*** zhihui has joined #openstack-security | 01:34 | |
openstackgerrit | zhangyanxian proposed openstack/syntribos: Fix some typos in the files https://review.openstack.org/355272 | 01:35 |
---|---|---|
openstackgerrit | zhangyanxian proposed openstack/syntribos: Fix some typos in the files https://review.openstack.org/355272 | 01:53 |
openstackgerrit | zhangyanxian proposed openstack/syntribos: Fix some typos in the files https://review.openstack.org/355272 | 02:01 |
*** jamielennox is now known as jamielennox|away | 02:10 | |
*** jamielennox|away is now known as jamielennox | 02:30 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Fix html escaping https://review.openstack.org/355283 | 03:09 |
openstackgerrit | Merged openstack/bandit: Fix html escaping https://review.openstack.org/355283 | 03:34 |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Show help when arguments are missing https://review.openstack.org/355287 | 03:35 |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Show help when arguments are missing https://review.openstack.org/355287 | 05:23 |
*** rcernin has joined #openstack-security | 05:25 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Detect binary output html file https://review.openstack.org/355305 | 05:49 |
*** liverpooler has joined #openstack-security | 05:59 | |
*** agireud has quit IRC | 06:01 | |
*** agireud has joined #openstack-security | 06:10 | |
*** vinaypotluri has quit IRC | 06:31 | |
*** pcaruana has joined #openstack-security | 06:36 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Skip key checks where size is not constant https://review.openstack.org/355328 | 06:43 |
openstackgerrit | zhangyanxian proposed openstack/syntribos: Some tiny errors need to be fixed https://review.openstack.org/355329 | 06:45 |
openstackgerrit | zhangyanxian proposed openstack/syntribos: Some tiny errors need to be fixed https://review.openstack.org/355329 | 06:46 |
*** v12aml has joined #openstack-security | 07:42 | |
*** sdake has joined #openstack-security | 08:01 | |
*** sdake has quit IRC | 08:15 | |
*** sdake has joined #openstack-security | 08:35 | |
*** markvoelker has joined #openstack-security | 08:41 | |
*** sdake has quit IRC | 08:43 | |
*** markvoelker has quit IRC | 08:45 | |
*** tkelsey has joined #openstack-security | 09:00 | |
*** xsdenied has joined #openstack-security | 09:06 | |
*** xsdenied has left #openstack-security | 09:12 | |
*** jass93 has quit IRC | 09:35 | |
*** jass93 has joined #openstack-security | 09:36 | |
*** jass93 has quit IRC | 09:41 | |
*** sdake has joined #openstack-security | 09:46 | |
*** jass93 has joined #openstack-security | 09:47 | |
*** jass93 has quit IRC | 09:48 | |
*** jass93 has joined #openstack-security | 09:50 | |
*** jass93 has quit IRC | 09:55 | |
*** jass93 has joined #openstack-security | 09:57 | |
*** jass93 has quit IRC | 10:09 | |
*** jass93 has joined #openstack-security | 10:16 | |
*** jass93 has quit IRC | 10:20 | |
*** jass93 has joined #openstack-security | 10:31 | |
*** markvoelker has joined #openstack-security | 10:42 | |
*** markvoelker has quit IRC | 10:47 | |
*** jass93 has quit IRC | 10:56 | |
*** jass93 has joined #openstack-security | 11:03 | |
*** jass93 has quit IRC | 11:07 | |
*** jass93 has joined #openstack-security | 11:08 | |
*** jass93 has quit IRC | 11:14 | |
*** jass93 has joined #openstack-security | 11:18 | |
*** jass93 has quit IRC | 11:20 | |
*** join1138 has joined #openstack-security | 11:28 | |
*** join1138 has quit IRC | 11:30 | |
*** join1138 has joined #openstack-security | 11:30 | |
*** join1138 has quit IRC | 11:31 | |
*** jass93 has joined #openstack-security | 11:38 | |
*** jass93 has quit IRC | 11:42 | |
*** jass93 has joined #openstack-security | 11:50 | |
*** dave-mccowan has joined #openstack-security | 11:53 | |
*** jass93 has quit IRC | 11:55 | |
*** jass93 has joined #openstack-security | 11:57 | |
*** sdake has quit IRC | 12:02 | |
*** jass93 has quit IRC | 12:02 | |
*** edmondsw has joined #openstack-security | 12:04 | |
*** jass93 has joined #openstack-security | 12:06 | |
*** sdake has joined #openstack-security | 12:06 | |
*** sigmavirus|away is now known as sigmavirus | 12:10 | |
*** jass93 has quit IRC | 12:23 | |
*** jass93 has joined #openstack-security | 12:24 | |
*** markvoelker has joined #openstack-security | 12:30 | |
*** sdake has quit IRC | 12:38 | |
*** zhihui has quit IRC | 12:41 | |
*** jass93 has quit IRC | 12:45 | |
*** jass93 has joined #openstack-security | 12:45 | |
*** jass93 has quit IRC | 12:50 | |
*** elmiko has joined #openstack-security | 13:04 | |
*** woodburn has quit IRC | 13:29 | |
*** sdake has joined #openstack-security | 14:10 | |
*** yab1138 has joined #openstack-security | 14:13 | |
*** yab1138 has quit IRC | 14:15 | |
*** yab1138 has joined #openstack-security | 14:15 | |
*** yab1138 has quit IRC | 14:16 | |
*** knangia has joined #openstack-security | 14:16 | |
*** yab1138 has joined #openstack-security | 14:16 | |
*** yab1138 has quit IRC | 14:17 | |
*** yab1138 has joined #openstack-security | 14:18 | |
*** yab1138 has quit IRC | 14:19 | |
*** ccneill has joined #openstack-security | 14:19 | |
*** yab1138 has joined #openstack-security | 14:21 | |
*** dave-mcc_ has joined #openstack-security | 14:21 | |
*** yab1138 has quit IRC | 14:21 | |
*** dave-mccowan has quit IRC | 14:22 | |
*** dave-mccowan has joined #openstack-security | 14:23 | |
*** ccneill has quit IRC | 14:24 | |
*** dave-mcc_ has quit IRC | 14:25 | |
*** yab1138 has joined #openstack-security | 14:26 | |
*** yab1138 has quit IRC | 14:26 | |
*** dave-mcc_ has joined #openstack-security | 14:26 | |
*** ametts has joined #openstack-security | 14:26 | |
*** yab1138 has joined #openstack-security | 14:28 | |
*** yab1138 has quit IRC | 14:28 | |
*** dave-mccowan has quit IRC | 14:29 | |
*** dave-mccowan has joined #openstack-security | 14:29 | |
*** pcaruana has quit IRC | 14:30 | |
openstackgerrit | Tim Kelsey proposed openstack/security-doc: Adding author field to securoty note template https://review.openstack.org/355496 | 14:30 |
*** dave-mcc_ has quit IRC | 14:32 | |
openstackgerrit | Tim Kelsey proposed openstack/security-doc: OSSN-0070: bandit version < 1.1.0 have possible XSS https://review.openstack.org/355493 | 14:34 |
openstackgerrit | Tim Kelsey proposed openstack/security-doc: Adding author field to security note template https://review.openstack.org/355496 | 14:34 |
*** sdake has quit IRC | 14:48 | |
tkelsey | lhinds: thanks for reviews :) | 14:48 |
lhinds | no worries, super quick turn around ob getting it out tkelsey , props there! | 14:49 |
tkelsey | :) | 14:49 |
tkelsey | well the sec team should set a good example with its own projects :P | 14:50 |
lhinds | very true | 14:51 |
openstackgerrit | Tim Kelsey proposed openstack/security-doc: Adding author field to securoty note template https://review.openstack.org/355496 | 14:51 |
openstackgerrit | Tim Kelsey proposed openstack/security-doc: Adding author field to security note template https://review.openstack.org/355496 | 14:52 |
