with 'self.resource_api.create_domain' stored ? | 07:45 |
*** e0ne has joined #openstack-keystone | 07:47 | |
*** josecastroleon has joined #openstack-keystone | 07:48 | |
*** vivekd has quit IRC | 07:50 | |
*** e0ne has quit IRC | 07:52 | |
*** e0ne has joined #openstack-keystone | 07:56 | |
davechen | jiaxi: hi jiaxi, | 07:58 |
davechen | jiaxi: I just replied your email, pls check it. | 07:58 |
*** vivekd has joined #openstack-keystone | 07:59 | |
jiaxi | davechen: Thanks , I will | 08:01 |
*** e0ne has quit IRC | 08:04 | |
*** fhubik has joined #openstack-keystone | 08:10 | |
*** fhubik is now known as fhubik_afk | 08:12 | |
*** yottatsa has quit IRC | 08:12 | |
*** vivekd has quit IRC | 08:14 | |
*** jistr has joined #openstack-keystone | 08:14 | |
breton | jiaxi: in the in-memory database | 08:18 |
jiaxi | breton: I want to understand the whole structure and design of keystone unittest . Can you recommend some docs to me ? | 08:19 |
jiaxi | breton: Before I read code of keystone, I will read docs. That will make the code easy to read. | 08:21 |
jiaxi | breton: Is there any good docs about the unitttest of keystone ? | 08:21 |
*** vivekd has joined #openstack-keystone | 08:22 | |
*** belmoreira has joined #openstack-keystone | 08:23 | |
charz | Hi | 08:25 |
charz | Is anyone can help to review this patch https://review.openstack.org/#/c/179777/ | 08:25 |
breton | jiaxi: I don't know any. Try looking at setUp of the test case you are interested in and check what it calls | 08:25 |
jiaxi | breton: Good suggestion. Thanks. | 08:26 |
*** boris-42 has quit IRC | 08:30 | |
*** lhcheng has quit IRC | 08:35 | |
*** josecastroleon has quit IRC | 08:36 | |
*** stevemar has joined #openstack-keystone | 08:41 | |
*** ChanServ sets mode: +v stevemar | 08:41 | |
*** mhu has joined #openstack-keystone | 08:43 | |
*** josecastroleon has joined #openstack-keystone | 08:45 | |
*** stevemar has quit IRC | 08:45 | |
vince_ | on my attempt to federate keystone to google, I am using the new OidcPassword plugin and following this https://developer.ibm.com/opentech/2015/06/17/use-websphere-liberty-as-an-openid-connect-provider-for-openstack/ | 08:49 |
vince_ | here is my request and response, done by the plugin | 08:49 |
vince_ | http://pastebin.com/MQaCcNr8 | 08:49 |
vince_ | the problem is that I get this "Invalid OAuth 2 grant type: PASSWORD" error | 08:49 |
vince_ | (request method is post) | 08:50 |
*** fhubik_afk is now known as fhubik | 08:51 | |
*** vivekd_ has joined #openstack-keystone | 08:53 | |
*** vivekd has quit IRC | 08:53 | |
*** vivekd_ is now known as vivekd | 08:53 | |
marekd | vince_: i suggest bugging stevemar later on | 09:01 |
vince_ | marekd: ok | 09:07 |
vince_ | on a related note, I was wondering why we would need to use the client id and secret at this level | 09:07 |
vince_ | as if apache is configured with the oidc module, those information are known to it | 09:07 |
vince_ | and one just needs to hit the federation auth uri on keystone and then apache does the redirect to the IdP | 09:08 |
marekd | isn't client id a user specific thing? | 09:08 |
vince_ | it's app specific | 09:08 |
marekd | vince_: what happens with >1 IdPs ? | 09:08 |
vince_ | (afaik, and I don't know much :D) | 09:08 |
vince_ | marekd: in case of multiple IdPs, I don't know how and if the oidc apache mod can handle that, but I could imagine that you have different auth URIs, each one setup with its different OIDC settings | 09:10 |
vince_ | but my point is that it should be possible from the end-user pov to just provide the auth uri of keystone and its credentials for the IdP to authenticate | 09:11 |
marekd | vince_: aha, i suggest talking with stevemar then : | 09:11 |
vince_ | marekd: ok, I will :), is he in canasa? | 09:12 |
vince_ | *canada | 09:12 |
marekd | vince_: yes | 09:12 |
marekd | toronto time. | 09:12 |
vince_ | still in its deep sleep probably :) | 09:12 |
marekd | vince_: yes | 09:14 |
marekd | vince_: he should be here in 5-6 hours. | 09:14 |
openstackgerrit | Dave Chen proposed openstack/keystone: Remove the redundant code https://review.openstack.org/209414 | 09:27 |
*** e0ne has joined #openstack-keystone | 09:31 | |
breton | davechen: https://review.openstack.org/#/c/201648/ | 09:33 |
*** e0ne has quit IRC | 09:38 | |
openstackgerrit | Boris Bobrov proposed openstack/keystone: Remove excessive transformation to list https://review.openstack.org/201648 | 09:40 |
*** stevemar has joined #openstack-keystone | 09:42 | |
*** ChanServ sets mode: +v stevemar | 09:42 | |
davechen | breton: ha, you have did that. | 09:45 |
davechen | breton: I will drop it when I back home. :) | 09:46 |
*** stevemar has quit IRC | 09:46 | |
breton | I wonder, why do we populate token dates as isotime? | 09:46 |
breton | why not timestamp or some datetime-like object that is converted to isotime before returning it to the user | 09:47 |
davechen | breton: done. | 09:50 |
*** davechen has left #openstack-keystone | 09:53 | |
*** yottatsa has joined #openstack-keystone | 09:56 | |
*** yottatsa has quit IRC | 09:56 | |
morganfainberg | breton: wire format. Must be serialized to a primitive so string. In that case isotime is the clear winner | 09:57 |
morganfainberg | We also historically stored the timestamps in a db serialized. | 09:58 |
*** dims has joined #openstack-keystone | 10:00 | |
*** dims has quit IRC | 10:00 | |
*** dims has joined #openstack-keystone | 10:00 | |
*** Qlawy has quit IRC | 10:08 | |
*** Qlawy has joined #openstack-keystone | 10:09 | |
*** yottatsa has joined #openstack-keystone | 10:13 | |
breton | morganfainberg: we store dates in db as isotime? | 10:14 |
morganfainberg | When it is in a serialized form such as the token body | 10:14 |
morganfainberg | Not when it is a top level column. We duplicate some of these data points for sql query purposes. Also remember we support storing serialized form in non-sql backends | 10:16 |
*** fhubik is now known as fhubik_afk | 10:20 | |
*** topol has joined #openstack-keystone | 10:23 | |
*** ChanServ sets mode: +v topol | 10:23 | |
*** topol has quit IRC | 10:27 | |
openstackgerrit | Andrey Pavlov proposed openstack/keystonemiddleware: Adding parse of protocol v4 of AWS auth to ec2_token https://review.openstack.org/205440 | 10:29 |
*** e0ne has joined #openstack-keystone | 10:30 | |
*** yottatsa has quit IRC | 10:34 | |
*** yottatsa has joined #openstack-keystone | 10:35 | |
*** yottatsa has quit IRC | 10:45 | |
*** e0ne has quit IRC | 10:46 | |
*** jasondotstar has joined #openstack-keystone | 10:47 | |
*** yottatsa has joined #openstack-keystone | 10:47 | |
*** jiaxi has quit IRC | 10:51 | |
*** josecastroleon has quit IRC | 10:52 | |
breton | morganfainberg: do we? http://paste.openstack.org/show/408223/ | 10:52 |
breton | that's from kvs.py, create_token | 10:53 |
breton | right after self._set_key(ptk, data_copy) | 10:53 |
morganfainberg | See issued_at | 10:53 |
morganfainberg | Different values different forms | 10:54 |
breton | oh, ok, see it | 10:54 |
morganfainberg | :) | 10:54 |
morganfainberg | It all depends on a number of things | 10:54 |
morganfainberg | But largely, legacy/compat/historical now | 10:55 |
morganfainberg | Not really worth changing at this point. Drive towards fernet and then fix things like that as needed | 10:55 |
breton | because of that we have to do something like https://review.openstack.org/#/c/208021/3/keystone/token/providers/fernet/core.py | 10:56 |
