Friday, 2014-09-12

*** david-lyle has quit IRC00:00
*** oomichi_ has joined #openstack-keystone00:05
*** wanghong has joined #openstack-keystone00:08
*** oomichi has quit IRC00:08
*** RockKuo_Office has joined #openstack-keystone00:09
*** dims__ has quit IRC00:17
*** richm1 has quit IRC00:27
jamielennoxmorganfainberg: what did you call the tracking id you added to a token?00:46
morganfainbergjamielennox, audit_id and i just responded to that thread00:46
morganfainberg;)00:46
*** david-lyle has joined #openstack-keystone00:48
*** amcrn has quit IRC00:48
jamielennoxmorganfainberg: your answer is way more comprehensive than mine00:51
morganfainbergjamielennox, hehehe00:51
morganfainbergoh crap... i need food.00:53
morganfainbergbe back later00:53
*** rodrigods_ has joined #openstack-keystone00:55
*** arosen has left #openstack-keystone00:56
*** ayoung has joined #openstack-keystone01:06
*** wanghong has quit IRC01:07
openstackgerritNathan Kinder proposed a change to openstack/keystone: Set LDAP certificate trust options for LDAPS and TLS  https://review.openstack.org/12095401:08
*** alex_xu has quit IRC01:14
*** rodrigods_ has quit IRC01:15
openstackgerritJamie Lennox proposed a change to openstack/keystonemiddleware: Convert authentication into a plugin  https://review.openstack.org/11585701:16
*** shakamunyi has joined #openstack-keystone01:16
*** shakamunyi has quit IRC01:24
*** alex_xu has joined #openstack-keystone01:24
*** dims_ has joined #openstack-keystone01:28
*** shakamunyi has joined #openstack-keystone01:31
*** dims_ has quit IRC01:31
*** dims_ has joined #openstack-keystone01:32
*** dims_ has quit IRC01:39
*** marcoemorais has quit IRC01:40
*** dims_ has joined #openstack-keystone01:40
*** dims__ has joined #openstack-keystone01:44
*** dims_ has quit IRC01:44
*** dims__ has quit IRC01:51
*** dims_ has joined #openstack-keystone01:52
*** hrybacki has quit IRC01:52
*** dims_ has quit IRC01:57
openstackgerritJamie Lennox proposed a change to openstack/python-keystoneclient: Versioned Endpoint hack for Sessions  https://review.openstack.org/9063202:02
jamielennoxayoung: re-opened ^, i don't know any better way and i don't think we have another choice02:02
ayoungjamielennox, what is the repo for the kerberos plugin going to be called?  what is the python namespace?02:13
jamielennoxkeystoneclient_kerberos02:14
dolphmjamielennox: i do not see anything that needs fixing in middleware, but just wanted to give you the chance to make changes if you thought any were necessary02:15
jamielennoxprobably having the plugin at keystoneclient_kerberos.Auth() is sufficient02:15
jamielennoxdolphm: ok, if swift unit tests are the only ones having problems i think it's ok02:15
jamielennoxdolphm: just having it marked critical i thought i should check02:16
dolphmjamielennox: that's why i marked it critical :) just to make sure we discuss it02:16
jamielennoxswift were the ones who originally requested it being handled elsewhere02:16
*** sunrenjie6 has joined #openstack-keystone02:26
r1chardj0n3sayoung: FYI https://review.openstack.org/#/c/120964/ is the CORS in oslo implementation; if you're going to give it a try beware of https://bugs.launchpad.net/oslo.middleware/+bug/136849002:27
uvirtbotLaunchpad bug 1368490 in oslo.middleware "oslo.middleware.sizelimit configuration conflict" [Undecided,New]02:27
r1chardj0n3sayoung: now that's submitted I'll move on to the angularjs-with-proxy codebase02:27
*** gokrokve has joined #openstack-keystone02:36
*** stevemar has joined #openstack-keystone02:41
*** yasu_ has joined #openstack-keystone02:52
*** KanagarajM has joined #openstack-keystone02:56
*** harlowja is now known as harlowja_away02:56
*** wanghong has joined #openstack-keystone03:04
*** rushiagr_away is now known as rushiagr03:07
*** stevemar has quit IRC03:16
*** stevemar2 has joined #openstack-keystone03:16
ayoungr1chardj0n3s, looking03:16
*** gokrokve_ has joined #openstack-keystone03:17
ayoungr1chardj0n3s, I think that makes sense.  I think the proxy is going to have issues long term, but some people are going to want it, and it will allow the Javascript coding to start while we deal with the CORS issues03:17
r1chardj0n3sayoung: yup. who knows, maybe a saner solution to CORS might pop out...03:17
*** gokrokve has quit IRC03:20
*** gokrokve_ has quit IRC03:21
*** shakamunyi has quit IRC03:22
*** rushiagr is now known as rushiagr_away03:28
*** jimhoagland has joined #openstack-keystone03:43
*** hrybacki has joined #openstack-keystone03:46
*** gokrokve has joined #openstack-keystone04:07
*** rushiagr_away is now known as rushiagr04:12
*** jimhoagland has quit IRC04:37
*** gokrokve has quit IRC04:50
*** HenryG is now known as HenryG_afk04:55
*** hrybacki has quit IRC04:57
*** hrybacki has joined #openstack-keystone04:58
*** jaosorior has joined #openstack-keystone05:01
*** hrybacki has quit IRC05:03
*** HenryG_afk has quit IRC05:04
*** jimhoagland has joined #openstack-keystone05:12
*** HenryG has joined #openstack-keystone05:23
*** HenryG is now known as HenryG_afk05:24
openstackgerritA change was merged to openstack/keystone: LDAP: refactor use of "1.1" OID  https://review.openstack.org/12047805:29
*** jimhoagland has quit IRC05:30
stevemar2morganfainberg, ping05:50
