*** thorst has quit IRC | 00:01 | |
*** jlopezgu_ has quit IRC | 00:02 | |
ayoung | knikolla, you get my response on the update on the RBAC patch? https://review.openstack.org/#/c/401808/ You can probably post what you have working now. | 00:14 |
---|---|---|
openstackgerrit | Ron De Rose proposed openstack/keystone master: Return the local user roles for federated users mapped to local users https://review.openstack.org/451604 | 00:19 |
openstackgerrit | Ron De Rose proposed openstack/keystone master: Return the local user roles for a federated user mapped to a local user https://review.openstack.org/451604 | 00:20 |
*** dikonoor has joined #openstack-keystone | 00:25 | |
*** thorst has joined #openstack-keystone | 00:36 | |
*** bjornar_ has joined #openstack-keystone | 00:44 | |
*** david-lyle_ has joined #openstack-keystone | 00:45 | |
*** david-lyle has quit IRC | 00:48 | |
*** thorst has quit IRC | 00:53 | |
lbragstad | knikolla well - it looks like the recheck passed -https://review.openstack.org/#/c/451559/1 | 00:54 |
lbragstad | https://review.openstack.org/#/c/451559/1 | 00:54 |
*** sjain has joined #openstack-keystone | 00:56 | |
knikolla | ayoung: yep, i'll do that tomorrow since it's in my work pc | 01:04 |
knikolla | lbragstad: awesome! | 01:04 |
openstackgerrit | Merged openstack/keystone master: Add charset to webob.Response https://review.openstack.org/451559 | 01:08 |
*** sjain has quit IRC | 01:09 | |
*** gyee has quit IRC | 01:11 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Remove create_container_group from tests https://review.openstack.org/450990 | 01:16 |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Updated from global requirements https://review.openstack.org/451014 | 01:16 |
*** dikonoor has quit IRC | 01:16 | |
*** liujiong has joined #openstack-keystone | 01:18 | |
*** luzC has quit IRC | 01:20 | |
*** jlwhite has quit IRC | 01:20 | |
*** luzC has joined #openstack-keystone | 01:25 | |
*** jlwhite has joined #openstack-keystone | 01:25 | |
*** edmondsw has quit IRC | 01:29 | |
openstackgerrit | ayoung proposed openstack/keystone master: Removed domain conflict guard in load_fixtures https://review.openstack.org/450991 | 01:31 |
openstackgerrit | ayoung proposed openstack/keystone master: Replace wip with skip https://review.openstack.org/450992 | 01:31 |
*** david-lyle__ has joined #openstack-keystone | 01:34 | |
*** david-lyle_ has quit IRC | 01:37 | |
*** chlong has joined #openstack-keystone | 01:47 | |
*** oomichi has quit IRC | 01:48 | |
*** thorst has joined #openstack-keystone | 01:51 | |
*** oomichi has joined #openstack-keystone | 01:52 | |
*** thorst has quit IRC | 02:04 | |
*** rderose has quit IRC | 02:08 | |
openstackgerrit | Anthony Washington proposed openstack/keystone master: Move project policies to DocumentedRuleDefault https://review.openstack.org/449238 | 02:09 |
*** guoshan has joined #openstack-keystone | 02:20 | |
*** knangia has quit IRC | 02:21 | |
*** prashkre has joined #openstack-keystone | 02:27 | |
*** adrian_otto has joined #openstack-keystone | 02:31 | |
*** thorst has joined #openstack-keystone | 02:31 | |
*** agrebennikov has quit IRC | 02:32 | |
*** prashkre has quit IRC | 02:35 | |
*** knangia has joined #openstack-keystone | 02:35 | |
*** thorst has quit IRC | 02:38 | |
*** bjornar_ has quit IRC | 02:42 | |
*** guoshan has quit IRC | 02:45 | |
*** adrian_otto has quit IRC | 02:53 | |
*** adrian_otto has joined #openstack-keystone | 02:53 | |
*** ravelar has quit IRC | 02:56 | |
*** adrian_otto has quit IRC | 03:03 | |
*** adrian_otto has joined #openstack-keystone | 03:03 | |
*** adrian_otto has quit IRC | 03:04 | |
*** cmurphy has quit IRC | 03:06 | |
*** oomichi has quit IRC | 03:08 | |
*** oomichi has joined #openstack-keystone | 03:12 | |
*** dikonoor has joined #openstack-keystone | 03:19 | |
*** dave-mccowan has quit IRC | 03:27 | |
*** cmurphy has joined #openstack-keystone | 03:29 | |
*** thorst has joined #openstack-keystone | 03:36 | |
*** guoshan has joined #openstack-keystone | 03:36 | |
openstackgerrit | Merged openstack/keystone master: Remove create_container_group from tests https://review.openstack.org/450990 | 03:37 |
