*** markvoelker has joined #openstack-keystone | 00:16 | |
*** markvoelker has quit IRC | 00:49 | |
*** ileixe has joined #openstack-keystone | 00:56 | |
*** markvoelker has joined #openstack-keystone | 01:46 | |
*** Dinesh_Bhor has joined #openstack-keystone | 02:06 | |
*** Dinesh_Bhor has quit IRC | 02:06 | |
*** markvoelker has quit IRC | 02:19 | |
*** Dinesh_Bhor has joined #openstack-keystone | 02:22 | |
*** markvoelker has joined #openstack-keystone | 03:16 | |
*** Dinesh_Bhor has quit IRC | 03:39 | |
*** shyamb has joined #openstack-keystone | 03:39 | |
*** Dinesh_Bhor has joined #openstack-keystone | 03:43 | |
*** markvoelker has quit IRC | 03:48 | |
*** vishakha has joined #openstack-keystone | 04:18 | |
*** shyamb has quit IRC | 04:28 | |
*** ileixe has quit IRC | 04:32 | |
vishakha | lbragstad, cmurphy : As shadow users are created in SP, shouldn't it be deleted when token gets expired? | 04:38 |
---|---|---|
*** Dinesh_Bhor has quit IRC | 04:46 | |
*** Dinesh_Bhor has joined #openstack-keystone | 04:53 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement system reader for role_assignments https://review.openstack.org/609210 | 04:58 |
*** ileixe has joined #openstack-keystone | 05:02 | |
*** spsurya has joined #openstack-keystone | 05:41 | |
*** Dinesh_Bhor has quit IRC | 06:16 | |
*** markvoelker has joined #openstack-keystone | 06:16 | |
*** Dinesh_Bhor has joined #openstack-keystone | 06:17 | |
*** aojea has joined #openstack-keystone | 06:17 | |
*** aojea has quit IRC | 06:22 | |
*** zioproto has quit IRC | 06:42 | |
*** cosss_ has quit IRC | 06:42 | |
*** cwright has quit IRC | 06:42 | |
*** johnsom has quit IRC | 06:42 | |
*** cwright has joined #openstack-keystone | 06:42 | |
*** cosss_ has joined #openstack-keystone | 06:42 | |
*** zioproto has joined #openstack-keystone | 06:42 | |
*** johnsom has joined #openstack-keystone | 06:42 | |
*** shyamb has joined #openstack-keystone | 06:45 | |
*** markvoelker has quit IRC | 06:48 | |
*** shyam89 has joined #openstack-keystone | 06:51 | |
*** shyamb has quit IRC | 06:55 | |
*** rcernin has quit IRC | 07:00 | |
*** shyam89 has quit IRC | 07:08 | |
*** shyam89 has joined #openstack-keystone | 07:10 | |
*** shyam89 has quit IRC | 07:14 | |
*** shyam89 has joined #openstack-keystone | 07:15 | |
*** shyam89 has quit IRC | 07:21 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement system reader for role_assignments https://review.openstack.org/609210 | 07:26 |
*** markvoelker has joined #openstack-keystone | 07:46 | |
*** tkajinam has quit IRC | 08:16 | |
*** markvoelker has quit IRC | 08:19 | |
*** yan0s has joined #openstack-keystone | 08:23 | |
cmurphy | vishakha: arguably yes, but then we wouldn't be able to create concrete role assignments with them | 08:29 |
cmurphy | and I don't think we have any mechanism to trigger notifications on token expiration | 08:29 |
*** xek_ has joined #openstack-keystone | 08:42 | |
*** markvoelker has joined #openstack-keystone | 09:16 | |
*** Dinesh_Bhor has quit IRC | 09:21 | |
*** Dinesh_Bhor has joined #openstack-keystone | 09:24 | |
vishakha | cmurphy: So we to manually delete users of federated_table? | 09:36 |
*** shyam89 has joined #openstack-keystone | 09:38 | |
cmurphy | vishakha: if you want to clean out the database then yes you would have to do it manually, but in practice i don't think keeping them around should cause an issue since those users still need to go through their IdP to get a new token | 09:41 |
vishakha | cmurphy: Yes True. I was thinking just in case of millions of users getting tokens, which can affect the performance. | 09:45 |
*** yan0s has quit IRC | 09:48 | |
*** markvoelker has quit IRC | 09:49 | |
*** jaosorior has joined #openstack-keystone | 09:53 | |
*** yan0s has joined #openstack-keystone | 10:01 | |
*** shyam89 has quit IRC | 10:17 | |
*** openstackgerrit has quit IRC | 10:21 | |
*** shyam89 has joined #openstack-keystone | 10:23 | |
vishakha | cmurphy: while issuing a token federated user has to give sp's project name in CLI. How does the user have the information about the projects of SP? I wasn't able to find this piece of information anywhere? | 10:26 |
