*** jaosorior has quit IRC | 00:00 | |
*** dims_ has joined #openstack-keystone | 00:10 | |
*** dims has quit IRC | 00:11 | |
*** jose-phillips has quit IRC | 00:45 | |
*** henrynash has quit IRC | 00:50 | |
*** henrynash has joined #openstack-keystone | 00:58 | |
*** ChanServ sets mode: +v henrynash | 00:58 | |
*** jperry has quit IRC | 01:07 | |
*** henrynash has quit IRC | 01:16 | |
*** browne has quit IRC | 01:37 | |
*** phalmos has quit IRC | 01:46 | |
*** tqtran has quit IRC | 01:51 | |
*** agrebennikov__ has quit IRC | 01:57 | |
openstackgerrit | Merged openstack/keystone: Fix bad error message from FernetUtils https://review.openstack.org/427004 | 02:33 |
---|---|---|
openstackgerrit | Merged openstack/keystone: Process and validate auth methods against MFA rules https://review.openstack.org/423548 | 02:34 |
openstackgerrit | Merged openstack/keystone: Cleanup TODO about auth.controller code moved to core https://review.openstack.org/426607 | 02:41 |
openstackgerrit | Merged openstack/keystone: Cleanup TODO, AuthContext and AuthInfo to auth.core https://review.openstack.org/426608 | 02:42 |
openstackgerrit | Merged openstack/keystone: Add validation for mfa rule validator (storage) https://review.openstack.org/426955 | 02:43 |
openstackgerrit | Merged openstack/keystone: Update PCI documenation https://review.openstack.org/426823 | 02:47 |
stevemar | yay | 02:59 |
*** stingaci has quit IRC | 03:39 | |
*** pramodrj07 has quit IRC | 03:43 | |
*** nicolasbock has quit IRC | 03:46 | |
*** phalmos has joined #openstack-keystone | 03:46 | |
*** henrynash has joined #openstack-keystone | 03:47 | |
*** ChanServ sets mode: +v henrynash | 03:47 | |
*** thorst_ has quit IRC | 04:00 | |
*** phalmos_ has joined #openstack-keystone | 04:04 | |
*** phalmos has quit IRC | 04:05 | |
*** lucas__ has joined #openstack-keystone | 04:06 | |
*** henrynash has quit IRC | 04:12 | |
*** lucas__ has quit IRC | 04:12 | |
*** phalmos_ has quit IRC | 04:16 | |
*** phalmos has joined #openstack-keystone | 04:19 | |
*** dikonoor has joined #openstack-keystone | 04:35 | |
*** lucas__ has joined #openstack-keystone | 04:38 | |
*** browne1 has joined #openstack-keystone | 04:43 | |
*** adriant has quit IRC | 04:47 | |
*** browne has joined #openstack-keystone | 04:50 | |
*** browne has left #openstack-keystone | 04:53 | |
*** browne has joined #openstack-keystone | 04:53 | |
*** browne has left #openstack-keystone | 04:53 | |
*** dikonoor has quit IRC | 04:54 | |
*** adrian_otto has joined #openstack-keystone | 04:55 | |
*** lucas__ has quit IRC | 04:57 | |
*** thorst_ has joined #openstack-keystone | 05:00 | |
*** jamespage has quit IRC | 05:00 | |
*** jamespage has joined #openstack-keystone | 05:00 | |
*** thorst_ has quit IRC | 05:04 | |
*** lucas__ has joined #openstack-keystone | 05:07 | |
*** dikonoor has joined #openstack-keystone | 05:12 | |
*** browne1 has quit IRC | 05:18 | |
*** dave-mccowan has quit IRC | 05:18 | |
*** lucas__ has quit IRC | 05:20 | |
*** dave-mccowan has joined #openstack-keystone | 05:22 | |
*** phalmos_ has joined #openstack-keystone | 05:25 | |
*** phalmos has quit IRC | 05:25 | |
*** thorst_ has joined #openstack-keystone | 05:31 | |
*** lucas__ has joined #openstack-keystone | 05:35 | |
*** thorst_ has quit IRC | 05:35 | |
*** lucas__ has quit IRC | 05:39 | |
*** lucas__ has joined #openstack-keystone | 05:40 | |
*** lucas__ has quit IRC | 05:43 | |
*** MasterOfBugs has joined #openstack-keystone | 05:54 | |
*** dave-mcc_ has joined #openstack-keystone | 05:59 | |
*** martinlopes has quit IRC | 06:00 | |
*** dave-mccowan has quit IRC | 06:01 | |
*** yarkot has quit IRC | 06:06 | |
*** lucas__ has joined #openstack-keystone | 06:11 | |
*** adrian_otto has quit IRC | 06:16 | |
*** lucas__ has quit IRC | 06:19 | |
*** lucas__ has joined #openstack-keystone | 06:19 | |
*** lucas__ has quit IRC | 06:23 | |
*** lucas__ has joined #openstack-keystone | 06:23 | |
*** lucas__ has quit IRC | 06:27 | |
*** lucas__ has joined #openstack-keystone | 06:27 | |
*** nkinder has quit IRC | 06:28 | |
*** rcernin has joined #openstack-keystone | 06:29 | |
*** lucas__ has quit IRC | 06:31 | |
*** yarkot has joined #openstack-keystone | 06:31 | |
*** lucas__ has joined #openstack-keystone | 06:40 | |
*** lucas__ has quit IRC | 06:42 | |
*** lucas__ has joined #openstack-keystone | 06:49 | |
*** lucas__ has quit IRC | 07:09 | |
*** phalmos_ has quit IRC | 07:13 | |
*** richm has joined #openstack-keystone | 07:16 | |
*** tesseract has joined #openstack-keystone | 07:18 | |
*** pcaruana has joined #openstack-keystone | 07:19 | |
*** richm has quit IRC | 07:27 | |
*** xek__ is now known as xek | 07:31 | |
*** thorst_ has joined #openstack-keystone | 07:31 | |
*** thorst_ has quit IRC | 07:36 | |
*** Jack_I has joined #openstack-keystone | 07:39 | |
*** richm has joined #openstack-keystone | 07:49 | |
*** nkinder has joined #openstack-keystone | 07:52 | |
*** dave-mcc_ has quit IRC | 08:24 | |
openstackgerrit | Merged openstack/keystone: update keystone.conf.sample for ocata-rc https://review.openstack.org/427483 | 08:25 |
*** zzzeek has quit IRC | 09:00 | |
*** zzzeek has joined #openstack-keystone | 09:00 | |
*** StefanPaetowJisc has joined #openstack-keystone | 09:07 | |
*** richm has quit IRC | 09:07 | |
*** richm has joined #openstack-keystone | 09:20 | |
*** thorst_ has joined #openstack-keystone | 09:32 | |
*** thorst_ has quit IRC | 09:38 | |
*** phalmos has joined #openstack-keystone | 09:41 | |
*** StefanPaetowJisc has quit IRC | 10:01 | |
*** Jack_I has quit IRC | 10:21 | |
*** dikonoor has quit IRC | 10:22 | |
*** edmondsw has joined #openstack-keystone | 10:30 | |
*** thorst_ has joined #openstack-keystone | 10:34 | |
*** edmondsw has quit IRC | 10:35 | |
*** thorst_ has quit IRC | 10:39 | |
*** dikonoor has joined #openstack-keystone | 10:40 | |
*** mvk has quit IRC | 10:49 | |
*** phalmos has quit IRC | 10:58 | |
*** nicolasbock has joined #openstack-keystone | 11:04 | |
*** mvk has joined #openstack-keystone | 11:19 | |
*** jamielennox is now known as jamielennox|away | 11:25 | |
*** dikonoor has quit IRC | 11:32 | |
*** dikonoor has joined #openstack-keystone | 11:41 | |
Adobeman | ayoung: I'm reading your blog about freeipa. So you did not use openldap, just use the LDAP within FreeIPA..? | 11:42 |
ayoung | Adobeman, yep | 11:42 |
Adobeman | and this can act like an CA so keystone will stop giving me fit about untrusted cert...? | 11:43 |
ayoung | Adobeman, yep | 11:44 |
Adobeman | ok, thanks. I will continue look into this. | 11:44 |
ayoung | Adobeman, and it will be a CA for every controller you deploy | 11:45 |
Adobeman | sure | 11:45 |
Adobeman | that's what I like | 11:45 |
ayoung | Adobeman, and we are working on a metadata plugin that lets you autoenroll VMs | 11:45 |
Adobeman | oh that's very cool | 11:45 |
ayoung | Adobeman, a lot of work has gone into IPA, to make it a viable alternative to AD | 11:45 |
Adobeman | I'm finding rather amusing that I'm the only person out there trying to do openldap with keystone.. :P | 11:46 |