*** morganfainberg is now known as stevemar305:50
stevemar3stevemar2 pong05:50
stevemar3>.>05:51
stevemar2stevemar3, i have a bunch the same reviews for you to review :D05:51
*** stevemar3 is now known as morganfainberg05:51
morganfainbergoh noes05:51
morganfainberg:)05:51
stevemar2nooo i wanted to talk to myself05:51
stevemar2https://review.openstack.org/#/c/119422/05:51
stevemar2https://review.openstack.org/#/c/120105/05:51
stevemar2and https://review.openstack.org/#/c/118537/05:51
stevemar2i'm too impatient >.<05:52
morganfainbergheh05:52
stevemar2partially because i feel they are easy (especially the third one)05:52
morganfainbergi'll look at them in a few05:53
stevemar2m'alrighty05:55
stevemar2i'm out for now i guess05:55
*** stevemar2 is now known as stevemar05:56
openstackgerritOpenStack Proposal Bot proposed a change to openstack/keystone: Imported Translations from Transifex  https://review.openstack.org/12069506:02
*** ajayaa has joined #openstack-keystone06:03
*** sunrenjie6 has quit IRC06:04
*** RockKuo_Office has quit IRC06:09
*** stevemar has quit IRC06:10
*** yasu_ has quit IRC06:23
*** yasu_ has joined #openstack-keystone06:24
*** henrynash has joined #openstack-keystone06:26
*** andreaf has joined #openstack-keystone06:30
*** ukalifon has joined #openstack-keystone06:33
*** bvandenh has joined #openstack-keystone06:35
*** k4n0 has joined #openstack-keystone06:45
*** ajayaa has quit IRC06:57
*** hrybacki has joined #openstack-keystone06:59
*** RockKuo_Office has joined #openstack-keystone07:01
*** hrybacki has quit IRC07:04
r1chardj0n3sayoung: https://github.com/r1chardj0n3s/angboard07:08
*** yasu_ has quit IRC07:11
*** yasu_ has joined #openstack-keystone07:12
*** marekd has joined #openstack-keystone07:17
*** ukalifon has quit IRC07:18
*** wanghong has quit IRC07:22
*** ajayaa has joined #openstack-keystone07:24
*** wanghong has joined #openstack-keystone07:24
*** dobson has quit IRC07:29
*** dobson has joined #openstack-keystone07:32
*** ukalifon has joined #openstack-keystone07:40
*** garnav has joined #openstack-keystone07:43
*** ukalifon has quit IRC07:45
*** ukalifon1 has joined #openstack-keystone07:46
openstackgerritA change was merged to openstack/identity-api: Remove expected dates for new features  https://review.openstack.org/11853708:08
*** oomichi has joined #openstack-keystone08:12
*** oomichi has quit IRC08:12
*** YorikSar_ has joined #openstack-keystone08:13
*** oomichi_ has quit IRC08:16
*** YorikSar has quit IRC08:17
*** wanghong has quit IRC08:26
openstackgerritAlexander Makarov proposed a change to openstack/keystone: LDAP additional attribute mappings validation  https://review.openstack.org/11859008:28
*** Dafna has joined #openstack-keystone08:54
openstackgerritA change was merged to openstack/keystone: Sync jsonutils from oslo-incubator 32e7f0b5  https://review.openstack.org/11963908:55
*** wanghong has joined #openstack-keystone08:55
openstackgerritA change was merged to openstack/keystone: Add V3 JSON Home support to GET /  https://review.openstack.org/11824008:55
*** hrybacki has joined #openstack-keystone09:00
*** rushiagr is now known as rushiagr_away09:01
*** hrybacki has quit IRC09:05
*** rushiagr_away is now known as rushiagr09:13
*** ukalifon1 has quit IRC09:32
*** YorikSar_ has quit IRC09:45
*** YorikSar has joined #openstack-keystone09:45
openstackgerritA change was merged to openstack/python-keystoneclient: Expose auth methods on the adapter  https://review.openstack.org/11770909:47
openstackgerritA change was merged to openstack/keystone: Make the extension docs a top level entry in the landing page  https://review.openstack.org/11915909:47
*** dims_ has joined #openstack-keystone10:11
*** alex_xu has quit IRC10:14
*** dims_ has quit IRC10:16
*** dims_ has joined #openstack-keystone10:16
openstackgerritMarek Denis proposed a change to openstack/python-keystoneclient: SAML2 federated authentication for ADFS.  https://review.openstack.org/11177110:17
*** dims_ has quit IRC10:20
openstackgerritRakesh H S proposed a change to openstack/python-keystoneclient: handles keyboard interrupt  https://review.openstack.org/12104610:23
*** YorikSar has quit IRC10:28
openstackgerritPeter Razumovsky proposed a change to openstack/keystone: Add a simple module to work with filters and DNs to LDAP backend  https://review.openstack.org/11748410:29
*** KanagarajM2 has joined #openstack-keystone10:30
*** YorikSar has joined #openstack-keystone10:30
*** KanagarajM has quit IRC10:31
*** KanagarajM2 has quit IRC10:34
openstackgerritPeter Razumovsky proposed a change to openstack/keystone: Add a simple module to work with filters and DNs to LDAP backend  https://review.openstack.org/11748410:36
openstackgerritMarek Denis proposed a change to openstack/keystone: Add documentation on LDAP 'user_id_attribute'  https://review.openstack.org/9348010:41
