*** gyee has quit IRC | 00:26 | |
*** gyee has joined #openstack-keystone | 00:27 | |
*** dave-mccowan has joined #openstack-keystone | 00:36 | |
*** markvoelker has joined #openstack-keystone | 00:50 | |
*** xek__ has joined #openstack-keystone | 00:58 | |
*** xek_ has quit IRC | 01:01 | |
*** xek_ has joined #openstack-keystone | 01:04 | |
*** whoami-rajat has joined #openstack-keystone | 01:07 | |
*** xek__ has quit IRC | 01:07 | |
*** lbragstad has quit IRC | 01:09 | |
*** gyee has quit IRC | 01:11 | |
*** dave-mccowan has quit IRC | 01:18 | |
*** erus has quit IRC | 01:18 | |
*** erus has joined #openstack-keystone | 01:19 | |
*** markvoelker has quit IRC | 01:22 | |
*** rcernin has quit IRC | 01:31 | |
*** rcernin has joined #openstack-keystone | 01:32 | |
*** xek__ has joined #openstack-keystone | 01:40 | |
*** xek_ has quit IRC | 01:43 | |
*** xek_ has joined #openstack-keystone | 01:43 | |
*** xek__ has quit IRC | 01:46 | |
*** xek__ has joined #openstack-keystone | 01:47 | |
*** xek_ has quit IRC | 01:50 | |
*** xek_ has joined #openstack-keystone | 01:54 | |
*** xek__ has quit IRC | 01:57 | |
*** xek__ has joined #openstack-keystone | 01:57 | |
*** xek_ has quit IRC | 02:00 | |
*** jamesmcarthur has joined #openstack-keystone | 02:01 | |
*** xek_ has joined #openstack-keystone | 02:02 | |
*** xek__ has quit IRC | 02:04 | |
*** jamesmcarthur has quit IRC | 02:08 | |
*** jamesmcarthur has joined #openstack-keystone | 02:08 | |
*** dave-mccowan has joined #openstack-keystone | 02:17 | |
*** jamesmcarthur has quit IRC | 02:17 | |
*** markvoelker has joined #openstack-keystone | 02:20 | |
*** jamesmcarthur has joined #openstack-keystone | 02:24 | |
*** jamesmcarthur has quit IRC | 02:38 | |
*** markvoelker has quit IRC | 02:52 | |
*** lbragstad has joined #openstack-keystone | 03:11 | |
*** ChanServ sets mode: +o lbragstad | 03:11 | |
lbragstad | timothyb89 nice! | 03:11 |
---|---|---|
lbragstad | that's good news - if you haven't done so already, it would be awesome to leave those results on the review | 03:13 |
*** awalende has joined #openstack-keystone | 03:17 | |
*** awalende has quit IRC | 03:21 | |
*** ileixe has joined #openstack-keystone | 03:27 | |
ileixe | Hi guys. I have a simple operational question. | 03:27 |
ileixe | We have LDAP system which is a endpoint user action started, and are using keystone for frontend for it. | 03:28 |
ileixe | So in our system, operator can delete LDAP user without notifying keystone. | 03:28 |
ileixe | Is there any way to bind bi-directionally between two systems using keystone? | 03:29 |
ileixe | Ideally, user action sould be started using keystone API though, reality is tough. | 03:30 |
*** shyamb has joined #openstack-keystone | 03:48 | |
*** markvoelker has joined #openstack-keystone | 03:49 | |
*** vishakha has joined #openstack-keystone | 03:50 | |
*** dave-mccowan has quit IRC | 04:00 | |
*** markvoelker has quit IRC | 04:22 | |
*** aning_ has quit IRC | 04:26 | |
*** bnemec has quit IRC | 04:26 | |
*** kukacz has quit IRC | 04:26 | |
*** cburgess has quit IRC | 04:26 | |
*** gary_perkins has quit IRC | 04:26 | |
*** brtknr has quit IRC | 04:26 | |
*** konetzed has quit IRC | 04:26 | |
*** kklimonda_ has quit IRC | 04:26 | |
*** ileixe has quit IRC | 04:31 | |
*** shyamb has quit IRC | 04:32 | |
*** shyamb has joined #openstack-keystone | 04:33 | |
*** erus has quit IRC | 