*** mvkr has joined #openstack-keystone | 00:12 | |
openstackgerrit | Ian Wienand proposed openstack/keystoneauth master: Fair semaphore fixes https://review.openstack.org/616717 | 00:16 |
---|---|---|
*** gyee has quit IRC | 00:16 | |
*** pcaruana has quit IRC | 00:25 | |
openstackgerrit | Monty Taylor proposed openstack/keystoneauth master: Add support for client-side rate limiting https://review.openstack.org/605043 | 00:27 |
*** Dinesh_Bhor has joined #openstack-keystone | 01:03 | |
*** Dinesh_Bhor has quit IRC | 01:25 | |
*** Dinesh_Bhor has joined #openstack-keystone | 01:31 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Update more info of vhost file https://review.openstack.org/616457 | 01:49 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remove deprecated "bind" in token https://review.openstack.org/613891 | 01:53 |
*** jrist has quit IRC | 02:30 | |
*** jrist has joined #openstack-keystone | 02:43 | |
openstackgerrit | 98k proposed openstack/ldappool master: Add python 3.6 unit test job https://review.openstack.org/616739 | 02:54 |
*** Dinesh_Bhor has quit IRC | 03:17 | |
*** Dinesh_Bhor has joined #openstack-keystone | 03:20 | |
*** aojea has joined #openstack-keystone | 03:24 | |
*** aojea has quit IRC | 03:29 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Update api-ref for set registered limits. https://review.openstack.org/616755 | 03:37 |
openstackgerrit | Merged openstack/keystone master: Replace usage of get_legacy_facade() with get_engine() https://review.openstack.org/615749 | 03:46 |
openstackgerrit | Merged openstack/keystone master: Change __all__ list to tuple https://review.openstack.org/616364 | 03:47 |
*** Dinesh_Bhor has quit IRC | 04:08 | |
*** Dinesh_Bhor has joined #openstack-keystone | 04:40 | |
*** openstackstatus has quit IRC | 04:59 | |
*** openstack has joined #openstack-keystone | 07:07 | |
*** ChanServ sets mode: +o openstack | 07:07 | |
*** pcaruana has joined #openstack-keystone | 07:21 | |
*** ebukha has quit IRC | 07:54 | |
*** trident has quit IRC | 08:12 | |
*** trident has joined #openstack-keystone | 08:14 | |
mbuil | vishakha: are you trying to deploy K2K federation? | 08:51 |
cmurphy | vishakha: yes that's helpful, that says Unauthorized: User 099285cabca64ca68037d15f765536aa has no access to project 8d5c2f4c615941cc8f7a8969b3618445 | 08:57 |
cmurphy | which wasn't showing up in the logs yesterday | 08:57 |
cmurphy | vishakha: double check that the group you created for federated users has a role assignment on that project | 08:58 |
vishakha | cmurphy: Yes I also saw that error. Let me check once again | 08:58 |
vishakha | mbuil: Yes | 08:59 |
mbuil | cmurphy: When doing K2K federation, why we don‘t need shibboleth in the IdP side. Does keystone already include code to handle SAML2 in IdP? | 09:00 |
cmurphy | mbuil: yes it does http://git.openstack.org/cgit/openstack/keystone/tree/keystone/federation/idp.py | 09:01 |
mbuil | cmurphy: ah ok thanks. Is anyone trying to do the same for SP? Is Shibboleth going to disappear from the picture? | 09:03 |
cmurphy | mbuil: it's in the backlog http://specs.openstack.org/openstack/keystone-specs/specs/keystone/backlog/native-saml.html | 09:03 |
mbuil | cmurphy: thanks!! | 09:03 |
cmurphy | possibly one of my outreachy interns might be able to start work on it in the next few months | 09:04 |
cmurphy | mbuil: what's your interest in getting rid of the shibboleth sp? | 09:05 |
mbuil | cmurphy: I was just curious, no reason :) | 09:06 |
cmurphy | :) | 09:06 |
vishakha | cmurphy: I got the token after giving admin role to group in thar project | 09:11 |
vishakha | s/thar/that | 09:11 |
cmurphy | vishakha: awesome | 09:12 |
*** Emine has joined #openstack-keystone | 09:18 | |
cmurphy | vishakha: so check again if it works in horizon, if it doesn't you can turn up the debug logging in logging -> handlers -> console -> level in horizon's local_settings.py which might give more information | 09:20 |
vishakha | cmurphy: Now I can use this token on SP to create instances right? | 09:20 |