*** aix has quit IRC10:53
*** aix has joined #openstack-keystone10:54
*** rushiagr is now known as rushiagr_away10:56
*** dims_ has joined #openstack-keystone11:00
*** hrybacki has joined #openstack-keystone11:00
*** RockKuo_Office has quit IRC11:01
*** andreaf has quit IRC11:05
*** andreaf has joined #openstack-keystone11:05
*** hrybacki has quit IRC11:05
*** amakarov_away is now known as amakarov11:10
*** Dafna is now known as Dafna_lunch11:14
*** david-lyle has quit IRC11:57
*** rushiagr_away is now known as rushiagr11:58
*** yasu_ has quit IRC12:02
*** rushiagr is now known as rushiagr_away12:05
*** rushiagr_away is now known as rushiagr12:12
*** dims_ has quit IRC12:21
*** dims_ has joined #openstack-keystone12:22
*** yasu_ has joined #openstack-keystone12:30
samuelmzdo we have a specific channel to discuss things about osclient ?12:31
*** Dafna_lunch is now known as Dafna12:39
*** HenryG_afk is now known as HenryG12:51
*** gordc has joined #openstack-keystone12:52
*** jimhoagland has joined #openstack-keystone12:52
*** hrybacki has joined #openstack-keystone13:01
*** enewlands has joined #openstack-keystone13:05
*** hrybacki has quit IRC13:08
*** yasu_ has quit IRC13:13
*** nkinder_ has quit IRC13:13
*** richm has joined #openstack-keystone13:19
*** joesavak has joined #openstack-keystone13:20
*** stevemar has joined #openstack-keystone13:20
*** garnav has quit IRC13:22
*** dims_ has quit IRC13:23
*** enewlands has quit IRC13:23
*** diegows has joined #openstack-keystone13:23
*** dims_ has joined #openstack-keystone13:23
*** topol has joined #openstack-keystone13:27
*** dims__ has joined #openstack-keystone13:28
*** dims_ has quit IRC13:29
*** hockeynut has joined #openstack-keystone13:31
*** topol has quit IRC13:31
*** sigmavirus24_awa is now known as sigmavirus2413:35
openstackgerritRichard Megginson proposed a change to openstack/keystone: ldap/core deleteTree not always supported  https://review.openstack.org/7489713:36
*** bknudson has joined #openstack-keystone13:39
openstackgerritSteve Martinelli proposed a change to openstack/python-keystoneclient: don't write python bytecode while testing  https://review.openstack.org/12111913:44
*** enewlands has joined #openstack-keystone13:46
*** zzzeek has joined #openstack-keystone13:50
openstackgerritSteve Martinelli proposed a change to openstack/keystone: don't write python bytecode while testing  https://review.openstack.org/12112213:51
*** sbasam_ has quit IRC13:52
openstackgerritSteve Martinelli proposed a change to openstack/keystonemiddleware: don't write python bytecode while testing  https://review.openstack.org/12112313:53
*** tim_r has quit IRC13:59
*** nkinder_ has joined #openstack-keystone14:00
*** zzzeek_ has joined #openstack-keystone14:02
*** bvandenh has quit IRC14:02
*** zzzeek has quit IRC14:04
*** zzzeek_ is now known as zzzeek14:04
*** dims has joined #openstack-keystone14:05
*** r-daneel has joined #openstack-keystone14:05
marekdstevemar: hello boss14:07
stevemarhola marekd !14:08
marekdfinally back.14:09
marekdstevemar: anyway, i wanted follow up with the domain in the fed-token14:09
marekdstevemar: you wrote it is on your todo. Did you guys came up with any good fix for that?14:09
stevemarmarekd, probably just make changes to whatever is incorrectly looking for the domain14:11
stevemartheres no reason to stick an invalid property in the token14:11
marekdstevemar: ++14:11
marekddoes dolphm agree with that?14:11
stevemarthe 'clients' should be smarter and if it's federated, don't look for domain14:11
stevemarmarekd, last i checked, that was his suggestion :)14:11
marekdstevemar: I super like it!!!!!!14:11
marekdstevemar: if you haven't started it yet I can take a look.14:13
stevemarmarekd, nah, i'll do it this afternoon14:13
stevemardo you have the resources to test k2k?14:13
stevemari tried out the metadata generator, works perfectly ++14:13
marekdstevemar: which means shib sp ate it without complains?14:14
*** jimhoagland has quit IRC14:18
*** dims has quit IRC14:18
*** dims has joined #openstack-keystone14:18
*** richm has quit IRC14:19
*** dims has quit IRC14:22
*** dims__ is now known as dimsum14:22
*** dimsum is now known as dimsum_14:22
*** dtroyer has joined #openstack-keystone14:25
*** radez_g0n3 is now known as radez14:25
*** rwsu has quit IRC14:28
*** dtroyer has quit IRC14:32
*** dtroyer has joined #openstack-keystone14:33
*** david-lyle has joined #openstack-keystone14:33
openstackgerritBrant Knudson proposed a change to openstack/keystone: Add characterization test for cleanup role assignments for group  https://review.openstack.org/11963014:33
openstackgerritBrant Knudson proposed a change to openstack/keystone: Fix delete group cleans up role assignments with LDAP  https://review.openstack.org/11963114:33
openstackgerritBrant Knudson proposed a change to openstack/keystone: Fix using local ID to clean up user/group assignments  https://review.openstack.org/11962914:34
openstackgerritBrant Knudson proposed a change to openstack/keystone: Fix LDAP group role assignment listing  https://review.openstack.org/11948014:34
stevemarmarekd, not to that level :(14:37
marekdstevemar: understood.14:39
*** richm has joined #openstack-keystone14:41
*** jorge_munoz has joined #openstack-keystone14:52
*** morganfainberg is now known as morgan14:53
*** rwsu has joined #openstack-keystone14:53
openstackgerritBrant Knudson proposed a change to openstack/keystone: Refactor keystone-all and http/keystone  https://review.openstack.org/6227514:57