*** adrian_otto has joined #openstack-keystone | 03:49 | |
*** thorst has quit IRC | 03:55 | |
openstackgerrit | Steve Martinelli proposed openstack/keystone master: Remove revocation API dependency from resource API https://review.openstack.org/447564 | 03:58 |
openstackgerrit | Steve Martinelli proposed openstack/keystone master: Remove revocation API dependency from identity API https://review.openstack.org/447573 | 03:58 |
*** guoshan has quit IRC | 04:00 | |
* stevemar punts through several things | 04:03 | |
*** adrian_otto has quit IRC | 04:20 | |
*** links has joined #openstack-keystone | 04:26 | |
*** adrian_otto has joined #openstack-keystone | 04:26 | |
openstackgerrit | Merged openstack/keystone master: Move endpoint policies to DocumentedRuleDefault https://review.openstack.org/449212 | 04:29 |
*** guoshan has joined #openstack-keystone | 04:33 | |
*** aojea has joined #openstack-keystone | 04:35 | |
*** dobson has quit IRC | 04:36 | |
*** adrian_otto has quit IRC | 04:37 | |
*** aojea has quit IRC | 04:39 | |
*** dobson has joined #openstack-keystone | 04:40 | |
*** ianw has quit IRC | 04:43 | |
*** ianw has joined #openstack-keystone | 04:43 | |
*** prashkre has joined #openstack-keystone | 04:52 | |
*** guoshan has quit IRC | 05:00 | |
*** guoshan has joined #openstack-keystone | 05:00 | |
*** oomichi has quit IRC | 05:09 | |
*** oomichi has joined #openstack-keystone | 05:12 | |
*** akrzos has quit IRC | 05:14 | |
*** dmellado has quit IRC | 05:14 | |
*** chlong has quit IRC | 05:14 | |
*** dmellado has joined #openstack-keystone | 05:16 | |
*** oomichi has quit IRC | 05:18 | |
*** akrzos has joined #openstack-keystone | 05:22 | |
*** oomichi has joined #openstack-keystone | 05:23 | |
*** Adobeman has quit IRC | 05:32 | |
*** Adobeman has joined #openstack-keystone | 05:33 | |
openstackgerrit | Merged openstack/keystone master: Move domain policies to DocumentedRuleDefault https://review.openstack.org/449234 | 05:35 |
openstackgerrit | Merged openstack/keystone master: Updated from global requirements https://review.openstack.org/451014 | 05:38 |
openstackgerrit | Merged openstack/keystone master: Doc db_sync --expand incurring downtime in upgrades to Newton https://review.openstack.org/450863 | 05:40 |
openstackgerrit | Merged openstack/keystone master: Remove unused revoke_by_project_role_assignment https://review.openstack.org/448613 | 05:40 |
openstackgerrit | Merged openstack/keystone master: Remove unused revoke_by_domain_role_assignment https://review.openstack.org/448615 | 05:42 |
*** richm has quit IRC | 05:43 | |
*** rcernin has joined #openstack-keystone | 05:45 | |
openstackgerrit | Merged openstack/keystone master: Fix some reST field lists in docstrings https://review.openstack.org/449892 | 05:50 |
openstackgerrit | Merged openstack/keystone master: Add group_members_are_ids to whitelisted options https://review.openstack.org/442048 | 05:50 |
openstackgerrit | Merged openstack/keystone master: Removed domain conflict guard in load_fixtures https://review.openstack.org/450991 | 05:50 |
openstackgerrit | Merged openstack/keystone master: Replace wip with skip https://review.openstack.org/450992 | 05:50 |
openstackgerrit | Richard Avelar proposed openstack/keystone master: Remove policy file from source and refactor tests https://review.openstack.org/449675 | 05:51 |
*** thorst has joined #openstack-keystone | 05:52 | |
*** thorst has quit IRC | 05:57 | |
*** zhurong has joined #openstack-keystone | 06:15 | |
openstackgerrit | Merged openstack/keystone master: Remove revocation API dependency from resource API https://review.openstack.org/447564 | 06:26 |
openstackgerrit | XieYingYun proposed openstack/keystone master: Remove unnecessary setUp function in testcase https://review.openstack.org/451666 | 06:33 |
