Sunday, 2015-06-28

*** dims has joined #openstack-keystone00:09
openstackgerritJamie Lennox proposed openstack/keystonemiddleware: Extract basic validation processing to base class  https://review.openstack.org/18081800:18
openstackgerritJamie Lennox proposed openstack/keystonemiddleware: Separate the fetch and validate token processes  https://review.openstack.org/19094000:18
openstackgerritJamie Lennox proposed openstack/keystonemiddleware: Don't cache signed tokens  https://review.openstack.org/19094100:18
openstackgerritJamie Lennox proposed openstack/keystonemiddleware: Create a simple base class from AuthProtocol  https://review.openstack.org/18081600:18
openstackgerritDavanum Srinivas (dims) proposed openstack/python-keystoneclient: Remove unnecessary install_venv_common module  https://review.openstack.org/18912300:21
*** arunkant_ has joined #openstack-keystone00:43
*** arunkant__ has quit IRC00:46
*** boris-42 has quit IRC00:52
openstackgerritMorgan Fainberg proposed openstack/keystone: Ensure trust tokens are properly handled in v3 to v2 conversion  https://review.openstack.org/19640600:57
*** stevemar has joined #openstack-keystone01:26
*** markvoelker has joined #openstack-keystone01:28
*** stevemar has quit IRC01:29
*** woodster_ has quit IRC01:31
*** markvoelker has quit IRC01:32
*** piyanai has joined #openstack-keystone01:34
*** arunkant__ has joined #openstack-keystone01:44
*** ankita_wagh has joined #openstack-keystone01:45
*** arunkant_ has quit IRC01:47
*** Ephur has quit IRC01:55
*** dims has quit IRC02:23
*** dims has joined #openstack-keystone02:27
*** stevemar has joined #openstack-keystone02:28
*** stevemar has quit IRC02:30
*** ankita_wagh has quit IRC02:40
*** dims has quit IRC02:55
*** woodster_ has joined #openstack-keystone03:09
*** markvoelker has joined #openstack-keystone03:16
*** boris-42 has joined #openstack-keystone03:18
*** markvoelker has quit IRC03:21
*** aix has joined #openstack-keystone03:28
*** stevemar has joined #openstack-keystone03:50
*** arunkant has joined #openstack-keystone04:04
*** arunkant__ has quit IRC04:07
*** markvoelker has joined #openstack-keystone05:05
*** markvoelker has quit IRC05:10
*** spandhe has quit IRC05:29
*** piyanai has quit IRC05:30
*** e0ne has joined #openstack-keystone05:34
openstackgerritSteve Martinelli proposed openstack/python-keystoneclient: Update README.rst and remove ancient reference  https://review.openstack.org/17875905:42
*** e0ne has quit IRC05:42
openstackgerritSteve Martinelli proposed openstack/python-keystoneclient: Remove keystoneclient CLI references in README  https://review.openstack.org/19641305:48
openstackgerritSteve Martinelli proposed openstack/python-keystoneclient: Remove unused images from docs  https://review.openstack.org/19641405:51
*** woodster_ has quit IRC05:51
*** arunkant_ has joined #openstack-keystone05:51
*** e0ne has joined #openstack-keystone05:53
*** arunkant has quit IRC05:54
*** e0ne has quit IRC06:05
*** mabrams has joined #openstack-keystone06:16
openstackgerritMorgan Fainberg proposed openstack/keystone: Issue all V2 tokens the same way as Fernet v2 Tokens  https://review.openstack.org/19642006:20
*** stevemar has quit IRC06:22
*** stevemar has joined #openstack-keystone06:22
*** stevemar has quit IRC06:25
*** vg_ has joined #openstack-keystone06:45
*** markvoelker has joined #openstack-keystone06:54
*** markvoelker has quit IRC06:59
*** ankita_wagh has joined #openstack-keystone07:01
*** boris-42 has quit IRC07:22
*** bknudson has quit IRC07:33
*** spandhe has joined #openstack-keystone07:43
*** belmoreira has joined #openstack-keystone07:45
*** henrynash has joined #openstack-keystone08:06
*** ChanServ sets mode: +v henrynash08:06
*** lhcheng has joined #openstack-keystone08:10
*** ChanServ sets mode: +v lhcheng08:10
*** stevemar