*** jimhoagland has joined #openstack-keystone15:02
*** zzzeek_ has joined #openstack-keystone15:06
*** zzzeek has quit IRC15:06
*** zzzeek_ is now known as zzzeek15:06
*** meker12 has joined #openstack-keystone15:09
*** cjellick has joined #openstack-keystone15:11
*** enewlands has quit IRC15:15
*** enewlands has joined #openstack-keystone15:23
*** r-daneel_ has joined #openstack-keystone15:24
*** r-daneel has quit IRC15:25
*** r-daneel__ has joined #openstack-keystone15:26
*** zzzeek has quit IRC15:28
*** r-daneel_ has quit IRC15:30
openstackgerritMarek Denis proposed a change to openstack/python-keystoneclient: Handle federated tokens.  https://review.openstack.org/12114615:30
*** zzzeek has joined #openstack-keystone15:30
*** enewlands has quit IRC15:33
*** openstackgerrit_ has joined #openstack-keystone15:35
*** Ugallu has joined #openstack-keystone15:35
*** enewlands has joined #openstack-keystone15:38
*** jorge_munoz has quit IRC15:40
*** ayoung has quit IRC15:40
*** Ugallu has quit IRC15:44
openstackgerritLance Bragstad proposed a change to openstack/keystone: Allow users to clean up role assignments.  https://review.openstack.org/11984315:50
*** ajayaa has quit IRC15:51
*** rushiagr is now known as rushiagr_away15:52
*** zzzeek_ has joined #openstack-keystone15:59
*** zzzeek has quit IRC16:00
*** zzzeek_ is now known as zzzeek16:00
*** morgan is now known as morganfainberg16:02
*** wwriverrat has joined #openstack-keystone16:03
*** enewlands has quit IRC16:07
*** enewlands has joined #openstack-keystone16:07
*** jsavak has joined #openstack-keystone16:08
*** joesavak has quit IRC16:11
*** rushiagr_away is now known as rushiagr16:12
*** r-daneel__ has quit IRC16:16
*** enewlands has quit IRC16:16
openstackgerritMarek Denis proposed a change to openstack/python-keystoneclient: Handle federated tokens.  https://review.openstack.org/12114616:21
*** mitz has quit IRC16:23
*** enewlands has joined #openstack-keystone16:25
openstackgerritMorgan Fainberg proposed a change to openstack/keystone: Update sample config  https://review.openstack.org/12116616:25
*** r-daneel__ has joined #openstack-keystone16:28
*** marcoemorais has joined #openstack-keystone16:29
*** enewlands has quit IRC16:29
*** Dafna has quit IRC16:29
*** amakarov is now known as amakarov_away16:33
openstackgerritMorgan Fainberg proposed a change to openstack/keystone: Update sample config  https://review.openstack.org/12116616:39
*** k4n0 has quit IRC16:40
*** zzzeek has quit IRC16:50
YorikSarmorganfainberg: Hi16:57
morganfainbergYorikSar, hi16:57
YorikSarmorganfainberg: Did you have a chance to have another round on memcache pool change?16:57
morganfainbergYorikSar, haven't had a chance to review yet, sorry16:58
morganfainbergjust getting going today16:58
YorikSarmorganfainberg: Ok, np.16:58
YorikSarmorganfainberg: I think I'll start working on backport to Icehouse on Monday16:59
morganfainbergsounds good16:59
*** marcoemorais has quit IRC16:59
*** marcoemorais has joined #openstack-keystone17:00
YorikSarmorganfainberg: If there won't be any big issue with this in master, of course.17:00
*** marcoemorais has quit IRC17:00
*** marcoemorais has joined #openstack-keystone17:01
morganfainbergYorikSar, likely no big issues17:02
YorikSarmorganfainberg: btw, where should I target keystonemiddleware part?17:04
YorikSarmorganfainberg: it looks like we should just encourage using latest python-keystoneclient with keystonemiddleware, right?17:05
*** rkofman has quit IRC17:05
*** rkofman has joined #openstack-keystone17:06
YorikSarmorganfainberg: Oh, wait... keystoneclient has a copy of auth_token. I thought it was importing auth_token from keystonemiddleware.17:07
morganfainbergit is17:07
morganfainbergkeystoneclient is frozen/deprecated17:07
morganfainbergfor the middelware17:07
YorikSarmorganfainberg: But in Icehouse services use it17:08
YorikSarmorganfainberg: So we should add memcache pool there as well?..17:08
*** lsmola_ has quit IRC17:18
*** grantbow has quit IRC17:18
*** lsmola_ has joined #openstack-keystone17:19
henrynashdolphm: I’d really like to get a fix for https://bugs.launchpad.net/keystone/+bug/1217017 into RC1….the fix is trivial, but the testing is a bit more complex…..I should have it posted tonight17:19
*** Guest55717 has quit IRC17:19
uvirtbotLaunchpad bug 1217017 in keystone "dependency injection fails to init domain-specific identity drivers" [Medium,New]17:19
*** grantbow has joined #openstack-keystone17:19
morganfainbergYorikSar, we'll evaluate keystoneclient once middleware is merged17:21
morganfainbergYorikSar, don't worry about it until then.17:21
morganfainbergYorikSar, basically anything that merged to python-keystoneclient middleware needs to first merge to keystonemiddleware. and we can see if it is something we want to do.17:22
*** wwriverrat1 has joined #openstack-keystone17:24
*** wwriverrat2 has joined #openstack-keystone17:25
YorikSarmorganfainberg: Ok. I'll just work on Icehouse Keystone then and we'll see if we need to port middleware changes to client.17:27
*** wwriverrat2 has left #openstack-keystone17:27
*** wwriverrat has quit IRC17:28
*** wwriverrat1 has quit IRC17:28
*** harlowja_away is now known as harlowja17:34
openstackgerritBob Thyne proposed a change to openstack/keystone: Add delete notification to endpoint grouping  https://review.openstack.org/11772317:39
