*** sapd1 has joined #openstack-keystone | 01:05 | |
*** imacdonn has quit IRC | 01:13 | |
*** imacdonn has joined #openstack-keystone | 01:14 | |
*** altlogbot_2 has quit IRC | 01:28 | |
*** altlogbot_1 has joined #openstack-keystone | 01:31 | |
*** hemna_ has quit IRC | 01:34 | |
*** adriant has joined #openstack-keystone | 01:36 | |
*** hemna_ has joined #openstack-keystone | 01:38 | |
*** jamesmcarthur has quit IRC | 02:00 | |
*** lbragstad has quit IRC | 02:57 | |
*** whoami-rajat has joined #openstack-keystone | 03:12 | |
*** jamesmcarthur has joined #openstack-keystone | 03:20 | |
*** jamesmcarthur has quit IRC | 03:33 | |
*** shyamb has joined #openstack-keystone | 03:40 | |
*** jamesmcarthur has joined #openstack-keystone | 04:01 | |
*** jamesmcarthur has quit IRC | 04:05 | |
*** etp has joined #openstack-keystone | 04:13 | |
*** jamesmcarthur has joined #openstack-keystone | 04:19 | |
*** shyamb has quit IRC | 04:20 | |
*** jamesmcarthur has quit IRC | 04:29 | |
*** rcernin has quit IRC | 04:30 | |
*** rcernin has joined #openstack-keystone | 04:31 | |
*** jamesmcarthur has joined #openstack-keystone | 04:32 | |
*** pcaruana has joined #openstack-keystone | 04:35 | |
*** pcaruana has quit IRC | 04:38 | |
*** vishakha has joined #openstack-keystone | 04:45 | |
openstackgerrit | guang-yee proposed openstack/keystone master: update documentation for X.509 tokenless auth https://review.opendev.org/669790 | 04:59 |
---|---|---|
*** gyee has quit IRC | 04:59 | |
*** ileixe has quit IRC | 04:59 | |
*** ileixe has joined #openstack-keystone | 05:01 | |
*** ileixe has quit IRC | 05:03 | |
*** ileixe has joined #openstack-keystone | 05:03 | |
*** jamesmcarthur has quit IRC | 05:05 | |
openstackgerrit | Merged openstack/keystone master: nit: remove some useless code https://review.opendev.org/612625 | 05:18 |
*** ivve has joined #openstack-keystone | 05:19 | |
ivve | Either [None] key_repository does not exist or Keystone does not have sufficient permission to access it: /etc/keystone/credential-keys/ | 05:36 |
*** shyamb has joined #openstack-keystone | 05:36 | |
ivve | was checking this | 05:37 |
ivve | https://github.com/openstack/keystone/blob/106b28ad4c30948c293dc9200adb908893b24a35/keystone/common/fernet_utils.py#L37-L73 | 05:37 |
ivve | using fernet with keystone.conf defaults | 05:38 |
ivve | this just appeared out of nowhere and became worse and worse | 05:39 |
ivve | keystone is working fine though | 05:39 |
ivve | there is no such directory at all | 05:39 |
ivve | i tried creating it and giving proper permissions so thats not it | 05:39 |
ivve | restarting and rotating keys does nothing | 05:40 |
*** shyam89 has joined #openstack-keystone | 05:41 | |
ivve | tried looking for bugs but can't find anyhing related | 05:41 |
*** shyamb has quit IRC | 05:41 | |
*** jamesmcarthur has joined #openstack-keystone | 05:44 | |
*** jamesmcarthur has quit IRC | 05:51 | |
*** rcernin has quit IRC | 05:57 | |
*** vishalmanchanda has joined #openstack-keystone | 06:05 | |
*** jamesmcarthur has joined #openstack-keystone | 06:24 | |
*** jamesmcarthur has quit IRC | 06:28 | |
*** etp has quit IRC | 06:38 | |
*** dancn has joined #openstack-keystone | 06:40 | |
*** shyam89 has quit IRC | 06:52 | |
*** jamesmcarthur has joined #openstack-keystone | 06:59 | |
*** shyamb has joined #openstack-keystone | 07:02 | |
*** pcaruana has joined #openstack-keystone | 07:03 | |