*** mvaldes has joined #openstack-security | 14:54 | |
openstackgerrit | Tim Kelsey proposed openstack/security-doc: OSSN-0070: bandit version < 1.1.0 have possible XSS https://review.openstack.org/355493 | 14:54 |
*** elo has quit IRC | 15:02 | |
*** rcernin has quit IRC | 15:06 | |
openstackgerrit | Merged openstack/bandit: Show help when arguments are missing https://review.openstack.org/355287 | 15:11 |
*** diazjf has joined #openstack-security | 15:27 | |
openstackgerrit | Merged openstack/bandit: Skip key checks where size is not constant https://review.openstack.org/355328 | 15:33 |
*** edtubill has joined #openstack-security | 15:33 | |
*** edtubill has quit IRC | 15:40 | |
*** edtubill has joined #openstack-security | 15:40 | |
*** elo has joined #openstack-security | 15:40 | |
*** mdong has joined #openstack-security | 15:48 | |
*** elo has quit IRC | 15:48 | |
openstackgerrit | Merged openstack/syntribos: Some tiny errors need to be fixed https://review.openstack.org/355329 | 15:55 |
*** elo has joined #openstack-security | 16:01 | |
*** vinaypotluri has joined #openstack-security | 16:01 | |
*** elo has quit IRC | 16:05 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding sub commands to Syntribos https://review.openstack.org/350325 | 16:08 |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding sub commands to Syntribos https://review.openstack.org/350325 | 16:12 |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding sub commands to Syntribos https://review.openstack.org/350325 | 16:13 |
*** ccneill has joined #openstack-security | 16:16 | |
*** mvaldes has quit IRC | 16:19 | |
*** ametts_ has joined #openstack-security | 16:28 | |
*** hockeynut has joined #openstack-security | 16:28 | |
*** ametts has quit IRC | 16:30 | |
*** Gr33nW0lf has joined #openstack-security | 16:58 | |
*** sdake has joined #openstack-security | 17:00 | |
*** Gr33nW0lf has quit IRC | 17:11 | |
*** Gr33nW0lf has joined #openstack-security | 17:12 | |
*** mvaldes has joined #openstack-security | 17:23 | |
*** Gr33nW0lf has quit IRC | 17:27 | |
*** Gr33nW0lf has joined #openstack-security | 17:30 | |
*** singlethink has joined #openstack-security | 17:30 | |
*** diazjf has quit IRC | 17:35 | |
*** rcernin has joined #openstack-security | 17:37 | |
*** edtubill has quit IRC | 17:40 | |
*** Gr33nW0lf has quit IRC | 17:42 | |
*** Gr33nW0lf has joined #openstack-security | 17:42 | |
*** Gr33nW0lf has quit IRC | 17:42 | |
*** Gr33nW0lf has joined #openstack-security | 17:43 | |
*** Gr33nW0lf has quit IRC | 17:43 | |
*** mvaldes has quit IRC | 17:44 | |
unrahul | ccneill: u here? | 17:44 |
unrahul | tempest has all the api tests https://github.com/openstack/tempest/tree/master/tempest/api , may be will use this to create the API from MITM.. ? | 17:45 |
*** mvaldes has joined #openstack-security | 17:59 | |
*** mvaldes1 has joined #openstack-security | 18:03 | |
*** mvaldes2 has joined #openstack-security | 18:05 | |
*** mvaldes has quit IRC | 18:05 | |
*** mvaldes1 has quit IRC | 18:08 | |
*** elo has joined #openstack-security | 18:10 | |
*** bknudson has joined #openstack-security | 18:21 | |
*** ccneill has quit IRC | 18:25 | |
*** ccneill has joined #openstack-security | 18:35 | |
ccneill | unrahul: good call! hadn't thought of that | 18:37 |
ccneill | unrahul: sorry, been away from my desk | 18:37 |
ccneill | let's see.. I see compute (nova), identity (keystone), image (glance), network (neutron).. | 18:38 |
*** rcernin has quit IRC | 18:42 | |
unrahul | yeah!.. i just went for lunch.. let me see how to configure it... on our cloud .. , or may be a devstack | 18:44 |