*** zhurong has quit IRC | 06:38 | |
*** haplo37- has quit IRC | 06:45 | |
*** pcaruana has joined #openstack-keystone | 06:47 | |
*** thorst has joined #openstack-keystone | 06:53 | |
*** haplo37_ has joined #openstack-keystone | 06:53 | |
*** thorst has quit IRC | 06:57 | |
*** d0ugal has joined #openstack-keystone | 06:58 | |
*** d0ugal has joined #openstack-keystone | 06:58 | |
*** Dinesh_Bhor has quit IRC | 07:07 | |
*** Dinesh_Bhor has joined #openstack-keystone | 07:07 | |
*** dineshbhor has joined #openstack-keystone | 07:09 | |
*** dineshbhor has quit IRC | 07:09 | |
*** tesseract has joined #openstack-keystone | 07:16 | |
*** kukacz has quit IRC | 07:17 | |
*** aojea has joined #openstack-keystone | 07:18 | |
*** kukacz has joined #openstack-keystone | 07:18 | |
*** pnavarro has joined #openstack-keystone | 07:19 | |
*** Dinesh_Bhor has quit IRC | 07:24 | |
*** Dinesh_Bhor has joined #openstack-keystone | 07:25 | |
*** Dinesh_Bhor has quit IRC | 07:30 | |
*** Dinesh_Bhor has joined #openstack-keystone | 07:32 | |
*** zhurong has joined #openstack-keystone | 07:37 | |
*** zhangqiankun has joined #openstack-keystone | 07:39 | |
*** Dinesh_Bhor has quit IRC | 07:40 | |
*** Dinesh_Bhor has joined #openstack-keystone | 07:43 | |
*** aojea has quit IRC | 07:49 | |
*** knangia has quit IRC | 07:51 | |
*** thorst has joined #openstack-keystone | 07:54 | |
*** pnavarro has quit IRC | 07:56 | |
*** zzzeek has quit IRC | 08:00 | |
*** wuyanjun has joined #openstack-keystone | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:02 | |
*** openstackgerrit has quit IRC | 08:03 | |
*** aojea has joined #openstack-keystone | 08:12 | |
*** thorst has quit IRC | 08:12 | |
*** openstackgerrit has joined #openstack-keystone | 08:22 | |
openstackgerrit | Merged openstack/keystone master: Remove revocation API dependency from identity API https://review.openstack.org/447573 | 08:22 |
*** haplo37_ has quit IRC | 08:28 | |
*** haplo37_ has joined #openstack-keystone | 08:31 | |
*** yulijie has joined #openstack-keystone | 08:35 | |
*** pnavarro has joined #openstack-keystone | 08:39 | |
*** zhangqiankun has quit IRC | 08:45 | |
*** zhangqiankun has joined #openstack-keystone | 08:46 | |
*** prashkre has quit IRC | 08:59 | |
*** zhurong has quit IRC | 09:01 | |
*** zhangqiankun has quit IRC | 09:01 | |
*** pradeep has joined #openstack-keystone | 09:02 | |
*** thorst has joined #openstack-keystone | 09:09 | |
*** prashkre has joined #openstack-keystone | 09:10 | |
*** thorst has quit IRC | 09:13 | |
*** zhangqiankun has joined #openstack-keystone | 09:28 | |
*** zhangqiankun has quit IRC | 09:29 | |
*** Dinesh_Bhor has quit IRC | 09:49 | |
*** bjornar_ has joined #openstack-keystone | 09:50 | |
*** thorst has joined #openstack-keystone | 10:10 | |
*** liujiong has quit IRC | 10:10 | |
*** Dinesh_Bhor has joined #openstack-keystone | 10:12 | |
*** richm has joined #openstack-keystone | 10:14 | |
*** thorst has quit IRC | 10:14 | |
*** mvk has quit IRC | 10:19 | |
*** edmondsw has joined #openstack-keystone | 10:21 | |
*** edmondsw has quit IRC | 10:26 | |
*** guoshan has quit IRC | 10:33 | |
*** raildo has joined #openstack-keystone | 10:42 | |
*** pradeep has quit IRC | 11:00 | |
*** thorst has joined #openstack-keystone | 11:11 | |
*** zhangqiankun has joined #openstack-keystone | 11:14 | |
*** thorst has quit IRC | 11:15 | |
*** zhangqiankun has quit IRC | 11:18 | |
*** ayoung has quit IRC | 11:25 | |
*** thorst has joined #openstack-keystone | 11:34 | |
*** mvk has joined #openstack-keystone | 11:59 | |
*** henrynash has quit IRC | 12:00 | |
*** dikonoo has joined #openstack-keystone | 12:05 | |
*** guoshan has joined #openstack-keystone | 12:06 | |
breton | so, i've just tested auto-provisioning on a larger audience | 12:09 |
breton | it worked pretty well! | 12:09 |
breton | there some issues, not with keystone though | 12:10 |
*** dave-mccowan has joined #openstack-keystone | 12:17 | |
*** voelzmo has joined #openstack-keystone | 12:18 | |
*** catintheroof has joined #openstack-keystone | 12:21 | |
*** edmondsw has joined #openstack-keystone | 12:22 | |
*** henrynash has joined #openstack-keystone | 12:28 | |
*** ayoung has joined #openstack-keystone | 12:34 | |
*** links has quit IRC | 12:54 | |
*** ayoung has quit IRC | 12:58 | |
*** knangia has joined #openstack-keystone | 13:00 | |
*** agrebennikov has joined #openstack-keystone | 13:04 | |
*** spilla has joined #openstack-keystone | 13:05 | |
*** lamt has joined #openstack-keystone | 13:06 | |
*** ma9_ has joined #openstack-keystone | 13:07 | |
ma9_ | Hi, does somebody know how to configure Keystone with PAM authentication as backend? | 13:07 |
