*** dave-mccowan has joined #openstack-keystone | 00:03 | |
*** markvoelker has quit IRC | 00:04 | |
*** thorst has joined #openstack-keystone | 00:14 | |
*** raildo has quit IRC | 00:14 | |
*** thorst has quit IRC | 00:15 | |
*** thorst has joined #openstack-keystone | 00:17 | |
*** masber has joined #openstack-keystone | 00:17 | |
*** thorst has quit IRC | 00:19 | |
*** masber has quit IRC | 00:26 | |
*** masber has joined #openstack-keystone | 00:26 | |
*** markvoelker has joined #openstack-keystone | 00:47 | |
*** frontrunner has joined #openstack-keystone | 00:49 | |
*** dikonoor has joined #openstack-keystone | 01:01 | |
*** Shunli has joined #openstack-keystone | 01:04 | |
*** markvoelker_ has joined #openstack-keystone | 01:16 | |
*** markvoelker has quit IRC | 01:17 | |
*** lucasxu has joined #openstack-keystone | 01:17 | |
*** lucasxu has quit IRC | 01:17 | |
*** thorst has joined #openstack-keystone | 01:19 | |
*** jose-phillips has quit IRC | 01:20 | |
*** lucasxu has joined #openstack-keystone | 01:20 | |
*** markvoelker_ has quit IRC | 01:21 | |
*** jose-phillips has joined #openstack-keystone | 01:22 | |
*** lucasxu has quit IRC | 01:22 | |
*** lucasxu has joined #openstack-keystone | 01:23 | |
*** markvoelker has joined #openstack-keystone | 01:23 | |
*** __Nautilus__ has joined #openstack-keystone | 01:23 | |
*** dikonoor has quit IRC | 01:24 | |
*** thorst has quit IRC | 01:24 | |
*** arahal_ has quit IRC | 01:32 | |
*** aselius has quit IRC | 01:45 | |
*** lucasxu has quit IRC | 02:01 | |
*** namnh has joined #openstack-keystone | 02:04 | |
*** lucasxu has joined #openstack-keystone | 02:11 | |
*** lucasxu has quit IRC | 02:13 | |
*** thorst has joined #openstack-keystone | 02:13 | |
*** thorst has quit IRC | 02:13 | |
*** lucasxu has joined #openstack-keystone | 02:14 | |
*** __Nautilus__ has quit IRC | 02:15 | |
*** __Nautilus__ has joined #openstack-keystone | 02:15 | |
*** dave-mccowan has quit IRC | 02:15 | |
*** __Nautilus__ has quit IRC | 02:19 | |
*** jrist has quit IRC | 02:20 | |
*** yunus has quit IRC | 02:29 | |
*** jrist has joined #openstack-keystone | 02:34 | |
*** thorst has joined #openstack-keystone | 02:37 | |
*** thorst has quit IRC | 02:38 | |
*** __Nautilus__ has joined #openstack-keystone | 02:39 | |
*** lucasxu has quit IRC | 02:40 | |
*** shuyingya has joined #openstack-keystone | 02:41 | |
*** zsli_ has joined #openstack-keystone | 02:44 | |
*** lucasxu has joined #openstack-keystone | 02:45 | |
*** Shunli has quit IRC | 02:46 | |
*** lucasxu has quit IRC | 02:47 | |
*** shuyingy_ has joined #openstack-keystone | 02:48 | |
*** shuyingya has quit IRC | 02:48 | |
*** nicolasbock has quit IRC | 02:49 | |
*** __Nautilus__ has quit IRC | 02:50 | |
*** __Nautil_ has joined #openstack-keystone | 02:53 | |
*** lucasxu has joined #openstack-keystone | 02:56 | |
*** lucasxu has quit IRC | 03:04 | |
*** __Nautil_ has quit IRC | 03:05 | |
*** __Nautilus__ has joined #openstack-keystone | 03:06 | |
*** zsli_ has quit IRC | 03:08 | |
*** Shunli has joined #openstack-keystone | 03:08 | |
*** __Nautil_ has joined #openstack-keystone | 03:09 | |
*** thorst has joined #openstack-keystone | 03:09 | |
*** __Nautil_ has quit IRC | 03:09 | |
*** __Nautilus__ has quit IRC | 03:09 | |
*** nicolasbock has joined #openstack-keystone | 03:20 | |
*** liujiong has joined #openstack-keystone | 03:21 | |
*** thorst has quit IRC | 03:26 | |
*** frontrunner has quit IRC | 03:26 | |
openstackgerrit | yangweiwei proposed openstack/keystone master: Expose a bug in getting federation projects https://review.openstack.org/469318 | 03:27 |
---|---|---|
openstackgerrit | yangweiwei proposed openstack/keystone master: Expose a bug in getting federation projects https://review.openstack.org/469318 | 03:31 |
