*** jamesmcarthur has joined #openstack-keystone | 00:05 | |
*** gyee has quit IRC | 00:07 | |
*** tkajinam has quit IRC | 00:10 | |
*** jamesmcarthur has quit IRC | 00:15 | |
*** dancn has quit IRC | 00:16 | |
*** ayoung has quit IRC | 01:11 | |
*** imacdonn has quit IRC | 01:18 | |
*** imacdonn has joined #openstack-keystone | 01:18 | |
*** jamesmcarthur has joined #openstack-keystone | 01:24 | |
*** jamesmcarthur_ has joined #openstack-keystone | 01:32 | |
*** jamesmcarthur has quit IRC | 01:34 | |
*** whoami-rajat has joined #openstack-keystone | 01:43 | |
*** jamesmcarthur_ has quit IRC | 02:35 | |
*** ayoung has joined #openstack-keystone | 03:14 | |
*** rcernin has quit IRC | 04:13 | |
*** rcernin has joined #openstack-keystone | 04:14 | |
*** rcernin has quit IRC | 04:20 | |
*** etp has joined #openstack-keystone | 04:25 | |
*** etp has quit IRC | 04:26 | |
*** etp has joined #openstack-keystone | 04:27 | |
*** pcaruana has joined #openstack-keystone | 04:43 | |
*** vishwanathj has quit IRC | 04:51 | |
*** vishwanathj has joined #openstack-keystone | 04:52 | |
openstackgerrit | Andreas Jaeger proposed openstack/keystone master: Update api-ref location https://review.opendev.org/672096 | 04:56 |
---|---|---|
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remove [signing] config https://review.opendev.org/659434 | 05:17 |
*** jamesmcarthur has joined #openstack-keystone | 05:55 | |
*** vishwanathj has quit IRC | 05:55 | |
*** jamesmcarthur has quit IRC | 05:56 | |
*** vishwanathj has joined #openstack-keystone | 05:56 | |
*** jamesmcarthur has joined #openstack-keystone | 06:09 | |
*** jhesketh has quit IRC | 06:11 | |
*** jhesketh has joined #openstack-keystone | 06:11 | |
*** jamesmcarthur has quit IRC | 06:13 | |
*** jamesmcarthur has joined #openstack-keystone | 06:16 | |
*** jamesmcarthur_ has joined #openstack-keystone | 06:28 | |
*** jamesmca_ has joined #openstack-keystone | 06:31 | |
*** etp has quit IRC | 06:31 | |
*** etp_ has joined #openstack-keystone | 06:31 | |
*** jamesmcarthur has quit IRC | 06:32 | |
*** etp_ has quit IRC | 06:35 | |
*** jamesmcarthur_ has quit IRC | 06:35 | |
*** etp has joined #openstack-keystone | 06:35 | |
*** etp has quit IRC | 06:36 | |
*** etp_ has joined #openstack-keystone | 06:36 | |
*** jamesmca_ has quit IRC | 06:38 | |
*** etp_ has quit IRC | 06:40 | |
*** jamesmcarthur has joined #openstack-keystone | 06:43 | |
*** etp has joined #openstack-keystone | 06:45 | |
*** jamesmcarthur has quit IRC | 06:51 | |
*** jamesmcarthur has joined #openstack-keystone | 06:53 | |
*** tesseract has joined #openstack-keystone | 07:09 | |
*** irclogbot_1 has quit IRC | 07:20 | |
*** jdennis has quit IRC | 07:20 | |
*** openstackstatus has quit IRC | 07:20 | |
*** jdennis has joined #openstack-keystone | 07:21 | |
*** irclogbot_1 has joined #openstack-keystone | 07:21 | |
*** dansmith has quit IRC | 07:23 | |
*** cwright has quit IRC | 07:23 | |
*** dansmith has joined #openstack-keystone | 07:24 | |
*** Anticimex has quit IRC | 07:24 | |
*** jamesmcarthur has quit IRC | 07:24 | |
*** cwright has joined #openstack-keystone | 07:24 | |
*** Anticimex has joined #openstack-keystone | 07:29 | |
*** ivve has joined #openstack-keystone | 08:22 | |
*** ileixe has quit IRC | 08:49 | |
*** jojoda has quit IRC | 09:45 | |
*** jaosorior has joined #openstack-keystone | 09:52 | |
*** rdopiera has joined #openstack-keystone | 11:14 | |
rdopiera | hello there, I'm working on adding the ability to change expired password to horizon, and I have some problems calling the change_password API with keystoneclient without authenticating | 11:15 |
rdopiera | the docs say that this API doesn't require authentication, but I still get keystoneauth1.exceptions.auth.AuthorizationFailure from keystone client when I try to call it | 11:15 |