ma9_ | I guess I need to put some driver to /opt/stack/keystone/keystone/identity/backends/ | 13:09 |
ma9_ | and configure [identity] | 13:09 |
ma9_ | driver = mypambackend | 13:09 |
ma9_ | ? | 13:10 |
breton | ma9_: yes, that's right | 13:11 |
ma9_ | I found this example https://admiyo.fedorapeople.org/openstack/keystone/coverage/keystone_identity_backends_pam.html | 13:12 |
ma9_ | is there anything more 'official' | 13:12 |
ma9_ | I could use? | 13:12 |
*** ayoung has joined #openstack-keystone | 13:12 | |
ma9_ | maybe this guide is better. https://thestaticvoid.com/post/2013/06/04/customizing-the-openstack-keystone-authentication-backend/ | 13:13 |
dstanek | breton: nice | 13:14 |
dstanek | ma9_: we removed our pam backend a long time ago | 13:15 |
dstanek | ma9_: http://git.openstack.org/cgit/openstack/keystone/commit/?id=6bd2307 | 13:17 |
*** lamt has quit IRC | 13:21 | |
ma9_ | damn :D | 13:24 |
ma9_ | thanks for the info! | 13:24 |
ma9_ | this is a bit odd though, that something like that has to be removed | 13:24 |
lbragstad | no one has seen the webob issues again yet, have they? | 13:28 |
lbragstad | cc dstanek? | 13:28 |
dstanek | lbragstad: i haven't yet | 13:28 |
dstanek | i haven't looked for any gate errors though | 13:29 |
*** henrynash has quit IRC | 13:31 | |
*** chlong has joined #openstack-keystone | 13:34 | |
*** jlvillal is now known as jlvillal_pto | 13:35 | |
*** guoshan has quit IRC | 13:36 | |
*** jaosorior is now known as jaosorior_away | 13:37 | |
*** ravelar has joined #openstack-keystone | 13:38 | |
*** lucasxu has joined #openstack-keystone | 13:43 | |
*** guoshan has joined #openstack-keystone | 13:48 | |
openstackgerrit | Richard Avelar proposed openstack/keystone master: Address comments from Policy in Code 5 https://review.openstack.org/448826 | 13:59 |
*** henrynash has joined #openstack-keystone | 13:59 | |
openstackgerrit | Richard Avelar proposed openstack/keystone master: Address comments from Policy in Code 5 https://review.openstack.org/448826 | 14:05 |
openstackgerrit | Richard Avelar proposed openstack/keystone master: Address comments from Policy in Code 5 https://review.openstack.org/448826 | 14:05 |
openstackgerrit | Richard Avelar proposed openstack/keystone master: Remove unused revocation check in revoke_models https://review.openstack.org/451452 | 14:07 |
*** aojea_ has joined #openstack-keystone | 14:13 | |
*** szaher has quit IRC | 14:14 | |
*** szaher has joined #openstack-keystone | 14:14 | |
*** aojea has quit IRC | 14:16 | |
*** prashkre has quit IRC | 14:17 | |
*** lamt has joined #openstack-keystone | 14:19 | |
*** browne has joined #openstack-keystone | 14:21 | |
*** yulijie has quit IRC | 14:26 | |
*** yulijie has joined #openstack-keystone | 14:27 | |
*** rderose has joined #openstack-keystone | 14:30 | |
antwash | lbragstad : so far so good, no webob issues | 14:41 |
*** aojea_ has quit IRC | 14:41 | |
*** dikonoo has quit IRC | 14:43 | |
*** dikonoor has quit IRC | 14:44 | |
*** henrynash has quit IRC | 14:45 | |
lbragstad | antwash good deal - i saw a few issues remaining and issued some rechecks | 14:47 |
lbragstad | antwash i did notice there were other failures on some of those patches, too | 14:47 |
dstanek | lbragstad: any thoughts on my the tests didn't catch the issue? | 14:48 |
lbragstad | (one being related to a pbr version and the others related to a failing nova tempest test) | 14:48 |
lbragstad | dstanek all the ones i saw that had issues with webob were py35 specific | 14:48 |
lbragstad | py27 seemed fine | 14:48 |
antwash | lbragstad: yeah I did as well, I'm going to look into the other issues as well | 14:48 |
lbragstad | from what i could tell - it looks like it was specific to WebOb > 1.7 and python 3.5 | 14:49 |
antwash | hopefully everything will be good to go, we have two merged so fa ^_^ | 14:49 |
antwash | s/fa/far | 14:49 |
lbragstad | antwash the trace from the nova tempest issue was reference "no host available" so it could have been a transient or a different/unrelated gate issue | 14:49 |
antwash | lbragstad: did you happen to find out about that 'ec2 authenticate' policy? | 14:50 |
lbragstad | antwash not yet - i saw your question, but i didn't get a chance to dig into it | 14:52 |
lbragstad | yet | 14:52 |