*** nicolasbock has quit IRC | 03:33 | |
*** david-lyle has joined #openstack-keystone | 03:35 | |
*** prashkre has joined #openstack-keystone | 03:36 | |
*** links has joined #openstack-keystone | 03:45 | |
*** lucasxu has joined #openstack-keystone | 03:45 | |
*** prashkre has quit IRC | 04:01 | |
*** wasmum has quit IRC | 04:05 | |
*** jaosorior has quit IRC | 04:10 | |
*** lucasxu has quit IRC | 04:11 | |
*** jaosorior has joined #openstack-keystone | 04:12 | |
*** zhurong has joined #openstack-keystone | 04:16 | |
*** aojea has joined #openstack-keystone | 04:18 | |
*** dikonoor has joined #openstack-keystone | 04:18 | |
*** zhurong has quit IRC | 04:19 | |
*** piliman974 has quit IRC | 04:20 | |
*** aojea has quit IRC | 04:22 | |
*** dikonoor has quit IRC | 04:37 | |
*** dikonoor has joined #openstack-keystone | 04:55 | |
*** dikonoor has quit IRC | 05:01 | |
*** hawk_ has joined #openstack-keystone | 05:09 | |
hawk_ | Dear All, I am trying to configure my keystone service in order to integrate with LDAP. But after I add driver = keystone.identity.backends.ldap.Identity into keystone.conf, openstack user list command gives an error like below, "Discovering versions from the identity service failed when creating the password plugin. Attempting to determine version from URL. Internal Server Error (HTTP 500) error." Do you have any opinion ab | 05:09 |
*** thorst has joined #openstack-keystone | 05:23 | |
*** thorst has quit IRC | 05:28 | |
*** gyee has quit IRC | 05:34 | |
openstackgerrit | zhengliuyang proposed openstack/keystone master: Remove hash_algorithms from performance.rst https://review.openstack.org/469333 | 05:47 |
*** tobberydberg has joined #openstack-keystone | 05:52 | |
*** prashkre has joined #openstack-keystone | 06:04 | |
*** jaosorior has quit IRC | 06:08 | |
*** mvk has quit IRC | 06:09 | |
*** rcernin has joined #openstack-keystone | 06:10 | |
pooja_jadhav | lbragstad: Hi, I went through the discussion which held previously. So team has decided to write API microversion for this change. am I right? that List resources with invalid filters should return 400. | 06:10 |
openstackgerrit | Van Hung Pham proposed openstack/keystone master: Replace assertRaisesRegexp with assertRaisesRegex https://review.openstack.org/469338 | 06:11 |
*** ducttap__ has joined #openstack-keystone | 06:16 | |
*** jaosorior has joined #openstack-keystone | 06:17 | |
*** ducttape_ has quit IRC | 06:17 | |
pooja_jadhav | lbragstad: this the bug reference-https://bugs.launchpad.net/keystone/+bug/1654084. i have referred. | 06:18 |
openstack | Launchpad bug 1654084 in OpenStack Identity (keystone) "Listing resources with invalid filters should result in a 400" [Wishlist,In progress] - Assigned to Tin Lam (lamt) | 06:18 |
pooja_jadhav | lamt: Hi | 06:19 |
lamt | pooja_jadhav There was discussion during the summit about microversioning | 06:19 |
pooja_jadhav | lamt: ok | 06:20 |
lamt | pooja_jadhav I think more discussion is needed, so that defect is on hold | 06:20 |
*** abhishek_k has joined #openstack-keystone | 06:21 | |
pooja_jadhav | lamt: Are you taking follow up for this issue? | 06:23 |
*** thorst has joined #openstack-keystone | 06:24 | |
lamt | pooja_jadhav: yup, but implementing microversion needs more discussion, I don't think that defect will be resolved in the immediate future though | 06:25 |
pooja_jadhav | lamt: ok, thank you for the update. | 06:26 |
lamt | pooja_jadhav not a problem | 06:26 |
*** thorst has quit IRC | 06:29 | |
hawk_ | Dear All, I am trying to configure my keystone service in order to integrate with LDAP. But after I add driver = keystone.identity.backends.ldap.Identity into keystone.conf, openstack user list command gives an error like below, "Discovering versions from the identity service failed when creating the password plugin. Attempting to determine version from URL. Internal Server Error (HTTP 500) error." Do you have any opinion ab | 06:29 |
openstackgerrit | yangweiwei proposed openstack/keystone master: Expose a bug in getting federation projects https://review.openstack.org/469318 | 06:31 |
openstackgerrit | yangweiwei proposed openstack/keystone master: Expose a bug in getting federation projects https://review.openstack.org/469318 | 06:36 |
cmurphy | hawk_: the keystone logs should give you a hint about what went wrong | 06:39 |
cmurphy | hawk_: also for the last couple of releases you can just have driver = ldap not the full entry point | 06:39 |
*** basilAB has quit IRC | 06:42 | |
*** basilAB has joined #openstack-keystone | 06:44 | |
hawk_ | I have only keystone-manage.log and do not have keystone.log. | 06:44 |
hawk_ | Do you have to change some configuration to keep logs? | 06:53 |
cmurphy | hawk_: if you're following the install guide it is probably run under apache and the keystone logs will be in /var/log/apache2 | 06:53 |