*** h00327910__ has quit IRC | 10:58 | |
*** yottatsa has quit IRC | 10:59 | |
*** yottatsa_ has joined #openstack-keystone | 10:59 | |
*** josecastroleon has joined #openstack-keystone | 11:06 | |
*** e0ne has joined #openstack-keystone | 11:07 | |
*** marzif__ has quit IRC | 11:15 | |
*** amakarov_away is now known as amakarov | 11:15 | |
*** marzif__ has joined #openstack-keystone | 11:16 | |
*** fhubik_afk is now known as fhubik | 11:26 | |
*** dims_ has joined #openstack-keystone | 11:26 | |
*** gordc has joined #openstack-keystone | 11:28 | |
*** dims has quit IRC | 11:28 | |
*** e0ne has quit IRC | 11:34 | |
*** yottatsa_ has quit IRC | 11:43 | |
*** yottatsa has joined #openstack-keystone | 11:44 | |
*** dims_ has quit IRC | 11:44 | |
*** afazekas_ has joined #openstack-keystone | 11:46 | |
*** afazekas has quit IRC | 11:48 | |
*** topol has joined #openstack-keystone | 11:49 | |
*** ChanServ sets mode: +v topol | 11:49 | |
*** bdossant has joined #openstack-keystone | 11:51 | |
*** dims has joined #openstack-keystone | 11:51 | |
*** jistr has quit IRC | 11:56 | |
*** bdossant_ has joined #openstack-keystone | 12:00 | |
amakarov | ayoung, hi! Should the driver for unified delegation be unified too, or it's better to implement separate driver for every component (assignment, trust, request token) | 12:01 |
amakarov | ayoung, ? | 12:01 |
*** bdossant has quit IRC | 12:02 | |
openstackgerrit | henry-nash proposed openstack/keystone: Improve List Role Assignments Filters Performance https://review.openstack.org/137202 | 12:04 |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for data-driven backend assignment testing https://review.openstack.org/149178 | 12:06 |
*** e0ne has joined #openstack-keystone | 12:06 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for effective & inherited mode in data driven tests https://review.openstack.org/151623 | 12:07 |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for group membership to data driven assignment tests https://review.openstack.org/151962 | 12:08 |
openstackgerrit | henry-nash proposed openstack/keystone: Broaden domain-group testing of list_role_assignments https://review.openstack.org/154302 | 12:08 |
openstackgerrit | henry-nash proposed openstack/keystone: Test list_role_assignment in standard inheritance tests https://review.openstack.org/153897 | 12:09 |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for data-driven backend assignment testing https://review.openstack.org/149178 | 12:12 |
*** fhubik is now known as fhubik_afk | 12:12 | |
*** ayoung has quit IRC | 12:13 | |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for effective & inherited mode in data driven tests https://review.openstack.org/151623 | 12:15 |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for effective & inherited mode in data driven tests https://review.openstack.org/151623 | 12:16 |
*** jistr has joined #openstack-keystone | 12:18 | |
*** jistr is now known as jistr|biab | 12:19 | |
*** alejandrito has joined #openstack-keystone | 12:19 | |
breton | fg | 12:22 |
openstackgerrit | henry-nash proposed openstack/keystone: Add support for group membership to data driven assignment tests https://review.openstack.org/151962 | 12:23 |
openstackgerrit | henry-nash proposed openstack/keystone: Broaden domain-group testing of list_role_assignments https://review.openstack.org/154302 | 12:24 |
openstackgerrit | henry-nash proposed openstack/keystone: Test list_role_assignment in standard inheritance tests https://review.openstack.org/153897 | 12:26 |
openstackgerrit | henry-nash proposed openstack/keystone: Support project hierarchies in data driver tests https://review.openstack.org/154485 | 12:27 |
*** piyanai has joined #openstack-keystone | 12:29 | |
openstackgerrit | henry-nash proposed openstack/keystone: Remove manager-driver assignment metadata construct https://review.openstack.org/148995 | 12:30 |
*** edmondsw has joined #openstack-keystone | 12:34 | |
breton | what's the reason to store reference to user and tenant in both token_data and in the root of the stored dict? | 12:34 |
*** hrou has joined #openstack-keystone | 12:37 | |
*** topol has quit IRC | 12:41 | |
*** marzif__ has quit IRC | 12:43 | |
*** marzif__ has joined #openstack-keystone | 12:44 | |
*** bapalm has joined #openstack-keystone | 12:52 | |
*** bapalm_ has joined #openstack-keystone | 12:53 | |
*** dims_ has joined #openstack-keystone | 12:57 | |
*** bapalm has quit IRC | 12:57 | |
*** dims has quit IRC | 12:59 | |
*** petertr7_away is now known as petertr7 | 13:03 | |
*** yottatsa has quit IRC | 13:05 | |
*** edmondsw has quit IRC | 13:05 | |
*** browne has joined #openstack-keystone | 13:06 | |
*** jistr|biab is now known as jistr | 13:06 | |
*** TheIntern has joined #openstack-keystone | 13:07 | |
*** afazekas_ has quit IRC | 13:10 | |
*** alejandrito has quit IRC | 13:10 | |
*** yottatsa has joined #openstack-keystone | 13:13 | |
*** yottatsa has quit IRC | 13:18 | |
*** bdossant_ has quit IRC | 13:20 | |
*** zzzeek has joined #openstack-keystone | 13:21 | |
*** diazjf has joined #openstack-keystone | 13:21 | |
*** ccard has quit IRC | 13:24 | |
*** btully has joined #openstack-keystone | 13:25 | |
*** bdossant has joined #openstack-keystone | 13:26 | |
*** urulama has quit IRC | 13:26 | |
*** urulama has joined #openstack-keystone | 13:27 | |
morganfainberg | Serialized token body vs indexed data. | 13:27 |
*** davi8784 has joined #openstack-keystone | 13:27 | |
*** bknudson has joined #openstack-keystone | 13:28 | |
*** ChanServ sets mode: +v bknudson | 13:28 | |
morganfainberg | Searching for user in a json blob is expensive. | 13:28 |
morganfainberg | Esp. Over many many many many many rows | 13:28 |
*** TheIntern has quit IRC | 13:29 | |
*** diazjf1 has joined #openstack-keystone | 13:29 | |
bknudson | or searching for the tenant ID in the json blob | 13:30 |
bknudson | morganfainberg: http://git.openstack.org/cgit/openstack/keystone/tree/keystone/token/persistence/backends/sql.py#n141 | 13:31 |
morganfainberg | bknudson: ++ | 13:31 |
*** diazjf has quit IRC | 13:31 | |
*** davi8784 has quit IRC | 13:32 | |
bknudson | btw - changing apiclient.exceptions seems to have worked, see https://review.openstack.org/#/c/209306/ (auth_integration branch passes) | 13:32 |
bknudson | and https://review.openstack.org/#/c/209302/ is the change in master | 13:33 |
*** diazjf has joined #openstack-keystone | 13:33 | |
*** TheIntern has joined #openstack-keystone | 13:33 | |
*** navid__ has quit IRC | 13:33 | |
*** diazjf1 has quit IRC | 13:34 | |
*** petertr7 is now known as petertr7_away | 13:34 | |
*** jecarey has joined #openstack-keystone | 13:36 | |
*** dims has joined #openstack-keystone | 13:36 | |
*** petertr7_away is now known as petertr7 | 13:38 | |
*** dims_ has quit IRC | 13:38 | |
*** jdandrea has joined #openstack-keystone | 13:39 | |
*** topol has joined #openstack-keystone | 13:42 | |
*** ChanServ sets mode: +v topol | 13:42 | |
*** dims_ has joined #openstack-keystone | 13:42 | |
*** dims has quit IRC | 13:44 | |
*** topol has quit IRC | 13:46 | |
*** ayoung has joined #openstack-keystone | 13:51 | |
*** ChanServ sets mode: +v ayoung | 13:51 | |
*** dobson has quit IRC | 13:52 | |
*** jamiec has quit IRC | 13:52 | |
*** jamiec has joined #openstack-keystone | 13:52 | |
*** dobson has joined #openstack-keystone | 13:52 | |
*** fhubik_afk is now known as fhubik | 13:54 | |
breton | I am talking about kvs | 13:54 |
*** dims has joined #openstack-keystone | 13:55 | |
breton | we currrently store the whole dict in memcache | 13:56 |
*** sigmavirus24_awa is now known as sigmavirus24 | 13:56 | |
*** diazjf1 has joined #openstack-keystone | 13:57 | |
*** dims_ has quit IRC | 13:57 | |
*** diazjf has quit IRC | 13:58 | |
*** ParsectiX has quit IRC | 14:00 | |
*** edmondsw has joined #openstack-keystone | 14:02 | |
dstanek | morganfainberg: do you not sleep anymore? | 14:05 |