*** wwriverrat has joined #openstack-keystone17:41
*** meker12 has quit IRC17:43
openstackgerritBob Thyne proposed a change to openstack/keystone: Add delete notification to endpoint grouping  https://review.openstack.org/11772317:43
*** rushiagr is now known as rushiagr_away17:45
*** wwriverrat has left #openstack-keystone17:47
*** meker12_ has joined #openstack-keystone17:48
*** marcoemorais has quit IRC17:49
*** marcoemorais has joined #openstack-keystone17:50
*** marcoemorais has quit IRC17:50
*** marcoemorais has joined #openstack-keystone17:50
*** marcoemorais has quit IRC17:51
*** marcoemorais has joined #openstack-keystone17:51
*** meker12_ has quit IRC17:59
*** zzzeek has joined #openstack-keystone18:00
openstackgerritBob Thyne proposed a change to openstack/keystone: Add delete notification to endpoint grouping  https://review.openstack.org/11772318:02
openstackgerritBob Thyne proposed a change to openstack/keystone: Add delete notification to endpoint grouping  https://review.openstack.org/11772318:05
*** topol has joined #openstack-keystone18:20
*** _cjones_ has joined #openstack-keystone18:31
*** meker12 has joined #openstack-keystone18:35
*** bjornar_ has joined #openstack-keystone18:39
*** meker12 has quit IRC18:41
*** meker12 has joined #openstack-keystone18:42
bknudsonhenrynash: so sql backend needs to take a conf?18:48
henrynashbknudson: yes18:48
bknudsonok, just making sure I understood it18:48
henrynashbknudson: the testing around proving that it works well is what’s taling the time (without duplicating swathes of test code)18:49
henrynashbknudson: should have it licked tonight18:49
stevemarmarekd, you took it from my todo list :)18:50
*** saipandi has joined #openstack-keystone18:52
*** stevemar has quit IRC18:52
*** stevemar has joined #openstack-keystone18:53
*** amcrn has joined #openstack-keystone18:55
*** bambam1 has quit IRC18:55
marekdstevemar: i had few spare cycles...tbh  when we talked before I was not sure you will be fine with that but i took the risk :-)18:57
marekdi hope you are fine with that.18:58
stevemarmarekd, hehe, of course i am!18:59
marekdstevemar: allright.19:00
marekdneed to get some food, be back soon.19:00
stevemarkk19:00
*** jaosorior has quit IRC19:02
*** _cjones_ has quit IRC19:11
stevemarmarekd, did you try if that fixes the issue?19:16
stevemarI'm worried that now we won't get a KeyError, but maybe another error19:17
openstackgerritayoung proposed a change to openstack/python-keystoneclient: Enumerate Projects with Unscoped Tokens  https://review.openstack.org/10683819:29
*** wwriverrat1 has joined #openstack-keystone19:39
*** wwriverrat1 has left #openstack-keystone19:39
*** bambam1 has joined #openstack-keystone19:45
*** andreaf has quit IRC19:48
*** andreaf has joined #openstack-keystone19:49
bknudsonmorganfainberg: your comment worked!19:50
marekdstevemar: nope, to be honest not really.19:51
morganfainbergbknudson, hehe19:51
marekdstevemar: i need to setup new vm with full devstack, so i can try nova/glance/other services.19:51
stevemarmarekd, alright19:51
stevemarmarekd, cause I'm noticing auth_token middleware still calls auth_ref.user_domain_name19:52
stevemarand i'm wondering what will happen if thats None19:52
marekdstevemar: can you copy the line number (where auth_token calls it)19:53
marekd?19:53
stevemarmarekd, 1 sec19:54
stevemarmarekd, https://github.com/openstack/python-keystoneclient/blob/master/keystoneclient/middleware/auth_token.py#L95919:54
stevemarkeep in mind, that code is in keystonemiddleware repo now19:54
*** amcrn has quit IRC19:59
marekdstevemar: hm, what's the role of keystonemiddleware btw?19:59
marekdand why it was moved to a separated repo?19:59
stevemarmarekd, keystonemiddleware is what all the other services like nova/glance use to interact with keystone20:00
marekdso auth plugins as well?20:00
stevemarseparate repo because realistically, it belonged there, let client handle the client API calls, let middleware be the place that other projects use20:01
stevemarno, just middleware stuff20:01
stevemarbknudson, dstanek any thing else you think i'm missing ^20:01
bknudsonkeystonemiddleware contains the middleware20:02
bknudsone.g. auth_token20:02
marekdbknudson: and what's the purpose of the auth_token ?20:04
*** marcoemorais1 has joined #openstack-keystone20:04
*** marcoemorais1 has quit IRC20:04
bknudsonmarekd: it sits in front of nova-api, etc., and validates the token in the request20:04
*** marcoemorais1 has joined #openstack-keystone20:05
marekdbknudson: ok.20:05
*** zzzeek has quit IRC20:07
*** marcoemorais has quit IRC20:07
*** joesavak has joined #openstack-keystone20:08
*** jsavak has quit IRC20:09
*** henrynash has quit IRC20:11
*** zzzeek has joined #openstack-keystone20:11
*** andreaf has quit IRC20:24
*** andreaf has joined #openstack-keystone20:25
*** achampion has joined #openstack-keystone20:25
achampionare sessions meant to be fully working in keystoneclient?20:28
*** ayoung has joined #openstack-keystone20:29
achampionI seem to have to pass an auth_url/endpoint into the Client in addition to the session object20:29
