*** felipemonteiro has joined #openstack-keystone | 00:05 | |
*** felipemonteiro has quit IRC | 00:14 | |
*** liuzz has quit IRC | 00:17 | |
*** liuzz has joined #openstack-keystone | 00:19 | |
*** panbalag has joined #openstack-keystone | 00:25 | |
*** oikiki has quit IRC | 00:26 | |
*** oikiki has joined #openstack-keystone | 00:27 | |
*** r-daneel has quit IRC | 00:29 | |
*** panbalag has quit IRC | 00:30 | |
*** david-lyle has quit IRC | 00:34 | |
*** oikiki has quit IRC | 00:36 | |
*** Dinesh_Bhor has joined #openstack-keystone | 00:39 | |
*** panbalag has joined #openstack-keystone | 00:48 | |
*** annp has quit IRC | 00:53 | |
*** annp has joined #openstack-keystone | 00:53 | |
*** oikiki has joined #openstack-keystone | 00:56 | |
*** oikiki has quit IRC | 01:01 | |
*** oikiki has joined #openstack-keystone | 01:02 | |
*** edmondsw has quit IRC | 01:19 | |
*** markvoelker_ has quit IRC | 01:34 | |
*** panbalag has quit IRC | 01:38 | |
*** markvoelker has joined #openstack-keystone | 01:38 | |
*** namnh has joined #openstack-keystone | 01:40 | |
*** panbalag has joined #openstack-keystone | 01:43 | |
*** oikiki has quit IRC | 01:45 | |
*** oikiki has joined #openstack-keystone | 01:46 | |
*** oikiki has quit IRC | 01:46 | |
*** panbalag has left #openstack-keystone | 01:58 | |
*** itlinux has joined #openstack-keystone | 02:02 | |
*** Dinesh_Bhor has quit IRC | 02:09 | |
*** Dinesh_Bhor has joined #openstack-keystone | 02:11 | |
*** itlinux has quit IRC | 02:30 | |
*** itlinux has joined #openstack-keystone | 02:38 | |
*** lbragstad has quit IRC | 02:39 | |
*** itlinux has quit IRC | 02:46 | |
*** masber has quit IRC | 02:49 | |
*** dave-mcc_ has quit IRC | 02:52 | |
*** masber has joined #openstack-keystone | 02:52 | |
*** edmondsw has joined #openstack-keystone | 02:59 | |
*** edmondsw has quit IRC | 03:04 | |
*** itlinux has joined #openstack-keystone | 03:08 | |
*** nicolasbock has quit IRC | 03:23 | |
bhagyashris | cmurphy: mordred: pooja_jadhav | 03:31 |
---|---|---|
bhagyashris | cmurphy: mordred: currently neha_alhat is working on providing split_looger functionality in different client | 03:33 |
*** itlinux has quit IRC | 03:34 | |
*** sonuk has joined #openstack-keystone | 03:54 | |
*** masuberu has joined #openstack-keystone | 03:56 | |
*** gyankum has joined #openstack-keystone | 03:59 | |
*** masber has quit IRC | 04:00 | |
*** masber has joined #openstack-keystone | 04:02 | |
*** masuberu has quit IRC | 04:05 | |
*** germs has quit IRC | 04:10 | |
*** links has joined #openstack-keystone | 04:24 | |
*** gyee has quit IRC | 04:26 | |
*** gongysh has joined #openstack-keystone | 04:32 | |
*** prashkre has joined #openstack-keystone | 04:44 | |
openstackgerrit | Merged openstack/keystone master: Limit description support https://review.openstack.org/553132 | 04:44 |
*** edmondsw has joined #openstack-keystone | 04:48 | |
*** prashkre has quit IRC | 04:53 | |
*** edmondsw has quit IRC | 04:53 | |
*** Dinesh__Bhor has joined #openstack-keystone | 04:59 | |
*** Dinesh_Bhor has quit IRC | 04:59 | |
*** liuzz has quit IRC | 05:47 | |
*** liuzz has joined #openstack-keystone | 05:48 | |
*** prashkre has joined #openstack-keystone | 06:12 | |
*** liuzz_ has joined #openstack-keystone | 06:15 | |
*** liuzz has quit IRC | 06:16 | |
*** Dinesh__Bhor has quit IRC | 06:17 | |
*** Dinesh__Bhor has joined #openstack-keystone | 06:17 | |
*** liuzz_ has quit IRC | 06:20 | |
*** liuzz has joined #openstack-keystone | 06:21 | |
*** liuzz has quit IRC | 06:23 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Unified limit update APIs Refactor https://review.openstack.org/559552 | 06:24 |
*** liuzz has joined #openstack-keystone | 06:25 | |
*** gongysh has quit IRC | 06:25 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Unified limit