dstanek | breton: kvs should die! | 14:05 |
morganfainberg | Im in australia until friday | 14:05 |
*** zigo has quit IRC | 14:05 | |
openstackgerrit | Merged openstack/keystone-specs: Remove KDS from the list of api extensions https://review.openstack.org/208383 | 14:06 |
morganfainberg | dstanek: it is 0:05 now | 14:06 |
dstanek | morganfainberg: ah, that makes more sense | 14:06 |
morganfainberg | dstanek: and I am trying to shift my schedule enough that I can avoid too much jet lag on the 17hr time change back home | 14:06 |
*** zigo has joined #openstack-keystone | 14:06 | |
dstanek | i thought this was part of your training :-) | 14:06 |
morganfainberg | Lol | 14:06 |
morganfainberg | Tomorrow night, no sleep. Sleep on the plane, 14hr flight. I leave at 10:30a Friday and land at 06:30a Friday in la | 14:07 |
*** diazjf has joined #openstack-keystone | 14:07 | |
morganfainberg | Won't start really training until post PTL. | 14:08 |
*** woodster_ has joined #openstack-keystone | 14:08 | |
*** diazjf1 has quit IRC | 14:09 | |
openstackgerrit | Vivek Dhayaal proposed openstack/keystone: Stable Keystone Driver Interfaces https://review.openstack.org/209524 | 14:09 |
*** jsavak has joined #openstack-keystone | 14:10 | |
*** diazjf1 has joined #openstack-keystone | 14:11 | |
*** afazekas_ has joined #openstack-keystone | 14:12 | |
*** diazjf has quit IRC | 14:12 | |
*** yottatsa has joined #openstack-keystone | 14:15 | |
*** bdossant has quit IRC | 14:19 | |
*** bdossant has joined #openstack-keystone | 14:19 | |
*** geoffarnold has joined #openstack-keystone | 14:19 | |
*** bdossant has quit IRC | 14:21 | |
breton | dstanek: not yet | 14:21 |
*** bdossant has joined #openstack-keystone | 14:21 | |
breton | it beats sql by performance | 14:22 |
*** geoffarnold has quit IRC | 14:22 | |
*** jsavak has quit IRC | 14:23 | |
*** vivekd has quit IRC | 14:23 | |
*** geoffarnold has joined #openstack-keystone | 14:23 | |
*** jsavak has joined #openstack-keystone | 14:23 | |
*** diazjf has joined #openstack-keystone | 14:24 | |
*** diazjf1 has quit IRC | 14:25 | |
*** mordred has quit IRC | 14:25 | |
*** dims_ has joined #openstack-keystone | 14:27 | |
*** urulama has quit IRC | 14:29 | |
*** urulama has joined #openstack-keystone | 14:29 | |
*** dims has quit IRC | 14:29 | |
*** dims has joined #openstack-keystone | 14:31 | |
*** fhubik is now known as fhubik_afk | 14:33 | |
*** dims_ has quit IRC | 14:33 | |
*** dims_ has joined #openstack-keystone | 14:34 | |
*** fhubik_afk is now known as fhubik | 14:35 | |
*** dims has quit IRC | 14:37 | |
*** dims has joined #openstack-keystone | 14:38 | |
*** bapalm_ has quit IRC | 14:38 | |
*** dims_ has quit IRC | 14:40 | |
*** jsavak has quit IRC | 14:42 | |
*** afazekas_ has quit IRC | 14:43 | |
*** vinsh has joined #openstack-keystone | 14:43 | |
*** afazekas_ has joined #openstack-keystone | 14:43 | |
*** jistr has quit IRC | 14:44 | |
*** jistr has joined #openstack-keystone | 14:44 | |
*** stevemar has joined #openstack-keystone | 14:46 | |
*** ChanServ sets mode: +v stevemar | 14:46 | |
*** bapalm_ has joined #openstack-keystone | 14:46 | |
*** mylu has joined #openstack-keystone | 14:48 | |
*** jsavak has joined #openstack-keystone | 14:49 | |
morganfainberg | breton: not really. | 14:51 |
morganfainberg | breton: kvs beats sql in a limited cross section of performance | 14:51 |
morganfainberg | Similarly sql really sucks if you don't flush the token table | 14:52 |
vince_ | stevemar: hello! I am using your OidcPassword plugin to federate with google and get auth from the CLI, I followed your blog post here (some parts, as the IdP here is google) https://developer.ibm.com/opentech/2015/06/17/use-websphere-liberty-as-an-openid-connect-provider-for-openstack/ | 14:52 |
morganfainberg | The house keeping code in kvs is very expensive | 14:52 |
vince_ | stevemar: problem is that I am getting this "Invalid OAuth 2 grant type: PASSWORD" error, you can see the request and response here: http://pastebin.com/MQaCcNr8 | 14:53 |
*** jsavak has quit IRC | 14:53 | |
*** afazekas_ has quit IRC | 14:54 | |
*** diazjf1 has joined #openstack-keystone | 14:55 | |
stevemar | vince_: hey there, uh... gimmie a sec, glad you are going through that, but i'm a bit busy at the moment, can you send me an email? | 14:55 |
*** jsavak has joined #openstack-keystone | 14:56 | |
vince_ | stevemar: sure! | 14:56 |
*** diazjf has quit IRC | 14:56 | |
vince_ | I don't have your address though :D | 14:56 |
*** thedodd has joined #openstack-keystone | 14:56 | |
*** diazjf has joined #openstack-keystone | 14:58 | |
iurygregory | hello stevemar, i have some questions about Federation, can you help me? | 14:58 |
openstackgerrit | Brant Knudson proposed openstack/python-keystoneclient: oslo-incubator apiclient.exceptions to keystoneclient.exceptions https://review.openstack.org/209302 | 14:59 |
*** diazjf1 has quit IRC | 14:59 | |
bknudson | morganfainberg: I just added a bug to ^ so that if it breaks something we'll have more info. | 15:00 |
samueldmq | ayoung: I was about to send out the email to the operators list, but just saw you did it | 15:00 |
ayoung | samueldmq, heh | 15:00 |
*** jsavak has quit IRC | 15:00 | |
ayoung | I 've been thinking about that one for a long time. We needed to get the ideas as clear as possible. | 15:00 |
*** diazjf1 has joined #openstack-keystone | 15:01 | |
*** jsavak has joined #openstack-keystone | 15:01 | |
ayoung | I realized that focusing on the problems was not going to get buy in. Need to show the additional value | 15:01 |
ayoung | samueldmq, either we will get crazy-too-much feedback or crickets. Lets see which. | 15:02 |
iurygregory | stevemar, When using (OpenID Connector and SAML - shib/mellon) can I use other webserver instead of apache? | 15:02 |
*** diazjf has quit IRC | 15:02 | |
samueldmq | ayoung: ++ sounds good | 15:03 |
ayoung | samueldmq, are you keeping up with the design discussion by Iorem and David? | 15:03 |
*** phalmos has joined #openstack-keystone | 15:03 | |
samueldmq | ayoung: the horizon part of dynamic policy, | 15:03 |
samueldmq | ayoung: not responded to that thread yet | 15:04 |
ayoung | samueldmq, let themn discuss, just keep abreast of the conversation | 15:04 |
*** diazjf has joined #openstack-keystone | 15:04 | |
samueldmq | ayoung: ++ | 15:04 |
ayoung | samueldmq, I kindof want to build support by letting as many voices be heard as possible. I think we have a good understanding of the approach and the tools needed...still details to clear up, of course. | 15:05 |
samueldmq | ayoung: yeah | 15:05 |
*** diazjf1 has quit IRC | 15:05 | |
*** vivekd has joined #openstack-keystone | 15:05 | |
samueldmq | ayoung: the most we hear, more people get involved, and we won"t face the issue we have today (lack of stackholders) | 15:06 |
ayoung | ++ | 15:06 |
samueldmq | ayoung: btw, sharing a thought I had .. | 15:06 |
samueldmq | ayoung: another thing .. what about a sort of Congress for access control policy checks ? | 15:06 |
samueldmq | ayoung: UFCG team started a similar porject last year | 15:07 |
ayoung | do you mean offload policy checks to a remote server? A remote PDP/PEP? | 15:07 |
samueldmq | ayoung: basically you had a class per role, and you defined the checks like : list_users_any_domain = False, list_users_own_domain = True | 15:07 |
samueldmq | ayoung: and that'd be ran against the cloud | 15:07 |
samueldmq | I'd say PVP | 15:08 |
*** diazjf1 has joined #openstack-keystone | 15:08 | |
samueldmq | Policy Validation Point | 15:08 |