Adobeman | looks like everyone else went freeipa | 11:46 |
Adobeman | ayoung: that's very ambiguous goal. Replace AD! | 11:46 |
Adobeman | I'm going to cheer for you guys :) | 11:47 |
ayoung | Adobeman, its a good tool. The biggest gotcha is in the install stage, getting naming set up. | 11:48 |
ayoung | Usually I create a new domain for the deployment, and add the host machines IP address to the /etc/hosts file with a name like ipa.mydomain.test for internal deployments | 11:48 |
ayoung | Adobeman, had a scheme for our development team that was ipa.<username>.<whichlab>.test | 11:49 |
ayoung | sometimes augmented with a "what is this deployment testing. | 11:49 |
ayoung | So ipa.ayoung.centos7.oslab.test | 11:50 |
Adobeman | wonder who runs this in production.. | 11:50 |
ayoung | the .test extension makes it look like a FQDN to things that do regex matching, say for email addresses | 11:50 |
ayoung | Adobeman, lots of our customers | 11:50 |
ayoung | I work at Red Hat. It is our Identity Management product | 11:50 |
ayoung | https://access.redhat.com/products/identity-management | 11:51 |
Adobeman | ohhhhhhh Id idnt realize that.. | 11:51 |
Adobeman | yes, I deal with redhat | 11:51 |
Adobeman | I stumble into their identity management thing other day, but I got skeptical and back away from it.. | 11:51 |
Adobeman | the current deployment I'm trying is centos | 11:52 |
Adobeman | if this goes well, I may just do this in rhel environment as well.. | 11:52 |
ayoung | Its in the base Centos REPO | 11:53 |
Adobeman | yep, I see it | 11:53 |
ayoung | yum install ipa-server ipa-dns-thingyicanneverremeberiwishtheydmakedefault | 11:53 |
ayoung | Adobeman, https://github.com/admiyo/rippowam/blob/master/roles/ipaserver/tasks/main.yml was my Ansible role to install it | 11:55 |
Adobeman | ok, very cool. thanks | 11:55 |
ayoung | the RPM is called freeipa-server-dns.noarch in Fedora now. Used to be called bind-dyndb-ldap | 11:55 |
ayoung | Well, technically they are different things, but the extra RPM you needed to get DNS working was called that | 11:56 |
*** v1k0d3n has quit IRC | 12:02 | |
samueldmq | morning keystone | 12:03 |
*** richm has quit IRC | 12:24 | |
*** catintheroof has joined #openstack-keystone | 12:28 | |
*** nkinder has quit IRC | 12:34 | |
*** richm has joined #openstack-keystone | 12:36 | |
*** thorst_ has joined #openstack-keystone | 12:45 | |
*** edmondsw has joined #openstack-keystone | 12:46 | |
*** edmondsw has quit IRC | 12:46 | |
*** edmondsw has joined #openstack-keystone | 12:46 | |
*** mvk has quit IRC | 12:47 | |
*** Mr_Smurf has joined #openstack-keystone | 12:58 | |
*** richm has quit IRC | 12:59 | |
*** mvk has joined #openstack-keystone | 13:00 | |
*** jascott1 has quit IRC | 13:03 | |
*** flwang has quit IRC | 13:05 | |
*** bapalm has quit IRC | 13:07 | |
*** nkinder has joined #openstack-keystone | 13:09 | |
*** mordred has quit IRC | 13:10 | |
*** bapalm has joined #openstack-keystone | 13:12 | |
*** richm has joined #openstack-keystone | 13:16 | |
*** mordred has joined #openstack-keystone | 13:18 | |
*** flwang has joined #openstack-keystone | 13:22 | |
*** bapalm has quit IRC | 13:24 | |
*** lamt has joined #openstack-keystone | 13:37 | |
rodrigods | stevemar, can you take a look in my comment at https://review.openstack.org/#/c/426449/5 ? | 13:45 |
rodrigods | stevemar, i didn't participate in the discussion about including the "federated" attribute for non-federated users, the change broke tempest and keystoneclient functional tests | 13:46 |