04:39 | |
*** erus has joined #openstack-keystone | 04:40 | |
*** aning_ has joined #openstack-keystone | 04:53 | |
*** bnemec has joined #openstack-keystone | 04:53 | |
*** kukacz has joined #openstack-keystone | 04:53 | |
*** cburgess has joined #openstack-keystone | 04:53 | |
*** gary_perkins has joined #openstack-keystone | 04:53 | |
*** brtknr has joined #openstack-keystone | 04:53 | |
*** konetzed has joined #openstack-keystone | 04:53 | |
*** kklimonda_ has joined #openstack-keystone | 04:53 | |
*** rcernin has quit IRC | 04:56 | |
*** ileixe has joined #openstack-keystone | 04:59 | |
*** rcernin has joined #openstack-keystone | 05:02 | |
*** markvoelker has joined #openstack-keystone | 05:19 | |
*** lbragstad has quit IRC | 05:33 | |
*** markvoelker has quit IRC | 05:53 | |
*** erus has quit IRC | 05:53 | |
*** jhesketh has quit IRC | 05:53 | |
*** erus has joined #openstack-keystone | 05:53 | |
*** jhesketh has joined #openstack-keystone | 05:54 | |
*** shyamb has quit IRC | 05:56 | |
*** shyamb has joined #openstack-keystone | 06:12 | |
*** erus has quit IRC | 06:48 | |
*** erus has joined #openstack-keystone | 06:49 | |
*** markvoelker has joined #openstack-keystone | 06:50 | |
*** shyamb has quit IRC | 06:57 | |
*** phasespace has quit IRC | 07:00 | |
*** markvoelker has quit IRC | 07:22 | |
*** pcaruana has joined #openstack-keystone | 07:25 | |
*** erus has quit IRC | 07:25 | |
*** erus has joined #openstack-keystone | 07:26 | |
*** rcernin has quit IRC | 07:27 | |
*** david-lyle has joined #openstack-keystone | 07:36 | |
*** dklyle has quit IRC | 07:37 | |
*** dklyle has joined #openstack-keystone | 07:41 | |
*** david-lyle has quit IRC | 07:42 | |
*** dklyle has quit IRC | 07:55 | |
*** dklyle has joined #openstack-keystone | 07:55 | |
*** shyamb has joined #openstack-keystone | 08:02 | |
*** tkajinam has quit IRC | 08:12 | |
*** awalende has joined #openstack-keystone | 08:19 | |
*** markvoelker has joined #openstack-keystone | 08:19 | |
*** ileixe has quit IRC | 08:20 | |
*** ileixe has joined #openstack-keystone | 08:21 | |
*** erus has quit IRC | 08:21 | |
*** erus has joined #openstack-keystone | 08:22 | |
*** ileixe has quit IRC | 08:26 | |
*** erus has quit IRC | 08:28 | |
*** erus has joined #openstack-keystone | 08:28 | |
*** phasespace has joined #openstack-keystone | 08:37 | |
*** shyamb has quit IRC | 08:38 | |
*** adriant has quit IRC | 08:47 | |
*** adriant has joined #openstack-keystone | 08:48 | |
*** shyamb has joined #openstack-keystone | 08:50 | |
*** cosss_ has quit IRC | 08:51 | |
*** cosss_ has joined #openstack-keystone | 08:51 | |
*** xek_ has quit IRC | 08:53 | |
*** markvoelker has quit IRC | 08:53 | |
*** xek_ has joined #openstack-keystone | 08:53 | |
openstackgerrit | Pavlo Shchelokovskyy proposed openstack/keystone master: Add hint for order of keys during distribution https://review.openstack.org/638397 | 09:08 |
openstackgerrit | Pavlo Shchelokovskyy proposed openstack/keystone master: Add hint for order of keys during distribution https://review.openstack.org/638397 | 09:11 |
*** shyamb has quit IRC | 09:23 | |
*** shyamb has joined #openstack-keystone | 09:23 | |
*** erus has quit IRC | 09:35 | |
*** erus has joined #openstack-keystone | 09:35 | |
openstackgerrit | Merged openstack/keystone master: Add JSON driver for access rules config https://review.openstack.org/628524 | 09:43 |