*** Dinesh_Bhor has quit IRC | 10:39 | |
cmurphy | vishakha: they can use an unscoped token and query /v3/auth/projects on the SP | 10:40 |
*** markvoelker has joined #openstack-keystone | 10:46 | |
*** shyam89 has quit IRC | 11:10 | |
vishakha | cmurphy: Thanks | 11:15 |
*** markvoelker has quit IRC | 11:19 | |
*** aojea_ has joined #openstack-keystone | 11:32 | |
*** shyam89 has joined #openstack-keystone | 11:48 | |
*** yan0s has quit IRC | 11:54 | |
*** yan0s has joined #openstack-keystone | 12:07 | |
*** markvoelker has joined #openstack-keystone | 12:16 | |
*** aojea_ has quit IRC | 12:26 | |
*** jistr is now known as jistr|afk | 12:38 | |
*** markvoelker has quit IRC | 12:49 | |
*** shyam89 has quit IRC | 13:06 | |
*** shyam89 has joined #openstack-keystone | 13:07 | |
*** jistr|afk is now known as jistr | 13:10 | |
*** yan0s has quit IRC | 13:46 | |
*** yan0s has joined #openstack-keystone | 13:48 | |
*** openstackgerrit has joined #openstack-keystone | 13:49 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Implement system reader for role_assignments https://review.openstack.org/609210 | 13:49 |
*** yan0s has quit IRC | 13:50 | |
*** yan0s has joined #openstack-keystone | 13:51 | |
*** ileixe has quit IRC | 13:56 | |
*** erus has joined #openstack-keystone | 14:08 | |
*** lbragstad has joined #openstack-keystone | 14:11 | |
*** ChanServ sets mode: +o lbragstad | 14:11 | |
lbragstad | o/ | 14:14 |
cmurphy | \o | 14:15 |
lbragstad | just a heads up - i doubt i'm going to be around this afternoon | 14:16 |
*** erus_ has joined #openstack-keystone | 14:17 | |
lbragstad | taking a sick day this afternoon - but i'll check in when i can | 14:19 |
*** shyam89 has quit IRC | 14:19 | |
cmurphy | feel better lbragstad | 14:20 |
lbragstad | well - i'm fine. henry is staying home from daycare today though | 14:20 |
cmurphy | oh poor thing :( | 14:21 |
lbragstad | day care really is the worst at spreading things around :) | 14:21 |
lbragstad | we want to get him to recover a bit more before we send him back | 14:22 |
lbragstad | so if there is anything folks need from me today - just let me know and i'll prioritize it this morning | 14:22 |
*** xek_ has quit IRC | 14:25 | |
*** xek_ has joined #openstack-keystone | 14:26 | |
*** mvkr has quit IRC | 14:33 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: [WIP] implement domain reader for role_assignments https://review.openstack.org/632101 | 14:35 |
*** kmalloc has joined #openstack-keystone | 14:43 | |
*** kmalloc has left #openstack-keystone | 14:45 | |
*** kmalloc has joined #openstack-keystone | 14:45 | |
*** mchlumsky has joined #openstack-keystone | 14:46 | |
kmalloc | O/ | 14:50 |
cmurphy | ohai kmalloc | 14:50 |
kmalloc | Mornin | 14:50 |
kmalloc | So .. vacation is over. :(. But it was a good long one. | 14:50 |
lbragstad | kmalloc welcome back | 14:53 |
kmalloc | Thanks. Still not quite setup with networking at new place. | 14:54 |
lbragstad | not to blast you with information as soon as you walk in, but i found some interesting thinks out about jwt last week | 14:54 |
lbragstad | things* | 14:54 |
*** dave-mccowan has joined #openstack-keystone | 14:55 | |
lbragstad | i didn't realize you moved? | 14:55 |
kmalloc | Cool look forward to hear about the jwt stuff | 14:56 |
lbragstad | most of it is here - https://review.openstack.org/#/c/631887/ | 14:56 |
kmalloc | Yeah moved last week. | 14:56 |
lbragstad | nice | 14:56 |
kmalloc | Found a nice house with a yard, in a great neighborhood, rent was less than the stupid townhome | 14:57 |
kmalloc | ;) | 14:57 |
lbragstad | sweet - i bet your dogs were happy with that decision | 14:57 |
kmalloc | And we got rid of 2 storage units (as well, saving $280+/mo) on top.of it | 14:57 |
kmalloc | Yeah puppers love the yard. | 14:57 |
kmalloc | The house has quirks... It is over 110 years old. | 14:58 |
lbragstad | i bet it has character | 14:58 |
kmalloc | Let me look at the JWT thing. | 14:58 |
kmalloc | I am a little hit/miss for the first part of the day. Getting the network up and running, requires network port/patch bay crimping. | 14:59 |