update APIs Refactor https://review.openstack.org/559552 | 06:30 |
*** liuzz_ has joined #openstack-keystone | 06:32 | |
*** liuzz has quit IRC | 06:33 | |
*** oikiki has joined #openstack-keystone | 06:45 | |
*** martinus__ has joined #openstack-keystone | 06:54 | |
*** gongysh has joined #openstack-keystone | 06:55 | |
*** ispp has joined #openstack-keystone | 06:59 | |
*** tesseract has joined #openstack-keystone | 07:01 | |
*** Dinesh__Bhor has quit IRC | 07:02 | |
*** oikiki has quit IRC | 07:10 | |
*** prashkre has quit IRC | 07:12 | |
*** prashkre has joined #openstack-keystone | 07:13 | |
*** ispp has quit IRC | 07:17 | |
*** gongysh has quit IRC | 07:27 | |
*** ispp has joined #openstack-keystone | 07:30 | |
*** AlexeyAbashkin has joined #openstack-keystone | 07:47 | |
*** ispp has quit IRC | 07:54 | |
*** prashkre has quit IRC | 07:57 | |
*** rcernin has quit IRC | 08:12 | |
*** gongysh has joined #openstack-keystone | 08:18 | |
*** ispp has joined #openstack-keystone | 08:20 | |
*** edmondsw has joined #openstack-keystone | 08:24 | |
*** edmondsw has quit IRC | 08:29 | |
*** links has quit IRC | 08:32 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Unified limit update APIs Refactor https://review.openstack.org/559552 | 08:33 |
*** gyankum has quit IRC | 08:33 | |
Shilpa | lbragstad: Hi | 08:34 |
Shilpa | lbragstad[m]: Hi | 08:35 |
*** links has joined #openstack-keystone | 08:49 | |
*** prashkre has joined #openstack-keystone | 08:51 | |
*** d0ugal__ has quit IRC | 08:51 | |
*** d0ugal has joined #openstack-keystone | 08:51 | |
*** d0ugal has quit IRC | 08:51 | |
*** d0ugal has joined #openstack-keystone | 08:51 | |
*** gyankum has joined #openstack-keystone | 09:04 | |
*** gyankum has quit IRC | 09:08 | |
*** gongysh has quit IRC | 09:09 | |
*** ispp has quit IRC | 09:15 | |
*** gongysh has joined #openstack-keystone | 09:17 | |
*** dims has quit IRC | 09:20 | |
*** gongysh has quit IRC | 09:24 | |
*** gyankum has joined #openstack-keystone | 09:46 | |
*** gyankum has quit IRC | 09:50 | |
*** AlexeyAbashkin has quit IRC | 09:53 | |
*** gyankum has joined #openstack-keystone | 09:56 | |
*** namnh has quit IRC | 10:00 | |
*** ispp has joined #openstack-keystone | 10:01 | |
openstackgerrit | wangxiyuan proposed openstack/oslo.limit master: Init repo https://review.openstack.org/556744 | 10:06 |
*** dims has joined #openstack-keystone | 10:07 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: Unified limit update APIs Refactor https://review.openstack.org/559552 | 10:10 |
*** edmondsw has joined #openstack-keystone | 10:13 | |
*** annp has quit IRC | 10:15 | |
*** edmondsw has quit IRC | 10:17 | |
*** dims has quit IRC | 10:17 | |
*** nicolasbock has joined #openstack-keystone | 10:30 | |
*** ispp has quit IRC | 10:40 | |
*** hoonetorg has quit IRC | 10:43 | |
*** edmondsw has joined #openstack-keystone | 10:52 | |
*** AlexeyAbashkin has joined #openstack-keystone | 10:54 | |
*** hoonetorg has joined #openstack-keystone | 11:00 | |
*** jaosorior has quit IRC | 11:01 | |
*** jaosorior has joined #openstack-keystone | 11:05 | |
*** dave-mccowan has joined #openstack-keystone | 11:08 | |
*** sonuk has quit IRC | 11:10 | |
*** gyan_ has joined #openstack-keystone | 11:14 | |
*** gyankum has quit IRC | 11:16 | |
*** links has quit IRC | 11:16 | |
*** prashkre has quit IRC | 11:22 | |
*** prashkre has joined #openstack-keystone | 11:28 | |
*** links has joined #openstack-keystone | 11:29 | |
*** ispp has joined #openstack-keystone | 11:30 | |
*** panbalag has joined #openstack-keystone | 11:31 | |
*** panbalag has left #openstack-keystone | 11:32 | |
*** lbragstad has joined #openstack-keystone | 11:33 | |
*** ChanServ sets mode: +o lbragstad | 11:33 | |
*** bhagyashri_s has joined #openstack-keystone | 11:42 | |
*** bhagyashri_s has quit IRC | 11:43 | |
*** bhagyashri_s has joined #openstack-keystone | 11:44 | |
*** bhagyashri_s has quit IRC | 11:45 | |
*** bhagyashris has quit IRC | 11:46 | |
*** bhagyashri_s has joined #openstack-keystone | 11:46 | |
*** pooja-jadhav has joined #openstack-keystone | 11:48 | |
*** pooja_jadhav has quit IRC | 11:50 | |
*** liuzz_ has quit IRC | 11:57 | |
doxa | Create a TOTP credential¶ - doesn't work for me. Any thoughts ? https://docs.openstack.org/keystone/queens/advanced-topics/auth-totp.html#create-a-totp-credential | 12:00 |