rodrigods | i would like to know why it is the best option | 13:46 |
rodrigods | instead of just not including the attribute for non-federated users | 13:47 |
*** v1k0d3n has joined #openstack-keystone | 13:48 | |
openstackgerrit | Merged openstack/keystone: Add comment to clarify resource-options jsonschema https://review.openstack.org/426604 | 13:54 |
*** richm1 has joined #openstack-keystone | 13:56 | |
*** nkinder has quit IRC | 13:58 | |
*** richm has quit IRC | 13:59 | |
*** lamt has quit IRC | 14:03 | |
Mr_Smurf | I'm having some federation issues... After federated login I just end up on my keystone endpoint and it does not redirect me back to horizon | 14:05 |
*** lucas_ has joined #openstack-keystone | 14:11 | |
*** lucas_ has quit IRC | 14:13 | |
*** lucas_ has joined #openstack-keystone | 14:20 | |
*** agrebennikov__ has joined #openstack-keystone | 14:24 | |
*** lamt has joined #openstack-keystone | 14:26 | |
*** lucas_ has quit IRC | 14:36 | |
*** nkinder has joined #openstack-keystone | 14:36 | |
rodrigods | Mr_Smurf, you might being affected by https://bugs.launchpad.net/keystoneauth/+bug/1660436 | 14:38 |
openstack | Launchpad bug 1660436 in OpenStack Dashboard (Horizon) "Federated users cannot log into horizon" [Undecided,In progress] - Assigned to Colleen Murphy (krinkle) | 14:38 |
*** spilla has joined #openstack-keystone | 14:39 | |
*** dikonoor has quit IRC | 14:39 | |
*** stingaci has joined #openstack-keystone | 14:43 | |
Mr_Smurf | rodrigods: ok, I will check | 14:43 |
*** lamt has quit IRC | 14:46 | |
*** dave-mccowan has joined #openstack-keystone | 14:46 | |
lbragstad | quick question here - does anyone know when/where this was discussed in the past? http://lists.openstack.org/pipermail/openstack-dev/2017-February/111352.html | 14:57 |
Mr_Smurf | rodrigods: not the same problem as I get.. I can login if I don't select a region.. after login if I select my region in the dropdown list I'm redirected via my idp and then I just end up at my keystone endpoint with som nice json text telling me version, status, mdeia-types etc... | 14:57 |
*** adrian_otto has joined #openstack-keystone | 15:02 | |
*** lucas_ has joined #openstack-keystone | 15:06 | |
*** MasterOfBugs has quit IRC | 15:07 | |
*** adrian_otto has quit IRC | 15:08 | |
*** jperry has joined #openstack-keystone | 15:11 | |
*** sigmavirus has quit IRC | 15:14 | |
*** adrian_otto has joined #openstack-keystone | 15:17 | |
*** lamt has joined #openstack-keystone | 15:22 | |
*** richm1 has quit IRC | 15:23 | |
*** sigmavirus has joined #openstack-keystone | 15:23 | |
*** richm has joined #openstack-keystone | 15:23 | |
*** richm has quit IRC | 15:24 | |
*** ravelar has joined #openstack-keystone | 15:27 | |
*** adrian_otto1 has joined #openstack-keystone | 15:27 | |
*** adrian_otto1 has quit IRC | 15:28 | |
*** adrian_otto has quit IRC | 15:28 | |
stevemar | breton: hmm, reading the heat meeting transcript | 15:29 |
stevemar | breton: would oauth work? | 15:29 |
Mr_Smurf | so are regions not compatible with federated login? | 15:30 |
Mr_Smurf | ie saml2 | 15:30 |
*** adrian_otto has joined #openstack-keystone | 15:31 | |
*** adrian_otto has quit IRC | 15:33 | |
*** chris_hultin|AWA is now known as chris_hultin | 15:33 | |
*** lamt has quit IRC | 15:34 | |
*** edtubill has joined #openstack-keystone | 15:34 | |
*** lamt has joined #openstack-keystone | 15:34 | |
*** spzala has joined #openstack-keystone | 15:39 | |
stevemar | dolphm: thanks for replying to the ML | 15:47 |