*** tesseract has joined #openstack-keystone | 06:53 | |
*** Dave has quit IRC | 07:02 | |
*** Dave has joined #openstack-keystone | 07:08 | |
*** mvk has joined #openstack-keystone | 07:08 | |
openstackgerrit | yangweiwei proposed openstack/keystone master: Fix bugs in mapping rules with blacklist https://review.openstack.org/468278 | 07:13 |
*** flwang has quit IRC | 07:24 | |
*** pcaruana has joined #openstack-keystone | 07:26 | |
*** aojea has joined #openstack-keystone | 07:26 | |
*** shuyingy_ has quit IRC | 07:27 | |
*** shuyingya has joined #openstack-keystone | 07:27 | |
*** aselius has joined #openstack-keystone | 07:45 | |
*** hawk_ has quit IRC | 07:45 | |
*** thorst has joined #openstack-keystone | 07:46 | |
*** thorst has quit IRC | 07:50 | |
*** adriant has quit IRC | 07:52 | |
*** hungpv has joined #openstack-keystone | 07:53 | |
*** hawk_ has joined #openstack-keystone | 07:54 | |
hawk_ | Dear All, When I enable LDAP, openstack user list commands gives error. I checked keystone.log here is the errors look like : 2017-05-31 07:48:06.359244 ImportError: No module named ldap.filter 2017-05-31 07:48:07.604887 mod_wsgi (pid=441): Target WSGI script '/usr/bin/keystone-wsgi-admin' cannot be loaded as Python module. 2017-05-31 07:48:07.605155 mod_wsgi (pid=441): Exception occurred processing WSGI script '/usr/bin/key | 07:56 |
hawk_ | Is there any suggestion? Thanks for helping. | 07:56 |
*** zzzeek has quit IRC | 08:00 | |
*** zzzeek has joined #openstack-keystone | 08:01 | |
*** dikonoor has joined #openstack-keystone | 08:02 | |
cmurphy | hawk_: do you have the ldap module installed? `pip freeze | grep ldap` | 08:06 |
*** Drankis has joined #openstack-keystone | 08:10 | |
hawk_ | Traceback (most recent call last): File "/usr/bin/pip", line 11, in <module> sys.exit(main()) File "/usr/lib/python2.7/dist-packages/pip/__init__.py", line 215, in main locale.setlocale(locale.LC_ALL, '') File "/usr/lib/python2.7/locale.py", line 581, in setlocale return _setlocale(category, locale) locale.Error: unsupported locale setting | 08:12 |
*** Shunli has quit IRC | 08:12 | |
*** Shunli has joined #openstack-keystone | 08:13 | |
breton | what's output of "locale"? | 08:18 |
hawk_ | locale: Cannot set LC_ALL to default locale: No such file or directory LANG=en_US.UTF-8 LANGUAGE= LC_CTYPE="en_US.UTF-8" LC_NUMERIC=tr_TR.UTF-8 LC_TIME=en_US.UTF-8 LC_COLLATE="en_US.UTF-8" LC_MONETARY=tr_TR.UTF-8 LC_MESSAGES="en_US.UTF-8" LC_PAPER=tr_TR.UTF-8 LC_NAME=tr_TR.UTF-8 LC_ADDRESS=tr_TR.UTF-8 LC_TELEPHONE=tr_TR.UTF-8 LC_MEASUREMENT=tr_TR.UTF-8 LC_IDENTIFICATION=tr_TR.UTF-8 LC_ALL= | 08:20 |
breton | something is very wrong with your system. Maybe https://stackoverflow.com/questions/14547631/python-locale-error-unsupported-locale-setting or https://stackoverflow.com/questions/36394101/pip-install-locale-error-unsupported-locale-setting could help you, but i am not sure | 08:23 |
cmurphy | yeah this is wandering away from a keystone issue, but "no module named ldap.filter" issue is probably because of a missing dependency | 08:25 |
breton | ++ | 08:29 |
hawk_ | i set lc_all = c then installed python_ldap and python_ldappool | 08:29 |
hawk_ | The request you have made requires authentication. (HTTP 401)then error changed to | 08:30 |
*** dikonoor has quit IRC | 08:39 | |
*** piliman974 has joined #openstack-keystone | 08:41 | |
*** thorst has joined #openstack-keystone | 08:47 | |
*** cristicalin has joined #openstack-keystone | 08:48 | |
*** cristicalin has quit IRC | 08:50 | |
*** hungpv_ has joined #openstack-keystone | 08:52 | |
*** ducttape_ has joined #openstack-keystone | 08:52 | |
*** jose-phi_ has joined #openstack-keystone | 08:53 | |
*** ediardo_ has joined #openstack-keystone | 08:54 | |
*** oomichi_ has joined #openstack-keystone | 08:59 | |
*** zzzeek_ has joined #openstack-keystone | 09:00 | |
*** johnthetubaguy_ has joined #openstack-keystone | 09:00 | |
*** zzzeek has quit IRC | 09:01 | |
*** hungpv has quit IRC | 09:01 | |
*** ducttap__ has quit IRC | 09:01 | |
*** links has quit IRC | 09:01 | |
*** jose-phillips has quit IRC | 09:01 | |
*** pooja_jadhav has quit IRC | 09:01 | |
*** ediardo has quit IRC | 09:01 | |
*** eandersson has quit IRC | 09:01 | |
*** oomichi has quit