*** imacdonn has quit IRC | 00:00 | |
*** imacdonn has joined #openstack-keystone | 00:01 | |
*** ileixe has joined #openstack-keystone | 00:52 | |
*** gyee has quit IRC | 01:33 | |
*** Dinesh_Bhor has joined #openstack-keystone | 01:48 | |
*** whoami-rajat has joined #openstack-keystone | 02:11 | |
*** dims has quit IRC | 02:38 | |
*** dims has joined #openstack-keystone | 02:55 | |
*** ileixe has quit IRC | 04:38 | |
*** lbragstad has quit IRC | 05:16 | |
*** ileixe has joined #openstack-keystone | 05:18 | |
*** shyamb has joined #openstack-keystone | 05:30 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add openstack_groups to assertion https://review.openstack.org/588211 | 06:23 |
---|---|---|
*** shyamb has quit IRC | 06:31 | |
*** zzzeek has quit IRC | 06:33 | |
*** zzzeek has joined #openstack-keystone | 06:37 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Replace 'tenant_id' with 'project_id' https://review.openstack.org/631706 | 07:04 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Replace 'tenant_id' with 'project_id' https://review.openstack.org/631706 | 07:07 |
*** markvoelker has joined #openstack-keystone | 07:26 | |
*** takamatsu has joined #openstack-keystone | 07:46 | |
*** shyamb has joined #openstack-keystone | 07:59 | |
*** markvoelker has quit IRC | 07:59 | |
*** tkajinam has quit IRC | 08:14 | |
*** shyam89 has joined #openstack-keystone | 08:37 | |
*** shyamb has quit IRC | 08:40 | |
*** shyam89 has quit IRC | 08:42 | |
*** Dinesh_Bhor has quit IRC | 08:44 | |
*** Dinesh_Bhor has joined #openstack-keystone | 08:44 | |
*** awalende has joined #openstack-keystone | 08:45 | |
*** shyamb has joined #openstack-keystone | 08:46 | |
*** markvoelker has joined #openstack-keystone | 08:56 | |
*** shyamb has quit IRC | 09:05 | |
*** shyamb has joined #openstack-keystone | 09:09 | |
*** markvoelker has quit IRC | 09:29 | |
*** awalende has quit IRC | 09:39 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add openstack_groups to assertion https://review.openstack.org/588211 | 09:40 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Add openstack_groups to assertion https://review.openstack.org/588211 | 09:52 |
*** shyamb has quit IRC | 09:58 | |
*** xek_ has joined #openstack-keystone | 09:59 | |
*** shyamb has joined #openstack-keystone | 10:08 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Test case for bad type user in assertion https://review.openstack.org/634193 | 10:09 |
*** shyamb has quit IRC | 10:25 | |
*** shyamb has joined #openstack-keystone | 10:25 | |
*** markvoelker has joined #openstack-keystone | 10:26 | |
*** jistr is now known as jistr|chat | 10:31 | |
*** shyamb has quit IRC | 10:40 | |
*** shyamb has joined #openstack-keystone | 10:43 | |
*** Dinesh_Bhor has quit IRC | 10:54 | |
*** shyamb has quit IRC | 10:55 | |
*** markvoelker has quit IRC | 10:59 | |
*** jistr|chat is now known as jistr | 11:05 | |
*** shyamb has joined #openstack-keystone | 11:08 | |
*** yan0s has joined #openstack-keystone | 11:16 | |
*** sapd1_ has quit IRC | 11:18 | |
*** ileixe has quit IRC | 11:20 | |
*** mchlumsky has quit IRC | 11:33 | |
*** mchlumsky has joined #openstack-keystone | 11:35 | |
*** shyamb has quit IRC | 11:40 | |
*** awalende has joined #openstack-keystone | 11:40 | |
*** shyamb has joined #openstack-keystone | 11:41 | |
*** awalende has quit IRC | 11:44 | |
*** markvoelker has joined #openstack-keystone | 11:57 | |
*** shyamb has quit IRC | 12:02 | |
*** shyamb has joined #openstack-keystone | 12:03 | |
*** shyamb has quit IRC | 12:14 | |
*** markvoelker has quit IRC | 12:29 | |
*** shyamb has joined #openstack-keystone | 12:34 | |
*** erus1 has quit IRC | 13:01 | |
*** shyamb has quit IRC | 13:16 | |
*** jistr is now known as jistr|call | 13:25 | |
*** markvoelker has joined #openstack-keystone | 13:26 | |
*** jistr|call is now known as jistr | 13:31 | |
*** shyamb has joined #openstack-keystone | 13:36 | |
*** xek_ has quit IRC | 13:45 | |
*** xek_ has joined #openstack-keystone | 13:45 | |
*** pcaruana has quit IRC | 13:52 | |
*** takamatsu has quit IRC | 13:54 | |
*** lbragstad has joined #openstack-keystone | 13:57 | |
*** ChanServ sets mode: +o lbragstad | 13:57 | |
*** markvoelker has quit IRC | 13:58 | |
*** pcaruana has joined #openstack-keystone | 14:02 | |
brtknr | ubuntu@devstack-master:/opt/stack$ openstack trust create demo service-user --project demo --role member | 14:03 |
