*** threestrands has joined #openstack-keystone | 00:05 | |
*** threestrands has quit IRC | 00:05 | |
*** threestrands has joined #openstack-keystone | 00:05 | |
*** lbragstad has quit IRC | 00:28 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Update the help message for unique_last_password_count https://review.openstack.org/522136 | 00:53 |
---|---|---|
*** daidv has joined #openstack-keystone | 01:02 | |
*** daidv_ has joined #openstack-keystone | 01:03 | |
openstackgerrit | wangxiyuan proposed openstack/keystone-specs master: Limits API https://review.openstack.org/455709 | 01:05 |
*** zhouyaguo has joined #openstack-keystone | 01:12 | |
*** zhurong has joined #openstack-keystone | 01:21 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add schema check for OS-TRUST:trust authentication https://review.openstack.org/522107 | 01:22 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Expose a bug when authenticating for a trust-scoped token https://review.openstack.org/522356 | 01:34 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add schema check for OS-TRUST:trust authentication https://review.openstack.org/522107 | 01:34 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Add schema check for OS-TRUST:trust authentication https://review.openstack.org/522107 | 01:35 |
openstackgerrit | wangxiyuan proposed openstack/keystone-specs master: Limits API https://review.openstack.org/455709 | 02:23 |
*** annp has joined #openstack-keystone | 02:29 | |
*** swain has quit IRC | 02:33 | |
*** prashkre has joined #openstack-keystone | 02:35 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Deprecate member_role_id and member_role_name https://review.openstack.org/522461 | 02:42 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Deprecate member_role_id and member_role_name https://review.openstack.org/522461 | 02:59 |
*** prashkre has quit IRC | 03:40 | |
*** zhurong has quit IRC | 03:43 | |
*** links has joined #openstack-keystone | 04:03 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Expose a bug when create trust with roles https://review.openstack.org/522705 | 04:43 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Fix 500 error when create trust with invalid role key https://review.openstack.org/522706 | 04:43 |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Deprecate member_role_id and member_role_name https://review.openstack.org/522461 | 04:46 |
*** prashkre has joined #openstack-keystone | 04:53 | |
*** threestrands_ has joined #openstack-keystone | 05:02 | |
*** threestrands has quit IRC | 05:04 | |
*** zhouyaguo has quit IRC | 05:09 | |
*** BenderRodriguez has quit IRC | 05:10 | |
*** threestrands_ has quit IRC | 05:14 | |
*** prashkre has quit IRC | 05:18 | |
*** prashkre has joined #openstack-keystone | 05:19 | |
*** dklyle has quit IRC | 05:19 | |
*** david-lyle has joined #openstack-keystone | 05:20 | |
*** prashkre_ has joined #openstack-keystone | 05:21 | |
*** prashkre has quit IRC | 05:25 | |
*** BenderRodriguez has joined #openstack-keystone | 05:34 | |
*** BenderRodriguez has quit IRC | 05:34 | |
*** BenderRodriguez has joined #openstack-keystone | 05:34 | |
*** sticker has quit IRC | 05:56 | |
*** sapd_ has quit IRC | 06:33 | |
*** sapd_ has joined #openstack-keystone | 06:35 | |
*** pcaruana has joined #openstack-keystone | 07:12 | |
*** prashkre_ has quit IRC | 07:43 | |
*** rcernin has quit IRC | 07:53 | |
*** magicboiz has quit IRC | 07:59 | |
*** magicboiz has joined #openstack-keystone | 08:02 | |
*** magicboiz has quit IRC | 08:07 | |
*** magicboiz has joined #openstack-keystone | 08:07 | |
*** aojea has joined #openstack-keystone | 08:12 | |
*** tesseract has joined #openstack-keystone | 08:13 | |
*** aojea has quit IRC | 08:16 | |
*** AlexeyAbashkin has joined #openstack-keystone | 08:21 | |
*** magicboiz has quit IRC | 10:16 | |
*** prashkre_ has joined #openstack-keystone | 10:19 | |
*** magicboiz has joined #openstack-keystone | 10:23 | |
*** magicboiz has quit IRC | 10:27 | |
*** magicboiz has joined #openstack-keystone | 10:27 | |
*** prashkre_ has quit IRC | 10:28 | |
*** magicboiz has quit IRC | 10:47 | |
*** daidv has quit IRC | 10:59 | |
*** daidv_ has quit IRC | 10:59 | |
*** annp has quit IRC | 11:08 | |
*** annp has joined #openstack-keystone | 11:09 | |
*** annp has quit IRC | 11:20 | |
*** annp has joined #openstack-keystone | 11:20 | |
*** annp has quit IRC | 11:30 | |
*** magicboiz has joined #openstack-keystone | 11:30 | |
*** magicboiz has quit IRC | 11:35 | |
*** magicboiz has joined #openstack-keystone | 11:41 | |
*** raildo has joined #openstack-keystone | 12:01 | |
*** links has quit IRC | 12:06 | |
*** links has joined #openstack-keystone | 12:20 | |
*** BenderRodriguez has quit IRC | 12:29 | |
*** dave-mccowan has joined #openstack-keystone | 12:51 | |
*** links has quit IRC | 13:11 | |
*** magicboiz has quit IRC | 13:15 | |
*** alex_xu has quit IRC | 13:31 | |
*** alex_xu has joined #openstack-keystone | 13:32 | |
*** openstackgerrit has quit IRC | 13:32 | |
*** Dinesh_Bhor has quit IRC | 13:57 | |
*** dave-mccowan has quit IRC | 14:10 | |
*** lbragstad has joined #openstack-keystone | 14:28 | |
*** ChanServ sets mode: +o lbragstad | 14:28 | |
lbragstad | o/ | 14:33 |
cmurphy | \o | 14:34 |
cmurphy | lbragstad: no thanksgiving holiday for you? | 14:35 |
lbragstad | cmurphy: had it yesterday :) | 14:35 |
cmurphy | lbragstad: most people take a long weekend :P | 14:35 |
lbragstad | yeah... that's true, i thought about it, but i'm waiting on some materials for the house | 14:36 |
lbragstad | so i don't really have a project to work on if i don't work lol | 14:37 |
lbragstad | cmurphy: did you do anything for thanksgiving? | 14:41 |
cmurphy | lbragstad: nah was just a normal day here | 14:42 |
lbragstad | cmurphy: you have early christmas right around the corner though | 14:43 |
lbragstad | december 4th? | 14:43 |
cmurphy | lbragstad: our christmas is the same as everyone else's :P | 14:44 |
lbragstad | cmurphy: oh - i'm thinking of St. Nick's Day | 14:45 |
lbragstad | december 6th, it's like a pre-christmas thing | 14:45 |
cmurphy | aha | 14:45 |
cmurphy | no public holiday :( | 14:46 |
lbragstad | yeah - doesn't look like it | 14:46 |
lbragstad | cmurphy: here is a pre-requisite patch to the one you +2'd | 15:01 |
lbragstad | https://review.openstack.org/#/c/522356/ | 15:01 |
lbragstad | oh - wait, nevermind | 15:01 |
lbragstad | that was a different one | 15:01 |
lbragstad | same author | 15:01 |
cmurphy | ya i haven't looked at those trust patches yet | 15:02 |
lbragstad | looks like another revision of the unified limits spec is up to | 15:02 |
* lbragstad moves that to the top of the list | 15:02 | |
lbragstad | along with app creds | 15:02 |
cmurphy | lbragstad: yep that needs another look | 15:02 |
lbragstad | cool - i'll review both today | 15:03 |
lbragstad | cmurphy: so for the application credential stuff | 15:06 |
lbragstad | without the ability to list application credentials on a project | 15:07 |
lbragstad | per the security concerns ofit | 15:07 |
lbragstad | if we work on a team together, and we know that i'm going to be leaving and you're going to be assuming ownership of the application | 15:07 |
lbragstad | then there has to be some sort of out-of-band process for you to know that is happening so that you create a new credential and propogate it through configuration of the application | 15:08 |
lbragstad | *before* my user is deleted | 15:08 |
cmurphy | right | 15:09 |
cmurphy | it'll have to be out-of-band | 15:09 |
cmurphy | we'll have no way to do audits through keystone | 15:09 |
lbragstad | ok - right | 15:09 |
lbragstad | and an application credential can be used to interact with multiple projects, right? | 15:09 |
cmurphy | i don't think so | 15:10 |
cmurphy | it would still be scoped to just one project | 15:10 |
