Saturday, 2016-03-05

*** mlima has joined #kolla00:02
mlimaSamYaple, i saw that some modules does not have reconfigure file yet, but i dont know if i can commit.00:04
mlimathe mitaka version has been "closed"?00:05
*** Jeffrey4l has quit IRC00:10
*** alisonh has joined #kolla00:12
*** britthouser has joined #kolla00:34
*** dimsum_ has quit IRC00:35
*** jtriley has quit IRC00:43
*** iceyao has joined #kolla00:53
*** mbound has joined #kolla00:59
openstackgerritDaniel Gonzalez Nothnagel proposed openstack/kolla: Unify vagrant bootstrap.sh scripts  https://review.openstack.org/28882101:02
*** mlima has quit IRC01:03
*** mbound has quit IRC01:04
*** sdake has joined #kolla01:06
*** britthou_ has joined #kolla01:08
*** britthouser has quit IRC01:11
openstackgerritMerged openstack/kolla: Bump ansible version to head of devel  https://review.openstack.org/28855301:24
*** dims has joined #kolla01:30
openstackgerritSerguei Bezverkhi proposed openstack/kolla: Partially-Implements: blueprint kolla-reconfig  https://review.openstack.org/28882401:33
*** sdake has quit IRC01:43
*** Allen_Gao has quit IRC01:50
*** dims has quit IRC01:55
*** Allen_Gao has joined #kolla02:05
openstackgerritSerguei Bezverkhi proposed openstack/kolla: Reconfigure for Swift  https://review.openstack.org/28882402:17
*** stvnoyes has quit IRC02:25
*** stvnoyes has joined #kolla02:26
*** gfidente has quit IRC02:41
*** Marga_ has quit IRC02:55
*** Jeffrey4l has joined #kolla03:03
*** jasonsb has joined #kolla03:24
*** klint has joined #kolla03:35
*** jasonsb has quit IRC03:36
*** vhosakot has joined #kolla03:39
*** Marga_ has joined #kolla03:53
*** Marga_ has quit IRC04:08
*** Marga_ has joined #kolla04:08
*** jasonsb has joined #kolla04:09
openstackgerritMD NADEEM proposed openstack/kolla: Reconfigure for haproxy  https://review.openstack.org/28824804:19
*** jasonsb has quit IRC04:19
*** britthou_ has quit IRC04:32
*** Allen_Gao has quit IRC05:02
openstackgerritJeffrey Zhang proposed openstack/kolla: Copy the logs out of the container  https://review.openstack.org/28854105:07
*** Allen_Gao has joined #kolla05:14
*** Jeffrey4l has quit IRC05:17
*** pbourke has quit IRC05:18
*** pbourke has joined #kolla05:18
*** Marga_ has quit IRC05:51
*** salv-orlando has joined #kolla05:52
*** salv-orl_ has quit IRC05:55
*** vhosakot has quit IRC06:26
*** akwasnie has joined #kolla07:14
*** Allen_Gao has quit IRC07:27
*** akwasnie has quit IRC07:35
*** akwasnie has joined #kolla07:35
*** akwasnie has quit IRC07:42
*** Allen_Gao has joined #kolla07:44
*** The_Ball has quit IRC08:04
*** akwasnie has joined #kolla08:04
*** iceyao has quit IRC08:20
*** akwasnie has quit IRC08:26
*** achanda has quit IRC08:36
*** achanda has joined #kolla08:40
*** achanda has quit IRC08:50
*** chandankumar has joined #kolla09:31
*** dwalsh has joined #kolla10:15
*** dwalsh has quit IRC10:37
*** iceyao has joined #kolla10:49
openstackgerritEric Lemoine proposed openstack/kolla: Make Heka send logs to Elasticsearch  https://review.openstack.org/28418810:52
openstackgerritEric Lemoine proposed openstack/kolla: Use alphabetical order in cleanup-containers  https://review.openstack.org/28762610:52
*** chandankumar has quit IRC10:54
*** The_Ball has joined #kolla11:29
*** Jeffrey4l has joined #kolla11:47
*** salv-orl_ has joined #kolla11:52
*** salv-orlando has quit IRC11:55
*** macsz has joined #kolla12:01
openstackgerritJeffrey Zhang proposed openstack/kolla: Copy the logs out of the container  https://review.openstack.org/28854112:05