brtknr | You are not authorized to perform the requested action: identity:create_trust. (HTTP 403) (Request-ID: req-6d767713-0ae2-46ac-9c8d-ddedb5148cbf) | 14:03 |
brtknr | ubuntu@devstack-master:/opt/stack$ openstack trust create demo service-user --project demo --role member | 14:03 |
brtknr | You are not authorized to perform the requested action: identity:create_trust. (HTTP 403) (Request-ID: req-6d767713-0ae2-46ac-9c8d-ddedb5148cbf) | 14:03 |
brtknr | Is anyone able to help me debug why I cant create trust as non-admin user | 14:03 |
*** shyamb has quit IRC | 14:17 | |
*** dave-mccowan has joined #openstack-keystone | 14:18 | |
*** dave-mccowan has quit IRC | 14:41 | |
yan0s | "identity:create_trust": "user_id:%(trust.trustor_user_id)s", | 14:45 |
yan0s | brtknr: this is the default policy for creating trust in keystone policy.json | 14:46 |
yan0s | brtknr: not sure how to translate it | 14:47 |
yan0s | brtknr: but setting it to : "identity:create_trust": "", | 14:48 |
yan0s | brtknr: should allow everyone to create trusts regardless of their role | 14:48 |
brtknr | yan0s: is there any downside to allowing this? | 14:49 |
yan0s | also you may need to restart apache2 service to apply the rule | 14:49 |
yan0s | not sure about downsides.. | 14:50 |
brtknr | yan0s: what does "user_id:%(trust.trustor_user_id)s" even mean? | 14:52 |
brtknr | who is currently allowed to create trust? | 14:52 |
brtknr | i mean, who is it currently allowing to create trust? | 14:52 |
cmurphy | don't disable the create_trust policy, that would allow anyone to create trusts for anyone | 14:53 |
cmurphy | the default policy is supposed to only allow a user to create a trust for themselves | 14:53 |
cmurphy | but the client has a strange issue with names because looking up a user by name requires admin privileges | 14:53 |
yan0s | brtknr: I don't know what this means, if someone can explain this I would be very interested to know too | 14:54 |
cmurphy | so it returns a confusing forbidden error | 14:54 |
cmurphy | the way around it is to use user IDs and not names | 14:54 |
yan0s | cmurphy: can you explain the "user_id" and "%(trust.trustor_user_id)s" parts of the filter? | 14:55 |
yan0s | cmurphy: I really need to be able to know what filters I can use in the policy files | 14:56 |
*** markvoelker has joined #openstack-keystone | 14:56 | |
cmurphy | yan0s: it looks at the token payload for user_id and matches the value to the trustor_user_id value in the trust body | 14:57 |
yan0s | cmurphy: what is the trust body? | 14:58 |
brtknr | cmurphy: great! that finally worked, using id istead of username | 14:58 |
cmurphy | yan0s: the json you use to create the trust | 14:58 |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Replace 'tenant_id' with 'project_id' https://review.openstack.org/631706 | 14:58 |
cmurphy | brtknr: great | 14:58 |
brtknr | so the trustor gives control of their account to the trustee correct? | 14:59 |
brtknr | what is impersonation? | 14:59 |
cmurphy | no not of their account, just their role on the project | 14:59 |
*** mvkr has quit IRC | 15:00 | |
yan0s | cmurphy: so all the variables I can use in a filter exist in the token payload? | 15:00 |
brtknr | cmurphy: oops thats what i meant | 15:00 |
brtknr | cmurphy: what is the difference between having impersonation on and off, its not very well documented afaics | 15:01 |
cmurphy | impersonation i think means that it will use the trustor's name/id for things so for auditing it looks like they themselves were acting, nonimpersonation means the other user has permission to do things but they're stilling their own name | 15:01 |
cmurphy | i think, i'm a little fuzzy on that part | 15:01 |
brtknr | --impersonate Tokens generated from the trust will represent | 15:01 |
brtknr | <trustor> (defaults to False) | 15:01 |
brtknr | as opposed to represting someone else? | 15:02 |
cmurphy | yan0s: i think so yes | 15:02 |
cmurphy | brtknr: yes as opposed to representing the trustee | 15:02 |