lbragstad | antwash what was it again? | 14:52 |
openstackgerrit | Anthony Washington proposed openstack/keystone master: Move role assignment to DocumentedRuleDefault https://review.openstack.org/449253 | 14:52 |
antwash | lbragstad: what's the rule for the ec2 authenticate policy, I | 14:53 |
antwash | I didn't see it in the old policy.json | 14:53 |
antwash | or in code | 14:53 |
lbragstad | antwash ah | 14:53 |
lbragstad | I would think that it would be unauthenticated | 14:54 |
lbragstad | since it's an authenticate call, | 14:54 |
lbragstad | which would be similar to how we treat authentication | 14:54 |
lbragstad | we don't protect the authentication endpoint | 14:54 |
lbragstad | (because it's the authentication endpoint, and it causes a circle dependency) | 14:54 |
antwash | lbragstad : also it's mentioned that theses policies deprecated https://review.openstack.org/#/c/449248/, but according to this they are not. https://developer.openstack.org/api-ref/identity/v3/?expanded=create-policy-detail | 14:56 |
antwash | maybe the doc needs to be updated? | 14:56 |
*** rcernin has quit IRC | 15:00 | |
lbragstad | antwash samueldmq updated | 15:01 |
lbragstad | https://review.openstack.org/#/c/449248/2 | 15:01 |
openstackgerrit | Anthony Washington proposed openstack/keystone master: Move project endpoint to DocumentedRuleDefault https://review.openstack.org/449276 | 15:02 |
*** guoshan has quit IRC | 15:04 | |
*** henrynash has joined #openstack-keystone | 15:06 | |
openstackgerrit | Anthony Washington proposed openstack/keystone master: Move policy policies to DocumentedRuleDefault https://review.openstack.org/449248 | 15:07 |
*** adrian_otto has joined #openstack-keystone | 15:11 | |
SamYaple | im having trouble running apache2 in front of uwsgi. im using the example configs in keystone/httpd directory. it is acting as if I need ot enable mod_proxy or mod_http_proxy and I cannot figure it out. http://paste.openstack.org/show/604872/ | 15:15 |
*** adrian_otto has quit IRC | 15:15 | |
SamYaple | any ideas? | 15:15 |
*** bjornar_ has quit IRC | 15:16 | |
*** henrynash has quit IRC | 15:24 | |
ayoung | SamYaple, what is the error? | 15:25 |
SamYaple | ayoung: in that pastebin | 15:26 |
SamYaple | AH01144: No protocol handler was valid for the URL / | 15:26 |
SamYaple | it seems like im not enabling uwsgi proxy.... but i am | 15:26 |
SamYaple | so im just confused | 15:26 |
ayoung | SamYaple, what do your configs look like? | 15:26 |
ayoung | SamYaple, or it is not matching the URL | 15:27 |
ayoung | or the port is not in the listens list etc | 15:27 |
SamYaple | straight copy from keystone/httpd | 15:27 |
ayoung | 127.0.0.1 vs 0.0.0.0 | 15:27 |
ayoung | note the protocol is uwsgi in the [Thu Mar 30 07:27:45.634203 2017] [proxy_http:debug] [pid 18:tid 140369991821056] mod_proxy_http.c(1942): [client 10.10.0.1:50156] AH01113: HTTP: declining URL uwsgi://127.0.0.1:35358/ | 15:27 |
SamYaple | ahhh nvm im dumb. i was enabling uwsgi, not proxy_uwsgi | 15:28 |
SamYaple | which are two different things | 15:28 |
SamYaple | seems ot be working now | 15:28 |
ayoung | Ach! | 15:28 |
ayoung | Cool. SamYaple you coming to Boston? | 15:28 |
SamYaple | i am | 15:30 |
ayoung | Cool...see you there! | 15:30 |
SamYaple | awesome! | 15:31 |
*** adrian_otto has joined #openstack-keystone | 15:35 | |
*** aloga_ is now known as aloga | 15:38 | |
*** voelzmo has quit IRC | 15:39 | |
*** voelzmo has joined #openstack-keystone | 15:40 | |
openstackgerrit | Richard Avelar proposed openstack/keystone master: Refactor test_revoke to call check_token directly https://review.openstack.org/451874 | 15:43 |
*** voelzmo has quit IRC | 15:44 | |
openstackgerrit | Merged openstack/keystone master: Add policy sample generation https://review.openstack.org/443344 | 15:44 |
*** jlopezgu_ has joined #openstack-keystone | 15:48 | |
* notmorgan lurks harder | 15:58 | |
SamYaple | so im wondering about why we do the 127.0.0.1 bind of uwsgi. if you use nginx as a LB upstream, couldn't you bind uwsgi to a private address and then LB directly to uwsgi? or are there security implications with that? | 16:16 |
*** jaosorior_away is now known as jaosorior | 16:19 | |
knikolla | o/ | 16:20 |