has joined #openstack-keystone08:24
*** stevemar has quit IRC08:26
*** henrynash has quit IRC08:31
*** hogepodge has quit IRC08:38
*** lhcheng has quit IRC08:38
*** markvoelker has joined #openstack-keystone08:43
*** ankita_wagh has quit IRC08:46
*** markvoelker has quit IRC08:48
*** spandhe has quit IRC08:55
*** belmoreira has quit IRC09:09
*** arunkant__ has joined #openstack-keystone09:17
*** archers has joined #openstack-keystone09:19
*** archers has quit IRC09:20
*** arunkant_ has quit IRC09:20
*** belmoreira has joined #openstack-keystone09:24
*** belmoreira has quit IRC09:24
*** henrynash has joined #openstack-keystone09:40
*** ChanServ sets mode: +v henrynash09:40
*** hogepodge has joined #openstack-keystone09:43
*** hogepodge has quit IRC09:56
*** hogepodge has joined #openstack-keystone10:00
*** hogepodge has quit IRC10:06
*** stevemar has joined #openstack-keystone10:13
*** stevemar has quit IRC10:15
*** aix has quit IRC10:25
*** markvoelker has joined #openstack-keystone10:31
*** markvoelker has quit IRC10:37
*** hogepodge has joined #openstack-keystone10:41
*** hogepodge has quit IRC10:46
*** hogepodge has joined #openstack-keystone10:48
*** hogepodge has quit IRC10:53
*** hogepodge has joined #openstack-keystone10:57
*** hogepodge has quit IRC11:02
*** hogepodge has joined #openstack-keystone11:11
*** hogepodge has quit IRC11:15
*** markvoelker has joined #openstack-keystone11:33
*** markvoelker has quit IRC11:37
*** hogepodge has joined #openstack-keystone12:20
*** hogepodge has quit IRC12:26
*** hogepodge has joined #openstack-keystone12:38
*** hogepodge has quit IRC12:43
*** hogepodge has joined #openstack-keystone12:44
*** hogepodge has quit IRC12:48
*** hogepodge has joined #openstack-keystone12:54
*** hogepodge has quit IRC12:58
*** hogepodge has joined #openstack-keystone13:00
*** hogepodge has quit IRC13:05
*** bknudson has joined #openstack-keystone13:17
*** ChanServ sets mode: +v bknudson13:17
*** markvoelker has joined #openstack-keystone13:22
*** markvoelker has quit IRC13:26
*** vg_ has quit IRC13:45
*** rushiagr_away is now known as rushiagr13:47
*** hogepodge has joined #openstack-keystone13:56
*** hogepodge has quit IRC14:00
*** hogepodge has joined #openstack-keystone14:01
*** hogepodge has quit IRC14:05
*** stevemar has joined #openstack-keystone14:09
*** mabrams has left #openstack-keystone14:11
*** stevemar has quit IRC14:29
*** hogepodge has joined #openstack-keystone14:34
*** arunkant_ has joined #openstack-keystone14:35
*** arunkant__ has quit IRC14:38
*** piyanai has joined #openstack-keystone14:41
openstackgerritBrant Knudson proposed openstack/keystone: Federation API provides method to evaluate rules  https://review.openstack.org/19630814:55
openstackgerritBrant Knudson proposed openstack/keystone: Change mapping model so rules is dict  https://review.openstack.org/19629314:55
*** dims has joined #openstack-keystone14:56
*** markvoelker has joined #openstack-keystone15:10
openstackgerritBrant Knudson proposed openstack/keystonemiddleware: Refactor use auth_ref.version rather than _token_is_v*  https://review.openstack.org/18901815:14
openstackgerritBrant Knudson proposed openstack/keystonemiddleware: Refactor TokenCache store takes auth_ref  https://review.openstack.org/18901915:15
*** markvoelker has quit IRC15:15
*** arunkant__ has joined #openstack-keystone15:16
*** rushiagr is now known as rushiagr_away15:17
*** arunkant_ has quit IRC15:20
*** wasmum has quit IRC15:23
*** stevemar has joined #openstack-keystone15:30
*** dims has quit IRC15:33
*** dims has joined #openstack-keystone15:34
*** stevemar has quit IRC15:35
*** dims has quit IRC15:39
openstackgerritBrant Knudson proposed openstack/keystone: Enable bandit check for password_config_option_not_marked_secret  https://review.openstack.org/19442015:41