kmalloc | Hard wiring 12 Ethernet ports in the office so I can run computers in the basement closet and do HDMI over Ethernet is a cool setup (office is quiet) | 15:00 |
kmalloc | (and need to run wifi still) | 15:00 |
lbragstad | i remember in denver i was having a hard time understand the whole multi-signature thing | 15:02 |
lbragstad | understanding* | 15:02 |
lbragstad | which would allow for a slightly different rotation process for the asymmetric keys | 15:02 |
lbragstad | turns out - that process is detailed in section 7 of the JWT specification | 15:03 |
lbragstad | but - i'm not sure it'll be something we can do without underlying support from the library that implements jwt | 15:05 |
kmalloc | Yes it is. | 15:05 |
kmalloc | The lib needs to support it | 15:05 |
kmalloc | First r sure. | 15:05 |
kmalloc | For* | 15:05 |
lbragstad | ok - i couldn't find a statement about PyJWT supporting it or not | 15:05 |
kmalloc | As long as we outline we intend to support it, we can work on implementing or improving a lib | 15:06 |
kmalloc | Or being agile about changing libs. | 15:06 |
lbragstad | so i dug through the code, and afaict i don't see support for it yet | 15:06 |
kmalloc | And I am ok with that. | 15:06 |
lbragstad | https://github.com/jpadilla/pyjwt/issues/390 | 15:06 |
kmalloc | So we should footnote it isn't in the lib yet. But we will aim to add it or work around the lib as we can | 15:07 |
*** dave-mccowan has quit IRC | 15:12 | |
*** szaher has quit IRC | 15:13 | |
openstackgerrit | Moisés Guimarães proposed openstack/oslo.policy master: Add ability for policy-checker to read configuration https://review.openstack.org/616659 | 15:15 |
*** szaher has joined #openstack-keystone | 15:17 | |
lbragstad | also - how much do we care about the various curves used for elliptic curves? | 15:22 |
lbragstad | currently, pyca/cryptography only supports NIST curves | 15:23 |
lbragstad | context: https://cryptography.io/en/latest/hazmat/primitives/asymmetric/ec/#elliptic-curves | 15:27 |
openstackgerrit | Moisés Guimarães proposed openstack/oslo.policy master: Add ability for policy-checker to read configuration https://review.openstack.org/616659 | 15:31 |
openstackgerrit | Moisés Guimarães proposed openstack/oslo.policy master: Add ability for policy-checker to read configuration https://review.openstack.org/616659 | 15:34 |
gagehugo | o/ | 15:34 |
openstackgerrit | Moisés Guimarães proposed openstack/oslo.policy master: Add ability for policy-checker to read configuration https://review.openstack.org/616659 | 15:35 |
lbragstad | hey gagehugo | 15:41 |
gagehugo | hey lbragstad o/ | 15:43 |
erus_ | welcome kmalloc o/ | 15:43 |
*** erus has quit IRC | 15:45 | |
*** whoami-rajat has quit IRC | 15:55 | |
kmalloc | lbragstad: I need to look at the EC stuff, but I think as long as we can say we are agile about EC if needed, we should be fine. | 15:56 |
*** erus has joined #openstack-keystone | 15:56 | |
kmalloc | lbragstad: I largely think we should replicate the password hashing style setup, where we can rotate the needed bits as we have support / need to. | 15:57 |
kmalloc | I'll check to see if there is a better curve later today for us to start on. | 15:57 |
lbragstad | well - there are curves that are more "trusted" | 15:57 |
kmalloc | Right. | 15:57 |
lbragstad | but they aren't formally supported by pyca/cryptography | 15:57 |
kmalloc | And we can simply say we use X anday make a shift to a more trusted on as pyca supports it. | 15:58 |
lbragstad | sure | 15:58 |
kmalloc | Today* not anday. | 15:58 |
lbragstad | ok - i thinks that about our only option, short if implementing curves ourselves | 15:59 |
kmalloc | Yes. And I don't want to do that. | 15:59 |
lbragstad | which i'm sure i'm vastly under-qualified to do | 15:59 |
kmalloc | We could but let's not. | 15:59 |
kmalloc | Unless we really really need it. | 15:59 |
kmalloc | Btw, 34 days of no code... Not even for funsies. | 16:00 |
kmalloc | It makes things a lot better. | 16:00 |
lbragstad | i bet | 16:04 |
lbragstad | btw - i have a pile of reviews for the system scope bugs | 16:04 |
lbragstad | in case you're looking for things to review :) | 16:04 |