*** macsz has quit IRC12:08
*** skape has joined #kolla12:09
*** dims has joined #kolla12:11
*** britthouser has joined #kolla12:13
*** akwasnie has joined #kolla12:13
*** dims has quit IRC12:13
*** akwasnie has quit IRC12:14
*** britthou_ has joined #kolla12:16
*** britthouser has quit IRC12:19
*** dims has joined #kolla13:08
*** openstackgerrit_ has quit IRC13:17
*** openstackgerrit_ has joined #kolla13:18
*** dims has quit IRC13:53
*** klint has quit IRC14:03
*** nihilifer has quit IRC14:15
*** nihilifer has joined #kolla14:17
*** openstackgerrit_ has quit IRC14:20
*** openstackgerrit_ has joined #kolla14:21
*** jmccarthy has quit IRC14:21
*** jmccarthy has joined #kolla14:22
*** openstackgerrit_ has quit IRC14:32
*** openstackgerrit_ has joined #kolla14:33
*** dims has joined #kolla14:49
*** sdake has joined #kolla14:51
sdakemorning14:51
sbezverkGood morning14:55
*** sdake_ has joined #kolla14:56
sbezverksdake I registered new BP, please let me know if it has been done correctly..14:57
*** sdake has quit IRC14:57
openstackgerritJeffrey Zhang proposed openstack/kolla: Copy the logs out of the container  https://review.openstack.org/28854115:00
*** britthou_ has quit IRC15:03
*** iceyao has quit IRC15:15
sdake_Jeffrey4l morning15:23
sdake_sbezverk cool15:23
sdake_sbezverk if you hav a link i'll take a look15:23
sdake_sbezverk btw your patch was slightly wrong15:23
sdake_the commit log was wrong - could you fix real quick?15:23
*** sdake_ is now known as sdake15:24
Jeffrey4lmorning sdake15:24
sdakeJeffrey4l i am definately tagging today15:25
sdakeassuming master works15:25
sdakei bsaically hit the wall last night and couldn't tag15:25
sdakedo you know what shape master is in atm?15:25
sdakei see our leaky gate says it looks good ;-)15:25
Jeffrey4lthe wall? what it?15:26
Jeffrey4lI have no time to test it today. If the gate says it good. it should be OK. at leat the main service is OK. sdake15:26
openstackgerritSerguei Bezverkhi proposed openstack/kolla: Reconfigure for Swift  https://review.openstack.org/28882415:27
sdakeJeffrey4l can you review that please15:31
Jeffrey4lnp15:32
openstackgerritOpenStack Proposal Bot proposed openstack/kolla: Updated from global requirements  https://review.openstack.org/28889015:32
sdakeJeffrey4l have one favor to ask, go through https://blueprints.launchpad.net/kolla/+spec/kolla-reconfig15:35
sdakeand mark the work items to the correct statte15:35
Jeffrey4lok.15:35
sdakeif you can do that now, i'm going to markt he blueprint implemented and file separate bugss for work items left over15:35
sdakeor altenately you can file seperate bugs and file them to mitaka->rc115:36
sdakeor in addition i mean15:36
openstackgerritMerged openstack/kolla: Make Heka send logs to Elasticsearch  https://review.openstack.org/28418815:36
openstackgerritMerged openstack/kolla: Use alphabetical order in cleanup-containers  https://review.openstack.org/28762615:36
sdakeI use POSTPONED for things we can't implement Jeffrey4l because there are no playbooks15:36
Jeffrey4lsdake, roger that.15:37
sdakeheat is DONE btw15:37
sdakesee, all the states are not set up to date in the work items15:37
*** dims has quit IRC15:41
*** dims has joined #kolla15:43
*** diogogmt has quit IRC15:45
*** diogogmt has joined #kolla15:48
sdakeJeffrey4l and if you could do that now (apologie for context switch) I'd apprecaite it15:48
Jeffrey4lsdake, I am working on it. :D15:48
Jeffrey4lalmost done15:48
sdakesweet ;)15:48
ccesarioit was changed any thing in multinode deploy!? http://pastebin.com/w2AgrRA2 O_o15:50
Jeffrey4lsdake, done.15:51
sdakedid you end up filing bugs targeted to milestone mitaka-rc1?15:52
sdakeccesario the keystone container has changed aroudn that area, it is possible multinode is busted15:52
sdakethe gate only tests single node15:53
Jeffrey4lsdake, no.15:53
Jeffrey4ljust mine filed? Or all?15:53
Jeffrey4lsdake,15:53