cmurphy | vishakha: yes | 09:21 |
vishakha | cmurphy: I moved to SP Horizon through drop down and I tried to list volumes, But n side its showing unable to retrieve volume list | 09:22 |
cmurphy | vishakha: hmm well if the SP dropdown worked then that sounds like keystone is working at least :) | 09:24 |
vishakha | cmurphy: yes it is :) | 09:24 |
vishakha | cmurphy: thank you | 09:24 |
cmurphy | you're welcome | 09:24 |
cmurphy | vishakha: are you going to be in Berlin next week? | 09:25 |
vishakha | cmurphy: No . My session wasn't selected. | 09:25 |
cmurphy | vishakha: ah too bad :( | 09:26 |
vishakha | cmurphy: Have a safe travel | 09:27 |
cmurphy | thanks :) | 09:27 |
*** Dinesh_Bhor has quit IRC | 09:34 | |
*** Dinesh_Bhor has joined #openstack-keystone | 09:57 | |
*** Dinesh_Bhor has quit IRC | 10:01 | |
openstackgerrit | Merged openstack/keystone master: Remove deprecated "bind" in token https://review.openstack.org/613891 | 11:21 |
*** raildo has joined #openstack-keystone | 11:22 | |
*** ebukha has joined #openstack-keystone | 12:23 | |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/oslo.policy master: WIP: Create OPA check https://review.openstack.org/614224 | 12:36 |
openstackgerrit | Juan Antonio Osorio Robles proposed openstack/oslo.policy master: Create OPA check https://review.openstack.org/614224 | 12:38 |
honza | What is morgan fainberg's irc nick? does he usually hang out here? | 12:59 |
honza | hm, github says he's in seattle so it might be too early still | 13:02 |
cmurphy | honza: his nick is kmalloc and yes it's a little early for him right now | 13:03 |
honza | cmurphy: perfect, thanks | 13:06 |
*** Dinesh_Bhor has joined #openstack-keystone | 13:18 | |
*** ebukha has quit IRC | 13:24 | |
*** Dinesh_Bhor has quit IRC | 13:34 | |
*** ebukha has joined #openstack-keystone | 13:41 | |
*** aojea_ has joined #openstack-keystone | 14:01 | |
*** Emine has quit IRC | 14:11 | |
lbragstad | o/ | 14:26 |
cmurphy | \o | 14:28 |
mbuil | cmurphy: I have the K2K federation working in CLI but I still get problems with horizon. When switching to "mysp" in Horizon, I see these logs in IdP's keystone_access.log: https://hastebin.com/kesecakozu.bash apparently, everything seems correct and Horizon(?) gets the SAML Response, or? | 14:34 |
cmurphy | mbuil: I don't see anything wrong there, what's the error you're seeing in horizon? | 14:38 |
openstackgerrit | Merged openstack/keystone master: Add a test for idp and federated user cascade deleting https://review.openstack.org/591946 | 14:41 |
mbuil | Error: "Switching to Keystone Provider mysp has failed. Service provider authentication failed. An error occurred authenticating. Please try again layer." | 14:41 |
cmurphy | mbuil: do the keystone logs on the SP have anything? | 14:42 |
mbuil | cmurphy ^. I can't see anything happening in the logs of the SP... how is the flow? Once Horizon gets the SAML Response, it should contact the SP's keystone? | 14:42 |
lbragstad | looks like keystone's operator feedback is at the same time as https://www.openstack.org/summit/berlin-2018/summit-schedule/events/22785/change-of-ownership-of-resources | 14:44 |
cmurphy | mbuil: yeah the horizon server should contact the keystone SP directly | 14:47 |
mbuil | cmurphy: ok, thanks. I think it is a connectivity issue | 14:47 |
*** aojea_ has quit IRC | 14:49 | |
cmurphy | lbragstad: sadness, I was planning on going to that | 14:52 |
cmurphy | lbragstad: the resource deletion one is on a different day though, I think that's more relevant to us | 14:52 |
lbragstad | yeah... we might have to divide and conquer | 14:52 |
lbragstad | i have the other one on my schedule for sure | 14:52 |
honza | kmalloc: hey, i noticed you worked on the flaskification of the keystone server --- i was hoping you could help me with a bug; i'm getting a 500 error on OPTIONS when requesting a new token | 14:55 |
honza | kmalloc: here is the bug report, note especially the one comment before last https://bugs.launchpad.net/tripleo/+bug/1801778 | 14:56 |