stevemar | was just typing something up... :) | 15:47 |
stevemar | happy to delete | 15:47 |
*** rcernin has quit IRC | 15:51 | |
*** lamt has quit IRC | 15:56 | |
*** lamt has joined #openstack-keystone | 15:57 | |
breton | stevemar: not sure. I think no, because from keystone POV federated user is groupless and roleless | 16:00 |
lbragstad | ping ping raildo, ktychkova, dolphm, dstanek, rderose, htruta, atrmr, gagehugo, lamt, thinrichs, edmondsw, ruan, ayoung, stevemar, ravelar, morgan | 16:02 |
lbragstad | policy meeting in #openstack-meeting-cp for those who want to join! | 16:02 |
*** adrian_otto has joined #openstack-keystone | 16:05 | |
*** BobBall has joined #openstack-keystone | 16:05 | |
ayoung | knikolla, care to join the policy meeting in #openstack-meeting-cp ? | 16:10 |
openstackgerrit | ayoung proposed openstack/keystone: Refactor Authorization: https://review.openstack.org/387161 | 16:16 |
openstackgerrit | ayoung proposed openstack/keystone: Refactor is_admin https://review.openstack.org/387710 | 16:17 |
openstackgerrit | ayoung proposed openstack/keystone: Add is_admin_project check to policy.json https://review.openstack.org/257636 | 16:17 |
*** adrian_otto has quit IRC | 16:22 | |
openstackgerrit | Merged openstack/keystone: Use https for docs.openstack.org references https://review.openstack.org/426944 | 16:36 |
openstackgerrit | Merged openstack/keystone: No need to enable infer_roles setting https://review.openstack.org/427109 | 16:36 |
*** gitudaniel has joined #openstack-keystone | 16:38 | |
gitudaniel | lbragstad: dstanek: morgan: thank you for tolerating my questions yesterday and for your help | 16:40 |
lbragstad | gitudaniel anytime - were you able to make some progress? | 16:40 |
dstanek | gitudaniel: np at all | 16:41 |
gitudaniel | lbragstad: yes I ran the keystone-manage fernet_setup as root like dstanek suggested now all I have to do is set up a --keystone-user and --keystone-group to proceed on | 16:42 |
*** spzala has quit IRC | 16:43 | |
*** spzala has joined #openstack-keystone | 16:44 | |
openstackgerrit | Samuel Pilla proposed openstack/keystone: Add `is_local` to user https://review.openstack.org/427807 | 16:44 |
*** spzala has quit IRC | 16:48 | |
gitudaniel | been reading up on ansible. I have no experience on that. I appreciate the challenge. I'm clocking out for the night have a great day | 16:48 |
lbragstad | gitudaniel good night! | 16:49 |
*** spzala has joined #openstack-keystone | 16:50 | |
*** gitudaniel has quit IRC | 16:50 | |
*** spzala has quit IRC | 16:54 | |
*** tesseract has quit IRC | 16:56 | |
*** browne has joined #openstack-keystone | 16:56 | |
*** edtubill has quit IRC | 16:56 | |
*** spzala has joined #openstack-keystone | 16:57 | |
*** spzala has quit IRC | 17:06 | |
*** spzala has joined #openstack-keystone | 17:08 | |
knikolla | o/ | 17:08 |
knikolla | ayoung: sorry, was in another meeting | 17:09 |
ayoung | knikolla, no problem. You should try to make sure to get to the policy one, though, if you are going to take the RBAC stuff | 17:10 |
knikolla | ayoung: i usually do, but today i had stuff come up. | 17:10 |
knikolla | i'll read the logs | 17:10 |
ayoung | knikolla, no problem. One thing we discussed was the bug 968696 work. I am not going to be able to finish it | 17:11 |
openstack | bug 968696 in OpenStack Identity (keystone) ""admin"-ness not properly scoped" [High,In progress] https://launchpad.net/bugs/968696 - Assigned to Adam Young (ayoung) | 17:11 |