*** pcaruana has quit IRC | 16:23 | |
gagehugo | knikolla: o/ | 16:31 |
*** prashkre has joined #openstack-keystone | 16:35 | |
*** tesseract has quit IRC | 16:40 | |
lbragstad | o/ | 16:42 |
*** jaosorior has quit IRC | 16:50 | |
*** lucasxu has quit IRC | 16:53 | |
*** lucasxu has joined #openstack-keystone | 16:56 | |
*** swatson has quit IRC | 16:59 | |
-openstackstatus- NOTICE: The Gerrit service on review.openstack.org is being restarted briefly to relieve performance issues, and should return to service again momentarily. | 17:03 | |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: URL pattern based RBAC Management Interface https://review.openstack.org/401808 | 17:04 |
*** MasterOfBugs has joined #openstack-keystone | 17:10 | |
*** bjornar_ has joined #openstack-keystone | 17:12 | |
openstackgerrit | Richard Avelar proposed openstack/keystone master: Address comments from Policy in Code 5 https://review.openstack.org/448826 | 17:16 |
openstackgerrit | Richard Avelar proposed openstack/keystone master: Address comments from Policy in Code 5 https://review.openstack.org/448826 | 17:17 |
openstackgerrit | Richard Avelar proposed openstack/keystone master: Address comments from Policy in Code 5 https://review.openstack.org/448826 | 17:17 |
*** david-lyle__ is now known as david-lyle | 17:30 | |
dstanek | SamYaple: you can bind to whatever address you want | 17:32 |
dstanek | SamYaple: i typically like to have an actual webserver in front of the python app though | 17:33 |
dstanek | protection from slow clients and some other things that are useful | 17:33 |
dstanek | it's also necessary with federation | 17:33 |
SamYaple | jut to clarify, all the nginx+uwsgi stuff i see, no federation support correct? | 17:34 |
dstanek | SamYaple: what are you looking at? | 17:35 |
*** chlong has quit IRC | 17:36 | |
SamYaple | dstanek: jsut random interweb things. basically i dont know uwsgi and was wondering if binding to 127.0.0.1 and putting apache2/nginx in front of it was done for security | 17:36 |
openstackgerrit | Sean Dague proposed openstack/keystone-specs master: Unified limits specification https://review.openstack.org/440815 | 17:42 |
openstackgerrit | Kristi Nikolla proposed openstack/keystone master: Remove LDAP delete logic and associated tests https://review.openstack.org/424344 | 17:43 |
dstanek | SamYaple: i don't think security. i like to do it for other reasons. for example, nginx is pretty good about protecting you from slow clients | 17:43 |
SamYaple | yea i get that part. i was trying to avoid nginx on LB -> nginx on host -> uwsgi on host | 17:46 |
SamYaple | which it sounds like i can | 17:46 |
dstanek | SamYaple: why would you have nginx on the LB? | 17:47 |
dstanek | SamYaple: also where do you do you SSL termination? | 17:47 |
*** prashkre has quit IRC | 17:49 | |
SamYaple | dstanek: nginx is a load balancer that can do ssl termination (much like haproxy) | 17:50 |
openstackgerrit | Merged openstack/keystone master: Remove policy file from source and refactor tests https://review.openstack.org/449675 | 17:51 |
ayoung | lbragstad, dstanek, please have a look at the server side of the RBAC code. https://review.openstack.org/#/c/401808 | 17:51 |
ayoung | rodrigods, ^^ you, too, please | 17:51 |
ayoung | it should be a pretty straight forward REST API. Does not do enforcement. | 17:52 |
openstackgerrit | Anthony Washington proposed openstack/keystone master: Move mapping to DocumentedRuleDefault https://review.openstack.org/449341 | 17:52 |
openstackgerrit | Anthony Washington proposed openstack/keystone master: Move policy policies to DocumentedRuleDefault https://review.openstack.org/449248 | 17:53 |
openstackgerrit | Richard Avelar proposed openstack/keystone master: Consolidate duplicate test and code in test_revoke https://review.openstack.org/451926 | 17:53 |
*** nikhil_ has joined #openstack-keystone | 17:55 | |
*** nikhil_ is now known as Guest23722 | 17:55 | |
openstackgerrit | ayoung proposed openstack/keystone master: URL pattern based RBAC Management Interface https://review.openstack.org/401808 | 17:56 |
openstackgerrit | Anthony Washington proposed openstack/keystone master: Move protocol to DocumentedRuleDefault https://review.openstack.org/449345 | 17:56 |