openstack | Launchpad bug 1801778 in tripleo "Keystone circular reference on OPTIONS" [High,Triaged] | 14:56 |
honza | kmalloc: any and all pointers would be much appreciated | 14:56 |
*** aojea_ has joined #openstack-keystone | 14:58 | |
*** lbragstad has quit IRC | 15:02 | |
*** lbragstad has joined #openstack-keystone | 15:03 | |
*** ChanServ sets mode: +o lbragstad | 15:03 | |
*** Emine has joined #openstack-keystone | 15:31 | |
kmalloc | lbragstad: change of ownership is easy imo. Services are allowed to do so if they want. Keystone does not allow rehoming resources. | 15:39 |
kmalloc | Because moving projects is bad news with inheritance | 15:39 |
kmalloc | Of roles. | 15:39 |
lbragstad | yeah - i was more or less just curious to be in the room | 15:40 |
lbragstad | i like being a fly on the wall | 15:40 |
kmalloc | honza: there is an error in keystone somewhere. The 500 is because rbac enforcement isn't called when that error happens. Request processing is probably a red herring in this case. | 15:40 |
kmalloc | A side effect, not the root cause. | 15:41 |
kmalloc | It also means whatever issue is occuring was never tested in keystone, so it realistically is broken due to lack of direct testing on merges. | 15:42 |
honza | kmalloc: any tips on finding the root cause? dig through logs some more? with the new flask stuff, do we need to change the way we do cors requests? | 15:42 |
kmalloc | I'll have to go look when I am more awake | 15:43 |
honza | kmalloc: thanks | 15:43 |
kmalloc | I just woke up 1m ago | 15:43 |
honza | kmalloc: https://media.giphy.com/media/DrJm6F9poo4aA/giphy.gif | 15:44 |
kmalloc | Yup | 15:50 |
*** bnemec is now known as beekneemech | 15:53 | |
mbuil | cmurphy: I fixed the connectivity problem and now I see "You are not authorized to access this page" when switching to mysp | 15:54 |
cmurphy | mbuil: as in it doesn't let you switch, or as in after you've switched some page elements aren't accessible? | 15:55 |
mbuil | cmurphy: it does not allow to switch. I mean, I did what is shown at the bottom of http://www.gazlene.net/demystifying-keystone-federation.html#Keystone%20to%20Keystone and now it shows mysp instead of Local Keystone. Hoever, that message appears and then a "Log in" | 15:59 |
*** jistr is now known as jistr|call | 16:00 | |
cmurphy | mbuil: like this? http://www.gazlene.net/horizon.png | 16:08 |
mbuil | cmurphy: exactly that | 16:08 |
cmurphy | mbuil: do you have a full openstack running on the service provider? nova glance etc? or just keystone? | 16:09 |
mbuil | cmurphy: everything | 16:09 |
cmurphy | i think that's normal if you're just running keystone and you don't have an admin role | 16:09 |
cmurphy | not sure about that then | 16:10 |
cmurphy | might still be a permission issue | 16:10 |
mbuil | cmurphy: Ok. I need to fix my networking issues permanently first. I did a hack and it does not work always :P. Then, I'll investigate further | 16:11 |
*** ayoung has joined #openstack-keystone | 16:12 | |
*** lbragstad has quit IRC | 16:14 | |
*** lbragstad has joined #openstack-keystone | 16:15 | |
*** ChanServ sets mode: +o lbragstad | 16:15 | |
*** jistr|call is now known as jistr | 16:17 | |
*** imacdonn has quit IRC | 16:18 | |
*** aojea_ has quit IRC | 16:20 | |
*** aojea_ has joined #openstack-keystone | 16:21 | |
*** etp has quit IRC | 16:21 | |
*** gyee has joined #openstack-keystone | 16:22 | |
openstackgerrit | Colleen Murphy proposed openstack/keystone master: [WIP] Add introduction section to federation docs https://review.openstack.org/615384 | 16:23 |
*** etp has joined #openstack-keystone | 16:27 | |
*** markvoelker has quit IRC | 17:30 | |
*** imacdonn has joined #openstack-keystone | 17:32 | |
ayoung | cmurphy, kmalloc lbragstad knikolla gagehugo can we fast track Catalog for Unscoped tokens through? https://review.openstack.org/#/c/607346/ It was originally approved, but then retracted. This just reinstates it. jamielennox was not around to drive it on home when he wrote it. | 17:36 |
