*** dave-mccowan has joined #openstack-security | 00:11 | |
openstackgerrit | Charles Neill proposed openstack/syntribos: Adding unittests for datagen https://review.openstack.org/276512 | 00:18 |
---|---|---|
*** edtubill has quit IRC | 00:29 | |
*** salv-orl_ has quit IRC | 00:54 | |
*** ccneill has quit IRC | 00:57 | |
*** winterIsLeaving has joined #openstack-security | 01:01 | |
*** winterIsLeaving has quit IRC | 01:38 | |
*** tmcpeak has quit IRC | 01:42 | |
*** raginbajin has quit IRC | 01:42 | |
*** raginbajin has joined #openstack-security | 01:46 | |
*** edmondsw has quit IRC | 02:10 | |
*** ccneill has joined #openstack-security | 02:32 | |
*** ccneill has left #openstack-security | 02:34 | |
*** browne has quit IRC | 03:00 | |
*** rtmorgan has quit IRC | 03:06 | |
*** rtmorgan has joined #openstack-security | 03:06 | |
*** yuanying_ has joined #openstack-security | 03:18 | |
*** yuanying has quit IRC | 03:21 | |
*** browne has joined #openstack-security | 03:37 | |
*** browne has quit IRC | 03:38 | |
*** yuanying has joined #openstack-security | 03:42 | |
*** yuanying_ has quit IRC | 03:44 | |
*** dave-mccowan has quit IRC | 04:00 | |
*** localloop127 has joined #openstack-security | 04:01 | |
*** kenn1 has joined #openstack-security | 04:05 | |
kenn1 | hola | 04:05 |
*** yuanying has quit IRC | 04:06 | |
*** yuanying has joined #openstack-security | 04:07 | |
kenn1 | bastardooos | 04:10 |
kenn1 | respondan mierdaaaaaa | 04:10 |
*** kenn1 has left #openstack-security | 04:15 | |
*** diazjf has joined #openstack-security | 04:29 | |
*** diazjf has quit IRC | 04:30 | |
*** localloop127 has quit IRC | 05:05 | |
*** salv-orlando has joined #openstack-security | 05:08 | |
*** salv-orlando has quit IRC | 05:18 | |
*** agireud has quit IRC | 05:20 | |
*** agireud has joined #openstack-security | 05:23 | |
*** yuanying_ has joined #openstack-security | 06:08 | |
*** yuanying has quit IRC | 06:11 | |
*** yuanying_ has quit IRC | 06:13 | |
*** yuanying has joined #openstack-security | 06:14 | |
*** yuanying has quit IRC | 06:15 | |
*** yuanying has joined #openstack-security | 06:28 | |
*** winterIsLeaving has joined #openstack-security | 07:08 | |
*** salv-orlando has joined #openstack-security | 08:45 | |
*** salv-orlando has quit IRC | 08:49 | |
*** salv-orlando has joined #openstack-security | 09:00 | |
*** openstackgerrit has quit IRC | 09:17 | |
*** openstackgerrit has joined #openstack-security | 09:17 | |
*** markvoelker has quit IRC | 09:20 | |
*** markvoelker has joined #openstack-security | 10:21 | |
*** markvoelker has quit IRC | 10:26 | |
*** dave-mccowan has joined #openstack-security | 10:36 | |
*** salv-orl_ has joined #openstack-security | 10:39 | |
*** salv-orlando has quit IRC | 10:42 | |
*** winterIsLeaving has quit IRC | 10:44 | |
*** dave-mccowan has quit IRC | 10:58 | |
*** nkinder has joined #openstack-security | 11:00 | |
*** mirona has quit IRC | 11:11 | |
openstackgerrit | venkatamahesh proposed openstack/security-doc: Fix exact link for home-page https://review.openstack.org/276690 | 11:24 |
*** mirona has joined #openstack-security | 11:25 | |
openstackgerrit | Merged openstack/anchor: Correct the bandit test dependency https://review.openstack.org/276412 | 11:47 |