IRC | 09:01 | |
*** johnthetubaguy has quit IRC | 09:01 | |
*** jistr has quit IRC | 09:01 | |
*** oomichi_ is now known as oomichi | 09:01 | |
*** ediardo_ is now known as ediardo | 09:01 | |
*** adriant has joined #openstack-keystone | 09:02 | |
*** jistr has joined #openstack-keystone | 09:02 | |
*** charz has quit IRC | 09:03 | |
*** andreaf has quit IRC | 09:03 | |
*** charz has joined #openstack-keystone | 09:06 | |
*** thorst has quit IRC | 09:06 | |
*** andreaf has joined #openstack-keystone | 09:06 | |
*** links has joined #openstack-keystone | 09:07 | |
*** pooja_jadhav has joined #openstack-keystone | 09:08 | |
*** eandersson has joined #openstack-keystone | 09:08 | |
*** david-lyle has quit IRC | 09:11 | |
*** david-lyle has joined #openstack-keystone | 09:12 | |
*** jaosorior is now known as jaosorior_lunch | 09:19 | |
*** cristicalin has joined #openstack-keystone | 09:22 | |
*** masber has quit IRC | 09:23 | |
*** Shunli has quit IRC | 09:32 | |
*** andreykurilin has quit IRC | 09:32 | |
*** shuyingya has quit IRC | 09:48 | |
*** shuyingya has joined #openstack-keystone | 09:49 | |
*** cristicalin has quit IRC | 09:52 | |
*** aselius has quit IRC | 09:54 | |
*** mvk has quit IRC | 09:55 | |
*** dikonoor has joined #openstack-keystone | 09:56 | |
*** nicolasbock has joined #openstack-keystone | 09:56 | |
*** liujiong has quit IRC | 10:02 | |
*** flwang has joined #openstack-keystone | 10:02 | |
*** mvk has joined #openstack-keystone | 10:10 | |
*** dikonoor has quit IRC | 10:13 | |
*** dikonoor has joined #openstack-keystone | 10:14 | |
*** links has quit IRC | 10:16 | |
*** piliman974 has quit IRC | 10:17 | |
*** piliman974 has joined #openstack-keystone | 10:19 | |
*** nicolasbock has quit IRC | 10:27 | |
*** nicolasbock has joined #openstack-keystone | 10:27 | |
*** nicolasbock has quit IRC | 10:28 | |
*** nicolasbock has joined #openstack-keystone | 10:28 | |
*** hawk_ has quit IRC | 10:35 | |
*** yk1 has joined #openstack-keystone | 10:36 | |
*** piliman974 has quit IRC | 10:36 | |
*** namnh has quit IRC | 10:36 | |
*** links has joined #openstack-keystone | 10:36 | |
*** adriant has quit IRC | 10:40 | |
*** jaosorior_lunch is now known as jaosorior | 10:41 | |
*** hungpv_ has quit IRC | 10:47 | |
*** piliman974 has joined #openstack-keystone | 10:50 | |
*** yk1 has quit IRC | 10:55 | |
*** thorst has joined #openstack-keystone | 11:04 | |
*** cristicalin has joined #openstack-keystone | 11:06 | |
*** thorst has quit IRC | 11:08 | |
*** raildo has joined #openstack-keystone | 11:11 | |
*** dave-mccowan has joined #openstack-keystone | 11:12 | |
*** xuhaigang has quit IRC | 11:16 | |
*** xuhaigang has joined #openstack-keystone | 11:19 | |
*** yunus has joined #openstack-keystone | 11:26 | |
*** thorst has joined #openstack-keystone | 11:30 | |
yunus | Hi all, I try to configure Ldap on keystone according to the documentation. Ldapsearch command works. How to check that it is working? When I run openstack user list, it gives an error. After removing driver = ldap from keystone.conf. openstack user list works. | 11:33 |
yunus | ldapsearch -x -LLL -h X.X.X.X -D cn=admin,dc=ldap,dc=example,dc=org -w XXXX -b dc=ldap,dc=example,dc=org => works but after configuring keystone.conf openstack user list not working | 11:35 |
yunus | [ldap] url = ldap://X.X.X.X user = cn=admin,dc=ldap,dc=example,dc=org password = XXXX suffix = dc=ldap,dc=example,dc=org | 11:36 |
yunus | user_tree_dn = ou=People,dc=ldap,dc=example,dc=org user_objectclass = organizationalUnit group_tree_dn = Groups,dc=ldap,dc=example,dc=org group_objectclass = organizationalUnit | 11:36 |
cmurphy | yunus: the keystone logs should give you a clue about what went wrong, and setting insecure_debug = true in keystone.conf will give even more information | 11:37 |
yunus | thanks for helping. Actually i am wondering that my keystone.conf's user field is correct or not? Because it is somehow unclear that what is expected? | 11:41 |
yunus | [ldap] url = ldap://X.X.X.X user = cn=admin,dc=ldap,dc=example,dc=org | 11:42 |
*** piliman974 has quit IRC | 11:45 | |
*** piliman974 has joined #openstack-keystone | 11:47 | |
openstackgerrit | rocky proposed openstack/keystone master: Add role test to test_consume_trust_once in test_v3_auth.py https://review.openstack.org/469444 | 11:47 |