sdakeall bugs wherre the state of the item is in TODO15:53
sdakefile a separate bug per one15:53
sdakeexample15:53
sdake"reconfigure work for service XYZ"15:53
sdakecritical mitaka->rc confirmed15:53
sdakemitaka-rc1 that is15:54
sdakee.g. https://bugs.launchpad.net/kolla/+bug/155351615:54
openstackLaunchpad bug 1553516 in kolla "droproot work for kibana" [Critical,Confirmed]15:54
Jeffrey4lroger. how about POSTPONED state? sdake15:55
sdakeignore postponed15:55
Jeffrey4lok15:55
sdakewhen we add new services it will be a requirement to  do the whole job15:55
sdakeaslo inprogreess as well15:57
sdakeif there are any inprogress that haven't merged15:57
sdakelets tryr to get them merged first15:57
*** diogogmt has quit IRC15:58
Jeffrey4lsdake, just haproxy https://review.openstack.org/28824815:59
sdakeok lets carry that over int oa bug15:59
sdakeand file a -1 on the reeview pointing at the bug id16:00
Jeffrey4lok16:00
Jeffrey4lsdake, then we can mark the bp is implemented? and tag m3. right?16:02
sdakeyup16:03
sdakeonce i get done with rootwrap fixup ;)16:03
sdakei am doing same thing with rootwrap atm16:03
Jeffrey4lcool16:03
*** dims has quit IRC16:04
sdakeJeffrey4l mark reconfig implemented when done with the bugs16:10
Jeffrey4lok16:10
Jeffrey4lsdake, all done. Have a long journal tomorrow. So need go to bed now. Good night. :p16:11
Jeffrey4ls/journal/journey/16:12
*** dims has joined #kolla16:16
*** dims has quit IRC16:18
sdakeJeffrey4l does mongodb deploy via ansible?16:19
sdakeI thought it did not16:19
*** Jeffrey4l has quit IRC16:19
*** vhosakot has joined #kolla16:19
*** vhosakot has quit IRC16:38
SamYapleholla16:55
*** macsz has joined #kolla16:59
sdakehey SamYaple17:02
sdakei'm about done with sorting out the tracker17:03
sdakeand then i'll do a test of centos source and binary17:03
sdakecan you test master ubuntu source multinode?17:03
sdakeif those tests come back with an a-ok i'll tag17:03
SamYapledoubtful. im working on some shade stuff right now to get the service and endpoint modules to land before anible 2.117:04
*** bmace has quit IRC17:07
*** bmace has joined #kolla17:07
sdakei guess we could release without testing multinode deploy of ubuntu but a couple peopel have complained it doesn't work properly17:07
sdakenot sure if its pebkac or a legitimate problem17:08
sdakeSamYaple re fernet, mind dave-mccowan takes implementation of that for the rc1 release?17:10
*** sdake_ has joined #kolla17:17
*** sdake has quit IRC17:18
*** sdake has joined #kolla17:27
*** SiRiuS_ has joined #kolla17:28
*** sdake_ has quit IRC17:29
*** sdake_ has joined #kolla17:31
openstackgerritDaniel Gonzalez Nothnagel proposed openstack/kolla: Unify vagrant bootstrap.sh scripts  https://review.openstack.org/28882117:34
*** sdake has quit IRC17:34
openstackgerritDave McCowan proposed openstack/kolla: Add two more examples of openrc for use with public endpoints  https://review.openstack.org/28816517:38
*** skape has quit IRC17:44
*** salv-orlando has joined #kolla17:52
*** macsz has quit IRC17:55
*** salv-orl_ has quit IRC17:55
*** macsz has joined #kolla17:59
*** macsz has quit IRC18:14
*** jasonsb has joined #kolla18:22
sdake_mitaka-3 looking pretty solid tracker wise: https://launchpad.net/kolla/+milestone/mitaka-318:24
sdake_now to see if it actually works correctly ;)18:25
*** sdake_ is now known as sdake18:27
*** v1k0d3n has joined #kolla18:32
sdakedave-mccowan it took this long to build centos binary and push it to a local registry 2.3 over 10gig:18:34
sdakereal12m29.995s18:34
dave-mccowan:-( sdake my last build took 2.5 hours.  i still don't know what my bottleneck is.  i timed downloads from my server at 30MB/s, but I'm not even seeing many downloads during the build process. could it be network latency?18:37