*** jamesmcarthur has quit IRC | 07:05 | |
*** awalende has joined #openstack-keystone | 07:16 | |
*** ianw is now known as ianw_pto | 07:16 | |
*** shyamb has quit IRC | 07:40 | |
*** shyamb has joined #openstack-keystone | 07:44 | |
*** starborn has joined #openstack-keystone | 07:49 | |
*** shyamb has quit IRC | 07:50 | |
*** rcernin has joined #openstack-keystone | 08:02 | |
*** awalende has quit IRC | 08:04 | |
*** awalende has joined #openstack-keystone | 08:05 | |
*** rcernin has quit IRC | 08:11 | |
*** shyamb has joined #openstack-keystone | 08:23 | |
*** dancn has quit IRC | 08:24 | |
*** rcernin has joined #openstack-keystone | 08:27 | |
*** dancn has joined #openstack-keystone | 08:29 | |
*** tkajinam has quit IRC | 08:42 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Fix keystone document https://review.opendev.org/669818 | 08:54 |
*** jamesmcarthur has joined #openstack-keystone | 09:01 | |
*** jamesmcarthur has quit IRC | 09:05 | |
*** jamesmcarthur has joined #openstack-keystone | 09:32 | |
*** jamesmcarthur has quit IRC | 09:37 | |
*** shyamb has quit IRC | 09:40 | |
*** pcaruana has quit IRC | 09:48 | |
*** shyamb has joined #openstack-keystone | 09:52 | |
*** dancn has quit IRC | 09:57 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remove [signing] config https://review.opendev.org/659434 | 10:22 |
*** xek_ is now known as xek | 10:32 | |
*** shyamb has quit IRC | 10:35 | |
*** shyamb has joined #openstack-keystone | 10:52 | |
*** dancn has joined #openstack-keystone | 11:11 | |
*** tesseract has joined #openstack-keystone | 11:11 | |
*** tesseract has quit IRC | 11:13 | |
*** tesseract has joined #openstack-keystone | 11:15 | |
*** altlogbot_1 has quit IRC | 11:19 | |
*** irclogbot_3 has quit IRC | 11:19 | |
*** altlogbot_3 has joined #openstack-keystone | 11:20 | |
*** tesseract has quit IRC | 11:23 | |
*** altlogbot_3 has quit IRC | 11:25 | |
*** jamesmcarthur has joined #openstack-keystone | 11:34 | |
*** jamesmcarthur has quit IRC | 11:39 | |
*** jistr_ has joined #openstack-keystone | 11:51 | |
*** niceplace_ has joined #openstack-keystone | 11:52 | |
*** kinrui has joined #openstack-keystone | 11:53 | |
*** jistr has quit IRC | 11:55 | |
*** aprice has quit IRC | 11:55 | |
*** niceplace has quit IRC | 11:55 | |
*** hogepodge has quit IRC | 11:55 | |
*** mordred has quit IRC | 11:55 | |
*** BlackDex has quit IRC | 11:55 | |
*** jamespage has quit IRC | 11:55 | |
*** kmalloc has quit IRC | 11:55 | |
*** TheJulia has quit IRC | 11:55 | |
*** dustinc has quit IRC | 11:55 | |
*** jrosser has quit IRC | 11:55 | |
*** fungi has quit IRC | 11:55 | |
*** melwitt has quit IRC | 11:56 | |
*** Krenair has quit IRC | 11:58 | |
*** shyamb has quit IRC | 11:59 | |
*** rcernin has quit IRC | 11:59 | |
*** irclogbot_0 has joined #openstack-keystone | 12:00 | |
*** aprice has joined #openstack-keystone | 12:01 | |
*** hogepodge has joined #openstack-keystone | 12:01 | |
*** jamespage has joined #openstack-keystone | 12:01 | |
*** mordred has joined #openstack-keystone | 12:01 | |
*** BlackDex has joined #openstack-keystone | 12:01 | |
*** kmalloc has joined #openstack-keystone | 12:01 | |
*** TheJulia has joined #openstack-keystone | 12:01 | |
*** dustinc has joined #openstack-keystone | 12:01 | |
*** jrosser has joined #openstack-keystone | 12:01 | |
*** altlogbot_2 has joined #openstack-keystone | 12:02 | |
*** raildo has joined #openstack-keystone | 12:03 | |
*** altlogbot_2 has quit IRC | 12:05 | |
*** irclogbot_0 has quit IRC | 12:05 | |
*** jamesmcarthur has joined #openstack-keystone | 12:07 | |
*** altlogbot_1 has joined #openstack-keystone | 12:08 | |
*** pcaruana has joined #openstack-keystone | 12:10 | |
*** altlogbot_1 has quit IRC | 12:11 | |
*** jamesmcarthur has quit IRC | 12:11 | |
*** kinrui is now known as fungi | 12:21 | |
*** shyamb has joined #openstack-keystone | 12:26 | |
*** jistr_ is now known as jistr | 12:33 | |
*** jamesmcarthur has joined #openstack-keystone | 12:45 | |
*** altlogbot_3 has joined #openstack-keystone | 12:54 | |
*** altlogbot_3 has quit IRC | 12:57 | |
*** lbragstad has joined #openstack-keystone | 13:15 | |
*** shyamb has quit IRC | 13:23 | |
*** vishakha has quit IRC | 13:33 | |
*** jamesmcarthur has quit IRC | 13:49 | |
*** cwright has quit IRC | 13:59 | |
*** cwright has joined #openstack-keystone | 14:00 | |
*** ayoung has joined #openstack-keystone | 14:02 | |
*** jamesmcarthur has joined #openstack-keystone | 14:17 | |
*** whoami-rajat has quit IRC | 14:18 | |
cmurphy | would anybody care to moderate today's meeting for me? I have a conflicting meeting that I'd like to give partial attention to | 14:22 |
*** BlackDex has quit IRC | 14:25 | |
*** BlackDex has joined #openstack-keystone | 14:27 | |
*** jamesmcarthur has quit IRC | 14:34 | |
*** awalende has quit IRC | 14:34 | |
*** jamesmcarthur has joined #openstack-keystone | 14:35 | |
*** awalende has joined #openstack-keystone | 14:35 | |
lbragstad | cmurphy sure - i can do that | 14:36 |
cmurphy | thanks lbragstad | 14:37 |
*** awalende has quit IRC | 14:39 | |
lbragstad | np | 14:40 |
*** BlackDex has quit IRC | 14:47 | |
*** BlackDex has joined #openstack-keystone | 14:48 | |
*** starborn has quit IRC | 14:48 | |
*** ivve has quit IRC | 14:53 | |
openstackgerrit | Gauvain Pocentek proposed openstack/keystone master: Make application credentials work with group-assigned roles https://review.opendev.org/669886 | 15:03 |
*** dancn has quit IRC | 15:08 | |
kmalloc | i might miss the meeting today | 15:11 |
kmalloc | dealing with a sick dog. | 15:11 |
kmalloc | just jumped/lunged at our walker because he's not feeling well. | 15:11 |
*** altlogbot_2 has joined #openstack-keystone | 15:12 | |
*** altlogbot_2 has quit IRC | 15:17 | |
*** altlogbot_2 has joined #openstack-keystone | 15:42 | |
*** altlogbot_2 has quit IRC | 15:47 | |
*** vishakha has joined #openstack-keystone | 15:56 | |
*** altlogbot_0 has joined #openstack-keystone | 16:08 | |
*** ivve has joined #openstack-keystone | 16:08 | |
*** njohnston has joined #openstack-keystone | 16:09 | |
*** altlogbot_0 has quit IRC | 16:13 | |
*** altlogbot_3 has joined #openstack-keystone | 16:20 | |
*** whoami-rajat has joined #openstack-keystone | 16:20 | |
*** altlogbot_3 has quit IRC | 16:23 | |
*** irclogbot_3 has joined #openstack-keystone | 16:24 | |
*** irclogbot_3 has quit IRC | 16:27 | |
openstackgerrit | Merged openstack/keystone-specs master: Add spec for immutable resources https://review.opendev.org/624692 | 16:32 |
*** altlogbot_2 has joined #openstack-keystone | 17:00 | |
*** altlogbot_2 has quit IRC | 17:05 | |
*** irclogbot_2 has joined #openstack-keystone | 17:10 | |
*** irclogbot_2 has quit IRC | 17:13 | |
njohnston | lbragstad: Hi, I was wondering if I could ask for your help; mlavalle suggested you'd be a good person to contact. I am working on https://bugs.launchpad.net/neutron/+bug/1720486 | 17:38 |