rdopiera | with "o valid authentication is available" | 11:16 |
rdopiera | does anybody know how to call that API without auth properly? | 11:16 |
*** raildo has joined #openstack-keystone | 11:35 | |
*** markvoelker has quit IRC | 11:58 | |
*** kplant has joined #openstack-keystone | 12:06 | |
*** etp has quit IRC | 12:11 | |
*** markvoelker has joined #openstack-keystone | 12:16 | |
openstackgerrit | Vishakha Agarwal proposed openstack/keystone master: Remove [signing] config https://review.opendev.org/659434 | 12:45 |
*** jamesmcarthur has joined #openstack-keystone | 13:08 | |
cmurphy | o/ | 13:11 |
*** jamesmcarthur has quit IRC | 13:18 | |
*** openstackstatus has joined #openstack-keystone | 13:21 | |
*** ChanServ sets mode: +v openstackstatus | 13:21 | |
*** jamesmcarthur has joined #openstack-keystone | 13:39 | |
cmurphy | starting the second midcycle session in a few minutes in https://global.gotomeeting.com/join/672157765 | 13:52 |
*** jamesmcarthur has quit IRC | 13:58 | |
*** lbragstad has joined #openstack-keystone | 14:00 | |
kmalloc | Few | 14:01 |
kmalloc | Minutes late. But will be there. | 14:01 |
lbragstad | https://bugs.launchpad.net/keystone/+bugs?field.tag=policy | 14:07 |
lbragstad | https://bugs.launchpad.net/keystone/+bugs?field.tag=default-roles | 14:08 |
lbragstad | https://bugs.launchpad.net/keystone/+bugs?field.tag=system-scope | 14:08 |
lbragstad | https://bugs.launchpad.net/keystone/+bug/1805363 | 14:09 |
openstack | Launchpad bug 1805363 in OpenStack Identity (keystone) "Oauth1 Consumer API doesn't use default roles" [Medium,Triaged] | 14:09 |
lbragstad | https://developer.openstack.org/api-ref/identity/v3-ext/index.html#os-oauth1-api | 14:12 |
lbragstad | this is the intended flow? https://developer.openstack.org/api-ref/identity/v3-ext/index.html#delegated-authentication-flow | 14:13 |
lbragstad | https://opendev.org/openstack/keystone/src/branch/master/keystone/common/policies/consumer.py | 14:16 |
lbragstad | https://bugs.launchpad.net/keystone/+bug/1805366 | 14:22 |
openstack | Launchpad bug 1805366 in OpenStack Identity (keystone) "Domain config API doesn't use default roles" [Medium,Triaged] | 14:22 |
*** gyee has joined #openstack-keystone | 14:23 | |
lbragstad | https://opendev.org/openstack/keystone/src/branch/master/keystone/common/policies/domain_config.py#L74-L101 | 14:28 |
lbragstad | https://bugs.launchpad.net/keystone/+bug/1750669 grant scope types bug | 14:36 |
openstack | Launchpad bug 1750669 in OpenStack Identity (keystone) "The v3 grant API should account for different scopes" [High,In progress] - Assigned to Lance Bragstad (lbragstad) | 14:36 |
cmurphy | lbragstad: you left us :'( | 14:37 |
*** lbragstad has quit IRC | 14:40 | |
cmurphy | taking a break, returning 14:55 | 14:42 |
*** lbragstad has joined #openstack-keystone | 14:43 | |
lbragstad | are people still on the call? | 14:44 |
cmurphy | lbragstad: still here but taking a break, kmalloc is dogwalking | 14:44 |
lbragstad | ah | 14:44 |
vishakha | lbragstad: we took 15 mins break | 14:44 |
lbragstad | sorry - my network dropped me | 14:45 |
lbragstad | are we starting at the top of the hour? | 14:45 |
cmurphy | lbragstad: 5 till | 14:45 |
lbragstad | ok | 14:45 |
lbragstad | thanks | 14:45 |
* cmurphy calls everybody back | 14:55 | |
kmalloc | woof | 15:00 |
cmurphy | :'D | 15:00 |
lbragstad | https://bugs.launchpad.net/keystone/+bug/1805371 | 15:00 |
openstack | Launchpad bug 1805371 in OpenStack Identity (keystone) "Implied role API doesn't support default roles" [Medium,Triaged] | 15:00 |
lbragstad | ayoung just fyi - we're going through you comments on https://bugs.launchpad.net/keystone/+bug/1805371 and curious if you could clarify something | 15:13 |