*** pooja_jadhav has joined #openstack-keystone | 12:02 | |
lbragstad | doxa: what error are you getting? | 12:02 |
*** bhagyashris_ has joined #openstack-keystone | 12:03 | |
*** prashkre_ has joined #openstack-keystone | 12:04 | |
doxa | lbragstad: Eror I receive is {"error": {"message": "The request you have made requires authentication.", "code": 401, "title": "Unauthorized"}} | 12:05 |
*** pooja-jadhav has quit IRC | 12:06 | |
*** bhagyashri_s has quit IRC | 12:06 | |
*** prashkre has quit IRC | 12:06 | |
lbragstad | are you able to authenticate against keystone? | 12:06 |
doxa | lbragstad: with nomal auth works fine | 12:09 |
*** prashkre_ has quit IRC | 12:09 | |
*** jaosorior has quit IRC | 12:12 | |
lbragstad | is the token you're passing in that request for the user in the request? | 12:15 |
*** bhagyashri_s has joined #openstack-keystone | 12:15 | |
*** ShilpaSD has joined #openstack-keystone | 12:16 | |
*** bhagyashris_ has quit IRC | 12:18 | |
*** Shilpa has quit IRC | 12:18 | |
*** jaosorior has joined #openstack-keystone | 12:19 | |
doxa | lbragstad: I am using the example from mentioned webpage. I have just changed the user ID. | 12:19 |
doxa | lbragstad: TOTP works independent from user/password auth or together ? | 12:20 |
doxa | lbragstad: is there any alternative way to setup totp blob beside curl method ? | 12:22 |
*** ispp has quit IRC | 12:23 | |
*** belmoreira has joined #openstack-keystone | 12:24 | |
*** ShilpaSD has quit IRC | 12:24 | |
*** ispp has joined #openstack-keystone | 12:25 | |
*** bhagyashris has joined #openstack-keystone | 12:25 | |
*** Shilpa has joined #openstack-keystone | 12:26 | |
Shilpa | lbragstad: Hi | 12:28 |
*** bhagyashri_s has quit IRC | 12:28 | |
lbragstad | doxa: you need a token in order to authenticate yourself and make that API call | 12:29 |
lbragstad | Shilpa: hi | 12:29 |
*** raildo has joined #openstack-keystone | 12:31 | |
doxa | lbragstad: do you mean the base 64 secret ? | 12:33 |
lbragstad | doxa: no - you need to pass a token in the request headers to prove who you are to keystone in order for keystone to authorize you to make that API call | 12:34 |
*** sapd_ has quit IRC | 12:34 | |
*** sapd_ has joined #openstack-keystone | 12:34 | |
*** sapd_ has quit IRC | 12:35 | |
*** sapd_ has joined #openstack-keystone | 12:35 | |
*** sapd_ has quit IRC | 12:36 | |
doxa | lbragstad: please send me an example | 12:36 |
*** sapd_ has joined #openstack-keystone | 12:36 | |
*** panbalag has joined #openstack-keystone | 12:37 | |
lbragstad | here are a bunch of examples using curl | 12:37 |
lbragstad | https://docs.openstack.org/keystone/latest/api_curl_examples.html | 12:37 |
*** panbalag has left #openstack-keystone | 12:37 | |
lbragstad | if you look at this specific example https://docs.openstack.org/keystone/latest/api_curl_examples.html#domains | 12:37 |
lbragstad | you can see that the X-Auth-Token header is being set | 12:38 |
lbragstad | you'll need to do that for the request you're making to create a TOTP credential | 12:38 |
lbragstad | the $OS_TOKEN in that example is a token from keystone that you've authenticated for | 12:38 |