samueldmq | hehe | 15:08 |
ayoung | samueldmq, that means Player-Versus-Player to me | 15:08 |
ayoung | so validation before upload? | 15:08 |
samueldmq | ayoung: not in this context, but we can play with it ofc | 15:08 |
samueldmq | ayoung: you can run validation whenever you want | 15:09 |
*** diazjf has quit IRC | 15:09 | |
samueldmq | ayoung: you define what you mean in a very very simple language | 15:09 |
samueldmq | ayoung: like list_users_any_domain = False, etc | 15:09 |
ayoung | samueldmq, so...I think that is what I was getting at with splitting up the role assignment from the scope check | 15:09 |
samueldmq | ayoung: so less susceptible to errors | 15:09 |
ayoung | image if policy were just | 15:09 |
henrynash | stevemar, dstanek, lbragstad: a plea for some eyes on https://review.openstack.org/#/c/137202/ there’s a lot piling up behind this one…. | 15:09 |
dstanek | breton: it's actually going to be gone soon if my reviews get merged | 15:09 |
*** diazjf has joined #openstack-keystone | 15:10 | |
ayoung | "dentity:list_users" : "role:member"\ | 15:10 |
ayoung | the scope checks really should not be touched | 15:10 |
dstanek | henrynash: i'll take a look in a few. just finishing up a commit | 15:10 |
samueldmq | henrynash: we gotta have a cake for this review in the summit, like 1-year old | 15:10 |
henrynash | dstanek: thx | 15:11 |
samueldmq | ayoung: hahahahaha I read that as "dentist:list_users" | 15:11 |
henrynash | samueldmq: yep, I’ll buy us all little fairy cakes with cherries on top… | 15:11 |
samueldmq | henrynash: +++ | 15:11 |
breton | dstanek: which ones? | 15:11 |
henrynash | samueldmq: (and that’s not a euphanism for anything….) | 15:11 |
*** HT_sergio has joined #openstack-keystone | 15:12 | |
samueldmq | ayoung: even if they aren't, we could check (before splitting the policy) | 15:12 |
*** diazjf2 has joined #openstack-keystone | 15:12 | |
samueldmq | ayoung: another option would be to have a DSL on the top of it (we didn't touched this part yet) | 15:12 |
*** diazjf1 has quit IRC | 15:12 | |
samueldmq | ayoung: so you'd specify things like: "as an admin, I must be able to list users",etc | 15:13 |
ayoung | samueldmq, splitting the policy has another benefit, in that the dynamic could be based on the URL and the scope could be based on the resource fetched from the database. | 15:13 |
ayoung | samueldmq, yeah, I think we want to be able to run checks like that against policy | 15:13 |
samueldmq | ayoung: yes I know, I agree with the split | 15:13 |
dstanek | breton: catalog for sure - i'd like to revisit token to see what value is in there | 15:13 |
samueldmq | ayoung: and put the RBAC check in the middleware possibly | 15:14 |
ayoung | right | 15:14 |
samueldmq | ayoung: btw, first reply to your email | 15:14 |
samueldmq | ayoung: loooking..... | 15:14 |
samueldmq | :) | 15:14 |
breton | dstanek: nah, I care only about memcache_pool for tokens. | 15:14 |
*** diazjf has quit IRC | 15:14 | |
dstanek | breton: i think those are the only things that still have a kvs driver | 15:15 |
ayoung | samueldmq, good to see people focus on scale. | 15:15 |
*** diazjf has joined #openstack-keystone | 15:15 | |
*** marzif__ has quit IRC | 15:15 | |
*** afazekas_ has joined #openstack-keystone | 15:15 | |
dstanek | breton: actually revoke too | 15:15 |
*** marzif__ has joined #openstack-keystone | 15:16 | |
*** yottatsa has quit IRC | 15:16 | |
samueldmq | ayoung: yeah | 15:16 |
*** Ephur has quit IRC | 15:16 | |
samueldmq | ayoung: btw, I am implementing the missing bit of the fetch (the server side) | 15:16 |
ayoung | samueldmq, lets see if we get more feedback before answering. I want this to be an operator driven discussion if possible | 15:17 |
*** diazjf2 has quit IRC | 15:17 | |
samueldmq | ayoung: and I'll see if I can recover some of the work in the Policy Validation Point we made last year | 15:17 |
samueldmq | ayoung: sure | 15:17 |
ayoung | samueldmq, which part> | 15:17 |
ayoung | ? | 15:17 |
dstanek | henrynash: do you have any strong opinions on how this would work? https://bugs.launchpad.net/keystone/+bug/1437407/comments/11 | 15:17 |
openstack | Launchpad bug 1437407 in Keystone "With using V3 cloud admin policy, domain admin unable to list role assignment for projects in his domain" [Medium,In progress] - Assigned to Guang Yee (guang-yee) | 15:17 |
ayoung | dstanek, I do! | 15:17 |
samueldmq | ayoung: all the implementation of "centralized policy distribution mechanism" | 15:17 |
dstanek | ayoung: let me have it! | 15:17 |
ayoung | dstanek, we need HMT for that | 15:17 |
samueldmq | ayoung: all the code is gonna to be small | 15:17 |
ayoung | a domain admin should not be able to list role assignments for projects without some inheritance set up. | 15:18 |
samueldmq | ayoung: I guess ~1000 lines by summing up middleware + server + oslo | 15:18 |
*** diazjf1 has joined #openstack-keystone | 15:18 | |
ayoung | dstanek, so that is why we were lookuing at "Domain IS-A project" | 15:18 |
ayoung | if you get the role on the domain, and the role assignment is inherited, it would work | 15:19 |
ayoung | but, without that, we need some way to change a domain scoped role assignment to a project scoped one when inherited | 15:19 |
*** diazjf has quit IRC | 15:20 | |
henrynash | dstanek, ayoung: and we are are adding some specific APIs to let you do some specific thisngs, e.g. list roles in a project hierarchy (wip in progress at: https://review.openstack.org/#/c/208152/) | 15:20 |
*** diazjf has joined #openstack-keystone | 15:21 | |
henrynash | ayoung, dstank: but these apis will have a separate policy entry, rather than rely on domain scoping or any such thing | 15:21 |
ayoung | henrynash, You do realize that you are lifting up the side of the tent and inviting the Camels on over, right? | 15:22 |
henrynash | ayoung: only the nice smelling ones | 15:22 |
henrynash | (going off line for a bit, back later) | 15:22 |
*** henrynash has quit IRC | 15:22 | |
dstanek | henrynash: is there a spec for the api changes already proposed? i'm assuming your change is a replacement for https://review.openstack.org/#/c/180846/6 | 15:23 |
*** diazjf1 has quit IRC | 15:23 | |
dstanek | @filterprotected('non-smelly-camels') | 15:23 |
*** diazjf1 has joined #openstack-keystone | 15:23 | |
bknudson | some like smelly camels so it needs to use RBAC | 15:24 |
*** jack__ has joined #openstack-keystone | 15:24 | |
*** vince_ has quit IRC | 15:24 | |
*** diazjf has quit IRC | 15:25 | |
jack__ | stevemar: Hi, steve. Would you please space one minute in reviewing my patch set ? https://review.openstack.org/#/c/203312/ | 15:25 |
*** vince_ has joined #openstack-keystone | 15:26 | |
*** vince_ has quit IRC | 15:26 | |
*** Ephur has joined #openstack-keystone | 15:26 | |
*** diazjf has joined #openstack-keystone | 15:27 | |
*** chris_19 has joined #openstack-keystone | 15:27 | |
*** diazjf1 has quit IRC | 15:28 | |
*** jack__ has quit IRC | 15:28 | |
openstackgerrit | David Charles Kennedy proposed openstack/keystone: Move endpoint catalog filtering to default driver https://review.openstack.org/167675 | 15:28 |
*** yottatsa has joined #openstack-keystone | 15:29 | |
*** diazjf1 has joined #openstack-keystone | 15:31 | |
chris_19 | Trying to enable federation in keystone, but getting a 404 when I try accessing /OS-FEDERATION/identity_providers. Pretty sure I have this instance configured identically to another instance which works. | 15:32 |