*** nkinder has quit IRC | 11:59 | |
*** salv-orl_ has quit IRC | 12:01 | |
*** markvoelker has joined #openstack-security | 12:22 | |
*** markvoelker has quit IRC | 12:27 | |
*** salv-orlando has joined #openstack-security | 12:29 | |
*** salv-orlando has quit IRC | 13:13 | |
*** markvoelker has joined #openstack-security | 13:23 | |
*** samueldmq1 has joined #openstack-security | 13:24 | |
*** markvoelker_ has joined #openstack-security | 13:24 | |
*** markvoelker has quit IRC | 13:24 | |
*** samueldmq1 has quit IRC | 13:28 | |
*** edmondsw has joined #openstack-security | 13:34 | |
*** localloop127 has joined #openstack-security | 13:35 | |
*** nkinder has joined #openstack-security | 13:50 | |
*** dave-mccowan has joined #openstack-security | 14:06 | |
*** jmckind has joined #openstack-security | 14:06 | |
*** salv-orlando has joined #openstack-security | 14:13 | |
*** agireud has quit IRC | 14:17 | |
*** agireud has joined #openstack-security | 14:19 | |
*** salv-orlando has quit IRC | 14:30 | |
*** mvaldes has joined #openstack-security | 14:35 | |
*** mvaldes1 has joined #openstack-security | 14:37 | |
*** mvaldes has quit IRC | 14:39 | |
*** ninag has joined #openstack-security | 14:50 | |
*** rtmorgan has quit IRC | 14:58 | |
*** samueldmq1 has joined #openstack-security | 15:00 | |
*** edtubill has joined #openstack-security | 15:03 | |
*** samueldmq1 has quit IRC | 15:05 | |
*** mvaldes1 has quit IRC | 15:07 | |
*** jhfeng has joined #openstack-security | 15:08 | |
*** mvaldes has joined #openstack-security | 15:10 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 15:10 | |
*** mvaldes has quit IRC | 15:14 | |
*** dave-mccowan has quit IRC | 15:17 | |
*** nkinder has quit IRC | 15:18 | |
*** nkinder has joined #openstack-security | 15:28 | |
*** dave-mccowan has joined #openstack-security | 15:32 | |
*** nkinder has quit IRC | 16:14 | |
openstackgerrit | Greg Anderson proposed openstack/syntribos: XSS Body Test https://review.openstack.org/276458 | 16:17 |
openstackgerrit | Michael Dong proposed openstack/syntribos: XSS Body Test https://review.openstack.org/276458 | 16:18 |
*** timkennedy1 has joined #openstack-security | 16:32 | |
*** diazjf has joined #openstack-security | 16:34 | |
*** timkennedy2 has joined #openstack-security | 16:35 | |
*** timkennedy has quit IRC | 16:35 | |
*** hyakuhei has joined #openstack-security | 16:36 | |
*** timkennedy1 has quit IRC | 16:37 | |
*** bpokorny has joined #openstack-security | 16:51 | |
elmiko | sigmavirus24: hey, trying to do some bandit stuff today and i'm getting this http://paste.openstack.org/show/486114/ does that look familiar? | 16:59 |
*** mvaldes has joined #openstack-security | 17:04 | |
sigmavirus24 | elmiko: that's surprising to be happening on 0.10.1 | 17:04 |
elmiko | sigmavirus24: yea, not sure what i did. i switched my tox to 2.3.1 and python to 3.4, now it's sad =( | 17:04 |
elmiko | oh well, i think i'll just update to bandit 0.17.3. this seems to be working | 17:05 |
*** nkinder has joined #openstack-security | 17:05 | |
elmiko | sigmavirus24: thanks! | 17:05 |
sigmavirus24 | elmiko: that's super surprising | 17:05 |
elmiko | huh, seems to work fine with py2.7.10 | 17:09 |
elmiko | oh well, it's such an old version of bandit | 17:09 |
*** avarner_ has joined #openstack-security | 17:10 | |
openstackgerrit | Christopher J Schaefer proposed openstack/bandit: Moving bandit baseline unit tests https://review.openstack.org/276836 | 17:10 |
*** avarner has quit IRC | 17:14 | |
*** nkinder has quit IRC | 17:27 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 17:39 | |
*** ibravo has joined #openstack-security | 17:41 | |
*** salv-orlando has joined #openstack-security | 17:55 | |
*** diazjf has quit IRC | 17:56 | |
*** diazjf has joined #openstack-security | 18:05 | |
*** ibravo has quit IRC | 18:14 | |
*** mvaldes has quit IRC | 18:16 | |
*** diazjf has quit IRC | 18:24 | |
*** liverpooler has joined #openstack-security | 18:27 | |
*** liverpoo1er has joined #openstack-security | 18:28 | |
*** browne has joined #openstack-security | 18:44 | |
*** jhfeng_ has joined #openstack-security | 18:47 | |
*** jhfeng has quit IRC | 18:50 | |
*** localloop127 has quit IRC | 18:53 | |
*** localloop127 has joined #openstack-security | 18:56 | |
openstackgerrit | Greg Anderson proposed openstack/syntribos: XSS Body Test https://review.openstack.org/276458 | 19:01 |
