Thursday, 2014-11-27

crinklezigo: hmm, I think I'm either misunderstanding or I didn't communicate effectively - we're looking to consume python-openstackclient in the stackforge puppet modules, ideally without the user having to add a new repository, so my inquiry was about its status in the ubuntu standard package repositories or ubuntu cloud archive (and similarly for epel/rdo)00:45
crinkleit's great that we can use that package for development in the mean time though00:46
zigocrinkle: I do *not* control whatever crap they do at Canonical ! :)00:50
crinklezigo: :)00:51
zigoI do my bugs only in Debian... :)00:51
zigocrinkle: You probably want to ask james page about that.00:51
crinklezigo: does he have an irc nick?00:52
zigoYeah... jamespage ... :)00:52
crinklehow unexpected00:52
zigoOtherwise James Page <>00:53
crinkleawesome, thanks for your help!00:53
zigoBut he's currently logged on IRC (both OFTC and Freenode).00:53
zigocrinkle: No problem, and please do consider switching to Debian ! :)00:53
crinklezigo: haha, we're trying to support Debian + Ubuntu + RHEL :)00:54
crinklewill probably try to bug people after the holiday00:55
mgagnecrinkle: there is a list of packages available in Ubuntu Cloud Archive: and
crinklethat is useful00:56
mgagnecrinkle: unfortunately, python-openstackclient looks to not be packaged in UCA00:56
crinklehence my inquiry00:56
*** NM has joined #openstack-keystone01:37
openstackgerritSteve Martinelli proposed openstack/keystone: Update docs to no longer show XML support
openstackgerritwanghong proposed openstack/keystone: move matching id check in policy update into controller
openstackgerritwanghong proposed openstack/keystone: move matching id check in policy update into controller
ayoungnkinder,  merged.  It twice got caught in a server migration issue, dropping it from Zuul.03:57
nkinderayoung: yep, I saw the notification04:00
nkinderayoung: nice to see that finally go through04:00
ayoungnkinder, I think we need to get more reviewers on the other puppet-keystone patches04:00
ayoungalso, Matt has an LDAP patch that is in merge conflict and has been sitting since August04:01
ayoungwant me to grab that?04:01
ayounger, Rich...not Matt04:02
ayoung  nkinder this one04:02
openstackgerritayoung proposed openstack/keystone: better handling for empty/None ldap values
*** tellesnobrega_ has quit IRC04:27
openstackgerritJamie Lennox proposed openstack/keystonemiddleware: Turn our auth plugin into a token interface
openstackgerritJamie Lennox proposed openstack/python-keystoneclient: Fix importing config module and classmethod params
openstackgerritMerged openstack/python-keystoneclient: Sync oslo-incubator to 1fc3cd47
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Imported Translations from Transifex
openstackgerritSteve Martinelli proposed openstack/keystone: New stuff
ekarlso-stevemar: ^ not the best title i've seen :P07:41
openstackgerritSteve Martinelli proposed openstack/keystone: Add support for listing public idps
openstackgerritMarcos Fermín Lobo proposed openstack/keystone: Implement group related methods for LDAP backend
mzbikAnyone alive here?08:54
mzbikHow can I pass filter like this (&(cn={0})(objectClass=groupOfUniqueNames)) in keystone with LDAP?08:55
mzbikexact question is: how to pass argument to that cn={0}?08:56
*** xiaozhi_ has joined #openstack-keystone09:29
samuelmsmzbik, hi10:36
samuelmsmzbik, what do you'd like to do? filter users when calling list_users API?10:36
mzbiksamuelms, rather I wanted to filter group name when listing groups11:13
mzbikI have huge LDAP11:13
mzbikI wanted to use /v3/groups?name=MyGroup&domain_id=123456 to filter only MyGroup11:14
mzbikin LDAP for that domain there are thousands of groups11:14
mzbikit too much for keystone (size exeeced)11:15
mzbikand I cant use page_size11:15
mzbikso I thout I could use that kind of filter to filter only one group without fetching all groups from LDAP11:17
openstackgerritBoris Bobrov proposed openstack/python-keystoneclient: Add self-installation to venv deployment
samuelmsmzbik, why are you passing domain_id on your request?  /v3/groups?name=MyGroup&domain_id=12345611:58
samuelmsmzbik, one you have a token for that domain, you just need to query /v3/groups?name=MyGroup11:59
mzbiksamuelms, im affraid you are wrong12:00
mzbikit is obligatory if you have multibackend in keystone12:00