openstack | Launchpad bug 1805371 in OpenStack Identity (keystone) "Implied role API doesn't support default roles" [Medium,Triaged] | 15:13 |
*** trident has quit IRC | 15:18 | |
lbragstad | https://bugs.launchpad.net/keystone/+bug/1818725 | 15:19 |
openstack | Launchpad bug 1818725 in OpenStack Identity (keystone) "Application credential API doesn't use default roles" [Medium,In progress] - Assigned to Guang Yee (guang-yee) | 15:19 |
*** trident has joined #openstack-keystone | 15:20 | |
lbragstad | https://bugs.launchpad.net/keystone/+bug/1750615 | 15:28 |
openstack | Launchpad bug 1750615 in OpenStack Identity (keystone) "The v3 application credential API should account for different scopes" [High,In progress] - Assigned to Guang Yee (guang-yee) | 15:28 |
lbragstad | gyee https://opendev.org/openstack/keystone/src/branch/master/keystone/common/policies/application_credential.py | 15:29 |
gyee | https://github.com/openstack/keystone/blob/master/keystone/api/users.py#L596-#L599 | 15:33 |
lbragstad | https://bugs.launchpad.net/keystone/+bug/1818732 | 15:39 |
openstack | Launchpad bug 1818732 in OpenStack Identity (keystone) "EC2 credential API doesn't use default roles" [Low,Triaged] | 15:39 |
*** david-lyle is now known as dklyle | 15:40 | |
*** trident has quit IRC | 15:52 | |
*** jaosorior has quit IRC | 15:53 | |
*** trident has joined #openstack-keystone | 15:55 | |
*** Ben78 has joined #openstack-keystone | 16:01 | |
Ben78 | I have an idea to improve Fernet token. I am looking for a collaborator. | 16:01 |
*** tesseract has quit IRC | 16:07 | |
kmalloc | Ben78: what idea are you thinking about, feel free to share it here and/or open an RFE bug at bugs.launchpad.net/keystone/+bugs | 16:11 |
kmalloc | Ben78: also we (the keystone team) are participating in a virtual midcycle meeting right now, some folks may not respond as quickly | 16:12 |
kmalloc | this will be over later today and everything should be back to more normal as of tomorrow. | 16:13 |
Ben78 | The idea is part of my PhD thesis. So, I am not allowed to publicly share it, before submitting a paper. | 16:15 |
kmalloc | Ben78: can you give us an idea of what kind of changes you're looking at? without too many details. part of the open source process tends to push heavily for open communication about planning. I get that there are some limits when it comes to academia, but I'd need a little more than "i have an idea" to help give you some guidance :) | 16:18 |
kmalloc | if it's core to the Fernet protocol itself, it's different than how keystone utilizes it. | 16:18 |
kmalloc | for example | 16:18 |
kmalloc | cmurphy, lbragstad: cc ^ | 16:20 |
cmurphy | +1 we collaborate openly here, i'm happy to help in the open | 16:22 |
Ben78 | Thanks guys. As you know, Fernet token can be used in any modular system. Our proposal can be utilized in any modular system. We chose OpenStack as a test-bed and we believe that it can solve the bearer token problems. I can share the detail via email. | 16:28 |
Ben78 | We have breifly mentioned the idea in https://eprint.iacr.org/2018/602.pdf at page 79 (RAFT) | 16:32 |
*** trident has quit IRC | 17:07 | |
*** trident has joined #openstack-keystone | 17:10 | |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Deprecate identity:revocation_list policy for removal https://review.opendev.org/672334 | 17:22 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain reader support for grants https://review.opendev.org/645968 | 17:56 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Implement domain admin support for grants https://review.opendev.org/667730 | 17:56 |
openstackgerrit | Lance Bragstad proposed openstack/keystone master: Remove obsolete grant policies from policy.v3cloudsample.json https://review.opendev.org/667731 | 17:56 |