*** diazjf has quit IRC | 15:32 | |
*** afazekas_ has quit IRC | 15:33 | |
*** bapalm_ has quit IRC | 15:34 | |
*** diazjf has joined #openstack-keystone | 15:34 | |
*** josecastroleon has quit IRC | 15:34 | |
*** petertr7 is now known as petertr7_away | 15:35 | |
*** diazjf1 has quit IRC | 15:36 | |
*** gyee has joined #openstack-keystone | 15:36 | |
*** ChanServ sets mode: +v gyee | 15:36 | |
*** _cjones_ has joined #openstack-keystone | 15:36 | |
chris_19 | but i can't figure out why the endpoint isn't even found | 15:37 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Refactor: rename Fernet's unscoped federated payload https://review.openstack.org/202190 | 15:38 |
*** belmoreira has quit IRC | 15:39 | |
*** bdossant has quit IRC | 15:39 | |
*** diazjf1 has joined #openstack-keystone | 15:39 | |
*** diazjf has quit IRC | 15:40 | |
*** drjones has joined #openstack-keystone | 15:40 | |
*** yottatsa has quit IRC | 15:41 | |
*** drjones has quit IRC | 15:41 | |
*** drjones has joined #openstack-keystone | 15:43 | |
*** yottatsa has joined #openstack-keystone | 15:43 | |
*** _cjones_ has quit IRC | 15:44 | |
*** drjones has quit IRC | 15:47 | |
*** piyanai has quit IRC | 15:49 | |
*** geoffarnold has quit IRC | 15:52 | |
*** bapalm_ has joined #openstack-keystone | 15:57 | |
*** vivekd has quit IRC | 15:58 | |
stevemar | chris_19: any replies yet? | 15:59 |
*** dims_ has joined #openstack-keystone | 16:00 | |
*** diazjf has joined #openstack-keystone | 16:01 | |
*** ayoung is now known as ayoung-lunch | 16:01 | |
*** dims__ has joined #openstack-keystone | 16:02 | |
*** dims has quit IRC | 16:02 | |
*** fhubik has quit IRC | 16:03 | |
*** diazjf1 has quit IRC | 16:03 | |
*** dims_ has quit IRC | 16:04 | |
*** vivekd has joined #openstack-keystone | 16:05 | |
*** jsavak has quit IRC | 16:08 | |
*** jsavak has joined #openstack-keystone | 16:08 | |
*** stevemar has quit IRC | 16:10 | |
*** dims has joined #openstack-keystone | 16:11 | |
*** stevemar has joined #openstack-keystone | 16:11 | |
*** ChanServ sets mode: +v stevemar | 16:11 | |
*** dims__ has quit IRC | 16:13 | |
*** drjones has joined #openstack-keystone | 16:17 | |
*** mylu has quit IRC | 16:17 | |
*** raildo has joined #openstack-keystone | 16:18 | |
*** mylu has joined #openstack-keystone | 16:20 | |
*** phalmos has quit IRC | 16:20 | |
*** jistr has quit IRC | 16:23 | |
*** browne has quit IRC | 16:23 | |
*** jistr has joined #openstack-keystone | 16:23 | |
*** jistr has quit IRC | 16:24 | |
openstackgerrit | Brant Knudson proposed openstack/python-keystoneclient: Move apiclient.base.Resource into keystoneclient https://review.openstack.org/209592 | 16:25 |
*** mylu has quit IRC | 16:25 | |
*** mylu has joined #openstack-keystone | 16:25 | |
*** pcaruana has quit IRC | 16:26 | |
lbragstad | morganfainberg: dolphm looks like we have two patches that attempt to solve the same thing (https://review.openstack.org/#/c/208021/3, https://review.openstack.org/#/c/196475/3) which one should we move forward with? | 16:26 |
*** diazjf1 has joined #openstack-keystone | 16:26 | |
lbragstad | each patch has a line of dependent patches behind it that could be consolidated into a single series | 16:27 |
lbragstad | or possibly worked in parallel | 16:27 |
bknudson | lbragstad: and there's duplicate bug reports | 16:28 |
*** diazjf has quit IRC | 16:28 | |
lbragstad | bknudson: ah, good point | 16:28 |
*** geoffarnold has joined #openstack-keystone | 16:29 | |
lbragstad | well, bug 1459790 was opened a month earlier | 16:29 |
openstack | bug 1459790 in Keystone "With fernet tokens, validate token loses the ms on 'expires' value " [Low,In progress] https://launchpad.net/bugs/1459790 - Assigned to Dolph Mathews (dolph) | 16:29 |
*** petertr7_away is now known as petertr7 | 16:29 | |
*** diazjf has joined #openstack-keystone | 16:29 | |
*** yottatsa has quit IRC | 16:30 | |
lbragstad | but bug 1469563 has the reference to kilo | 16:30 |
openstack | bug 1469563 in Keystone liberty "Fernet tokens do not maintain expires time across rescope (V2 tokens)" [High,In progress] https://launchpad.net/bugs/1469563 - Assigned to Lance Bragstad (lbragstad) | 16:30 |
*** openstackgerrit_ has joined #openstack-keystone | 16:30 | |
*** diazjf1 has quit IRC | 16:31 | |
*** diazjf1 has joined #openstack-keystone | 16:33 | |
*** drjones has quit IRC | 16:33 | |
*** diazjf has quit IRC | 16:34 | |
openstackgerrit | Raildo Mascena de Sousa Filho proposed openstack/keystone: List credentials by type https://review.openstack.org/208620 | 16:34 |
*** lhcheng has joined #openstack-keystone | 16:34 | |
*** ChanServ sets mode: +v lhcheng | 16:34 | |
*** piyanai has joined #openstack-keystone | 16:35 | |
*** vivekd has quit IRC | 16:36 | |
*** jsavak has quit IRC | 16:36 | |
*** diazjf has joined #openstack-keystone | 16:37 | |
*** yottatsa has joined #openstack-keystone | 16:37 | |
*** diazjf1 has quit IRC | 16:38 | |
*** yottatsa has quit IRC | 16:39 | |
*** yottatsa has joined #openstack-keystone | 16:44 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Unified delegation driver https://review.openstack.org/209600 | 16:45 |
*** _cjones_ has joined #openstack-keystone | 16:47 | |
*** diazjf1 has joined #openstack-keystone | 16:48 | |
*** ayoung-lunch is now known as ayoung | 16:49 | |
*** spandhe has joined #openstack-keystone | 16:49 | |
*** _cjones_ has quit IRC | 16:49 | |
*** diazjf has quit IRC | 16:50 | |
*** vivekd has joined #openstack-keystone | 16:56 | |
*** mylu has quit IRC | 16:56 | |
*** piyanai has quit IRC | 16:58 | |
*** bapalm_ has quit IRC | 17:00 | |
*** piyanai has joined #openstack-keystone | 17:01 | |
*** _cjones_ has joined #openstack-keystone | 17:01 | |
*** mylu has joined #openstack-keystone | 17:02 | |
*** raildo has quit IRC | 17:03 | |
*** openstackgerrit_ has quit IRC | 17:05 | |
*** vivekd has quit IRC | 17:07 | |
*** jasonsb has quit IRC | 17:10 | |
openstackgerrit | Lin Hua Cheng proposed openstack/keystone: List credentials by type https://review.openstack.org/208620 | 17:11 |
*** tsymancz1k is now known as tsymanczyk | 17:11 | |
*** dims has quit IRC | 17:11 | |
*** dims has joined #openstack-keystone | 17:12 | |
*** e0ne has quit IRC | 17:13 | |
*** diazjf has joined #openstack-keystone | 17:13 | |
*** browne has joined #openstack-keystone | 17:14 | |
*** diazjf1 has quit IRC | 17:15 | |
*** mylu has quit IRC | 17:17 | |
*** mylu has joined #openstack-keystone | 17:23 | |
*** openstackgerrit_ has joined #openstack-keystone | 17:24 | |
stevemar | nkinder ayoung hey question for you guys | 17:29 |
openstackgerrit | Brant Knudson proposed openstack/python-keystoneclient: Deprecate openstack.common.apiclient https://review.openstack.org/209609 | 17:29 |
stevemar | ayoung: ever hear of a problem with RDO where the user is 404'ed on certain routes/paths? | 17:29 |
stevemar | chris_19 can hit /OS-OAUTH1/consumers, but not /OS-FEDERATION/identity_providers | 17:30 |
*** diazjf1 has joined #openstack-keystone | 17:30 | |
stevemar | gets a 401 on the prior, and on the later he just gets 404 | 17:31 |
stevemar | listing users/groups is all fine | 17:31 |
stevemar | the paste file seems fine too | 17:31 |
ayoung | stevemar, V2 vs V3? | 17:31 |
stevemar | v3 | 17:31 |
*** mylu has quit IRC | 17:31 | |
ayoung | that might be intentional stevemar | 17:31 |
ayoung | the 404 might be what we return if the request is denied. We do that a lot to not leak info | 17:32 |
stevemar | thought, we edited paste.ini and removed oauth1 and federation, and reset httpd - the behaviour didn't change | 17:32 |
*** iamjarvo has joined #openstack-keystone | 17:32 | |
*** iamjarvo has quit IRC | 17:32 | |
stevemar | ayoung: hmm | 17:32 |
ayoung | look at the API calls themselves | 17:32 |