*** markvoelker has joined #openstack-keystone | 09:50 | |
*** ianw is now known as ianw_pto | 09:52 | |
*** shyamb has quit IRC | 09:53 | |
*** shyamb has joined #openstack-keystone | 09:57 | |
*** erus has quit IRC | 10:06 | |
*** erus has joined #openstack-keystone | 10:06 | |
*** shyamb has quit IRC | 10:16 | |
*** shyamb has joined #openstack-keystone | 10:16 | |
*** markvoelker has quit IRC | 10:23 | |
*** erus has quit IRC | 10:30 | |
*** erus has joined #openstack-keystone | 10:31 | |
vishakha | lbragstad: In https://review.openstack.org/#/c/639718/, project users(admin or member or reader) won't | 10:52 |
vishakha | be able to list role assignments? | 10:52 |
*** odyssey4me has quit IRC | 10:53 | |
*** odyssey4me has joined #openstack-keystone | 10:53 | |
*** ileixe has joined #openstack-keystone | 11:01 | |
*** erus has quit IRC | 11:01 | |
*** erus has joined #openstack-keystone | 11:01 | |
*** markvoelker has joined #openstack-keystone | 11:20 | |
*** erus has quit IRC | 11:20 | |
*** erus has joined #openstack-keystone | 11:20 | |
*** shyamb has quit IRC | 11:30 | |
*** ileixe has quit IRC | 11:35 | |
*** xek_ has quit IRC | 11:45 | |
*** markvoelker has quit IRC | 11:53 | |
*** raildo has joined #openstack-keystone | 12:14 | |
*** dave-mccowan has joined #openstack-keystone | 12:22 | |
*** erus has quit IRC | 12:47 | |
*** erus has joined #openstack-keystone | 12:48 | |
*** markvoelker has joined #openstack-keystone | 12:50 | |
cmurphy | https://etherpad.openstack.org/p/BER19-OPS-KEYSTONE-FEEDBACK <-- notes from keystone session at ops meetup | 13:21 |
*** markvoelker has quit IRC | 13:22 | |
*** phasespace has quit IRC | 13:32 | |
*** lbragstad has joined #openstack-keystone | 13:48 | |
*** ChanServ sets mode: +o lbragstad | 13:48 | |
*** jmlowe has quit IRC | 13:51 | |
lbragstad | cmurphy \o/ | 13:54 |
*** erus has quit IRC | 13:54 | |
cmurphy | :D | 13:54 |
*** erus has joined #openstack-keystone | 13:54 | |
cmurphy | lbragstad: since you weren't in the channel: https://etherpad.openstack.org/p/BER19-OPS-KEYSTONE-FEEDBACK <-- notes from keystone session at ops meetup | 13:56 |
lbragstad | sweet | 13:56 |
lbragstad | there are some good point in there | 13:58 |
*** BlackDex has quit IRC | 13:59 | |
lbragstad | unrelated: someone pinged me saying http://lists.openstack.org/pipermail/openstack-discuss/2019-March/003552.html got filtered as spam by gmail, did any other gmail users notice that? | 13:59 |
*** BlackDex has joined #openstack-keystone | 14:02 | |
*** markvoelker has joined #openstack-keystone | 14:20 | |
*** mchlumsky has joined #openstack-keystone | 14:21 | |
*** jmlowe has joined #openstack-keystone | 14:30 | |
HD|Laptop | hey all | 14:30 |
HD|Laptop | I'm trying to enable ldap authentication - but as soon as I set driver = ldap | 14:31 |
*** erus has quit IRC | 14:31 | |
HD|Laptop | all my authentication breaks | 14:32 |
*** erus has joined #openstack-keystone | 14:32 | |
HD|Laptop | how do I keep sql for the "default" domain, or at least keep all the users for the various service accounts? | 14:32 |
lbragstad | HD|Laptop https://docs.openstack.org/keystone/latest/admin/configuration.html#domain-specific-configuration | 14:36 |
lbragstad | you can use domain-specific identity backends | 14:36 |
*** imacdonn has quit IRC | 14:39 | |
HD|Laptop | lbragstad: so keep driver=sql in keystone.conf, create /etc/keystone/domains/foo.conf and there do a section [identity] driver=ldap [ldap] ...? | 14:46 |