cmurphy | yunus: I think it's the user used to bind to the ldap server, so if it works with ldapsearch -D then i think it's probably right | 11:49 |
*** andreykurilin has joined #openstack-keystone | 11:51 | |
yunus | 2017-05-31 11:39:08.534789 2017-05-31 11:39:08.534 6707 WARNING keystone.auth.plugins.core [req-xxxx - - - - -] Could not find user: admin | 11:53 |
yunus | 2017-05-31 11:39:08.535920 2017-05-31 11:39:08.535 6707 WARNING keystone.common.wsgi [req-xxxx - - - - -] Authorization failed. Could not find user: admin (Disable insecure_debug mode to suppress these det$ | 11:54 |
*** frontrunner has joined #openstack-keystone | 12:00 | |
*** edmondsw has joined #openstack-keystone | 12:02 | |
*** chlong has quit IRC | 12:03 | |
*** links has quit IRC | 12:11 | |
samueldmq | morning keystone! | 12:12 |
cmurphy | morning samueldmq | 12:12 |
samueldmq | cmurphy: o/ | 12:14 |
samueldmq | I am not able to run our tests locally | 12:31 |
samueldmq | I am getting http://paste.openstack.org/show/611083/ on almost all tests | 12:32 |
samueldmq | Clean Python 3.5 venv on a macOS | 12:33 |
samueldmq | Has anybody seen that before? | 12:33 |
*** shuyingya has quit IRC | 12:39 | |
lamt | samueldmq yeah - keystone unittest doesn't work on macOS because macOS ships with an outdated OpenLDAP library | 12:54 |
lamt | samueldmq I did get it to work by rebuilding pyldap with newer library | 12:55 |
samueldmq | lamt: is that a system dependency or a Python one? | 12:56 |
samueldmq | lamt: I guess it is a system dependency, if it was Python should be fine since I am using a venv | 12:56 |
lamt | samueldmq it is a system one - lemme find a blog I was reading the other day | 12:57 |
lamt | samueldmq #link https://keathmilligan.net/python-ldap-and-macos/ | 12:57 |
lamt | samueldmq I built a wheel based on that blog and just pip install into my tox venv - that works for me | 12:59 |
yunus | ldapsearch -x -LLL -h X.X.X.X -D cn=admin,dc=ldap,dc=example,dc=org -w XXXX -b dc=ldap,dc=example,dc=org => works but after configuring keystone.conf openstack user list not working | 13:00 |
yunus | [ldap] url = ldap://X.X.X.X user = cn=admin,dc=ldap,dc=example,dc=org password = XXXX suffix = dc=ldap,dc=example,dc=org | 13:00 |
yunus | user_tree_dn = ou=People,dc=ldap,dc=example,dc=org user_objectclass = organizationalUnit group_tree_dn = Groups,dc=ldap,dc=example,dc=org group_objectclass = organizationalUnit | 13:00 |
yunus | WARNING keystone.auth.plugins.core [req-xxxx - - - - -] Could not find user: admin | 13:00 |
yunus | WARNING keystone.common.wsgi [req-xxxx - - - - -] Authorization failed. Could not find user: admin (Disable insecure_debug mode to suppress these det$ | 13:00 |
samueldmq | lamt: interesting, why doesn't just updating the system openldap get it working? | 13:00 |
samueldmq | lamt: or is the version it updates different from the version the wheel was built with | 13:01 |
samueldmq | or that does not make sense at all | 13:01 |
samueldmq | :-) | 13:02 |
lamt | samueldmq it should, but homebrew won't let you override the osx library - I didn't try too hard to override the system libs | 13:02 |
samueldmq | lamt: ah got it | 13:03 |
samueldmq | lamt: I will try that out, thanks! | 13:03 |
cmurphy | yunus: well it looks like it couldn't find the user? | 13:04 |
lamt | samueldmq np, feels hacky and I wish Apple would just update their ldap library :( | 13:04 |
cmurphy | yunus: are you using domain specific configs? https://docs.openstack.org/developer/keystone/configuration.html#domain-specific-drivers if not, are you trying to authenticate with the old non-ldap admin user's credentials? | 13:05 |
*** cristicalin has quit IRC | 13:07 | |
*** lucasxu has joined #openstack-keystone | 13:11 | |
*** lifeless has quit IRC | 13:15 | |
yunus | nope i am not using domain specific configs | 13:17 |
yunus | probably it tries to authenticate with admin_openrc.sh credentials | 13:17 |
*** mugsie has quit IRC | 13:27 | |
prashkre | ayoung: Hi. could you please review backport to stable/ocata https://review.openstack.org/#/c/469299/ | 13:30 |