yan0s | cmurphy: thanks! | 15:02 |
brtknr | interesting, so its main implication is for auditing | 15:03 |
brtknr | sounds like the desired behaviour is the default behaviour | 15:03 |
brtknr | unless the trustee account is ephemeral | 15:03 |
vishakha | cmurphy: hey, By any chance you have time we can discuss over https://review.openstack.org/#/c/588211/ | 15:06 |
cmurphy | vishakha: i need to take a closer look at that, not sure what to suggest offhand | 15:09 |
cmurphy | it's on my list for when I have time | 15:10 |
vishakha | surr thanks | 15:10 |
vishakha | Also pl have a look over https://review.openstack.org/#/c/631706/ will not take much time | 15:11 |
*** mvkr has joined #openstack-keystone | 15:13 | |
gagehugo | o/ | 15:26 |
*** markvoelker has quit IRC | 15:29 | |
brtknr | vishakha: +1 | 15:46 |
*** jmlowe has quit IRC | 15:49 | |
*** jmlowe has joined #openstack-keystone | 16:04 | |
*** yan0s has quit IRC | 16:07 | |
brtknr | cmurphy: is there a way to delege trust without specifying the --role arg? | 16:26 |
brtknr | i want to delegate all roles | 16:26 |
*** markvoelker has joined #openstack-keystone | 16:27 | |
brtknr | but I dont know what roles I'm assigned to as a non-admin user | 16:27 |
lbragstad | brtknr as a user, you can validate your token and see the role assignment you have associate to that token | 16:31 |
brtknr | how? | 16:31 |
*** imacdonn has quit IRC | 16:31 | |
brtknr | lbragstad: openstack token issue? | 16:32 |
lbragstad | brtknr yeah - that will issue you a token | 16:37 |
lbragstad | if you use openstack token issue --debug, osc will print the actual response and request so you get the entire token body | 16:37 |
lbragstad | which will contain the roles you have associated to that token | 16:37 |
*** imus has joined #openstack-keystone | 16:41 | |
kmalloc | o/ | 16:46 |
kmalloc | mornin | 16:46 |
brtknr | lbragstad: excellent! that worked like a treat!! | 16:46 |
lbragstad | good deal | 16:47 |
lbragstad | o/ kmalloc | 16:47 |
*** spsurya has quit IRC | 16:54 | |
*** markvoelker has quit IRC | 17:00 | |
*** takamatsu has joined #openstack-keystone | 17:14 | |
*** gyee has joined #openstack-keystone | 17:19 | |
*** dave-mccowan has joined #openstack-keystone | 18:25 | |
*** mvkr has quit IRC | 18:35 | |
*** markvoelker has joined #openstack-keystone | 19:27 | |
*** pcaruana has quit IRC | 19:30 | |
*** sapd1 has joined #openstack-keystone | 19:42 | |
*** sapd1 has quit IRC | 19:48 | |
kmalloc | hm. | 19:52 |
*** markvoelker has quit IRC | 20:00 | |
*** jmlowe has quit IRC | 20:04 | |
*** awalende has joined #openstack-keystone | 20:16 | |
*** awalende has quit IRC | 20:20 | |
*** jmlowe has joined #openstack-keystone | 20:24 | |
*** markvoelker has joined #openstack-keystone | 20:57 | |
*** xek_ has quit IRC | 21:19 | |
*** xek has joined #openstack-keystone | 21:19 | |
*** markvoelker has quit IRC | 21:30 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add configuration options for JWS provider https://review.openstack.org/628676 | 21:33 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add keystone-manage create_jws_keypair functionality https://review.openstack.org/615315 | 21:33 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add test fixture for the JWS key repository https://review.openstack.org/614547 | 21:33 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add PyJWT as a requirement https://review.openstack.org/614548 | 21:33 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement JWS token provider https://review.openstack.org/614549 | 21:33 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Add JWS token provider documentation https://review.openstack.org/633831 | 21:33 |
openstackgerrit | Islam Musleh proposed openstack/keystone master: Converting the API tests to use flask's test_client https://review.openstack.org/630301 | 21:40 |
*** mchlumsky has quit IRC | 21:51 | |
*** markvoelker has joined #openstack-keystone | 22:27 | |
*** erus1 has joined #openstack-keystone | 22:38 | |
*** markvoelker has quit IRC | 22:41 | |
*** tkajinam has joined #openstack-keystone | 22:56 | |
*** whoami-rajat has quit IRC | 23:00 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!