openstackgerritBrant Knudson proposed openstack/keystone: Bandit config updates  https://review.openstack.org/19441715:41
*** piyanai has quit IRC15:43
*** rushiagr_away is now known as rushiagr15:45
*** dims has joined #openstack-keystone15:46
openstackgerritBrant Knudson proposed openstack/keystone: admin and public httpd files  https://review.openstack.org/19444215:53
openstackgerritBrant Knudson proposed openstack/keystone: admin and public httpd files  https://review.openstack.org/19444215:55
*** stevemar has joined #openstack-keystone15:57
openstackgerritBrant Knudson proposed openstack/keystone: Document update sample config up to developer  https://review.openstack.org/19490615:59
openstackgerritBrant Knudson proposed openstack/keystone: Update MANIFEST.in  https://review.openstack.org/19532716:01
*** dims has quit IRC16:02
*** arunkant_ has joined #openstack-keystone16:05
*** arunkant__ has quit IRC16:08
*** wasmum has joined #openstack-keystone16:09
*** dims has joined #openstack-keystone16:10
*** dims has quit IRC16:11
*** gabriel-bezerra has quit IRC16:17
*** browne has joined #openstack-keystone16:27
*** browne has quit IRC16:34
*** iamjarvo has joined #openstack-keystone16:39
*** iamjarvo has quit IRC16:40
*** dims has joined #openstack-keystone16:44
*** dims has quit IRC16:51
*** dims has joined #openstack-keystone16:58
*** gabriel-bezerra has joined #openstack-keystone16:58
*** markvoelker has joined #openstack-keystone16:59
*** markvoelker has quit IRC17:04
*** stevemar has quit IRC17:07
*** stevemar has joined #openstack-keystone17:08
*** dims has quit IRC17:12
*** NomePadrao has joined #openstack-keystone17:17
*** NomePadrao has quit IRC17:18
*** sigmavirus24_awa is now known as sigmavirus2417:18
*** iamjarvo has joined #openstack-keystone17:22
openstackgerritBrant Knudson proposed openstack/keystone: admin and public httpd files  https://review.openstack.org/19444217:49
morganfainbergstevemar: our token provider code makes me cry17:57
morganfainbergit's just so bad.17:57
morganfainbergjamielennox: you here?17:58
morganfainbergjamielennox: or is it a wierd time for you atm? [my tz math is bad]17:58
stevemarmorganfainberg: i still like it more than the auth code18:07
*** stevemar has quit IRC18:09
*** iamjarvo has quit IRC18:09
*** stevemar has joined #openstack-keystone18:09
*** dims has joined #openstack-keystone18:13
*** stevemar has quit IRC18:14
*** stevemar has joined #openstack-keystone18:15
*** dims has quit IRC18:19
*** iamjarvo has joined #openstack-keystone18:31
sigmavirus24morganfainberg: I think it's too early for Jamie, give him a couple more hours18:36
*** arunkant__ has joined #openstack-keystone18:36
*** e0ne has joined #openstack-keystone18:37
*** arunkant_ has quit IRC18:40
*** rushiagr is now known as rushiagr_away18:44
*** rushiagr_away is now known as rushiagr18:47
*** markvoelker has joined #openstack-keystone18:48
*** iamjarvo has quit IRC18:49
morganfainbergsigmavirus24: yeah my brain can't do tzmath atm18:51
*** markvoelker has quit IRC18:52
openstackgerritSteve Martinelli proposed openstack/keystone: switch to oslo.cache  https://review.openstack.org/19587318:53
morganfainbergcrap18:53
morganfainbergfound a fernet token bug18:53
morganfainberg:(18:53
*** openstackgerrit has quit IRC19:02
*** openstackgerrit has joined #openstack-keystone19:02
stevemarmorganfainberg: oslo.cache was missing a whole whack of tests19:06
morganfainbergnot surprising19:06
morganfainbergstevemar: needs more cowbell19:07
lifelessmorganfainberg: EAR WORM19:08
lifelessmorganfainberg: I mean, how could you19:08
morganfainberglifeless: just like that19:08
morganfainberglifeless: ^_^19:08
lifelessclonk clonk clonk clonk19:08
lifelessI'm not really feeling it19:08
stevemarmorganfainberg: you've got one auzzie up19:08
lifelessstevemar: who?19:08