Ben78 | The main idea is as follows: | 18:23 |
Ben78 | - Keystone continues to issue Fernet tokens. | 18:23 |
Ben78 | - Each party does not pass the received token to any other party except Keystone ( for validation). | 18:23 |
Ben78 | - Whenever a party needs a service from any OpenStack module, it issues a Recursive Augmented Fernet Token (RAFT) . | 18:23 |
Ben78 | - A RAFT token is a self-descriptive cryptographic token, which is valid if the Original Fernet token is valid. Only, Keystone can extract the original Fernet token from a RAFT token. | 18:23 |
*** spilla has joined #openstack-keystone | 18:28 | |
openstackgerrit | Merged openstack/keystone master: Fixing dn_to_id function for cases were id is not in the DN https://review.opendev.org/649177 | 18:52 |
*** Ben78 has quit IRC | 19:04 | |
kplant | is it possible to use openid for k2k instead of saml2 with mellon/shib? | 19:05 |
knikolla | kplant: are you referring to openid connect or plain openid? | 19:19 |
*** spilla has quit IRC | 19:20 | |
cmurphy | kplant: knikolla either way keystone as an idp only supports saml | 19:20 |
knikolla | cmurphy: oh, i missed the k2k part of the question :) | 19:21 |
kplant | knikolla: openidc | 19:21 |
kplant | cmurphy: ty | 19:21 |
*** whoami-rajat has quit IRC | 19:22 | |
kplant | bah. the only thing i could get kind of working was keystone(sp) -> keycloak with openidc... i've had absolutely zero luck with saml2 | 19:26 |
kplant | i see a lot of scripts and guides using 'mapped' instead of explicitly configuring saml2/openid as the auth type. is there a reason for that? | 19:27 |
cmurphy | kplant: it's a little jumbled because we created the 'mapped' plugin which works for all types of federated auth so we encouraged people to use that, but since the plugin is configured globally in keystone.conf it inhibits you from setting up more than one service provider per keystone so we kind of switched back | 19:31 |
kplant | aaah that makes sense | 19:32 |
cmurphy | if you use 'mapped' just make sure that all the protocol IDs are also named 'mapped' including in the apache paths, or same for 'saml2', just be consistent | 19:32 |
*** spilla has joined #openstack-keystone | 19:42 | |
*** kplant has quit IRC | 19:54 | |
*** lbragstad has quit IRC | 20:01 | |
*** Ben78 has joined #openstack-keystone | 20:50 | |
*** pcaruana has quit IRC | 20:50 | |
*** spilla has quit IRC | 20:56 | |
*** ayoung has quit IRC | 21:31 | |
*** altlogbot_1 has quit IRC | 21:33 | |
*** irclogbot_1 has quit IRC | 21:33 | |
*** altlogbot_0 has joined #openstack-keystone | 21:34 | |
*** irclogbot_2 has joined #openstack-keystone | 21:34 | |
*** irclogbot_2 has quit IRC | 21:59 | |
*** altlogbot_0 has quit IRC | 22:01 | |
*** adriant has quit IRC | 22:11 | |
*** altlogbot_1 has joined #openstack-keystone | 22:22 | |
*** gyee has quit IRC | 22:23 | |
*** altlogbot_1 has quit IRC | 22:27 | |
*** raildo has quit IRC | 22:35 | |
*** tkajinam has joined #openstack-keystone | 22:51 | |
*** ayoung has joined #openstack-keystone | 22:53 | |
*** gyee has joined #openstack-keystone | 23:10 | |
*** altlogbot_0 has joined #openstack-keystone | 23:14 | |
*** rcernin has joined #openstack-keystone | 23:16 | |
*** altlogbot_0 has quit IRC | 23:19 | |
*** altlogbot_0 has joined #openstack-keystone | 23:28 | |
*** Ben78 has quit IRC | 23:31 | |
*** irclogbot_3 has joined #openstack-keystone | 23:32 | |
*** jamesmcarthur has joined #openstack-keystone | 23:36 | |
*** spilla has joined #openstack-keystone | 23:38 | |
*** jamesmcarthur has quit IRC | 23:52 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!