*** hemnaaway is now known as hemna | 16:17 | |
*** erus has quit IRC | 16:19 | |
*** erus has joined #openstack-keystone | 16:37 | |
*** yan0s has quit IRC | 16:39 | |
*** whoami-rajat has joined #openstack-keystone | 16:41 | |
kmalloc | On my list to catch up on as soon as my computer is online. | 16:50 |
kmalloc | Only mobile for the moment. | 16:50 |
kmalloc | No network at the house yet. | 16:51 |
lbragstad | sounds good | 17:06 |
*** errr has quit IRC | 17:19 | |
erus_ | hello :) | 17:41 |
*** openstackgerrit has quit IRC | 18:07 | |
*** markvoelker has joined #openstack-keystone | 18:16 | |
*** vishakha has quit IRC | 18:23 | |
*** openstackgerrit has joined #openstack-keystone | 18:24 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add configuration options for JWS provider https://review.openstack.org/628676 | 18:24 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add keystone-manage jws_setup functionality https://review.openstack.org/615315 | 18:24 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add test fixture for the JWS key repository https://review.openstack.org/614547 | 18:24 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add PyJWT as a requirement https://review.openstack.org/614548 | 18:24 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement JWS token provider https://review.openstack.org/614549 | 18:24 |
lbragstad | ok - ^ should be ready for another set of reviews | 18:25 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement JWS token provider https://review.openstack.org/614549 | 18:27 |
*** lbragstad is now known as lbragstad_afk | 18:27 | |
*** lbragstad_afk is now known as lbragstad_503 | 18:27 | |
*** markvoelker has quit IRC | 18:50 | |
*** mvkr has joined #openstack-keystone | 18:56 | |
-openstackstatus- NOTICE: The error causing post failures on jobs has been corrected. It is safe to recheck these jobs. | 19:17 | |
openstackgerrit | Islam Musleh proposed openstack/keystone master: Converting the API tests to use flask's test_client https://review.openstack.org/630301 | 19:22 |
*** erus has quit IRC | 19:34 | |
*** aojea has joined #openstack-keystone | 19:38 | |
*** aojea has quit IRC | 19:38 | |
*** erus has joined #openstack-keystone | 19:39 | |
*** aojea has joined #openstack-keystone | 19:39 | |
*** markvoelker has joined #openstack-keystone | 19:46 | |
*** xek_ has quit IRC | 20:09 | |
*** aojea has quit IRC | 20:10 | |
*** whoami-rajat has quit IRC | 20:15 | |
*** markvoelker has quit IRC | 20:20 | |
erus_ | hi, is anyone available? I'm trying to run devstack but after finished running stack.sh it does not allow me to access through the dashboard | 20:24 |
*** ianw is now known as ianw_pto | 20:26 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Allow project users to retrieve domains https://review.openstack.org/605871 | 20:50 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove domain policies from policy.v3cloudsample.json https://review.openstack.org/605876 | 20:50 |
*** aojea has joined #openstack-keystone | 21:02 | |
*** markvoelker has joined #openstack-keystone | 21:17 | |
*** honza has quit IRC | 21:19 | |
*** markvoelker has quit IRC | 21:49 | |
*** rcernin has joined #openstack-keystone | 21:54 | |
openstackgerrit | Adrian Turjak proposed openstack/keystone master: bump Keystone version for Stein https://review.openstack.org/631369 | 22:01 |
*** erus_ has quit IRC | 22:03 | |
*** erus has quit IRC | 22:04 | |
*** erus has joined #openstack-keystone | 22:06 | |
openstackgerrit | Adrian Turjak proposed openstack/keystone master: Add documentation for Auth Receipts and MFA https://review.openstack.org/580535 | 22:07 |
*** markvoelker has joined #openstack-keystone | 22:08 | |
*** spsurya has quit IRC | 22:09 | |
*** erus has quit IRC | 22:31 | |
*** aojea has quit IRC | 22:36 | |
*** erus has joined #openstack-keystone | 22:38 | |
*** imacdonn_ has quit IRC | 22:48 | |
*** imacdonn_ has joined #openstack-keystone | 22:48 | |
*** tkajinam has joined #openstack-keystone | 23:03 | |
*** erus has quit IRC | 23:35 | |
*** erus_ has joined #openstack-keystone | 23:47 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!