*** spzala has quit IRC | 17:12 | |
knikolla | ayoung: you already have reviews up for that right? | 17:13 |
ayoung | knikolla, yeah, but they need tempest work to pass CI | 17:13 |
ayoung | knikolla, https://review.openstack.org/#/q/topic:bug/968696 | 17:14 |
knikolla | ayoung: does RBAC depend on it? | 17:15 |
*** richm has joined #openstack-keystone | 17:24 | |
*** nkinder has quit IRC | 17:30 | |
*** spzala has joined #openstack-keystone | 17:43 | |
*** spzala has quit IRC | 17:47 | |
*** spzala has joined #openstack-keystone | 17:49 | |
*** spzala has quit IRC | 17:54 | |
*** richm has left #openstack-keystone | 17:54 | |
*** richm has joined #openstack-keystone | 17:55 | |
*** v1k0d3n has quit IRC | 17:56 | |
*** spzala has joined #openstack-keystone | 17:57 | |
*** v1k0d3n has joined #openstack-keystone | 18:00 | |
*** spzala has quit IRC | 18:02 | |
openstackgerrit | Gage Hugo proposed openstack/keystone: WIP Fix multiple uuid warnings with pycadf https://review.openstack.org/426411 | 18:03 |
*** spzala has joined #openstack-keystone | 18:03 | |
*** harlowja_ has joined #openstack-keystone | 18:05 | |
*** harlowja has quit IRC | 18:06 | |
*** spzala has quit IRC | 18:08 | |
*** tqtran has joined #openstack-keystone | 18:13 | |
*** spzala has joined #openstack-keystone | 18:19 | |
*** ravelar has quit IRC | 18:23 | |
*** pcaruana has quit IRC | 18:28 | |
*** ravelar has joined #openstack-keystone | 18:35 | |
*** adrian_otto has joined #openstack-keystone | 18:38 | |
*** adrian_otto has quit IRC | 18:45 | |
openstackgerrit | Andreas Jaeger proposed openstack/keystone: Prepare for using standard python tests https://review.openstack.org/427862 | 18:49 |
*** richm has quit IRC | 18:50 | |
*** spzala has quit IRC | 18:51 | |
*** spzala has joined #openstack-keystone | 18:52 | |
*** richm has joined #openstack-keystone | 18:53 | |
*** MasterOfBugs has joined #openstack-keystone | 18:53 | |
*** spzala has quit IRC | 18:56 | |
*** mvk has quit IRC | 18:57 | |
*** spzala has joined #openstack-keystone | 18:58 | |
*** spzala has quit IRC | 19:01 | |
*** spzala has joined #openstack-keystone | 19:02 | |
*** jaosorior has joined #openstack-keystone | 19:06 | |
*** harlowja_ has quit IRC | 19:19 | |
*** adrian_otto has joined #openstack-keystone | 19:30 | |
*** mvk has joined #openstack-keystone | 19:34 | |
openstackgerrit | ayoung proposed openstack/keystone: Remove ADMIN_TOKEN from paste pipeline https://review.openstack.org/427878 | 19:39 |
ayoung | stevemar, I wonder who ^^ is going to break | 19:39 |
ayoung | its not a full removal of ADMIN_TOKEN, but makes sure people have to really want to use it ... | 19:40 |
*** stingaci has quit IRC | 19:40 | |
*** adrian_otto has quit IRC | 19:43 | |
*** jdennis has quit IRC | 19:59 | |
lbragstad | this would be good for us to get our eyes on https://review.openstack.org/#/c/427872/1 | 20:00 |
*** jdennis has joined #openstack-keystone | 20:01 | |
*** lamt has quit IRC | 20:05 | |
*** stingaci has joined #openstack-keystone | 20:05 | |
*** charz_ has quit IRC | 20:09 | |
*** charz has joined #openstack-keystone | 20:10 | |
*** MasterOfBugs has quit IRC | 20:16 | |
openstackgerrit | Merged openstack/keystone: Add validation that token method isn't needed in MFARules https://review.openstack.org/426959 | 20:16 |