ccneill | yeah, I think that might be the best way for us to solve for all the OpenStack services that we need to | 18:45 |
ccneill | if we get a good approach going for parsing the results of tempest test runs into templates, we should be able to apply it to anything that has a good set of functional tests | 18:46 |
lhinds | ccneill / unrahul : you're both syntribos devs? | 18:49 |
ccneill | lhinds: indeed | 18:49 |
unrahul | lhinds: +1 | 18:50 |
lhinds | cool, I have just been having a play, but having some issues with an endpoint that has the format identity/v3 | 18:50 |
lhinds | just been trying to work back on the stack trace | 18:50 |
unrahul | i can give u a config file , that should work with keystone v3 | 18:50 |
lhinds | that would be cool, I expected it might be my config | 18:51 |
ccneill | one handy thing is to run through a proxy like Burp suite or ZAP | 18:51 |
ccneill | so that you can see where it might be screwing up | 18:51 |
lhinds | I am getting a KeyError as its being passed to authenticate_v2_config | 18:51 |
ccneill | hmmm | 18:51 |
lhinds | I think from parser.py | 18:51 |
*** hockeynut has quit IRC | 18:51 | |
ccneill | if you could post the stacktrace that would be handy.. there are definitely a few rough edges around handling Keystone at this point | 18:52 |
ccneill | :X | 18:52 |
lhinds | sure, just a min | 18:52 |
ccneill | np, we're about to run to a meeting soon but we'll try to get it figured out for ya | 18:53 |
lhinds | http://paste.openstack.org/show/557613/ | 18:54 |
unrahul | https://gist.github.com/rahulunair/388fec8b7c064573435c363ba9fc0f25 is ur config similar to this..? | 18:54 |
lhinds | there are couple of debug prints, as I was trying see what JSON was being set / parsed | 18:54 |
unrahul | I think if u add domain_name and domain_id | 18:55 |
unrahul | it should work.. if it doesnt let us know.. we shall fix it.. | 18:55 |
lhinds | unrahul: so this is where I am not up to speed on keystone | 18:55 |
unrahul | as ccneill said.. there are some really rough edges.. we are trying to fix most of them.. | 18:56 |
lhinds | but I have nothing running on the standard ports, everything is on endpoint= | 18:56 |
lhinds | derp | 18:56 |
lhinds | endpoint=http://192.168.124.2/identity/v3 | 18:56 |
lhinds | I just spun up devstack to have a play | 18:56 |
lhinds | nothing on :5000 or :35357/ | 18:56 |
unrahul | mmm.. | 18:57 |
unrahul | is keystone catalog returning the uri like that.. ? | 18:57 |
lhinds | sure | 18:57 |
lhinds | If I curl to /identity/v3 I see the auth json come back | 18:57 |
lhinds | {"version": {"status": "stable", "updated": "2016-10-06T00:00:00Z", "media-types": [{"base": "application/json", "type": "application/vnd.openstack.identity-v3+json"}], "id": "v3.7", "links": [{"href": "http://192.168.124.2/identity/v3/", "rel": "self"}]}} | 18:58 |
unrahul | yeah.. our auth appends v2 or v3 depends upon the config.. | 18:58 |
ccneill | hmm | 18:59 |
unrahul | so u might have some issue there.. , can u tell me what the command `keystone catalog` return.. | 18:59 |
ccneill | so looking at the code, that error should only be raised when you're missing either the endpoint or the password | 18:59 |
ccneill | https://github.com/openstack/syntribos/blob/master/syntribos/extensions/identity/client.py#L73 | 18:59 |
*** tkelsey has quit IRC | 18:59 | |
lhinds | I have the endpoint, let me stick a debug to see what is stored in password | 19:00 |
ccneill | hmmmm | 19:00 |
ccneill | wondering if we need to change how params are sent to the get_token_v2 call from CALL_EXTENSION | 19:02 |