*** bhagyashri_s has joined #openstack-keystone | 12:41 | |
*** pooja_jadhav has quit IRC | 12:41 | |
*** Shilpa has quit IRC | 12:42 | |
*** bhagyashris has quit IRC | 12:42 | |
*** pooja_jadhav has joined #openstack-keystone | 12:42 | |
*** Shilpa has joined #openstack-keystone | 12:42 | |
*** dims has joined #openstack-keystone | 12:43 | |
doxa | lbragstad: I'm looking into it now. | 12:45 |
*** bhagyashri_s has quit IRC | 12:48 | |
doxa | lbragstad: I'm sorry to bother. Where do I get that token ? I've used command "openstack token issue" and there I get 3 params id, project_id and user_id | 12:49 |
doxa | lbragstad: The problem is that the ID field is huge as length - 2 rows | 12:49 |
*** pooja-jadhav has joined #openstack-keystone | 12:49 | |
*** bhagyashri_s has joined #openstack-keystone | 12:49 | |
lbragstad | the ID in that response is a token | 12:49 |
Shilpa | lbragstad: basic query, i am on python novaclient and getting successful result for CLI 'nova --os-auth-type password --os-password admin list' command | 12:50 |
doxa | lbragstad: I'll make a curl test with that ID | 12:50 |
lbragstad | when you use `openstack token issue` the openstack client is taking your credentials (e.g. a user ID + password) and presenting them to keystone, if successful, keystone will return to you a token | 12:50 |
Shilpa | but for CLI 'nova --os-auth-type v3password --os-password admin list' and 'nova --os-auth-type v2password --os-password admin list', getting issue 'ERROR (AttributeError): 'Namespace' object has no attribute 'os_project_domain_id' | 12:51 |
Shilpa | For this i have made changes in python-novaclient in shell.py | 12:51 |
Shilpa | And able to overcome above said error | 12:51 |
*** pooja_jadhav has quit IRC | 12:52 | |
Shilpa | But now facing error for v2Password 'ERROR (NotFound): (http://10.232.48.204/identity/tokens): The resource could not be found. (HTTP 404)' | 12:52 |
*** belmoreira has quit IRC | 12:52 | |
Shilpa | And for v3Password 'ERROR (NotFound): (http://10.232.48.204/identity/auth/tokens): The resource could not be found. (HTTP 404)' | 12:52 |
Shilpa | Did i am missing any configuration here? | 12:52 |
*** bhagyashris_ has joined #openstack-keystone | 12:53 | |
lbragstad | Shilpa: you might need to make sure you have apache or uwsgi configured properly | 12:53 |
Shilpa | IMO its properly configured, for 'nova --os-auth-type password --os-password admin list' its Success, list is getting displyed on CLI | 12:54 |
*** gyan_ has quit IRC | 12:54 | |
lbragstad | do you have access to the keystone logs? | 12:55 |
Shilpa | yes | 12:55 |
*** bhagyashri_s has quit IRC | 12:55 | |
lbragstad | maybe try checking those if you haven't already? | 12:56 |
Shilpa | May 17 18:24:54 shilpa-VirtualBox devstack@keystone.service[9497]: [pid: 9502|app: 0|req: 65/129] 10.232.48.204 () {62 vars in 1415 bytes} [Thu May 17 18:24:54 2018] GET /identity/v3/auth/tokens => generated 4149 bytes in 44 msecs (HTTP/1.1 200) 6 headers in 380 bytes (1 switches on core 0) | 12:56 |
*** jmlowe has quit IRC | 12:56 | |
lbragstad | if that was a 200 - then it looks like your path wasn't properly configured | 12:57 |
lbragstad | you're getting a 404 because the path you're using is /identity/auth/tokens as opposed to /identity/v3/auth/tokens | 12:57 |
*** ispp has quit IRC | 12:58 | |
Shilpa | Sorry, it was for success, here are failure logs May 17 18:30:07 shilpa-VirtualBox devstack@keystone.service[9497]: [pid: 9502|app: 0|req: 67/133] 10.232.48.204 () {62 vars in 1075 bytes} [Thu May 17 18:30:07 2018] POST /identity/tokens => generated 133 bytes in 1 msecs (HTTP/1.1 404) 4 headers in 118 bytes (2 switches on core 0) | 13:00 |
*** goofie has joined #openstack-keystone | 13:02 | |
Shilpa | lbragstad: for v2 implementation in keystoneauth, path takes http://10.232.48.204/identity/tokens and for v3, it takes 'http://10.232.48.204/identity/auth/tokens' | 13:02 |