*** chlong has joined #openstack-keystone | 13:30 | |
*** shuyingya has joined #openstack-keystone | 13:30 | |
*** lifeless has joined #openstack-keystone | 13:33 | |
prashkre | lbragstad: Hi. could you please take a look at https://review.openstack.org/#/c/469299/, this is a backport to stable/ocata from https://review.openstack.org/#/c/468103/ with few changes to fix UT. | 13:34 |
*** shuyingya has quit IRC | 13:34 | |
*** prashkre has quit IRC | 13:40 | |
*** zhurong has joined #openstack-keystone | 13:42 | |
*** cristicalin has joined #openstack-keystone | 13:43 | |
*** chlong has quit IRC | 13:43 | |
*** piliman974 has quit IRC | 13:43 | |
*** piliman974 has joined #openstack-keystone | 13:45 | |
*** chlong has joined #openstack-keystone | 13:46 | |
*** tobberyd_ has joined #openstack-keystone | 13:55 | |
*** tobberydberg has quit IRC | 13:58 | |
*** jefrite has quit IRC | 14:02 | |
*** Drankis has quit IRC | 14:11 | |
*** aselius has joined #openstack-keystone | 14:13 | |
*** dikonoor has quit IRC | 14:27 | |
openstackgerrit | Samriddhi proposed openstack/keystone master: Added keystone admin guides to documentation https://review.openstack.org/469515 | 14:34 |
*** zhurong has quit IRC | 14:35 | |
*** cristicalin has quit IRC | 14:49 | |
*** agrebennikov has joined #openstack-keystone | 14:54 | |
*** flwang has quit IRC | 14:56 | |
*** arahal_ has joined #openstack-keystone | 14:59 | |
*** ducttape_ has quit IRC | 15:04 | |
*** hoonetorg has quit IRC | 15:04 | |
*** ducttape_ has joined #openstack-keystone | 15:05 | |
*** shuyingya has joined #openstack-keystone | 15:05 | |
*** gyee has joined #openstack-keystone | 15:09 | |
*** prashkre has joined #openstack-keystone | 15:14 | |
*** hoonetorg has joined #openstack-keystone | 15:17 | |
*** mvk has quit IRC | 15:19 | |
*** tobberyd_ has quit IRC | 15:21 | |
knikolla | o/ | 15:21 |
lbragstad | o/ | 15:26 |
prashkre | lbragstad: on you comment at https://review.openstack.org/#/c/469299/3/keystone/tests/unit/default_fixtures.py, we don't have a common role_id matching in both master and ocata. | 15:37 |
prashkre | lbragstad: why do we need a change in master because we already have MEMBER_ROLE_ID in master but doesn't exits in ocata. | 15:37 |
lbragstad | prashkre: so a patch went into master to change that, can it be backported to ocata? | 15:38 |
lbragstad | prashkre: the reviewers on that patch were looking for a way to not have a delta between ocata and master as far as the back port is concerns | 15:38 |
lbragstad | concerned* | 15:38 |
edmondsw | lbragstad I don't know that I'm super concerned... if you're fine with the current backport patch then I would be | 15:41 |
edmondsw | I don't think it should really be a big deal, but just wanted to point out what I saw there and see what you thought | 15:41 |
lbragstad | i don't expect much to change in that area for ocata | 15:41 |
lbragstad | i'll take another look | 15:42 |
lbragstad | i'm preparing for the policy meeting | 15:42 |
lbragstad | but i can take another look at the backport right afterwords | 15:42 |
*** piliman974 has quit IRC | 15:42 | |
*** piliman974 has joined #openstack-keystone | 15:43 | |
*** nhelgeson has joined #openstack-keystone | 15:54 | |
prashkre | lbragstad: edmondsw: I don't think detla between ocata and master affects other tests in ocata because roles in default_fixtures.py serve has lookup of existing roles to validate against them. To keep the test(test_list_role_assignments_group_not_found) same in both master and ocata, I would say this change is needed in ocata because we don't have common role_id to make use of it in in master and ocata. | 15:56 |
*** aojea has quit IRC | 15:59 | |
*** david-lyle has quit IRC | 16:06 | |
*** rcernin has quit IRC | 16:07 | |
*** tesseract has quit IRC | 16:08 | |
*** david-lyle has joined #openstack-keystone | 16:14 | |
*** shuyingya has quit IRC | 16:21 | |
*** piliman974 has quit IRC | 16:28 | |
*** rcernin has joined #openstack-keystone | 16:46 | |
*** mvk has joined #openstack-keystone | 16:49 | |
*** pcaruana has quit IRC | 16:50 | |
*** dikonoor has joined #openstack-keystone | 17:00 | |
knikolla | lunch break, back in 1 hr. | 17:05 |
edmondsw | knikolla I added my comments in https://review.openstack.org/#/c/456974 | 17:07 |
edmondsw | lbragstad also added you as a reviewer there | 17:07 |
lbragstad | knikolla: edmondsw awesome - i have it in my queue for this afternoon after I get my comments posted on the rbac in middleware approach | 17:08 |