*** MasterOfBugs has joined #openstack-keystone | 20:17 | |
*** richm has quit IRC | 20:22 | |
*** richm has joined #openstack-keystone | 20:25 | |
*** jamielennox|away is now known as jamielennox | 20:30 | |
*** lamt has joined #openstack-keystone | 20:34 | |
*** browne has quit IRC | 20:36 | |
*** browne has joined #openstack-keystone | 20:37 | |
*** clayg has left #openstack-keystone | 20:39 | |
*** harlowja has joined #openstack-keystone | 20:39 | |
*** browne has quit IRC | 20:48 | |
*** browne has joined #openstack-keystone | 20:49 | |
openstackgerrit | Merged openstack/keystone: Remove de-dupe for MFA Rule parsing. https://review.openstack.org/427026 | 20:51 |
openstackgerrit | Merged openstack/keystone: Add MFA Rules Release Note https://review.openstack.org/427328 | 20:51 |
*** aloga_ has joined #openstack-keystone | 20:56 | |
*** aloga_ has quit IRC | 20:56 | |
*** aloga_ has joined #openstack-keystone | 20:56 | |
*** aloga_ has quit IRC | 20:56 | |
*** jose-phillips has joined #openstack-keystone | 21:05 | |
*** erlon has quit IRC | 21:20 | |
*** stingaci has quit IRC | 21:24 | |
*** adrian_otto has joined #openstack-keystone | 21:29 | |
*** erlon has joined #openstack-keystone | 21:29 | |
*** richm has quit IRC | 21:33 | |
*** lucas_ has quit IRC | 21:34 | |
*** catintheroof has quit IRC | 21:37 | |
*** catintheroof has joined #openstack-keystone | 21:37 | |
*** browne has quit IRC | 21:38 | |
*** edmondsw has quit IRC | 21:44 | |
*** adrian_otto has quit IRC | 21:45 | |
*** browne has joined #openstack-keystone | 21:50 | |
*** edmondsw has joined #openstack-keystone | 21:53 | |
*** spzala has quit IRC | 21:55 | |
*** adrian_otto has joined #openstack-keystone | 21:57 | |
*** catintheroof has quit IRC | 21:57 | |
*** spzala has joined #openstack-keystone | 21:58 | |
*** catintheroof has joined #openstack-keystone | 21:58 | |
*** phalmos has joined #openstack-keystone | 21:59 | |
*** spzala_ has joined #openstack-keystone | 22:00 | |
openstackgerrit | Dirk Mueller proposed openstack/keystone: Stop reading lcoal config dirs for domain-specific SQL config driver https://review.openstack.org/427940 | 22:01 |
openstackgerrit | Dirk Mueller proposed openstack/keystone: Stop reading local config dirs for domain-specific SQL config driver https://review.openstack.org/427940 | 22:01 |
*** stingaci has joined #openstack-keystone | 22:01 | |
*** spzala has quit IRC | 22:03 | |
*** spzala_ has quit IRC | 22:04 | |
*** phalmos has quit IRC | 22:04 | |
*** stingaci has quit IRC | 22:06 | |
*** lucas_ has joined #openstack-keystone | 22:07 | |
*** stingaci has joined #openstack-keystone | 22:08 | |
*** thorst_ has quit IRC | 22:09 | |
*** thorst_ has joined #openstack-keystone | 22:16 | |
*** spilla has quit IRC | 22:19 | |
*** thorst_ has quit IRC | 22:20 | |
*** MasterOfBugs has quit IRC | 22:20 | |
*** browne has quit IRC | 22:28 | |
*** lamt has quit IRC | 22:29 | |
*** lamt has joined #openstack-keystone | 22:30 | |
*** adriant has joined #openstack-keystone | 22:31 | |
*** flwang has left #openstack-keystone | 22:34 | |
*** catintheroof has quit IRC | 22:35 | |
*** edtubill has joined #openstack-keystone | 22:35 | |
morgan | stevemar: it's all merged. | 22:39 |
*** thorst_ has joined #openstack-keystone | 22:40 | |
morgan | ayoung: uhm... | 22:40 |
morgan | ayoung: i think we have another fix that will be super easy | 22:40 |
ayoung | morgan,for what? | 22:40 |
morgan | ayoung: admin_token | 22:41 |
morgan | i *think* | 22:41 |
ayoung | morgan, less than what I did, or more? | 22:41 |
morgan | different | 22:41 |
morgan | let me check | 22:41 |
*** edmondsw has quit IRC | 22:41 | |
morgan | ayoung: so i think the better fix is to merge admin token bits into authcontext middleware | 22:42 |