lbragstad | the implementation will pull the endpoint values depending on the auth url you have specified | 13:03 |
lbragstad | which is usually in an rc file, environment variable, or clouds.yaml depending on how/where you're storing that information | 13:03 |
lbragstad | if you find where that is, you can try and update OS_AUTH_URL to use 'http://10.232.48.204/identity/v3/auth/tokens' | 13:05 |
*** links has quit IRC | 13:09 | |
doxa | lbragstad: No luck with that long ID. I've tried now with master token taken from keystone.conf. I still get the authentication error. | 13:12 |
doxa | lbragstad: I am using Openstack queen with RDO install on centos | 13:12 |
*** mchlumsky has joined #openstack-keystone | 13:17 | |
*** panbalag has joined #openstack-keystone | 13:18 | |
*** panbalag has left #openstack-keystone | 13:20 | |
lbragstad | doxa: do you have access to the keystone logs? | 13:20 |
Shilpa | lbragstad: checked auth url is correct i.e. http://<ip address>/identity, but at keystoneauth side it should append '/v3/auth/tokens', but currently its appending only '/auth/token', so why this happening? | 13:28 |
*** gongysh has joined #openstack-keystone | 13:29 | |
lbragstad | Shilpa: i'm not sure, it likely depends on how you're configuring keystoneauth | 13:29 |
lbragstad | so you'll probably need to start by looking at your environment variables or an rc file that holds credentials | 13:30 |
*** belmoreira has joined #openstack-keystone | 13:31 | |
Shilpa | is it possible fo ryou to check in your environment and help me to find this where exactly i am missing, u need to run at python-novaclient, 'nova --os-auth-type v2password --os-password admin list and 'nova --os-auth-type v3password --os-password admin list' | 13:37 |
*** jmlowe has joined #openstack-keystone | 13:38 | |
lbragstad | i use clouds.yaml, but this is what i have in dev currently | 13:38 |
hrybacki | cmurphy: kmalloc not sure if this is related to what y'all were discussing yesterday but I saw they changed sphinx requirement revert being discussed: https://review.openstack.org/#/c/568248/ | 13:38 |
*** felipemonteiro has joined #openstack-keystone | 13:39 | |
lbragstad | Shilpa: http://paste.openstack.org/raw/721166/ | 13:39 |
Shilpa | Thank you, i have compared only diff is that i am missing section 'devstack-system-admin:', is it required? | 13:41 |
lbragstad | no - it's not required, it just a profile that i define | 13:42 |
lbragstad | it's* | 13:42 |
*** felipemonteiro has quit IRC | 13:46 | |
lbragstad | unless the python-novaclient bit is doing something with the auth url? | 13:48 |
*** ispp has joined #openstack-keystone | 13:50 | |
*** panbalag has joined #openstack-keystone | 13:52 | |
*** panbalag has left #openstack-keystone | 13:55 | |
Shilpa | that i am looking into, but as of now observed that at keystonauth side at https://github.com/openstack/keystoneauth/blob/master/keystoneauth1/identity/v3/base.py#L73 and https://github.com/openstack/keystoneauth/blob/master/keystoneauth1/identity/v2.py#L51, URL get created | 13:59 |
*** belmorei_ has joined #openstack-keystone | 14:00 | |
*** belmoreira has quit IRC | 14:01 | |
*** panbalag has joined #openstack-keystone | 14:02 | |
*** ispp has quit IRC | 14:31 | |
*** ispp has joined #openstack-keystone | 14:32 | |
*** spilla has joined #openstack-keystone | 14:46 | |
*** dklyle has joined #openstack-keystone | 14:54 | |
cmurphy | hrybacki: it's a different error but that revert might be why we saw it magically resolve itself | 14:57 |
*** panbalag has quit IRC | 15:03 | |
*** panbalag has joined #openstack-keystone | 15:07 | |
hrybacki | cmurphy: interesting. Well hopefully that data point is of use :) | 15:08 |
*** AlexeyAbashkin has quit IRC | 15:12 | |
*** AlexeyAbashkin has joined #openstack-keystone | 15:15 | |
hrybacki | knikolla: ping regarding default roles spec | 15:16 |