sdakelatency plays a big part18:37
sdakekolal downlaods alot of small files during build18:37
sdakenote i am also using overlayfs18:38
sdake320 plays yay looks like it deployed centos binary18:38
dave-mccowanif i have keepcache=1 in my docker config, then it should have to download, just check the version/hash/time/whatever, right?18:39
sdakehorizon seems broken18:42
sdake{"versions": [{"status": "CURRENT", "id": "v1.0", "links": [{"href": "http://broked.selfip.net:8000/v1/", "rel": "self"}]}]}18:42
sdakewhen i connect to broked.selfip.net:800018:42
sdakemaybe I need to set the horizon port18:43
sdakeoh 8000 is heat18:43
sdakei guess its working ;)18:44
sdakehorizon seems to work http://broked.selfip.net:800/auth/login/?next=/18:45
dave-mccowansdake no https:// ?  :-(   ;-)18:46
sdakeis there a script to configure tls, if so, I'll give it a spin18:47
sdakewtb TLS documentation ;)18:47
dave-mccowankolla-ansible certificates18:47
dave-mccowankolla_enable_tls_external=yes18:48
dave-mccowankolla-ansible deploy18:48
dave-mccowan(you also need two vips)18:49
sdakegetting a create failed with heat18:49
* sdake groans18:49
dave-mccowankolla_external_vip_address=another.ip.free.for.vip18:50
sdakedave-mccowan got it, let me try to get heat working first18:50
sdakeSamYaple heat is busted, how did you test it in your keystone v3 work?18:58
*** sdake_ has joined #kolla19:06
*** SiRiuS_ has quit IRC19:06
* sdake_ wonders how many other services fail authorization19:06
* sdake_ groans19:06
sdake_atleast the basic compute kit works19:07
sdake_although I can't ssh into my vms19:07
sdake_so not clear if neutron works for me19:07
sdake_dave-mccowan are you able to ssh into your vms that you create with nova boot?19:07
sdake_could just be an environmental thing on my side - my lab is afu19:07
*** sdake has quit IRC19:08
*** sdake has joined #kolla19:10
*** sdake_ has quit IRC19:12
sdakedave-mccowan my deploy with tls is real2m7.647s19:14
sdakedave-mccowan with tls doesnt work for me https://broked.selfip.net:800/19:15
sdaketry it uot19:15
sdakehttp://paste.fedoraproject.org/334551/14572053/ -> http://paste.fedoraproject.org/334551/1457205319:16
sdakedave-mccowan any suggestons?19:17
sdakeI have zero idea how to diagnose tls problems19:17
sdakei should probalby set my stuff up to use the external tls gateway for my external fqdn let me try that19:21
*** achanda has joined #kolla19:34
*** achanda has quit IRC19:34
*** SiRiuS_ has joined #kolla19:38
sdakei dont like that a misconfgiuraton of the vips requires a reboot to get things back in working order19:43
sdakedave-mccowan ^^19:43
sdakedave-mccowan I believe I have my tls configured properly19:46
sdakebut getting  this with keystone user-list:19:46
sdakeAuthorization Failed: SSL exception connecting to https://broked.selfip.net:5000/tokens: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:590)19:46
sdakethis was after wiping out /etc/kolla19:46
sdakemaking sure external was 149 and is mapped to my nat (wrt router)19:47
sdakedoes nat require some special magic to work with ssl?19:47
sdakedave-mccowan i got the cert to work but https has a big red line through it sayign the certificate is invalid :)19:54
sdakehe identity of this website has not been verified.19:55
sdake • Server's certificate does not match the URL.19:55
sdake • Server's certificate is not trusted.19:55
sdakeour connection to broked.selfip.net is encrypted using an obsolete cipher suite.19:56
sdakeThe connection uses TLS 1.2.19:56
sdakeThe connection is encrypted using AES_256_CBC, with HMAC-SHA1 for message authentication and ECDHE_RSA as the key exchange mechanism.19:56
sdake[alt_names]19:58
sdakeIP.1 = 192.168.1.14919:58
