*** gyee has quit IRC | 00:55 | |
*** felipemonteiro has joined #openstack-keystone | 01:19 | |
*** ayoung has quit IRC | 01:29 | |
openstackgerrit | wangxiyuan proposed openstack/keystone master: nit: remove some useless code https://review.openstack.org/612625 | 01:31 |
---|---|---|
*** Dinesh_Bhor has joined #openstack-keystone | 01:49 | |
*** felipemonteiro has quit IRC | 02:33 | |
*** markvoelker has joined #openstack-keystone | 02:45 | |
*** markvoelker has quit IRC | 02:45 | |
*** markvoelker has joined #openstack-keystone | 02:45 | |
*** markvoelker has quit IRC | 02:50 | |
*** felipemonteiro has joined #openstack-keystone | 02:55 | |
*** markvoelker has joined #openstack-keystone | 02:55 | |
*** fungi has quit IRC | 03:06 | |
*** erus has joined #openstack-keystone | 03:06 | |
*** fungi has joined #openstack-keystone | 03:09 | |
*** fungi has quit IRC | 03:10 | |
openstackgerrit | Merged openstack/keystone master: Add abstract method in trusts base.py https://review.openstack.org/614716 | 03:34 |
*** felipemonteiro has quit IRC | 03:35 | |
*** felipemonteiro has joined #openstack-keystone | 03:36 | |
*** Dinesh_Bhor has quit IRC | 03:38 | |
*** fungi has joined #openstack-keystone | 03:40 | |
*** fungi has quit IRC | 03:41 | |
*** fungi has joined #openstack-keystone | 03:45 | |
openstackgerrit | Merged openstack/keystone master: Remove redundant variables from context class https://review.openstack.org/616198 | 03:48 |
*** sapd1 has quit IRC | 03:58 | |
*** sapd1 has joined #openstack-keystone | 03:58 | |
*** felipemonteiro has quit IRC | 04:11 | |
*** Dinesh_Bhor has joined #openstack-keystone | 04:42 | |
*** Dinesh_Bhor has quit IRC | 05:15 | |
*** Dinesh_Bhor has joined #openstack-keystone | 05:20 | |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Remove "crypt_strength" option https://review.openstack.org/613218 | 06:23 |
openstackgerrit | Morgan Fainberg proposed openstack/keystone master: Drop the compatibility password column https://review.openstack.org/613513 | 06:23 |
*** pcaruana has joined #openstack-keystone | 07:34 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remove deprecated "bind" in token https://review.openstack.org/613891 | 07:43 |
*** bnemec has quit IRC | 08:00 | |
*** Dinesh_Bhor has quit IRC | 08:11 | |
*** Dinesh_Bhor has joined #openstack-keystone | 08:12 | |
*** amoralej|off is now known as amoralej | 08:18 | |
*** sapd1 has quit IRC | 08:20 | |
*** sapd1 has joined #openstack-keystone | 08:20 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Update more info of vhost file https://review.openstack.org/616457 | 08:26 |
*** bnemec has joined #openstack-keystone | 08:26 | |
vishakha | cmurphy: Hello. I was doing K2K federation, in which I logged in the horizon of my IDP and tried switching to my SP through drop down but getting unauthorized. I am not able to get the issue. These are the logs I am getting. | 08:47 |
vishakha | https://www.irccloud.com/pastebin/m9MqcoB0/ | 08:47 |
*** sapd1_ has joined #openstack-keystone | 08:47 | |
cmurphy | vishakha: you'll have to turn on insecure_debug in keystone.conf to get it to tell you why you're not authorized | 08:48 |
vishakha | cmurphy: sure | 08:48 |
vishakha | cmurphy: I will do that | 08:48 |
*** sapd1 has quit IRC | 08:49 | |
vishakha | cmurphy: it is not accepting the idp token | 09:06 |
vishakha | https://www.irccloud.com/pastebin/Lafw7kEC/ | 09:06 |
cmurphy | vishakha: "auth_context did not decode anything useful" I think that means it couldn't process the assertion from the apache service provider | 09:08 |
cmurphy | vishakha: these logs are from the SP right? | 09:08 |
vishakha | cmurphy: No from IDP | 09:08 |
cmurphy | vishakha: oh okay, maybe check the logs on the SP too to see if there is more information | 09:09 |
cmurphy | some things it could be off the top of my head are 1) the user attributes aren't being passed through by mod_shib, you can check the shibd logs on the SP to see if there are warnings 2) the mapping rules are wrong | 09:10 |
cmurphy | vishakha: are you using shibboleth or mellon for the SP? | 09:11 |
vishakha | cmurphy: shibboleth | 09:11 |
cmurphy | okay | 09:11 |