*** panbalag has left #openstack-keystone | 15:17 | |
openstackgerrit | Merged openstack/oslo.policy master: Include deprecated_reason when deprecated_rule is set https://review.openstack.org/568687 | 15:22 |
*** cz2 has quit IRC | 15:24 | |
cmurphy | fyi early bird pricing for the next ptg is ending today already http://lists.openstack.org/pipermail/openstack-dev/2018-May/130548.html | 15:27 |
*** panbalag has joined #openstack-keystone | 15:30 | |
*** ispp has quit IRC | 15:31 | |
*** germs has joined #openstack-keystone | 15:34 | |
*** germs has quit IRC | 15:34 | |
*** germs has joined #openstack-keystone | 15:34 | |
*** panbalag has quit IRC | 15:35 | |
*** ispp has joined #openstack-keystone | 15:37 | |
*** germs has quit IRC | 15:39 | |
*** germs has joined #openstack-keystone | 15:40 | |
*** germs has quit IRC | 15:40 | |
*** gyee has joined #openstack-keystone | 15:41 | |
*** germs has joined #openstack-keystone | 15:41 | |
*** germs has quit IRC | 15:41 | |
*** germs has joined #openstack-keystone | 15:41 | |
*** ispp has quit IRC | 15:41 | |
*** fiddletw_ has joined #openstack-keystone | 15:43 | |
*** fiddletw_ has quit IRC | 15:43 | |
*** fiddletwix has joined #openstack-keystone | 15:43 | |
*** dklyle has quit IRC | 15:43 | |
*** gongysh has quit IRC | 15:44 | |
*** dklyle has joined #openstack-keystone | 15:48 | |
*** fiddletwix has quit IRC | 15:49 | |
*** panbalag has joined #openstack-keystone | 15:50 | |
*** panbalag has left #openstack-keystone | 15:50 | |
*** cz2 has joined #openstack-keystone | 15:52 | |
*** germs has quit IRC | 15:57 | |
*** germs has joined #openstack-keystone | 15:58 | |
*** germs has quit IRC | 15:58 | |
*** germs has joined #openstack-keystone | 15:58 | |
*** germs has quit IRC | 15:58 | |
*** germs has joined #openstack-keystone | 15:59 | |
*** germs has quit IRC | 15:59 | |
*** germs has joined #openstack-keystone | 15:59 | |
*** felipemonteiro has joined #openstack-keystone | 16:02 | |
openstackgerrit | Felipe Monteiro proposed openstack/keystone-specs master: Patrole (RBAC) Keystone Gating https://review.openstack.org/464678 | 16:03 |
lbragstad | cmurphy: good call - thanks for the reminder | 16:05 |
*** felipemonteiro has quit IRC | 16:12 | |
*** jrist has quit IRC | 16:24 | |
kmalloc | Already bought the ticket. | 16:28 |
kmalloc | ;) | 16:28 |
knikolla | hrybacki: o/ | 16:29 |
gagehugo | tempted to grab a room on the off-chance they run out | 16:29 |
gagehugo | I don't think there was another hotel nearby | 16:29 |
knikolla | gagehugo: in denver? | 16:30 |
gagehugo | yea | 16:30 |
knikolla | there's a holiday inn 2 mins away | 16:30 |
* gagehugo memory is terrible | 16:30 | |
gagehugo | ah ok | 16:31 |
knikolla | if it's the same venue as last time, let me double check | 16:31 |
* lbragstad takes lunch real quick | 16:32 | |
knikolla | quality inn* not holiday inn | 16:33 |
gagehugo | oh yeah | 16:33 |
kmalloc | The hotel, if cancellation is good should be worth it. | 16:33 |
gagehugo | there was the shopping area next to it | 16:33 |
kmalloc | This far out should be ok. | 16:33 |
gagehugo | I'm still scarred from walking 30 mins in the snow in dublin | 16:34 |
*** tesseract has quit IRC | 16:38 | |
*** dklyle has quit IRC | 16:42 | |
hrybacki | knikolla o/ I just wanted to confirm that update_project_tags is or is not also an admin api? | 16:55 |
*** belmorei_ has quit IRC | 17:02 | |
*** AlexeyAbashkin has quit IRC | 17:04 | |
*** oikiki has joined #openstack-keystone | 17:08 | |
knikolla | hrybacki: it is an admin api https://github.com/openstack/keystone/blob/master/keystone/common/policies/project.py#L127-L130 | 17:16 |