lhinds | Password is there | 19:02 |
lhinds | password = CONF.get(user_section).password or CONF.user.password | 19:02 |
lhinds | print('Password: {0}'.format(password)) | 19:03 |
lhinds | that gets me at runtimr | 19:03 |
lhinds | s/runtimr/runtime | 19:03 |
lhinds | Password: secret | 19:03 |
mdong | hmm, do you have an endpoint in both the [syntribos] and the [user] section of your config? | 19:04 |
lhinds | and as said earlier, endpoint too | 19:04 |
lhinds | mdong: yep | 19:04 |
lhinds | let me pastebin, as I might have done something daft | 19:05 |
mdong | sure | 19:05 |
lhinds | http://paste.openstack.org/show/557614/ | 19:05 |
lhinds | previous to the above, I had endpoint=http://192.168.124.2/identity/v3 | 19:06 |
*** ccneill has quit IRC | 19:06 | |
*** edtubill has joined #openstack-security | 19:08 | |
mdong | yeah, the endpint shold just be the url. Are you trying to authenticate against v3 or v2.0? | 19:09 |
lhinds | v3 | 19:09 |
mdong | add the line endpoint=http://192.168.124.2 to the [user] section | 19:11 |
unrahul | can u try this config https://gist.github.com/rahulunair/388fec8b7c064573435c363ba9fc0f25 | 19:11 |
mdong | just above the password | 19:11 |
unrahul | lhinds: ? | 19:12 |
lhinds | unrahul: I have nothing listening on :5000 | 19:12 |
*** aastha has joined #openstack-security | 19:12 | |
*** diazjf has joined #openstack-security | 19:12 | |
*** ametts_ has quit IRC | 19:13 | |
unrahul | lhinds: then avoid the port and try | 19:13 |
lhinds | k, one sec | 19:13 |
unrahul | as mdong said, can u try to make sure the endpoint is also in the user section.. so the config I have posted, without the port should work | 19:13 |
lhinds | still getting some json issues | 19:14 |
lhinds | let me pastebin | 19:14 |
*** elo has quit IRC | 19:14 | |
lhinds | http://paste.openstack.org/show/557615/ | 19:15 |
lhinds | this is the line that is causing issue (I suspect) | 19:16 |
lhinds | if not endpoint or not password: | 19:16 |
lhinds | msg = "Required config parameters not present: {0}".format( | 19:16 |
lhinds | [x for x in [endpoint, password] if not x]) | 19:16 |
lhinds | raise KeyError(msg) | 19:16 |
lhinds | as both endpoint and password have assignments that look correct | 19:16 |
mdong | are you still getting the original error? | 19:16 |
mdong | or are you just getting the json issue now? | 19:17 |
lhinds | latest error is the above paste | 19:17 |
lhinds | just the json one now. | 19:17 |
lhinds | Its not a burning need to fix this now, was curious and thought I would have a play and it might be useful feedback | 19:18 |
mdong | hmm, well the original error seemed to be because of your config, but the latest one is interesting…are you sure you’re getting a valid response back? | 19:18 |
*** ametts_ has joined #openstack-security | 19:18 | |
*** ametts_ has quit IRC | 19:18 | |
lhinds | where do you recommend I capture the response? | 19:18 |
*** ametts has joined #openstack-security | 19:19 | |
lhinds | so this is what I see: | 19:19 |
lhinds | endpoint = CONF.get(user_section).endpoint or CONF.user.endpoint | 19:19 |
lhinds | password = CONF.get(user_section).password or CONF.user.password | 19:19 |
lhinds | print ('EP:{0}'.format(endpoint)) | 19:19 |
lhinds | print ('PW:{0}'.format(password)) | 19:19 |
lhinds | runtime: | 19:20 |
lhinds | EP:http://192.168.124.2 | 19:20 |
lhinds | PW:secret | 19:20 |
lhinds | sorry, long day, we moved on from that :) | 19:20 |
mdong | the response should be in our logs, the path of which should be printed at the bottom of the console otuput, though they take a bit of digging through. | 19:21 |