lbragstad | yeah - that's the idea | 14:47 |
HD|Laptop | lbragstad: doesn't work. i have restarted apache, but while openstack list user shows the normal sql users, openstack list user --domain=foo is empty | 14:49 |
HD|Laptop | but there should be ~3500 users returned | 14:49 |
HD|Laptop | in the logs it says "keystone.exception.DomainNotFound: Could not find domain: foo" | 14:51 |
*** markvoelker has quit IRC | 14:53 | |
*** erus has quit IRC | 14:53 | |
HD|Laptop | d'oh, wrong naming convention | 14:53 |
*** erus has joined #openstack-keystone | 14:54 | |
HD|Laptop | simple_bind() argument 1 must be str or None, not bytes: TypeError: simple_bind() argument 1 must be str or None, not bytes | 14:54 |
HD|Laptop | WTF? | 14:54 |
HD|Laptop | I'll ask over at debian-openstack, looks like yet ANOTHER python3 fuckup | 14:54 |
*** erus has quit IRC | 14:59 | |
*** erus has joined #openstack-keystone | 15:00 | |
*** erus has quit IRC | 15:07 | |
knikolla | o/ | 15:07 |
*** erus has joined #openstack-keystone | 15:08 | |
*** awalende has quit IRC | 15:16 | |
*** awalende has joined #openstack-keystone | 15:17 | |
*** awalende has quit IRC | 15:21 | |
vishakha | o/ | 15:27 |
vishakha | lbragstad: In https://review.openstack.org/#/c/639718/, project users(admin or member or reader) won't be able to list role assignments? | 15:27 |
lbragstad | vishakha correct | 15:29 |
lbragstad | i think we reached consensus that only system and domain users should be able to view that information | 15:29 |
*** erus has quit IRC | 15:30 | |
vishakha | lbragstad: Ok. And what will be the behaviour of this API https://github.com/openstack/keystone/blob/bf7ca0bc7d934fa965fd7f264e464537b55a0388/keystone/common/policies/role_assignment.py#L52-L62 | 15:31 |
*** erus has joined #openstack-keystone | 15:31 | |
coreycb | cmurphy: hi, do you know what i need to do to get ldappool===2.3.1 into upper-constraints for stable/rocky? | 15:37 |
coreycb | cmurphy: it seems fairly straight forward for projects that are listed in releases/deliverables/rocky but ldappool is in releases/deliverables/_independent | 15:38 |
lbragstad | vishakha we might be able to continue with the plan in that NOTE | 15:40 |
lbragstad | we can just open that API up to project-admins, but we can do that in a follow-on, too | 15:40 |
coreycb | cmurphy: for example - https://github.com/openstack/releases/commit/fc79a3a6a71e6f859027b6c83c6d9cdf5f242b6f | 15:40 |
lbragstad | vishakha by follow-on, specifically we can fix that subtree assignment list once we know we have good test coverage for all users and roles against the /v3/role_assignment API | 15:41 |
* lbragstad back in 10 minutes | 15:42 | |
vishakha | lbragstad: Should I leave that for now? Later on we can add as follow-on? | 15:43 |
*** erus has quit IRC | 15:45 | |
*** erus has joined #openstack-keystone | 15:46 | |
*** markvoelker has joined #openstack-keystone | 15:50 | |
*** jamesmcarthur has joined #openstack-keystone | 16:08 | |
lbragstad | vishakha yeah - i think that is fine | 16:14 |
lbragstad | vishakha making it work for all system users and domain users will probably be more useful initially anyway | 16:15 |
vishakha | lbragstad: thanks. So I need to fix tempest test cases then and put the project test cases which should not allow users to list role assignments | 16:17 |