openstackgerrit | Michael Dong proposed openstack/syntribos: XSS Body Test https://review.openstack.org/276458 | 19:02 |
*** mvaldes has joined #openstack-security | 19:09 | |
*** jhfeng_ has quit IRC | 19:09 | |
*** mvaldes1 has joined #openstack-security | 19:10 | |
*** mvaldes has quit IRC | 19:13 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 19:14 | |
*** localloop127 has quit IRC | 19:18 | |
*** localloop127 has joined #openstack-security | 19:21 | |
*** salv-orlando has quit IRC | 19:24 | |
*** hyakuhei has quit IRC | 19:40 | |
*** avarner_ has quit IRC | 19:44 | |
openstackgerrit | Christopher J Schaefer proposed openstack/bandit: Added cli.main unit tests https://review.openstack.org/276889 | 19:45 |
*** sigmavirus24 is now known as sigmavirus24_awa | 19:52 | |
*** diazjf has joined #openstack-security | 19:58 | |
*** agireud has quit IRC | 20:00 | |
*** agireud has joined #openstack-security | 20:02 | |
*** dave-mccowan has quit IRC | 20:14 | |
*** jhfeng has joined #openstack-security | 20:19 | |
*** localloop127 has quit IRC | 20:20 | |
*** salv-orlando has joined #openstack-security | 20:24 | |
*** avarner has joined #openstack-security | 20:27 | |
*** diazjf has quit IRC | 20:35 | |
*** dave-mccowan has joined #openstack-security | 20:37 | |
*** diazjf has joined #openstack-security | 20:40 | |
*** diazjf has quit IRC | 20:40 | |
*** diazjf has joined #openstack-security | 20:41 | |
*** jmckind has quit IRC | 20:50 | |
*** localloop127 has joined #openstack-security | 20:51 | |
*** hyakuhei has joined #openstack-security | 20:52 | |
*** hyakuhei has quit IRC | 20:56 | |
*** hyakuhei has joined #openstack-security | 21:02 | |
*** hyakuhei has quit IRC | 21:05 | |
*** ahilsinhas has joined #openstack-security | 21:09 | |
*** winterIsLeaving has joined #openstack-security | 21:11 | |
*** jhfeng has quit IRC | 21:12 | |
*** mvaldes1 has quit IRC | 21:15 | |
*** diazjf has quit IRC | 21:42 | |
*** localloop127 has quit IRC | 21:43 | |
*** jhfeng has joined #openstack-security | 22:01 | |
*** ibravo has joined #openstack-security | 22:35 | |
*** salv-orl_ has joined #openstack-security | 22:40 | |
*** salv-orlando has quit IRC | 22:43 | |
*** ninag has quit IRC | 22:44 | |
ahilsinhas | hello - i have a question regarding public endpoints. i've attempted the cryptographic separation of internal and external environments and the public endpoint is on a physically isolated network from internal/admin endpoints. if i pass the os-interface public argument from a public remote client everything works, however without it it leaks my internal endpoint. im wondering if this is a problem that im causing or a problem | 22:51 |
ahilsinhas | token issue seems to work without specifying the os-interface option, however any other command without will yeild an error for keystone:35357 | 22:53 |
elmiko | ahilsinhas: could you describe a little more about how it is leaking? | 22:54 |
elmiko | (for example, what command are you running?) | 22:54 |
ahilsinhas | elmiko: absolutely! | 22:54 |
ahilsinhas | service list, endpoint-list, set password (2 of those should return a 403 for this user and do with the option set) | 22:55 |
ahilsinhas | it appears without the option right after the token issue the remote client using public endpoints tries to use an admin endpoint | 22:55 |
elmiko | is this using the openstack common cli tool? | 22:55 |
ahilsinhas | yes | 22:55 |