sdakethis doesn't match my nat unfortunately19:58
sdakethe ciphers look solid to  me20:08
sdakenot sure what the problem is with chrome complainign about that20:08
sdakemaybe rsa's DE is in question considering backdooring20:09
sdakerather DH20:09
sdake256 block chaining is unbreakable imo and hmac with sha1 also unfakeable20:10
*** macsz has joined #kolla20:20
sdakedave-mccowan need a bone here, can't use any cli tools because the site certificate is invalid20:24
sdakegoogle chrome just says it has an invalid cert authority20:24
*** harmw_ is now known as harmw20:32
*** Marga_ has joined #kolla20:32
openstackgerritOpenStack Proposal Bot proposed openstack/kolla: Updated from global requirements  https://review.openstack.org/28889020:45
sdakedave-mccowan when yo uget a chance check out https://bugs.launchpad.net/kolla/+bug/155357720:50
openstackLaunchpad bug 1553577 in kolla "self-signed certificates don't function with keystone" [High,Triaged] - Assigned to Dave McCowan (dave-mccowan)20:50
dave-mccowansdake look here for instructions on building your openrc https://review.openstack.org/28816520:52
openstackgerritBenedikt Trefzer proposed openstack/kolla: Use debian repos for debian base docker image.  https://review.openstack.org/28893620:56
sdakehttps://github.com/openstack/kolla/releases/tag/2.0.0.0b3 enjoy ;)20:58
sdakewhere is this external ca cert dave-mccowan ?21:01
dave-mccowanat /etc/kolla/certificates/haproxy-ca.pem21:02
sdakei used that, get a resource not found error21:03
sdakeAuthorization Failed: The resource could not be found. (HTTP 404)21:03
sdakeexport OS_CACERT=./external_cacert21:04
sdakesame result as running with --insecure21:04
*** SiRiuS_ has quit IRC21:04
dave-mccowando a command with -vvv and pastebin it21:05
dave-mccowanwhere is your client?21:05
sdakeon my macontosh21:05
sdakelaptop21:05
sdakei tried this instead: export OS_CACERT=file:///external_cacert21:06
sdakeand get Authorization Failed: SSL exception connecting to https://broked.selfip.net:5000/tokens: [Errno 2] No such file or directory21:06
sdakekeystone doesn't take a -v operation21:06
openstackgerritBenedikt Trefzer proposed openstack/kolla: Use debian repos for debian base docker image.  https://review.openstack.org/28893621:09
sdakeDEBUG:keystoneclient.auth.identity.v2:Making authentication request to https://broked.selfip.net:5000/tokens21:09
sdakeINFO:requests.packages.urllib3.connectionpool:Starting new HTTPS connection (1): broked.selfip.net21:09
sdakeDEBUG:requests.packages.urllib3.connectionpool:"POST /tokens HTTP/1.1" 404 9321:09
sdakeDEBUG:keystoneclient.session:Request returned failure status: 40421:09
sdakeAuthorization Failed: The resource could not be found. (HTTP 404)21:09
sdakewhat does your openrc file look like?21:09
sdakeI wouldn't think we would have to provide an external ca cert to keystone/nova/etc to get  things to work21:09
dave-mccowanmaybe try connecting from your deploy node first to rule out deployment issue, then check out figure out if it's your mac or your nat box.21:09
sdakebut then again, I dont know how all this stuf fworks :)21:09
*** macsz has quit IRC21:09
dave-mccowanwe don't.  only the client should need the CA certificate.21:10
sdakedave-mccowan what is thte contents of your tls enabled openrc file?21:12
sdaketry connecting to my horizon at https://broked.selfip.net:44321:13
sdakesee if that looks correct to you21:13
dave-mccowannope, that doesn't look right.  your NAT box is hosing up the connection.21:14
dave-mccowanit might still be able to work, but your certificate needs to match the FQDN that's being presented.21:15
sdakethe ceritficate has broked.selfip.net in it21:17