vishakha | cmurphy: these are from sp | 09:14 |
vishakha | https://www.irccloud.com/pastebin/nh10MxMo/ | 09:14 |
cmurphy | hmm that all looks normal | 09:16 |
*** BlackDex has quit IRC | 09:20 | |
cmurphy | vishakha: do you have a log from 14:34 for the SP? that's when I see the unauthorized message on the IdP | 09:20 |
*** BlackDex has joined #openstack-keystone | 09:25 | |
cmurphy | vishakha: so my strategy would be first to get a correlation between the two keystone logs and see exactly what was happening on each of them at the time you're trying to switch the SP, then also look for error logs in /var/log/shibboleth/shibd.log and /var/log/shibboleth/shibd_warn.log on the SP, and also check for apache errors in /var/log/apache2/error.log on the SP, and also if you have | 09:26 |
cmurphy | horizon set up on the SP you might need to check /var/log/apache2/horizon_error.log because for some reason generic error logs get directed there on devstack sometimes | 09:26 |
vishakha | cmurphy: yes I understand. | 09:28 |
vishakha | cmurphy: I think i will quickly reproduce the issue again and will store all the logs in the above mentioned files | 09:29 |
cmurphy | vishakha: sounds good | 09:30 |
vishakha | cmurphy: these are new idp logs | 09:40 |
vishakha | https://www.irccloud.com/pastebin/fr0dwLWS/ | 09:40 |
vishakha | These are SP logs | 09:41 |
vishakha | https://www.irccloud.com/pastebin/T48F4gLb/ | 09:41 |
cmurphy | hmm still looks normal on the SP side | 09:43 |
vishakha | https://www.irccloud.com/pastebin/1uBgKwOj/ | 09:43 |
cmurphy | I wonder if the new rbacenforcer broke this | 09:43 |
vishakha | cmurphy: I am also wondering, because I am not able to find the solution | 09:45 |
vishakha | cmurphy: I got no log in shibd_warm | 09:45 |
vishakha | s/warm/warn | 09:46 |
cmurphy | it's definitely weird because if there's an authorization problem it would usually be on the service provider | 09:46 |
cmurphy | i'm gonna try to reproduce | 09:46 |
vishakha | cmurphy: Thanks. Pl let me know for any more info. I am also looking for same | 09:47 |
cmurphy | vishakha: by the way we got samltest.id to work instead of testshib.org in case you still want to pursue setting up keystone with an external idp | 09:50 |
vishakha | Also no logs in apache2/error | 09:50 |
vishakha | cmurphy: Yes I am going to setup with samltest.id soon | 09:51 |
*** sapd1_ has quit IRC | 09:55 | |
*** mvkr has quit IRC | 09:58 | |
*** sapd1_ has joined #openstack-keystone | 10:05 | |
*** jrist has quit IRC | 10:14 | |
*** jrist has joined #openstack-keystone | 10:16 | |
*** mvkr has joined #openstack-keystone | 10:26 | |
*** Emine has joined #openstack-keystone | 10:32 | |
*** mbuil has joined #openstack-keystone | 11:21 | |
mbuil | cmurphy: hello, I need a bit of extra help with keystone federation. ping me when you have 5 minutes please :) | 11:22 |
*** xek__ is now known as xek | 12:02 | |
cmurphy | hi mbuil what's up? | 12:03 |
*** emine__ has joined #openstack-keystone | 12:08 | |
*** Emine has quit IRC | 12:11 | |
*** raildo has joined #openstack-keystone | 12:17 | |
*** Dinesh_Bhor has quit IRC | 12:43 | |
*** emine__ has quit IRC | 13:00 | |
*** emine__ has joined #openstack-keystone | 13:00 | |
mbuil | cmurphy: I deployed keystone federation again and I had one question but I found the answer in your blog ;) | 13:07 |
cmurphy | vishakha: hmm i didn't reproduce, it works okay for me | 13:07 |
cmurphy | mbuil: haha cool | 13:07 |
cmurphy | vishakha: maybe try with the cli instead of horizon? | 13:09 |
cmurphy | vishakha: I think it must be related to this 'TokenNotFound: Could not recognize Fernet token' but I don't know offhand what would be wrong with the token | 13:19 |
mbuil | cmurphy: one question, if I use export OS_TOKEN=token_id and export OS_URL=Service_endpoint, what should I remove from openrc? | 13:23 |
cmurphy | mbuil: everything except perhaps OS_IDENTITY_API_VERSION | 13:24 |
mbuil | cmurphy: I've got this right now ==> https://hastebin.com/avunufovay.bash | 13:24 |
cmurphy | mbuil: almost all the OS_ variables will conflict if you try to use them with OS_TOKEN/OS_URL | 13:25 |
cmurphy | the nova and cinder ones are probably fine | 13:25 |