stevemari dunno19:08
morganfainberglifeless: I got a fever, and the only prescription, is more cowbell19:09
morganfainbergstevemar: we might have a NZ/kiwi/whatever they prefer to be called19:09
morganfainbergbut i don't think we have an auzzie19:09
stevemarwhooooops19:09
lifeless:)19:09
lifelessstevemar: if you were referring to me, yeah, Kiwi.19:10
stevemaras a canadian, i know how it feels19:10
morganfainbergstevemar: wait... you don't live in the US? *duck*19:10
* stevemar throws ducks at morgan19:10
morganfainbergnah, need to throw wet cats19:10
morganfainbergtake a lesson from mordred19:10
morganfainbergmore effective than ducks19:10
morganfainbergbut you're canadian.. so you can throw moose or geese19:11
morganfainberg(don't send those birds this way.. please)19:11
stevemarmorganfainberg: i'll throw a few beavers at you19:11
* morganfainberg looks at the change in flight for unifying v2 token issuance19:11
morganfainberggod. i think i need to throw them out and start over.19:12
morganfainbergmore and more and more and more and more and more and more and more and more and more and more edge cases19:12
morganfainberglifeless: so i think we're really close to being able to drop keystoneauth out onto the world.19:13
morganfainberglifeless: yay!19:13
morganfainberglifeless: just need to extract out the oslo.config stuff19:14
morganfainbergand i think we'll be 90% there or so.19:14
bknudsonfernet tokens fail tempest -- https://review.openstack.org/#/c/195780/19:18
morganfainbergbknudson: fernet tokens also don't maintain same expiration19:19
morganfainbergbknudson: just found this bug (when you rescope)19:19
morganfainbergi'll have a fix proposed soon i hope.19:20
morganfainbergunless someone beats me to it19:20
bknudsonmorganfainberg: tempest shows it -- http://logs.openstack.org/80/195780/2/check/check-tempest-dsvm-full/957b981/console.html#_2015-06-28_16_43_22_86619:20
bknudsonthere also seem to be a lot of tests that should fail but don't19:21
stevemarbknudson: "should" pfft19:21
stevemarthats just an opinion19:21
bknudsontest_list_roles_request_without_token19:21
bknudsonis supposed to raise but apparently it works19:22
*** arunkant has joined #openstack-keystone19:29
morganfainbergbknudson:  yeah19:30
*** arunkant__ has quit IRC19:31
*** stevemar has quit IRC19:33
*** stevemar has joined #openstack-keystone19:33
*** rushiagr is now known as rushiagr_away19:34
*** arunkant_ has joined #openstack-keystone19:58
*** arunkant has quit IRC20:01
mordredmorganfainberg: what did I do?20:02
morganfainbergmordred: you threw wet cats via IRC in the past20:04
*** arunkant__ has joined #openstack-keystone20:04
* mordred hands morganfainberg an emu that has been in a small cage for the last week20:05
morganfainbergbknudson: https://bugs.launchpad.net/keystone/+bug/146956320:07
openstackLaunchpad bug 1469563 in Keystone liberty "Fernet tokens do not maintain expires time across rescope" [High,Triaged]20:07
*** arunkant_ has quit IRC20:08
morganfainbergmordred: should I be worries where you get all these animals from?20:12
morganfainbergs/worries/worried20:12
*** e0ne has quit IRC20:22
*** stevemar has quit IRC20:26
*** stevemar has joined #openstack-keystone20:26
openstackgerritMorgan Fainberg proposed openstack/keystone: Maintain the expiry of v2 fernet tokens  https://review.openstack.org/19647520:33
*** markvoelker has joined #openstack-keystone20:37
*** crc32 has joined #openstack-keystone20:39
*** pnavarro|off has joined #openstack-keystone20:39
*** markvoelker has quit IRC20:41
*** crc32 has quit IRC21:00
*** dims has joined #openstack-keystone21:07
openstackgerritMorgan Fainberg proposed openstack/keystone: Do not require the token_id for converting v3 to v2 tokens  https://review.openstack.org/19647621:08