*** r-daneel__ has quit IRC20:29
achampionsess = session.Session(auth=auth); keystone = client.Client(version=(2,0), session=sess)20:30
stevemarachampion, did you check out http://docs.openstack.org/developer/python-keystoneclient/using-sessions.html20:30
achampionDiscoveryFailure: Not enough information to determine URL. Provide either auth_url or endpoint20:31
achampionYes20:31
*** meker12 has quit IRC20:31
achampionThough using v2.0 API vs v320:32
stevemarachampion, it *should* work, can you write the code/error in a paste?20:32
*** gyee has joined #openstack-keystone20:34
*** andreaf has quit IRC20:34
*** andreaf has joined #openstack-keystone20:35
achampionhttp://paste.openstack.org/show/110793/20:36
stevemarbknudson, if the token is validated, the token info gets slotted into headers right? so i guess it's up to nova/glace/etc to use the headers if they want? cc marekd20:36
bknudsonstevemar: right, it pulls fields out of the token and puts them into the request context.20:36
bknudsonthat's used in policy checks mostly, but can also be used elsewhere.20:37
stevemarbknudson, would nova or novaclient look @ that content?20:37
stevemartrying to find a example of it actually being consumed20:37
achampionI'm using branch origin/master20:38
bknudsonstevemar: y, nova would look at it. The token has the roles so it matches the roles against the policy.20:39
stevemarbknudson, i'm wondering if anything looks @ user_domain_name or user_domain_id20:40
bknudsonstevemar: probably not due to nobody using identity v320:41
bknudsonstevemar: I think morganfainberg might have been looking at a policy change to check for domain-scoped tokens?20:41
*** radez is now known as radez_g0n320:42
*** ayoung has quit IRC20:42
achampiontested with v3 api and same result: DiscoveryFailure - hmmm.20:42
achampionIt seems the wrapper class keystone.client breaks when using sessions, using the direct client keystone.v2.client works okay.20:45
achampionI mean: keystoneclient.v2_0.client20:45
stevemarbknudson, marekd seems like nova uses X-auth-token, roles, userid, tenantid, status and catalog, thats about it20:47
stevemarand it just uses them to create a glance client, to create an image, sure why not20:48
*** fifieldt_ has joined #openstack-keystone20:50
*** meker12 has joined #openstack-keystone20:51
*** marcoemorais1 has quit IRC20:52
*** marcoemorais has joined #openstack-keystone20:53
*** marcoemorais has quit IRC20:53
*** marcoemorais has joined #openstack-keystone20:54
*** fifieldt has quit IRC20:54
*** marcoemorais has quit IRC20:55
*** marcoemorais has joined #openstack-keystone20:55
*** ayoung has joined #openstack-keystone20:57
*** rodrigods has quit IRC20:59
*** henrynash has joined #openstack-keystone21:02
marekdstevemar: where did you find it?21:08
marekdstevemar: btw i grepped for X-Project-Domain-Id in nova and found nothing, but to me it doesn't prove it will never use it.21:09
stevemarmarekd, https://github.com/openstack/nova/blob/master/nova/image/glance.py#L121-L12921:09
*** jsavak has joined #openstack-keystone21:10
stevemarmarekd, as bknudson said, I doubt any project is using X-User-Domain-Id or Name, since none are really talking v321:10
marekdstevemar: ++21:10
stevemarmarekd, i think we'll be OK for the time being21:12
*** joesavak has quit IRC21:13
*** topol has quit IRC21:17
marekdstevemar: so review, please :-)21:18
marekdstevemar: i will add jamielennox21:18
marekdas a reviewer21:18
stevemarmarekd, haha, of course21:19
stevemarI was wondering if we could have a test that actually tries to push that sort of data through the middleware21:19
*** zzzeek has quit IRC21:20
nkinder_marekd: jamielennox is going to be gone for a while21:20
marekdnkinder_: why?21:20
nkinder_marekd: getting married and going on honeymoon21:21
bknudsonjamielennox is gone, dolphm is gone... time to party.21:21
marekdnkinder_: wow! I didn't know that.21:21
marekdbknudson: and dolph is where?21:21
*** dhellmann is now known as dhellmann_21:22
bknudsonmarekd: he said he was going to be out for a couple weeks.21:22
marekdbknudson: okay.21:23
marekdhope is is doing fine.21:23
stevemarmarekd, reviewed21:24
marekdstevemar: looking.21:25
openstackgerritA change was merged to openstack/keystone: Update the docs that list sections in keystone.conf  https://review.openstack.org/11855021:34
*** andreaf has quit IRC21:34
openstackgerrithenry-nash proposed a change to openstack/keystone: Ensure identity sql driver supports domain-specific configuration.  https://review.openstack.org/12124621:34
*** andreaf has joined #openstack-keystone21:34
*** dimsum_ has quit IRC21:36
marekdstevemar: well, it's more like academic discussion, but i didn't put the tests in test_saml2_auth because this change is federation specific, not saml2 specific.21:36
*** dimsum_ has joined #openstack-keystone21:36
bknudsonhenrynash: doesn't the sql backend need to use a different engine and session?21:37
*** stevemar2 has joined #openstack-keystone21:37
henrynashbknudson: so, this patch only let’s you have one sql backend….21:37
henrynashbknudson: e.g. LDAP for evyerthing, but put my service users in an SQL backend one domain21:38
henrynashbknudson: a further enhancement is to see if we can actually have multiple SQL backends21:38