ahilsinhas | v 1.7.0 | 22:56 |
elmiko | interesting | 22:56 |
ahilsinhas | and leaks the admin endpoint ;p | 22:56 |
ahilsinhas | now this could be totally because of my configuration and probably is | 22:56 |
elmiko | you may want to ask around in #openstack-sdks, it's possible you've found a bug | 22:56 |
ahilsinhas | it felt kinda like one | 22:56 |
elmiko | also, do you have any environment variables or config files that may be affecting the endpoint option when you do not specify it? | 22:57 |
ahilsinhas | you know i might | 22:57 |
elmiko | (i'm not sure what the default it | 22:57 |
ahilsinhas | ill check | 22:57 |
ahilsinhas | haha i do | 22:58 |
elmiko | ;) | 22:58 |
ahilsinhas | actually false alarm | 22:58 |
ahilsinhas | they all us the OOS prefix | 22:58 |
elmiko | ok, so it really *is* failing with the leakage? | 22:59 |
ahilsinhas | ya | 22:59 |
elmiko | so yea, next step would be either to ask in openstack-sdks, or report a bug to the openstackclient launchpad | 22:59 |
ahilsinhas | ok | 22:59 |
elmiko | you may have uncovered something that was not intended, and it sounds fairly reproduceable | 23:00 |
ahilsinhas | i am concerned that perhaps i set up my public/private endpoints wrong | 23:00 |
*** ibravo has quit IRC | 23:00 | |
elmiko | that's possible too | 23:00 |
ahilsinhas | particularly their references in keystone.conf | 23:00 |
elmiko | do you have them setup in the service catalog endpoint list properly? | 23:00 |
ahilsinhas | ya i think the error should be repeatable and i can write it up | 23:00 |
openstackgerrit | Merged openstack/bandit: Moving bandit baseline unit tests https://review.openstack.org/276836 | 23:01 |
ahilsinhas | endpoints are set up appropriately i refer to internal/admin endpoints via hostname | 23:01 |
elmiko | great, i know there is some confusion around the ways that public/internal/admin interfaces are used. so it may be something common | 23:01 |
ahilsinhas | which has entries in /etc/hosts per the ubuntu install guide | 23:01 |
ahilsinhas | ya it is a bit confusing | 23:01 |
ahilsinhas | but i *think* i got it right | 23:01 |
elmiko | agreed | 23:01 |
ahilsinhas | public endpoint is a domain with dns entries to public ip | 23:02 |
ahilsinhas | only port 5000 is exposed | 23:02 |
ahilsinhas | for now | 23:02 |
elmiko | then yea, maybe just report a bug or ask the sdks guys. although, it might be kinda quiet in there given its late on friday u.s. time | 23:02 |
ahilsinhas | i will for sure | 23:02 |
ahilsinhas | i suppose i can be happy that everything works when i pass the option | 23:02 |
elmiko | so, you are saying that when you try to `openstack token issue` without specifying the os-endpoint, then you see it try to hit the adminURL ? | 23:03 |
ahilsinhas | ooo good question | 23:03 |
ahilsinhas | i believe for token | 23:03 |
ahilsinhas | it is 100% port 5000 public | 23:03 |
elmiko | ok, cool | 23:03 |
ahilsinhas | but token always happens for everything right? | 23:03 |
elmiko | yea | 23:03 |
ahilsinhas | so for any other command token goes OK and then it tries private endpoints unless i specify the option | 23:04 |
ahilsinhas | so i do have one specific question | 23:04 |
elmiko | hmm | 23:04 |
elmiko | sure | 23:04 |
ahilsinhas | these things all only started to work when i set admin_endpoint and public_endpoint in keystone.conf | 23:04 |
* elmiko digs out his keystone.conf | 23:05 | |
ahilsinhas | to hostname:35357 and publicurl:5000 respectively | 23:05 |
ahilsinhas | ;p | 23:05 |
elmiko | and that controller is serving both hostname and publicurl? | 23:07 |
ahilsinhas | oo i also have auth_uri twice, once with public and private | 23:07 |
ahilsinhas | yes unfortunately for now | 23:07 |