morgan | and then make admin token no-op | 22:42 |
morgan | and issue a deprecation warning it will be dropped code wise soon | 22:42 |
morgan | and do what you did. | 22:42 |
ayoung | morgan, so long as the existing ADMIN_TOKEN code is disabled by default, I don't care. But it should be possible to re-enable | 22:43 |
ayoung | the deprecation warning has been in there since mitaka | 22:43 |
morgan | right, i want to drop the actual entry in the paste_ini. it is deisabled by default because the option is disabled | 22:43 |
morgan | it doesn't actually have a deprecation warning | 22:43 |
morgan | it has a "hey this is insecure" warning | 22:43 |
ayoung | I thought that was what I did | 22:43 |
ayoung | there is a deprecation warning in the config file | 22:44 |
morgan | it is in the config | 22:44 |
morgan | it doesn't emit a warning though :( | 22:44 |
morgan | a deprecation warning that is | 22:44 |
*** thorst_ has quit IRC | 22:44 | |
morgan | basically i want to just do a couple more things than you did in yours | 22:44 |
morgan | i'll add on to your patch (followups) ^_^ | 22:44 |
morgan | good start, not sufficient imo | 22:45 |
*** martinlopes has joined #openstack-keystone | 22:45 | |
ayoung | Ah, I'm totaly ok with that. | 22:47 |
*** lamt has quit IRC | 22:53 | |
*** lamt has joined #openstack-keystone | 22:55 | |
*** phalmos has joined #openstack-keystone | 22:57 | |
*** chris_hultin is now known as chris_hultin|AWA | 22:58 | |
morgan | trying to make it easier to make it go away forever down the line | 22:58 |
morgan | but also not need extra cruft in the pipeline | 22:58 |
*** edtubill has quit IRC | 22:59 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone: Deprecate (and emit message) auth_token_middleware https://review.openstack.org/427962 | 23:07 |
morgan | ayoung: ^ something like that | 23:07 |
*** v1k0d3n has quit IRC | 23:07 | |
openstackgerrit | Ken Johnston proposed openstack/keystone: Readability enhancements to architecture doc https://review.openstack.org/422375 | 23:08 |
*** jperry has quit IRC | 23:09 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone: Deprecate (and emit message) auth_token_middleware https://review.openstack.org/427962 | 23:09 |
*** phalmos has quit IRC | 23:13 | |
*** spzala has joined #openstack-keystone | 23:15 | |
jamielennox | morgan: the admin_token middleware? | 23:18 |
*** spzala has quit IRC | 23:18 | |
*** spzala has joined #openstack-keystone | 23:18 | |
jamielennox | morgan: cause i'd like to not remove auth_token | 23:18 |
*** v1k0d3n has joined #openstack-keystone | 23:22 | |
*** browne1 has joined #openstack-keystone | 23:23 | |
*** spzala has quit IRC | 23:25 | |
*** phalmos has joined #openstack-keystone | 23:27 | |
*** browne1 has quit IRC | 23:36 | |
*** v1k0d3n has quit IRC | 23:41 | |
morgan | jamielennox: admin_token | 23:46 |
morgan | jamielennox: it's a typo | 23:46 |
jamielennox | morgan: no worries, just flicked past to see what was happening and was concerned | 23:47 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone: Deprecate (and emit message) admin_token_auth https://review.openstack.org/427962 | 23:47 |
morgan | jamielennox: ^ | 23:47 |
jamielennox | :) | 23:48 |
*** martinlopes has quit IRC | 23:49 | |
*** gyee has joined #openstack-keystone | 23:52 | |
*** martinlopes has joined #openstack-keystone | 23:52 | |
*** lamt has quit IRC | 23:56 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!