bknudsonotherwise it's using the same database.21:38
*** stevemar has quit IRC21:38
*** csd has quit IRC21:39
*** jamielennox has quit IRC21:39
henrynashbknudson: agreed…and I should state the limitations with the patch, you are right21:39
*** jamielenz has joined #openstack-keystone21:40
*** jamielenz is now known as jamielennox21:40
*** dimsum_ has quit IRC21:40
*** rkofman has quit IRC21:41
*** nonameentername has quit IRC21:41
*** rkofman has joined #openstack-keystone21:41
*** csd has joined #openstack-keystone21:42
*** nonameentername has joined #openstack-keystone21:42
*** bjornar_ has quit IRC21:43
*** arunkant has quit IRC21:43
*** stevemar2 has quit IRC21:43
*** rodrigods has joined #openstack-keystone21:43
*** rodrigods has quit IRC21:43
*** rodrigods has joined #openstack-keystone21:43
*** bjornar_ has joined #openstack-keystone21:44
morganfainbergbknudson, not sure how hard it would be to switch over to audit_ids.21:44
morganfainbergbknudson, instead of the **REDACTED** bit21:44
morganfainbergbknudson, but i think that should be the end goal if possible.21:44
*** arunkant has joined #openstack-keystone21:46
bknudsonmorganfainberg: I also would prefer audit ids, but sometimes all we have is the token ID21:46
morganfainbergright21:47
bknudsonhenrynash: can that be enforced in code (as in, fail to start if you're trying to config with multiple sql backends, or have sql config options in your local config...)21:48
henrynashbknudson: let me think on that one21:49
openstackgerritA change was merged to openstack/keystone: Enable filtering of services by name  https://review.openstack.org/11090421:52
openstackgerrithenry-nash proposed a change to openstack/keystone: Ensure identity sql driver supports domain-specific configuration.  https://review.openstack.org/12124621:54
openstackgerritMarek Denis proposed a change to openstack/python-keystoneclient: Handle federated tokens.  https://review.openstack.org/12114621:55
*** david-lyle has quit IRC22:03
*** gordc has quit IRC22:05
*** nkinder_ has quit IRC22:08
*** topol has joined #openstack-keystone22:12
*** richm1 has joined #openstack-keystone22:13
*** rodrigods has quit IRC22:14
*** ctracey has quit IRC22:15
*** serverascode has quit IRC22:15
*** sigmavirus24 is now known as sigmavirus24_awa22:15
*** ctracey has joined #openstack-keystone22:15
*** jraim___ has joined #openstack-keystone22:16
*** joesavak has joined #openstack-keystone22:17
*** electrichead has joined #openstack-keystone22:17
*** serverascode has joined #openstack-keystone22:18
*** richm has quit IRC22:18
*** afazekas has quit IRC22:18
*** dhellmann_ has quit IRC22:18
*** jraim__ has quit IRC22:18
*** Alexander has joined #openstack-keystone22:19
*** Alexander is now known as Guest3789022:19
*** jraim___ is now known as jraim__22:20
*** boris-42_ has joined #openstack-keystone22:22
*** nkinder_ has joined #openstack-keystone22:23
*** mfisch` has joined #openstack-keystone22:23
henrynashbknudson: yes, I think it can be enforced with code….I will add that over the weekend22:24
bknudsonhenrynash: cool. I'm sure someone would try it and complain to us if it didn't fail early and hard.22:24
henrynashbknudsonL indeed…it wouldn’t corrupt data if they did that (since we still pass the domain into sql backend tables)…but it wouldn’t do what they were expecting22:25
henrynashbknudson: which is bad22:26
*** andreaf has quit IRC22:26
*** topol_ has joined #openstack-keystone22:26
*** stevemar has joined #openstack-keystone22:27
*** nonameentername has quit IRC22:27
*** openstack has joined #openstack-keystone23:36
*** sendak.freenode.net sets mode: +ns 23:36
*** meker12 has joined #openstack-keystone23:38
*** bjornar has joined #openstack-keystone23:38
*** sendak.freenode.net sets mode: -o openstack23:42
-sendak.freenode.net- *** Notice -- TS for #openstack-keystone changed from 1410565002 to 137738402423:42
*** sendak.freenode.net sets mode: +ct-s 23:42
*** YorikSar has joined #openstack-keystone23:42
*** dimsum_ has joined #openstack-keystone23:42
*** xianghui has joined #openstack-keystone23:42
*** marcoemorais has joined #openstack-keystone23:42
*** afazekas has joined #openstack-keystone23:42
*** nonameentername has joined #openstack-keystone23:42
*** ekarlso- has joined #openstack-keystone23:42
*** raildo has joined #openstack-keystone23:42
*** thiagop has joined #openstack-keystone23:42
*** dhellmann has joined #openstack-keystone23:42
*** openstackgerrit has joined #openstack-keystone23:42
*** Guest37890 has joined #openstack-keystone23:42
*** sigmavirus24_awa has joined #openstack-keystone23:42
*** Daviey has joined #openstack-keystone23:42
*** larsks has joined #openstack-keystone23:42
*** HenryG has joined #openstack-keystone23:42
*** diegows has joined #openstack-keystone23:42
*** gus has joined #openstack-keystone23:42
*** afaranha has joined #openstack-keystone23:42
*** marzif_ has joined #openstack-keystone23:42
*** Guest74618 has joined #openstack-keystone23:42
*** montanvi has joined #openstack-keystone23:42
*** cjellick_ has joined #openstack-keystone23:42
*** rm_work has joined #openstack-keystone23:42
*** lbragstad has joined #openstack-keystone23:42