lbragstad | correct | 16:17 |
lbragstad | or - at least as far as i understand it | 16:17 |
lbragstad | we might have to tinker with how tempest is configured, too | 16:18 |
vishakha | Yeah. So after feature freeze these all system scope patches be merged in train? | 16:22 |
*** markvoelker has quit IRC | 16:23 | |
*** jmlowe has quit IRC | 16:36 | |
lbragstad | vishakha well - after feature freeze we'll be in release candidate mode | 16:49 |
lbragstad | so we can still merge bug fixes | 16:49 |
lbragstad | as soon as we cut a release candidate for keystone, technical the master branch will be open for Train development | 16:49 |
lbragstad | cmurphy were you in the room during the berlin ops session? | 16:50 |
lbragstad | bah - nevermind, i just read line 4 | 16:51 |
lbragstad | timothyb89 fyi - https://bugs.launchpad.net/keystone/+bug/1819036 | 17:12 |
openstack | Launchpad bug 1819036 in OpenStack Identity (keystone) "keystone validates X-Auth-Token twice on every request" [High,Triaged] | 17:12 |
*** markvoelker has joined #openstack-keystone | 17:20 | |
*** imacdonn has joined #openstack-keystone | 17:37 | |
cmurphy | coreycb: i think you can just go ahead and propose an update directly to stable/rocky of requirements | 17:38 |
cmurphy | lbragstad: lol | 17:38 |
*** jmlowe has joined #openstack-keystone | 17:49 | |
*** markvoelker has quit IRC | 17:53 | |
*** gyee has joined #openstack-keystone | 17:57 | |
*** phasespace has joined #openstack-keystone | 17:57 | |
*** erus has quit IRC | 17:59 | |
*** erus has joined #openstack-keystone | 17:59 | |
*** irclogbot_1 has joined #openstack-keystone | 18:02 | |
coreycb | cmurphy: ok thanks. promethianfire recommended the same so i'll go ahead and do that. | 18:27 |
*** erus has quit IRC | 18:28 | |
coreycb | cmurphy: fyi https://review.openstack.org/#/c/641752/ | 18:36 |
*** pcaruana has quit IRC | 18:46 | |
*** markvoelker has joined #openstack-keystone | 18:51 | |
*** vishakha has quit IRC | 18:54 | |
*** pcaruana has joined #openstack-keystone | 19:05 | |
*** xek_ has joined #openstack-keystone | 19:17 | |
*** markvoelker has quit IRC | 19:23 | |
*** pcaruana has quit IRC | 19:33 | |
*** brtknr has quit IRC | 20:10 | |
*** brtknr has joined #openstack-keystone | 20:15 | |
*** markvoelker has joined #openstack-keystone | 20:20 | |
*** jamesmcarthur has quit IRC | 20:23 | |
*** jamesmcarthur_ has joined #openstack-keystone | 20:23 | |
*** markvoelker has quit IRC | 20:53 | |
*** xek_ has quit IRC | 21:15 | |
*** whoami-rajat has quit IRC | 21:17 | |
*** markvoelker has joined #openstack-keystone | 21:50 | |
*** dave-mccowan has quit IRC | 22:02 | |
*** jamesmcarthur_ has quit IRC | 22:03 | |
*** raildo has quit IRC | 22:13 | |
*** markvoelker has quit IRC | 22:23 | |
*** rcernin has joined #openstack-keystone | 22:41 | |
*** tkajinam has joined #openstack-keystone | 22:58 | |
*** mloza has joined #openstack-keystone | 23:09 | |
mloza | hello, we have existing openldap server, is it possible to integrate it with keystone or do I have build to a new openldap because keystone needs a new schema? | 23:12 |
*** markvoelker has joined #openstack-keystone | 23:20 | |
*** jmlowe has quit IRC | 23:46 | |
*** jmlowe has joined #openstack-keystone | 23:46 | |
*** markvoelker has quit IRC | 23:52 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!