vishakha | cmurphy: thank you . I will try that with CLI. One thing I wanted to confirm can it be a issue with my configuration also? I mean I just wanted to be sure that whatever I have changed in the configs files is good to go? | 13:26 |
mbuil | cmurphy: ok. I am getting ==> __init__() got an unexpected keyword argument 'token'. I'll comment all | 13:26 |
cmurphy | mbuil: yeah setting OS_AUTH_TYPE=password will confuse it when you try to pass it OS_TOKEN | 13:27 |
cmurphy | vishakha: it might be a configuration issue but I'm not sure what it would be, assuming you followed the docs | 13:27 |
vishakha | cmurphy: Yes I have followed the docs | 13:27 |
cmurphy | vishakha: there would usually be more information in the logs if it was a config issue | 13:27 |
cmurphy | or warnings in the shib logs if that was misconfigured | 13:28 |
vishakha | cmurphy: ok. Thank you for the early responses. I will check with CLI once. | 13:28 |
vishakha | cmurphy: no warnings logs for now | 13:29 |
*** _cryptosignal_me has joined #openstack-keystone | 13:42 | |
*** aojea_ has joined #openstack-keystone | 13:48 | |
*** aojea_ has quit IRC | 14:02 | |
*** bnemec has quit IRC | 14:02 | |
*** kukacz has quit IRC | 14:02 | |
*** jaosorior has quit IRC | 14:02 | |
*** tonyb has quit IRC | 14:02 | |
*** dmellado has quit IRC | 14:02 | |
*** mattoliverau has quit IRC | 14:02 | |
*** rook has quit IRC | 14:02 | |
*** dmellado has joined #openstack-keystone | 14:04 | |
*** kukacz has joined #openstack-keystone | 14:04 | |
*** aojea_ has joined #openstack-keystone | 14:04 | |
*** ebukha has joined #openstack-keystone | 14:04 | |
*** tonyb has joined #openstack-keystone | 14:07 | |
*** bnemec has joined #openstack-keystone | 14:07 | |
*** jaosorior has joined #openstack-keystone | 14:08 | |
*** jmlowe has quit IRC | 14:12 | |
*** ebukha has quit IRC | 14:35 | |
*** emine__ has quit IRC | 14:53 | |
*** _cryptosignal_me has quit IRC | 14:55 | |
*** Emine has joined #openstack-keystone | 15:02 | |
lbragstad | o/ | 15:03 |
cmurphy | \o | 15:03 |
lbragstad | do folks know what days they'll be getting into and leaving Berlin? | 15:04 |
lbragstad | I get in sometime on saturday afternoon | 15:04 |
*** mvkr has quit IRC | 15:04 | |
*** jmlowe has joined #openstack-keystone | 15:04 | |
* cmurphy sunday morning -> friday morning | 15:04 | |
*** ebukha has joined #openstack-keystone | 15:06 | |
lbragstad | i'm leaving on saturday | 15:07 |
*** mvkr has joined #openstack-keystone | 15:20 | |
*** jmlowe has quit IRC | 15:22 | |
*** erus has quit IRC | 15:30 | |
*** erus has joined #openstack-keystone | 15:32 | |
*** mchlumsky has joined #openstack-keystone | 15:35 | |
*** mchlumsky has quit IRC | 15:35 | |
*** erus has quit IRC | 15:54 | |
*** aojea_ has quit IRC | 15:56 | |
*** aojea_ has joined #openstack-keystone | 15:56 | |
*** aojea_ has quit IRC | 15:58 | |
*** aojea_ has joined #openstack-keystone | 15:58 | |
*** ebukha has quit IRC | 16:02 | |
*** aojea_ has quit IRC | 16:03 | |
*** aojea_ has joined #openstack-keystone | 16:09 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Refactor directory creation into a common place https://review.openstack.org/615314 | 16:10 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add keystone-manage jwt_setup functionality https://review.openstack.org/615315 | 16:10 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add test fixture for JWT key repository https://review.openstack.org/614547 | 16:10 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add PyJWT as a requirement https://review.openstack.org/614548 | 16:10 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement JSON Web Token provider https://review.openstack.org/614549 | 16:10 |
*** pcaruana has quit IRC | 16:14 | |
*** mvkr has quit IRC | 16:16 | |
*** dklyle has quit IRC | 16:17 | |
*** imacdonn has quit IRC | 16:17 | |
*** erus has joined #openstack-keystone | 16:17 | |
*** imacdonn has joined #openstack-keystone | 16:18 | |
*** gyee has joined #openstack-keystone | 16:18 | |
*** dklyle has joined #openstack-keystone | 16:23 | |
*** mvkr has joined #openstack-keystone | 16:28 | |
kmalloc | I'll be arriving in Berlin on ... Monday, I think let me check | 17:04 |