*** dims has quit IRC21:11
*** pnavarro|off has quit IRC21:21
*** stevemar has quit IRC21:21
*** stevemar has joined #openstack-keystone21:22
openstackgerritSteve Martinelli proposed openstack/keystone: switch to oslo.cache  https://review.openstack.org/19587321:26
*** iamjarvo has joined #openstack-keystone21:26
*** stevemar has quit IRC21:31
*** stevemar has joined #openstack-keystone21:31
*** hogepodge has quit IRC21:32
*** hogepodge has joined #openstack-keystone21:34
*** stevemar has quit IRC21:35
*** stevemar has joined #openstack-keystone21:36
*** stevemar has quit IRC21:42
*** stevemar has joined #openstack-keystone21:43
*** iamjarvo has quit IRC21:48
*** sigmavirus24 is now known as sigmavirus24_awa21:54
stevemarmorganfainberg: gonna need you to look @ some oslo.cache stuff when you get a chance21:55
jamielennoxmorganfainberg: what's up?21:57
openstackgerritSteve Martinelli proposed openstack/keystone: switch to oslo.cache  https://review.openstack.org/19587322:00
morganfainbergjamielennox: i think we're pretty darn close on the KSA stuff22:02
morganfainbergjamielennox: i think we need to ditch oslo_config and maybe do some minor massaging22:02
jamielennoxmorganfainberg: so i was out for most of last week so i haven't looked at those patches yet22:03
jamielennoxthe big change left is the loading split22:03
jamielennoxi don't know how we want to organize that - does it really want to be in its own library?22:04
morganfainbergjamielennox: and then figuring out how to drop oslo_config22:04
morganfainbergjamielennox: hmmm.. not sure on the split22:04
morganfainbergstevemar: ack22:04
jamielennoxplaying with it i like the seperation between classes, but i'm still not sure it needs its own librarry22:04
jamielennoxdtroyer, mordred: ^ ?22:04
jamielennoxactually has dtroyer been away?22:05
stevemarjamielennox: i think so22:05
jamielennoxhe'd be my best chance of getting some of these v3 devstack patches reviewed - they're going nowhere22:05
stevemarmorganfainberg: keystone patch: https://review.openstack.org/#/c/195873/11 and some oslo.cache ones: https://review.openstack.org/#/c/196468/ (follow the chain)22:06
stevemarjamielennox: no luck from ianw or sdague?22:06
jamielennoxstevemar: i really haven't tried yet22:07
stevemarjamielennox: wanted your opinion on https://review.openstack.org/#/c/178759/ and it's follow ons22:07
jamielennoxi was hoping something would have happened last week, i can bug ianw - he'll be around son22:07
stevemarand this one should be a no brainer: https://review.openstack.org/#/c/196414/22:07
stevemarjamielennox: this was also a nice read: https://dmsimard.com/2015/06/28/openstackclient-is-better-than-i-thought/22:08
jamielennoxstevemar: nice, the only thing is that github won't render the _PyPi links22:09
jamielennoxi think dolphm found this a while ago and i was looking for the other place he did it22:09
stevemarjamielennox: they should still link ... i think... https://pypi.python.org/pypi/python-openstackclient22:09
jamielennoxah - ok, must have been fixed22:10
*** dims has joined #openstack-keystone22:12
jamielennoxstevemar: nice, who is dmsimard? i don't recognize the nick22:14
*** dims has quit IRC22:17
morganfainbergjamielennox: David Moreau Simard ยท22:20
morganfainbergjamielennox: not sure who that is though22:20
jamielennoxmorganfainberg: no, i don't think i've come across him either22:21
morganfainbergits hot today :(22:21
jamielennoxlucky you22:22
morganfainbergjamielennox: i want cool weather already22:23
morganfainberghttp://www.wunderground.com/q/zmw:91102.1.99999?sp=KCAPASAD2222:23
mordredjamielennox: reading scrollback22:23
jamielennoxmordred: i assume you are still keen for plugin loading to be a seperate library22:23
mordredhrm. I'm not sure I have a big opinion on whether it's a separate library22:24