elmiko | auth_uri in your keystone.conf? | 23:07 |
ahilsinhas | yes | 23:07 |
ahilsinhas | those iirc had no real impact | 23:08 |
ahilsinhas | on things working or not | 23:08 |
elmiko | hmm, yea. i don't understand auth_uri inside keystone.conf | 23:08 |
ahilsinhas | i took it from the gentoo-openstack guy's blog when he was talking about ssl keystone ;p | 23:08 |
elmiko | does that keystone controller talk to another keystone or a kerb or something? | 23:08 |
elmiko | :q | 23:09 |
elmiko | mt | 23:09 |
ahilsinhas | oh my ill have to change that anyway - im actually planning on using oidc for auth so maybe that setting has to do with federation? | 23:09 |
ahilsinhas | anyway i think that might be a red herring | 23:09 |
elmiko | i would think so, usually auth_url instructs the keystone middleware on where it can make identity requests | 23:10 |
ahilsinhas | the question is how do you properly refer to public and private endpoints within keystone.conf itself? | 23:10 |
elmiko | yea, probably | 23:10 |
elmiko | i think you have it correct by specifying the public_endpoint admin_endpoint | 23:10 |
ahilsinhas | those were my thoughts | 23:10 |
ahilsinhas | agreed then it very well may be leaking | 23:10 |
elmiko | and put them on separate IPs or whatever | 23:11 |
ahilsinhas | they are | 23:11 |
elmiko | trying to look at the openstackclient source now | 23:11 |
ahilsinhas | the public ip cant even route to the private one | 23:11 |
ahilsinhas | ditto | 23:11 |
ahilsinhas | i can give you the exception | 23:11 |
ahilsinhas | hold on | 23:11 |
ahilsinhas | well that might not help | 23:11 |
ahilsinhas | it will with full trace perhaps | 23:12 |
*** edmondsw has quit IRC | 23:13 | |
ahilsinhas | elmiko: http://pastebin.com/arHUMFjw | 23:13 |
ahilsinhas | ha shit my home is in there | 23:14 |
ahilsinhas | ;p | 23:14 |
elmiko | huh, i wonder if it just tries admin as a backup? | 23:15 |
ahilsinhas | what file(s) were you thinking relevant in the client? | 23:16 |
elmiko | not sure, i'm trying to figure out where it grabs the --os-endpoint option from | 23:17 |
ahilsinhas | oo good idea | 23:17 |
elmiko | i thought it was os-client-config | 23:17 |
ahilsinhas | im looking at service catalog generation | 23:18 |
ahilsinhas | self.app.client_manager.identity.services.list() | 23:18 |
ahilsinhas | so im guessing service "Type" is public/internal/admin | 23:20 |
ahilsinhas | what is the name of an endpoint? | 23:20 |
elmiko | i would think so, but i haven't played around with that option on the cli | 23:20 |
elmiko | well, i guess regardless of the option, it shouldn't be leaking those details | 23:22 |
ahilsinhas | yes definitely | 23:22 |
ahilsinhas | which is why i came here ;p | 23:22 |
ahilsinhas | ill go to sdk and keep plugging along with the deployment and see if i come across any other issues | 23:23 |
ahilsinhas | tricky cause im never sure if its me that is the problem ;p | 23:23 |
elmiko | good luck, sorry i couldn't be of more help :/ | 23:23 |
elmiko | totally | 23:23 |
ahilsinhas | elmiko: you were totally helpful | 23:23 |
ahilsinhas | thank you so much | 23:23 |
elmiko | np =) | 23:23 |
ahilsinhas | confirming that im generally doing public/internal/admin right was a load off | 23:24 |
elmiko | i *think* you are, but there are probably more details here that need to be exposed | 23:24 |
ahilsinhas | ya i think creating a bug is perhaps sensible | 23:24 |
ahilsinhas | i wish i could have someone reproduce | 23:25 |
*** ninag has joined #openstack-security | 23:25 | |
*** ninag has quit IRC | 23:25 | |
*** edtubill has quit IRC | 23:26 | |
*** jhfeng has quit IRC | 23:33 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!