*** SamYaple_ has joined #openstack-keystone | 17:57 | |
*** prashkre has joined #openstack-keystone | 17:58 | |
*** rm_work has quit IRC | 17:59 | |
*** nikhil has quit IRC | 17:59 | |
*** Krenair has quit IRC | 17:59 | |
*** mordred has quit IRC | 17:59 | |
*** SamYaple has quit IRC | 17:59 | |
*** BlackDex has quit IRC | 17:59 | |
*** rm_work has joined #openstack-keystone | 18:00 | |
*** Guest23722 is now known as nikhil | 18:01 | |
*** mordred has joined #openstack-keystone | 18:01 | |
*** chlong has joined #openstack-keystone | 18:02 | |
*** SamYaple_ has quit IRC | 18:03 | |
*** SamYaple has joined #openstack-keystone | 18:03 | |
*** ravelar has quit IRC | 18:03 | |
*** ayoung has quit IRC | 18:03 | |
*** davechen has quit IRC | 18:04 | |
*** Krenair has joined #openstack-keystone | 18:04 | |
*** voelzmo has joined #openstack-keystone | 18:06 | |
*** ravelar has joined #openstack-keystone | 18:08 | |
samueldmq | hi keystoners | 18:10 |
samueldmq | antwash: done! all reviewed | 18:10 |
samueldmq | :) | 18:10 |
antwash | samueldmq : thanks sam!! | 18:10 |
*** mvk has quit IRC | 18:10 | |
samueldmq | antwash: glad to help! | 18:11 |
*** chlong has quit IRC | 18:11 | |
*** voelzmo has quit IRC | 18:13 | |
dstanek | samueldmq: ah, i see. i think you would be ok then to not run it on the keystone nodes. i usurally terminate SSL at the node itself so even local traffic is protected | 18:13 |
samueldmq | dstanek: what did I do ? | 18:14 |
samueldmq | SamYaple: ^ | 18:14 |
samueldmq | :-) | 18:14 |
dstanek | samueldmq: sorry not you | 18:15 |
dstanek | SamYaple: ^ that was for you | 18:15 |
SamYaple | dstanek: right, im just making sure i understand the flow here. what can be done, what can't. whats safe. that kind of thing | 18:17 |
SamYaple | thanks for the help | 18:17 |
*** davechen has joined #openstack-keystone | 18:18 | |
*** henrynash has joined #openstack-keystone | 18:20 | |
*** henrynash has quit IRC | 18:23 | |
*** d0ugal has quit IRC | 18:24 | |
openstackgerrit | Tin Lam proposed openstack/keystonemiddleware master: Replace pycrypto with cryptography https://review.openstack.org/451941 | 18:24 |
lbragstad | lamt yes! | 18:25 |
lamt | @lbragstad : \o/ I will add a release note to that patch set later. | 18:26 |
lbragstad | i'm excited to test that out | 18:26 |
lbragstad | lamt thanks for jumping on that one so quick | 18:27 |
*** ravelar1 has joined #openstack-keystone | 18:27 | |
lamt | np | 18:27 |
*** adrian_otto has quit IRC | 18:28 | |
*** mvk has joined #openstack-keystone | 18:43 | |
*** ravelar1 has quit IRC | 18:59 | |
*** aojea has joined #openstack-keystone | 18:59 | |
*** zhangqiankun has joined #openstack-keystone | 19:00 | |
*** chlong has joined #openstack-keystone | 19:00 | |
openstackgerrit | Merged openstack/keystone master: Move project policies to DocumentedRuleDefault https://review.openstack.org/449238 | 19:05 |
*** chlong has quit IRC | 19:07 | |
mfisch | lbragstad: I have a question for you. Have a weird thing where a service is getting tokens ,which are valid and then after 3-4 mins a token validation returns "404 not found" | 19:12 |
mfisch | does that sound familiar at all? fernet of course | 19:12 |
mfisch | they're not in the revocation table | 19:12 |
*** aloga has quit IRC | 19:14 | |
*** MasterOfBugs has quit IRC | 19:15 | |
openstackgerrit | Merged openstack/keystone master: Move service provider to DocumentedRuleDefault https://review.openstack.org/449347 | 19:15 |
*** zhangqiankun has quit IRC | 19:18 | |
breton | so... | 19:18 |
breton | where do i report security bugs? | 19:18 |
breton | ok, https://security.openstack.org/ | 19:19 |
dstanek | breton: did you get it figured out? | 19:23 |
dstanek | mfisch: that's really strange | 19:23 |
breton | dstanek: yes | 19:24 |
mfisch | something is revoking them looks like its saying "Revoke all this users tokens" there's no project or domain scope in the revoke table | 19:24 |
*** aloga has joined #openstack-keystone | 19:25 | |
*** MasterOfBugs has joined #openstack-keystone | 19:29 | |
dstanek | mfisch: and you're not seeing anything in the logs? | 19:31 |
mfisch | looking | 19:31 |
dstanek | mfisch: do you have an idea what the user is doing with the token? | 19:31 |