stevemar | ever hear of that sort of weirdness around restarting httpd? | 17:32 |
*** iamjarvo has joined #openstack-keystone | 17:32 | |
*** iamjarvo has quit IRC | 17:32 | |
*** diazjf2 has joined #openstack-keystone | 17:33 | |
*** diazjf has quit IRC | 17:33 | |
*** iamjarvo has joined #openstack-keystone | 17:33 | |
iurygregory | Hey people, when using (OpenID Connector or SAML - shibboleth/mellon) can I use other web server instead of apache? | 17:33 |
*** iamjarvo has quit IRC | 17:33 | |
*** marzif__ has quit IRC | 17:34 | |
*** iamjarvo has joined #openstack-keystone | 17:34 | |
ayoung | iurygregory, so long as the web server supports SAML | 17:34 |
*** openstackgerrit_ has quit IRC | 17:34 | |
ayoung | iurygregory, from a Keystone perspective, the SAML has to get turned into REMOTE_USER and REMOTE_GROUPS or some other mappable env var | 17:34 |
*** diazjf1 has quit IRC | 17:35 | |
*** piyanai has quit IRC | 17:35 | |
iurygregory | thanks ayoung | 17:35 |
*** diazjf has joined #openstack-keystone | 17:35 | |
*** piyanai has joined #openstack-keystone | 17:37 | |
*** diazjf2 has quit IRC | 17:37 | |
*** piyanai has quit IRC | 17:38 | |
*** piyanai has joined #openstack-keystone | 17:39 | |
*** piyanai has quit IRC | 17:39 | |
*** lsmola has quit IRC | 17:42 | |
*** mylu has joined #openstack-keystone | 17:44 | |
*** iamjarvo has quit IRC | 17:45 | |
*** piyanai has joined #openstack-keystone | 17:45 | |
*** petertr7 is now known as petertr7_away | 17:46 | |
*** piyanai has quit IRC | 17:47 | |
*** piyanai has joined #openstack-keystone | 17:50 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: List projects filtering by is_domain flag https://review.openstack.org/158398 | 17:51 |
*** piyanai has quit IRC | 17:52 | |
*** diazjf1 has joined #openstack-keystone | 17:52 | |
*** e0ne has joined #openstack-keystone | 17:53 | |
*** piyanai has joined #openstack-keystone | 17:54 | |
*** mylu has quit IRC | 17:55 | |
*** diazjf has quit IRC | 17:56 | |
*** petertr7_away is now known as petertr7 | 17:56 | |
*** mylu has joined #openstack-keystone | 17:57 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Restricting domain_id update https://review.openstack.org/207218 | 17:58 |
*** diazjf has joined #openstack-keystone | 17:59 | |
stevemar | ayoung: well that was super weird | 17:59 |
ayoung | that's what...oh forget it | 18:00 |
stevemar | we needed to specify the full path to the paste file in keystone.conf, it wasn't picking it up by default | 18:00 |
*** bapalm_ has joined #openstack-keystone | 18:00 | |
*** diazjf1 has quit IRC | 18:01 | |
*** mylu has quit IRC | 18:01 | |
*** mylu has joined #openstack-keystone | 18:01 | |
*** diazjf1 has joined #openstack-keystone | 18:02 | |
*** diazjf has quit IRC | 18:04 | |
*** bapalm_ has quit IRC | 18:06 | |
*** yottatsa has quit IRC | 18:06 | |
*** phalmos has joined #openstack-keystone | 18:07 | |
*** urulama has quit IRC | 18:15 | |
*** urulama has joined #openstack-keystone | 18:15 | |
*** jasonsb has joined #openstack-keystone | 18:17 | |
*** tsymanczyk has quit IRC | 18:19 | |
*** yottatsa has joined #openstack-keystone | 18:25 | |
*** mylu has quit IRC | 18:26 | |
*** mylu has joined #openstack-keystone | 18:26 | |
*** diazjf1 has left #openstack-keystone | 18:28 | |
*** josecastroleon has joined #openstack-keystone | 18:29 | |
*** yottatsa has quit IRC | 18:29 | |
*** yottatsa has joined #openstack-keystone | 18:31 | |
*** mylu has quit IRC | 18:33 | |
*** tsymanczyk has joined #openstack-keystone | 18:35 | |
*** mylu has joined #openstack-keystone | 18:35 | |
*** tsymanczyk is now known as Guest35446 | 18:35 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Assignment driver cleaning https://review.openstack.org/209624 | 18:35 |
*** ayoung has quit IRC | 18:38 | |
*** openstackgerrit has quit IRC | 18:46 | |
*** mylu has quit IRC | 18:46 | |
*** openstackgerrit has joined #openstack-keystone | 18:47 | |
*** mylu has joined #openstack-keystone | 18:49 | |
*** mylu has quit IRC | 18:50 | |
*** mylu has joined #openstack-keystone | 18:50 | |
*** geoffarnold has quit IRC | 18:55 | |
*** josecastroleon has quit IRC | 18:58 | |
*** geoffarnold has joined #openstack-keystone | 19:01 | |
*** thedodd has quit IRC | 19:04 | |
morganfainberg | lbragstad: lose ms is different than losing consistent expiry | 19:07 |
lbragstad | so keep them separate? | 19:08 |
morganfainberg | Separate bugs. May be fixed by the same patch | 19:08 |
morganfainberg | Haven't looked at the code for either | 19:08 |
* morganfainberg just woke up | 19:09 | |
lbragstad | the code seems to be close | 19:09 |
morganfainberg | But short version is: maintain expiry properly is more important than microseconds | 19:09 |
morganfainberg | Poke dolphin and see if they can be merged into a patch / set a ℅-authored | 19:10 |
morganfainberg | Lol dolphm not dolphin | 19:10 |
morganfainberg | :) | 19:11 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Remove domain table references https://review.openstack.org/165936 | 19:12 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Bye Bye Domain Table https://review.openstack.org/161854 | 19:12 |
openstackgerrit | Henrique Truta proposed openstack/keystone: Add is_domain in token response https://review.openstack.org/197331 | 19:12 |
*** yottatsa has quit IRC | 19:12 | |
openstackgerrit | Henrique Truta proposed openstack/keystone: Change policy to comply with is_domain in token https://review.openstack.org/206063 | 19:13 |
*** yottatsa has joined #openstack-keystone | 19:14 | |
*** Guest35446 has quit IRC | 19:15 | |
*** iamjarvo has joined #openstack-keystone | 19:17 | |
*** TheIntern has quit IRC | 19:17 | |
*** tsymancz1k has joined #openstack-keystone | 19:17 | |
*** r-daneel has joined #openstack-keystone | 19:20 | |
*** narengan has joined #openstack-keystone | 19:23 | |
stevemar | narengan: hi | 19:23 |
stevemar | dolphm: bknudson dstanek gyee morganfainberg marekd lhcheng hey everyone, i'm working with narengan - bringing her up to speed, any suggestions for small work items? :) | 19:24 |
*** sigmavirus24 is now known as sigmavirus24_awa | 19:24 | |
morganfainberg | Uhmmmmmmm | 19:24 |
*** sigmavirus24_awa is now known as sigmavirus24 | 19:24 | |
dstanek | stevemar: nothing specific - i think we still have bugs marked as low hanging fruit | 19:25 |
morganfainberg | Maybe... Ask me again on Monday ;) | 19:25 |
stevemar | dstanek: i think most are committed, let me take another look | 19:25 |
*** yottatsa has quit IRC | 19:27 | |
gyee | stevemar, I usually have a new guy start with documentation update and adding new test cases | 19:28 |
gyee | adding mo func tests for dstanek? | 19:31 |
openstackgerrit | Joshua Harlow proposed openstack/oslo.policy: Ensure checking/setting the 'reducers' attribute is atomic https://review.openstack.org/209644 | 19:31 |
*** mylu has quit IRC | 19:33 | |
dstanek | why do we load domain configs lazily? | 19:33 |
*** roxanaghe has joined #openstack-keystone | 19:33 | |
gyee | why not? :) | 19:33 |
dstanek | why wait until runtime to notice a configuration problem? you would think service start time is the best place for it | 19:34 |
gyee | dstanek, we have per-domain config store in SQL feature | 19:34 |
gyee | so essentially, the configs are dynamic | 19:35 |
gyee | for LDAP backend anyway | 19:35 |
dstanek | but those are loaded once and not re-read so not really dynamic | 19:35 |
dstanek | we should load them once early | 19:36 |
gyee | no, they are reloaded from cache | 19:36 |
dstanek | what reloads them? | 19:36 |
gyee | the managers I think | 19:36 |
dstanek | not that i can see. once it's configured it's configured | 19:37 |