*** ebukha has quit IRC | 17:44 | |
kmalloc | honza: i'm looking now, so, this indicates we have somehow failed in our circular reference checking, but more importantly i need to exempt that check from enforcement/change where enforcement occurs for that to ensure that our hard-check ensuring ALL apis are enforced doesn't get trigggered. | 17:55 |
kmalloc | honza: i bet i can have something proposed to fix that today. | 17:55 |
honza | kmalloc: wonderful news, thank you for checking so quickly | 18:18 |
honza | jrist: ^ | 18:18 |
jrist | oh yeay | 18:20 |
jrist | good work finding a bug honza | 18:20 |
jrist | :) | 18:20 |
jrist | kmalloc++ | 18:21 |
kmalloc | jrist: it really is something we weren't testing clearly | 18:29 |
kmalloc | and you are creating a bad set of roles | 18:29 |
kmalloc | somehow | 18:29 |
kmalloc | but we also are raising an exception before we run enforcement, so it wasn't marked as an enforced API | 18:29 |
kmalloc | this is a good thing for us, means there is no way to accidently have an unenforced api call, it must be enforced or it raises a 500 (as it should) | 18:30 |
kmalloc | drastic improvement to previous keystones | 18:30 |
kmalloc | honza: so... out of curoisity did OPTIONS actually ever work before flask? | 18:39 |
kmalloc | honza: for keystone? | 18:39 |
kmalloc | i'm inclined to say it never really did. | 18:39 |
kmalloc | it just didn't error. | 18:39 |
*** bigdogstl has joined #openstack-keystone | 18:50 | |
honza | kmalloc: it worked great before | 18:59 |
honza | kmalloc: i mean, i was able to authenticate against keystone using cors in the browser | 19:01 |
honza | kmalloc: no errors | 19:01 |
*** bigdogstl has quit IRC | 19:08 | |
*** bigdogstl has joined #openstack-keystone | 19:12 | |
*** zigo has quit IRC | 19:25 | |
*** bigdogstl has quit IRC | 19:26 | |
*** bigdogstl has joined #openstack-keystone | 19:30 | |
kmalloc | yeah | 19:33 |
kmalloc | figured no errors but not giving useful information | 19:33 |
*** bigdogstl has quit IRC | 19:35 | |
*** Emine has quit IRC | 19:48 | |
*** bigdogstl has joined #openstack-keystone | 19:53 | |
*** bigdogstl has quit IRC | 19:57 | |
*** bigdogstl has joined #openstack-keystone | 20:59 | |
* lbragstad heads to the airport and puts some John Denver on the stereo | 21:08 | |
lbragstad | safe travels, all | 21:08 |
*** lbragstad has quit IRC | 21:08 | |
*** bigdogstl has quit IRC | 21:09 | |
*** bigdogstl has joined #openstack-keystone | 21:13 | |
*** bigdogstl has quit IRC | 21:18 | |
*** raildo has quit IRC | 22:00 | |
*** bigdogstl has joined #openstack-keystone | 22:51 | |
*** bigdogstl has quit IRC | 23:03 | |
*** bigdogstl has joined #openstack-keystone | 23:05 | |
*** erus has quit IRC | 23:08 | |
*** bigdogstl has quit IRC | 23:10 | |
*** erus has joined #openstack-keystone | 23:11 | |
*** bigdogstl has joined #openstack-keystone | 23:11 | |
*** erus has quit IRC | 23:17 | |
openstackgerrit | Merged openstack/keystone master: Update more info of vhost file https://review.openstack.org/616457 | 23:18 |
openstackgerrit | Merged openstack/keystone master: Emit CADF notifications on authentication for invalid users https://review.openstack.org/613455 | 23:18 |
openstackgerrit | Merged openstack/keystone master: Remove unused lower constraints https://review.openstack.org/615750 | 23:20 |
openstackgerrit | Merged openstack/keystone master: Provide a Location on HTTP 300 https://review.openstack.org/613633 | 23:20 |
*** erus has joined #openstack-keystone | 23:22 | |
*** bigdogstl has quit IRC | 23:24 | |
*** bigdogstl has joined #openstack-keystone | 23:27 | |
*** erus has quit IRC | 23:29 | |
*** bigdogstl has quit IRC | 23:32 | |
*** erus has joined #openstack-keystone | 23:37 | |
*** bigdogstl has joined #openstack-keystone | 23:43 | |
*** erus has quit IRC | 23:43 | |
*** erus has joined #openstack-keystone | 23:52 | |
*** aojea_ has quit IRC | 23:52 | |
*** bigdogstl has quit IRC | 23:54 | |
*** erus has quit IRC | 23:59 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!