*** oikiki has quit IRC | 17:24 | |
*** oikiki has joined #openstack-keystone | 17:31 | |
*** rmascena has joined #openstack-keystone | 17:33 | |
*** raildo has quit IRC | 17:35 | |
*** neha_alhat_ has joined #openstack-keystone | 17:41 | |
hrybacki | ack knikolla thanks | 17:54 |
*** felipemonteiro has joined #openstack-keystone | 17:54 | |
neha_alhat_ | modred Hi | 17:57 |
*** links has joined #openstack-keystone | 17:58 | |
neha_alhat_ | mordred: Hi | 17:59 |
neha_alhat_ | mordred: Thanks for this patch: https://review.openstack.org/#/c/568878. I was making same changes for registering 'split_loggers' conf option in keystoneauth | 18:02 |
*** fiddletw_ has joined #openstack-keystone | 18:04 | |
*** neha_alhat_ has quit IRC | 18:07 | |
*** links has quit IRC | 18:35 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Decouple bootstrap from cli module https://review.openstack.org/558903 | 18:38 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Introduce new TokenModel object https://review.openstack.org/559129 | 18:38 |
lbragstad | kmalloc: oh - most of the new code added in that model should be tested with the exception of oauth tokens and a case with app creds ^ | 18:39 |
lbragstad | i'm wondering if the usability of the new model is headed in the right direction though | 18:39 |
*** dklyle has joined #openstack-keystone | 18:56 | |
*** pcichy has joined #openstack-keystone | 19:01 | |
*** felipemonteiro__ has joined #openstack-keystone | 19:04 | |
*** felipemonteiro has quit IRC | 19:08 | |
kmalloc | lbragstad: cool | 19:15 |
kmalloc | lbragstad: thanks! | 19:15 |
devx | are there any requirements for running keystone with ADFS? ie does it require Apache or Nginx modules? or does it use python bindings? (sorry if my question is not clear) | 19:21 |
kmalloc | mordred: NIT on the timing code, a NamedTuple would have been my preference instead of a new object def. | 19:22 |
kmalloc | mordred: however... +2. | 19:22 |
kmalloc | lbragstad: ^ cc | 19:22 |
kmalloc | devx: there is a bunch of config needed to make it work, see https://docs.openstack.org/security-guide/identity/federated-keystone.html#enabling-federation as the starting point. | 19:23 |
kmalloc | devx: there are some folks here very familiar with SAML and ADFS with Keystone if you're running into stumbling blocks. | 19:23 |
devx | Thanks! and sorry i should of gone there first.. i'll be back when I get stuck :) | 19:24 |
kmalloc | devx: ADFS is (mostly) a SAML2 provider | 19:24 |
kmalloc | devx: no worries! I'd rather you ask than wander off frustrated. We're here to help | 19:24 |
kmalloc | if you find issues with the documentation, also let us know -- we'd like to make sure the docs are fixed if they are broken. | 19:25 |
kmalloc | or unclear. | 19:25 |
devx | I will, it's not a priority so it might take a me a bit to get through this setup :) | 19:25 |
*** jmlowe has quit IRC | 19:27 | |
kmalloc | devx: sounds good! :) | 19:29 |
kmalloc | devx: and good luck! | 19:29 |
kmalloc | mordred: https://review.openstack.org/#/c/568877/2 if you want to make that a NamedTuple, we can do so before release. | 19:36 |
kmalloc | mordred: if not, we can just let it ride as an object | 19:36 |
*** jrist has joined #openstack-keystone | 19:36 | |
lbragstad | kmalloc: no problem - just curious about the ergonomics of the whole model... | 19:36 |
lbragstad | it feels pretty heavy | 19:36 |
lbragstad | (not sure if that is the right word) | 19:36 |
lbragstad | but at the same time, it's modeling a pretty complex object | 19:37 |
kmalloc | yeah | 19:37 |
lbragstad | so maybe that's ok? | 19:37 |
kmalloc | i would love to simplify it. | 19:37 |
kmalloc | that said, we have a ${HISTORY} that makes it impossible | 19:37 |
lbragstad | idk - like the whole token.user_id when using a trust for example and having token.trustee | 19:37 |
kmalloc | yeah, it's tough. | 19:38 |