*** rmascena has joined #openstack-keystone | 17:09 | |
*** raildo has quit IRC | 17:11 | |
samueldmq | edmondsw: lbragstad: would appreciate your review on https://review.openstack.org/#/c/466066/ | 17:25 |
samueldmq | just compare what it is building against https://docs.openstack.org/developer/keystone/ | 17:26 |
samueldmq | L27 in https://review.openstack.org/#/c/466066/7/doc/source/index.rst contains my main concern | 17:26 |
samueldmq | so you can look directly at that if you want, other than that the new theme looks great | 17:27 |
*** aojea has joined #openstack-keystone | 17:29 | |
*** MasterOfBugs has joined #openstack-keystone | 17:38 | |
*** jaosorior is now known as jaosorior_away | 17:44 | |
edmondsw | samueldmq yeah, I think I would echo that concern. Is there a way to see what this will actually look like? | 17:48 |
edmondsw | (before it merges) | 17:48 |
samueldmq | edmondsw: just click on the docs-gate | 17:48 |
edmondsw | samueldmq there it is... I knew I'd done this once before... | 17:49 |
samueldmq | :) | 17:50 |
*** aojea has quit IRC | 17:50 | |
*** aojea has joined #openstack-keystone | 17:51 | |
*** aojea has quit IRC | 17:55 | |
*** aojea has joined #openstack-keystone | 17:57 | |
*** nicolasbock has quit IRC | 17:58 | |
*** aojea has quit IRC | 18:03 | |
*** prashkre has quit IRC | 18:04 | |
*** chlong has quit IRC | 18:05 | |
*** ducttape_ has quit IRC | 18:06 | |
*** ducttape_ has joined #openstack-keystone | 18:12 | |
eandersson | If you have multiple groups, and the groups has different permissions | 18:14 |
eandersson | does keystone combine the groups? | 18:14 |
eandersson | e.g. if group1 has _member_ and group2 has heat_stack_owner, does the user have _member_ and heat_stack_owner? | 18:15 |
samueldmq | eandersson: yes | 18:16 |
*** prashkre has joined #openstack-keystone | 18:16 | |
samueldmq | eandersson: if that user is in both of those groups, yes | 18:16 |
eandersson | thanks samueldmq! | 18:16 |
samueldmq | eandersson: anytime | 18:17 |
*** aojea has joined #openstack-keystone | 18:18 | |
cmurphy | lbragstad: when you have time, could you sign off on https://review.openstack.org/#/c/468954/ and https://review.openstack.org/#/c/468943/ for me? | 18:19 |
*** chlong has joined #openstack-keystone | 18:22 | |
*** aojea has quit IRC | 18:22 | |
*** prashkre has quit IRC | 18:30 | |
*** ayoung has quit IRC | 18:42 | |
*** tobberydberg has joined #openstack-keystone | 18:43 | |
edmondsw | samueldmq I added my comments to the docs rework | 18:45 |
lbragstad | cmurphy: yep - i can do that | 18:46 |
samueldmq | edmondsw: thanks! | 18:47 |
edmondsw | np | 18:47 |
edmondsw | didn't take as much thought as these policy things :) | 18:47 |
*** tobberydberg has quit IRC | 18:48 | |
*** dikonoor has quit IRC | 18:50 | |
*** nhelgeson has quit IRC | 18:54 | |
*** tobberydberg has joined #openstack-keystone | 18:59 | |
*** tobberydberg has quit IRC | 19:03 | |
*** lucasxu has quit IRC | 19:13 | |
lbragstad | morgan: quick stable review for you if you're interested https://review.openstack.org/#/c/469299/3 | 19:21 |
lbragstad | mordred: it's a new one (not the stable/newton one you reviewed recently) | 19:22 |
*** makoto_ has joined #openstack-keystone | 19:23 | |
lbragstad | mordred: sorry - i hit a rogue tab there | 19:24 |
lbragstad | cmurphy: done | 19:24 |
cmurphy | lbragstad: ty | 19:24 |
lbragstad | cmurphy: thank you for taking the initiative | 19:26 |
cmurphy | lbragstad: no problem | 19:27 |
*** aojea has joined #openstack-keystone | 19:28 | |
makoto_ | Hello, at OpenStack Summit in Boston, ayoung mentioned somebody developed Ansible playbook to setup keystone+Federation+Kerberos. Has anybody got one? Thank you | 19:33 |
lbragstad | makoto_: that's a good question - i'm not sure where that lives though | 19:34 |
lbragstad | makoto_: i know the openstack-ansible team has keystone playbooks for federation | 19:34 |
lbragstad | makoto_: i'm not sure what the kerberos support is like though | 19:34 |
*** pcaruana has joined #openstack-keystone | 19:45 | |
*** pcaruana has quit IRC | 20:02 | |
edmondsw | lbragstad can you do kerberos and federation at the same time? I thought it had to be one or the other | 20:02 |
lbragstad | edmondsw: yeah - that's why i'm curious to know where that lives | 20:03 |