sdakei tried using both my nat address and the internal VIP address prior to cert gen with no luck21:17
sdakehorizon works, so internal http of keystone works21:17
sdakebut external keystone ssl doesn't appear to work21:17
dave-mccowanor maybe my company's firewall is blocking that domain.21:17
sdakei am connected via cox, not via csco21:18
dave-mccowanbroked.selfip.net uses an invalid security certificate. The certificate is only valid for the following names: rtp5-sinkhole-01.cisco.com, rtp5-sinkhole-01-svc.cisco.com, sinkhole.esl.cisco.com (Error code: ssl_error_bad_cert_domain)21:18
dave-mccowanthat the error i got.21:18
sdakeSTDAKE-M-J2VL:demo sdake$ nslookup rt5-sinkhole-01.cisco.com21:19
sdakeServer:192.168.1.121:19
sdakeAddress:192.168.1.1#5321:19
sdakeNon-authoritative answer:21:19
sdakeName:rt5-sinkhole-01.cisco.com21:19
sdakeAddress: 92.242.140.221:19
sdakeSTDAKE-M-J2VL:demo sdake$ nslookup broked.selfip.net21:19
sdakeServer:192.168.1.121:19
sdakeAddress:192.168.1.1#5321:19
sdakeNon-authoritative answer:21:19
sdakeName:broked.selfip.net21:19
sdakeAddress: 98.165.69.13721:19
sdakethose ip addresses arent even in the same ballpark21:19
sdakecan you try without connecting via the vpn?21:20
sdakesinkhole is a firewall block I think21:20
*** dims has joined #kolla21:20
sdakelet me try via the cvo21:21
*** dave-mcc_ has joined #kolla21:21
sdakeinside the firewall i get a tracerotue to sinkhole21:23
sdakewhich is probably a firewall of some sort21:23
sdakeit should be tracerouting to my dyndns machine21:23
*** dave-mccowan has quit IRC21:24
sdakedave-mcc_ how does it look from that angle?21:25
dave-mcc_it looks great if i use curl (and insecure, since i don't have your CA certificate).21:26
sdakecertificate: http://paste.fedoraproject.org/334612/14572132/21:26
sdakeopen in chrome - get a big red bar from chrome :(21:27
dave-mcc_do you have a linux box you can try from?  i turned up security pretty high; maybe macs have an older version of SSL support.21:28
sdakeyes moment21:28
sdakeyou can try form your machine as well21:29
sdakeyou ahve my certificate ;)21:29
dave-mcc_i don't have a linux box outside of VPN21:30
dave-mcc_i'm getting  [Errno 8] _ssl.c:510: EOF occurred in violation of protocol,   when using CLI21:31
dave-mcc_is that what you're getting now?21:31
sdakenope21:31
dave-mcc_OS_AUTH_URL=https://98.165.69.137:5000/v321:33
dave-mcc_how does that work for you?21:33
dave-mcc_i mean: OS_AUTH_URL=https://98.165.69.137:500021:33
sdake in favor of keystoneauth1 plugins. They will be removed in future releases.21:34
sdake  'in future releases.', DeprecationWarning)21:34
sdakeAuthorization Failed: SSL exception connecting to https://98.165.69.137:5000/tokens: hostname '98.165.69.137' doesn't match u'broked.selfip.net'21:34
sdakeis reverse dns lookup used during ssl autentication ?21:35
sdakeSTDAKE-M-J2VL:demo sdake$ nslookup 98.165.69.13721:36
dave-mcc_no, the certificate contains the configured values of  kolla_external fqdn and address21:36
sdakeServer:192.168.1.121:36
sdakeAddress:192.168.1.1#5321:36
sdakeNon-authoritative answer:21:36
sdake137.69.165.98.in-addr.arpaname = ip98-165-69-137.ph.ph.cox.net.21:36
sdakeyes, I hacked the address to not be external_vip_address, but to be my external external address on the internet21:36
sdakethe external vip address is 192.168.1.14921:36
sdakebut i'm wondering if the ssl auth is doing a reverse dns lookup and that is damaging things21:37
dave-mcc_no, ssl wouldn't do that21:37
sdakebecause as you can see, I have no control over reverse dns :)21:37
sdakeanyway I end up with same results on linux machine which is to say esource not round21:37
sdakefound21:38
sdakewith /v3 and without /v321:38