*** d34dh0r53 has joined #openstack-keystone23:42
*** csd has joined #openstack-keystone23:42
*** adam_g has joined #openstack-keystone23:42
*** gokrokve has joined #openstack-keystone23:42
*** dolphm has joined #openstack-keystone23:42
*** boris-42 has joined #openstack-keystone23:42
*** jimbaker has joined #openstack-keystone23:42
*** r1chardj0n3s_afk has joined #openstack-keystone23:42
*** kevinbenton has joined #openstack-keystone23:42
*** harlowja_ has joined #openstack-keystone23:42
*** amerine_ has joined #openstack-keystone23:42
*** mfisch` has joined #openstack-keystone23:42
*** serverascode has joined #openstack-keystone23:42
*** electrichead has joined #openstack-keystone23:42
*** joesavak has joined #openstack-keystone23:42
*** jraim__ has joined #openstack-keystone23:42
*** ctracey has joined #openstack-keystone23:42
*** richm1 has joined #openstack-keystone23:42
*** bjornar_ has joined #openstack-keystone23:42
*** rkofman has joined #openstack-keystone23:42
*** jamielennox has joined #openstack-keystone23:42
*** ayoung has joined #openstack-keystone23:42
*** gyee has joined #openstack-keystone23:42
*** saipandi has joined #openstack-keystone23:42
*** lsmola_ has joined #openstack-keystone23:42
*** rwsu has joined #openstack-keystone23:42
*** dtroyer has joined #openstack-keystone23:42
*** hockeynut has joined #openstack-keystone23:42
*** aix has joined #openstack-keystone23:42
*** wanghong has joined #openstack-keystone23:42
*** dobson has joined #openstack-keystone23:42
*** marekd|away has joined #openstack-keystone23:42
*** gothicmindfood has joined #openstack-keystone23:42
*** portante has joined #openstack-keystone23:42
*** miqui has joined #openstack-keystone23:42
*** f13o has joined #openstack-keystone23:42
*** gabriel-bezerra has joined #openstack-keystone23:42
*** jasondotstar has joined #openstack-keystone23:42
*** lvh has joined #openstack-keystone23:42
*** comstud has joined #openstack-keystone23:42
*** Haneef has joined #openstack-keystone23:42
*** htruta has joined #openstack-keystone23:42
*** roock has joined #openstack-keystone23:42
*** morgan_remote has joined #openstack-keystone23:42
*** morgan has joined #openstack-keystone23:42
*** palendae has joined #openstack-keystone23:42
*** mflobo has joined #openstack-keystone23:42
*** esmute has joined #openstack-keystone23:42
*** therve has joined #openstack-keystone23:42
*** vishy has joined #openstack-keystone23:42
*** rushiagr_away has joined #openstack-keystone23:42
*** EmilienM has joined #openstack-keystone23:42
*** hyakuhei has joined #openstack-keystone23:42
*** zhiyan has joined #openstack-keystone23:42
*** mhu has joined #openstack-keystone23:42
*** radez_g0n3 has joined #openstack-keystone23:42
*** chmouel has joined #openstack-keystone23:42
*** notmyname has joined #openstack-keystone23:42
*** rharwood has joined #openstack-keystone23:42
*** sudorandom has joined #openstack-keystone23:42
*** jamiec has joined #openstack-keystone23:42
*** dvorak has joined #openstack-keystone23:42
*** uvirtbot has joined #openstack-keystone23:42
*** wolsen has joined #openstack-keystone23:42
*** gmurphy has joined #openstack-keystone23:42
*** anteaya has joined #openstack-keystone23:42
*** sendak.freenode.net sets mode: +o morgan23:42
*** zigo has joined #openstack-keystone23:42
*** achudnovets has joined #openstack-keystone23:42
*** ByteSore has joined #openstack-keystone23:42
*** shufflebot has joined #openstack-keystone23:42
*** d0ugal has joined #openstack-keystone23:42
*** ChanServ has joined #openstack-keystone23:42
*** dstanek has joined #openstack-keystone23:42
*** sendak.freenode.net sets mode: +o ChanServ23:42
*** sendak.freenode.net sets mode: +b *!awrbgh@197.123.75.19123:42
*** sendak.freenode.net changes topic to "Review RC1 blockers plzkthx https://gist.github.com/dolph/651c6a1748f69637abd0"23:42
*** dimsum_ has quit IRC23:43
*** grantbow has joined #openstack-keystone23:44
*** hrybacki has joined #openstack-keystone23:44
*** amerine has joined #openstack-keystone23:44
*** harlowja has joined #openstack-keystone23:44
*** amerine has quit IRC23:44
*** harlowja has quit IRC23:44
*** gokrokve has quit IRC23:46
*** montanvi has quit IRC23:48
*** amerine_ is now known as amerine23:50
*** dimsum_ has joined #openstack-keystone23:54
*** jimhoagland has joined #openstack-keystone23:54
*** fifieldt has joined #openstack-keystone23:54
*** arunkant has joined #openstack-keystone23:54
*** andreaf has joined #openstack-keystone23:54
*** samuelmz has joined #openstack-keystone23:54
*** mitz has joined #openstack-keystone23:54
*** mitz has quit IRC23:54
*** dimsum_ has quit IRC23:54
*** mitz has joined #openstack-keystone23:55
*** dimsum_ has joined #openstack-keystone23:55
*** bjornar_ has quit IRC23:56
*** ctracey has quit IRC23:58
*** ctracey has joined #openstack-keystone23:58
*** jraim__ has quit IRC23:58
*** jraim__ has joined #openstack-keystone23:58
*** serverascode has quit IRC23:58
*** serverascode has joined #openstack-keystone23:58
*** harlowja_ has quit IRC23:58
*** harlowja_ has joined #openstack-keystone23:58
*** marzif_ has quit IRC23:59
*** marzif_ has joined #openstack-keystone23:59

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!