*** e0ne has quit IRC | 19:38 | |
dstanek | oh, wait. i may have found it | 19:38 |
gyee | https://github.com/openstack/keystone/blob/master/keystone/identity/core.py#L270 | 19:38 |
dstanek | i may have to get out my red pen and start refactoring | 19:39 |
gyee | do it amigo! | 19:41 |
dstanek | soon, my friend, soon | 19:41 |
gyee | earn you mo karma and mojo | 19:41 |
dstanek | i got caught up rewriting some ldap tests because things were breaking in weird ways while i was testing some flask changes | 19:41 |
*** TheIntern has joined #openstack-keystone | 19:42 | |
dstanek | too many rabbit holes | 19:42 |
gyee | feeling like Alex in Wonderland huh? :) | 19:42 |
dstanek | i'm still falling and haven't hit the ground yet | 19:43 |
dstanek | i'm hoping that once i do it'll be over quickly | 19:43 |
gyee | dstanek, on a serious note, we may need to start reimplementing our LDAP layer | 19:43 |
gyee | I am hoping to get some time on it soon | 19:43 |
dstanek | morganfainberg wants to move to the new ldap lib too | 19:44 |
*** ayoung has joined #openstack-keystone | 19:51 | |
*** ChanServ sets mode: +v ayoung | 19:51 | |
*** diazjf has joined #openstack-keystone | 19:51 | |
stevemar | lbragstad: ping | 19:51 |
*** thedodd has joined #openstack-keystone | 19:52 | |
*** diazjf1 has joined #openstack-keystone | 19:54 | |
*** diazjf has quit IRC | 19:55 | |
*** rm_work is now known as rm_work|away | 19:59 | |
dstanek | gyee: i can't figure out how to get the dumb configs pre-loaded for the tests | 20:00 |
*** iamjarvo_ has joined #openstack-keystone | 20:00 | |
gyee | dstanek, you can turn off per-domain backend in sql feature if you only care about the static configurations | 20:01 |
gyee | unless you intend to test that part as well | 20:01 |
*** diazjf has joined #openstack-keystone | 20:02 | |
dstanek | gyee: i'm just trying to make sure that they are loaded by the end of the setUp - i'm working with the existing test_backend_ldap tests | 20:02 |
*** narengan_ has joined #openstack-keystone | 20:03 | |
dstanek | i noticed that small changes in the setup ordering mess up the backends so i had the wrong ones running | 20:03 |
*** iamjarvo has quit IRC | 20:03 | |
dstanek | unfortunately the tests all still passed :-( so now i am adding a check to make sure the correct backends are loaded | 20:03 |
*** diazjf1 has quit IRC | 20:04 | |
openstackgerrit | Joshua Harlow proposed openstack/oslo.policy: Have the enforcer have its own file cache https://review.openstack.org/209656 | 20:04 |
*** rm_work|away is now known as rm_work | 20:04 | |
openstackgerrit | Joshua Harlow proposed openstack/oslo.policy: Have the enforcer have its own file cache https://review.openstack.org/209656 | 20:05 |
*** narengan has quit IRC | 20:06 | |
*** diazjf1 has joined #openstack-keystone | 20:06 | |
*** diazjf has quit IRC | 20:07 | |
gyee | dstanek, yeah, you should be able to do something like self.domain_configs.setup_domain_drivers() | 20:07 |
gyee | in the manager | 20:07 |
*** jasondot_ has joined #openstack-keystone | 20:07 | |
dstanek | gyee: yeah, i'm doing something like that, but having trouble | 20:08 |
*** jasondotstar has quit IRC | 20:08 | |
dstanek | gyee: preview - https://www.dropbox.com/s/o6p50w2korrn38f/Screenshot%202015-08-05%2016.08.50.png?dl=0 | 20:09 |
*** diazjf has joined #openstack-keystone | 20:09 | |
gyee | CONF.identity.domain_configurations_from_database is set to False right? | 20:10 |
*** diazjf1 has quit IRC | 20:10 | |
marekd | stevemar: how about functional tests? | 20:10 |
amakarov | gyee, hello! | 20:11 |
gyee | amakarov, hi! | 20:11 |
amakarov | I've implemented materialized path - can you give it a push? ) | 20:11 |
dstanek | gyee: nope, at least for the test case i do workin on right now it pulls it from the db | 20:11 |
gyee | marekd, I also have the new guy to learn the art of coffee making first as well | 20:11 |
amakarov | gyee, https://review.openstack.org/#/c/198418/ | 20:11 |
* gyee add it to his todo list | 20:12 | |
*** urulama has quit IRC | 20:12 | |
*** boris-42 has joined #openstack-keystone | 20:12 | |
*** urulama has joined #openstack-keystone | 20:12 | |
gyee | dstanek, that's strange, if that config is off, it should load from file | 20:13 |
dstanek | gyee: every time i do that it seems like just another thing i won't have time for :-( | 20:13 |
*** diazjf1 has joined #openstack-keystone | 20:13 | |
*** diazjf has quit IRC | 20:13 | |
gyee | https://github.com/openstack/keystone/blob/master/keystone/identity/core.py#L237 | 20:13 |
gyee | you sure you have the path setup correctly? | 20:14 |
*** bapalm has joined #openstack-keystone | 20:16 | |
samueldmq | hello! │ briancurtin | 20:16 |
*** diazjf has joined #openstack-keystone | 20:16 | |
gyee | better yet, just turn off domain-specific driver altogether CONF.identity.domain_specific_drivers_enabled=False | 20:16 |
samueldmq | oops | 20:16 |
dstanek | gyee: then the won't be tested :-) | 20:17 |
gyee | dstanek, so you are trying to test domain-specific backends, but not the domain config in sql part correct? | 20:17 |
*** diazjf1 has quit IRC | 20:17 | |
*** diazjf1 has joined #openstack-keystone | 20:18 | |
*** diazjf has quit IRC | 20:21 | |
dstanek | gyee: i think it thinks the domain config is in sql - i have no idea if it's supposed to | 20:23 |
*** diazjf has joined #openstack-keystone | 20:24 | |
*** diazjf1 has quit IRC | 20:26 | |
gyee | I wonder if the config got overwritten somehow | 20:26 |
dstanek | yeah, this is all sorts of messed up | 20:28 |
dstanek | additionally we load the fixture data 2-3 times per test | 20:28 |
gyee | wtf? | 20:28 |
gyee | 2-3 times, no wonder the shit is slow :) | 20:28 |
*** diazjf has quit IRC | 20:29 | |
*** diazjf has joined #openstack-keystone | 20:29 | |
dstanek | oh... i found my problem | 20:30 |
dstanek | too much subsclassing | 20:32 |
*** diazjf1 has joined #openstack-keystone | 20:32 | |
gyee | they are written by former Java coders :) | 20:33 |
gyee | were | 20:33 |
*** diazjf has quit IRC | 20:33 | |
openstackgerrit | Alexander Makarov proposed openstack/keystone: Materialized path mixin for hierarchical models https://review.openstack.org/198418 | 20:34 |
*** diazjf has joined #openstack-keystone | 20:35 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 20:36 | |
*** diazjf1 has quit IRC | 20:36 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 20:36 | |
*** marzif__ has joined #openstack-keystone | 20:38 | |
openstackgerrit | Doug Fish proposed openstack/python-keystoneclient: Add Keystone2Keystone auth plugin for K2K https://review.openstack.org/207585 | 20:40 |
*** diazjf1 has joined #openstack-keystone | 20:42 | |
*** diazjf has quit IRC | 20:42 | |
*** stevemar has quit IRC | 20:46 | |
*** diazjf has joined #openstack-keystone | 20:47 | |
*** diazjf1 has quit IRC | 20:49 | |
*** roxanaghe has quit IRC | 20:51 | |
openstackgerrit | Dan Nguyen proposed openstack/keystone: Allow Domain Admin to get domain details https://review.openstack.org/208082 | 20:53 |
*** diazjf1 has joined #openstack-keystone | 20:56 | |
openstackgerrit | Doug Fish proposed openstack/python-keystoneclient: Add Keystone2Keystone auth plugin for K2K https://review.openstack.org/207585 | 20:56 |
*** iamjarvo has joined #openstack-keystone | 20:56 | |
*** narengan_ has quit IRC | 20:57 | |
*** narengan has joined #openstack-keystone | 20:58 | |
*** thedodd has quit IRC | 20:58 | |
*** diazjf2 has joined #openstack-keystone | 20:58 | |
*** diazjf has quit IRC | 20:58 | |
*** iamjarvo_ has quit IRC | 20:59 | |
*** gordc has quit IRC | 20:59 | |
*** diazjf1 has quit IRC | 21:00 | |
*** tsymancz1k has quit IRC | 21:00 | |
*** iamjarvo has quit IRC | 21:00 | |
*** iamjarvo has joined #openstack-keystone | 21:01 | |
openstackgerrit | Doug Fish proposed openstack/keystoneauth: Update k2k plugin with related code comments https://review.openstack.org/209671 | 21:01 |