morganfainbergjamielennox: 36C at the moment and feels like 38C - thankfully humidity dropped was almost 60% a couple days ago, today 33% humidity22:24
morganfainbergmordred: i think it's fine if it's part of KSA - as long as we can ensure we don;t break compatibility22:24
morganfainbergcompatibility once we release that is22:25
mordredwell, the only risk is if we broke the plugin interface, right? and we don't want to do that22:25
morganfainbergyeah22:25
jamielennoxmordred: it changes part of the plugin interface22:25
*** markvoelker has joined #openstack-keystone22:25
jamielennoxit will be fine, i can patch it from keystoneclient so people won't notice22:25
jamielennoxbut it moves the .load_from_options and etc to their own object22:26
jamielennoxwhich i know dtroyer was a stickler about22:26
mordredI think I'm _probably_ fine with whichever thing you like here22:27
jamielennoxso it's partially a problem of deps22:27
mordredit's possible I havent' fully grokked the problem22:27
jamielennoxthe ideal here would be to make it so that the clouds.yaml thing could at least live close22:27
mordredso - assuming that I have a clouds.yaml and zero or more environment variables, I should wind up with a plugin name and an opaque dict of arguments22:29
mordredI'd imagine that I'd do "session = ksa.Session(plugin_type, **args) or something ... but I'm probably WAY oversimplifying22:29
jamielennoxmordred: i was hoping to bring it more as a auth.load_from_clouds or something22:29
jamielennoxie - i really don't see the point of users getting a dict cause it needs to get re-mangled22:30
mordredsure - I mean, we have an object we schelp around22:30
mordredso "session = ksa.load_from_cloud_config(my_config_object)" seems totally reasonable22:30
*** markvoelker has quit IRC22:30
mordredand/or22:31
mordredjust "ksa.load_from_clouds('cloud_name')" to have ksa make you one if you don't have one?22:31
* mordred is talking himself in circles :)22:32
jamielennoxyea, i guess it doesn't really matter22:32
jamielennoxmorganfainberg: part of the reason i came around to liking the split is talking to marekd with some of the more complex k2k and saml auths22:33
jamielennoxwhere essentially you want to reuse the same plugin object, but have different ways of loading it from the cmdline22:33
morganfainbergjamielennox: this is one of the cases i'm going to trust your decision. i think we've talked circles around a lot of this stuff in the past22:34
morganfainbergand you have the best handle on it22:34
jamielennoxi'd like to see if it's possible to make it easy to integrate the clouds.yaml stuff but it will at worst be the same22:34
*** dims has joined #openstack-keystone22:35
jamielennoxmorganfainberg: https://review.openstack.org/#/c/194470/ fixes a bug that we may want to backport22:37
*** dims has quit IRC22:37
morganfainbergi think i'm running into all sorts of gaps in fernet tokens22:40
morganfainberg:(22:40
morganfainbergjust looking at the code.22:40
morganfainbergi'm surprised they work *at all*22:40
jamielennoxheh, that's not good22:45
*** piyanai has joined #openstack-keystone22:52
bretonbtw, I am going to make a big testing of fernet tokens next week for our distro22:53
bretonmaybe it will help somehowe with polishing them22:55
morganfainbergbreton: well i'm finding more gaps with things like... our intermix v2/v3 testing23:13
morganfainbergand that fernet tokens really were written off in a corner23:13
morganfainbergbreton: so a *lot* of inconsistencies23:14
morganfainberghopefully i'll have another 3-4 changes posted today that will get them in shape23:14
morganfainbergand i think these all probably are going to need a close eye on "do we want to backport"23:15
* morganfainberg dislikes being a janitor23:15