*** erus has quit IRC | 17:05 | |
*** erus has joined #openstack-keystone | 17:08 | |
kmalloc | yeah | 17:08 |
*** nicolasbock_ has joined #openstack-keystone | 17:09 | |
kmalloc | i leave saturday super early (after the summit) | 17:09 |
kmalloc | cmurphy: i responded to the domains refactor. | 17:11 |
*** erus has quit IRC | 17:11 | |
kmalloc | cmurphy: it's different in that it combines some logic but the params are optional | 17:12 |
kmalloc | so it functions the same as previous. it's fine if we want to isolate and explicitly override with the previous code. not a big deal | 17:12 |
*** erus has joined #openstack-keystone | 17:14 | |
*** irclogbot_1 has quit IRC | 17:31 | |
*** aojea_ has quit IRC | 17:35 | |
*** mvkr has quit IRC | 17:35 | |
cmurphy | kmalloc: the docstring is wrong though | 18:00 |
*** irclogbot_1 has joined #openstack-keystone | 18:00 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add keystone-manage jwt_setup functionality https://review.openstack.org/615315 | 18:01 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add test fixture for JWT key repository https://review.openstack.org/614547 | 18:01 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add PyJWT as a requirement https://review.openstack.org/614548 | 18:01 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement JSON Web Token provider https://review.openstack.org/614549 | 18:01 |
*** irclogbot_1 has quit IRC | 18:05 | |
*** pcaruana has joined #openstack-keystone | 18:10 | |
*** aojea_ has joined #openstack-keystone | 18:15 | |
kmalloc | cmurphy: yeah | 18:17 |
kmalloc | cmurphy: and that we should totally fix if we're not keeping it separate | 18:17 |
*** amoralej is now known as amoralej|off | 18:19 | |
*** ebukha has joined #openstack-keystone | 18:23 | |
*** irclogbot_1 has joined #openstack-keystone | 18:25 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/oslo.policy master: Add ability for policy-checker to read configuration https://review.openstack.org/616659 | 18:27 |
cmurphy | kmalloc: knikolla want to sync up again on outreachy? | 18:30 |
*** jmlowe has joined #openstack-keystone | 18:31 | |
*** irclogbot_1 has quit IRC | 18:32 | |
*** irclogbot_1 has joined #openstack-keystone | 18:35 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/oslo.policy master: Add ability for policy-checker to read configuration https://review.openstack.org/616659 | 18:35 |
*** Emine has quit IRC | 18:40 | |
*** aojea_ has quit IRC | 18:44 | |
kmalloc | cmurphy: sure in a few mins | 18:58 |
kmalloc | like 5 sound good? | 18:58 |
cmurphy | kmalloc: sure | 18:59 |
*** jmlowe has quit IRC | 18:59 | |
kmalloc | cmurphy: same bluejeans link | 19:04 |
kmalloc | can supply it again if needed | 19:04 |
*** Emine has joined #openstack-keystone | 19:04 | |
*** aojea_ has joined #openstack-keystone | 19:17 | |
*** Emine has quit IRC | 19:18 | |
*** jmlowe has joined #openstack-keystone | 19:26 | |
*** ebukha has quit IRC | 19:35 | |
*** aojea_ has quit IRC | 19:49 | |
*** dave-mccowan has joined #openstack-keystone | 19:56 | |
*** dave-mccowan has quit IRC | 20:33 | |
*** raildo has quit IRC | 20:37 | |
*** jmlowe has quit IRC | 20:38 | |
*** aojea has joined #openstack-keystone | 20:41 | |
*** dklyle has quit IRC | 20:45 | |
*** dklyle has joined #openstack-keystone | 20:45 | |
*** dklyle has quit IRC | 20:46 | |
*** jmlowe has joined #openstack-keystone | 21:05 | |
*** erus has quit IRC | 21:11 | |
*** erus has joined #openstack-keystone | 21:13 | |
*** aojea has quit IRC | 21:14 | |
*** nicolasbock_ has quit IRC | 21:32 | |
*** Emine has joined #openstack-keystone | 21:36 | |
*** aojea has joined #openstack-keystone | 21:47 | |
*** aojea has quit IRC | 21:58 | |
*** aojea has joined #openstack-keystone | 21:59 | |
*** mattoliverau has joined #openstack-keystone | 22:06 | |
*** Emine has quit IRC | 22:14 | |
*** Emine has joined #openstack-keystone | 22:41 | |
*** Emine has quit IRC | 23:06 | |
*** dklyle has joined #openstack-keystone | 23:44 | |
*** aojea has quit IRC | 23:50 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!