openstack | Launchpad bug 1720486 in neutron "ValueError: Circular reference detected when enable keystonemiddle audit" [Medium,Confirmed] - Assigned to Liyingjun (liyingjun) | 17:38 |
*** gyee has joined #openstack-keystone | 17:39 | |
njohnston | lbragstad: There's a proposed solution in keystonemiddleware but it's downvoted with indications that the fix should be in neutron - but as I look at the neutron codebase I don't see where keystonemiddleware (or filter_factory) gets called in the neutron code that could be altered to prevent this. | 17:40 |
*** tesseract has joined #openstack-keystone | 17:40 | |
kmalloc | hey | 17:43 |
kmalloc | sorry for missing the meeting | 17:43 |
kmalloc | sick dog =/ dealing with that among other things | 17:43 |
kmalloc | lbragstad, cmurphy: changing a 500 -> 4XX is a better choice IMO, but a 500 is fine really | 17:44 |
kmalloc | i would like to go with easiest to maintain | 17:44 |
cmurphy | hmm | 17:47 |
lbragstad | njohnston o/ | 17:52 |
njohnston | lbragstad o/ | 17:53 |
*** dancn has joined #openstack-keystone | 17:53 | |
lbragstad | njohnston is there a ksm patch floating around somewhere? | 17:53 |
njohnston | lbragstad: https://review.opendev.org/#/c/508659/ | 17:54 |
openstackgerrit | Merged openstack/keystone master: Fix keystone document https://review.opendev.org/669818 | 17:54 |
lbragstad | trying to refresh myself | 17:55 |
lbragstad | looks like it's been a while | 17:55 |
lbragstad | was one of the alternatives to not use `neutron_context` and instead just name the context `context`? | 17:56 |
njohnston | lbragstad: wouldn't that have the same issue? In the bug, the nova guys talk about how they had to pop the context out of the notification entirely. | 17:57 |
lbragstad | digging up the nova patch | 17:58 |
njohnston | lbragstad: https://review.opendev.org/446948 | 17:58 |
lbragstad | aha - sure | 17:58 |
lbragstad | https://review.opendev.org/#/c/446948/1/nova/exception_wrapper.py,unified | 17:58 |
lbragstad | i think it would be reasonable to do this ksm if we're dealing with a generic name for context (as opposed to neutron_context) | 18:00 |
njohnston | right. but the traces in the bug don't give an indication which notification it might be that neutron is passing through keystonemiddleware to cause this issue | 18:00 |
njohnston | lbragstad: so if I was able to change neutron to use 'service_context' instead of 'neutron_context' then the ksm patch could key off of that perhaps? | 18:01 |
lbragstad | i think something to that effect might get us closer, yes | 18:01 |
lbragstad | mainly because it makes things more generic and it's reuseable across services | 18:02 |
lbragstad | otherwise, ksm needs a patch for each project that is using some sort of $project_context naming convention | 18:02 |
njohnston | right. ok, so I'll propose a change in neutron and update the ksm change | 18:03 |
njohnston | lbragstad: Thanks very much! | 18:03 |
lbragstad | iiuc - it looks like that was the main concern behind the current proposal in 508659 | 18:03 |
lbragstad | njohnston no problem | 18:03 |
kmalloc | cmurphy: i should have the SQL migrations up tonight. | 18:15 |
kmalloc | cmurphy: they're doing construction nearby and i can't get anything done (like right outside my front door) atm | 18:15 |
ayoung | kmalloc, you do all of your work in Docker, right? | 18:17 |