mfisch | lots of logs | 19:31 |
mfisch | these are service users | 19:31 |
mfisch | so designate, heat, and 2 otehrs | 19:32 |
mfisch | its causing API failures | 19:32 |
mfisch | every 5 or so mins like clockwork, 4 new revokes show up | 19:32 |
dstanek | mfisch: and the fernet keys are not being rotated or anything? | 19:32 |
mfisch | the revoke table only has a user_id the rest is null (except times) | 19:32 |
mfisch | nope, no rotations | 19:32 |
dstanek | mfisch: the 5 mintues sounds like some kind of automated job or maybe token timeout | 19:33 |
mfisch | token timeout is 2 hours but yeah it is suspicious | 19:33 |
mfisch | found it, well a colleague did | 19:33 |
mfisch | PATCH call to a user | 19:34 |
mfisch | FOUND IT | 19:34 |
mfisch | damn you puppet | 19:35 |
dstanek | mfisch: lol | 19:35 |
dstanek | a cron? | 19:35 |
mfisch | puppet is being dumb, unsure why | 19:36 |
mfisch | Mar 30 19:30:27 dnvrco01-keystone-001 puppet-agent[15163]: (/Stage[main]/Designate::Keystone::Auth/Keystone::Resource::Service_identity[designate]/Keystone_user[designate]/password) changed password | 19:36 |
mfisch | 6 nodes, run every 30 minutes = about 5 min per break | 19:36 |
mfisch | in other news I have 7 days left at this job, next time it's gonna cost them | 19:37 |
mfisch | today I had to cancel golf | 19:38 |
*** mvk has quit IRC | 19:42 | |
*** ma9_1 has joined #openstack-keystone | 19:42 | |
*** ma9_ has quit IRC | 19:45 | |
lbragstad | mfisch nice - glad you figured it out | 19:53 |
* lbragstad stumbles around to find coffee before the keystone/horizon meeting | 19:53 | |
robcresswell | \o/ | 19:54 |
*** mvk has joined #openstack-keystone | 19:55 | |
robcresswell | ayoung, cmurphy, david-lyle, dolphm, dstanek, edtubill, kenji-i, knikolla, lbragstad, r1chardj0n3s, rderose, robcresswell, stevemar | 19:57 |
robcresswell | Reminder about keystone meeting in #openstack-meeting-cp | 19:58 |
robcresswell | (Just pinging because your names are registered on https://etherpad.openstack.org/p/keystone-horizon) | 19:58 |
*** pnavarro has quit IRC | 20:13 | |
*** adrian_otto has joined #openstack-keystone | 20:24 | |
openstackgerrit | Sean Dague proposed openstack/keystone-specs master: Unified limits specification https://review.openstack.org/440815 | 20:32 |
*** chlong has joined #openstack-keystone | 20:36 | |
*** prashkre has quit IRC | 20:44 | |
*** catintheroof has quit IRC | 21:03 | |
*** spilla has quit IRC | 21:06 | |
*** chlong has quit IRC | 21:09 | |
*** henrynash has joined #openstack-keystone | 21:19 | |
*** edmondsw has quit IRC | 21:30 | |
*** rarora has quit IRC | 21:30 | |
*** edmondsw has joined #openstack-keystone | 21:31 | |
*** dave-mccowan has quit IRC | 21:32 | |
*** edmondsw has quit IRC | 21:35 | |
*** marekd has quit IRC | 21:38 | |
*** adrian_otto has quit IRC | 21:45 | |
*** marekd has joined #openstack-keystone | 21:45 | |
*** sjain has joined #openstack-keystone | 21:50 | |
*** bjornar_ has quit IRC | 21:50 | |
*** lucasxu has quit IRC | 21:54 | |
*** aojea has quit IRC | 21:55 | |
*** rarora has joined #openstack-keystone | 21:55 | |
*** harlowja has quit IRC | 22:02 | |
*** thorst has quit IRC | 22:03 | |
*** lamt has quit IRC | 22:35 | |
*** sjain has quit IRC | 22:41 | |
*** henrynash has quit IRC | 22:43 | |
*** guoshan has joined #openstack-keystone | 22:47 | |
*** thorst has joined #openstack-keystone | 23:04 | |
*** thorst has quit IRC | 23:08 | |
*** thorst has joined #openstack-keystone | 23:14 | |
*** thorst has quit IRC | 23:17 | |
*** guoshan has quit IRC | 23:19 | |
*** guoshan has joined #openstack-keystone | 23:20 | |
*** adrian_otto has joined #openstack-keystone | 23:23 | |
*** harlowja has joined #openstack-keystone | 23:24 | |
*** guoshan has quit IRC | 23:24 | |
*** MasterOfBugs has quit IRC | 23:30 | |
*** edmondsw has joined #openstack-keystone | 23:31 | |
*** edmondsw has quit IRC | 23:35 | |
*** MasterOfBugs has joined #openstack-keystone | 23:35 | |
*** openstack has joined #openstack-keystone | 23:42 | |
*** thorst has joined #openstack-keystone | 23:47 | |
*** niteshnarayanlal has joined #openstack-keystone | 23:56 | |
*** thorst has quit IRC | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!