lbragstad | also | 19:39 |
*** felipemonteiro__ has quit IRC | 19:39 | |
lbragstad | we have a mint() method | 19:39 |
*** felipemonteiro has joined #openstack-keystone | 19:39 | |
lbragstad | but i wonder if there is a better way to expose methods that make the interactions with the model flow better? | 19:39 |
lbragstad | you wouldn't re-mint a method in the validation process | 19:39 |
lbragstad | s/method/token/ | 19:40 |
kmalloc | well validate implicitly mints by supplying the needed information | 19:41 |
lbragstad | yeah | 19:43 |
*** jrist has quit IRC | 19:48 | |
*** jrist has joined #openstack-keystone | 19:51 | |
cmurphy | kmalloc: don't link the security guide docs, they're super out of date :( devx: try this https://docs.openstack.org/keystone/latest/advanced-topics/federation/federated_identity.html | 19:51 |
kmalloc | cmurphy: ah crap, wrong link. | 19:54 |
kmalloc | cmurphy: thanks | 19:54 |
kmalloc | cmurphy: can we make a bug to fix that | 19:54 |
kmalloc | :P | 19:54 |
kmalloc | i had both open | 19:54 |
kmalloc | clicked the wrong one w/ control+c :) | 19:54 |
cmurphy | they also come up first in google searches | 19:55 |
kmalloc | yeah. | 19:55 |
kmalloc | we should fix that, maybe a 301 or some such | 19:55 |
kmalloc | or at least get the security docs to point to the right place | 19:55 |
cmurphy | ya figuring out what needs to be done to fix it is somewhere deep in my todo list... | 19:56 |
kmalloc | cool. lets make sure we get a bug open in LP ;) | 19:56 |
kmalloc | maybe someone else will jump on it | 19:56 |
kmalloc | doc bugs are funny like that | 19:56 |
*** pcichy has quit IRC | 19:57 | |
*** jmlowe has joined #openstack-keystone | 19:57 | |
cmurphy | kmalloc: here https://bugs.launchpad.net/ossn/+bug/1771884 | 20:03 |
openstack | Launchpad bug 1771884 in OpenStack Security Notes "Keystone guide is out of date" [Undecided,New] | 20:03 |
kmalloc | cmurphy: ++ THANKS! :) | 20:08 |
kmalloc | cmurphy: you rock | 20:08 |
*** jmlowe has quit IRC | 20:22 | |
*** rmascena has quit IRC | 20:44 | |
openstackgerrit | Merged openstack/keystoneauth master: Collect timing information for API calls https://review.openstack.org/568877 | 21:06 |
openstackgerrit | Merged openstack/keystoneauth master: Add oslo.config option for split-loggers https://review.openstack.org/568878 | 21:06 |
openstackgerrit | Merged openstack/keystoneauth master: Expose version_between as a real function https://review.openstack.org/568640 | 21:06 |
*** martinus__ has quit IRC | 21:18 | |
*** felipemonteiro has quit IRC | 21:28 | |
*** felipemonteiro has joined #openstack-keystone | 21:28 | |
*** felipemonteiro has quit IRC | 21:28 | |
*** felipemonteiro has joined #openstack-keystone | 21:28 | |
*** edmondsw has quit IRC | 21:46 | |
*** rcernin has joined #openstack-keystone | 22:04 | |
*** felipemonteiro has quit IRC | 22:20 | |
*** oikiki has quit IRC | 22:35 | |
*** threestrands has joined #openstack-keystone | 22:37 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Introduce new TokenModel object https://review.openstack.org/559129 | 22:37 |
*** d34dh0r53 has quit IRC | 22:47 | |
*** d34dh0r53 has joined #openstack-keystone | 22:47 | |
*** cloudnull has quit IRC | 22:48 | |
*** eglute has quit IRC | 22:48 | |
*** cloudnull has joined #openstack-keystone | 22:48 | |
*** eglute has joined #openstack-keystone | 22:49 | |
*** spilla has quit IRC | 22:51 | |
*** spilla has joined #openstack-keystone | 22:52 | |
*** spilla has quit IRC | 22:56 | |
*** panbalag has joined #openstack-keystone | 23:00 | |
*** panbalag has left #openstack-keystone | 23:00 | |
*** edmondsw has joined #openstack-keystone | 23:03 | |
*** edmondsw has quit IRC | 23:08 | |
*** edmondsw has joined #openstack-keystone | 23:46 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!