mdong | you can also just set HTTP_PROXY in your environment and pipe syntribos to your preferred proxy | 19:21 |
*** mvaldes2 has quit IRC | 19:21 | |
lhinds | ok that helps! | 19:22 |
lhinds | its trying to post to v2 still | 19:22 |
lhinds | http://paste.openstack.org/show/557616/ | 19:22 |
mdong | some of the example templates we have will explicitly try to post to v2 | 19:23 |
*** ccneill has joined #openstack-security | 19:23 | |
lhinds | so there is no filter to stop v2 running on v3? | 19:23 |
mdong | no, if the request template has the CALL_EXTERNAL directive to explicitly reference v2.0, then that’s what it’ll do | 19:24 |
mdong | the templates in examples/templates/keystone should all be v3.0 | 19:25 |
mdong | I think it’s just the Swift request templates that try to post to v2.0 | 19:25 |
lhinds | hmm | 19:26 |
lhinds | CALL_EXTERNAL|syntribos.extensions.identity.client:get_token_v2:["user"]| | 19:27 |
*** ccneill has quit IRC | 19:41 | |
lhinds | ok, got it working | 19:50 |
*** sigmavirus is now known as sigmavirus|away | 20:03 | |
*** ccneill has joined #openstack-security | 20:04 | |
lhinds | mdong: how about the following (and no more then a nit): | 20:05 |
lhinds | syntribos/examples/templates/keystone/v2/ | 20:05 |
lhinds | syntribos/examples/templates/keystone/v3/ | 20:06 |
*** liverpooler has quit IRC | 20:07 | |
lhinds | (and admin too ofc) | 20:07 |
*** ccneill has quit IRC | 20:09 | |
*** lhinds is now known as lhinds|out | 20:09 | |
*** sdake has quit IRC | 20:32 | |
unrahul | cc | 20:32 |
*** Gr33nW0lf has joined #openstack-security | 20:40 | |
*** Gr33nW0lf has quit IRC | 20:40 | |
*** Gr33nW0lf has joined #openstack-security | 20:40 | |
*** Gr33nW0lf has quit IRC | 20:40 | |
*** mvaldes has joined #openstack-security | 20:45 | |
*** sdake has joined #openstack-security | 20:57 | |
*** sdake has quit IRC | 21:08 | |
*** sdake has joined #openstack-security | 21:17 | |
*** diazjf has quit IRC | 21:20 | |
*** elo has joined #openstack-security | 21:21 | |
*** mvaldes has quit IRC | 21:24 | |
*** ccneill has joined #openstack-security | 21:26 | |
*** diazjf has joined #openstack-security | 21:27 | |
*** edtubill has quit IRC | 21:28 | |
*** diazjf has quit IRC | 21:28 | |
*** ametts has quit IRC | 21:28 | |
*** sdake has quit IRC | 21:39 | |
*** edtubill has joined #openstack-security | 21:41 | |
*** diazjf has joined #openstack-security | 21:41 | |
unrahul | hey ccneill | 21:43 |
unrahul | u here? | 21:43 |
*** mvaldes has joined #openstack-security | 21:50 | |
*** sdake has joined #openstack-security | 21:54 | |
*** tkelsey has joined #openstack-security | 21:58 | |
*** tkelsey has quit IRC | 22:03 | |
*** diazjf has quit IRC | 22:10 | |
*** edtubill has quit IRC | 22:10 | |
*** ccneill has quit IRC | 22:17 | |
*** sdake has quit IRC | 22:20 | |
*** mvaldes has quit IRC | 22:21 | |
*** mvaldes has joined #openstack-security | 22:23 | |
*** Gr33nW0lf has joined #openstack-security | 22:27 | |
*** Gr33nW0lf has joined #openstack-security | 22:27 | |
*** hockeynut has joined #openstack-security | 22:29 | |
*** mvaldes has quit IRC | 22:30 | |
*** singlethink has quit IRC | 22:32 | |
*** jass93 has joined #openstack-security | 22:34 | |
*** sdake has joined #openstack-security | 22:35 | |
*** edmondsw has quit IRC | 22:51 | |
*** mdong has quit IRC | 22:51 | |
*** sdake has quit IRC | 22:57 | |
*** Gr33nW0lf has quit IRC | 23:04 | |
*** markvoelker has quit IRC | 23:06 | |
*** hockeynut has quit IRC | 23:43 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!