lbragstad | which is the project the token is scoped to that is used to create the application credential | 15:10 |
cmurphy | yeah - well now i'm trying to work through whether that's necessary | 15:11 |
lbragstad | associating a project to an application credential? | 15:11 |
cmurphy | yeah | 15:11 |
cmurphy | i've been assuming this was like a scoped token but maybe it's more like a username/password | 15:11 |
*** AlexeyAbashkin has quit IRC | 15:12 | |
lbragstad | if we don't do that, then i think the application using the credential needs to figure out what project to operator on | 15:12 |
lbragstad | and i'm not sure if ^ that is good or bad? | 15:12 |
lbragstad | because i could see where that could be dangerous, because it's kinda like impersonation of all the user's roles | 15:13 |
lbragstad | (if the user doesn't explicitly say, this application credential is dedicated to this project) | 15:13 |
cmurphy | okay - right - when it's created, it has a fixed set of roles on a project, letting it exist as just another set of user credentials would take away that polp feature | 15:14 |
lbragstad | yeah | 15:14 |
cmurphy | so yes, an application credential can only be used on one project | 15:14 |
lbragstad | because it would allow the application credential to do things in other projects that might not be necessary or allowed | 15:14 |
cmurphy | right | 15:15 |
lbragstad | so - which it's associated to the lifecycle of the user, it must be validated against the project and tied to the project in someway | 15:15 |
lbragstad | s/which/while | 15:15 |
cmurphy | yes | 15:16 |
cmurphy | it has a project_id attribute for that | 15:16 |
lbragstad | if i look at it that way, it seems useful to have a project_id attribute for each application credential | 15:16 |
lbragstad | awesome | 15:16 |
lbragstad | and that would technically be considered a project-scoped operation, so pulling it from the token context makes sense | 15:17 |
lbragstad | I can't really think of a reason why you'd want to have a user specify the project in the request | 15:18 |
cmurphy | lbragstad: this is what we have now http://paste.openstack.org/show/627331/ i agree i don't think specifying the project would be needed | 15:20 |
lbragstad | cool - that makes sense | 15:21 |
lbragstad | yeah - specifying the project seems redundant | 15:21 |
lbragstad | it would be just another thing for users to have to include in the request and another bit of information for keystone to validate | 15:21 |
*** jaosorior has quit IRC | 15:44 | |
*** swain has joined #openstack-keystone | 15:47 | |
*** openstackgerrit has joined #openstack-keystone | 17:00 | |
openstackgerrit | Merged openstack/keystone master: Update the help message for unique_last_password_count https://review.openstack.org/522136 | 17:00 |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Propose follow-on comments for unified limits https://review.openstack.org/522876 | 17:04 |
lbragstad | wxy_: ^ proposed a follow-on, feel free to steal anything from there if you want | 17:08 |
*** aojea has joined #openstack-keystone | 17:29 | |
*** aojea has quit IRC | 17:34 | |
*** pcaruana has quit IRC | 17:55 | |
*** swain has quit IRC | 17:57 | |
*** jose-phillips has joined #openstack-keystone | 18:03 | |
*** jose-phillips has quit IRC | 18:07 | |
*** AJaeger has joined #openstack-keystone | 18:20 | |
AJaeger | keystone cores, we have a couple of changes up for your repos to fix releasenotes build so that they work with the new infra scripts. Please review https://review.openstack.org/520882 https://review.openstack.org/521021 https://review.openstack.org/520728 https://review.openstack.org/520892 | 18:22 |
*** AlexeyAbashkin has joined #openstack-keystone | 18:22 | |
cmurphy | thanks AJaeger | 18:24 |
*** AlexeyAbashkin has quit IRC | 18:27 | |
*** jose-phillips has joined #openstack-keystone | 18:37 | |
AJaeger | thanks, cmurphy ! Have a great weekend! | 18:56 |