uvirtbotLaunchpad bug 1387379 in keystone "No documentation on the fact that List users/groups  require a domain to be specified in multi domain configuration" [Medium,In progress]12:00
mzbik"if domain-specific drivers are enabled then, as indicated above, you must specify a domain_id as par of the a GET /users or GET /groups call."12:01
samuelmsmzbik, so you're using this?12:03
samuelmsmzbik, you have multiple ldap connected instead of a single one as you said ..12:03
rodrigodsmzbik, you need to specify only if you don't have the domain_id in your token12:04
*** diegows has joined #openstack-keystone12:04
mzbikrodrigods, I have but it does not work, anyways clue is a bit different ;)12:05
mzbiksamuelms, yes I have SQL backend for service users and LDAP for rest of users cause I have read-only LDAP and cannot change it.12:20
samuelmsmzbik, ok .. I think ayoung is a good person to help you out .. he understand better how ldap things are implemented12:29
mzbikayoung, ping12:30
marekdmzbik: ^^ so you are now doomed :P12:30
mzbikAm I? :(12:30
mzbikerm... ayound is Adam Young?12:30
mzbikyes... Im doomed12:31
openstackgerritAndre Aranha proposed openstack/keystone-specs: Modify the policy file
*** kobtea has joined #openstack-keystone12:55
openstackgerritIlya Pekelny proposed openstack/keystone: Comparision of database models and migrations.
openstackgerritIlya Pekelny proposed openstack/keystone: Fix index name the assignment.actor_id table.
openstackgerritIlya Pekelny proposed openstack/keystone: Add primary key to the endpoint_group id column.
openstackgerritIlya Pekelny proposed openstack/keystone: Add index to the revocation_event.revoked_at.
openstackgerritIlya Pekelny proposed openstack/keystone: Migrate_repo init version helper
openstackgerritIlya Pekelny proposed openstack/keystone: Use metadata.create_all() to fill a test database
ajayaaHi. How does other openstack components check for project's existence in keystone, where project_id is used in the url.13:58
ayoungmzbik, it is thanksgiving here, and I am really not supposed to be doing work....13:59
ayoungI think you can filter on groups13:59
mzbikayoung, I will try to ping you after holidays then14:01
*** mzbik has quit IRC14:09
marekdstevemar: if you make an apache configuration with <Location /v3/OS-FEDERATION/identity_providers/*/...>  you would need to *again* implement Discover service, something you want to do for Horizon already...15:29
marekdstevemar: so, you 'd go to horizon, choose idp of your choice, get redirected to Keystone, go again to similar page where you choose a IdP of your choice.15:29
marekdstevemar: hi, btw :-)15:31
stevemarmarekd, hello as well :)15:32
marekdmaybe the the alternative is to implement one endpoint, v3/OS-FEDERATION/websso15:33
marekdwhere a user is redirected always15:33
marekdthen, he actually gets to the DS15:33
marekdwhich is completely separate from Keystone15:34
marekduser authenticates15:34
marekdgets back to /websso endpoint15:34
marekdand the right mapping is choosed basing on IdP identifier squeezed into saml assertion15:34
marekdthen, we would need to add entityId in the identity_provider objects, instead of is_public15:35
marekdlike here:
marekdyou know what i mean?15:41
*** ukalifon1 has quit IRC15:59
openstackgerritAlexander Makarov proposed openstack/keystone-specs: Trust redelegation documentation
*** stevemar has quit IRC16:27
openstackgerritSergey Kraynev proposed openstack/python-keystoneclient: Using correct keyword for region in v3
openstackgerritAndre Aranha proposed openstack/keystone: Modify the policy v3 sample
openstackgerritAndre Aranha proposed openstack/keystone-specs: Modify the policy file
samuelmshenrynash, which one sounds better: '_list_applicable_assignments_TO_user_and_project' or '_list_applicable_assignments_FOR_user_and_project'?21:08
samuelmshenrynash, applicable should be direct + indirect assignments (from expansion)21:09
samuelmsdoes anyone know which one sounds better ?21:10
samuelmsI meant, which one is correct ? if both, then which one sounds better :p21:10
*** mzbik_ has quit IRC21:12
*** NM has quit IRC21:12
*** dims has joined #openstack-keystone21:14
openstackgerritOpenStack Proposal Bot proposed openstack/keystone: Updated from global requirements
openstackgerritOpenStack Proposal Bot proposed openstack/keystonemiddleware: Updated from global requirements
openstackgerritOpenStack Proposal Bot proposed openstack/python-keystoneclient: Updated from global requirements