edmondsw | lbragstad makoto_ https://specs.openstack.org/openstack/openstack-ansible-specs/specs/kilo/keystone-federation.html | 20:05 |
lbragstad | "Later options to extend support to would include the saml-based Apache mod_auth_mellon, the OpenID-based Apache mod_auth_openidc, the kerberos-based Apache mod_auth_kerb/mod_auth_identity." | 20:06 |
edmondsw | right | 20:06 |
lbragstad | someone in #openstack-ansible might know | 20:06 |
edmondsw | I didn't see a newer spec that, from it's title, would seem to have extended the kilo one | 20:07 |
lbragstad | they've had support for setting up keystone federation with ansible for a while | 20:07 |
*** lucasxu has joined #openstack-keystone | 20:20 | |
*** rcernin has quit IRC | 20:21 | |
*** lucasxu has quit IRC | 20:21 | |
*** rcernin has joined #openstack-keystone | 20:22 | |
*** prashkre has joined #openstack-keystone | 20:23 | |
*** rcernin has quit IRC | 20:42 | |
*** rmascena has quit IRC | 20:45 | |
*** prashkre has quit IRC | 20:48 | |
*** ayoung has joined #openstack-keystone | 20:52 | |
*** chlong has quit IRC | 20:53 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Specification for global roles https://review.openstack.org/464763 | 20:59 |
*** chlong has joined #openstack-keystone | 21:05 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Specification for global roles https://review.openstack.org/464763 | 21:06 |
lbragstad | samueldmq: thanks for the suggestions on the spec | 21:08 |
*** pcaruana has joined #openstack-keystone | 21:12 | |
*** aojea has quit IRC | 21:13 | |
*** thorst has quit IRC | 21:17 | |
flwang2 | lbragstad: hello | 21:18 |
openstackgerrit | Merged openstack/keystone master: Change url scheme passed to oauth signature verifier https://review.openstack.org/464577 | 21:18 |
flwang2 | lbragstad: i have some questions about the service token, could you tell me who is the right person i can ask? thanks | 21:18 |
*** harlowja has quit IRC | 21:21 | |
*** pcaruana has quit IRC | 21:29 | |
samueldmq | lbragstad: sure | 21:38 |
samueldmq | lbragstad: glad to help | 21:38 |
*** ayoung has quit IRC | 21:39 | |
*** tobberydberg has joined #openstack-keystone | 21:40 | |
*** tobberydberg has quit IRC | 21:45 | |
*** xuhaigang has quit IRC | 21:51 | |
*** xuhaigang has joined #openstack-keystone | 21:52 | |
*** esp has joined #openstack-keystone | 21:55 | |
*** thorst has joined #openstack-keystone | 21:56 | |
*** edmondsw has quit IRC | 22:01 | |
*** edmondsw has joined #openstack-keystone | 22:01 | |
*** shuyingya has joined #openstack-keystone | 22:02 | |
makoto_ | Got it, thank you lbragstad and edmondsw | 22:02 |
*** edmondsw_ has joined #openstack-keystone | 22:03 | |
*** edmondsw has quit IRC | 22:05 | |
*** harlowja has joined #openstack-keystone | 22:06 | |
*** shuyingya has quit IRC | 22:07 | |
*** edmondsw_ has quit IRC | 22:07 | |
lbragstad | flwang2: sure - feel free to ask your questions here | 22:12 |
*** esp has quit IRC | 22:14 | |
*** esp has joined #openstack-keystone | 22:15 | |
lbragstad | flwang2: jamielennox|away was one of the people who implemented it | 22:27 |
morgan | flwang2: most of us can answer though | 22:27 |
lbragstad | but several people here are familiar with it | 22:27 |
morgan | since most of us reviewed a chunk of it | 22:27 |
morgan | ;) | 22:27 |
*** edmondsw has joined #openstack-keystone | 22:31 | |
*** edmondsw has quit IRC | 22:35 | |
*** jose-phi_ has quit IRC | 22:42 | |
*** jose-phillips has joined #openstack-keystone | 22:50 | |
*** esp has quit IRC | 22:57 | |
*** esp has joined #openstack-keystone | 22:59 | |
*** chlong has quit IRC | 23:00 | |
*** MasterOfBugs has quit IRC | 23:07 | |
*** adriant has joined #openstack-keystone | 23:08 | |
*** thorst has quit IRC | 23:09 | |
*** agrebennikov has quit IRC | 23:09 | |
*** ducttape_ has quit IRC | 23:15 | |
*** nicolasbock has joined #openstack-keystone | 23:16 | |
*** thorst has joined #openstack-keystone | 23:20 | |
*** tobberydberg has joined #openstack-keystone | 23:29 | |
*** tobberydberg has quit IRC | 23:33 | |
*** tobberydberg has joined #openstack-keystone | 23:45 | |
*** masber has joined #openstack-keystone | 23:46 | |
*** tobberydberg has quit IRC | 23:49 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!