*** jasonsb has quit IRC21:38
sdakei think what would be better is to configure keystone not to complain about the signing cert chain if using a self signed cert, then to force develoeprs tof igure all this stuffo ut ;)21:39
sdakeopenstack-ansible does exactly this21:39
sdakewhat does your web browser look like when you connect to https://broked.selfip.net?21:40
dave-mcc_the complaining is on the client side21:40
sdakedave-mcc_ check out the horizon interface, tell me if thta looks correct21:41
sdakeyou said sam didn't have any issues on his server, i wonder what the delta is21:41
dave-mcc_i get the dashboard with only a warning that the certificate is self signed21:41
sdakewas his cert self-signed?21:42
dave-mcc_yes21:42
sdakeand you were able to access keystone with his certificate?21:42
dave-mcc_it's weird that it works with curl, but not CLI.  CLI is just curl library calls.21:42
sdakedid his machine complain about the self signing?21:42
dave-mcc_i didn't hit his box.  yes, self slgning work fine. that's not our problem.21:43
sdakei suspect it may be reverse dns lookup21:43
sdakelet me try that out quickly21:43
*** dave-mccowan has joined #kolla21:46
sdakedave-mcc_ how i alt_names used?21:47
*** dave-mcc_ has quit IRC21:48
*** salv-orlando has quit IRC21:52
*** salv-orlando has joined #kolla21:53
sdakestill resource not found21:56
sdakeis ssl version of keystone using any port besides 5000?21:56
sdakedave-mccowan ^^21:57
sdakethis is what chrome gives me dave-mccowan The identity of this website has not been verified.21:58
sdake • Server's certificate does not match the URL.21:58
sdake • Server's certificate is not trusted.21:58
dave-mccowanno.  you have two different vips, right?  it will be 5000 on external with SSL21:58
sdakeyes two different vips21:58
dave-mccowancan you click more info on chrome?  firefox gave more details on what it didn't like?21:59
dave-mccowani was able to curl your keystone endpoint using your cert with no issues.  can you do that too?22:00
dave-mccowanhere's what i'm seeing:  curl works and handshakes to TLSv1.2.  openstack cli fails with handshake error.  i'm thinking that the openstack CLI on mac is using old crypto and can't do newer protocols.  i'm trying an experiment on my box now.22:03
sdakei tried on linux mchine with same results22:04
sdakemy mac uses tls 1.2 in chrome22:04
sdakehow do you curl with a cert?22:04
dave-mccowan--cacert $OS_CACERT22:04
dave-mccowani got o your dashboard fine22:05
sdakeSTDAKE-M-J2VL:demo sdake$ curl --cacert $OS_CACERT https://broked.selfip.net22:05
sdakecurl: (51) SSL: certificate verification failed (result: 5)22:05
sdakeSTDAKE-M-J2VL:demo sdake$ curl --cacert $OS_CACERT https://ip98-165-69-137.ph.ph.cox.net22:06
sdakeSTDAKE-M-J2VL:demo sdake$22:06
sdakeSTDAKE-M-J2VL:demo sdake$ curl --cacert $OS_CACERT https://ip98-165-69-137.ph.ph.cox.net:500022:06
sdake{"versions": {"values": [{"status": "stable", "updated": "2015-09-15T00:00:00Z", "media-types": [{"base": "application/json", "type": "application/vnd.openstack.identity-v3+json"}], "id": "v3.5", "links": [{"href": "https://ip98-165-69-137.ph.ph.cox.net:5000/v3/", "rel": "self"}]}, {"status": "stable", "updated": "2014-04-17T00:00:00Z", "media-types": [{"base": "application/json", "type": "application/vnd.openstack.identity-v2.0+json"}],22:06
sdake "id": "v2.0", "links": [{"href": "https://ip98-165-69-137.ph.ph.cox.net:5000/v2.0/", "rel": "self"}, {"href": "http://docs.openstack.org/", "type": "text/html", "rel": "describedby"}]}]}}STDAKE-M-J222:06
sdakei guess that is what i should expect to see dave-mccowan ?22:07
sdakeall that curl was from mac machine22:07
dave-mccowanyep.. that's what a version endpoint should return.  looks perfect.22:08