*** iamjarvo has quit IRC | 21:02 | |
*** narengan has quit IRC | 21:02 | |
*** diazjf has joined #openstack-keystone | 21:03 | |
*** diazjf has left #openstack-keystone | 21:03 | |
-openstackstatus- NOTICE: Zuul has been restarted to resolve a reconfiguration failure: previously running jobs have been reenqueued but change events between 19:50-20:54 UTC have been lost and will need to be rechecked or their approvals reapplied to trigger testing. | 21:05 | |
*** diazjf2 has quit IRC | 21:05 | |
samueldmq | dstanek: how far are we on getting CacheControl on ksclien? | 21:06 |
*** bapalm has quit IRC | 21:06 | |
dstanek | samueldmq: i think i have a basic version working... i can publish what i have a little later after i get this ldap stuff out of the way | 21:07 |
*** chris_19 has left #openstack-keystone | 21:07 | |
samueldmq | dstanek: oh nice, let me know once you posted the code | 21:08 |
samueldmq | dstanek: I am plannig to have all the necessary code submitted until next Tuesday | 21:09 |
samueldmq | dstanek: so we can have another demo | 21:09 |
samueldmq | thanks | 21:09 |
-openstackstatus- NOTICE: Correction: change events between 20:50-20:54 UTC (during the restart only) have been lost and will need to be rechecked or their approvals reapplied to trigger testing. | 21:10 | |
*** petertr7 is now known as petertr7_away | 21:10 | |
*** tsymanczyk has joined #openstack-keystone | 21:11 | |
*** narengan has joined #openstack-keystone | 21:11 | |
*** urulama has quit IRC | 21:11 | |
*** tsymanczyk is now known as Guest88240 | 21:11 | |
*** urulama has joined #openstack-keystone | 21:12 | |
*** narengan has quit IRC | 21:13 | |
*** narengan has joined #openstack-keystone | 21:14 | |
*** narengan_ has joined #openstack-keystone | 21:14 | |
*** topol has joined #openstack-keystone | 21:16 | |
*** ChanServ sets mode: +v topol | 21:16 | |
*** chlong has quit IRC | 21:16 | |
*** narengan_ has quit IRC | 21:18 | |
*** narengan has quit IRC | 21:18 | |
*** narengan has joined #openstack-keystone | 21:18 | |
*** narengan_ has joined #openstack-keystone | 21:20 | |
*** topol has quit IRC | 21:20 | |
*** narengan has quit IRC | 21:22 | |
*** chlong has joined #openstack-keystone | 21:30 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Consolidate the fernet provider validate_v3_token() https://review.openstack.org/196877 | 21:32 |
openstackgerrit | Lance Bragstad proposed openstack/keystone: Consolidate the fernet provider issue_v2_token() https://review.openstack.org/197647 | 21:32 |
*** marzif__ has quit IRC | 21:39 | |
*** TheIntern has quit IRC | 21:43 | |
*** tsymancz1k has joined #openstack-keystone | 21:45 | |
*** Guest88240 has quit IRC | 21:45 | |
*** geoffarnold has quit IRC | 21:48 | |
*** geoffarnold has joined #openstack-keystone | 21:50 | |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Validate domain ownership for v2 tokens https://review.openstack.org/208069 | 21:55 |
openstackgerrit | Dolph Mathews proposed openstack/keystone: Fix the claimed expires_at & created_at timestamps for Fernet https://review.openstack.org/208021 | 21:55 |
*** narengan_ has quit IRC | 21:58 | |
*** narengan has joined #openstack-keystone | 21:58 | |
*** roxanaghe has joined #openstack-keystone | 21:59 | |
*** hrou has quit IRC | 21:59 | |
*** edmondsw has quit IRC | 22:00 | |
*** tsymancz1k is now known as tsymanczyk | 22:01 | |
*** narengan has quit IRC | 22:03 | |
roxanaghe | anyone here knows if Fernet token expiration date should contain or not milliseconds? (I am trying to fix: https://bugs.launchpad.net/keystone/+bug/1459790) | 22:04 |
openstack | Launchpad bug 1459790 in Keystone "With fernet tokens, validate token loses the ms on 'expires' value " [Low,In progress] - Assigned to Dolph Mathews (dolph) | 22:04 |
roxanaghe | dolphm, maybe? ^^ | 22:04 |
*** phalmos has quit IRC | 22:11 | |
*** piyanai has quit IRC | 22:16 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 22:27 | |
*** bknudson has quit IRC | 22:33 | |
morganfainberg | roxanaghe: assume we should contain microseconds if it was issued as a v3 token | 22:42 |
morganfainberg | It doesn't break any compatibility if v2 has microseconds (we have cases where it is possible) | 22:42 |
morganfainberg | ideally we should just make everything have microseconds | 22:42 |
*** hrou has joined #openstack-keystone | 22:45 | |
openstackgerrit | Samuel de Medeiros Queiroz proposed openstack/keystone: WIP: Centralized Policies Distribution Mechanism https://review.openstack.org/209695 | 22:48 |
samueldmq | morganfainberg: dstanek ^ implementation was quite simple, I am already calculating the timeouts, etc .. just need to put them in the appropriate HTTP headers in the response | 22:49 |
morganfainberg | Cool | 22:49 |
samueldmq | ayoung: I see good and motivating responses to that thread in the operators list | 22:49 |
samueldmq | morganfainberg: fyi I am planning to have the complete set of patches for the distribution submitted until next meeting | 22:50 |
samueldmq | morganfainberg: so they'll all be reviewable :) | 22:50 |
roxanaghe | morganfainberg: thanks, that sounds good, there are some inconsistencies because uuid v2 token doesn't have ms, uuid v3 has ms, and Fernet has ms for both v2 and v3, so wanted to see if we have a direction | 22:54 |
ayoung | samueldmq, yep. | 22:54 |
*** mordred has joined #openstack-keystone | 22:54 | |
morganfainberg | roxanaghe: move towards microseconds when in doubt | 22:54 |
morganfainberg | Vs removing them | 22:55 |
roxanaghe | morganfainberg: understood, thanks | 22:55 |
morganfainberg | Np | 22:55 |
*** iamjarvo has joined #openstack-keystone | 23:12 | |
*** iamjarvo has quit IRC | 23:13 | |
*** iamjarvo has joined #openstack-keystone | 23:14 | |
*** geoffarnold has quit IRC | 23:15 | |
*** RA_ has joined #openstack-keystone | 23:17 | |
*** woodster_ has quit IRC | 23:20 | |
*** jasonsb has quit IRC | 23:25 | |
*** Guest58084 has quit IRC | 23:28 | |
RA_ | Heya I'm having issues with token renewal, services like nova, cinder are giving unauthorized in horizon after their tokens expire and they don't seem to get a new one until they get restarted. Does anyone have any pointers? | 23:31 |
*** jecarey has quit IRC | 23:34 | |
*** Guest58084 has joined #openstack-keystone | 23:38 | |
morganfainberg | dolphm (re breton's link^): lets just go to microseconds everywhere. we already have cases where you can have / not have microseconds in both v2 and v3. | 23:42 |
morganfainberg | defcore already specifies both are acceptibvle | 23:43 |
*** zzzeek has quit IRC | 23:48 | |
dstanek | samueldmq: why do you need to do client side freshness at all? | 23:54 |
*** iamjarvo has quit IRC | 23:55 | |
*** topol has joined #openstack-keystone | 23:55 | |
*** ChanServ sets mode: +v topol | 23:55 | |
openstackgerrit | Merged openstack/keystone: Disable migration sanity check https://review.openstack.org/196329 | 23:56 |
*** topol has quit IRC | 23:57 | |
*** topol has joined #openstack-keystone | 23:58 | |
*** ChanServ sets mode: +v topol | 23:58 | |
jamielennox | i would suggest microseconds are fine - but more to the point if you format this properly as iso8601 then microseconds or not should just be parsed correctly | 23:58 |
*** henrynash has joined #openstack-keystone | 23:59 | |
*** ChanServ sets mode: +v henrynash | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!