openstackgerrit | Merged openstack/keystone master: Remove apache-httpd related link https://review.openstack.org/516813 | 18:57 |
*** dave-mccowan has joined #openstack-keystone | 18:57 | |
lbragstad | thanks AJaeger, reviewing now | 18:58 |
AJaeger | thanks, lbragstad | 18:59 |
lbragstad | AJaeger: anytime - thanks for the ping | 18:59 |
openstackgerrit | Merged openstack/ldappool master: Updated from global requirements https://review.openstack.org/520425 | 19:05 |
*** dave-mccowan has quit IRC | 19:08 | |
openstackgerrit | Merged openstack/keystone-specs master: Update project-tags spec https://review.openstack.org/508339 | 19:15 |
*** dave-mccowan has joined #openstack-keystone | 19:21 | |
*** jistr has quit IRC | 19:30 | |
*** jistr has joined #openstack-keystone | 19:31 | |
openstackgerrit | Merged openstack/python-keystoneclient master: Remove setting of version/release from releasenotes https://review.openstack.org/520728 | 19:43 |
*** dave-mccowan has quit IRC | 19:47 | |
openstackgerrit | Merged openstack/keystoneauth master: Updated from global requirements https://review.openstack.org/520418 | 20:02 |
openstackgerrit | Merged openstack/keystonemiddleware master: Updated from global requirements https://review.openstack.org/520421 | 20:17 |
openstackgerrit | Merged openstack/keystonemiddleware master: Imported Translations from Zanata https://review.openstack.org/514529 | 20:17 |
*** hoonetorg has joined #openstack-keystone | 20:19 | |
openstackgerrit | Merged openstack/keystoneauth master: Remove setting of version/release from releasenotes https://review.openstack.org/520882 | 20:19 |
openstackgerrit | Merged openstack/keystone master: Updated from global requirements https://review.openstack.org/519781 | 20:23 |
openstackgerrit | Merged openstack/python-keystoneclient master: Updated from global requirements https://review.openstack.org/519803 | 20:29 |
openstackgerrit | Merged openstack/python-keystoneclient master: Remove functional tests for v2.0 API https://review.openstack.org/519678 | 20:29 |
*** AJaeger has left #openstack-keystone | 20:30 | |
openstackgerrit | Merged openstack/keystone master: Remove setting of version/release from releasenotes https://review.openstack.org/520892 | 20:36 |
*** BenderRodriguez has joined #openstack-keystone | 20:42 | |
*** dave-mccowan has joined #openstack-keystone | 20:45 | |
*** d0ugal has quit IRC | 20:56 | |
*** tesseract has quit IRC | 20:59 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Fix wrong links in keystone documentation https://review.openstack.org/501177 | 21:00 |
*** dave-mccowan has quit IRC | 21:00 | |
*** d0ugal has joined #openstack-keystone | 21:01 | |
lbragstad | easy +2 ^ | 21:01 |
*** aojea has joined #openstack-keystone | 21:06 | |
*** raildo has quit IRC | 21:19 | |
openstackgerrit | Merged openstack/keystone master: Reorganize api-ref: v3 users https://review.openstack.org/506994 | 21:43 |
openstackgerrit | Merged openstack/keystone master: Reorganize api-ref: v3-ext federation auth https://review.openstack.org/501139 | 21:50 |
*** aojea has quit IRC | 22:28 | |
*** magicboiz has joined #openstack-keystone | 23:03 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Validate disabled domains and projects online https://review.openstack.org/253273 | 23:12 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Validate disabled domains and projects online https://review.openstack.org/253273 | 23:17 |
lbragstad | ^ that should be resolved and passing tests locally | 23:19 |
lbragstad | it also closes a bug | 23:19 |
cmurphy | oof 42 patchsets | 23:33 |
openstackgerrit | Merged openstack/keystone master: Fix wrong links in keystone documentation https://review.openstack.org/501177 | 23:37 |
openstackgerrit | Merged openstack/keystonemiddleware master: Remove setting of version/release from releasenotes https://review.openstack.org/521021 | 23:40 |
*** magicboiz has quit IRC | 23:53 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!