sdakeSTDAKE-M-J2VL:demo sdake$ curl --cacert $OS_CACERT https://ip98-165-69-137.ph.ph.cox.net:5000/tokens22:08
sdake{"error": {"message": "The resource could not be found.", "code": 404, "title":22:08
sdakethis is what keytone client is doing, banging on 5000/tokens22:08
dave-mccowantry /v3/auth/tokens22:09
dave-mccowanexport OS_IDENTITY_API_VERSION=322:09
sdakeSTDAKE-M-J2VL:demo sdake$ curl --cacert $OS_CACERT https://ip98-165.cox.net:5000/v3/auth/tokens22:09
sdake{"error": {"message": "The request you have made requires authentication.", "code": 401, "title": "Unauthorized"}}STDAKE-M-J2VL:demo sdake$22:09
dave-mccowando you have OS_PASSWORD?22:10
sdakeyup22:10
sdakeits password22:10
dave-mccowanOK, i confirmed the issue I was tracking.  the openstack client as installed on my mac can't do TLSv1.1 or higher. :-(  i don't know if i need to fix my mac, or loosen security on kolla.22:11
sdakesurely we are not  the first people to run into this22:12
sdakehow did you verify that exactly?22:12
sdakethe same results happen on a linux machine as well22:12
dave-mccowani think you're chasing more than one problem.22:12
dave-mccowandoes your openrc look like that (sent via pm)?22:14
dave-mccowanyes, if i change my kolla install to support TLV1022:15
dave-mccowani think maybe i have an issue with my mac though.  maybe i need to pip upgrade something.22:15
dave-mccowani had tried before from my mac, and assumed i had something wrong, so just always tested from linux.22:16
dave-mccowanpaste me your haproxy.cfg22:18
sdakedave-mccowan moment22:19
sdakehttp://paste.fedoraproject.org/334631/57216383/ -> http://paste.fedoraproject.org/334631/5721638322:19
sdakei am pretty sure my machine gets through via tls, the problem is it is hitting the wrong endpoint22:20
sdakeas you saw above, curl to /tokens fails22:20
sdakethis is what keystone clinet does with --debug22:20
sdakeopenstack user list works22:21
sdakeso its just that python keystone client is a big pile of muck22:21
sdakefwiw the keystone devs said not to use keystoneclient for cli :)22:22
sdakeso dave-mccowan looks like everything works as expected ;)22:22
sdakenice job on tls!22:22
dave-mccowanah ha.  yea, i'm getting same thing from keystone client.  i was using openstack client.  it must be a V3 thing.22:22
dave-mccowanoh yea, everytime you type keystone it comes back "warning deprecated".22:23
sdakeshould be 'warning we gave up" :)22:23
dave-mccowanok... in that case, it is just my mac that is having an issue doing TLSv1.2.22:24
*** Jeffrey4l has joined #kolla22:25
dave-mccowangreat.  you probably have more services running that i do.  if you can hit as many as you can and let me know what errors you find, i can do some touch up.  many services require a one-liner in the config to work properly behind a tls proxy.22:25
sdakecompute kit all works22:27
sdakeheat works as well22:27
sdakethat is all i had time to deploy from source and inary to tag today22:27
sdakeheat engine however fails22:27
sdakeheat-api ha san auth failure22:27
sdakeSamYaple  ^^22:27
sdakehttps://bugs.launchpad.net/kolla/+bug/155356522:28
openstackLaunchpad bug 1553565 in kolla "heat is DOA in mitaka-3" [Critical,Confirmed]22:28
openstackgerritJeffrey Zhang proposed openstack/kolla: Copy the logs out of the container  https://review.openstack.org/28854122:33
*** sdake has quit IRC22:38
*** salv-orlando has quit IRC22:39
*** SiRiuS_ has joined #kolla22:42
*** Jeffrey4l has quit IRC22:48
*** v1k0d3n has quit IRC23:10
*** v1k0d3n has joined #kolla23:10
*** sdake has joined #kolla23:13
*** dims has quit IRC23:16
*** sdake has quit IRC23:21
*** salv-orlando has joined #kolla23:40
*** salv-orlando has quit IRC23:47

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!