kfox1111mroganfainberg: I gave up. way too many cooks in the kitchen. I just rebooted the spec putting all the knowlege I can on the problem in the description and folks can debate the best way to solve it. :/23:21
kfox1111s/mroganfainberg/morganfainberg/23:21
*** vilobhmm has joined #openstack-keystone23:23
*** vilobhmm has quit IRC23:29
*** vilobhmm has joined #openstack-keystone23:29
*** vilobhmm has quit IRC23:29
*** vilobhmm has joined #openstack-keystone23:29
*** mestery has joined #openstack-keystone23:36
morganfainbergkfox1111: sorry :(23:36
*** markvoelker has joined #openstack-keystone23:41
kfox1111morganfainberg: Sokay. I really do apreciate all the help youve given. At this point, I think the only way forward though is to lay out all the cards on the table, and let people propose whatever idea's they want, and then when they don't match the problem, we can just say, "wont work. go read the problem description again" rather then have to go over and over the same thing. :/23:44
morganfainbergkfox1111: yeah i was trying to keep anything i was advising on to the keystone interaction bits23:45
morganfainbergkfox1111: i didn't want to add to the mess on the other project sides(s) where i could avoid it23:45
morganfainbergkfox1111: since it's not my area of expertise.23:46
kfox1111I did kind of keep that I think. seperated things into phase1 authentication and phase 2. the phase 2 is basically what we discussed. using a barbican ca and keystone federation.23:46
*** markvoelker has quit IRC23:46
morganfainbergyep23:46
morganfainbergyou did a good job of it :)23:46
morganfainbergafaict you covered the keystone concerns decently23:46
kfox1111thanks. :)23:46
morganfainbergi wasn't super worried about what you were doing causing problems fwiw23:46
kfox1111oh good. I was hoping to capture them ok.23:46
morganfainbergwell at least when dealing with keystone23:47
morganfainberglike i said, i didn't have a "we need this" or "this is a terrible idea" view on the overall feature23:47
morganfainbergso i tried to stay out of that conversation best I could23:47
kfox1111yeah. thats cool. :)23:48
kfox1111that really gets into what people want to use openstack for. and everyone has a different opinion at the moment.23:48
openstackgerritMorgan Fainberg proposed openstack/keystone: When validating a V3 token as V2, use the v3_to_v2 conversion  https://review.openstack.org/19648323:50
kfox1111interesting... would that allow you to use v3 tokens with nova setup as v2?23:50
bknudsonyou can already use v3 tokens with nova setup as v223:51
kfox1111We've wanted to setup all of our service users in a secondary domain, but as of juno, not all services allow v3.23:51
bknudsonI'm not sure that having service users in a non-default domain even works now.23:52
kfox1111:/23:53
kfox1111we have primary ldap, secondary sql. was hoping some day to have service accounts in sql, regular accounts in ldap.23:53
kfox1111can do it the other way around, if all openstack services allow v3.23:53
bknudsonI think you'd be happier with primary sql and secondary ldap23:53
kfox1111in juno, nova -> neutron was v2 only. :/23:54
kfox1111so we had to do primary ldap just to allow users to launch vm's. :/23:54
kfox1111I wonder if Kilo provides enough v3 support to at least switch it around like you suggest. secondary ldap, primary sql.23:57
kfox1111at least then we woudn't have to have service accounts in ldap any more.23:57
bknudsonput your service accounts in the default domain in sql23:58
bknudsonthen have the other users in ldap in non-default domain23:58
kfox1111will that work in kilo? We're planning on upgrading in a couple of weeks.23:59
bknudsonthat should work even in juno23:59
kfox1111We ended up having to do primary ldap, and we ended up making just one service user account in ldap just to have something to work in the mean time.23:59

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!