cmurphy | kmalloc: blegh :( | 18:17 |
*** jamesmcarthur has quit IRC | 18:21 | |
*** dancn has quit IRC | 18:23 | |
*** whoami-rajat has quit IRC | 18:30 | |
*** jamesmcarthur has joined #openstack-keystone | 18:34 | |
*** melwitt has joined #openstack-keystone | 18:35 | |
*** irclogbot_0 has joined #openstack-keystone | 18:36 | |
*** tesseract has quit IRC | 18:39 | |
*** irclogbot_0 has quit IRC | 18:39 | |
openstackgerrit | Merged openstack/python-keystoneclient master: Blacklist bandit 1.6.0 & cap sphinx for 2.7 https://review.opendev.org/660609 | 18:40 |
openstackgerrit | Lance Bragstad proposed openstack/keystone-specs master: Expose root domain as assignment target https://review.opendev.org/661837 | 18:59 |
*** lbragstad has quit IRC | 20:02 | |
*** vishakha has quit IRC | 20:04 | |
*** ivve has quit IRC | 20:06 | |
*** xek has quit IRC | 20:21 | |
*** irclogbot_3 has joined #openstack-keystone | 20:24 | |
*** irclogbot_3 has quit IRC | 20:27 | |
*** jamesmcarthur has quit IRC | 20:40 | |
*** jamesmcarthur has joined #openstack-keystone | 20:41 | |
*** jamesmcarthur has quit IRC | 20:48 | |
*** lbragstad has joined #openstack-keystone | 20:56 | |
*** jmlowe has joined #openstack-keystone | 21:10 | |
*** irclogbot_1 has joined #openstack-keystone | 21:14 | |
*** pcaruana has quit IRC | 21:19 | |
*** irclogbot_1 has quit IRC | 21:19 | |
*** raildo has quit IRC | 21:27 | |
*** irclogbot_2 has joined #openstack-keystone | 21:38 | |
*** irclogbot_2 has quit IRC | 21:43 | |
*** jmlowe has quit IRC | 21:51 | |
*** jmlowe has joined #openstack-keystone | 21:53 | |
*** irclogbot_2 has joined #openstack-keystone | 21:54 | |
*** altlogbot_3 has joined #openstack-keystone | 21:55 | |
*** altlogbot_3 has quit IRC | 21:55 | |
*** irclogbot_2 has quit IRC | 21:59 | |
*** rcernin has joined #openstack-keystone | 22:10 | |
*** jamesmcarthur has joined #openstack-keystone | 22:21 | |
*** awalende has joined #openstack-keystone | 22:37 | |
*** awalende has quit IRC | 22:42 | |
*** altlogbot_0 has joined #openstack-keystone | 22:44 | |
*** Krenair has joined #openstack-keystone | 22:47 | |
*** altlogbot_0 has quit IRC | 22:49 | |
*** tkajinam has joined #openstack-keystone | 22:52 | |
kmalloc | ayoung: yes i did for a while | 23:12 |
*** jamesmcarthur has quit IRC | 23:21 | |
*** jamesmcarthur has joined #openstack-keystone | 23:42 | |
gyee | cmurphy, lbragstad, https://bugs.launchpad.net/keystone/+bug/1813335 is not related to x.509. I think the doc is wrong. X.509 should always be used with federation. | 23:42 |
openstack | Launchpad bug 1813335 in OpenStack Identity (keystone) "x509 configured domains are redundant with auto-generated identity provider domains" [Low,Triaged] | 23:42 |
gyee | I even go as far as saying the remote user plugin is quite dangerous :-) | 23:42 |
cmurphy | gyee: you mean instead of 'external' ? | 23:44 |
cmurphy | i thought x.509 was the classic use case for the external auth method | 23:44 |
cmurphy | gyee: i'm reviewing your doc change now btw | 23:45 |
*** jamesmcarthur has quit IRC | 23:46 | |
gyee | no, x.509 is not designed for external auth | 23:47 |
gyee | x.509 should always be using the federation mechanism | 23:47 |
cmurphy | kmalloc: ayoung ^ | 23:48 |
gyee | external auth, which trust a single attribute (REMOTE_USER), is quite dangerous | 23:48 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!